TechTronBlog.com

Technology, Innovation, Collaboration
Menu
  • Features
  • Gadget
  • Mobile
  • Uncategorized

Daily Tech Updates Sent to your Email

Join our Newsletter
Home
Gadget
Voice Phishers Targeting Corporate VPNs
Gadget

Voice Phishers Targeting Corporate VPNs

August 21, 2020

<div><p>The COVID-19 epidemic has brought a wave of email phishing attacks that try to trick work-at-home employees into giving away credentials needed to remotely access their employers’ networks. But one increasingly brazen group of crooks is taking your standard phishing attack to the next level, marketing a voice phishing service that uses a combination of one-on-one phone calls and custom phishing sites to steal VPN credentials from employees.</p>
<p><img class="aligncenter wp-image-45224" src="https://krebsonsecurity.com/wp-content/uploads/2018/09/phonescam.png" alt="" width="598" height="377"></p>
<p>According to interviews with several sources, this hybrid phishing gang has a remarkably high success rate, and operates primarily through paid requests or “bounties,” where customers seeking access to specific companies or accounts can hire them to target employees working remotely at home.</p>
<p>And over the past six months, the criminals responsible have created dozens if not hundreds of phishing pages targeting some of the world’s biggest corporations. For now at least, they appear to be focusing primarily on companies in the financial, telecommunications and social media industries.</p>
<p>“For a number of reasons, this kind of attack is really effective,” said <strong>Allison Nixon</strong>, chief research officer at New York-based cyber investigations firm <a href="https://www.unit221b.com/" target="_blank" rel="noopener noreferrer">Unit 221B</a>. “Because of the Coronavirus, we have all these major corporations that previously had entire warehouses full of people who are now working remotely. As a result the attack surface has just exploded.”</p>
<h4>TARGET: NEW HIRES</h4>
<p>A typical engagement begins with a series of phone calls to employees working remotely at a targeted organization. The phishers will explain that they’re calling from the employer’s IT department to help troubleshoot issues with the company’s virtual private networking (VPN) technology.</p>
<div id="attachment_52747" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-52747" class="size-full wp-image-52747" src="https://krebsonsecurity.com/wp-content/uploads/2020/08/bofaticket.png" alt="" width="520" height="529"><p id="caption-attachment-52747" class="wp-caption-text">The employee phishing page bofaticket[.]com. Image: urlscan.io</p></div>
<p>The goal is to convince the target either to divulge their credentials over the phone or to input them manually at a website set up by the attackers that mimics the organization’s corporate email or VPN portal.</p>
<p><strong>Zack Allen</strong> is director of threat intelligence for <a href="https://www.zerofox.com/" target="_blank" rel="noopener noreferrer">ZeroFOX</a>, a Baltimore-based company that helps customers detect and respond to risks found on social media and other digital channels. Allen has been working with Nixon and several dozen other researchers from various security firms to monitor the activities of this prolific phishing gang in a bid to disrupt their operations.</p>
<p>Allen said the attackers tend to focus on phishing new hires at targeted companies, and will often pose as new employees themselves working in the company’s IT division. To make that claim more believable, the phishers will create LinkedIn profiles and seek to connect those profiles with other employees from that same organization to support the illusion that the phony profile actually belongs to someone inside the targeted firm.</p>
<p>“They’ll say ‘Hey, I’m new to the company, but you can check me out on LinkedIn’ or Microsoft Teams or Slack, or whatever platform the company uses for internal communications,” Allen said. “There tends to be a lot of pretext in these conversations around the communications and work-from-home applications that companies are using. But eventually, they tell the employee they have to fix their VPN and can they please log into this website.”</p>
<h4>SPEAR VISHING</h4>
<p>The domains used for these pages often invoke the company’s name, followed or preceded by hyphenated terms such as “vpn,” “ticket,” “employee,” or “portal.” The phishing sites also may include working links to the organization’s other internal online resources to make the scheme seem more believable if a target starts hovering over links on the page.</p>
<p>Allen said a typical voice phishing or “vishing” attack by this group involves at least two perpetrators: One who is social engineering the target over the phone, and another co-conspirator who takes any credentials entered at the phishing page and quickly uses them to log in to the target company’s VPN platform in real-time.</p>
<p>Time is of the essence in these attacks because many companies that rely on VPNs for remote employee access also require employees to supply some type of multi-factor authentication in addition to a username and password — such as a one-time numeric code generated by a mobile app or text message. And in many cases, those codes are only good for a short duration — often measured in seconds or minutes.</p>
<p>But these vishers can easily sidestep that layer of protection, because their phishing pages simply request the one-time code as well. </p>
<div id="attachment_52743" class="wp-caption aligncenter"><a class="lightbox" href="https://krebsonsecurity.com/wp-content/uploads/2020/08/attgl.png"><img aria-describedby="caption-attachment-52743" class="wp-image-52743" src="https://krebsonsecurity.com/wp-content/uploads/2020/08/attgl.png" alt="" width="598" height="417" srcset="https://krebsonsecurity.com/wp-content/uploads/2020/08/attgl.png 810w, https://krebsonsecurity.com/wp-content/uploads/2020/08/attgl-580×405.png 580w, https://krebsonsecurity.com/wp-content/uploads/2020/08/attgl-768×536.png 768w" sizes="(max-width: 598px) 100vw, 598px"></a><p id="caption-attachment-52743" class="wp-caption-text">A phishing page (helpdesk-att[.]com) targeting AT&amp;T employees. Image: urlscan.io</p></div>
<p>Allen said it matters little to the attackers if the first few social engineering attempts fail. Most targeted employees are working from home or can be reached on a mobile device. If at first the attackers don’t succeed, they simply try again with a different employee.</p>
<p>And with each passing attempt, the phishers can glean important details from employees about the target’s operations, such as company-specific lingo used to describe its various online assets, or its corporate hierarchy.</p>
<p>Thus, each unsuccessful attempt actually teaches the fraudsters how to refine their social engineering approach with the next mark within the targeted organization, Nixon said.</p>
<p>“These guys are calling companies over and over, trying to learn how the corporation works from the inside,” she said.<span id="more-52718"></span></p>
<h4>NOW YOU SEE IT, NOW YOU DON’T</h4>
<p>All of the security researchers interviewed for this story said the phishing gang is pseudonymously registering their domains at just a handful of domain registrars that accept bitcoin, and that the crooks typically create just one domain per registrar account.</p>
<p>“They’ll do this because that way if one domain gets burned or taken down, they won’t lose the rest of their domains,” Allen said.</p>
<p>More importantly, the attackers are careful to do nothing with the phishing domain until they are ready to initiate a vishing call to a potential victim. And when the attack or call is complete, they disable the website tied to the domain.</p>
<p>This is key because many domain registrars will only respond to external requests to take down a phishing website if the site is live at the time of the abuse complaint. This requirement can stymie efforts by companies like ZeroFOX that focus on identifying newly-registered phishing domains <em>before</em> they can be used for fraud.</p>
<p>“They’ll only boot up the website and have it respond at the time of the attack,” Allen said. “And it’s super frustrating because if you file an abuse ticket with the registrar and say, ‘Please take this domain away because we’re 100 percent confident this site is going to be used for badness,’ they won’t do that if they don’t see an active attack going on. They’ll respond that according to their policies, the domain has to be a live phishing site for them to take it down. And these bad actors know that, and they’re exploiting that policy very effectively.”</p>
<div id="attachment_52745" class="wp-caption aligncenter"><a class="lightbox" href="https://krebsonsecurity.com/wp-content/uploads/2020/08/github.png"><img aria-describedby="caption-attachment-52745" class="wp-image-52745" src="https://krebsonsecurity.com/wp-content/uploads/2020/08/github.png" alt="" width="594" height="450" srcset="https://krebsonsecurity.com/wp-content/uploads/2020/08/github.png 1054w, https://krebsonsecurity.com/wp-content/uploads/2020/08/github-580×439.png 580w, https://krebsonsecurity.com/wp-content/uploads/2020/08/github-940×712.png 940w, https://krebsonsecurity.com/wp-content/uploads/2020/08/github-768×581.png 768w" sizes="(max-width: 594px) 100vw, 594px"></a><p id="caption-attachment-52745" class="wp-caption-text">A phishing page (github-ticket[.]com) aimed at siphoning credentials for a target organization’s access to the software development platform Github. Image: urlscan.io</p></div>
<h4>SCHOOL OF HACKS</h4>
<p>Both Nixon and Allen said the object of these phishing attacks seems to be to gain access to as many internal company tools as possible, and to use those tools to seize control over digital assets that can quickly be turned into cash. Primarily, that includes any social media and email accounts, as well as associated financial instruments such as bank accounts and any cryptocurrencies.</p>
<p>Nixon said she and others in her research group believe the people behind these sophisticated vishing campaigns hail from a community of young men who have spent years learning how to <a href="https://krebsonsecurity.com/?s=sim+swapping&amp;x=0&amp;y=0" rel="noopener noreferrer" target="_blank">social engineer employees at mobile phone companies and social media firms into giving up access to internal company tools</a>.</p>
<p>Traditionally, the goal of these attacks has been gaining control over highly-prized social media accounts, which can sometimes fetch thousands of dollars when resold in the cybercrime underground. But this activity gradually has evolved toward more direct and aggressive monetization of such access.</p>
<p>On July 15, a number of high-profile <strong>Twitter</strong> accounts <a href="https://krebsonsecurity.com/2020/07/whos-behind-wednesdays-epic-twitter-hack/" target="_blank" rel="noopener noreferrer">were used to tweet out a bitcoin scam that earned more than $100,000</a> in a few hours. According to Twitter, that attack succeeded because the perpetrators were able to social engineer several Twitter employees over the phone into giving away access to internal Twitter tools.</p>
<p>Nixon said it’s not clear whether any of the people involved in the Twitter compromise are associated with this vishing gang, but she noted that the group showed no signs of slacking off after <a href="https://krebsonsecurity.com/2020/07/three-charged-in-july-15-twitter-compromise/" target="_blank" rel="noopener noreferrer">federal authorities charged several people with taking part in the Twitter hack</a>.</p>
<p>“A lot of people just shut their brains off when they hear the latest big hack wasn’t done by hackers in North Korea or Russia but instead some teenagers in the United States,” Nixon said. “When people hear it’s just teenagers involved, they tend to discount it. But the kinds of people responsible for these voice phishing attacks have now been doing this for several years. And unfortunately, they’ve gotten pretty advanced, and their operational security is much better now.”</p>
