Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

81–90 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#81
post #71

Earlier quoted context omitted.

1. Password spray 2. Access non-prod environment 3. ??? 4. "Look at me, look at me, I am the CEO now."

I reflexively read #4 to the tune of Flobots - Handlebars

underrated comment

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#82
post #61
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

I love how they emphasize only few were exposed. Like just a few, only our senior staff and cybersecurity team... I mean -- they aren't lying, but... Wow

Isn't the rule "if you are being targeted directly, lose all hope"?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#83
post #71

Earlier quoted context omitted.

1. Password spray 2. Access non-prod environment 3. ??? 4. "Look at me, look at me, I am the CEO now."

I reflexively read #4 to the tune of Flobots - Handlebars

It was a "Captain Phillips" reference for me.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#84
post #58

How did they pivot from a test tenant to corporate email access? That's the most concerning fact that they just glossed over.

I suspect more corpos have exposure like this than any of them would like to admit. E.g.: BigCo picks up a company SmallCo, and inherits their systems for some time. There's some cruddy ancient CRM, IT or travel system, and some random test tenant, that has hooks to email, and from there it's a short step to enumerate targets, send auto-generated emails from a trusted system and the hackers are off to the races.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#85
post #60

Earlier quoted context omitted.

Depends. If the breadcrumbs are key material which correlates to other known incidents from the same group, or exclusive tooling, or C2 infrastructure, then there is definitely something stopping them from putting breadcrumbs there. They'd have to hack the other group first in order to do so. I agree with you that seeing evidence would be nice, but I understand that there is the possibility that evidence supporting t…

As we've seen, many of the cybersecurity teams have been pwned, so a large part of the breadcrumbs they'd pattern match are already out there. Additionally, if security is poor enough, there can be more than one hacker into a system, which is another way they could accumulate breadcrumbs. This has precedent - there has been malware that uninstalls other malware.

Many? I'm only aware of the Equation group, believed to be the NSA, whose extremely powerful tools were made public.

What other threat actor's internals (and I mean more then chat logs) have been made public?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#86
post #61

Earlier quoted context omitted.

I love how they emphasize only few were exposed. Like just a few, only our senior staff and cybersecurity team... I mean -- they aren't lying, but... Wow

Isn't the rule "if you are being targeted directly, lose all hope"?

I wonder, is it any different, if it's not just average "you", but CEO? Don't they have additional security measures? May be not, I think Jeff Bezo's WhatsApp was hacked few years ago...

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#87
post #65

>Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts I have so many questions from this sentence alone. What did they password spray? Microsoft's internal identity provider? Was the non-prod system inte…

Indeed. How can they not be mandating MFA?
Post reply on HN