Threat hunters have disclosed a widespread data theft and extortion campaign that exploits corporate help desks to compromise executive Microsoft 365 and other SaaS accounts. The attack chain leverages vishing, adversary-in-the-middle (AitM) proxy session token theft, and residential-proxy evasion.
According to the researchers' findings, the operation specifically targets high-ranking officials, including directors, vice presidents, and other executive staff. The attack begins with vishing, where a threat actor impersonates an internal employee—often the executive themselves—and contacts IT support. Using a fabricated urgent scenario, they convince help desk staff to reset Multi-Factor Authentication (MFA) or account credentials.
Following the successful social engineering, the attackers deploy an AitM proxy during the subsequent login. This proxy captures the legitimate session token granted upon successful authentication, giving the attackers authenticated access to the executive's account and data without needing the password.
To mask their activity, the threat actors use residential proxy networks to sign in with the stolen tokens. This makes the malicious sessions appear to originate from typical home internet connections, evading alerts that would trigger for logins from data centers or unusual geographic locations.
The ultimate goals are data theft for espionage or sale, and extortion, with attackers threatening to release stolen internal documents unless a ransom is paid. This approach underscores a strategic shift by adversaries toward exploiting human trust relationships as cloud platforms themselves become more secure.
For defenders, the report serves as a critical alert to harden identity and access protocols. Immediate priorities include: * Mandate Out-of-Band Verification: Never process MFA resets or credential changes based solely on an inbound phone call. Verify identity through a separate, pre-established channel. * Deploy Phishing-Resistant Authentication: Accelerate the rollout of FIDO2 hardware keys or certificate-based authentication for privileged accounts to mitigate AitM token theft. * Hunt for Anomalous Sessions: Implement monitoring to flag sign-ins from residential IP ranges and configure identity solutions for continuous access evaluation to revoke suspicious sessions automatically. * Train and Simulate: Conduct targeted vishing awareness training for help desk and administrative staff, supported by regular simulated social engineering exercises. * Restrict Privileged Self-Service: For highly sensitive accounts, disable automated or phone-based self-service password resets, requiring stronger verification methods like in-person or video confirmation.
The campaign demonstrates that securing the internal trust fabric, particularly at the help desk, is now a fundamental component of enterprise cybersecurity.
威脅獵人已揭露一場大規模數據竊取及勒索行動,該行動利用企業客服熱線入侵高管的Microsoft 365及其他SaaS帳戶。攻擊鏈利用語音釣魚、中間人(AitM)代理會話代碼竊取及住宅代理規避技術。
根據研究人員的發現,該行動專門針對總監、副總裁及其他高管人員。攻擊始於語音釣魚,威脅行為者偽裝成內部員工——通常是高管本人——聯絡IT支援部門。利用偽造的緊急情況,他們說服客服人員重置多重驗證(MFA)或帳戶憑證。
在成功的社會工程學操作後,攻擊者於隨後的登入過程中部署中間人(AitM)代理。該代理會擷取成功驗證後獲發的合法會話代碼,使攻擊者無需密碼即可取得對高管帳戶及數據的認證存取權限。
為了掩飾活動,威脅行為者使用住宅代理網絡以被盜代碼進行登入。這使得惡意會話看似源自一般家庭網絡連線,從而規避因登入來自數據中心或異常地理位置而觸發的警報。
最終目標包括以間諜活動或出售為目的的數據竊取,以及勒索——攻擊者威脅除非支付贖金,否則將公開被盜的內部文件。此手法突顯對手在策略上轉向利用人際信任關係,因為雲端平台本身已趨於安全。
對於防禦方而言,報告發出了加強身份與存取協議的關鍵警示。當務之急包括: * 強制要求帶外驗證: 切勿僅憑來電處理MFA重置或憑證變更。應透過另一獨立預設渠道核實身份。 * 部署防釣魚驗證機制: 加速為特權帳戶推出FIDO2硬件密鑰或基於證書的驗證,以減輕AitM代碼竊取風險。 * 主動追蹤異常會話: 實施監控以標記來自住宅IP範圍的登入,並配置身份解決方案以持續評估存取權限,自動撤銷可疑會話。 * 進行培訓與模擬演練: 針對客服及管理人員進行針對性的語音釣魚防範意識培訓,並定期配合模擬社會工程學演習。 * 限制特權自助服務: 對於高度敏感的帳戶,應停用自動化或電話自助密碼重置功能,要求採用面對面或視像核實等更強驗證方式。
此攻擊行動表明,保護內部信任架構——尤其是客服熱線環節——現已成為企業網絡安全的基本組成部分。
