logo

APT40__2020__Microsoft_Security_detecting_empires_in_the_cloud_-_Microsoft_Security.pdf

ID: 1d6b8d38-20d5-40a9-92d8-ff8df48d98e6

STIX ID: report--1d6b8d38-20d5-40a9-92d8-ff8df48d98e6

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2020-09-25

Last Modified Date: 2020-09-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
# Executive summary Microsoft Threat Intelligence Center (MSTIC) describes GADOLINIUM, a nation-state activity group that has targeted maritime, health, education and government organizations since 2016 and has evolved from bespoke malware to abusing cloud services and open-source toolkits (TechNet, GitHub, OneDrive/Graph API, Outlook Tasks) to deliver payloads, run C2 and obfuscate activity; the report documents attack chains (VBA droppers, PowerShell Empire, LazyCat, web shells), detection examples, IOCs (hashes, attacker emails, Azure AD app IDs), and Microsoft’s proactive mitigation actions including suspending malicious Azure AD applications.