Using the access to virtual machines the attackers employed malicious use of the Serial Console on Azure Virtual Machines to install third-party remote management software within client environments.
A financially motivated cybergang tracked by Mandiant as 'UNC3944' is using phishing and SIM swapping attacks to hijack Microsoft Azure admin accounts and gain access to virtual machines. From there, ...
This allows us to react flexibly to business developments such as new products in the portfolio, increased data requirements, or the integration of new markets and target groups.” — Mathias Kuhn, ...