Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » More than 80,000 Microsoft Entra ID credits, directed using an open source Teamfiltration tool
Global Security

More than 80,000 Microsoft Entra ID credits, directed using an open source Teamfiltration tool

AdminBy AdminJune 12, 2025No Comments3 Mins Read
Open-Source TeamFiltration Tool
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


June 12, 2025Red LakshmananSpecial Security / Active Directory

Teamfiltration tool with open source

Cybersecurity researchers have discovered a new accounting company (ATO), which uses an open source penetration scope, called Teamfiltration to violate ID Microsoft Entra (formerly Azure Active Directory).

Activity, codonomena Unk_sneakystrike According to the data, more than 80,000 targeted user accounts in hundreds of cloud tenants of organizations, since in December 2024 there was a splash of the login’s attempts, which led to a successful absorption of accounts.

“Attackers use API and Amazon Web Services servers Microsoft Teams and Amazon (AWS) located in various geographical regions to launch users’ removal and attempts to disclose passwords,” – Note. “The attackers used access to specific resources and relatives such as Microsoft Teams, OneDrive, Outlook and others.”

Cybersecurity

Teamfiltration, Publicly released According to the researcher Melvin “Flangwick” Langvik, in August 2022 in Def Conference Conferencedescribed as the interplatform base For “listing, spraying, exports and back” Entra ID accounts.

The tool offers extensive opportunities to facilitate the absorption of the account, using password spray attacks, data exploration, and sustainable access, downloading malicious files into Microsoft OneDrive.

While the instrument requires the Amazon Web Services account (AWS) and a one -time Microsoft 365 account to facilitate the password and list of account listing, ProofPoint noted that there is evidence of a malicious activity that uses a team for such activities to take part Geographical place.

Three primary source geography is associated with malicious activity, based on the number of IP -units include the United States (42%), Ireland (11%) and the United Kingdom (8%).

Cybersecurity

Unk_sneakstrike activity has been described as a “large -scale users’ transfer”, when unauthorized access efforts occurring in “high concentrated explosions”, focusing on several users in one cloud environment. Then there is a lull, which lasts four to drink days.

The conclusions again emphasize how tools designed to assist cybersecurity specialists can be abused by the subjects of threats to carry out a wide range of moody actions that allow them to violate users’ accounts, collect data, and set permanent securing.

“The Unk_sneakysstrike target strategy suggests that they are trying to access all user accounts from smaller cloud tenants, focusing only on the subsens of users in large tenants,” PROFPOINT said. “This behavior corresponds to the advanced features of acquiring the purpose of the tool designed to filter less desirable credentials.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025

AI AI agents work on secret accounts – learn how to fasten them in this webinar

June 12, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.