Microsoft Threat Intelligence
@threatintel
We are Microsoft's global network of security experts. Follow for security research and threat intelligence.
On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor.
We’re seeing multiple forms of command obfuscation and living-off-the-land abuse, including conhost, cmd, PowerShell, pcalua, mshta, rundll32, msiexec, curl, WMI, WebDAV, and scheduled tasks. Carets split keywords, environment variables hide interpreters, and Windows run headlessly or minimized.
An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smart contract previously reported in connection with ClearFake to fetch next-stage instructions. Content stored in a smart contract is resistant to conventional takedown or sinkholing.
Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign.
Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware.
Microsoft released security updates on July 14, 2026, to address CVE-2026-54121 (Certighost), an elevation-of-privilege vulnerability in Active Directory Certificate Services (AD CS).
“Developers are terraforming the battlefield that defenders have to fight on.” msft.it/6011vFIcv In this Microsoft Threat Intelligence Podcast episode, the authors of the new book “Threat-Driven Software Development” discuss why modern software security must be guided by how attackers operate.
AI is accelerating vulnerability research, enabling defenders to find and prioritize issues faster while also lowering barriers for threat actors. As these capabilities become more accessible, cybersecurity experts expect vulnerability volume to continue growing. msft.it/63325vtZAT
Microsoft has observed a supply chain attack targeting the Leo Platform/RStreams npm ecosystem. On June 24, 2026, at 23:04:55 UTC, a compromised maintainer account ("czirker") to publish malicious versions of 20+ npm packages in a coordinated, fully automated operation completed in under 3 seconds.
Microsoft has published an analysis of the npm supply chain compromise affecting 32 maliciously modified packages across more than 90 versions under the redhat-cloud-services npm scope and leading to credential theft and compromise of additional maintainer packages: msft.it/63329vjuvf
Microsoft is investigating a new, emerging Mini Shai-Hulud npm supply chain attack targeting antv packages. Attackers compromised an antv maintainer account and published malicious versions of multiple widely used packages (for example, antv/g2).
Microsoft is investigating mistralai PyPI package v2.4.6 compromise. Attackers injected code in mistralai/client/__init__.py that executes on import, downloads hxxps://83[.]142[.]209[.]194/transformers.pyz to /tmp/transformers.pyz, and launches a second-stage payload on Linux.
With the expansion of Microsoft Sentinel User and Entity Behavior Analytics (UEBA) into new data sources spanning multi-cloud, identity providers, and authentication logs, defenders can detect behavioral anomalies across hybrid environments from a single place. msft.it/63327vHE7v
While Storm-1175's methodology aligns with the TTPs of many ransomware actors, analysis of their post-compromise tactics provides insight into how organizations can disrupt attackers even if they have gained initial access to a network.
The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have impacted healthcare organizations, as well as those in the education, professional services, and finance sectors in Australia, United Kingdom, and United States.
The financially motivated threat actor Storm-1175 operates high-velocity campaigns that weaponize N-days, targeting web-facing systems and rapidly moving from initial access to data exfiltration and deployment of Medusa ransomware. msft.it/63323Q2R8Z
In the second attack path, when a user pastes a hex-encoded, XOR-compressed command into Windows Terminal, the command downloads a .bat file invoked through cmd.exe to write a VBScript. The batch script is executed via cmd.exe with the /launched argument, and then through MSBuild.exe.
The decoded PowerShell script downloads a legitimate but renamed 7-Zip binary that extracts and executes a multi-stage attack chain that includes additional payloads, scheduled tasks, Microsoft Defender exclusions, and exfiltration of stolen machine and network data.
Microsoft Defender Experts identified a widespread ClickFix social engineering campaign in February 2026 leveraging Windows Terminal as the primary execution mechanism, rather than the traditional Win + R → paste → execute technique.
It evaded detection by deleting the initial downloader and by adding Microsoft Defender exclusions for the RAT components. It also added persistence using a scheduled task and startup script named world.vbs.
Microsoft Defender Experts uncovered a coordinated campaign targeting developers through malicious repositories disguised as legitimate Next.js projects and technical assessments leading to command and control, payload delivery, and data exfiltration: msft.it/63327QZtTN
Microsoft Defender was able to confirm a small but noticeable uptick in installations of OpenClaw initiated by Cline CLI installation script during the supply chain compromise of their NPM package that lasted approximately eight hours on February 17, 2026 between 11:26 and 19:30 UTC.
The malicious Python performs a series of discovery commands, before dropping the final payload `%APPDATA%\WPy64-31401\python\script.vbs` and `%STARTUP%/MonitoringService.lnk`pointing to the VBScript for persistence. This final payload is a remote access trojan and called ModeloRAT.
Using DNS in this way reduces dependency on traditional web requests and can help blend malicious activity into normal network traffic.
Microsoft Defender researchers observed attackers using yet another evasion approach to the ClickFix technique: Asking targets to run a command that executes a custom DNS lookup and parses the `Name:` response to receive the next-stage payload for execution.
Cyberattacks succeed when basic controls are missing or inconsistently applied. Microsoft is engaging in Operation Winter SHIELD, an FBI Cyber Division initiative focused on closing the gap between security intent and consistent execution. msft.it/63327QMwON
This was followed by ClickFix, a technique that threat actors use to trick users into running malicious commands on their devices. If users fell for the ClickFix lure and executed a command in their Run prompt, a PowerShell script would run.
The URLs in the phishing emails redirected to an attacker-controlled landing page on the malicious domain permit-service[.]top that employed several rounds of user interaction. First, users needed to solve a slider captcha by clicking and dragging a slider.
On Thanksgiving eve, November 26, Microsoft detected and blocked a high-volume phishing campaign from a threat actor we track as Storm-0900. The campaign used parking ticket and medical test result themes and referenced Thanksgiving to lend credibility and lower recipients’ suspicion.
Throughout 2025, Tycoon2FA (tracked by Microsoft as Storm-1747) has consistently been the most prolific phishing-as-a-service (PhaaS) platform observed by Microsoft. In October 2025, Microsoft Defender for Office 365 blocked more than 13 million malicious emails linked to Tycoon2FA.