Compromised Account Used to Launch Internal Phishing Attack

August 9, 2020

Compromised accounts are commonly used by cybercriminals to send additional attacks because they appear to originate from a trustworthy source—typically a known partner or customer, or a known coworker within the organization. In this attack, the account was first compromised, and then attackers used it to launch internal phishing attacks to gain access to additional accounts.

Summary of Attack Target

  • Platform: Office 365
  • Email Security: Proofpoint
  • Victims: Internal Employees
  • Payload: Malicious Link
  • Technique: Compromised Internal Account

Overview of the Internal Phishing Atack

In this attack, the email itself is simple and masquerades as an encrypted message notification related to a OneDrive for Business file. It appears to come from an internal account and is sent to a known coworker, asking them to open the message.

Internal phishing attack email
The email sent in an internal phishing attack

If the recipient clicks on the link, it takes them to a PDF hosted on a Russian domain, which guides victims to click on another link to view and download the supposed file. After clicking the second link, the victims are taken to a phishing page.

Internal phishing attack PDF
The PDF link that leads to a phishing page

The phishing page asks the victim to enter their Microsoft credentials in order to access the document. Should victims fall for this attack, they risk further compromise within their company as the attacker gains access to more OneDrive and Microsoft Office accounts, from which they can steal valuable and sensitive information, hijack existing conversations, or create new attacks on other employees.

Why Compromised Accounts are Effective for Phishing

By utilizing a compromised internal account, the attacker is able to bypass any external email filtering set in place by the company, as most traditional infrastructure does not view internal-to-internal, or east-west traffic. In addition, it is easier to deceive recipients of this email, as the email appears to be coming from a coworker.

In addition, the link in the email is hidden in the text of the company’s name, and the link hosted on the Russian domain is concealed in the text that says “VIEW ONLINE / DOWNLOAD”. After clicking the links, victims are taken to a phishing page tailored specifically to their company.

Abnormal Security detecting internal phishing
Abnormal Security detecting an internal phishing attempt

Abnormal stopped this attack due to a variety of malicious signals. Most notably, the attacker sent the original email from an IP located in the United Kingdom, which is suspicious because this sender never sends from the UK, and the recipient rarely receives emails from there either. Combined with the BCC recipient pattern and the suspicious link, it's clear that this account has been compromised and is now being used to attack the organization.

To learn how Abnormal can detect account takeovers within your organization, request a demo today.

Image

Prevent the Attacks That Matter Most

Get the Latest Email Security Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.

Demo 2x 1

See the Abnormal Solution to the Email Security Problem

Protect your organization from the attacks that matter most with Abnormal Integrated Cloud Email Security.

Related Posts

B 05 11 22 Scaling Out Redis
As we’ve scaled our customer base, the size of our datasets has also grown. With our rapid expansion, we were on track to hit the data storage limit of our Redis server in two months, so we needed to figure out a way to scale beyond this—and fast!
Read More
B 05 17 22 Impersonation Attack
See how threat actors used a single mailbox compromise and spoofed domains to subtly impersonate individuals and businesses to coerce victims to pay fraudulent vendor invoices.
Read More
B 05 14 22 Best Workplace
We are over the moon to announce Abnormal has been named one of Inc. Magazine's Best Workplaces of 2022! Learn more about our commitment to our workforce.
Read More
B 05 13 22 Spring Product Release
This quarter, the team at Abnormal launched new features to improve lateral attack detection, role-based access control (RBAC), and explainable AI. Take a deep dive into all of the latest product enhancements.
Read More
B 05 11 22 Champion Finalist
Abnormal has been selected as a Security Customer Champion finalist in the Microsoft Security Excellence Awards! Here’s a look at why.
Read More
Blog series c cover
When we raised our Series B funding 18 months ago, I promised our customers greater value, more capabilities, and better customer support. We’ve delivered on each of those promises and as we receive an even larger investment, I’m excited about how we can continue to further deliver on each of them.
Read More
B 05 09 22 Partner Community
It’s an honor to be named one of CRN’s 2022 Women of the Channel. Here’s why I appreciate the award and what I love about being a Channel Account Manager at Abnormal.
Read More
B 05 05 22 Fast Facts
Watch this short video to learn current trends and key issues in cloud email security, including how to protect your organization against modern threats.
Read More
B 05 03 22
Like all threats in the cyber threat landscape, ransomware will continue to evolve over time. This post builds on our prior research and looks at the changes we observed in the ransomware threat landscape in the first quarter of 2022.
Read More
B 04 28 22 8 Key Differences
At Abnormal, we pride ourselves on our excellent machine learning engineering team. Here are some patterns we use to distinguish between effective and ineffective ML engineers.
Read More
B 04 26 22 Webinar Re Replacing Your SEG
Learn how Microsoft 365 and Abnormal work together to provide comprehensive defense-in-depth protection in part two of our webinar recap.
Read More
Blog mitigate threats cover
Learn about the most common socially-engineered attacks and why these tactics are still so successful—despite a growing awareness from employees.
Read More