We are Microsoft's global network of security experts. Follow for security research and threat intelligence.

Redmond, WA
Microsoft Threat Intelligence has identified a cluster of compromised websites leading to ClickFix attacks. Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file. When a user is later tricked into executing the malicious command, the cached website content is already on the device, loaded, and ready to be executed. This helps to hide the payload script and helps bypass the character limit of the Run dialog. ClickFix attacks persuade users to execute attacker-supplied commands under the guise of verification or repair. In this specific campaign, a fake lure instructs users to open Windows Run, paste clipboard content and press Enter. The injected page uses browser caching to stage the larger VBScript payload separately from the Run command. The command invokes cmd.exe to recursively enumerate files whose names start with "f_” in the browser’s profile folder such as %LOCALAPPDATA%\Mozilla\Firefox\Profiles. It compares each file’s byte length with an expected value. Rather than searching for a marker within the contents like previous attacks, it copies a size-matching cache entry to %LOCALAPPDATA%\Temp\t.vbs, giving the cached payload a VBScript extension, then executes it with wscript.exe. Copy output and errors are suppressed. The expected size varies across variants. The VBScript collects host information through WMI, retrieves v.ps1 from cocojambo[.]us[.]com/alfa, and launches PowerShell without a profile and with execution-policy bypass. A later PowerShell stage downloads the next-stage payload as cab.dat, then reads and executes its contents in a hidden window. The PowerShell stage triggers .NET compilation using csc.exe and cvtres.exe, then launches timeout.exe. Subsequent payloads load .NET assemblies into memory and inject code into timeout.exe to target browser and device credentials. The injected process launches PowerShell to retrieve another in-memory stage from capsysnet[.]vg and makes outbound connections to ciliabula[.]cc. The payload modifies the per-user PowerShell registry configuration to use the Bypass execution policy, then unpacks Python with tar.exe and creates a scheduled task that launches a Python payload through pythonw.exe for persistence. Microsoft Defender provides layered protection across the ClickFix attack chain. Defender SmartScreen and Defender for Office 365 help block malicious sites, links, attachments, and fake CAPTCHA lures, while Defender for Endpoint detects suspicious command execution and outbound connections through alerts like “Possible ClickFix activity”. Defender Antivirus blocks malicious command execution as Trojan:Win32/ClickFix and Trojan:Win32/TermFix. Microsoft recommends cloud-delivered, web, and network protection, application control, and PowerShell script-block logging. Hunt across browser activity, RunMRU registry key, WScript/PowerShell child processes and scheduled tasks, not download events alone. A CAPTCHA should not ask users to run code. Users shouln not paste commands from verification prompts into Run, Terminal or PowerShell and should treats such requests as potential initial access attempts.
16
104
468
51,719
The 2026 Microsoft Digital Defense Report is out today, examining a threat landscape increasingly defined by interdependence. Read the full report: msft.it/6018alHd6 Connections among identities, AI systems, cloud services, software supply chains, edge infrastructure, and critical systems can create points of leverage where one compromise has effects far beyond the initial target. AI is accelerating familiar threat actor tradecraft rather than replacing it. Identity compromise, credential reuse, social engineering, and exploitation remain prevalent, but automation enables adversaries to conduct these activities with greater speed and scale. In 52.2% of intrusions involving valid accounts, attackers pursued additional credential theft, creating opportunities for one compromised identity to fuel further unauthorized access. These operations leave signals across identities, endpoints, infrastructure, applications, cloud environments, email, and networks. Individually, those signals may provide only a partial view. When correlated with threat intelligence, they can reveal threat actor activity across campaigns, clarify how an intrusion is progressing, and surface risks that isolated investigations may miss. For defenders, success increasingly depends on connecting telemetry quickly enough to understand adversary operations and act before threats can escalate. Get more insights on this year’s report from Terrell Cox: msft.it/6017alHjh
3
37
110
9,051
Microsoft Threat Intelligence identified and tracked exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability affecting internet-facing mail servers that enabled compromise without authentication or user interaction. msft.it/6015aYZ6L Successful exploitation led to webshell deployment, reverse shells, privilege escalation, persistent remote access tooling, and collection of authentication and mailbox data. Microsoft observed both automated payload delivery and hands-on-keyboard activity on compromised mail servers. Analysis of confirmed compromises revealed multiple attack paths and pre-disclosure reconnaissance activity targeting the same injection path before public disclosure. Read the full research for technical details, detection opportunities, and mitigation guidance.
