
South Korean Attackers Are Trying to Get Into Your Microsoft Exchange Online
Attackers operating from South Korean infrastructure are systematically targeting organisational credentials via legacy email authentication, exploiting protocol gaps that bypass modern identity controls across many accounts.
A targeted credential stuffing campaign has been recorded originating from IP address 211.228.113.27, registered to infrastructure in South Korea. The source carries a maximum abuse confidence score of 100, confirming this address has been conclusively and repeatedly identified as malicious by the international security community. The attack leveraged Legacy SMTP authentication — an older protocol pathway that circumvents many modern conditional access controls — making the method a deliberate and informed choice by the threat actor rather than an opportunistic attempt.
The systematic targeting of multiple distinct accounts, rather than a single user, indicates the attacker arrived with a prepared list of valid or likely-valid credentials sourced from prior data breaches. This is the defining characteristic of credential stuffing: structured, automated testing of stolen username and password combinations at scale. The resulting account lockouts confirm that active credentials were being tested and that the campaign was not merely scanning infrastructure, but actively probing for access.
Legacy SMTP presents a disproportionate risk relative to the volume of attempts it attracts. Organisations that have invested significantly in modern authentication controls — including multi-factor authentication and conditional access policy — may still be exposed through this older protocol pathway if it has not been explicitly disabled. Threat actors actively catalogue environments where legacy protocols remain active, treating them as preferred targets precisely because the defences are weaker.
Each account involved in this campaign requires credential rotation and a thorough review of recent mailbox activity, including sent items, forwarding rules, and any OAuth application permissions that may have been modified. Organisations should implement a conditional access policy that blocks legacy authentication at the identity provider level, eliminating this attack surface across all current and future accounts. This incident should be treated as confirmation that legacy protocol exposure is being actively identified and exploited by international threat actors.
Signals about the attacker's network — abuse history, hosting provider, and the ISP's typical role. Bulletproof hosts and residential-proxy networks are the usual bad-actor infrastructure.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
Disable legacy authentication protocols; Enforce Multi-Factor Authentication (MFA) across all accounts; Apply geo-blocking for high-risk regions.

