Target Industry

Indiscriminate, opportunistic targeting. 

Overview

A significant botnet attack is actively targeting Microsoft 365 users accounts worldwide through password-spraying techniques. There are claims the botnet consists of over 130,000 compromised devices, which has been active since December 2024. The botnet is believed to be operated by a sophisticated Chinese-affiliated group, possibly linked to Volt Typhoon or Salt Typhoon. The threat actors are using command-and-control servers hosted in the US, with traffic routed through Hong Kong and China. 

Impact

Through password-spraying techniques the botnet attack is targeting Microsoft 365 users with serious repercussions. It can lead to account takeovers, disrupting business operations and causing downtime. Compromised accounts may be used for internal phishing, further compromising security. The threat actors are bypassing multi-factor authentication (MFA) by exploiting non-interactive sign-ins and basic authentication, which do not always enforce MFA. This reduces visibility for security teams, making it harder to detect and respond to these attacks. 

Exploitation

By taking advantage of Basic Authentication, password-spraying techniques guess widely used or compromised passwords to target a large number of accounts. When the threat actor cracks the credentials, they will not be prompted for MFA and can frequently get past Conditional Access Policies (CAP) undetected. This is because Basic Authentication doesn’t require any back-and-forth communication, and credentials are transmitted in plain text. 

After credentials are validated, the compromised account can be exploited in further sophisticated phishing attempts or to access legacy services that do not require MFA. This enables the attackers to covertly verify the legitimacy of an account’s credentials. 

Containment, Mitigations & Remediations

To mitigate the risks associated with password-spraying attacks leveraging Basic Authentication: 

  • Disable Basic Authentication: To force the use of more secure authentication methods that support MFA 
  • Implement CAP: To enforce stricter access controls based on user location, device compliance, and risk level, helping to detect and block suspicious login attempts 
  • Implement MFA: Enforce MFA for all users to add an extra layer of security 
  • Sign-In Risk Policy: Implement a sign-in risk policy to automate responses to risky sign-ins 
  • Strong password policies: use of strong, unique passwords and regular password changes, along with the use of password managers. 

Threat Landscape

More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. Due to the complexity of this botnet attack and the password-spraying techniques, this threat is concerning because of its advanced capabilities and widespread use. 

Threat Group

The specific threat group behind this has not been publicly identified at the time of writing. 

TTPs

  • T1071.005: Application Layer Protocol: Publish/Subscribe Protocols 
  • T1556.004: Modify Authentication Process: Network Device Authentication 
  • T1584.005: Compromise Infrastructure: Botnet 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content