Home Blog Page 121

Decoding the SolarWinds Hack

decoding the SolarWinds hack, CISO MAG interview

After Thanksgiving, the working class, especially the IT workforce, CISOs and CIOs, would have loved to sit back and sip on hot chocolate during the holiday season. After all, the COVID-19 pandemic stretched their resources beyond imagination as they worked around the clock to secure remote workforce and support business continuity plans. But this was a distant dream! There was a ticking time bomb waiting to explode, and when it did, forget hot chocolate, the cybersecurity industry found itself in a hot mess with SolarWinds.

The SolarWinds attack was discovered in mid-December last year and has since been in the news showcasing the extent of damages it has caused. The gravity of the situation seemed low at the beginning, with tech companies like Microsoft and FireEye claiming they had devised a “Killswitch” for the hack. But soon, the can of worms was opened when the White House issued an official statement accepting that multiple Federal Agencies were targeted in the hack. The situation got messier when Microsoft and Malwarebytes issued statements of compromise on how their source code was accessed in the attack.

Questions were left unanswered. So, we decided to bring you definitive answers to your what, when, why, and how of the SolarWinds hack. In a fireside chat with Mihir Bagwe,Tech Writer at CISO MAG, Pushkar Tiwari, Director Development at Symantec Enterprise Division of Broadcom Inc., unfolds the entire episode. Tiwari has closely followed and analyzed the modus operandi of the hack.

He has been leading Data Loss Prevention (DLP) and Cloud Access Security Broker (CASB) solutions in his current role and has more than 15 years of experience in cybersecurity and enterprise software.

Edited excerpts from the interview follow:

1. The Biggest Hack?

decoding the SolarWinds hack

A.

The hack has impacted more than 18,000 customers of SolarWinds across the globe. This includes a lot of Fortune 500 customers and U.S. federal agencies. It was a stunningly large and sophisticated operation that gave attackers access to a vast trove of the U.S. government emails. It can be considered as the biggest cyber raid against the U.S. government in years.

Another important characteristic of this attack was it stayed undetected for six to nine months. This gave an ample amount of time to attackers with privileged access to important and sensitive networks.

2. The Cause and Difference

decoding the SolarWinds hack

A.

SolarWinds breach is a classic supply chain attack. Attackers used Sunspot malware to get access to the company’s software development pipeline and injected the Sunburst backdoor into the SolarWinds Orion Platform DLL. The backdoor comprised of around 4,000 lines of code that allowed the threat actor behind the attack to operate unfettered with elevated access in a highly-sensitive network.

The software update, which contained this backdoor, was made available to SolarWinds customers using their Orion platform. More than 18,000 customers downloaded this update from the authenticated source of SolarWinds. Once the software gets updated in the customer’s environment, the backdoor stays dormant for about 14 days and then starts communicating with the command-and-control server.

SolarWinds network management and security solutions are expected to run with elevated privilege in customers’ environments to provide the desired network management capabilities. This enabled the backdoor code as well to run with elevated privilege and provided unrestricted access to the network.

The backdoor was receiving the instructions on actions to be performed on the network from the command-and-control center and the backdoor was sending sensitive information to this server.

This attack is unlike other prior attacks like Equifax or the Sony data breach. In those hacks, attackers exploited the vulnerabilities in the software or got access to privileged credentials. This kind of attack only impacts very few customers.

3. The Late Detection

decoding the SolarWinds hack

A.

This attack was conducted by highly sophisticated attackers. They managed to get access to the SolarWinds deployment pipeline in September 2019 and employed various techniques to stay undetected in their environment. The backdoor initialization had very few lines of code and was nicely blended with the existing code of the Orion platform. They made sure that these lines of code do not lead to build failure or introduce any error to their existing code path.

Backdoor code had specific checks to not trigger in SolarWinds test environment so that it does not get detected during their quality control process. It also ensured to remove any security products by meddling with registry keys, or it would not run if the security product were running.

Communication with the command-and-control server was also done in a very discrete way and leveraged DNS response like A Record and CNAME in a non-standard way and interpreted them to perform malware actions.

These different sets of strategies were meticulously executed and kept Sunburst undetected in SolarWinds and their customers’ environment for a longer time.

4. The Vulnerability Exploited

decoding the SolarWinds hack

A.It was a typical software supply chain attack. Threat actors deployed Sunspot malware, which monitors the processes involved in compiling and building Orion product code — and in modifying one of the source files to include initialization code for the Sunburst backdoor. It appears that a significant amount of investment was made to ensure that the code was properly inserted and that the presence of malware remained undetected in their build environment.

5. The Worst Affected

decoding the SolarWinds hack

A.

The overall client list includes a lot of big names from the private sector as well as U.S. government federal agencies like the U.S. Military, the Department of Homeland Security, the Treasury Department, and the Department of Commerce.  Its list of private sector customers is also huge and includes different business verticals like security, technology, telecommunications, and aviation.

This attack has impacted businesses of multiple sectors, and a lot of organizations are still evaluating the impact. Organizations will not reveal the true extent of damage done.

6. The Attackers Involved

decoding the SolarWinds hack

A.

As per the U.S. government’s investigations, Russia was most likely behind this attack. The Federal Bureau of Investigation (FBI), the Cyber Security and Infrastructure Security Agency (CISA), the Office of the Director of National Intelligence (ODNI), and the National Security Agency (NSA) released a joint statement stating that a task force has been created to investigate the extent of the attacks and concluded that an advanced persistent threat (APT) actor is likely Russian in origin.

As per Kaspersky’s research, there are some links between the SolarWinds attacks and the Russian Turla (aka Waterbug) espionage group. There are several similarities between the Sunburst backdoor and older malware known as Kazaur.

The clear motivations are yet to be known but based on state actors involved, the most likely motivations could be intelligence gathering.

There is some news that the website named SolarLeaks reported being selling data stolen in the SolarWinds attacks.

7. Were You Hacked?

decoding the SolarWinds hack

A.

To know if your organization is affected by the hack, a detailed assessment needs to be done for the software inventory and needs to be ensured that SolarWinds code is not used in the environment directly or indirectly.  If any machine is running the SolarWinds code, it needs to be immediately quarantined and carefully assessed to check if the machine is infected.

A thorough evaluation is needed to seek out any indication of a compromised network. If there are any signs of an attack, all instances of SolarWinds Orion must be disconnected from the network immediately. Also, all traffic to and from SolarWinds Orion needs to be blocked, and compromised accounts must be identified and removed.

After all, compromised accounts and prior instances of SolarWinds have been updated or removed, all credentials used by or stored in SolarWinds Orion must be reset.

8. Prevention in Future

decoding the SolarWinds hack

A.

The SolarWinds attack is an eye-opener for all of us. It has demonstrated build systems are very critical production systems, and they should get their due attention. Build systems should have a similar or higher level of security requirements than production environments. Build systems need to have stricter security audits.

This attack exposes that no industry standard specifically covers the security of vendors’ software development process. As part of the vendor’s selection process, their software build and development process should also be reviewed.

About the Interviewer

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity tech and trends.

 


Other Interviews from the Author:
Other Posts from the Author:

Cybercriminals Play Spy Game with NoxPlayer Users in Asia

battle of galaxy game

The online media and entertainment industry has been recently bombarded by multiple cyberattacks. So much so that the gaming industry has itself reported nearly 10 billion cyberattacks in only the last two years. However, the latest findings from ESET researchers suggest that threat actors are now turning towards espionage campaigns,  unlike others. But what is their modus operandi?

NoxPlayer – The New Spy Games Version

NoxPlayer, which is a product from BigNox, emulates Android games on Windows and macOS desktops. Thus, it is generally used by gamers for testing and playing mobile games on their computers. ESET researchers found striking evidence that one of the company’s official API (api.bignox.com) and file-hosting servers (res06.bignox.com) was compromised by unknown threat actors in September last year.

Related News:

Gaming Industry Suffered 10 Billion Cyberattacks in Two Years

However, unlike recent cyberattacks, where threat actors installed malware or ransomware to exfiltrate data and demand hefty ransoms, they only installed three malware for spying on their victims. What made things more unusual was the fact that attackers did not target all users either. They only targeted five users, which included targets from Hong Kong, Sri Lanka, and Taiwan. It meant it was a sophisticated and highly targeted espionage campaign.

On further analysis of the three malware deployed during this supply chain attack, the research team could draw parallels with another supply chain attack against the Myanmar presidential office in 2018 and Hong Kong University in 2020. The same malware strains were used in those attacks too.

In order to help users determine whether they installed the malware-ridden update of NoxPlayer and what remedies could be applied, ESET released a detailed report, which can be viewed here.

Related News:

Level-Up! Five Security Precautions for Online Gamers

Bug in Accellion’s Software Exposes Data of 1.4 Mn Washington State Residents

Nearly Half of Global Consumers Affected by Data Breaches

The Office of the Washington State Auditor (SAO) is inspecting a security incident after unemployment claims data of over 1.4 million Washington state residents were exposed in a third-party data breach. State Auditor Pat McCarthy attributed the data breach to a third-party software vendor Accellion, whose services are used by SAO to transfer digital files.

“I know this is one more worry for Washingtonians who have already faced unemployment in a year scarred by both job loss and a pandemic. I am sorry to share this news and add to their burdens,” McCarthy said in a news report.

Accellion’s Software – The Culprit Again!

Accellion, a provider of hosted file transfer services, confirmed that an unauthorized threat actor obtained access to SAO files in late December 2020 by exploiting a vulnerability in Accellion’s file-transfer service.

The SAO stated that data files from the Employment Security Department (ESD) were impacted, which contained unemployment compensation claim information, including the names, social security numbers, driver’s license or state identification numbers, bank account numbers, bank routing numbers, and place of employment. All the residents who have filed for unemployment benefits with the SAO between January 1 to December 10, 2020, were impacted by the security incident. Besides, the compromised files include the personal data of other Washington residents who have not yet been identified but whose information was with the state agency.

The security incident is under Accellion’s investigation and reported to the law enforcement authorities for further probe. “At this time, SAO does not have enough information to conclude the timing or full scope of what took place. It was not until the week of January 25, 2021, that Accellion confirmed to SAO that SAO files were subject to this attack and provided the information needed for SAO to begin to identify which data files were impacted, and individuals whose personal information is in those files,” SAO said.

One Software Multiple Attacks

Other government agencies that used the Accellion software service have also been similarly impacted by outsider intrusions. Recently, the Australian Securities and Investment Commission (ASIC) became aware of a security incident that affected one of its servers used to transfer files like credit license applications. The securities regulator stated that the security incident occurred due to a vulnerability in Accellion’s file-sharing software, used by New Zealand’s Reserve Bank that also faced a cyberattack earlier.

U.K. Research and Innovation Agency Suffers Ransomware Attack

Cybersecurity Skill Shortage Leads U.K. Firms to Outsourced Security Services

The U.K. Research and Innovation (UKRI) center confirmed that it suffered a ransomware attack that encrypted sensitive data and affected two of its services – a portal for the U.K. Research Office (UKRO) based in Brussels and an extranet (also known as the BBSRC extranet) used by Councils.

The UKRO portal provides research information to the subscribers, and the BBSRC extranet is used for peer review processing. UKRI temporarily suspended both the services to avoid further damage.

UKRI is a government entity supported by the Department for Business, Energy, and Industrial Strategy (BEIS) to manage investments in science and research and support innovative business opportunities in the U.K. The compromised information included grant applications, expense claims, and review data hosted in the portals. However, there is no information on whether any financial information has been compromised in the incident.

UKRI has reported the security incident to the U.K. National Crime Agency (NCA), the National Cyber Security Centre (NCSC), and the Information Commissioner’s Office (ICO).

“UKRI councils and a number of cross-cutting schemes use the impacted extranet for some of their peer review activity as a result the data that has been compromised includes grant applications and review information. Although we do not know at this stage whether the data has been taken. We are working to securely re-instate impacted services as well as conducting forensic analysis to ascertain if any data was taken, including the potential loss of personal, financial or other sensitive data,” UKRI said.

The number of businesses in the U.K. affected by cyberattacks has increased after the country went into lockdown. Several organizations suffered over 177,000 targeted attacks between April and June 2020, which accounts for one cyberattack every 45 seconds. Organizations in the U.K. need to take the necessary actions to improve their cybersecurity resilience and keep their employees and data as secure as possible.

North Korean Cybercriminals Target Security Researchers: Google

Cryptocurrency Lazarus, North Korean TA406, Lazarus Group , Korea Atomic Energy Research Institute

Google’s Threat Analysis Group (TAG) has uncovered an ongoing cyber campaign targeting security experts working on vulnerability research and development at various organizations. In an official release, the security giant stated that threat actors behind the campaign are linked to North Korean government-backed entity. Google warned the security research community that they might be a target for attackers and asked to remain vigilant while connecting with unknown individuals on social networking platforms.

Attackers with Fake Personas

Cybercriminals created multiple fake profiles on various social media handles, including Twitter, Telegram, LinkedIn, Discord, and Keybase, to reach out to security professionals working in various vulnerability disclosure programs. Besides, hackers prepared research blogs containing write-ups and vulnerability disclosure analysis, illicitly obtained from legitimate security researchers, to build credibility and connect with the security research community.

“The actors established a research blog and multiple Twitter profiles to interact with potential targets. They’ve used these Twitter profiles for posting links to their blog, posting videos of their claimed exploits and for amplifying and retweeting posts from other accounts that they control,” Google said.

Hacker-controlled Websites and Social Media Accounts

 Exploit Research Blog:

https://blog.br0vvnn[.]io

Twitter Handles:

  • https://twitter.com/br0vvnn
  • https://twitter.com/BrownSec3Labs
  • https://twitter.com/dev0exp
  • https://twitter.com/djokovic808
  • https://twitter.com/henya290
  • https://twitter.com/james0x40
  • https://twitter.com/m5t0r
  • https://twitter.com/mvp4p3r
  • https://twitter.com/tjrim91
  • https://twitter.com/z0x55g

LinkedIn

  • https://www.linkedin.com/in/billy-brown-a6678b1b8/
  • https://www.linkedin.com/in/guo-zhang-b152721bb/
  • https://www.linkedin.com/in/hyungwoo-lee-6985501b9/
  • https://www.linkedin.com/in/linshuang-li-aa696391bb/
  • https://www.linkedin.com/in/rimmer-trajan-2806b21bb/

Keybase

  • https://keybase.io/zhangguo

 Telegram

  • https://t.me/james50d

Social Engineering Attacks on Researchers

Google stated that threat actors have been targeting security researchers using social engineering tactics. The computers of several security researchers were compromised after visiting attackers’ blogs or by clicking on fraudulent links on social media accounts.

“After establishing initial communications, the actors would ask the targeted researcher if they wanted to collaborate on vulnerability research together, and then provide the researcher with a Visual Studio Project. Within the Visual Studio Project would be source code for exploiting the vulnerability, as well as an additional DLL that would be executed through Visual Studio Build Events. The DLL is custom malware that would immediately begin communicating with actor-controlled C2 domains,” Google added.

Is Trickbot Botnet Back?

