Threat Actors Capitalize on Recent Events: Ransomware/Malware Activity on the Rise

Threat actors are taking advantage of the recent death of Queen Elizabeth II to launch a phishing campaign targeting Microsoft users. The attackers aim to exfiltrate victims' multi-factor authentication (MFA) codes and compromise their Microsoft account credentials. This campaign is just one of many recent incidents highlighting the increasing threat of ransomware and malware activity.

Key Takeaways:

  • Threat actors have begun taking advantage of the recent death of Queen Elizabeth II to launch a phishing campaign targeting Microsoft users.
  • The campaign's goal is to exfiltrate victims' MFA codes and compromise their Microsoft account credentials.
  • The attackers are using the EvilProxy reverse-proxy Phishing-as-a-Service (PaaS) kit in the campaign.
  • Microsoft users must remain vigilant of threat actors attempting to take advantage of recent tragedies or big news stories.
  • The UK's National Cyber Security Center (NCSC) has published an article on potential scams rising during national mourning.
  • Threat actors have also compromised Uber's internal network, gaining access to AWS, GCP, and HackerOne accounts.
  • The attacker, an 18-year-old male, stated they have been practicing cybersecurity skills for years.
  • The threat actor resorted to messaging the user on WhatsApp, claiming to be Uber IT, and asking the user to accept the authentication request.
  • The attack vector is similar to those conducted by the teenagers who ran the LAPSUS$ group.
  • The US Department of Treasury has sanctioned ten Iranian individuals connected with malicious state-sponsored cyber campaigns.
  • The individuals were identified as employees/associates of the Iranian-based Najee Technology and Afkar System companies.
  • The sanctioned threat actors have been attributed to malicious cyber campaigns going back at least two years.
  • Gamaredon, a Russian cyber-espionage threat group, has launched a new phishing campaign against Ukraine.
  • The email phishing campaign targets Ukrainian citizens with Microsoft Office document templates laced with VBScript macros.
  • The indicators of compromise from this campaign overlap with an attack series on Ukraine's Computer Emergency Response Team (CERT-UA).
  • Microsoft has patched a zero-day vulnerability allowing threat actors to escalate local privileges to SYSTEM.
  • The vulnerability, CVE-2022-37969, has been actively exploited in-the-wild.
  • EOP flaws are highly sought after by threat actors, often being one of the first actions taken after gaining initial access to a vulnerable system.
  • The Russian cyber-espionage threat group, SecureWorks, has discovered a flaw in Microsoft's Azure Active Directory (Azure AD).
  • The flaw allows threat actors to gain persistence and virtually undetectable access to a target's Azure AD instance.
  • The vulnerability does not pose any additional risk due to requiring access to the victim device.

Statistics:

  • 64 vulnerabilities were patched across Microsoft's hardware and software products in the September 2022 Patch Tuesday security update.
  • 5 critical remote code execution (RCE) flaws were discovered in the patch.
  • 2 zero-day vulnerabilities were patched, including the actively exploited Windows zero-day CLFS driver EOP vulnerability.
  • The CVE-2022-37969 vulnerability has been given a CVSS score of 7.8/10.
  • The US Department of Treasury has placed a $10 million bounty on each of the three indicted Iranian individuals.
  • The sanctioned threat actors have been connected with malicious cyber campaigns going back at least two years.

Sources:

  • Proofpoint: Queen Elizabeth II Phishing Campaign Tweets
  • The New York Times: Uber Attack Article
  • The Hacker News: Iranian Sanctions Article
  • SecureWorks: Azure Active Directory Report
  • Microsoft: September 2022 Patch Tuesday Security Update Guide