New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Microsoft and Okta confirm, detail impact of Lapsus$ gang’s attacks

New York Tech Editorial Team by New York Tech Editorial Team
March 23, 2022
in Cybersecurity
0
Microsoft and Okta confirm, detail impact of Lapsus$ gang’s attacks
Share on FacebookShare on Twitter

Recent claims by the cyber extortion gang have been validated by Okta and Microsoft: Lapsus$ have managed to get their hands on some of Microsoft’s source code and have gained access to the laptop of a support engineer working for a third-party contractor for Okta, allowing them to potentially impact approximately 2.5% of the company’s customers.

Microsoft Okta Lapsus$

Okta

After the gang published screenshots from Okta’s internal systems and said that they focused their incursion on Okta customers, the company’s CEO first said that, in late January 2022, they detected an attempt to compromise the account of a customer support engineer working for one of their subprocessors, and that “there is no evidence of ongoing malicious activity beyond the activity detected in January.”

Later that day, David Bradbury, Okta’s Chief Security Officer, first shared that “there was a five-day window of time between January 16-21, 2022, where an attacker had access to a support engineer’s laptop,” that “the potential impact to Okta customers is limited to the access that support engineers have,” and finally, that “a small percentage of customers – approximately 2.5% – have potentially been impacted and whose data may have been viewed or acted upon.”

Okta’s main product is a popular identity platform that enables single sign-on to many cloud services. The company has, by their own count, over 15,000 customers, so the compromise might end up affecting nearly 400 of them. Okta did not name them and did not say what customer data may have been accessed.

The gang has disputed parts of Okta’s statements.

As the situation is still developing, new revelations are sure to come. In the meantime, Microsoft has shared extensive details about Lapsus$ group’s tactics, techniques and procedures.

Microsoft

Microsoft tracks Lapsus$ as DEV-0537 and confirmed that the gang does not use ransomware – for them it’s all about extortion and destruction.

“DEV-0537 started targeting organizations in the United Kingdom and South America but expanded to global targets, including organizations in government, technology, telecom, media, retail, and healthcare sectors,” the company said, and confirmed that it was one of its targets.

“Our investigation has found a single account had been compromised, granting limited access,” they shared. The attackers haven’t been able to access customer code or data but did have access to the company’s own source code – something that Microsoft doesn’t consider a big deal, as it “does not rely on the secrecy of code as a security measure.”

“Our team was already investigating the compromised account based on threat intelligence when the actor publicly disclosed their intrusion. This public disclosure escalated our action allowing our team to intervene and interrupt the actor mid-operation, limiting broader impact,” the company concluded.

More generally, though, the company’s security teams have been tracking the gang’s activities, and have now shared some of the tactics Lapsus$ uses (as well as recommendations on how security teams can counter them).

“Unlike most activity groups that stay under the radar, DEV-0537 doesn’t seem to cover its tracks. They go as far as announcing their attacks on social media or advertising their intent to buy credentials from employees of target organizations,” they noted.

“DEV-0537 also uses several tactics that are less frequently used by other threat actors tracked by Microsoft. Their tactics include phone-based social engineering; SIM-swapping to facilitate account takeover; accessing personal email accounts of employees at target organizations; paying employees, suppliers, or business partners of target organizations for access to credentials and multifactor authentication (MFA) approval; and intruding in the ongoing crisis-communication calls of their targets.”

After gaining initial access via social engineering, compromised credentials and/or session tokens, and recruited company insiders, they perform reconnissance via publicly available tool and collaboration platforms to discover high-privilege account credentials or exploit privilege escalation vulnerabilities in Confluence, Jira, and GitLab.

“In some cases, DEV-0537 even called the organization’s help desk and attempted to convince the support personnel to reset a privileged account’s credentials. The group used the previously gathered information (for example, profile pictures) and had a native-English-sounding caller speak with the help desk personnel to enhance their social engineering lure. Observed actions have included DEV-0537 answering common recovery prompts such as ‘first street you lived on’ or ‘mother’s maiden name’ to convince help desk personnel of authenticity,” Microsoft researchers explained.

“Since many organizations outsource their help desk support, this tactic attempts to exploit those supply chain relationships, especially where organizations give their help desk personnel the ability to elevate privileges.”

The group exfiltrates targets’ data and uses it for future extortion or public release; sometimes there is no extortion attempt and the data is simply leaked.


Credit: Source link

Previous Post

Asset servicing fund services news

Next Post

Startup with Chainlink to Provide Founders with Blueprint for Launching Blockchain Projects

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Startup with Chainlink to Provide Founders with Blueprint for Launching Blockchain Projects

Startup with Chainlink to Provide Founders with Blueprint for Launching Blockchain Projects

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Clubhouse will soon let you pin links to the top of rooms

Clubhouse will soon let you pin links to the top of rooms

October 23, 2021
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
three men posing outdoors

An AI Company on a Tiny Island Just Beat the Biggest Names on Wall Street. Here’s the Part That Should Surprise You.

June 2, 2026
man in a blue coat wearing glasses

Why Human Skills Matter More Than Ever in the AI Era

May 27, 2026
essential travel gadgets

May 24, 2026
graphic of Next-Gen Entrepreneurs event

Leadership, Judgment, and Innovation: A Post-Event Conversation with Dr. Fang Miao

May 21, 2026
Arito founding team

Arito AI Raises $6 Million To Bring Agentic Intelligence To Finance And Revenue Teams

May 20, 2026
Viewz founding team

Viewz Raises $7M to Retire the Finance Stack as We Know It

May 19, 2026

Recommended

three men posing outdoors

An AI Company on a Tiny Island Just Beat the Biggest Names on Wall Street. Here’s the Part That Should Surprise You.

June 2, 2026
man in a blue coat wearing glasses

Why Human Skills Matter More Than Ever in the AI Era

May 27, 2026
essential travel gadgets

May 24, 2026
graphic of Next-Gen Entrepreneurs event

Leadership, Judgment, and Innovation: A Post-Event Conversation with Dr. Fang Miao

May 21, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media