[HN Gopher] Multiple Russian Threat Actors Targeting Microsoft D...
___________________________________________________________________
Multiple Russian Threat Actors Targeting Microsoft Device Code
Authentication
Author : ChrisArchitect
Score : 76 points
Date : 2025-02-15 18:59 UTC (4 hours ago)
(HTM) web link (www.volexity.com)
(TXT) w3m dump (www.volexity.com)
| ChrisArchitect wrote:
| Related Microsoft post: https://www.microsoft.com/en-
| us/security/blog/2025/02/13/sto...
| FpUser wrote:
| >"United States Department of State, Ukrainian Ministry of
| Defence, European Union Parliament"
|
| What kind of bright mind would consider not moving unsolicited
| emails like these straight to a dust bin?
| Muromec wrote:
| I didn't get how people end up entering paswords into randon
| places and click on suspicions links until I started to work
| for a big corp.
|
| You get a lot of stuff in the inbox that doesn't exactly relate
| to your day to day work from departments you only vaguely heard
| about.
|
| Then the UX of corporate stuff, especially one from microsoft
| is designed in a way to randomly jump in your face with a
| password prompt without you starting it actively. The session
| timeout here, kerberos prompt for smartcard here, the vpn
| hickup, teams needs to reconnect after the laptop gets out of
| sleep state. Then half of it random at some point updates and
| looks subtly different too.
|
| After some exposure to this kind of stuff you don't even know
| what's real and what's level of corporate-sanctioned bullshit
| is above or below the baseline set by The Policy.
| redserk wrote:
| I'm surprised it isn't common for companies to just block
| inbound external email by default.
|
| Most of the time I have an inbox rule enabled that just
| deletes anything not from the corporate domain and a few
| other known services.
| hsbauauvhabzb wrote:
| I setup filters to eradicate some of the internal corporate
| scam. The CEOs email ramblings have no relevance to my day
| to day.
| jasonjayr wrote:
| And don't forget the "SSO Tax" that some SaaS implement.
| Ideally, your company login should be your one and only
| login, and should be strongly tied to your device, a hardware
| token, and a central directory. Often, Saas providers charge
| far more to integrate with these directories, so, companies
| will just use a lower cost "LDAP Authentication" and
| condition users to enter their staff passwords on multiple
| sites :(
| dist-epoch wrote:
| > All authentication and download events came from virtual
| private server (VPS) and Tor IP addresses, which is not the most
| subtle way to access an account.
|
| If I login from my computer and a few hours later an attacker
| logs in from the other side of the planet, most big providers
| will trigger extra checks/email notifications of unusual events.
|
| I wonder if intentionally using Tor/VPS is a way to bypass those
| checks, since a Tor/VPS can have a far away geo-IP.
| sepositus wrote:
| Yes, I've also had this thought. I also wonder how wide the
| geographic net is for some providers. If it's sufficiently
| wide, it's not infeasible to brute-force the right geographic
| location by just looping through a few locations. It also has
| the adverse affect of locating the victim.
| BoingBoomTschak wrote:
| I'd like for those entities (be it MS or Volexity) to provide
| proof before accusing an entire country. It just seems
| irresponsible in its current form of "source: trust me".
| antithesis-nl wrote:
| Yeah, can confirm, there are a _lot_ of targeted emails going out
| inviting people to dodgy auth flow endpoints.
|
| Disabling device authentication (which is rarely needed anyway)
| and forcing Microsoft Authenticator (with the yes-this-is-really-
| me number entry thing) or something like a Yubikey should make
| your org like 99% less vulnerable. If you're not on a Microsoft-
| or-similar platform (good for you!), one word of advice:
| passkeys.
|
| As for the inevitable "who would fall for this" question: prior
| to 2017, when Google instituted a strict 2FA policy, even
| _members of their elite security team_ were successfully phished.
| After that, not so much:
| https://krebsonsecurity.com/2018/07/google-security-keys-neu...
___________________________________________________________________
(page generated 2025-02-15 23:00 UTC)