HomeSecurityAiTM attack targets Google G-Suite Enterprise users

AiTM attack targets Google G-Suite Enterprise users

The AiTM phishing campaign targets Google Workspace users in addition to Microsoft corporate email service users.

The threat actors behind a large-scale adversary-in-the-middle (AiTM) targeting corporate users of Microsoft email services have also targeted Google Workspace users.

“This campaign specifically targeted executives and other senior members of various organizations using Google Workspace,” Zscaler researchers Sudeep Singh and Jagadeeswar Ramanukolanu in a report published this month.

AiTM attack targets Google G-Suite Enterprise users
AiTM attack targets Google G-Suite Enterprise users

The AitM phishing attacks are said to have begun in mid-July 2022, following a similar modus operandi to that of a social engineering campaign designed to wipe users' Microsoft credentials and even bypass multi-factor authentication .

See also: Google: Repel record-breaking HTTPS DDoS attack

The Gmail AiTM also involves the use of compromised executive emails to conduct further phishing attacks by the threat actor, with the attacks also using several compromised domains as an intermediary URL redirector to take victims to the landing page.

The attack chains involve sending password expiration emails to potential targets that contain an embedded malicious link to supposedly “extend access,” which leads the recipient to open Google Ads and Snapchat to load the phishing page URL.

AiTM attack targets Google G-Suite Enterprise users
AiTM attack targets Google G-Suite Enterprise users

In addition to the overt redirection abuse, a second variant of the attacks relies on infected websites hosting a Base64 encoded version of the next-stage redirector and the victim's email address in the URL. This intermediate redirector is JavaScript that leads to a Gmail phishing page.

In one case highlighted by Zscaler, the redirector page used in the Microsoft AiTM on July 11, 2022, was updated to take the user to a Gmail AiTM, linking the two campaigns to the same threat actor.

AiTM attack targets Google G-Suite Enterprise users
AiTM attack targets Google G-Suite Enterprise users

See also: Phishing: Sharp increase in abuse of legitimate SaaS platforms

"There was also an infrastructure overlap and we even identified several cases where the threat actor switched from Microsoft AiTM phishing to Gmail phishing using the same infrastructure," the researchers said.

The findings indicate that multi-factor authentication safeguards alone cannot offer protection against advanced phishing attacks, requiring users to carefully check URLs before entering credentials and avoid opening attachments or clicking links in emails sent from untrusted or unknown sources.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS