Today, Microsoft is sharing information and issuing security guidance about activity originating from an advanced threat actor that is targeting high-value targets, such as government agencies and cybersecurity companies. Microsoft says, “We believe this is a nation-state operation targeting both government and private sectors. While we don’t share details specifically about individual organizations, it’s important for us to share more details about some of the threat activity we’ve discovered in recent weeks, along with guidance that security professionals can use to find and mitigate potential malicious activity.”

"We also want to assure our customers that we have not identified any vulnerabilities in Microsoft products or cloud," the company said.
Microsoft continues: “As part of our ongoing threat research, we are monitoring new indicators that could signal attacker activity . As we recently shared in the 2020 Digital Defense Report, we have delivered over 13,000 alerts to customers who were attacked by state-sponsored attacks over the past two years and have seen a rapid increase in security and operational capabilities .”
Due to the complexity of hackers' techniques and security capabilities, we want to encourage greater scrutiny from the broader community. While these elements are not present in every attack, these techniques are part of this hacker's toolbox.
- A malicious code intrusion into the SolarWinds Orion product. This results in the attacker gaining a network foothold, which the attacker can use to gain elevated privileges. Microsoft Defender scans for these files.
- An attacker who uses administrative gained through an on-premises breach to gain access to an organization's trusted SAML token. This allows them to forge SAML tokens that impersonate any of the organization, including accounts with highly privileged permissions.
- Anomaly logins using SAML tokens generated by a compromised token signing certificate, which can be used against any internal resources, as well as against any cloud, because they are configured to trust the certificate. Because SAML tokens are signed with their own trusted certificate, the anomalies may be missed by the organization.
- Using highly privileged accounts obtained through the above technique or by other means, attackers can add their own credentials to existing application service principals, allowing them to call APIs with the permission granted to that application.
Here you can see the company's detailed instructions .
Information source: blogs.microsoft.com
