CONNECT WITH US
Cyber Security

Cyber Security

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

The Hacker News logo

Published on

Add as a preferred source on Google
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.

According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses.

"The campaign compromised 7 accounts – all of which were unmanaged functional or service accounts rather than individual employee accounts – highlighting a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no MFA [multi-factor authentication]," the enterprise security company said in a statement.

The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events -

Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated. The activity mainly targeted dormant service accounts as opposed to personal employee accounts, since users are mandated to change passwords from time to time.

These service accounts, per Proofpoint, were provisioned to run business operations and then left unmonitored, while still carrying their original credentials. Every successful compromise has been linked to unmonitored service accounts with a default password.

Six of the seven compromised accounts were broken into within 7 minutes, likely indicating a shared or default password set rather than individually targeted credential stuffing.

The activity is characterized by the use of TeamFiltration, a legitimate cross-platform offensive framework designed for "enumerating, spraying, exfiltrating, and backdooring" Entra ID accounts.


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We TheMorningPulse.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It's possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.