EBurst is an open-source, Python-based password-attack tool used to compromise Microsoft Exchange and Microsoft 365 email accounts. It automates password spraying and password guessing against supplied email addresses, including attempts using a small number of common passwords across many accounts. Supported authentication interfaces include Exchange Control Panel, Exchange Web Services, Offline Address Book, Outlook Web Access, RPC, API, MAPI, PowerShell, Autodiscover, and Microsoft-Server-ActiveSync.
Chinese government-linked actors associated with Flax Typhoon and activity enabled by Integrity Technology Group have used EBurst for initial access to email accounts and cloud services. These operations have targeted critical infrastructure and other organizations across Southeast Asia, Africa, and North America. EBurst provides password-based account-compromise functionality; it is distinct from the persistence, credential-dumping, and email-exfiltration utilities used alongside it in those operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Flax Typhoon was also seen using ... the EBurst Microsoft Exchange password spraying tool for initial access.
The actors also use EBurst, an open source Python tool, to attack Microsoft Office 365 and Exchange email accounts through password spraying and password guessing.
“The threat actors use EBurst, an open source Python-based tool, to target accounts in the Microsoft Office365 Cloud environment.”
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offensive tool used to conduct password spraying against Exchange as part of initial access.
Offensive authentication-testing tool used to compromise email accounts through password spraying and guessing. It supports Exchange Control Panel, Exchange Web Services, Offline Address Book, and Outlook Web Access interfaces.
An open-source Python offensive tool used to automate password guessing against Microsoft 365 accounts. It appears in the joint advisory's account of attacks conducted by actors supported by Integrity Technology Group; no specific named operator is directly identified for this tool.
A Microsoft Exchange password-spraying tool used by Flax Typhoon to obtain initial access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.