``` Security researchers have demonstrated a method for stealing user credentials during routine login attempts by hijacking the trust relationship between identity platforms and multi-factor authentication (MFA) services. The technique, detailed by BleepingComputer, leverages legitimate administrative functions to create a persistent backdoor that bypasses conventional security monitoring.
The attack does not exploit a software bug but rather abuses the configuration processes that define trusted authentication providers. An attacker who first obtains administrative privileges on an organization's identity system—like Azure Active Directory or Okta—can register a rogue, attacker-controlled service as a legitimate external MFA provider.
Once this malicious provider is embedded, users logging in are seamlessly redirected to it after their password is verified. The initial password check occurs correctly against the legitimate identity provider, satisfying the first authentication factor. The system then hands the authentication flow over to the now-compromised MFA step. At this point, the attacker's portal presents a convincing page—such as a fake login form or a fraudulent MFA prompt—to capture whatever additional credentials or tokens the user enters, completing the attack and granting the attacker a fully authenticated session.
The stealth of this method creates a critical blind spot. Because the authentication chain appears valid at each step—the password is correct and the MFA provider is officially registered—standard security logs may not flag the activity as malicious. The attacker maintains persistent access using the user's own legitimate session.
To combat this threat, security experts urge organizations to secure the administrative control plane of their identity systems. Proactive governance is critical. Key defenses include treating administrative access to identity providers with the same caution as Domain Admin rights, enforcing least-privilege access, and mandating MFA for all administrative accounts.
Continuous monitoring is essential. Teams should regularly audit the list of configured external MFA providers and authentication partnerships, setting up alerts for any new registrations or changes. Where feasible, using natively integrated MFA solutions from the identity provider's vendor can reduce the attack surface by keeping the authentication flow within a single, controlled environment.
This incident highlights a core tenet of modern cybersecurity: the systems that manage trust have become primary targets. Securing logins now requires defending not just user passwords, but the entire administrative pipeline that configures and validates authentication pathways.
安全研究人員已展示一種方法,可在常規登入嘗試期間,透過劫持身份驗證平台與多重認證服務之間的信任關係,竊取用戶憑證。《BleepingComputer》詳細報導的這種技術,利用合法管理功能建立一個持續性後門,從而繞過常規安全監控。
這次攻擊並非利用軟件漏洞,而是濫用定義可信認證供應商的配置流程。首先取得組織身份驗證系統(如 Azure Active Directory 或 Okta)管理員權限的攻擊者,可以將一個由攻擊者控制的惡意服務註冊為合法的外部多重認證供應商。
一旦這個惡意供應商被嵌入系統,用戶在密碼驗證後便會被無縫重定向至該供應商。初步密碼檢查會正確地透過合法身份驗證供應商完成,滿足第一重認證因素。隨後系統會將認證流程移交給已被入侵的多重認證步驟。此時,攻擊者的入口網站會呈現一個看似可信的頁面——例如偽造的登入表格或欺詐性的多重認證提示——用以捕捉用戶輸入的任何額外憑證或令牌,從而完成攻擊,並令攻擊者獲得一個完全驗證的合法會話。
這種方法的隱蔽性造成一個重大盲點。由於整個認證鏈在每個步驟都顯得合法——密碼正確,且多重認證供應商已正式註冊——標準安全日誌可能不會將此活動標記為惡意。攻擊者利用用戶自身的合法會話維持持續訪問權限。
為對抗這種威脅,安全專家敦促組織加強其身份驗證系統管理員控制平面的防護。主動治理至關重要。關鍵防禦措施包括:以與Domain Admin權限同等的謹慎態度對待身份驗證供應商的管理員訪問權限、強制實施最低權限訪問原則,以及要求所有管理員帳戶必須啟用多重認證。
持續監控必不可少。團隊應定期審核已配置的外部多重認證供應商及認證合作夥伴名單,並為任何新註冊或變更設置警報。在可行情況下,使用身份驗證供應商原生整合的多重認證解決方案,可透過將認證流程保持在單一受控環境內來減少攻擊面。
這次事件突顯了現代網絡安全的一個核心原則:管理信任的系統已成為首要攻擊目標。保護登入安全現時不僅需要防護用戶密碼,還要保護整個配置及驗證認證路徑的管理員流程。
