Posts

Showing posts with the label MFA

Massive SMS stealer campaign infects Android devices in 113 countries

Image
By Bill Toulas,  Bleeping Computer A malicious campaign targeting Android devices worldwide utilizes thousands of Telegram bots to infect devices with SMS-stealing malware and steal one-time 2FA passwords (OTPs) for over 600 services. Zimperium researchers discovered the operation and have been tracking it since February 2022. They report finding at least 107,000 distinct malware samples associated with the campaign. The cybercriminals are motivated by financial gain, most likely using infected devices as authentication and anonymization relays. Telegram entrapment The SMS stealer is distributed either through malvertising or Telegram bots that automate communications with the victim. In the first case, victims are led to pages mimicking Google Play, reporting inflated download counts to add legitimacy and create a false sense of trust. On Telegram, the bots promise to give the user a pirated application for the Android platform, asking for their phone number before they share the ...

The Biggest Takeaways from Recent Malware Attacks

Image
Among the never-ending list of malicious software that threat actors use in cyber attacks are viruses, worms, trojans, ransomware, spyware, and adware. Today's malware is not just about causing immediate damage; some programs get embedded within systems to siphon off data over time, disrupt operations strategically, or lay the groundwork for massive, coordinated attacks.  A prime example is a recently found malicious backdoor in a popular compression tool, known as xz Utils. Thankfully the malicious code was identified early “due to bad actor sloppiness”, but the consequences could’ve been massive. Read on to get the lowdown on recent high-profile malware attacks along with strategies to help limit malware risks at your organization.  Recent High-Profile Malware Attacks Here's a detailed overview of recent malware attacks, highlighting key incidents and offering valuable insights and lessons learned from each event. StripedFly A prolific and advanced cross-platform malware fra...

Recent ‘MFA Bombing’ Attacks Targeting Apple Users

Image
By  KrebsOnSecurity Several Apple customers recently reported being targeted in elaborate phishing attacks that involve what appears to be a bug in Apple’s password reset feature. In this scenario, a target’s Apple devices are forced to display dozens of system-level prompts that prevent the devices from being used until the recipient responds “Allow” or “Don’t Allow” to each prompt. Assuming the user manages not to fat-finger the wrong button on the umpteenth password reset request, the scammers will then call the victim while spoofing Apple support in the caller ID, saying the user’s account is under attack and that Apple support needs to “verify” a one-time code. Parth Patel is an entrepreneur who is trying to build a startup in the conversational AI space. On March 23, Patel documented on Twitter/X a recent phishing campaign targeting him that involved what’s known as a “push bombing” or “MFA fatigue” attack, wherein the phishers abuse a feature or weakness of a multi-factor au...

Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks

Image
By  The Hacker News Key Points MuddyWater Phishing : MuddyWater used seemingly harmless PDF attachments containing malicious links. Clicking these links downloaded an installer for the real Atera Agent (RMM software), granting them unauthorized access to compromised systems. Shift in Tactics : This campaign represents a shift for MuddyWater, who previously relied on directly embedded malicious links. This new tactic increases deception and potentially widens their attack reach. MuddyWater Targets : This is not the first time MuddyWater has targeted organizations. Since October 2023, they’ve used other legitimate remote access tools for infiltration attempts. Supply Chain Attack : Another Iranian group, Lord Nemesis, compromised a software provider in a supply chain attack, potentially impacting their clients. Dangers of Supply Chain Attacks : This attack highlights the growing risk of supply chain attacks, where compromising a trusted vendor grants access to a wider network of targ...

New MFA-bypassing phishing kit targets Microsoft 365, Gmail accounts

Image
By Bill Toulas,  Bleeping Computer Cybercriminals have been increasingly using a new phishing-as-a-service (PhaaS) platform named 'Tycoon 2FA' to target Microsoft 365 and Gmail accounts and bypass two-factor authentication (2FA) protection. Tycoon 2FA was discovered by Sekoia analysts in October 2023 during routine threat hunting, but it has been active since at least August 2023, when the Saad Tycoon group offered it through private Telegram channels. The PhaaS kit shares similarities with other adversary-in-the-middle (AitM) platforms, such as Dadsec OTT, suggesting possible code reuse or a collaboration between developers. In 2024, Tycoon 2FA released a new version that is stealthier, indicating a continuous effort to improve the kit. Currently, the service leverages 1,100 domains and has been observed in thousands of phishing attacks.

Microsoft: Phishing bypassed MFA in attacks against 10,000 orgs

Image
By Sergiu Gatlan,  Bleeping Computer Microsoft says a massive series of phishing attacks has targeted more than 10,000 organizations starting with September 2021, using the gained access to victims' mailboxes in follow-on business email compromise (BEC) attacks. The threat actors used landing pages designed to hijack the Office 365 authentication process (even on accounts protected by multifactor authentication (MFA) by spoofing the Office online authentication page. In some of the observed attacks, the potential victims were redirected to the landing pages from phishing emails using HTML attachments that acted as gatekeepers ensuring the targets were being sent via the HTML redirectors. After stealing the targets' credentials and their session cookies, the threat actors behind these attacks logged into the victims' email accounts. They subsequently used their access in business email compromise (BRC) campaigns targeting other organizations. "A large-scale phishing cam...

Toll fraud malware continues to evolve, says Microsoft: Here's how Android users can protect themselves

Toll fraud, one of the most prevalent types of Android malware, continues to evolve. In a blog post on Thursday, the Microsoft 365 Defender Research Team revealed the details of this threat - how it operates, how analysts can better identify such threats, and how Android security can be improved to mitigate this threat. According to Microsoft's blog, toll fraud malware is a subcategory of billing fraud in which malicious applications subscribe users to premium services without their knowledge or consent. The malware accounted for 34.8% of installed Potentially Harmful Application (PHA) from the Google Play Store in the first quarter of 2022, ranking second only to spyware. The malware has unique behaviors. While SMS or call frauds use a simple attack flow to send messages or calls to a premium number, toll fraud has a complex multi-step attack flow that malware developers continue to improve. Microsoft security researchers observed new capabilities related to how this threat target...

Clever phishing method bypasses MFA using Microsoft WebView2 apps

By Lawrence Abrams,  Bleeping Computer A clever, new phishing technique uses Microsoft Edge WebView2 applications to steal victim's authentication cookies, allowing threat actors to bypass multi-factor authentication when logging into stolen accounts. With the large number of data breaches, remote access trojan attacks, and phishing campaigns, stolen login credentials have become abundant. However, the increasing adoption of multi-factor authentication (MFA) has made it difficult to use these stolen credentials unless the threat actor also has access to the target's one-time MFA passcodes or security keys. This has led to threat actors and researchers coming up with new ways of bypassing MFA, including zero-day website vulnerabilities, reverse proxies, and clever techniques, such as the Browser in the Browser attack and utilizing VNC to display remote browsers locally. This week, cybersecurity researcher mr.d0x has created a new phishing method that uses Microsoft Edge WebView2...

Russian state hackers swap malware with cloud-based attacks

By Vilius Petkauskas,  Cybernews Russian adversaries increasingly focus on targeting the cloud environment, Crowdstrike’s Global Threat Report on Cloud Security revealed. Fancy Bear, a Russian adversary associated with Russia’s Main Intelligence Directorate (GRU), used to rely on malware-based spear-phishing attacks, the report claims. However, with their tactics exposed by the US Department of Justice (DoJ), hackers have refocused their attention on cloud service providers. Since Fancy Bear’s primary source of intelligence comes from various credential harvesting practices that allow penetrating target organizations and individuals, it’s no surprise that the main targets are cloud-based email providers. According to the report, Fancy Bear focused their attention on service providers such as Microsoft 365, Google’s GSuite, as well as webmail providers that individuals usually use. Meanwhile, Cozy Bear, Russia’s state-sponsored hacker group controlled by the Federal Security service...

Has Your Facebook Account Been Hacked? You May Never Get it Back

The problem is, you can't speak to a real human being to explain what happened and ask for help. By Matthew Humphries, PC Mag Have you ever wondered what happens if your Facebook account gets hacked? It turns out your account could be lost forever and there's absolutely nothing you can do about it. That's the ordeal exercise physiologist Emily Cordes is currently experiencing . Last week, she decided to access Facebook Marketplace and discovered she was logged out of her Facebook account. Her login credentials no longer worked and the password recovery process failed to send a verification code. Then she noticed the primary email address associated with the account was no longer hers, confirming she'd been hacked. The person in control of the account had enabled two-factor authentication, then started posting spammy ads for Alaskan crab meat, which led to the account being suspended. Cordes now faces a race against time to regain control of her account in the 30-day per...

Hackers steal WhatsApp accounts using call forwarding trick

Image
By Ionut Ilascu, Bleeping Computer There’s a trick that allows attackers to hijack a victim’s WhatsApp account and gain access to personal messages and contact list. The method relies on the mobile carriers’ automated service to forward calls to a different phone number, and WhatsApp’s option to send a one-time password (OTP) verification code via voice call. The MMI code trick Rahul Sasi, the founder and CEO of digital risk protection company CloudSEK, posted some details about the method saying that it is used to hack WhatsApp account.  BleepingComputer tested and found that the method works, albeit with some caveats that a sufficiently skilled attacker could overcome. It takes just a few minutes for the attacker to take over the WhatsApp account of a victim, but they need to know the target’s phone number and be prepared do some social engineering. Sasi says that an attacker first needs to convince the victim to make a call to a number that starts with a Man Machine Interface (M...

Password safety: How do hackers steal your information?

By Rich DeMuro, Nexstar Media Wire Ever wonder how hackers get your password and gain access to your account? Recent research has identified several major ways: Password theft Password guessing Unauthorized password resetting or bypass “The biggest reason why people hate passwords is they’re all being told that they all need to be longer and longer and more complex,” started Roger Grimes, a Data-Driven Defense Evangelist at security awareness training company KnowBe4. He says phishing emails are a top way hackers get our passwords. You’ve seen them before — they say your Netflix account is about to be deactivated, your Facebook account has a copyright issue or something needs to be fixed with your Instagram. They trick us into handing over our information by making us log into a page that looks like the real thing but instantly sends our username and password to hackers, who immediately take over our accounts. Another way your password gets out into the wild: when a website is hack...

Phishing Campaign by Russian Hackers Uses Trello, Dropbox to Target Diplomats

By Scott Ikeda, CPO Magazine A newly-uncovered phishing campaign is targeting diplomats by presenting malicious messages as official embassy communications, and basing out of legitimate cloud-based services such as DropBox and Trello to aid in evading detection and remediation. The scheme was uncovered by security firm Mandiant , who believe that state-backed Russian hackers are behind it. Embassies targeted by Russian hackers The phishing campaign is just one element of a rash of recent activity by advanced persistent threat group 29 (APT 29), probably better known to the general public as “Cozy Bear.” Believed to be backed by Russian intelligence, the group conducted a similar operation in 2021 that focused on compromising diplomats via legitimate-looking Constant Contact emails. Mandiant says that the current phishing campaign makes use of legitimate email addresses that have been previously compromised, and opens with what appears to be an administrative notice from an embassy. The...

How Google passwordless sign-in will work

Image
By Chris Smith, BGR The first Thursday of May each year is World Password Day, which explains all the password-related announcements we saw this week. First, 1Password 8 for Mac launched with a few big new features. Then, Google started rolling out its Google Assistant password-changing feature. More importantly, Apple, Google, and Microsoft have announced plans to support passwordless sign-in . That last one is a massive cross-platform initiative that will bring us closer to killing passwords. In turn, this could significantly boost the security of online accounts, making them a lot harder to hack. It’ll take some time for websites and apps to support passwordless sign-in. But Google already gave us an idea of how it’ll all work. Proper password practices can help prevent hacks right now. You don’t need passwordless sign-in options if you’re already using unique, long passwords in connection with a password manager like 1Password or LastPass. These passwords are much harder to hack, e...

Microsoft warns Exchange Online basic auth will be disabled

By Sergiu Gatlan, Bleeping Computer Microsoft warned customers today that it will start disabling Basic Authentication in random tenants worldwide on October 1, 2022. This reminder comes after the company's September announcement and after seeing that there are still lots of customers who haven't yet moved their clients and apps to Modern Authentication. Basic Authentication (aka proxy authentication) is an HTTP-based auth scheme apps use to send locally stored credentials in plain text to servers, endpoints, or online services. This allows attackers to capture credentials via man-in-the-middle attacks over TLS or guess them in password spray attacks. They can steal the clear text credentials from apps using basic auth using various tactics, including info stealing malware and social engineering. Modern Authentication (Active Directory Authentication Library and OAuth 2.0 token-based authentication) uses OAuth access tokens with a limited lifetime that can't be re-used to a...

Cybersecurity Stocks Increase—Bad News for US Businesses and Agencies?

Image
By Griffin Davis, Tech Times Cybersecurity stocks are now increasing as more people invest in security firms. This may sound like a good thing since the industry that focuses on preventing hackers, and other online attackers is further growing.   A participant looks at lines of code on a laptop on the first day of the 28th Chaos Communication Congress (28C3) - Behind Enemy Lines computer hacker conference on December 27, 2011 in Berlin, Germany. The Chaos Computer Club is Europe's biggest network of computer hackers and its annual congress draws up to 3,000 participants. However, this is bad news for some U.S. companies and government agencies. Among the cybersecurity firms that experience share increases are FireEye Inc. and Crowdstrike Holdingfs Inc.  "It's really the pure-play security companies that do threat detection that are the ones that can be the direct beneficiary of something like this," said Mandeep Singh, an intelligence analyst working for Bloomberg.  ...