BYOD registration abused in large-scale phishing campaign

By
Follow google news

Australian organisations targeted.

Microsoft is urging users to enable multi-factor authentication (MFA) to prevent phishing attempts using stolen credentials by attackers who register devices on organisations' networks.

BYOD registration abused in large-scale phishing campaign

The novel attack abuses the bring-your-own device (BYOD) concept and is part of a large-scale multi-phase campaign discovered by Microsoft's Defender Threat Intelligence Team.

Organisations in Australia, Singapore, Indonesia and Thailand have been targeted by the attackers.

After stealing user credentials, the attackers then attempt to join unmanaged devices that they control on organisations' networks, for lateral movement.

Leveraging BYOD registration by threat actors is on the rise, Microsoft said.

"These unmanaged devices are often ignored or missed by security teams at join time, making them lucrative targets for compromising, quietly performing lateral movements, jumping network boundaries, and achieving persistence for the sake of launching broader attacks," Microsoft said.

"Even more concerning, as our researchers uncovered in this case, is when attackers manage to successfully connect a device that they fully operate and is in their complete control."

To foil the attacks, Microsoft said organisations should enable MFA, which prevents the use of stolen credentials.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Home Affairs orders gov-wide 'legacy' system stocktake within six months

Home Affairs orders gov-wide 'legacy' system stocktake within six months

Citrix confirms exploitation of Netscaler zero-day bugs

Citrix confirms exploitation of Netscaler zero-day bugs

OpenAI agent accessed "credentials" via Medicare data portal

OpenAI agent accessed "credentials" via Medicare data portal

Australian Medicare data portal "infiltrated" by OpenAI agent

Australian Medicare data portal "infiltrated" by OpenAI agent

Log In

  |  Forgot your password?