Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network | Microsoft Security Blog
Since August 2023, Microsoft has observed intrusion activity targeting and successfully stealing credentials from multiple Microsoft customers that is enabled by highly evasive password spray attacks. Microsoft has linked the source of these password spray attacks to a network of compromised devices we track as CovertNetwork-1658, also known as xlogin and Quad7 (7777). Microsoft is publishing this blog on how covert networks are used in attacks, with the goal of increasing awareness, improving defenses, and disrupting related activity against our customers. Microsoft assesses that credentials acquired from CovertNetwork-1658 password spray operations are used by multiple Chinese threat actors. In particular, Microsoft has observed the Chinese threat actor Storm-0940 using credentials from CovertNetwork-1658. Active since at least 2021, Storm-0940 obtains initial access through password spray and brute-force attacks, or by exploiting or misusing network edge applications and services. S
Since August 2023, Microsoft has observed intrusion activity targeting and successfully stealing credentials from multiple Microsoft customers that is enabled by highly evasive password spray attacks. Microsoft has linked the source of these password spray attacks to a network of compromised devices we track as CovertNetwork-1658, also known as xlogin and Quad7 (7777). Microsoft is publishing this blog on how covert networks are used in attacks, with the goal of increasing awareness, improving defenses, and disrupting related activity against our customers. Microsoft assesses that…
saved by
related reading
- Threat actors misuse OAuth applications to automate financially driven attacksmicrosoft.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Responding to Adversary in the Middle attacksinvictus-ir.com
- Exposing and shutting down an inbox heist in actionredcanary.com
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise - Syne's Cyber Cornercybercorner.tech