Storm-2139 is a cybercrime group exploiting stolen Azure OpenAI API keys to bypass GenAI guardrails and generate harmful content.
Analyst brief
Storm-2139 is a cybercrime group that exploited stolen Azure OpenAI Service API keys to generate harmful content. The group targets U.S.-based enterprises, systematically harvesting their authentication tokens. Key TTPs include the use of stolen credentials, reverse proxy infrastructure, and custom software to bypass Microsoft's GenAI guardrails. Defenders should focus on securing Azure OpenAI API keys, monitoring for anomalous authentication activities, and detecting unauthorized API calls.
Storm-2139
unknown
Storm-2139 is a cybercrime group that exploited stolen API keys from compromised Azure OpenAI Service accounts to generate harmful content, including non-consensual intimate imagery, using the DALL-E model. The group utilized reverse proxy infrastructure and custom software to bypass guardrails in Microsoft’s GenAI services. Microsoft has filed a lawsuit against four individuals associated with Storm-2139, alleging they modified customer systems and resold access to these capabilities. The group systematically harvested authentication tokens from U.S.-based enterprises and is linked to a broader network of illicit AI tool development and distribution.