10 ms·
We got hit by an alarmingly well-prepared phish spammer
- BLKNSLVR 2y agoSeems like a lot of effort to just send spam. Almost feels like their preparation outweighs their imagination by a large margin. I'd have thought there would be a lot more that could be done with VPN access than immediately burn it by sending spam.
- freitasm 2y agoOr perhaps sending spam was just a ploy to divert attention from something happening on a different server while people were trying to stop the flow of emails? Distraction. Like a magician.
- michaelt 2y agoThe prize isn't sending spam. The prize is sending phishing e-mails that are indistinguishable from authentic e-mails. E-mails where every check and signature says they really come from the university's employee pensions team, or the IT accounts team, or the legal team.
- ale42 2y agoThat's why we have now 2FA enabled on most external access, VPN included.
- jamespo 2y agoAmazing they don't have 2FA on VPN, even if you don't go for yubikey/phone app you could at least require a cert.
- kmoser 2y ago> As far as we can tell [...] the phish spam attacker used the main password they'd just stolen to register the person for our VPN and obtain a VPN password... Requiring admin approval for VPN accounts would have prevented the phisher from getting VPN access to begin with.
- NVHacker 2y agoI don't know where is the tech ability bar for spammers but this doesn't strike me as unusually clever or well prepared.
- rurban 2y agoFor the typical spammer, this was pretty good. For the typical hacker or foreign service this went as expected. Just that they detected it very soon, so not much harm done. Only VPN
- Arnt 2y agoMost of them are said to be quick about exploiting Gmail or other systems they know, but slow with unknown software (hours rather than seconds). If your system is on-premises, you may reasonably assume that the attacker will need to read the man page, like a new employee, see? But these guys didn't need to read the man page.
- dangus 2y agoYou're right, it's not clever at all, the attacker just happened to find a completely zero authentication internal service. They might have even done so via an automated tool like some kind of script kiddie network scanning program. This is the kind of dumb stuff we were doing 30 years ago: making the assumption that being physically on the network implies authentication. There's zero excuse to have a no-auth SMTP server, or anything else for that matter.
- nubinetwork 2y agoI feel bad for cks, but I probably would have handled it a little differently... - shut their accounts off network-wide - drop all related network connections - forcibly reset their password and make them choose a new one in person. They may have changed it earlier, but do it again - increase logging to catch any potential reoccurrences against the same user or other users - inspect ACLs and reduce access for all users if possible - prevent users from connecting from areas outside of their usual network sphere - let the user back on, and ask them to be more careful in the future - better mail filtering would be nice, but they'll always find a way to beat the spam filter - (i hate this option the most, but...) send fake scam emails internally to see if anyone else takes the bait This is of course ignoring 2fa, but 2fa isn't perfect either with sim swapping... but I personally don't think changing the password is enough for an event like this.
- nonrandomstring 2y agoTFA describes a perfect example of unwarranted implicit trust. Any tunnel-in should terminate in an environment not unlike being outside a regular perimeter, with internal per-host access control (perhaps by RADIUS or some coordinated ACL - which would also have fixed the parallel account problem )... especially to an unsecured Internet mail server. I wish the misnomer "Zero Trust" were better crafted and understood as a broad philosophy. I think it's psychologically difficult to do the role-play and imagine "what if I couldn't trust myself?"
- Ekaros 2y agoOnly place I accept implicit trust is inside a single program. Even on same machine one should think is trusting other processes warranted.
- nonrandomstring 2y ago> inside a single program Cool, but hey get this... I'm interviewing next week some guys working in API security. and the discussion notes so far are terrifying. People do all this work to build secure networks and OS, and then someone says "Hmm we need an API for <fashionable reason>", and next thing a junior dev exposes all the top level functions of a program running with high privileges as URL handlers. So maybe even _within_ your app it's not too paranoid to think "what if someone got an entry point into this function?" and at least put a "NEVER EXPOSE" comment there :)
- chinathrow 2y ago> People connecting through our VPN have access to an internal-only SMTP gateway machine that doesn't require SMTP authentication. Time to clean that up while you're at it.
- Ekaros 2y agoLayered defence. These days, why do you have anything unauthenticated anywhere? Every system should be authenticated and authorized. Unless information is fully public.
- buran77 2y agoBecause of that one cobbled together system, or old network MFP that sends to mail, that's needed for a whole bunch of stuff, can't authenticate, and someone decided it's too expensive to replace for such a small attack surface. Until the problem costs more than the solution large organizations don't move by design. This is usually officially the benchmark: what costs more.
- maccard 2y agoIn my experience, there’s a random server that nobody knows who maintains it offhand, including the person who maintains it. People ask, and it just doesn’t go anywhere. Until something like this happens. It’s nothing to do with costs, its just an oversight
- arccy 2y ago(opportunity) cost to dig into ownership
- ivan_gammel 2y ago1. Carefully establish the one critical data flow the whole business depends on. It may cost some time, but this one you have to protect by all means, so stakeholders won't mind. 2. As for the rest, take them down one by one and see what breaks. Got a call to internal support hotline? "Ooops, sorry, we will turn it on and let's chat about it soon." There can be a few announcements in advance to shift the blame before (2): "Declare yourself or face consequences" (ChatGPT will write a nicer email). If you are on good terms with CFO, the noise won't matter. In fact, many people will thank you, when their weird stuff is taken over for care by IT.
- altacc 2y agoI see a lot of posts, articles, etc... stating that people are surprised by the complexity of a cyber attack or scam. It seems that most people haven't yet learnt that this is a full blown industry targeting countless businesses, institutions and individuals 24/7, not just some script kiddies in their bedroom. There are office blocks full of trained professionals with sophisticated tools working to compromise digital security and manipulate human nature to gain access to accounts, data and funds. Everyone needs to be adopting a form of zero trust or trust but verify to every digital interaction and every use of technology.
- randunel 2y agoAs a passive hotel owner and active programmer, I can confirm it's always been the case. In the hotels business, getting customer requests, invoices and refund requests seemingly out of nowhere isn't too uncommon. Receptionists, who have the authority handle customer cancellations and refunds, but also package / documents receipt for them, frequently fall for the slightly more laborious scams, in spite of the safeguards in place. The phishing emails we get at my software dev job for security certification and pen testing pale in comparison to the actual effort being put in by scammers, who coordinate bookings with parcels and random invoices so that they tell a story, always targeting different shifts (almost never the same).
- selestify 2y agoWhat are these scammers looking for? Presumably not to just get a refund on their vacation or package delivery.
- withinboredom 2y agoThey're looking for a refund for a vacation or package delivery that never happened -- or did happen, but not for them.
- randunel 2y agoAs the other commenter has posted, refunds for inexistent bookings or refunds for someone else's booking are pretty frequent. Other simple stuff is overdue payments for fictive deliveries such as soaps, toilet paper, cleaning bills or even outsourced work. The more complex scams involve making bookings and sending packages with fees and totals paid by the recipient, they try to convince the receptionists that their package needs to be delivered, and an actual delivery of random stuff happens using a real delivery company to complete the scam. They don't always mention that there's payment required on delivery. Other scams involve claiming lost luggage, wallets, electronics without them being the owners, and trying to convince the receptionist to send the item internationally. We're a hotel next to the airport, so international travellers are the norm, plus we have a room full of lost stuff. They make a booking with a fictional name, then cancel it or no show, and then ask for their black luggage, black wallet, tablet, gold bracelet, etc.
- sim7c00 2y agoztna+ can help here. VPN give access to entire network, with all the rubbish services sysadmins have laying around like unauthenticated smtp servers (sounds total shit but it happen everywhere.... need to send email notifications from all sorts of shit and no one wants to manage these accounts... sadstory..) ztna+ will for users kind of seem like vpn, good protection,but it only give access to services the user is allowed to access, not the entire vpn network. it help alot against these type of scenarios. also, how fast is fast? you can scan an internal network on a single port in the blink of an eye, so if u don't have good network IDS/IPS internally, u will not really see the scan and it seems like someone 'knows the network in advance' because they scan it in like 2 seconds and based on results automatically run scripts etc. - it doesn't need to be knowledge gained in advance. - monitor internal network properly, asif its external network. - use ztna+ if you can afford such solution - do regular audits for things like unauthenticated services and use these kind of incident to in a friendly manner educate sysadmins about risks of such services. they will usually understand it, especially after an incident. aslong as you bring it friendly with a good explanation, not some demanding attitude. - use a lot of mail filtering... more is better. it can be a bit tedious. at my company we have more than 4 solutions to scan all email and attachements etc. , still stuff slip through, but not a lot... - also scan outbound or 'local' email. (BEC fraud etc.) - do good post-incident reviews and use learnings each time something happens (sounds obvious, but this is often omitted, the learnings are only kept within sec teams, or turnt into one-off remediations rather than process etc. ) edit: oh.. and also monitor for logon anomalies. a lot of solutions support this. e.g. a user logs in from a unique new ip - alert on it, or even block it. , that action depends a bit on what's normal, so here actually ML and such solutions are great.. but basic statistical analysis etc. can also help if u can't pay or create ml solution. (its not too hard to create really, basic models will suffice.)
- hatly22 2y agoSounds like it is possibly an automated script or agent doing most of this work accessing the VPN and SMTP server. Really shouldnt have any open mail servers anywhere.
- Vampiero 2y agoYou got hit by a former employee
- dh2022 2y agoOr maybe an upset former student.
- dmurray 2y agoThis is a university. I expect they have a higher than normal proportion of attackers who know the system and exactly how they'd escalate having gained some access, and have the free time to prepare a customized attack. On the other hand, those attackers are probably less malicious than the average Russian ransomware group.
- indymike 2y agoWhen I was in the US Navy, I learned most of the time, the weak points in security were usually people. Attackers know this and exploit it. And it usually wasn't movie plot style "do this or your wife gets it" exploits. Those seemed to get blown up easily. It was mundane things. Distracting a watch stander with something that was actually stupid. Making someone late for duty. Putting something really gross in the garbage hoping the inspector would skip that bag. So many little lapses in human judgement. Most completely innocent. This was with vigilant, uniformed people subject to military discipline, and those thing happened. So you have to focus on process and systems. Some easy stuff: * Never ask customers/employees for a password. If someone does it's a scam. * Refund money only to the payment method used to pay for the product/service. * 2FA is your friend no matter how much the VP of Sales whines about it. * have a way to expire tokens and force reset of passwords.
- duxup 2y agoPeople… and frankly even just accounting at many places is surprisingly informal.
- RandomBacon 2y agoThat's why it's easy. People think "I'm not important enough" to be targeted, or "My job isn't that important", but that's what adversaries are counting on. Their "unimportant" job or whatever is just a stepping stone.
- voytec 2y ago> When I was in the US Navy, I learned most of the time, the weak points in security were usually people. Good example: > Navy chiefs conspired to get themselves illegal warship Wi-Fi [0] [0] https://www.navytimes.com/news/your-navy/2024/09/03/how-navy-chiefs-conspired-to-get-themselves-illegal-warship-wi-fi/ https://www.navytimes.com/news/your-navy/2024/09/03/how-navy... [0] https://news.ycombinator.com/item?id=41441486 https://news.ycombinator.com/item?id=41441486
- wbeckler 2y agoWhat's the threat scenario where forcing a password reset increases security? I'm genuinely curious, because I feel it's often the case that password expirations might introduce more threats than they mitigate.
- cookiengineer 2y agoAfter the takedown of APT28, I continued to receive spam from IP ranges that were associated with APT29's malware campaigns. Turns out there's a lot of fake shell companies that act either as hosting companies specifically for malware campaigns from Russia and China or specifically as a company that tries to fraud people, e.g. their CEO being on the FBI most wanted list or the company being sanctioned by the UN. I'm currently creating some sort of cyber map of these spam/phish/malware campaign overlaps, as part of my antispam [1] effort. I got tired of LLM based targeted spam where they have a system in place that is trained on my social media profiles, because they are very hard to identify as being spam. Blocking specific domains is a useless effort because they keep on spawning new fake company domains that are either copies of legit ones or are generated fake profiles. They are so automated that they also create staff members and fake profiles on LinkedIn, specifically for that spam effort. Nobody at LinkedIn gives a shit about those fake avatars, I reported hundreds by now and they did absolutely nothing. Anyways, long story short, here's the blocklist of those ASNs and companies. I'm working on the map at the moment and don't wanna publish it until I can prove its correctness: [1] https://github.com/cookiengineer/antispam https://github.com/cookiengineer/antispam
- joelfried 2y agoThank you for doing this important work!
- c00kien1gg3r 2y ago[dead]
- igleria 2y ago> I reported hundreds by now and they did absolutely nothing. Ha. Same here but reporting a job ad that targets the dublin area, but it's really for bangkok. I hate it.
- nzach 2y ago> they are very hard to identify as being spam For every account I create on the internet I create a new mail inbox, this way I can just compare the email title with the inbox it was sent to. So, when I receive a notice from my bank on my github email I know what happened. This genuinely saved me a few times already.
- axus 2y agoI've gotten emails with links "From" my parents names, but checking the addresses it was accounts on random .edu domains. The fact that separate emails came from two different names I knew really made me feel targeted.
- f4c39012 2y agoNot necessarily. We have employees sent the usual phishing emails claiming to be from the CEO - but sent to their personal email addresses, since the attackers know targeting a corporate domain won't work because of the "similar-name-but-external-domain" warnings. I figure these kinds of relationships are determinable from linkedin etc., but they're still automated. Using family members seems like an extension of this technique, sending phishing from someone you probably know.
- toobulkeh 2y agoOr you can ask a GPT, that has already indexed your publicly available support docs, to prioritize potential places for a user looking to keep access as a backup. AI is available to everyone, and we’re not prepared.
- voytec 2y ago> People connecting through our VPN have access to an internal-only SMTP gateway machine that doesn't require SMTP authentication. This part sounds... not great. Even bad actor within org could send messages as someone else: president to payroll etc.
- spogbiper 2y agonot great indeed. is this organization not under any compliance requirements? unauthenticated SMTP is not going to pass even the laziest of security scans. although neither is VPN access without MFA
- bluGill 2y agoI have concluded that I will eventually fall for a scam and pay a medical bill for some service I never received. All the bills look like scams, and for one service there are often 3 separate bills from different areas so it would be easy for someone to tack on one more and get some cash from me...
- patcon 2y ago> It seems extremely likely that the attacker had already researched our mail and VPN environment before they sent their initial phish spam, since they knew exactly where to go and what to do. As someone else said, I would increasingly suspect that apparently targeted or seemingly highly-invested hacking behaviour is just a new breed of scripts that are puppeteer by phishing AI multi-agent systems (maybe backed by deepseek now). Just like self driving cars that will never make the same mistake twice, these things will likely keep a catalog of successful tactics, and so always be learning obscure new tricks
- deckar01 2y agoI thought our unauthenticated SMTP got shutoff after switching to Office 365. I looped over the SMTP servers in the hop list in the headers of an email and one of the Microsoft domains accepted unauthenticated requests from within the network.
- 1970-01-01 2y agoThe invisible lesson here is to just use 2FA everywhere or accept the risk of this happening to you.
- aaroninsf 2y agoMaybe we just stop using email.
- spogbiper 2y agoIn the comments, the author mentions this: "As for information on our VPN setup (and our mail sending setups), it's on our support site (for obvious reasons) so we assume the attacker read it in advance." That really changes the level of complexity for the attacker here
- Lord_Zero 2y agoIts just full of bad practices. No 2FA? Why is VPN its own username and password? Why not use a product that can use SSO?
- rosiesophia10 2y ago[dead]
- Scotrix 2y agoNo auth smtp server sounds like a very bad idea and the real culprit here. Security by obscurity (VPN in this case) never works.
- JayDustheadz 2y ago> because they are very hard to identify as being spam. Why not just use Duckduckgo's free e-mail protection? Generate a new forwarding address for a new service/website/account takes a second.