<div id="attachment_52749" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-52749" class=" wp-image-52749" src="https://krebsonsecurity.com/wp-content/uploads/2020/08/vzw-employee.png" alt="" width="594" height="392" srcset="https://krebsonsecurity.com/wp-content/uploads/2020/08/vzw-employee.png 696w, https://krebsonsecurity.com/wp-content/uploads/2020/08/vzw-employee-580×383.png 580w" sizes="(max-width: 594px) 100vw, 594px"><p id="caption-attachment-52749" class="wp-caption-text">A phishing page (vzw-employee[.]com) targeting employees of Verizon. Image: DomainTools</p></div>
<h4>PROPER ADULT MONEY-LAUNDERING</h4>
<p>While it may seem amateurish or myopic for attackers who gain access to a Fortune 100 company’s internal systems to focus mainly on stealing bitcoin and social media accounts, that access — once established — can be re-used and re-sold to others in a variety of ways.</p>
<p>“These guys do intrusion work for hire, and will accept money for any purpose,” Nixon said. “This stuff can very quickly branch out to other purposes for hacking.”</p>
<p>For example, Allen said he suspects that once inside of a target company’s VPN, the attackers may try to add a new mobile device or phone number to the phished employee’s account as a way to generate additional one-time codes for future access by the phishers themselves or anyone else willing to pay for that access.</p>
<p>Nixon and Allen said the activities of this vishing gang have drawn the attention of U.S. federal authorities, who are growing concerned over indications that those responsible are starting to expand their operations to include criminal organizations overseas.</p>
<p>“What we see now is this group is really good on the intrusion part, and really weak on the cashout part,” Nixon said. “But they are learning how to maximize the gains from their activities. That’s going to require interactions with foreign gangs and learning how to do proper adult money laundering, and we’re already seeing signs that they’re growing up very quickly now.”</p>
<h4>WHAT CAN COMPANIES DO?</h4>
<p>Many companies now make security awareness and training an integral part of their operations. Some firms even <a href="https://krebsonsecurity.com/2019/05/should-failing-phish-tests-be-a-fireable-offense/" rel="noopener noreferrer" target="_blank">periodically send test phishing messages to their employees to gauge their awareness levels</a>, and then require employees who miss the mark to undergo additional training.</p>
<p>Such precautions, while important and potentially helpful, may do little to combat these phone-based phishing attacks that tend to target new employees. Both Allen and Nixon — as well as others interviewed for this story who asked not to be named — said the weakest link in most corporate VPN security setups these days is the method relied upon for multi-factor authentication.</p>
<div id="attachment_28417" class="wp-caption alignright"><img aria-describedby="caption-attachment-28417" class=" wp-image-28417" src="https://krebsonsecurity.com/wp-content/uploads/2014/10/yubikey.png" alt="" width="258" height="314" srcset="https://krebsonsecurity.com/wp-content/uploads/2014/10/yubikey.png 468w, https://krebsonsecurity.com/wp-content/uploads/2014/10/yubikey-285×346.png 285w" sizes="(max-width: 258px) 100vw, 258px"><p id="caption-attachment-28417" class="wp-caption-text">A U2F device made by Yubikey, plugged into the USB port on a computer.</p></div>
<p>One multi-factor option — physical <strong>security keys</strong> — appears to be immune to these sophisticated scams. The most commonly used security keys are inexpensive USB-based devices. A security key implements a form of multi-factor authentication known as <a href="https://en.wikipedia.org/wiki/Universal_2nd_Factor" rel="noopener noreferrer" target="_blank">Universal 2nd Factor</a> (U2F), which allows the user to complete the login process simply by inserting the USB device and pressing a button on the device. The key works without the need for any special software drivers.</p>
<p>The allure of U2F devices for multi-factor authentication is that even if an employee who has enrolled a security key for authentication tries to log in at an impostor site, the company’s systems simply refuse to request the security key if the user isn’t on their employer’s legitimate website, and the login attempt fails. Thus, the second factor cannot be phished, either over the phone or Internet.</p>
<p>In July 2018, <strong>Google</strong> <a href="https://krebsonsecurity.com/2018/07/google-security-keys-neutralized-employee-phishing/" target="_blank" rel="noopener noreferrer">disclosed</a> that it had not had any of its 85,000+ employees successfully phished on their work-related accounts since early 2017, when it began requiring all employees to use physical security keys in place of one-time codes.</p>
<p>Probably the most popular maker of security keys is&nbsp;<a href="https://www.yubico.com/" target="_blank" rel="noopener noreferrer">Yubico</a>, which sells a basic U2F <strong>Yubikey</strong> for $20. It offers regular USB versions as well as those made for devices that require USB-C connections, such as Apple’s newer <strong>Mac OS</strong> systems. Yubico also sells more expensive keys designed to work with mobile devices. [Full disclosure: Yubico was recently an advertiser on this site].</p>
<p>Nixon said many companies will likely balk at the price tag associated with equipping each employee with a physical security key. But she said as long as most employees continue to work remotely, this is probably a wise investment given the scale and aggressiveness of these voice phishing campaigns.</p>
<p>“The truth is some companies are in a lot of pain right now, and they’re having to put out fires while attackers are setting new fires,” she said. “Fixing this problem is not going to be simple, easy or cheap. And there are risks involved if you somehow screw up a bunch of employees accessing the VPN. But apparently these threat actors really hate Yubikey right now.”</p></div>

