UNK_SneakyStrike is an unattributed account-takeover cluster active since December 2024 that targets Microsoft Entra ID accounts. The cluster has targeted more than 80,000 user accounts across approximately 100 cloud tenants, affecting hundreds of organizations, and has achieved multiple account takeovers. It abuses TeamFiltration, a publicly available penetration-testing framework, to enumerate users through the Microsoft Teams API and conduct distributed password-spraying operations using AWS infrastructure. Activity occurred in concentrated bursts separated by several days of inactivity and peaked in January 2025. Following successful compromise, the operators accessed Microsoft 365 services including Teams, OneDrive, and Outlook. Observed activity also included apparent user-agent spoofing intended to obscure the actual client or device used for authentication. UNK_SneakyStrike is distinct from the separately tracked TeamFiltration-related cluster UNK_CondorFiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously targeted over 80,000 user accounts across hundreds of organizations' cloud tenants using TeamFiltration.
Conducting an active account takeover campaign against Microsoft Entra ID accounts using the TeamFiltration framework for large-scale user enumeration, password spraying, access to Microsoft 365 resources, and resulting in multiple successful account takeovers.
Conducting account takeover campaigns against Microsoft Entra ID (Azure Active Directory) users using the open-source TeamFiltration tool.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.