Showing posts with label Microsoft News. Show all posts
Showing posts with label Microsoft News. Show all posts
Microsoft Uncovers Banking AitM Phishing and BEC Attacks Targeting Financial Giants

Microsoft Uncovers Banking AitM Phishing and BEC Attacks Targeting Financial Giants

 

Banking and financial services organizations are the targets of a new multi-stage adversary-in-the-middle (AitM) phishing and business email compromise (BEC) attack, Microsoft has revealed.

"The attack originated from a compromised trusted vendor and transitioned into a series of AiTM attacks and follow-on BEC activity spanning multiple organizations," the tech giant disclosed in a Thursday report.

Microsoft, which is tracking the cluster under its emerging moniker Storm-1167, called out the group's use of indirect proxy to pull off the attack.

This enabled the attackers to flexibly tailor the phishing pages to their targets and carry out session cookie theft, underscoring the continued sophistication of AitM attacks.

The modus operandi is unlike other AitM campaigns where the decoy pages act as a reverse proxy to harvest credentials and time-based one-time passwords (TOTPs) entered by the victims.

"The attacker presented targets with a website that mimicked the sign-in page of the targeted application, as in traditional phishing attacks, hosted on a cloud service," Microsoft said.

"The said sign-in page contained resources loaded from an attacker-controlled server, which initiated an authentication session with the authentication provider of the target application using the victim's credentials."

The attack chains commence with a phishing email that points to a link, which, when clicked, redirects a victim into visiting a spoofed Microsoft sign-in page and entering their credentials and TOTPs.

The harvested passwords and session cookies are then used to impersonate the user and gain unauthorized access to the email inbox by means of a replay attack. The access is then abused to get hold of sensitive emails and orchestrate a BEC attack.

AitM Phishing and BEC Attacks

What's more, a new SMS-based two-factor authentication method is added to the target account in order to sign in using the pilfered credentials sans attracting any attention.

In the incident analyzed by Microsoft, the attacker is said to have initiated a mass spam campaign, sending more than 16,000 emails to the compromised user's contacts, both within and outside of the organization, as well as distribution lists.

The adversary has also been observed taking steps to minimize detection and establish persistence by responding to incoming emails and subsequently taking steps to delete them from the mailbox.

Ultimately, the recipients of the phishing emails are targeted by a second AitM attack to steal their credentials and trigger yet another phishing campaign from the email inbox of one of the users whose account was hacked as a result of the AitM attack.

"This attack shows the complexity of AiTM and BEC threats, which abuse trusted relationships between vendors, suppliers, and other partner organizations with the intent of financial fraud," the company added.

The development comes less than a month after Microsoft warned of a surge in BEC attacks and the evolving tactics employed by cybercriminals, including the use of platforms, like BulletProftLink, for creating industrial-scale malicious mail campaigns.

Another tactic entails the use of residential internet protocol (IP) addresses to make attack campaigns appear locally generated, the tech giant said.

"BEC threat actors then purchase IP addresses from residential IP services matching the victim's location creating residential IP proxies which empower cybercriminals to mask their origin," Redmond explained.

"Now, armed with localized address space to support their malicious activities in addition to usernames and passwords, BEC attackers can obscure movements, circumvent 'impossible travel' flags, and open a gateway to conduct further attacks."

Windows 10 Will Now Let You Reset Forgotten Password Directly From the Lock Screen

reset-windows-10-password-forget
Microsoft is making every effort to make its Windows 10 Fall Creators Update bigger than ever before by beefing up its security practices and hardening it against hackers and cyber attacks in its next release.

Microsoft is finally adding one of the much-requested features to Windows 10: Pin and Password recovery option directly from the lock screen.

Yes, the next big update of Windows 10, among other features, will allow you to recover your forgotten pin and password, allowing you to reset your Windows password directly from the lock screen.


In Windows 10 Fall Creators Update, you will see "Reset password" or "I forgot my PIN" options on the login screen along with the sign-in box, mspoweruser confirmed.
windows-10-password-reset

Once you click on the option, Windows 10 will take you to the OOBE where Cortana will help you reset your password, after you successfully verify your identity using either your secondary email, your phone number, or Microsoft Authenticator.


windows-10-password-reset

A verification code will be sent to the option you chose, and once you entered and verified your identity, you will be able to reset the password and regain access to your computer directly from the login screen.

The tech giant is currently testing this new feature in its Windows 10 Insiders build 16237, making it much easier for them to recover their Microsoft Accounts.

You can use this option if you have either activated the Windows Hello authentication system or have a PIN to secure your account.

With the launch of Windows 10 Creator Update (also known as RedStone 3), which is expected to release sometime between September and October 2017, the company has already planned to:

  • Remove the 30-year-old SMB v1 file sharing protocol.
  • Build AI-powered antivirus software.
  • Build its EMET anti-exploit tool into the kernel of the operating system.
  • Support three different flavours of the Linux OS – Ubuntu, Fedora, and SUSE – directly through their Windows Store.
  • Add new anti-ransomware feature, called Controlled Folder Access, as part of its Windows Defender.

Besides this new upgrade, Windows 10 Fall Update also includes improvements to Acrylic Material translucency effects, Task Manager, Mixed Reality headset and much more.

You can check out the complete list here.
MIT researchers used a $150 Microsoft Kinect to 3D scan a giant T. rex skull

MIT researchers used a $150 Microsoft Kinect to 3D scan a giant T. rex skull

MIT’s Camera Culture group has been able to successfully capture a high-resolution 3D scan of a Tyrannosaurus rex skull using about $150 worth of equipment and some free software.
The skull, which belongs to the Field Museum of Natural History in Chicago, was discovered in 1990 and is the largest and most complete T. rex skull yet found. However, it has some strange holes in the jawbone that have puzzled researchers for some time. Early on, it was believed that the holes in the jaw were teeth marks. However, the holes are irregularly placed and inconsistent with biting patterns. More recently, researchers believed the holes were caused by an infection from eating diseased prey.
Last year, a group of forensic dentists tried to find out more about the holes by 3D-scanning an image of the skull using some high-tech equipment. However, the skull was too large for their equipment to handle.
MIT’s researchers decided to give it a try recently using the much cheaper Microsoft Kinect, an in-depth-sensing camera and free MeshLab software. Though MIT’s Media Lab does have a prototype system for producing high-resolution 3D scans, that system wasn’t ready yet for such a large scan, so the researchers improvised with the cheaper devices.
That was a pretty smart move, as most high-resolution scanning systems out on the market can cost tens of thousands of dollars for a resolution of about 50 to 100 micrometers. But, the Kinect works just fine for this type of job, with a resolution of 500 micrometers for about $100, enabling researchers to now take a good look at the skull without damaging the original.
Already, the group has been able to observe the mysterious holes taper from the outside in, undermining the hypothesis of a mouth infection. And now that the 3D image can be shared in the cloud, more research can be done to determine what may have happened.
“A lot of people will be able to start using this,” says Anshuman Das, a research scientist at the Camera Culture group. “That’s the message I want to send out to people who would generally be cut off from using technology — for example, paleontologists or museums that are on a very tight budget. There are so many other fields that could benefit from this.”

Popular Posts