Storm-2949 Microsoft 365 and Azure data-theft campaign
Campaign
Summary
Hide ▲
Show ▼
The Storm-2949 campaign is targeting Microsoft 365 and Azure production environments to steal sensitive data, increasing the risk of privileged-account takeover and cloud asset loss. Attackers are using social engineering and Self-Service Password Reset (SSPR) abuse to capture Microsoft Entra ID credentials, then expanding into mail, file, and Azure services. The operation matters because it combines account hijacking, persistence, and large-scale exfiltration from high-value cloud resources.
Related Happenings
Microsoft Entra OAuth Client ID spoofing campaign
Campaign
H score58
First: 13.07.2026 16:00
Last: 13.07.2026 16:00
Sources 1
About this happening:
A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft Entra OAuth Client ID spoofing campaign
CampaignAbout this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
Campaign
H score37
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
CampaignAbout this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
Microsoft Azure CLI password-spray campaign using ROPC
Campaign
H score24
First: 01.07.2026 08:46
Last: 01.07.2026 08:46
Sources 1
About this happening:
A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
Microsoft Azure CLI password-spray campaign using ROPC
CampaignAbout this happening: A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Fox Tempest's malware-signing service scales trusted-signed malware for ransomware gangs
Threat Actor Meta
H score26
First: 20.05.2026 00:47
Last: 20.05.2026 00:47
Sources 1
About this happening:
Microsoft disrupted Fox Tempest's malware-signing service in May 2026, cutting off a criminal platform that helped ransomware gangs and other cybercriminals obtain tru...
Fox Tempest's malware-signing service scales trusted-signed malware for ransomware gangs
Threat Actor MetaAbout this happening: Microsoft disrupted Fox Tempest's malware-signing service in May 2026, cutting off a criminal platform that helped ransomware gangs and other cybercriminals obtain tru...
Timeline
-
19.05.2026 22:35 2 articles · 1mo ago
Microsoft discloses Storm-2949 cloud data-theft campaign
Initial DisclosureMicrosoft disclosed that Storm-2949 is targeting Microsoft 365 and Azure production environments with social engineering and abuse of the Self-Service Password Reset (SSPR) flow to obtain Microsoft Entra ID credentials, hijack privileged accounts, and steal sensitive data from high-value cloud assets. The activity included Microsoft Graph API enumeration, custom Python scripts, downloading thousands of files from OneDrive, searching SharePoint for VPN configurations and IT operational files, expanding into Azure Key Vaults, Azure SQL servers, Storage accounts, app services, and virtual machines, and later deploying ScreenConnect while attempting to disable Microsoft Defender protections and wipe forensic evidence.
Show sources
- Microsoft Self-Service Password Reset abused in Azure data theft attacks — www.bleepingcomputer.com — 19.05.2026 22:35
- Microsoft Self-Service Password Reset abused in Azure data theft attacks — www.bleepingcomputer.com — 19.05.2026 22:35