Hackers use FastHTTP in new high-speed Microsoft 365 password attacks
ID: da7edd48-7bad-582b-8adf-f003e0e59fd1
STIX ID: report--da7edd48-7bad-582b-8adf-f003e0e59fd1
Feed Name: Bleeping Computer
SpearTip discovered a global automated brute-force campaign (starting 2025-01-06) that uses the FastHTTP Go library to target Azure AD / Microsoft 365 sign-ins and to execute MFA‑fatigue attacks; actors achieve roughly a 9.7–10% successful account takeover rate, with most malicious traffic originating from Brazil. The report details attack telemetry, success/failure breakdowns, recommended detection steps (PowerShell and Sign-in log filters), and remediation actions (expire sessions, reset credentials, review MFA devices).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
