Key Takeaways

  • Proofpoint researchers identified an active TeamFiltration campaign - tracked as UNK_CondorFiltration, that targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America, focusing intensively on Chilean organizations.
  • All 7 successfully compromised accounts were unmanaged functional/service accounts with no prior legitimate login baseline, strongly indicating default or predictable passwords that had never been rotated, with no MFA enforcement.
  • Several compromised accounts showed post-access activity beyond the initial credential validation: the attacker signed in from a German VPN node, attempted to authenticate to the corporate VPN, and accessed several Azure apps, including OfficeHome, Azure Portal, and SharePoint Online.

Intro

In late July 2026, Proofpoint threat researchers detected a concentrated Microsoft 365 brute-force campaign targeting Chilean organizations. The attacker's tooling left a familiar artifact: the hardcoded user agent unique to TeamFiltration - a cross-platform offensive framework publicly documented by Proofpoint in the UNK_SneakyStrike blogpost.