Kaspersky Lab experts warn of a new scam that uses Windows Live ID as bait to extract personal information stored in user profiles on services such as Xbox LIVE, Zune, Hotmail, Outlook, MSN, Messenger, and OneDrive.
“Honest” phishing
Users are receiving email warnings that their Windows Live ID accounts are being used to distribute spam and that they should be blocked.
To prevent their accounts from being suspended, users are asked to follow a link and update their information to comply with the service's alleged new security requirements.
This looks a lot like a typical phishing email, where those who follow the links are taken to fake websites that look like official ones and the data they enter there is sent to the scammers.
However, Kaspersky Lab experts were surprised to find that the phishing email link led to the Windows Live page (Windows Live ID) and there was no obvious attempt to steal victims' login details.
The trick of cybercriminals
After following the link in the email and logging into their live.com, users received a strange prompt from the service. An app was asking for permission to automatically log in to the account, view profile information and contact list, and access user lists of personal and work emails.
The fraudsters gained access to this technique through security vulnerabilities in OAuth, the open protocol for granting permissions.
Users who click "Yes" do not hand over their login details, but do provide their personal information, email addresses of their contacts, as well as the nicknames and real names of their friends.
Digital fraudsters could also access other parameters, such as appointment lists and important events.
This information is more likely to be used for fraudulent purposes, such as sending spam to all contacts in the victim's address book or launching spearphishing attacks.
"We've known about the security holes in the OAuth protocol for some time. In early 2014, a Singaporean student described possible ways to steal a user's data after authentication. However, this is the first time we've seen scammers using a phishing email to implement these techniques."
A fraudster can use the intercepted information to create a detailed picture of users, taking into account information about what they do, who they meet, who their friends are, etc. This profile can then be used for criminal purposes,”said Andrey Kostin, Senior Web Content Analyst at Kaspersky Lab.
Developers of social network web applications that use the OAuth protocol are advised to:
- Avoid using open redirects from their websites
- Create a whitelist of trusted addresses for redirects made using the OAuth protocol, since fraudsters can perform a covert redirect to a malicious site by finding an application that can be successfully attacked and changing its “redirect_uri” parameter.
Users are advised to:
- Do not follow links they receive via email or through personal messages on social media
- Do not give unknown applications the right to access personal data
- Make sure they fully understand the access rights they grant to each application
- If they discover that an application has already distributed spam or malicious links on their behalf, they can send a complaint to the administrator of the social networking site or online service and the application will be blocked
- Keep antivirus databases and comprehensive anti-phishing protection solutions up to date
For more information, visit Securelist.com.
