Microsoft Threat Intelligence’s cover photo
Microsoft Threat Intelligence

Microsoft Threat Intelligence

Computer and Network Security

Redmond, Washington 133,563 followers

We are Microsoft's global network of security experts. Follow for security research and threat intelligence.

About us

The Microsoft Threat Intelligence community is made up of more than 10,000 world-class experts, security researchers, analysts, and threat hunters analyzing 78 trillion signals daily to discover threats and deliver timely and hyper-relevant insight to protect customers. Our research covers a broad spectrum of threats, including threat actors and the infrastructure that enables them, as well as the tools and techniques they use in their attacks.

Website
https://aka.ms/threatintelblog
Industry
Computer and Network Security
Company size
10,001+ employees
Headquarters
Redmond, Washington
Specialties
Computer & network security, Information technology & services, Cybersecurity, Threat intelligence, Threat protection, and Security

Updates

  • Some of the most effective intrusions rely on the tools and relationships an organization already trusts, allowing malicious activity to blend into routine administration and delaying detection. Because that activity runs through approved software and legitimate access, it rarely matches a known malware signature, and telling an administrator apart from an intruder comes down to recognizing how the tools are being used rather than what was deployed. Microsoft Threat Intelligence investigated one such campaign in which a threat actor gained access through a compromised third-party IT services provider that managed the customer's enterprise monitoring and administration platform. Rather than exploiting a vulnerability, the actor operated through this approved, signed tooling exactly as an administrator would, letting the activity pass as routine maintenance. From that trusted position, they extended access and harvested credentials through other legitimate system features, remaining undetected for months: https://lnkd.in/eXYj45Et The same logic extends to the software supply chain, where trust in widely used components becomes the delivery mechanism. For example in one case, a popular open-source library was compromised when a malicious dependency was slipped into new releases; that dependency ran an install-time script that quietly retrieved a remote access trojan (RAT) whenever the package was installed or auto-updated, while the library's own code remained unchanged: https://lnkd.in/e5FN74g2 As threat actors increasingly operate through trusted providers, approved tools, and widely used software, the decisive factor becomes how rigorously an organization controls and verifies the access it has already extended. Microsoft Threat Intelligence continues to track how these trusted pathways are abused, and tightening identity and privileged access controls remains one of the most effective ways to close that gap. To start, review Microsoft's identity and access management best practices: https://lnkd.in/gbApiF-r 

    Attackers do not always need custom malware to move through an environment. Sometimes they just need the same tools the organization already trusts. Remote support tools and administrative utilities are attractive precisely because they look normal, are often allowed, and do not generate the kind of alerts defenders expect from obviously malicious software. Remote support tools and standard remote execution methods are used across multiple actors for execution, lateral movement, and command-and-control. These techniques blur the line between routine activity and malicious behavior, making context and speed critical. Can the team recognize that normal tools are being used abnormally? And when something feels off, can they move decisively without waiting for perfect information? That's the real challenge. It's not just detecting threats; it's building the confidence to make the right decisions when the picture is still unfolding.  That is what maturity looks like in an environment where attackers increasingly blend into the workflows defenders already depend on. If you’re reassessing how to govern trusted tools and administrative access, Microsoft’s identity and privilege control guidance is a strong baseline: https://lnkd.in/eKG86ZqZ #MSFTHotCybercrimeSummer #MicrosoftSecurity #ThreatIntelligence #MSFT

    • No alternative text description for this image
  • Microsoft released security updates on July 14, 2026, to address CVE-2026-54121 (Certighost), an elevation-of-privilege vulnerability in Active Directory Certificate Services (AD CS). An authenticated, low-privileged attacker with network access could manipulate certificate enrollment to impersonate a Domain Controller, potentially enabling privileged operations and full domain compromise. Exploitation requires no administrative privileges or user interaction, but it does require network access and a valid domain account. The publication of proof-of-concept code increases the likelihood of exploitation attempts, so we recommend customers prioritize installing the July 2026 security update as soon as possible. Microsoft has observed researcher testing activity but has not confirmed active exploitation by threat actors. In response to these early signs of activity, we are sharing detection and hunting guidance to help defenders identify potential exploitation attempts, particularly in environments where the security update has not yet been applied. Microsoft Defender detects malicious certificate requests associated with this vulnerability and generates the alert: - “Potential Certighost (CVE-2026-54121) AD CS abuse” - "Active Directory Certificate Services attack tool activity" Other alerts, including the following, may also appear during the attack chain. These signals support investigation but are not independently specific to Certighost. - Security principal reconnaissance (LDAP) - Suspicious Active Directory Certificate Services abuse tool activity - Suspected suspicious Kerberos ticket request - DCSync attack (replication of directory services) Customers should apply the July 14, 2026 security update to every server running an Enterprise Certification Authority (CA). The security update provides the primary protection by validating the enrollment chase target before the CA contacts it, preventing invalid or attacker-controlled systems from influencing certificate issuance. Customers who can't apply the July 14, 2026 security update immediately for all affected servers, should consider configuring the following audit logs to enable the mentioned detections and forensic: - Enable Certification Services auditing for both successful and failed operations. - Configure the CA audit filter to capture certificate lifecycle activity. - Monitor Security events 4886 and 4887 for anomalous certificate requests and issuance. - Investigate certificates requested through machine templates that contain unexpected Domain Controller identity information.

    • No alternative text description for this image
  • The continuing effects of Microsoft's disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques during the second quarter of 2026 (April-June), including QR code phishing and CAPTCHA-gated phishing. Despite attempts to rebuild operations, no single service emerged to replace Tycoon2FA at comparable scale. https://msft.it/6042vA9t4 At the same time, threat actors continued to diversify delivery channels. Microsoft Threat Intelligence observed continued growth in Teams-based social engineering, particularly vishing, as threat actors expanded beyond email into trusted workplace communication platforms. Notable campaigns demonstrated how threat actors combine automation, trusted services, and multi-stage delivery chains to scale operations, including a high-volume automated business email compromise (BEC) campaign and a phishing campaign that ultimately delivered malware through a multi-stage attack chain. Get detections, mitigation guidance, and deeper insights into phishing techniques, malicious payload trends, BEC activity, and more from this Microsoft Threat Intelligence blog post.

  • Healthcare appears repeatedly across ransomware and extortion reporting in part because the sector concentrates the conditions that make intrusions worthwhile. Care delivery depends on continuous, time-sensitive access to clinical systems and records, so disruption carries immediate consequences for patient safety. That pressure, combined with the sensitive data healthcare holds and the interconnected systems care relies on, creates the leverage that financially motivated actors move to exploit. Recent Microsoft investigations show how broadly these conditions draw activity. The Gentlemen ransomware, a self-propagating Go encryptor, has impacted healthcare and multiple other industries across continents. Self-propagation is especially consequential in the interconnected clinical networks hospitals depend on: https://lnkd.in/eunWMfKA Fox Tempest, a malware signing service that Microsoft's Digital Crimes Unit disrupted in May 2026, produced signed binaries that lend legitimacy to downstream malware, including ransomware, used against healthcare and other industries worldwide. Because code signing exploits the trust defenders and users place in familiar, validated software, it is well suited to environments where that trust runs high: https://lnkd.in/eHR4zJhE A multi-stage phishing campaign that culminated in adversary-in-the-middle (AiTM) token compromise impacted healthcare alongside other industries, using stolen session tokens to bypass multifactor authentication (MFA). That technique can be particularly effective against the responsive, high-tempo workflows common in care delivery: https://lnkd.in/eAvztjEa Across these cases the actors and techniques differ and the victims span many industries, yet healthcare recurs throughout. Because that pattern reflects durable economics, the strongest response is resilience through pairing sustained visibility with recovery practices that limit disruption when intrusions occur. For the latest ransomware research from the Microsoft Threat Intelligence community, visit the Microsoft Threat Intelligence Blog: https://lnkd.in/e_U_gyfb

    Healthcare shows up repeatedly in ransomware victim lists but not because it is uniquely unlucky. It shows up because it combines the exact conditions cybercriminals value most: urgency, high-value data, historically understaffed security teams, and workflows where trust and responsiveness matter more than friction. Healthcare victims appear across multiple actors, including Pistachio Tempest, Storm-1811, Storm-1874, and Vanilla Tempest. Quick Assist social engineering is particularly effective in hospital IT environments, where support calls are frequent and trust is high. This is not just a sector story. It is a structural story. Healthcare combines operational urgency and security asymmetry in a way that makes extortion economically attractive. In other words, the sector is not only vulnerable. It is pressured. That is why recurring targeting should not be read only as adversary preference. It should also be read as a signal about where cybercrime economics work best. For a broader view of how adversaries target sectors and adapt tactics, Microsoft’s threat intelligence reporting across industries provides useful context: https://lnkd.in/eg8J7qQN #MSFTHotCybercrimeSummer #MicrosoftSecurity #ThreatIntelligence #MSFT

    • No alternative text description for this image
  • Microsoft’s investigation into increased ACR Stealer activity surfaced two distinct intrusion paths that both begin with ClickFix, diverge in execution, but lead to the same outcome: the exfiltration of browser credentials, session tokens, and other sensitive data. https://msft.it/6041v2sn7 One attack chain uses WebDAV-delivered payloads, Python-based loaders, and blockchain-backed dead-drop infrastructure, while the other relies on fileless execution, obfuscated PowerShell, and steganography-assisted in-memory payload delivery. This research highlights how operators of malware-as-a-service (MaaS) infostealers like ACR Stealer are using multiple intrusion chains to achieve the same objective. Read our blog for technical analysis, along with protection, detection, and hunting guidance.

  • Microsoft has published an in-depth analysis of the AsyncAPI npm supply chain compromise, from CI/CD compromise to a multi-stage payload that executed at import time, bypassing common npm script-based defenses. Read the blog to get technical info, along with detection, protection, and hunting guidance. https://msft.it/6046v2GyE

  • “Developers are terraforming the battlefield that defenders have to fight on.” https://msft.it/6043vFIwv In this episode of the Microsoft Threat Intelligence Podcast, the authors of the new book “Threat-Driven Software Development: Defending Online Services from Modern Threat Actors” discuss why modern software security must be guided by how attackers actually operate. Drawing on their experiences across threat intelligence, software engineering, identity security, and threat modeling, Michael Howard, Lee Holmes, Sherrod DeGrippo, and Shawn Hernan begin every chapter with a threat intelligence perspective, using real-world attacker techniques to frame the technical guidance that follows. Watch the latest podcast episode to learn what inspired the book and what the authors hope readers will learn. You can get “Threat-Driven Software Development: Defending Online Services from Modern Threat Actors” here: https://msft.it/6044vFIwa

  • Adaptation is a defining feature of cybercrime. Under pressure, actors rotate payloads, shift infrastructure, and rebrand operations, yet still rely on the same tradecraft, access patterns, and economics. For example, Microsoft observed financially motivated actor Storm-0501’s primary objective shift from deploying on-premises endpoint ransomware to cloud-based ransomware tactics. Rather than encrypting endpoints, Storm-0501 uses cloud-native capabilities to exfiltrate large volumes of data, destroy backups, and demand ransom without deploying malware. Even when the actor’s payloads changed repeatedly over the years, such as from Sabbath to Embargo, the opportunistic targeting and the drive to escalate privileges across hybrid and cloud identities remained: https://lnkd.in/gy8rMFYg Disruption further shapes this adaptation, and adaptation reshapes the response in turn. In February 2026, Microsoft observed the malware signing service Fox Tempest move to pre-configured virtual machines hosted on a US-based virtual private server provider, letting customers upload malicious files and receive signed binaries in return. The shift reduced friction and improved its operational security for threat actors, until Microsoft's Digital Crimes Unit disrupted that infrastructure in May 2026: https://lnkd.in/eHR4zJhE The phishing-as-a-service platform Tycoon2FA followed a similar arc. After a March 2026 disruption cut its platform reach and message volume, more than 41% of its domains moved to .RU registrations. The platform also shifted from predominantly using a single hosting service toward using a variety of services, suggesting that the group has been attempting to find replacement services with comparable anti-analysis protections: https://lnkd.in/eDeTPZrZ These cases display how the tooling and infrastructure change, but the operating model does not, which is why long-term tracking matters. It reveals when apparently "new" activity is really a known operation adapting under pressure. For the latest ransomware research from the Microsoft Threat Intelligence community, visit the Microsoft Threat Intelligence Blog: https://lnkd.in/e_U_gyfb

    A ransomware group gets taken down. Headlines call it a win. Six months later, the same people are back under a new name, using the same playbook. A disrupted tool is not a disrupted market. When one malware family is taken down, actors pivot. When a ransomware brand becomes toxic, another appears. Actors rotate payloads, shift infrastructure, and rebrand. But the economic dependencies, access patterns, privilege escalation logic, and tradecraft stay the same. The names change. The operating logic does not. Modern cybercrime is an adaptive system: pressure changes behavior but rarely ends the business model. That's why long-term tracking matters. It reveals when "new" activity is really continuity under a different label, and reminds defenders that surface change is not structural change. To understand how ransomware ecosystems evolve and adapt over time, Microsoft's threat intelligence reporting is a strong reference point: https://lnkd.in/eBeY4xwK #MSFTHotCybercrimeSummer #MicrosoftSecurity #ThreatIntelligence #MSFT

    • No alternative text description for this image
  • Microsoft Threat Intelligence is tracking reports of a suspected compromise of AsyncAPI's release pipeline, resulting in malicious packages published to the asyncapi npm namespace. Four packages (five versions) contain obfuscated malware. Combined, these packages see over 3 million downloads per week: - asyncapi/generator@3.3.1 - asyncapi/specs@6.11.2-alpha.1 - asyncapi/generator-helpers@1.1.1 - asyncapi/specs@6.11.2 - asyncapi/generator-components@0.7.1 The payload deploys a multi-stage RAT (characteristics overlapping publicly reported Miasma variants; attribution not confirmed) via hidden spawn, then downloads a second-stage payload from IPFS and persists as sync.js in user AppData. Microsoft Defender for Endpoint customers should act on these alerts: - Trojan:Script/Supychain.A To mitigate the issue: Pin to known-good versions, use lockfiles, and rotate any secrets exposed to affected CI runners.

    • No alternative text description for this image

Affiliated pages

Similar pages