HomeSecurityTwitter hack: Beware! The same phishing technique targets dozens of companies

Twitter hack: Beware! Same phishing technique targets dozens of companies

phishing

When authorities arrested three young hackers in the US and UK for the massive Twitter hack, many thought the case was closed. However, it turns out that the phishing technique that allowed hackers to take control of the accounts of Joe Biden, Jeff Bezos, Elon Musk and dozens of other famous figures is still being used against many other companies.

In mid-July, Twitter revealed that hackers used a technique called “phone spear phishing,” which allowed attackers to target the accounts of 130 people, including CEOs, celebrities, and politicians. According to Twitter, the hackers called Twitter employees and, using fake identities, tricked them into giving up their credentials, gaining access to an internal company tool that allowed them to reset the passwords and two-factor authentication settings of the targeted accounts.

However, Twitter is not the only target of “phone spear phishing,” or as it is also known, “vishing” or “voice phishing.” This technique is essentially a form of social engineering. Since last month, dozens of companies – including banks, exchanges and web hosting companies– have been targeted with the same technique. As in the Twitter hack, employees of these companies received phone calls from hackers posing as IT personnel and asking for passwords to internal tools. The attackers then sold that access to others who used it to target users . The main goal was to steal cryptocurrencies.

“At the same time as the Twitter hack and in the days following, we saw a big increase in this type of phishing across many different industries,” says Allison Nixon, a security researcher at Unit 221b.

As with the Twitter hack, the perpetrators appear to be young, English-speaking hackers who organize themselves on forums like the website OGUsers.com and the chat service Discord, says researcher Zack Allen. The researcher says he has been shocked by the research the hackers did and their careful moves to find inexperienced employees and have a better chance of success.

“I’ve never seen anything like this before, nothing so targeted,” Allen says. He warns that the hackers’ tactic has been so effective that it’s only a matter of time before ransomware groups and state-sponsored hackers adopt it. What’s more worrying is that the attacks are not being carried out by professionals, but by teenagers.

“Phone spear phishing” is a relatively new practice for hackers. Until recently, attacks related to phones focused mainly on “SIM swap” attacks, which exploit telecommunications companies.

With the rise of remote work, phone-based social engineering has become more powerful

The same hackers who have honed their skills against telecommunications companies have found other industries less well-prepared for their tricks, researchers say.

Despite the hackers' young age, Nixon says the ongoing attacks appear to be well-coordinated and involve multiple hackers. In addition, the perpetrators are hiring freelance hackers who offer specialized voice spoofing services. There are such ads on forums to find the right people.

Twitter hack

In most cases, hackers use a VoIP service, which allows them to hide their phone number. They try to get the victim to trust them by mentioning seemingly private data, such as the victim's role in the company or names of their colleagues, etc. Once the victim is convinced, they ask them to go to a fake login page to enter their credentials.

Another member of the hacking group immediately takes this information and puts it on the real login page. The real login page then asks the victim to enter their two-factor authentication code. The user types this code into the fake website, and the hacker takes the code and puts it on the real page. This gives them access to the victim’s account. The fake site is taken down immediately after the victim’s credentials are stolen. The site being taken down and the phone spear phishing technique leave no trace of the attack, making it harder to detect. Employees almost never realize they are talking to a scammer. It is not like phishing emails that can be detected.

Companies should train their employees to spot suspicious phone calls or use FIDO tokens like Yubikeys for two-factor authentication. These USB dongles should be plugged into the USB port of any new machine when a user wants to access their accounts. Nixon also suggests using security systems that require a specific software certificate to be on a user's machine to gain access to accounts remotely, blocking everyone else.

Therefore, great caution is needed because if this technique is used by experienced or state hackers, the problems will be even greater.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS