Spraying in the Andes TeamFiltration Returns to Exploit Forgotten Service Accounts
Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts
Published on: September 22, 2026
Source: Proofpoint
Proofpoint researchers have identified an active TeamFiltration campaign, tracked as UNK_CondorFiltration, that targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America, with a strong focus on Chilean organizations. 🚨
In late July 2026, Proofpoint threat researchers detected this concentrated Microsoft 365 brute-force campaign. The attacker’s tooling left a familiar artifact: the hardcoded user agent unique to TeamFiltration - a cross-platform offensive framework publicly documented by Proofpoint in the UNK_SneakyStrike blog post. TeamFiltration is designed for penetration testing Microsoft 365 environments and was first used internally in January 2021 before being publicly released at DEF CON 30.
The campaign was concentrated almost entirely on Chilean organizations, with one major retailer accounting for 78.3% of all observed events. All seven successfully compromised accounts were unmanaged functional/service accounts with no prior legitimate login baseline, indicating default or predictable passwords that had never been rotated and lacked MFA enforcement.
The attacker likely sprayed accounts with default passwords against dormant service accounts, which proved effective. Every confirmed compromise traced back to the same likely root cause: a default password on a forgotten account. The attacker targeted more than 5,700 accounts across 28 tenants and achieved zero compromises against personal employee accounts.
The UNK_CondorFiltration campaign unfolded across three distinct bursts over a 26-day window. The final wave, from August 13-16, shifted focus to a major Chilean retailer, where all seven confirmed account compromises and observed post-access activity occurred on August 14-15. For most compromised accounts, the only post-login activity observed was access to “Microsoft Office,” “OneDrive,” and “Teams.” This was done from the same AWS infrastructure and matches TeamFiltration’s -auto-exfil mode, which automatically pulls email, Teams conversations, and OneDrive files after a successful sign-in.
Within 90 seconds of the successful compromise, the attacker switched from the TeamFiltration infrastructure to a German VPN node and began a post-access sequence: probing the corporate VPN, accessing Azure Portal, browsing SharePoint, and triggering a Microsoft Graph API token request.
The UNK_CondorFiltration campaign serves as a reminder that one of the weakest links in an enterprise identity perimeter is often not a phished employee or a zero-day exploit, but rather the forgotten account. Service accounts provisioned for convenience and never revisited represent a structurally unprotected attack surface.