HomeSecurityProofpoint: Hackers exploited bug to send Phishing emails

Proofpoint: Hackers exploited bug to send phishing emails

An unknown threat actor has been linked to an extensive phishing campaign that exploited email misrouting in the defenses of email security vendor Proofpoint.

proof point

This campaign has resulted in the sending of millions of phishing emails, which appear to come from various legitimate companies.

"These emails were transmitted by official Proofpoint relays, with certified SPF and DKIM signatures, thus bypassing important security measures. Their purpose was to defraud recipients and steal money and credit card information," said Nati Tal, a researcher at Guardio Labs, in a detailed report published on The Hacker News.

Read more: New service for hackers combines phishing kits and malicious Android apps

Guardio Labs has dubbed the campaign “EchoSpoofing.” The activity is estimated to have begun in January 2024, with the threat actor exploiting the flaw to send an average of up to three million emails per day. That number reached 14 million in early June, as Proofpoint began implementing countermeasures.

"The idea behind EchoSpoofing is really powerful. It's strange that it's being used for large-scale phishing instead of a targeted spear-phishing campaign, where a hacker can quickly impersonate any member of a company's team and send emails to other associates, ultimately gaining access to internal data or credentials and putting the entire company at risk."

The hackers' technique involves sending messages from an SMTP server to a virtual private server (VPS), which complies with authentication and security measures such as SPF and DKIM, which are intended to prevent hackers from impersonating a legitimate domain.

These emails are routed through various Microsoft 365 users controlled by malicious actors and then relayed through Proofpoint's enterprise customer email infrastructures, ending up with people using free email apps like Yahoo!, Gmail, and GMX.

This situation arises from what Guardio describes as a “super-permissive misconfiguration flaw” in Proofpoint servers (“pphosted.com”), which allowed spammers to exploit the email infrastructure to send their messages.

See also: CrowdStrike: Phishing attacks target German customers

The main cause is a feature that configures email routing on Proofpoint servers, allowing the relay of outbound organization messages from Microsoft 365 users, without specifying which tenants would have this permission, according to Proofpoint in a coordinated report shared with The Hacker News.

“Any email infrastructure that offers this capability could be targeted by spammers.” In other words, a hacker could exploit this vulnerability to install malicious Microsoft 365 tenants and send fake emails to Proofpoint’s relay servers, from where they would return as genuine digital shipments impersonating customer domains.

This is achieved by tailoring the outgoing Exchange Server email connection directly to the vulnerable pphosted.com endpoint associated with the client. In addition, a tampered version of the legitimate PowerMTA email sending software is used to send the messages.

“The spammer used a rotating series of virtual private servers (VPS) from different providers, launching rapid bursts of thousands of messages at a time from their SMTP servers. These messages were sent to Microsoft 365 for relay to Proofpoint servers,” Proofpoint said.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

“Microsoft 365 accepted these phishing emails and forwarded them to customers’ email infrastructures for relay. When the customers’ domain was spoofed during relay through the customer infrastructure, applying DKIM signing along the message path through Proofpoint resulted in increased deliverability of the spam messages.

There are suspicions that the operators deliberately chose the EchoSpoofing tactic to create illicit sources of revenue while avoiding the risk of exposure for extended periods. Directly targeting companies could increase the chances of detection, jeopardizing the entire scheme.

However, it is unclear who is behind this campaign. Proofpoint said the activity is not associated with a known actor or threat. “In March, Proofpoint researchers identified spam campaigns that were transmitted through a limited number of Proofpoint customer email infrastructures, sending spam messages from Microsoft 365 users,” Proofpoint said. “All analysis indicates that this activity originated from a spam actor, whose identity we do not attribute to a known entity.”

Read also: ODPA calls for increased security after phishing attacks in Guernsey

“Since discovering this spam campaign, we have been working hard to provide remediation guidance, including implementing an improved administrative interface for customers to specify which M365 tenants are allowed to relay, while all other users are automatically rejected.”

Proofpoint stressed that no customer data was exposed or lost as a result of these campaigns, and said it has contacted some customers directly to adjust their settings to limit the effectiveness of the spamming activity.

“As we began to block the spammer’s activity, he accelerated his testing and quickly turned to other customers,” the company said. “We created an ongoing process to identify affected customers on a daily basis, prioritizing the approach to correct their settings.

To reduce spam, VPS providers are urged to limit their users’ ability to send large amounts of messages through the SMTP servers they host on their infrastructure. Additionally, email service providers are urged to limit the capabilities of free trials and unverified startups so that they cannot send outbound bulk emails. It is also important to prevent the sending of messages that mislead about domain ownership for which there is no proof that they belong.

proof point

“For CISOs, the key challenge is ensuring that their organization’s approach to the cloud is right, especially when using third-party services that form the backbone of a company’s network and communications processes,” said Tal. “In the email domain, it’s crucial to always maintain a feedback mechanism and your own control, even if you have complete trust in your email provider.”

See more: North Korean hackers Andariel turn to ransomware

"As for other companies that provide these types of services, like Proofpoint, they need to be vigilant and think proactively about all possible types of threats. Not just threats that affect their customers, but also the wider public.".

"It is vital for the security of all of us, and the companies that create and manage the internet, even if they are private, bear the greatest responsibility."

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS