[Heads Up] What Is Consent-Phishing? Microsoft Warns About New App-Based Attack Angle

Microsoft has issued an advisory warning about “consent phishing,” or application-based phishing attacks that rely on users granting permissions to malicious apps. These attacks aren’t as well-known or as obvious as credential-harvesting or email-based phishing attacks, but they can be just as dangerous.

In consent phishing attacks, the user sees a pop-up from an application requesting extensive permissions. This consent screen lists all the permissions the app will receive, and many users may go on to accept the terms uncritically because they assume the app is trustworthy.

“If the user accepts, the attacker can gain access to their mail, forwarding rules, files, contacts, notes, profile, and other sensitive data and resources,” Microsoft explains.

Microsoft describes the steps in such an attack:
  • “An attacker registers an app with an OAuth 2.0 provider, such as Azure Active Directory.
  • “The app is configured in a way that makes it seem trustworthy, like using the name of a popular product used in the same ecosystem.
  • “The attacker gets a link in front of users, which may be done through conventional email-based phishing, by compromising a non-malicious website, or other techniques.
  • “The user clicks the link and is shown an authentic consent prompt asking them to grant the malicious app permissions to data.
  • “If a user clicks accept, they will grant the app permissions to access sensitive data.
  • “The app gets an authorization code which it redeems for an access token, and potentially a refresh token.
  • “The access token is used to make API calls on behalf of the user.”
Microsoft says users should pay attention to which app is actually requesting permissions. “Keep a watchful eye on app names and domain URLs,” the company says. “Attackers like to spoof app names that make it appear to come from legitimate applications or companies but drive you to consent to a malicious app. Make sure you recognize the app name and domain URL before consenting to an application.”

New-school security awareness training helps your employees to stay up to date regarding these new attack vectors. Microsoft has the story:
Twitter Employees Fall for Social Engineering Attack and the Bad Guys Get "God Mode"

A number of high-profile Twitter accounts were hacked including those of Elon Musk, Bill Gates, Kanye West, Joe Biden and Barack Obama. This is clearly the worst hacking incident in Twitter’s history. It began 7/15/2020 when compromised accounts began posting a bitcoin scam.

In a series of tweets posted under its support channel, Twitter said that its internal systems were compromised, confirming theories that the attack could not have been conducted without access to the company’s own tools and employee privileges. In the industry it's called God Mode and Facebook also has had trouble with this in the past.

Employees Fell for Social Engineering Attack

“We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools,” the first tweet in a multi-tweet explainer thread reads. “We know they used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf.”

Looks like Twitter found out that more than one person appears to have been involved in the hacks, not just one individual, and also that numerous employees were compromised, too.

Full story with updates at the KnowBe4 Blog:
Like Twitter, MFA Will Not Save You!

By Roger Grimes, KnowBe4's Data-Driven Defense Evangelist

"I’m sure we are all interested in the latest Twitter hack. As the author of the soon to be released Wiley book called Hacking Multifactor Authentication, I have to laugh at the “experts” recommending for Twitter and people to use Multi-Factor Authentication (MFA) to prevent this type of social engineering and phishing attacks.

It's likely that everyone else involved already was. MFA will not save you!

In my book, I cover over 50 ways to hack different types of MFA solutions. I can hack any MFA solution at least 5 different ways…many times in ways that the MFA vendor or victim cannot stop. MFA can stop many types of hacking, especially the general, broadcasted, phishing attacks for logon credentials sent to millions of potential victims all at once. But MFA is far less successful at stopping targeted attacks and it oftentimes cannot stop many forms of general, broadcast attacks.

How Do I Know?

Well, history and science. The world is full of vendors who implemented MFA as a way to decrease hacking attacks, and while it did temporarily decrease them, ultimately, in every case the hackers just learned how to attack and circumvent the MFA protection.

