logo

Botnet looks for quiet ways to try stolen logins in Microsoft 365 environments

ID: 4ba7d600-66c7-5b43-b79a-d106de51c80c

STIX ID: report--4ba7d600-66c7-5b43-b79a-d106de51c80c

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2025-02-24

Date Updated: 2026-05-01

...
...

SecurityScorecard warns of a massive botnet-driven password-spraying campaign using roughly 130,000 compromised devices to target Microsoft 365 environments that allow non-interactive sign-ins with Basic Authentication. The technique enables attackers to bypass modern login protections and evade MFA enforcement; researchers urge monitoring non-interactive sign-in logs and rotating exposed credentials, while noting attribution is likely Chinese-affiliated but still under investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.