
Selena Larson talks about the recent AitM phishing and ClickFix trends.
Loading summary
A
Hello, this is Katalin Campano and this is a risky business news sponsored interview with Selena Larson, senior threat Intelligence analyst at proofpoint. Welcome, Selena.
B
Hello. Hello. Thanks for having me.
A
Two days ago I recorded an interview with Jacques Low from Push Security, and one of the topics we talked about was attacker in the middle phishing, and especially the prevalence of these phishing kits, which are basically reverse proxies that help out the classic phishing kit by intercept, accepting your two factor authentication challenges, and then the authentication cookie that gets exchanged during this process. My conversation with him revolves primarily around how they detect this inside the browser where the product works. Now, I want to talk about attacker in the middle of phishing with you because I want to know what email security vendors see and how they treat this or what kind of data they have on this. Is attacker in the middle phishing just an outlier or is actually quite that prevalent these days?
B
Yeah, it is very prevalent. We see a lot of it in email threat data. And it really comes down to two different types of attacker in the middle phishing. So you have reverse proxies, which you mentioned, essentially rewriting the sites and pages in real time to steal all of that information. And then you have relays. So relays are a separate fake site that will interact with the login portal on the back end. So, but essentially from a technical perspective there, you know, the result is the same. They still, you know, usernames, passwords, and MFA authentication tokens. So what we see a lot of are kits like Mamba or Tycoon. The reverse proxies, obviously like Evil Proxy and Evil Jinx. These are, you know, the main phishings as a service that operate as sort of like reverse proxy. And it's interesting because you see a lot of this sort of like customized phishing with a lot of these. It's made it fairly easy on the point of the threat actor to, you know, buy these services, use these services, customize them if they have, you know, the ability or desire to do so. And frankly, you know, at this point, most phishing as a service solutions, I guess, are capable of defeating these MFA controls. I mean, fundamentally, like attackers are fully leaning into MFA because, you know, MFA is everywhere. And, you know, from a defense perspective, it's really just, you know, conditional access policies or Fido tokens that are the technical solution to this problem. So it's, it's interesting to see the volume on a lot of these campaigns. It can be, you know, thousands of messages, tens of thousands of messages. A lot of them go after, obviously 0365 credentials, Gmail credentials, things like that. But yeah, it is a, it is pretty prevalent and we do see quite a bit of it in email threat data.
A
I actually had a question now, but while we were talking I figured out that it was actually wrong. Like I want to ask you if these stolen cookies end up on credential shops. And then I remember that I read a lot of research about how most of the stuff on credential stores actually comes from info stealers. I was wondering if you ever ran some kind of test with just put a test account in one of these phishing kits and see if they actually end up on credential stores as well.
B
So we've actually never done that. Proofpoint doesn't really monitor the sort of like leak sites and the, you know, like the hacking tool for sale sites. So we don't have not seen that.
A
Now it doesn't seem like something you'd be able to monetize that easy because info stealers usually have loads more data that can be monetized while an attacker in the middle. Phishing is just for that one site. It's not usually worth the effort for one of these sellers, right?
B
Well, I'm not sure from the perspective of a seller, but from what we see in terms of these phishing as a service kits, they are a lot more widespread. Not a ton of specifically targeted or, you know, apt types of activity. It mostly does align with sort of like the cyber criminal enterprise. And from a perspective of selling the information, like the login information, obviously MFA codes are very difficult to resell. Right. Because they're temporary just by nature of, you know, whether it's a session cookie or you know, a MFA code that you're inputting or something. But obviously the usernames and passwords could be, you know, sold and used. But when you get access to a, an environment, I mean from our perspective we see the fish kits themselves and the information that, that they're trying to get. But in terms of follow on activity could be used for a variety of things. Right? So everything from follow on phishing to gain further access to a network to leveraging information to create business email compromise attacks, for example, like, you know, looking through inboxes to see who are they talking to? How can I leverage potential people across the supply chain for, you know, further business email compromise, for example, certainly gaining access to O365 instances, potentially installing malicious cloud apps for persistence, being able to, you know, have that visibility within a network to then have potential follow on whether that's you know, additional phishing or malware deployment or bec. But for most of the stuff that we see, it's a lot more sort of higher volume and not quite so much of the sort of targeted piece. But yeah, I mean, to your point, like, information stealers obviously can grab a lot more from a host once actually infected, but I think, you know, in tandem, it could be a follow on deployment or something like that if an actor is able to access the actual environment.
A
Another rising trend in threat intel space is something that people call click fix. I was wondering if you could tell us more about it.
B
I can tell you more about it. I find click fix fascinating. So for any of your listeners who are unfamiliar, I will explain what click fix is. Essentially, it is a social engineering technique that uses these dialogue boxes, these little things that pop up and say, either have fake error messages or, you know, here's how to fix it. And then they basically trick people into copying, pasting, and running malicious content on their computer. Basically, here, copy this PowerShell code and run it, and then this PowerShell code will then install malware, basically. So, but what's so interesting is that we see a lot, because it's very basic, right? Like, and a lot of people are like, oh, well, why would you just copy and paste that? Well, a lot of people don't really know what they're doing, but they see an error message on their laptop and instead of being like, oh, I want to. I have to call it, I have to contact people, I have to kind of like jump through these hoops. If they're shown a problem and a solution both together, it says, oh, here's the problem, but here's how you can fix it. You're kind of giving that person agency into solving this problem, and they're probably more likely to copy and paste something even if they're unfamiliar with it, because it has something to do with security or broken piece of technology. So it's kind of a very clever technique that we see in use by various threat actors that ultimately deliver malware. One thing that we have seen an increase of is this sort of recaptcha fish using the click fix technique many of the campaigns that we see. So essentially it's pretends to be a captcha and then it leads the user through the same sort of like, copy and paste and run PowerShell. In this particular thing, though, what was interesting is that this recaptcha fish is actually something that is available, you know, on GitHub, and it was published by a security researcher for, quote, educational purposes. And when this tool was released back in mid September, we started seeing it in email threat data just days later. So we're seeing a lot of the variance of click fix. Fundamentally what it comes down to is a user being socially engineered to copy, paste and write PowerShell, to ultimately install malware. And we're seeing it from a lot of different threat clusters, some attributed to threat actors, some not. But ultimately, it does seem to be a very compelling and potentially effective technique, just by nature of how much we're seeing it in volume across the landscape.
A
Now, from a Defender standpoint, most of these click fix campaigns usually end up leveraging PowerShell, right? So if, let's say a Defender team wants to get on top of this, probably the best way would be to limit PowerShell execution in their environments. Right. This is not the end of the world. It could be very easily solved.
B
Yeah. I mean, while it is kind of a very interesting social engineering technique. Yes. Essentially restricting access, restricting what's, you know, able to run on a host can definitely defend against it. It's also important too, I think, you know, having users be aware of this. So, you know, if you have like phishing training, user training, people becoming more aware that this is something that is being used because it does a lot of these, these dialogue boxes look very legitimate, right. They'll impersonate Chrome or they'll impersonate Microsoft Office or in some cases, we've actually seen these threat actors create very customized how to fix this trucking and transportation software, for example, that we saw in campaigns specifically targeting the transportation industry. And they customize these lures so they do look very convincing. But yes, from a Defender perspective, restricting the use and execution of PowerShell on, on hosts can definitely prevent this.
A
Do we know where the click fix technique came from?
