CuraSec

tag: Vishing · 4 items

  • Engineer — Learn: No CVE or patch required; the attack path abuses Teams social engineering rather than a software flaw, so review Teams external-access settings and restrict who can initiate calls from outside the tenant.
  • SOC/IR — Act: Active enterprise campaign targeting domain controllers via Teams vishing — hunt for anomalous Teams call activity from external tenants followed by process execution or lateral movement, and review Unit 42’s published TTPs for detection rule development.
  • Leader — Plan: Campaign targets enterprise domain controllers through a trusted communication channel (Teams), raising both breach-risk and vendor-trust questions — brief IT leadership and consider tightening external Teams communication policies this quarter.
2026-08-26 · BleepingComputer · source ↗ #phishing-as-a-service#voice-ai#vishing
  • Engineer — Skip
  • SOC/IR — Learn: The use of automated voice AI agents in a PhaaS platform to socially engineer victims is a meaningful escalation in vishing sophistication; no IOCs or enterprise detection surface are available yet, but analysts should track how this technique migrates toward corporate credential theft campaigns.
  • Leader — Skip
2026-08-09 · The Hacker News · source ↗ #vishing#social-engineering#saas-security
  • Engineer — Learn: UNC6671 exploits human trust rather than software vulnerabilities, so there is no patch or config fix. The campaign reinforces the value of phishing-resistant (FIDO2) MFA on SaaS to limit what a tricked employee can surrender.
  • SOC/IR — Plan: Named actor with defined TTPs (IT help-desk impersonation via personal phone → SaaS credential handover) but no IOCs published yet; build or tune detections for anomalous SaaS logins and new device enrollments, and consider hunting for suspicious authentication spikes in M365 or Google Workspace logs correlated with help-desk ticket activity.
  • Leader — Act: An active data extortion group is deliberately targeting employees at financial services, private equity, and professional services firms by phone; if your org is in those sectors, brief employees this week on the IT impersonation lure and verify that help-desk identity-verification procedures are documented and enforced.
2026-08-07 · Google Threat Intelligence · source ↗ #vishing#aitm#cloud-security
  • Engineer — Plan: Active group uses AiTM to bypass MFA on M365 and Okta; implement phishing-resistant FIDO2/hardware-key MFA and tighten Conditional Access or Okta device-trust policies to invalidate intercepted session tokens.
  • SOC/IR — Act: Active campaign with mappable TTPs — hunt for anomalous Okta and M365 session activity (unexpected token origins, bulk SharePoint/OneDrive exfil) since May 2026 and pull the GTIG report for infrastructure IOCs tied to Redact, Pink, Helix, and Falcon brands.
  • Leader — Act: Extortion group is actively hitting financial services, private equity, and professional services — if your org falls in these verticals, brief leadership this week on the campaign and verify that helpdesk impersonation and personal-device contact scenarios are covered in your security awareness program.