TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Proofpoint details UNK_CondorFiltration, a TeamFiltration password-spray campaign against 5,700+ Microsoft 365 accounts that compromised seven default-password service accounts.
Proofpoint tracked an active campaign dubbed UNK_CondorFiltration that targeted over 5,700 accounts across 28 Microsoft 365 tenants, mostly Chilean retail and financial institutions, from 1,487 AWS EC2 source IPs. Seven unmanaged service accounts were compromised via password spraying with default, never-rotated credentials and no MFA; six fell within 7 minutes. After compromise, the operator pivoted through a German VPN node, accessed the Azure Portal, SharePoint Online, and requested Microsoft Graph API tokens. The campaign used the TeamFiltration offensive framework for enumeration, spraying, and backdooring Entra ID accounts.