HomeSecurityHackers use IMAP to infiltrate Office 365 & G Suite...

Hackers use IMAP to break into Office 365 & G Suite Cloud accounts

Based on the Proofpoint study, IMAP is the most abused protocol – IMAP is the protocol that bypasses MFA and lock-outs for failed logins. These clever new brute-force attacks take a new approach to traditional methods that used username and password combinations.

IMAP

Based on Proofpoint's analysis of over one hundred thousand unauthorized connections to millions of monitored cloud user accounts, we have the following conclusions:

  • 72% of accounts had been targeted by threats at least once
  • 40% had at least one compromised account in their environment
  • Approximately 2% of active user accounts were targeted by malicious actors
  • 15 out of 10,000 active user accounts were successfully compromised by the attackers

The ultimate goal of hackers is to initiate internal phishingandgain a strong position within the organization. Internal phishing attempts are difficult to detect compared to external ones.

Therefore, hackers try to gain access to the user's cloud accounts and try to expand their intrusion through internal phishing.

Based on Proofpoint analysis, most of the connection attempts come from Nigerian IP addresses (40%), followed by China (26%), and other significant sources are the United States, Brazil, and South Africa.

The report shows that IMAP is the most abused protocol and IMAP-based attacks are highest in volume from September 2018 through February 2019.

  • About 60% of Microsoft Office 365 and G Suite accounts were targeted by IMAP attacks
  • About 25% of Office 365 and G Suite users experienced a successful breach
  • The success rate of attackers on an account in a targeted organization was 44%

Proofpoint researchers found that “over 31% of all cloud users have been breached by successful espionage campaigns.”.

How does Phishing Attack work?

Hackers compromise users' cloud accounts and then send internal phishing emails from trusted accounts for lateral moves. Threat actors also use anonymization services like VPN or Tor to hide their geographic location.

The attack has a higher rate in educational institutions, especially university and high school students. The target also includes other industries such as retail, finance and technology.

The study shows that the threat landscape is driven by increasing sophistication with brute force attacks aimed at exposing cloud accounts.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS