Threat Actor Abuses TeamFiltration for Entra ID Account Takeovers
ID: bf75a70b-bad4-5168-ae42-9ed12cfeef5e
STIX ID: report--bf75a70b-bad4-5168-ae42-9ed12cfeef5e
Feed Name: Dark Reading
Proofpoint researchers observed an active ATO campaign called UNK_SneakyStrike that leverages the open-source TeamFiltration framework to enumerate Microsoft Entra ID accounts, perform password-spraying from rotating AWS regions, abuse OAuth family refresh tokens to mint access tokens, and automate exfiltration and persistence (including OneDrive look-alike backdoors). The activity began in December 2024, peaked in January, and targeted roughly 80,000 user accounts across about 100 cloud tenants with several confirmed successful account takeovers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
