Understanding Default Password Exploits in Microsoft 365: The UNK_CondorFiltration Campaign
An analysis of the active UNK_CondorFiltration campaign that leveraged default passwords to compromise Microsoft 365 accounts, with detection and mitigation guidance.
Overview
In early September 2026, security researchers uncovered an active threat operation dubbed UNK_CondorFiltration. The group used a tool called TeamFiltration to target Microsoft 365 (M365) tenants, ultimately compromising seven user accounts. While the overall campaign scanned 5,700 accounts across 28 tenants, the successful breaches were limited to a handful of accounts—still enough to illustrate the danger of default credentials in cloud services.
1. What is TeamFiltration?
TeamFiltration is an open‑source framework that automates credential‑spraying and password‑guessing against cloud platforms such as Azure AD and Microsoft 365. It works by:
- Harvesting publicly available or leaked username lists (often corporate email addresses).
- Iterating through a short list of common or default passwords.
- Submitting authentication requests via Microsoft’s OAuth or legacy authentication endpoints.
- Logging any successful logins for later exploitation (e.g., data exfiltration, mailbox access).
The tool is deliberately lightweight, allowing attackers to launch thousands of login attempts from a distributed set of cloud instances.
2. How the UNK_CondorFiltration Campaign Operated
| Attribute | Detail | |---|---| | Target Scope | Over 5,700 accounts in 28 M365 tenants | | Geographic Focus | Chilean retail and financial institutions | | Infrastructure | 1,487 distinct AWS EC2 IP addresses | | Outcome | 7 accounts successfully compromised |
The attackers leveraged default passwords—credentials that are often set during initial provisioning of services (e.g., Password123!, Welcome1). Because many organizations fail to enforce password changes after deployment, these secrets remain viable entry points.
Attack Flow
- Reconnaissance – The adversary enumerated tenant domains (e.g.,
contoso.com) using public DNS records and Azure AD discovery endpoints. - User Harvesting – Email addresses were scraped from corporate websites, LinkedIn, and data‑leak repositories.
- Password Spraying – TeamFiltration launched parallel login attempts from the AWS EC2 fleet, rotating source IPs to evade simple rate‑limit blocks.
- Success Logging – When a default password matched, the session token was captured and stored for later use.
- Post‑Compromise – The compromised accounts could be used to read emails, download files from SharePoint, or pivot to other services within the tenant.
3. Detecting Credential‑Spraying Activity
Defenders can spot the hallmark signs of a TeamFiltration‑style campaign:
a. Anomalous Sign‑In Patterns
- High‑volume, low‑success rate logins from many distinct IPs.
- Geographically dispersed source addresses that do not align with typical user locations.
- Authentication from legacy protocols (e.g., Basic Auth) which are less common in modern M365 environments.
b. Azure AD Sign‑In Logs
- Look for “Password spray” risk detections in the Azure AD sign‑in reports.
- Filter for “Unknown device” or “Impossible travel” alerts.
c. AWS‑Origin Traffic
Since the campaign originated from AWS EC2 instances, correlating sign‑in logs with known AWS IP ranges (via AWS IP address JSON) can surface suspicious activity.
4. Mitigation Strategies
4.1 Enforce Strong Password Policies
- Disable default passwords by requiring a password change on first login.
- Implement complexity rules (minimum length, mixed character sets) and password expiration.
4.2 Enable Multi‑Factor Authentication (MFA)
MFA blocks credential‑only attacks. Enforce MFA for all users, especially privileged and service accounts.
4.3 Conditional Access Policies
- Block legacy authentication protocols.
- Restrict sign‑ins to trusted locations or compliant devices.
- Rate‑limit sign‑in attempts per user/IP.
4.4 Continuous Monitoring
- Deploy Azure Sentinel or a SIEM to ingest Azure AD logs and set up alerts for credential‑spraying patterns.
- Use Microsoft Defender for Identity to detect abnormal authentication behavior.
4.5 Incident Response Playbook
- Isolate the compromised account (reset password, revoke sessions).
- Force MFA enrollment for the user.
- Review audit logs for any data accessed or exfiltrated.
- Notify affected stakeholders and, where required, regulatory bodies.
5. Lessons Learned
- Default credentials are a low‑hanging fruit; even a single unchanged password can open a door to an entire tenant.
- Distributed cloud infrastructure (e.g., AWS EC2) provides attackers with a massive, mutable IP pool, complicating IP‑based blocking.
- Proactive hygiene—regular password audits, MFA enforcement, and conditional access—remains the most effective defense against credential‑spraying tools like TeamFiltration.
6. Quick Checklist for M365 Administrators
- [ ] Enforce mandatory password change on first login.
- [ ] Deploy MFA for all users.
- [ ] Disable legacy authentication protocols.
- [ ] Set up Azure AD sign‑in risk alerts for password‑spray detection.
- [ ] Regularly review sign‑in logs for anomalous IP ranges.
- [ ] Conduct periodic penetration testing focused on credential‑spraying scenarios.
By integrating these controls, organizations can dramatically reduce the attack surface that campaigns such as UNK_CondorFiltration aim to exploit.