Microsoft Hijacking Windows Server: A System Hacker’s View of the Midnight Blizzard Cybersecurity Threats Against Microsoft and HPE
Microsoft said on Friday that it had detected a system hack on January 12. The attackers targeted and compromised some historic Microsoft system test accounts that then allowed them to access “a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions.” The group was able to find some emails and attached documents. Microsoft noted in its disclosure that the attackers appeared to be seeking information about Microsoft’s investigations and knowledge of Midnight Blizzard itself.
Hewlett Packard Enterprise (HPE) revealed earlier this week that the same group of hackers had previously gained access to its “cloud-based email environment.” The company said it was likely related to the intrusion of a limited number of Microsoft files as early as May 2023.
Russian intelligence-backed threat actors are targeting technology companies, and we shouldn’t be surprised. With organizations that size, it would be a much bigger surprise to learn they weren’t,” says Jake Williams, a former US National Security Agency hacker and current faculty member at the Institute for Applied Network Security.
Nobelium initially accessed Microsoft’s systems through a password spray attack. This type of attack is a brute force one that sees hackers use a dictionary of potential passwords against accounts. The account that was breached didn’t have two-factor authentication enabled, which is important. Nobelium “tailored their password spray attacks to a limited number of accounts, using a low number of attempts to evade detection,” says Microsoft.
From this attack, the group “leveraged their initial access to identify and compromise a legacy test OAuth application that had elevated access to the Microsoft corporate environment.” The open standard for token-based authentication is called OAuth. It is often used to allow people to sign into applications and services without a website with their password. Think of websites you might sign into with your Gmail account, that’s OAuth in action.
More has come out than previously thought, but a few important details are missing. Microsoft does claim that if this same non-production test environment was deployed today then “mandatory Microsoft policy and workflows would ensure MFA and our active protections are enabled” to better protect against these attacks. Microsoft needs to explain more to its users if it wants them to believe that it is making a difference in the way it protects against security threats.




