TeamFiltration Campaign Password-Sprays Forgotten Microsoft 365 Service Accounts in Chile

Summary
Proofpoint researchers report that a TeamFiltration campaign targeted 5,714 accounts across 28 Microsoft 365 tenants, compromising seven dormant service accounts. Post-access activity included VPN probing and access to Azure and SharePoint.
Key points
- The campaign ran in three bursts from July 21 to August 16, 2026, and focused primarily on Chilean organizations.
- Attackers generated 32,825 authentication events from 1,487 source IPs, all identified as AWS EC2 infrastructure.
- Seven accounts were compromised; all were functional or service accounts with no prior legitimate login activity in the available telemetry. Six were compromised within seven minutes.
- Researchers assess that default or predictable passwords and absent MFA contributed to the compromises; the activity did not compromise personal employee accounts.
- TeamFiltration automates account enumeration and password spraying, and can access or collect email, Teams, and OneDrive data. Observed sign-ins suggest possible collection, but logs do not confirm exfiltration.
- After one compromise, the attacker probed a corporate VPN from a German VPN node; that attempt was blocked. The attacker also accessed Azure Portal and SharePoint.
- Proofpoint says service accounts should be reviewed and managed; the report highlights dormant accounts with unrotated credentials and weak controls as an enterprise identity risk.
Article Details
- Attack Vectors
- The UNK_CondorFiltration campaign used TeamFiltration to spray passwords against Microsoft 365 accounts across 28 tenants, primarily targeting Chilean organizations.
- All seven confirmed compromises involved functional or service accounts at a major Chilean retailer. The researchers said the pattern strongly suggests default or shared passwords that had not been rotated; they reported no confirmed compromises of personal employee accounts.
- After one compromise, the attacker switched from AWS infrastructure to a German VPN node, unsuccessfully probed the corporate VPN, and accessed Azure Portal and SharePoint Online. An Azure Portal MFA enrollment prompt indicated that the account had no MFA configured at that time.
- Defensive Notes
- Review active service accounts for ownership, legitimate use, default or unrotated passwords, and MFA coverage.
- The corporate VPN attempt was blocked by MFA or conditional access, but that control did not prevent the initial Microsoft 365 account compromise.
- Sign-in activity involving Microsoft Office, OneDrive, Teams, and SharePoint Online may warrant investigation, but the observed sign-in logs alone do not confirm data exfiltration.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 149[.]88[.]104[.]19 | German VPN node used after compromise to probe the corporate VPN and access Azure Portal and SharePoint Online. |
| IPV4 | 3[.]101[.]157[.]240 | AWS source IP recorded for the initial successful password-spray compromise. |
MITRE ATT&CK
T1078.004 · Cloud AccountsThe attacker signed in to Microsoft 365 using seven compromised functional or service accounts.T1087.004 · Cloud AccountTeamFiltration's enumeration module validates cloud-account existence through the Teams API before password spraying.T1110.003 · Password SprayingThe attacker sprayed passwords across 5,714 Microsoft 365 accounts, compromising seven functional or service accounts.
People
Threat Actors
Vendors
AWSSystematically tests common or targeted passwords across enumerated accounts, rotating AWS regions via FireProx to evade IP-based blocking.MicrosoftTeamFiltration campaign - tracked as UNK_CondorFiltration, that targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America, focusing intensively on Chilean organizations.
Products
Azure Portalattempted to authenticate to the corporate VPN, and accessed several Azure apps, including OfficeHome, Azure Portal, and SharePoint Online.Microsoft 365campaign - tracked as UNK_CondorFiltration, that targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America, focusing intensively on Chilean organizations.Microsoft OfficeFor most of the compromised accounts, the only post-login activity observed was access to “Microsoft Office” and “OneDrive” alongside “Teams”.Microsoft TeamsTeamFiltration's default configuration includes a hardcoded user agent string from a 2020 Microsoft Teams desktop client - a non-common version these days:OfficeHomeVPN node, attempted to authenticate to the corporate VPN, and accessed several Azure apps, including OfficeHome, Azure Portal, and SharePoint Online.OneDriveAfter access is obtained, harvests email, Teams chats, OneDrive/SharePoint files, and Graph API data automatically.OneDrive SyncEngineOneDrive SyncEngineSharePoint Onlineto the corporate VPN, and accessed several Azure apps, including OfficeHome, Azure Portal, and SharePoint Online.
Tools
FireProxSystematically tests common or targeted passwords across enumerated accounts, rotating AWS regions via FireProx to evade IP-based blocking.TeamFiltrationProofpoint researchers identified an active TeamFiltration campaign - tracked as UNK_CondorFiltration, that targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America, focusing intensively on Chilean