Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

181–190 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#181

Earlier quoted context omitted.

I find this reply incredibly cynical. GP is clearly saying "this is important because small people will get hurt invisibly" and your hot take is that them being exploited isn't going to impact Microsoft's bottom line, so this isn't newsworthy? This is vice-signaling.

Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attac…

> It says nothing about users being compromised.

Making my point. It doesn't mean users weren't compromised. And even if it did, that doesn't make it so for every security breach.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#182
post #58

How did they pivot from a test tenant to corporate email access? That's the most concerning fact that they just glossed over.

I wouldn't put it passed them to straight up lie about the vector. How many have worked in these situations where some slick dicky worked up the word salad to make issues sound like non-issues?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#183
post #179

Earlier quoted context omitted.

They’ve been around for a while and identified by several governments. “NOBELIUM is an advanced persistent threat group also known as APT29, which is publicly attributed to the Russian government and specifically to the Foreign Intelligence Service of the Russian Federation (SVR)” https://blogs.blackberry.com/en/2023/03/nobelium-targets-eu-...

It still doesn't answer how they know that: 1) they were hacked by that exact group 2) that group is sponsored by the Russian government. The only evidence I've seen before in cases like this one was that they found that the hacks happened during Russia's working hours (i.e. Moscow timezone), and that they found some word in Cyrillic in some of the shell scripts. Which is honestly not hard to pull off if you want to…

I am not going to go read every MS blog on this group to find the original attribution, but generally it is from reusing infrastructure associated with a government (often even more specifically, a branch of government). IP addresses, correlated email accounts, domains, who they have targeted in the past, code ties between the malware they use, etc. These indicators can be paired with government releases (CISA) or made independently for attribution.

Say some specific infrastructure is used to hack a law firm involved in prosecuting Russia for war crimes in Ukraine. Then that same infra is used to send disinfo targeting Ukrainian groups. Then the some distinct malware used in those attacks is also used to wipe machines in the Ukraine conflict. There are full time groups that track these indicators to tie one attack to another and distinguish groups. This group is likely the SVR.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#184
post #40

> Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts [...] > The attack was not the result of a vulnerability in Microsoft products or services. Hmm...

[deleted]

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#185
post #40

> Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts [...] > The attack was not the result of a vulnerability in Microsoft products or services. Hmm...

They mention it was a password spray guess.

My point is that if one can guess the password on a random test box and through that gain access to critical internal systems, you have lost the right to call your system "not vulnerable".

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#186
post #40

> Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts [...] > The attack was not the result of a vulnerability in Microsoft products or services. Hmm...

It’s technically correct but misleading: the products are not inherently flawed but their lack of MFA means the product wasn’t used in a secure configuration. I hope that this is held against them by regulators or in court because they’ve known and even advocated for FIDO-2/WebAuthn for years and there’s no excuse for not requiring them by policy.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#187
post #70

Earlier quoted context omitted.

Ever since Delve was introduced, Microsoft Outlook has felt weird to me

I’m not familiar with Delve. Care to elaborate?

Delve could lead to accidental document sharing with peer accounts?

https://learn.microsoft.com/en-us/sharepoint/delve-for-offic...

Microsoft365 is deprecating Delve in December 2024

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#189
post #180

Earlier quoted context omitted.

They are certainly identifiable from their work. State hackers are professionals and they work like other professionals do; they work 9-5 in their local time zone and they have modular implants with code reuse. Amateurs aren't like this.

That's basically the only argument I've heard so far - if a hacking activity happens between 06:00 UTC and 14:00 UTC then it must be the Russians, otherwise it's someone else. Doesn't sound like a very strong argument? "Modular implants with code reuse" - sounds like exploit kits you can buy on hacking forums.

> "Modular implants with code reuse" - sounds like exploit kits you can buy on hacking forums.

This isn't a category argument, they're using a different one than what you can get on forums.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#190

Earlier quoted context omitted.

If the blog post was written by their internal IT team, you’d be totally justified in reading “production” to include their internal systems.

No. Whether or not a system runs in production as opposed to a testing/development environment is not a question of who is writing a blog post. Microsoft produces software and services. The communications of their CEO as well as their cybersecurity and legal teams is part of that overall production process.

[deleted]
Post reply on HN