Phishing attacks don’t look fake anymore: Watch for these 7 scams

1. Microsoft 365 login trap circumvents two-factor authentication

A new attack method uses the genuine Microsoft login dialog and therefore requires almost no fake websites. To do this, the criminals use the OAuth device code flow. This is a sign-in procedure for devices or programs that do not have a usable browser or convenient text input, such as smart TVs, IoT devices, printers, or CLI tools.

Officially, it is called the “OAuth 2.0 Device Authorization Grant.” This method can also be used to take over accounts protected by two-factor authentication.

The criminals send their victims a phishing message, claiming that the victim’s device needs to be re-authorized to log in to their Microsoft 365 account. The messages usually start off innocently — for example, with “Your session has expired,” and provide a link to log in again. If the victim follows the link in the message, they are initially directed to a fake website, but eventually end up at the official Microsoft authentication process for devices and applications (OAuth Device Code Flow).

With this trick, the attackers can also take over accounts that are protected by two-factor authentication. To do this, they combine genuine Microsoft authentication pages with phishing websites.

Proofpoint

These are genuine Microsoft notifications and web pages. However, the victim is not authorizing access to their own PC or smartphone, but to an application controlled by the criminals. Once authorized by the deceived victim, the criminals receive an access token. This allows the malicious application to access the Microsoft account via API without the need to enter a password again.

Incidentally, most of these attacks hide the link to the fake website within a QR code. This is more likely to bypass spam filters than a standard link, and it prompts most victims to switch from their PC to their smartphone.

On a smartphone, due to the smaller screen and the frequent lack of security software, it is even more likely that the victim will fail to notice the deception. The security experts at Proofpoint have published a detailed analysis of the attacks on Microsoft 365 accounts.

Exit mobile version