TOPIC:

Computer Security: One click to many

Written by:

Computer Security Office

More senior colleagues might still recall the regularclickingcampaigns that were intended to raise security awareness within the Organization among staff and users. With the roll-out of two-factor authentication, such campaigns were dropped. However, the world continues to turn and novel functionality and novel attack vectors try to circumvent our protections. And they have managed, this time!

Arriving in the mailbox of an unlucky colleague, an innocent-looking email was met with the usual response. The subject and content corresponded to something expected, as in the two examples below:

By clicking on the embedded link to a Word document, and not noticing that it pointed to an obscure, non-CERN-related domain (more on that below), a landing page popped up displaying a dedicated “verification code” to be typed into a subsequent webpage (similar to the code you get when you use Netflix on a new device). This code is the crucial part of the attack and is designed to gain full access to the victim’s account: by copying the “verification code” (left screenshot) into the next webpage in order “to allow access” (right screenshot), the victim’s account is gone. Compromised. And waiting to be abused. Boom!

Behind the scenes, the attack benefits from a Microsoft cloud configuration that uses “device code authentication”. Basically, this is a locally installed token, valid for 90 days, that makes your life easier by not requiring you to log into Microsoft cloud services on a daily basis. But also making life easier for an attacker by removing the bother of CERN’s two-factor authentication… Boom, boom!

Now with access to the victim’s mailbox, an AI-automatism kicks in, identifying a plethora of new email addresses as potential targets, linking those targets one by one to “reasonable” hooks (like “Back orders” or “Q’2 EMEA Project” in the screenshots above) and cascading the attack onwards… to more than 5000 recipients at CERN. And another 108 of them click… Boom, boom, pow!

…and 108 account holders get their Microsoft cloud token revoked, requiring them to log in again via CERN’s 2FA-protected Single Sign-On. But that’s not enough. While the Computer Security Office investigates additional means to protect against these kinds of attacks (disabling “device code authentication”? reducing the “90 days”? limiting the number of emails sent per day?), CERN also counts on you: even if an email message might sound legitimate (does it?), be vigilant! Hover your mouse pointer over any URL, any link, any QR code, to check their destination, and STOP – THINK – DON’T CLICK! In particular, if that destination is unknown to you, unexpected, unfamiliar or just weird (as in the screenshot below, with an unexpected “mata-asia[.]com”):

________

Do you want to learn more about computer security incidents and issues at CERN? Follow our Monthly Report. For further information, questions or help, check our website or contact us at Computer.Security@cern.ch.

Related Articles

No posts were found. Try to change the category or the date filters.