A large botnet targets M365 accounts with password spraying attacks
ID: 14909fec-48d9-52f2-96be-eba0ce2aa959
STIX ID: report--14909fec-48d9-52f2-96be-eba0ce2aa959
Feed Name: Security Affairs
Threat Score
SecurityScorecard uncovered a botnet of over 130,000 devices performing large-scale password-spraying attacks against Microsoft 365 tenants by leveraging Basic Authentication and Non-Interactive Sign-In paths to evade MFA and Conditional Access; attackers use stolen credentials from infostealer logs and operate C2 servers (with identifiable IPs, ports and user-agent) linked to specific hosting providers and an alleged China-affiliated group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
