Microsoft 365 Accounts Get Sprayed by Mega-Botnet
ID: 0aef7f68-e6b8-50ce-9042-9f89f079c1b8
STIX ID: report--0aef7f68-e6b8-50ce-9042-9f89f079c1b8
Feed Name: Dark Reading
Date Published: 2025-02-25
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Security researchers observed a botnet of more than 130,000 compromised devices conducting large-scale, stealthy password-spray attacks against Microsoft 365 by abusing noninteractive sign-ins, allowing high-volume credential attempts to evade interactive-sign-in monitoring; the activity has been seen across multiple tenants, may enable account takeover and MFA/conditional-access bypass, and is suspected (but not confirmed) to be Chinese-affiliated, with recommendations to rotate service-account credentials, monitor noninteractive authentication, and apply PAM and strong credential hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