It even happened in the latest Twitter hack. Likely, all the employees accounts involved were already using MFA. It would be a dereliction of duty if they were not. And Twitter is a good company with good security processes. Likely all the VIPs accounts involved were also using MFA. VIPs accounts are constantly under attack and have been for years. They likely moved to MFA-protected log-ons as soon as Twitter offered it.

And it did not stop Twitter or those celebrities from being hacked.

Welcome to the real world. If you didn’t already know this, all MFA can be hacked. Anyone telling you any different is lying to you to sell you something or naïve. Yes, MFA can significantly reduce some forms of hacking, and for that alone you should use MFA to protect your most critical accounts and information when and where possible.

But there is a difference between saying that MFA makes some hacking scenarios harder to accomplish and that MFA is unhackable or makes your account unhackable."

Security News
Ragnar Locker Ransomware Attacks Energy Company, Potentially Stealing 10TB in Data

In a letter to customers, EDP Renewables North America CEO acknowledges the attack occurred back in April of this year, but claims “no evidence” of data theft exists.

The ransomware “note” demanded approximately $10 million in Bitcoin. It also included a warning that over 10TB of information had been exfiltrated from encrypted systems, offering to decrypt some of the impacted files for free as a demonstration of their claim. EDP declined to pay the ransom and data has yet to be published.

This attack demonstrates a few things. First, it shows how pervasive ransomware can be. The attack started in the network of EDP Renewable’s parent company, Energias de Portugal in April, with their American subsidiary learning about the attack in early May.

Second, it shows how integrated the idea of stealing data as part of a ransomware attack (whether actual or simply claimed) is becoming the norm. I’ve talked about the Maze “cartel” before – there are plenty of ransomware gangs that partake in the “steal-and-publish” ransomware method.

But, it appears, thus far, that in the case of the attack in EDP, it’s merely a statement meant to improve the chances of payment. There is no detail on how many systems were impacted, but judging by the claim of 10TB, one would assume at least 10TB of data was encrypted, implying a number of critical systems were affected.

It’s Worse Than You Thought: Remote Employees Interaction With Unsafe Websites Is up 50%

New data shows just how frequently remote users are accessing risky web content that would normally be blocked by firewalls and other network monitoring solutions.

You still have some material portion of your workforce working remotely (or you wouldn’t be reading this article). And, it’s probably a safe guess that you propped them up to work from home rather quickly, without truly getting around to the part where you secure their home working environment as strongly as it would be if they worked at the office, right?

You’re not alone – but that doesn’t really make it any better; if your remote employees are unprotected, your organization and its data are at risk. So, just how much should you be concerned about remote cybersecurity now that your workforce seems to be productive?

New data from perimeter security vendor NetMotion shows just how exposed remote employees are to potentially malicious web content. According to the report, remote employees:
  • Encounter 8 potentially malicious URLs daily
  • Visit 1 malware site daily and 1 phishing domain every 3 days
  • 26% of risky sites visited were related to botnets
In addition, the volume of attempted clicks on potentially malicious URLs has increased 50% between the middle of the pandemic (mid-May to mid-June) and January of this year.

According to NetMotion, the lack of preventative and protective security in place is likely to blame. With 65% of organizations allowing employees to access managed applications from personal devices, this is a volatile combination.

Organizations need both a layered security strategy in place, and user enrollment in continual security awareness training. When it comes right down to it, users are choosing to click these risky URLs. Proper education on social engineering attacks, phishing tactics, and more that commonly are used to trick users can make the difference between a user unknowingly falling for a scam and one that easily spots the questionable, suspicious, or malicious web content.
Who's Behind Last Week's Epic 130 Twitter Celebrity Account Hack?

Brian Krebs Said: "Twitter was thrown into chaos on Wednesday after accounts for some of the world's most recognizable public figures, executives and celebrities starting tweeting out links to bitcoin scams. Twitter says the attack happened because someone tricked or coerced an employee into providing access to internal Twitter administrative tools.

This post is an attempt to lay out some of the timeline of this attack, and point to clues about who may have been behind it:
