Security News > 2022 > August > Phishers use custom phishing kit to hijack MFA-protected enterprise Microsoft accounts

Phishers use custom phishing kit to hijack MFA-protected enterprise Microsoft accounts
2022-08-03 13:01

An ongoing, large-scale phishing campaign is targeting owners of business email accounts at companies in the FinTech, Lending, Insurance, Energy and Manufacturing sectors in the US, UK, New Zealand and Australia, Zscaler researchers are warning.

The attackers are using a variety of tecniques and tactics to evade corporate email security solutions and a custom phishing kit that allows them to bypass multi-factor authentication protection to hijack enterprise Microsoft accounts.

According to the researchers, the threat actor behing the campaign is using various cloaking and browser fingerprinting techniques to bypass automated URL analysis systems, and diverse URL redirection methods to evade corporate email URL analysis solutions.

Because of some unique attributes - HTML parsing, lack of domain traslation - the researchers believe that the attackers are using a custom adversary-in-the-middle phishing kit to phish the targets' second authentication factor as well as their email credentials.

"This indicates that the threat actor might have compromised the corporate emails of chief executives of these organizations using this phishing attack and later used these compromised business emails to send further phishing emails as part of the same campaign."

"As an extra precaution, users should not open attachments or click on links in emails sent from untrusted or unknown sources. As a best practice, in general, users should verify the URL in the address bar of the browser before entering any credentials," the researchers advised.


News URL

https://www.helpnetsecurity.com/2022/08/03/hijack-microsoft-accounts/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 681 811 4541 4194 3708 13254