Target: Microsoft
Date: January 2024
Threat Actor: Storm-0558 / Midnight Blizzard (Russian SVR)
Attack Vector: Stolen Signing Key & Non-Human Identity Exploitation
Impact: Widespread geopolitical fallout, severe reputational damage and overhaul of cloud identity architecture
The Crack
Forgotten Non-Production Accounts & Over-Privileged SaaS Integrations
Attackers don’t always need complex zero-days when legacy configurations exist. A dormant, non-production test tenant lacked Multi-Factor Authentication (MFA) and hosted a forgotten, high-privilege OAuth application. By exploiting this single weak point, the threat actor bridged the gap between a non-critical test environment and Microsoft’s core production infrastructure.
The Execution
- Password Spraying Entry: Attackers launched a low-and-slow password spraying campaign via residential proxies to evade detection controls, successfully compromising a legacy test account that lacked MFA protection.
- OAuth Key Hijacking: Using the compromised test account, the attackers created new credentials for a legacy, dormant OAuth app that had previously been granted high-level permissions across Microsoft’s corporate Microsoft Entra ID (formerly Azure AD) environment.
- Lateral Movement & Privilege Escalation: Leveraging the OAuth app’s Graph API permissions (Directory.ReadWrite.All), they generated new malicious administrative users and apps inside the main corporate tenant.
- Persistent Mailbox Access: The attackers granted their malicious OAuth applications the full_access_as_app permission for Office 365 Exchange Online, giving them full, persistent access to executive, cybersecurity, and legal team mailboxes without needing user credentials.
The Blast Radius
- Executive Surveillance: Threat actors maintained undetected access for months, monitoring communications from Microsoft senior leadership, cybersecurity staff, and legal teams to understand what Microsoft knew about their operations.
- Secondary Source Code Compromise: The state-backed hackers subsequently used exfiltrated mailbox information and secrets to gain unauthorized access to source code repositories and internal systems.
- Mandatory Cloud Architecture Overhaul: The incident forced Microsoft to drastically alter its internal risk management, fast-tracking its Secure Future Initiative (SFI) and overhauling cross-tenant permissions, identity management, and legacy test environments across the enterprise.
The Hardening Plan
- Enforce Universal MFA Without Exception: Extend Multi-Factor Authentication (and preferably phishing-resistant FIDO2 tokens) to every account, including test tenants, sandbox environments, and legacy accounts.
- Audit Non-Human Identities (NHIs) & OAuth Apps: Treat service principals, OAuth tokens, and API integrations with the same governance as human admins. Continuously scan for over-privileged, dormant, or cross-tenant app consents.
- Isolate Test & Production Tenants: Maintain strict boundary separation between non-production sandbox environments and enterprise production tenants to prevent lateral movement.
- Monitor API Volume Spikes: Implement anomaly detection rules specifically targeted at spikes in Exchange Web Services (EWS) or Microsoft Graph API calls coming from third-party or non-standard applications.