Mandiant reported that attackers combined SIM swapping with abuse of the Microsoft Azure Serial Console to gain access to cloud-hosted environments. The activity showed how control of a victim’s phone number can be used to intercept authentication flows and support broader account takeover, while Azure’s serial console capability provided a path to interact directly with virtual machines and maintain access during the intrusion.
The incident highlights a blended attack chain that moved from telecom-layer compromise into cloud infrastructure abuse. By pairing identity takeover techniques with legitimate administrative features in Azure, the attackers were able to escalate the impact of SIM swapping beyond consumer account fraud and into enterprise cloud operations, underscoring the need to harden MFA recovery processes, tightly restrict serial console access, and monitor for unusual use of privileged cloud management functions.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Mandiant published research describing an attack chain involving SIM swapping and abuse of the Microsoft Azure Serial Console. The reference indicates public disclosure of the campaign and its techniques, but provides no additional dated milestones in the supplied content.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.