Microsoft Warns of Cloud Storage Threats and Financial Fraud Scams Targeting Customers

www.news4hackers.com-microsoft-warns-of-cloud-storage-threats-and-financial-fraud-scams-targeting-customers-microsoft-warns-of-cloud-storage-threats-and-financial-fraud-scams-targeting-customers

Microsoft has issued alerts regarding two emerging social engineering campaigns targeting Microsoft accounts and financial transactions.

Overview of the Emerging Threats

Microsoft has issued alerts regarding two emerging social engineering campaigns designed to compromise Microsoft accounts, leading to unauthorized access to cloud-based assets and fraudulent financial transactions. The first campaign, outlined in a September 9 blog post, involves unsolicited calls or messages to individuals’ personal phone numbers, falsely claiming they need to update passkey, multi-factor authentication (MFA), or single sign-on (SSO) settings. Attackers direct victims to counterfeit login pages to extract credentials and session tokens using adversary-in-the-middle (AiTM) techniques, or exploit device code phishing to bypass MFA protections. The second campaign targets employees by impersonating high-level executives, such as CEOs or presidents, to pressure staff into processing Automated Clearing House (ACH) payments of approximately $50,000. Microsoft attributed this scheme to the use of generative AI tools, which enable attackers to create highly convincing email threads and invoices. Both attacks pose significant risks, as compromised accounts often lead to the exfiltration of sensitive data, followed by extortion from groups like ShinyHunters and Helix.

First Campaign: Phishing for Credentials

The first campaign involves unsolicited calls or messages to individuals’ personal phone numbers, falsely claiming they need to update passkey, multi-factor authentication (MFA), or single sign-on (SSO) settings. Attackers direct victims to counterfeit login pages to extract credentials and session tokens using adversary-in-the-middle (AiTM) techniques, or exploit device code phishing to bypass MFA protections.

Second Campaign: Executive Impersonation for Financial Fraud

The second campaign targets employees by impersonating high-level executives, such as CEOs or presidents, to pressure staff into processing Automated Clearing House (ACH) payments of approximately $50,000. Microsoft attributed this scheme to the use of generative AI tools, which enable attackers to create highly convincing email threads and invoices. Both attacks pose significant risks, as compromised accounts often lead to the exfiltration of sensitive data, followed by extortion from groups like ShinyHunters and Helix.

Attack Methods: Adversary-in-the-Middle (AiTM) and Device Code Phishing

Attackers employ two primary methods to gain initial access: AiTM and device code phishing. In AiTM attacks, victims are tricked into logging into fake Microsoft portals hosted on domains such as passkeyhelpdesk.com or integratedsso.com, with subdomains tailored to the target organization to enhance credibility. These domains mimic legitimate Microsoft services, making the deception more plausible. Device code phishing leverages Microsoft’s official device code approval process, typically used for IoT devices, to grant attackers access to user accounts. Victims enter a code on a phishing page, which the attacker then uses to bypass MFA protections.

Adversary-in-the-Middle (AiTM) Attacks

In AiTM attacks, victims are tricked into logging into fake Microsoft portals hosted on domains such as passkeyhelpdesk.com or integratedsso.com, with subdomains tailored to the target organization to enhance credibility. These domains mimic legitimate Microsoft services, making the deception more plausible.

Device Code Phishing

Device code phishing leverages Microsoft’s official device code approval process, typically used for IoT devices, to grant attackers access to user accounts. Victims enter a code on a phishing page, which the attacker then uses to bypass MFA protections.

Data Exfiltration and Extortion Risks

Once access is achieved, attackers systematically extract data from cloud storage platforms like SharePoint Online and OneDrive for Business, as well as Exchange Online content via the REST API. Microsoft observed this data collection activity using a python-httpx user-agent, with attackers retrieving fewer than 1,000 files per hour to avoid detection. The pattern aligns with tactics used by threat groups such as Storm-3121 and Storm-3032, which have been linked to subsequent extortion operations by ShinyHunters and Helix.

Threat Groups and Extortion

The pattern aligns with tactics used by threat groups such as Storm-3121 and Storm-3032, which have been linked to subsequent extortion operations by ShinyHunters and Helix.

Executive Impersonation Campaign Details

A separate campaign involves impersonating executives to manipulate employees into approving fraudulent ACH payments. Microsoft reported that this scheme, active between August 3 and 5, involved over one million emails sent to U.S.-based targets. The emails featured fabricated email chains between executives and vendors like ServiceNow, complete with detailed invoices and fabricated signatures. Microsoft noted signs of AI-generated content, including excessive HTML comments and frequent use of em dashes. Inconsistencies in the emails, such as formatting discrepancies and missing email headers, were identified as red flags. For example, one email falsely claimed a CEO requested an invoice be sent directly to the recipient without a copy, despite the email appearing to originate from the CEO. Attackers utilized third-party service accounts to distribute the emails, complicating tracking efforts.

Red Flags and AI-Generated Content

Microsoft noted signs of AI-generated content, including excessive HTML comments and frequent use of em dashes. Inconsistencies in the emails, such as formatting discrepancies and missing email headers, were identified as red flags. For example, one email falsely claimed a CEO requested an invoice be sent directly to the recipient without a copy, despite the email appearing to originate from the CEO.

Microsoft’s Recommendations and Conclusion

Microsoft emphasized that social engineering tactics have evolved significantly, with AI reducing the time and effort required to create credible fraud scenarios. Experts noted that attackers can now scale these operations to target large audiences with minimal manual input. The company urged users to remain vigilant, verify requests for financial transactions through alternative communication channels, and implement additional security measures to mitigate risks associated with these campaigns.

Key Takeaways for Users

Microsoft urged users to remain vigilant, verify requests for financial transactions through alternative communication channels, and implement additional security measures to mitigate risks associated with these campaigns.



About Author

en_USEnglish