logo

Cybercriminals Use Go Resty and Node Fetch in 13 Million Password Spraying Attempts

ID: 9d9ca5fb-1059-5d3d-8bf6-ebec2dbd338a

STIX ID: report--9d9ca5fb-1059-5d3d-8bf6-ebec2dbd338a

Feed Name: Proofpoint Blog

Threat Score
75/100

Date Published: 2025-02-05

Date Updated: 2026-04-28

...
...

Proofpoint observed large-scale account takeover campaigns targeting Microsoft 365 that employ common HTTP client libraries (Axios, Node Fetch, Go Resty, Python Requests) alongside Adversary-in-the-Middle and brute-force techniques; attackers used millions of hijacked residential IPs, performed mass password spraying (13 million login attempts), abused OAuth app registrations and mailbox rules, and successfully impacted numerous organizations—particularly education—resulting in substantial account compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.