HomeSecurityConsent-phishing attack passes Microsoft's 'Verified Publisher' checks

Consent-phishing attack passes Microsoft's 'Verified Publisher' checks

Despite Microsoft's strict "Verified Publisher" security checks, a Consent-Phishing attack managed to get past them.

Microsoft announced that it has taken steps to disable fake Microsoft Partner Network (MPN) accounts that were used to create malicious OAuth applications as part of a phishing campaign designed to compromise organizations' cloud environments and steal emails.

“The apps created by these fraudulent actors were then used in a consent-phishing campaign, which tricked users into granting permissions to the fraudulent apps,” Microsoft said. “This phishing campaign targeted a subset of customers based primarily in the United Kingdom and Ireland.”

See also: New Sh1mmer ChromeBook exploit unenrolls managed devices

phishing OAuth consent-phishing microsoft

Microsoft has warned that fraudulent Microsoft Partner Network (MPN) accounts were used in a phishing campaign that presented fake applications that tricked victims into granting them access to their email accounts.

To disguise their malicious activities, the attackers created fraudulent MPN accounts and published fake apps that closely resembled the legitimate ones, such as “Single Sign On (SSO)” and “Meeting,” with recognizable Zoom icons and URLs. This was discovered by security firm Proofpoint, which was able to reveal these subtle differences between the fake apps and the real ones.

See also: Prilex PoS malware: Can prevent contactless transactions

To launch their malicious campaign, the attackers impersonated trusted organizations to join the Microsoft Cloud Partner Program, or MCCP (formerly known as the Microsoft Partner Network, or MPN). They then used these accounts to add a verified issuer to OAuth application registrations that were built in Azure Active Directory (AD).

Microsoft has labeled this attack as “consent phishing,” as attackers use fraudulent applications and Azure AD-based OAuth consent requests to trick victims into granting permissions, such as reading emails, accessing contacts, etc., for up to a year. Additionally, with verified publisher status achieved by being verified by Microsoft, the publisher’s name receives a blue “verified” badge that serves as a sign of trust.

In a blog post, Microsoft said that the phishing attempts were targeting several customers located in the United Kingdom and Ireland. In addition to disabling these malicious applications, they have also issued a notification to all affected customers.

Microsoft has seen a steady increase in consent phishing incidents in recent years, where the technique has been used to target Office 365. Once granted by a victim, OAuth permission tokens are useful because the attacker does not require the target's account password, but still has access to confidential data. Microsoft recently updated its white paper on the style of attack.

See also: Pig butchering scams: Fake crypto apps on App Store and Google Play

On December 6, Proofpoint detected the malicious external OAuth applications and notified Microsoft on December 20. This phishing activity was terminated on December 27. Microsoft was notified of this consent-phishing campaign on the 15th of the same month.

Proofpoint highlights that consent phishing for authorized OAuth permissions poses a powerful threat, giving malicious applications the ability to act as if they were the user themselves. This includes accessing mailbox resources, calendars, and meeting invitations associated with compromised accounts.

Microsoft pointed out that the primary purpose of this campaign is to hijack a target organization's email.

After a thorough investigation, Microsoft has concluded that malicious actors were able to leak the emails of users who had granted authorization to third-party OAuth applications. The individuals affected by this breach have been notified and are aware of the situation.

So how did the threat actors bypass Microsoft’s MPN/MCPP checks? According to Proofpoint, the hackers displayed a name on their fraudulent apps that resembled the name of an existing legitimate publisher. Meanwhile, they hid the actual “verified publisher” name, which was different from the display name. Proofpoint notes that, in two cases, the hackers received verification just a day after they created the malicious app.

consent-phishing microsoft

Once the attacker obtained a verified publisher ID, they also added links to each app in the “Terms of Service” and “Policy Statement” of the impersonated organization’s website. In the past, consent-phishing campaigns have compromised existing MPN-verified publishers to abuse OAuth. The new method strengthens the credibility of malicious OAuth apps.

Microsoft has taken key steps to strengthen the MCPP verification process and reduce any potential fraudulent behavior in the future. Numerous additional security precautions have been put in place to ensure the utmost security for all users involved.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS