Interestana
Home/News/TeamFiltration Campaign Exploits Default Passwords in Microsoft 365
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

TeamFiltration Campaign Exploits Default Passwords in Microsoft 365

TeamFiltration Campaign Exploits Default Passwords in Microsoft 365

Cybersecurity researchers have detailed an ongoing TeamFiltration campaign, identified by the codename UNK_CondorFiltration, which has successfully compromised more than 5,700 accounts across 28 distinct Microsoft 365 tenants. Proofpoint, a cybersecurity firm, reported that this campaign has predominantly targeted retail and financial institutions located in Chile. The malicious activity was observed originating from 1,487 unique Amazon Web Services (AWS) Elastic Compute Cloud (EC2) source IP addresses, indicating a sophisticated and distributed infrastructure. The campaign's primary vector for initial access involves the exploitation of default or weak passwords, a common but persistent vulnerability in many organizations' security postures. While the overall number of compromised accounts is substantial, the campaign has specifically compromised 7 accounts, with the report indicating that these accounts were accessed without the use of multi-factor authentication (MFA). This suggests a targeted approach within the broader campaign, focusing on accounts that present the lowest barrier to entry. The attackers leveraged these compromised accounts to gain initial access to victim environments, subsequently deploying additional malicious tools and techniques to further their objectives. The nature of these objectives is still under investigation, but typical follow-on actions in such campaigns include credential harvesting, lateral movement within the network, and the deployment of ransomware or other forms of malware. The use of AWS EC2 instances for originating the attacks highlights the reliance of threat actors on cloud infrastructure, which can be provisioned and scaled rapidly to support large-scale operations. The specific targeting of Chilean retail and financial sectors suggests a potential motive related to financial gain or disruption of critical services within that region. Proofpoint's analysis underscores the persistent threat posed by password-based attacks and the critical importance of enforcing strong password policies and multi-factor authentication across all user accounts. The campaign's ability to operate at scale, evidenced by the thousands of compromised accounts and the extensive use of cloud infrastructure, presents a significant challenge for cybersecurity defenses. Further investigation is ongoing to fully understand the scope and impact of the UNK_CondorFiltration campaign and to develop effective countermeasures.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next