logo

Microsoft 365 Accounts Get Sprayed by Mega-Botnet

ID: 0aef7f68-e6b8-50ce-9042-9f89f079c1b8

STIX ID: report--0aef7f68-e6b8-50ce-9042-9f89f079c1b8

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-02-25

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Security researchers observed a botnet of more than 130,000 compromised devices conducting large-scale, stealthy password-spray attacks against Microsoft 365 by abusing noninteractive sign-ins, allowing high-volume credential attempts to evade interactive-sign-in monitoring; the activity has been seen across multiple tenants, may enable account takeover and MFA/conditional-access bypass, and is suspected (but not confirmed) to be Chinese-affiliated, with recommendations to rotate service-account credentials, monitor noninteractive authentication, and apply PAM and strong credential hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.