HomeSecurityFBI: Home proxies exploited in credential stuffing attacks

FBI: Home proxies exploited in credential stuffing attacks

The FBI raises awareness among admins about the increasing credential stuffing attacks using home proxies.

The Federal Bureau of Investigation (FBI) is warning of a growing trend of cybercriminals using home-made proxies to conduct credential stuffing without being monitored or blocked.

The warning was issued as a Private Industry Notification to the Bureau's Internet Crime Complaint Center (IC3) late last week to raise awareness among online platform administrators who need to implement defenses against credential stuffing attacks.

Credential stuffing is a type of attack wherethreat actors use large collections of username/password combinations exposed in previous data breaches to attempt to gain access to other online platforms.

Because people usually use the same password on every site, cybercriminals have abundant opportunities to take accounts without cracking passwords or finding any other information via phishing.

FBI: Home proxies exploited in credential stuffing attacks
FBI: Home proxies exploited in credential stuffing attacks

See also: Hackers steal crypto due to zero-day vulnerability in Bitcoin ATM

“Malicious actors using valid user credentials have the ability to access multiple accounts and services across multiple industries – including media companies, retail, healthcare, restaurant groups, and food delivery – to fraudulently obtain goods, services, and gain access to other online resources, such as financial accounts, at the expense of legitimate account holders,” the FBI statement said.

Because credential stuffing attacks have specific characteristics that differentiate them from normal login attempts, websites can easily detect and stop them.

To bypass basic protections, the FBI warns that threat actors are using home proxies to hide their real IP address behind those typically associated with home users, which are unlikely to be on block lists.

FBI: Home proxies exploited in credential stuffing attacks
FBI: Home proxies exploited in credential stuffing attacks

Proxies are web servers that accept and forward requests, making it appear that the connection originates from them and not from the attacker.

Home-based proxies are preferable to data center-hosted proxiesbecause they make it difficult for protection mechanisms to distinguish between suspicious and normal consumer traffic.

Typically, these proxies are made available to cybercriminals through the compromise of legitimate home devices, such as modems or other IoT devices , or through malware that turns a home user's computer into a proxy without the user's knowledge.

Using these tools, cybercriminals automate credential stuffing attacks, with bots attempting to log in to multiple websites using previously stolen login credentials.

Additionally, some of these proxy tools offer the option to brute force account passwords or include “configs” that modify the attack to meet specific requirements, such as unique characters, minimum password length, etc.

FBI: Home proxies exploited in credential stuffing attacks
FBI: Home proxies exploited in credential stuffing attacks

The FBI says credential stuffing attacks are not limited to websites and have been seen targeting apps mobile due to their poor security.

«Cybercriminals may also target a company's mobile device applications as well as its website», warns the FBI advisory.

“ Mobile apps, which often have weaker security protocols than traditional web apps, often allow a higher rate of login attempts, known as checks per minute (CPMs), facilitating faster account validation.”

In a joint operation involving the FBI and the Australian Federal Police, the agencies investigated two websites containing over 300,000 unique sets of credentials obtained through credential stuffing attacks.

The FBI says these sites had over 175,000 registered users and generated over $400,000 in sales for their services.

FBI: Home proxies exploited in credential stuffing attacks
FBI: Home proxies exploited in credential stuffing attacks

See also: Hackers target hotels and infect systems with malware

The FBI advisory urges admins to follow certain practices to help protect users from losing their accounts to credential stuffing attacks, even when they use weak passwords.

The key points include:

  • Offer MFA (multi-factor authentication) and encourage or even enforce its adoption across all accounts.
  • Download widely available credentials and compare them to customer accounts to find matches and force a password reset.
  • Use fingerprint checks to make sure the person trying to log in is the account owner.
  • Identify and monitor the default user agent strings used by credential stuffing attack tools.
  • Search and discover which configurations proxy tools are using for your website and apply targeted changes to render them useless.
  • Implement “shadow-banning” to limit what suspicious users/accounts can do on the platform without banning them.

Regular users can protect themselves by enabling MFA on their accounts, using strong and unique passwords, and remaining vigilant against phishing.

Source:

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS