TeamFiltration Pentesting Tool Harnessed in Global Microsoft Entra ID Attack Campaign
4 Articles
4 Articles
Hackers Weaponize TeamFiltration: Open-Source Pentest Tool Powers Major Entra ID Account Takeover Wave
What began as a legitimate penetration testing framework has now become the centerpiece of a sprawling campaign compromising tens of thousands of enterprise cloud accounts. In a recently disclosed report, Proofpoint researchers unveiled UNK_SneakyStrike—a large-scale, stealthy attack series exploiting the open-source tool TeamFiltration to infiltrate Microsoft Entra ID environments.The campaign, active since December 2024, has already targeted m…
TeamFiltration pentesting tool harnessed in global Microsoft Entra ID attack campaign
Attacks exploiting the TeamFiltration penetration testing framework have been launched by the threat actor UNK_SneakyStrike to target over 80,000 Microsoft Entra ID accounts across hundreds of organizations worldwide, some of which were successfully taken over, as part of a campaign that commenced in December, BleepingComputer reports. Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon …
A recent analysis by the security company Proofpoint reveals how the popular test framework teamFiltration is currently being massively abused for attacks on cloud infrastructures. Attack campaign "UNK_SneakyStrike" targets Entra ID accounts Since December 2024, security researchers have been monitoring a coordinated wave of attacks that target attackers trying to gain access to Microsoft Entra ID accounts. The internal name of this campaign: UN…
An active campaign since December 2024 uses the Pentesting Framework TeamFiltration. The backmen also use AWS infrastructures and manipulate OneDrive files.
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
To view factuality data please Upgrade to Premium