We are Microsoft's global network of security experts. Follow for security research and threat intelligence.

Redmond, WA
Microsoft Security Research has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. msft.it/6015a9lob Two compromised service principals divided discovery, destruction, and credential collection, with timing and overlapping token streams strongly indicating automated or scripted execution that included more than 100 storage account deletion attempts in about seven minutes. Discovered by Sysdig in July 2026, JADEPUFFER is reported to be the first documented agentic ransomware operation. These new findings expand publicly documented activity associated with Storm-3168 and indicate an evolution in the threat actor's cloud operations. Read the blog for analysis, Microsoft Defender detections, and mitigation guidance on protecting workload identities, revoking or rotating exposed credentials, and safeguarding backup and recovery resources.
1
21
76
12,772
Across intrusions leading to different ransomware payloads, the ransomware affiliate Storm-2570 has used consistent post-compromise tools and techniques, highlighting the value of monitoring recurring attacker behaviors rather than tracking payloads alone. msft.it/6015a9GkD Storm-2570 has used largely uniform tradecraft, including remote access, credential theft, lateral movement, security tampering, and data exfiltration, across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Read the latest Microsoft Threat Intelligence blog for a comprehensive analysis of Storm-2570 activity, as well as Microsoft Defender detections, hunting guidance, and relevant mitigation recommendations, including tamper protection, credential hygiene, and configuring automatic attack disruption.
3
17
75
13,303
Since emerging in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, enabling sophisticated device code phishing campaigns aimed at compromising organizational accounts at scale. msft.it/6015a50C3
6
30
97
11,577
This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than12,000 inboxes in over 10,000 organizations worldwide. In collaboration with partners, Microsoft DCU facilitated a disruption of EvilTokens infrastructure and operations. msft.it/6016a50CO
2
2
2
2,911
The EvilTokens toolkit offered customers prebuilt phishing templates, landing pages, and an AI-powered assistant for tailoring emails to targets. Stolen tokens enabled email exfiltration and persistence, and in some cases were also used to grant new devices access to a compromised mailbox. Microsoft Threat Intelligence tracks the threat actor behind EvilTokens as Storm-2992. Our analysis provides Microsoft Defender detection and hunting guidance, mitigations, and resources to help defend against phishing attacks.
2
1
2,047
Recorded live at Black Hat, Andrew “Spike” Grant of Huntress shares real-world observations from incident response, stories from years of interacting directly with threat actors, and insights into identifying suspicious activity before it escalates. msft.it/6018aZiGE Cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) and remote access tools to blend into normal activity, making it harder for defenders to distinguish authorized access from intrusion. Compromised access can be maintained through multiple remote access tools and later leveraged for ransomware deployment, data theft, or other follow-on activity, while AI-assisted phishing and social engineering continue to make initial compromise easier. Learn more on this episode of the Microsoft Threat Intelligence Podcast, hosted by Elliot Volkman.
5
23
8,658
Microsoft Security Research has observed an invoice fraud campaign that sent more than one million emails in three days, using templates that indicated AI-assisted development, including verbose HTML comments, structured labels, uniform construction. msft.it/6016akhVn The campaign used executive impersonation, fake vendor invoices, lookalike domains, and third-party email delivery infrastructure to target finance personnel. It combined spoofed sender and reply-to display names, executive signatures, fabricated forwarded conversations, and ACH requests of nearly $50,000. Read our latest blog for IOCs, Microsoft Defender detections, mitigation guidance, and recommendations for email authentication, spoof protection, and other configurations.
2
33
108
10,828
Microsoft developed the Cloud web applications threat matrix to organize relevant techniques across cloud-hosted web applications and serverless platforms using MITRE ATT&CK tactics. msft.it/6015ak507 The matrix can help security teams assess visibility gaps, prioritize hardening, and plan investigations across application code, managed runtimes, workload identities, deployment pipelines, and connected cloud resources. Read the blog to learn more about the framework, the technique catalog, and guidance for reducing exposure across cloud-native environments.
1
27
83
9,579
Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins are followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, and cloud data access. msft.it/6010aknRC The activity begins with identity-focused social engineering, progresses through authentication persistence and cloud reconnaissance, and is followed by targeted data access consistent with data collection and potential exfiltration. Microsoft Threat Intelligence assesses that the initial access activity observed in this campaign is used by multiple threat actors, including Storm-3121, Storm-3032, and others. Defenders should focus on the behavioral sequence rather than individual indicators. Monitor for unusual sign-ins, authentication method changes, Microsoft Graph reconnaissance, and abnormal cloud data access. Read the research for detections and hunting guidance.
2
48
175
18,387
The September 2026 security updates are available. In addition, starting today, Microsoft is publishing Vulnerability Exploitability eXchange (VEX) statements for all Microsoft-assigned CVEs. Learn more: msft.it/6012aXv5M
Security updates for September are now available: msft.it/6018SZEg0. Alongside this month's release, we're expanding machine-readable Vulnerability Exploitability eXchange (VEX) coverage to all Microsoft-assigned CVEs, providing customers with more consistent, machine-readable security information to help understand exposure and prioritize risk. Learn more about this latest milestone in our transparency efforts: microsoft.com/en-us/msrc/blo…
3
28
115
17,571
Microsoft Security Researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized by AI prompt injection research as ASCII smuggling, to obscure financial lure words before email filters parsed them. msft.it/6017apIGx Microsoft telemetry linked the technique to a large-scale finance-themed phishing operation that persisted for months, using hundreds of rotating sender domains and consistent infrastructure patterns. The research shows how techniques popularized in AI security research can quickly cross into traditional phishing campaigns as threat actors adapt tradecraft across domains. Learn how to identify this activity and strengthen detection against similar tradecraft.
9
36
160
19,711
Microsoft Threat Intelligence is tracking a human-operated intrusion campaign in which attackers are impersonating IT personnel & abusing external Teams collaboration to gain remote access and deploy a Node.js implant for persistent command execution & C2. msft.it/6010apXAw After establishing access, the attackers use trusted tooling to perform reconnaissance, capture screenshots, execute follow-on payloads, and move laterally toward domain controllers, certificate authorities, and other high-value systems. Organizations should restrict Teams external access to trusted domains, reinforce user education, and harden systems against social engineering. Read the blog for analysis, Microsoft Defender coverage, indicators, hunting queries, and mitigation guidance.
3
57
160
22,207
Microsoft Defender Experts is tracking a malware campaign that uses counterfeit software-download sites impersonating trusted vendors and dynamically generated installer archives to deliver multistage payloads leading to system compromise. msft.it/6011aTt3H Once executed, the malware payloads establish persistence through scheduled tasks, abuse trusted binaries, leverage a legitimate updater framework for payload delivery, inject code into legitimate processes, and communicate with command-and-control infrastructure over non-standard ports. Defenders should prioritize preventing downloads from untrusted sources and hunting for behavioral indicators rather than file names or hashes, which can rotate. Read the blog for an in-depth technical analysis, along with detection, mitigation, and hunting information.
2
23
97
12,200
Microsoft Threat Intelligence retweeted
Microsoft Security Research has published an in-depth technical analysis of this TerminalFix campaign, including the attack chain, indicators of compromise, as well as detections, mitigations, and hunting guidance: msft.it/6018aRXJG
7
39
7,531
Microsoft Security Research is investigating a TerminalFix campaign, a variant of the ClickFix technique, that leads to a reverse-tunnel implant capable of providing network-level proxy access through a compromised host. This TerminalFix campaign uses fake CAPTCHA verification prompts to facilitate user-executed PowerShell commands. Beyond the initial lure, this campaign uses DLL sideloading through LockScreenContentServer.exe, steganographic payload delivery, and persistence mechanisms. It then performs extensive reconnaissance to identify reachable systems and key infrastructure. Organizations should investigate devices where users interacted with suspicious CAPTCHA verification prompts and look for unusual execution of LockScreenContentServer.exe, hidden ProgramData folders, and outbound connections associated with the activity. Additional guidance and technical analysis will be published soon by Microsoft Security Research.
3
52
163
18,984
Microsoft is observing threat actors increasingly target AI infrastructure concentrating credentials, data access, model connectivity, and execution privileges, creating new opportunities to gain access, establish persistence, and monetize environments. msft.it/6017aPhKH Across multiple AI workload intrusions, attackers used different access paths but consistently sought provider credentials, database access, workflow execution, container visibility, and other resources that could support follow-on activity beyond the initially compromised system. AI infrastructure is increasingly functioning as a control plane where credential theft, host compromise, and downstream data access can converge, making these platforms attractive targets for threat actors. Read the Microsoft Security Research blog for additional analysis and guidance.
7
19
75
10,851
The ransomware attack dubbed “JADEPUFFER”, one of the first documented cases of a threat actor using large language model (LLM) to conduct an end-to-end attack, offers a glimpse into how AI could shape future ransomware campaigns. msft.it/6013aPFdv While the attack relied on familiar techniques, it demonstrated how AI can rapidly iterate, adapt to failures, and continue progressing toward an objective. In this episode of the Microsoft Threat Intelligence Podcast, Elliot Volkman speaks with Michael Clark and Crystal Morin of Sysdig about the AI-driven activity, including its ability to generate and modify code, reason through errors, and work through technical obstacles that might slow a human operator. Despite its use of AI, JADEPUFFER relied on familiar weaknesses, including exposed services, unpatched vulnerabilities, and poor credential hygiene, highlighting the continued importance of exposure management and foundational security practices.
3
33
125
17,124
Microsoft Defender is monitoring the active exploitation of the CVE-2026-65400 improper authentication vulnerability on a limited number of macOS devices, with telemetry showing successful root account network sign-ins through Screen Sharing. Microsoft urges customers to immediately apply security updates and to investigate related Microsoft Defender alerts and detections. After gaining access, the attackers transferred files (scripts and a Secure Shell (SSH) public key) to the devices through Screen Sharing, established SSH persistence, removed histories and logs, modified Packet Filter settings, and deployed the cryptocurrency miner XMRig 6.26.0. They copied and ad-hoc signed XMRig as a hidden .config/sysmond binary, masqueraded it as com[.]apple[.]airportd, and persisted it with a KeepAlive LaunchDaemon. Indicators of compromise (IOCs): - SHA-256: 84006055916e267f7c2f9324f1848563e589e4526a296d4e9e9ce8e2112d357c (customized XMRig binary produced on multiple affected devices after the stock miner binary was copied, renamed to sysmond, and ad-hoc signed) - /private/var/root/.config/sysmond (hidden path used for the customized miner) - /Library/LaunchDaemons/com.xmr.miner.plist (malicious RunAtLoad and KeepAlive persistence) - exec -a com[.]apple[.]airportd (command-line masquerading used to present the miner as an Apple process) - 4AUZ9XNsffcPn13Yjk5yWAaZg8x5Fgu9cL9kWwDCnmACUFLuwrLg41WU31qiKfmo9ee62mVbwG9F5G82Ko8vck8nCtxdicj (Monero wallet reused across the observed deployments) - auto[.]c3pool[.]org:443 (mining-pool endpoint used by the miner; treat as contextual because mining pools may also receive legitimate traffic) The stock XMRig binary and its legitimate GitHub release URL should not be treated as malicious without the surrounding adversary technique context. Microsoft Defender alerts and detections: - 'CoinMiner' malware was prevented (Investigate retained SSH access, hidden miner copies, and com.xmr.miner.plist, even when quarantine succeeds) - Suspicious file or content ingress (Inspect the responsible process, destination, signing state, and nearby persistence) - Suspicious connection to remote service (Investigate unexpected root SSH sessions and sshd-session -i -R) When hunting, higher-confidence signals combine root-level Screen Sharing file transfer activity through SSFileCopyReceiver with writes to privileged .ssh, /private/etc, hidden /private/var/tmp, or LaunchDaemon paths. Microsoft recommends updating macOS to at least Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9; disabling unnecessary Screen Sharing; blocking untrusted TCP/5900 access; inspecting SSH keys and LaunchDaemons; removing unauthorized persistence; and rotating affected credentials.
6
63
184
43,655