Hackers have used the TeamFiltration penetration testing tool in attacks against more than 80,000 Microsoft Entra ID accounts in hundreds of organizations worldwide.
See also: Fog ransomware attack uses open source tools

The campaign began in December and has already managed to compromise multiple accounts, according to researchers at cybersecurity firm Proofpoint, who attribute the activity to a threat called UNK_SneakyStrike.
According to the researchers, the campaign peaked on January 8, when 16,500 accounts were targeted in a single day. Such spikes were followed by several days of inactivity.
TeamFiltration is a cross-platform tool used for enumeration, password spraying, data extraction , and backdooring of O365 Entra ID accounts. It was created by TrustedSec red-team researcher Melvin Langvik and published in 2022.
In the UNK_SneakyStrike malicious campaign monitored by Proofpoint, TeamFiltration plays a key role in facilitating large-scale breach attempts
The researchers report that the malicious actor targets all users in small tenants, while in larger tenants it selects only a subset of users. The activity was linked to TeamFiltration by identifying a rare user agent that uses the tool, as well as by matching OAuth client IDs embedded in its code.
See also: Coordinated Brute-Force Attacks on Apache Tomcat Manager
Other telltale signs include access patterns to incompatible applications, as well as the presence of an outdated instance of Secureworks' FOCI project, which is embedded in TeamFiltration's code.

The attackers used AWS servers in multiple geographic regions to execute the attacks and relied on a “sacrificial” Office 365 account with a Business Basic license to abuse the Microsoft Teams API for account counting.
Most attacks originate from IP addresses located in the United States (42%), with Ireland (11%) and the United Kingdom (8%) following.
Organizations should block all IPs listed in Proofpoint's "indicators of compromise" section and create detection rules for the TeamFiltration user agent string.
Additionally, it is recommended to enable multi-factor authentication (MFA) for all users, enforce the use of OAuth 2.0 , and implement conditional access policies on Microsoft Entra ID.
See also: Sensata Technologies: Ransomware attack led to data breach
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Based on the above, it seems that the UNK_SneakyStrike campaign highlights the importance of proactive identity protection in cloud environments, such as Microsoft Entra ID. The fact that attackers are exploiting legitimate services like the Microsoft Teams API and using a tool like TeamFiltration, which was originally designed for security testing, shows how easily a red-team tool can be turned into a malicious weapon.
Source: bleepingcomputer
