Cybersecurity experts have revealed a significant threat campaign, identified as UNK_CondorFiltration, which has targeted over 5,700 accounts within 28 Microsoft 365 environments. This operation has primarily affected retail and financial sectors in Chile, originating from 1,487 distinct AWS EC2 IP addresses, according to research by Proofpoint.
Focus on Chilean Institutions
The campaign’s main targets were Chilean retail and financial entities. It exploited a critical security gap by compromising seven accounts, which were primarily service accounts with default or unrotated passwords, lacking multi-factor authentication (MFA). These accounts are often overlooked and remain unmonitored, making them vulnerable to such attacks.
The attack unfolded in three waves from late July to August 2026. Notably, an unnamed Chilean retailer bore the majority of the attack, with 78.3% of authentication events targeting it. The campaign’s phases included:
- July 21-24: Targeting 100-120 accounts daily against two major Chilean banks.
- July 26-28: Peaking at 1,520 accounts on July 27, focusing on another financial institution.
- August 13-16: Reaching 1,560 accounts on August 15, aimed at a major retailer, resulting in seven compromises.
Technical Insights and Methods
The threat actor utilized TeamFiltration, a legitimate cross-platform offensive framework, to execute the attack. This tool allows for the enumeration, password spraying, and backdooring of Entra ID accounts. It facilitated the validation of email accounts, testing of common passwords, and covert access to OneDrive.
Most compromised accounts granted access to Microsoft Office, OneDrive, and Teams, suggesting potential data exfiltration. However, sign-in activities alone do not confirm data theft. The attackers swiftly pivoted their operations, utilizing a German VPN node to access corporate VPNs, Azure Portals, and SharePoint Online.
Broader Implications and Historical Context
The UNK_CondorFiltration is not an isolated incident. In June 2025, the TeamFiltration framework was also employed in another campaign, UNK_SneakyStrike, targeting over 80,000 user accounts across various cloud tenants. These incidents underline the persistent vulnerability of unmonitored service accounts.
Proofpoint emphasizes that the weakest link in enterprise security may not be a vulnerable employee or zero-day exploit but rather forgotten, unmonitored accounts. These service accounts, often left with default credentials, represent an unprotected attack surface within the digital infrastructure.
The recent breaches serve as a stark reminder of the need for robust cybersecurity measures, including regular password updates and stringent monitoring of all accounts, to protect against evolving threats in the digital landscape.
