{"id":2653,"date":"2024-03-01T18:27:49","date_gmt":"2024-03-01T18:27:49","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/cryptochameleon-attackers-target-apple-okta-users-tech-support-gambit"},"modified":"2024-03-01T18:27:49","modified_gmt":"2024-03-01T18:27:49","slug":"cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/01\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit\/","title":{"rendered":"CryptoChameleon Attackers Target Apple, Okta Users With Tech Support Gambit"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt498fe946dd8235a2\/65e21afeff1537040aefdc8c\/chameleon-imageBROKER.com_GmbH_%26_Co._KG-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt498fe946dd8235a2\/65e21afeff1537040aefdc8c\/chameleon-imageBROKER.com_GmbH_%26_Co._KG-Alamy.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A phishing kit dubbed CryptoChameleon has been discovered targeting cryptocurrency platforms, including employees of Binance and Coinbase \u2014 as well as the Federal Communications Commission (FCC).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to an analysis from Lookout, the victims primarily use Apple iOS and Google Android devices with single sign-on (SSO) solutions, including Okta, Outlook, and Google.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Worryingly, successful attacks have yielded sensitive data beyond just usernames and passwords \u2014 for example, password reset URLs and photo IDs \u2014 making the attacks more damaging.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Cryptocurrency platforms, single sign-on services, government agencies, and other B2C-facing organizations should look at stronger forms of authentication, such as WebAuthn-based passkeys,&#8221; says Jason Soroko, senior vice president of product at Sectigo.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Sophisticated CryptoChameleon's Phishing Tactics Are Convincing\">Sophisticated CryptoChameleon&#8217;s Phishing Tactics Are Convincing<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.lookout.com\/threat-intelligence\/article\/cryptochameleon-fcc-phishing-kit\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">sophisticated cyberattackers behind CryptoChameleon<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> are notably exhibiting advanced tactics, such as personal outreach. The social engineering includes personalized text messages and voice calls impersonating legitimate support personnel from reputable companies.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And they&#8217;re also convincingly duplicating legitimate pages, making them harder to recognize, according to Lookout. Specifically, the use of phone numbers and websites that mimic real company support teams adds another layer of authenticity to the phishing attempts, further misleading the victims.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, the CryptoChameleon kit also utilizes hCaptcha to evade automated analysis tools.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In general, CryptoChameleon&#8217;s MO resembles techniques used by the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/-scattered-spider-mgm-cyberattack-casinos\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Scattered Spider financial cyberthreat group<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, in particular <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/application-security\/okta-flaw-involved-mgm-resorts-breach-attackers-claim\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">targeting Okta users<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> through voice calls by purporting to be help desk personnel \u2014 but Lookout noted the attacks are carried out with enough variance to suggest a different threat actor.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In fact, the researchers suspect the phishing kit might be offered as an as-a-service offering on Dark Web forums.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It is unknown whether this is a single threat actor, or a common tool being used by many different groups,&#8221; according to Lookout&#8217;s researchers. &#8220;However, there are many similarities in the backend C2 [command-and-control] servers and test data our team found across the various phishing sites.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Don't Be Duped by Fake Phone Calls From Tech Support\">Don&#8217;t Be Duped by Fake Phone Calls From Tech Support<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When it comes to social engineering from text messages and phone calls, organizations must educate their employees and set up a policy to verify the source of requests, Soroko says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We have seen deepfake audio phone calls that were very effective, which means that normal means of communication that were once fully trusted require a higher level of scrutiny,&#8221; he notes. &#8220;You need to verify who is texting and calling, and moving forward, we need better ways to make that easier.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Patrick Tiquet, vice president of security and architecture at Keeper Security, agrees that organizations should prioritize user education, emphasizing the risks associated with unsolicited messages and the importance of additional verification to ensure the URL of the destination website matches the authentic website.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;When a password manager is used, it automatically identifies when a site&#8217;s URL doesn&#8217;t match what&#8217;s contained in the user&#8217;s vault, which provides a critical extra layer of security,&#8221; he explains.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Tiquet says multifactor authentication (MFA) can also provide a critical second layer of protection that protects against phishing attacks \u2014 but he warns that cybercriminals are working to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cyberattackers-double-down-bypassing-mfa\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">evade MFA protections<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and are developing advanced tactics to gain access to high-value accounts and steal credentials.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/cryptochameleon-attackers-target-apple-okta-users-tech-support-gambit\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A phishing kit dubbed CryptoChameleon has been discovered targeting cryptocurrency<\/p>\n","protected":false},"author":12,"featured_media":2654,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2653","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?fit=2560%2C1707&ssl=1",2560,1707,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?fit=640%2C427&ssl=1",640,427,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?fit=1536%2C1024&ssl=1",1536,1024,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?fit=2048%2C1365&ssl=1",2048,1365,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?fit=1024%2C683&ssl=1",1024,683,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/cryptochameleon-attackers-target-apple-okta-users-with-tech-support-gambit-scaled.jpg?fit=2560%2C1707&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2653","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2653"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2653\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2654"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2653"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2653"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2653"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}