logo

A large botnet targets M365 accounts with password spraying attacks

ID: 14909fec-48d9-52f2-96be-eba0ce2aa959

STIX ID: report--14909fec-48d9-52f2-96be-eba0ce2aa959

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2025-02-24

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

SecurityScorecard uncovered a botnet of over 130,000 devices performing large-scale password-spraying attacks against Microsoft 365 tenants by leveraging Basic Authentication and Non-Interactive Sign-In paths to evade MFA and Conditional Access; attackers use stolen credentials from infostealer logs and operate C2 servers (with identifiable IPs, ports and user-agent) linked to specific hosting providers and an alleged China-affiliated group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.