• News/
  • https://www.bleepingcomputer.com/news/security/hackers-use-fasthttp-in-new-high-speed-microsoft-365-password-attacks/

Hackers use FastHTTP in new high-speed Microsoft 365 password attacks

BleepingComputer
·
Bill Toulas
·
Published Jan 14, 2025
·
Updated

Threat actors are utilizing the FastHTTP Go library to launch high-speed brute-force password attacks targeting Microsoft 365 accounts globally. The campaign was recently discovered by incident response firm SpearTip, who said the attacks began on January 6, 2025, targeting the Azure Active Directory Graph API. The researchers warn that the brute-force attacks have to successful account takeovers 10% of the time. FastHTTP is a high-performance HTTP server and client library for the Go programming language, optimized for handling HTTP requests with improved throughput, low latency, and high efficiency even when used with numerous concurrent connections. In this campaign, it is leveraged to create HTTP requests to automate attempts at unauthorized logins. SpearTip says all requests target the Azure Active Directory endpoints to either brute-force passwords or repeatedly send multi-factor authentication (MFA) challenges to overwhelm targets in MFA Fatigue attacks. SpearTip reports that 65% of the malicious traffic originates from Brazil, leveraging a broad range of ASN providers and IP addresses, followed by Turkey, Argentina, Uzbekistan, Pakistan, and Iraq. The researchers say that 41.5% of the attacks fail, 21% lead to account lockouts imposed by protection mechanisms, 17.7% are rejected due to access policy violations (geographic or device compliance), and 10% were protected by MFA. This leaves 9.7% of cases where the threat actors successfully authenticate to the target acc...

Read full article

Affected Software

5 affected components
Microsoft Microsoft 365
Microsoft Azure Active Directory
FastHTTP Go library
Microsoft Microsoft 365
Microsoft Azure Active Directory
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses high-speed brute-force password attacks targeting Microsoft 365 accounts using the FastHTTP Go library.

2

What security implications are discussed in the article?

The article highlights the risk of compromised Microsoft 365 accounts due to sophisticated brute-force attacks.

3

Who discovered this password attack campaign?

The password attack campaign was discovered by the incident response firm SpearTip.

4

Which products or software are specifically mentioned as affected?

The affected products include Microsoft 365 and Azure Active Directory.

5

What method are hackers using to execute these attacks?

Hackers are utilizing the FastHTTP Go library to perform high-speed brute-force attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203