Microsoft to alert Office 365 users of nation-state hacking activity

Microsoft will soon notify Office 365 of suspected nation-state hacking activity detected within their tenants according to a new listing on the company’s Microsoft 365 roadmap.

Microsoft Defender for Office 365 (previously known as Office 365 Advanced Threat Protection or Office 365 ATP) provides Office 365 enterprise accounts with email protection against several types of threats including credential phishing and business email compromise, as well as automated attack remediation.

Alerts based on Microsoft built threat profiles

These notifications will be added to the customers’ security portal to give them a head start against what Redmond considers the most advanced hacking groups it currently tracks.

“We’re adding an alert to the security portal to alert customers when suspected nation-state activity is detected in the tenant,” Microsoft says.

“Nation state threats are defined as cyber threat activity that originates in a particular country with the apparent intent of furthering national interests. These attacks represent some of the most advanced and persistent threat activity Microsoft tracks.”

The alerts regarding hacking activity with potential nation-state fingerprints will be based on indicators of compromise and threat profiles collected and put together by Microsoft’s security experts.

“The Microsoft Threat Intelligence Center follows these threats, builds comprehensive profiles of the activity, and works closely with all Microsoft security teams to implement detections and mitigations to protect our customers,” Redmond explains.

Support for the “Potential Nation State Activity Alerts” feature is currently in development and Microsoft is planning to make it generally available worldwide this month in all environments, for all Microsoft Defender for Office 365 (Office 365 Advanced Threat Protection) users.

Long track record of tracking nation-state hackers

Microsoft has been tracking, warning of, and disrupting state-sponsored hacking operations originating from Russia, Iran, and China for years.

For instance, last month, Microsoft disclosed that vulnerability researchers have been targeted by the North Korean backed hacking group tracked as ZINC or Lazarus for several months using a Chrome exploit chain that likely “used 0-day or patch gap exploits”.

In the last 6 months alone, Microsoft has warned of state-sponsored hackers from Russia, China, and Iran targeting the 2020 US elections, Iranian-backed attackers hacking security conference attendees, and has also disrupted a nation-state hacking op that used the Azure Cloud infrastructure in attacks.

Microsoft also added priority protection for accounts of high-profile employees such as executive-level managers who are regularly targeted in attacks.

A new Office 365 feature to allow customers to test Microsoft Defender email protection without having to configure their environment and devices has also been added to Office 365 recently.

Organizations that don’t yet have a license with support for Microsoft Defender for Office 365 can start a free 30-day evaluation and test it within the Office 365 Security & Compliance Center.