HomeSecurityKaspersky: New phishing campaign uses Windows Live ID

Kaspersky: New phishing campaign uses Windows Live ID

Kaspersky security experts are warning of a new scam that uses Windows Live ID as bait to extract personal information stored in user profiles on services such as Xbox LIVE, Zune, Hotmail, Outlook, MSN, Messenger, and OneDrive.

Kaspersky: New phishing campaign uses Windows Live ID

Users are receiving email warnings that their Windows Live ID accounts are being used to distribute spam and that they should be blocked.

To prevent their accounts from being suspended, users are asked to follow a link and update their information to comply with the service's alleged new security requirements.

This looks a lot like a typical phishing email, where those who follow the links are taken to fake websites that look like official ones and the data they enter there is sent to the scammers.

However, Kaspersky experts were surprised to find that the phishing email link led to a Windows Live page and there was no obvious attempt to steal victims' login details.
 
After following the link in the email and logging into their live.com account, users received a strange prompt from the service.

Kaspersky: New phishing campaign uses Windows Live ID

An app was requesting permission to automatically log in to the account, view profile information and contact list, and access user lists of personal and work emails.

The fraudsters gained access to this technique through security vulnerabilities in OAuth, the open protocol for granting permissions.

Users who click "Yes" do not hand over their login details, but do provide their personal information, email addresses of their contacts, as well as the nicknames and real names of their friends.

According to Kaspersky experts, cybercriminalscould also access other parameters, such as lists of appointments and important events. This information is more likely to be used for fraudulent purposes, such as sending spam to all contacts in the victim's address book or launching spearphishing attacks.

According to Andrey Kostin, Senior Web Content Analyst at Kaspersky Lab:

“We have known about the security vulnerabilities in the O Auth protocol for some time. In early 2014, a student from Singapore described possible ways to steal a user’s data after authentication.

However, this is the first time we have seen scammers using a phishing email to carry out these techniques. A scammer can use the information they intercept to create a detailed picture of users, taking into account information about what they do, who they meet, who their friends are, etc. This profile can then be used for criminal purposes.”

Developers of social network web applications that use the OAuth protocol are advised to:

▪ Avoid using open redirects from their websites
▪ Create a whitelist of trusted addresses for redirects made using the OAuth protocol, since fraudsters can perform a hidden redirect to a malicious site by finding an application that can be successfully attacked and changing its “redirect_uri” parameter.

Kaspersky: New phishing campaign uses Windows Live ID

According to Kaspersky experts, users are recommended to:

▪ Do not follow links received via email or through private messages on social media
▪ Do not give unknown applications the right to access personal data
▪ Make sure that they have fully understood the access rights they grant to each application
▪ If they discover that an application has already distributed spam or malicious links on their behalf, they can send a complaint to the administrator of the social networking site or online service and the application should be blocked
▪ Keep databasesand comprehensive anti-phishing protection solutions updated

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS