{"id":4914,"date":"2025-06-26T10:05:32","date_gmt":"2025-06-26T10:05:32","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/26\/teamfiltration-pentesting-tool-weaponized-to-hijack-microsoft-teams-outlook-and-other-accounts\/"},"modified":"2025-06-26T10:05:32","modified_gmt":"2025-06-26T10:05:32","slug":"teamfiltration-pentesting-tool-weaponized-to-hijack-microsoft-teams-outlook-and-other-accounts","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/26\/teamfiltration-pentesting-tool-weaponized-to-hijack-microsoft-teams-outlook-and-other-accounts\/","title":{"rendered":"TeamFiltration Pentesting Tool Weaponized to Hijack Microsoft Teams, Outlook, and Other Accounts"},"content":{"rendered":"<p>    TeamFiltration Pentesting Tool Weaponized to Hijack Microsoft Teams, Outlook, and Other Accounts<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated cyberattack campaign has weaponized a legitimate penetration testing framework to compromise thousands of Microsoft cloud accounts across hundreds of organizations worldwide.<\/p>\n<p>The malicious operation, designated UNK_SneakyStrike, leverages TeamFiltration, a popular cybersecurity tool originally designed for Office 365 security assessments, to conduct large-scale account takeover attacks targeting Microsoft Teams, OneDrive, Outlook, and other enterprise applications.<\/p>\n<p>TeamFiltration emerged in January 2021 as a robust framework created by threat researchers and publicly released at DefCon30.<\/p>\n<p>The tool was originally intended to help security professionals simulate intrusions against cloud environments, offering capabilities for Office 365 Entra ID account takeover, data exfiltration, and persistent access establishment.<\/p>\n<p>However, like many dual-use security tools, <a href=\"https:\/\/cybersecuritynews.com\/new-account-takeover-campaign-leverages-pentesting-tool\/\" target=\"_blank\" rel=\"noreferrer noopener\">TeamFiltration<\/a> has now been repurposed by cybercriminals to conduct unauthorized attacks against legitimate organizations.<\/p>\n<p>The UNK_SneakyStrike campaign began its operations in December 2024, with activity peaking in January 2025.<\/p>\n<p>Proofpoint researchers <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/attackers-unleash-teamfiltration-account-takeover-campaign\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malicious use of TeamFiltration through careful analysis of the tool\u2019s distinctive characteristics and attack patterns.<\/p>\n<p>Since the campaign\u2019s inception, threat actors have targeted over 80,000 user accounts across roughly 100 cloud tenants, resulting in multiple successful account compromises.<\/p>\n<p>The attackers exploit TeamFiltration\u2019s advanced capabilities to conduct systematic user enumeration and password spraying attacks.<\/p>\n<p>The framework utilizes Microsoft Teams API and Amazon Web Services infrastructure deployed across multiple geographical regions, with the majority of malicious traffic originating from the United States (42%), Ireland (11%), and Great Britain (8%).<\/p>\n<p>This distributed approach helps attackers evade detection while maintaining operational resilience.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism and Technical Implementation<\/strong><\/h2>\n<p>The technical sophistication of UNK_SneakyStrike lies in its exploitation of Microsoft\u2019s <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploit-microsoft-365-oauth-workflows\/\" target=\"_blank\" rel=\"noreferrer noopener\">OAuth<\/a> client application ecosystem.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhR0v2r9ZvE48OpFp8UmonODXojbp9tWtaifvB8JBE7FykEQrc5Hb-1hyphenhypheniIT1afl6E580DY8eT-Pz653gQ7n0SRxLFw1ZqNBv2Quxzw9RkVZIx1GfbHP7LvA5uT3Ipjuyf1YOXGsUPKoE6LpUovoUxV-Bu9VelZubYs5cttjzeRr_N2hH2m67sgJu_uETs\/s16000\/Execution%2520flow%2520of%2520TeamFiltration%2520%28Source%2520-%2520Proofpoint%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Execution flow of TeamFiltration (Source \u2013 Proofpoint)<\/figcaption><\/figure>\n<\/div>\n<p>TeamFiltration targets specific client applications that belong to Microsoft\u2019s \u201cfamily refresh token\u201d group, enabling attackers to obtain special authentication tokens that can be exchanged across multiple Microsoft services.<\/p>\n<p>The framework\u2019s configuration reveals a predefined list of target applications:-<\/p>\n<pre class=\"wp-block-code\"><code>var clientIdList = new List{\n(\"1fec8e78-bce4-4aaf-ab1b-5451cc387264\", \"Microsoft Teams\"),\n(\"04b07795-8ddb-461a-bbee-02f9e1bf7b46\", \"Microsoft Azure CLI\"),\n(\"ab9b8c07-8f02-4f72-87fa-80105867a763\", \"OneDrive SyncEngine\"),\n(\"d3590ed6-52b3-4102-aeff-aad2292ab01c\", \"Microsoft Office\")\n};<\/code><\/pre>\n<p>Proofpoint analysts noted that attackers maintain <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> through a \u201cbackdooring\u201d technique via OneDrive, uploading malicious files to target environments and replacing legitimate desktop files with malware-laden lookalikes.<\/p>\n<p>The campaign\u2019s attack pattern involves highly concentrated bursts targeting multiple users within single cloud environments, followed by dormant periods lasting four to five days.<\/p>\n<p>This tactical approach, combined with systematic AWS region rotation, demonstrates the threat actors\u2019 sophisticated understanding of detection evasion techniques and infrastructure management.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-leverage-teamfiltration-pentesting-framework\/\">TeamFiltration Pentesting Tool Weaponized to Hijack Microsoft Teams, Outlook, and Other Accounts<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-leverage-teamfiltration-pentesting-framework\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TeamFiltration Pentesting Tool Weaponized to Hijack Microsoft Teams, Outlook, and Other Accounts A sophisticated cyberattack campaign has weaponized a legitimate penetration testing framework to compromise thousands of Microsoft cloud accounts across hundreds of organizations worldwide. The malicious operation, designated UNK_SneakyStrike, leverages TeamFiltration, a popular cybersecurity tool originally designed for Office 365 security assessments, to conduct [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4914","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4914"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4914"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4914\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4914"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4914"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4914"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}