Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign
Microsoft Defender researchers have identified a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting organizations within the energy sector through the exploitation of SharePoint file-sharing systems. This multi-stage attack resulted…
Microsoft Defender researchers have identified a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting organizations within the energy sector through the exploitation of SharePoint file-sharing systems. This multi-stage attack resulted in the compromise of multiple user accounts, leading to extensive business email compromise (BEC) operations.
Initial Compromise Through Trusted Vendor
The attack commenced with phishing emails originating from a compromised vendor's email address. The attackers used SharePoint URLs that required authentication, imitating legitimate document-sharing processes to bypass suspicion. By exploiting the trust in Microsoft SharePoint and OneDrive services, which are prevalent in enterprise environments, the attackers avoided traditional email security filters.
Victims who accessed the malicious links and provided credentials on mock login pages unwittingly gave attackers access to their user sessions. Subsequently, the attackers created inbox rules to delete incoming emails and mark messages as read, thereby maintaining stealth and preventing the detection of suspicious activities.
Following the initial compromise, attackers launched a significant phishing campaign, distributing over 600 emails to both internal and external contacts of the victim organization. This campaign targeted recipients identified from recent email threads, expanding the attack's reach.
Attackers actively monitored compromised mailboxes, deleting undelivered and out-of-office notifications to remain undetected. In cases where recipients questioned the legitimacy of emails, attackers responded from compromised accounts to falsely confirm authenticity before erasing the conversation threads, thus maintaining persistence without alerting victims.
This multi-stage attack resulted in the compromise of multiple user accounts, leading to extensive business email compromise (BEC) operations.
Microsoft Defender Experts identified additional compromised users by analyzing landing IP and sign-in patterns, revealing the campaign's extensive impact across multiple organizations in the energy sector.
Microsoft emphasizes the insufficiency of password resets alone for mitigating AiTM attacks. Organizations must also revoke active session cookies, remove attacker-created inbox rules, and reset any modified multi-factor authentication (MFA) settings. Attackers can sustain access through stolen session cookies and may register alternative MFA methods using attacker-controlled phone numbers.
Microsoft advises the implementation of conditional access policies that assess sign-in requests using identity signals such as IP location, device status, and user group membership. Additional security layers can be ensured by continuous access evaluation, security defaults in Azure Active Directory, and advanced anti-phishing solutions.
To detect suspicious activities, including multiple account sign-in attempts and malicious inbox rule creation, the deployment of Microsoft Defender XDR is recommended.
178.130.46.8 (Attacker infrastructure) 193.36.221.10 (Attacker infrastructure)
Organizations within the energy sector should immediately search for these IP addresses in authentication logs and investigate any related sign-in activities.
Based on reporting by Cyber Security News.
