The last week of June and early July saw a surge in zero-day phishing attacks targeting both corporate Microsoft/Ouook logins and personal web services (e-commerce, streaming, and email) on work devices. Threat actors employed sophisticated tactics – from obfuscated JavaScript and fake OAuth login flows to Telegram-based exfiltration – allowing many of these phishing pages to evade traditional detection measures. Here are some examples and highlights.
boa[.]devicehub[.]co/login
s3[.]lax[.]sharktech[.]net
ru0[.]eotskyj[.]es
zolotayanora[.]com
nextflyerpub[.]store
cpcontacts[.]164-92-78-92[.]cprapid[.]com
fhi9o09i5[.]uywpk[.]es
j43okxouoz0[.]franksdarmatology[.]com
webmail[.]50-6-111-88[.]cprapid[.]com
Microsoft Spearphish and Telegram Bot Exfiltration
This period witnessed a number of interesting attacker techniques like the use of Telegram Bot APIs and clever techniques to conceal page content.
On July 2, a staff member at a Texas organization clicked on a Microsoft Outlook spear-phishing email delivered via a file-sharing link.
On June 24, a Kentucky employee clicked the link below to an Office 365 sign-in page.
In early July, another Kentucky user was lured to a fraudulent Outlook Web Access page that employed multiple evasive techniques.
On June 23, an employee at a Washington organization clicked the spear-phishing page below, which loaded several resources from legitimate Microsoft content delivery networks (such as aadcdn.msauth.net and aadcdn.msftauth.net) and even referenced Microsoft’s own “Watson” telemetry service in its code.
This midsummer period saw a surge in spearphishing targeting district users on their personal accounts, particularly Amazon account phishing.
On June 30, a Texas employee clicked on a fake Amazon login page on their work device, which included fake “Sign in with Google” and “Sign in with Facebook” authentication flows designed to steal multiple types of identity credentials.
The period also included Netflix and AOL spearphish targeting corporate users in Kentucky, with tactics including aggressive device fingerprinting and fake Google Captchas.
Block the specified domains on corporate firewalls and endpoint security solutions.
Educate users about phishing risks even on pages that purport to use MFA.
Remind users of phishing risks for their personal accounts that they access even if they are on corporate devices.
Enforce multi-factor authentication (MFA) on all corporate logins to reduce the risk of credential compromise.