Microsoft sounds the alarm over new wave of password spraying attacks

An image of security icons for a network encircling a digital blue earth.
(Image credit: Shutterstock)

Cybersecurity experts at Microsoft have warned against an increase in password spray attacks against cloud administrator accounts as well as high-profile identities such as C-level executives.

Password spraying is a type of brute force attack where the attackers use commonly used or previously compromised passwords repeatedly, but avoid triggering account lookouts by attacking different accounts. 

“Over the past year, the Microsoft Detection and Response Team (DART), along with Microsoft’s threat intelligence teams, have observed an uptick in the use of password sprays as an attack vector,” shared DART

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

The group says that identity attacks, such as password sprays, have become popular of late since best practices such as complex password policies and limiting access to resources prove to be ineffective at preventing unauthorized access.

Moving target

Just about a week ago researchers from Microsoft had shared that Nobelium, the threat actor behind last year’s widely-reported SolarWinds campaign, had been attacking IT services organizations including cloud service providers (CSP), with password spraying attacks.

In the new post, DART explains that it has seen a recent uptick in password spray attacks against administrator accounts, adding that threat actors are constantly evolving their tools and techniques, forcing the group to find new ways to detect the attacks.

The recent spate of attacks has targeted users with privileged access. These include global administrators, security administrators, SharePoint administrators, Microsoft Exchange administrators, helpdesk administrators, billing administrators, and others with similar access.

“It is easy to make exceptions to policy for staff who are in executive positions, but in reality, these are the most targeted accounts,” asserts DART as it shares recommendations for protecting against them.

In the post DART recommends disabling legacy authentication, and instead switching to multi-factor authentication (MFA) across all accounts. 

This doesn’t mean we should give up on passwords altogether, but the rabbit hole of password policies, and the potentially endless discussions about complexity, length, and “correct battery horse staple” should be avoided in favor of applying Zero Trust logic to identity and authentication.

One way to thwart identity attacks is to use one of the best security keys around today!

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A padlock resting on a keyboard.
Massive botnet is targeting Microsoft 365 accounts across the world
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
A hand laying out a password
Security attacks on password managers have soared
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)