HomeSecurityNew tool makes it easier to carry out phishing attacks by bypassing two-factor authentication...

New tool makes it easier to carry out phishing attacks by bypassing two-factor authentication

phishing Recently, it was revealed that there is a new tool that hackers to carry out phishing attacks, bypassing two-factor authentication. The worst thing is, it is not easy to detect and block. This tool makes it easier to carry out attacks, so companies should take protective measures.

The new tool was unveiled at the Hack in the Box conference in Amsterdam and released to GitHub a few days later. It consists of two components: a reverse-proxy, called Muraena, and a Docker container, called NecroBrowser.

Man-in-the-middle attacks

Typically, in phishing attacks, victims are taken to fake pages controlled by hackers. However, these attacks are not particularly effective when two-factor authentication is used.

To bypass two-factor authentication, phishing sites must act as proxies, forwarding requests on behalf of victims to legitimate sites and responding in real time. The ultimate goal is to enable session state cookies, which are used to connect legitimate sites to user accounts. These cookies can be placed in a browser, allowing direct access to the connected user accounts without requiring authentication.

This proxy-based technique has been known for some time. However, using it to carry out attacks was not a simple matter, as it required a lot of technical knowledge and many tools, such as the NGINX web server to act as a reverse-proxy. Then, the hackers would have to manually abuse the stolen session state cookies. Another obstacle is that some sites use technologies to prevent proxying.

Muraena and NecroBrowser were designed to bypass these protections and speed up the process, allowing more and more hackers to carry out attacks. The tools were created by researchers Michele Orru and Giuseppe Trotta.

How do Muraena and NecroBrowser work?

Muraena is written in the programming . This means that Muraena can run on any platform where Go is available. Hackers can use it to modify their phishing domain and obtain a legitimate certificate.

The tool has a server that acts as a reverse proxy and a detector that automatically determines the resources to be used by the legitimate site. The proxy processes the requests received from the victim before forwarding them.

The crawler automatically creates a JSON file, which is modified and can bypass various defenses on more complex websites.

When the victim is redirected to a phishing page that has Muraena installed, the login process will be exactly the same as on a real site. They will be prompted for their two-factor authentication code, and once the verification process is complete, the proxy will steal the session state cookie.

Cookies are stored by the browser in a file. This allows hackers to gain access to connected accounts for a certain period of time without being asked for a password again.

Muraena then passes the stolen cookies to NecroBrowser, which immediately begins abusing them.

The abuse involves taking screenshots of emails, resetting passwords, collecting information about contacts and friends on social media, sending phishing emails to friends, and more.

How to protect yourself from these phishing attacks?

It seems that it is very difficult to provide complete protection against these attacks, since this particular tool was created to bypass existing protection measures.

However, not all two-factor authentication methods can be bypassed. For example, those that use USB hardware tokens with support for the Universal 2nd Factor (U2F) standard cannot be bypassed. This is because these USB tokens are connected with special encryption processes to the legitimate site, via the browser, and do not go through the attacker's reverse-proxy.

In contrast, verification based on codes received via SMS or generated by apps is vulnerable. This is because victims enter the code manually, so there is a risk of entering it on a phishing site.

Another protection measure is to use an extension that checks whether the user is entering their credentials on the correct site. Google has such an extension for Chrome. It's called Password Alert and it warns users if they attempt to enter their credentials on a site that isn't owned by Google.

Users need to be trained to recognize fake pages and be constantly vigilant. TLS/SSL protocols and valid certificates are not enough to make a site legitimate. Certificates can now be obtained for free, so most phishing sites can be displayed with HTTPS.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS