HomeSecurityFBI Warning: MFA Flaw Exploited by Government Hackers

FBI Warning: MFA Flaw Exploited by Government Hackers

According to the FBI, Russian state-backed hackers gained access to a cloud after enrolling their own device in the organization's Duo MFA after exploiting faulty default multi-factor authentication (MFA) protocols.

See also: FBI: Ragnar Locker ransomware has targeted 52 organizations belonging to US critical infrastructure
FBI Warning: MFA Flaw Exploited by Government Hackers

To breach the network, they used credentials from a brute-force password guessingto gain access to an unregistered and inactive account that had not yet been deactivated in the organization's Active Directory.

Because Duo’s default configuration settings allow for re-registration of a new device for dormant accounts, malicious users were able to register a new device for that account, complete the authentication requirements, and gain access to the victims’ network,” federal agencies explain.

The next step was to disable the MFA service by redirecting all Duo MFA calls to localhost instead of the Duo server, after modifying a domain controller file.

This allowed them to control identity on the nonprofit's virtual private network (VPN) as non‑administrators, to connect to Windows domain controllers via Remote Desktop Protocol (RDP) and to obtain credentials for other domain accounts.

See also: FBI: BlackByte ransomware has targeted critical US infrastructure

With the help of these compromised accounts and without MFA enforcement, malicious users from Russiacould move laterally and gain access to cloud storage and email accounts and infiltrate data.

FBI Warning: MFA Flaw Exploited by Government Hackers

The FBI and CISA urged all organizations to implement the following mitigation measures:

  • Enforcement of MFA and revision of configuration policies to protect against “fail open” scenarios and re-registration.
  • Verify that all inactive accounts are uniformly disabled in Active Directory and MFA systems.
  • Patch all systems, prioritizing code updates for known exploitable vulnerabilities.

See also: Lockbit ransomware: FBI provides details on the operation and protection tips

The two federal agencies shared additional information on tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and recommendations for protecting against this malicious activity.

Previous security advisories also warned that Russian state-sponsored hackers target and compromise U.S. defense contractors supporting the U.S. Army, the Air Force, the Navy, the Space Force, and Department of Defense and Intelligence programs.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS