It is a good time to implement Multi-Factor Authentication (MFA), if you have not already done so. Microsoft researchers recently discovered and disrupted a large-scale business email compromise (BEC) infrastructure hosted in multiple web services. The hackers used compromised mailboxes via phishing emails. They added forwarding rules to get access to emails about financial transactions.
Initial access via phishing
The attack starts with a phishing email, sent to the mailboxes, with the typical voice message lure and an HTML attachment.

Figure 1. Sample phishing email used to steal credential to be used for BEC attack
Once the end user opens the attachment, the embedded JavaScript produces an imitation Microsoft Sign-in page.

Figure 3. Forwarding rules created on compromised account.
Microsoft Alerts would have sent you an email warning of the compromised email account. It looks like this.
The user account has been restricted from sending outbound messages. Learn more.
Details:
https://www.microsoft.com/security/blog/2021/06/14/behind-the-scenes-of-business-email-compromise-using-cross-domain-threat-data-to-disrupt-a-large-bec-infrastructure/
Recommendations:
It’s very likely that the user account has been compromised. We recommend that you review the following information and take any actions as necessary. Learn more
– Review mailbox delegates
– Review mail forwarding rules to external domains
– Review global mail forwarding property on mailbox
– Enable mailbox auditing logs
– Review audit log details for the user account
– View/edit mailbox settings
– Ensure protection
To protect accounts from further compromise, we recommend you enable the following features on the account:
– Enforce complex passwords on the account
– Enable multi-factor authentication


When the end user entered their password, they are presented with “File not found”


Figure 2. Phishing page serving a fake error
In the background, the JavaScript transmitted the credentials to the attackers to an external cloud provider.
Email forwarding rules were also created. They look like this.
Keep in mind that multi-factor authentication (MFA) prevents attackers from signing into mailboxes. Attacks like this can be blocked by enabling MFA.
Contact us to get setup!








Bromium Endpoint Protection is built on the Bromium Microvisor, a Xen-based, security-focused hypervisor designed to automatically isolate each vulnerable user task, such as visiting a website, reading an email, opening a document, or accessing a USB drive. Today’s enterprises are supporting a number of legacy applications which in turn may be dependent on legacy browsers, java or active X components. Also, do not forget the “road warriors”, living on public networks outside of the prying eyes of internal security team. In these scenarios there is very little that can be done on the technology side and a lot of focus is being put on user training, however, the attackers are getting more innovative in targeting their audience leaving the user exposed. Being infected in the office is one thing, being infected on the road presents a very different scenario, just imagine going into a meeting with a new client, turning on your laptop and finding out that your system has been hijacked or will not even start, not the best first impression.