Share
Tweet
Email
Prev Article
Next Article

Related Articles

https://www.engadget.com/google-pixel-5-leak-dual-camera-fingerprint-sensor-141305914.html

Google Pixel 5 leak hints at dual cameras and a fingerprint reader

https://www.cnet.com/news/best-instant-pot-model-2020-instapot-pot-pressure-cooker-compare/#ftag=CAD590a51e

The best Instant Pots of 2020: Duo, Ultra, Lux and more compared – CNET

About The Author

Leave a Reply

Cancel reply

Recent Posts

  • New tech and gadgets you absolutely can’t miss
  • Razer Pro Click ergonomic wireless mouse maximizes your productivity
  • Lume Cube Panel Mini Bicolor LED Light provides on-the-go lighting for photographers
  • LINKA LEO GPS Smart Bike Lock can track your bicycle’s movements in more than 100 countries
  • Razer Pro Glide soft mouse mat cushions your hand during use

Recent Comments

    Archives

    • August 2020

    Categories

    • Features
    • Gadget
    • Mobile
    • Uncategorized

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    TechTronBlog.com

    Technology, Innovation, Collaboration
    Copyright © 2021 TechTronBlog.com
    Theme by MyThemeShop.com

    Ad Blocker Detected

    Our website is made possible by displaying online advertisements to our visitors. Please consider supporting us by disabling your ad blocker.

    Refresh