Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration — Threadlinqs Intelligence
As of 2026-05-30, Storm-2949 Cloud-Wide Breach — SSPR Abuse & Azure RBAC Lateral Movement to Mass Data Exfiltration is a critical-severity cloud threat attributed to Storm-2949, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-0529 · Severity: CRITICAL · Status: ACTIVE · Category: CLOUD
Attribution: Storm-2949 · FINANCIAL
Microsoft Threat Intelligence has attributed a malware-less, identity-driven cloud breach campaign to a newly tracked actor designated Storm-2949. The actor abuses Microsoft Entra Self-Service
Storm-2949 is a financially-motivated and intrusion-for-impact threat cluster first publicly named by Microsoft Threat Intelligence in May 2026. The cluster is distinguished by an exclusively cloud-native kill chain that abuses native Microsoft Entra ID and Azure Resource Manager (ARM) features rather than custom malware, allowing the actor to operate inside the trust boundary of victim tenants and largely evade endpoint-centric detection.
Initial Access — Storm-2949 acquires a foothold by abusing Microsoft Entra Self-Service Password Reset (SSPR). The actor first harvests target identities and verification artefacts (mobile numbers, alternative email addresses, security questions, manager attributes) through pretext calls to corporate help desks and through reconnaissance of public-facing directories (LinkedIn, GitHub, conference rosters). With those artefacts the actor performs an SSPR flow against the victim tenant''s default SSPR endpoint (passwordreset.microsoftonline.com), satisfies the verification challenges (frequently using SIM-swapped or social-engineered MFA push fatigue), and resets the victim''s primary credential. Because SSPR satisfies MFA registration claims, the actor effectively bypasses Conditional Access MFA enforcement on subsequent logins. In several incidents the actor also social-engineered help-desk operators into manually clearing the targeted user''s MFA methods, achieving an MFA reset by proxy.
Discovery & Resource Development — Once authenticated, the actor performs deep tenant enumeration through Microsoft Graph using the standard delegated permissions of the compromised principal: User.Read.All, Group.Read.All, Application.Read.All, RoleManagement.Read.Directory and Directory.Read.All. Microsoft observed Graph traffic from non-corporate egress points (residential proxy and commercial VPN ranges) listing users, groups, directory role assignments, service principals, application consents, conditional access policy names and named locations. Tenant inventory data is staged to attacker-controlled OneDrive accounts or compressed in memory and exfiltrated over HTTPS to Cloudflare-worker fronted infrastructure.
Privilege Escalation — In tenants where the compromised user holds eligible Privileged Identity Management (PIM) roles, the actor activates Global Reader, Application Administrator, Cloud Application Administrator or Privileged Authentication Administrator and bridges from Entra ID into Azure subscriptions by abusing pre-existing RBAC role assignments such as Owner, Contributor, User Access Administrator, Storage Account Key Operator, Key Vault Administrator and Virtual Machine Contributor scoped at the subscription or management group level. Where direct privileges are absent, the actor adds new client secrets or certificates to existing privileged enterprise applications and authenticates as the service principal, taking advantage of the fact that service principal sign-ins are often exempt from interactive Conditional Access policies.
M365 Data Theft — The actor performs mass enumeration of OneDrive for Business and SharePoint Online sites using the Graph endpoints /v1.0/drives/{driveId}/root/search, /sites/{siteId}/lists, and /me/drive/recent. Files matching a hard-coded keyword list (passwords, secret, customer, contract, vpn, ssh, m&a, financials, source, .pem, .pfx, .kdbx, .ovpn) are downloaded in chunks. Exchange Online mailboxes are accessed using IMAP/EWS where legacy authentication is still enabled, or via Graph Mail.Read.All on consent-phished applications.
Azure Data Plane Theft — Within Azure, Storm-2949 systematically targets four data services. (1) Azure Storage — the actor issues microsoft.Storage/storageAccounts/listkeys/action against every accessible storage account, then uses the listed keys to enumerate and download blob containers and file shares with azcopy. (2) Azure SQL — to defeat IP allow-listing the actor calls microsoft.sql/servers/firewallrules/write to add a
Weaknesses (CWE)
CWE-287, CWE-269, CWE-732, CWE-285, CWE-522
Target sectors: technology, professional-services, healthcare, public-sector, financial-services
Target regions: North America, Western Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
CLOUD, CRITICAL, threat intelligence, cybersecurity, T1589, T1589.001, T1589.003, T1583.006, T1588.002, T1078.004, T1199, T1651, T1648, T1059.001