PROOFPOINT researchers identified a password-spraying campaign targeting 28 Microsoft 365 tenants in Latin America, mainly Chilean retailers and banks. Tracked with low confidence as UNK_Condor Filtration, the activity ran in three waves between 21 July and 16 August 2026. Attackers used the open-source TeamFiltration framework to validate accounts through Microsoft Teams application interfaces before testing passwords from rotating Amazon Web Services infrastructure. The campaign generated 32,825 login events against 5,714 unique accounts, with more than 78% of activity directed at one retailer.
Seven accounts were compromised, all of them unmanaged service or functional accounts rather than personal employee accounts. Proofpoint said these accounts had no established legitimate-login baseline, predictable or default passwords that had not been rotated, and no multi-factor authentication. After gaining access, the attacker moved to a German virtual private network within 90 seconds and accessed the Azure Portal, SharePoint Online and the Microsoft 365 portal. An attempt to access the corporate VPN was blocked by conditional-access policies.
The operators remain unattributed, although their activity used a distinctive user-agent string associated with an outdated 2020 Teams desktop client. Proofpoint recommends that organisations inventory non-human accounts, apply multi-factor authentication or phishing-resistant credentials, and review sign-in logs for the old Teams user agent and cloud-hosting IP addresses associated with spraying.