Threat reportCloud SecurityTL-2026-0529

Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration

criticalACTIVE

Storm-2949 Cloud-Wide Breach (TL-2026-0529), also tracked as Storm-2949 Cloud Breach, is a critical-severity cloud security threat, first published 2026-05-19. It is attributed to Storm-2949 with medium confidence, affects Microsoft Entra ID (Azure AD), maps to 40 MITRE ATT&CK techniques (T1053.005, T1059.001, T1069.003), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
40MITRE ATT&CK
Actors
1Storm-2949
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-0529

Threat ID
TL-2026-0529
Also known as
Storm-2949 Cloud Breach, Microsoft Storm-2949 Campaign
Severity
CRITICAL
Status
ACTIVE
Category
CLOUD
First published
Last reviewed
Attribution
Storm-2949
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, professional-services, healthcare, public-sector, financial-services
Target regions
North America, Western Europe
Detection rules
9
Indicators of compromise
25

Malware and tooling in Storm-2949 Cloud-Wide Breach

Malware and tooling: None — Storm-2949 operates malware-less, Azure CLI (az) and Azure PowerShell (Az), ConnectWise ScreenConnect (Control) agent, ConnectWise ScreenConnect (Control) relay tenants registered under attacker-controlled trial accounts, Microsoft.Graph PowerShell SDK, azcopy.exe

How Storm-2949 Cloud-Wide Breach works

Microsoft Threat Intelligence has attributed a malware-less, identity-driven cloud breach campaign to a newly tracked actor designated Storm-2949. The actor abuses Microsoft Entra Self-Service Password Reset (SSPR) combined with help-desk and end-user social engineering to seize accounts and bypass multi-factor authentication, then weaponises legitimate Azure RBAC permissions, Microsoft Graph enumeration, App Service publishing profiles, Storage account keys, Key Vault secrets, and Azure VM Run Command to perform mass data theft from Microsoft 365 and Azure. Persistence is established by deploying ConnectWise ScreenConnect via the VM Run Command extension after disabling Microsoft Defender for Endpoint, producing a full cloud-wide compromise without dropping traditional malware.

Storm-2949 is a financially-motivated and intrusion-for-impact threat cluster first publicly named by Microsoft Threat Intelligence in May 2026. The cluster is distinguished by an exclusively cloud-native kill chain that abuses native Microsoft Entra ID and Azure Resource Manager (ARM) features rather than custom malware, allowing the actor to operate inside the trust boundary of victim tenants and largely evade endpoint-centric detection.

Initial Access — Storm-2949 acquires a foothold by abusing Microsoft Entra Self-Service Password Reset (SSPR). The actor first harvests target identities and verification artefacts (mobile numbers, alternative email addresses, security questions, manager attributes) through pretext calls to corporate help desks and through reconnaissance of public-facing directories (LinkedIn, GitHub, conference rosters). With those artefacts the actor performs an SSPR flow against the victim tenant''s default SSPR endpoint (passwordreset.microsoftonline.com), satisfies the verification challenges (frequently using SIM-swapped or social-engineered MFA push fatigue), and resets the victim''s primary credential. Because SSPR satisfies MFA registration claims, the actor effectively bypasses Conditional Access MFA enforcement on subsequent logins. In several incidents the actor also social-engineered help-desk operators into manually clearing the targeted user''s MFA methods, achieving an MFA reset by proxy.

Discovery & Resource Development — Once authenticated, the actor performs deep tenant enumeration through Microsoft Graph using the standard delegated permissions of the compromised principal: User.Read.All, Group.Read.All, Application.Read.All, RoleManagement.Read.Directory and Directory.Read.All. Microsoft observed Graph traffic from non-corporate egress points (residential proxy and commercial VPN ranges) listing users, groups, directory role assignments, service principals, application consents, conditional access policy names and named locations. Tenant inventory data is staged to attacker-controlled OneDrive accounts or compressed in memory and exfiltrated over HTTPS to Cloudflare-worker fronted infrastructure.

Privilege Escalation — In tenants where the compromised user holds eligible Privileged Identity Management (PIM) roles, the actor activates Global Reader, Application Administrator, Cloud Application Administrator or Privileged Authentication Administrator and bridges from Entra ID into Azure subscriptions by abusing pre-existing RBAC role assignments such as Owner, Contributor, User Access Administrator, Storage Account Key Operator, Key Vault Administrator and Virtual Machine Contributor scoped at the subscription or management group level. Where direct privileges are absent, the actor adds new client secrets or certificates to existing privileged enterprise applications and authenticates as the service principal, taking advantage of the fact that service principal sign-ins are often exempt from interactive Conditional Access policies.

M365 Data Theft — The actor performs mass enumeration of OneDrive for Business and SharePoint Online sites using the Graph endpoints /v1.0/drives/{driveId}/root/search, /sites/{siteId}/lists, and /me/drive/recent. Files matching a hard-coded keyword list (passwords, secret, customer, contract, vpn, ssh, m&a, financials, source, .pem, .pfx, .kdbx, .ovpn) are downloaded in chunks. Exchange Online mailboxes are accessed using IMAP/EWS where legacy authentication is still enabled, or via Graph Mail.Read.All on consent-phished applications.

Azure Data Plane Theft — Within Azure, Storm-2949 systematically targets four data services. (1) Azure Storage — the actor issues microsoft.Storage/storageAccounts/listkeys/action against every accessible storage account, then uses the listed keys to enumerate and download blob containers and file shares with azcopy. (2) Azure SQL — to defeat IP allow-listing the actor calls microsoft.sql/servers/firewallrules/write to add a transient rule (commonly 0.0.0.0-255.255.255.255 named ''ClientIPAddress_2026-05-12_18-04-22''), authenticates with Entra credentials of synced sql_admin accounts, and bulk-exports tables with sqlcmd -Q ''select * ...'' bcp. (3) Azure Key Vault — the actor issues microsoft.KeyVault/vaults/secrets/getSecret/action and microsoft.KeyVault/vaults/keys/wrap/action against every accessible vault, retrieving database connection strings, application secrets and code-signing keys. (4) Azure App Service — the actor abuses microsoft.Web/sites/publishxml/action to download publishing profiles and then either deploys a webshell via Kudu (/api/zip, /DebugConsole) or reads connection strings and app settings to pivot back into databases.

VM Compromise & Persistence — On selected high-value Azure VMs the actor calls microsoft.Compute/virtualMachines/runCommand/action (or installs the VMAccess extension to reset the local administrator) to execute a sequence of PowerShell commands that: (a) tamper Microsoft Defender for Endpoint (Set-MpPreference -DisableRealtimeMonitoring $true, Set-MpPreference -DisableTamperProtection $true where Tamper Protection is configurable, and stopping the WinDefend service via sc.exe stop windefend after taking ownership of the service registry key); (b) download and install ConnectWise ScreenConnect MSI from an attacker-controlled Azure Front Door endpoint; (c) configure the ScreenConnect agent against attacker-controlled relay tenants instance-relay.screenconnect[.]com:8041 hosted under attacker-registered ConnectWise Control trials; (d) create a scheduled task ''Microsoft\Windows\UpdateOrchestrator\Heartbeat'' for persistence. ScreenConnect provides interactive RDP-equivalent access with native binary signed by ConnectWise, defeating signature-based detection.

Impact — Microsoft documented terabyte-scale exfiltration of M365 and Azure data, Key Vault secret theft used to pivot into downstream SaaS services, and in two incidents the actor used the same access to read Microsoft Sentinel and Defender data, identify which of their actions had triggered alerts, and re-tool. No ransomware or wiper has been deployed by Storm-2949 to date; observed motivations are data theft, extortion, and follow-on access brokering. The campaign is broadly cross-vertical with confirmed victims in technology, professional services, healthcare and the public sector across North America and Western Europe.

MITRE ATT&CK techniques used in TL-2026-0529

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1098.001 Account Manipulation: Additional Cloud Credentials; T1098.003 Account Manipulation: Additional Cloud Roles; T1136.003 Create Account: Cloud Account

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1648 Serverless Execution; T1651 Cloud Administration Command

Discovery

T1069.003 Permission Groups Discovery: Cloud Groups; T1087.004 Account Discovery: Cloud Account; T1526 Cloud Service Discovery; T1538 Cloud Service Dashboard; T1619 Cloud Storage Object Discovery

Initial Access

T1078.004 Valid Accounts: Cloud Accounts; T1199 Trusted Relationship

Command and Control

T1102 Web Service

Collection

T1114.002 Email Collection: Remote Email Collection; T1213.002 Data from Information Repositories: SharePoint; T1530 Data from Cloud Storage

command-and-control

T1219 Remote Access Tools

Privilege Escalation

T1484.002 Domain or Tenant Policy Modification: Trust Modification

Credential Access

T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials in Files; T1552.005 Unsecured Credentials: Cloud Instance Metadata API; T1556.006 Modify Authentication Process: Multi-Factor Authentication; T1606.002 Forge Web Credentials: SAML Tokens; T1621 Multi-Factor Authentication Request Generation

Exfiltration

T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Lateral Movement

T1550.001 Use Alternate Authentication Material: Application Access Token; T1550.004 Use Alternate Authentication Material: Web Session Cookie

Defense Evasion

T1564.011 Hide Artifacts: Ignore Process Interrupts

defense-impairment

T1578.005 Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations; T1685 Disable or Modify Tools; T1685.002 Disable or Modify Cloud Log

Resource Development

T1583.006 Acquire Infrastructure: Web Services; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1589 Gather Victim Identity Information; T1589.001 Gather Victim Identity Information: Credentials; T1589.003 Gather Victim Identity Information: Employee Names

Impact

T1657 Financial Theft

Affected products and versions in Storm-2949 Cloud-Wide Breach

  • Microsoft — Entra ID (Azure AD)
    Vulnerable versions: All tenants with SSPR enabled and non-phishing-resistant MFA methods
  • Microsoft — Microsoft 365 (OneDrive, SharePoint, Exchange Online)
    Vulnerable versions: All tenants
  • Microsoft — Azure Resource Manager
    Vulnerable versions: All subscriptions with broad RBAC assignments
  • Microsoft — Azure Key Vault
    Vulnerable versions: Vaults with public network access and broad data-plane access policies
  • Microsoft — Azure Storage
    Vulnerable versions: Storage accounts with shared-key access enabled
  • Microsoft — Azure SQL Database
    Vulnerable versions: Servers with public network access and IP-firewall-only protection
  • Microsoft — Azure App Service
    Vulnerable versions: Web Apps with publishing profile-based deployment enabled
  • Microsoft — Azure Virtual Machines
    Vulnerable versions: VMs with Run Command / VMAccess extension permitted
  • ConnectWise — ScreenConnect (Control)
    Vulnerable versions: Hosted relays abused by attacker-registered trial tenants

Remediation for Storm-2949 Cloud-Wide Breach

Patches

  • No CVE patch — campaign abuses by-design tenant features; mitigation is configuration and policy hardening
  • Apply latest Microsoft Defender for Endpoint platform and security intelligence updates with Tamper Protection in tenant-locked enforcement

