OS
AA
BACK TO ARCHIVE
TLP:AMBERINTERNAL
ID: REP-2026-042
Date: 2026-02-14

ANALYZED: ADVANCED PERSISTENT THREAT GROUP 'MIDNIGHT BLIZZARD' LEVERAGING NEW OAUTH EXPLOITS

ImpactHigh
ConfidenceHigh
Regions:
EUROPEAMERICAS

Executive Summary

Midnight Blizzard (formerly Nobelium) has been observed utilizing a novel technique involving the abuse of OAuth applications to maintain persistent access to cloud environments. This campaign targets technology and government sectors.

Key Findings

  1. Persistence via OAuth: The actor creates malicious OAuth applications within compromised tenants to bypass MFA and maintain long-term access.
  2. Targeting Strategy: Focus remains on high-value targets in the defense and diplomatic sectors.
  3. Evasion: Use of residential proxy networks to mask origin traffic.

Technical Details

The actor gains initial access through password spraying attacks against accounts without MFA. Once inside, they register a new OAuth application and grant it Mail.ReadWrite permissions.

"The use of legitimate OAuth flows makes this activity extremely difficult to detect with traditional perimeter monitoring."

Mitigation

  • Audit all OAuth applications with high-privilege scopes.
  • Enforce phish-resistant MFA for all users.
  • Monitor for New-Application events in audit logs.
Omnisite Intelligence Platform // v0.1-MVP

Stylistic classification markings only; OSINT-based analysis. Not for operational use on classified networks.

PUBLIC DEMO ENVIRONMENT - DO NOT UPLOAD PII/PHI

Key Entities
Midnight BlizzardMicrosoftHewlett Packard Enterprise
Vectors
OAuth AbuseCredential StuffingPassword Spraying

Chronology

2026-01-12Initial Access Detected

Anomalous login activity detected on legacy tenant.

2026-01-28Privilege Escalation

Actor created a new OAuth application with elevated permissions.

2026-02-04Data Exfiltration

Exfiltration of corporate email inboxes beginning with executive accounts.

Technical Indicators

TYPEVALUE
IP198.51.100.24
DOMAINupdate-microsoft-auth.com
HASHa1b2c3d4e5f6...

AUTOMATED ANALYTICS v1.0