Account Takeover Campaign Exploits Pentesting Tool To Target Entra ID Users

A major cybersecurity threat has emerged with the discovery of a widespread account takeover campaign targeting Microsoft Entra ID users.

Security researchers recently identified a series of attacks that exploit a legitimate penetration testing tool named TeamFiltration, which has been repurposed by malicious actors to compromise enterprise cloud environments.

Since the end of 2024, this campaign has compromised tens of thousands of user accounts across diverse organizations, leading to a series of account takeovers and data breaches.

Technical Exploitation: How TeamFiltration Became A Weapon

TeamFiltration was originally developed as an advanced penetration testing utility, aimed at helping security professionals simulate attacks and identify vulnerabilities within Microsoft Entra ID, formerly Azure Active Directory.

The multi-functional nature of this tool has now made it attractive to cybercriminal groups, who have weaponized it for real attacks.

At the core of the campaign, TeamFiltration is used to automate account enumeration, password spraying, and identity-related reconnaissance on targeted cloud tenants.

The attackers start by conducting account enumeration, which involves systematically identifying valid Entra ID users through automated queries.

Once a list of potential targets is created, the password spraying feature comes into play.

Unlike brute-force attacks that rapidly try many passwords against one user, password spraying tries a small list of commonly used or weak passwords across many accounts.

This “low-and-slow” approach helps evade typical account lockout protections and alerting mechanisms.

With ongoing attempts, especially during off-hours, the attackers are able to minimize detection.

Once credentials are cracked, TeamFiltration enables attackers to extract emails, documents, and other sensitive information from compromised accounts.

The tool even offers a OneDrive abuse feature, where it uploads malicious files masquerading as legitimate documents potentially enabling further internal spread or attack persistence.

A key technical indicator of TeamFiltration activity is its unique user agent string, which imitates an outdated Microsoft Teams client.

This string is seldom used in genuine environments, making it a reliable flag in authentication logs for suspicious behavior.

The attackers also exploit a set of hardcoded Microsoft OAuth application client IDs within TeamFiltration, attempting to obtain refresh tokens that provide ongoing access to Office 365 and other Microsoft cloud services.

By scripting requests through these endpoints, the attackers can masquerade as different applications and further blend in with normal traffic.

Notably, all these attacks are routed through rotating cloud-based infrastructure, primarily Amazon Web Services (AWS), with traffic emerging from data centers in the United States, Ireland, and Britain.

This distributed approach helps mask the true origin of the attacks and makes blocking by simple IP address impractical.

Campaign Patterns, Impact, And Defense Strategies

The account takeover campaign follows distinct operational patterns.

Attacks are launched in bursts, targeting entire small- and medium-sized organizations by enumerating every user, while focusing on high-value or privileged accounts within large enterprises.

This selective targeting is believed to be guided by TeamFiltration’s built-in filtering scripts, which prioritize users with elevated access or valuable data.

Attack traffic is coordinated through multiple AWS regions, and authentication logs often show rapid spikes of failed logins immediately preceding a compromise.

Victims have reported not just unauthorized mailbox access but also theft of business data and, in some cases, persistence established through compromised OneDrive accounts.

The aftermath includes reputation damage, regulatory penalties, and operational disruptions for affected organizations.

Detection remains challenging due to the tool’s ability to mimic legitimate cloud behavior and the attack’s reliance on trusted cloud networks.

According to the Report, To defend against this evolving threat, organizations must adopt layered security strategies. Monitoring for the outdated Teams user agent and correlating login attempts from suspicious AWS IPs are effective starting points.

Enhanced conditional access policies should be enforced, filtering out logins based on user agent strings, known cloud IP ranges, and anomalous geographic locations.

Multifactor authentication (MFA) should be mandated for all users, and end-user education on password security is essential to prevent password spraying success.

The rise of such campaigns underscores the dual-use dilemma of penetration testing tools and the need for enterprises to pair traditional security controls with advanced behavioral analytics to detect and stop sophisticated account takeover attempts before they escalate.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories