A phishing campaign detected in late November 2023 has compromised hundreds of user accounts in dozens of Microsoft Azure environments, including those of senior executives. Hackers target executives' accounts because they can access confidential corporate information, self-approve fraudulent financial transactions, and access critical systems to use them as a foothold for launching more extensive attacks against the breached organization or its partners. Proofpoint's Cloud Security Response Team, which has been monitoring the malicious activity, issued an alert earlier today highlighting the lures the threat actors use and proposing targeted defense measures. The attacks employ documents sent to targets that embed links masqueraded as "View document" buttons that take victims to phishing pages. Proofpoint says the messages target employees who are more likely to hold higher privileges within their employing organization, which elevates the value of a successful account compromise. "The affected user base encompasses a wide spectrum of positions, with frequent targets including Sales Directors, Account Managers, and Finance Managers. Individuals holding executive positions such as "Vice President, Operations", "Chief Financial Officer & Treasurer" and "President & CEO" were also among those targeted," explains Proofpoint. The analysts identified the following Linux user-agent string which attackers use to gain unauthorized access to Microsoft365 apps: This user agent has bee...
Ongoing Microsoft Azure account hijacking campaign targets executives
BleepingComputer
·Bill Toulas
·Published Feb 12, 2024
·Updated
Affected Software
1 affected component
Microsoft Azure