“We assess this adversary is focused on espionage, such as gaining access to email systems for intelligence collection. Storm-0885’s malicious activity had gone undetected for about a month until customers alerted Microsoft to anomalous mail activity, Microsoft said. Then, the hackers exploited a token validation issue to impersonate Azure AD users and gain access to enterprise email accounts. Microsoft’s investigation determined that Storm-0558, a China-based hacking group that the firm describes as a “well-resourced” adversary, gained access to email accounts using Outlook Web Access in Exchange Online (OWA) and by forging authentication tokens to access user accounts. In its technical analysis of the attack, Microsoft explained that the hackers used an acquired Microsoft consumer signing key to forge tokens to access OWA and. State alerted Microsoft to the breach, reports CNN. The State Department was one of the several federal agencies compromised, according to The Wall Street Journal. We continue to hold the procurement providers of the U.S. “Officials immediately contacted Microsoft to find the source and vulnerability in their cloud service. government safeguards identified an intrusion in Microsoft’s cloud security, which affected unclassified systems,” Hodge told TechCrunch in a statement. Microsoft has not identified the government agencies targeted by Storm-0558. Adam Hodge, a spokesperson for the White House’s National Security Council, confirmed to TechCrunch that U.S. “Storm” is a nickname used by Microsoft to track hacking groups that are new, emerging or “in development.” The hacking group, tracked as Storm-0558, compromised approximately 25 email accounts, including government agencies, as well as related consumer accounts linked to individuals associated with these organizations, according to Microsoft. government employees, the technology giant has confirmed. Chinese hackers exploited a flaw in Microsoft’s cloud email service to gain access to the email accounts of U.S.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |