Critical Microsoft 365 Flaw Let Attackers Access Accounts
Key Takeaways Attackers successfully breached Microsoft 365 environments by exploiting dormant or unmonitored service accounts. The campaign, identified as UNK_CondorFiltration, leveraged the...
Key Takeaways
- Attackers successfully breached Microsoft 365 environments by exploiting dormant or unmonitored service accounts.
- The campaign, identified as UNK_CondorFiltration, leveraged the TeamFiltration testing framework to conduct widespread password spraying attacks.
- Seven confirmed compromises occurred across 28 Microsoft 365 tenants, primarily targeting organizations in Chile.
- The vulnerabilities stemmed from outdated passwords and the absence of multi-factor authentication (MFA) on these service accounts.
- Post-compromise activities included reconnaissance within Microsoft Office, OneDrive, and Teams, with potential for data exfiltration.
Cybersecurity researchers have uncovered a series of intrusions into Microsoft 365 ecosystems, where threat actors gained unauthorized access by targeting active but neglected accounts. These breaches capitalized on weak security postures, specifically the presence of old passwords and a lack of robust sign-in protections, allowing attackers to infiltrate critical corporate resources such as email, files, and cloud applications.
Table Of Content
The campaign primarily focused on entities within Chile, impacting a major retailer and several financial institutions. Instead of focusing on individual accounts, the attackers utilized a password spraying technique, systematically testing common or default passwords across a large volume of accounts. Successful logins then provided a foothold for further exploration of cloud services.
Analysts at Proofpoint attributed this malicious activity to a campaign they labeled UNK_CondorFiltration. This operation did not involve new malware but rather exploited the legitimate TeamFiltration testing framework. According to a report from Proofpoint, the attackers targeted 5,714 accounts across 28 distinct Microsoft 365 tenants, resulting in seven confirmed compromises.
These statistics highlight a specific and critical vulnerability. None of the confirmed breaches involved standard employee accounts. Instead, every compromised identity was a functional or service account, typically used for automated processes like payment processing, ticketing systems, or point-of-sale operations, and not regularly accessed by human users. These accounts often remain operational without consistent oversight.
Hackers Exploited Forgotten Accounts
Investigations revealed that the seven compromised accounts exhibited no prior legitimate sign-in activity in the available logs. Six of these accounts were breached within a mere seven-minute window, suggesting the attackers exploited either shared or default passwords that had never been changed. Crucially, these accounts were still enabled, lacked clear administrative ownership, and, most critically, appeared to be unprotected by multi-factor authentication (MFA), making a simple valid password sufficient for access.
One particular retailer bore the brunt of the attack, accounting for 25,715 of the campaign’s 32,825 authentication attempts, or 78.3%. The peak of this activity occurred between August 13 and 16, with approximately 1,560 targeted accounts on August 15. All seven confirmed compromises at this retailer transpired on August 14 and 15.
This attack pattern echoes a previous TeamFiltration campaign that also targeted cloud identities. The TeamFiltration framework enables attackers to verify account existence via the Teams API, conduct large-scale password testing, and obscure their origins by cycling through various cloud infrastructure locations. Once access is gained, the framework is capable of collecting data from email, Teams messages, OneDrive, and SharePoint, making unmonitored operational accounts highly attractive targets.
From Valid Login to Cloud Reconnaissance
The attackers’ activities extended beyond merely gaining entry. For most compromised accounts, researchers observed subsequent access to Microsoft Office, OneDrive, and Teams, all originating from the same cloud-hosted infrastructure. This behavior aligns with TeamFiltration’s automated data collection capabilities, although forensic analysis of sign-in logs alone cannot definitively confirm whether files or messages were exfiltrated.
In one documented instance, the attacker swiftly switched to a German VPN node within 90 seconds of the initial compromise. The operator then unsuccessfully attempted to probe the corporate VPN before accessing Azure Portal, OfficeHome, and SharePoint Online. An MFA enrollment prompt encountered during the Azure Portal interaction clearly indicated that the compromised account was not protected by MFA.
Access to SharePoint could facilitate document discovery, data theft, or the planting of malicious files for unsuspecting users. Furthermore, a request for an access token through the SharePoint Online Web Client Extensibility application pointed to attempts to interact with Microsoft Graph or other external application programming interfaces. Such post-login tactics are consistent with reports on hidden cloud mailbox rules, a technique used by intruders to maintain covert visibility into business email communications.
What You Should Do
- Inventory Service Accounts: Conduct a comprehensive audit of all service and functional accounts. Identify their purpose, associated applications, and assigned permissions.
- Assign Account Ownership: Ensure every service account has a clear, accountable owner responsible for its lifecycle and security.
- Deactivate Unused Accounts: Promptly remove or disable any service accounts that are no longer necessary for business operations.
- Rotate Credentials: Regularly change passwords for service accounts, especially those with inherited or default credentials.
- Enforce Multi-Factor Authentication (MFA): Implement MFA for all accounts, including service accounts, wherever technically feasible. If MFA isn’t directly supported, explore alternative, safer workload identity solutions.
- Review Conditional Access Policies: Regularly examine conditional access rules to prevent broad access failures across multiple accounts.
- Monitor Sign-in Logs: Implement robust logging and alerting for unusual patterns, such as sign-in attempts from distributed cloud hosts, first-time logins, or sudden access to sensitive applications, which can indicate password spraying or other intrusion attempts.
- Block Legacy Authentication: Where possible, disable legacy or unnecessary authentication protocols that can be exploited for password spraying.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.