Threat Advisory

Adversary-in-the-Middle Attack Campaign Hits Dozens of Global Organizations

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

Summary:[/subscribe_to_unlock_form]

 

Summary:[emaillocker id="1283"]

Numerous organizations worldwide have been subject to a comprehensive campaign of business email compromise (BEC), wherein the attackers employed adversary-in-the-middle (AitM) methods to execute their assaults. After a phishing attempt proved successful, the malicious actor managed to gain initial entry into the account of one of the targeted employees. Subsequently, they employed an 'adversary-in-the-middle' attack to circumvent Office365 authentication, ensuring continued access and persistence to that particular account. After establishing persistence, the threat actor proceeded to extract data from the compromised account and utilized their access to propagate phishing attacks against other employees within the victim's organization, as well as several external organizations specifically targeted by the attacker.

One of the client's employees received a phishing email that appeared to be sent from a legitimate mailbox of an external company, which is believed to have been compromised beforehand. The phishing email contained a hyperlink directing the recipient to a file sharing request page. This page was hosted on a domain that is suspected to have been compromised, and the URL path used was associated with the email sender's company. Upon clicking the provided link, the victim was redirected to an 'I'm not a robot' verification page hosted by Cloudflare. This page served as an anti-tracing measure to prevent easy detection of the attacker's activities. Once the victim successfully passed the verification check, they were redirected to a deceptive Office365 authentication page. This fraudulent page was generated using a phishing kit, designed to deceive the victim into entering their login credentials. Once the victim entered their credentials, the phishing kit initiated an 'Adversary in The Middle' (AiTM) attack. This attack involved forwarding the client's authentication and multi-factor authentication (MFA) challenge to a genuine Microsoft authentication service.

Simultaneously, the attacker stealthily captured the acquired session token and the stolen credentials, allowing them unauthorized access to the victim's account. Subsequently, the threat actor utilized the stolen token to log into the victim's account, granting them unauthorized access. To ensure persistent access, the attacker added a new multi-factor authentication (MFA) device to the account. This allowed them to maintain continued and unauthorized control over the compromised account. After establishing persistent access, the threat actor proceeded to create a new file sharing request site that was specifically tailored to the new victim's company and compromised account. This site served as a fraudulent platform for carrying out further malicious activities. The threat actor exfiltrate data from the compromised account. Additionally, they exploited their access to propagate phishing attacks targeting other employees within the victim's organization, as well as several external organizations that were specifically targeted by the attacker.Furthermore, apart from extracting sensitive data from the compromised account, the threat actor exploited their access to send new phishing emails containing the recently created malicious link. These emails were distributed to numerous employees within the client's organization, as well as additional targeted organizations. The aim was to expand the reach of the phishing campaign and ensnare more victims.

According to researchers, the phishing emails exhibited a "worm-like" behavior, propagating from one targeted organization to another and even spreading among employees within the same company. The precise magnitude of the campaign remains undisclosed at present, and further investigation is required to determine its full extent.

 

Threat Profile:

Tactic Technique Id Technique
Reconnaissance T1598 Phishing for Information
Resource Development T1586 Compromised Accounts
Initial Access T1566 Phishing
Credential Access T1003 OS Credential Dumping
T1557 Adversary-in-the-Middle
Exfiltration T1041 Exfiltration Over C2 Channel

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/06/adversary-in-middle-attack-campaign.html

[/emaillocker]
crossmenu