TeamFiltration UNK_CondorFiltration Microsoft 365 default-password spraying campaign
Campaign
Summary
Hide ▲
Show ▼
The UNK_CondorFiltration campaign used TeamFiltration to spray Microsoft 365 accounts across 28 tenants, compromising 7 service accounts and creating a broad takeover risk. It targeted more than 5,700 accounts and focused on Chilean retail and financial institutions. Attackers relied on default passwords and absent MFA, then moved into Office, OneDrive, Teams, and SharePoint Online. The scale and repetition show an active credential-access operation with cross-tenant reach.
Related Happenings
TrustSink rogue external MFA provider attack against Microsoft Entra
Technical Analysis
H score30
First: 23.09.2026 00:45
Last: 23.09.2026 00:45
Sources 1
About this happening:
Researchers demonstrated TrustSink, a post-compromise technique that abuses Microsoft Entra external MFA providers to capture passwords during legitimate sign-ins, creatin...
TrustSink rogue external MFA provider attack against Microsoft Entra
Technical AnalysisAbout this happening: Researchers demonstrated TrustSink, a post-compromise technique that abuses Microsoft Entra external MFA providers to capture passwords during legitimate sign-ins, creatin...
N0va phishing campaign targeting North America and Europe
Campaign
H score36
First: 16.09.2026 14:58
Last: 16.09.2026 14:58
Sources 1
About this happening:
N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-accoun...
N0va phishing campaign targeting North America and Europe
CampaignAbout this happening: N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-accoun...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
Campaign
H score34
First: 11.09.2026 20:26
Last: 11.09.2026 20:26
Sources 1
About this happening:
A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
CampaignAbout this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
RecruitTrap recruitment-themed phishing campaign
Campaign
H score25
First: 14.08.2026 13:57
Last: 14.08.2026 13:57
Sources 1
About this happening:
The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...
RecruitTrap recruitment-themed phishing campaign
CampaignAbout this happening: The RecruitTrap campaign used fake recruiter outreach and BitB login pages to steal Google and Facebook credentials and relay MFA prompts in real time. It span...
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Timeline
-
24.09.2026 09:32 1 articles · 4h ago
UNK_CondorFiltration targets two Chilean banking institutions in a Microsoft 365 spraying wave
Campaign Scope UpdateOn July 24, 2026, a Microsoft 365 brute-force wave tied to UNK_CondorFiltration targeted two major Chilean banking institutions at roughly 100–120 unique accounts per day.
Show sources
- TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords — thehackernews.com — 24.09.2026 09:32
-
24.09.2026 09:32 1 articles · 4h ago
UNK_CondorFiltration peaks at 1,520 account targets against a Chilean financial institution
Campaign Scope UpdateOn July 27, 2026, the campaign reached a peak of about 1,520 targeted accounts in a Microsoft 365 spraying surge directed against another major Chilean financial institution.
Show sources
- TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords — thehackernews.com — 24.09.2026 09:32
-
24.09.2026 09:32 1 articles · 4h ago
UNK_CondorFiltration compromises seven service accounts at a Chilean retailer
Victim Impact UpdateOn August 15, 2026, the campaign peaked at about 1,560 targeted accounts against a major Chilean retailer and led to seven service account compromises; across most compromised accounts, the operator accessed Microsoft Office, OneDrive, and Teams.
Show sources
- TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords — thehackernews.com — 24.09.2026 09:32
-
24.09.2026 09:32 2 articles · 4h ago
Proofpoint discloses active UNK_CondorFiltration TeamFiltration campaign against Microsoft 365 tenants
Initial DisclosureProofpoint disclosed an active TeamFiltration campaign codenamed UNK_CondorFiltration that targeted over 5,700 accounts across 28 Microsoft 365 tenants, mainly in Chilean retail and financial institutions, using default passwords and no MFA.
Show sources
- TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords — thehackernews.com — 24.09.2026 09:32
- TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords — thehackernews.com — 24.09.2026 09:32