B
I feel like the click fix technique is an evolution of tactics that we're seeing from threat actors in much the same way, you know, we're talking about MFA kind of being the big bad of credential phishing now, in response to people using MFA everywhere, and then the solution being, oh, you know, going to Fido, we are seeing threat actors respond to the landscape of improved defense and trying to come up with more creative ways of infecting a user. Right. So, you know, we're seeing social engineering like, you know, calling someone and pretending to be it to steal their MFA tokens and, you know, ultimately lead to ransomware execution. Now we're seeing this sort of. Oh, this is, you know, this is a technical issue. Here's how to fix it yourself. We're giving you agency, you can solve this problem. In reality, you're just infecting yourself. So it's threat actors kind of being very creative and trying new ways to sort of circumvent existing security controls. So in a couple cases we've actually seen for example, an email that doesn't have a malicious attachment or URL, it literally just has the powershell and the instructions in the email says, you know, copy and paste this to fix this problem. And so, you know, it's sort of an evolution of threat actors trying to bypass some of these security controls and being very creative. And it's interesting to see in use from a variety of threat actors, from sort of like commodity info stealers all the way up to reportedly Ukraine Start published details on a suspected APT28 even using the click fix technique. So it's very, you know, spans the gamut of the capabilities of these various threat actors. But they're all kind of using this social engineering to, to basically get people to infect themselves unsuspecting. And I think that's a really interesting psychological piece of this, this security threat.
A
So you could see a possible shift towards more social engineering and human interaction compared to classic. Here's a file, run it. That's, that's basically the future, right?
B
I think so, yeah. And what we've seen too is even like with benign conversation starters, right? So you'll have threat actors that will reach out, have a conversation with, with somebody and you know, before sending the payload. And that's something that we've seen a long time with business email compromise actors, for example, right. Like they're trying to have these conversations before asking someone to send them a check, right? Where they don't have a malicious URL or attachment, but they have this sort of, oh, you know, I'm contact you because of X, Y and Z, because they have, you know, a conversation that they want to strike up and building up a little bit of trust increases the likelihood of interaction on malicious applications. So you know, I think that that's definitely something that we've seen an increase of from the cybercrime space. We see it with APT actors certainly as well. They have oftentimes played very long games of benign conversations back and forth.
A
Especially the Iranians.
B
Yeah, yeah. Oh, and pretending to be people. Yes, definitely. So, yeah, but I, but I think that's something, you know, that's kind of like leaning into it. In fact, we've seen threat actors, for example, TA4557 is a threat actor that delivers Morax. They'll send these sort of benign emails about a potential job. And they'll have in their email, which I find very funny. Like, oh, you know, sometimes emails block my, my CV website, so I'm just going to type out the domain and, you know, have these spaces, but when you put it into the. The address bar, just delete the spaces. So they're, like, literally providing these instructions to a potential victim, which I find very funny. Like, you know, trying to convince people to do something is going to get harder if you just don't have, like, a one click to download the malware type of attack chain.
A
I think it's a great way to end it. Thank you very much.
B
Cool. Thank you so much.
A
Dam.
Risky Business News - Episode Summary
Title: Sponsored: Proofpoint on the Rise of ClickFix Attacks
Host: Katalin Campano
Guest: Selena Larson, Senior Threat Intelligence Analyst at Proofpoint
Release Date: December 8, 2024
In this episode of Risky Business News, host Katalin Campano engages in a compelling discussion with Selena Larson, a Senior Threat Intelligence Analyst at Proofpoint. Sponsored by Proofpoint, the conversation delves into the evolving landscape of phishing attacks, with a particular focus on the rise of ClickFix techniques and the broader implications for cybersecurity.
The episode opens with an exploration of attacker-in-the-middle phishing, a sophisticated method where threat actors intercept and manipulate authentication processes to steal sensitive credentials. Katalin references a prior discussion with Jacques Low from Push Security on similar topics, setting the stage for an in-depth analysis.
Selena Larson emphasizes the prevalence of this threat, stating, “[01:04] B: Yeah, it is very prevalent. We see a lot of it in email threat data.” She explains the two main types: reverse proxies and relays. Reverse proxies rewrite legitimate sites in real-time to harvest information, while relays interact with login portals on the backend. Kits such as Mamba and Tycoon, along with services like Evil Proxy and Evil Jinx, are highlighted as common tools used by cybercriminals to facilitate these attacks.
Larson notes, “[01:04]... most phishing as a service solutions are capable of defeating these MFA controls,” underscoring the adaptability of attackers in overcoming security measures like Multi-Factor Authentication (MFA).
Katalin raises an insightful question about the monetization of stolen credentials, pondering whether data from attacker-in-the-middle phishing ends up in credential shops. She observes, “[02:51]... most of the stuff on credential stores actually comes from info stealers.”
Larson responds, “[03:19] B: So we've actually never done that. Proofpoint doesn't really monitor the sort of leak sites...,” indicating that while Proofpoint tracks phishing kits and the information they target, they do not specifically monitor credential leakage on resale platforms. She elaborates on the complexities of monetizing MFA tokens due to their temporary nature, contrasting them with more valuable data like usernames and passwords.
However, Larson acknowledges the potential for stolen credentials to facilitate a variety of malicious activities, including business email compromise (BEC) and network access: “[03:31]... usernames and passwords could be sold and used... everything from follow on phishing to gain further access to a network...”
The conversation shifts to a rising trend in threat intelligence: ClickFix attacks. Katalin introduces the topic, and Larson provides a comprehensive overview.
Selena Larson describes ClickFix as a social engineering technique that employs fake dialogue boxes mimicking legitimate error messages or fix prompts. These deceptive prompts trick users into copying and executing malicious PowerShell commands, thereby installing malware. She explains, “[05:57] B: Essentially, it is a social engineering technique that uses these dialogue boxes... trick people into copying, pasting, and running malicious content on their computer.”
Larson highlights the simplicity and effectiveness of ClickFix, noting its prevalence across various threat actors. She cites the rapid adoption following its public release, “[05:57]... when this tool was released back in mid September, we started seeing it in email threat data just days later.” This underscores the technique’s adaptability and appeal within the cybercriminal community.
Addressing defense mechanisms, Katalin suggests limiting PowerShell execution to mitigate ClickFix threats. Larson concurs, emphasizing a multi-faceted defense approach:
“[08:31] B: ...restricting access and execution of PowerShell on hosts can definitely prevent this.”
She further advocates for user awareness and training, pointing out that informed users are less likely to fall victim to such social engineering tactics. Larson notes the importance of recognizing the legitimacy of malware delivery methods: “[08:31]... having users be aware of this... these dialogue boxes look very legitimate.”
Katalin inquires about the origins of the ClickFix technique, to which Larson responds by tracing it as an evolution of threat actor tactics in response to enhanced security measures like MFA.
“[09:28] B: I feel like the click fix technique is an evolution of tactics that we're seeing from threat actors... being very creative and trying new ways to infect users.”
Larson illustrates how threat actors continuously adapt, moving from MFA bypassing to leveraging social engineering methods that grant users a false sense of control, ultimately leading to malware installation.
She also mentions the diverse adoption of ClickFix across various threat levels, including Advanced Persistent Threats (APTs) like APT28, showcasing its broad applicability and effectiveness.
The discussion transitions to a broader shift in cyberattack strategies, moving from traditional methods to more sophisticated social engineering and human-centric interactions.
Katalin posits, “[11:13] A: So you could see a possible shift towards more social engineering and human interaction compared to classic... That’s basically the future, right?”
Larson agrees, highlighting the trend towards building trust and engaging users in conversation before deploying malicious payloads. She explains, “[11:23] B:... threat actors reach out, have a conversation with somebody... building up a little bit of trust increases the likelihood of interaction on malicious applications.”
Examples include tailored phishing attempts that mimic non-threatening interactions, such as job offer emails that gradually introduce malicious elements: “[12:10] A: Especially the Iranians... [12:12] B:... TA4557 is a threat actor that delivers Morax. They send benign emails about a potential job...”
This strategy reflects a more psychologically nuanced approach, making attacks harder to detect and more convincing.
The episode wraps up with Larson reiterating the importance of adaptability in cybersecurity defenses and the need for continuous user education. The conversation underscores the dynamic nature of cyber threats, emphasizing that as defenses evolve, so too do the tactics of threat actors.
Selena Larson concludes, “[13:02] A: I think it's a great way to end it. Thank you very much.”
Katalin Campano and Selena Larson exchange final remarks, highlighting the critical need for vigilance and proactive measures in combating sophisticated phishing techniques like ClickFix.
Notable Quotes:
For those interested in the latest cybersecurity threats and defense strategies, this episode of Risky Business News offers invaluable insights from a leading expert in the field.