Sunday, July 21, 2024
EHA

Cybercriminals Target Employees of Companies Worldwide to Exploit Network Access and Privilege Escalation

The FBI has published a Private Industry Notification (PIN) observing Cybercriminals are focusing to target employees of companies worldwide who maintain network access and an ability to escalate network privilege.

Throughout COVID-19, many companies had to quickly adapt to changing environments and technology. With these restrictions, network access and privilege escalation may not be fully monitored.

Several tools to automate services are implemented on companies’ networks, the ability to keep track of who has access to different points on the network, and what type of access they have, will become more difficult to regulate.

Threat

Presently, cybercriminals are attempting to gain all employees’ credentials, not just individuals who would likely have more access based on their corporate position.

According to FBI case information, as of December 2019, cybercriminals work together to target both US-based and international-based employees’ at large companies using social engineering techniques. The cybercriminals vished these employees through the use of VoIP platforms.

Vishing attacks are voice phishing, which occurs during a phone call to users of VoIP platforms. During the phone calls, employees were tricked into logging into a phishing webpage to capture the employee’s username and password.

Subsequently gaining access to the network, many cybercriminals found they had more network access, including the ability to escalate privileges of the compromised employees’ accounts.

In one instance, the cybercriminals found an employee via the company’s chatroom and influenced the individual to log into the fake VPN page operated by cybercriminals.

The actors used these credentials to log into the company’s VPN and performed an investigation to locate someone with higher privileges.

The cybercriminals were scanning for employees who could perform username and e-mail changes and found an employee through a cloud-based payroll service. The cybercriminals used a chatroom messaging service to contact and phish this employee’s login credentials.

Mitigations

  • Apply multi-factor authentication (MFA) for accessing employees’ accounts in order to minimize the chances of an initial compromise.
  • When new employees are hired, network access should be granted on a least privilege scale. Periodic review of this network access for all employees can significantly reduce the risk of compromise of vulnerable and/or weak spots within the network.
  • Scanning and monitoring for unauthorized access or modifications can help detect and minimize the loss of data.
  • Network segmentation should be implemented to break up one large network into multiple smaller networks which allow administrators to control the flow of network traffic.
  • Administrators should be issued two accounts: one account with admin privileges to make system changes and the other account used for email, deploying updates, and generating reports.

Final Word

Thus the report issued by FBI provides potential usage to recipients to protect against cyber threats.

“This data is provided to help cybersecurity professionals and system administrators guard against the persistent malicious actions of cyber actors”, says the FBI.

The FBI also encourages the recipients to report information concerning suspicious or criminal activity to their local FBI field office.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Website

Latest articles

Hackers Claiming Dettol Data Breach: 453,646 users Impacted

A significant data breach has been reported by a threat actor known as 'Hana,'...

CrowdStrike Update Triggers Widespread Windows BSOD Crashes

A recent update from cybersecurity firm CrowdStrike has caused significant disruptions for Windows users,...

Operation Spincaster Disrupts Approval Phishing Technique that Drains Victim’s Wallets

Chainalysis has launched Operation Spincaster, an initiative to disrupt approval phishing scams that have...

Octo Tempest Know for Attacking VMWare ESXi Servers Added RansomHub & Qilin to Its Arsenal

Threat actors often attack VMware ESXi servers since they accommodate many virtual machines, which...

TAG-100 Actors Using Open-Source Tools To Attack Gov & Private Orgs

Hackers exploit open-source tools to execute attacks because they are readily available, well-documented, and...

macOS Users Beware Of Weaponized Meeting App From North Korean Hackers

Meeting apps are often targeted and turned into weapons by hackers as they are...

Hackers Exploiting Legitimate RMM Tools With BugSleep Malware

Since October 2023, MuddyWater, which is an Iranian threat group linked to MOIS, has...
Guru baran
Guru baranhttps://gbhackers.com
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles