Microsoft Threat Intelligence’s cover photo
Microsoft Threat Intelligence

Microsoft Threat Intelligence

Computer and Network Security

Redmond, Washington 135,351 followers

We are Microsoft's global network of security experts. Follow for security research and threat intelligence.

About us

The Microsoft Threat Intelligence community is made up of more than 10,000 world-class experts, security researchers, analysts, and threat hunters analyzing 78 trillion signals daily to discover threats and deliver timely and hyper-relevant insight to protect customers. Our research covers a broad spectrum of threats, including threat actors and the infrastructure that enables them, as well as the tools and techniques they use in their attacks.

Website
https://aka.ms/threatintelblog
Industry
Computer and Network Security
Company size
10,001+ employees
Headquarters
Redmond, Washington
Specialties
Computer & network security, Information technology & services, Cybersecurity, Threat intelligence, Threat protection, and Security

Updates

  • Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations. https://msft.it/6047aGqgU DeadLock's recovery ecosystem combines a messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process, allowing DeadLock operators to recover from some disruption efforts while maintaining continuity for victims. As defenders, law enforcement, and industry partners increase pressure on cybercriminal ecosystems, threat actors are being forced to adapt their operations and invest in new ways to maintain resilience. The ransomware employs double extortion tactics and has impacted organizations across multiple sectors and global regions. Get detections, mitigation guidance, and deeper insights into DeadLock's infrastructure, recovery ecosystem, and encryptor design from this Microsoft Threat Intelligence blog post.

  • On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor. Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by Microsoft Threat Intelligence since April 2026, and a shift away from Medusa ransomware, which the threat actor had previously been known to use. StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts. It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory. While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026. Storm-1175 is known to operate high-velocity ransomware campaigns that weaponize N-days, taking advantage of the window between vulnerability disclosure and patch adoption. https://msft.it/6042a1nVY In this new activity, Storm-1175’s post-compromise behavior includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz. This threat actor is known to rapidly move from initial access to data exfiltration and ransomware deployment, often within a few days. Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible. Microsoft Defender Antivirus detects StormEncryptor (SHA-256: c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054) as Ransom:Win64/StormEncryptor. Microsoft Defender for Endpoint detects this activity through multiple alerts, including “Hands-on-keyboard attack involving multiple devices” and “Potential human-operated malicious activity”.

    • StormEncryptor ransom note
  • Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing because only the owner of the cryptocurrency wallet that deployed it can make changes. Users are presented with a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard content, and press Enter to execute an attacker-supplied command under the guise of verification. We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized. TerminalFix lures apply the same technique but direct users to Windows Terminal or PowerShell instead of the Run dialog. This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique. Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages. Numerous actors use the technique to deliver Lumma Stealer and other infostealers, RATs such as Xworm and AsyncRAT, loaders including MintsLoader, and remote management tools. A single successful execution can expose credentials, establish persistence, enable lateral movement, and create a path to human-operated ransomware and potential domain compromise. Microsoft recommends that organizations enable Microsoft Defender network, web, and cloud-delivered protection; restrict Run and command-line tools where not required; enable PowerShell script-block logging; and implement application control. Users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command prompt. Microsoft Defender XDR provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Suspicious command in RunMRU registry”, “Possible ClickFix activity”, “Possible initial access from an emerging threat”. Microsoft Defender Antivirus blocks malicious command execution using detections such as Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. Treat these alerts as evidence of a potential initial access incident: isolate affected devices, investigate credential exposure and persistence, and hunt for related activity.

    • Sample fake CAPTCHA instructing the victim to paste a clipboard command.
    • Injected Base64 JavaScript visible in the compromised site source.
    • Blockchain RPC traffic used to retrieve next-stage instructions.
    • Observed command patterns.
  • When successful, credential harvesting can become the point where a single compromised device turns into an enterprise-wide problem. Once an intruder holds valid credentials and session tokens, they can move past the initial foothold toward broader access, higher privilege, and durable control, often without triggering defenses that look for known malware. Microsoft Threat Intelligence has tracked Storm-2945, a sub-cluster of Midnight Blizzard, running the CaptiveCrunch campaign against travelers connecting through Wi-Fi captive portals at hospitality-related venues. After redirecting users through actor-controlled infrastructure and delivering malware disguised as browser or operating system updates, the actor deployed CornFlake, a Go-based remote access trojan, and ChocoShell, an in-memory PowerShell infostealer, both built for credential theft. Together they harvested saved passwords and live session cookies from browsers, along with Microsoft 365 Single Sign-On (SSO) tokens and Wi-Fi credentials. Theft of refresh and session tokens is especially consequential, because it lets an actor replay authenticated sessions and bypass multifactor authentication: https://lnkd.in/e28EiBWq Across the second quarter of 2026, credential phishing dominated the malicious payload landscape, accounting for 94-96% of payload-based attacks each month, whether by linking users to phishing pages or loading spoofed sign-in screens locally on the device: https://lnkd.in/eDMPPwWk Attackers are also shaping those lures around current interest in AI, impersonating well-known AI brands across phishing, malvertising, and search-driven campaigns that lead to credential theft: https://lnkd.in/eV6fBxfy Attackers enter through different doors, but the credentials and privilege behind them are what turn access into control. Reducing that risk depends on disciplined identity architecture, including strong token and session controls, least-privilege design, and phishing-resistant MFA. To start, review Microsoft's identity and access management best practices: https://lnkd.in/eSMbdiC7

