30 C
Mumbai
Monday, June 5, 2023
HomeCyber AttacksNew Phishing-as-a-Service Platform Lets Cybercriminals Generate Phishing Pages

New Phishing-as-a-Service Platform Lets Cybercriminals Generate Phishing Pages

Date:

Related stories

MOVEit Transfer Under Attack: Zero-Day Vulnerability Actively Being Exploited

MOVEit Transfer Under Attack: Zero-Day Vulnerability Actively Being Exploited A...

SuperVPN Free VPN Service Exposes 360 Million User Records

SuperVPN Free VPN Service Exposes 360 Million User Records: SuperVPN...

Apple and Google Join Forces to Stop Unauthorized Location-Tracking Devices

Apple and Google Join Forces to Stop Unauthorized Location-Tracking...

Kodi Confirms Data Breach User Records and Private Messages Stolen

Kodi Confirms Data Breach User Records and Private Messages...

Western Digital Hackers Demanded ‘minim 8 figures’ as a ransom

Western Digital Hackers Demanded 'minim 8 figures' as a...

New Phishing-as-a-Service Platform Lets Cybercriminals Generate Phishing Pages

A new phishing-as-a-service (PhaaS or PaaS) platform named Greatness has been leveraged by cybercriminals to target business users of the Microsoft 365 cloud service since at least mid-2022, effectively lowering the bar to entry for phishing attacks.

“Greatness, for now, is only focused on Microsoft 365 phishing pages, providing its affiliates with an attachment and link builder that creates highly convincing decoy and login pages,” Cisco Talos researcher Tiago Pereira said.

“It contains features such as having the victim’s email address pre-filled and displaying their appropriate company logo and background image, extracted from the target organization’s real Microsoft 365 login page.”

Campaigns involving Greatness have mainly manufacturing, health care, and technology entities located in the U.S., the U.K., Australia, South Africa, and Canada, with a spike in activity detected in December 2022 and March 2023.

Phishing kits like Greatness offer threat actors, rookies or otherwise, a cost-effective and scalable one-stop shop, making it possible to design convincing login pages associated with various online services and bypass two-factor authentication (2FA) protections.

Specifically, the authentic-looking decoy pages function as a reverse proxy to harvest credentials and time-based one-time passwords (TOTPs) entered by the victims.

Phishing kits like Greatness offer threat actors, rookies or otherwise, a cost-effective and scalable one-stop shop, making it possible to design convincing login pages associated with various online services and bypass two-factor authentication (2FA) protections.

Specifically, the authentic-looking decoy pages function as a reverse proxy to harvest credentials and time-based one-time passwords (TOTPs) entered by the victims.

Attack chains begin with malicious emails containing an HTML attachment, which, upon opening, executes obfuscated JavaScript code that redirects the user to a landing page with the recipient’s email address already pre-filled and prompts for their password and MFA code.

The entered credentials and tokens are subsequently forwarded to the affiliate’s Telegram channel for obtaining unauthorized access to the accounts in question.

The AiTM phishing kit also comes with an administration panel that enables the affiliate to configure the Telegram bot, keep track of stolen information, and even build booby-trapped attachments or links.

What’s more, each affiliate is expected to have a valid API key in order to be able to load the phishing page. The API key also prevents unwanted IP addresses from viewing the phishing page and facilitates behind-the-scenes communication with the actual Microsoft 365 login page by posing as the victim.

Found this article interesting? Signup for our newsletter to read more exclusive content we post.

Technogeek Online
Technogeek Onlinehttps://technogeek.online
Technogeek Online mission is to be a digital for technical decision-makers to gain knowledge about transformative technology. We deliver essential information on cyber technologies and strategies to guide you as you lead your organizations. We are inviting you to become a member of our community.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

LEAVE A REPLY

Please enter your comment!
Please enter your name here