Proofpoint cloud threat researchers have recently uncovered an account takeover (ATO) campaign weaponizing TeamFiltration, a pentesting framework designed to assist cybersecurity practitioners in testing and improving defense solutions.
Attackers leverage Microsoft Teams API and globally distributed Amazon Web Services (AWS) servers for greater speed and efficiency, allowing for automating the tedious work of user enumeration and password spraying for both efficacy and stealth.
So far, over 80,000 user accounts across roughly 100 cloud tenants have been targeted.
Read the full campaign analysis here: https://brnw.ch/21wTk3G
#ATO #accounttakeover #MicrosoftTeams #OneDrive #Outlook #AWS #cyber