A distributed brute force campaign, completely invisible to Microsoft SigninLogs.
The Autonomous Hunter uncovered a distributed brute force campaign that ran 33 failed logons from more than 20 international IPs, completely invisible to Microsoft SigninLogs.
OrgIdWsTrust2 is a legacy auth endpoint. Failed attempts bypass SigninLogs entirely. MFA and Conditional Access apply only after authentication, so attackers learn if a password is correct before any protection triggers. Standard SIEM rules are completely blind.
The attacker made one attempt per IP every 2 to 3 hours, rotating across India, Indonesia, Vietnam, Kenya, Egypt, Turkey, South Africa, and Europe — a classic slow distributed botnet, designed to evade rate limiting and threshold-based detection rules.
Broader scanning revealed a campaign targeting thousands of users across the org, all exploiting the same OrgIdWsTrust2 endpoint and all invisible to existing detection rules. Without behavioral anomaly detection, this runs indefinitely.