Tuesday, July 16, 2024
EHA

Iranian Hackers Attack the US & Israeli Defense Technology – Microsoft Warns

Iranian hackers have recently attacked Microsoft in which more than 250 Microsft Office 365 accounts that are linked to the United States, the European Union, and the Israeli government were being compromised through comprehensive password spraying.

Despite having strong protection, the Iranian threat actors have managed to classify the vulnerabilities of their company’s protection and infiltrate them. 

After knowing about the attack, Microsoft asserts that organizations that have been attacked by Iranian groups are currently working with the EU, the United States, and Israel in the production of defense technologies.

Behaviors noted

A series of behaviors and tactics are being used by the attackers, and that’s why here we have mentioned some of them below:-

  • Comprehensive inbound traffic from Tor IP addresses for password spray campaigns
  • Emulation of Firefox or Chrome browsers in password spray campaigns
  • Enumeration of Exchange ActiveSync (most common) or Autodiscover endpoints
  • Use of enumeration/password spray tool comparable to the ‘o365spray’ tool hosted at https://github.com/0xZDH/o365spray
  • Use of Autodiscover to verify accounts and passwords
  • Found password spray activity commonly topping between 04:00:00 and 11:00:00 UTC

Recommended Precautions

Here are some of the defenses that are to be followed by the organizations to keep themself safe from this kind of attack:-

  • Always allow multifactor authentication.
  • Microsoft fully assists customers to download and use passwordless resolutions such as Microsoft Authenticator to keep the accounts safe.
  • Examine and implement approved Exchange Online access policies.
  • Remember to block all incoming traffic from anonymizing services.

The main motive of the DEV-0343 operators is to gain access to commercial satellite description and their own plans and shipping records, which would be utilized to increase Iran’s developing satellite program.

That’s why Microsoft affirmed that each and every customer should stay aware of this kind of attack, as they are quite harmful in nature and can put a lot of impact on different organizations.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Website

Latest articles

HardBit Ransomware Using Passphrase Protection To Evade Detection

In 2022, HardBit Ransomware emerged as version 4.0. Unlike typical ransomware groups, this ransomware...

New Poco RAT Weaponizing 7zip Files Using Google Drive

The hackers weaponize 7zip files to pass through security measures and deliver malware effectively.These...

New ShadowRoot Ransomware Attacking Business Via Weaponized PDF’s

X-Labs identified basic ransomware targeting Turkish businesses, delivered via PDF attachments in suspicious emails...

Hacktivist Groups Preparing for DDoS Attacks Targeting Paris Olympics

Cyble Research & Intelligence Labs (CRIL) researchers have identified a cyber threat targeting the...

Critical Cellopoint Secure Email Gateway Flaw Let Attackers Execute Arbitrary Code

A critical vulnerability has been discovered in the Cellopoint Secure Email Gateway, identified as...

Singapore Banks to Phase out OTPs for Bank Account Logins Within 3 Months

The Monetary Authority of Singapore (MAS) and The Association of Banks in Singapore (ABS)...

GuardZoo Android Malware Attacking military personnel via WhatsApp To Steal Sensitive Data

A Houthi-aligned group has been deploying Android surveillanceware called GuardZoo since October 2019 to...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles