• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Security»0ktapus phishing campaign has attacked over 130 companies
Security

0ktapus phishing campaign has attacked over 130 companies

August 26, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Apple Lockdown mode adds ‘extreme’ protection to your iPhone, iPad and Mac
Share
Facebook Twitter LinkedIn Pinterest Email

Over 130 organizations, including Twilio, DoorDash, and Signal, have been potentially compromised by hackers as part of a months-long phishing campaign nicknamed “0ktapus” by security researchers. Login credentials belonging to nearly 10,000 individuals were stolen by attackers who imitated the popular single sign-on service Okta, according to a report from cybersecurity outfit Group-IB.

Targets were sent text messages that redirected them to a phishing site. As the report from Group-IB states, “From the victim’s point of view, the phishing site looks quite convincing as it is very similar to the authentication page they are used to seeing.” Victims were asked for their username, password, and a two-factor authentication code. This information was then sent to the attackers.

Despite the campaign’s success, Group-IB’s analysis suggests that the attackers were somewhat inexperienced

Interestingly, Group-IB’s analysis suggests that the attackers were somewhat inexperienced. “The analysis of the phishing kit revealed that it was poorly configured and the way it had been developed provided an ability to extract stolen credentials for further analysis,” Roberto Martinez, a senior threat intelligence analyst at Group-IB, told TechCrunch.

But inexperienced or not, the scale of the attack is massive, with Group-IB detecting 169 unique domains targeted by the campaign. It’s believed that the 0ktapus campaign began around March 2022 and that so far, around 9,931 login credentials have been stolen. The attackers have spread their net wide, targeting multiple industries, including finance, gaming, and telecoms. Domains cited by Group-IB as targets (but not confirmed breaches) include Microsoft, Twitter, AT&T, Verizon Wireless, Coinbase, Best Buy, T-Mobile, Riot Games, and Epic Games.

See also  Battlefield's next campaign being developed by Halo co-creator's new studio

Cash appears to be at least one of the motives for the attacks, with researchers stating, “Seeing financial companies in the compromised list gives us the idea that the attackers were also trying to steal money. Furthermore, some of the targeted companies provide access to crypto assets and markets, whereas others develop investment tools.”

Group-IB warns that we likely won’t know the full scale of this attack for some time

Group-IB warns that we likely won’t know the full scale of this attack for some time. In order to guard against similar attacks like this, Group-IB offers the usual advice: always be sure to check the URL of any site where you’re entering login details; treat URLs received from unknown sources with suspicion; and for added protection, you can use an “unphishable” two-factor security keys, such as a YubiKey.

This recent string of phishing attacks is one of the most impressive campaigns of this scale to date, according to Group-IB, with the report concluding that “Oktapus shows how vulnerable modern organizations are to some basic social engineering attacks and how far-reaching the effects of such incidents can be for their partners and customers.”

The scale of these threats isn’t likely to decrease any time soon, either. Research from Zscaler shows that phishing attacks increased by 29 percent globally in 2021 compared to the previous year and notes that SMS phishing in particular is increasing faster than other kinds of scams as people have started to better recognize fraudulent emails. Socially engineered scams and hacks were also seen rising during the COVID-19 pandemic, and earlier this year, we even saw that both Apple and Meta shared data with hackers pretending to be law enforcement officials.

See also  NCSC warns public of potential Queen-related phishing attacks

Source link

0ktapus attacked campaign companies Phishing
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Generative AI Is Making Companies Even More Thirsty for Your Data

August 10, 2023

6 Steps For Using ChatGPT In Your Next Email Marketing Campaign

August 9, 2023

Capitalizing On TikTok Trends: How Companies Stay Relevant

July 27, 2023

A Market Niche For Startup Tech Companies?

May 6, 2023
Add A Comment

Comments are closed.

Editors Picks

Samsung Galaxy Buds FE review

December 18, 2023

Grand strategy society simulator Victoria 3 will be released October 25

August 30, 2022

How to Spot AI-Generated Art, According to Artists

January 22, 2023

A US Rail Strike Was Averted—but the Crisis Is Far From Over

September 16, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.