Microsoft Warns of Large-Scale Use of Phishing Kits to Send Millions of Emails Daily

March 14, 2023Rabbi LakshmananThreat Intelligence / Cyber ​​Attack

Open-source man-in-the-middle (AiTM) phishing kits have found a large following in the cybercrime world due to their ability to orchestrate large-scale attacks.

Microsoft Threat Intelligence Tracks Threat Actors Behind Kit Development Under New Moniker DEV-1101.

AiTM phishing attacks typically involve an attacker deploying a proxy server between the user and the website to steal and intercept the target’s passwords and session cookies.

Such attacks are more effective because they can bypass multi-factor authentication (MFA) protection.

According to the tech giant, DEV-1101 is said to be the party behind several phishing kits that other criminals can buy or rent. This reduces the effort and resources required to launch a phishing campaign.

“The ability for attackers to purchase such phishing kits is part of the industrialization of the cybercrime economy and lowers the barrier to entry for cybercrime,” Microsoft said in a technical report. .

The service-based economy that facilitates such services can also lead to double theft, where stolen credentials are sent to both phishing-as-a-service providers and their customers.

The DEV-1101 open source kit comes with features that allow you to set up phishing landing pages that mimic Microsoft Office and Outlook, manage campaigns from your mobile device, and use CAPTCHA checks for detection. Needless to say, avoid it.

The service has undergone several enhancements since its debut in May 2022. Chief among them is the ability to manage the servers running the kit via the Telegram bot. Currently, the monthly license fee is $300 and the VIP license is $1,000.

Microsoft says it has detected a number of high-volume phishing campaigns spanning millions of phishing emails per day from various actors using the tool.

This included an activity cluster dubbed DEV-0928, which Redmond described as one of “DEV-1101’s more prominent patrons,” and since September 2022, over one million electronic Linked to phishing campaigns consisting of emails.

webinar

Discover the hidden dangers of third-party SaaS apps

Are you aware of the risks associated with third-party app access to your company’s SaaS apps? Join our webinar to learn about the types of permissions granted and how to minimize the risks.

reserve a seat

The attack sequence begins with a document-themed email message containing links to PDF documents. Clicking on this email message directs the recipient to a login page masquerading as Microsoft’s sign-in portal, but not before prompting the victim to complete her CAPTCHA procedure.

“Injecting a CAPTCHA page into a phishing sequence can make it difficult for automated systems to reach the final phishing page, but humans can easily click through to the next page.” said Microsoft.

While these AiTM attacks are designed to bypass MFA, it is critical that organizations employ phishing-resistant authentication methods, such as using FIDO2 security keys, to block suspicious login attempts.

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *