Sign in

Microsoft Threat Intelligence

@threatintel.microsoft.com
2.4K followers 57 following 696 posts

We are Microsoft's global network of security experts. Follow for security research and threat intelligence. aka.ms/threatintelblog

PostsRepliesMedia
Microsoft Threat Intelligence @threatintel.microsoft.com · 11/09/2026
Recorded live at Black Hat, Andrew “Spike” Grant of Huntress shares real-world observations from incident response, stories from years of interacting directly with threat actors, and practical insights into identifying suspicious activity before it escalates. msft.it/63322aZ9Am
132
Microsoft Threat Intelligence @threatintel.microsoft.com · 28/08/2026
Microsoft Security Research is investigating a TerminalFix campaign, a variant of the ClickFix technique, that leads to a reverse-tunnel implant capable of providing network-level proxy access through a compromised host.
Image of shield
181
Microsoft Threat Intelligence @threatintel.microsoft.com · 26/08/2026
The ransomware attack dubbed JADEPUFFER, one of the first documented cases of a threat actor using a large language model (LLM) to conduct an end-to-end attack, offers a glimpse into how AI could shape future ransomware campaigns. msft.it/63326aP26k
152
Microsoft Threat Intelligence @threatintel.microsoft.com · 19/08/2026
Microsoft Defender is monitoring the active exploitation of the CVE-2026-65400 improper authentication vulnerability on a limited number of macOS devices, with telemetry showing successful root account network sign-ins through Screen Sharing.
Image of a stylized, black shield with a white silhouette and a diagonal line, set against a gradient background of purple and orange.
183
Microsoft Threat Intelligence @threatintel.microsoft.com · 13/08/2026
In this episode of the Microsoft Threat Intelligence Podcast, Principal Threat Intelligence Analyst Crane Hassold explores how phishing and social engineering attacks are evolving beyond email in the threat landscape. msft.it/63329aydrl
132
Microsoft Threat Intelligence @threatintel.microsoft.com · 07/08/2026
On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor.
StormEncryptor ransom note
21110
Microsoft Threat Intelligence @threatintel.microsoft.com · 06/08/2026
We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized.
Observed command patterns.
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 06/08/2026
An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing.
Injected Base64 JavaScript visible in the compromised site source.Blockchain RPC traffic used to retrieve next-stage instructions.
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 06/08/2026
Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign.
Sample fake CAPTCHA instructing the victim to paste a clipboard command.
184
Microsoft Threat Intelligence @threatintel.microsoft.com · 04/08/2026
Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware.
Supply chain
163
Microsoft Threat Intelligence @threatintel.microsoft.com · 28/07/2026
Microsoft released security updates on July 14, 2026, to address CVE-2026-54121 (Certighost), an elevation-of-privilege vulnerability in Active Directory Certificate Services (AD CS).
CVE-2026-54121
182
Microsoft Threat Intelligence @threatintel.microsoft.com · 15/07/2026
“Developers are terraforming the battlefield that defenders have to fight on.” msft.it/6011vFIcv In this Microsoft Threat Intelligence Podcast episode, the authors of the new book “Threat-Driven Software Development” discuss why modern software security must be guided by how attackers operate.
130
Microsoft Threat Intelligence @threatintel.microsoft.com · 14/07/2026
Microsoft Threat Intelligence is tracking reports of a suspected compromise of AsyncAPI's release pipeline, resulting in malicious packages published to the asyncapi npm namespace. Four packages (five versions) contain obfuscated malware.
npm
152
Microsoft Threat Intelligence @threatintel.microsoft.com · 01/07/2026
AI is accelerating vulnerability research, enabling defenders to find and prioritize issues faster while also lowering barriers for threat actors. As these capabilities become more accessible, cybersecurity experts expect vulnerability volume to continue growing. msft.it/63325vtZAT
121
Microsoft Threat Intelligence @threatintel.microsoft.com · 25/06/2026
Microsoft has observed a supply chain attack targeting the Leo Platform/RStreams npm ecosystem. On June 24, 2026, at 23:04:55 UTC, a compromised maintainer account ("czirker") to publish malicious versions of 20+ npm packages in a coordinated, fully automated operation completed in under 3 seconds.
Graphic showing chains
140
Microsoft Threat Intelligence @threatintel.microsoft.com · 17/06/2026
Microsoft has identified a supply chain attack on the Mastra-AI npm ecosystem, with 80+ packages compromised via npm account takeover. The attacker introduced a phantom dependency into the compromised packages. The malicious dependency was published by a single anonymous maintainer <24 hours ago.
Image of supply chain attack
166
Microsoft Threat Intelligence @threatintel.microsoft.com · 03/06/2026
Microsoft has published an analysis of the npm supply chain compromise affecting 32 maliciously modified packages across more than 90 versions under the redhat-cloud-services npm scope and leading to credential theft and compromise of additional maintainer packages: msft.it/63329vjuvf
Visual for credential theft
040
Microsoft Threat Intelligence @threatintel.microsoft.com · 01/06/2026
Microsoft has identified a npm supply chain compromise impacting 90+ redhat-cloud-services/* packages, including patch-client 4.0.4, insights-client 4.0.4, rbac-client 9.0.3, host-inventory-client 5.0.3, etc. The payload is a self-propagating worm that infects other npm packages and self-publishes.
Image for supply chain attacks
151
Microsoft Threat Intelligence @threatintel.microsoft.com · 19/05/2026
Microsoft is investigating a new, emerging Mini Shai-Hulud npm supply chain attack targeting antv packages. Attackers compromised an antv maintainer account and published malicious versions of multiple widely used packages (for example, antv/g2).
Attack chain of Mini Shai-Hulud npm supply chain compromise targeting antv packages
2105
Microsoft Threat Intelligence @threatintel.microsoft.com · 12/05/2026
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux.
Screenshot of mistralai PyPI package v2.4.6 compromise
2126
Microsoft Threat Intelligence @threatintel.microsoft.com · 28/04/2026
With the expansion of Microsoft Sentinel User and Entity Behavior Analytics (UEBA) into new data sources spanning multi-cloud, identity providers, and authentication logs, defenders can detect behavioral anomalies across hybrid environments from a single place. msft.it/63327vHE7v
A colorful graphic showing a radar scanning icon representing new detection and hunting guidance.
122
Microsoft Threat Intelligence @threatintel.microsoft.com · 06/04/2026
While Storm-1175's methodology aligns with the TTPs of many ransomware actors, analysis of their post-compromise tactics provides insight into how organizations can disrupt attackers even if they have gained initial access to a network.
Diagram showing the Storm-1175 attack chain
010
Microsoft Threat Intelligence @threatintel.microsoft.com · 06/04/2026
The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have impacted healthcare organizations, as well as those in the education, professional services, and finance sectors in Australia, United Kingdom, and United States.
Timeline of Storm-1175's exploitation of various vulnerabilities over the last few years, including date of disclosure and date of exploitation
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 06/04/2026
The financially motivated threat actor Storm-1175 operates high-velocity campaigns that weaponize N-days, targeting web-facing systems and rapidly moving from initial access to data exfiltration and deployment of Medusa ransomware. msft.it/63323Q2R8Z
Photo of medical professional working with a computer, with the exploitation icon in overlay
133
Microsoft Threat Intelligence @threatintel.microsoft.com · 05/03/2026
In the second attack path, when a user pastes a hex-encoded, XOR-compressed command into Windows Terminal, the command downloads a .bat file invoked through cmd.exe to write a VBScript. The batch script is executed via cmd.exe with the /launched argument, and then through MSBuild.exe.
Screenshot of decoded ClickFix command
100
Microsoft Threat Intelligence @threatintel.microsoft.com · 05/03/2026
The decoded PowerShell script downloads a legitimate but renamed 7-Zip binary that extracts and executes a multi-stage attack chain that includes additional payloads, scheduled tasks, Microsoft Defender exclusions, and exfiltration of stolen machine and network data.
Screenshot of decoded ClickFix command
100
Microsoft Threat Intelligence @threatintel.microsoft.com · 05/03/2026
Microsoft Defender Experts identified a widespread ClickFix social engineering campaign in February 2026 leveraging Windows Terminal as the primary execution mechanism, rather than the traditional Win + R → paste → execute technique.
Screenshot of ClickFix lure using Windows Terminal
153
Microsoft Threat Intelligence @threatintel.microsoft.com · 26/02/2026
It evaded detection by deleting the initial downloader and by adding Microsoft Defender exclusions for the RAT components. It also added persistence using a scheduled task and startup script named world.vbs.
Screenshot of startup script
100
Microsoft Threat Intelligence @threatintel.microsoft.com · 24/02/2026
Microsoft Defender Experts uncovered a coordinated campaign targeting developers through malicious repositories disguised as legitimate Next.js projects and technical assessments leading to command and control, payload delivery, and data exfiltration: msft.it/63327QZtTN
A colorful graphic showing a radar scanning icon representing new detection and hunting guidance.
132
Microsoft Threat Intelligence @threatintel.microsoft.com · 19/02/2026
Microsoft Defender was able to confirm a small but noticeable uptick in installations of OpenClaw initiated by Cline CLI installation script during the supply chain compromise of their NPM package that lasted approximately eight hours on February 17, 2026 between 11:26 and 19:30 UTC.
Percentage of OpenClaw installations from Cline
152
Microsoft Threat Intelligence @threatintel.microsoft.com · 14/02/2026
The malicious Python performs a series of discovery commands, before dropping the final payload `%APPDATA%\WPy64-31401\python\script.vbs` and `%STARTUP%/MonitoringService.lnk`pointing to the VBScript for persistence. This final payload is a remote access trojan and called ModeloRAT.
PowerShell script running discovery commands
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 14/02/2026
Using DNS in this way reduces dependency on traditional web requests and can help blend malicious activity into normal network traffic.
Screenshot of DNS call
100
Microsoft Threat Intelligence @threatintel.microsoft.com · 13/02/2026
Microsoft Defender researchers observed attackers using yet another evasion approach to the ClickFix technique: Asking targets to run a command that executes a custom DNS lookup and parses the `Name:` response to receive the next-stage payload for execution.
ClickFix command that executes a custom DNS lookup and parses the `Name:` response to receive the next-stage payload for execution.
171
Microsoft Threat Intelligence @threatintel.microsoft.com · 05/02/2026
Cyberattacks succeed when basic controls are missing or inconsistently applied. Microsoft is engaging in Operation Winter SHIELD, an FBI Cyber Division initiative focused on closing the gap between security intent and consistent execution. msft.it/63327QMwON
Graphic reading "Microsoft supports the Winter Shield."
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 02/12/2025
This was followed by ClickFix, a technique that threat actors use to trick users into running malicious commands on their devices. If users fell for the ClickFix lure and executed a command in their Run prompt, a PowerShell script would run.
Screenshot of instructions to run a command, a technique called ClickFix
100
Microsoft Threat Intelligence @threatintel.microsoft.com · 02/12/2025
The URLs in the phishing emails redirected to an attacker-controlled landing page on the malicious domain permit-service[.]top that employed several rounds of user interaction. First, users needed to solve a slider captcha by clicking and dragging a slider.
Screenshot of landing page showing a slider CAPTCHA
100
Microsoft Threat Intelligence @threatintel.microsoft.com · 02/12/2025
On Thanksgiving eve, November 26, Microsoft detected and blocked a high-volume phishing campaign from a threat actor we track as Storm-0900. The campaign used parking ticket and medical test result themes and referenced Thanksgiving to lend credibility and lower recipients’ suspicion.
