Overview
On the 12th of January 2024, the Microsoft Security Team detected a nation-state cyber-attack against its corporate email systems, with the Microsoft Threat Intelligence investigation identifying the threat actor as the Russian state-sponsored cyber unit, tracked as Midnight Blizzard.
After Microsoft immediately activated its incident response process, evidence emerged of Midnight Blizzard leveraging data extracted from Microsoft corporate email systems to gain, or attempt to gain, unauthorised access, including access to some of the company’s source code repositories and internal systems. As a follow up warning from the tech giant, Midnight Blizzard not only breached Microsoft systems and staff inboxes earlier this year, but also stole customer emails.
In a recent development, Microsoft recently emailed tenant admins to provide a security notification of the incident. This is outside of the normal reporting mechanism for Microsoft, and Quorum Cyber has identified multiple cases where the nominated tenant administrator account is not a monitored mailbox. As such, clients may be unaware that their data may have been compromised.
Impact
The breach of stolen customer emails would likely result in the loss of confidentiality and integrity of data. Any compromised data will likely be leveraged for further attacks by Midnight Blizzard as they seek to meet state-level agendas.
These data breaches would likely negatively affect company reputation, potentially resulting in the loss of clients. The breach could also have legal and compliance consequences, impacting individuals and companies, causing loss of privacy and, in some cases, identity theft.
Containment, Mitigations & Remediations
In this instance, Microsoft emailed tenant admins, meaning that notifications will not be found in the customer portal. Customers should check email logs (including Exchange Online) for an email from [email protected] with the subject of “Action Required – Microsoft Email Data Sharing Request”. The spam folder should also be checked for emails dating back to June.
Nation State Threat Actor Profile
The Quorum Cyber Threat Intelligence team has assessed that Midnight Blizzard likely operates under the direction of the Russian Foreign Intelligence Service (SVR), an agency focused on cyber campaigns outside of the Commonwealth of Independent States. The state actor employs a wide variety of advanced techniques in their cyber operations in support of the SVR’s intelligence collection requirements and dedicated espionage of foreign interests. Midnight Blizzard applies a wide range of bespoke tools developed in a variety of programming languages, whilst utilising a range of initial access methods that include stolen credentials, supply chain attacks and the deployment of the Active Directory Federation Services (ADFS) malware, named as FOGGYWEB and MAGICWEB.
Midnight Blizzard Targeting Profile
Midnight Blizzard primarily targets government, inter-governmental and non-governmental organisations (NGOs), as well as think tanks, military, IT service providers, health technology, research and telecommunications entities based in or operating out of North Atlantic Treaty Organisation (NATO) states, including the US, the UK and Western Europe.
Midnight Blizzard Toolset
Although no IoCs are currently available for this incident, the Quorum Cyber Threat Intelligence team has assessed with high confidence that the state actor leverages the following toolset within its tradecraft to conduct its offensive operations:
- PinchDuke: Toolkit that consists of multiple loaders and a core information stealer trojan
- CosmicDuke: Information stealer malware
- GeminiDuke: Toolset that consists of a core information stealer, a loader and multiple persistence-related components
- CozyDuke: Modular malware platform that can be instructed by a C2 server to download and execute arbitrary modules
- OnionDuke: Toolkit that includes at least a dropper, a loader, an information stealer trojan and multiple modular variants
- SeaDuke: Backdoor malware that focuses on executing commands retrieved from its C2 server, such as uploading and downloading files, executing system commands, and evaluating additional Python code
- POSHSPY: Backdoor that leverages PowerShell and Windows Management Instrumentation (WMI)













