Proofpoint UNK_CondorFiltration: TeamFiltration sprays 5,700+ M365 accounts; 7 Chilean service accounts compromised (default passwords, no MFA)
Proofpoint Threat Insight (22 September 2026) details active TeamFiltration campaign UNK_CondorFiltration targeting over 5,700 accounts across 28 Microsoft 365 tenants in Latin America (focus Chile; major retailer + financial institutions). Late July–August 2026 waves; 78.3% of observed auth events against one unnamed Chilean retailer. All seven confirmed compromises were unmanaged functional/service accounts with no prior legitimate login baseline — default/predictable passwords never rotated, no MFA. Six of seven broken within ~7 minutes (shared/default password set). Post-access: German VPN pivot, corporate VPN SAML probe, Azure Portal / OfficeHome / SharePoint Online / Microsoft Graph token activity (sign-ins alone are not proof of exfiltration). TeamFiltration (Joakim Kandefelt / TrustedSec; DEF CON 30) automates Entra ID enumerate/spray/exfil/backdoor. Prior related cluster UNK_SneakyStrike (Proofpoint Jun 2025) hit 80k+ accounts. Primary: Proofpoint; wire: The Hacker News 24 Sep 2026.
- Product
- Microsoft 365 / Entra ID (service accounts; TeamFiltration offensive framework abuse)
- Versions
- n/a (identity campaign; Jul–Aug 2026 waves)
- Exploited in Australia?
- unknown
- Patch to
- Inventory Entra ID service/functional accounts; force rotate any default/never-changed passwords; enforce MFA or workload-identity alternatives; hunt TeamFiltration user-agent and spray telemetry; disable unused service accounts; review Azure Portal/SharePoint/Graph sign-ins from unexpected VPN egress
Primary: Proofpoint — Spraying in the Andes: TeamFiltration Returns (22 Sep 2026) · Vendor: Proofpoint Threat Insight — UNK_CondorFiltration · The Hacker News — TeamFiltration compromises seven M365 accounts (24 Sep 2026)
