newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools
Technology

Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools

June 12, 2025 3 Min Read
Share
Over 80,000 Microsoft Entra ID accounts targeted using open source team filtration tools
SHARE

Cybersecurity researchers have discovered a new account Takeover (ATO) campaign that leverages an open source penetration testing framework called TeamFiltration that violates Microsoft Entra ID (formerly Azure Active Directory) user accounts.

Activity, codename unk_sneakystrike According to Proofpoint, since a surge in login attempts was observed in December 2024, it has targeted more than 80,000 user accounts across hundreds of organizations’ cloud tenants, and has successfully acquired the account.

“Attackers will launch attempts to leverage Microsoft Teams APIs and Amazon Web Services (AWS) servers in various geographical regions to spray user approvals and passwords,” Enterprise Security Company said. “The attackers used access to certain resources and native applications, such as Microsoft Teams, OneDrive, and Outlook.”

TeamFiltration, published by researcher Melvin “Franvik” Langvik at the DEF CON Security Conference in August 2022, is described as a cross-platform framework for Entra ID accounts for “enumeration, spray, exfoliation, backdooring.”

The tool offers a wide range of features to promote account takeover using password spray attacks, data removal, and permanent access by uploading malicious files to the target Microsoft OneDrive account.

The tool requires an Amazon Web Services (AWS) account and a disposable Microsoft 365 account to promote password spray and account enumeration capabilities, but ProofPoint said it has leveraged these activities to observe evidence of malicious activity to leverage these activities so that each password spray wave comes from another server in a new geographical location.

Three major source regions linked to malicious activity based on the number of IP addresses include the US (42%), Ireland (11%), and the UK (8%).

UNK_SNeakyStrike activity is known as “large user enumeration and password spray attempts,” and leads to unauthorized access efforts with “high bursts” targeting multiple users within a single cloud environment. This is followed by a lull that lasts for 4-5 days.

See also  Researchers have discovered over 20 composition risks, including five CVEs, in the Salesforce industry cloud

The findings once again highlight how tools designed to assist cybersecurity experts can be misused by threat actions.

“UNK_SNeakyStrike’s targeting strategy suggests that we try to access all user accounts within a small cloud tenant, focusing only on a subset of users in the larger tenant,” ProofPoint said. “This behavior matches the advanced targeting capabilities of tools designed to exclude unwanted accounts.”

Share This Article
Facebook Twitter Copy Link
Previous Article Pacers ‘Tyrese Haliburton will perform “Ankle Problem” in Game 3 of the 2025 NBA Finals Pacers ‘Tyrese Haliburton will perform “Ankle Problem” in Game 3 of the 2025 NBA Finals
Next Article Why ‘Hellcats’ could be the answer to Democrats troubles Why ‘Hellcats’ could be the answer to Democrats troubles
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

New research uses attachment theory to decipher relationships with humans
Technology

New research uses attachment theory to decipher relationships with humans

9 Min Read
Fake recruiters email target CFOs using legal netbird tools in six global regions
Technology

Fake recruiters email target CFOs using legal netbird tools in six global regions

9 Min Read
Researchers have discovered over 20 composition risks, including five CVEs, in the Salesforce industry cloud
Technology

Researchers have discovered over 20 composition risks, including five CVEs, in the Salesforce industry cloud

5 Min Read
295 Malicious IPS launches a coordinated brute force attack against ApacheTomcat manager
Technology

295 Malicious IPS launches a coordinated brute force attack against ApacheTomcat manager

3 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?