• Latest
  • All
  • How To
Microsoft 365

Hackers Use Massive Botnet to Exploit Microsoft 365 Security Loophole

February 25, 2025
China Kills Meta’s $2 Billion Manus Deal: How The Deal Unravelled

China Kills Meta’s $2 Billion Manus Deal: How The Deal Unravelled

June 15, 2026
UK Bans Social Media For Under-16s, Joining a Growing Global Push

UK Bans Social Media For Under-16s, Joining a Growing Global Push

June 15, 2026
Huduma Kenya call centre open till 9 Pm

New! Huduma Centre Services Halted After Data Centre Loses Power

June 15, 2026
Big Brother is Watching as Kenya Joins the CCTV Surveillance Club

Big Brother is Watching as Kenya Joins the CCTV Surveillance Club

June 15, 2026
DHgate Tablet Cases deals
How to Download and Verify Your NTSA eLogbook

How to Verify an NTSA eLogbook Is Not Fake

June 15, 2026
Outside Enterprise Allegedly Used Gemini to Build Massive Phishing Operation

Google Sues Scammers Using Gemini to Build Fake Government and Brand Sites

June 13, 2026
SpaceX

SpaceX Debuts at $2.1 Trillion Valuation in Largest IPO Ever

June 13, 2026
Elon Musk

Elon Musk Becomes World’s First Trillionaire

June 13, 2026
Who Will Win The World Cup According to Prediction Models

Who Will Win The World Cup According to Prediction Models

June 12, 2026
Airbuds: The App That Turns Your Music Into a Social Feed

Airbuds: The App That Turns Your Music Into a Social Feed

June 13, 2026
How a Remote IMEI Kill Switch Is Shaking Up the Stolen iPhone Market Worldwide

Following London Success, Apple Deploys Global Killswitch Feature to Eliminate Stolen iPhones Market

June 12, 2026
CS Mbadi clarifies: June 30 remains tax deadline; nil return may shift to January 31

Kenya’s June 30 Tax Deadline Remains, But Nil Returns Deadline May Move to Jan 31

June 12, 2026
Techweez | Tech News, Reviews, Deals, Tips and How To
  • News
  • Entertainment
  • Reviews
  • Features
  • Editorial
No Result
View All Result
Techweez | Tech News, Reviews, Deals, Tips and How To
  • News
  • Entertainment
  • Reviews
  • Features
  • Editorial
No Result
View All Result
Techweez | Tech News, Reviews, Deals, Tips and How To
No Result
View All Result

Hackers Use Massive Botnet to Exploit Microsoft 365 Security Loophole

Naftary Thitu by Naftary Thitu
February 25, 2025
in News
Reading Time: 4 mins read
284
0
Microsoft 365

Imagine waking up to find your Microsoft 365 account compromised. Not because you had a weak password, but because cybercriminals found a way to bypass multi-factor authentication (MFA) entirely. That’s what is happening.

A massive botnet, made up of over 130,000 compromised devices, is running large-scale password spraying attacks against Microsoft 365 users worldwide. By exploiting a security blind spot in non-interactive sign-ins and basic authentication, these attackers are slipping past security defenses undetected.

How Are Hackers Breaking Into Microsoft 365 Accounts?

This is not your typical brute-force attack. Instead of guessing passwords randomly, the attackers are using stolen login credentials from infostealer malware logs. They then attempt logins using non-interactive sign-ins, which don’t require user input and don’t often trigger MFA prompts.

Non-interactive sign-ins are commonly used for:

  1. Service-to-service authentication.
  2. Legacy email protocols (POP, IMAP, SMTP).
  3. Automated processes.

Since these sign-ins don’t always enforce MFA, hackers can use basic authentication to get in; no extra verification is needed. Despite Microsoft working to phase out Basic Auth, many organizations still have it enabled, giving attackers an easy backdoor.

.

Cybersecurity researchers suspect that this campaign is linked to a Chinese-affiliated threat group, though investigations are still ongoing.

These criminals aren’t just using stolen credentials; they’ve built an entire attack infrastructure to cover their tracks:

  • Password spraying: Systematically trying stolen login details across thousands of accounts.
    Proxy-based evasion: Distributing attacks across different IP addresses to avoid detection.
  • Command-and-Control (C2) servers: Six servers, all based in the US, are directing these attacks.
    Massive botnet: Over 130,000 hijacked devices are communicating with these C2 servers.

A four-hour snapshot of botnet activity showed these devices aggressively trying to break into accounts worldwide, without triggering security alerts.

If your organization relies only on interactive sign-in monitoring, this attack will go unnoticed. A successful breach can lead to:

  • Stolen sensitive data: Emails, documents, and collaboration tools compromised.
  • Account lockouts: Repeated login attempts causing downtime and frustration.
  • Internal phishing: Attackers using breached accounts to launch secondary attacks.
  • Bypassing MFA: No verification prompt means no extra layer of protection.
  • Reduced visibility: Many security tools don’t track non-interactive sign-ins.

How to Protect Your Microsoft 365 Accounts

Hackers are exploiting gaps in the authentication security, but you don’t have to be their next victim. Here’s how to defend against this attack:

  1. Disable basic authentication: Microsoft is retiring it soon, but don’t wait; turn it off now.
    Monitor Non-Interactive Sign-Ins: Set up alerts for unusual logins and activity.
  2. Enforce MFA Everywhere: Even for service accounts and automated processes.
    Use Privileged Access Management (PAM): Limit service account permissions and enforce credential rotation.
  3. Strengthen Conditional Access Policies: Restrict logins based on location, risk level, and device type.
    Educate Security Teams: Awareness is key. Make sure your IT team knows about this attack.

Darren Guccione, CEO of Keeper Security, warns that this attack is a wake-up call for businesses still relying on outdated authentication methods.

“Attackers are bypassing MFA by abusing non-interactive sign-ins and stolen credentials. Securing authentication pathways is critical; just having MFA isn’t enough.”

Microsoft plans to fully retire Basic Authentication by 2025, but until then, this botnet will continue to exploit organizations that haven’t updated their security settings.

Tags: MalwareMicrosoftMicrosoft 365Phishing
SendShare158Tweet99
Naftary Thitu

Naftary Thitu

Tech enthusiast and ICT guru by trade, I simplify digital trends and gadgets into articles everyone can enjoy. Email: [email protected]

Related Posts

Outside Enterprise Allegedly Used Gemini to Build Massive Phishing Operation

Google Sues Scammers Using Gemini to Build Fake Government and Brand Sites

June 13, 2026
Nvidia RTX laptop

Nvidia Wants to Sell You a PC Again

June 2, 2026
Data center

Kenya’s $1 Billion Microsoft AI Data Center Project Stalls Over Electricity Limits

May 8, 2026
Countersuit

Elon Musk vs. OpenAI: What the Trial Has Revealed So Far

May 8, 2026
Cyber Threats

Kenya Detects 3.3 Billion Cyber Threats in 2026 Led by System Attacks

May 6, 2026
Sony PlayStation

PlayStation Reverses Plan to Bring More Games to PC as Sony Shifts Strategy

March 4, 2026

Techweez is where tomorrow’s tech stories break today, thanks to intelligent analysis, real-world insight, and visionary storytelling.

Follow Us

Editorials

Airbuds: The App That Turns Your Music Into a Social Feed

Kenya Might Need to Crack Down on Wealth Porn Like China

Techweez and Gearhaus Score BAKE Awards 2026 Nominations

Death by AI: Opportunities That Were Disrupted by Automation

CBK Approved 200+ Digital Lenders, But That’s Not the Real Story

Data Centers, Petrodollars and the Price of Building the AI Age

More News

SpaceX Debuts at $2.1 Trillion Valuation in Largest IPO Ever

Elon Musk Becomes World’s First Trillionaire

Who Will Win The World Cup According to Prediction Models

Airbuds: The App That Turns Your Music Into a Social Feed

Following London Success, Apple Deploys Global Killswitch Feature to Eliminate Stolen iPhones Market

Kenya’s June 30 Tax Deadline Remains, But Nil Returns Deadline May Move to Jan 31

  • Terms Of Use
  • Techweez Brand
  • Privacy & Policy
  • Contact Us

© 2024 Techweez - Palahala Media Group may earn a commission when you buy through links on our sites.
A Palahala Media Group Brand. All rights reserved.
.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Techweez | Tech News, Reviews, Deals, Tips and How To
Crunchy Cookies 🍪 Ahead!

Hey there! Just a heads-up: we're big fans of cookies - both the digital and edible kind! 🍪 We use our cookies and some from third parties to ensure your browsing experience on our site is smooth sailing and secure.

 

But wait, there's more! We also use cookies to gather stats and insights on how you navigate our site. It's like getting a behind-the-scenes peek at your digital adventures!

 

Don't worry, you're in control. You can adjust your cookie settings anytime to suit your preferences. Feeling curious? Dive into our Privacy Policy for all the juicy details. Happy browsing! 🚀

Functional Always active
Listen, this legal stuff is about as exciting as watching paint dry. But it basically says we only use your stuff for what you asked us to do, and nobody else gets to peek!
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
It's those sneaky cookie crumbs websites leave behind to count visitors, like counting ants at a picnic! Totally harmless, just for fun facts. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
Hey there! Just letting you know we use some fancy gizmos to remember your preferences. This way, we can show you ads that are, well, not completely bananas.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Make cookies
{title} {title} {title}
Techweez | Tech News, Reviews, Deals, Tips and How To
Crunchy Cookies 🍪 Ahead!
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
Listen, this legal stuff is about as exciting as watching paint dry. But it basically says we only use your stuff for what you asked us to do, and nobody else gets to peek!
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
It's those sneaky cookie crumbs websites leave behind to count visitors, like counting ants at a picnic! Totally harmless, just for fun facts. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
Hey there! Just letting you know we use some fancy gizmos to remember your preferences. This way, we can show you ads that are, well, not completely bananas.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
Make cookies
{title} {title} {title}
No Result
View All Result
  • News
  • Reviews
  • Features
  • Editorial
  • Automotive
  • Entertainment

© 2024 Techweez - Palahala Media Group may earn a commission when you buy through links on our sites.
A Palahala Media Group Brand. All rights reserved.
.