Threat Advisory

Researchers Warns of Large-Scale AiTM Attacks Targeting Enterprise Users

Threat: Malicious Campaign
Criticality: High
[subscribe_to_unlock_form]

Summary:

A new, large-scale phishing campaign has been observed using adversary-in-the-middle (AitM) techniques to get around security protections and compromise enterprise email accounts. Prominent targets include fintech, lending, insurance, energy, manufacturing, and federal credit union verticals located in the U.S., U.K., New Zealand, and Australia. The ongoing campaign, effective June 2022, commences with an invoice-themed email sent to targets containing an HTML attachment, which includes a phishing URL embedded within it. Opening the attachment via a web browser redirects the email recipient to the phishing page that masquerades as a login page for Microsoft Office, but not before fingerprinting the compromised machine to determine whether the victim is actually the intended target. What stands out here is the use of different methods, counting open redirect pages hosted by Google Ads and Snapchat, to load the phishing page URL as opposed to embedding the rogue URL directly in the email.[/subscribe_to_unlock_form]

Summary:

A new, large-scale phishing campaign has been observed using adversary-in-the-middle (AitM) techniques to get around security protections and compromise enterprise email accounts. Prominent targets include fintech, lending, insurance, energy, manufacturing, and federal credit union verticals located in the U.S., U.K., New Zealand, and Australia. The ongoing campaign, effective June 2022, commences with an invoice-themed email sent to targets containing an HTML attachment, which includes a phishing URL embedded within it. Opening the attachment via a web browser redirects the email recipient to the phishing page that masquerades as a login page for Microsoft Office, but not before fingerprinting the compromised machine to determine whether the victim is actually the intended target. What stands out here is the use of different methods, counting open redirect pages hosted by Google Ads and Snapchat, to load the phishing page URL as opposed to embedding the rogue URL directly in the email.[emaillocker id="1283"]

References:

The following reports contain further technical details:

https://thehackernews.com/2022/08/researchers-warns-of-large-scale-aitm.html

https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services

[/emaillocker]
crossmenu