Cybercriminals have launched a phishing campaign targeting senior executives in U.S. firms, using the EvilProxy phishing toolkit for credential harvesting and account takeover attacks. This campaign, initiated in July 2023, primarily targets sectors such as banking, financial services, insurance, property management, real estate, and manufacturing. The attackers exploit an open redirection vulnerability on the job search platform "indeed.com," redirecting victims to malicious phishing pages impersonating Microsoft. EvilProxy functions as a reverse proxy, intercepting credentials, two-factor authentication codes, and session cookies to hijack accounts. The threat actors, known as Storm-0835 by Microsoft, have hundreds of customers who pay monthly fees for their services, making attribution difficult. The attacks involve sending phishing emails with deceptive links to Indeed, redirecting victims to EvilProxy pages for credential harvesting.
Executive Summary
Storm-0835, a cybercriminal group identified by Microsoft, operates using the EvilProxy phishing toolkit to target senior executives in U.S. firms across banking, financial services, and manufacturing sectors. Their campaign exploits vulnerabilities on job platforms like Indeed.com for credential harvesting and account takeovers, leveraging reverse proxy techniques to intercept login details and session cookies.
Goals & Targeting
Storm-0835's primary goal appears to be financial gain through credential harvesting and account takeovers. They specifically target senior executives due to their access to sensitive corporate data and high-value accounts in sectors with significant financial stakes. The group's focus on U.S.-based firms suggests a strategic approach to capitalize on the lucrative nature of these industries.
Enhanced Description
Storm-0835 is a cybercriminal group uncovered by Microsoft, utilizing the EvilProxy phishing toolkit in their attacks. They target high-ranking executives primarily in the United States across sectors such as banking, financial services, insurance, property management, real estate, and manufacturing. Their modus operandi involves sending phishing emails that direct victims to malicious pages via an open redirection vulnerability on Indeed.com. These pages mimic Microsoft's login interface, allowing the attackers to intercept credentials, two-factor authentication codes, and session cookies through EvilProxy, a reverse proxy tool designed for credential harvesting and account hijacking. The group is known to offer their services under a cybercriminal-as-a-service model, recruiting hundreds of customers who pay monthly fees. This business model complicates direct attribution as multiple actors may utilize the same tools。
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-0835 has been observed in an active campaign since July 2023, primarily targeting executives in the U.S. Their campaigns show a high level of organization, using phishing emails and malicious redirects to compromise credentials. The group's services being sold under a cybercriminal-as-a-service model indicates potential widespread adoption of their tools across multiple actors, making long-term tracking difficult. Notable past operations include credential harvesting from financial institutions and real estate companies via EvilProxy.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the analysis is medium to high. The data is sufficient for understanding their operational methods and tools, but gaps exist regarding their exact location, full scope of operations beyond 2023, and long-term strategic goals. Additional information on campaign history, specific TTPs, and associated infrastructure would enhance confidence.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics