tag: Phishing · 27 items
- Engineer — Skip
- SOC/IR — Learn: TVRAT and DarkVNC are remote access trojans worth reviewing in your detection library; no new IOCs or active campaign signals in this item, but the freelancer-targeting lure pattern is worth noting for awareness.
- Leader — Learn: A useful data point on scale of freelancer-targeting campaigns (80,000 victims) for risk discussions around contractor onboarding and device trust policies.
- Engineer — Skip
- SOC/IR — Learn: Decade-old campaign with no current exploitation or IOCs; useful as historical context for malicious-attachment lure tradecraft but yields no actionable detection work today.
- Leader — Learn: Demonstrates ongoing DoJ extradition efforts against cybercrime actors; no immediate vendor exposure or board-level risk action required given the 2016–17 vintage of the campaign.
- Engineer — Learn: No CVE or patch involved — attackers are abusing a legitimate admin tool’s functionality. Review whether Faronics Deploy is in your environment and whether its deployment permissions are appropriately scoped.
- SOC/IR — Act: Hunt for unexpected ScreenConnect installations originating from Faronics Deploy processes; build detections for remote-management tool deployments not initiated by IT change management workflows.
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: SANS ISC diary on the Astaroth/Guildma infection chain; useful for understanding email-lure TTPs, but the summary is too thin to extract IOCs — read the full diary if this actor targets your sector.
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: The analysis of polymorphic phishing page behavior — including how the page mutates and occasionally self-breaks — offers useful context for tuning detection logic around evasive phishing infrastructure, but there are no IOCs or detections provided here.
- Leader — Skip
- Engineer — Learn: This highlights npm and its mirrors being misused as hosting infrastructure for phishing redirects — not a package-level supply-chain attack, but a reminder that npm CDN URLs can surface malicious HTML content. No patch or config change needed today; worth noting if internal tooling renders or fetches npm-hosted content for users.
- SOC/IR — Learn: A novel phishing delivery technique using trusted npm mirror domains as redirect hosts; without specific IOCs in this report, there is no immediate hunt to run, but analysts should track for follow-on reporting with domains or URLs to add to proxy/DNS blocklists.
- Leader — Skip
- Engineer — Learn: Novel abuse of unpkg CDN as free phishing infrastructure — developers who install the packages are not the target, but this technique shows how legitimate CDN reputation can carry malicious payloads. Worth factoring into proxy/WAF policy reviews for unpkg.com egress.
- SOC/IR — Plan: ClickFix-style fake CAPTCHA pages hosted on unpkg.com may bypass domain-reputation filters; build or tune proxy detections for unpkg.com redirects to non-package HTML content and correlate with clipboard-execution behaviors downstream.
- Leader — Skip
- Engineer — Learn: No exploitable software vulnerability here — the attack surface is social engineering over Teams external messages. Review whether your Teams tenant restricts external/guest messaging and confirm phishing-resistant MFA is enforced for all accounts.
- SOC/IR — Plan: Active campaign using Teams external messages to deliver a fake lock screen overlay for credential harvesting; build or tune detections for Teams-sourced phishing followed by unusual lock screen events and credential access patterns in EDR telemetry.
- Leader — Learn: Confirms Microsoft Teams is an active credential-phishing vector, useful context for awareness training priorities, but no corroborating signals or sector-specific targeting reported that would require immediate leadership action.
- Engineer — Learn: Research on how attackers abuse trusted communication channels (Slack, Teams, email) for credential theft; review OIDC/SAML trust configurations and conditional access policies as a follow-up architecture exercise.
- SOC/IR — Plan: Unit 42 analysis of TTPs for collaboration-tool identity phishing is worth building detections around this quarter — prioritize tuning alerts for anomalous OAuth consent grants and unusual login sources following collaboration-platform interactions.
- Leader — Skip
- Engineer — Learn: No exploited vulnerability or configuration to change; this is a conceptual piece on how AI-generated sender agents are outpacing signature-based email filters — useful context when evaluating email security tooling this cycle.
- SOC/IR — Learn: No IOCs or ATT&CK-mapped TTPs, but the framing — that phishing intent is now harder to detect because the sender is an AI agent, not a human — is worth internalizing when tuning behavioral email analytics.
- Leader — Learn: No breach or regulation trigger; the AI-on-both-sides framing is useful background for board-level conversations about whether current email security investment is keeping pace with AI-enabled adversaries.
- Engineer — Plan: Active campaign bypasses MFA via session-token theft on M365 — no KEV or PoC signals, but the exposure is real. Prioritize enforcing phishing-resistant MFA (FIDO2/passkeys) for finance and payroll accounts in Entra ID conditional access policies this quarter.
- SOC/IR — Act: Widespread active campaign with clear TTPs: AitM proxy intercept, residential proxy blend-in, and finance-account targeting. Hunt M365 sign-in logs for logins from residential proxy ASNs, and sweep finance/payroll mailboxes for new unauthorized forwarding rules or OAuth app grants added since the campaign was reported.
- Leader — Plan: An active, widespread BEC-style campaign harvesting payroll and finance email warrants directing the security team to assess phishing-resistant MFA coverage for high-risk financial roles and briefing finance leadership on social-engineering risk this quarter.
- Engineer — Skip
- SOC/IR — Act: A phishing campaign is actively distributing ScreenConnect as a RAT using COLDCARD vulnerability lures; hunt for unexpected ScreenConnect installations on endpoints and tune EDR detections for ScreenConnect deployed outside approved baselines.
- Leader — Learn: This campaign illustrates how high-profile crypto incidents are rapidly weaponized as phishing lures; useful context for security awareness briefings but no immediate organizational action required.
- Engineer — Learn: Browser-level, technique-based phishing detection is a useful design principle to evaluate when assessing IdP or SSO defenses, but no specific CVE or configuration change is required today.
- SOC/IR — Plan: Evaluate whether current phishing detections rely heavily on domain blocklists and investigate adding technique-based behavioral signals (e.g., credential-harvest page patterns) to supplement IOC-driven coverage.
- Leader — Learn: Useful framing for a board conversation about why threat intelligence investments have diminishing returns against AI-assisted phishing — relevant for future budget and vendor evaluation discussions.
- Engineer — Learn: No CVE or patchable component; this is a social-engineering lure delivering macOS malware via fake downloads. Useful for hardening developer and CI/CD endpoint policies around unsanctioned software installs.
- SOC/IR — Plan: Build or tune detections for ClickFix-style clipboard-execution patterns on macOS endpoints; begin collecting the 250+ domain indicators from the Microsoft Threat Intelligence report to block and hunt across DNS and proxy logs.
- Leader — Learn: Illustrates that attackers are specifically targeting macOS users — a data point worth referencing when justifying endpoint security coverage parity between Mac and Windows fleets.
- Engineer — Plan: Device code flow phishing is a real and growing vector for M365/Azure tenants; audit Conditional Access policies to block or restrict device code flow for user accounts that don’t require it, and enforce compliant-device requirements where the flow must remain enabled.
- SOC/IR — Plan: Build or tune detections on Entra ID sign-in logs for device code authorization events originating from unexpected locations or apps; also hunt for refresh token reuse anomalies that may indicate post-phishing lateral movement within M365.
- Leader — Learn: A named actor targeting US M365 tenants via Microsoft’s own authentication UI is useful context for the risk register and customer security questionnaire responses, but no confirmed breaches or near-term regulatory deadlines make this a monitor-and-track item rather than an executive action.
- Engineer — Learn: Novel attack class showing how state-dependent smart contracts can make malicious transactions appear benign during wallet simulation previews; relevant for teams building Web3 integrations or DeFi applications, but no patch or configuration action is available for typical enterprise stacks.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Learn: No KEV listing, EPSS, or PoC signals present; the campaign targets iOS users via fake AWS phishing pages rather than a vulnerability in cloud infrastructure itself. Worth understanding the DarkSword exploit kit’s capabilities if you manage MDM or BYOD policies, but no immediate patch or config action is indicated.
- SOC/IR — Act: Over 100 fake AWS sign-in domains linked to a single actor provide a concrete hunting surface — search proxy/email logs for traffic to lookalike AWS domains and tune phishing detections around this lure pattern; the Censys report implies enough infrastructure detail to build IOC-based blocks.
- Leader — Learn: A Chinese threat actor running a large-scale iOS phishing campaign mimicking AWS is worth noting for sector awareness and BYOD risk discussions, but without confirmed breaches at named organizations there is no immediate board-level action required.
- Engineer — Learn: No patch or config action — this is a social-engineering delivery chain, not a software vulnerability. Worth knowing that legitimate RMM binaries (Level RMM, ScreenConnect) are being weaponized so anomalous installations can be flagged during code-review or build-pipeline audits.
- SOC/IR — Act: Active campaign uses a fake Microsoft Teams update lure to drop legitimate RMM tools that provide persistent remote access; hunt for unexpected Level RMM or ScreenConnect processes spawned from browser or user-space paths, and tune detections for counterfeit Microsoft Store redirect chains since Teams-themed lures are a high-volume enterprise vector.
- Leader — Learn: Noteworthy campaign pattern — abusing legitimate RMM software bypasses many controls — but no named vendor breach or regulatory trigger; file for context when briefing on social-engineering trends or evaluating security-awareness training priorities.
- Engineer — Skip
- SOC/IR — Plan: AiTM (adversary-in-the-middle) phishing bypasses MFA by proxying sessions in real time; build or tune detections for impossible-travel, session token anomalies, and auth from new ASNs immediately after login events.
- Leader — Learn: Real-time session hijacking erodes MFA as a control — useful context for risk register and security awareness program updates, but no immediate action required given no corroborating signals or named breach.
- Engineer — Plan: Review whether corporate travel policy requires VPN enforcement on untrusted Wi-Fi; audit M365 tenant for conditional access policies that would block logins from non-compliant networks or flag impossible-travel anomalies.
- SOC/IR — Act: Hunt for M365 sign-ins from hotel/conference-center IP ranges or unexpected geolocations since this campaign began; tune Conditional Access or SIEM rules to flag credential use immediately after untrusted-network logins.
- Leader — Learn: A reminder that credential phishing via rogue DNS is an ongoing risk for traveling employees; no board-level action warranted without evidence of organizational impact, but useful context for travel security awareness programs.
- Engineer — Plan: Vulnerability is already patched server-side by OpenAI (June 8), but organizations using ChatGPT Workspace should audit deployed agents for any unauthorized instances created before the patch date.
- SOC/IR — Plan: Novel attack chain — phishing link silently builds and authorizes an autonomous AI agent inside the target org — is worth mapping to detection coverage; build or tune detections for unauthorized workspace agent creation and authorization events.
- Leader — Plan: This flaw illustrates AI workspace agents as a persistent-access attack surface; use it to prioritize an AI agent governance policy — defining who can authorize agents and what audit logging is required — before enterprise rollout expands.
- Engineer — Plan: Configure DNS/URL filtering to block typosquatted Zoom and Teams domains; audit endpoint policies to detect script execution spawned from video-conferencing app processes, which is an anomalous ClickFix-style delivery path.
- SOC/IR — Plan: Build or tune detections for ClickFix-style prompts (unexpected clipboard/script-paste behavior) and process chains where msiexec or PowerShell launches as a child of a meeting application; no IOCs are published yet but the TTPs are specific enough to act on this quarter.
- Leader — Learn: North Korean BlueNoroff is maturing its crypto-sector targeting by combining compromised industry contacts with wallet-profiling before payload delivery — useful context for risk posture briefings if your org has cryptocurrency holdings or operates in financial services.
- Engineer — Skip
- SOC/IR — Learn: The shift toward Teams-based social engineering and automated multi-stage attack chains signals new lure surfaces worth reviewing when tuning detection coverage for collaboration platforms.
- Leader — Learn: Useful benchmarking data on Q2 phishing trends — the Teams social engineering expansion is a talking point for future board or awareness discussions, but no immediate action is required.
- Engineer — Learn: Kratos used adversary-in-the-middle techniques to steal M365 session tokens and bypass MFA — a reminder that TOTP/push-based MFA is insufficient against phishing; engineers should evaluate phishing-resistant MFA (FIDO2/passkeys) for privileged M365 accounts.
- SOC/IR — Learn: No IOCs or detection specifics are provided, so no immediate hunt is actionable; the takedown does validate that AiTM session-token theft against M365 was widespread, which reinforces monitoring for anomalous token reuse and impossible-travel sign-ins if not already covered.
- Leader — Learn: The scale of Kratos confirms that MFA bypass via phishing is not theoretical — useful evidence when making the case for phishing-resistant MFA investment or reviewing identity risk with the board; no immediate action required given the infrastructure has been seized.
- Engineer — Skip
- SOC/IR — Learn: Active campaign harvesting password manager credentials could affect enterprise employees; no IOCs or TTPs are published in this item to hunt or detect against, but credential-stuffing follow-on activity is worth monitoring in identity logs.
- Leader — Learn: If staff use LastPass or Bitwarden for work credentials, this campaign warrants a targeted security awareness reminder; no breach or vendor incident requiring formal action at this time.
- Engineer — Plan: Evilginx bypasses TOTP-based MFA by proxying credentials; if your M365 tenant uses authenticator-app OTP rather than FIDO2/hardware keys, plan migration to phishing-resistant MFA and enforce Entra ID Conditional Access requiring compliant devices this quarter.
- SOC/IR — Act: Three live AiTM operations were exposed with their full toolkits; pull the IOCs Lexfo published, sweep M365/Entra ID sign-in logs for unfamiliar token-issuing IP ranges, and tune detections for impossible-travel or session-token reuse patterns since AiTM bypasses MFA alerts entirely.
- Leader — Learn: The exposure of three concurrent industrial-scale M365 phishing operations illustrates why TOTP MFA is insufficient as a control; useful context when building the case for phishing-resistant MFA investment in the next budget cycle.
- Engineer — Learn: Comment stuffing in HTML attachments is a novel obfuscation technique worth understanding when tuning email security tooling or evaluating AI-based scanning products; no patch or config change required.
- SOC/IR — Plan: Build or tune email-gateway detections to flag HTML attachments with abnormally high comment-to-content ratios, as this technique is designed specifically to bypass AI-based filters your stack may rely on.
- Leader — Skip