Microsoft Threat Intelligence
banner
threatintel.microsoft.com
Microsoft Threat Intelligence
@threatintel.microsoft.com
We are Microsoft's global network of security experts. Follow for security research and threat intelligence. https://aka.ms/threatintelblog
Recorded live at Black Hat, Andrew “Spike” Grant of Huntress shares real-world observations from incident response, stories from years of interacting directly with threat actors, and practical insights into identifying suspicious activity before it escalates. msft.it/63322aZ9Am
September 11, 2026 at 3:37 PM
Microsoft Security Research has observed an invoice fraud campaign that sent more than one million emails in three days, using templates that displayed indicators consistent with AI-assisted development, including verbose HTML comments, structured labels, and uniform construction. msft.it/6016akhVn
Protecting organizations from AI-assisted executive impersonation and invoice fraud | Microsoft Security Blog
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud.
msft.it
September 10, 2026 at 5:47 PM
Microsoft developed the Cloud web applications threat matrix to organize relevant techniques across cloud-hosted web applications and serverless platforms using MITRE ATT&CK tactics. msft.it/63323ak5N5
Threat Matrix: Mapping threats across cloud web applications | Microsoft Security Blog
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.
msft.it
September 9, 2026 at 10:25 PM
Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins are followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, and cloud data access. msft.it/63324aknMs
Passkey-themed social engineering leads to identity and cloud compromise | Microsoft Security Blog
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance.
msft.it
September 9, 2026 at 6:08 PM
The September 2026 security updates are available.

In addition, starting today, Microsoft is publishing Vulnerability Exploitability eXchange (VEX) statements for all Microsoft-assigned CVEs. Learn more: msft.it/63329aXvYd
Security updates for September are now available:
msft.it/6018SZEg0
September 8, 2026 at 5:47 PM
Microsoft Security Researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized by AI prompt injection research as ASCII Smuggling, to obscure financial lure words before email filters parsed them. msft.it/63322apxE0
ASCII smuggling crosses over from AI prompt injection to phishing evasion | Microsoft Security Blog
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them.
msft.it
September 3, 2026 at 4:08 PM
Microsoft Threat Intelligence is tracking a human-operated intrusion campaign in which attackers are impersonating IT personnel and abusing external Teams collaboration to gain remote access and deploy a Node.js implant for persistent command execution and C2. msft.it/63325apXCR
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access | Microsoft Security Blog
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity.
msft.it
September 2, 2026 at 10:58 PM
Microsoft Defender Experts is tracking a malware campaign that uses counterfeit software-download sites impersonating trusted vendors and dynamically generated installer archives to deliver multistage payloads leading to system compromise. msft.it/63320aTtOs
Counterfeit installers to system compromise: Tracking a deceptive software download campaign | Microsoft Security Blog
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat.
msft.it
September 1, 2026 at 11:00 PM
Microsoft Security Research is investigating a TerminalFix campaign, a variant of the ClickFix technique, that leads to a reverse-tunnel implant capable of providing network-level proxy access through a compromised host.
August 28, 2026 at 8:09 PM
Microsoft is observing threat actors increasingly target AI infrastructure that concentrates credentials, data access, model connectivity, and execution privileges, creating new opportunities to gain access, establish persistence, and monetize environments. msft.it/63327aPCAc
When AI infrastructure becomes the target: Securing gateways and control points | Microsoft Security Blog
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
msft.it
August 26, 2026 at 7:50 PM
The ransomware attack dubbed JADEPUFFER, one of the first documented cases of a threat actor using a large language model (LLM) to conduct an end-to-end attack, offers a glimpse into how AI could shape future ransomware campaigns. msft.it/63326aP26k
August 26, 2026 at 4:44 PM
Microsoft Defender is monitoring the active exploitation of the CVE-2026-65400 improper authentication vulnerability on a limited number of macOS devices, with telemetry showing successful root account network sign-ins through Screen Sharing.
August 19, 2026 at 12:55 AM
Microsoft Defender Experts’ analysis of MacSync Stealer, a macOS-focused infostealer that relies on constantly changing infrastructure for payload delivery, C2, and exfiltration, demonstrates that malicious domains rotate quickly, but attacker behavior often remains consistent. msft.it/6012azMLa
Hunting MacSync Stealer infrastructure through behavioral pivots | Microsoft Security Blog
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots.
msft.it
August 18, 2026 at 5:16 PM
In this episode of the Microsoft Threat Intelligence Podcast, Principal Threat Intelligence Analyst Crane Hassold explores how phishing and social engineering attacks are evolving beyond email in the threat landscape. msft.it/63329aydrl
August 13, 2026 at 3:26 PM
Based on leak site data tracked by Microsoft Threat Intelligence, The Gentlemen ransomware has claimed one of the highest victim counts among RaaS operations in the past 3 months, while Microsoft Defender data shows it's the 4th most impactful payload after Akira, Qilin, & LockBit. msft.it/6017aHAXl
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor | Microsoft Security Blog
Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target.
msft.it
August 12, 2026 at 5:08 PM
The August 2026 security updates are available:
Security updates for August 2026 are now available. Details are here: msft.it/6018SZEg0
August 11, 2026 at 5:30 PM
Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations. msft.it/63329aGqol
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | Microsoft Security Blog
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.
msft.it
August 10, 2026 at 3:06 PM
On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor.
August 7, 2026 at 9:32 PM
Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign.
August 6, 2026 at 4:17 PM
Microsoft observed a macOS ClickFix campaign that evolved from openly serving infostealer lures to hiding them behind a server-side fingerprinting gate, exposing the content primarily to qualifying macOS visitors. msft.it/6049aEBu1
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | Microsoft Security Blog
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities.
msft.it
August 5, 2026 at 4:04 PM
Microsoft has published an in-depth technical analysis of the supply chain attack known as "ChainDrop" affecting hundreds of packages and delivering a self-propagating credential-stealing worm. Read our blog for mitigation, detection, and hunting guidance: msft.it/63322aDU0s
ChainDrop supply chain compromise: Anatomy of a self-propagating worm | Microsoft Security Blog
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remediation.
msft.it
August 4, 2026 at 11:53 PM
Attackers are increasingly establishing footholds directly on endpoints, using legitimate tools and locally executed payloads to prolong access and evade traditional containment measures. msft.it/63325aDi7h
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET  | Microsoft Security Blog
Microsoft Defender automatically isolated a compromised QNET endpoint in 129 seconds, stopping a multi-stage attack before the payload could persist or spread.
msft.it
August 4, 2026 at 7:59 PM
Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware.
August 4, 2026 at 2:03 PM
Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, compromising hospitality-related networks worldwide to steal credentials, access cloud environments, and deliver malware to travelers. msft.it/63328aBnhE
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
msft.it
July 31, 2026 at 9:04 PM
Microsoft released security updates on July 14, 2026, to address CVE-2026-54121 (Certighost), an elevation-of-privilege vulnerability in Active Directory Certificate Services (AD CS).
July 28, 2026 at 12:41 AM