Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
How CEO Ed Bastion built Delta’s  billion per year partnership with American Express

How CEO Ed Bastion built Delta’s $8 billion per year partnership with American Express

3 April 2026
Video: Skilled Foreign Workers Think About Leaving the U.S.

Video: Skilled Foreign Workers Think About Leaving the U.S.

3 April 2026
Cyprus and Ireland top best places to retire as boomers are forced to move abroad

Cyprus and Ireland top best places to retire as boomers are forced to move abroad

3 April 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Microsoft Confirms Password Spraying Attack — What You Need To Know
Innovation

Microsoft Confirms Password Spraying Attack — What You Need To Know

Press RoomBy Press Room28 April 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Microsoft Confirms Password Spraying Attack — What You Need To Know

With a billion stolen passwords up for sale on dark web criminal marketplaces, and infostealer malware attacks continuing to add to that number, it’s no wonder that cybercriminals are turning to automatic password hacking machines in their nefarious campaigns. I have previously reported on password spray and pray attacks against Windows users without two-factor authentication, now Microsoft has issued a warning of a new password spraying attack by a hacking group identified only as Storm-1977 that is targeting cloud tenants.

Beware This Password Spraying Attack, Microsoft Warns

The Microsoft Threat Intelligence team has published a new warning after observing hackers taking particular advantage of unsecured workload identities in order to gain access to containerized environments. With Microsoft research showing that 51% of such workload identities being completely inactive over the past year, it’s no wonder that threat actors are exploiting this attack surface. “As the adoption of containers-as-a-service among organizations rises,” the report said, “Microsoft Threat Intelligence continues to monitor the unique security threats that affect containerized environments.” One of these is the password spraying attack, specifically targeting cloud tenants in the education sector, that has now been pinned on the Storm-1977 threat group.

The password spraying attack exploited a command line interface tool called AzureChecker to “download AES-encrypted data that when decrypted reveals the list of password spray targets,” the report said. It then, to add salt to the now open wound, accepted an accounts.txt file containing username and password combinations used for the attack, as input. “The threat actor then used the information from both files and posted the credentials to the target tenants for validation,” Microsoft explained.

The successful attack enabled the Storm-1977 hackers to then leverage a guest account in order to create a compromised subscription resource group and, ultimately, more than 200 containers that were used for cryptomining.

Mitigating The Password Spraying Container Attack Threat

Microsoft said that, in light of attackers such as Storm-1977
increasingly using compromised identities for initial access as well as long-term persistence within an environment, the following mitigations are recommended:

  • Use strong authentication when exposing sensitive interfaces to the internet.
  • Use strong authentication methods for the Kubernetes API to help prevent attackers from gaining access to the cluster even if valid credentials such as kubeconfig are obtained.
  • Avoid using the read-only endpoint of Kubelet on port 10255, which doesn’t require authentication.
  • Configure the Kubernetes role-based access controls for each user and service account to have only those permissions that are absolutely necessary.

I have reached out to Microsoft for further information regarding the Storm-1977 password spraying attack campaign.

Azure AzureChecker Education enterprise Hackers Kubernetes Microsoft Password Attack Password Spraying Storm-1977
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Microsoft and Chevron enter exclusivity deal on powering West Texas data center complex

Microsoft and Chevron enter exclusivity deal on powering West Texas data center complex

2 April 2026
1 Habit Emotionally Intelligent Adults Had As Kids, By A Psychologist

1 Habit Emotionally Intelligent Adults Had As Kids, By A Psychologist

1 April 2026
The Graveyard Of OpenAI’s Dead Products And Incomplete Deals

The Graveyard Of OpenAI’s Dead Products And Incomplete Deals

1 April 2026
How The Children’s Movie “Cars” Forewarns A Post-Human Era

How The Children’s Movie “Cars” Forewarns A Post-Human Era

1 April 2026
Inside The New Deal Pipelines Female Founders Are Quietly Building

Inside The New Deal Pipelines Female Founders Are Quietly Building

1 April 2026
Apple Did The Unthinkable With Its 9 MacBook Neo

Apple Did The Unthinkable With Its $599 MacBook Neo

1 April 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

6 February 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
I was rejected 33 times and built a 0 million company — at 48 years old. Age bias in tech is costing us all

I was rejected 33 times and built a $390 million company — at 48 years old. Age bias in tech is costing us all

3 April 20260 Views
UK accuses Iran of Hormuz ‘hijack,’ holding global economy hostage

UK accuses Iran of Hormuz ‘hijack,’ holding global economy hostage

3 April 20260 Views
U.S. gas prices are at their highest since 2022, and it’s primarily hurting low-income households

U.S. gas prices are at their highest since 2022, and it’s primarily hurting low-income households

3 April 20260 Views
Jack Dorsey and Roelof Botha think AI can make middle management obsolete 

Jack Dorsey and Roelof Botha think AI can make middle management obsolete 

3 April 20261 Views

Recent Posts

  • How CEO Ed Bastion built Delta’s $8 billion per year partnership with American Express
  • Video: Skilled Foreign Workers Think About Leaving the U.S.
  • Cyprus and Ireland top best places to retire as boomers are forced to move abroad
  • What it takes to retire comfortably in America: Nearly $1.5 million, Northwestern Mutual says
  • I was rejected 33 times and built a $390 million company — at 48 years old. Age bias in tech is costing us all

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
How CEO Ed Bastion built Delta’s  billion per year partnership with American Express

How CEO Ed Bastion built Delta’s $8 billion per year partnership with American Express

3 April 2026
Video: Skilled Foreign Workers Think About Leaving the U.S.

Video: Skilled Foreign Workers Think About Leaving the U.S.

3 April 2026
Cyprus and Ireland top best places to retire as boomers are forced to move abroad

Cyprus and Ireland top best places to retire as boomers are forced to move abroad

3 April 2026
Most Popular
What it takes to retire comfortably in America: Nearly .5 million, Northwestern Mutual says

What it takes to retire comfortably in America: Nearly $1.5 million, Northwestern Mutual says

3 April 20260 Views
I was rejected 33 times and built a 0 million company — at 48 years old. Age bias in tech is costing us all

I was rejected 33 times and built a $390 million company — at 48 years old. Age bias in tech is costing us all

3 April 20260 Views
UK accuses Iran of Hormuz ‘hijack,’ holding global economy hostage

UK accuses Iran of Hormuz ‘hijack,’ holding global economy hostage

3 April 20260 Views

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.