EBurst Password Spraying and Mailbox Exfiltration
An adversary is conducting automated password spraying via the EBurst tool against Exchange interfaces and then using successful logins to exfiltrate mailbox data via cloud APIs.
Based on research by CISA 2026-10-09 9 steps · 3 queries T1041 T1110.001 T1110.003 T1190
Brief
Why this hunt
(CISA AA26-281A) The Cybersecurity and Infrastructure Security Agency (CISA) recently issued advisory AA26-281A, which details the tactics of Chinese government-linked cyber actors. These groups frequently combine automated tools like EBurst for password spraying with hands-on-keyboard activity to exfiltrate sensitive data. This hunt is designed to identify this specific progression from distributed credential access to cloud-based mailbox collection.
Phase 1: Scoping Exchange Authentication
The hunt begins by identifying Exchange endpoints experiencing high authentication failure rates. This initial scoping step queries the sign-in logs to aggregate failures per host. By focusing on services such as OWA, EWS, and Autodiscover, we narrow the search to the specific interfaces the EBurst tool exploits. An analyst uses this list of hostnames to populate the scope for the next phase, ensuring the hunt remains performant and focused on impacted infrastructure. This step provides the initial signal that a spray may be in progress.
Phase 2: Correlating Spraying and API Activity
Once we have the target hosts, the hunt executes parallel searches to identify source IPs and their subsequent actions. The first query isolates source IPs that attempt to authenticate against five or more unique user accounts. This metric helps distinguish between brute-force attacks on a single user and the broader spraying campaigns used by state-sponsored actors. Simultaneously, the hunt queries cloud API logs for mailbox-related operations like reading items, accessing folders, or updating messages. We specifically target the Microsoft 365 and Exchange provider logs to find high-volume calls coming from external sources. The core of the hunt is the correlation phase. An automated agent or a human investigator compares the IPs found in the password spray with the IPs interacting with mailbox resources. This connection provides a high-confidence signal that an account was not only targeted but successfully compromised and used for exfiltration.
Blind Spots and Limitations
This hunt relies on high-fidelity logging. Without Microsoft 365 Advanced Auditing (specifically the MailItemsAccessed operation), an analyst can see that a mailbox was accessed but not necessarily which specific messages the actor read or exported. Furthermore, if the adversary uses a large botnet to rotate IPs for every single login attempt, the activity may fall below the unique-user threshold defined in our queries. Analysts should consider pivoting to user-agent or ASN-based stacking if they suspect IP-masking is in play.
Running the Hunt
This hunt is provided as a hunt.md playbook. You can import it into Huntbase or any security operations platform that supports the hunt.md format. It uses SQLite DSL to process authentication events and cloud API activity. Because it is a hunt, not a static detection, it prioritizes the correlation of behavior over single-event alerts, allowing teams to find the low and slow activity characteristic of state-sponsored campaigns.
In this series
Steps
-
Scoping Exchange Auth Failures
Query · scopingIdentify Exchange servers or endpoints experiencing an unusual volume of authentication failures to narrow the hunt scope. Note: Populate the scope_hosts parameter with the hostnames discovered here for use in the subsequent ip-spray-detection step.
reads hb_auth_signinsqlSELECT device_hostname, COUNT(*) AS failure_count, MIN(time) AS first_fail, MAX(time) AS last_fail FROM hb_auth_signin WHERE status_id = 2 AND (instr(',' || '{{exchange_interfaces}}' || ',', ',' || UPPER(dst_endpoint_name) || ',') > 0 OR LOWER(service_name) LIKE '%exchange%' OR LOWER(logon_process_name) LIKE '%exchange%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING failure_count > 20 ORDER BY failure_count DESCWhat a hit looks like. A list of hosts acting as targets for auth failures. Silence suggests no broad spraying against Exchange targets is currently observable.
-
IP-based Password Spraying Detection
Query · baselineFind source IPs attempting to authenticate against multiple unique user accounts.
reads hb_auth_signinsqlSELECT src_endpoint_ip, COUNT(DISTINCT actor_user_name) AS unique_targets, COUNT(*) AS total_attempts, MIN(time) AS start_time FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip HAVING unique_targets >= 5 ORDER BY unique_targets DESCWhat a hit looks like. A few IPs targeting multiple unique users. Benign noise typically targets one user many times.
-
Unusual Mailbox API Operations
Query · enrichmentIdentify API activity targeting mailbox resources, specifically high-volume read or update operations.
reads hb_cloud_api_activitysqlSELECT src_endpoint_ip, actor_user_name, api_operation, api_service_name, resource_name, COUNT(*) AS call_count FROM hb_cloud_api_activity WHERE (provider = 'm365' OR api_service_name = 'Exchange') AND (LOWER(api_operation) LIKE '%mailbox%' OR LOWER(api_operation) LIKE '%message%' OR LOWER(api_operation) LIKE '%folder%') AND activity_id IN (2, 3) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, actor_user_name, api_operation, api_service_name, resource_name HAVING call_count > 10 ORDER BY call_count DESCWhat a hit looks like. High frequency of API calls targeting mailbox data per IP and account. This identifies post-auth data access.
-
Triage Auth and API Correlation
Agent triageEvaluate whether the observed auth failures, password sprays, and mailbox API activities constitute a confirmed compromise.
-
Route on Triage Verdict
DecisionRoute the hunt based on the agent's maliciousness verdict.
-
Suspend Compromised Identity
Response actionImmediately halt further data exfiltration by suspending the affected account.
-
Analyst Review of Exfiltration
Analyst taskConduct a manual review of the data accessed to determine the scope of exfiltration.
-
Hunt Close-out
Analyst taskFinalize the hunt and document any tuning notes for future detection rules.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| EBurst Password Spraying T1110.003 · T1110.001 |
Yes | scoping-exchange-auth, ip-spray-detection |
| Email Data Collection T1041 |
Yes | mailbox-api-activity |
| Web and Service Exploitation T1190 · T1189 |
Out of scope | Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series. |
| Malware Execution T1059.006 · T1059.007 · T1059.001 |
Out of scope | Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series. |
| VPN-based Persistence T1133 |
Out of scope | Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series. |
| Service and Process Masquerading T1036.003 |
Out of scope | Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series. |
| Multi-protocol Command and Control T1071 |
Out of scope | Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series. |
Blind spots
- Needs Microsoft 365 Advanced Auditing (MailItemsAccessed). Without Advanced Auditing, the API logs only show that a mailbox was accessed, not which specific items were viewed or exported, making it difficult to assess the exact impact of exfiltration. It would answer Which specific email messages were read by the adversary?. Remediation: Enable 'MailItemsAccessed' auditing for all critical mailboxes.
- Needs Source IP Geolocation and ASN context. If the adversary rotates IPs for every single login attempt, the per-IP unique user stack-count will fall below the detection threshold. It would answer Is the spray originating from a known botnet or common VPN providers?. Remediation: Pivot to user-agent and ASN stacking if per-IP spraying metrics are low.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
exchange_interfaces | list[string] | ECP, EWS, OAB, OWA, RPC, API, MAPI, Autodiscover, ActiveSync | Names of Exchange interfaces to monitor for password spraying. |
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Exchange servers or endpoints identified in the scoping step to focus the hunt. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Identity / sign-in telemetry | identity | identity |
Source
---
analysis: While a detection rule might alert on a single high-volume spray from an
IP, this hunt correlates that spraying behavior across multiple distinct Exchange
interfaces with follow-on cloud API operations against mailboxes, reducing noise
and identifying the complete attack chain.
blind_spots:
- id: cloud-logging-limitations
owner: Cloud Infrastructure Team
question: Which specific email messages were read by the adversary?
remediation: Enable 'MailItemsAccessed' auditing for all critical mailboxes.
requires: Microsoft 365 Advanced Auditing (MailItemsAccessed)
risk: Without Advanced Auditing, the API logs only show that a mailbox was accessed,
not which specific items were viewed or exported, making it difficult to assess
the exact impact of exfiltration.
stage: collection-mailbox-exfiltration
- id: ip-masking-via-botnets
owner: Security Engineering
question: Is the spray originating from a known botnet or common VPN providers?
remediation: Pivot to user-agent and ASN stacking if per-IP spraying metrics are
low.
requires: Source IP Geolocation and ASN context
risk: If the adversary rotates IPs for every single login attempt, the per-IP unique
user stack-count will fall below the detection threshold.
stage: credential-access-eburst-spraying
coverage:
- stage: credential-access-eburst-spraying
status: covered
steps:
- scoping-exchange-auth
- ip-spray-detection
- stage: collection-mailbox-exfiltration
status: covered
steps:
- mailbox-api-activity
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
stage: initial-access-vulnerability-exploitation
status: out_of_scope
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
stage: execution-malware-payload
status: out_of_scope
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
stage: persistence-vpn-installation
status: out_of_scope
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
stage: defence-evasion-masquerading
status: out_of_scope
- reason: Belongs to another part of the 'Chinese Government-linked Cyber Threat Actors
Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data' series.
stage: command-and-control-obfuscated-channels
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: Chinese state-linked actors are documented to use the EBurst tool
to target critical infrastructure for credential theft and mailbox exfiltration.
Identifying these campaigns before they reach full data exfiltration prevents
significant intelligence loss.
methodology: model-assisted
trigger: intel-report
hypothesis: An adversary is conducting automated password spraying via the EBurst
tool against Exchange interfaces and then using successful logins to exfiltrate
mailbox data via cloud APIs.
labels:
- hunt
- attack.t1110.003
- attack.t1110.001
- attack.t1041
- attack.t1190
- collection
- command and control
- credential access
- defense evasion
- execution
- initial access
- persistence
name: EBurst Password Spraying and Mailbox Exfiltration
parameters:
exchange_interfaces:
default:
- ECP
- EWS
- OAB
- OWA
- RPC
- API
- MAPI
- Autodiscover
- ActiveSync
description: Names of Exchange interfaces to monitor for password spraying.
from:
kind: article
observed: '2026-10-08'
ref: AA26-281A
type: list[string]
lookback_days:
default: '14'
description: Days of history to examine.
from:
kind: manual
observed: '2024-01-01'
ref: standard-retention
type: number
scope_hosts:
default: []
description: Exchange servers or endpoints identified in the scoping step to focus
the hunt.
from:
kind: manual
observed: '2024-01-01'
ref: analyst-defined
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Focus on high-value identity targets and servers hosting publicly accessible
Exchange interfaces (OWA, ActiveSync). Monitoring the Autodiscover service is critical
as it is a common target for the EBurst tool.
references:
- name: CISA AA26-281A - Chinese Government-linked Cyber Threat Actors
url: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a
related:
- hunt: softether-vpn-persistence-detection
reason: The same advisory identifies SoftEther VPN as a persistence mechanism used
after credential theft.
relation: sibling
- hunt: perimeter-exploitation-vpn-persistence
relation: follows
scenario:
stages:
- name: Web and Service Exploitation
observables:
- BBScan
- dirsearch
- Fscan
- ksubdomain
- masscan
- NMAP
- OneForAll
- ShuiZe
- wpscan
- MicroScan
- XSS payloads targeting JavaScript
- Exploits for CVE-2016-3081
- Exploits for CVE-2019-11510
- Exploits for CVE-2021-22205
- Targeting ports 21, 22, 53, 80, 443, 1080
- PHP/ASP enumeration
slug: initial-access-vulnerability-exploitation
tactic: initial-access
techniques:
- T1190
- T1189
- name: Malware Execution
observables:
- live700_v1.exe
- DiagTrack.exe
- Python-based exploit scripts
- Go-based exploit utilities
- Password-protected .zip files containing executables
slug: execution-malware-payload
tactic: execution
techniques:
- T1059.006
- T1059.007
- T1059.001
- name: VPN-based Persistence
observables:
- SoftEther VPN installers
- conhost.exe (renamed installer)
- dllhost.exe (renamed installer)
- curl or wget used to download SoftEther on Linux
- PowerShell used to download SoftEther on Windows
- Automatic reconnection configuration on startup
slug: persistence-vpn-installation
tactic: persistence
techniques:
- T1133
- name: Service and Process Masquerading
observables:
- DiagTrack.exe
- conhost.exe
- dllhost.exe
slug: defence-evasion-masquerading
tactic: defence-evasion
techniques:
- T1036.003
- name: EBurst Password Spraying
observables:
- EBurst tool
- Password spraying against ECP
- Password spraying against EWS
- Password spraying against OWA
- Password spraying against ActiveSync
- Password spraying against MAPI/RPC
slug: credential-access-eburst-spraying
tactic: credential-access
techniques:
- T1110.003
- T1110.001
- name: Multi-protocol Command and Control
observables:
- dns.studiocloud.xyz
- 98aiblog.com
- hmbcloud.com
- hmbcloud.net
- hmbiplc-01.com
- iepl.node.cm
- javacheck.ooguy.com
- javaupdate.giize.com
- sexytube0.com
- twimg.co.uk
- HTTP-based C2 communications
slug: command-and-control-obfuscated-channels
tactic: command-and-control
techniques:
- T1071
- name: Email Data Collection
observables:
- Querying user mailbox data via DiagTrack.exe
slug: collection-mailbox-exfiltration
tactic: collection
techniques:
- T1041
summary: Chinese government-linked threat actors, enabled by Integrity Technology
Group, use a combination of automated scanning tools like MicroScan and manual
exploitation to target global organizations. They establish persistence using
legitimate VPN software like SoftEther and perform large-scale password spraying
with EBurst to exfiltrate sensitive email data and credentials.
series:
index: 2
slug: chinese-government-linked-cyber-threat-actors-combine-automated-and-hands-on-hacking-tools-to-st
title: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on
Hacking Tools to Steal Sensitive Data
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
identity:
category: identity
name: Identity / sign-in telemetry
telemetry:
- identity
tlp: clear
type: investigation
---
# EBurst Password Spraying and Mailbox Exfiltration
This hunt targets the identity-focused tradecraft of Chinese government-linked actors. It begins by identifying Exchange endpoints experiencing high authentication failure rates, then fans out to identify specific source IPs conducting distributed password sprays across multiple accounts. Finally, it correlates these IPs with unusual mailbox-related API activity in the cloud control plane to detect post-compromise data collection and exfiltration.
## scoping-exchange-auth
<!-- Scoping Exchange Auth Failures -->
Identify Exchange servers or endpoints experiencing an unusual volume of authentication failures to narrow the hunt scope. Note: Populate the scope_hosts parameter with the hostnames discovered here for use in the subsequent ip-spray-detection step.
```sqlite target=identity role=scoping params=(lookback_days=lookback_days, exchange_interfaces=exchange_interfaces)
~~~yaml
expected: A list of hosts acting as targets for auth failures. Silence suggests no
broad spraying against Exchange targets is currently observable.
reads:
- device_hostname
- dst_endpoint_name
- logon_process_name
- service_name
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, COUNT(*) AS failure_count, MIN(time) AS first_fail, MAX(time) AS last_fail FROM hb_auth_signin WHERE status_id = 2 AND (instr(',' || '{{exchange_interfaces}}' || ',', ',' || UPPER(dst_endpoint_name) || ',') > 0 OR LOWER(service_name) LIKE '%exchange%' OR LOWER(logon_process_name) LIKE '%exchange%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING failure_count > 20 ORDER BY failure_count DESC
```
## correlate-activities
<!-- Correlate Auth and API Behavior -->
parallel:
- → ip-spray-detection
- → mailbox-api-activity
join: → triage-investigation
## ip-spray-detection
<!-- IP-based Password Spraying Detection -->
Find source IPs attempting to authenticate against multiple unique user accounts.
```sqlite target=identity role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A few IPs targeting multiple unique users. Benign noise typically targets
one user many times.
prevalence:
by: actor_user_name
key:
- src_endpoint_ip
rare_below: 5
reads:
- actor_user_name
- device_hostname
- src_endpoint_ip
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT src_endpoint_ip, COUNT(DISTINCT actor_user_name) AS unique_targets, COUNT(*) AS total_attempts, MIN(time) AS start_time FROM hb_auth_signin WHERE status_id = 2 AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip HAVING unique_targets >= 5 ORDER BY unique_targets DESC
```
## mailbox-api-activity
<!-- Unusual Mailbox API Operations -->
Identify API activity targeting mailbox resources, specifically high-volume read or update operations.
```sqlite target=endpoint role=enrichment params=(lookback_days=lookback_days)
~~~yaml
expected: High frequency of API calls targeting mailbox data per IP and account. This
identifies post-auth data access.
reads:
- activity_id
- actor_user_name
- api_operation
- api_service_name
- provider
- resource_name
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_cloud_api_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT src_endpoint_ip, actor_user_name, api_operation, api_service_name, resource_name, COUNT(*) AS call_count FROM hb_cloud_api_activity WHERE (provider = 'm365' OR api_service_name = 'Exchange') AND (LOWER(api_operation) LIKE '%mailbox%' OR LOWER(api_operation) LIKE '%message%' OR LOWER(api_operation) LIKE '%folder%') AND activity_id IN (2, 3) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY src_endpoint_ip, actor_user_name, api_operation, api_service_name, resource_name HAVING call_count > 10 ORDER BY call_count DESC
```
## triage-investigation
<!-- Triage Auth and API Correlation -->
```agent target=hunter
cite: required
context:
- scoping-exchange-auth
- ip-spray-detection
- mailbox-api-activity
max_iterations: 6
objective: Identify if any IP conducting a spray in the auth logs matches an IP performing
mailbox API operations. Determine if the accounts targeted in the spray were successfully
used for API access.
success_criteria: A verdict of malicious | suspicious | benign citing specific rows
for each host and account.
tools:
- endpoint
- identity
```
## route-on-verdict
<!-- Route on Triage Verdict -->
if~: "the triage verdict is malicious for at least one source IP and account pair" (confidence: high, judge=hunter)
then: → suspend-identity
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: cloud-logging-limitations)
else: → close-out
## suspend-identity
<!-- Suspend Compromised Identity -->
```action target=identity
~~~yaml
approval: required
~~~
Suspend the user account identified as compromised and revoke all active OAuth/MFA tokens.
```
→ analyst-review
## analyst-review
<!-- Analyst Review of Exfiltration -->
```manual target=analyst
Review the specific 'resource_name' entries in the mailbox API query. Identify if any mailbox redirection rules or auto-forwarding was configured by the attacker for persistence.
```
→ close-out
## close-out
<!-- Hunt Close-out -->
```manual target=analyst
Document the findings. If benign scanning IPs were found, recommend them for a global exclusion list to reduce future false positives.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.