{"id":3119,"date":"2026-09-24T09:58:15","date_gmt":"2026-09-24T09:58:15","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3119"},"modified":"2026-09-24T09:58:15","modified_gmt":"2026-09-24T09:58:15","slug":"teamfiltration-campaign-compromises-seven-microsoft-365-accounts-using-default-passwords","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3119","title":{"rendered":"TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 24, 2026<\/span><\/span><span class=\"p-tags\">Cloud Security \/ Identity Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgQgKN3zS7GtEpakDcL7zk0tL-zcz3GJMkVf9vMLCVXf33XZ1Yad77dg3Zen_EEB58BltCG_pj0c-yVDm6VbV9cw5Baxtf26vVtRwW4qwDDy1s8HYMFKfTyl382lwJIRfSWBSA-WK6RAZ8lmy9zf5IZb_Ilqol0AcVdEaMp599tZ4NxqUc-KY4-fyFNYYFg\/s1700-nu-rw-lo-l85-e365\/ms-365.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed <strong><a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/Spraying-in-the-Andes-TeamFiltration-Returns\" target=\"_blank\">UNK_CondorFiltration<\/a><\/strong> that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.<\/p>\n<p>According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses.<\/p>\n<p>\u00abThe campaign compromised 7 accounts \u2013 all of which were unmanaged functional or service accounts rather than individual employee accounts \u2013 highlighting a critical exposure gap around forgotten, non-human identities carrying default or unrotated passwords and no MFA [multi-factor authentication],\u00bb the enterprise security company said in a statement.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The Microsoft 365 brute-force campaign is said to have unfolded across three different waves from late July to August 2026, with an unnamed Chilean retailer facing the brunt of 78.3% of all observed authentication events &#8211;<\/p>\n<ul>\n<li>July 21-24, targeting approximately 100\u2013120 unique accounts per day and directed against two major Chilean banking institutions<\/li>\n<li>July 26-28, targeting a peak of about 1,520 accounts on July 27 before dropping sharply and directed against another major Chilean financial institution<\/li>\n<li>August 13-16, targeting a peak of about 1,560 accounts on August 15 and directed against a major Chilean retailer, leading to seven account compromises<\/li>\n<\/ul>\n<p>Evidence indicates that the threat actor likely sprayed accounts with default passwords, including credentials provisioned by IT teams and never rotated. The activity mainly targeted dormant service accounts as opposed to personal employee accounts, since users are mandated to change passwords from time to time.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>These service accounts, per Proofpoint, were provisioned to run business operations and then left unmonitored, while still carrying their original credentials. Every successful compromise has been linked to unmonitored service accounts with a default password.<\/p>\n<p>Six of the seven compromised accounts were broken into within 7 minutes, likely indicating a shared or default password set rather than individually targeted credential stuffing.<\/p>\n<p>The activity is characterized by the use of TeamFiltration, a legitimate cross-platform offensive framework designed for \u00abenumerating, spraying, exfiltrating, and backdooring\u00bb Entra ID accounts. It allows an operator to validate email accounts, test common or targeted passwords across enumerated accounts, harvest sensitive data, and gain covert, interactive access to OneDrive.<\/p>\n<p>Across most of the compromised accounts, the threat actor leveraged the foothold to access Microsoft Office, OneDrive, and Teams, potentially indicative of data harvesting and exfiltration. That said, sign-in events alone cannot be taken as evidence of exfiltration.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Less than 2 minutes after successful compromise, the operator has been observed pivoting to a German VPN node to probe the corporate VPN (\u00abvpn.[redacted].cl\/SAML20\/SP\u00bb), access Azure Portal, browse SharePoint Online, and initiate Microsoft Graph API token requests.<\/p>\n<p>This is not the first time TeamFiltration has been put to use in malicious attacks. In June 2025, Proofpoint detailed another threat cluster dubbed UNK_SneakyStrike that targeted over 80,000 user accounts across hundreds of organizations&#8217; cloud tenants using the open-source penetration testing framework.<\/p>\n<p>\u00abThe UNK_CondorFiltration campaign is a reminder that one of the weakest links in an enterprise identity perimeter is often not a phished employee or a zero-day exploit,\u00bb Proofpoint said. \u00abIt is the forgotten account. Service accounts provisioned for convenience and never revisited are a structurally unprotected attack surface.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 24, 2026Cloud Security \/ Identity Security Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3120,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[592,6,173,1607,147,296,3528],"class_list":["post-3119","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-accounts","tag-campaign","tag-compromises","tag-default","tag-microsoft","tag-passwords","tag-teamfiltration"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3119","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3119"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3119\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3120"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}