
Microsoft says Chinese hackers Storm-0558 stole a signing key used to compromise government email accounts from a Windows crash dump after they compromised the corporate account of a Microsoft engineer.
See also: Microsoft: Windows will soon disable insecure TLS
The attackers used the stolen MSA key to compromise the Exchange Online and Azure Active Directory (AD) accounts of about two dozen organizations, including government agencies in the United States, such as the U.S. Departments of State and Commerce.
They exploited a now-patched zero-day validation issue in GetAccessTokenForResourceAPI, which allowed them to forge signed access tokens and impersonate accounts within targeted organizations.
Windows crash dump diving
While investigating the Storm-0558 attack, Microsoft found that the MSA key was leaked in a crash dump after a consumer signing system crashed in April 2021.
Although the Windows crash dump was not supposed to include signing keys, a race condition led to the key being added. This crash dump was later moved from the company's isolated production network to the company's online debugging.
The perpetrators found the key after successfully compromising the corporate account of a Microsoft engineer, who had access to the debug environment that contained the key incorrectly included in the April 2021 crash dump.
"Due to log retention policies, we do not have logs with specific evidence of this release by this perpetrator, but this was the most likely mechanism by which the perpetrator obtained the key," Microsoft revealed today
"Our credential scanning methods did not detect its presence (this issue has been fixed).".
Broad access to Microsoft cloud services

While Microsoft said when it disclosed the incident in July that only Exchange Online and Outlook were affected, Wiz security researcher Shir Tamari later said that the compromised Microsoft consumer signing key gave Storm-0558 broad access to Microsoft cloud services.
Suggestion: Microsoft will soon get rid of a number of features from Edge
As Tamari said, the key could be used to impersonate any account on any affected Microsoft cloud-based client or application.
“This includes managed Microsoft apps, such as Outlook, SharePoint, OneDrive, and Teams, as well as client apps that support Microsoft account authentication, including those that enable the 'Sign in to Microsoft' feature,” Tamari said.
"Everything in the Microsoft world leverages Azure Active Directory auth tokens for access," Wiz CTO and co-founder Ami Luttwak also told BleepingComputer.
“An attacker with an AAD signing key is the most powerful attacker you can imagine, because they can access almost any application – as any user. This is the ultimate cyber-informant ‘shape shifter’ superpower.”.
“The old public key certificate revealed that it was issued on April 5, 2016, and expired on April 4, 2021,” Tamari added.
Redmond later told BleepingComputer that the compromised key could only be used to target apps that accepted personal accounts and had the validation bug that the Chinese hackers exploited.
In response to the security breach, Microsoft revoked all valid MSA signing keys to prevent the attackers from accessing other compromised keys. This step also effectively blocked any additional attempts to create new passwords. In addition, Microsoft migrated the newly generated access keys to the keystore used by its corporate systems.

After revoking the stolen signing key, Microsoft found no additional evidence of unauthorized access to customer accounts using the same auth token forgery technique.
Under pressure from CISA, Microsoft also agreed to extend free access to cloud logging data to help network defenders detect similar breach attempts in the future.
Previously, such logging capabilities were only available to customers with Purview Audit (Premium) logging licenses. As a result, Redmond faced significant criticism for preventing organizations from immediately detecting Storm-0558 attacks.
Read also: Windows 11 23H2: Three top new features
source of information:bleepingcomputer.com
