top of page

The Thieves Didn’t Crack the Safe. Someone Never Changed the Locks

hace 1 hora
3 min de lectura

Picture a gang of thieves standing outside a huge corporate building.

Thousands of doors.

Security cameras.

Employees with badges.

A vault somewhere deep inside.

They could steal a key. Trick a guard. Break a window.

Instead, one thief pulls out a ring containing the factory-default keys.

And starts trying doors.

One after another.

Until seven locks click open.

That is essentially the weakness exploited in the TeamFiltration campaign tracked as UNK_CondorFiltration.

More than 5,700 Microsoft 365 accounts across 28 tenants were targeted.

Seven were compromised.

And every successful compromise had something important in common:

the attackers found forgotten service accounts still carrying default passwords.


Phase 1 — Walk the Building


The operation unfolded across three waves between late July and August 2026, primarily targeting Chilean financial institutions and retail organizations.

The attackers tested thousands of identities, with one retailer accounting for 78.3% of the observed authentication activity.

Imagine the thieves walking down an enormous corridor.

Door 1.

Locked.

Door 2.

Locked.

Door 3.

Locked.

They don’t need every door to open.

They only need one.


Phase 2 — Try the Factory Keys


Evidence indicates that the attackers sprayed accounts with default passwords, including credentials originally provisioned by IT teams and never rotated.

Their preferred targets weren’t necessarily employees.

They were service and functional accounts created to keep business processes running.

Then forgotten.

Still active.

Still trusted.

Still carrying their original credentials.

Every successful compromise involved one of these unmonitored accounts.

The thieves had discovered something better than picking locks:

somebody had never changed them.


Phase 3 — Seven Doors Open


Seven accounts were successfully compromised.

Six fell within seven minutes.

That speed suggests the attackers were not carefully cracking unique passwords one by one. Proofpoint assessed that it likely reflected shared or default credentials.

Click.

Click.

Click.

Six doors open almost together.

Behind them aren’t employees.

There is nobody sitting at a desk who notices something strange.

These are machine identities quietly performing their jobs.

Perfect rooms for thieves who don’t want anyone asking why the door opened.


Phase 4 — Bring in TeamFiltration


The attackers used TeamFiltration, a legitimate offensive security framework capable of enumerating Entra ID accounts, password spraying, harvesting information and establishing interactive access to OneDrive.

Think of it as the burglars’ reconnaissance kit.

Map the building.

Identify the doors.

Try the keys.

Find the ones that open.

Then explore what lies behind them.

The activity originated from 1,487 unique AWS EC2 source IP addresses, distributing the authentication attempts across substantial infrastructure.


Phase 5 — Move Through the Building


Once a door opened, the thieves didn’t remain in the entrance hall.

Across most compromised accounts, activity reached Microsoft Office, OneDrive and Teams.

In less than two minutes after successful compromise, the operator was also observed pivoting through a German VPN node and probing the corporate VPN while accessing Azure Portal, browsing SharePoint Online and initiating Microsoft Graph API token requests.

The thieves had found an unlocked service entrance.

Now they were checking:

Where does this corridor lead?

Which other rooms can this identity enter?

What can its badge unlock?

Proofpoint noted that these access events may indicate data harvesting, but sign-in activity alone does not establish that data was actually exfiltrated.


Phase 6 — Lock the Forgotten Doors


The lesson isn’t simply to build a stronger front entrance.

It’s to find every forgotten door.

Organizations need to inventory both human and non-human identities, remove default credentials, rotate service-account passwords, enforce MFA wherever possible, disable dormant identities and monitor authentication and subsequent cloud activity continuously.

Because an identity does not stop being dangerous when people forget about it.

It simply becomes unguarded.


The Forgotten Door


Cybersecurity often focuses on sophisticated intrusions.

Zero-days.

Phishing.

Malware.

Exploit chains.

But UNK_CondorFiltration demonstrates a much simpler possibility.

The thieves arrive at night.

They see the cameras.

The alarms.

The reinforced entrance.

The vault deep inside.

And they don’t attack any of them.

Instead, they walk around the back of the building.

There is an old service door.

Nobody remembers who created it.

Nobody uses it anymore.

Nobody changed its lock.

The thief takes out the factory key.

Slides it inside.

Turns it.

Click.

Sometimes attackers don’t need to pick the lock.

They just need to find the one nobody ever changed.


The Hacker News


 
 
 

Comentarios


bottom of page