AzureChecker is a command-line tool (AzureChecker.exe) observed by Microsoft Threat Intelligence being used by threat actor Storm-1977, as well as by a wider range of actors, to conduct password-spraying attacks against cloud tenants in the education sector. In the reported activity, AzureChecker.exe retrieved AES-encrypted targeting data from sac-auth[.]nodefunction[.]vip; once decrypted, the data contained a list of accounts to target. The tool also used an accounts.txt file containing username/password combinations, merged the target list with those credentials, and attempted logins sequentially to validate credentials against target tenants. Microsoft observed at least one successful compromise via a guest user cloud account. Following access, the actor created a resource group containing more than 200 containers and used them for cryptomining, resulting in resource hijacking. The reporting also links the activity to risks affecting containerized environments, including Kubernetes-related assets. A high-confidence network indicator directly mentioned in the content is sac-auth[.]nodefunction[.]vip.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft Threat Intelligence researchers observed a threat actor, tracked as Storm-1977, using AzureChecker.exe to launch password spray attacks against cloud tenants in the education sector.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A command-line tool used to conduct password-spraying against Microsoft cloud tenants. It downloads AES-encrypted targeting data from a remote server, decrypts it to obtain password-spray targets, and can also ingest an accounts.txt list of username/password pairs to validate credentials against target tenants.
Command-line tool used to conduct password spraying against cloud tenant accounts by iterating through account lists and username/password combinations to attempt logins at scale.
A command-line tool used to conduct password spray attacks against cloud tenants by downloading an AES-encrypted target list, ingesting username/password combinations (e.g., from accounts.txt), and submitting credentials to target tenants for validation; observed leading to account compromise and subsequent creation of containers for cryptomining.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.