UPDATED 20:04 EST / MAY 18 2023

SECURITY

Threat actor uses phishing and SIM-swapping to gain access to Azure Virtual Machines

A threat actor who has been known to target Microsoft Corp. products in the past has started using a combination of phishing and SIM-swapping attacks to take over Microsoft Azure administrative accounts to gain access to Azure Virtual Machines.

Detailed May 16 by researchers at Google LLC-owned Mandiant, the threat actor, designated UNC3944, uses the Serial Console on Azure VMs to install third-party remote management software within client environments. Hackers gaining access to Azure VMs is hardly new, but the researchers noted that the attack method is unique in that it avoided many of the traditional detection methods within Azure while giving the attacker full administrative access to the VM.

UNC3944 is a financially motivated threat group that Mandiant has been tracking since May 2022. Their tactics typically include email and SIM swapping, followed by the establishment of persistence using compromised accounts. Once through the door, UNC3944 steals data from within the victim organization’s environment.

Mandiant’s researchers have observed the attacker using access to a highly privileged Azure account to leverage Azure Extensions for reconnaissance purposes. The extensions used include built-in Azure diagnostic extensions, such as CollectGuestLogs, a tool that can “gather log files for offline analysis and preservation.” UNC3944 has also been observed to use the Azure Network Watcher extension, as well as Guest Agent Automatic Log Collection, VMSnapshot and Guest Configuration.

To maintain a presence on the VM, UNC3944 deploys commercially available remote administration tools via PowerShell. The researchers noted that the advantage of using commercially available tools is that as legitimately signed applications, they provide remote access without triggering alerts in most endpoint detection platforms.

The Mandiant researchers recommend that organizations restrict access to remote administration channels and disable SMS as a multifactor authentication method wherever possible.

“Sophisticated attacks into your network like this require a zero trust approach that employs defense in depth controls at the infrastructure and data layers,” Amit Shaked, chief executive of data security platform provider Laminar Tehnologies Inc., told SiliconANGLE. “The shift to the cloud has enabled organizations to quickly spin up data stores in buckets or blob storage and many data security and governance professionals don’t have visibility into where their sensitive data lives. This unknown or ‘shadow data,’ is… a prime target for cyber adversaries as they are not monitored and less protected.”

Image: Needpix

A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU