Proofpoint disclosed an active TeamFiltration campaign codenamed UNK_CondorFiltration on September 24, 2026, that targeted over 5,700 Microsoft 365 accounts across 28 tenants at Chilean retail and financial institutions. The campaign successfully compromised 7 accounts by exploiting default passwords, demonstrating weak password policies at targeted organizations and highlighting the persistent risk of credential-based attacks against cloud infrastructure.
UNK_CondorFiltration Targets Chilean Critical Infrastructure
The campaign focused specifically on Chilean retail and financial institutions, sectors that represent critical economic infrastructure. Targeting 28 separate Microsoft 365 tenants indicates the attackers conducted reconnaissance to identify Chilean organizations using Microsoft cloud services and then attempted credential-based access across multiple targets rather than focusing on a single organization.
The use of the TeamFiltration toolset links the campaign to broader credential stuffing and password spraying activity that has targeted Microsoft 365 environments across multiple regions. TeamFiltration is an open-source tool originally developed for penetration testing that automates credential validation, account enumeration, and data exfiltration from compromised Microsoft 365 accounts. While designed for legitimate security testing, the tool has been adopted by threat actors for unauthorized access campaigns.
1,487 AWS EC2 IP Addresses Used for Attack Distribution
The campaign originated from 1,487 unique AWS EC2 IP addresses, indicating the attackers distributed their credential testing across a large pool of cloud infrastructure to avoid detection and IP-based blocking. Using AWS infrastructure for attacks provides several advantages: cloud provider IP addresses often receive less scrutiny than residential or known-malicious IP ranges, the ability to rapidly provision and discard IP addresses complicates attribution and blocking efforts, and distributed attack traffic appears less suspicious than concentrated activity from a small number of sources.
The scale of infrastructure deployed—nearly 1,500 distinct IP addresses—suggests either a well-resourced threat actor or the use of compromised AWS accounts to host attack infrastructure. Either scenario indicates significant operational capabilities and planning behind what might otherwise appear to be opportunistic credential attacks.
Default Password Exploitation Results in 7 Successful Compromises
Of the 5,700 accounts targeted across 28 Microsoft 365 tenants, the attackers successfully compromised 7 accounts by using default passwords. This relatively low success rate—approximately 0.1%—nonetheless represents complete account takeover for those seven users, granting attackers access to email, documents stored in SharePoint and OneDrive, Teams conversations, and any other Microsoft 365 services the compromised accounts had permissions to access.
The use of default passwords indicates that some organizations deployed Microsoft 365 accounts without enforcing password changes from initial setup credentials or used predictable password patterns that the attackers successfully guessed. Default password attacks rely on either unchanged initial credentials (common when accounts are created in bulk) or standard password patterns that organizations apply across multiple accounts (such as “CompanyName2026!” or similar easily guessed formats).
Chilean Retail and Financial Sector Implications
The targeting of retail and financial institutions creates multiple risk scenarios. Compromised retail accounts could provide access to customer data, payment systems, or supply chain communications. Financial institution accounts might expose transaction data, customer financial information, or internal communications about security controls and operational procedures.
The seven successful compromises occurred across the 28 targeted tenants, suggesting multiple organizations had weak password practices rather than a single organization with systematic default password usage. This distribution of compromises indicates the password hygiene problem extends across the Chilean retail and financial sectors rather than representing an isolated incident at a single organization.
Credential Attack Defense and Password Policy Requirements
The UNK_CondorFiltration campaign demonstrates that credential-based attacks remain effective despite years of security awareness training and best-practice guidance on password policies. Default passwords, weak passwords, and password reuse continue to provide attackers with access to cloud environments that may have sophisticated perimeter defenses and monitoring capabilities but fail at the fundamental level of ensuring users cannot authenticate with easily guessed credentials.
Organizations using Microsoft 365 or other cloud platforms must enforce password policies that eliminate default passwords, require password complexity that resists dictionary and pattern-based attacks, and implement multi-factor authentication to protect against credential compromise. MFA adoption would have blocked the UNK_CondorFiltration campaign even for accounts with weak or default passwords, as the attackers’ credential validation would have failed at the second factor verification step.
Monitoring and Detection for Credential Stuffing Campaigns
Beyond password policies, organizations should monitor authentication logs for patterns consistent with credential stuffing or password spraying attacks. Indicators include authentication attempts from unusual geographic locations, high volumes of failed login attempts across multiple accounts, successful authentications from IP addresses with no prior access history, or authentication activity during off-hours when legitimate users are unlikely to be working.
The 1,487 AWS IP addresses used in the UNK_CondorFiltration campaign would have appeared in Microsoft 365 authentication logs as the source addresses for login attempts. Organizations that correlate authentication sources with known cloud provider IP ranges can flag unusual authentication patterns from cloud infrastructure, particularly when those attempts target multiple accounts or occur from IP addresses that have no established relationship with the organization.
Proofpoint’s disclosure provides affected Chilean organizations with specific indicators of compromise and campaign characteristics that can be used to audit authentication logs for signs of UNK_CondorFiltration activity. Organizations that identify suspicious authentication patterns consistent with the campaign should investigate whether accounts were compromised and what actions the attackers took with any successfully accessed accounts. Email forwarding rules, data downloads, and privilege escalation attempts are common post-compromise activities that warrant review.
Broader TeamFiltration Threat Landscape
The UNK_CondorFiltration campaign represents one instance of TeamFiltration tool usage, but the open-source availability of the tool means similar campaigns likely target Microsoft 365 environments in other regions and sectors. The tool’s automation of credential testing, account enumeration, and post-compromise data collection lowers the barrier for attackers to conduct large-scale credential-based attacks against cloud infrastructure.
The campaign’s focus on Chilean critical infrastructure may indicate either opportunistic targeting of organizations with weaker password practices or a deliberate focus on Latin American economic targets. Either way, the successful compromise of retail and financial institution accounts demonstrates that credential-based attacks remain a viable entry point for attackers targeting cloud environments, and organizations that have not implemented strong password policies and multi-factor authentication remain vulnerable to these well-established attack techniques.
