TeamFiltration Campaign Password-Sprays Forgotten Microsoft 365 Service Accounts in Chile

· Original article ↗

Summary

Proofpoint researchers report that a TeamFiltration campaign targeted 5,714 accounts across 28 Microsoft 365 tenants, compromising seven dormant service accounts. Post-access activity included VPN probing and access to Azure and SharePoint.

Key points

  • The campaign ran in three bursts from July 21 to August 16, 2026, and focused primarily on Chilean organizations.
  • Attackers generated 32,825 authentication events from 1,487 source IPs, all identified as AWS EC2 infrastructure.
  • Seven accounts were compromised; all were functional or service accounts with no prior legitimate login activity in the available telemetry. Six were compromised within seven minutes.
  • Researchers assess that default or predictable passwords and absent MFA contributed to the compromises; the activity did not compromise personal employee accounts.
  • TeamFiltration automates account enumeration and password spraying, and can access or collect email, Teams, and OneDrive data. Observed sign-ins suggest possible collection, but logs do not confirm exfiltration.
  • After one compromise, the attacker probed a corporate VPN from a German VPN node; that attempt was blocked. The attacker also accessed Azure Portal and SharePoint.
  • Proofpoint says service accounts should be reviewed and managed; the report highlights dormant accounts with unrotated credentials and weak controls as an enterprise identity risk.

Article Details

Attack Vectors
  • The UNK_CondorFiltration campaign used TeamFiltration to spray passwords against Microsoft 365 accounts across 28 tenants, primarily targeting Chilean organizations.
  • All seven confirmed compromises involved functional or service accounts at a major Chilean retailer. The researchers said the pattern strongly suggests default or shared passwords that had not been rotated; they reported no confirmed compromises of personal employee accounts.
  • After one compromise, the attacker switched from AWS infrastructure to a German VPN node, unsuccessfully probed the corporate VPN, and accessed Azure Portal and SharePoint Online. An Azure Portal MFA enrollment prompt indicated that the account had no MFA configured at that time.
Defensive Notes
  • Review active service accounts for ownership, legitimate use, default or unrotated passwords, and MFA coverage.
  • The corporate VPN attempt was blocked by MFA or conditional access, but that control did not prevent the initial Microsoft 365 account compromise.
  • Sign-in activity involving Microsoft Office, OneDrive, Teams, and SharePoint Online may warrant investigation, but the observed sign-in logs alone do not confirm data exfiltration.

Indicators of compromise

TypeIndicatorContext
IPV4149[.]88[.]104[.]19German VPN node used after compromise to probe the corporate VPN and access Azure Portal and SharePoint Online.
IPV43[.]101[.]157[.]240AWS source IP recorded for the initial successful password-spray compromise.

MITRE ATT&CK

People

Threat Actors

Vendors

Products

Tools

Countries

Industries

Related Articles