A large-scale campaign targeting Microsoft 365 has compromised thousands of accounts by exploiting a pervasive flaw in security hygiene: the use of default or weak passwords. According to researchers at Proofpoint, the operation, tracked as UNK_CondorFiltration, demonstrates how attackers use cloud infrastructure to mask their origins and mount attacks at scale.

The campaign, part of the broader TeamFiltration toolkit, has targeted over 5,700 user accounts across 28 Microsoft 365 tenants. Its activity is heavily concentrated on retail and financial institutions in Chile, resulting in seven confirmed account compromises.

A defining tactic of the campaign is its evasion technique. Researchers traced the malicious authentication attempts to a network of 1,487 unique IP addresses hosted on Amazon Web Services (AWS) EC2 instances. By distributing requests across this vast pool of cloud IPs, threat actors can bypass conventional IP-blocking defenses, as each login attempt appears to originate from a distinct, legitimate cloud source.

The attack does not rely on a software vulnerability. Instead, it succeeds by targeting privileged accounts that still use default or easily guessable credentials. This underscores that the security of a cloud environment often hinges on the consistent enforcement of basic administrative controls.

For Microsoft 365 administrators, the necessary defenses against such campaigns are foundational and urgent:

  1. Eradicate Default Credentials: Immediately audit and replace any default or weak passwords, particularly for administrative and service accounts.
  2. Enforce Universal MFA: Require multi-factor authentication for all users without exception, neutralizing the value of compromised passwords.
  3. Monitor Authentication Sources: Establish alerts for logins from unusual locations or originating from known cloud provider IP ranges, which can indicate automated or external attacks.

This incident is a clear reminder that adversaries frequently succeed through simplicity. Protecting cloud environments requires a disciplined focus on these core security principles to thwart campaigns like UNK_CondorFiltration.


一場針對Microsoft 365的大規模攻擊活動,利用了安全衛生管理中普遍存在的漏洞——使用預設或弱密碼——已入侵數千個帳戶。根據Proofpoint研究人員的報告,這項代號為「UNK_CondorFiltration」的行動,展示了攻擊者如何利用雲端基礎設施掩蓋其來源,並進行大規模攻擊。

這場攻擊是更廣泛的TeamFiltration攻擊工具包的一部分,已針對橫跨28個Microsoft 365租戶的超過5,700個用戶帳戶。其活動高度集中於智利的零售及金融機構,導致七個帳戶被證實入侵。

該攻擊的一個核心策略是其規避手法。研究人員追蹤到,這些惡意認證嘗試源自託管於亞馬遜雲端服務(AWS)EC2實例上的1,487個獨特IP位址網絡。透過將請求分散到這個龐大的雲端IP池中,威脅行為者能繞過傳統的IP封鎖防禦機制,因為每次登入嘗試看似都來自不同的合法雲端來源。

這場攻擊並非依賴軟件漏洞。相反,它的成功在於針對那些仍在使用預設或易於猜測憑證的高權限帳戶。這凸顯了雲端環境的安全性,往往取決於是否能持續執行基本的管理控制措施。

對於Microsoft 365管理員而言,防禦此類攻擊的必要措施是基礎且緊急的:

  1. 根除預設憑證: 立即審計並更換任何預設或弱密碼,尤其是管理員及服務帳戶的密碼。
  2. 強制實施全面多重認證: 要求所有用戶毫無例外地啟用多重認證(MFA),使被盜用的密碼失去價值。
  3. 監控認證來源: 設立警報機制,監控來自異常地點或已知雲端供應商IP範圍的登入活動,這可能表示自動化或外部攻擊。

此次事件清楚提醒我們,對手經常透過簡單的手段得逞。保護雲端環境需要嚴格專注於這些核心安全原則,以挫敗類似「UNK_CondorFiltration」的攻擊活動。

新聞來源 / Original News Source