HomeSecurityXeon Sender: New tool for SMS phishing and spam attacks

Xeon Sender: New tool for SMS phishing and spam attacks

Hackers are using a malicious cloud tool, called Xeon Sender, to conduct SMS phishing and spam attacks on a large scale, abusing legitimate services.

Xeon Sender SMS phishing and spam attacks

“Attackers can use Xeon to send messages across multiple software-as-a-service (SaaS) providers, using valid credentials for the service providers,” said SentinelOne security researcher Alex Delamotte.

See also: Phishing scam targets OneDrive users to execute malicious PowerShell script

Services used to facilitate the mass distribution of phishing and spam SMS messages include Amazon Simple Notification Service (SNS), Nexmo, Plivo, Proovl, Send99, Telesign, Telnyx, TextBelt, and Twilio. However, hackers do not exploit vulnerabilities in these services. Xeon Sender uses legitimate APIs to conduct mass SMS spam attacks.

Xeon Sender is distributed via Telegram and hacking forums. The latest version, available for download as a ZIP file, is attributed to a Telegram called Orion Toolxhub (oriontoolxhub). Orion Toolxhub was created on February 1, 2023 and has 200 members. At times, it has also been used to distribute other malware.

Xeon Sender is also referred to as XeonV5 and SVG Sender and is written in Python. Early versions of the program have been detected as early as 2022. Since then, it has been reused by several threat actors for different malicious purposes.

See also: Proofpoint: Hackers exploited bug to send phishing emails

“Another version of the tool is hosted on a web server with a GUI,” Delamotte said. According to the expert, this hosting method removes a potential barrier to access, helping less skilled attackers who may not be familiar with running Python tools.

Xeon Sender, regardless of the variant used, offers users a command-line interface that can be used to communicate with the backend APIs of the chosen service provider and orchestrate mass SMS spam attacks.

This means that the attackers already have the necessary API keys to access the endpoints. The crafted API requests also include the sender ID, the message , and one of the phone numbers selected from a predefined list contained in a text file.

Xeon Sender also has features for validating Nexmo and Twilio account credentials , generating phone numbers for a given country code and area code, and checking the validity of a phone number.

Examining the tool's source code, SentinelOne found that it is designed to make debugging much more difficult.

The researcher says that defenses against this threat (Xeon Sender) include monitoring activity related to evaluating or modifying SMS sending permissions as well as observing changes to distribution lists (e.g., a large upload of new recipient phone numbers).

See also: New service for hackers combines phishing kits and malicious Android apps

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Xeon Sender: New tool for SMS phishing and spam attacks

The implications of the Xeon Sender tool are significant, especially in terms of cybersecurity and information privacy. As it leverages legitimate services, detecting this type of attack becomes increasingly complex. Companies and individuals must remain vigilant and adopt strong security to mitigate the risk of falling victim to such phishing and spam attacks.

updates to spam filters, continuous monitoring of incoming messages, and educating users about phishing risks can play a key role in safeguarding sensitive information. In addition, it is important for service providers to improve their identity verification mechanisms and monitor for unusual activity related to API usage to prevent exploitation by cybercriminals .

Additionally, individuals should be cautious about sharing sensitive information via SMS messages and always verify the authenticity of the sender before responding to any requests for personal or financial information.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS