Threat actors are utilizing the FastHTTP Go library to launch high-speed brute-force password attacks targeting Microsoft 365 accounts globally. The campaign was recently discovered by incident response firm SpearTip, who said the attacks began on January 6, 2025, targeting the Azure Active Directory Graph API. The researchers warn that the brute-force attacks have to successful account takeovers 10% of the time. FastHTTP is a high-performance HTTP server and client library for the Go programming language, optimized for handling HTTP requests with improved throughput, low latency, and high efficiency even when used with numerous concurrent connections. In this campaign, it is leveraged to create HTTP requests to automate attempts at unauthorized logins. SpearTip says all requests target the Azure Active Directory endpoints to either brute-force passwords or repeatedly send multi-factor authentication (MFA) challenges to overwhelm targets in MFA Fatigue attacks. SpearTip reports that 65% of the malicious traffic originates from Brazil, leveraging a broad range of ASN providers and IP addresses, followed by Turkey, Argentina, Uzbekistan, Pakistan, and Iraq. The researchers say that 41.5% of the attacks fail, 21% lead to account lockouts imposed by protection mechanisms, 17.7% are rejected due to access policy violations (geographic or device compliance), and 10% were protected by MFA. This leaves 9.7% of cases where the threat actors successfully authenticate to the target acc...
Hackers use FastHTTP in new high-speed Microsoft 365 password attacks
BleepingComputer
·Bill Toulas
·Published Jan 14, 2025
·Updated
Affected Software
5 affected components
Microsoft Microsoft 365
Microsoft Azure Active Directory
FastHTTP Go library
Microsoft Microsoft 365
Microsoft Azure Active Directory
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses high-speed brute-force password attacks targeting Microsoft 365 accounts using the FastHTTP Go library.
2
What security implications are discussed in the article?
The article highlights the risk of compromised Microsoft 365 accounts due to sophisticated brute-force attacks.
3
Who discovered this password attack campaign?
The password attack campaign was discovered by the incident response firm SpearTip.
4
Which products or software are specifically mentioned as affected?
The affected products include Microsoft 365 and Azure Active Directory.
5
What method are hackers using to execute these attacks?
Hackers are utilizing the FastHTTP Go library to perform high-speed brute-force attacks.