Sign in

Microsoft Threat Intelligence

@threatintel.microsoft.com
2.4K followers 57 following 696 posts

We are Microsoft's global network of security experts. Follow for security research and threat intelligence. aka.ms/threatintelblog

PostsRepliesMedia
Microsoft Threat Intelligence @threatintel.microsoft.com · 5h
Analysis of confirmed compromises revealed multiple attack paths and pre-disclosure reconnaissance activity targeting the same injection path before public disclosure. Read the full research for technical details, detection opportunities, and mitigation guidance.
010
Microsoft Threat Intelligence @threatintel.microsoft.com · 5h
Successful exploitation led to webshell deployment, reverse shells, privilege escalation, persistent remote access tooling, and collection of authentication and mailbox data. Microsoft observed both automated payload delivery and hands-on-keyboard activity on compromised mail servers.
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 6h
Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability affecting internet-facing mail servers that enabled compromise without authentication or user interaction. msft.it/63324aYk4n
msft.it
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 | Microsoft Security Blog
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance.
132
Microsoft Threat Intelligence @threatintel.microsoft.com · 29/09/2026
The activity highlights how threat actors continue to abuse legitimate administration tools to blend into normal IT operations while maintaining access and reducing detection opportunities. Read the full analysis for additional findings and guidance.
010
Microsoft Threat Intelligence @threatintel.microsoft.com · 29/09/2026
After execution, the software established a remote management foothold and was used to deploy a second remote access platform, creating redundant access channels that supported persistent access and follow-on activity, including information collection and credential access operations.
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 29/09/2026
Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed legitimate RMM software through meeting invitations, PDF-themed lures, software update prompts, and other social engineering content. msft.it/63326acCeC
msft.it
Phishing Abuses RMM Tools for Persistent Access | Microsoft Security Blog
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity
121
Microsoft Threat Intelligence @threatintel.microsoft.com · 29/09/2026
These developments reflect the actor’s continued efforts to streamline malware deployment and scale operations to support ongoing cyberespionage objectives. Get detections, indicators of compromise (IOCs), and hunting guidance from this Microsoft Threat Intelligence blog post.
020
Microsoft Threat Intelligence @threatintel.microsoft.com · 29/09/2026
RedFlick can enable CosmicPulse malware installation after a single user interaction, reducing friction in the compromise process. Combined with the actor’s updated TTPs, these changes improve Star Blizzard’s ability to reach more targets and increase the likelihood of successful compromise.
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 29/09/2026
Since January 2026, Microsoft has observed Russian state actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique tracked as RedFlick. msft.it/63328act10
msft.it
Star Blizzard refines phishing and malware delivery with the RedFlick technique | Microsoft Security Blog
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”.
376
Microsoft Threat Intelligence @threatintel.microsoft.com · 28/09/2026
The malware combines custom loaders, encrypted archives, and modular components that enable operators to evade analysis and extend functionality. Get detections, mitigation, indicators of compromise (IOCs), and hunting guidance from this Microsoft Threat Intelligence blog post.
030
Microsoft Threat Intelligence @threatintel.microsoft.com · 28/09/2026
NeedyMantis is typically deployed after access has already been established, suggesting it is used to maintain long-term access and support follow-on operations for selective intrusions rather than gain an initial foothold.
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 28/09/2026
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware family used in a limited number of targeted operations. Observed activity has thus far aligned with activity Microsoft associates with threat actors operating from China. msft.it/63320acEdK
msft.it
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations | Microsoft Security Blog
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.
141
Microsoft Threat Intelligence @threatintel.microsoft.com · 25/09/2026
Read the blog for analysis, Microsoft Defender detections, and mitigation guidance on protecting workload identities, revoking or rotating exposed credentials, and safeguarding backup and recovery resources.
040
Microsoft Threat Intelligence @threatintel.microsoft.com · 25/09/2026
Discovered by Sysdig in July 2026, JADEPUFFER is reported to be the first documented agentic ransomware operation. These new findings expand publicly documented activity associated with Storm-3168 and indicate an evolution in the threat actor's cloud operations.
131
Microsoft Threat Intelligence @threatintel.microsoft.com · 25/09/2026
Two compromised service principals divided discovery, destruction, and credential collection, with timing and overlapping token streams strongly indicating automated or scripted execution that included more than 100 storage account deletion attempts in about seven minutes.
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 25/09/2026
Microsoft has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. msft.it/6015a9lob
msft.it
Storm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders.
163
Microsoft Threat Intelligence @threatintel.microsoft.com · 24/09/2026
Read the latest Microsoft Threat Intelligence blog for a comprehensive analysis of Storm-2570 activity, as well as Microsoft Defender detections, hunting guidance, and relevant mitigation recommendations, including tamper protection, credential hygiene, and configuring automatic attack disruption.
030
Microsoft Threat Intelligence @threatintel.microsoft.com · 24/09/2026
Storm-2570 has used largely uniform tradecraft, including remote access, credential theft, lateral movement, security tampering, and data exfiltration, across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.
130
Microsoft Threat Intelligence @threatintel.microsoft.com · 24/09/2026
Across multiple intrusions leading to different ransomware payloads, the ransomware affiliate tracked as Storm-2570 has used consistent post-compromise tools and techniques, highlighting the value of monitoring recurring attacker behaviors rather than tracking payloads alone. msft.it/63328a9HMw
msft.it
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments | Microsoft Security Blog
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment.
142
Microsoft Threat Intelligence @threatintel.microsoft.com · 22/09/2026
Microsoft Threat Intelligence tracks the threat actor behind EvilTokens as Storm-2992. Our analysis provides Microsoft Defender detection and hunting guidance, mitigations, and resources to help defend against phishing attacks.
020
Microsoft Threat Intelligence @threatintel.microsoft.com · 22/09/2026
The EvilTokens toolkit offered customers prebuilt phishing templates, landing pages, and an AI-powered assistant for tailoring emails to targets. Stolen tokens enabled email exfiltration and persistence, and in some cases were also used to grant new devices access to a compromised mailbox.
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 22/09/2026
This AI-powered cybercrime platform facilitated sophisticated business email compromise campaigns that compromised more than 12,000 inboxes in over 10,000 organizations worldwide. In collaboration with partners, Microsoft DCU facilitated a disruption of EvilTokens infrastructure. msft.it/6016a50CO
msft.it
Disrupting EvilTokens: The AI Chatbot Built for Cybercrime - Microsoft On the Issues
Microsoft, Health-ISAC, industry partners and law enforcement coordinated legal and operational action to disrupt the EvilTokens cybercrime platform.
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 22/09/2026
Since emerging in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, enabling sophisticated device code phishing campaigns aimed at compromising organizational accounts at scale. msft.it/63321a54KS
msft.it
Unmasking EvilTokens: Getting to the root of device code phishing | Microsoft Security Blog
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations.
165
Microsoft Threat Intelligence @threatintel.microsoft.com · 11/09/2026
Learn more on this episode of the Microsoft Threat Intelligence Podcast, hosted by Elliot Volkman.
020
Microsoft Threat Intelligence @threatintel.microsoft.com · 11/09/2026
Compromised access can be maintained through multiple remote access tools and later leveraged for ransomware deployment, data theft, or other follow-on activity, while AI-assisted phishing and social engineering continue to make initial compromise easier.
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 11/09/2026
Cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) and remote access tools to blend into normal activity, making it harder for defenders to distinguish authorized access from intrusion.
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 11/09/2026
Recorded live at Black Hat, Andrew “Spike” Grant of Huntress shares real-world observations from incident response, stories from years of interacting directly with threat actors, and practical insights into identifying suspicious activity before it escalates. msft.it/63322aZ9Am
132
Microsoft Threat Intelligence @threatintel.microsoft.com · 10/09/2026
Read our latest blog for IOCs, Microsoft Defender detections, mitigation guidance, and recommendations for email authentication, spoof protection, and other configurations.
021
Microsoft Threat Intelligence @threatintel.microsoft.com · 10/09/2026
The campaign used executive impersonation, fake vendor invoices, lookalike domains, & third-party email delivery infrastructure to target finance personnel. It combined spoofed sender and reply-to display names, executive signatures, fabricated forwarded threads, & ACH requests of nearly $50,000.
131
Microsoft Threat Intelligence @threatintel.microsoft.com · 10/09/2026
Microsoft Security Research has observed an invoice fraud campaign that sent more than one million emails in three days, using templates that displayed indicators consistent with AI-assisted development, including verbose HTML comments, structured labels, and uniform construction. msft.it/6016akhVn
msft.it
Protecting organizations from AI-assisted executive impersonation and invoice fraud | Microsoft Security Blog
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud.
151
Microsoft Threat Intelligence @threatintel.microsoft.com · 09/09/2026
Read the blog to learn more about the framework, the technique catalog, and guidance for reducing exposure across cloud-native environments.
020
Microsoft Threat Intelligence @threatintel.microsoft.com · 09/09/2026
The matrix can help security teams assess visibility gaps, prioritize hardening, and plan investigations across application code, managed runtimes, workload identities, deployment pipelines, and connected cloud resources.
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 09/09/2026
Microsoft developed the Cloud web applications threat matrix to organize relevant techniques across cloud-hosted web applications and serverless platforms using MITRE ATT&CK tactics. msft.it/63323ak5N5
msft.it
Threat Matrix: Mapping threats across cloud web applications | Microsoft Security Blog
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.
142
Microsoft Threat Intelligence @threatintel.microsoft.com · 09/09/2026
Defenders should focus on the behavioral sequence rather than individual indicators. Monitor for unusual sign-ins, authentication method changes, Microsoft Graph reconnaissance, and abnormal cloud data access. Read the research for detections and hunting guidance.
020
Microsoft Threat Intelligence @threatintel.microsoft.com · 09/09/2026
Microsoft Threat Intelligence assesses that the initial access activity observed in this campaign is used by multiple threat actors, including Storm-3121, Storm-3032, and others.
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 09/09/2026
The activity begins with identity-focused social engineering, progresses through authentication persistence and cloud reconnaissance, and is followed by targeted data access consistent with data collection and potential exfiltration.
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 09/09/2026
Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins are followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, and cloud data access. msft.it/63324aknMs
msft.it
Passkey-themed social engineering leads to identity and cloud compromise | Microsoft Security Blog
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance.
1710
Microsoft Threat Intelligence @threatintel.microsoft.com · 08/09/2026
The September 2026 security updates are available. In addition, starting today, Microsoft is publishing Vulnerability Exploitability eXchange (VEX) statements for all Microsoft-assigned CVEs. Learn more: msft.it/63329aXvYd
020
Microsoft Threat Intelligence @threatintel.microsoft.com · 03/09/2026
The research shows how techniques popularized in AI security research can quickly cross into traditional phishing campaigns as threat actors adapt tradecraft across domains. Learn how to identify this activity and strengthen detection against similar tradecraft.
030
Microsoft Threat Intelligence @threatintel.microsoft.com · 03/09/2026
Microsoft telemetry linked the technique to a large-scale finance-themed phishing operation that persisted for months, using hundreds of rotating sender domains and consistent infrastructure patterns.
130
Microsoft Threat Intelligence @threatintel.microsoft.com · 03/09/2026
Microsoft Security Researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized by AI prompt injection research as ASCII Smuggling, to obscure financial lure words before email filters parsed them. msft.it/63322apxE0
msft.it
ASCII smuggling crosses over from AI prompt injection to phishing evasion | Microsoft Security Blog
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them.
171
Microsoft Threat Intelligence @threatintel.microsoft.com · 02/09/2026
Organizations should restrict Teams external access to trusted domains, reinforce user education, and harden systems against social engineering. Read the blog for analysis, Microsoft Defender coverage, indicators, hunting queries, and mitigation guidance.
020
Microsoft Threat Intelligence @threatintel.microsoft.com · 02/09/2026
After establishing access, the attackers use trusted tooling to perform reconnaissance, capture screenshots, execute follow-on payloads, and move laterally toward domain controllers, certificate authorities, and other high-value systems.
120
Microsoft Threat Intelligence @threatintel.microsoft.com · 02/09/2026
Microsoft Threat Intelligence is tracking a human-operated intrusion campaign in which attackers are impersonating IT personnel and abusing external Teams collaboration to gain remote access and deploy a Node.js implant for persistent command execution and C2. msft.it/63325apXCR
msft.it
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access | Microsoft Security Blog
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity.
171
Microsoft Threat Intelligence @threatintel.microsoft.com · 02/09/2026
Defenders should prioritize preventing downloads from untrusted sources and hunting for behavioral indicators rather than file names or hashes, which can rotate. Read the blog for an in-depth technical analysis, along with detection, mitigation, and hunting information.
010
Microsoft Threat Intelligence @threatintel.microsoft.com · 02/09/2026
Once executed, the malware payloads establish persistence through scheduled tasks, abuse trusted binaries, leverage a legitimate updater framework for payload delivery, inject code into legitimate processes, and communicate with command-and-control infrastructure over non-standard ports.
110
Microsoft Threat Intelligence @threatintel.microsoft.com · 02/09/2026
Microsoft Defender Experts is tracking a malware campaign that uses counterfeit software-download sites impersonating trusted vendors and dynamically generated installer archives to deliver multistage payloads leading to system compromise. msft.it/63320aTtOs
msft.it
Counterfeit installers to system compromise: Tracking a deceptive software download campaign | Microsoft Security Blog
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat.
132
Microsoft Threat Intelligence @threatintel.microsoft.com · 29/08/2026
Microsoft Security Research has published an in-depth technical analysis of this TerminalFix campaign, including the attack chain, indicators of compromise, as well as detections, mitigations, and hunting guidance: msft.it/63325aRXHf
031
Microsoft Threat Intelligence @threatintel.microsoft.com · 28/08/2026
Organizations should also look for unusual execution of LockScreenContentServer.exe, hidden ProgramData folders, and outbound connections associated with the activity. Additional guidance and technical analysis will be published soon by Microsoft Security Research.
130
Microsoft Threat Intelligence @threatintel.microsoft.com · 28/08/2026
It then performs extensive reconnaissance to identify reachable systems and key infrastructure. Organizations should investigate devices where users interacted with suspicious CAPTCHA verification prompts.
120