
Attackers registered their own authentication methods
Once an identity was compromised, Microsoft observed attackers registering authentication methods under their control, including phone numbers, authenticator applications, and software-based OTP tokens. This gave them a way to satisfy future MFA challenges without the legitimate user.
Attackers then used Microsoft Graph to enumerate users, groups, roles, authentication methods, applications, and cloud resources. They subsequently moved into SharePoint and OneDrive to locate and access files, while some intrusions involved Exchange Online and REST API-based access to email.
“The actor registers their own authenticator method, maps the tenant through Microsoft Graph, and pulls files and mail at a pace that reads like a busy employee,” Baker said. “None of those calls is suspicious on its own. The sequence is.”
