Microsoft disclosed that Midnight Blizzard (APT29/NOBELIUM) breached its corporate environment by password-spraying a legacy non-production tenant account without MFA, then abusing OAuth applications and the full_access_as_app role to access Exchange Online mailboxes. Microsoft said the Russian state-backed actor used distributed residential proxy infrastructure to hide its activity, while Mandiant separately documented the same group using residential proxies, Microsoft-owned IP space via external Azure subscriptions, MFA self-enrollment abuse, and audit-log suppression to blend into normal Microsoft 365 traffic and sustain email collection against government and policy targets.
A broader analysis of the residential proxy market found that these services are widely available through cybercrime forums and are increasingly used by both espionage actors and criminal groups for attribution resistance, phishing, spam, DDoS, and fraud. The report said proxy pools are built through proxyware installs, embedded SDKs, and compromised systems, and identified links among providers including PiaS5Proxy, ABCProxy, and 922Proxy through shared cryptocurrency wallets and Hong Kong-linked entities, underscoring how opaque proxy ecosystems can materially support stealthy nation-state operations and prompting recommendations to detect and block proxyware inside enterprise environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On January 25, 2024, Microsoft publicly disclosed the Midnight Blizzard intrusion, describing password-spray access to a legacy non-production test tenant account without MFA, abuse of OAuth applications, Exchange Online mailbox access, and use of distributed residential proxy infrastructure. Microsoft also said it had begun notifying other organizations targeted by the actor and published detection and hardening guidance.
Microsoft detected a nation-state attack on its corporate systems on January 12, 2024, and immediately activated its incident response process. The company attributed the intrusion to Midnight Blizzard, also known as APT29/NOBELIUM.
The Sekoia.io report notes that IPRoyal rebranded to Pawns.app in December 2023.
Researchers documented a 2023 incident in which an attacker gained SSH access to a partner system and clandestinely installed Pawns.app proxyware with persistence via cron jobs and service modification.
The Sekoia.io study found that the majority of the residential proxy providers it analyzed had emerged during 2023.
Sekoia.io and Orange Cyberdefense analyzed more than 50 residential proxy offerings advertised on forums including BreachForums, Nulled, XSS, BlackHatWorld, and Zelenka during 2023.
In 2022, Mandiant observed APT29 targeting organizations involved in shaping NATO countries’ foreign policy and revisiting previously compromised victims.
Mandiant states it has tracked APT29, a Russian espionage group likely sponsored by Russia’s SVR, since at least 2014.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
blog.sekoia.io
Open sourcecadosecurity.com
Open sourcemicrosoft.com
Open sourcemandiant.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.