Chinese Botnet Bypasses MFA in Microsoft 365 Attacks
ID: ce468cad-ec85-5590-a973-360d19dc6906
STIX ID: report--ce468cad-ec85-5590-a973-360d19dc6906
Feed Name: Infosecurity Magazine (News)
SecurityScorecard reports a large-scale botnet of over 130,000 compromised devices conducting global password-spraying attacks against Microsoft 365 tenants using stolen credentials from infostealer accounts. The campaign leverages non-interactive sign-ins to evade multifactor authentication and Conditional Access Policies, enabling access to email and collaboration data, possible lateral movement, and widespread disruption across finance, healthcare, government, and tech sectors; researchers link infrastructure to providers with ties to China and recommend tightening conditional access, monitoring non-interactive sign-in logs, disabling legacy authentication, and monitoring leaked credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
