EXECUTIVE SUMMARY
A threat group is behind a phishing-as-a-service campaign targeting Microsoft 365 accounts, using a combination of adversary-in-the-middle credential and token theft, as well as device code phishing. The campaign targets various sectors, including financial services, and aims to steal sensitive data and gain unauthorized access to systems. The attackers' goal is to disrupt business operations and potentially demand ransom.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A threat group is behind a phishing-as-a-service campaign targeting Microsoft 365 accounts, using a combination of adversary-in-the-middle credential and token theft, as well as device code phishing. The campaign targets various sectors, including financial services, and aims to steal sensitive data and gain unauthorized access to systems. The attackers' goal is to disrupt business operations and potentially demand ransom.[emaillocker id="1283"]
The malware infects systems through spoofed emails, often masquerading as legitimate communications from trusted vendors, such as RingCentral. Once inside, the malware uses various tactics, including encryption, persistence, and lateral movement, to maintain control and exfiltrate sensitive data. The attackers use a centralized backend infrastructure, sharing resources and proxy servers to maintain control and evade detection.
This threat is significant for organizations because it is difficult to detect and recover from, as it exploits trust in vendor communications and bypasses traditional email security controls. To defend against this threat, organizations should take defensive actions, such as patching vulnerabilities, monitoring email traffic, implementing robust backup systems, and using endpoint protection solutions to detect and prevent phishing attacks. Additionally, organizations should review their email security configurations to prevent domain-based exclusions from being exploited by attackers.
THREAT PROFILE:
| Tactic | Technique ID | Technique | Sub-technique |
| Resource Development | T1583 | Acquire Infrastructure | — |
| Initial Access | T1566.002 | Phishing | Spearphishing Link |
| Command and Control | T1090.002 | Proxy | External Proxy |
| Initial Access | T1199 | Trusted Relationship | — |
| Credential Access | T1557 | Adversary-in-the-Middle | — |
| Initial Access | T1078.004 | Valid Accounts | Cloud Accounts |
| Command and Control | T1102 | Web Service | — |
REFERENCES:
The reports contain further technical details:
https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/