PROOFPOINT researchers have identified a threat actor, tracked as UNK_CondorFiltration, using the open-source TeamFiltration toolkit and credential spraying against Microsoft 365 environments at Chilean organisations. The campaign began on 21 July and covered more than 5,700 accounts across 28 tenants, including two major banks, a third financial institution and a major retailer. Although the actor did not compromise any employee accounts, it eventually accessed seven functional or service accounts at the retailer.
The seven accounts had no recorded user activity and were apparently created for business processes such as ticket management or vendor-payment approval before being forgotten. Proofpoint believes they may have used default or shared credentials and lacked multi-factor authentication; six were compromised within seven minutes. TeamFiltration then enabled the theft of emails, Teams chats and files from Outlook, Teams and OneDrive.
In at least one case, the attacker also probed the victim’s VPN, accessed Microsoft 365 and Azure management portals, and viewed SharePoint files. The article does not report confirmed exploitation beyond the retailer or quantify the data taken.
Proofpoint’s Yaniv Miron recommends linking every service account to a named employee, applying expiry dates and auditing existing accounts. Administrators should inventory Microsoft 365 users and investigate accounts with unusual usernames or naming patterns, particularly those without clear ownership or activity.