It has recently become known that hackers are targeting user accounts in Office 365, through takeover attacks (ATO), with the aim of using them for other attacks, such as phishing, BEC attacks, and malicious advertising campaigns.
Some researchers showed in their report that during March, hackers sent 1.5 million malicious and spam emails, using 4,000 accounts, which they compromised through ATO attacks.
Hackers gained access to Office 365 accounts, installed malicious settings to hide their activity, and then deleted the phishing and spam messages they sent from the accounts.
The researchers found that the attacks came primarily from Chinese IP addresses (about a quarter of the total attacks). However, some also used servers located in Brazil (9%), Russia (7%), the Netherlands (5%), and Vietnam (5%).
Attack methods on Office 365
Hackers do a pretty careful job of deceiving victims. The methods they use are a combination of impersonation, phishing, and social engineering. The scammers use large companies (e.g. Microsoft) to trick victims into visiting specific pages, which are actually controlled by the hackers.
This way they can steal users' credentials.
Additionally, because many people use the same username and password on various accounts, hackers can use the stolen credentials and gain access to all accounts.
With the stolen credentials, hackers try to gain access to users' corporate emails (BEC attack-Business Email Compromise).
Researchers also discovered brute-force attacks, which exploit the fact that users use very easy and predictable passwords.
Before carrying out the attack, hackers monitor the businesses they target. What work the company does, how transactions are made, and much more. Based on this information and stolen credentials, criminals are able to carry out successful attacks.
They then use the compromised accounts to target company employees, especially those working in the finance department. Through BEC attacks and social engineering, they deceive employees.
An FBI report showed that criminals managed to extract about $1.2 billion in 2018 by carrying out this type of attack. According to the report, BEC/EAC attacks were the ones that earned hackers the most money.
In 2018, there were three times as many attacks of this type as in 2017, and more specialized methods were used.
According to the report , hackers use the compromised accounts to steal personal, financial and confidential data as well as for other crimes, while also attacking the companies' partners and customers.
Treatment
Experts recommend that organizations use machine learning to combat attacks that compromise email accounts.
Also, two-factor authentication is very useful, as it adds an extra layer of protection.
Finally, tools must be developed that will detect ATO attacks, monitor accounts, and alert you to any breaches. Training a company's employees to be able to recognize phishing emails and spot suspicious activity is equally important.
