{"id":39345,"date":"2022-07-13T09:30:00","date_gmt":"2022-07-13T09:30:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/39345"},"modified":"2022-07-13T09:30:00","modified_gmt":"2022-07-13T09:30:00","slug":"slippery-phish-wriggles-around-mfa-protections-says-microsoft","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=39345","title":{"rendered":"Slippery phish wriggles around MFA protections, says Microsoft"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/slippery-phish-wriggles-around-mfa-protections-says-microsoft.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>A large-scale <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/phishing\">phishing campaign<\/a> that has targeted more than 10,000 organisations since September 2021 used <a href=\"https:\/\/www.techtarget.com\/iotagenda\/definition\/man-in-the-middle-attack-MitM\">adversary-in-the-middle<\/a> (AiTM) phishing sites to steal passwords, hijack sign-in sessions and bypass authentication features, including <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252520645\/MFA-technology-is-rapidly-evolving-are-mandates-next\">multifactor authentication<\/a> (MFA).<\/p>\n<p>That is according to Microsoft\u2019s 365 Defender Research Team, which this week alerted users to the threat and <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/07\/12\/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud\/\">published the findings of its investigation<\/a>.<\/p>\n<p>The initial lure used by the attackers was an email informing the recipient that they needed to pick up a voicemail message.<\/p>\n<p>The subsequent attack chain exploited a feature held in common by every modern web service \u2013 the use of <a href=\"https:\/\/www.techtarget.com\/searchsoftwarequality\/definition\/cookie\">session cookies<\/a> after authentication that prove to the service that the user is authenticated to its website.<\/p>\n<p>But if the attacker deploys a webserver in between the user and the service website they want to visit, which proxies HTTP packets from the user to the service and vice versa, they essentially trick both the user into authenticating to the service using their credentials, and the service into returning a legitimate session cookie, both of which are then intercepted and stolen.<\/p>\n<p>In this campaign, the proxy website was the organisation\u2019s <a href=\"https:\/\/www.techtarget.com\/searchwindowsserver\/definition\/Active-Directory\">Azure Active Directory<\/a> logon page, but the same technique would work elsewhere.<\/p>\n<p>Once the attacker has both the credentials and the session cookies, they can inject it into their browser to skip the authentication process, even if MFA is enabled. Meanwhile, the unwitting victim proceeds about their business unaware that they have just had their pockets picked.<\/p>\n<p>This method is also more convenient for the attackers, because it means they can present the victim with a credible fake site \u2013 with only the URL being different \u2013 and do not need to expend effort creating a fake phishing site, as would more usually be the case.<\/p>\n<p>The attackers behind the campaign subsequently used the stolen credentials and session cookies to access mailboxes and exploit them to perform <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/business-email-compromise-BEC-man-in-the-email-attack\">business email compromise<\/a> (BEC) attacks against downstream targets.<\/p>\n<p>Commenting on the success of the campaign, <a href=\"https:\/\/www.cybsafe.com\/\">CybSafe<\/a> CEO and co-founder Oz Alashe said it was clear to see why individuals at so many organisations had been caught out by it.<\/p>\n<p>\u201cThe phishing campaign targeting Microsoft shows the methods attackers are using to steal people\u2019s credentials,\u201d he said. \u201cThese fake, lookalike login pages that 365 users were being directed to are difficult to detect to the untrained eye, so it is not surprising so many people and organisations have been caught out.<\/p>\n<p>\u201cOnce people enter their login credentials, attackers then have the keys to the enterprise digital kingdom, and from there they can access corporate files and take sensitive data.<\/p>\n<p>\u201cThe first, and most practical step in defending against these attacks is to support employees to login into 365 using their desktop app only \u2013 and make sure there are plenty of nudges to remind them. It\u2019s not enough to say it once \u2013 these attacks are designed to trick people into thinking \u2018oh this must be a new thing\u2019 or \u2018just this once must be needed\u2019.\u201d<\/p>\n<p>Alashe added: \u201cAny links sent in emails should always be treated with caution, and always double-check a URL to make sure it really does have the correct Microsoft 365 address (https:\/\/www.office.com\/) before clicking on it, or disclosing confidential information.\u201d<\/p>\n<p>Although <a href=\"https:\/\/www.computerweekly.com\/news\/252495081\/Should-I-be-worried-about-MFA-bypassing-pass-the-cookie-attacks\">MFA-bypassing attacks using similar techniques are nothing new<\/a>, and the attack chain does not exploit a vulnerability inherent to MFA technology, Microsoft said the campaign had concerning implications for users, and organisations could indeed do more to protect themselves.<\/p>\n<p>\u201cTo further protect themselves from similar attacks, organisations should also consider complementing MFA with&nbsp;<a href=\"https:\/\/docs.microsoft.com\/azure\/active-directory\/conditional-access\/overview\">conditional access<\/a>&nbsp;policies, where sign-in requests are evaluated using additional identity-driven signals like user or group membership, IP location information, and device status, among others,\u201d the team said in its write-up.<\/p>\n<p>\u201cWhile AiTM phishing attempts to circumvent MFA, it is important to underscore that MFA implementation remains an essential pillar in identity security. MFA is still very effective at stopping a wide variety of threats. Its effectiveness is why AiTM phishing emerged in the first place.\u201d<\/p>\n<p>Sharon Nachshony, a security researcher at Israel-based identity and access management (IAM) specialist <a href=\"https:\/\/www.silverfort.com\/\">Silverfort<\/a>, said: \u201cThis campaign is interesting because it outlines the creative approaches attackers will take to steal identities and the resultant domino effect once they have breached a network. <\/p>\n<p>\u201cBEC, the endgame in this attack, has been used historically to siphon hundreds of thousands of dollars from single organisations. If, as Microsoft states, there were 10,000 targets \u2013 that is a potentially huge return from compromised credentials.\u201d<\/p>\n<p>Nachshony added: \u201cWhile AiTM is not a new approach, obtaining the session cookie after authentication shows how attackers have had to evolve and take steps to try and sidestep MFA, which they hate. In addition to the steps outlined by Microsoft, an organisation could also defeat this attack by sending the legitimate user a location with the MFA request. This would defeat the problem posed by proxy servers, which would be in a different location, and ensure a more secure authentication process.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A large-scale phishing campaign that has targeted more than 10,000 organisations since September 2021 used adversary-in-the-middle (AiTM) phishing sites to steal passwords, hijack sign-in sessions and bypass authentication features, including multifactor authentication (MFA). That is according to Microsoft\u2019s 365 Defender Research Team, which this week alerted users to the threat and published the findings of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":39346,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-39345","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39345","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39345"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39345\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/39346"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}