Phishing campaigns hosted on Backblaze infrastructure, which were active earlier in September, experienced a significant increase in intensity during the second half of the month. These campaigns involved credential exfiltration via Telegram and utilized lures related to purchase orders. Additionally, other widespread phishing attacks, affecting multiple organizations during this period, employed Attack in the Middle (AiTM) tools to exfiltrate two-factor authentication codes and session tokens in real time as users logged in. We also observed a notable rise in Microsoft scam scareware and phishing attempts targeting personal accounts, such as those of American Express and Netflix. Below are some examples and highlights.
tronklamnsj5rdf4[.]z13[.]web[.]core[.]windows[.]net
quinoa-sc2ddream[.]nagaisti[.]sa[.]com
secure[.]formloaders[.]com
login[.]beckleyrsvs[.]com
ferlo[.]psitesinternal[.]com
fdbn35fdhn[.]z13[.]web[.]core[.]windows[.]net/win[.]html
ghch78hjvhj[.]z13[.]web[.]core[.]windows[.]net/win[.]html
instantlyper[.]com
organizationbush[.]shop
8e3138d0-2704-45a8-a76f-a0748981346d-00-2e8qjjpf3umir[.]janeway[.]replit[.]dev
comejoinus[.]de/beepoint/AcrobatN/
globalconfidentialprobook[.]us-southeast-1[.]linodeobjects[.]com
f005[.]backblazeb2[.]com
Within 24 hours on September 23, phishing attacks hosted on the Backblaze domain were clicked by 10 users across half a dozen organizations in Kentucky and Minnesota.
The campaign made use of a cluster of URLs hosted on the same domain, for example:
f005[.]backblazeb2[.]com/file/soooodheeeded/onedr-updated[.]html
f005[.]backblazeb2[.]com/file/asssrrrruuueeee/onedr-updated[.]html
Other phishing attacks during this period used legitimate third party storage. On September 19, an employee at a North Carolina organization clicked the below Microsoft phishing page.
Another widespread campaign was first detected on September 16th, when a staff member at a Kentucky organization clicked the below Microsoft spear phish.
It also makes use of a suite of subdomains to coordinate the attack across larger-scale infrastructure, following the below pattern:
newnewdomnew*[.]beckleyrsvs[.]com
The same period saw a major uptick in general Microsoft spear phish and scareware campaigns. On September 15, a staff member at a Minnesota school organization clicked the below Microsoft phishing attack.
The same day, a principal at an organization in Kentucky clicked on a Microsoft spear phish.
On September 16, a staff member at another Kentucky organization clicked the Microsoft phishing page shown below.
50b8883cece74335ad4ed2c0d7e5fcef.formloaders[.]com
7fbf392b40364463bd1f4fcb152691ed.formloaders[.]com
It utilizes hidden scripts to automatically extract credentials before the user clicks the submit button.
On September 17, an employee at yet another Kentucky organization clicked the below Microsoft spear phish.
The same day, an admin at the same organization clicked the below Microsoft scam.
A similar attack was clicked the same day by an admin at a Georgia organization.
On September 18th, an employee at a Texas organization clicked the below Outlook phishing attack.
The same day, an employee at a Georgia organization clicked on the Netflix phishing attack.
Mitigations
Block the specified domains on corporate firewalls and endpoint security solutions.
Educate users about phishing risks even on pages that purport to use MFA
Remind users of phishing risks for their personal accounts that they access, even if they are on corporate devices
Enforce multi-factor authentication (MFA) on all corporate logins to reduce the risk of credential compromise.