This phishing kit looks more like BEC-as-a-service
Toolkits to wage phishing campaigns are a now-venerable instrument for cybercriminals, but researchers recently turned up details on something like a full-fledged βbusiness email compromise-as-a-serviceβ platform.
Cisco Talos said Wednesday that it had found an operator panel dubbed ARToken, which shares infrastructure and other things in common with, and as an affiliate to, the EvilTokens phishing-as-a-service operation built to bypass multi-factor authentication and compromise Microsoft 365 accounts. EvilTokens has reportedly seen a dramatic increase in its phishing attacks β by 1,380% early this year compared to the same period last year β with an assist from artificial intelligence integration.
ARToken is notable, though, for the capabilities that go beyond whatβs been made public about EvilTokens so far by companies like Sekoia and Microsoft itself, such as inbox rule manipulation and shared access links.
βThese features indicate the platform is more mature than a simple device code phishing kit β it is a complete BEC operations environment,β wrote Michael Kelley, security research engineer at Cisco Talos, in a blog post, referring to business email compromise scams that involve sending fake emails to solicit fraudulent payments.
Kelley told CyberScoop that βweβve seen some offerings that touch on this capability, but this definitely seems more fleshed out and polished than previous instances.β
ARToken is also notable for its evasive capabilities, with a seven-layer anti-analysis system, the post states.
The research provides further details on what ARTokenβs actual phishing lures look like in practice. They are targeted, rather than scattershot and opportunistic, as one lure the firm examined shows.
βThe messages spoof an accounts-payable contact at a legitimate Wisconsin contractor, addressed to an accounts-payable recipient at a U.S. life sciences company β abusing a real vendor relationship rather than inventing a sender,β Kelley wrote. βThe lure theme is an outstanding-invoice inquiry (βthe following invoices appear to still be outstandingβ¦ advise when this will be processedβ), the kind of message accounts-payable staff are conditioned to act on.β
Kelley told CyberScoop that Cisco Talos doesnβt yet have a full sense of the breadth of the activity, nor who is making use of the capability.
βWeβve seen the public sector targeted but itβs unlikely to be the only one,β he said.
The post This phishing kit looks more like BEC-as-a-service appeared first on CyberScoop.