Cybersecurity researchers have uncovered details regarding an active and sophisticated credential-spraying campaign orchestrated using the legitimate TeamFiltration framework. Codenamed UNK_CondorFiltration by threat intelligence experts at Proofpoint, the malicious operation has systematically targeted over 5,700 user accounts spread across 28 distinct Microsoft 365 tenants, shining a harsh spotlight on the persistent vulnerabilities lurking within corporate cloud perimeters.

According to telemetry and analysis from Proofpoint, the campaign’s primary focus has centered on financial institutions and retail organizations located in Chile. The threat actors launched their aggressive authentication attempts from a massive infrastructure footprint consisting of 1,487 unique Amazon Web Services (AWS) Elastic Compute Cloud (EC2) source IP addresses, demonstrating a calculated effort to distribute traffic, evade standard rate-limiting controls, and obscure the true origins of the attack.

Despite the broad scope of the targeting—which involved thousands of accounts—the actual number of successful breaches remained remarkably narrow, though deeply consequential. The campaign successfully compromised seven individual accounts. Crucially, security analysts noted that none of these breached profiles belonged to everyday human employees. Instead, every single compromised credential belonged to unmanaged functional or service accounts.

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

This narrow focus highlights a critical and widespread exposure gap across modern enterprises: the neglected, non-human identity carrying default, unrotated passwords and operating completely devoid of multi-factor authentication (MFA) protections. These accounts, often provisioned hastily by IT administrators to run specific automated business operations, are frequently abandoned to the shadows of the network topology, remaining unmonitored while retaining their original, factory-default credentials.

The Microsoft 365 brute-force and credential-spraying onslaught unfolded across three distinct operational waves between late July and August 2026. The brunt of the malicious activity was absorbed by an unnamed Chilean retail enterprise, which faced a staggering 78.3 percent of all authentication events observed during the campaign lifecycle. Evidence gathered by researchers indicates that the threat actors systematically sprayed accounts using default passwords—specifically those initially generated by IT teams during the setup phase and subsequently left untouched without undergoing routine rotation cycles.

Because standard corporate security policies frequently mandate that human employees periodically update their personal passwords, attackers largely bypassed individual user accounts in favor of dormant service accounts. These machine identities, once deployed to handle automated background tasks, were left unattended, creating a structurally unprotected attack surface. Furthermore, the speed of the operation underscored the automated nature of the threat: six of the seven compromised accounts were successfully breached within a frantic seven-minute window, suggesting the deployment of a shared or default credential list rather than prolonged, individualized brute-force efforts or sophisticated targeted credential stuffing.

The underlying tooling utilized in these attacks centers on TeamFiltration, a legitimate, open-source cross-platform offensive security framework originally built for authorized penetration testing. However, threat actors have increasingly repurposed the framework for malicious objectives, leveraging its robust capabilities for enumerating, spraying, exfiltrating, and backdooring Microsoft Entra ID environments. Within an active campaign, TeamFiltration enables an operator to validate target email addresses, test common or targeted password combinations across large batches of enumerated accounts, harvest sensitive corporate data, and establish covert, interactive access to cloud storage solutions like OneDrive.

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Following successful authentication across the targeted Microsoft 365 environments, the operators swiftly expanded their footprint. In the majority of the compromised accounts, the threat actors leveraged their initial foothold to access Microsoft Office, OneDrive, and Teams. Such activity strongly indicates active data harvesting and unauthorized exfiltration, although security researchers caution that standard sign-in events alone cannot be definitively taken as absolute proof of data theft.

The operational tempo following a breach was remarkably swift. In multiple instances, less than two minutes after a successful account compromise, the threat actor was observed pivoting through a German virtual private network (VPN) node. From this new operational relay, the attackers began actively probing corporate infrastructure endpoints, including specific corporate VPN login portals, navigating the Azure Portal, browsing SharePoint Online repositories, and initiating Microsoft Graph API token requests to sustain their access and deepen their foothold within the cloud tenant.

This campaign is not an isolated incident involving the weaponization of the TeamFiltration framework. In June 2025, Proofpoint documented a separate, large-scale threat cluster dubbed UNK_SneakyStrike. That earlier campaign leveraged the same open-source penetration testing framework to target more than 80,000 Microsoft Entra ID user accounts spanning hundreds of organizational cloud tenants across various industries, illustrating a continuing reliance by threat actors on legitimate administrative tools turned against enterprise defenses.

Security analysts emphasize that the UNK_CondorFiltration campaign serves as a sobering reminder that the weakest link in an organization’s identity perimeter is frequently not a phished employee falling victim to social engineering, nor is it an advanced zero-day software exploit. Instead, the greatest risk often stems from the forgotten account—service identities provisioned for administrative convenience, left unmonitored over long periods, and forgotten by IT staff tasked with maintaining comprehensive asset inventories.

By Sagoh

Leave a Reply

Your email address will not be published. Required fields are marked *