HomeCII/OTThreat actors exploit legitimate Microsoft feature to compromise M365 accounts

Threat actors exploit legitimate Microsoft feature to compromise M365 accounts

Published on

spot_img

Suspected Russian threat actors have been exploiting Microsoft Device Code Authentication to deceive targets into granting access to their Microsoft 365 (M365) accounts, a tactic that has proven more successful than traditional social engineering and spear-phishing attacks, according to Volexity threat analysts.

The attacks, which have been ongoing since August 2024 and targeted government organizations, non-governmental organizations, and various industries globally, involve impersonating US, Ukrainian, and EU government officials or researchers. The attackers initiate contact through social media or messaging apps like Signal, inviting the target to participate in a Microsoft Teams Meeting, access applications as an external M365 user, or join a chatroom.

Once the target accepts a fake invitation that directs them to the Microsoft Device Code Authentication page, they are prompted to enter an alphanumeric code, username, password, and second authentication factor. This information allows the threat actor to capture access and refresh tokens, enabling unauthorized access to the target’s M365 account.

The attackers have utilized this access to search through emails for specific keywords and extract sensitive documents. Additionally, compromised accounts have been used to send phishing messages containing malicious links for Device Code Authentication to other users within the organization.

The success of these attacks can be attributed to the lack of malicious links or attachments in phishing emails, users’ unfamiliarity with attacks leveraging legitimate services, and the difficulty in detecting account compromises as authentication logs appear legitimate.

To mitigate these threats, organizations can implement conditional access policies to block device code authentication. Monitoring Microsoft Entra ID sign-in logs for specific values associated with Device Code Authentication can also aid in detecting suspicious activity. Revoking refresh tokens and monitoring URLs accessed by users for known phishing URLs are recommended preventive measures.

Volexity has provided indicators of compromise associated with the campaigns they have identified, assisting organizations in enhancing their detection capabilities and safeguarding against future attacks. By remaining vigilant and proactive in implementing security measures, organizations can mitigate the risk posed by these sophisticated threat actors exploiting Microsoft Device Code Authentication for malicious purposes.

Source link

Latest articles

Fifteen JetBrains Marketplace Plugins Compromising API Keys

Security Researchers Uncover Coordinated Campaign Targeting Developers' AI API Keys Security researchers have recently identified...

The Future of SASE: Top 5 Predictions and Trends Webinar

The Future of SASE: Navigating Complexity in Enterprise Connectivity and Security Presented by Fortinet, a...

Hackers Leverage AI-Generated YouTube Narrators to Promote Crypto Clipper Malware

A sophisticated social-engineering campaign has come to light, utilizing cutting-edge AI technology to enhance...

AI Threats and Alert Fatigue Challenge Cybersecurity Teams

A recent study presented at Infosecurity Europe 2026 has revealed that the most pressing...

More like this

Fifteen JetBrains Marketplace Plugins Compromising API Keys

Security Researchers Uncover Coordinated Campaign Targeting Developers' AI API Keys Security researchers have recently identified...

The Future of SASE: Top 5 Predictions and Trends Webinar

The Future of SASE: Navigating Complexity in Enterprise Connectivity and Security Presented by Fortinet, a...

Hackers Leverage AI-Generated YouTube Narrators to Promote Crypto Clipper Malware

A sophisticated social-engineering campaign has come to light, utilizing cutting-edge AI technology to enhance...