• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Tech News»IAM house Okta confirms 0ktapus/Scatter Swine attack
Tech News

IAM house Okta confirms 0ktapus/Scatter Swine attack

August 31, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
LinkedIn most impersonated brand in phishing attacks
Share
Facebook Twitter LinkedIn Pinterest Email

Identity and access management specialist Okta has warned customers to be on their guard against a widespread and impactful phishing campaign that has already hit a very limited number of its customers.

This comes after researchers at Group-IB gathered evidence that tied together multiple recent incidents, including an attack on Twilio, in a criminal campaign that seems to have heavily exploited the Okta brand, and the trust its customers hold in it, in order to compromise its targets.

The campaign, which Okta has dubbed Scatter Swine – Group-IB coined a different name, 0ktapus – found that the data of some Okta customers was accessible to the threat actor through Twilio’s systems.

Okta’s defensive cyber ops team determined that a small number of mobile phone numbers and associated SMS messages containing one-time passcodes were accessible to the threat actor via the Twilio console.

“Okta has notified any customers where a phone number was visible in the console at the time the console was accessed,” said a company spokesperson. “There are no actions necessary for customers at this time.”

Okta’s own investigation found that the events of the incident unfolded as follows. On 7 August 2022, Twilio had disclosed that customer accounts and internal apps were accessed in attacks resulting from a successful phish. It notified Okta that unspecified data relevant to its customers was accessed during this incident on 8 August.

At that point, Okta rerouted SMS-based communications to an alternative provider so that it could have clear space to investigate alongside Twilio, which provided data such as internal systems logs that could be used to correlate and identify the extent of the activity relating to its users.

See also  The best documentaries on Netflix right now (August 2022)

This activity, as detailed above, affected 38 unique phone numbers, nearly all of which can be linked to a single unnamed organisation. Okta said it appeared that the threat actor was attempting to expand its access to that organisation. It had previously used usernames and passwords stolen in phishing campaigns to trigger SMS-based multifactor authentication challenges at its target and used its access to Twilio’s systems to weed out the one-time passcodes sent in these challenges.

Subsequently, Okta has been engaged in threat hunting across its platform logs and has found evidence that the threat actor also tested this technique against a single account unrelated to its main target, but performed no other actions. There is no evidence that it successfully used the technique to expand the scope of its access beyond the primary target.

Okta said 0ktapus/Scatter Swine has directly targeted Okta in the past, but has been unable to access accounts because of its in-house security.

The group uses infrastructure provided by the crypto-friendly Bitlaunch provider, providing servers from DigitalOcean, Vultr and Linode. Its preferred domain name registrars are Namecheap and Porkbun, both of which take bitcoin payments.

It initially harvests phone numbers from data aggregation services that link phone numbers to employees – Group-IB presented evidence that it may have hacked into some comms providers to get this data – and sends bulk phishing lures to multiple employees at its targets and even, in some cases, their family members. It has been known to follow up with phone calls pretending to be a tech support agent, and in these calls its operators apparently speak fluent North American-accented English.

See also  Finest washer and dryer offers for August 2022

If it successfully obtains user credentials from its phishing campaign, it then attempts to authenticate using an anonymised proxy. In this campaign, it favoured the Mullvad (Mole) VPN service, an open source, commercial service based out of Sweden.

Its phishing kit is designed to capture usernames, passwords and one-time passcode factors, and it has been known to trigger multiple push notifications in a further attempt to trick targets into allowing access to their accounts.

It has registered multiple domain names in common formats to further trick targets into entering their credentials on its phishing sites. In the case of Okta customers, these have generally taken the form of [target company]-okta.com, .net, .org or .us, although other domains have also been used.

More information on 0ktapus/Scatter Swine’s tactics, techniques and procedures is available from Okta, which is also advising its customers to adopt a defence-in-depth strategy to best protect themselves from this, or similar attacks.

Source link

0ktapusScatter Attack confirms house IAM Okta Swine
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Revolut Needs to Get Its House in Order

September 23, 2023

Sam Bankman-Fried’s House of Cards Is Falling Down

December 13, 2022

What is a Service Robot? The vision of an intelligent service application is possible.

November 7, 2022

Red Sift acquisition shows Attack Surface Management should include email too

October 13, 2022
Add A Comment

Comments are closed.

Editors Picks

Univ. of Washington spinout Somalytics, which is developing sensory tech, raises $1.9M – Startup

August 30, 2022

Nope evaluate: Jordan Peele’s good sci-fi horror delivers

July 23, 2022

Xbox Insiders adds classic Wolfenstein games

August 5, 2022

Production has started on Halo Season 2

September 18, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.