Article Details
Scrape Timestamp (UTC): 2023-12-16 05:06:02.095
Source: https://thehackernews.com/2023/12/microsoft-warns-of-storm-0539-rising.html
Original Article Text
Click to Toggle View
Microsoft Warns of Storm-0539: The Rising Threat Behind Holiday Gift Card Frauds. Microsoft is warning of an uptick in malicious activity from an emerging threat cluster it's tracking as Storm-0539 for orchestrating gift card fraud and theft via highly sophisticated email and SMS phishing attacks against retail entities during the holiday shopping season. The goal of the attacks is to propagate booby-trapped links that direct victims to adversary-in-the-middle (AiTM) phishing pages that are capable of harvesting their credentials and session tokens. "After gaining access to an initial session and token, Storm-0539 registers their own device for subsequent secondary authentication prompts, bypassing MFA protections and persisting in the environment using the fully compromised identity," the tech giant said in a series of posts on X (formerly Twitter). Traditional security measures won't cut it in today's world. It's time for Zero Trust Security. Secure your data like never before. The foothold obtained in this manner further acts as a conduit for escalating privileges, moving laterally across the network, and accessing cloud resources in order to grab sensitive information, specifically going after gift card-related services to facilitate fraud. On top of that, Storm-0539 collects emails, contact lists, and network configurations for follow-on attacks against the same organizations, necessitating the need for robust credential hygiene practices. Redmond, in its monthly Microsoft 365 Defender report published last month, described the adversary as a financially motivated group that has been active since at least 2021. "Storm-0539 carries out extensive reconnaissance of targeted organizations in order to craft convincing phishing lures and steal user credentials and tokens for initial access," it said. "The actor is well-versed in cloud providers and leverages resources from the target organization's cloud services for post-compromise activities." The disclosure comes days after the company said it obtained a court order to seize the infrastructure of a Vietnamese cybercriminal group called Storm-1152 that sold access to approximately 750 million fraudulent Microsoft accounts as well as identity verification bypass tools for other technology platforms. Earlier this week, Microsoft also warned that multiple threat actors are abusing OAuth applications to automate financially motivated cyber crimes, such as business email compromise (BEC), phishing, large-scale spamming campaigns, and deploy virtual machines to illicitly mine for cryptocurrencies.
Daily Brief Summary
Microsoft has identified an uptick in cybercrime by a group called Storm-0539, targeting gift card services.
The threat actor utilizes sophisticated email and SMS phishing scams to steal credentials and session tokens.
Victims are lured to phishing sites that enable Storm-0539 to bypass MFA by registering their own devices.
Once inside a network, the group escalates privileges and accesses sensitive information, particularly aiming at gift card-related services for fraud.
Storm-0539 also harvests emails, contact lists, and network configurations to prepare for subsequent attacks.
The group, reportedly active since 2021, conducts thorough reconnaissance to create effective phishing lures.
Microsoft’s recent actions include seizing infrastructure of a related Vietnamese cybercriminal group and warning against OAuth app abuse by multiple threat actors.