CondorFiltration Exploits Default Credentials in Cloud Attacks on Retail, Finance
Moyen · The Hacker News ·
En bref
- Threat actor CondorFiltration leveraged default credentials to breach Microsoft 365 accounts.
- Campaign involved 5,700 accounts across 28 tenants and 1,487 IP addresses, with 7 confirmed compromises.
- Attacks originated from AWS EC2 instances and targeted Chilean retail and financial institutions.
- No CVEs were exploited; weak password practices were the primary vector.
- Education sector should review cloud identity configurations and enforce strong authentication.
An unidentified threat group, tracked as CondorFiltration, carried out a credential-based intrusion against Microsoft 365 environments. The attackers relied on default passwords to gain unauthorized access, leveraging infrastructure hosted on AWS EC2. No software vulnerabilities (CVEs) were involved, highlighting that weak authentication remains a primary attack path.
The operation touched 5,700 user accounts across 28 separate tenants. The actors used 1,487 distinct IP addresses, all originating from Amazon Web Services. Seven accounts were successfully compromised. The primary targets were retail businesses in Chile and financial institutions, indicating a focused but broad campaign.
For K-12 districts, this incident underscores the risk of default or weak passwords in cloud services. Schools often depend on Microsoft 365 and similar platforms, and attackers can exploit these without any CVE. The use of cloud-hosted IPs complicates detection, as traffic may appear legitimate. No organization is too small to be targeted.
Context suggests the actor may have used the TeamFiltration tool, and vendors like Proofpoint and Microsoft are likely involved in threat intelligence. What to watch: similar campaigns against government and education, anomalous logins from AWS IP ranges, and any sign of credential stuffing. Enforce MFA and eliminate default credentials immediately.
À faire maintenant
- Audit all Microsoft 365 tenants for accounts using default or weak passwords and force immediate resets.
- Enforce multi-factor authentication (MFA) for every user, with priority on administrators and remote access.
- Block or closely monitor sign-ins from AWS IP ranges unless business-critical, using conditional access policies.
- Review sign-in logs for anomalous activity, focusing on the 1,487 IPs if threat intelligence is available.
- Disable legacy authentication protocols that bypass MFA and enable password complexity and length policies.
- Conduct a password hygiene campaign and consider threat intelligence feeds for CondorFiltration indicators.
Source originale
Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.