A widespread botnet, consisting of over 130,000 compromised devices, is launching password spraying attacks on Microsoft 365 (M365) Basic Auth on a global scale. Its goal is to exploit basic authentication, bypassing multi-factor authentication (MFA).
See also: New botnet exploits vulnerabilities in cameras and routers

According to a report by SecurityScorecard, cybercriminals are exploiting stolen credentials obtained through infostealerto target accounts en masse.
The attacks exploit non-interactive links that use Basic Authentication, bypassing multi-factor authentication (MFA) protections. In this way, they gain unauthorized access without triggering security alerts.
Basic Auth is an outdated authentication method, where the user's credentials are sent either in plain text or in base64-encoded form with each request to the server. It does not support modern security methods, such as MFA and token authentication, making its use obsolete. Microsoft has already disabled most Microsoft 365 services that use it and plans to completely remove it in September 2025, promoting a transition to the more secure OAuth 2.0.
The newly discovered botnet exploits Basic Auth techniques, targeting a large number of accounts through the use of shared or leaked passwords.
See also: New botnet targets industrial routers with zero-day exploits
Because Basic Auth is non-interactive, when the tested credentials match, attackers are not required to go through an MFA check and are often not restricted by Conditional Access Policies (CAPs). This allows them to verify an account's credentials without being detected.

Once the credentials are verified, they can be exploited either to access traditional services that do not require multi-factor authentication (MFA), or to carry out more sophisticated phishing. In this way, attackers can bypass security measures and gain full access to the account.
SecurityScorecard notes that you can spot signs of password spraying attacks in Entra’s logs. Specifically, these signs include increased non-interactive login attempts, multiple failed attempts from different IP addresses , and the appearance of the “ fasthttp ” user agent in the authentication logs.
In January, SpearTip warned of hackers performing password spraying attacks on Microsoft 365, using the FastHTTP Go in a similar manner, but did not mention non-interactive connections. It is unclear whether this is a newer evolution of the botnet to target Basic Auth and evade detection.
See also: Mirai Botnet targets Juniper smart routers
Password spraying attacks are a common form of cyberattack that targets mass account access. Instead of trying multiple passwords for a specific account, attackers use one or a few common passwords across a large number of accounts. This method avoids lockouts due to multiple failed login attempts, making it particularly effective. Organizations can protect themselves through strategies such as strong and unique password policies, multi-factor authentication, and monitoring for unusual login attempts.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
