chat
expand_more

Compromised Account Used to Launch Internal Phishing Attack

Compromised accounts are commonly used by cybercriminals to send additional attacks because they appear to originate from a trustworthy source—typically a known partner or customer, or a known coworker within the organization. In this attack, the account was first...
August 9, 2020

Compromised accounts are commonly used by cybercriminals to send additional attacks because they appear to originate from a trustworthy source—typically a known partner or customer, or a known coworker within the organization. In this attack, the account was first compromised, and then attackers used it to launch internal phishing attacks to gain access to additional accounts.

Summary of Attack Target

  • Platform: Office 365
  • Email Security: Proofpoint
  • Victims: Internal Employees
  • Payload: Malicious Link
  • Technique: Compromised Internal Account

Overview of the Internal Phishing Atack

In this attack, the email itself is simple and masquerades as an encrypted message notification related to a OneDrive for Business file. It appears to come from an internal account and is sent to a known coworker, asking them to open the message.

Internal phishing attack email
The email sent in an internal phishing attack

If the recipient clicks on the link, it takes them to a PDF hosted on a Russian domain, which guides victims to click on another link to view and download the supposed file. After clicking the second link, the victims are taken to a phishing page.

Internal phishing attack PDF
The PDF link that leads to a phishing page

The phishing page asks the victim to enter their Microsoft credentials in order to access the document. Should victims fall for this attack, they risk further compromise within their company as the attacker gains access to more OneDrive and Microsoft Office accounts, from which they can steal valuable and sensitive information, hijack existing conversations, or create new attacks on other employees.

Why Compromised Accounts are Effective for Phishing

By utilizing a compromised internal account, the attacker is able to bypass any external email filtering set in place by the company, as most traditional infrastructure does not view internal-to-internal, or east-west traffic. In addition, it is easier to deceive recipients of this email, as the email appears to be coming from a coworker.

In addition, the link in the email is hidden in the text of the company’s name, and the link hosted on the Russian domain is concealed in the text that says “VIEW ONLINE / DOWNLOAD”. After clicking the links, victims are taken to a phishing page tailored specifically to their company.

Abnormal Security detecting internal phishing
Abnormal Security detecting an internal phishing attempt

Abnormal stopped this attack due to a variety of malicious signals. Most notably, the attacker sent the original email from an IP located in the United Kingdom, which is suspicious because this sender never sends from the UK, and the recipient rarely receives emails from there either. Combined with the BCC recipient pattern and the suspicious link, it's clear that this account has been compromised and is now being used to attack the organization.

To learn how Abnormal can detect account takeovers within your organization, request a demo today.

Compromised Account Used to Launch Internal Phishing Attack

See Abnormal in Action

Get a Demo

Get the Latest Email Security Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.

Get AI Protection for Your Human Interactions

Protect your organization from socially-engineered email attacks that target human behavior.
Request a Demo
Request a Demo

Related Posts

B MKT628 Cyber Savvy Social Images
Discover key insights from seasoned cybersecurity professional Nicholas Schopperth, CISO at Dayton Children’s Hospital.
Read More
B Podcast Blog
Discover 'SOC Unlocked,' Abnormal Security's new podcast featuring host Mick Leach and cybersecurity expert guests like Jeremy Ventura, Dave Kennedy, and Mick Douglas.
Read More
B 07 22 24 MKT624 Images for Paris Olympics Blog
Threat actors are targeting French businesses ahead of the Paris 2024 Olympics. Learn how they're capitalizing on the event and how to protect your organization.
Read More
B Cross Platform ATO
Cross-platform account takeover is an attack where one compromised account is used to access other accounts. Learn about four real-world examples: compromised email passwords, hijacked GitHub accounts, stolen AWS credentials, and leaked Slack logins.
Read More
B Why MFA Alone Will No Longer Suffice
Explore why account takeover attacks pose a major threat to enterprises and why multi-factor authentication (MFA) alone isn't enough to prevent them.
Read More
B NLP
Learn how Abnormal uses natural language processing or NLP to protect organizations from phishing, account takeovers, and more.
Read More