Threat actors have targeted more than 5,700 Microsoft 365 accounts across 28 tenants in a password-spraying campaign that successfully breached seven forgotten service accounts lacking MFA.
The activity, tracked by Proofpoint as UNK_CondorFiltration, focused heavily on Chilean retail and financial organizations and abused the TeamFiltration offensive framework.
The framework, initially created for legitimate Microsoft 365 and Entra ID penetration testing, can automate account enumeration, password spraying, data collection, and OneDrive-based persistence.
It has previously been linked to the UNK_SneakyStrike account-takeover activity, which targeted more than 80,000 Entra ID accounts beginning in December 2024.
The latest operation generated 32,825 authentication events against 5,714 unique accounts using 1,487 AWS EC2 source IP addresses.
A major Chilean retailer absorbed 78.3% of all observed events, while several Chilean banks were also targeted.
The activity unfolded in three bursts between July 21 and August 16, with the highest-volume wave peaking at roughly 1,560 targeted accounts on August 15.
All seven confirmed compromises occurred during the final wave against the retailer.
The most consequential finding is that attackers did not successfully compromise any ordinary employee accounts.
Instead, every breached identity was an unmanaged functional or service account, including accounts used for business processes such as ticket handling, vendor-payment approval, point-of-sale operations, and internal request processing.
Proofpoint found no prior legitimate login activity for any of the seven compromised accounts, indicating they had likely been provisioned, forgotten, and left active with predictable or unrotated default passwords.
Six of the accounts were compromised within seven minutes, a pattern that strongly suggests the accounts shared a password created through the same provisioning workflow.
Unlike human users, who are typically prompted to change passwords periodically, dormant machine-linked identities can retain their initial credentials indefinitely.
Their predictable naming conventions, lack of clear ownership, and frequent exemption from MFA make them a high-value attack surface in Microsoft 365 environments.
Proofpoint detected the campaign, in late July 2026 after identifying the distinctive hardcoded Microsoft Teams user-agent string associated with TeamFiltration.
Microsoft 365 accounts Targeted
TeamFiltration is particularly effective for this type of intrusion because it can validate account existence through the Microsoft Teams API before attempting password sprays.
It can then rotate AWS infrastructure to distribute login attempts and reduce the effectiveness of IP-based blocking.
Following a successful authentication, the framework can access Teams chats, email, OneDrive and SharePoint data, and Microsoft Graph resources.
It also supports OneDrive-based persistence, including browsing, downloading, and potentially replacing files with malicious lookalikes.
In the observed campaign, compromised accounts accessed Microsoft Teams, Microsoft Office, and OneDrive from AWS-hosted infrastructure.
While sign-in telemetry alone cannot prove data theft, Proofpoint said the activity matched TeamFiltration’s automated exfiltration capability.
One account was used for more extensive post-compromise reconnaissance within 90 seconds of the initial breach.
The attacker then shifted to a German VPN node, 149.88.104.19, and attempted to authenticate to a corporate VPN portal. That attempt failed because MFA or Conditional Access blocked entry.
The same account subsequently accessed Azure Portal, OfficeHome, SharePoint Online, and SharePoint Online Web Client Extensibility.
Azure Portal generated an MFA-enrollment interruption, directly indicating that MFA had not been configured on the compromised account at the time of access.
Defenders should treat non-human identities as first-class privileged assets.
Organizations should immediately inventory active service and functional accounts, assign accountable owners, disable unused identities, rotate inherited or default passwords, and enforce phishing-resistant MFA where technically possible.
Security teams should also investigate Microsoft 365 sign-ins using the outdated TeamFiltration user agent, review AWS-originated authentication bursts, and hunt for suspicious access to Teams, OneDrive, SharePoint, Azure Portal, and Microsoft Graph following successful logins.
The campaign demonstrates that enterprise identity security can fail not through a sophisticated zero-day exploit, but through an account that no employee remembers exists.
IOCs
| Type | Indicator | Description |
| User Agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Teams/1.3.00.30866 Chrome/80.0.3987.165 Electron/8.5.1 Safari/537.36 | Hardcoded in TeamFiltration default config. Not seen in legitimate modern Teams clients. |
| IP Ranges | 3.101.0.0/1618.144.76.0/2413.52.201.0/24 | Primary spray infrastructure. All resolve to amazon.com (AWS EC2). |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

