Microsoft: Hackers are using a new tactic to bypass multi-factor authentication. Microsoft says token theft attacks are on the rise. Here's what you need to do to protect yourself.
Microsoft has outlined several mitigations to protect against attacks on multi-factor authentication that will unfortunately make life more difficult for remote workers.
Three years ago, attacks on multi-factor authentication (MFA) were so rare that Microsoft didn't have decent statistics on them.
However, as MFA usage increases and password attacks become more common , Microsoft has seen an increase in attackers using token theft in their attempts to bypass MFA. See also : QBot phishing: Abuses Windows 10 Control Panel to infect devices

In these attacks, the attacker compromises a token issued to someone who has already completed MFA and reuses that token to gain access from a different device.
Tokens are central to OAuth 2.0, including Azure Active Directory (AD), which aim to make authentication simpler and faster for users, but in a way that is still resistant to password attacks.
“Recently, the Microsoft Detection and Response Team (DART) has seen an increase in attackers using token theft for this purpose,” Microsoft says.
In addition, Microsoft warns that token theft is dangerous because it does not require high technical skills, detection is difficult, and few organizations have implemented mitigation measures.
When accessing web applications that are protected by Azure AD, the user must present a valid token, which they can obtain after signing in to Azure AD using their credentials. Admins can then set a policy to require MFA to log in to an account from a browser. The token is issued to the user, presented to the web application, which validates it and grants access.
See also: Attacks on US airport websites. The next day
“When the user is phished, the malicious infrastructure captures both the user’s credentials and the token,” Microsoft explains.

Once both are stolen, the hacker can use them for multiple attacks. Microsoft points to BECas the biggest cause of financial losses from cybercrime today.
Tokens: Mitigating Theft
To address the threat of token theft attacks in MFA, Microsoft recommends shortening the session duration. Mitigations include the following:
- Reducing the session lifetime increases the number of times a user is forced to re-authenticate.
- Reducing the viable time of a token forces hackers to increase the frequency of token theft attempts.
- Microsoft recommends Conditional Access App Control in Microsoft Defender for Cloud Apps for users connecting from unmanaged devices
Users with high-level privileges, such as Global Domain admin, should have a separate identity just for the cloud.
See also: GitHub: Hacker breached dozens of orgs using stolen OAuth tokens
Source: zdnet.com
