Microsoft Threat Intelligence has revealed details of a cyberattack carried out by a threat actor dubbed Storm-2949, which evolved from a targeted identity breach to a large-scale breach of cloud infrastructure and sensitive enterprise systems. The campaign focused heavily on stealing data from Microsoft 365, production environments hosted on Azure, and cloud storage resources, demonstrating how compromised identities can become gateways to an organization’s entire cloud ecosystem.
See also: FlowerStorm phishing gang adopts virtual machine obfuscation

According to Microsoft, the attack evolved in two main stages: an initial identity breach phase followed by a broader takeover of the cloud infrastructure. Rather than using traditional malware or relying on conventional on-premises attack methods, the attackers exploited legitimate cloud management tools and Azure management features to blend into normal activity while gaining access to high-value systems.
Attackers exploited MFA rollback processes to take over highly privileged accounts.
The attackers first targeted employees through social engineering techniques tied to Self-Service Password Reset (SSPR) . Researchers believe Storm-2949 pretended to be internal IT support staff and convinced victims to approve multi-factor authentication (MFA) requests under the guise of regular account verification or password reset procedures.
Once a targeted user implemented the MFA prompts, the attackers reset account passwords and removed existing authentication methods, including phone numbers, email addresses, and Microsoft Authenticator. This effectively neutralized MFA protections and locked legitimate users out of their accounts. The attackers then registered their own devices for access to Microsoft Authenticator, ensuring ongoing control of the compromised accounts.
Microsoft said the group repeated this process against multiple employees, including IT staff and senior executives, indicating deliberate targeting of users with elevated access privileges.
After gaining access, Storm-2949 began conducting directory discovery operations using Microsoft Graph API executed through a custom Python script. The attackers enumerated users, applications, and service principals within the Microsoft Entra ID tenant to identify privileged accounts and map potential paths to expand access.
The attackers also attempted to establish persistence by adding credentials to a compromised service principal, although this attempt reportedly failed due to insufficient privileges. Despite this failure, they continued to examine service principals and application identifiers to identify additional long-term access opportunities.
The campaign quickly expanded to Microsoft 365 services such as OneDrive and SharePoint. Microsoft said the attackers particularly focused on sensitive IT-related documents related to VPN configurations and remote access procedures, suggesting they were looking for methods to move laterally into other environments.
See also: Apple and Which? in legal battle over iCloud

In one case, Storm-2949 used the OneDrive web interface to download thousands of files in a single operation. Similar data extraction activity occurred across multiple compromised accounts, likely because each user account had access to different shared folders and repositories. Azure Key Vaults, SQL Servers , and Storage Accounts became primary targets.
With several compromised identities under their control, the attackers turned their attention to Azure subscriptions linked to the organization's production environment. The compromised accounts reportedly had privileged custom role-based access control (RBAC) permissions in Azure, allowing broader access to Azure services and infrastructure.
Microsoft said the attackers targeted Azure App Services, Key Vaults, storage accounts, SQL databases, and virtual machines. One of their primary goals was to compromise a production Azure App Service web application that contained sensitive data.
After several failed attempts to directly access the primary application due to network and gateway restrictions, the attackers turned to secondary applications within the same ecosystem, including identity services and internal APIs. Using Azure RBAC privileges, they exploited the “microsoft.Web/sites/publishxml/action” management function to retrieve publishing profiles containing deployment credentials for services such as FTP, Web Deploy, and the Kudu management console.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Kudu, an administrative interface for Azure App Services, allowed attackers to inspect environment variables, browse application files, and execute commands within compromised applications. However, Microsoft noted that the secondary services did not provide the level of access or sensitive information that the attackers ultimately sought.
Storm-2949 then directed its efforts towards Azure Key Vault resources. A compromised account had the Owner role on a Key Vault believed to contain credentials associated with the main production application. Over a four-minute period, the attackers changed the Key Vault access settings and gained access to dozens of secrets, including database connection strings and identity credentials.
Microsoft believes that these secrets ultimately allowed access to the main production web application. After successful authentication, the attackers changed the application's password to maintain control and began extracting sensitive data.
The campaign also included attacks on Azure SQL servers and storage accounts. To gain access to the SQL infrastructure, the attackers modified firewall rules via the “microsoft.sql/servers/firewallrules/write” function, and then logged in using credentials recovered from the compromised Key Vault. Once the data was extracted, the modified firewall rules were deleted in what Microsoft described as a defense evasion tactic.
Similarly, the attackers manipulated the network access configurations of Azure storage accounts via the “microsoft.storage/storageaccounts/write” function, allowing public access from IP addresses controlled by the attackers. They also used the “microsoft.Storage/storageAccounts/listkeys/action” function to retrieve storage account keys and Shared Access Tokens (SAS).
See also: Serious vulnerabilities in Salesforce Marketing Cloud

The attackers also attempted to exploit the managed identities assigned to the virtual machines by requesting access tokens from the Azure Instance Metadata Service (IMDS). They then attempted to use these tokens to gain access to production-related Key Vaults, although Microsoft said these attempts failed because the managed identities did not have sufficient permissions.
