APT40__2020__Microsoft_Security_detecting_empires_in_the_cloud_-_Microsoft_Security.pdf
ID: 1d6b8d38-20d5-40a9-92d8-ff8df48d98e6
STIX ID: report--1d6b8d38-20d5-40a9-92d8-ff8df48d98e6
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2020-09-25
Last Modified Date: 2020-09-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
# Executive summary
Microsoft Threat Intelligence Center (MSTIC) describes GADOLINIUM, a nation-state activity group that has targeted maritime, health, education and government organizations since 2016 and has evolved from bespoke malware to abusing cloud services and open-source toolkits (TechNet, GitHub, OneDrive/Graph API, Outlook Tasks) to deliver payloads, run C2 and obfuscate activity; the report documents attack chains (VBA droppers, PowerShell Empire, LazyCat, web shells), detection examples, IOCs (hashes, attacker emails, Azure AD app IDs), and Microsoft’s proactive mitigation actions including suspending malicious Azure AD applications.
