At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | UNK_Condor Filtration (unattributed cybercrime operator) |
| Activity Type | Password spraying, credential validation, cloud data exfiltration |
| Targets or Victims | 28 Microsoft 365 tenants in Latin America (primarily Chilean retailers and banks) |
| Scale | 5,714 unique accounts targeted across 32,825 login events; 7 service accounts compromised |
| Jurisdiction / Status | Unidentified cybercriminals; uncharged |
| Source | Proofpoint Threat Insight |
Executive Summary
Security researchers identified an aggressive brute-force campaign targeting corporate identity systems across Chile. An unknown adversary used the open-source TeamFiltration tool to test default credentials against thousands of business accounts. The attack successfully breached seven unmonitored service accounts that lacked multi-factor authentication.
What Happened During the Spray Waves
The campaign unfolded in three distinct bursts between July 21 and August 16, 2026. During the initial wave, the attacker probed accounts belonging to two major Chilean banks. Later, spray traffic surged to more than 1,500 accounts in a single day. The final wave concentrated on a major Chilean retailer, which absorbed over 78 percent of all authentication events.
The attacker used TeamFiltration, an offensive framework originally developed for cloud penetration testing. As Proofpoint noted, “In late July 2026, Proofpoint threat researchers detected a concentrated Microsoft 365 brute-force campaign targeting Chilean organizations.” The tool validated account existence through Teams application interfaces at high speeds. Next, it tested passwords across rotating Amazon Web Services infrastructure to evade address blocks.

Who Is Behind It
Researchers track the intrusion cluster as UNK_Condor Filtration with low attribution confidence. The operators remain anonymous, and analysts cannot tie the activity to a specific criminal syndicate. However, the operational signature matches known penetration testing frameworks.
The framework broadcasts a distinct user-agent string linked to an outdated 2020 Teams desktop client. This unique fingerprint helped analysts connect the intrusion to earlier activity. While the underlying software originated as a legitimate security tool, criminal actors now repurpose it for automated attacks.
Impact and Operational Scale
The attacker targeted 5,714 unique accounts across 28 corporate tenants. Interestingly, the TeamFiltration password spray campaign failed to breach any personal employee accounts. Instead, every confirmed compromise affected unmanaged service accounts.
Proofpoint researchers confirmed this vulnerability pattern across victim environments. The report highlighted: “All 7 successfully compromised accounts were unmanaged functional/service accounts with no prior legitimate login baseline, strongly indicating default or predictable passwords that had never been rotated, with no MFA enforcement.” These accounts managed business tasks like vendor payments and ticketing without human oversight.
Within 90 seconds of breaching an account, the attacker shifted to a German virtual private network. From there, the operator accessed the Azure Portal, SharePoint Online, and the Microsoft 365 portal. The intruder also attempted to connect to the corporate VPN, but conditional access policies blocked that attempt.
What Comes Next and Defense Guidance
Identity administrators must discover and inventory all non-human service accounts across their tenants. Because service accounts often escape regular password change cycles, they create dangerous security gaps. Organizations must enforce multi-factor authentication or phishing-resistant credentials across every active profile.
Security teams can detect these intrusions by inspecting sign-in logs for outdated Teams desktop user agents. Additionally, monitoring for a TeamFiltration password spray originating from cloud hosting IP ranges helps stop account takeovers early. As Proofpoint concluded, “The UNK_Condor Filtration campaign is a reminder that one of the weakest links in an enterprise identity perimeter is often not a phished employee or a zero-day exploit. It is the forgotten account.”
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!