What Was Midnight Blizzard? The Test Account That Reached Microsoft's Executive Inbox
The initial access was a password spray.
Not a zero-day. Not a supply chain implant. Not a stolen signing key. Somebody guessed a password on an account in a legacy, non-production test tenant, and that account did not have multi-factor authentication on it.
Everything after that was genuinely good tradecraft. The first step was the oldest one there is.
What was Midnight Blizzard?
Midnight Blizzard is Microsoft's name for the threat actor also tracked as APT29, Nobelium and Cozy Bear, attributed to the SVR, Russia's foreign intelligence service. It is the same actor behind the SolarWinds compromise in 2020.
In this case the target was Microsoft itself. Microsoft detected the intrusion on 12 January 2024 and disclosed it publicly on 19 January, in an 8-K filing and a Microsoft Security Response Center post. The actor had been inside since November 2023.
What they took was corporate email — from senior leadership, and from the cybersecurity and legal teams. Microsoft's own assessment was that the actor was looking for what Microsoft knew about Midnight Blizzard.
How they got in
A password spray is the inverse of a brute force. Instead of many passwords against one account, you try one or two very common passwords against a great many accounts. It stays under lockout thresholds because no individual account sees more than a couple of failures.
Microsoft's account of it adds two details that matter. The volume was deliberately low, and the attempts came from distributed residential proxy infrastructure — traffic that looks like ordinary consumer broadband, spread across many addresses, so that neither the per-account rate nor the source concentration trips anything.
The account that answered was in a legacy, non-production test tenant. It had no MFA.
The part that turned a test account into executive email
A password on a dormant test account is not, by itself, worth much. The escalation is the interesting half, and it is worth reading slowly because none of it involved a vulnerability.
- From that foothold the actor identified a legacy test OAuth application that had elevated access to the Microsoft corporate environment. Something built for a purpose that had passed, left with permissions it no longer needed, owned by nobody.
- Using that application's access, they created additional malicious OAuth applications of their own.
- They then created a new user account whose job was to grant consent, in the corporate environment, to those applications.
- Finally they granted their applications the Office 365 Exchange Online
full_access_as_approle — which does what the name says: full access to mailboxes, as an application, without a user.
That is the whole chain. A guessed password, an over-privileged legacy app, a consent grant, and a role assignment. Every step is a supported feature of the platform being used exactly as designed.
Why an application and not a user
Because application access does not look like a person.
An account signing in from an unusual place at an unusual hour generates signals — impossible travel, risky sign-in, MFA prompts. An OAuth application holding full_access_as_app is not signing in at all. It is authorised, permanent until revoked, and it reads mail as a normal function of the tenant.
This is the shape most cloud identity incidents have taken since. The perimeter question stopped being whose password is it and became what is allowed to act on its own, and who approved that.
It did not stop when it was disclosed
In March 2024 Microsoft published an update that did not read like a company that felt finished. The actor was using secrets found in the exfiltrated email to attempt further access — credentials that customers and Microsoft had sent each other in messages, which is a thing everybody swears they do not do.
Microsoft described a sustained increase in attempted access, including password sprays at volumes many times the level seen in January, and said it was applying enhanced security controls across its estate.
Hewlett Packard Enterprise disclosed its own Midnight Blizzard intrusion in the same month, also involving exfiltrated mailboxes, with access dating to May 2023.
Correcting the record
This gets filed as a sophisticated nation-state attack on Microsoft, and the framing does real damage, because it makes the story unlearnable. If the entry point was some exotic capability available to a foreign intelligence service, there is nothing here for anyone else.
The entry point was an account with no MFA in a tenant somebody forgot to delete.
The sophistication was in what came next — the patience, the proxy infrastructure, the choice to escalate through OAuth consent rather than credentials, the selection of which mailboxes to read. That part is genuinely SVR-grade. But the door was not.
What it actually costs to fix
Nothing in this chain is exotic, which means none of the mitigations are either. They are just tedious, and tedium is why they do not get done.
- MFA on every account, including the ones in tenants that do not matter. The tenant that does not matter is the one nobody watches.
- An inventory of OAuth applications and the permissions each one holds, with an owner attached to each. Elevated access that outlives its purpose is the actual vulnerability here.
- Restricting who can consent to applications, so a newly created user cannot authorise one.
- Alerting on role grants like
full_access_as_app, which almost no legitimate change should ever need. - A decommissioning process for test environments that ends in deletion rather than in nobody logging in any more.
Every organisation of any size has the tenant in question. It was stood up for a migration, or a proof of concept, or a vendor evaluation, by someone who has since changed teams. It is not in the CMDB. It is in the identity provider.
Further reading
- Microsoft Security Response Center — Midnight Blizzard: Guidance for responders on nation-state attack (19 and 25 January 2024). The primary account, including the OAuth escalation chain.
- Microsoft — Update on Midnight Blizzard (8 March 2024), on the use of exfiltrated secrets.
- Microsoft's 8-K filing, 19 January 2024.
- CISA Emergency Directive 24-02, on the Microsoft corporate email compromise and its implications for federal agencies.
EXHIBIT 0007 — MIDNIGHT BLIZZARD
We put it on a shirt. A forgotten rack unit with a paper tag reading TEST tied to the handle, and a chain of OAuth consent nodes running out of the back of it — each one larger than the last — into a bank of archival mail drawers standing open.
Most people will read it as a drawing of an old server. A smaller number will follow the chain left to right and recognise the escalation.
That's the whole idea.