6
32
134
25,787
Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed legitimate RMM software via meeting invitations, PDF-themed lures, software update prompts, and other social engineering content. msft.it/6016acCYr After execution, the software established a remote management foothold and was used to deploy a second remote access platform, creating redundant access channels that supported persistent access and follow-on activity, including information collection and credential access operations. The activity highlights how threat actors continue to abuse legitimate administration tools to blend into normal IT operations while maintaining access and reducing detection opportunities. Read the full analysis for additional findings and guidance.
2
20
119
14,713
Since January 2026, Microsoft has observed Russian state actor Star Blizzard evolve their detection evasion capabilities via large-scale phishing campaigns, the use of accounts on compromised websites, and a new malware delivery technique called RedFlick. msft.it/6010actya RedFlick can enable CosmicPulse malware installation after a single user interaction, reducing friction in the compromise process. Combined with the actor’s updated tactics, techniques, and procedures (TTPs), these changes improve Star Blizzard’s ability to reach more targets and increase the likelihood of successful compromise These developments reflect the actor’s continued efforts to streamline malware deployment and scale operations to support ongoing cyberespionage objectives. Get detections, indicators of compromise (IOCs), and hunting guidance from this Microsoft Threat Intelligence blog post.
3
26
110
22,308
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware family used in a limited number of targeted operations. Observed activity has aligned with activity Microsoft associates with threat actors operating from China. msft.it/6011acEgc NeedyMantis is typically deployed after access has already been established, suggesting it is used to maintain long-term access and support follow-on operations for selective intrusions rather than gain an initial foothold. The malware combines custom loaders, encrypted archives, and modular components that enable operators to evade analysis and extend functionality. Get detections, mitigation, IOCs, and hunting guidance from this Microsoft Threat Intelligence blog post.
2
23
88
10,134
Microsoft Security Research has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. msft.it/6015a9lob Two compromised service principals divided discovery, destruction, and credential collection, with timing and overlapping token streams strongly indicating automated or scripted execution that included more than 100 storage account deletion attempts in about seven minutes. Discovered by Sysdig in July 2026, JADEPUFFER is reported to be the first documented agentic ransomware operation. These new findings expand publicly documented activity associated with Storm-3168 and indicate an evolution in the threat actor's cloud operations. Read the blog for analysis, Microsoft Defender detections, and mitigation guidance on protecting workload identities, revoking or rotating exposed credentials, and safeguarding backup and recovery resources.
8
32
107
28,784
Across intrusions leading to different ransomware payloads, the ransomware affiliate Storm-2570 has used consistent post-compromise tools and techniques, highlighting the value of monitoring recurring attacker behaviors rather than tracking payloads alone. msft.it/6015a9GkD Storm-2570 has used largely uniform tradecraft, including remote access, credential theft, lateral movement, security tampering, and data exfiltration, across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Read the latest Microsoft Threat Intelligence blog for a comprehensive analysis of Storm-2570 activity, as well as Microsoft Defender detections, hunting guidance, and relevant mitigation recommendations, including tamper protection, credential hygiene, and configuring automatic attack disruption.
4
17
76
16,123
Since emerging in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, enabling sophisticated device code phishing campaigns aimed at compromising organizational accounts at scale. msft.it/6015a50C3
6
31
97
12,293
This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than12,000 inboxes in over 10,000 organizations worldwide. In collaboration with partners, Microsoft DCU facilitated a disruption of EvilTokens infrastructure and operations. msft.it/6016a50CO
2
2
3
3,400
The EvilTokens toolkit offered customers prebuilt phishing templates, landing pages, and an AI-powered assistant for tailoring emails to targets. Stolen tokens enabled email exfiltration and persistence, and in some cases were also used to grant new devices access to a compromised mailbox. Microsoft Threat Intelligence tracks the threat actor behind EvilTokens as Storm-2992. Our analysis provides Microsoft Defender detection and hunting guidance, mitigations, and resources to help defend against phishing attacks.
2
1
2,218
Recorded live at Black Hat, Andrew “Spike” Grant of Huntress shares real-world observations from incident response, stories from years of interacting directly with threat actors, and insights into identifying suspicious activity before it escalates. msft.it/6018aZiGE Cybercriminals are increasingly abusing legitimate remote monitoring and management (RMM) and remote access tools to blend into normal activity, making it harder for defenders to distinguish authorized access from intrusion. Compromised access can be maintained through multiple remote access tools and later leveraged for ransomware deployment, data theft, or other follow-on activity, while AI-assisted phishing and social engineering continue to make initial compromise easier. Learn more on this episode of the Microsoft Threat Intelligence Podcast, hosted by Elliot Volkman.
