Microsoft Threat Intelligence’s cover photo
Microsoft Threat Intelligence

Microsoft Threat Intelligence

Computer and Network Security

Redmond, Washington 143,160 followers

We are Microsoft's global network of security experts. Follow for security research and threat intelligence.

About us

The Microsoft Threat Intelligence community is made up of more than 10,000 world-class experts, security researchers, analysts, and threat hunters analyzing 78 trillion signals daily to discover threats and deliver timely and hyper-relevant insight to protect customers. Our research covers a broad spectrum of threats, including threat actors and the infrastructure that enables them, as well as the tools and techniques they use in their attacks.

Website
https://aka.ms/threatintelblog
Industry
Computer and Network Security
Company size
10,001+ employees
Headquarters
Redmond, Washington
Specialties
Computer & network security, Information technology & services, Cybersecurity, Threat intelligence, Threat protection, and Security

Updates

  • Microsoft Threat Intelligence reposted this

    AI is changing the physics of cybersecurity. But faster attacks don’t make the fundamentals less important. They make the cost of getting them wrong higher. Three findings from the 2026 Microsoft Digital Defense Report bring that into focus: • Exposed container workloads faced their first exploit attempt a median of just 5.3 hours after starting. • In Microsoft Defender Experts customer notifications, user execution accounted for 30% of observed initial access activity, and valid accounts another 20%. • Among valid-account intrusions, 52.2% involved follow-on credential theft. One compromised identity becomes a path to more. These are different datasets, but together they illustrate the challenge: threat actors can move quickly through access and trust that already exist inside an organization. At Black Hat this year, I discussed how threat actors follow trust. A software dependency. A developer workflow. A legitimate credential. Increasingly, an AI agent’s access to data and tools. AI can accelerate discovery and exploitation of those weaknesses. It can also help defenders find exposure earlier, connect signals faster, and shorten the time from investigation to response. But more information alone won’t close that gap. Threat intelligence has to connect with the context of the organization and change what defenders do next. In my latest blog, I explore what this year’s report means for security leaders: strengthening the foundations, securing AI systems and agents, and using AI to turn intelligence into faster action. As the distance between discovery and attack shrinks, we need to close the distance between intelligence and action. Read the blog: https://lnkd.in/gsBpnc5V

  • The 2026 Microsoft Digital Defense Report is out today, examining a threat landscape increasingly defined by interdependence. Connections among identities, AI systems, cloud services, software supply chains, edge infrastructure, and critical systems can create points of leverage where one compromise has effects far beyond the initial target. AI is accelerating familiar threat actor tradecraft rather than replacing it. Identity compromise, credential reuse, social engineering, and exploitation remain prevalent, but automation enables adversaries to conduct these activities with greater speed and scale. In 52.2% of intrusions involving valid accounts, attackers pursued additional credential theft, creating opportunities for one compromised identity to fuel further unauthorized access. These operations leave signals across identities, endpoints, infrastructure, applications, cloud environments, email, and networks. Individually, those signals may provide only a partial view. When correlated with threat intelligence, they can reveal threat actor activity across campaigns, clarify how an intrusion is progressing, and surface risks that isolated investigations may miss. For defenders, success increasingly depends on connecting telemetry quickly enough to understand adversary operations and act before threats can escalate. Get more insights on this year’s report from Terrell Cox: https://msft.it/6041alHgH Read the full 2026 Microsoft Digital Defense Report: https://msft.it/6042alHgy

  • Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability affecting internet-facing mail servers that enabled compromise without authentication or user interaction. https://msft.it/6047aYZMd Successful exploitation led to webshell deployment, reverse shells, privilege escalation, persistent remote access tooling, and collection of authentication and mailbox data. Microsoft observed both automated payload delivery and hands-on-keyboard activity on compromised mail servers. Analysis of confirmed compromises revealed multiple attack paths and pre-disclosure reconnaissance activity targeting the same injection path before public disclosure. Read the full research for technical details, detection opportunities, and mitigation guidance.

  • Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed legitimate remote monitoring and management (RMM) software through meeting invitations, PDF-themed lures, software update prompts, and other social engineering content. https://msft.it/6041acCbB After execution, the software established a remote management foothold and was used to deploy a second remote access platform, creating redundant access channels that supported persistent access and follow-on activity, including information collection and credential access operations. The activity highlights how threat actors continue to abuse legitimate administration tools to blend into normal IT operations while maintaining access and reducing detection opportunities. Read the full analysis for additional findings and guidance.

  • Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique tracked as RedFlick. https://msft.it/6042act80 RedFlick can enable CosmicPulse malware installation after a single user interaction, reducing friction in the compromise process. Combined with the actor’s updated tactics, techniques, and procedures (TTPs), these changes improve Star Blizzard’s ability to reach more targets and increase the likelihood of successful compromise. These developments reflect the actor’s continued efforts to streamline malware deployment and scale operations to support ongoing cyberespionage objectives. Get detections, indicators of compromise (IOCs), and hunting guidance from this Microsoft Threat Intelligence blog post.

  • Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware family used in a limited number of targeted operations. Observed activity has thus far aligned with activity Microsoft associates with threat actors operating from China. https://msft.it/6042acEbY NeedyMantis is typically deployed after access has already been established, suggesting it is used to maintain long-term access and support follow-on operations for selective intrusions rather than gain an initial foothold. The malware combines custom loaders, encrypted archives, and modular components that enable operators to evade analysis and extend functionality. Get detections, mitigation, indicators of compromise (IOCs), and hunting guidance from this Microsoft Threat Intelligence blog post.

  • Microsoft Security Research has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. https://msft.it/6047a9lcd Two compromised service principals divided discovery, destruction, and credential collection, with timing and overlapping token streams strongly indicating automated or scripted execution that included more than 100 storage account deletion attempts in about seven minutes. Discovered by Sysdig in July 2026, JADEPUFFER is reported to be the first documented agentic ransomware operation. These new findings expand publicly documented activity associated with Storm-3168 and indicate an evolution in the threat actor's cloud operations. Read the blog for analysis, Microsoft Defender detections, and mitigation guidance on protecting workload identities, revoking or rotating exposed credentials, and safeguarding backup and recovery resources.

  • Across multiple intrusions leading to different ransomware payloads, the ransomware affiliate tracked as Storm-2570 has used consistent post-compromise tools and techniques over time, highlighting the value of monitoring recurring attacker behaviors rather than tracking payloads alone. https://msft.it/6045a9GNz Storm-2570 has used largely uniform tradecraft, including remote access, credential theft, lateral movement, security tampering, and data exfiltration, across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Read the latest Microsoft Threat Intelligence blog for a comprehensive analysis of Storm-2570 activity, as well as Microsoft Defender detections, hunting guidance, and relevant mitigation recommendations, including tamper protection, credential hygiene, and configuring automatic attack disruption.

  • Since emerging in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, enabling sophisticated device code phishing campaigns aimed at compromising organizational accounts at scale. https://msft.it/6045a50I9 This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in over 10,000 organizations worldwide. In collaboration with partners, Microsoft DCU facilitated a disruption of EvilTokens infrastructure. https://msft.it/6046a50Ii The EvilTokens toolkit offered customers prebuilt phishing templates, landing pages, and an AI-powered assistant for tailoring emails to targets. Stolen tokens enabled email exfiltration and persistence, and in some cases were also used to grant new devices access to a compromised mailbox. Microsoft Threat Intelligence tracks the threat actor behind EvilTokens as Storm-2992. Our analysis provides Microsoft Defender detection and hunting guidance, mitigations, and resources to help defend against phishing attacks.

  • Recorded live at Black Hat, Andrew “Spike” Grant of Huntress shares real-world observations from incident response, stories from years of interacting directly with threat actors, and practical insights into identifying suspicious activity before it escalates. https://msft.it/6041aZipT Cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) and remote access tools to blend into normal activity, making it harder for defenders to distinguish authorized access from intrusion. Compromised access can be maintained through multiple remote access tools and later leveraged for ransomware deployment, data theft, or other follow-on activity, while AI-assisted phishing and social engineering continue to make initial compromise easier. Learn more on this episode of the Microsoft Threat Intelligence Podcast, hosted by Elliot Volkman.

Affiliated pages

Similar pages