Initial access brokers (IABs) are phishing employees by calling or texting their personal devices, then exploiting the Microsoft Graph API to perform large-scale corporate data exfiltration.
It's almost unavoidable that, in general corporate settings, employees will use personal devices to access company resources. Only the most careful government, research, and other high-value organizations ban it entirely, and most security-forward organizations allow it insofar as employees don't use personal devices to engage with sensitive resources. Even this reasonable latter policy is being tested, though, by attackers who know how to maximize seemingly low-risk attack paths.
Since May, Microsoft researchers have tracked at least two threat actors — Storm 3032 and Storm-3121, in its nomenclature — exploiting personal devices to totally bypass companies' authentication security protections. Worse: The two Storms are then likely passing on their earned access to extortion groups, including the nettlesome ShinyHunters. (Microsoft however did not connect any known corporate breaches to these initial access campaigns.)
Related:Identity-Based AI Attack Threatens Security of Enterprise Data
IABs Exploit Personal Devices
It's intuitive that if an attacker wants to gain access to a corporate system, they should target a corporate account or device connected to it. The problem is that, in doing so, they'll have to face whatever security measures that company has in place to stop them: email security gateways, endpoint detection and response (EDR), what have you.
It's arguably far easier, then, to target employees' personal devices. Those — particularly mobile phones — possess few or no security barriers. And anyone who's worked in an office knows that people use their mobile phones in and around their work environments all the time.
Recently, threat actors have been calling or texting employees on their own devices, impersonating their employers' IT helpdesks. The pretext of the call is that the employee has to update some means of authenticating to their work accounts — a passkey, multifactor authentication (MFA), or a single sign-on (SSO) configuration — in order to not lose access to their work. Through a link sent to their phones, employees can log into their accounts and restore order.
If an employee doesn't shrewdly identify that an important work communication shouldn't reach them this way, they'll likely follow the phishing link to a convincing Microsoft sign-in page. At this point, attackers have been utilizing both adversary-in-the-middle (AiTM) techniques to steal credentials and session tokens, and device code phishing flows.
Related:Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
... continue reading