logo

Chinese Botnet Bypasses MFA in Microsoft 365 Attacks

ID: ce468cad-ec85-5590-a973-360d19dc6906

STIX ID: report--ce468cad-ec85-5590-a973-360d19dc6906

Feed Name: Infosecurity Magazine (News)

Threat Score
82/100

Date Published: 2025-02-25

Date Updated: 2026-04-22

...
...

SecurityScorecard reports a large-scale botnet of over 130,000 compromised devices conducting global password-spraying attacks against Microsoft 365 tenants using stolen credentials from infostealer accounts. The campaign leverages non-interactive sign-ins to evade multifactor authentication and Conditional Access Policies, enabling access to email and collaboration data, possible lateral movement, and widespread disruption across finance, healthcare, government, and tech sectors; researchers link infrastructure to providers with ties to China and recommend tightening conditional access, monitoring non-interactive sign-in logs, disabling legacy authentication, and monitoring leaked credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.