phishing – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 06 Sep 2025 21:43:44 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 phishing – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 VirusTotal finds hidden malware phishing campaign in SVG files https://earlybirdsinvest.com/virustotal-finds-hidden-malware-phishing-campaign-in-svg-files/ https://earlybirdsinvest.com/virustotal-finds-hidden-malware-phishing-campaign-in-svg-files/#respond Sat, 06 Sep 2025 21:43:44 +0000 https://earlybirdsinvest.com/virustotal-finds-hidden-malware-phishing-campaign-in-svg-files/

Malware phishing

VirusTotal has discovered a phishing campaign hidden in SVG files that create convincing portals impersonating Colombia’s judicial system that deliver malware.

VirusTotal detected this campaign after it added support for SVGs to its AI Code Insight platform.

VirusTotal’s AI Code Insight feature analyzes uploaded file samples using machine learning to generate summaries of suspicious or malicious behavior found in the files.

After adding support for SVGs, VirusTotal found an SVG file that had zero detections by antivirus scans, but whose AI-powered Code Insight feature detected using JavaScript to display HTML, impersonating a portal for Colombia’s government judiciary system.

VirusTotal Code insights detecting a malicious SVG file
VirusTotal Code insights detecting a malicious SVG file
Source: VirusTotal

SVG, or Scalable Vector Graphics, is used to generate images of lines, shapes, and text through textual mathematical formulas in the file.

However, threat actors have begun increasingly using SVG files in attacks, as they can also be used to display HTML using the element and execute JavaScript when the graphic is loaded.

In the campaign discovered by Virustotal, SVG image files are used to render fake portals that display a phony download progress bar, ultimately prompting the user to download a password-protected zip archive [VirusTotal]. The password for this file is displayed in the fake portal page.

“As shown in the screenshots below, the fake portal is rendered exactly as described, simulating an official government document download process,” explains VirusTotal.

“The phishing site includes case numbers, security tokens, and visual cues to build trust, all of it crafted within an SVG file.”

Fake portal for Colombia’s judicial system​​​​​​​
Fake portal for Colombia’s judicial system
Source: VirusTotal

BleepingComputer found that the extracted file contains four files: a legitimate executable from the Comodo Dragon web browser, renamed to be an official judicial document, a malicious DLL [VirusTotal], and what appears to be two encrypted files.

Extracted password-protected archive
Extracted password-protected archive
Source: BleepingComputer

If the user opens the executable, the malicious DLL will be sideloaded to install further malware on the system.

After detecting this initial SVG, VirusTotal identified 523 previously uploaded SVG files that were part of the same campaign but had evaded detection by security software.

The addition of SVG support to AI Code Insights was crucial in exposing this particular campaign, as VirusTotal noted that the use of AI makes it easier to identify new malicious campaigns.

“This is where Code Insight helps most: giving context, saving time, and helping focus on what really matters. It’s not magic, and it won’t replace expert analysis, but it’s one more tool to cut through the noise and get to the point faster,” concludes VirusTotal.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/virustotal-finds-hidden-malware-phishing-campaign-in-svg-files/feed/ 0 57116
Phishing scams cost users over $12M in August — Here's how to stay safe https://earlybirdsinvest.com/phishing-scams-cost-users-over-12m-in-august-heres-how-to-stay-safe/ https://earlybirdsinvest.com/phishing-scams-cost-users-over-12m-in-august-heres-how-to-stay-safe/#respond Sat, 06 Sep 2025 21:26:37 +0000 https://earlybirdsinvest.com/phishing-scams-cost-users-over-12m-in-august-heres-how-to-stay-safe/

Phishing scams, attacks disguised as legitimate communication or websites designed to steal funds and sensitive information, cost crypto users over $12 million in August, up 72% from July, Web3 anti-scam service Scam Sniffer reported on Saturday.

Crypto phishing scams impacted 15,230 victims in August, a 67% increase from July, with the single largest loss costing one user over $3 million, according to Scam Sniffer.

The Scam Sniffer team also noted a “sharp escalation” in EIP-7702 signature scams. EIP-7702 is an Ethereum improvement proposal that allows Externally Owned Accounts to act as smart contract wallets that can execute transactions and shift funds.

Phishing, Cybersecurity, Scams
August 2025 phishing attack numbers. Source: Scam Sniffer

Scammers and hackers exploiting this functionality drained over $5.6 million in August through three separate attacks, Scam Sniffer said.

