All vulnerabilities
CRITICALOpSec

OPSEC-MIDNIGHT-BLIZZARD-2024

Identity · Microsoft 365 / Entra ID

Summary

Disclosed January 19, 2024, the Russian SVR-linked actor Midnight Blizzard breached Microsoft's corporate tenant by password-spraying a legacy, non-production test account that had a weak password and no MFA, using residential proxies to evade detection. The actor then abused a malicious OAuth application, leveraging the test account's permissions to grant itself Exchange Online full_access_as_app rights and read corporate mailboxes. A small percentage of corporate email accounts were accessed, including senior leadership and staff in cybersecurity and legal functions, with some emails and attachments exfiltrated. A later update noted attempts to use exfiltrated secrets and source-code repository access.

References

Related vulnerabilities

All OpSec →