Threat intelligence
The Microsoft Threat Intelligence community is made up of world-class experts, security researchers, analysts, and threat hunters who analyze 100 trillion signals daily to discover threats and deliver timely and relevant insight to protect customers. See our latest findings, insights, and guidance.
Refine results
Topic
Threat intelligence
Products and services
Publish date
-
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. -
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. -
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node. -
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. -
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. -
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. -
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. -
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates.