Threat actors are using a new phishing kit called “GhostCode” to target sales teams with phony business inquiries, according to researchers at eSentire. The threat actors begin the attack using the targeted company’s web contact form, so the messages won’t be blocked by security filters.
“Threat actors initiated the attack by submitting a seemingly innocuous inquiry through Salesforce,” the researchers write. “After the sales team followed up, the threat actors replied that a subsequent email would be sent to ‘sign an NDA.’ The follow-up email contained a WeTransfer link to a password-gated HTML attachment. When opened, the HTML file launched in the victim's browser and redirected to the device code phishing page. The page instructed the victim to copy a code and enter it into Microsoft's legitimate sign-in page for "authentication". After the victim signed in and completed MFA, the threat actors obtained authentication tokens and delivered a decoy NDA document to complete the loop. They then registered several devices, acquired long-living tokens, and harvested emails.”
The phishing kit uses AI-generated webpages to harvest OAuth device codes, bypassing multifactor authentication (MFA) and granting the attackers access. The researchers warn that while MFA is an important layer of defense, it’s not foolproof.
“MFA does not protect against device code phishing,” eSentire says. “The token carries the MFA claim forward. Every subsequent attacker API call - across 9 successful non-interactive sign-in events - passed MFA checks without re-authentication. Organizations that have deployed MFA and consider themselves protected against token theft are specifically the intended victims.”
eSentire has the story: https://www.esentire.com/blog/ghostcode-dissecting-a-novel-device-code-phishing-kit
