“Being Annoying” as a Social Engineering Approach

Stu Sjouwerman | Apr 18, 2022

“Being Annoying” as a Social Engineering Approach in MFA AttacksAttackers are spamming multifactor authentication (MFA) prompts in an attempt to irritate users into approving the login, Ars Technica reports. Both criminal and nation-state actors are using this technique. Researchers at Mandiant observed the Russian state-sponsored actor Cozy Bear launching repeated MFA prompts until the user accepted the request.

Ars Technica quotes Mandiant’s researchers as saying, “Many MFA providers allow for users to accept a phone app push notification or to receive a phone call and press a key as a second factor. The [Nobelium] threat actor took advantage of this and issued multiple MFA requests to the end user’s legitimate device until the user accepted the authentication, allowing the threat actor to eventually gain access to the account.”

The Lapsus$ criminal hacking group is also making use of this method. A member of Lapsus$ said on the group’s Telegram channel the technique is particularly effective late at night.

“No limit is placed on the amount of calls that can be made,” the individual said. “Call the employee 100 times at 1 am while he is trying to sleep, and he will more than likely accept it. Once the employee accepts the initial call, you can access the MFA enrollment portal and enroll another device.”

Ars Technica notes that there are multiple variations to this approach.

  • “Sending a bunch of MFA requests and hoping the target finally accepts one to make the noise stop.
  • “Sending one or two prompts per day. This method often attracts less attention, but ‘there is still a good chance the target will accept the MFA request.’
  • “Calling the target, pretending to be part of the company, and telling the target they need to send an MFA request as part of a company process.”

New-school security awareness training can teach your employees to follow security best practices so they can avoid falling for social engineering attacks.

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.