2026-05-20HIGHStorm-2949 SSPR-to-Key-Vault Azure kill chain
Storm-2949 SSPR-to-Key-Vault kill chain
campaign · campaign:storm-2949-sspr-to-key-vault-azure-cloud-wide-kill-chain
Storm-2949 malware-less Azure kill chain: voice-phishing SSPR reset → Entra ID → M365 Graph → App Service Kudu → Key Vault → SQL → Storage → Azure VM.
Coverage
1
first 2026-05-20 → last 2026-05-20
Latest activity
2026-05-20
Storm-2949 SSPR-to-Key-Vault Azure kill chain
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, healthcare, finance · regions: europe
Sources cited
11
3 hosts
Defender insights
What each entry about Storm-2949 SSPR-to-Key-Vault kill chain tells a defender to do, newest first.
Detection
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
attributed to
Story timeline
Hunting pivots
ATT&CK techniques (15 across 10 tactics)
15 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts · Valid Accounts: Cloud Accounts
- PersistenceValid Accounts · Valid Accounts: Cloud Accounts · Account Manipulation · Account Manipulation: Device Registration · Modify Authentication Process · Modify Authentication Process: Multi-Factor Authentication
- Privilege EscalationValid Accounts · Valid Accounts: Cloud Accounts · Account Manipulation · Account Manipulation: Device Registration
- StealthValid Accounts · Valid Accounts: Cloud Accounts
- Defense ImpairmentModify Authentication Process · Modify Authentication Process: Multi-Factor Authentication · Disable or Modify Tools · Disable or Modify System Firewall: Cloud Firewall
- Credential AccessUnsecured Credentials · Unsecured Credentials: Credentials In Files · Modify Authentication Process · Modify Authentication Process: Multi-Factor Authentication
- DiscoveryFile and Directory Discovery
- Lateral MovementRemote Services · Remote Services: Cloud Services
- CollectionData from Cloud Storage
- ExfiltrationExfiltration Over C2 Channel
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1556Modify Authentication Process×1
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1098Account Manipulation×1
Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1078.004Valid Accounts: Cloud Accounts×1
Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Defense Impairment TA0112
T1556Modify Authentication Process×1
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1686.001Disable or Modify System Firewall: Cloud Firewall×1
Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1556Modify Authentication Process×1
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1556.006Modify Authentication Process: Multi-Factor Authentication×1
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Discovery TA0007
T1083File and Directory Discovery×1
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Lateral Movement TA0008
T1021Remote Services×1
Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
T1021.007Remote Services: Cloud Services×1
Adversaries may log into accessible cloud services within a compromised environment using Valid Accounts that are synchronized with or federated to on-premises user identities. The adversary may then perform management actions or access cloud-hosted resources as the logged-on user.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Collection TA0009
T1530Data from Cloud Storage×1
Adversaries may access data from cloud storage.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Exfiltration TA0010
T1041Exfiltration Over C2 Channel×1
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.
Evidence: 2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain · ATT&CK page ↗
Entries about Storm-2949 SSPR-to-Key-Vault kill chain (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- attack.mitre.org9 (82%)
- bleepingcomputer.com1 (9%)
- microsoft.com1 (9%)
All cited sources (11)
- attack.mitre.orgT1021.007 (Remote Services: Cloud Services)https://attack.mitre.org/techniques/T1021/007/
- attack.mitre.orgT1041 (Exfiltration Over C2 Channel)https://attack.mitre.org/techniques/T1041/
- attack.mitre.orgT1078.004 (Valid Accounts: Cloud Accounts)https://attack.mitre.org/techniques/T1078/004/
- attack.mitre.orgT1083 (File and Directory Discovery)https://attack.mitre.org/techniques/T1083/
- attack.mitre.orgT1098.005 (Account Manipulation: Device Registration)https://attack.mitre.org/techniques/T1098/005/
- attack.mitre.orgT1530 (Data from Cloud Storage)https://attack.mitre.org/techniques/T1530/
- attack.mitre.orgT1552.001 (Unsecured Credentials: Credentials In Files)https://attack.mitre.org/techniques/T1552/001/
- attack.mitre.orgT1556.006 (Modify Authentication Process: Multi-Factor Authentication)https://attack.mitre.org/techniques/T1556/006/
- attack.mitre.orgT1562.007 (Impair Defenses: Disable or Modify Cloud Firewall)https://attack.mitre.org/techniques/T1562/007/
- bleepingcomputer.comBleepingComputer, 2026-05-19https://www.bleepingcomputer.com/news/security/microsoft-self-service-password-reset-abused-in-azure-data-theft-attacks/
- microsoft.comMicrosoft Threat Intelligence, Storm-2949, 2026-05-18https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/