Device Code Phishing Is How Midnight Blizzard Beat MFA on Hotel Wi-Fi – Latest Hacking News

714

A recent cybersecurity incident involving device code phishing allowed a Russian state hacking group to gain access to business travelers’ Microsoft 365 accounts without stealing passwords. This technique was attributed to Storm-2945, a sub-cluster of Midnight Blizzard, operating through compromised hotel Wi-Fi networks since July 16th. The attack was layered on top of an existing malware campaign that has been active since May.

Understanding how device code phishing works is crucial for Entra ID tenants. The exploit takes advantage of a legitimate Microsoft feature designed for devices without browsers, such as smart TVs or conference room consoles. The attacker initiates a request for a device code, which is then displayed to the victim under the guise of a fake update or verification process. When the victim enters this code on a genuine Microsoft sign-in page, they unintentionally authenticate the attacker’s session instead of their own device.

\"A

Implications and Recommendations

This device code phishing technique was integrated into a broader campaign that also utilized ClickFix-style lures to deploy malware tools like CornFlake and ChocoShell. These tools specifically target Microsoft 365 and Azure AD tokens, posing a significant threat to corporate cloud accounts. It’s crucial for organizations to proactively monitor and secure their systems against such attacks.

Organizations should conduct thorough sign-in log analysis, cross-referencing travel records, and be vigilant for indicators like specific domains and file hashes associated with the attack. Implementing security measures such as disabling device code authentication flow, deploying phishing-resistant MFA for privileged users, and utilizing Security Service Edge tools can help mitigate the risk of such attacks.