Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-2949

Also known as: tracked as, ConnectWise Control, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Sandworm Team

Description

Storm‑2949 demonstrates a sophisticated blend of social engineering, legitimate cloud tooling, and custom scripting to achieve broad access within target organizations. The campaign begins with spear‑phishing emails containing malicious links that compel users to complete fabricated MFA prompts, thereby compromising their identities without triggering standard security alerts. Once inside, the actors leverage Azure service principals, the Microsoft Graph API, and native administrative consoles to enumerate data repositories such as OneDrive, SharePoint, Key Vaults, and SQL databases. Using custom Python scripts, Storm‑2949 performs automated directory discovery and bulk data exfiltration, often routing traffic through Microsoft's own cloud infrastructure to avoid network perimeter filters. The attacker then attempts lateral movement from the compromised cloud identity into on‑premises or hybrid workstations, carefully logging activity under legitimate administrative credentials to obfuscate their presence. This methodical approach allows multiple victims within a single organization to be exploited with minimal initial effort, maximizing data theft while preserving a low attack surface. The attacker’s focus on high‑value IT and executive accounts indicates an intent to harvest strategic or technical information that can be leveraged for further financial exploitation or resale to other adversaries. Evidence from the 2026 Microsoft Threat Intelligence report confirms that Storm‑2949 repeatedly targets cloud identities across diverse sectors, using stolen credentials to expand access into Azure services before pivoting outwards; this pattern highlights both the actor’s technical proficiency and its operational rigor.

Goals & Targeting

Targeted Sectors

Government
Energy
Financial services
Defense
Healthcare
Telecommunications
Aviation
Education
Manufacturing
Critical infrastructure
Maritime
Transportation
Construction
Hospitality
Think tank
Non profit
Information technology
Chemical
Media
Aerospace
Food agriculture
Oil gas
Nuclear
Legal services

Targeted Countries / Regions

CN
UA
US
IN
JP
AU
RU
IL
KR
GB
PL
CA
SG
VN
TW
IR
DE
KZ
TR
FR
BR
MX
ES
IT
KP

AI Analysis

Grounded in web research
· 22 hours ago

Executive Summary

Storm‑2949 is a financially motivated threat actor that has mastered cloud‑native tactics by weaponizing Microsoft’s Self‑Service Password Reset (SSPR) flow and Azure APIs to compromise high‑value accounts such as IT staff and senior leaders. The group conducts methodical reconnaissance across Microsoft 365 and Azure environments, exfiltrates large volumes of data via legitimate storage services, and exploits lateral movement paths between cloud resources and endpoints while mimicking authorized administrative behavior.

Goals & Targeting

Storm‑2949 seeks to monetize large-scale data exfiltration by targeting sectors rich in sensitive information, including government, energy, finance, defense, healthcare, and critical infrastructure. The attack vector focuses on cloud identities that provide wide-reaching administrative privileges; by compromising such accounts, the actor can access documents, configuration files, and credential stores essential for espionage or blackmail. Common victims are IT personnel, senior leadership, and anyone with privileged roles within Microsoft 365 or Azure environments—positions where users routinely handle network diagrams, VPN settings, or policy configurations. The organization’s geographic spread—spanning North America, Europe, Asia, and the Middle East—suggests an opportunistic reach rather than narrow geopolitical targeting. Nonetheless, the consistent pattern of harvesting infrastructure‑specific data signals a motive to facilitate future targeted attacks, either on the same victims or on their supply chains, thereby creating a pipeline for subsequent financial operations. By focusing on cloud‑native attacks, Storm‑2949 removes many of the traditional hurdles associated with perimeter defenses, allowing it to penetrate through legitimate services and user trust rather than brute‑forcing network ingress points.

Enhanced Description

Key Capabilities

  • Phishing with malicious links leading to MFA manipulation
  • Credential theft via SSPR exploitation
  • Use of Azure APIs and Microsoft Graph for reconnaissance
  • Exfiltration using native Azure storage and Microsoft 365 services
  • Custom Python scripting for data discovery and extraction
  • Lateral movement across cloud and endpoint environments

MITRE ATT&CK Tactics

Initial Access
Credential Access
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1566.001 (Spearphishing Link)
T1078.001 (Valid Accounts: Cloud Accounts)
T1087.001 (Account Discovery)
T1046 (Network Services Scanning)
T1520 (Data Obfuscation)
T1020 (Automated Exfiltration)
T1072 (Software Deployment Tools)

Software / Tooling

Azure PowerShell
AzCopy
Microsoft Graph API
Custom Python Scripts
Az CLI

Campaigns & Victims

Storm‑2949’s operational cadence showcases a consistent two‑phase campaign: first, targeted identity compromise via spear‑phishing and MFA manipulation; second, exploitation of the compromised cloud identity to explore Azure resources, exfiltrate data, and attempt lateral movement into on‑prem networks. Victims are repeatedly chosen based on their access level—primarily IT staff and senior executives—enabling extensive data harvest while maintaining low detectability. Unlike destructive wiper campaigns observed against Polish energy infrastructure in 2025 (e.g., DynoWiper), Storm‑2949 concentrates on silent, high‑value extraction rather than damage. Its tactics are emblematic of financially motivated groups that prefer data ransom or resale to more strategic actors. The actor’s reach across a broad list of target sectors and global countries indicates a flexible threat model aimed at maximizing profitable payloads rather than geopolitical objectives.

IOC Patterns

  • Spear-phishing with malicious links designed to lure users into MFA prompts
  • Compromise of Azure SSPR flow for credential theft
  • Exfiltration via legitimate Microsoft 365 storage (OneDrive, SharePoint)
  • Use of custom Python scripts for automated directory discovery

Recommended Actions

  • Implement conditional access policies that block or require multi‑factor authentication for all privileged identity and service principal accounts in Azure AD; restrict SSPR to only a vetted set of high‑privilege users.
  • Audit and monitor abnormal API activity within Microsoft Graph and Azure Resource Manager, including credential changes or unusual data export commands. Enforce least privilege by segregating account roles and disabling full tenant-wide privileges for non‑essential personnel. Deploy Microsoft Defender for Cloud to flag anomalous lateral movement patterns between cloud identities and on‑prem resources. Conduct continuous phishing simulations targeting administrators with MFA manipulation scenarios, coupled with rapid response teams to validate user education effectiveness.

Suggested Tags

APT
Cloud-compromise
Credential theft
Financial motivation
Data exfiltration
Microsoft 365
Azure

Confidence Assessment

The confidence in the core attack narrative—phishing leading to MFA bypass, subsequent use of Azure APIs for data extraction—is high, based on recent Microsoft Threat Intelligence documentation and independent reports from Abel Solutions. Gaps remain regarding precise attribution to a state or criminal entity, specific insider tools beyond generic Azure scripting, and detailed post‑exploitation techniques used after the initial credential compromise.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  2. attack.mitre.org — Cited by web research for: systemd
  3. www.microsoft.com — Cited by web research for: PowerShell
  4. learn.microsoft.com — Cited by web research for: Tsunami
  5. https://www.microsoft.com/en-us/security/blog/2026-05-22/storm-2949-case-study — Cited by AI analysis.
  6. https://www.abelsolutions.com/cloud-identity-breach-inside-the-storm-2949-hack — Cited by AI analysis.

Intel Summary

7

Techniques

50

Tools

0

Campaigns

9

IOCs

0

Observed Data

1

Tactics

Tags

Critical Infrastructure
Data Exfiltration
APT
Cloud-compromise
Credential theft
Financial motivation
Data exfiltration
Microsoft 365
Azure

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.