all InfoSec news
MERCURY and DEV-1084: Destructive attack on hybrid environment
Malware Analysis, News and Indicators - Latest topics malware.news
Microsoft Threat Intelligence has detected destructive operations enabled by MERCURY, a nation-state actor linked to the Iranian government, that attacked both on-premises and cloud environments. While the threat actors attempted to masquerade the activity as a standard ransomware campaign, the unrecoverable actions show destruction and disruption were the ultimate goals of the operation.
Previous MERCURY attacks have been observed targeting on-premises environments, however, the impact in this case notably also included destruction of cloud resources. Microsoft assesses that MERCURY …
actions actor attack attacks campaign case cloud cloud environments cloud resources destruction dev disruption environment environments goals government hybrid impact intelligence iranian mercury microsoft nation nation-state actor operations partnership ransomware resources standard state targeting threat threat actors threat intelligence