Executive Summary
ROADtools, originally an open-source red-teaming framework, has been operationalized by several nation-state threat actors for cloud intrusions. Notable groups include Cloaked Ursa (APT29/Midnight Blizzard), which utilized the tool for discovery following spear-phishing, and Curious Serpens (APT33), which leveraged it after successful password spray campaigns. In 2025, a Russian-affiliated actor (UTA0355) was also observed using capabilities matching the ROADtools token exchange module to register rogue devices.
The framework consists of modules like ROADrecon for internal discovery and ROADtx for token acquisition and manipulation. By interacting with legitimate Microsoft APIs, ROADtools can mimic authorized traffic, making it difficult for traditional defenses to distinguish between administrative actions and malicious activity. This transition from a security utility to an adversary-favored toolkit underscores a growing trend in targeting cloud identity and authentication layers.
For organizations, this threat poses a significant risk of long-term persistence, lateral movement, and the bypassing of multi-factor authentication (MFA) through token replay or Primary Refresh Token (PRT) theft. Defending against these tactics requires a combination of robust conditional access policies, token protection, and rigorous monitoring of Microsoft Graph API activity for anomalous, high-volume enumeration.
