On 12 December 2023, Microsoft Threat Intelligence described how a financially motivated actor it tracks as Storm-1283 turned OAuth applications into a cryptomining engine. Using a compromised user account, the actor signed in through a VPN, registered a new single-tenant OAuth application in Microsoft Entra ID, added secrets to it and, because the account owned an Azure subscription, gave the application the Contributor role. It also added its own credentials to existing line-of-business applications the account could reach. Those application identities then deployed virtual machines to mine cryptocurrency. Microsoft says targeted organisations incurred compute fees of between 10,000 and 1.5 million US dollars. The same report covered two other actors who used OAuth apps for phishing and spam. Microsoft blocked the applications involved and informed affected organisations. It has not named the victims, said how many there were or given dates for the Storm-1283 activity.
Key takeaways
- Microsoft Threat Intelligence reported on 12 December 2023 that Storm-1283 used a compromised user account to create and modify OAuth applications in Microsoft Entra ID and deploy cryptomining virtual machines.
- The actor added secrets to a new single-tenant app, granted it Contributor rights on an Azure subscription, and added credentials to existing line-of-business apps, so the mining ran under application identities rather than the user.
- Microsoft says targeted organisations incurred compute fees ranging from 10,000 to 1.5 million US dollars; it did not say how many organisations were hit.
- This is a confirmed, Microsoft-reported campaign. Microsoft blocked the apps with the Entra team and informed affected organisations; victims have not been named.
- The identity lesson: a user who can create apps and assign subscription roles can mint durable machine identities, and those identities outlive a password reset unless their credentials are found and removed.
At a glance
| Organisations | Unnamed Microsoft Entra ID and Azure customers (Microsoft describes "targeted organizations" but gives no count) |
|---|---|
| When | Activity dates not published; disclosed by Microsoft Threat Intelligence on 12 December 2023 |
| Attacker | Storm-1283, a financially motivated actor tracked by Microsoft |
| Entry point | A compromised user account that could sign in through a VPN and held an ownership role on an Azure subscription |
| Identities abused | A new single-tenant OAuth application with attacker-added secrets and the Contributor role; existing line-of-business OAuth applications with added credentials |
| Impact | Cryptomining virtual machines deployed in victims' Azure subscriptions; compute fees of 10,000 to 1.5 million US dollars per Microsoft |
| Category | NHI. Incident class: confirmed NHI breach (OAuth application identities created and modified to run cryptomining) |
What happened
Microsoft's report, "Threat actors misuse OAuth applications to automate financially driven attacks", set out a pattern seen across several actors in 2023. Attackers compromise a user account that has rights to create or modify OAuth applications, then create apps, add credentials to them and grant them high privileges. Microsoft says this lets them hide what they are doing and keep access even if they lose the original account. In general, the report says, initial access came from phishing or password spraying against poorly protected accounts. It does not say how the specific Storm-1283 account was compromised.
In the Storm-1283 case, the compromised account let the actor sign in through a VPN. It then created a new single-tenant OAuth application in Microsoft Entra ID, giving it a name similar to the tenant's own domain name, and added a set of secrets to it. Because the account held an ownership role on an Azure subscription, the actor granted the new application Contributor permissions on an active subscription. It also added credentials to existing line-of-business OAuth applications that the account could access. Security Affairs and The Hacker News reported the same sequence.
The mining followed in two stages. According to Microsoft, the actor first deployed a small set of virtual machines through one of the existing applications, then came back later and deployed more through the new one. The machines were named after the tenant and region so they would look routine. "Targeted organizations incurred compute fees ranging from 10,000 to 1.5 million USD from the attacks," Microsoft wrote, with the cost depending on the actor's activity and how long the attack ran.
Microsoft says its analysts worked with the Entra team to block the OAuth applications used in the attack. "Affected organizations were also informed of the activity and recommended further actions," it added. The same report described an unnamed actor that created about 17,000 multitenant OAuth apps and sent more than 927,000 phishing emails between July and November 2023, and a spam actor, Storm-1286, that password-sprayed accounts most of which lacked multifactor authentication. Microsoft's mitigation advice notes that "In most cases the compromised accounts did not have MFA enabled." That statement covers the whole report, not Storm-1283 alone.
Timeline
| Date | Event |
|---|---|
| 2023 | Storm-1283 uses a compromised account to create and modify OAuth apps and deploy cryptomining VMs; Microsoft gives no exact dates. |
| July 2023 | A separate actor in the same report begins an OAuth-based phishing campaign that runs until November 2023. |
| 12 December 2023 | Microsoft Threat Intelligence publishes its report on OAuth application misuse, including Storm-1283. |
| 13 December 2023 | The Hacker News, Security Affairs and SiliconANGLE report Microsoft's findings. |
How it happened: the identity attack path
- Compromised user account. Storm-1283 gained a user account that could sign in through a VPN and held an ownership role on an Azure subscription. How it was compromised has not been published.
- New application identity. The actor registered a single-tenant OAuth application in Microsoft Entra ID with a name resembling the tenant domain, and added secrets to it.
- Privilege grant. Using the account's subscription ownership, the actor gave the new application the Contributor role on an active Azure subscription.
- Credentials added to existing apps. The actor also added credentials to existing line-of-business OAuth applications the account could access, giving it more than one machine identity to work through.
- Cryptomining through the apps. The application identities deployed virtual machines for mining, first a small set through an existing app, then more through the new one, with names chosen to blend in.
Impact
- Confirmed: cryptomining virtual machines ran in victims' Azure subscriptions, and Microsoft says targeted organisations incurred compute fees of 10,000 to 1.5 million US dollars.
- Persistence: attacker-controlled secrets on new and existing OAuth applications gave access that did not depend on the original user account.
- Not disclosed: the number and names of victims, the dates of the activity and how the first account was compromised.
- Potential: an application with Contributor rights on a subscription can do far more than run virtual machines, so the same access could have been used to change or read other resources.
What this means for NHI governance
Storm-1283 did not mine with a stolen user session. It built and borrowed application identities, gave them secrets it controlled and let them do the work. That is why this belongs on an NHI list: the durable access was an Entra ID application with Contributor rights, and the existing line-of-business apps became attacker tools the moment new credentials were added to them. Resetting the user's password would not have removed either.
The general lesson is that the right to create applications, add credentials and assign subscription roles is itself a privileged capability. It should be held by few accounts, protected by strong authentication and watched. Credential additions to existing applications, new single-tenant apps named like the tenant and virtual machines created by applications rather than people are all signals Microsoft points to. Our SaaS and OAuth App Governance Guide and Cloud PAM and CIEM Guide cover these controls, and the Microsoft Midnight Blizzard breach shows the same app-credential technique used for espionage rather than profit.
Recommendations
- Restrict who can create applications and add credentials. Limit app registration and credential management in Entra ID to a small set of administrators and review the list regularly. See our SaaS and OAuth App Governance Guide.
- Require phishing-resistant MFA for anyone with subscription ownership. Microsoft says most compromised accounts in its report had no MFA; owners and VM Contributors should never be single-factor. See our MFA Guide.
- Alert on credential changes to existing applications. A new secret or certificate on a line-of-business app is a high-signal event; route it to the app owner and the security team.
- Give applications the least privilege on Azure resources. Avoid Contributor at subscription scope for application identities and review role assignments held by service principals. See our Cloud PAM and CIEM Guide.
- Monitor resource creation by applications. Microsoft advises watching Azure Resource Manager audit logs for virtual machines created by OAuth apps, and watching for unusual quota increases. See our ITDR Guide.
- Remove app credentials during account compromise response. When a privileged user is compromised, review every application it could create or modify and revoke credentials added during the window. See the Leaked Credential Response Playbook.
Frequently asked questions
What is Storm-1283?
Storm-1283 is Microsoft's name for a financially motivated threat actor that, according to Microsoft's December 2023 report, used a compromised user account to create and modify OAuth applications in Microsoft Entra ID and deploy virtual machines for cryptocurrency mining in victims' Azure subscriptions.
How did attackers use OAuth apps for cryptomining?
Storm-1283 registered a new OAuth application, added secrets to it, granted it the Contributor role on an Azure subscription and added credentials to existing apps. Those application identities then created the virtual machines that mined cryptocurrency, leaving victims with compute bills of up to 1.5 million US dollars, according to Microsoft.
How can organisations detect malicious OAuth applications?
Audit applications and the permissions consented to them, alert when credentials are added to existing apps, review role assignments held by service principals, and watch Azure Resource Manager logs for virtual machines created by OAuth applications. Microsoft also recommends MFA and conditional access for accounts that can manage apps or subscriptions.
Related NHI Mgmt Group resources
Microsoft Verified Publisher OAuth Phishing 2022 · Amazon AWS Crypto-Mining Campaign 2025 · Storm-0501 Hybrid Cloud Attack 2024 · SaaS and OAuth App Governance Guide · Cloud PAM and CIEM Guide
How NHI Mgmt Group can help
OAuth applications and service principals are some of the least watched identities in a Microsoft tenant, yet they can hold subscription-wide rights. We help teams inventory application identities, decide who may create them and spot credential changes that should not be there. See our NHI and AI agent security training.
References
- Microsoft Threat Intelligence: Threat actors misuse OAuth applications to automate financially driven attacks (12 December 2023)
- The Hacker News: Microsoft Warns of Hackers Exploiting OAuth for Cryptocurrency Mining and Phishing (13 December 2023)
- Security Affairs: OAuth apps used in cryptocurrency mining, phishing campaigns, and BEC attacks (13 December 2023)
- SiliconANGLE: Microsoft details three OAuth-focused hacking campaigns (13 December 2023)