“Being Annoying” as a Social Engineering Approach

Stu Sjouwerman | Apr 18, 2022

“Being Annoying” as a Social Engineering Approach in MFA AttacksAttackers are spamming multifactor authentication (MFA) prompts in an attempt to irritate users into approving the login, Ars Technica reports. Both criminal and nation-state actors are using this technique. Researchers at Mandiant observed the Russian state-sponsored actor Cozy Bear launching repeated MFA prompts until the user accepted the request.

Ars Technica quotes Mandiant’s researchers as saying, “Many MFA providers allow for users to accept a phone app push notification or to receive a phone call and press a key as a second factor. The [Nobelium] threat actor took advantage of this and issued multiple MFA requests to the end user’s legitimate device until the user accepted the authentication, allowing the threat actor to eventually gain access to the account.”

The Lapsus$ criminal hacking group is also making use of this method. A member of Lapsus$ said on the group’s Telegram channel the technique is particularly effective late at night.

“No limit is placed on the amount of calls that can be made,” the individual said. “Call the employee 100 times at 1 am while he is trying to sleep, and he will more than likely accept it. Once the employee accepts the initial call, you can access the MFA enrollment portal and enroll another device.”

Ars Technica notes that there are multiple variations to this approach.

  • “Sending a bunch of MFA requests and hoping the target finally accepts one to make the noise stop.
  • “Sending one or two prompts per day. This method often attracts less attention, but ‘there is still a good chance the target will accept the MFA request.’
  • “Calling the target, pretending to be part of the company, and telling the target they need to send an MFA request as part of a company process.”

New-school security awareness training can teach your employees to follow security best practices so they can avoid falling for social engineering attacks.

Find out if your organization's MFA solution
can be hacked by cybercriminals now!

Did you know that all MFA mechanisms can be hacked, and in some cases it's as simple as sending a phishing email? That's why it's important to know the exact security risks your MFA solution has and how your users' accounts may be compromised.

masareport-thumbHere's how MASA works:

  • You will receive a custom link to take your assessment
  • Answer a series of technology questions relevant to your MFA solution
  • Get an instant high-level snapshot of potential risks with your MFA
  • Receive your in-depth report packed with actionable insight and detailed analysis on specific MFA attacks and tips for your top defenses 

Assess My MFA Solution Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/multi-factor-authentication-security-assessment

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.