Security researchers have spotted a new type of low-and-slow brute-force attack aimed at Office 365 accounts. The attacks have been going on since May 2017, and have gone through two distinct phases, both devilishly clever in their approach. Attackers used a small botnet of 67 IP addresses spread over 12 networks trying to break into the system accounts of 48 companies in total, Skyhigh says. The attack is launched using a relatively small network of 83 confirmed IPs distributed across 63 networks.
Source: https://www.bleepingcomputer.com/news/security/devilishly-clever-knockknock-attack-tries-to-break-into-system-email-accounts/