Botnet looks for quiet ways to try stolen logins in Microsoft 365 environments
ID: 4ba7d600-66c7-5b43-b79a-d106de51c80c
STIX ID: report--4ba7d600-66c7-5b43-b79a-d106de51c80c
Feed Name: The Record from Recorded Future News
SecurityScorecard warns of a massive botnet-driven password-spraying campaign using roughly 130,000 compromised devices to target Microsoft 365 environments that allow non-interactive sign-ins with Basic Authentication. The technique enables attackers to bypass modern login protections and evade MFA enforcement; researchers urge monitoring non-interactive sign-in logs and rotating exposed credentials, while noting attribution is likely Chinese-affiliated but still under investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
