Home Blog Page 149

REvil Ransomware Buys KPOT Malware; Adds Another Weapon to its Arsenal

KPOT Malware auctioned to REvil Ransomware gang, REvil ransomware, KPOT malware, ransomware

Last month, operators of the infamous information-stealing malware KPOT held an online auction on a dark web forum. Interestingly, the KPOT malware auction saw only one buyer ready to shell out the base price of $6500 to acquire the source code. On further investigation, it was found that the winning bidder was none other than UNKN, a known member from the REvil (also known as Sodinokibi) ransomware gang.

KPOT Malware Auction

The idea behind the KPOT malware auction was that the operators wanted to move to another project. Thus, for monetary gains, the base price of the auction was set to $6500. However, this base price seemed to be too high for the members of the dark web forum where it was being advertised.

KPOT malware was launched in mid-2018 and advertised as Malware-as-a-Service (MaaS). Its latest version, KPOT 2.0, displayed malicious functionalities like the collection of:

  • Passwords
  • Cookies
  • Browsing history
  • Browser auto fill form details
  • RDP files
  • System information including IP address, username, and installed software

Related News:

Not a Hoax! REvil Ransomware Operators Launch Auction Website

This malware is a perfect fit for a threat actor who is attempting to break into a network or system to infect it further with other vectors like ransomware. This is what the REvil ransomware gang must have thought because with such a steep price and no buyers, the REvil ransomware gang member, UNKN, bought the source code of KPOT 2.0 at the base price that it was placed for. Another reason behind no apprehensions in paying the steep price could well be the fact that the REvil gang claims to have an annual turnover of more than $100 million from ransom demands. A Russian YouTube channel that claims to have interviewed a member from the famous Russian speaking REvil ransomware gang has revealed this explosive news.

REvil ransomware, coupled with KPOT’s capabilities, can cause targeted strikes against major corporations. It is one to be put on the lookout list of your organization’s threat indicators.

Related News:

Are We Really Out of the Maze? The Ransomware Gang Announces Retirement

Old Unpatched Vulnerabilities Could Invoke Cyberattacks and Malware

actively exploited vulnerabilities, Vulnerabilities, risk-based vulnerability management

The “new normal” business operations left most organizations vulnerable to new attack vectors. From database misconfigurations to unpatched vulnerabilities, organizations suffered several challenges in terms of remote workforce migration and changes in the threat landscape, Bitdefender’s business threat landscape report revealed.

According to the report, nearly 63% of all reported unpatched vulnerabilities involve CVEs that date back to 2018 and earlier, leaving organizations potentially open to various cyberattacks. Companies globally could be at severe security risk if they do not adopt patch management solutions as soon as possible.

Over 45% of security professionals believe that IoT devices in employees’ home networks pose serious security risks as they could be easily exploited by remote attackers to compromise the entire corporate network systems. Besides, the surge in the APT-as-a-service threat landscape gave businesses new security challenges and paved the way for opportunistic hackers to misuse the change in workforce deployment.

Key Findings:

  • 87.31% of all misconfigurations involve having WinRM Service enabled.
  • 93.10% of human risk factors involve employees using old passwords for accounts.
  • 46.84% of all reported network-level attacks involve SMB exploits.
  • 41.63% of all reported network-level attacks involve brute force attempts on RDP and FTP.
  • 46% increase in suspicious IoT incidents in households throughout the first half of 2020.
  • 4 in 10 emails on the Coronavirus topic are fraud, phishing, or malware.
  • 42.52 % of Execution stage Command and Scripting interpreter sub-techniques involve the use of PowerShell Commands and Scrips.

“In the wake of 2020, 50% of organizations were unprepared to face a scenario in which they would have to migrate their entire workforce in a work-from-home environment. The global SARS-CoV22 pandemic may have been a respiratory illness that affected people around the world, but it also impaired the way organizations and business conducted normal operations. The lack of forward planning for such a scenario left many organizations open to potential vulnerabilities and misconfigurations that threat actors could have easily leveraged to score breaches, exfiltrate data, or even generate additional profit by extorting vulnerable companies,” said Bogdan Dumitru, CTO at Bitdefender.

Insights for CISOs to Secure Telework for the Long-term

1 in 3 CISOs feel biggest challenge of endpoint solution is its complexity

The COVID-19 pandemic drove the formation of a “new normal” that saw organizations shift the majority of, if not their entire, workforce to a remote work model. While moving employees to a telework model typically involves long-term IT planning and preparation, this situation simply did not allow for anything less than the rapid adoption of new strategies. In fact, between March and April of this year, the number of employed Americans working from home doubled to 62%.

By Jonathan Nguyen-Duy, Vice President, Global Field CISO Team at Fortinet

At the same time, cybercriminals have taken every opportunity to take advantage of the new security gaps arising from a wide variety of issues, such as new work locations and more devices. From creating emails that appear to come from the World Health Organization (WHO) to sending fake messages alleging payment issues that need to be resolved, threat actors are feeling extremely confident about their ability to exploit networks.

Adapting to Full-Time Remote Work Models 

Worldwide, business continuity has been top of mind as the pandemic continues to impact all facets of life. Fortinet’s 2020 Remote Workforce Cybersecurity Report investigated how global enterprises handled this rapid shift to telework, as well as their plans for supporting and securing remote work environments moving forward.

Comprising those involved in the purchase or planning decision-making for cybersecurity, networking, financial planning, remote working, facilities, and human resources, the data we gathered in this study provided key insight into just how prepared organizations were for this pandemic, both in terms of general technology and cybersecurity.

By understanding how other organizations reacted, CISOs can establish a well-informed plan for cybersecurity budgeting and selecting secure telework solutions. Among responses from participants, who spanned 17 different countries and nearly all industries and public sectors, the following trends came to light.

Enterprises Will Invest More in Secure Telework Moving Forward 

The Fortinet study also found that approximately 60% of enterprises plan to spend more than $250,000 in secure telework investments over the next 24 months as a direct result of the pandemic. While these investments were not initially planned for, securing remote work has quickly become a top priority for organizations.

Areas that respondents plan to upgrade include VPN (55%) and network access control (55%), among others. In terms of new investments, respondents noted multi-factor authentication (30%), secure telephony/unified communications (27%), and software-defined wide-area networking (SD-WAN) for both enterprise facilities  (26%) and employees’ homes (26%) as top priorities.

As they seek to secure their remote workforce, CISOs should take care to understand the tools that they already have in their arsenal so they can ensure a wise investment, whether it be upgrades or new technologies. When adopting new solutions, they must consider a wide array of threats their employees could face while working from home, whether it be a phishing email or a vulnerable website.

Telework May Remain a Permanent Fixture for Many Organizations 

Since the start of the pandemic, approximately two-thirds of firms have transitioned more than half of their workforces to telework. And for many, this strategy will stay in place for the foreseeable future. According to a recent study by Harvard University and the University of Illinois, more than a third of firms that had employees switch to remote work believe it will remain in effect (in some form) even after the COVID-19 crisis ends. For some companies, that may be full-time, while others may implement policies such as having employees work two or three days in the office and the rest at home. For CISOs, this insight should help inform long-term strategies for securing remote work, as traditional methods for keeping in-office devices and networks protected no longer fully apply. To ensure business continuity and secure operations, CISOs must now assume that telework is a standard part of their operations.

Breaches and Breach Attempts are Increasing Across Organizations 

Considering the rapid rate at which cybercriminals have developed new attacks, it comes as no surprise that 60% of survey respondents noted an increase in attempts to breach their networks.

As CISOs establish plans for both their current and future remote workforces, they must keep in mind the constant potential for breaches. In addition to investing in the right technologies, these leaders must also prioritize cybersecurity awareness among their employees through training opportunities and regular updates about phishing emails, malware, and other threats that have increased in recent months.

CISOs Can Secure Remote Work with the Right Technology 

The insights gathered through this study should help lay the groundwork for CISOs as they look to support new remote work strategies. When working on expanding secure remote access, organizations should consider the following technologies:

  • Multifactor authentication: While critical, VPNs do not address the inherent security issues associated with username/password logins on a variety of applications or databases. By requiring their employees to use multifactor authentication to access critical information and applications, CISOs can manage the risks of that weak or compromised passwords.
  • Network Access Control: By deploying an advanced network access control product, CISOs can ensure that all users are authenticated, and devices are inspected as they connect to the network – enabling validation and monitoring of all requests for network access. In addition to providing visibility across all connections to the network, these solutions also ensure constant network monitoring to help mitigate suspicious events.
  • Endpoint Detection and Response: Securing endpoints is more important than ever because most home networks are highly vulnerable. Endpoint detection and response (EDR) tools can help secure remote user devices without hindering productivity. They proactively reduce the attack surface, prevent infection by malware, detect and block malicious activity right on the spot, and automate procedures for response and remediation.

Final Thoughts 

While not many could have expected the global impact of the COVID-19 pandemic, leaders, including CISOs, are still responsible for maintaining operations and safeguarding information, all the while delivering business outcomes and enhanced user experiences.  By taking the time to prepare for a long-term, or even permanent, shift to telework, organizations can ensure overall resiliency and security.


About the Author

Jonathan Nguyen-DuyJonathan Nguyen-Duy is vice president, global field CISO team at Fortinet. He has a unique global government and commercial experience with a deep understanding of threats, technology, compliance, and business issues. Nguyen-Duy holds a BA in International Economics and an MBA in IT Marketing and International Business from the George Washington University.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Employee Education Singled Out as the Biggest Weakness During the Pandemic

employee education

Employee education has been singled out as one of the biggest cybersecurity weaknesses for organizations during the COVID-19 lockdown. According to a Twitter poll by Apricorn, a manufacturer of computer storage products, nearly 30% of employees admit to using unencrypted devices. More than 30%  of respondents also singled out employee education as the biggest area where companies needed to make changes to improve their cybersecurity posture.

Other Areas of Weakness include:
  • Updates to hardware (29%)
  • Endpoint control (21%)
  • Enforcing encryption (19%)

Kurt Markley, Director of Sales at Apricorn, commented, “Employees have a critical role to play in their organization’s cybersecurity processes, from recognizing the tools required, through to the policies in place to protect sensitive data. Whether it be through the delivery of awareness programs or ongoing training, establishing a culture of security within the workforce is essential. He continued:

Endpoint security is critical, and deploying removable storage devices with built-in hardware encryption, for example, will ensure all data can be stored or moved around safely offline. Even if the device is lost or stolen, the information will be unintelligible to anyone not authorized to access it.”

Is Your Endpoint Device Secure? Take our Endpoint Security Survey and win exciting goodies. Don’t miss out! Take Survey Now!

Several respondents also highlighted that they weren’t fully prepared to work at home securely and productively, where nearly 18% of respondents felt they didn’t have the right tools and technology while 16% admitting being completely ignorant of it.

Markley highlighted that COVID-19 may have bettered productivity among employees, while without the right tools and technology, these can easily backfire. He also highlighted that with more than 60% of employees planning to work remotely, the threat landscape may continue to widen.

According to Jon Fielding, Managing Director, EMEA at Apricorn, “IT and security teams had to scramble to respond to this crisis and in doing so, left a lot of companies wide open to breach. Nine months into employees working remotely, some know already that they have been attacked. Others think they may have been but can’t be sure. In the same way that we had to learn how to protect ourselves from illness and modify our behavior, we had to also learn how to protect our data outside of the firewall and more importantly, to remain vigilant about it.”

Endpoint Security

Business Email Compromise Attacks Surge in Q3 2020

BEC Scammers Exploit Email Auto-Forwarding Rules, FBI warns

A research from email security solutions provider Abnormal Security revealed that Business Email Compromise (BEC) attacks have surged across most industries, with a drastic increase in invoice and payment fraud attacks. Abnormal Security analyzed BEC campaigns across eight major industries, including retail/consumer goods and manufacturing, technology, energy/infrastructure, services, medical, media, finance, and hospitality sectors. It was found that the attacks increased in six of the eight industries during Q3 2020. The energy/infrastructure sector suffered the largest increase (93%) from Q2 to Q3.

Key Findings:

  • During Q3, attackers continued to focus primarily on invoice and payment fraud, which increased 155% from Q2 to Q3. This trend was particularly notable in retail/consumer goods & manufacturing.
  • While credential-phishing COVID-19 related attacks decreased by 82%, invoice and payment fraud continued to leverage fear, uncertainty and doubt about the pandemic increased by 81%.
  • The most impersonated brands returned to the pre-pandemic “normal,” as Zoom dropped from the top spot, replaced by DHL, and followed by Dropbox and Amazon. Rounding out the top five were iCloud and LinkedIn.

Evan Reiser, CEO of Abnormal Security, said, “BEC research is important for CISOs to prepare and stay ahead of attackers. Not only are BEC campaigns continuing to increase overall, but they are also rising in 75% of industries that we track. Since these attacks are targeted and sophisticated, these increases could indicate an ability for threat actors to scale that may overwhelm some businesses.”

BEC Attacks: A Lucrative Business

A similar research from the APWG (Anti-Phishing Working Group) revealed how enterprises lose their wealth to BEC attacks. BEC attacks have become a highly remunerative line of business for threat actors. In its “Phishing Activity Trends Report,” APWG stated that the average wire transfer loss from BEC attacks surged from $54,000 in Q1 2020 to $80,183 in Q2 2020, as cybercriminals expected high returns. Read more…

Hackers Hit Gold with JM Bullion Hack

Online bullion dealer JM Bullion, who trades precious metals including gold, silver, copper, platinum, and palladium, has reported a hacking incident, which compromised and leaked the PII and credit card details of its customers. JM Bullion and its subsidiary, Provident Metals, both sent a “Notice of Data Security Incident” to all its affected customers, which stated that the timeline of the attack began on February 18, 2020; however, the malicious activity was discovered in July 2020.

 Key Highlights 

  • Malicious scripts were added on the JM Bullion’s website on February 18, 2020 and remained active until July 17, 2020. Thus, the customers who made transactions during this timeframe only were affected.
  • The attackers were able to exfiltrate the personal data and credit card details of JM Bullion’s customers used during the checkout process.
  • Such an attack used to compromise and exfiltrate data from sections of a website is popularly known as Magecart attack.
  • In Magecart attacks, cybercriminals often insert malicious JavaScript in the checkout and/or payment page of the website. They steal the PII and credit card details of the website users, which is then sent to a remote C2 server under their control, as was the case here.

JM Bullion’s Hacking Incident

According to the notice (as seen in the image below), the IT department of JM Bullion first became suspicious on July 6, when they observed some malicious activity on the website.

It further stated that,

“JM Bullion immediately began an investigation, with the assistance of a third-party forensic specialist, to assess the nature and scope of the incident. Through an investigation, it was determined that malicious code was present on the website from February 18, 2020 to July 17, 2020, which had the ability to capture customer information entered into the website in limited scenarios while making a purchase.”

JB Bullion Hacked
Image Credit: Reddit User

JM Bullion has notified the required law enforcement departments and reviewed their internal procedures and safeguards to help protect against such incidents in the future. Additionally, the company suggested the following protection measures against identity theft and fraud:

  • Watchfully review your account statements and monitor your credit reports for suspicious activity.
  • Place a “security freeze” on credit reports which prevents potential creditors from accessing your credit file.
  • As an alternative to a security freeze, place an initial or extended “fraud alert” on your file at no cost.
  • Contact the consumer reporting agencies, the Federal Trade Commission, or your state Attorney General for your protection.

Related News:

Under Attack! 2000 Magento Stores Hacked in a Magecart Campaign

Hackers Sell 80K Stolen Credit Card Details on Dark Web

U.S. City New Haven Fined $200K Over Former Employee’s HIPAA Violation

Accellion Lawsuit, Google and Apple, Excellus to Pay $5.1 Mn to Settle Potential HIPPA Violations

Federal regulators have imposed a $202,400 fine on the City Health Department in New Haven, Connecticut, for potentially violating the Health Insurance Portability and Accountability Act (HIPAA). In a statement, the Department of Health and Human Services’ Office for Civil Rights (HHS OCR) stated the city of New Haven has agreed to pay the penalty and execute corrective measures to settle the lawsuit related to the 2016 data breach suit.

According to OCR, the city’s health department failed to terminate the access credentials of an ex-employee. It is found that the former employee continued to access citizens’ health records and shared her credentials with an intern. In 2016, the New Haven Health Department filed a breach report declaring that a former employee illegally downloaded a file that contained protected health information of over 498 individuals in a USB drive. The exposed information included the test results for sexually transmitted diseases along with patients’ names, dates of birth, gender, addresses, and origin.

Related Story: Failure in HIPAA Compliance Costs URMC $3 million fine

“Medical providers need to know who in their organization can access patient data at all times. When someone’s employment ends, so must their access to patient records,” said OCR Director Roger Severino.

Biggest HIPAA Fine

In one of the biggest HIPAA fines imposed by OCR in 2019, Jackson Health Systems, Florida, was charged for $2.15 million on account of multiple HIPAA violation instances. With an intent of identity theft, an employee of Jackson Health Systems leaked and sold around 2,000 PHI patient records. Read more

Endpoint Security Extends to the Cloud

The notion and definition of endpoints have evolved with the increased adoption of cloud computing and the virtualization of IT resources. Not long ago, endpoint security was only about securing the devices connected to an enterprise network. The increased use of personal devices at work introduced another acronym – BYOD (Bring Your Own Device). But today, as almost every device is connected to the cloud, to consume cloud services, the fundamental thinking about endpoint security changes; it certainly extends to the cloud, and that needs to be an important consideration when formulating endpoint security policy. Here are five reasons to support this statement.

By Brian Pereira, Principal Editor, CISO MAG

1. It’s a two-way street – The threats to IT infrastructure could come from the endpoints. A device with out-of-date software or no antimalware, and a careless user could open a can of “worms” that could crawl back to the private or public cloud (upstream) and then spread laterally, infecting other devices on the network. But the threat could also come from the Internet itself. A compromised service, malicious scripts, cross-site scripting, misconfigured S3 buckets that may have been infected; poorly configured cloud resources – could all infect the endpoint (downstream). Both the cloud service/resource owner and the endpoint user/administrator are equally responsible for securing the endpoints.

2. CASB – Cloud Access Security Broker is the way to ensure proper security in both directions (upstream and downstream). It is a software that acts as an intermediary between users and cloud service providers. McAfee, a pioneer in CASB technology, says CASB allows an organization to extend its security policy from on-premise infrastructure to the cloud — and create new policies for cloud-specific context. This includes SaaS, IaaS, and PaaS environments across public, private, and hybrid clouds.

3. Now even the Cloud has endpoints – Before cloud, we had physical resources like servers, storage, networking switches, and clients (PCs and Workstations) and we had to secure them. But today, resources are abstracted; we have virtual equivalents. For instance, physical network interface cards (NICs) on physical servers and nodes today have VNICs (virtual NICs) in the cloud. These are logical instances. Likewise, we have virtual switches vs. physical network switches. And APIs vs. cables, and physical connectors. Welcome to the Virtual world! These virtualized resources are on virtual networks in virtual private clouds. And these networks are organized into subnets. So you could have virtual instances (virtual machines), load balancers, storage, network connectivity within a subnet. A subnet is secured through ACLs (Access Control Lists) that defines who or what is allowed to access resources within that subnet. So, it boils down to good configuration. And that’s where managed endpoint security services come in.

4. The cloud is getting decentralized – With the advent of the pandemic, workforces became decentralized. IT infrastructure also had to keep up because it was not easy to administer distributed endpoints (outside the corporate perimeter) using traditional IT administration. So, the cloud began to get decentralized. The endpoint devices are now getting virtualized (VDI) to ensure better security and control for distributed (work from home) users. For years, organizations have been using VPNs to ensure secure communication between remote endpoints and the corporate network

5. Edge computing – In the years ahead we will see applications that demand real-time processing (closer to the endpoint or on the endpoint itself). The cloud will extend back into the enterprise. The endpoints will be connected to the cloud through high-speed connectivity like 5G. So, endpoint security will once again be redefined.

Conclusion

Over the years, endpoint protection has evolved from prevention (antivirus, data encryption, intrusion prevention, data loss prevention) to detection and response (EDR). So we now have various types of endpoint security and endpoint security tools and endpoint services. Moving into the future, with the proliferation of edge computing and high-speed connectivity, the cloud and the endpoints will be viewed as one seamless infrastructure. The focus will shift from securing endpoints to securing “workloads” and infrastructure. It would be “intrinsic” security with analytics and predictive capabilities. The industry acquisitions (notably VMware’s acquisition of endpoint security vendor Carbon Black2) are testimony to that – with billions of dollars spent on these acquisitions.


Brian Pereira
About the Author
Brian Pereira is the Principal Editor of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

 


Is Your Endpoint Device Secure? Take our Endpoint Security Survey and win exciting goodies. Don’t miss out! Take Survey Now!
Endpoint Security

Wroba Trojan Resurfaces, Targets U.S. Users

Android Trojan, Trojan, ReverseRat, Numando Banking Trojan

For the most part, Wroba Trojan activities were limited to the Asian countries. But very recently, researchers at Kaspersky Labs are seeing the mobile banking Trojan now targeting Android and iPhone users in the U.S with fake package-delivery notification. According to Kaspersky, during the Wroba Trojan campaign cybercriminals try to lure customers by sending them a text message. The message reads, “Your parcel has been sent out. Please check and accept it.”

Once an unsuspecting user clicks on the link, it goes either of the two ways depending on the OS on the mobile device.

If a user of an Android device clicks “OK,” they are redirected to a malicious site that reads, “Your browser is out-of-date and needs to be updated.” If the user clicks “OK,” the malicious application is downloaded onto the device. For iPhone users, the download doesn’t work. Instead, the iPhone users are greeted with a phishing page designed to look like Apple’s login page — in a bid to steal the credentials of the users.

Once the Trojan is installed on a device, it can perform several nefarious activities like sending fake SMSs, access financial transaction data, check installed packages, and steal contact list and credentials for financial data.  According to Kaspersky, Wroba belongs to a family of malware that attempts to steal mobile banking accounts as well as one-time passwords sent by banks for client authentication.

Related News: FBI Warns About Fake Mobile Banking Apps, Trojans

Geographical distribution of attacks by the Trojan-Banker.AndroidOS.Wroba family

According to Malwarebytes, associated families of the mobile bank Trojan include:

  • Trojan.Bank.Marcher
  • Trojan.Bank.Perkel
  • Trojan.Bankun
  • Trojan.Spy.FakeBank
  • Trojan.Spy.FakeKRBank
  • Trojan.Spitmo
  • Trojan.Zitmo
What is Wroba Trojan?

For the uninitiated, Wroba is not altogether a new malware. Back in 2013, Wroba Trojan masqueraded itself as a legitimate application on Google Play Store. Also known as FunkyBot, Wroba had mainly targeted users in Korea, China, Russia, Japan, and other countries in the APAC region.

What is a Trojan horse?

A Trojan horse or Trojan is a malicious program or malicious code disguised to look like a popular or legitimate application. Unlike viruses, Trojans cannot replicate and spread on their own, but depending on user action for infecting other systems. The user has to open the Trojan application for it to spread.

What is malware?

Malware is a generic or collective term for malicious software code. It includes viruses, Trojans, ransomware, and spyware. Typically malware is delivered as a link in email or as an email attachment. Clicking the link will lead to a malicious website. Opening a malicious attachment will execute the malicious program or code.

High-Profile Personalities on Hacker Radar! Attackers Target Munich Conference Attendees

Doxing attacks

Microsoft’s threat intelligence center uncovered a cyberthreat operation in which hackers disguised as conference organizers to target more than 100 high-worth profiles, including heads of state, world leaders, former ambassadors, and industry experts to pilfer intelligence information. According to a report, the Iranian threat actor group “Phosphorus” targeted potential attendees of the upcoming Munich Security Conference and the Think 20 (T20) Summit in Saudi Arabia.

The Munich Security Conference is a summit on international security policy held annually in Munich, Bavaria since 1963.

Fake Invitations

It was found that threat actors had been sending fake invitations to potential attendees via email. Attackers sent imposter invitations of the Munich Security Conference to former government officials, policy experts, academics, and security leaders from non-governmental organizations.

No Links to the U.S. Elections

Tom Burt, Corporate Vice President, Customer Security and Trust at Microsoft, said, “Based on current analysis, we do not believe this activity is tied to the U.S. elections in any way. Phosphorus helped assuage fears of travel during the Covid-19 pandemic by offering remote sessions.”

“We believe Phosphorus is engaging in these attacks for intelligence collection purposes. The attacks were successful in compromising several victims, including former ambassadors and other senior policy experts who help shape global agendas and foreign policies in their respective countries. We will continue to use a combination of technology, operations, legal action and policy to disrupt and deter malicious activity, but nothing replaces vigilance from people who are likely targets of these operations,” Burt added.

Microsoft recommended its users to enable multi-factor authentication across both business and personal email accounts to prevent credential harvesting attacks like these. “We’ve already worked with conference organizers who have warned and will continue to warn their attendees, and we’re disclosing what we’ve seen so that everyone can remain vigilant to this approach being used in connection with other conferences or events,” Microsoft said.