Microsoft has identified a nation-state actor tracked as Flax Typhoon quietly gaining and maintaining access to organizations in Taiwan via known exploits, malware, built-in tools, and legitimate VPN software. Get the actor's TTPs and detection info: https://t.co/gkD08aQiVP
Today we are highlighting an actor we are tracking as Volt Typhoon. This activity is targeting US and Guam critical infrastructure. Volt Typhoon has been observed mostly living off the land during our investigations.
We're excited to share that Microsoft Threat Intelligence is shifting to a new threat actor naming taxonomy aligned with the theme of weather to help bring better clarity and context to the threats that we track. https://t.co/NFYWcPue5t
New blog: In-depth analysis of newly detected NOBELIUM malware: a post-exploitation backdoor that Microsoft refers to as FoggyWeb. NOBELIUM uses FoggyWeb to remotely exfiltrate data from compromised AD FS servers. Get IOCs, protection info, and guidance: https://t.co/miVx4gAOxp
Iran-based threat actor MERCURY was recently observed targeting organizations in Israel. Microsoft assesses with moderate confidence the actor leveraged exploitation of Log4j 2 vulnerabilities as initial access in these attacks. Get TTPs & protection info: https://t.co/ARiqUVj69J
Microsoft discovered and patched a 0-day exploit (CVE-2022-22047) that #KNOTWEED, an Austria-based private sector offensive actor, used to deploy #Subzero malware. Analysis of campaigns, tactics, & payloads in this #MSTIC blog w/ @msftsecresponse@RiskIQ: https://t.co/9QZbKSo9FA
Microsoft Security has been tracking criminal actor DEV-0537 (LAPSUS$) targeting organizations with data exfiltration and destructive attacks - including Microsoft. Analysis and guidance in our latest blog: https://t.co/gTMXJCoPY5
When "wiper" malware appeared to target Ukraine a few hours before Russia's invasion, Microsoft stepped in, throwing itself into the middle of a war.
Check how a good Threat Intelligence can be the new military strategy defence
https://t.co/4nPC7VmG4L
The threat actor ACTINIUM (aka #Gamaredon) continues to target organizations primarily in Ukraine for espionage purposes. MSTIC’s latest blog outlines the tactics that this persistent actor employs to pursue access and exfiltrate info from these orgs. https://t.co/9iihjccIvL
Interesting Job Posting at , Herzliya, Tel Aviv, Israel, Senior Threat Intelligence Analyst - Microsoft Threat Intelligence Center (MSTIC)
https://t.co/1rIegCWNFB