Threat Advisory

Microsoft 365 Phishing Campaigns Rise

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A threat group is behind a phishing-as-a-service campaign targeting Microsoft 365 accounts, using a combination of adversary-in-the-middle credential and token theft, as well as device code phishing. The campaign targets various sectors, including financial services, and aims to steal sensitive data and gain unauthorized access to systems. The attackers' goal is to disrupt business operations and potentially demand ransom.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A threat group is behind a phishing-as-a-service campaign targeting Microsoft 365 accounts, using a combination of adversary-in-the-middle credential and token theft, as well as device code phishing. The campaign targets various sectors, including financial services, and aims to steal sensitive data and gain unauthorized access to systems. The attackers' goal is to disrupt business operations and potentially demand ransom.[emaillocker id="1283"]

The malware infects systems through spoofed emails, often masquerading as legitimate communications from trusted vendors, such as RingCentral. Once inside, the malware uses various tactics, including encryption, persistence, and lateral movement, to maintain control and exfiltrate sensitive data. The attackers use a centralized backend infrastructure, sharing resources and proxy servers to maintain control and evade detection.

This threat is significant for organizations because it is difficult to detect and recover from, as it exploits trust in vendor communications and bypasses traditional email security controls. To defend against this threat, organizations should take defensive actions, such as patching vulnerabilities, monitoring email traffic, implementing robust backup systems, and using endpoint protection solutions to detect and prevent phishing attacks. Additionally, organizations should review their email security configurations to prevent domain-based exclusions from being exploited by attackers.

THREAT PROFILE:

Tactic Technique ID Technique Sub-technique
Resource Development T1583 Acquire Infrastructure
Initial Access T1566.002 Phishing Spearphishing Link
Command and Control T1090.002 Proxy External Proxy
Initial Access T1199 Trusted Relationship
Credential Access T1557 Adversary-in-the-Middle
Initial Access T1078.004 Valid Accounts Cloud Accounts
Command and Control T1102 Web Service

REFERENCES:

The reports contain further technical details:
https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/

[/emaillocker]
crossmenu