Storm-2949 walked through a Microsoft customer’s cloud environment for weeks, exfiltrated data at scale, and never dropped a single piece of malware. No droppers. No payloads. No binaries to sign. Just a stolen credential, a few API calls against trusted services, and a tenant’s worth of customer data on its way out the door. The EDR stayed quiet. The antivirus stayed quiet. The threat detection dashboard stayed quiet. The data was gone anyway.
This is the cybersecurity reality your stack was not designed to catch.
While Microsoft was publishing its Storm-2949 breakdown this morning, INTERPOL was announcing Operation Ramz: 201 arrests, 53 servers seized, hundreds of compromised devices reclaimed across the Middle East and North Africa. Two stories. Same day. Completely different threat models. One of them gets a takedown. The other one logs in tomorrow and does it again.

Malware Stopped Being The Hard Part
Operation Ramz worked because the criminals had infrastructure to seize. Phishing servers. Malware panels. Hardware you can pull off a rack. That model still exists, and INTERPOL just proved it can still be hit hard.
Storm-2949 looks nothing like it.
From Microsoft’s own description: Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware.
Read that twice. The attacker logged in. They used the same APIs your administrators use. They read from the same services your applications read from. They pulled data out through the same endpoints your business uses for backups, exports, and vendor integrations. Every action looked like work. Some of it was, technically. It just wasn’t yours.
When the entire attack chain runs inside trusted services, there’s nothing for a signature to match. No file to quarantine. No command-and-control beacon to sinkhole. INTERPOL cannot kick down a server that doesn’t exist. Your firewall cannot block traffic to api.your-cloud-provider.com because that’s where your business runs.
Storm-2949 is not a one-off. It’s the dominant shape of cloud intrusion in 2026. Identity is the perimeter, and almost nobody is meaningfully watching the inside of it.
Your Cybersecurity Stack Is Watching The Wrong Layer
Most programs still spend the majority of their detection budget on the endpoint. EDR licenses. AV renewals. Behavioral analytics tuned to process trees and file writes. That’s a defensible choice when the threat is malware. It is a near-useless choice when the threat is a federated login that travels from a stolen token, through Graph API calls, into your storage tier.
Endpoint telemetry has nothing to say in a malware-free intrusion. The attacker isn’t on an endpoint. They are calling APIs from infrastructure you don’t own. Network controls don’t apply either, since the traffic is TLS to your own SaaS providers and your egress proxy will wave it through. SIEM rules tuned for brute-force patterns and known-bad indicators miss the whole thing, because the login succeeded on the first try with a real credential.
That last point matters. The classic brute-force pattern of hundreds of failed logins followed by one success doesn’t apply when the attacker bought a working session token from an infostealer log. There is no failed login to alert on. The session is already authenticated, often already MFA-passed, by the time it reaches you.
Storm-2949, the Edge plaintext-password fix Microsoft pushed this week, and the steady drumbeat of session-token theft from infostealer markets all point at the same hole. The credential is not a secret anymore. Treating it like one is how you end up writing the postmortem.

What To Actually Do This Week
Tooling won’t save you here unless you point it somewhere new. Concrete moves, in order of how fast they pay back:
- Inventory non-human identities. Service principals, managed identities, OAuth app registrations, automation accounts. Most tenants have hundreds. Most security teams have looked at a handful. Pull the list, find the ones with no owner, and disable them.
- Shorten refresh token lifetimes. Default token lifetimes in major identity providers are generous to a fault. Cut them. A stolen token that dies in two hours is a much smaller blast radius than one that lives for ninety days.
- Alert on impossible-travel and new-ASN logins for privileged identities only. Trying to cover everyone produces unworkable noise. Scope to accounts with admin rights or access to sensitive data stores. This is the cheapest threat detection rule you can deploy this week.
- Log and review Graph API and cloud control-plane calls. If you cannot tell the difference between an admin pulling a user export and an attacker doing the same thing, you have no chance against Storm-2949. The data sits in the logs. Most teams aren’t looking.
- Pre-stage an identity-led incident response runbook. When the alert fires, the first three questions are: which identity, what scopes, what did it touch in the last seventy-two hours. If you don’t have that query saved and tested, write it now, not at 2 a.m. on a Saturday.
- Treat conditional access security hardening as continuous work. Review the exclusion lists. Test the bypass paths. Most policies have exclusions that grew without review and never got pruned.
Defense in depth still applies. Endpoint controls and firewalls aren’t worthless. They simply cannot be the load-bearing wall. The load-bearing wall is identity governance, and most organizations are running on a wall they haven’t inspected since the initial cloud migration.
There’s a hard truth in the back-to-back Microsoft and INTERPOL announcements. The takedown model is excellent at clearing yesterday’s threat. It does almost nothing against the operator who logs into your tenant tomorrow with a token they bought for forty dollars. That operator doesn’t need a server. They don’t need malware. They don’t even need to be technically sophisticated. They need a credential, and the credential is already out there.
If your cyber security spend for the next quarter still leans heavily on signatures and perimeter detection, you are funding the wrong half of the problem.
Sources
- How Storm-2949 turned a compromised identity into a cloud-wide breach
- INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
- INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests
- Microsoft is changing Edge’s plaintext password behavior
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