5
23
8,882
Microsoft Security Research has observed an invoice fraud campaign that sent more than one million emails in three days, using templates that indicated AI-assisted development, including verbose HTML comments, structured labels, uniform construction. msft.it/6016akhVn The campaign used executive impersonation, fake vendor invoices, lookalike domains, and third-party email delivery infrastructure to target finance personnel. It combined spoofed sender and reply-to display names, executive signatures, fabricated forwarded conversations, and ACH requests of nearly $50,000. Read our latest blog for IOCs, Microsoft Defender detections, mitigation guidance, and recommendations for email authentication, spoof protection, and other configurations.
2
33
108
10,908
Microsoft developed the Cloud web applications threat matrix to organize relevant techniques across cloud-hosted web applications and serverless platforms using MITRE ATT&CK tactics. msft.it/6015ak507 The matrix can help security teams assess visibility gaps, prioritize hardening, and plan investigations across application code, managed runtimes, workload identities, deployment pipelines, and connected cloud resources. Read the blog to learn more about the framework, the technique catalog, and guidance for reducing exposure across cloud-native environments.
1
27
83
9,617
Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins are followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, and cloud data access. msft.it/6010aknRC The activity begins with identity-focused social engineering, progresses through authentication persistence and cloud reconnaissance, and is followed by targeted data access consistent with data collection and potential exfiltration. Microsoft Threat Intelligence assesses that the initial access activity observed in this campaign is used by multiple threat actors, including Storm-3121, Storm-3032, and others. Defenders should focus on the behavioral sequence rather than individual indicators. Monitor for unusual sign-ins, authentication method changes, Microsoft Graph reconnaissance, and abnormal cloud data access. Read the research for detections and hunting guidance.
2
48
176
18,426
The September 2026 security updates are available. In addition, starting today, Microsoft is publishing Vulnerability Exploitability eXchange (VEX) statements for all Microsoft-assigned CVEs. Learn more: msft.it/6012aXv5M
Security updates for September are now available: msft.it/6018SZEg0. Alongside this month's release, we're expanding machine-readable Vulnerability Exploitability eXchange (VEX) coverage to all Microsoft-assigned CVEs, providing customers with more consistent, machine-readable security information to help understand exposure and prioritize risk. Learn more about this latest milestone in our transparency efforts: microsoft.com/en-us/msrc/blo…
3
28
115
17,610
Microsoft Security Researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized by AI prompt injection research as ASCII smuggling, to obscure financial lure words before email filters parsed them. msft.it/6017apIGx Microsoft telemetry linked the technique to a large-scale finance-themed phishing operation that persisted for months, using hundreds of rotating sender domains and consistent infrastructure patterns. The research shows how techniques popularized in AI security research can quickly cross into traditional phishing campaigns as threat actors adapt tradecraft across domains. Learn how to identify this activity and strengthen detection against similar tradecraft.
9
36
160
19,741
Microsoft Threat Intelligence is tracking a human-operated intrusion campaign in which attackers are impersonating IT personnel & abusing external Teams collaboration to gain remote access and deploy a Node.js implant for persistent command execution & C2. msft.it/6010apXAw After establishing access, the attackers use trusted tooling to perform reconnaissance, capture screenshots, execute follow-on payloads, and move laterally toward domain controllers, certificate authorities, and other high-value systems. Organizations should restrict Teams external access to trusted domains, reinforce user education, and harden systems against social engineering. Read the blog for analysis, Microsoft Defender coverage, indicators, hunting queries, and mitigation guidance.
3
57
160
22,237
Microsoft Defender Experts is tracking a malware campaign that uses counterfeit software-download sites impersonating trusted vendors and dynamically generated installer archives to deliver multistage payloads leading to system compromise. msft.it/6011aTt3H Once executed, the malware payloads establish persistence through scheduled tasks, abuse trusted binaries, leverage a legitimate updater framework for payload delivery, inject code into legitimate processes, and communicate with command-and-control infrastructure over non-standard ports. Defenders should prioritize preventing downloads from untrusted sources and hunting for behavioral indicators rather than file names or hashes, which can rotate. Read the blog for an in-depth technical analysis, along with detection, mitigation, and hunting information.
2
23
96
12,219