Case #003: The Key to the Kingdom

Target: Microsoft

Date: January 2024

Threat Actor: Storm-0558 / Midnight Blizzard (Russian SVR)

Attack Vector: Stolen Signing Key & Non-Human Identity Exploitation

Impact: Widespread geopolitical fallout, severe reputational damage and overhaul of cloud identity architecture

The Crack

Forgotten Non-Production Accounts & Over-Privileged SaaS Integrations

Attackers don’t always need complex zero-days when legacy configurations exist. A dormant, non-production test tenant lacked Multi-Factor Authentication (MFA) and hosted a forgotten, high-privilege OAuth application. By exploiting this single weak point, the threat actor bridged the gap between a non-critical test environment and Microsoft’s core production infrastructure.  

The Execution

  • Password Spraying Entry: Attackers launched a low-and-slow password spraying campaign via residential proxies to evade detection controls, successfully compromising a legacy test account that lacked MFA protection.  
  • OAuth Key Hijacking: Using the compromised test account, the attackers created new credentials for a legacy, dormant OAuth app that had previously been granted high-level permissions across Microsoft’s corporate Microsoft Entra ID (formerly Azure AD) environment.  
  • Lateral Movement & Privilege Escalation: Leveraging the OAuth app’s Graph API permissions (⁠Directory.ReadWrite.All⁠), they generated new malicious administrative users and apps inside the main corporate tenant.  
  • Persistent Mailbox Access: The attackers granted their malicious OAuth applications the ⁠full_access_as_app⁠ permission for Office 365 Exchange Online, giving them full, persistent access to executive, cybersecurity, and legal team mailboxes without needing user credentials.  

The Blast Radius

  • Executive Surveillance: Threat actors maintained undetected access for months, monitoring communications from Microsoft senior leadership, cybersecurity staff, and legal teams to understand what Microsoft knew about their operations.  
  • Secondary Source Code Compromise: The state-backed hackers subsequently used exfiltrated mailbox information and secrets to gain unauthorized access to source code repositories and internal systems.
  • Mandatory Cloud Architecture Overhaul: The incident forced Microsoft to drastically alter its internal risk management, fast-tracking its Secure Future Initiative (SFI) and overhauling cross-tenant permissions, identity management, and legacy test environments across the enterprise.

The Hardening Plan

  • Enforce Universal MFA Without Exception: Extend Multi-Factor Authentication (and preferably phishing-resistant FIDO2 tokens) to every account, including test tenants, sandbox environments, and legacy accounts.  
  • Audit Non-Human Identities (NHIs) & OAuth Apps: Treat service principals, OAuth tokens, and API integrations with the same governance as human admins. Continuously scan for over-privileged, dormant, or cross-tenant app consents.  
  • Isolate Test & Production Tenants: Maintain strict boundary separation between non-production sandbox environments and enterprise production tenants to prevent lateral movement.
  • Monitor API Volume Spikes: Implement anomaly detection rules specifically targeted at spikes in Exchange Web Services (EWS) or Microsoft Graph API calls coming from third-party or non-standard applications.

Scroll to Top