Immediate actions

  • Disable Microsoft Entra Self-Service Password Reset for privileged and high-value accounts; require admin-assisted reset with strong identity proofing
  • Enforce phishing-resistant MFA (FIDO2 / Windows Hello for Business / certificate-based) for all administrators and synced service accounts and revoke SMS/voice methods
  • Apply Conditional Access policies that block sign-ins from non-corporate networks for privileged roles and service principals, and require token protection (PRT binding) for Microsoft Graph
  • Audit and revoke recently added application credentials (clientSecret, keyCredential) on all enterprise applications and service principals; alert on new credential creation
  • Disable Azure VM Run Command and the VMAccess extension on production VMs that do not require it; require just-in-time approval through Azure PIM for the microsoft.Compute/virtualMachines/runCommand/action
  • Configure Azure SQL servers to deny public network access and use private endpoints; alert on microsoft.sql/servers/firewallrules/write events that add /0 ranges
  • Rotate all Storage account keys, Key Vault secrets, App Service publishing profile credentials and Entra ID app credentials accessible to recently compromised principals

Workarounds

  • Temporarily disable SSPR entirely while implementing admin-assisted reset workflows for the entire workforce
  • Restrict Microsoft Graph access for the Microsoft.Graph PowerShell and az cli first-party application IDs from non-corporate IPs via Conditional Access named locations
  • Block ConnectWise ScreenConnect (instance-relay.screenconnect.com, *.screenconnect.com, screenconnect.com) at egress proxies and EDR application control unless explicitly authorised

Longer-term hardening

  • Adopt managed identities everywhere; eliminate Storage account keys, App Service publishing profiles, and legacy service-principal client secrets in favour of federated credentials and managed identities
  • Migrate Key Vault to RBAC permission model with least-privilege role assignments; segment vaults by trust boundary and require Private Endpoint access
  • Roll out Defender for Cloud Apps + Defender for Identity policies that detect impossible-travel and risky-sign-in patterns against service principals, and tie Conditional Access risk to sign-in and user risk from Entra ID Protection
  • Enable Microsoft Defender for Endpoint Tamper Protection in tenant-locked mode (not configurable from the endpoint) and onboard Azure VMs to Defender for Servers Plan 2
  • Implement just-in-time and just-enough-access for all Azure RBAC privileged roles via Entra PIM with approval workflows and access reviews

Weaknesses (CWE) in Storm-2949 Cloud-Wide Breach

CWE-287, CWE-269, CWE-732, CWE-285, CWE-522

Timeline of Storm-2949 Cloud-Wide Breach

  • Earliest Storm-2949 cluster activity retrospectively identified by Microsoft Threat Intelligence: SSPR-driven account takeover at a North American technology firm followed by Azure RBAC enumeration.
  • Actor begins systematically deploying ConnectWise ScreenConnect via Azure VM Run Command for persistence instead of relying on browser session cookies alone.
  • First observed Key Vault secret bulk-dump and pivot into downstream SaaS services using stolen API keys.
  • Microsoft Incident Response engaged on a large multi-victim incident; cluster formally tracked under the Storm-2949 designation.
  • Actor observed reading Microsoft Sentinel and Defender XDR alert data to identify which TTPs triggered detections and adjusting tradecraft (residential proxy rotation, smaller chunked Graph downloads).
  • Observed expansion of victim set to professional-services and healthcare verticals in Western Europe; help-desk social engineering callbacks intensify.
  • Microsoft Threat Intelligence publishes the Storm-2949 cloud-wide breach blog naming the actor and releasing detection guidance, Sentinel hunting queries and Defender XDR rules.
  • Threadlinqs Intelligence publishes TL-2026-0529 with MITRE mapping, IOCs, detections and simulations covering the Storm-2949 cloud kill chain.
  • As of 2026-05-29, Storm-2949 remains an active, unattributed cloud-breach actor abusing by-design Entra SSPR/Azure RBAC features with no CVE or patch — only configuration hardening. Microsoft's May 18 disclosure is widely corroborated (BleepingComputer, SC Media, SOC Prime) with no takedown, arrests, or signs the campaign has gone quiet.

Sources cited for Storm-2949 Cloud-Wide Breach

Detection coverage for TL-2026-0529

As of 2026-05-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0529 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats