Résumé
In January 2024, Microsoft revealed that Russia's foreign-intelligence service, the same APT29 behind SolarWinds, had been reading the email of its senior leadership. The way in was almost insulting in its simplicity: a forgotten, non-production test account with a weak password and no MFA. The attackers guessed the password by spraying common ones across many accounts, then pivoted through a forgotten over-privileged application to grant themselves access to corporate mailboxes, including those of executives and the security and legal teams. It is the lesson that your security is only as strong as the account you forgot about, and that even Microsoft's perimeter fell to a missing MFA checkbox.
How it happened
The Russian SVR-linked actor Midnight Blizzard (APT29, also called Nobelium) used password spraying against Microsoft's corporate tenant, trying a few common passwords across many accounts, low and slow, and routing through residential proxies to blend in. It worked on a legacy, non-production test account that had a weak password and, critically, no MFA. The spray had begun in late November 2023 and went unnoticed until 12 January 2024, roughly seven weeks of quiet access.
That account should not have mattered, but the attackers used it to reach a second forgotten asset: a legacy OAuth application that already held elevated access to Microsoft's corporate environment. Through that app they created additional malicious OAuth apps and granted themselves the Exchange Online full_access_as_app role, which opens every mailbox in the organisation. They read a small percentage of corporate email accounts, including senior leadership and members of the cybersecurity and legal teams, exfiltrating emails and attachments, in part to learn what Microsoft knew about them. Microsoft was explicit that this was not the result of any vulnerability in its products. A later update, in March 2024, disclosed a further escalation: using secrets found in the stolen email, the actor accessed some of Microsoft's source-code repositories and internal systems.
The damage
Russian intelligence read the email of Microsoft's senior executives and its security and legal staff over a period of weeks, and in a later phase some secrets and source code were exposed. For the company that secures much of the world's computing, being breached through a forgotten test account without MFA was deeply embarrassing, and coming after the separate Storm-0558 incident, it triggered serious external scrutiny and Microsoft's company-wide Secure Future Initiative. The blast radius reached past Microsoft: in April 2024 CISA issued Emergency Directive 24-02 after the SVR used secrets stolen from Microsoft's email to target US federal agencies, and the same actor was found to have separately breached Hewlett Packard Enterprise's cloud email months earlier.
Why Midnight Blizzard still matters
It is the forgotten-account, missing-MFA lesson at the highest possible level. A non-production test account with a weak password and no MFA became a full path into executive email, because it could reach a legacy application that carried standing permissions nobody had removed. The defences are unglamorous and absolute: enforce MFA on every account with no exceptions, including legacy, test, and service accounts (the very lesson of Colonial Pipeline); inventory and deprovision dormant accounts and applications and strip their standing permissions; tightly govern OAuth application consents, which were the privilege-escalation vector here; and detect password spraying. It was carried out by the same APT29 behind the SolarWinds compromise.
Comment le corriger
- Disable the compromised test account and every other dormant or non-MFA account, and revoke the malicious OAuth applications and their granted permissions.
- Reset credentials and review mailbox access; assume any mailbox the app could reach was read.
- Audit all OAuth app consents and standing permissions for other abuse, and rotate exposed secrets, especially any found in email.
Comment l’éviter
- Enforce MFA on every account without exception, including legacy, test, and service accounts; the breach turned on one account that lacked it.
- Inventory and deprovision dormant accounts and applications and strip standing permissions, so a forgotten asset is not a standing door.
- Audit and tightly govern OAuth application consents; the privilege escalation here ran through a forgotten app and malicious app grants.
- Detect password spraying (distributed low-rate failed logins across many accounts) and block residential-proxy login patterns.
Références
- https://www.microsoft.com/en-us/msrc/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/
- https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/
- https://www.microsoft.com/en-us/msrc/blog/2024/03/update-on-microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/
- https://www.cisa.gov/news-events/directives/ed-24-02-mitigating-significant-risk-nation-state-compromise-microsoft-corporate-email-system-closed
Vulnérabilités liées
Tout OpSec →- CRITICALOPSEC-SNOWFLAKE-2024
In mid-2024, a single gap, accounts without multi-factor authentication, turned into one of the largest waves of data theft ever, hitting Ticketmaster, AT&T, Santander, and around 165 other companies at once. The attackers never broke Snowflake, the cloud data platform all of them used. They simply logged in with valid usernames and passwords, harvested months or years earlier by infostealer malware from employees' personal computers and bought on criminal markets. Where MFA was not turned on, a stolen password was a full key. It is the defining lesson of the infostealer era: your breach can start on an employee's home laptop, and MFA is the difference between a leaked password and a catastrophe.
- CRITICALOPSEC-23ANDME-2023
23andMe held the most personal data there is: people's DNA. In 2023 attackers got into more than 18,000 accounts and, through a single social feature, turned that into the genetic and ancestry data of roughly 6.9 million people. The break-in required no flaw in 23andMe at all. Attackers simply took username-and-password pairs leaked from other companies' breaches and tried them, betting, correctly, that people reuse passwords. The accounts had no MFA, and 23andMe did not notice the five-month wave of automated logins. From those footholds, the attackers scraped relatives' data through an opt-in feature, and the fallout, fines, a $50 million settlement, and ultimately bankruptcy and a fire-sale of the DNA database itself, shows that a breach can be fatal even when your own systems were never hacked.
- CRITICALOPSEC-MGM-CAESARS-2023
In September 2023, two of the biggest names in Las Vegas, MGM Resorts and Caesars Entertainment, were brought to their knees, not by a sophisticated exploit, but by a phone call. The Scattered Spider group simply called the companies' IT help desks, impersonated employees, and talked the support staff into resetting their multi-factor authentication, handing the attackers a way in. From there they deployed ALPHV/BlackCat ransomware. Caesars paid about $15 million; MGM refused and took a roughly $100 million hit as slot machines, hotel keys, and check-in systems went dark for days. It is the lesson that the help desk is part of your attack surface, and that the most advanced MFA is undone by a human who can be convinced to reset it.
- CRITICALOPSEC-LASTPASS-2022
LastPass is a password manager, the digital vault tens of millions of people trusted with every password they have. In 2022 attackers got into it, and the breach unfolded in a way that turned a developer's home computer into a path to those vaults. A first intrusion stole source code. The attackers used it to identify and target one of only four engineers who held the keys to production backups, planting a keylogger on his home PC through an unpatched flaw in, of all things, his Plex media server. With his master password captured, they exfiltrated backups of customers' encrypted password vaults. The encryption held, but anyone with a weak master password was now exposed to offline cracking at the attacker's leisure. It is the lesson that a vault is only as strong as the master password protecting it, and that your blast radius includes your engineers' home machines.
- HIGHOPSEC-UBER-2022
In September 2022, an 18-year-old broke into Uber and posted screenshots of its internal systems to prove it, an embarrassingly total compromise that started with a tactic anyone can fall for: pestering. The attacker, part of the Lapsus$ group, had a contractor's stolen password, and to get past multi-factor authentication, simply spammed the contractor with login-approval prompts until, worn down and then nudged over WhatsApp by the attacker posing as IT, they tapped "approve." Once inside, the attacker found a script with a hardcoded admin password that unlocked Uber's most powerful systems at once. It is the textbook lesson in MFA fatigue, and in how one hardcoded secret turns a foothold into a takeover.
- HIGHOPSEC-TWILIO-2022
On 7 August 2022, Twilio, a company whose entire business is sending text messages and verification codes for other companies, was breached through text messages. Attackers ran an SMS phishing campaign against Twilio's own employees, texting them fake "your password expired" alerts from numbers that looked like Twilio IT and linking to convincing fake login pages. Several staff entered their credentials, handing over access to internal tools and the data of more than 200 customers, and rippling downstream to users of the secure-messaging app Signal. It was one strike in a sprawling campaign, dubbed 0ktapus, that phished around 130 companies the same way. It is the lesson that phishing-resistant MFA exists for a reason: ordinary credentials and codes can always be talked out of a human.