Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Microsoft Azure accounts hit with phishing attacks to hijack virtual machines

  • May 17, 2023
Total
0
Shares
0
0
0


Cybersecurity researchers from Mandiant have uncovered a hacking collective with extensive knowledge of the Azure environment, using phishing and SIM-swapping techniques to infiltrate virtual machines and exfiltrate sensitive data.

In its report (opens in new tab), Mandiant says it is tracking the group as “UNC3944”, claiming it’s been active since at least May 2022. 

First, the group would run SMS phishing attacks in order to obtain the passwords for Microsoft Azure admin accounts. After that, they would run a SIM-swapping attack, gaining the ability to receive multi-factor authentication (MFA) codes through SMS. Mandiant isn’t sure exactly how the group SIM-swaps, but says that “knowing the target’s phone number and conspiring with unscrupulous telecom employees is enough to facilitate illicit number ports”.

Impersonating admins

Then, the group would impersonate the administrator and reach out to help desk agents in order to receive the MFA code and use it to access the target’s Azure environment. Once inside, they’d gather information, modify existing Azure accounts, or create new ones, depending on who they compromised and what the goal at that moment is. 

The next step was to use Azure Extensions add-ons to hide as they gather as much data as possible, and Azure Serial Console to gain admin console access to VMs and run commands over the serial port. 

“This method of attack was unique in that it avoided many of the traditional detection methods employed within Azure and provided the attacker with full administrative access to the VM,” Mandiant said in its report.

After that, the group does a number of additional moves to remain on the network, and to keep stealthy, as they identify and exfiltrate as much sensitive data as they can.

UNC3944 demonstrated a “deep understanding” of the Azure environment, Mandiant said, noting this level of technical know-how, combined with high-level social engineering skills, makes this malicious (opens in new tab) group quite dangerous.

  • These are the best firewalls (opens in new tab) to keep your business protected

Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Landlord-focused insurtech Obie lands $25.5M led by Battery Ventures

  • May 17, 2023
View Post
Next Article
  • Technology

Audio journalism app Curio can now create personalized episodes using AI

  • May 17, 2023
View Post
You May Also Like
View Post
  • News

WWDC 2023: the 3 big reveals we need from Apple

  • June 4, 2023
View Post
  • News

GTA 5 took 10 years to introduce this feature and we’re so pleased it’s finally here

  • June 4, 2023
View Post
  • News

This new Steam update will show you the lowest price a game has sold for in the last 30 days

  • June 4, 2023
View Post
  • News

This Google Workspace security flaw could let hackers quietly steal your Drive files

  • June 4, 2023
View Post
  • News

Apple rumored to be announcing major Siri updates at WWDC 2023

  • June 4, 2023
View Post
  • News

These Activists Distrust Voting Machines. Just Don’t Call Them Election Deniers.

  • June 4, 2023
View Post
  • News

Quordle today – hints and answers for Sunday, June 4 (game #496)

  • June 4, 2023
View Post
  • News

Diablo 4’s authentication servers are down, preventing players from logging in

  • June 3, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.