Massive Azure/Entra ID Exfiltration Campaign Targets Fortune 500 Directories
A large-scale exfiltration campaign has targeted Azure/Entra ID tenants across multiple Fortune 500 organizations, resulting in the leakage of millions of internal employee records. The threat actor, identified as 'TheHatman,' utilized compromised credentials—likely obtained via Infostealer-driven session token theft—to access corporate directories through Azure/Entra portals and the Azure CLI. Exfiltrated datasets comprise core identities, detailed organizational metadata, and sensitive access control information, including service account listings and Global Administrator records. This breach provides high-value intelligence that significantly facilitates downstream high-impact attacks, such as Business Email Compromise (BEC), advanced spear-phishing, and ransomware deployment through lateral movement and privilege escalation.
Deployment of AZUREVEIL/Adaptix C2 Agent via "Operation Dragon Weave"
China-aligned threat actors have launched "Operation Dragon Weave," a sophisticated cyber espionage campaign targeting high-value sectors, including government, research, academic, technology, and financial services. The campaign utilizes highly targeted spearphishing emails to deliver malicious ZIP archives containing deceptive shortcut (.LNK) files masquerading as legitimate documents. Upon execution, these files deploy the AZUREVEIL malware framework, which leverages the Adaptix Command-and-Control (C2) agent to establish persistent communication with actor-controlled infrastructure. The campaign demonstrates a strategic geographic focus on the Czech Republic and Taiwan, aiming for long-term intelligence gathering and unauthorized access within critical infrastructure and academic networks.