Security News > 2023 > July > Microsoft hit by Storm season – a tale of two semi-zero days
Another way, which is apparently what Microsoft originally investigated, is that the attackers were able to steal enough data from the authentication servers to generate fraudulent but valid-looking authentication tokens for themselves.
Microsoft ultimately determined that although the rogue access tokens in the Storm-0558 attack were legitimately signed, which seemed to suggest that someone had indeed pinched a company singing key.
Corporate accounts are supposed to be authenticated in the cloud using Azure Active Directory tokens, but these fake attack tokens were signed with what's known as an MSA key, short for Microsoft consumer account.
Loosely speaking, the crooks were minting fake authentication tokens that passed Microsoft's security checks, yet those tokens were signed as if for a user logging into a personal outlook.com account instead of for a corporate user logging into a corporate account.
The good news is that, because the crooks were using corporate-style access tokens signed with a consumer-style cryptographic key, their rogue authnetication tokens could reliably be threat-hunted once Microsoft's security team knew what to look for.
Use of the incorrect key to sign this scope of assertions was an obvious indicator of the actor activity as no Microsoft system signs tokens in this way.
News URL
Related news
- Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws (source)
- Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572) (source)
- Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools (source)
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 91 flaws (source)
- Microsoft November 2024 Patch Tuesday fixes 4 zero-days, 89 flaws (source)
- Microsoft fixes actively exploited zero-days (CVE-2024-43451, CVE-2024-49039) (source)
- Microsoft patches Windows zero-day exploited in attacks on Ukraine (source)
- Microsoft launches Zero Day Quest hacking event with $4 million in rewards (source)
- Microsoft announces Zero Day Quest hacking event with big rewards (source)