Trojans, RAT, remote access trojan, Snip3 Crypter-as-a-Service

The infamous Trickbot botnet is back again with new phishing and malware campaigns mostly targeting insurance and legal enterprises in North America. An analysis from Menlo Security found an ongoing malware campaign in which Trickbot operators leveraged various phishing techniques to trick users into clicking and downloading the Trickbot malware on their devices.

Once the user clicks on the malicious link in the email, it redirects the user to a compromised server that prompts the victim into downloading the malicious payload. The redirected page contains a Download Photo Proof button, which, if clicked, downloads the malicious JavaScript to compromise the victim’s device.

“The initial vector appears to be an email, which includes a link to a URL. While in the past, Trickbot has used weaponized documents, the infection mechanism detailed in this campaign seems to be a new modus operandi used by this group,” Menlo Security said.

The Trickbot Botnet

Previously, Trickbot malware was a banking Trojan and evolved as a prolific malware used in several cyberattacks against businesses and individuals across the globe. Trickbot is specially crafted malware used to access victim’s online accounts to obtain personally identifiable information (PII). Trickbot malware was linked to numerous malware and ransomware attacks in 2020, leveraging COVID-19 themed emails.

Trickbot’s Capabilities

  • Lateral movement in the network for maximum damage
  • Exfiltrating user credentials from browsers
  • Exfiltrating Active Directory Services databases
  • Stealing cookies and OpenSSH keys
  • Theft of RDP, VNC, and PuTTY Credentials
  • Installing additional payloads like ransomware

The Comeback

In October 2020, Microsoft disrupted Trickbot operations and infrastructure by working along with telecommunications providers around the world. “We have now cut off key infrastructure so those operating Trickbot will no longer be able to initiate new infections or activate ransomware already dropped into computer systems,” Microsoft said.

While the actions of Microsoft and its partners resulted in a dip in Trickbot’s operations, the latest signs of its phishing campaigns are again fueling fears of the forgotten malware.

Fonix Ransomware Gang Locks Shop and Releases Master Decryption Key

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

Fonix ransomware, which notoriously seemed to be picking up in the last few months of 2020, has reportedly suspended operations and released a master decryption key for all its victims. Fonix operators had noticeably begun operations in June 2020 only in the wake of the economic crisis; however, it’s unclear if it was due to the pandemic or any personal reasons. The gang is proposing a launch of a malware analysis website and put its abilities to use in “positive ways.”

End of FonixCrypter Project

The operators of Fonix took to Twitter to announce the “End of FonixCrypter Project.” The person who claimed to be one of the admins in the project stated that not all team members were happy with this move and thus, indicated that the source code could be duplicated for future use.

In a separate tweet, the admin shared a link, which has a downloadable RAR file named ‘Fonix_decrypter.rar,’ which contains a decryptor and the master private decryption key, proving that he was indeed serious about shutting shop. However, this decryption tool is not a decryptor that allows victims to get their encrypted files back. Instead, it is an admin tool used by the ransomware gang internally.

Most ransomware operations follow a modus operandi where they ask their victims to send a few encrypted files for decryption as proof that they can indeed decrypt them. The said decryptor does exactly that. It allows the user to decrypt only a few files and not the entire set on the infected computer.

But this dark cloud has a silver lining because experts have found that the generated master keys work. On the other hand, the best news comes from Emsisoft, a cybersecurity firm providing anti-malware and ransomware products. Emsisoft said its decryptor tool effectively decrypts all versions of the ransomware, including [.]Fonix, [.]FONIX, [.]repter, [.]XINOF encrypted file extensions. This means the victims can hope for a solution soon.

Earlier in late 2020, Maze ransomware gang had announced similar suspension of operations.

Read more about that story here – Are We Really Out of the Maze? The Ransomware Gang Announces Retirement

BlastDoor: New Security Feature in Apple iOS 14 to Counter Zero-click Exploits

Apple iMessage

Samuel Grob, a security researcher at Google Project Zero, uncovered a new security feature that Apple added in its iOS 14 version without any revelation. Dubbed “BlastDoor,” the improved sandbox system feature was introduced due to the zero-click exploits that leveraged the Apple iMessage flaw in iOS 13.5.1. Reportedly, iPhones of 36 Al Jazeera journalists were infected with malware, leaving their devices open to cyber espionage.

The introduction of BlastDoor is a major change in iOS 14. BlastDoor is a tightly sandboxed service responsible for parsing untrusted data in iMessage.

“One of the major changes in iOS 14 is the introduction of a new, tightly sandboxed BlastDoor service which is now responsible for almost all parsing of untrusted data in iMessages. Furthermore, this service is written in Swift, a (mostly) memory-safe language which makes it significantly harder to introduce classic memory corruption vulnerabilities into the code base,” Grob said 

How BlastDoor Works

Grob stated that BlastDoor possesses a variety of new security protections. The strong sandbox of the BlastDoor service prevents the exploitation of a privilege escalation vulnerability after compromising the BlastDoor process. Whenever a message arrives in iMessage, it will pass via several security protocols that scan for malicious codes or links in the incoming message before allowing Apple’s push notification service to display the message.

BlastDoor
Image Courtesy: Google Project Zero

“The sandbox profile is quite tight. Only a handful of local IPC services can be reached, almost all file system interaction is blocked, any interaction with IOKit drivers is forbidden, outbound network access is denied. With this change, an exploit that relied on repeatedly crashing the attacked service would now likely require in the order of multiple hours to roughly half a day to complete instead of a few minutes. Overall, these changes are probably very close to the best that could’ve been done given the need for backwards compatibility, and they should have a significant impact on the security of iMessage and the platform as a whole,” Grob added. 

Related Story: Why Apple Dropped macOS Big Sur Feature ‘ContentFilterExclusionList’

Cybercriminals Do Not Retire

Cybercrime, internet crime

MAZE, a “famous” and active Criminal Hacker group notorious for its Ransomware attacks that made even multinational corporations tremble — has officially decided to close its doors. At the end of last year, MAZE made an announcement on a Dark Web page, about its termination of activities with immediate effect.

By Pierguido Iezzi, CEO of Swascan

This, on the surface, seemed like a piece of “good news” in 2020.

A few months have passed but can we breathe a sigh of relief? Should we be happy because one of the great “enemies” that sided with cybercrime has decided to throw in the towel?

Not so fast!

Look at the announcement, and you’ll notice it is filled with grammatical errors and published within the same corner of the dark web. A corner where, for a long time, these attackers used to “post” all the data they had been able to steal from their victims, as some sort of trophy room.

Victims also included companies linked to big names like Tesla and SpaceX.

Is it possible that these Criminal Hackers have decided to pull the oars in the boat because they were already satisfied with the earnings obtained with their attacks?

At first glance, it could be a hypothesis to consider. On the other hand, MAZE has been an innovator in the world of Criminal Hacking for a long time.

For instance, the group was the first to introduce the “double blackmail” strategy. In addition to completely blocking the systems of its victims in exchange for a ransom, the attackers threatened to release all the targeted companies’ data until this was paid (strictly in bitcoin).

Do not celebrate yet

All these innovations, unfortunately, have also borne their fruits and reaped illustrious victims. More fuel on the fire of the theory that the announcement could be true, then?

Unfortunately, it is not that simple.

Although criminalistic, these groups operate in a business-like manner: profit is the ultimate goal. And which business closes its doors after a good year?

We should therefore take this announcement with a great deal of skepticism.

Related News:

Are We Really Out of the Maze? The Ransomware Gang Announces Retirement

Surely there are people within this group who are “satisfied” with what they have achieved over years of criminal activity and are happy to “enjoy” the spoils, but it is also likely that this closure is simply a strategic move to reorganize under a different name – a rebranding if you will.

Whatever the future of MAZE may be, the possibility that all its operators (another name for those Criminal Hackers who decide to work as part of a single group) are currently holding their suitcases – COVID permitting – with sombreros on their heads ready to enjoy their “retirement” on a Caribbean island is almost zero.

On the contrary – the dissolution of the Group leaves many questions open, especially regarding this sudden skill surplus and the collaborative relationship they had with other Cyber-criminal organizations.

These, probably, having closed the MAZE chapter, are already looking for something else to put their criminal “skills” to good use.

On the contrary, it is not even a hypothetical question.

We already know that MAZE had close relations with two other groups of Criminal Hackers: LockBit and Ragnar Locker, as well as having been compared several times, for methodology and code, to the new entry Egregor.

The latter two groups have already claimed victims in Italy.

A hydra

In short, the most plausible scenario is that nobody really “retired” or decided to dedicate their time to activities that did not include cybercrime.

Those who greeted MAZE’s closure with a sigh of relief will be forced to think again.

In a certain way, MAZE became the Hydra of cybercrime: once one head was cut off, two (or maybe even three!) were born.

All its expertise has not been lost, nor taken off the market. It has been divided and passed on to other groups that have picked up right where MAZE decided to stop — hitting small and big organizations and causing huge economic and brand reputation damages.

They may have also tried to put on a good face with their statement, claiming they were not a cybercrime cartel, but MAZE had been working with its “descendants” for some time already — and now they have already taken its place.

Hardly anything will change, Criminal Hackers and ransomware will always be “out there” and will continue to target public and private organizations with their vast arsenal of tactics and techniques honed over years and years of practice.

We will just have to maintain a high state of alert and not let our guard down!


About the Author

Pierguido IezziPierguido Lezzi is the Cyber Security Director and Co-founder of Swascan with over 30 years of experience in the world of cybersecurity. With a degree in Information Sciences, he has had the opportunity to work nationally and internationally in large corporate contexts and in the largest multinationals as a cybersecurity representative. Author of several publications, he regularly collaborates as author and contributor to a number of newspapers and publications. He has also been a keynote speaker and testimonial at universities, national, and international events.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Related News:

Fonix Ransomware Gang Locks Shop and Releases Master Decryption Key

Attackers are Using Fake Office 365 Pages to Phish C-Suite Executives

Hackers Target Office 365 Users with SurveyMonkey Phishing Campaign

Security experts from Trend Micro uncovered an ongoing phishing campaign spreading fake Office 365 password expiration reports to compromise email accounts of C-Suite executives. The campaign has been active since 2019. In an official release, Trend Micro stated that the phishing campaign has targeted multiple organizations in the finance, government, real estate, manufacturing, and IT sectors in several countries like Japan, the U.S., the U.K., Canada, Australia, and Europe.

Image Courtesy: Trend Micro

“We found over 300 unique compromised URLs and 70 email addresses from eight compromised sites, including 40 legitimate emails of company CEOs, directors, owners, and founders, among other enterprise employee targets. We are now working with the respective authorities for further investigation,” Trend Micro said.

Leveraging Compromised Infrastructure

The attackers targeted unsuspecting victims with emails attached with fake Office 365 password expiration reports to trick them into clicking the embedded link in the email. The email prompts the users to click on the “Keep Password” option if they want to continue using the same password. Once clicked, the option leads the user to the phishing page, which asks the user to enter login credentials.

Trend Micro researchers also found several advertisements of malicious actors selling account credentials of CEOs, CFOs, and other C-suite executives in multiple English- and Russian-speaking underground darknet forums. “The attackers are reusing compromised infrastructure and victims’ account credentials to host phishing pages and gain more victims. The kit, which is available for sale, can validate the credentials’ details and accuracy once the victim interacts with the embedded link,” Trend Micro added.