Storm-1283 compromises Microsoft Azure cloud accounts with stolen credentials and deploys resources for cryptomining.
Analyst brief
Storm-1283 is a threat actor targeting the Microsoft Azure cloud platform. They compromise user accounts using stolen credentials. Their primary TTPs include creating OAuth applications, taking control of resources, and deploying virtual machines for cryptomining. Defenders should focus on enforcing multi-factor authentication, monitoring for suspicious OAuth applications, and setting budget alerts for abnormal cloud compute costs.
Storm-1283
unknown
Storm-1283 is a threat actor that targeted Microsoft Azure cloud platform. They gained access to user accounts and created OAuth applications using stolen credentials, allowing them to control resources and deploy virtual machines for cryptomining. The targeted organizations incurred significant financial losses ranging from $10,000 to $1.5 million. Storm-1283 utilized compromised accounts and subscriptions to carry out their illicit activities.