CISA warns of Exchange password spraying and automated email theft
News
Published 9 Oct 2026
Updated 9 Oct 2026
8 min read
Summarize with

On October 8, 2026, the FBI, CISA, NSA, and international partners published joint advisory AA26-281A. It describes China-linked actors using password spraying against Microsoft Exchange interfaces and automated tools to collect email from on-premises and Microsoft 365 mailboxes. The FBI says the activity was enabled by Integrity Technology Group, a China-based company linked to the Chinese government.
This is a newly published account of activity investigated across several years. It is not evidence that a new Exchange attack began this week. The agencies did not announce a new Exchange zero-day, a Microsoft service breach, a victim total, or a universal remediation deadline. The CISA announcement frames the release as a warning to hunt for compromise and reduce exposure.
What the agencies found
The advisory attributes the activity to China-linked threat actors enabled by Integrity Technology Group. It says their tactics, techniques, and procedures are consistent with activity publicly tracked as Flax Typhoon, Ethereal Panda, and Red Juliett, among others. That wording matters. It does not prove that every observed action came from one actor identity, and the agencies note that some related actors also conduct activity outside Integrity Technology Group's support.
Attribution boundary
Treat Flax Typhoon, Ethereal Panda, and Red Juliett as overlaps in observed TTPs, not interchangeable names for one conclusively proven operator. Incident reports should preserve that distinction.
The FBI recovered an archived email database and observed theft from both on-premises systems and cloud services. Named victim categories included government bodies, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia. The wider campaign also reached US critical infrastructure, education, information technology, and organizations across Southeast Asia, Africa, and North America.
The evidence covers scanning, exploitation, credential attacks, persistence through VPN software, Active Directory credential access, and data collection. I read the email-specific sequence more narrowly: identify reachable Exchange authentication paths, detect repeated login attempts, inspect successful access that follows them, and look for large or unusual mailbox collection.
How Exchange and Microsoft 365 mail theft worked
EBurst is an open-source Python tool used to spray or guess passwords across multiple Exchange interfaces. The advisory lists EWS, OWA, ECP, Autodiscover, ActiveSync, OAB, RPC, MAPI, PowerShell, and API paths. Defenders who watch only an interactive webmail login can miss activity aimed at other endpoints.
|
|
|---|---|
EWS | Mailbox data access |
OWA and ECP | Web authentication |
Autodiscover | Account discovery |
ActiveSync | Mobile access |
OAB, RPC, MAPI | Legacy client paths |
PowerShell and API | Programmatic access |
Exchange paths named in AA26-281A

Observed path from an exposed Exchange interface to password spraying, account access, mail collection, and remote upload.
After access, Curlc4.txt provided automated collection through the EWS API. The PHP bot could obtain email plus calendar and contact content, compress the results, and upload them to remote infrastructure. The advisory says it appeared to operate as a stand-alone tool rather than being installed on a compromised device. Searching only the Exchange host filesystem for that filename is therefore an incomplete hunt. EWS logs, account activity, network telemetry, and the advisory's published indicators all matter.
The office-cli utility addressed Microsoft 365 mail. It automated access to Outlook 365 accounts with configuration values such as client_id, tenant_id, and secret, then saved collected data into dump directories. Because this used legitimate access methods, teams need to audit connected cloud applications, application credentials, consent, mailbox access, and unusual collection patterns. A password reset alone does not revoke every token or application secret.
What Exchange and Microsoft 365 teams should do
I would start with exposure and identity controls, then hunt across the full authentication surface. The first column below tracks agency-backed priorities. The second adds operator scoping steps based on the email-specific behavior in the advisory.
Agency-backed priorities
- Inventory: Identify externally reachable Exchange authentication interfaces and unused services.
- MFA: Require MFA, particularly for webmail, VPN access, and critical accounts.
- Credentials: Use strong unique passwords, remove defaults, and restrict administrative privilege.
- Monitoring: Review access logs, abnormal logins, unexpected uploads, and connected cloud applications.
Operator scoping additions
- Correlate: Link failed sprays to later successful sessions and mailbox access.
- Audit apps: Review mail-reading permissions, secrets, consent grants, and service principals.
- Inspect EWS: Check access frequency, mailbox breadth, source addresses, and export volume.
- Preserve: Retain logs and artifacts before broad eviction changes erase useful evidence.
Patch supported infrastructure and disable services only after checking business dependencies. Exchange teams should pay special attention to old client paths that remain enabled for a small number of users or devices. Removing an interface without validating those dependencies can interrupt mail access, while leaving it exposed without monitoring preserves an avoidable entry point.
No new Exchange deadline
AA26-281A does not establish a specific new Exchange CVE or a universal email remediation deadline. Do not apply KEV deadlines for unrelated BIND, Struts, or FTP vulnerabilities to Exchange systems. Prioritize confirmed exposure, observed activity, vendor-supported patching, and incident severity.
MFA has the highest value when it covers every reachable authentication route and uses a strong method. Conditional access, disabled legacy authentication, least privilege, and tightly governed application permissions reduce paths that a password-only control leaves open. For a related example of cloud mailbox access through a different login flow, see the report on Forg365 device code attacks.
Why SPF, DKIM, and DMARC do not stop mailbox compromise
SPF, DKIM, and DMARC authenticate how a domain is used in outgoing mail. They do not secure a mailbox login, enforce MFA, revoke OAuth access, or stop someone who has valid account or application credentials. AA26-281A does not describe a DMARC, SPF, or DKIM bypass. It also does not report measured sender-reputation harm or an outgoing-spam incident.
Mailbox security controls
MFA, authentication policy, access logging, application governance, session revocation, and incident response protect access to stored mail and cloud data.
Domain authentication controls
SPF, DKIM, and DMARC help receiving systems evaluate authorized domain use in sent mail. They address spoofing and authentication, not mailbox login.
That separation does not make domain authentication optional. A compromised mailbox and a spoofed domain create different risks, so both control sets need owners. Suped is our DMARC platform, and its role in this workflow is limited to the domain-authentication side. Suped's DMARC monitoring helps teams review SPF, DKIM, and DMARC results, stage policy changes, and investigate unauthorized sending sources. It does not detect EWS exfiltration or password spraying.
For most teams that need a practical DMARC control plane, Suped is the best overall option because it combines issue detection, guided fixes, hosted policy management, alerts, and multi-domain reporting. Keep the workflow evidence-based: use a domain health check for DNS authentication posture, then test a real email to inspect the message that receivers actually evaluate. Treat those results as a separate workstream from the Exchange and Microsoft 365 access investigation.
How to respond when compromise is suspected
Preserve enough evidence to understand the intrusion before making broad changes, while containing accounts or hosts that present an immediate risk. The agencies recommend identifying and isolating compromised hosts, starting threat hunting, reporting through the appropriate national channel, applying eviction measures, and hardening the network afterward.
- Preserve evidence: Retain Exchange, identity, EWS, web application, VPN, firewall, endpoint, and cloud audit logs. Record time ranges and affected accounts.
- Scope access: Correlate password attempts, successful sessions, mailbox operations, application consent, token use, and outbound transfers.
- Contain safely: Isolate compromised hosts and accounts, block confirmed indicators, and keep business owners informed about service impact.
- Recover identity: Reset affected credentials, revoke sessions and tokens, rotate application secrets, review delegated access, and remove unauthorized applications.
- Validate closure: Confirm that spraying has stopped, mailbox access is expected, exposed services are justified, and detections cover every retained interface.
Use the IOCs in the advisory as leads, not as the complete definition of compromise. Password spraying and legitimate cloud access often leave identity and behavior evidence that survives changes in source infrastructure. An organization can have no IOC match and still need to investigate an unusual successful login followed by broad EWS collection.
Do not stop at password resets
If cloud applications, refresh tokens, delegated permissions, or application secrets were abused, changing the user's password leaves other access paths active. Recovery must cover credentials, sessions, tokens, permissions, and application secrets.
The practical takeaway
AA26-281A gives Exchange and Microsoft 365 defenders a concrete reason to review every exposed authentication interface and every application that can read mail. The most useful action is not a search for one filename. It is a joined investigation across failed logins, successful sessions, EWS behavior, cloud application access, and outbound data movement.
Keep the claims bounded. The agencies documented investigated activity with long-running roots, not a new Exchange zero-day or a breach of Microsoft's service. They also did not find an email-authentication bypass. Protect mailbox access with identity and incident-response controls, and operate SPF, DKIM, and DMARC as a distinct defense against domain spoofing.

