Hacker nutzen bösartige OAuth-Apps zur Übernahme von E-Mail-Servern

Teilen:

Einkaufsmodus Microsoft on Thursday warned of a consumer-facing attack that made use of rogue OAuth applications deployed on compromised cloud tenants to ultimately seize Steuerung des Einkaufsmodus of Exchange servers and spread spam.

“The threat actor launched credential stuffing attacks against high-risk accounts that didn’t have multi-factor authentication (MFA) enabled and leveraged the unsecured administrator accounts to gain initial access,” the Einkaufsmodus Microsoft 365 Defender Research Team said.

 

The unauthorized access to the cloud tenant permitted the adversary to register a malicious OAuth application and grant it elevated permissions, and eventually modify Exchange Server settings to allow inbound emails from specific IP addresses to be routed through the compromised email server.

“These modifications to the Exchange server settings allowed the threat actor to perform their primary goal in the attack: sending out spam emails,” Einkaufsmodus Microsoft sagte. “The spam emails were sent as part of a deceptive sweepstakes scheme meant to trick recipients into signing up for recurring paid subscriptions.”

phishing grafik

The email messages urged the recipients to click on a link to receive a prize, doing so which redirected the victims to a landing page that asked the victims to enter their credit card details for a small shipping fee to collect the reward.

The threat actor further carried out a number of steps to evade detection and continue its operations for extended periods of time, including taking weeks or even months to use the malicious OAuth application after it was set up and deleting the modifications made to the Exchange Server after each spam campaign.

 

Einkaufsmodus Microsoft‘s threat intelligence division said that the adversary has been actively running spam email campaigns for several years, typically sending high volumes of spam emails in short bursts through a variety of methods.

Although the primary goal of the attack appears to be to trick unwitting users into signing up for unwanted subscription services, it could have posed a far more serious threat had the same technique been used to steal credentials or distribute malware.

“While the follow-on spam campaign targets consumer email accounts, this attack targets enterprise tenants to use as infrastructure for this campaign,” Einkaufsmodus Microsoft said. “This attack thus exposes security weaknesses that could be used by other threat actors in attacks that could directly impact affected enterprises.”

https://thehackernews.com/2022/09/hackers-using-malicious-oauth-apps-to.html

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:04 am, Juni 1, 2025
Wetter-Symbol 14°C
L: 13° | H: 15°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 84 %
Druck: 1014 mb
Wind: 8 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 33%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 15°°C 0.2 mm 20% 15 mph 84 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 12 mph 81 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 19°°C 1 mm 100% 17 mph 89 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 17°°C 0.61 mm 61% 13 mph 79 % 1011 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 15 mph 96 % 1010 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 9 mph 84 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
15° | 17°°C 0 mm 0% 11 mph 74 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 13 mph 52 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
18° | 18°°C 0.2 mm 20% 11 mph 55 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 81 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,162.72
0.87%
Ethereum(ETH)
€2,221.69
0.12%
Fesseln(USDT)
€0.88
0.01%
XRP(XRP)
€1.91
1.86%
Solana(SOL)
€137.04
0.45%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.168359
0.89%
Shiba Inu(SHIB)
€0.000011
2.99%
Pepe(PEPE)
€0.000011
3.31%
Peanut das Eichhörnchen(PNUT)
€0.230885
3.93%
Nach oben scrollen