    Initial access is only the beginning. Once inside, attackers move quickly toward the same objectives: broader access, stronger privileges, and durable control. That is why credential harvesting remains one of the most important inflection points in an intrusion. Credential dumping and harvesting techniques appear across multiple financially motivated actors, including the use of credential theft from code repositories, DevOps pipelines, and cloud identity providers rather than just from disk. This is where a narrow compromise becomes enterprise risk. Attackers enter in different ways, but many of them expand through the same playbook: find credentials, map privilege, move laterally, and turn access into control. That is why what looks like hygiene—secret handling, privilege design, pipeline security, recovery controls—often has disproportionate strategic consequence. To reduce risk from credential theft and privilege expansion, this identity-focused guidance aligns directly with the patterns discussed: https://lnkd.in/ebrJm96n #MSFTHotCybercrimeSummer #MicrosoftSecurity #ThreatIntelligence #MSFT

    • No alternative text description for this image
  • Microsoft observed a macOS ClickFix campaign that evolved from openly serving infostealer lures to hiding them behind a server-side fingerprinting gate, exposing the content primarily to qualifying macOS visitors. https://msft.it/6049aEBu1 The campaign distributes infostealers like MacSync and Atomic Stealer (AMOS) through a large cluster of look-alike domains, using fingerprinting to determine which macOS users receive the lure while presenting benign or decoy content to other visitors. The shift makes the campaign harder to observe through traditional automated collection, increasing the importance of infrastructure- and behavior-based hunting. Read the blog from the Microsoft Security Research team for hunting guidance, detections, and recommendations.

  • Microsoft has published an in-depth technical analysis of the supply chain attack known as "ChainDrop" affecting hundreds of packages and delivering a self-propagating credential-stealing worm. Read the blog for mitigation, detection, and hunting guidance: https://msft.it/6040aDUv0

  • Attackers are increasingly establishing footholds directly on endpoints, using legitimate tools and locally executed payloads to prolong access and evade traditional containment measures. In these cases, stopping the attack requires more than containing a compromised identity. https://msft.it/6048aDcDM In a recent incident, an attacker used a legitimate Windows utility to retrieve a second-stage payload on a compromised device. Microsoft Defender correlated behavioral signals across the attack chain, reached a high-confidence verdict, and automatically enforced its new device isolation response action before the intrusion could progress. The entire sequence—from first detection to enforced isolation—took 128 seconds. No lateral movement was observed, no additional payloads were retrieved, and the incident remained contained to a single endpoint. Read the case study to see how automatic attack disruption helps stop attacks in progress.

  • Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware. Compromised packages (confirmed malicious) include: - keyv@6.0.0 - file-entry-cache@11.1.6 - cache-manager@7.2.10 - cacheable-request@13.0.20 - @qlik/api@2.14.2 - @cacheable/memory, /utils, /net - 17+ @servicetitan/* packages (eslint-config, anvil-themes, table, form, log-service, etc.) In this attack, a malicious preinstall hook launches an obfuscated dropper (setup.mjs) that downloads a Bun binary from GitHub and executes a credential-stealing payload, either Math_Symbol.js or Math_Init.js. The payload is a Mini Shai-Hulud variant, a self-propagating npm supply-chain malware family. It harvests npm, GitHub, cloud and continuous integration (CI) credentials, exfiltrates collected secrets, and uses stolen publishing access to inject itself into package tarballs, increment their versions and republish the compromised releases. Microsoft observed the same pattern across all affected packages, suggesting a single actor using multiple stolen tokens. Microsoft Defender for Endpoint customers should act on these alerts: “Trojan:npm/MalBun.A”

    • No alternative text description for this image
  • Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, compromising hospitality-related networks worldwide to steal credentials, access cloud environments, and deliver malware to travelers in an operation we call CaptiveCrunch. https://msft.it/6048aBXBe Since early May 2026, the threat actor has conducted widespread but targeted traffic manipulation attacks involving networks served by captive portals. In some cases, users were redirected through actor-controlled phishing infrastructure, while other activity led to the delivery of malware on impacted systems. Microsoft assesses Storm-2945 to be an operational sub-cluster of Midnight Blizzard and details the malware, tradecraft, and cloud-focused techniques used throughout the campaign, including device code phishing and credential theft activity targeting travelers. Get detections, mitigation, and hunting guidance from this Microsoft Threat Intelligence blog post.

Affiliated pages

Similar pages