
Black Basta Affiliates Target Over 80,000 Microsoft Entra ID Accounts Using TeamFiltration and Exploit SimpleHelp Flaws in 2025 Attacks
Former affiliates of the Black Basta ransomware group have resumed cyberattacks in 2025 by leveraging Microsoft Teams phishing combined with Python scripts to covertly hijack networks. Approximately half of these attacks originate from legitimate-looking Microsoft domains, complicating detection by security teams. A recent campaign targeted over 80,000 Microsoft Entra ID accounts using an open-source tool called TeamFiltration. Attackers exploited the Microsoft Teams API and Amazon Web Services (AWS) servers globally to conduct password spraying, data exfiltration, and establish persistent access within compromised systems. Additionally, ransomware groups have been exploiting unpatched vulnerabilities in the remote access software SimpleHelp to carry out double extortion attacks on victims. The ongoing abuse of TeamFiltration for Entra ID account takeovers has been highlighted by cybersecurity sources.
Sources
Infosec Alevski 💻🕵️♂️Threat Actor Abuses TeamFiltration for Entra ID Account Takeovers: https://t.co/OWC5aJYdMt by darkreading #infosec #cybersecurity #technology #news
Infosec Alevski 💻🕵️♂️Ransomware Gangs Exploit Unpatched SimpleHelp Flaws to Target Victims with Double Extortion: https://t.co/qhOKDCXtyI by The Hacker News #infosec #cybersecurity #technology #news
Nicolas KrassasOver 80,000 Microsoft Entra ID Accounts Targeted Using Open-Source TeamFiltration Tool https://t.co/C3DnjTM5j8

