Penyalahgunaan Microsoft Entra ID untuk Eksfiltrasi Data Microsoft 365 dan Azure
May 21, 2026
Deskripsi
1
| |
|
|
| |
Kampanye Storm-2949 menarget akun Microsoft Entra ID untuk mencuri data sensitif dari Microsoft 365 dan Azure dengan menyalahgunakan fitur cloud yang sah, tanpa mengandalkan malware tradisional. Microsoft mengungkap teknik ini pada 18 Mei 2026 dan laporan media dipublikasikan pada 19 Mei 2026; tidak ada CVE yang disebutkan. Severity: High. (microsoft.com)
|
|
| |
|
|
Metode Serangan
2
| |
|
|
| |
Social engineering yang menyalahgunakan Self-Service Password Reset (SSPR) dan MFA prompt fraud, lalu enumerasi tenant via Microsoft Graph API, eksfiltrasi file dari OneDrive/SharePoint, abuse Azure RBAC untuk mengakses Key Vault, Storage, SQL, serta Run Command dan VMAccess untuk persistence dan lateral movement. (microsoft.com)
|
|
| |
|
|
Sistem Terdampak
3
| |
|
|
| |
Microsoft Entra ID, Microsoft 365 (OneDrive dan SharePoint), Azure App Service, Azure Key Vault, Azure Storage accounts, Azure SQL Server, dan Azure Virtual Machines, terutama tenant dengan akun berprivilege atau RBAC tinggi. (microsoft.com)
|
|
| |
|
|
Mitigasi
4
| |
|
|
| |
- Wajibkan phishing-resistant MFA untuk admin dan akun berprivilege, serta aktifkan Microsoft Entra ID Protection dan Conditional Access.
- Terapkan principle of least privilege, audit Azure RBAC role assignment, dan batasi akses ke App Service publish profile credentials.
- Gunakan private endpoints dan nonaktifkan public network access pada Azure Storage dan Key Vault, serta monitor perubahan firewall SQL/Storage.
- Audit dan restriksi penggunaan Azure VM Run Command/VMAccess, serta aktifkan logging dan monitoring untuk aktivitas management-plane.
|
|
| |
|
|
Referensi: ?
1. https://cybersecuritynews.com/hackers-abuse-microsoft-entra-id-accounts/