Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s detailed warning about destructive MERCURY attacks across on-premises systems and Azure was published on April 7, 2023—not a newly disclosed 2026 campaign. Microsoft now names MERCURY as Mango Sandstorm and maps its reported partner, DEV-1084, to Storm-1084. The incident showed how attackers could move from vulnerable on-premises applications to privileged cloud identities, then combine ransomware-like activity with destructive deletion of Azure resources.

What Microsoft reported—and when

Microsoft Threat Intelligence’s April 7, 2023 report described destructive activity affecting both on-premises and cloud environments. Its April 2023 update adopted the names Mango Sandstorm for MERCURY and Storm-1084 for DEV-1084. Microsoft’s current threat actor naming table lists Mango Sandstorm as Iran-linked and MERCURY among its associated names.

Microsoft assessed that the operators used known vulnerabilities in unpatched applications to gain initial access, then worked with DEV-1084, which carried out reconnaissance, persistence, and lateral movement. The relationship between the groups was not settled: Microsoft said it was unclear whether DEV-1084 acted independently or as an effects-focused sub-team. It linked the activity through shared infrastructure and tooling, including an IP address previously associated with MERCURY, MULLVAD VPN, Rport, a customized Ligolo version, and a command-and-control domain it assessed with high confidence was controlled by MERCURY operators. This is Microsoft’s attribution assessment, not independently proven identity.

How the intrusion moved from on-premises to Azure

1. Initial access and footholds

In the 2023 report, Microsoft described remote exploitation of an unpatched internet-facing device or vulnerable application as an initial-access route. It listed web shells, local administrator accounts, remote-access tools, customized PowerShell backdoors, and credential theft among the methods used to maintain access. Operators used native Windows commands for discovery and scheduled tasks, Windows Management Instrumentation (WMI), and remote services for lateral movement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Disrupting on-premises defenses

Operators often left weeks or months between stages. On-premises, they used Group Policy to interfere with security tools, staged a ransomware payload on domain controllers, and launched it with scheduled tasks. The payload encrypted files and changed their extensions to DARKBIT.

3. Pivoting through directory synchronization and credentials

To reach cloud resources, the attackers compromised privileged accounts and manipulated the Azure AD Connect agent, which synchronizes identities between on-premises Active Directory and Azure AD. Microsoft reported extraction of plaintext credentials for a privileged Azure AD account. One account had Global Administrator permissions because of an old DirSync setup. Another compromised administrator account had multifactor authentication, but the attackers accessed it through an already open Remote Desktop Protocol (RDP) session. The report therefore illustrates why MFA alone does not protect an unattended, authenticated session.

4. Escalating cloud access and causing damage

Microsoft observed the actors claiming Global Administrator permissions through Azure Privileged Identity Management and elevating access to management groups and subscriptions. Within hours, they deleted server farms, virtual machines, storage accounts, and virtual networks. They also granted an existing OAuth application full Exchange Web Services mailbox access.

Although the activity was presented as ransomware, Microsoft judged the unrecoverable actions to indicate that destruction and disruption were the operation’s ultimate goals. Ransomware was part of the attack, but it did not explain the full impact.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How this differs from Microsoft’s 2022 MERCURY reporting

A separate Microsoft report, published August 25, 2022, described MERCURY activity against Israeli organizations involving suspected exploitation of Log4j 2 vulnerabilities in vulnerable SysAid Server instances. Microsoft assessed with moderate confidence that the actor exploited Apache Log4j 2 remote-code-execution vulnerabilities and with high confidence that the activity was affiliated with Iran’s Ministry of Intelligence and Security. It dated observed SysAid exploitation to July 23 and 25, 2022. Those findings are earlier campaign context; they are not the same incident narrative as the 2023 destructive hybrid-environment report.

The two reports together describe different aspects of activity associated with the actor: the 2022 account focuses on a suspected route into SysAid Server, while the 2023 account details a multi-stage intrusion spanning on-premises infrastructure and Azure.

What defenders should monitor

Microsoft recommends investigating related identity, endpoint, directory-synchronization, and cloud events as a connected sequence rather than treating each alert in isolation. Its 2023 report identifies these signals:

  • Risky-user access elevation and unfamiliar sign-in properties.
  • Unusual activity involving Azure AD Connect sync accounts.
  • Suspicious additions to sensitive groups or suspicious Exchange application-role grants.
  • Unexpected deletion activity, including multiple storage accounts or virtual machines and other Azure resource deletions.
  • Honeytoken activity.
  • Suspicious web shells, scheduled tasks, SSH tunneling, PowerShell use, antivirus exclusions, or tampering with Microsoft Defender.

A useful investigation thread is to connect a suspicious endpoint or sync-account event to subsequent identity elevation, application permissions, and cloud deletions. The sequence matters: the reported attack crossed boundaries that separate endpoint security, directory administration, and cloud operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Microsoft’s mitigation guidance

For organizations using the relevant Microsoft security products, the 2023 report recommends enabling cloud-delivered protection, using applicable Defender detections for exploitation and post-exploitation activity, enabling attack-surface-reduction protections, and using Controlled Folder Access to help prevent ransomware from changing protected files. These are product-specific recommendations from that report; Microsoft’s available detections and settings may change over time.

The incident also makes the identity path a practical review priority: check privileged accounts and legacy directory-sync configurations, investigate unexpected access to active administrator sessions, and scrutinize changes to Azure roles, management groups, subscriptions, and OAuth application permissions. These checks address the access routes and escalation activity Microsoft described; they do not establish that any particular organization has been targeted.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.