Summary
Key Points:
- A new cybercrime group named Pink is targeting corporate Microsoft 365 data through vishing scams, manipulating employees into revealing credentials.
- The group bypasses multi-factor authentication and uses compromised accounts to extort companies by demanding payment via internal communications, having accessed sensitive files from OneDrive and SharePoint.
- Recommended actions include employee training on verifying IT calls, monitoring logs for unusual scripts, blocking known malicious domains, and implementing behavioral monitoring for large file downloads.
Technical Details: Pink employs voice phishing (vishing) tactics to steal credentials without traditional malware. They utilize compromised sessions to access Microsoft 365 systems and employ fileless techniques to remain undetected.
MITRE ATT&CK Techniques:
- T1566.001 - Phishing: Vishing (Initial Access)
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1040 - Network Sniffing (Credential Access)
- T1036.004 - Masquerading: Match Legitimate Name or Location (Defense Evasion)
IOCs Mentioned:
- passkeyaddcom
- passkeydeploy.com
Join the discussion — sign up to comment, upvote, and save articles.