Threat Actors Capitalize on Recent Events: Ransomware/Malware Activity on the Rise
Threat actors are taking advantage of the recent death of Queen Elizabeth II to launch a phishing campaign targeting Microsoft users. The attackers aim to exfiltrate victims' multi-factor authentication (MFA) codes and compromise their Microsoft account credentials. This campaign is just one of many recent incidents highlighting the increasing threat of ransomware and malware activity.
Key Takeaways:
- Threat actors have begun taking advantage of the recent death of Queen Elizabeth II to launch a phishing campaign targeting Microsoft users.
- The campaign's goal is to exfiltrate victims' MFA codes and compromise their Microsoft account credentials.
- The attackers are using the EvilProxy reverse-proxy Phishing-as-a-Service (PaaS) kit in the campaign.
- Microsoft users must remain vigilant of threat actors attempting to take advantage of recent tragedies or big news stories.
- The UK's National Cyber Security Center (NCSC) has published an article on potential scams rising during national mourning.
- Threat actors have also compromised Uber's internal network, gaining access to AWS, GCP, and HackerOne accounts.
- The attacker, an 18-year-old male, stated they have been practicing cybersecurity skills for years.
- The threat actor resorted to messaging the user on WhatsApp, claiming to be Uber IT, and asking the user to accept the authentication request.
- The attack vector is similar to those conducted by the teenagers who ran the LAPSUS$ group.
- The US Department of Treasury has sanctioned ten Iranian individuals connected with malicious state-sponsored cyber campaigns.
- The individuals were identified as employees/associates of the Iranian-based Najee Technology and Afkar System companies.
- The sanctioned threat actors have been attributed to malicious cyber campaigns going back at least two years.
- Gamaredon, a Russian cyber-espionage threat group, has launched a new phishing campaign against Ukraine.
- The email phishing campaign targets Ukrainian citizens with Microsoft Office document templates laced with VBScript macros.
- The indicators of compromise from this campaign overlap with an attack series on Ukraine's Computer Emergency Response Team (CERT-UA).
- Microsoft has patched a zero-day vulnerability allowing threat actors to escalate local privileges to SYSTEM.
- The vulnerability, CVE-2022-37969, has been actively exploited in-the-wild.
- EOP flaws are highly sought after by threat actors, often being one of the first actions taken after gaining initial access to a vulnerable system.
- The Russian cyber-espionage threat group, SecureWorks, has discovered a flaw in Microsoft's Azure Active Directory (Azure AD).
- The flaw allows threat actors to gain persistence and virtually undetectable access to a target's Azure AD instance.
- The vulnerability does not pose any additional risk due to requiring access to the victim device.
Statistics:
- 64 vulnerabilities were patched across Microsoft's hardware and software products in the September 2022 Patch Tuesday security update.
- 5 critical remote code execution (RCE) flaws were discovered in the patch.
- 2 zero-day vulnerabilities were patched, including the actively exploited Windows zero-day CLFS driver EOP vulnerability.
- The CVE-2022-37969 vulnerability has been given a CVSS score of 7.8/10.
- The US Department of Treasury has placed a $10 million bounty on each of the three indicted Iranian individuals.
- The sanctioned threat actors have been connected with malicious cyber campaigns going back at least two years.
Sources:
- Proofpoint: Queen Elizabeth II Phishing Campaign Tweets
- The New York Times: Uber Attack Article
- The Hacker News: Iranian Sanctions Article
- SecureWorks: Azure Active Directory Report
- Microsoft: September 2022 Patch Tuesday Security Update Guide