Key Takeaways
- Proofpoint researchers identified an active TeamFiltration campaign - tracked as UNK_CondorFiltration, that targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America, focusing intensively on Chilean organizations.
- All 7 successfully compromised accounts were unmanaged functional/service accounts with no prior legitimate login baseline, strongly indicating default or predictable passwords that had never been rotated, with no MFA enforcement.
- Several compromised accounts showed post-access activity beyond the initial credential validation: the attacker signed in from a German VPN node, attempted to authenticate to the corporate VPN, and accessed several Azure apps, including OfficeHome, Azure Portal, and SharePoint Online.
Intro
In late July 2026, Proofpoint threat researchers detected a concentrated Microsoft 365 brute-force campaign targeting Chilean organizations. The attacker's tooling left a familiar artifact: the hardcoded user agent unique to TeamFiltration - a cross-platform offensive framework publicly documented by Proofpoint in the UNK_SneakyStrike blogpost.
The campaign was concentrated almost entirely on Chilean organizations, with a major retailer and multiple financial institutions among the primary targets. The attacker likely sprayed accounts with default passwords - credentials provisioned by IT and never rotated. Against personal employee accounts, this approach yielded no confirmed compromises, since users are required to change passwords from time to time. Against dormant service accounts, it worked. These accounts were provisioned to run business operations and then left unmonitored, still carrying their original credentials. Every confirmed compromise traced back to the same likely root cause: a default password on a forgotten account.
Attack Tool Overview: What Is TeamFiltration?
TeamFiltration is a cross-platform offensive framework built by Joakim Kandefelt (@Flangvik / TrustedSec) for penetration testing Microsoft 365 environments. First used internally in January 2021 and publicly released at DEF CON 30 in a talk titled "Taking a Dump In The Cloud," it automates four attack phases that chain reconnaissance through exfiltration:
|
Module |
Description |
|
Enumeration |
Validates account existence at ~300 emails/sec via the Teams API - without triggering account lockouts. |
|
Spray |
Systematically tests common or targeted passwords across enumerated accounts, rotating AWS regions via FireProx to evade IP-based blocking. |
|
Exfiltrate |
After access is obtained, harvests email, Teams chats, OneDrive/SharePoint files, and Graph API data automatically. |
|
Backdoor |
Grants interactive OneDrive access to browse, download, and silently replace files - enabling an attacker to plant malicious files in place of legitimate ones, triggering execution the next time the file is opened. |
The Attribution Fingerprint
TeamFiltration's default configuration includes a hardcoded user agent string from a 2020 Microsoft Teams desktop client - a non-common version these days:
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Teams/1.3.00.30866 Chrome/80.0.3987.165 Electron/8.5.1 Safari/537.36"
Campaign Overview
The campaign was concentrated almost entirely on Chilean organizations - with one major retailer accounting for 78.3% of all observed events. This regional focus is a notable departure from the geographically distributed targeting seen in UNK_SneakyStrike.
Campaign Statistics
|
Metric |
Value |
|
Total authentication events |
32,825 |
|
Unique accounts targeted |
5,714 |
|
Unique source IPs |
1,487 (All AWS EC2) |
|
Tenants targeted |
28 |
|
Accounts compromised |
7 |
|
Primary target sector |
Retailer(53.2% of accounts) |

Figure 1: Campaign Activity Timeline — daily unique accounts targeted, Jul 21–Aug 16
Activity Timeline
The campaign unfolded across three distinct bursts over a 26-day window:
- Jul 21-24 A small-volume opening wave targeted approximately 100–120 unique accounts per day. This activity was directed primarily at two major Chilean banking institutions.
- Jul 26-28 Spray volume surged to a peak of roughly 1,520 accounts on Jul 27 before collapsing sharply. This wave targeted another major Chilean financial institution.
- Aug 13-16 After approximately two weeks of silence, the operator returned with a second high-volume burst, peaking at around 1,560 accounts on Aug 15 - marginally exceeding the July peak. This wave shifted focus to a major Chilean retailer, where all seven confirmed account compromises and the observed post-access activity occurred on Aug 14–15.
Target Landscape
|
Domain |
Accounts |
% Accounts |
Events |
% Events |
Outcome |
|
Major retailer |
3,038 |
53.2% |
25,715 |
78.3% |
7 accounts compromised |
|
Major financial institution #1 |
1,873 |
32.8% |
3,776 |
11.5% |
N/A |
|
Major financial institution #2 |
110 |
1.9% |
1,536 |
4.7% |
N/A |
|
Other Chilean orgs |
217 |
3.8% |
464 |
1.4% |
N/A |
|
Other (non-Chile) |
476 |
8.3% |
1,334 |
4.1% |
N/A |
Notable Side Target
A major Chilean banking institution was targeted in 1,536 (Major financial institution #2) authentication attempts across the small amount of 114 accounts. Over half of those attempts (782) targeted 57 senior accounts, including multiple managers.
Dormant Accounts as the Attack Surface
The attacker targeted more than 5,700 accounts across 28 tenants and achieved zero compromises against personal employee accounts. Every confirmed breach involved a functional or service account.
A review of login telemetry for all 7 compromised accounts revealed a consistent and striking pattern: none had any prior legitimate user sessions in the period covered by our telemetry. These accounts were not used by humans. They were created to run business operations - managing tickets, approving vendor payments, operating a point-of-sale system, and handling requests - then left idle, still active in the tenant's identity plane, but belonging to nobody. Six of them compromised within 7 minutes during the campaign - strongly suggesting a shared or default password set consistent with an organizational provisioning process, not individually targeted credential stuffing.
Why Service Accounts Are the Perfect Target
Service accounts are particularly vulnerable due to a combination of predictable usernames, default passwords, and weak security controls in addition to lack of ownership of a human (sometimes). These accounts are usually being poorly managed and overlooked. These accounts usually lack MFA.
Post-Compromise: Beyond the Password
For most of the compromised accounts, the only post-login activity observed was access to “Microsoft Office” and “OneDrive” alongside “Teams”. This was done from the same AWS infrastructure. This matches TeamFiltration's -auto-exfil mode, which automatically pulls email, Teams conversations, and OneDrive files after a successful sign-in. Sign-in logs alone cannot confirm exfiltration occurred, but the access pattern points to it.
A Compromised Service Account: Case Study in Post-Compromise Activity
Within 90 seconds of the successful compromise, the attacker switched from the TeamFiltration infrastructure to a German VPN node and began a post-access sequence: probing the corporate VPN, accessing Azure Portal, browsing SharePoint, and triggering a Microsoft Graph API token request.
|
Time (UTC) |
Application |
IP / ISP |
Action |
|
18:41:41 |
Microsoft Teams |
3.101.157.240 amazon.com |
Initial compromise via password spray |
|
18:42:30 |
Corporate VPN Portal (vpn.[redacted].cl/SAML20/SP) |
149.88.104.19 cdn77.com/DE |
Corporate VPN probe - FAILED (MFA/CA blocked entry). Telemetry records target_application_id = https://vpn.[redacted]/SAML20/SP |
|
18:43:29 |
Azure Portal |
149.88.104.19 cdn77.com/DE |
Azure Portal access triggered an MFA enrollment prompt (userstrongauthenrollmentrequiredinterrupt), indicating the account had no MFA configured at the time of compromise. |
|
19:03:59 |
OfficeHome |
149.88.104.19 cdn77.com/DE |
M365 Portal access |
|
19:07:23 |
SharePoint Online |
149.88.104.19 cdn77.com/DE |
File system access - potential document reconnaissance, exfiltration or backdoor delivery |
|
19:07:35 |
SharePoint Online Web Client Extensibility |
149.88.104.19 cdn77.com/DE |
Client-side code requested an access token to interact with Microsoft Graph or external APIs |
Applications Accessed by the Attacker
|
Application |
App ID |
Accounts |
Purpose |
|
TeamFiltration via AWS infrastructure |
|||
|
Microsoft Teams |
1fec8e78-bce4-4aaf-ab1b-5451cc387264 |
All 7 |
Enumeration, credential spray, and Teams chat/file exfiltration |
|
Microsoft Office |
d3590ed6-52b3-4102-aeff-aad2292ab01c |
All 7 |
Email and calendar exfiltration (Outlook REST) |
|
OneDrive SyncEngine |
ab9b8c07-8f02-4f72-87fa-80105867a763 |
subset of accounts |
File exfiltration and OneDrive backdoor |
|
German VPN |
|||
|
Corporate VPN Portal (SAML) |
https://vpn.[redacted]/SAML20/SP |
subset of accounts |
Corporate VPN access attempt |
|
Azure Portal |
c44b4083-3bb0-49c1-b47d-974e53cbdf3c |
one compromised account |
Azure Portal access |
|
OfficeHome (M365 Portal) |
4765445b-32c6-49b0-83e6-1d93765276ca |
one compromised account |
M365 Portal access |
|
SharePoint Online |
00000003-0000-0ff1-ce00-000000000000 |
one compromised account |
File and document reconnaissance/exfiltration |
|
SharePoint Online Web Client Extensibility |
08e18876-6177-487e-b8b5-cf950c1e598c |
one compromised account |
Client-side code requested an access token to interact with Microsoft Graph or external APIs |
IOCs
|
Type |
Indicator |
Description |
|
User Agent |
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Teams/1.3.00.30866 Chrome/80.0.3987.165 Electron/8.5.1 Safari/537.36 |
Hardcoded in TeamFiltration default config. Not seen in legitimate modern Teams clients. |
|
IP Ranges |
3.101.0.0/16 18.144.76.0/24 13.52.201.0/24 |
Primary spray infrastructure. All resolve to amazon.com (AWS EC2). |
|
IP (Post-access) |
149.88.104.19 |
cdn77.com / datacamp.co.uk German VPN that used for VPN probing, Azure Portal access, and SharePoint recon. |
Conclusion
The UNK_CondorFiltration campaign is a reminder that one of the weakest links in an enterprise identity perimeter is often not a phished employee or a zero-day exploit. It is the forgotten account. Service accounts provisioned for convenience and never revisited are a structurally unprotected attack surface.