Ad End 1 August 2026
Ad End 4 july 2026
ad End 17 June 2026
ad End 25 July 2026
banner Expire 25 July 2026
adv exp at 20 April 2026
banner Expire 25 July 2025
banner Expire 3 July 2026
Ads end 31 October 2026
What's new
Ad expires at 9 July 2026
Ads end 31 October 2026
Wizard's shop 2.0
RonalClub cc shop
Patrick Stash
Luki Crown
best shop
best shop

Microsoft removes 18 Chinese hacker apps from Azure

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
8,076
Reaction score
1,049
Points
212
Awards
2
  • trusted user
  • Rich User
The Gadolinium group abused Azure AD applications to attack Microsoft Azure users.

d2eb65d26e4965290745ba41624c225e.jpg



Microsoft has removed from its Azure portal 18 Azure Active Directory applications that were developed and used by the Chinese cybercriminal group Gadolinium (also known as APT40 or Leviathan). The programs were removed in April this year.

Azure apps were used as part of a malware campaign in 2020 that Microsoft described as "particularly difficult" to detect due to the multi-stage infection process and the widespread use of PowerShell payloads.

The attacks began with targeted phishing, in which criminals sent malicious emails to organizations, usually containing COVID-19-themed PowerPoint files. As soon as the victim opened the document, malicious programs were installed on their system.

According to Microsoft, the hackers used malware on infected computers to install one of 18 Azure AD applications. The role of these applications was to automatically configure the victim's endpoint “with the permissions required to steal and send data to the attackers' Microsoft OneDrive.

In addition to removing malicious apps, Microsoft has also been working on removing the GitHub account that the same Gadolinium group used in their attacks in 2018. These actions will prevent criminals from reusing the same account for other potential attacks in the future.
 
Ad End 1 November 2024
Top