HomeSecurityPhishing attacks manage to bypass Microsoft Office MFA!

Phishing attacks manage to bypass Microsoft Office MFA!

Microsoft says a massive series of phishing attacks has targeted more than 10,000 organizations starting in September 2021, which manage to bypass Microsoft Office MFA! In fact, hackersthen use access to victims' inboxes in subsequent business email compromise (BEC) attacks.

Microsoft Phishing MFA

Hackers used landing pages designed authentication process Office 365 (even on accounts protected by multi-factor authentication (MFA)) by spoofing the Office online authentication page.

In some of the attacks observed, potential victims were redirected to landing pages from phishing emails using HTML attachments that acted as gatekeepers.

After stealing the targets' credentials and cookies session, the hackers behind these attacks accounts email the victims' They then used their access to launch business email compromise campaigns targeting other organizations.

“A large-scale phishing campaign using adversary-in-the-middle (AiTM) phishing sites stole passwords, compromised a user’s login session, and bypassed the authentication process even if the user had enabled multi-factor authentication (MFA),”said the Microsoft 365 Defender research team and the Microsoft Threat Intelligence Center (MSTIC).

“The attackers then used the stolen credentials and session cookies to gain access to the affected users’ inboxes and execute subsequent business compromise (BEC) campaigns against other targets.

The phishing process used in this large-scale Phishing campaign can be automated with the help of many open source Phishing tools including the widely used Evilginx2, Modlishka, and Muraena.

The phishing websites used in this campaign operated as reverse proxies and were hosted on web servers designed to forward the targets' authentication requests to the legitimate website they were attempting to connect to via two separate Transport Layer Security (TLS) sessions.

Microsoft Phishing MFA BEC attacks

Using this tactic, the attackers' phishing page acted as a man-in-the-middle agent that intercepted the authentication process to extract sensitive information from compromised HTTP requests, including passwords and, more importantly, session cookies.

After the attackers got their hands on the targets' session cookie , they imported it into their own web browser, which allowed them to bypass the authentication process, even if the victims had enabled MFA on the compromised accounts.

To defend against such attacks, Microsoft recommends using "phish-resistant" MFA applications with certificate-based authentication and Fast ID Online (FIDO) v2.0 support.

Other recommended best practices that would enhance protection include monitoring for suspicious login attempts and activity, as well as conditional access policies that would prevent attackers from attempting to use stolen cookie sessions from no-trust devices or untrusted IP addresses. “While AiTM phishing attempts to bypass MFA, it’s important to emphasize that implementing MFA remains an essential pillar of identity security,” Redmond added.

“MFA is still very effective at stopping a wide variety of threats. Its effectiveness is why AiTM phishing appeared in the first place.” Additional technical details and indicators of compromise associated with this campaign are available at the end of Microsoft’s report.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS