Hackers are using the FastHTTP Go library to launch high-speed brute-force password attacks targeting Microsoft 365 accounts worldwide.
See also: Unable to access Microsoft 365 apps due to MFA!

The campaign was recently discovered by incident response firm SpearTip, which said the attacks began on January 6, 2025, targeting the Azure Active Directory Graph API. Researchers warn that brute-force attacks have been successful in taking over accounts in 10% of cases.
FastHTTP is a high-performance HTTP server and client library for the Go, optimized for handling HTTP requests with improved performance, low latency, and high throughput, even when used with many simultaneous connections.
In this campaign, it is leveraged to generate HTTP requests to automate attempts for unauthorized connections.
SpearTip says that all requests target Azure Active Directory endpoints to either brute-force passwords or repeat multi-factor authentication (MFA) challenges to overwhelm targets in MFA Fatigue attacks.
See also: CISA – Publishes Best Practices for Securing Microsoft 365 Cloud Environments
SpearTip reports that 65% of malicious traffic originates from Brazil, leveraging a wide range of ASN providers and IP addresses, followed by Turkey, Argentina, Uzbekistan, Pakistan, and Iraq.

Researchers say that 41.5% of Microsoft 365 attacks fail, 21% result in account lockouts enforced by protection mechanisms, 17.7% are rejected due to access policy violations (geographic or device compliance), and 10% are protected by MFA.
This leaves 9.7% of cases where malicious actors successfully control the target account, a particularly high success rate.
Microsoft 365 account takeovers can lead to exposure of confidential data, intellectual property theft, service , and other negative outcomes.
See also: Microsoft 365 outage removes web apps
Preventing such incidents requires strong measures, including enabling multi-factor authentication (MFA), monitoring account activity for anomalies, and educating users on how to recognize phishing. Proactive security practices are essential to mitigating the risks associated with account takeovers in Microsoft 365. Organizations should also consider implementing role-based access controls (RBAC) to restrict account permissions based on specific job functions. This minimizes the risk of highly privileged accounts being compromised and exploited. Regularly updating passwords and conducting regular audits of account permissions can further enhance security. Additionally, leveraging advanced threat protection (ATP) tools capable of detecting and mitigating sophisticated attacks can provide an additional layer of defense.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