Screenshot of emails used by Storm-0900 in phishing campaign
188
Microsoft Threat Intelligence @threatintel.microsoft.com · 21/11/2025
Throughout 2025, Tycoon2FA (tracked by Microsoft as Storm-1747) has consistently been the most prolific phishing-as-a-service (PhaaS) platform observed by Microsoft. In October 2025, Microsoft Defender for Office 365 blocked more than 13 million malicious emails linked to Tycoon2FA.
Tycoon2FA Storm-1747
194
Microsoft Threat Intelligence @threatintel.microsoft.com · 18/11/2025
The Threat Intelligence Briefing Agent, which delivers daily briefings that combine Microsoft’s global threat intelligence with insights specific to each organization, is now fully integrated into the Microsoft Defender portal, available in public preview. msft.it/63329trKYc
Screenshot of the Microsoft Defender portal showing the Threat Intelligence Briefing agent
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 07/11/2025
Dive into the heart of threat intelligence as Principal Security Researcher Jonathan Bar Or reveals how proactive security research powers Microsoft’s defenses. msft.it/63325tJxpx
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 27/10/2025
Microsoft’s threat hunters are transforming cyber defense by seeking out emerging threats before they strike. Instead of waiting for alerts, these experts combine human intuition with AI-powered analysis to uncover malicious activity that others miss. msft.it/63321tBQRR
220
Microsoft Threat Intelligence @threatintel.microsoft.com · 15/10/2025
In early October 2025, Microsoft disrupted a Vanilla Tempest campaign by revoking over 200 certificates that the threat actor had fraudulently signed and used in fake Teams setup files to deliver the Oyster backdoor and ultimately deploy Rhysida ransomware.
The text "Vanilla Tempest" and the icon for financially motivated threat actors in white against a blue background.
1133
Microsoft Threat Intelligence @threatintel.microsoft.com · 14/10/2025
The October 2025 security updates are available: msft.it/6018SZEg0. #PatchTuesday #SecurityUpdateGuide
Image with "October 2025 Patch Tuesday" in white text on a blue background.
020
Microsoft Threat Intelligence @threatintel.microsoft.com · 01/10/2025
The nature of incident response is its chaos, and the second chapter of our four-part Inside Microsoft Threat Intelligence miniseries displays how Microsoft’s IR team thrives amid disorder, stepping in when environments are compromised and confidence is shaken: msft.it/63322svfky
252
Microsoft Threat Intelligence @threatintel.microsoft.com · 17/09/2025
"Microsoft Threat Intelligence is fully focused on disrupting threat actor activity." The first of a four-part Inside Microsoft Threat Intelligence miniseries gives behind-the-scenes look at how Microsoft's Digital Crimes Unit disrupted Storm-1152: msft.it/63327sWnGF
141
Microsoft Threat Intelligence @threatintel.microsoft.com · 09/09/2025
The September 2025 security updates are available: msft.it/6018SZEg0
Image with text September 2024 Patch Tuesday in whie font and blue background
031
Microsoft Threat Intelligence @threatintel.microsoft.com · 12/08/2025
The August 2025 security updates are available: msft.it/6018SZEg0
Image with Patch Tuesday in white text and the udpate logo in blue
061
Microsoft Threat Intelligence @threatintel.microsoft.com · 20/06/2025
Microsoft has continuously observed hybrid attacks leading to espionage, business interruption, and ransomware deployment that involve threat actors moving from on-premises environments to the cloud.
Diagram of an hybrid attack
121
Microsoft Threat Intelligence @threatintel.microsoft.com · 18/06/2025
While Golden SAML (Security Assertion Markup Language) attacks are less frequently observed than others, their impact can be huge. Whereas an adversary-in-the-middle (AiTM) attack only affects the account that got phished, a successful Golden SAML attack could compromise every account in an org.
142