市值: $3.516T -0.630%
成交额(24h): $123.3546B 21.810%
  • 市值: $3.516T -0.630%
  • 成交额(24h): $123.3546B 21.810%
  • 恐惧与贪婪指数:
  • 市值: $3.516T -0.630%
加密货币
话题
百科
资讯
加密话题
视频
热门新闻
加密货币
话题
百科
资讯
加密话题
视频
bitcoin
bitcoin

$104492.464223 USD

-0.72%

ethereum
ethereum

$3259.381067 USD

2.17%

xrp
xrp

$3.088281 USD

-1.07%

tether
tether

$0.999963 USD

-0.01%

solana
solana

$237.703952 USD

-0.51%

bnb
bnb

$679.531010 USD

0.30%

usd-coin
usd-coin

$1.000026 USD

-0.01%

dogecoin
dogecoin

$0.328829 USD

-0.90%

cardano
cardano

$0.955910 USD

-0.64%

tron
tron

$0.254578 USD

3.38%

chainlink
chainlink

$25.069629 USD

2.85%

avalanche
avalanche

$35.018519 USD

3.72%

stellar
stellar

$0.424992 USD

5.02%

sui
sui

$4.222963 USD

5.48%

toncoin
toncoin

$4.839835 USD

-1.34%

加密货币新闻

Mamba 2FA 网络钓鱼平台针对 AiTM 入侵中的 Microsoft 365 帐户

2024/10/09 21:55

威胁参与者一直在使用新出现的 Mamba 2FA 网络钓鱼即服务平台来通过中间对手入侵来破坏 Microsoft 365 帐户

Mamba 2FA 网络钓鱼平台针对 AiTM 入侵中的 Microsoft 365 帐户

Threat actors are now using the Mamba 2FA phishing-as-a-service platform to compromise Microsoft 365 accounts in adversary-in-the-middle (AiTM) attacks, BleepingComputer reports. Mamba 2FA's AiTM attacks against Microsoft 365 accounts are enabled by proxy relays and the Socket.IO JavaScript library, which allows for one-time passcode and authentication cookie access and communications between Microsoft 365 service phishing pages and relay servers, respectively, according to a report from Sekoia. The attackers then use a Telegram bot to enable transmission of stolen credentials and authentication cookies, Sekoia researchers found. They also noted improvements in Mamba 2FA since it was first reported by Any.Run in June. These enhancements include Mamba 2FA's use of IPRoyal proxy servers, regularly rotated phishing URLs, and benign content on HTML attachments to better conceal malicious activity. The findings should prompt organizations to bolster their defenses against AiTM intrusions launched by PhaaS operations by implementing certificate-based authentication, geo-blocking, hardware security keys, device allowlisting, IP allowlisting, and reduced token lifespans.

据 BleepingComputer 报道,威胁行为者现在正在使用 Mamba 2FA 网络钓鱼即服务平台在中间对手 (AiTM) 攻击中危害 Microsoft 365 帐户。一份报告称,Mamba 2FA 针对 Microsoft 365 帐户的 AiTM 攻击是通过代理中继和 Socket.IO JavaScript 库启用的,该库分别允许一次性密码和身份验证 cookie 访问以及 Microsoft 365 服务网络钓鱼页面和中继服务器之间的通信来自塞科亚。 Sekoia 研究人员发现,攻击者随后使用 Telegram 机器人来传输被盗凭证和身份验证 cookie。他们还注意到自 6 月份 Any.Run 首次报道以来 Mamba 2FA 的改进。这些增强功能包括 Mamba 2FA 使用 IPRoyal 代理服务器、定期轮换的网络钓鱼 URL 以及 HTML 附件上的良性内容,以更好地隐藏恶意活动。研究结果应促使组织通过实施基于证书的身份验证、地理封锁、硬件安全密钥、设备白名单、IP 白名单和缩短令牌寿命来加强防御 PhaaS 运营发起的 AiTM 入侵。

免责声明:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

2025年02月01日 发表的其他文章