Automatically translated.View original post

Phishing "Forg365" can steal Microsoft active sessions.

Phishing tool found "Forg365" can easily steal a Microsoft 365 implementation session.

According to a report by The Hacker News website, a research team from ZeroBEC, an email security specialist company, has detected a new PhaaS tool called "Forg365," distributed through Telegram for US $400 per month ($13,349.20) or US $3,800 per year ($126,844) with claims of various abilities, such as device ID phishing, AiTM theft, anti-Bot protection, artificial intelligence applications. (AI or Artificial Intelligence) to create Lure, and Mailbox Management after successful hacking, with the goal of focusing on Microsoft 365 accounts.

For the use of this tool, the Email Delivery System of trusted services such as Amazon Simple Email Service (Amazon SES) and Twilio SendGrid is used to ensure the consistency of sending. In addition, the Panel has many tools to choose from, such as Account, Link, Invitation, OAuTH Application Settings, Redirect Link, SVG File Creator, Campaign Sender, SMTP Profiler, SMTP Rotation, AI Email Wizard, Token Vaulting, and more. To the extent that the research team says the tools are available to help in a comprehensive scam campaign. Customers who have successfully paid and registered through the channel of hackers on Telegram will be able to access the control panel with these tools through "logfriend.com / login."

This tool supports two major attack patterns:

The e-mail scam uses the Amazon SES service to send e-mail, while the images on the e-mail are deposited on the SendGrid service. The user uses these to create business-oriented e-mails that accompany the victim to press a fraudulent link embedded on the e-mail, which leads to a Device-Auth Phishing authentication screen similar to the real one. If the victim enters the authentication code, it will authorize the controlling hacker to use the victim's Microsoft 365 account session immediately.

AiTM Data Stealing, where the tool intervenes in traffic and then uses Route Token, Session Cookies, and Data Traffic Classification to determine whether to display fraudulent content to the victim. If the victim is detected to activate a VPN or Virtual Private Network, the tool will take the victim to a harmless fraudulent page instead of to a fraudulent page used for phishing.

In addition to the above capabilities, this tool provides an extension for use on Google Chrome, Microsoft Edge, and Brave web browsers called ForgCookie that allows hackers to access Microsoft 365 accounts that have been successfully hacked (Compromise Account). The add-on works as follows:

Retrieve hacked account data from Forg365's backyard system.

Run the Endpoint Cookie creation tool for selected accounts.

Delete the original Session Cookie

Shoot (Injection) The Token Cookie Password for access to Microsoft's domain used to log in to the service.

Start the OAuth identity confirmation process quietly.

Save Microsoft cookies obtained from different domains of Microsoft.

# gmail # microsoft # Trending # lemon 8 diary # freedomhack

1 day agoEdited to

... Read moreจากประสบการณ์ที่ผมได้ติดตามความเคลื่อนไหวของภัยคุกคามไซเบอร์ในเวที Microsoft 365 พบว่าเครื่องมืออย่าง Forg365 กำลังกลายเป็นภัยที่น่ากังวลอย่างมากสำหรับองค์กรและผู้ใช้งานทั่วไป เพราะด้วยราคาค่าสมัครที่เข้าถึงได้และความสามารถในการขโมยเซสชันการใช้งานซึ่งแทบไม่ต้องใช้รหัสผ่านโดยตรง ส่งผลให้แฮกเกอร์สามารถเข้าสู่ระบบได้ทันทีโดยไม่ต้องธงรหัสผ่านใหม่ สิ่งที่น่าทึ่งคือ Forg365 ใช้บริการส่งอีเมลที่เชื่อถือได้อย่าง Amazon SES และ SendGrid ทำให้อีเมลหลอกลวงดูน่าเชื่อถือและผ่านการตรวจสอบของระบบป้องกันสแปมทั่วไปได้ง่าย นอกจากนี้ยังใช้ AI สร้างอีเมลจูงใจที่เข้าถึงผู้ใช้เป้าหมายได้ดี เครื่องมือนี้ยังสนับสนุนเทคนิคการหลอกลวงหลากหลายรูปแบบ ตั้งแต่การหลอกให้ยืนยันตัวตนอุปกรณ์ (Device ID Phishing) จนถึงการแทรกแซงข้อมูลจราจรแบบ Adversary-in-the-Middle (AiTM) ที่ซับซ้อนและฉลาดในการตรวจจับสภาพแวดล้อมของเหยื่อ เช่น การตรวจสอบการใช้งาน VPN ผมเคยเห็นหลายองค์กรที่ได้รับผลกระทบจากการใช้เครื่องมือประเภทนี้ บางองค์กรพบว่าการโจมตีถูกตรวจจับสายเกินไปจนข้อมูลหายหรือถูกเข้าถึงโดยไม่ได้รับอนุญาตไปแล้ว จึงแนะนำให้ทีมเทคนิคและผู้ใช้งานเพิ่มความเข้มงวดเรื่องการตรวจสอบการเข้าใช้งานหลายปัจจัย และติดตั้งส่วนเสริมหรือโปรแกรมป้องกันที่ตรวจจับการเข้าถึงจากเครื่องมือพวกนี้ได้ หากคุณใช้งาน Microsoft 365 ควรระวังอีเมลที่มีลิงก์แปลกปลอมหรือขอให้ยืนยันข้อมูลอย่างเร่งด่วน และหลีกเลี่ยงการคลิกลิงก์จากอีเมลที่ไม่แน่ใจ รวมทั้งติดตั้งอัปเดตแพตช์ระบบความปลอดภัยอย่างสม่ำเสมอเพื่อป้องกันการโจมตีจากเครื่องมือ Forg365 ที่แฝงตัวมาในรูปแบบและช่องทางหลายรูปแบบ