Scams and cybersecurity exploits continue to be a problem in crypto, with over $163 million stolen in August through malicious activity. The persistent threat is a reminder for crypto users to remain vigilant and practice good anti-phishing and anti-scam security measures.

Related: Venus Protocol recovers user’s $13.5M stolen in phishing attack

Good practices for staying safe against phishing scams

Losses from crypto hacks and scams crossed $3.1 billion in the first half of 2025 amid increasingly sophisticated attack methods.

Scammers often target users by posing as legitimate and well-known cryptocurrency exchanges, either setting up fake websites with similar URL addresses to legitimate exchanges or sending fake communications to users.

These communications include emails, text messages, and even physical letters sent through the mail, designed to steal sensitive user information, including seed phrases for crypto wallets and passwords to online accounts. 

Typically, the scammers will pretend to be customer service agents from reputable exchanges, claiming that the user’s account is facing some sort of threat or cybersecurity issue and demand personal information from the user, including seed phrases.

Good practices to avoid phishing scams include checking URLs for tiny mistakes and bookmarking pages instead of using search engines or the search bar to access websites every time, verifying website links, and avoiding downloading attachments or clicking links from unknown sources. 

Phishing scams often contain misspelled words or grammatical errors, and any of these mistakes is a red flag; users should read through messages carefully to detect such errors.

Crypto and Web3 users should also use virtual private networks (VPNs) to mask their IP addresses and physical locations, never give out seed phrases or passwords, and enable two-factor authentication for sensitive online accounts.

Magazine: $55M DeFi Saver phish, copy2pwn hijacks your clipboard: Crypto Sec

]]> https://earlybirdsinvest.com/phishing-scams-cost-users-over-12m-in-august-heres-how-to-stay-safe/feed/ 0 57113 Threat actors downgrade FIDO2 MFA auth in PoisonSeed phishing attack https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/ https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/#respond Sun, 20 Jul 2025 14:36:11 +0000 https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/

Hacker

A PoisonSeed phishing campaign is bypassing FIDO2 security key protections by abusing the cross-device sign-in feature in WebAuthn to trick users into approving login authentication requests from fake company portals.

The PoisonSeed threat actors are known to employ large-volume phishing attacks for financial fraud. In the past, distributing emails containing crypto seed phrases used to drain cryptocurrency wallets.

In the recent phishing attack observed by Expel, the PoisonSeed threat actors do not exploit a flaw in FIDO2’s security but rather abuse the legitimate cross-device authentication feature.

Cross-device authentication is a WebAuthn feature that allows users to sign in on one device using a security key or authentication app on another device. Instead of requiring a physical connection, such as plugging in a security key, the authentication request is transmitted between devices via Bluetooth or a QR code scan.

The attack begins by directing users to a phishing site that impersonates corporate login portals, such as from Okta or Microsoft 365.

When the user enters their credentials into the portal, the campaign uses an adversary-in-the-middle (AiTM) backend to silently log in with the submitted credentials on the legitimate login portal in real-time.

The user targeted in the attack normally would use their FIDO2 security keys to verify multi-factor authentication requests. However, the phishing backend instead tells the legitimate login portal to authenticate using cross-device authentication.

This causes the legitimate portal to generate a QR code, which is transmitted back to the phishing page and displayed to the user.

When the user scans this QR code using their smartphone or authentication app, it approves the login attempt initiated by the attacker.

PoisonSeed attack flow to bypass FIDO2 protections
PoisonSeed attack flow to bypass FIDO2 protections
Source: Expel

This method effectively bypasses FIDO2 security key protections by allowing attackers to initiate a login flow that relies on cross-device authentication instead of the user’s physical FIDO2 key.

Expel warns that this attack does not exploit a flaw in the FIDO2 implementation, but instead abuses a legitimate feature that downgrades the FIDO key authentication process.

To mitigate the risk, Expel recommends the following defenses:

  • Limiting geographic locations from which users are allowed to log in and establishing a registration process for individuals traveling.
  • Routinely check for the registration of unknown FIDO keys from unknown locations and uncommon security key brands.
  • Organizations can consider enforcing Bluetooth-based authentication as a requirement for cross-device authentication, which significantly reduces the effectiveness of remote phishing attacks.

Expel also observed a separate incident where a threat actor registered their own FIDO key after compromising an account via what is believed to be phishing and resetting the password. However, this attack did not require any methods to trick the user, like a QR code.

This attack highlights how threat actors are finding ways to bypass phishing-resistant authentication by tricking users into completing login flows that bypass the need for physical interaction with a security key.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/threat-actors-downgrade-fido2-mfa-auth-in-poisonseed-phishing-attack/feed/ 0 48711
Threat actors abuse Google Apps Script in evasive phishing attacks https://earlybirdsinvest.com/threat-actors-abuse-google-apps-script-in-evasive-phishing-attacks/ https://earlybirdsinvest.com/threat-actors-abuse-google-apps-script-in-evasive-phishing-attacks/#respond Thu, 29 May 2025 16:33:23 +0000 https://earlybirdsinvest.com/threat-actors-abuse-google-apps-script-in-evasive-phishing-attacks/

Threat actors abuse Google Apps Script in evasive phishing attacks

Threat actors are abusing the ‘Google Apps Script’ development platform to host phishing pages that appear legitimate and steal login credentials.

This new trend was spotted by security researchers at Cofense, who warn that the fraudulent login window is “carefully designed to look like a legitimate login screen.”

“The attack uses an email masquerading as an invoice, containing a link to a webpage that uses Google Apps Script, a development platform integrated across Google’s suite of products,” Cofense explains.

“By hosting the phishing page within Google’s trusted environment, attackers create an illusion of authenticity. This makes it easier to trick recipients into handing over sensitive information.”

Legitimate service abuse

Google Apps Script is a JavaScript-based cloud scripting platform from Google that allows users to automate tasks and extend the functionality of Google Workspace products like Google Sheets, Docs, Drive, Gmail, and Calendar.

These scripts run on a trusted Google domain under “script.google.com,” which is on the allowlist of most security products.

Attackers write a Google Apps Script that displays a fake login page to capture the credentials victims enter. The data is exfiltrated to the attacker’s server via a hidden request.

Phishing page hosted on Google infrastructure
Phishing page hosted on Google infrastructure
Source: Cofense

As the platform allows anyone with an account to publish a script as a public web app, giving it a Google domain, the threat actors can easily share it with the victims via a phishing email that won’t trigger any warnings.

The phishing email contains an invoice payment or tax-related call to action for the recipient, linking to the malicious Google-hosted phishing page.

Sample of a phishing email used in the attacks
Sample of a phishing email used in the attacks
Source: Cofense

After the victim enters their username and password, they are redirected to the legitimate service that was spoofed to lower suspicion and give threat actors time to exploit the stolen data.

Google Apps Script appears to be the new focus of phishing actors that look for legitimate platforms to abuse for evasion and operational efficiency.

In this case, it also gives the attackers the flexibility to remotely adjust their script without having to resend a new link, switching to a different lure without much effort.

An effective defense measure would be to configure email security to scrutinize cloud service links and, if possible, block access to Google Apps Script URLs altogether, or at least flag them as potentially dangerous.

BleepingComputer has contacted Google to ask if they plan to implement any anti-abuse measures in response to Cofense’s findings, but we have not heard back as of publication.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/threat-actors-abuse-google-apps-script-in-evasive-phishing-attacks/feed/ 0 38994
Phishing scammers now exploiting Google’s infrastructure to target crypto users https://earlybirdsinvest.com/phishing-scammers-now-exploiting-googles-infrastructure-to-target-crypto-users/ https://earlybirdsinvest.com/phishing-scammers-now-exploiting-googles-infrastructure-to-target-crypto-users/#respond Wed, 16 Apr 2025 13:04:04 +0000 https://earlybirdsinvest.com/phishing-scammers-now-exploiting-googles-infrastructure-to-target-crypto-users/

Phishing scams targeting crypto users have become more advanced, with attackers abusing Google’s infrastructure to conduct highly convincing attacks.

On April 16, Nick Johnson, the founder and lead developer of Ethereum Name Service (ENS), raised concerns over a fresh method cybercriminals use to compromise Gmail accounts and potentially target associated crypto wallets.

How phishing attackers are using Google to their advantage

According to Johnson, the attackers exploit a loophole in Google’s ecosystem that allows them to send phishing emails that appear genuine security alerts from the tech giant itself.

These emails are signed with valid DomainKeys Identified Mail (DKIM) signatures, enabling them to bypass spam filters and appear authentic to recipients.

Once opened, these emails direct users to a counterfeit support portal hosted on a Google subdomain. This fake page prompts victims to log in and upload sensitive documents.

However, Johnson warned that the attackers are likely harvesting credentials, which could compromise Gmail accounts and any services linked to those emails.

The phishing sites are built using Google’s Sites platform, which allows custom scripts and embedded content.

While this flexibility benefits legitimate users, it also allows malicious actors to create convincing phishing portals. Even more concerning is that there’s currently no way to report abuse directly through the Google Sites interface, making it easier for attackers to keep their content online.

He said:

“Google long ago realised that hosting public, user-specified content on google.com is a bad idea, but Google Sites has stuck around. IMO they need to disable scrips and arbitrary embeds in Sites; this is too powerful a phishing vector.”

To further enhance the illusion of legitimacy, the scammers create a Google OAuth application that formats and shares the phishing message. These messages are always complete with structured text and what appears to be contact information for Google Legal Support.

Google’s response

Johnson reported that he submitted a bug report to Google about this vulnerability.

Still, the search engine giant reportedly stated that the features work as intended and do not constitute a security issue.

Johnson wrote:

“I’ve submitted a bug report to Google about this; unfortunately they closed it as ‘Working as Intended’ and explained that they don’t consider it a security bug.”

Nevertheless, he urged Google to consider limiting script and embedding functionality to help prevent future abuse.

This incident highlights the increasing sophistication of phishing campaigns within the crypto space. According to Scam Sniffer, nearly 6,000 users lost around $6.37 million to phishing scams in March 2025 alone. In the first quarter of the year, 22,654 victims suffered total losses of $21.94 million.

Mentioned in this article

]]>
https://earlybirdsinvest.com/phishing-scammers-now-exploiting-googles-infrastructure-to-target-crypto-users/feed/ 0 31100
Hacker falls victim to phishing scam after exploiting ZkLend for millions https://earlybirdsinvest.com/hacker-falls-victim-to-phishing-scam-after-exploiting-zklend-for-millions/ https://earlybirdsinvest.com/hacker-falls-victim-to-phishing-scam-after-exploiting-zklend-for-millions/#respond Tue, 01 Apr 2025 09:58:25 +0000 https://earlybirdsinvest.com/hacker-falls-victim-to-phishing-scam-after-exploiting-zklend-for-millions/

ZkLend, a decentralized lending protocol built on Starknet, has confirmed that the hacker responsible for its February exploit lost a significant portion of the stolen funds to a phishing scam.

In an April 1 post on X, ZkLend revealed that the attacker tried to launder 2,930 ETH, worth around $5.4 million, through crypto mixer Tornado Cash.

However, instead of using the legitimate platform, the hacker mistakenly interacted with a malicious phishing site: tornadoeth[.]cash. As a result, another party successfully drained the ETH.

Blockchain analytics firm Lookonchain corroborated ZkLend’s findings, confirming the loss of 2,930 ETH due to the phishing incident.

Interestingly, the hacker later sent an on-chain message to ZkLend’s deployer address, admitting the blunder. In the message, the attacker wrote:

“I tried to move funds to Tornado but used a phishing website. All the funds have been lost. I’m devastated and sorry for the havoc and losses caused. I don’t have the coins anymore.”

The hacker urged ZkLend to pursue the phishing site operators instead.

‘No connection’

This unexpected turn has fueled speculation that the original hacker and the phishing scammers might be connected, though no proof has surfaced to support that theory.

Meanwhile, ZkLend stated that the phishing website appears to have been active for over five years. The project furthered that no concrete evidence links the phishing operators to the original hacker.

Nonetheless, wallet addresses tied to the phishing site have been added to ongoing fund-tracing efforts.

The team also noted increased activity from wallets associated with the hacker. Security experts, centralized exchanges (CEXs), and relevant authorities were monitoring these movements in real-time.

ZkLend was exploited in February, with blockchain security firm Cyvers estimating the loss at approximately $9.5 million.

The protocol offered the attacker a 10% bounty if they returned the rest. However, the hacker ignored the proposal and kept the funds, prompting ZkLend to partner with security teams from Starknet, StarkWare, and Binance in a broader fund recovery effort.

XRP Turbo
]]>
https://earlybirdsinvest.com/hacker-falls-victim-to-phishing-scam-after-exploiting-zklend-for-millions/feed/ 0 28380
New Mac phishing attack causes fake freezes to nab your Apple ID password https://earlybirdsinvest.com/new-mac-phishing-attack-causes-fake-freezes-to-nab-your-apple-id-password/ https://earlybirdsinvest.com/new-mac-phishing-attack-causes-fake-freezes-to-nab-your-apple-id-password/#respond Wed, 19 Mar 2025 22:56:23 +0000 https://earlybirdsinvest.com/new-mac-phishing-attack-causes-fake-freezes-to-nab-your-apple-id-password/

]]>
https://earlybirdsinvest.com/new-mac-phishing-attack-causes-fake-freezes-to-nab-your-apple-id-password/feed/ 0 26103
PayPal “New Address” feature abused to send phishing emails https://earlybirdsinvest.com/paypal-new-address-feature-abused-to-send-phishing-emails/ https://earlybirdsinvest.com/paypal-new-address-feature-abused-to-send-phishing-emails/#respond Sun, 23 Feb 2025 22:45:09 +0000 https://earlybirdsinvest.com/paypal-new-address-feature-abused-to-send-phishing-emails/

PayPal

An ongoing PayPal email scam exploits the platform’s address settings to send fake purchase notifications, tricking users into granting remote access to scammers

For the past month, BleepingComputer and others [1, 2] have received emails from PayPal stating, “You added a new address. This is just a quick confirmation that you added an address in your PayPal account.” 

The email includes the new address that was allegedly added to your PayPal account, including a message claiming to be a purchase confirmation for a MacBook M4, and to call the enclosed PayPal number if you did not authorize the purchase.

“Confirmation: Your shipping address for the MacBook M4 Max 1 TB ($1098.95) has been changed. If you did not authorize this update, please reach out to PayPal at +1-888-668-2508′,” reads the scam email.

PayPal smishing text and landing page
PayPal “new address” feature abused in scam
Source: BleepingComputer

The emails are being sent directly by PayPal from the address “service@paypal.com,” causing people to be concerned their account was hacked.

However, those who received this email confirmed that no new addresses were actually added to their accounts. In our case, the scam email was sent to an email address with no PayPal account.

Furthermore, as the emails are legitimate PayPal emails, they are bypassing security and spam filters. In the next section, we will explain how scammers send these emails.

The goal of these emails is to trick recipients into thinking their account was hacked to purchase a MacBook and scare the email recipient into calling the scammer’s “PayPal support” phone number.

When calling the number, a recording will automatically play stating that you have reached PayPal customer service and to hold while a support person becomes available. The call will then attempt to connect you to a “customer support” person.

This scammer will try to scare you into thinking your account was hacked and convince you to download and run the software so that they can “help” you regain access to the account and block the alleged transaction.

The scammer will direct you to visit a site like pplassist[.]com and enter a service code given by the fake PayPal employee. Entering this code will download a ConnectWise ScreenConnect client [VirusTotal] from lokermy.numaduliton[.]icu or other sites, which the scammer will ask you to run.

Scammer's site to distribute ConnectWise ScreenConnect
Scammer’s site to distribute ConnectWise ScreenConnect
Source: BleepingComputer

At this point, we hung up on the scammer and did not execute the program on our devices.

However, in previous scams like this, once the threat actor gains access to the computer, they attempt to steal money from bank accounts, deploy malware, or steal data from the computer.

Therefore, if you receive a legitimate email from PayPal stating you updated your address, and it contains a bogus purchase confirmation, simply ignore the email and do not contact the listed phone number as it belongs to the scammer.

To be safe, instead, log into your PayPal account and confirm no additional addresses were added, and if not, junk the email.

How the PayPal scam works

When BleepingComputer first received this email, we were confused as the email was sent from “service@paypal.com” to an email address that does not have a PayPal account associated with it.

Furthermore, the mail headers show that the emails are legitimate, passing DKIM email security checks and originating directly from PayPal’s mail server, as shown below.

Received: from mx1.phx.paypal.com (mx1.phx.paypal.com. [66.211.170.87])
        by mx.google.com with ESMTPS id 41be03b00d2f7-addf237d3e1si10521113a12.387.2025.02.18.07.30.09
        for 

It was unclear at first how these legitimate emails were being sent from PayPal until we noticed this text at the bottom of the email.

“If you want to link your credit card to this address, or make it your primary address, log in to your PayPal account and go to your Profile,” reads the PayPal email notification.

“Since this address is a gift address, you can send packages to it with just a click.”

Further research revealed that “gift addresses” are just additional addresses you can add to your PayPal profile.

In a test, BleepingComputer added a new address to one of our accounts and pasted the scammer’s fake MacBook purchase confirmation message into the Address 2 field.

After saving the address, PayPal sent us the same confirmation email, notifying us of the new address we added, which also included the fake purchase message.

Now that we know how they are generating the email from PayPal, we still do not know how they are getting PayPal to send it to all of the targets.

Upon further analysis of the mail headers, we can see that the email is actually being sent to the address “noreply_@usaea.institute,” which is the email address associated with the scammer’s PayPal address.

The headers further show that this email address automatically forwards the email it receives to “bill_complete1@zodu.onmicrosoft.com”, an account associated with a Microsoft 365 tenant.

This account is likely a mailing list, which automatically forwards any email it receives to all other group members. In this case, the members are you and I, the scammer’s targets.

When they add the scam address to PayPal, the payment platform will email a confirmation to the threat actor’s email, which will then forward it to the Microsoft 365 account, which then forwards it to everyone on the mailing list, as shown in the flow chart below.

Scam attack flow
Scam attack flow
Source: BleepingComputer

PayPal enables this scam by not limiting the number of characters in the address form fields, allowing the threat actors to inject their scam message.

To fix this, PayPal needs to restrict the number of characters in the address field to a reasonable character count, like 50 characters, if not less.

BleepingComputer contacted PayPal about this scam and is awaiting a response to our email.

]]>
https://earlybirdsinvest.com/paypal-new-address-feature-abused-to-send-phishing-emails/feed/ 0 21454
Hackers steal emails in device code phishing attacks https://earlybirdsinvest.com/hackers-steal-emails-in-device-code-phishing-attacks/ https://earlybirdsinvest.com/hackers-steal-emails-in-device-code-phishing-attacks/#respond Sat, 15 Feb 2025 21:38:16 +0000 https://earlybirdsinvest.com/hackers-steal-emails-in-device-code-phishing-attacks/

Microsoft: Hackers steal emails in device code phishing attacks

An active campaign from a threat actor potentially linked to Russia is targeting Microsoft 365 accounts of individuals at organizations of interest using device code phishing.

The targets are in the government, NGO, IT services and technology, defense, telecommunications, health, and energy/oil and gas sectors in Europe, North America, Africa, and the Middle East.

Microsoft Threat Intelligence Center tracks the threat actors behind the device code phishing campaign as ‘Storm-237’, Based on interests, victimology, and tradecraft, the researchers have medium confidence that the activity is associated with a nation-state operation that aligns with Russia’s interests.

Device code phishing attacks

Input constrained devices – those that lack keyboard or browser support, like smart TVs and some IoTs, rely on a code authentication flow to allow allowing users to sign into an application by typing an authorization code on a separate device like a smartphone or computer.

Microsoft researchers discovered that since last August, Storm-2372 abuses this authentication flow by tricking users into entering attacker-generated device codes on legitimate sign-in pages.

The operatives initiate the attack after first establishing a connection with the target by “falsely posing as a prominent person relevant to the target” over messaging platforms like WhatsApp, Signal, and Microsoft Teams.

Messages Storm-2372 sent to targets
Messages Storm-2372 sent to targets
Source: Microsoft

The threat actor gradually establishes a rapport before sending a fake online meeting invitation via email or message.

According to the researchers, victim receives a Teams meeting invite that includes a device code generated by the attacker.

“The invitations lure the user into completing a device code authentication request emulating the experience of the messaging service, which provides Storm-2372 initial access to victim accounts and enables Graph API data collection activities, such as email harvesting,” Microsoft says.

This gives the hackers access to the victim’s Microsoft services (email, cloud storage) without needing a password for as long as the stolen tokens remain valid.

Device code phishing attack overview
Device code phishing attack overview
Source: Microsoft

However, Microsoft says that the attacker is now using the specific client ID for Microsoft Authentication Broker in the device code sign-in flow, which allows them to generate new tokens.

This opens new attack and persistence possiblities as the threat actor can use the client ID to register devices to Entra ID, Microsoft’s cloud-based identity and access management solution.

“With the same refresh token and the new device identity, Storm-2372 is able to obtain a Primary Refresh Token (PRT) and access an organization’s resources. We have observed Storm-2372 using the connected device to collect emails” – Microsoft

Defending against Storm-2372

To counter device code phishing attacks used by Storm-2372, Microsoft proposes blocking device code flow where possible and enforcing Conditional Access policies in Microsoft Entra ID to limit its use to trusted devices or networks.

If device code phishing is suspected, immediately revoke the user’s refresh tokens using ‘revokeSignInSessions’ and set a Conditional Access Policy to force re-authentication for affected users.

Finally, use Microsoft Entra ID’s sign-in logs to monitor for, and quickly identify high volumes of authentication attempts in a short period, device code logins from unrecognized IPs, and unexpected prompts for device code authentication sent to multiple users.

]]>
https://earlybirdsinvest.com/hackers-steal-emails-in-device-code-phishing-attacks/feed/ 0 19711