No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Ongoing Azure Compromises Target Senior Execs, Microsoft 365 Apps

February 12, 2024
in Protection
0
Ongoing Azure Compromises Target Senior Execs, Microsoft 365 Apps


Dozens of environments and hundreds of individual user accounts have already been compromised in an ongoing campaign targeting Microsoft Azure corporate clouds.

The activity is in some ways scattershot — involving data exfiltration, financial fraud, impersonation, and more, against organizations in a wide variety of geographic regions and industry verticals — but also very honed, with tailor-made phishing directed at highly strategic individuals along the corporate ladder.

“While attackers may appear opportunistic in their approach, the extensive range of post-compromise activities suggests an increasing level of sophistication,” a Proofpoint representative tells Dark Reading. “We acknowledge that threat actors demonstrate adaptability by selecting appropriate tools, tactics, and procedures (TTPs) from a diverse toolkit to suit each unique circumstance. This adaptability reflects a growing trend within the cloud threat landscape.”

Corporate Cloud Compromise

The ongoing activity dates back at least a few months to November, when researchers first spotted suspicious emails containing shared documents.

The documents typically use individualized phishing lures and, often, embedded links that redirect to malicious phishing pages. The goal in each case is to obtain Microsoft 365 login credentials.

What stands out is the diligence with which the attacks target different, variously leverageable employees within organizations.

Some targeted accounts, for instance, belong to those with titles such as account manager and finance manager — the kinds of mid-level positions likely to have access to valuable resources or, at least, provide a base for further impersonation attempts higher up the chain.

Other attacks aim straight for the head: vice presidents, CFOs, presidents, CEOs.

Clouds Gather: Cyber Fallout for Organizations

With access to user accounts, the threat actors treat corporate cloud apps like an all-you-can-eat buffet.

Using automated toolkits, they roam across native Microsoft 365 applications, performing everything from data theft to financial fraud and more.

For example, through “My Signins,” they will manipulate the victim’s multifactor authentication (MFA) settings, registering their own authenticator app or phone number for receiving verification codes.

They also perform lateral movement in organizations via Exchange Online, sending out highly personalized messages to specially targeted individuals, particularly employees of human resources and finance departments who enjoy access to personnel info or financial resources. They’ve also been observed exfiltrating sensitive corporate data from Exchange (among other sources within 365) and creating dedicated rules aimed at erasing all evidence of their activity from victims’ mailboxes.

To defend against these potential outcomes, Proofpoint recommends that organizations pay close attention to potential initial access attempts and account takeovers — particularly a Linux user-agent that the researchers have identified as an indicator of compromise (IoC). Organizations should also enforce strict password hygiene for all corporate cloud users and employ auto-remediation policies to limit any potential damage in a successful compromise.



Editorial Team

Editorial Team

Related Posts

Artists Love the XP-Pen Magic Note Pad Drawing Tablet, and It's $140 Off During Amazon's Big Spring Sale
Protection

Artists Love the XP-Pen Magic Note Pad Drawing Tablet, and It’s $140 Off During Amazon’s Big Spring Sale

March 26, 2026
The Garmin Forerunner 265 Is a Pretty Good Buy During Amazon's Big Spring Sale
Protection

The Garmin Forerunner 265 Is a Pretty Good Buy During Amazon’s Big Spring Sale

March 26, 2026
This Hydrow Rowing Machine Delivers a Full-Body Workout, and It's $300 Off for Amazon's Big Spring Sale
Protection

This Hydrow Rowing Machine Delivers a Full-Body Workout, and It's $300 Off for Amazon's Big Spring Sale

March 26, 2026
What Happens Now That Meta and YouTube Were Found Legally Negligent
Protection

What Happens Now That Meta and YouTube Were Found Legally Negligent

March 26, 2026
If I Had a Home Gym, This Is the Storage Rack I'd Buy During Amazon's Spring Sale
Protection

If I Had a Home Gym, This Is the Storage Rack I’d Buy During Amazon’s Spring Sale

March 26, 2026
This Budget Fitbit Is Only $70 During Amazon's Big Spring Sale
Protection

This Budget Fitbit Is Only $70 During Amazon’s Big Spring Sale

March 26, 2026
Load More
Next Post
1 FAANG Stock to Buy Hand Over Fist in February and 1 to Avoid

1 FAANG Stock to Buy Hand Over Fist in February and 1 to Avoid

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Majority of Fitch-rated sub lines have AA+ rating

    0 shares
    Share 0 Tweet 0
  • The Best Luxury Hotels in Kansas City, Whether You’re Visiting for Barbecue or the World Cup

    0 shares
    Share 0 Tweet 0

Latest News

Artists Love the XP-Pen Magic Note Pad Drawing Tablet, and It's $140 Off During Amazon's Big Spring Sale

Artists Love the XP-Pen Magic Note Pad Drawing Tablet, and It’s $140 Off During Amazon’s Big Spring Sale

March 26, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

UK Pushes Ahead Temporary Ban Crypto Political Donations

UK Pushes Ahead Temporary Ban Crypto Political Donations

March 26, 2026
0

The UK government is advancing plans for a moratorium on political donations made through cryptocurrencies, following an independent review and...

StandardAero Q4 2025 slides: 16% revenue growth, LEAP momentum builds

StandardAero Q4 2025 slides: 16% revenue growth, LEAP momentum builds

March 26, 2026
0

StandardAero Q4 2025 slides: 16% revenue growth, LEAP momentum builds

Interactive Brokers lets clients move crypto from external wallets without liquidating

Interactive Brokers lets clients move crypto from external wallets without liquidating

March 26, 2026
0

Interactive Brokers now lets clients transfer supported crypto from external wallets into IBKR accounts without selling first, extending its low-fee,...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.