Also known as: tracked as, ConnectWise Control, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Sandworm Team
Storm‑2949 demonstrates a sophisticated blend of social engineering, legitimate cloud tooling, and custom scripting to achieve broad access within target organizations. The campaign begins with spear‑phishing emails containing malicious links that compel users to complete fabricated MFA prompts, thereby compromising their identities without triggering standard security alerts. Once inside, the actors leverage Azure service principals, the Microsoft Graph API, and native administrative consoles to enumerate data repositories such as OneDrive, SharePoint, Key Vaults, and SQL databases. Using custom Python scripts, Storm‑2949 performs automated directory discovery and bulk data exfiltration, often routing traffic through Microsoft's own cloud infrastructure to avoid network perimeter filters. The attacker then attempts lateral movement from the compromised cloud identity into on‑premises or hybrid workstations, carefully logging activity under legitimate administrative credentials to obfuscate their presence. This methodical approach allows multiple victims within a single organization to be exploited with minimal initial effort, maximizing data theft while preserving a low attack surface. The attacker’s focus on high‑value IT and executive accounts indicates an intent to harvest strategic or technical information that can be leveraged for further financial exploitation or resale to other adversaries. Evidence from the 2026 Microsoft Threat Intelligence report confirms that Storm‑2949 repeatedly targets cloud identities across diverse sectors, using stolen credentials to expand access into Azure services before pivoting outwards; this pattern highlights both the actor’s technical proficiency and its operational rigor.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑2949 is a financially motivated threat actor that has mastered cloud‑native tactics by weaponizing Microsoft’s Self‑Service Password Reset (SSPR) flow and Azure APIs to compromise high‑value accounts such as IT staff and senior leaders. The group conducts methodical reconnaissance across Microsoft 365 and Azure environments, exfiltrates large volumes of data via legitimate storage services, and exploits lateral movement paths between cloud resources and endpoints while mimicking authorized administrative behavior.
Goals & Targeting
Storm‑2949 seeks to monetize large-scale data exfiltration by targeting sectors rich in sensitive information, including government, energy, finance, defense, healthcare, and critical infrastructure. The attack vector focuses on cloud identities that provide wide-reaching administrative privileges; by compromising such accounts, the actor can access documents, configuration files, and credential stores essential for espionage or blackmail. Common victims are IT personnel, senior leadership, and anyone with privileged roles within Microsoft 365 or Azure environments—positions where users routinely handle network diagrams, VPN settings, or policy configurations. The organization’s geographic spread—spanning North America, Europe, Asia, and the Middle East—suggests an opportunistic reach rather than narrow geopolitical targeting. Nonetheless, the consistent pattern of harvesting infrastructure‑specific data signals a motive to facilitate future targeted attacks, either on the same victims or on their supply chains, thereby creating a pipeline for subsequent financial operations. By focusing on cloud‑native attacks, Storm‑2949 removes many of the traditional hurdles associated with perimeter defenses, allowing it to penetrate through legitimate services and user trust rather than brute‑forcing network ingress points.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑2949’s operational cadence showcases a consistent two‑phase campaign: first, targeted identity compromise via spear‑phishing and MFA manipulation; second, exploitation of the compromised cloud identity to explore Azure resources, exfiltrate data, and attempt lateral movement into on‑prem networks. Victims are repeatedly chosen based on their access level—primarily IT staff and senior executives—enabling extensive data harvest while maintaining low detectability. Unlike destructive wiper campaigns observed against Polish energy infrastructure in 2025 (e.g., DynoWiper), Storm‑2949 concentrates on silent, high‑value extraction rather than damage. Its tactics are emblematic of financially motivated groups that prefer data ransom or resale to more strategic actors. The actor’s reach across a broad list of target sectors and global countries indicates a flexible threat model aimed at maximizing profitable payloads rather than geopolitical objectives.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core attack narrative—phishing leading to MFA bypass, subsequent use of Azure APIs for data extraction—is high, based on recent Microsoft Threat Intelligence documentation and independent reports from Abel Solutions. Gaps remain regarding precise attribution to a state or criminal entity, specific insider tools beyond generic Azure scripting, and detailed post‑exploitation techniques used after the initial credential compromise.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
50
Tools
0
Campaigns
9
IOCs
0
Observed Data
1
Tactics