Microsoft has revealed that hackers , tracked as Storm-1977 , carried out password spraying attacks against cloud tenants in the education sector . The attacks took place last year.

"This particular campaign involved the use of AzureChecker.exetool Command Line Interface that is leveraged by various threat actors," said in its analysis.
See also: Bulgaria: Hackers say they stole data from Road Infrastructure Agency
Microsoft observed that the binary connected to an external server named “sac-auth.nodefunction[.]vip”, through which it downloaded encrypted (with AES) data containing a list of targets for password spraying attacks.
The tool also accepted as input a text file named “accounts.txt”, which contained username and password for executing the attacks.
"The attacker (Storm-1977) leveraged information from both files to attempt to validate credentials on the targeted accounts," Microsoft noted.
In one incident recorded by the company, the attacker managed to gain access via a guest account, then created a resource group within the infected cloud subscription. He then proceeded to create over 200 containers within this resource group for the purpose of illegally mining cryptocurrency.
See also: Lazarus hackers breached six organizations in South Korea
Microsoft warns that containerized assets, such as Kubernetes clusters, container registries, and container images, are exposed to various forms of attacks:
- Using compromised cloud credentials to take over clusters.
- Exploitation of vulnerable or incorrectly configured container images to perform malicious actions.
- Exploiting poorly configured management interfaces to access the Kubernetes API and deploy malicious containers or take full control of the cluster.
- Existence of nodes running on vulnerable software or code.
To prevent such threats (attacks by the Storm-1977 group and others), Microsoft recommends that organizations strengthen security both during container deployment and execution, monitor for unusual Kubernetes API requests, implement policies that block container deployment from untrusted registries , and ensure that the images used do not contain vulnerabilities.
Targeting the education sector: General protection strategies
One of the most effective strategies is to educate staff and students about cyberattacks. This can include learning the basics of cybersecurity, understanding the most common attack techniques, and learning best practices for protecting personal and institutional data. For example, it is essential to use strong and unique logins and enable MFA on accounts wherever and whenever possible.
Additionally, the use of advanced security solutions, such as intrusion protection systems (IPS), intrusion detection systems (IDS), and antivirus software, can provide significant protection against cyberattacks. These tools can detect and repel attacks before they cause significant damage.
See also: Cookie-Bite Attack: How can hackers bypass MFA?

Network segmentation can also help protect educational institutions by preventing a potential attack from spreading to all systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Implementing a least privilege policy, which limits access to systems and applications to only those who truly need that access, can reduce the risk of cyberattacks.
Updating all software and applications is also essential, as it fixes potential security vulnerabilities that hackers can exploit.
Finally, regularly backing up important data and implementing disaster recovery plans can ensure that, even if a cyberattack occurs, data can be recovered.
Source: thehackernews.com
