Normal view
This phishing kit looks more like BEC-as-a-service
Toolkits to wage phishing campaigns are a now-venerable instrument for cybercriminals, but researchers recently turned up details on something like a full-fledged βbusiness email compromise-as-a-serviceβ platform.
Cisco Talos said Wednesday that it had found an operator panel dubbed ARToken, which shares infrastructure and other things in common with, and as an affiliate to, the EvilTokens phishing-as-a-service operation built to bypass multi-factor authentication and compromise Microsoft 365 accounts. EvilTokens has reportedly seen a dramatic increase in its phishing attacks β by 1,380% early this year compared to the same period last year β with an assist from artificial intelligence integration.
ARToken is notable, though, for the capabilities that go beyond whatβs been made public about EvilTokens so far by companies like Sekoia and Microsoft itself, such as inbox rule manipulation and shared access links.
βThese features indicate the platform is more mature than a simple device code phishing kit β it is a complete BEC operations environment,β wrote Michael Kelley, security research engineer at Cisco Talos, in a blog post, referring to business email compromise scams that involve sending fake emails to solicit fraudulent payments.
Kelley told CyberScoop that βweβve seen some offerings that touch on this capability, but this definitely seems more fleshed out and polished than previous instances.β
ARToken is also notable for its evasive capabilities, with a seven-layer anti-analysis system, the post states.
The research provides further details on what ARTokenβs actual phishing lures look like in practice. They are targeted, rather than scattershot and opportunistic, as one lure the firm examined shows.
βThe messages spoof an accounts-payable contact at a legitimate Wisconsin contractor, addressed to an accounts-payable recipient at a U.S. life sciences company β abusing a real vendor relationship rather than inventing a sender,β Kelley wrote. βThe lure theme is an outstanding-invoice inquiry (βthe following invoices appear to still be outstandingβ¦ advise when this will be processedβ), the kind of message accounts-payable staff are conditioned to act on.β
Kelley told CyberScoop that Cisco Talos doesnβt yet have a full sense of the breadth of the activity, nor who is making use of the capability.
βWeβve seen the public sector targeted but itβs unlikely to be the only one,β he said.
The post This phishing kit looks more like BEC-as-a-service appeared first on CyberScoop.
Better spreadsheets with sensible AI
FBI warns about fast-growing phishing kit targeting Microsoft 365 users
The FBI is warning organizations and defenders about Kali365, a growing phishing-as-a-service platform that retrieves Microsoft 365 access tokens, issuing a public service announcement Thursday.Β
The toolkit bypasses multi-factor authentication and abuses OAuth device code authorizations via phishing lures impersonating common enterprise services. This technique grants cybercriminal-controlled applications access to Microsoft 365 accounts, opening victims up to a host of follow-on malicious activity, including data theft, fraud, extortion and ransomware attacks.
Kali365 is one of many rapidly emerging device-code phishing tools, which are gaining popularity as a more effective means for cybercriminals to circumvent security controls while abusing legitimate Microsoft device authorization pages, according to researchers.Β
Instead of gaining access to accounts via phishing kits that steal credentials and second-factor authentication codes, device-code phishing platforms connect a malicious app to a legitimate account with a single code. The process requires fewer steps and less interaction with the user, but victims do have to copy-and-paste a code generated by the Kali365 platform to grant access.
βWe see quite a bit of this device-code phishing activity, but so much of it looks really similar. Theyβre all using the same types of lures, the same types of content, the same branding,β Selena Larson, senior threat researcher at Proofpoint, told CyberScoop. βIt is very much AI generated, AI driven, and the threat actors, I think, are finding it pretty effective because weβre seeing this shift happen kind of all at once.β
Proofpoint researchers observed seven device-code phishing tools that looked nearly identical during a 10-day period last month.
Device-code phishing isnβt new, but platforms like Kali365 have integrated new techniques that differ from MFA phishing, and might be more effective as a result. βItβs something that people might not be used to. Itβs a little bit sleeker,β Larson said.
This also partly explains why these cybercriminal tools are growing so quickly. Larson said Proofpoint observed an explosion in device-code phishing activity starting in February.Β
By April, Kali365 was up and running and primarily distributed on Telegram, according to the FBI. βKali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities,β the agency said in the public warning.Β
Researchers at Arctic Wolf Labs, which has also been tracking large-scale campaigns linked to Kali365, said the platform charges affiliates $250 for 30 days of service or $2,000 for a full year.
Kali365 stores the OAuth access and refresh tokens it captures, and makes those available to affiliates on its platform. Those tokens can also be shared and reused by other cybercriminals who didnβt participate in the initial phishing lure, Arctic Wolf researchers added.Β
The FBI also noted that these Microsoft 365 tokens provide persistent access, allowing attackers to wade through multiple Microsoft services without a password or additional MFA requests.Β
βIdentity can be very, very powerful once youβre in an organization,β Larson said, adding that attackers can abuse that access to impersonate people, access and steal data for extortion, commit fraud and deploy malware.
The post FBI warns about fast-growing phishing kit targeting Microsoft 365 users appeared first on CyberScoop.
Outlook rules move online
-
Black Hills Information Security
- Augmenting Security Testing and Analysis Activities with Microsoft 365 Products
Augmenting Security Testing and Analysis Activities with Microsoft 365 Products
![]()
Use of Microsoft 365 products in security testing is not a new concept. For a long time, Iβve incorporated various activities using Office products into my testing regimen. In the [β¦]
The post Augmenting Security Testing and Analysis Activities with Microsoft 365 Products appeared first on Black Hills Information Security, Inc..
Wrangling the M365 UAL with SOF-ELK and CSV Data (Part 3 of 3)
![]()
Patterson Cake // PART 1 PART 2 In part one of βWrangling the M365 UAL,β we talked about acquiring, parsing, and querying UAL data using PowerShell and SOF-ELK. In part [β¦]
The post Wrangling the M365 UAL with SOF-ELK and CSV Data (Part 3 of 3) appeared first on Black Hills Information Security, Inc..
Wrangling the M365 UAL with SOF-ELK on EC2 (Part 2 of 3)
Patterson Cake // In PART 1 of βWrangling the M365 UAL,β we talked about the value of the Unified Audit Log (UAL), some of the challenges associated with acquisition, parsing, [β¦]
The post Wrangling the M365 UAL with SOF-ELK on EC2 (Part 2 of 3) appeared first on Black Hills Information Security, Inc..
Wrangling the M365 UAL with PowerShell and SOF-ELK (Part 1 of 3)
Patterson Cake // When it comes to M365 audit and investigation, the βUnified Audit Logβ (UAL) is your friend. It can be surly, obstinate, and wholly inadequate, but your friend [β¦]
The post Wrangling the M365 UAL with PowerShell and SOF-ELK (Part 1 of 3) appeared first on Black Hills Information Security, Inc..
Spoofing Microsoft 365 Like Itβs 1995
![]()
Steve Borosh // Why Phishing? Those of us on the offensive side of security often find ourselves in the position to test our clientsβ resilience to phishing attacks. According to [β¦]
The post Spoofing Microsoft 365 Like Itβs 1995 appeared first on Black Hills Information Security, Inc..