[HN Gopher] Multiple Russian Threat Actors Targeting Microsoft D...
       ___________________________________________________________________
        
       Multiple Russian Threat Actors Targeting Microsoft Device Code
       Authentication
        
       Author : ChrisArchitect
       Score  : 76 points
       Date   : 2025-02-15 18:59 UTC (4 hours ago)
        
 (HTM) web link (www.volexity.com)
 (TXT) w3m dump (www.volexity.com)
        
       | ChrisArchitect wrote:
       | Related Microsoft post: https://www.microsoft.com/en-
       | us/security/blog/2025/02/13/sto...
        
       | FpUser wrote:
       | >"United States Department of State, Ukrainian Ministry of
       | Defence, European Union Parliament"
       | 
       | What kind of bright mind would consider not moving unsolicited
       | emails like these straight to a dust bin?
        
         | Muromec wrote:
         | I didn't get how people end up entering paswords into randon
         | places and click on suspicions links until I started to work
         | for a big corp.
         | 
         | You get a lot of stuff in the inbox that doesn't exactly relate
         | to your day to day work from departments you only vaguely heard
         | about.
         | 
         | Then the UX of corporate stuff, especially one from microsoft
         | is designed in a way to randomly jump in your face with a
         | password prompt without you starting it actively. The session
         | timeout here, kerberos prompt for smartcard here, the vpn
         | hickup, teams needs to reconnect after the laptop gets out of
         | sleep state. Then half of it random at some point updates and
         | looks subtly different too.
         | 
         | After some exposure to this kind of stuff you don't even know
         | what's real and what's level of corporate-sanctioned bullshit
         | is above or below the baseline set by The Policy.
        
           | redserk wrote:
           | I'm surprised it isn't common for companies to just block
           | inbound external email by default.
           | 
           | Most of the time I have an inbox rule enabled that just
           | deletes anything not from the corporate domain and a few
           | other known services.
        
             | hsbauauvhabzb wrote:
             | I setup filters to eradicate some of the internal corporate
             | scam. The CEOs email ramblings have no relevance to my day
             | to day.
        
           | jasonjayr wrote:
           | And don't forget the "SSO Tax" that some SaaS implement.
           | Ideally, your company login should be your one and only
           | login, and should be strongly tied to your device, a hardware
           | token, and a central directory. Often, Saas providers charge
           | far more to integrate with these directories, so, companies
           | will just use a lower cost "LDAP Authentication" and
           | condition users to enter their staff passwords on multiple
           | sites :(
        
       | dist-epoch wrote:
       | > All authentication and download events came from virtual
       | private server (VPS) and Tor IP addresses, which is not the most
       | subtle way to access an account.
       | 
       | If I login from my computer and a few hours later an attacker
       | logs in from the other side of the planet, most big providers
       | will trigger extra checks/email notifications of unusual events.
       | 
       | I wonder if intentionally using Tor/VPS is a way to bypass those
       | checks, since a Tor/VPS can have a far away geo-IP.
        
         | sepositus wrote:
         | Yes, I've also had this thought. I also wonder how wide the
         | geographic net is for some providers. If it's sufficiently
         | wide, it's not infeasible to brute-force the right geographic
         | location by just looping through a few locations. It also has
         | the adverse affect of locating the victim.
        
       | BoingBoomTschak wrote:
       | I'd like for those entities (be it MS or Volexity) to provide
       | proof before accusing an entire country. It just seems
       | irresponsible in its current form of "source: trust me".
        
       | antithesis-nl wrote:
       | Yeah, can confirm, there are a _lot_ of targeted emails going out
       | inviting people to dodgy auth flow endpoints.
       | 
       | Disabling device authentication (which is rarely needed anyway)
       | and forcing Microsoft Authenticator (with the yes-this-is-really-
       | me number entry thing) or something like a Yubikey should make
       | your org like 99% less vulnerable. If you're not on a Microsoft-
       | or-similar platform (good for you!), one word of advice:
       | passkeys.
       | 
       | As for the inevitable "who would fall for this" question: prior
       | to 2017, when Google instituted a strict 2FA policy, even
       | _members of their elite security team_ were successfully phished.
       | After that, not so much:
       | https://krebsonsecurity.com/2018/07/google-security-keys-neu...
        
       ___________________________________________________________________
       (page generated 2025-02-15 23:00 UTC)