<?xml version="1.0" encoding="UTF-8" ?>

<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <atom:link rel="self" href="https://www.okta.com/ja-jp/blog/threat-intelligence.rss"/>
        <link>https://www.okta.com/ja-jp/blog/threat-intelligence</link>
        <title>Threat Intelligence | Blog | Okta</title>
        
        <pubDate>Wed, 24 Jun 2026 13:38:51 +0000</pubDate>
        
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/defending_against_team_pcp_software_supply_chain_attacks/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/defending_against_team_pcp_software_supply_chain_attacks/</link>
                <title>????????TeamPCP????????????????????</title>
                <description>
                    <![CDATA[&lt;p&gt;???????&lt;a href=&#34;https://www.okta.com/blog/threat-intelligence/defending_against_team_pcp_software_supply_chain_attacks/&#34;&gt;???&lt;/a&gt;???????2026?5?18??????????????????????&lt;/p&gt;
&lt;h2&gt;??&lt;/h2&gt;
&lt;p&gt;2025???????TeamPCP?????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????CI/CD????????GitHub?????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????????????????SSH???Git???????????????????CI/CD????????????????????????&amp;nbsp;&lt;/p&gt;
&lt;p&gt;??????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;GitHub Actions ? &lt;code style=&#34;font-weight: bold; font-style: italic;&#34;&gt;pull_request_target&lt;/code&gt; ????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;OSS???????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;????????????????????&lt;/h2&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;pull_request_target????????&lt;/h2&gt;
&lt;p&gt;&lt;a href=&#34;https://docs.github.com/en/actions/get-started/understand-github-actions&#34;&gt;GitHub Actions&lt;/a&gt;?????????&lt;a href=&#34;https://github.blog/news-insights/product-news/github-actions-improvements-for-fork-and-pull-request-workflows/&#34;&gt;&lt;code style=&#34;font-weight: bold; font-style: italic;&#34;&gt;pull_request_target&lt;/code&gt;????&lt;/a&gt;???????????????????????????????????????&lt;code style=&#34;font-weight: bold; font-style: italic;&#34;&gt;pull_request_target&lt;/code&gt;???????????Pwn Request????????GiHub?&lt;a href=&#34;https://securitylab.github.com/resources/github-actions-preventing-pwn-requests/&#34;&gt;2021?&lt;/a&gt;?&lt;a href=&#34;https://securitylab.github.com/resources/github-actions-new-patterns-and-mitigations/&#34;&gt;2025?&lt;/a&gt;???????????????????&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;code style=&#34;font-weight: bold; font-style: italic;&#34;&gt;pull_request_target&lt;/code&gt;??????????&lt;br&gt;
???????????????????????????????????????????????????????????????????&lt;br&gt;
&lt;code style=&#34;font-weight: bold; font-style: italic;&#34;&gt;pull_request_target&lt;/code&gt;?????????????????????????????????????GitHub?????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;?????????&lt;br&gt;
????????????????????????????????????????????????GitHub Actions??????????????????????????????????????????????????&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;TeamPCP????DeadCatx3?PCPcat??????&lt;/h2&gt;
&lt;p&gt;TeamPCP?2025?????????????????????????????GitHub??????????????????????????????????????????????????????????????????????????????????????????????API??????????????????????&lt;/p&gt;
&lt;h2&gt;OSS?????????????????&lt;/h2&gt;
&lt;p&gt;???????????????????????OSS??????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;2025?9? (npm):&amp;nbsp;&lt;/h3&gt;
&lt;p&gt;???npm??????????2FA????????????????????????????????????????????????&lt;a href=&#34;https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised&#34;&gt;18??????&lt;/a&gt;???????????????????????????&lt;/p&gt;
&lt;h3&gt;2025?7? (PyPi):&lt;/h3&gt;
&lt;p&gt;PyPi????????&lt;a href=&#34;https://blog.pypi.org/posts/2025-07-28-pypi-phishing-attack/&#34;&gt;????AitM??????????&lt;/a&gt;???4??????????????????API?????????? num2words ??????????????????????PyPi??????????????????????????????????????&lt;a href=&#34;https://blog.pypi.org/posts/2025-07-31-incident-report-phishing-attack/&#34;&gt;??&lt;/a&gt;?????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;p&gt;OSS????????????????????????????????????????????????????????????URL???????&lt;/p&gt;
&lt;h3&gt;???? (Cooldown period) ????:&lt;/h3&gt;
&lt;p&gt;????????????????????n-1?????????????????pnpm 11.0 ??????????????24????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;????????? (SBOMs) ???:&lt;/h3&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;??????? (SCA??????):&amp;nbsp;&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://docs.npmjs.com/cli/v8/commands/npm-audit&#34;&gt;npm audit&lt;/a&gt; ??...&lt;a href=&#34;https://github.com/marketplace/snyk&#34;&gt;Snyk&lt;/a&gt;?&lt;a href=&#34;https://github.com/marketplace/socket-security&#34;&gt;Socket.dev&lt;/a&gt;???&lt;a href=&#34;https://niccs.cisa.gov/training/catalog/cmdctrl/using-software-composition-analysis-sca-secure-open-source-components&#34;&gt;???????????????&lt;/a&gt;?SCA???????????????????????????????&lt;/p&gt;
&lt;h3&gt;GitHub Actions ?????:&amp;nbsp;&lt;/h3&gt;
&lt;p&gt;?????? &lt;code style=&#34;font-weight: bold; font-style: italic;&#34;&gt;pull_request_target&lt;/code&gt;????????????????????????????????????????????????????**????????????????????SHA???????????SHA pinning?**??????????&lt;/p&gt;
&lt;h3&gt;?????????????????:&lt;/h3&gt;
&lt;p&gt;?????????????????FIDO2/WebAuthn??????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;??URL&lt;/h2&gt;
&lt;p&gt;TeamPCP????????TTP??????????????Okta????????????????????Security Trust Center?????????&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/defending-against-teampcp-software-supply-chain-attacks&#34;&gt;https://security.okta.com/product/oktathreatintelligence/defending-against-teampcp-software-supply-chain-attacks&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;????????????????????? - ????????????????????????????CISA??&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-security-supply-chains&#34;&gt;https://www.cisa.gov/sites/default/files/publications/defending_against_software_supply_chain_attacks_508.pdf&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;???????????????????????? - ??????????? (NIST)&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-security-supply-chains&#34;&gt;https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-security-supply-chains&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;??????????????????????? - ???????????????????NCSC??&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.ncsc.gov.uk/collection/supply-chain-security&#34;&gt;https://www.ncsc.gov.uk/collection/supply-chain-security&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;?????????????????????????? - ????????????????????????????????OWASP??&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://cheatsheetseries.owasp.org/cheatsheets/Software_Supply_Chain_Security_Cheat_Sheet.h&#34;&gt;https://cheatsheetseries.owasp.org/cheatsheets/Software_Supply_Chain_Security_Cheat_Sheet.h&lt;/a&gt;&lt;/p&gt;
]]>
                </description>
                <pubDate>Sun, 17 May 2026 15:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,threat-insights,software-supply-chain,token-replay,social-engineering,credential-phishing</category>
                
                <dc:creator>Jeremy Kirk, George Wang, ????</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/disrupting-shieldguard--a-security-extension-primed-to-drain-cry/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/disrupting-shieldguard--a-security-extension-primed-to-drain-cry/</link>
                <title>???????????ShieldGuard?????????????????????????????????</title>
                <description>
                    <![CDATA[&lt;p&gt;Okta????????????????ShieldGuard??????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;ShieldGuard????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????ShieldGuard??Binance?Coinbase?MetaMask?OpenSea?Phantom?Uniswap?????????????????????Google????????????????????????????????????????????????????????????????????????Binance?Coinbase?OpenSea?Uniswap??????????????????HTML????????????????&lt;/p&gt;
&lt;h3&gt;????&lt;/h3&gt;
&lt;p&gt;ShieldGuard??Web3????????????????????????????????????????????????????????ShieldGuard???????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Google Chrome???????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;X.com????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Telegram?????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;ShieldGuard????????????SNS?????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;ShieldGuard??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;????????????? EIP-6963????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????????? ????????DeFi?????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????? ??????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;??????? ????UUID?????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;???????&lt;/h2&gt;
&lt;h4&gt;????&lt;/h4&gt;
&lt;p&gt;???????????????ShieldGuard??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h4&gt;????????????&lt;/h4&gt;
&lt;p&gt;ShieldGuard??Chrome?Manifest V3????????????????????????????????????????????????????????????????JavaScript???????vendor.js?????????????&lt;/p&gt;
&lt;p&gt;??????????RCE??????? ??????? eval() ??????????????????????????????????C2?????????????????????????????????????????JS????????????????????????????????????????????????????????????Chrome??????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;????????? ????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;????????????????&lt;/h4&gt;
&lt;p&gt;?????????????????????????&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????C2?????shieldguards[.]net/scripts?????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????EIP-6963????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????Binance?Coinbase?OpenSea?Uniswap??????????????????????????????????HTML???????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;HTML????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;?????????shieldguards[.]net ?C2????????2????????????????????????????&lt;/p&gt;
&lt;p&gt;?????1???????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????EIP-6963??????????????????????????????????????MetaMask?Phantom?Coinbase Wallet????????????????????????????????C2????????https://shieldguards[.]net/notifications????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;?????2????????????????????????????????&lt;/b&gt;&lt;br&gt;
????????????????2??????????????????????????????????5?????????????????????????HTML?document.documentElement.outerHTML?????????https://shieldguards[.]net/snapshots ?????????????????DOM???????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;C2?????????????????&lt;/h3&gt;
&lt;p&gt;??????????Cloudflare?????????? shieldguards[.]net ??C2???????????&lt;/p&gt;
&lt;p&gt;????????C2????????????????&lt;/p&gt;
&lt;table&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;???????&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;????&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;??&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/scripts&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;POST&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;???JavaScript????????&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/snapshots&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;POST&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;?????????HTML???&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/notifications&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;POST&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;?????????????????????&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/check/{domain}&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;GET&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;???????????????????????????&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/uninstall&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;GET&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;UUID???????????????????????????&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h3&gt;??????????????????&lt;/h3&gt;
&lt;p&gt;????JavaScript?????????????????????????&amp;quot;??????: ?? ??????? ?????????? ?????&amp;quot;???????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????Radex??????????????????????????????????????Auth0?????????????????????????radex4me@proton.me???Radex????????Chrome????ID?fkogigpebmhlbldifmjngmlooifljnif???????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;????&lt;/h3&gt;
&lt;p&gt;Okta???????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;CDN?????? shieldguards[.]net ?????????????????????????????????????????????????Partner Hosting LTD?????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Google Chrome?????ShieldGuard????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;?????????? shieldguards[.]net ??????????????????????C2?????????????????&lt;/p&gt;
&lt;h3&gt;??????????????&lt;/h3&gt;
&lt;p&gt;?????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;??????????? ??????Chrome????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????? ???????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????? ??????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????? ??????????????????????????????????????????????????????????????/???????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;??????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????MFA????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;Okta???????????&lt;/h3&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????Allowlist???????????&lt;/p&gt;
&lt;p&gt;???2??????????????&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;p&gt;????Chrome????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Okta??????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????Chrome????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????????????????Allowlist??????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Okta??????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????Okta Verify??????Okta????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????Okta??????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????????????????????????????Custom remediation messages?????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;br&gt;
???? (IoC)&lt;/h2&gt;
&lt;table&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;???&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;???????&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;??&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;AS??&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;AS215826&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;?????????????????????????????&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Chrome????ID&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;olnppmocapoaecjhkiilemmnkjbmabfj&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;ShieldGuard????????ID&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Chrome????ID&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;fkogigpebmhlbldifmjngmlooifljnif&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Radex?????ID&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2&gt;&amp;nbsp;&lt;/h2&gt;
]]>
                </description>
                <pubDate>Mon, 16 Mar 2026 07:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,ciam,threat-insights,fraudulent-registration,identity-theft</category>
                
                <dc:creator>Grayson Schermerhorn, Yang Wang, Simon Conant, Adam Smallhorn</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/</link>
                <title>??????????????????????????????????????</title>
                <description>
                    <![CDATA[&lt;p&gt;Okta??????????????????????????vishing?????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????Google?Microsoft?Okta???????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????MFA??????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????MFA??????????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????MFA????????????????&lt;/p&gt;
&lt;p&gt;Okta????????????????????????????????2?????????????????&lt;a href=&#34;https://security.okta.com/product/okta/vishing-operators-synchronize-phishing-sites-to-their-script-for-hybrid-social-engineering-attacks&#34;&gt;?????????&lt;/a&gt;??????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????????????&lt;/h2&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????OTP????????MFA???????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?1?????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????????????????IT??????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;IT?????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????????Telegram?????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????????MFA???????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????OTP?????????????????MFA???????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????????????????????????????????????????C2?????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?2?Okta??????????????????C2????Microsoft?????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????Okta FastPass?FIDO????????&lt;a href=&#34;https://help.okta.com/oie/ja-jp/content/topics/identity-engine/authenticators/phishing-resistant-auth.htm&#34;&gt;???????????????&lt;/a&gt;?????????????????????????????&lt;/p&gt;
&lt;h2&gt;?????????????&lt;/h2&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?Vishing?????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????Google?Microsoft Entra?Okta????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;p&gt;???????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta???????????????????Okta FastPass?????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????&lt;a href=&#34;https://help.okta.com/ja-jp/content/topics/security/network/network-zones.htm&#34;&gt;?????????&lt;/a&gt;?&lt;a href=&#34;https://auth0.com/docs/secure/tenant-access-control-list?_gl=1*127n2a3*_gcl_au*MTAwOTg2ODI5OC4xNzY4OTgyNzU5*_ga*MjcwMTYxOTUuMTc2ODk4Mjc1OQ..*_ga_QKMSDV5369*czE3NjkxNTU3OTMkbzEwJGcxJHQxNzY5MTU1OTI0JGo1OCRsMCRoMA..&amp;amp;adobe_mc=TS%3D1769155937%7CMCMID%3D81815360123345482620118513604094722876%7CMCORGID%3DADD71D3E633F65A90A495CE5%2540AdobeOrg&#34;&gt;??????????????&lt;/a&gt;?????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???&lt;a href=&#34;https://monzo.com/help/monzo-fraud-category/monzo-call-status-web&#34;&gt;??&lt;/a&gt;??????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
]]>
                </description>
                <pubDate>Wed, 21 Jan 2026 15:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,iam,social-engineering,threat-insights</category>
                
                
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/jobseekers-exploited-in-fake-recruiter-phishing-campaigns/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/jobseekers-exploited-in-fake-recruiter-phishing-campaigns/</link>
                <title>Jobseekers exploited in fake recruiter phishing campaigns</title>
                <description>
                    <![CDATA[&lt;h2&gt;???????????&lt;/h2&gt;
&lt;p&gt;Okta ????????????400?????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????O-UNC-038???????????&lt;/p&gt;
&lt;p&gt;????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Telegram???????????????????????Facebook????????????????Browser in the Browser??BitB???????????????&lt;/li&gt;
&lt;li&gt;Socket.IO?????Google Workspace?????????????????????????????????????&lt;/li&gt;
&lt;li&gt;???????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;?????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????MFA??????????????????????????Adversary-in-the-Middle?AitM???????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;????????????????????&lt;/h3&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????Salesforce ExactTarget ?????????????????????????&lt;/p&gt;
&lt;pre&gt;
cl.s12[.]exct[.]net/?qs=&amp;lt;UniqueIdentifierString&amp;gt;
&lt;/pre&gt;
&lt;p&gt;?????????????E?????????????????????????????E????????????????????????????????????E????????????????????????????????????????????????????????????????????????????????????E ??????????????&lt;/p&gt;
&lt;p&gt;Okta ???????????????? Salesforce ?????????? ????????? Salesforce ?????????????????????????????????&lt;/p&gt;
&lt;p&gt;????2???????????????????????????????&lt;br&gt;
&lt;br&gt;
&lt;/p&gt;
&lt;h2&gt;???? - ??????1&lt;/h2&gt;
&lt;h3&gt;Browser in the Browser?BitB?Facebook??????????????????1??&lt;/h3&gt;
&lt;p&gt;???????????????????? in the ???? (BitB)???????????????????????????????????????????????Facebook????????????&lt;/p&gt;
&lt;p&gt;BitB?Browser in the Browser?????????????????HTML?CSS?JavaScript?????????????????????????????????????????????????????????????????????????????????????Facebook??????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????Facebook/BitB????????????????143??????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????Vercel????????????????????????registrar.eu???????????Amazon Web Services????????????????????????????????????????????????Telegram????????????&lt;/p&gt;
&lt;h3&gt;????Meta?????&lt;/h3&gt;
&lt;p&gt;???????????????Meta???????3????????????????????????????????????Facebook?????????????????&lt;/p&gt;
&lt;h3&gt;????Puma??&lt;/h3&gt;
&lt;p&gt;???3???????????????????Puma??????????????&lt;/p&gt;
&lt;h2&gt;?????????????? - ??????1&lt;/h2&gt;
&lt;p&gt;BitB???????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;???? - ?????? 2&lt;/h2&gt;
&lt;p&gt;????????Campaign 1?????BitB????????????????????????????Google???????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????E ?????????????????&lt;/p&gt;
&lt;p&gt;????????????????84?????????????????Cloudflare????????????IP??????????Socket.IO???????????????????????&lt;/p&gt;
&lt;h3&gt;???????Playstation??????&lt;/h3&gt;
&lt;p&gt;????????? Google ?????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????1?????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;???????????????????????????&lt;/h2&gt;
&lt;p&gt;???2???????????????????????200?????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????Group ??????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Adecco&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Adidas&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Aquent&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Calendly&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Cisco&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;CocaCola&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Genpact&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Givenchy&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Google&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Hays&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Ikea&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Inditex&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Meta&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Randstand&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Robert Half&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Robert Walters&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Salesforce&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;youtube&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Zara&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;??????????????????????????www???????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;apply.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;hire.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;careers.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;calendly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;hr.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;jobs.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;join.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;kvn.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;recruit.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;schedule.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;start.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;threads.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;xds.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;???????????????????URL????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;??????????&lt;/h3&gt;
&lt;p&gt;???????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???Okta????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;???????????MFA?FastPass/webauthn/???????????????????????SMS/???????????????&lt;/li&gt;
&lt;li&gt;???????????????????????????????????????????????????????????????????????????????????????????????Web?????????????????????????????????????&lt;/li&gt;
&lt;li&gt;DMARC/DKIM/SPF???????????????/????????????????????????&lt;/li&gt;
&lt;li&gt;???????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;BitB ??????????????????????:&lt;ul&gt;
&lt;li&gt;???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;???????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;IoC??????Telegram???API?????t.me/, bot*getUpdates, sendMessage; BitB CSS/JS??????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;???????????????????????&lt;/li&gt;
&lt;li&gt;???????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;???????????SSO????????????&lt;/li&gt;
&lt;li&gt;?????????????????Browser-in-the-browser???????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;p&gt;Okta????????????????security.okta.com????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://security.okta.com/product/okta/jobseekers-exploited-in-fake-recruiter-phishing-campaigns&#34; target=&#34;_blank&#34;&gt;https://security.okta.com/product/okta/jobseekers-exploited-in-fake-recruiter-phishing-campaigns&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;??????????&lt;/h3&gt;
&lt;p&gt;Okta?????????????????????????????????????203??????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;???&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???&lt;/th&gt;
&lt;th&gt;???&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;???????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;?????&lt;/th&gt;
&lt;th&gt;?????????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
??(?)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;??&lt;/td&gt;
&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;???&lt;br&gt;
???????&lt;/td&gt;
&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;td&gt;??????&lt;/td&gt;
&lt;td&gt;&lt;br&gt;?????????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;1?5?&lt;/td&gt;
&lt;td&gt;5?20?&lt;/td&gt;
&lt;td&gt;20?45?&lt;/td&gt;
&lt;td&gt;45?55?&lt;/td&gt;
&lt;td&gt;55?80?&lt;/td&gt;
&lt;td&gt;80?95?&lt;/td&gt;
&lt;td&gt;95?99?&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Thu, 18 Dec 2025 16:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,ciam,iam,platform-abuse,social-engineering,credential-phishing,threat-insights</category>
                
                
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/phishing-campaigns-use-employee-benefits-lure-logins/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/phishing-campaigns-use-employee-benefits-lure-logins/</link>
                <title>Phishing campaigns use &amp;apos;Employee Benefits&amp;apos; lure to intercept Microsoft and Okta logins</title>
                <description>
                    <![CDATA[&lt;h2&gt;???????????&lt;/h2&gt;
&lt;p&gt;Okta????????????Microsoft?????????????????????????????????????????????????????????????????? Okta ????????????????IdP???????????&lt;/p&gt;
&lt;p&gt;???O-UNC-037????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????O-UNC-037???????????????????????????????????????&lt;/p&gt;
&lt;p&gt;O-UNC-037?????????????2025?10????????????????????????????????????????&lt;b&gt;???????????HR??????????????????????E&lt;/b&gt; ??????????Microsoft???????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????MFA????????????????????????????????Adversary-in-the-Middle?AitM????????????????SMS???????????????????????OTP?????????????MFA?????????????&lt;/p&gt;
&lt;p&gt;Okta???????????SSO??????????????????2????????????????????????????????????????2???????????????Okta ????????????Okta?????????????????????Cookie??????????????????????&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;p&gt;?????????????????????????????????????Microsoft???????????Okta SSO?????????????????????????????????????AitM????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;?????????????????TTP??&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;??????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;??????E ?????????????????????????????????????&lt;b&gt;?????????????&lt;/b&gt;???&lt;b&gt;??????????????&lt;/b&gt;??????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????????????????????E ?????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????????????????????????????&lt;b&gt;Cloudflare CAPTCHA&lt;/b&gt;??????????????&lt;br&gt;
&lt;br&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Adversary-in-the-Middle (AiTM)&lt;/b&gt;????????????????????????????MFA??????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????Microsoft???????????federation?????????Okta SSO?????????&lt;br&gt;
&lt;br&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;???????????????????????URL????????P&lt;b&gt;hishing-as-a-Service (PhaaS)&lt;/b&gt;?????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;E ????????&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;????????????????????? E ????????????????????????????????????E ??? ????????????? (LLM) ?????????????????????E ???????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????E ??????????&lt;/p&gt;
&lt;pre&gt;
????ADP BENEFITS &amp;lt;notifications[@]duobenefits[.]com&amp;gt;???[?????]??????????? - ??????????????
&lt;/pre&gt;
&lt;pre&gt;
????Secure Mail &amp;lt;noreply[@]mailsafe365[.]com&amp;gt;???[?????]???????????????????????
&lt;/pre&gt;
&lt;p&gt;????????????????????????????????E ??????????????????????????????????????&lt;/p&gt;
&lt;pre&gt;
???: ADP Benefits &amp;lt;notifications_adp_com[@]emails[.]t??????s[.]org&amp;gt;??: Confidential: [???? Name]????????????????
&lt;/pre&gt;
&lt;h3&gt;E ????????????????&lt;/h3&gt;
&lt;p&gt;?????????E ??????????????????????????????????????????????????????E ??????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;benefits-alerts[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsapp001[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;qrcodelnk[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;302lnk[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;goto365[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;fastlink247[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;link24x7[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;fast2url[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;url247[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;?????????????????????E ?????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;t??????s[.]msg???[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;?????? ???? 1 ????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Marketing.s??????y[.].com&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;?????E ???????????????????????????????Web??????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;???????????&lt;/h3&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????Cloudflare CAPTCHA???????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;?????????&lt;/h3&gt;
&lt;p&gt;CAPTCHA????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;???????&lt;/h3&gt;
&lt;p&gt;????????????????????????Microsoft?????????AitM?????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;Okta???????2??????????&lt;/h3&gt;
&lt;p&gt;????????????????????????????????Okta????????????????????????????????????????????????????Okta??????URL??????????????SSO[.]oktacloud[.]io????????????????????Okta?????????????????AitM?????SSO???????????????????????Cookie????????????????????????????????????????? &lt;/p&gt;
&lt;h3&gt;????????????&lt;/h3&gt;
&lt;p&gt;O-UNC-037????????????????????Microsoft???????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;benefitsemployeeaccess[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsquickaccess[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsworkspace[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitscentralportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsselfservice[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsmemberportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsgatewayportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitshubportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsadminportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsaccessportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsviewportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;?????? ??????????????????????????????????URL???????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;/benefits/????/&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;/compensation/auth/&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;rewards/verify/&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;employee/access/&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;???????????Microsoft??????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;sso[.]oktacloud[.]io&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;sso[.]okta-access[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Internal-networks[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Okta?????????????????????????????Cloudflare Workers????????????????????????Cloudflare Workers???????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;sso[.]okta-proxy[.]workers[.]dev&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;okta[.]undermine[.]workers[.]dev&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;oktapage[.]oktamain[.]workers[.]dev&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;okta[.]eventspecial[.]workers[.]dev&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;???????????????????&lt;/h3&gt;
&lt;p&gt;O-UNC-037????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????O-UNC-037?????????????&lt;/p&gt;
&lt;h3&gt;????????????&lt;/h3&gt;
&lt;p&gt;????????????????????????Microsoft 365???Okta???????????????????????AitM?????????????????????????????????URL???????????????Phishing-as-a-Service?PhaaS????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????URL?????????????????????Base64?????????JSON??????????ht???????????????????????????????????? &lt;/p&gt;
&lt;pre&gt;
https://benefitsemployeeaccess[.]com/rewards/verify/d582500e?s=3&amp;amp;ht=eyJpZCI6IjY2ZmI2OWMwNjA2N2RjOTM5Yzc5OTM1NWE0ODNjNzM3IiwidHlwZSI6ImhvcCIsImNhbXBhaWduX2lkIjoiY2FtcF82OGYyNjQ3YTlmYjE0IiwiaG9wX3RlbXBsYXRlIjoiYmVuZWZpdHMiLCJzdWNjZXNzX3RlbXBsYXRlIjoiYmVuZWZpdHNfZXJyb3IiLCJjcmVhdGVkIjoxNzYwOTM3NDcyLCJleHBpcmVzIjoxNzYwOTQ0NjcyLCJpcCI6IjExMy4yOS4yNDMuMSIsIm1heF91c2VzIjoxMDAwMDAwMCwidXNlcyI6MCwiaG9wX2NvdW50IjozLCJzZXNzaW9uIjoiZG9oNnBhbnE0Y3RhZTVsMjhvNWoyaTdoa3YifQ%3D%3D.bb0c9db57db67ff678edafb64f3cdc4fccfa93d4a8952e05ca2a3176e8134db5
&lt;/pre&gt;
&lt;pre style=&#34;text-align: left;&#34;&gt;


&lt;/pre&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????????????????campaign_id???????ip???????????????????ID?????????????????????????????????????????????created???expires??????????????uses???max_uses????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;pre&gt;
{
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;id&amp;quot;: &amp;quot;66fb69c06067dc939c799355a483c737&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
&amp;quot;type&amp;quot;: &amp;quot;hop&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
&amp;quot;campaign_id&amp;quot;: &amp;quot;camp_68f2647a9fb14&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;hop_template&amp;quot;: &amp;quot;benefits&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
&amp;quot;success_template&amp;quot;: &amp;quot;benefits_error&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;created&amp;quot;: 1760973582,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;expires&amp;quot;: 1760980782,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;ip&amp;quot;: &amp;quot;?????&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;max_uses&amp;quot;: 10000000,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;uses&amp;quot;: 0,
&lt;/pre&gt;
&lt;pre&gt;
&amp;quot;hop_count&amp;quot;: 3,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;?????&amp;quot;: &amp;quot;qa061c1uiht26gmtqcj49fsgci&amp;quot;
&lt;/pre&gt;
&lt;pre&gt;
}
&lt;/pre&gt;
&lt;p&gt;???Microsoft???????????????Okta????????????????????????????????????E ????????????????O365?????????????Okta???????FederationRedirectUrl???JSON????????&lt;/p&gt;
&lt;p&gt;?????????????????????JavaScript???????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;FederationRedirectUrl?AuthURL?RedirectUrl?????????JSON???????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;URL????Okta?????.okta.com??????????????????.oktapreview.com????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???Okta URL???????????????????????????????????????????????????URL?????????: sso[.]oktacloud[.].io?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????????????????????????????????Okta?????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????Cookie??????????????/api???????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????URL??????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;??AitM???????????????????????????????Okta???????????????????????SSO???????????????Cookie???????????&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;pre&gt;
var _wd = &amp;quot;https://sso.oktacloud.io&amp;quot;;
&lt;/pre&gt;
&lt;pre&gt;
var _iO = function (u) {
&lt;/pre&gt;
&lt;pre&gt;
            if (typeof u !== &amp;quot;string&amp;quot;) return false;
&lt;/pre&gt;
&lt;pre&gt;
if (u.includes(&amp;quot;sso.oktacloud.io&amp;quot;))return false;
&lt;/pre&gt;
&lt;pre&gt;
            if (u.includes(&amp;quot;/app/office365&amp;quot;)) return true;
&lt;/pre&gt;
&lt;pre&gt;
            if (u.match(/\.(okta|oktapreview|okta-emea)\.com/i)) return true;
&lt;/pre&gt;
&lt;pre&gt;
if (u.match(/\/sso\/saml|\/sso\/wsfed|\/???\/[^\/]+\/sso/i)) return true;
&lt;/pre&gt;
&lt;pre&gt;
return false;
&lt;/pre&gt;
&lt;pre&gt;
}; 
&lt;/pre&gt;
&lt;h3&gt;????????????????&lt;/h3&gt;
&lt;p&gt;????????????????????????????CloudFlare IP?AS13335????????????????????????????&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;??????????&lt;/h3&gt;
&lt;p&gt;???????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???Okta????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;?????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Okta FastPass?FIDO2 webauthn????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;Okta????????????????????????????????????????????????????????????????????????????????????????????????Endpoint Management???????&lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/managed-main.htm&#34; target=&#34;_blank&#34;&gt;??&lt;/a&gt;???&lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/edr-integration-main.htm&#34; target=&#34;_blank&#34;&gt;?????????????????????????&lt;/a&gt;????????Application ?????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/fp/fp-main.htm&#34; target=&#34;_blank&#34;&gt;????&lt;/a&gt;??????Okta FastPass??????&lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/device-assurance.htm&#34; target=&#34;_blank&#34;&gt;?????????????&lt;/a&gt;?????????&lt;/li&gt;
&lt;li&gt;?????????????????????????????????????????????????Okta Network Zones???????????????ASN???????????IP????IP????????????????????????????????&lt;/li&gt;
&lt;li&gt;Okta Behavior and Risk evaluations??????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;?????????E ??????????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/security_general.htm&#34;&gt;?????????&lt;/a&gt;?&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/suspicious-activity-reporting.htm&#34;&gt;?????????????&lt;/a&gt;?????????????????????????????????&lt;/li&gt;
&lt;li&gt;IT??????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;??????????????????????????????Zero Standing Privileges???????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/custom-admin-role/custom-admin-roles.htm&#34;&gt;?????????&lt;/a&gt;??????????????????JIT????????????????????????????&lt;/li&gt;
&lt;li&gt;?????????????????????????????????IP???????????????????&lt;/li&gt;
&lt;li&gt;??????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/admin-console-protected-actions.htm#:~:text=Protected%20actions%20are%20critical%20tasks,according%20to%20a%20configured%20interval.&#34;&gt;??????????&lt;/a&gt;????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;???????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;????????????Okta???Web?????E ?????????DNS?????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;??????????????????????????????????????????????????????????Web?????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;?????&lt;/h2&gt;
&lt;p&gt;Okta????????????????security.okta.com????????CSV?????????????????????????????????????:&lt;br&gt;
&lt;br&gt;
&lt;a href=&#34;https://security.okta.com/product/okta/phishing-campaigns-use-employee-benefits-lure-to-intercept-microsoft-and-okta-logins&#34; target=&#34;_blank&#34;&gt;https://security.okta.com/product/okta/phishing-campaigns-use-employee-benefits-lure-to-intercept-microsoft-and-okta-logins&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;??????????&lt;/h3&gt;
&lt;p&gt;Okta?????????????????????????????????????203??????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;???&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???&lt;/th&gt;
&lt;th&gt;???&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;???????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;??????&lt;/th&gt;
&lt;th&gt;?????????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
??(?)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;??&lt;/td&gt;
&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;???&lt;br&gt;
???????&lt;/td&gt;
&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;td&gt;??????&lt;/td&gt;
&lt;td&gt;&lt;br&gt;?????????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;1?5?&lt;/td&gt;
&lt;td&gt;5?20?&lt;/td&gt;
&lt;td&gt;20?45?&lt;/td&gt;
&lt;td&gt;45?55?&lt;/td&gt;
&lt;td&gt;55?80?&lt;/td&gt;
&lt;td&gt;80?95?&lt;/td&gt;
&lt;td&gt;95?99?&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Tue, 21 Oct 2025 07:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,social-engineering,credential-phishing,token-replay,iam</category>
                
                <dc:creator>Houssem Eddine Bordjiba</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/opportunistic-sms-pumping-attacks-target-customer-sign-up-pages/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/opportunistic-sms-pumping-attacks-target-customer-sign-up-pages/</link>
                <title>Wide-scale, opportunistic SMS pumping attacks target customer sign-up pages</title>
                <description>
                    <![CDATA[&lt;h2&gt;Executive Summary&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence has identified a cluster of shared disposable email infrastructure and commodity proxy services, internally designated as O-UNC-036, that is being used to launch high-volume, automated attempts against public API endpoints.&lt;/p&gt;
&lt;p&gt;This infrastructure has been observed in multiple persistent, large scale and&amp;nbsp;financially motivated SMS pumping campaigns starting at least as&amp;nbsp;early as July 2025.&lt;/p&gt;
&lt;p&gt;To execute this attack, threat actors undertake the following sequence of&amp;nbsp;actions:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Create a new account using a disposable email address, often tied to a&amp;nbsp;set of domains&lt;br&gt;
&lt;/li&gt;
&lt;li&gt;Add an actor-controlled phone number as an authentication factor&lt;br&gt;
&lt;/li&gt;
&lt;li&gt;Send as many messages to the number as possible in order to achieve&amp;nbsp;their monetary objectives&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;These attacks generate significant financial costs for the target&amp;nbsp;organizations by running up bills with their telephony providers.&amp;nbsp;We have been able to track historical activity from this cluster of disposable&amp;nbsp;email domains back to at least March 2024, indicating a sustained, adaptive&amp;nbsp;effort. Due to the high financial risk and potential for service degradation, we&amp;nbsp;strongly recommend the immediate implementation of the protective&amp;nbsp;controls, monitoring and aggressive response outlined in this report.&lt;/p&gt;
&lt;h2&gt;Threat&amp;nbsp;Analysis&lt;/h2&gt;
&lt;p&gt;The primary objective of this campaign is opportunistic, large-scale account&amp;nbsp;creation in order to carry out SMS pumping campaigns. In these attacks,&amp;nbsp;threat actors profit by collaborating with high-cost international or premium-rate SMS providers. By exploiting the SMS delivery system of the target&amp;nbsp;identity platform, the attacker triggers messages to phone numbers they&amp;nbsp;control in high-cost regions. The victim organization is then billed for the&amp;nbsp;exorbitant volume and cost of these international or premium SMS&amp;nbsp;messages, with the cost of attacks potentially costing hundreds of&amp;nbsp;thousands of dollars in telephony bills.&lt;/p&gt;
&lt;p&gt;The attack follows a high-volume pattern:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Reconnaissance and Enumeration: &lt;/b&gt;Attackers identify multi-factor authentication (MFA) or user registration endpoints that trigger an SMS code.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Infrastructure Setup: &lt;/b&gt;Actors use commodity proxy services (VPNs, anonymizing proxies, residential botnets etc.) to distribute the source IP addresses of the traffic, reducing the efficacy of rate-limiting based solely on IP.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;High-Volume Requests: &lt;/b&gt;Automated scripts submit requests using known, high-cost phone country codes and rapidly generated, disposable email addresses.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Cluster Activity: &lt;/b&gt;The O-UNC-036 infrastructure is a key enabler. This cluster utilizes a revolving pool of shared disposable email domains to bypass email-based rate limits and tenant-level velocity checks, allowing them to rapidly cycle through accounts for message requests. Okta Threat Intelligence has tracked activity in this cluster back to at least March 2024.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Target Scope: &lt;/b&gt;We observed this activity in multiple tenants and organizations of both Auth0 and OCI, indicating a widespread, indiscriminate search for vulnerable endpoints that trigger SMS delivery. The same shared infrastructure is likely also used to attack organizations building their own customer sign-in pages or using alternative services.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For technical details of how to identify these attacks in your logs, see the&amp;nbsp;Detection and Indicators sections of this report.&lt;/p&gt;
&lt;h2&gt;Detection&lt;/h2&gt;
&lt;p&gt;Our research has not uncovered any legitimate use of emails under domains&amp;nbsp;listed in the indicators section of this report. Thus the existence of users with such&amp;nbsp;emails is sufficient to detect attacks. Given the potential duration of this&amp;nbsp;attack, it is critical that administrators look back as far as possible in their&amp;nbsp;logs to determine the scope of past and future impact.&lt;/p&gt;
&lt;h3&gt;Okta Customer Identity&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;High numbers of messages being sent to countries outside of your&amp;nbsp;company&#39;s normal operating regions.&lt;/li&gt;
&lt;li&gt;A spike in the following event types:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;system.sms.send_okta_push_verify_message
&lt;/pre&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;or&lt;/p&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;system.sms.send_factor_verify_message where result=DENY
&lt;/pre&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;and&lt;/p&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;reason=Toll Fraud Suspected
&lt;/pre&gt;
&lt;ul&gt;
&lt;li&gt;A spike in the following event type:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;system.email.new_device_notification.sent_message
&lt;/pre&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;as malicious account&#39;s alternative proxy providers&amp;nbsp;or ASNs every login.&lt;/p&gt;
&lt;p&gt;See the &#34;Monitoring of your Okta org&#34; section of our support article &#34;&lt;a href=&#34;https://support.okta.com/help/s/article/How-to-mitigate-toll-fraud-when-using-Okta-for-voice-authentication?language=en_US&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;How to&amp;nbsp;Mitigate Toll Fraud when Using Okta for Voice Authentication&lt;/a&gt;&#34; for a&amp;nbsp;comprehensive overview of detection strategies.&lt;/p&gt;
&lt;h3&gt;Auth0&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;ss events from the domains listed in the Indicators of Compromise&amp;nbsp;section. Administrators should refer to &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/a735af3848d4e22e9157ea9982578d21bc399100/detections/risk_of_signup_fraud_by_disposable_domains.yml&#34;&gt;detection rules&lt;/a&gt; provided in the FOSS Auth0 Security Detection Catalog and modify them as needed.&lt;/li&gt;
&lt;li&gt;Spikes in Guardian events, especially gd_enrollment_complete and gd_send_sms events. We advise administrators to use the &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/a735af3848d4e22e9157ea9982578d21bc399100/detections/risk_of_signup_fraud_by_volume.yml&#34;&gt;risk_of_signup_fraud_by_volume.yml&lt;/a&gt; and &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/a735af3848d4e22e9157ea9982578d21bc399100/detections/sms_bombarding.yml&#34;&gt;sms_bombarding.yml&lt;/a&gt; detection rules in the &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/a735af3848d4e22e9157ea9982578d21bc399100/detections/risk_of_signup_fraud_by_disposable_domains.yml&#34;&gt;Auth0 Security Detection Catalog&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;A spike in &#34;&lt;a href=&#34;https://auth0.com/docs/secure/security-center#threat-behavior-trends&#34;&gt;MFA bypass&#34; events in Security Center&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;High numbers of messages being sent to countries outside of your company&#39;s normal operating regions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Protective&amp;nbsp;controls and&amp;nbsp;response&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence has observed these attackers abandon a target&amp;nbsp;when frustrated by the introduction of controls. This makes aggressive&amp;nbsp;response and implementation of proper controls effective in stopping these&amp;nbsp;attacks.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;While ever sending SMS messages costs money, attackers will find a&amp;nbsp;way to skim off the top. This risk can only be fully mitigated by migrating to another authentication factor. We strongly recommend the adoption of FIDO Authentication (passkeys).&lt;/li&gt;
&lt;li&gt;Our research has not uncovered legitimate use of the domains provided in the &lt;b&gt;Identicators&lt;/b&gt; section of this document. Deactivate users that provided these emails after making your own assessment.&lt;/li&gt;
&lt;li&gt;Accounts created from the ASNs in the &lt;b&gt;Indicators&lt;/b&gt; section of this document are seldom legitimate. Administrators are advised to deactivate these accounts unless friction is a major concern.&lt;/li&gt;
&lt;li&gt;Disable sending messages to untrusted countries in your telephony provider.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Okta Customer Identity&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Implement &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-webauthn.htm&#34;&gt;FIDO Authentication with WebAuthn&lt;/a&gt; and migrate users&#39; factors away from SMS.&lt;/li&gt;
&lt;li&gt;Use &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-webauthn.htm&#34;&gt;passkeys&lt;/a&gt; instead of SMS or voice factors.&lt;/li&gt;
&lt;li&gt;Enable &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/itp/bot-protection-config.htm&#34;&gt;bot protection for enforcement&lt;/a&gt;. We recommend setting a Bot Likeliness threshold of Low and above or Always on Sign-up and Sign-in flows when you are under attack.&lt;/li&gt;
&lt;li&gt;Block anonymizers and proxies at edge by leveraging &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/network/about-enhanced-dynamic-zones.htm&#34;&gt;enhanced dynamic network zones&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Utilizing workflows to manage self-service registration users from malicious domains. An Okta Identity Defense generated workflow exists that can be utilized or expanded upon and can be found &lt;a href=&#34;https://github.com/okta/customer-detections/tree/cf328c23953bc3aab8f9007a41f895ca1fb2585a/workflows/deactivate_ssr_users&#34;&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Utilize the Okta API to quickly &lt;a href=&#34;https://developer.okta.com/docs/api/openapi/okta-management/management/tag/UserLifecycle/#tag/UserLifecycle/operation/deactivateUser&#34;&gt;deactivate&lt;/a&gt; large batches of identified users.&lt;/li&gt;
&lt;li&gt;Leverage &lt;a href=&#34;https://www.okta.com/identity-verification/&#34;&gt;identity proofing integrations&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;See our support article &#34;&lt;a href=&#34;https://support.okta.com/help/s/article/How-to-mitigate-toll-fraud-when-using-Okta-for-voice-authentication?language=en_US&#34;&gt;How to Mitigate Toll Fraud when Using Okta for Voice Authentication&lt;/a&gt;&#34; for a comprehensive overview of responses and preventative controls.&lt;/li&gt;
&lt;li&gt;Block suspicious activity using the tooling provided by your telephony provider.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Contact Okta Support to provide a list of allowed telephony countries if&amp;nbsp;you&#39;re confident in the specific list of countries servicing your customers.&amp;nbsp;You can also request to modify the rate limits on your organization.&lt;/p&gt;
&lt;h3&gt;Auth0&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Implement &lt;a href=&#34;https://auth0.com/docs/secure/multi-factor-authentication/fido-authentication-with-webauthn&#34;&gt;FIDO Authentication with Webauthn&lt;/a&gt; and migrate users&#39;&amp;nbsp;factors away from SMS or voice factors.&lt;/li&gt;
&lt;li&gt;Use &lt;a href=&#34;https://auth0.com/docs/authenticate/database-connections/passkeys&#34;&gt;passkeys&lt;/a&gt; instead of SMS or voice factors.&lt;/li&gt;
&lt;li&gt;Block requests from the ASes and TLS client fingerprints in the Indicators of Compromise section at edge with &lt;a href=&#34;https://auth0.com/docs/secure/tenant-access-control-list&#34;&gt;Auth0&#39;s Tenant Access Control List&lt;/a&gt; feature.&lt;/li&gt;
&lt;li&gt;Since these attackers are especially sensitive to friction, enabling &lt;a href=&#34;https://auth0.com/docs/secure/attack-protection/bot-detection&#34;&gt;bot detection&lt;/a&gt; and enforcing CAPTCHA can be an effective control.&lt;/li&gt;
&lt;li&gt;Block users from registering using the email domains listed in the&lt;/li&gt;
&lt;li&gt;Indicators of Compromise section with &lt;a href=&#34;https://auth0.com/docs/customize/actions/explore-triggers/signup-and-login-triggers/login-trigger#access-control&#34;&gt;Signup and Login triggers&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Disable sending messages to untrusted countries in your telephony provider.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://auth0.com/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy#user-requests&#34;&gt;Lower your rate limits&lt;/a&gt; to lower the number of accounts attackers can create using the same IP address.&lt;/li&gt;
&lt;li&gt;Consider identity proofing integrations like those available in the &lt;a href=&#34;https://marketplace.auth0.com/categories/identity-proofing&#34;&gt;Auth0 marketplace&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;If you identify a large number of fraudulent users, engage Auth0 support for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;Grayson Schermerhorn and Mathew Woodyard contributed to this research.&lt;/i&gt;&lt;/p&gt;
&lt;h2&gt;Appendix A: Indicators&lt;/h2&gt;
&lt;p&gt;This is an ongoing investigation, and additional Indicators may be identified as the campaign evolves. Organizations&amp;nbsp;are advised to remain vigilant and implement the recommended mitigation strategies.&lt;/p&gt;
&lt;table cellpadding=&#34;10&#34; cellspacing=&#34;0&#34; border=&#34;0&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th style=&#34;text-align: left;&#34; colspan=&#34;2&#34;&gt;Domain&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;ul&gt;
&lt;li&gt;2mails1box.com&lt;/li&gt;
&lt;li&gt;300bucks.net&lt;/li&gt;
&lt;li&gt;blueink.top&lt;/li&gt;
&lt;li&gt;desumail.com&lt;/li&gt;
&lt;li&gt;e-boss.xyz&lt;/li&gt;
&lt;li&gt;e-mail.lol&lt;/li&gt;
&lt;li&gt;echat.rest&lt;/li&gt;
&lt;li&gt;electroletter.space&lt;/li&gt;
&lt;li&gt;emailclub.net&lt;/li&gt;
&lt;li&gt;energymail.org&lt;/li&gt;
&lt;li&gt;gogomail.ink&lt;/li&gt;
&lt;li&gt;gopostal.top&lt;/li&gt;
&lt;li&gt;guesswho.click&lt;/li&gt;
&lt;li&gt;homingpigeon.org&lt;/li&gt;
&lt;li&gt;kakdela.net&lt;/li&gt;
&lt;li&gt;letters.monster&lt;/li&gt;
&lt;li&gt;lostspaceship.net&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;td&gt;&lt;ul&gt;
&lt;li&gt;message.rest&lt;/li&gt;
&lt;li&gt;myhyperspace.org&lt;/li&gt;
&lt;li&gt;mypost.lol&lt;/li&gt;
&lt;li&gt;postalbro.com&lt;/li&gt;
&lt;li&gt;protonbox.pro&lt;/li&gt;
&lt;li&gt;rocketpost.org&lt;/li&gt;
&lt;li&gt;sendme.digital&lt;/li&gt;
&lt;li&gt;shroudedhills.com&lt;/li&gt;
&lt;li&gt;specialmail.online&lt;/li&gt;
&lt;li&gt;ultramail.pro&lt;/li&gt;
&lt;li&gt;whyusoserious.org&lt;/li&gt;
&lt;li&gt;wirelicker.com&lt;/li&gt;
&lt;li&gt;writeme.live&lt;/li&gt;
&lt;li&gt;writemeplz.net&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Autonomous Systems Number (ASN)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;ul&gt;
&lt;li&gt;212238&lt;/li&gt;
&lt;li&gt;16276&lt;/li&gt;
&lt;li&gt;44477&lt;/li&gt;
&lt;li&gt;26548&lt;/li&gt;
&lt;li&gt;200373&lt;/li&gt;
&lt;li&gt;137409&lt;/li&gt;
&lt;li&gt;214483&lt;/li&gt;
&lt;li&gt;13213&lt;/li&gt;
&lt;li&gt;397368&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;TLS Client JA4 Fingerprints are also available from an unredacted advisory that Okta customers can download at &lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/wide-scale-opportunistic-sms-pumping-attacks-target-customer-sign-up-pages&#34;&gt;security.okta.com&lt;/a&gt;.&lt;/p&gt;
]]>
                </description>
                <pubDate>Tue, 14 Oct 2025 07:00:00 +0000</pubDate>
                
                    <category>threat-insights,blog-post,threat-intelligence,ciam,fraudulent-registration</category>
                
                <dc:creator>Grayson Schermerhorn, Mathew Woodyard</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/the-s1ngularity-attack--when-attackers-prompt-your-ai-agents-to/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/the-s1ngularity-attack--when-attackers-prompt-your-ai-agents-to/</link>
                <title>The s1ngularity attack: When attackers prompt your AI agents to do their bidding</title>
                <description>
                    <![CDATA[&lt;p&gt;9?????s1ngularity?????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????npm??????????????????????????????????????????????????????????AI??????????????????????????????????1????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????AI?????????????????????????&lt;/p&gt;
&lt;p&gt;?????Safety Cybersecurity????????????Paul McCarty?????????????????????????????????????????????????????????????????AI???????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;?????????????&lt;/h2&gt;
&lt;p&gt;????????????&lt;a href=&#34;https://www.npmjs.com/package/nx&#34; target=&#34;_blank&#34;&gt;nx&lt;/a&gt;????????npm???????????????????????????????????????????????????????????telemetry.js??????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????????????????????????????????????????LLM????Claude?Gemini?AWS Q?????CLI???????????????????&lt;/p&gt;
&lt;p&gt;McCarty???????????????????????????????????????????????????????????????????????????????????????????????CLI?????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;??????????????&lt;/h2&gt;
&lt;p&gt;????? telemetry.js ??????????????????????????????? AI ??????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;??????:&lt;/b&gt; ???????????????? AI ?????? (CLI ???) ????????????????????????????????????????? (???????? Linux ??? macOS ????????????????)?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;?????:&lt;/b&gt; ?????????????????????????????????????????????????????????????????????AI ????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;??????????&lt;/b&gt;???????????????????????????.env????????????????????????????.config?????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;GitHub ??? npm ????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????AWS?????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;SSH?&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;AI ???????????LLM ?????????? ??????????????????????????????????????????????AI ??????????????????????????????????? ???????????????&lt;/p&gt;
&lt;h2&gt;AI??????????????????????????????????&lt;/h2&gt;
&lt;p&gt;McCarty??&lt;a href=&#34;https://www.getsafety.com/blog-posts/analyzing-nx-ai-prompt&#34; target=&#34;_blank&#34;&gt;??????????&lt;/a&gt;??????????????????????????????????????????????????????????4???????????AI????????????????&lt;/p&gt;
&lt;p&gt;??????????????AI???????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;????????????&lt;/b&gt; ????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;?????????&lt;/b&gt;???????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;??????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;????????????AI???????1??????????????????????????????????????????????????????????????????????????????????????????????AI??????????????????????????????McCarty??????????????AI????????????????????YOLO???????????????&lt;/p&gt;
&lt;p&gt;????????????????AI???????????????????????????developer???????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;???????&lt;/h2&gt;
&lt;p&gt;4 ??????? AI ?????????????Claude ? Gemini ????????????????????????????Paul McCarty ? Safety ?????????????????????????:&lt;a href=&#34;https://www.getsafety.com/blog-posts/analyzing-nx-ai-prompt&#34; target=&#34;_blank&#34;&gt; Analysing the AI used in the NX Attack&lt;/a&gt;?&lt;/p&gt;
]]>
                </description>
                <pubDate>Mon, 06 Oct 2025 16:00:00 +0000</pubDate>
                
                    <category>threat-intelligence,ai,malware</category>
                
                <dc:creator>Brett Winterford</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/north-korea-s-it-workers-expand-beyond-us-big-tech/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/north-korea-s-it-workers-expand-beyond-us-big-tech/</link>
                <title>North Korea&amp;apos;s IT Workers expand beyond US big tech</title>
                <description>
                    <![CDATA[&lt;p&gt;Okta ?????????????????????????DPRK??IT??????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????DPRK??????????????????????????????????????????????? focus ?????????????????????????????????????????????????????????IT????ITW???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????DPRK ITW?????????????????????????&lt;a href=&#34;https://en.wikipedia.org/wiki/International_Standard_Industrial_Classification&#34; target=&#34;_blank&#34;&gt;????????&lt;/a&gt;??????????????????????????????????????????4??1???27????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta ????????????DPRK?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????DPRK?????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;DPRK?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;??????130???????????????????&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence????????????????????????????DPRK ITW????????????????????????????????????130??????????????????????????????2025??????5,000??????????6,500????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????Okta ????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????DPRK IT????????????????????????????????????????DPRK???????????????????????????????Okta???????????????????????????????????????????????????????DPRK????????????????????Okta Threat Intelligence ??????? 130 ?????????????? DPRK ITW ???????????????????????????&lt;/p&gt;
&lt;h2&gt;??????&lt;/h2&gt;
&lt;p&gt;??5???????????????DPRK???????????????????????????&lt;a href=&#34;https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;????????????&lt;/a&gt;????????????DPRK?IT???????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????Application ????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;ITW??????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://www.ic3.gov/PSA/2025/PSA250123&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;???????????&lt;/a&gt;????????????&lt;/p&gt;
&lt;p&gt;?????????????????&lt;a href=&#34;https://www.justice.gov/archives/opa/pr/north-korean-government-hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;????????????&lt;/a&gt;??????????????????????????DPRK????????????????????????????????DPRK??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;DPRK?ITW??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????????????IT????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;DPRK????????????????????????????????????????&lt;/h2&gt;
&lt;p&gt;ITW???????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;DPRK?IT??????????????????????????????????????????DPRK???????????????????????????????????????????????????????????????????????????????????????????????????????????Application ???????????????????????????????????????DPRK?????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????4????ITW??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????DPRK??????????????/??????????????????????????????????????????&lt;br&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;????????????????????????????????????React????????Java?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;DPRK???????????&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;???????????IT????????&lt;/h3&gt;
&lt;p&gt;????IT????????????????????????IT??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta?????????????????????????????????????????????????????????HR??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????IT??????????????????????????????Okta ??????????????????????????????????????????????????? ???????????? ????????????? ????????&lt;/p&gt;
&lt;h3&gt;????&lt;/h3&gt;
&lt;p&gt;2023??????Okta??AI???????????????AI?????????????????????AI????????????????????DPRK????????????????????????????AI?????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????AI????????????????????????????????????????????????????????????????????????????????????????????????????????Okta??DPRK?IT????????????????????????????????AI???????????????????????????????????????AI?????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;????????????????&lt;/h3&gt;
&lt;p&gt;?????????????????????????????????DPRK????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????PII??????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????????????????????????????IT?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????HIPAA????????????????&lt;/p&gt;
&lt;p&gt;Okta????????????DPRK?????IT?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????PII??????????????????????????????&lt;/p&gt;
&lt;h3&gt;??????&lt;/h3&gt;
&lt;p&gt;DPRK?IT???????????????????????????????????????????????????????????????????????????FinTech???????????????????&lt;/p&gt;
&lt;p&gt;??????DPRK?????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????????????????????????????????????????????DPRK???????????????????????????????????????????????DPRK????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????????????????????????????????DeFi????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;???????&lt;/h3&gt;
&lt;p&gt;Okta??2023???2025?????DPRK?????IT??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????DPRK????????????????????????????????????????????Okta???????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;????????? IT ??????????&lt;/h3&gt;
&lt;p&gt;???????????????IT????????????Okta???????????????????????????DPRK?????IT????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????Okta?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????????????&lt;/h2&gt;
&lt;p&gt;Okta ???????????????????????????????????????73?????????????????????????????????????DPRK IT Worker???????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????ITW???????????27?/?????????????????????????????????????????????????????DPRK?????????????????????????????????2????????????????150?250????????????&lt;/p&gt;
&lt;h2&gt;????????????????&lt;/h2&gt;
&lt;p&gt;Okta??DPRK IT Worker???????????????????????????????????????????????????????????????????????????DPRK??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????ITW??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta ??????????????????DPRK???IT????????????????????????????????????????Application ?????????????????????????????????????????????????????????????????????10???????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????Okta ??DPRK IT Worker ???????????????????????????????????????????????2 ????? 3 ?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? 1 ???????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://sec.okta.com/articles/2025/04/GenAIDPRK/&#34; target=&#34;_self&#34; rel=&#34;noopener noreferrer&#34;&gt;AI???????&lt;/a&gt;??????&lt;/p&gt;
&lt;h2&gt;????????????&lt;/h2&gt;
&lt;p&gt;ITW??????????DPRK???????????????????????????????????&lt;a href=&#34;https://www.dtexsystems.com/exposing-dprk/&#34;&gt;???????????&lt;/a&gt;?????????????????????DPRK?ITW????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????ITW???????????????????????????????????????????????DPRK ITW????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????DPRK?????ITW?????????????????????????????????????????????????????????????????ITW????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????????????????&lt;/h2&gt;
&lt;p&gt;Okta????????DPRK?IT???????????????????????????????????????????????????????????????????????????????????????????????????????????????????IT??????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????DPRK???????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;???????????DPRK??????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????????????????????&lt;/h2&gt;
&lt;p&gt;Okta ?????????????????????????????????????????????????????????????????????????????????????????????????????????????????Okta??????????&lt;/p&gt;
&lt;h3&gt;1. ???????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????????ID??????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????IP?????VPN??????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;2. ??????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;HR?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????????????CV???PDF??????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????????? (?????????????????? ???????????????)?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????Web??????????E ??????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;3. ?????????????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????/ VPN?????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;4. ????????????????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;???????????ID??????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;5. ???????????????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;????????????????IT????????????????????????????????? Group ?????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;ITW???????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;6. ????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????ISAC/ISAO???????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????????Group ??????????E ????????IP?????VPN???????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????ITW????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;7. ?????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????DPRK?Application ??????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;p&gt;Okta?????DPRK IT Worker??????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????????DPRK???????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????ITW????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????&lt;/p&gt;
]]>
                </description>
                <pubDate>Tue, 30 Sep 2025 07:00:00 +0000</pubDate>
                
                    <category>threat-intelligence,threat-insights,fraudulent-registration,identity-theft,iam</category>
                
                <dc:creator>Simon Conant, Alex Tilley</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/evil-proxy-phishing-campaign/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/evil-proxy-phishing-campaign/</link>
                <title>EvilProxy phishing campaign leverages convincing impersonations of enterprise applications</title>
                <description>
                    <![CDATA[&lt;h2&gt;???????????&lt;/h2&gt;
&lt;p&gt;Okta?????????????2025?3?????????????????????????????????????????????????????EvilProxy phishing-as-a-service?PhaaS??????????????????????????????????????????????????????????????????????????????????O-UNC-035???????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????SAP Concur????????????????Adobe?DocuSign?????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;EvilProxy??????????????&lt;/h3&gt;
&lt;p&gt;EvilProxy?O-TA-041???????????/????AitM??????????????????????????????????????????????????????MFA????????????????????????PaaS?????????&lt;/p&gt;
&lt;p&gt;2022?????????????Web????????????????????EvilProxy???????????????????????????????????E ??????BEC???????????????????????????????MFA???????????????????Cookie????????????????????????EvilProxy???????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;?????????&lt;/h3&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;?????????Docusign?Adobe Acrobat?Adobe Sign?EchoSign????&lt;/b&gt;???????????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;??????????????? (SAP Concur?Coupa ??):&lt;/b&gt; ??????????????????????????????????????????????????????????????????????????????????????????????expense?expensereport???? expensesolutions ?????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Microsoft SharePoint:&lt;/b&gt; ???????????????????????????????????????????Microsoft 365?????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;????????????&lt;/b&gt;??????????????????????????????meeting?????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;KnowBe4:&lt;/b&gt; ???????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;?????&lt;/h3&gt;
&lt;p&gt;????????????????????URL ???????? E ?????????????????????????????????????????????????????????????????????????????????????? Microsoft ??????????????????????????????? JavaScript ?????? E ???????????????????????????????????????????????????????? URL ???????&lt;/p&gt;
&lt;h3&gt;HTTP??????1&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]expensereport[.]ch/[coded_string]
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;&lt;br&gt;
????????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://][company][.]sapconcur[.]sa[.]com/expense/?uid=[uid]&amp;amp;hid=[hid]&amp;amp;document=[document]&amp;amp;token=[token]&amp;amp;t=[t]
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;&lt;br&gt;
??URL??????????????????Web????????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://][32_characters_string][.]laurimarierefling[.]com/?uid=[uid]&amp;amp;hid=[hid]
&amp;amp;document=[document]&amp;amp;token=[token]&amp;amp;t=[token]&amp;amp;[string_7_characters]=[string_32_characters]
&lt;/pre&gt;
&lt;h3&gt;&lt;br&gt;
HTTP??????2&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]sapconcursolutions[.]pl/[coded_string]
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;&lt;br&gt;
????????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://][company][.]sapconcur[.]sa[.]com/expense/?uid=[uid]&amp;amp;hid=[hid]&amp;amp;document=[document]&amp;amp;token=[token]&amp;amp;t=[t]
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;&lt;br&gt;
??URL?????????????????????????????&lt;br&gt;
&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://][32_characters_string][.]concurmgt[.]pl//?uid=[uid]&amp;amp;hid=[hid]&amp;amp;document=[document]&amp;amp;token=[????]&amp;amp;t=[????]&amp;amp;[string_7_characters]=[string_32_characters]
&lt;/pre&gt;
&lt;h3&gt;&lt;br&gt;
??????????????????????????????????&lt;/h3&gt;
&lt;p&gt;??????????????????????????????@????????????????????????????????16???Base32????Base64????????????????????????????????????????????????????????????E ?????????&lt;/p&gt;
&lt;pre&gt;
let encodedValue = window.location.pathname.split(&#39;/&#39;).pop();...
E ??? = decodeEmail(encodedValue); // ???? tri-gram map
...
if (!decodingSuccessful &amp;amp;&amp;amp; isHexadecimal(encodedValue)) E ??? = hexToString(encodedValue);
if (!decodingSuccessful &amp;amp;&amp;amp; isBase32(encodedValue)) E ??? = base32ToString(encodedValue);
if (!decodingSuccessful &amp;amp;&amp;amp; isBase64(encodedValue)) E ??? = base64ToString(encodedValue);
&lt;/pre&gt;
&lt;pre&gt;
???????????????????????????3????????????????
&lt;/pre&gt;
&lt;pre&gt;
const encodingMap = {
    &amp;quot;@&amp;quot;:&amp;quot;MN3&amp;quot;,&amp;quot;.&amp;quot;:&amp;quot;OP4&amp;quot;,&amp;quot;a&amp;quot;:&amp;quot;QR5&amp;quot;,&amp;quot;e&amp;quot;:&amp;quot;ST6&amp;quot;,&amp;quot;i&amp;quot;:&amp;quot;UV7&amp;quot;,
    &amp;quot;o&amp;quot;:&amp;quot;WX8&amp;quot;,&amp;quot;u&amp;quot;:&amp;quot;YZ9&amp;quot;,&amp;quot;s&amp;quot;:&amp;quot;ABO&amp;quot;,&amp;quot;n&amp;quot;:&amp;quot;CD1&amp;quot;,&amp;quot;r&amp;quot;:&amp;quot;EF2&amp;quot;,
    &amp;quot;d&amp;quot;:&amp;quot;GH3&amp;quot;,&amp;quot;I&amp;quot;:&amp;quot;JK4&amp;quot;
};
&lt;/pre&gt;
&lt;h3&gt;&lt;br&gt;
?????????&lt;/h3&gt;
&lt;p&gt;?????????????????????????????????????????&lt;/p&gt;
&lt;pre&gt;
function isBot() {
    const botPatterns = [&#39;???&#39;,&#39;spider&#39;,&#39;crawl&#39;,&#39;slurp&#39;,&#39;baidu&#39;,&#39;yandex&#39;,
        &#39;wget&#39;,&#39;curl&#39;,&#39;lighthouse&#39;,&#39;pagespeed&#39;,&#39;prerender&#39;,&#39;screaming frog&#39;,
        &#39;semrush&#39;,&#39;ahrefs&#39;,&#39;duckduckgo&#39;];
if (navigator.webdriver || navigator.?????.length === 0 ||
    navigator.languages === &amp;quot;&amp;quot; || navigator.languages === undefined)
return true;
...
}
&lt;/pre&gt;
&lt;p&gt;?????????????????????????????????????????????????????????Microsoft???????????????????????????????????????????????????????????API.ipify.?????????????????IP????????IP?????????????????????????&lt;/p&gt;
&lt;h3&gt;?????????????????&lt;/h3&gt;
&lt;p&gt;????????2??????????????????????????E ???????????????????????????????????????????????Microsoft??????????????&lt;/p&gt;
&lt;pre&gt;
const blockedDomains = [&#39;belfius&#39;, &#39;baringa&#39;];
const E ???Domain = E ???.split(&#39;@&#39;)[1].toLowerCase();for (const blocked of blockedDomains) {
				if (emailDomain.startsWith(blocked)){
				window.location.href = &amp;quot;https://login.microsoftonline.com/common/login&amp;quot;;return;
				}
}
&lt;/pre&gt;
&lt;p&gt;???2?????????????????????belfius?????????????????????????baringa???????????????????????????????&lt;/p&gt;
&lt;h3&gt;????????&lt;/h3&gt;
&lt;p&gt;????????????????????????????????URL???????????????????????2?????????????????????E ???????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;uid ? &lt;b&gt;Base64(E ???)&lt;/b&gt;&lt;ul&gt;
&lt;li&gt;CyberChef?&lt;a href=&#34;https://gchq.github.io/CyberChef/#recipe=From_Base64(%27A-Za-z0-9%2B/%3D%27,true,false)&#34;&gt;???&lt;/a&gt;?????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;hid ? &lt;b&gt;hex(Base64(E ???))&lt;/b&gt;&lt;ul&gt;
&lt;li&gt;CyberChef?&lt;a href=&#34;https://gchq.github.io/CyberChef/#recipe=From_Hex(%27Auto%27)From_Base64(%27A-Za-z0-9%2B/%3D%27,true,false)&#34;&gt;???&lt;/a&gt;?????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;document, ???? ? ????ID???????????&lt;/li&gt;
&lt;li&gt;t ? &lt;b&gt;Unix ??????? (ms)&lt;/b&gt;&lt;ul&gt;
&lt;li&gt;CyberChef?&lt;a href=&#34;https://gchq.github.io/CyberChef/#recipe=From_UNIX_Timestamp(%27Seconds%20(s)%27)&amp;amp;oeol=FF&#34;&gt;???&lt;/a&gt;??????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;?????&lt;/h3&gt;
&lt;p&gt;???????????????????????????????URL???????????????????????????????????????????E ???????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]expensereport[.]ch/616c6578616e6465722e652e6261754073662e6672622e6f7267
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]sf[.]sapconcur[.]sa[.]com/expense/?uid=...&amp;amp;hid=...&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;??URL&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]299afcb76fac4238a0facad80c326230[.]concursolutions[.]asia/?uid=...&amp;amp;hid=...
&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...&amp;amp;u9pPUdqL=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]concursecure[.]pl/AB0ST6QR5CD1OP4kUV7CD1CD1MN3cST6CD1AB0YZ9AB0OP4gWX8v
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
{&amp;quot;en-US&amp;quot;:&amp;quot;hxxps[://]census[.]concursystem[.]cv/auth/?uid=...&amp;amp;hid=...&amp;amp;document=...\r\n&amp;amp;token=...&amp;amp;t=...&amp;quot;,&amp;quot;ja-JP&amp;quot;:&amp;quot;hxxps[://]census[.]concursystem[.]cv/auth/?uid=...&amp;amp;hid=...&amp;amp;document=...\r\n&amp;amp;token=...&amp;amp;t=...&amp;quot;}
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;??URL&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
{&amp;quot;en-US&amp;quot;:&amp;quot;hxxps[://]6b81e59848ba4a9d8cc3b4570b303a24[.]reports[.]sa[.]com/adfs/ls/?login_hint=&amp;quot;,&amp;quot;ja-JP&amp;quot;:&amp;quot;hxxps[://]6b81e59848ba4a9d8cc3b4570b303a24[.]reports[.]sa[.]com/adfs/ls/?login_hint=&amp;quot;}{&amp;quot;en-US&amp;quot;:&amp;quot;...&amp;amp;wa=wsignin1[.]0&amp;amp;wtrealm=...&amp;amp;wctx=...&amp;quot;,&amp;quot;ja-JP&amp;quot;:&amp;quot;...&amp;amp;wa=wsignin1[.]0&amp;amp;wtrealm=...&amp;amp;wctx=...&amp;quot;}
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]expensereport[.]ch/phUV7JK4UV7ppQR5mQR5CD1CD1UV7xMN3tfJK4OP4gWX8vOP4YZ9k
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]tfl[.]sapconcur[.]sa[.]com/expense/uid=...&amp;amp;hid=...&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;??URL&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]b4f1341373f341d98f11caea1052d878[.]laurimarierefling[.]com/?uid=...&amp;amp;hid=
...&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...&amp;amp;...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]concursolution[.]de/UV7JK4QR5CD1_CD1ST6tzST6EF2MN3mcQR5fST6ST6OP4cWX8m
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;???????&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]mcafee[.]concursystem[.]cv/auth/?uid=...&amp;amp;hid=...&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;??URL&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]3b2c66787c6349369fc9f90ecf789899[.]echosign[.]uk[.]com/app/office365/.../wsfed/passive?login_hint=...&amp;amp;wa=wsignin1[.]0&amp;amp;...
&lt;/pre&gt;
&lt;h3&gt;?????????&lt;/h3&gt;
&lt;p&gt;????????????????????? Microsoft ???????????????????????????????????????????????????????????????&lt;b&gt;E ???&lt;/b&gt;????????????????????&lt;b&gt;??&lt;/b&gt;?????????????????????????????????????????????????? (uid/hid/document/????/t) ?????????????&lt;b&gt;?????? URL ????&lt;/b&gt;???????????????????????????????????????????????? Office ???????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;??????????????&lt;/h3&gt;
&lt;p&gt;???????????????&lt;b&gt;???????&lt;/b&gt;?????????????????????????????????????????????????????????????????&lt;b&gt;??????MFA????&lt;/b&gt;????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;??????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;?????????&lt;/b&gt;??????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;???????IT?????&lt;/b&gt; ???????????????????IT??????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;??????????????????:&lt;/b&gt; ???????????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;?????????????:&lt;/b&gt; ??????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;?????????&lt;/b&gt;???????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;?????????&lt;/b&gt;????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;???????????:&lt;/b&gt; ???????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;??????&lt;/h3&gt;
&lt;p&gt;?????????????????????????????????????????????????????Artistic One Page?????Archery Master???????1??????????????????????????????????????????????urlscan.io??????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;page.title:(&amp;quot;ArtisticOne Page&amp;quot; OR &amp;quot;Archery Master&amp;quot;)&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????test?????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;????????????&lt;/h3&gt;
&lt;p&gt;???????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;?????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;???Okta???????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;?????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Okta FastPass?FIDO2 webauthn????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;Okta???????????????????????????????????????????????????????????????????????????????????????Endpoint Management???????????????????????????????????????????????????Application ?????????????????????????????????????????????????????????????????????????????Okta FastPass???????????&lt;/li&gt;
&lt;li&gt;?????????????????????????????????????????????????Okta Network Zones???????????????ASN???????????IP????IP????????????????????????????????&lt;/li&gt;
&lt;li&gt;Okta Behavior and Risk evaluations??????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????E ????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/security_general.htm&#34;&gt;?????????&lt;/a&gt;?&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/suspicious-activity-reporting.htm&#34;&gt;??????????????????&lt;/a&gt;?????????????????????????????????&lt;/li&gt;
&lt;li&gt;IT??????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;??????????????????????????????Zero Standing Privileges???????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/custom-admin-role/custom-admin-roles.htm&#34;&gt;??????????&lt;/a&gt;??????????????????JIT????????????????????????????&lt;/li&gt;
&lt;li&gt;?????????????????????????????????IP???????????????????&lt;/li&gt;
&lt;li&gt;???????????????????????????????????????&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/admin-console-protected-actions.htm#:~:text=Protected%20actions%20are%20critical%20tasks,according%20to%20a%20configured%20interval.&#34;&gt;Protected Actions&lt;/a&gt;????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;???????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;????????????Okta???Web?????E ?????????DNS?????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;??????????????????????????????????????????????????????????Web?????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;??A?????&lt;/h2&gt;
&lt;p&gt;????????????????????????????????IOC??????????????????????????????????????????????????????????IOC???&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;???&lt;/th&gt;
&lt;th&gt;??&lt;/th&gt;
&lt;th&gt;????&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;acrobatsign[.]es&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;adobeacrobat[.]sa[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;adobesign[.]ceelegal[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;adobesign[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;adobesign[.]us[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;asir[.]co[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;blue-styles[.]cz&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;ceelegal[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;codemonkey[.]cc&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;comcursolutions[.]de&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;comcursolutions[.]eu&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;comcursolutions[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;comcursolutions[.]us&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concur[.]cv&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concur[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concurexpense[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concurmgt[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursap[.]netlify[.]???&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursecure[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolution[.]de&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolution[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]asia&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]at&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]ceelegal[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]ch&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]com[.]tr&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]cv&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]cz&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]de[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]es&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]in&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]mex[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]my&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]nl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]pt&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursolutions[.]re&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursystem[.]cv&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;concursystem[.]netlify[.]???&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;coupahost[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;crsign[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;cruisesaudi[.]sa[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;dfwcom[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;dnglobal[.]ca&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;echosign[.]cv&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;echosign[.]de[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;echosign[.]eu02-safelink[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;echosign[.]nl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;echosign[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;echosign[.]ru[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;echosign[.]uk&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;echosign[.]za[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;esign[.]sa[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;{&amp;quot;en-US&amp;quot;:&amp;quot;eu02-safelink[.]com&amp;quot;,&amp;quot;ja-JP&amp;quot;:&amp;quot;eu02-safelink[.]com&amp;quot;}&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;eumai1-docusign[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;excelpediatric[.]us[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;expense[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;expense[.]sa[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;expensereport[.]ch&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;expensereports[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;expensereports[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;expensereports[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;getadobesign[.]eu02-safelink[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;getconcur[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;khs[.]co[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;knowbe4[.]es&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;meeting[.]sa[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;myapps[.]sa[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;na4-6l9[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;na4[.]it[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;saferedirect[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;sapconcur[.]cv&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;sapconcur[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;sapconcur[.]sa[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;sapconcursolutions[.]pl&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;scality[.]us[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;secure[.]za[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;sharepoint[.]za[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;supancasign[.]netlify[.]app&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;{&amp;quot;en-US&amp;quot;:&amp;quot;sutheha[.]za[.]com&amp;quot;,&amp;quot;ja-JP&amp;quot;:&amp;quot;sutheha[.]za[.]com&amp;quot;}&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;team[.]sa[.]com&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;ug4t5w[.]cfd&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;wepp[.]website&lt;/td&gt;
&lt;td&gt;????????????&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h3&gt;??????????&lt;/h3&gt;
&lt;p&gt;Okta Threat Intelligence??????????????????????????????203 - ?????????????????????????????????????????&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;???&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???&lt;/th&gt;
&lt;th&gt;???&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;???????&lt;/th&gt;
&lt;th&gt;????&lt;br&gt;
???????&lt;span style=&#34;font-weight: 400;&#34;&gt;&lt;/span&gt;&lt;/th&gt;
&lt;th&gt;??????&lt;/th&gt;
&lt;th&gt;?????????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
??(?)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;b&gt;??&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;???&lt;br&gt;
???????&lt;/td&gt;
&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;td&gt;??????&lt;/td&gt;
&lt;td&gt;&lt;br&gt;?????????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;b&gt;Percentage&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;1?5?&lt;/td&gt;
&lt;td&gt;5?20?&lt;/td&gt;
&lt;td&gt;20?45?&lt;/td&gt;
&lt;td&gt;45-55%&lt;/td&gt;
&lt;td&gt;55?80?&lt;/td&gt;
&lt;td&gt;80?95?&lt;/td&gt;
&lt;td&gt;95?99?&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Mon, 29 Sep 2025 07:00:00 +0000</pubDate>
                
                    <category>threat-intelligence,iam,blog-post,social-engineering,token-replay,credential-phishing,threat-insights</category>
                
                <dc:creator>Daniel López</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/help-desks-targeted-in-social-engineering-targeting-hr-applications/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/help-desks-targeted-in-social-engineering-targeting-hr-applications/</link>
                <title>Help desks targeted in social engineering campaign targeting HR applications</title>
                <description>
                    <![CDATA[&lt;h2&gt;???????????&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence??2025?8????&lt;b&gt;O-UNC-034&lt;/b&gt;???????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;O-UNC-034?????????????????????????????????????????????????????????????????????????????????????????????????Okta??????????????????????????????????????????????????????????????????????1?????????????????????????O-TA-54????AitM???????STORM-2657???????????&lt;/p&gt;
&lt;p&gt;O?UNC?034???????HR??????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????TTP????????????????????????????????????IOC????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;p&gt;???????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&lt;b&gt;??????&lt;/b&gt;?????????????IT???????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????MFA?????????????????????????&lt;b&gt;???&lt;/b&gt;????????????Okta Verify??????????SMS?????????????????????????????????MFA?????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Workday?Dayforce HCM?ADPsuite???&lt;b&gt;??????????&lt;/b&gt;???????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Customer Relationship Management?CRM????Salesforce?ServiceNow???IT ???????ITSM??????????????????????????????????????????IT?????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????????????????Office 365???Google Workspace????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;?????????????????????IP??????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;IPVANISH VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;CYBERGHOST VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;ZENMATE VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;EXPRESS VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;WINDSCRIBE VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;STRONG VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;ZENLAYER&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????IP????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Mac OS 14.5.0?Sonoma?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Mac OS 15.5.0 (Sequoia)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;macOS 13.1.0?Ventura?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Windows 11&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;iOS?iPhone?&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;???????????&lt;/h3&gt;
&lt;p&gt;?????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???Okta????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Okta FastPass?FIDO2 webauthn????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????IT?????????????????????????????????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/idvs-as-idps.htm&#34;&gt;ID??????&lt;/a&gt;?????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-temporary-access-code.htm&#34;&gt;?????????&lt;/a&gt;??????????????????????????????????????????????????????????????????????????????????????Group ??????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Okta?????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/managed-main.htm&#34;&gt;??&lt;/a&gt;???&lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/edr-integration-main.htm&#34;&gt;??????????????????????&lt;/a&gt;????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/device-assurance.htm&#34;&gt; ????? ?&lt;/a&gt;&lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/fp/fp-main.htm&#34;&gt; ????&lt;/a&gt; ?????Okta FastPass???????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????????????????????Okta Network Zones???????????????ASN???????????IP????IP????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Okta Behavior and Risk evaluations??????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????E ??????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/Security/Security_General.htm&#34;&gt;?????????&lt;/a&gt;?&lt;a href=&#34;https://help.okta.com/en-us/Content/Topics/Security/suspicious-activity-reporting.htm&#34;&gt;?????????????&lt;/a&gt;?????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????????Zero Standing Privileges????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/custom-admin-role/custom-admin-roles.htm&#34;&gt;??????????&lt;/a&gt;?????????????????? JIT (?????????) ?????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;?????????????????????????????????IP???????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;???????????????????????????????????????&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/admin-console-protected-actions.htm#:~:text=Protected%20actions%20are%20critical%20tasks,according%20to%20a%20configured%20interval.&#34;&gt;Protected Actions&lt;/a&gt;????????&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;p&gt;Okta????????????????security.okta.com????????????????????????????????????????&lt;br&gt;
&lt;br&gt;
&lt;a href=&#34;https://security.okta.com/product/okta/help-desks-targeted-in-social-engineering-campaign-targeting-hr-applications&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;https://security.okta.com/product/okta/help-desks-targeted-in-social-engineering-campaign-targeting-hr-applications&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;??????????&lt;/h3&gt;
&lt;p&gt;Okta?????????????????????????????????????203??????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;???&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???&lt;/th&gt;
&lt;th&gt;???&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;???????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;??????&lt;/th&gt;
&lt;th&gt;?????????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
??(?)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;??&lt;/td&gt;
&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;???&lt;br&gt;
???????&lt;/td&gt;
&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;td&gt;??????&lt;/td&gt;
&lt;td&gt;&lt;br&gt;?????????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Percentage&lt;/td&gt;
&lt;td&gt;1?5?&lt;/td&gt;
&lt;td&gt;5?20%&lt;/td&gt;
&lt;td&gt;20?45?&lt;/td&gt;
&lt;td&gt;45-55%&lt;/td&gt;
&lt;td&gt;55?80?&lt;/td&gt;
&lt;td&gt;80?95?&lt;/td&gt;
&lt;td&gt;95?99?&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Mon, 29 Sep 2025 07:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,iam,social-engineering,threat-insights</category>
                
                
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/uncloaking-void-proxy/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/uncloaking-void-proxy/</link>
                <title>Uncloaking VoidProxy: a novel and evasive Phishing-as-a-Service framework</title>
                <description>
                    <![CDATA[&lt;h2&gt;??&lt;/h2&gt;
&lt;p&gt;Okta ????????????Microsoft 365???Google Workspace???????????????????????????????????-as-a-Service?PhaaS????????????????????&lt;b&gt;VoidProxy&lt;/b&gt;???&lt;b&gt;O-TA-083&lt;/b&gt;???????????&lt;/p&gt;
&lt;p&gt;VoidProxy PhaaS?????????????????2025?1??????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;VoidProxy??Adversary-in-the-Middle?AitM?????????????????????????????????????MFA?????????????????Cookie?????????MFA?????????&lt;/p&gt;
&lt;p&gt;????????SMS???????????????????????OTP????????MFA?????????????????Okta?????????????????????????????????Okta FastPass???????Okta FastPass?????????????????VoidProxy???????????????????????????&lt;/p&gt;
&lt;p&gt;VoidProxy
									??????????
									????????????????????E ????? (BEC)?????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;PhaaS??????VoidProxy?????????AitM?????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;VoidProxy - ??????&lt;/h3&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;?????: VoidProxy
									???????&lt;/h3&gt;
&lt;p&gt;VoidProxy???????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;????1???&lt;/h3&gt;
&lt;p&gt;VoidProxy????????????Microsoft 365?Google Workspace?????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????E??????????????ESP????????Constant Contact?Active Campaign?Postmarkapp??NotifyVisitors?????????????????????????????????????????????????????????????????IP?????????E?????E?????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????E ???????????????????????
TinyURL
									???????
URL
									???????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????Okta??????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;VoidProxy????????????????????Zoom Docs????????????????????DocuSign??????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;????2?Cloudflare Workers????????????????&lt;/h3&gt;
&lt;p&gt;????????????????????????????????????????????????????????????Cloudflare CAPTCHA??????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;???????????Cloudflare Worker?*.workers.dev??????????Worker??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Microsoft 365&lt;/b&gt;?????????????????&amp;lt;phishing_domain&amp;gt;.&amp;lt;tld&amp;gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Google Workspace&lt;/b&gt;????????????&amp;lt;phishing_domain&amp;gt;.&amp;lt;tld&amp;gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;???????????????????????????????????????????????????????&amp;quot;Welcome!&amp;quot;
									????????????????????????&lt;/p&gt;
&lt;h3&gt;???? 3?SSO??????????????????????&lt;/h3&gt;
&lt;p&gt;???????VoidProxy???????????????Okta????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????Microsoft???Google????????????????????????AiTM?????????sslip.io/nip.io???????????????????????????&lt;/p&gt;
&lt;p&gt;???????????Okta?????????????????????????????Okta?????????????2??????????????????????????????&lt;/p&gt;
&lt;p&gt;??2??????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Okta&lt;/b&gt;?&lt;b&gt;Microsoft&lt;/b&gt;?????: newnewdom&amp;lt;random&amp;gt;.&amp;lt;phishing_domain&amp;gt;?&amp;lt;tld&amp;gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Okta&lt;/b&gt;?&lt;b&gt;Google&lt;/b&gt;??????securedauthxx&amp;lt;random&amp;gt;.&amp;lt;phishing_domain&amp;gt;?&amp;lt;tld&amp;gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;pre&gt;
securedauthxxccbgchgfj.xhfwez[.]icu
&lt;/pre&gt;
&lt;pre&gt;
securedauthxxdcigbjdddj.losozr[.]icu
&lt;/pre&gt;
&lt;pre&gt;
securedauthxxeafihgjdhb.dcohcv[.]icu
&lt;/pre&gt;
&lt;hr&gt;

&lt;pre&gt;
newnewdomnewcgbdhghjhi.prophfrot[.]top
&lt;/pre&gt;
&lt;pre&gt;
newnewdomnewebjjfjegfd.eeocl[.]com
&lt;/pre&gt;
&lt;pre&gt;
newnewdomnewdihbddahf.access-point[.]icu
&lt;/pre&gt;
&lt;hr&gt;

&lt;p&gt;?9. SSO???????????????????????????????&lt;/p&gt;
&lt;h3&gt;???? 4?AitM???????????????&lt;/h3&gt;
&lt;p&gt;????????????????sslip.io???nip.io???????????????????????????????Adversary-in-the-Middle?AitM??????????&lt;/p&gt;
&lt;p&gt;??????????????????MFA?????????Microsoft?Google?Okta??????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;VoidProxy???????????&lt;/h2&gt;
&lt;p&gt;VoidProxy???????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;VoidProxy????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&lt;b&gt;????????????????&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;VoidProxy???????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;???????????&lt;/b&gt; ?????????????.icu????????????TLD?????????????????????.sbs?.cfd?xyztop????.home?????????????????????????????????????????????????????????????????????????????????????Cloudflare??????????????????????????????IP???????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;???????????????&lt;/b&gt;???VoidProxy URL???????????????????????securedauthxx?newnewdom?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Cloudflare Workers??????????????????&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;???????PhaaS????????????????????????????Cloudflare Workers (*.workers.dev)?????????????????????????????????Cloudflare CAPTCHA?????????????????????????&lt;/p&gt;
&lt;p&gt;VoidProxy PhaaS??????????????????Cloudflare Worker??????????????????????????????????????????????????????????Cloudflare Worker???????????????????????????????????????????aidenveliz?kelvingomez?sammybruce?????????????????????????&lt;/p&gt;
&lt;pre&gt;
&amp;lt;alphanumeric&amp;gt;&amp;lt;firstnamelastname&amp;gt;..workers.dev.
&lt;/pre&gt;
&lt;p&gt;????????PhaaS???????????????????????????????????????????????????????????????????????????Cloudflare??????????????????????????????????????????VoidProxy???????????????????API?????????????????????????????????????????????????????&amp;lt;firstnamelastname&amp;gt;??????????????????????????????????????????????????????&amp;lt;alphanumeric&amp;gt;????????????????????????????????????????????????????????????????????????????????????????????????VoidProxy?????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;???????
C2
									??????????&lt;/h3&gt;
&lt;p&gt;AiTM
									????????????????????????
VoidProxy
									???????????
DNS
									???????????
sslip.io
									???
nip.io
									???????????????????????????????????????
IP
									????????????????
IP
									???????????????????
IP
									????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;b&gt;AitM?????????&lt;/b&gt;??????????????????????????????Cookie?????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;??????????&lt;/b&gt;????URL??PhaaS???????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;?voidproxy???????????????C2???????????????????????????????????????URL????????????????????????*.sslip.io????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;???????????????????????????&lt;/h3&gt;
&lt;p&gt;Okta Threat Intelligence??VoidProxy?????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????MFA???OTP??????????????????????????????????????????????VoidProxy?AitM??????????????????????????????????????????????MFA??????????????&lt;/p&gt;
&lt;p&gt;?????Okta FastPass????????????????????????????????FastPass??????????????????????????AitM?????????????????????????????????&lt;/p&gt;
&lt;p&gt;????VoidProxy???????PaaS?????????????????????????????????????MFA??????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????
ASN
									???????????
IP
									????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AS36352 - HostPapa&lt;/li&gt;
&lt;li&gt;AS149440 - Evoxt ????????&lt;/li&gt;
&lt;li&gt;AS210558 - 1337 Services GmbH&lt;/li&gt;
&lt;li&gt;AS401120 - cheapy.host LLC&lt;/li&gt;
&lt;li&gt;AS23470 - ReliableSite.Net LLC&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;VoidProxy??????&lt;/h3&gt;
&lt;p&gt;????????????????PaaS???????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????Web????????????????PaaS??????????????????????????&lt;br&gt;&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;??????????&lt;/b&gt;?/dashboard?&lt;/h3&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;?????????&lt;/li&gt;
&lt;li&gt;???????????&lt;/li&gt;
&lt;li&gt;????????&lt;/li&gt;
&lt;li&gt;??????????????????&lt;/li&gt;
&lt;li&gt;??????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;?????????&lt;/b&gt; (/dashboard/campaigns)&lt;/h3&gt;
&lt;p&gt;?????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;???&lt;/b&gt;?????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;???&lt;/b&gt;????????????????????????????Microsoft 365?Google???????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;????:&lt;/b&gt; ????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;??????&lt;/b&gt;????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;????????????&lt;/b&gt;?/dashboard/campaigns/[campaign_id]?&lt;/h3&gt;
&lt;p&gt;????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;??????&lt;/b&gt;?????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;???????????:&lt;/b&gt; ????????????????????????IP????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;??????&lt;/b&gt;????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;??????/???????/settings?&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;????????&lt;/b&gt;??????????????API??????????????????&lt;/li&gt;
&lt;li&gt;&lt;b&gt;???&lt;/b&gt;???????????????????????????????????????????Telegram ??? ??????????????????? URL?????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;b&gt;VoidProxy???????????????????&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;???????????Okta?????????????????PaaS???????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????&lt;b&gt;BIGFATCHAT&lt;/b&gt;???????????????????????????????2024?8????Telegram????????????????????????&lt;b&gt;VOID&lt;/b&gt;????????????????2FA??????????????????????&lt;/p&gt;
&lt;p&gt;?????????? $ 250 ??AOL?Yahoo?iCloud?Live?Google???? Office 365?ADFS?GODADDY?OKTA???? 2 ?????2FA???????????????????????????????AWS ??????????????????voidproxy?????????????????????????????????????????????????????????????????????????????????????????MITMSERVER??Man-in-the-Middle Server?????????Google?Office 365????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????Telegram????????????????AitM????????????????????????????????????????????????????????????????????????PhaaS??????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????
2022
									????????????????????????????????????
Telegram
									????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&lt;b&gt;VOID&lt;/b&gt;???GODLESS666????????????BEC?????????????????SMS???????????????????????????????????????&lt;/p&gt;
&lt;p&gt;2023??&lt;b&gt;VOID&lt;/b&gt;??????????????????????????????Okta?Duo Security??????????????Okta ???????????????&lt;b&gt;VOID&lt;/b&gt;???????????????????????????????????Breached???????????????godlessvoid666????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????VoidProxy PhaaS???????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;&lt;b&gt;???????????&lt;br&gt;
&lt;/b&gt;&lt;span style=&#34;font-weight: normal; font-size: 14.0px;&#34;&gt;????????????????????????????????????&lt;/span&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;?????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;?????????????????????????? Okta AI ????? Okta Identity Threat Protection ???????&lt;/li&gt;
&lt;li&gt;???Okta????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Protective Controls&lt;/h2&gt;
&lt;h3&gt;?????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Okta FastPass?FIDO2 webauthn???????????????????????????????????&lt;b&gt;???????????&lt;/b&gt;????Okta Verify??????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;Okta????????????????????????????????????????????????????????????Endpoint Management???????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/managed-main.htm&#34;&gt;??&lt;/a&gt;???&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/edr-integration-main.htm&#34;&gt;??????????????????????&lt;/a&gt;????????????????????????????????????????????????????????????????????????????????????????????Okta FastPass??????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/device-assurance.htm&#34;&gt;?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;?????????????????????????????????????????????????Okta Network Zones???????????????ASN???????????IP????IP????????????????????????????????&lt;/li&gt;
&lt;li&gt;Okta Behavior and Risk evaluations??????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????E ????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/security_general.htm&#34;&gt;?????????&lt;/a&gt;?&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/suspicious-activity-reporting.htm&#34;&gt;??????????????????&lt;/a&gt;?????????????????????????????????&lt;/li&gt;
&lt;li&gt;IT??????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;??????????????????????????????Zero Standing Privileges?????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/custom-admin-role/custom-admin-roles.htm&#34;&gt;??????????&lt;/a&gt;????????????????????????????????????JIT????????????????????????????&lt;/li&gt;
&lt;li&gt;??????????&lt;a href=&#34;https://sec.okta.com/articles/protectingadminsessions/&#34;&gt;IP????????????&lt;/a&gt;?????????????????????????????&lt;/li&gt;
&lt;li&gt;???????????????????????????????????????&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/admin-console-protected-actions.htm#:~:text=Protected%20actions%20are%20critical%20tasks,according%20to%20a%20configured%20interval.&#34;&gt;Protected Actions&lt;/a&gt;????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;???????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;????????????Okta???Web?????E ?????????DNS?????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;??????????????????????????????????????????????????????????Web?????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;??A??????&lt;/h2&gt;
&lt;p&gt;????????????????????????????????IOC??????????????????????????????????????????????????????????IOC??????&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;???&lt;/th&gt;
&lt;th&gt;??&lt;/th&gt;
&lt;th&gt;????&lt;/th&gt;
&lt;th&gt;????&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;????.&amp;lt;phishing.page&amp;gt;.&amp;lt;tld&amp;gt;&lt;/td&gt;
&lt;td&gt;???????????????&lt;br&gt;
Microsoft&lt;/td&gt;
&lt;td&gt;08.2024 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;accounts.&amp;lt;phishing_domain&amp;gt;.&amp;lt;tld&amp;gt;&lt;/td&gt;
&lt;td&gt;Google????????????????&lt;br&gt;&lt;/td&gt;
&lt;td&gt;08.2024 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;newnewdom&amp;lt;random&amp;gt;.&lt;br&gt;
&amp;lt;phishing_domain.tld&amp;gt;&lt;/td&gt;
&lt;td&gt;?????????????????&lt;br&gt;
??Microsoft???Okta?&lt;/td&gt;
&lt;td&gt;01.2025 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;securedauthxx&amp;lt;random&amp;gt;.&lt;br&gt;
&amp;lt;phishing_domain&amp;gt;.tld&lt;/td&gt;
&lt;td&gt;???????????????????&lt;br&gt;
??Okta??Google???&lt;/td&gt;
&lt;td&gt;01.2025 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;&amp;lt;alphanumeric&amp;gt;.&lt;br&gt;
&amp;lt;firstnamelastname&amp;gt;.workers.dev.&lt;/td&gt;
&lt;td&gt;Cloudflare Workers&lt;br&gt;
????&lt;/td&gt;
&lt;td&gt;01.2025 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AS??&lt;/td&gt;
&lt;td&gt;AS36352 - HostPapa&lt;/td&gt;
&lt;td&gt;Proxy?????&lt;br&gt;??????????&lt;/td&gt;
&lt;td&gt;01.2025 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AS??&lt;/td&gt;
&lt;td&gt;AS149440 - Evoxt ????????&lt;/td&gt;
&lt;td&gt;Proxy?????&lt;br&gt;??????????&lt;/td&gt;
&lt;td&gt;01.2025 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AS??&lt;/td&gt;
&lt;td&gt;AS210558 - 1337 Services GmbH&lt;/td&gt;
&lt;td&gt;Proxy?????&lt;br&gt;??????????&lt;/td&gt;
&lt;td&gt;01.2025 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AS??&lt;/td&gt;
&lt;td&gt;AS401120- cheapy.host LLC&lt;/td&gt;
&lt;td&gt;Proxy?????&lt;br&gt;??????????&lt;/td&gt;
&lt;td&gt;01.2025 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AS??&lt;/td&gt;
&lt;td&gt;AS23470 - ReliableSite.Net LLC&lt;/td&gt;
&lt;td&gt;Proxy?????&lt;br&gt;??????????&lt;/td&gt;
&lt;td&gt;01.2025 - 08.2025&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;???????Okta?????&lt;a href=&#34;https://security.okta.com/&#34;&gt;security.okta.com&lt;/a&gt;???????????????????????????????????&lt;/p&gt;
&lt;h3&gt;&lt;b&gt;??????????&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;Okta?????????????????????????????????????203??????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;???&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???&lt;/th&gt;
&lt;th&gt;???&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;???????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;??????&lt;/th&gt;
&lt;th&gt;?????????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
??(?)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;??&lt;/td&gt;
&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;???&lt;br&gt;
???????&lt;/td&gt;
&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;td&gt;??????&lt;/td&gt;
&lt;td&gt;&lt;br&gt;?????????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;1?5?&lt;/td&gt;
&lt;td&gt;5?20?&lt;/td&gt;
&lt;td&gt;20?45?&lt;/td&gt;
&lt;td&gt;45-55%&lt;/td&gt;
&lt;td&gt;55?80?&lt;/td&gt;
&lt;td&gt;80?95?&lt;/td&gt;
&lt;td&gt;95?99?&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Mon, 25 Aug 2025 07:00:00 +0000</pubDate>
                
                    <category>credential-phishing,threat-intelligence,threat-insights,iam,blog-post,platform-abuse</category>
                
                <dc:creator>Houssem Eddine Bordjiba</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/threat-actors-please-do-not-use-okta-fastpass/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/threat-actors-please-do-not-use-okta-fastpass/</link>
                <title>Threat actors: &amp;quot;Please do not use Okta FastPass&amp;quot;</title>
                <description>
                    <![CDATA[&lt;p&gt;?????????????????Okta FastPass???????????????&lt;/p&gt;
&lt;p&gt;Okta???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????CEO????????????????????????????????????????????????????????????????????????????????????????Slack???????????????????????&lt;/p&gt;
&lt;p&gt;Okta????????????????security.okta.com?????????????????????????&lt;a href=&#34;https://support.okta.com/help/s/article/accessing-okta-s-security-trust-center?language=en_US&#34; target=&#34;_self&#34;&gt;???????????&lt;/a&gt;?&lt;a href=&#34;https://security.okta.com/product/okta/instant-messaging-services-abused-for-phishing-redirection&#34; target=&#34;_self&#34;&gt;????&lt;/a&gt;?????&lt;/p&gt;
&lt;h2&gt;????????????????????????????????????&lt;/h2&gt;
&lt;p&gt;???????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????Evilginx?????AitM????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????????????????????????????SMS?TOTP????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;AitM????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????Okta FastPass?FIDO2??????????PIV?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????&lt;a href=&#34;https://sec.okta.com/articles/2023/07/unexpected-endorsement-webauthn/&#34; target=&#34;_self&#34;&gt;FIDO2?????????????????&lt;/a&gt;????????????????????????????????????????????????????????????????????????????????????FIDO????????????????????????????????????????????????????????????????????????????????????MFA????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????FIDO2 ?????????????????????????????????????????????????FastPass ?????????????????????&lt;a href=&#34;https://sec.okta.com/articles/phishingasaservice/&#34; target=&#34;_self&#34;&gt;Okta ????????????????&lt;/a&gt;??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ?????????FastPass ??????Universal Logout????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h2&gt;??????????????????????????????????&lt;/h2&gt;
&lt;p&gt;??????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta Identity Engine??????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta FastPass ???????????????????????????????????????????????????&lt;a href=&#34;https://www.okta.com/sites/default/files/2023-02/FastPass_Technical_Whitepaper.pdf&#34; target=&#34;_self&#34;&gt;Okta FastPass Technical ????????&lt;/a&gt; ??????????&lt;/p&gt;
&lt;p&gt;????????????????????SMS?????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????&lt;a href=&#34;https://support.okta.com/help/s/article/accessing-okta-s-security-trust-center?language=en_US&#34; target=&#34;_self&#34;&gt;????&lt;/a&gt;?????&lt;a href=&#34;https://security.okta.com/product/okta/instant-messaging-services-abused-for-phishing-redirection&#34; target=&#34;_self&#34;&gt;???????????&lt;/a&gt;?????Okta ??????????????&lt;a href=&#34;https://security.okta.com/product/okta/instant-messaging-services-abused-for-phishing-redirection&#34; target=&#34;_self&#34;&gt;Okta Security Trust Center&lt;/a&gt;???????????&lt;/p&gt;
]]>
                </description>
                <pubDate>Mon, 04 Aug 2025 16:00:00 +0000</pubDate>
                
                    <category>threat-intelligence,mfa-downgrade,social-engineering,credential-phishing</category>
                
                <dc:creator>Brett Winterford</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/instant-messaging-services-abused-for-phishing-redirection/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/instant-messaging-services-abused-for-phishing-redirection/</link>
                <title>Instant messaging services abused for phishing redirection</title>
                <description>
                    <![CDATA[&lt;h2&gt;??&lt;/h2&gt;
&lt;p&gt;Okta ????????????????????????????????????????&lt;b&gt;Slack&lt;/b&gt;?????????????????????????????AitM???????????????????????????????&lt;/p&gt;
&lt;p&gt;2025?7????&lt;br&gt; &lt;b&gt;O-UNC-031&lt;/b&gt; ?????????????????????????????????????&lt;b&gt; ????&lt;/b&gt; ?&lt;b&gt; ??????&lt;/b&gt; ????&lt;b&gt; &lt;/b&gt;&lt;b&gt;???????CRM?&lt;/b&gt; ?????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????&lt;b&gt;Evilginx&lt;/b&gt; AitM??????????????????????????????&lt;/p&gt;
&lt;p&gt;???????????????????????????????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;Slack????????????????&lt;/h3&gt;
&lt;p&gt;??????????????????Slack??????????O-UNC-031????Slack????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????Slack????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????Slack???????????????????&lt;b&gt;??????&lt;/b&gt;??????????????????????????????E ???????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????Slack???????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????????????????Slack??????E ????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????????????????????????????????@channel????????????????????????????????????????????Slack?????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;okta-integrations.com&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&amp;lt;target&amp;gt;-onelogin.com&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&amp;lt;target&amp;gt;admin.io&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&amp;lt;target&amp;gt;-okta.com&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;slack-&amp;lt;target&amp;gt;.com&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&amp;lt;target&amp;gt;employees.com&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&amp;lt;target&amp;gt;okta.com&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;???????&amp;quot;????????&amp;quot;???????????&amp;quot;[???] Okta??????????????????&amp;quot;???????????&lt;/li&gt;
&lt;li&gt;???????????????????????Slack?????????????????Okta??????????????????&lt;/li&gt;
&lt;li&gt;??????????????????????URL???&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;https://&amp;lt;phishing domain&amp;gt; /slack/connection/2138-4f92-acb7-bk51?&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;https://&amp;lt;phishing domain&amp;gt;/integration/slack/&amp;lt;target&amp;gt;/,&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;https://&amp;lt;phishing domain&amp;gt;/integration/payroll/&amp;lt;target&amp;gt;/&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Slack?????????????????????????????????????????????????????????DM??????????&lt;/li&gt;
&lt;li&gt;Slack???????????????????????????????????????????DM?????????????????E ?????????????&lt;/li&gt;
&lt;li&gt;Markdown?Slack???Markup?????????????????????????????????????????????URI????????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Slack????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;Adversary-in-the-Middle ??????&lt;/h3&gt;
&lt;p&gt;???MFA???????????????AitM?????????????Evilginx???????????????????????????MFA???????????????????????????????Okta FastPass??????????????????????????????????????????????????????Evilginx?Okta???????????????&lt;/p&gt;
&lt;p&gt;Okta Threat Intelligence??Evilginx?Okta Sign-In???????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;???????????????????????????????????&lt;/h3&gt;
&lt;p&gt;Okta Threat Intelligence????????????????Okta FastPass??????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????????Okta FastPass?AitM???????????????????????????????????????Okta??????????????????????????????????????????????????????????????????????????????????????OTP?SMS???????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;h3&gt;????????????&lt;/h3&gt;
&lt;p&gt;??????????????????????BitLaunch???????????????????????????VPS?????????????????????BitLaunch?????????????????????????????????????????????????VPS????????????????????????????????????NICENIC INTERNATIONAL????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;?????????WHOIS????????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;?????/????: &lt;b&gt;kond&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;???: &lt;b&gt;AW&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;O-UNC-031&lt;/b&gt;??????????????????????????????????&lt;b&gt;Mullvad VPN&lt;/b&gt;????IP???????????????????&lt;/p&gt;
&lt;h2&gt;????&lt;/h2&gt;
&lt;h3&gt;?????????&lt;/h3&gt;
&lt;p&gt;???????????????????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;???????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;???Okta????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Protective Controls&lt;/h2&gt;
&lt;h3&gt;&lt;b&gt;?????????&lt;/b&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Okta FastPass?FIDO2 webauthn?????????????????????????????&lt;/li&gt;
&lt;li&gt;???????&lt;b&gt;???????????&lt;/b&gt;??????????????????????&lt;/li&gt;
&lt;li&gt;Okta????????????????????????????????????????????????????????????Endpoint Management???????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/managed-main.htm&#34;&gt;??&lt;/a&gt;???&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/edr-integration-main.htm&#34;&gt;??????????????????????&lt;/a&gt;?????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/fp/fp-main.htm&#34;&gt;????&lt;/a&gt;?????Okta FastPass??????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/device-assurance.htm&#34;&gt;??????????????????&lt;/a&gt;?????????&lt;/li&gt;
&lt;li&gt;?????????????????????????????????????????????????Okta Network Zones???????????????ASN???????????IP????IP????????????????????????????????&lt;/li&gt;
&lt;li&gt;Okta Behavior and Risk evaluations??????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;?????????E ??????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/security_general.htm&#34;&gt;?????????&lt;/a&gt;?&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/suspicious-activity-reporting.htm&#34;&gt;?????????????&lt;/a&gt;?????????????????????????????????&lt;/li&gt;
&lt;li&gt;?????????IT??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/custom-admin-role/custom-admin-roles.htm&#34;&gt;??????????&lt;/a&gt;?????????????????JIT????????????????????????????&lt;/li&gt;
&lt;li&gt;?????????????????????????????????IP???????????????????&lt;/li&gt;
&lt;li&gt;???????????????????????????????????????&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/admin-console-protected-actions.htm#:~:text=Protected%20actions%20are%20critical%20tasks,according%20to%20a%20configured%20interval.&#34;&gt;Protected Actions&lt;/a&gt;????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;???????????????????????&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;????????????Okta???Web?????E ?????????DNS?????????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;????????????????????????????????????????&lt;/li&gt;
&lt;li&gt;??????????????????????????????????????????????????????????Web?????????????????????????????????????&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;??A???/?????&lt;/h2&gt;
&lt;p&gt;????????????????????????????????IOC??????????????????????????????????????????????????????????IOC??????&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;???&lt;/th&gt;
&lt;th&gt;??&lt;/th&gt;
&lt;th&gt;????&lt;/th&gt;
&lt;th&gt;????&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;IP Address ?IP ?????&lt;/td&gt;
&lt;td&gt;157.245.242[.]172&lt;/td&gt;
&lt;td&gt;??????????&lt;/td&gt;
&lt;td&gt;2025?7?11?&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;IP Address ?IP ?????&lt;/td&gt;
&lt;td&gt;157.245.227[.]25&lt;/td&gt;
&lt;td&gt;??????????&lt;/td&gt;
&lt;td&gt;2025?7?9?&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;IP Address ?IP ?????&lt;/td&gt;
&lt;td&gt;157.245.129[.]184&lt;/td&gt;
&lt;td&gt;??????????&lt;/td&gt;
&lt;td&gt;2025?7?9?&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;IP Address ?IP ?????&lt;/td&gt;
&lt;td&gt;64.190.113[.]119&lt;/td&gt;
&lt;td&gt;??????????&lt;/td&gt;
&lt;td&gt;2025?7?4?&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;IP Address ?IP ?????&lt;/td&gt;
&lt;td&gt;157.245.134[.]111&lt;/td&gt;
&lt;td&gt;??????????&lt;/td&gt;
&lt;td&gt;2025?7?4?&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;IP Address ?IP ?????&lt;/td&gt;
&lt;td&gt;167.99.236[.]196&lt;/td&gt;
&lt;td&gt;??????????&lt;/td&gt;
&lt;td&gt;2025?7?3?&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;IP Address ?IP ?????&lt;/td&gt;
&lt;td&gt;206.188.197[.]224&lt;/td&gt;
&lt;td&gt;??????????&lt;/td&gt;
&lt;td&gt;2025?7?2?&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;IP Address ?IP ?????&lt;/td&gt;
&lt;td&gt;50.189.65[.]60&lt;/td&gt;
&lt;td&gt;??????????&lt;/td&gt;
&lt;td&gt;2025?7?8?&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VPN??????&lt;/td&gt;
&lt;td&gt;Mullvad VPN&lt;/td&gt;
&lt;td&gt;VPN??????&lt;/td&gt;
&lt;td&gt;2025-07&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Whois&lt;/td&gt;
&lt;td&gt;kond&lt;/td&gt;
&lt;td&gt;?????/????&lt;/td&gt;
&lt;td&gt;2025-07&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Whois&lt;/td&gt;
&lt;td&gt;AW&lt;/td&gt;
&lt;td&gt;????2025-07&lt;/td&gt;
&lt;td&gt;2025-07&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;&lt;br&gt;
???????Okta ????? &lt;a href=&#34;https://security.okta.com/&#34;&gt;security.okta.com&lt;/a&gt; ???????????????????????????????????&lt;/p&gt;
&lt;p&gt;&lt;b&gt;???????????&lt;/b&gt;&lt;br&gt;
Okta??????????????????????????????????????203 - ?????????????????????????????????????????&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;???&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???&lt;/th&gt;
&lt;th&gt;???&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;???????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
???????&lt;/th&gt;
&lt;th&gt;??????&lt;/th&gt;
&lt;th&gt;?????????&lt;/th&gt;
&lt;th&gt;??&lt;br&gt;
??(?)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;??&lt;/td&gt;
&lt;td&gt;????&lt;/td&gt;
&lt;td&gt;???&lt;br&gt;
???????&lt;/td&gt;
&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;td&gt;??????&lt;/td&gt;
&lt;td&gt;&lt;br&gt;?????????&lt;/td&gt;
&lt;td&gt;??&lt;br&gt;
??&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;???????&lt;/td&gt;
&lt;td&gt;1?5?&lt;/td&gt;
&lt;td&gt;5?20?&lt;/td&gt;
&lt;td&gt;20?45?&lt;/td&gt;
&lt;td&gt;45-55%&lt;/td&gt;
&lt;td&gt;55?80?&lt;/td&gt;
&lt;td&gt;80?95?&lt;/td&gt;
&lt;td&gt;95?99?&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Mon, 14 Jul 2025 07:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,platform-abuse,mfa-downgrade,social-engineering,credential-phishing,threat-insights</category>
                
                
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/okta-observes-v0-ai-tool-used-to-build-phishing-sites/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/okta-observes-v0-ai-tool-used-to-build-phishing-sites/</link>
                <title>Okta observes v0 AI tool used to build phishing sites</title>
                <description>
                    <![CDATA[&lt;p&gt;Okta Threat Intelligence??&lt;a href=&#34;https://vercel.com/ai&#34; target=&#34;_blank&#34;&gt;Vercel&lt;/a&gt;?????????Generative Artificial Intelligence?GenAI???????v0??????????????Web????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????AI?????????????????????Okta?????????????????????????&lt;/p&gt;
&lt;p&gt;Vercel?&lt;a href=&#34;http://v0.dev/&#34; target=&#34;_blank&#34;&gt;v0.dev&lt;/a&gt;????????????????Web??????????????AI????????Okta???????????Okta???????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????Vercel??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????CDN??????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;Vercel ????????????????????????????????????????????????????????? Okta ????????&lt;/p&gt;
&lt;p&gt;????????????????????????????????????????????GenAI??????????????????????????????Vercel?v0.dev????????????????????????????????????????????????????????????????????????&lt;br&gt;
&lt;br&gt;Vercel?v0.dev???????????????????????GitHub???????v0.dev Application ??????????????????????????????????????????????Do-It-Yourself?DIY??????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta ?????????? ???????? Vercel ???????? ??????Microsoft 365 ????????????????????????? ?????? ?????????????????????Okta ??????&lt;a href=&#34;https://support.okta.com/help/s/article/accessing-okta-s-security-trust-center?language=en_US&amp;amp;_gl=1*1j182tq*_gcl_aw*R0NMLjE3NDgyODQzMjcuQ2owS0NRandvdERCQmhDUUFSSXNBRzVwaW5NNDl3cUlfSGZ3T2lVR19wTzhZRzQybXVoT0dNd202aGEwREd6VVNrcU9qTW9BNDhOS0tMUWFBZ2VkRUFMd193Y0I.*_gcl_au*MjEyNDE1NDI4MC4xNzQ3NzYwMDE1*_ga*NTE0NTAxODM2LjE3MjQwOTM3NjA.*_ga_QKMSDV5369*czE3NTA0MjkzNTkkbzE5OCRnMSR0MTc1MDQyOTQxOCRqMSRsMCRoMA..&#34; target=&#34;_self&#34;&gt;??&lt;/a&gt;??????????????&lt;a href=&#34;https://security.okta.com/product/okta/how-a-phishing-as-a-service-operation-enables-fraud-actors&#34; target=&#34;_self&#34;&gt;??????????????&lt;/a&gt;??????????&lt;/p&gt;
&lt;h2&gt;?????????&lt;/h2&gt;
&lt;p&gt;???????????????????????????????????????????????AI???????????????????????????????????????????AI??????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;??????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;????&lt;a href=&#34;https://www.okta.com/products/fastpass/&#34; target=&#34;_self&#34;&gt;Okta FastPass&lt;/a&gt;???????????Okta Verify????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;p&gt;Okta Threat Intelligence????????????????&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;??????????????????: Okta FastPass????????????????????????????????????????????????????????????????????????????????????&lt;a href=&#34;https://www.okta.com/resources/whitepaper-ultimate-guide-to-phishing/&#34; target=&#34;_self&#34;&gt;??????????????????????????&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????????????????????????????????????????????????????????????????????????????????Application ??????????????????????Okta????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;??????????????????????????Okta Network Zones?????????ASN???????????IP????IP???????????????????????????????????????????Okta ?????????????????????????????????????????????????????????????????????????????????????????????&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;????????????AI???????????????????????????????????????&lt;br&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;?????????????????????????&lt;a href=&#34;https://security.okta.com/product/okta/how-a-phishing-as-a-service-operation-enables-fraud-actors&#34; target=&#34;_self&#34;&gt;????????????????&lt;/a&gt; (Okta ??????) ????????????????????????????????????????????????????????&lt;a href=&#34;https://www.linkedin.com/newsletters/access-granted-newsletter-7155652997908193280/&#34; target=&#34;_blank&#34;&gt;Access Granted LinkedIn ???????&lt;/a&gt;??????????&lt;/p&gt;
]]>
                </description>
                <pubDate>Mon, 30 Jun 2025 16:00:00 +0000</pubDate>
                
                    <category>ai,threat-intelligence,iam,social-engineering,credential-phishing</category>
                
                <dc:creator>Houssem Eddine Bordjiba, Paula De la Hoz</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/ja-jp/blog/threat-intelligence/the-secrets-agentic-ai-leaves-behind/</guid>
                <link>https://www.okta.com/ja-jp/blog/threat-intelligence/the-secrets-agentic-ai-leaves-behind/</link>
                <title>The Secrets Agentic AI Leaves Behind</title>
                <description>
                    <![CDATA[&lt;h2&gt;Executive&amp;nbsp;Summary&lt;/h2&gt;
&lt;p&gt;At the current pace of acceleration in agentic AI, it no longer seems&amp;nbsp;prophetic to say that before too long, there will be more AI agents&amp;nbsp;connecting to production applications and data than human users.&lt;/p&gt;
&lt;p&gt;There will be profound implications for the workplace - with some estimates&amp;nbsp;that half of the white collar workforce may not be employed within five years.&amp;nbsp;There are also profound implications for cybersecurity.&lt;/p&gt;
&lt;p&gt;Agentic AI presents novel risks, such as prompt injection attacks, in which AI&amp;nbsp;agents are effectively &#34;social engineered&#34; into taking action on behalf of an&amp;nbsp;attacker after being exposed to untrusted input.&lt;/p&gt;
&lt;p&gt;As an identity company, Okta&#39;s larger and more immediate concern is how&amp;nbsp;agentic AI adds to the attack surface of every organization from an&amp;nbsp;authentication and authorization perspective. We can reliably expect that&amp;nbsp;attackers will discover and abuse the innumerable service account&amp;nbsp;passwords and static API keys developers are generating in order to grant AI&amp;nbsp;agents access to corporate resources. We can also reliably expect that the&amp;nbsp;broad authorization granted to AI agents will exacerbate the potential data&amp;nbsp;loss from the compromise of any given account.&lt;/p&gt;
&lt;p&gt;This document is intended as a guide to service providers, organizations and&amp;nbsp;developers experimenting with agentic AI with a view to building production&amp;nbsp;applications.&lt;/p&gt;
&lt;h2&gt;The role AI plays in&amp;nbsp;identity debt&lt;/h2&gt;
&lt;p&gt;Identity debt accumulates when shared, static secrets are allowed to&amp;nbsp;accumulate over time in a system. A secret is shared when it&#39;s known or&amp;nbsp;stored by more than one user or in more than one place. A secret is static&amp;nbsp;when it is long-lived, and goes for long periods of time without being rotated.&lt;/p&gt;
&lt;p&gt;Agentic AI, our research found, is contributing to an acceleration in this&amp;nbsp;buildup of identity debt.&amp;nbsp;Organizations should rely on enterprise-grade methods of authorizing a&amp;nbsp;client (AI application) to act on a user&#39;s behalf in a protected resource&amp;nbsp;(apps and data).&lt;/p&gt;
&lt;p&gt;Our research found the opposite. The most commonly used methods of&amp;nbsp;authorizing an AI agent&#39;s access to functions and data in SaaS apps, code&amp;nbsp;repositories, databases and other resources result in the exposure of highly&amp;nbsp;privileged secrets.&lt;/p&gt;
&lt;p&gt;The table on the following page assesses the security properties of various&amp;nbsp;approaches to authorization.&lt;/p&gt;
&lt;h2&gt;Agentic&amp;nbsp;plugins: the&amp;nbsp;forerunners&amp;nbsp;to MCP&lt;/h2&gt;
&lt;h3&gt;A study of Copilot plugins&lt;/h3&gt;
&lt;p&gt;Our research found that the majority of the machine-to-machine authentication methods used to connect Al agents to protected resources (enterprise apps and data) use forms of authentication that aren&#39;t fit for purpose in production environments, with little to no control over authorization.&lt;/p&gt;
&lt;p&gt;To illustrate, we assessed the available authentication methods made available for allowing Microsoft Copilot Al agents to access some of the most sensitive data in the enterprise: security applications.&lt;/p&gt;
&lt;p&gt;Copilot is among the world&#39;s dominant general-purpose Al assistants. Microsoft offers the ability to create &amp;quot;plugins&amp;quot; for Microsoft Copilot to expose the features of third-party security apps to Microsoft applications (under the brand &amp;quot;Microsoft Security Copilot&amp;quot;). Each Microsoft Security Copilot plugin is configured in a YAML or JSON file (a plugin manifest) that describes what tools in the external service are available to the Copilot agent.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Using these services:&lt;/b&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Microsoft Copilot acts as the host application&lt;/li&gt;
&lt;li&gt;The tools and data of security apps, such as Splunk, SentinelOne, Forescout or Cyberark, are protected resources.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A mutual customer (of both services) must first authorize Copilot to access protected resources on their behalf. This requires the customer to provide Copilot with credentials (passwords, API keys or the Client ID and Client Secret in an OAuth flow), which are stored at-rest on Microsoft servers. The available schemes are listed in the table below.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Security Copilot supports several schemes for authenticating plugins:&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;When a user prompts Copilot to use a protected resource, the Copilot Al analyzes the request and determines which plugin advertises the relevant &amp;quot;skill&amp;quot; (as defined in the plugin manifest) to draw from. Copilot then uses the stored credentials to make an authenticated API call to the third-party application, which retrieves the data or performs an action and returns a result back to Copilot. We sought to understand what authentication methods were used to connect these protected resources (security applications) to Microsoft Copilot. 5&lt;/p&gt;
&lt;p&gt;From our analysis of the third-party plugin manifests published on GitHub, we found:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;20% support &lt;b&gt;Basic Authentication&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;75% support the &lt;b&gt;ApiKey&lt;/b&gt; method&lt;/li&gt;
&lt;li&gt;5% support an &lt;b&gt;OAuth2&lt;/b&gt; flow&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The risks associated with using a Copilot AI plugin hinge largely on (a) thischoice of authentication method and (b) the scope of access provided to&amp;nbsp;the agent.&lt;/p&gt;
&lt;h3&gt;Basic Authentication&lt;/h3&gt;
&lt;p&gt;Using Basic Authentication, administrators must create a service account in the third-party application and upload the username and password to Microsoft servers. Copilot then sends the username and password in the header of every request to the security app (whenever Copilot selects that tool based on a user prompt.)&lt;/p&gt;
&lt;p&gt;By definition, user or service accounts configured to allow an Al agent to access resources using the http:basic scheme (basic authentication) cannot support multifactor authentication.&lt;/p&gt;
&lt;p&gt;Customers using this scheme must by consequence expose user or service accounts - which are often scoped for broad access to sensitive data - to credential stuffing and password spray attacks.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;APIKey&lt;/h3&gt;
&lt;p&gt;Three in four Microsoft Security Copilot plugins can be authorized using the APIKey method.&lt;/p&gt;
&lt;p&gt;During configuration, administrators create a long-lived API token in the protected resource, which is typically created in the context of a user or service account, and manually upload the API token to Microsoft servers. Copilot sends the API token in the header of every HTTP request it makes to the protected resource (that is, whenever Copilot selects that security tool based on a user prompt.)&lt;/p&gt;
&lt;p&gt;Static API keys offers several benefits over basic authentication:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;API keys are better suited to machine-to-machine flows. Each unique API token can often be configured to expire after inactivity or a set duration. Revocation of the key doesn&#39;t have any impact on the user or service account that created it.&lt;/li&gt;
&lt;li&gt;Access to the service account used to create the API token can now be protected using Multifactor Authentication.&lt;/li&gt;
&lt;li&gt;Administrators are more likely to limit the &amp;quot;scope&amp;quot; of what an API token can be used to read or modify, as compared with the permissions of a service account used for basic authentication.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The residual risks are that these API tokens are typically long-lived. API keys are routinely checked into source control systems. API keys are routinely stored in logs when set as query parameters. Occasionally API keys are saved in text files on developer workstation, ready for collection by the next generic infostealer that infects the device.&lt;/p&gt;
&lt;p&gt;Static API tokens are highly valued by attackers, and the first thing many attackers search for after compromising a system. Once intercepted, these tokens are typically valid for long periods of time, making them ideal candidates for resale in online markets.&lt;/p&gt;
&lt;p&gt;Static API tokens also present availability risks, at least when compared to temporary tokens created in OAuth flows, as static tokens tend to be created in the context of a user rather than an application.&lt;/p&gt;
&lt;p&gt;In many cases, if the user or service account that created the token is deleted or deprovisioned, the token is deleted with it, and breaks whatever M2M integration it glued together.&lt;/p&gt;
&lt;h3&gt;OAuth2&lt;/h3&gt;
&lt;p&gt;The small remainder of Microsoft Security Copilot plugins appear to use enterprise-grade &lt;b&gt;OAuth2 flows&lt;/b&gt;.&lt;/p&gt;
&lt;p&gt;In these schemes, a client ID and client secret (shared with Microsoft) are exchanged with an authorization server to obtain a short-lived access token, which is independently validated by the resource server.&lt;/p&gt;
&lt;p&gt;If these flows were created in Okta, the resulting access tokens can be IP- constrained (only valid from a configured IP range) and client-constrained (only valid from the client that requested it). Scopes are set at the service application level, not at the user level, which means that administrators do not accidentally disable machine-to-machine integrations when an administrative account or service account is deprovisioned. &lt;/p&gt;
&lt;p&gt;While it is disappointing to observe that so few Copilot agents are designed for enterprise-grade authentication, in many respects these choices are a reflection of the existing authentication methods made available by the security apps. In the context of integrating with a single proprietary Al tool, these security vendors were evidently not prepared to invest in updating their available authentication methods.&lt;/p&gt;
&lt;p&gt;But what if, instead of writing plugin manifests for every Al application, developers could build a single server to an industry standard supported by all flavours of Al application?&lt;/p&gt;
&lt;p&gt;Enter Model Context Protocol.&lt;/p&gt;
&lt;h2&gt;Modelling threats to Model Context Protocol&lt;/h2&gt;
&lt;p&gt;If you&#39;re a developer of enterprise apps, the economics of having to write a new custom connector (such as a Microsoft Copilot plugin) for every other flavour of Al model is far from desirable.&lt;/p&gt;
&lt;p&gt;Service providers would prefer to declare from the outset what data and tools the company is willing to share with any Al model, define the conditions under these resources are exposed, define how customers should authorize the access, and allowlist the Al applications that can access these resources. &lt;/p&gt;
&lt;p&gt;For this reason, the momentum in agentic Al is now building around Model Context Protocol (MCP). MCP is a standardized interface for connecting Al applications (hosts) to enterprise services as diverse as cloud platforms, SaaS applications, code repositories, databases and even payment services. MCP&#39;s client-server architecture allows for the &amp;quot;plug and play&amp;quot; of Al applications to the data sources and tools that provide them context.&lt;/p&gt;
&lt;p&gt;In the enterprise, MCP promises an ability to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Determine what enterprise-owned data sources and tools are available,&lt;/li&gt;
&lt;li&gt;Allow agentic Al applications to access data sources and tools from multiple applications, without cross-contamination of data,&lt;/li&gt;
&lt;li&gt;Lower the cost of experimenting with different Al applications that access those data sources and tools.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MCP servers can be deployed locally or remotely. This choice of deployment model for any given use case has a significant bearing on the resulting threat model.&lt;/p&gt;
&lt;p&gt;The scope of our research was constrained to understanding how Al applications (hosts), MCP clients and MCP servers handle credentials. The core components we assessed were:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;MCP hosts: Al applications, including Integrated Development Environments (IDEs) like Cursor, VS Code or Claude, which require access to the tools advertised by MCP servers.&lt;/li&gt;
&lt;li&gt;MCP clients: The multiple clients an MCP host uses to communicate with a paired MCP server.&lt;/li&gt;
&lt;li&gt;MCP servers: MCP servers advertise the tools and resources available in an external service and make API calls to these services.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Local MCP servers&lt;/h2&gt;
&lt;p&gt;The MCP model is especially attractive for software development use cases. &lt;/p&gt;
&lt;p&gt;Software engineers using Al-enabled IDEs like Cursor and VS Code can build code locally, while drawing on the assistance of remote Al models to make suggestions as the developer writes code.&lt;/p&gt;
&lt;p&gt;Anthropic makes its Claude Al agent available for local deployment as &amp;quot;Claude Desktop&amp;quot;. Claude Desktop is a locally-deployed MacOS and Windows client and an alternative to accessing Anthropic&#39;s Al models via the browser. One advantage to local MCP servers is that clients can interact with both a remote Al model and local files (docs, images etc).&lt;/p&gt;
&lt;p&gt;These desktop applications often need to authenticate to both the LLM (this typically requires an API key) and to remote data sources (such as code repositories, which require a Personal Access Token).&lt;/p&gt;
&lt;p&gt;When a user launches the host application, such as Claude or Cursor, the MCP client spawns an MCP server and passes the server any credentials (API keys, database credentials, passwords, OAuth client secrets etc) required for operation from a local configuration file, including those credentials the MCP server requires for access to remote services.&lt;/p&gt;
&lt;p&gt;If the MCP server is designed for access to Github resources, for example, the host requires a Github Personal Access Token (PAT) to be available in the local configuration file. The server will error out if the Github PAT is not provided.&lt;/p&gt;
&lt;p&gt;The location of configuration files for three of the most popular development applications that use Al are provided below:&lt;/p&gt;
&lt;table&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;App&lt;/th&gt;
&lt;th&gt;Local Configuration File&lt;/th&gt;
&lt;th&gt;Default Locations&lt;/th&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Claude Desktop&lt;/td&gt;
&lt;td&gt;claude_desktop_config.json&lt;/td&gt;
&lt;td&gt;Default location on MacOS: ~/Library/Application Support/Claude/ Default location on Windows: ~/AppData/Roaming/Claude&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Cursor&lt;/td&gt;
&lt;td&gt;mcp.json&lt;/td&gt;
&lt;td&gt;Default location when used globally (all OS): ~/.cursor/mcp.json If an MCP server is only available to a specific project, the configuration file is placed in the project directory.&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VS Code&lt;/td&gt;
&lt;td&gt;settings.json&lt;/td&gt;
&lt;td&gt;Default location on MacOS: ~/Library/Application Support/Code/User/ Default location on Windows: ~/AppData/Roaming/Code/User&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Research by Keith Hoodlet at&amp;nbsp;&lt;a href=&#34;https://blog.trailofbits.com/2025/04/30/insecure-credential-storage-plagues-mcp/&#34;&gt;Trail of Bits&lt;/a&gt;&amp;nbsp;noted the risks of storing static API keys in plaintext in these files, and cited examples of where these files were world-readable (i.e. able to be accessed by any user of the system).&lt;/p&gt;
&lt;p&gt;Extending this research, we assessed the default configuration files for Claude Desktop, Cursor and VS Code, and observed the same permissions.&lt;/p&gt;
&lt;hr&gt;

&lt;p style=&#34;text-align: right;&#34;&gt;[1] &lt;a href=&#34;https://blog.trailofbits.com/2025/04/30/insecure-credential-storage-plagues-mcp/&#34;&gt;Insecure credential storage plagues MCP&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The same permissions appear to apply to configuration files included in numerous &lt;a href=&#34;https://github.com/modelcontextprotocol/servers?tab=readme-ov-file#%EF%B8%8F-official-integrations&#34;&gt;official MCP server&lt;/a&gt; implementations that are described as &amp;quot;production-ready&amp;quot;, and for just about all the community integrations developed by third parties, which are not endorsed by the service providers in question.&lt;/p&gt;
&lt;p&gt;Any threat modelling should anticipate that the vast majority of MCP servers shared to date are not endorsed, which leads to heightened risks around developer use of rogue MCP servers. &lt;/p&gt;
&lt;p&gt;A &lt;a href=&#34;https://blog.virustotal.com/2025/06/what-17845-github-repos-taught-us-about.html?m=1&#34;&gt;preliminary VirusTotal analysis&lt;/a&gt; of MCP servers uploaded to GitHub [2] discovered that 8% of them were suspicious. An undisclosed number of those included code that attempts to identify secrets (keys, passwords etc) in prompts and posts them to external endpoints.&lt;/p&gt;
&lt;p&gt;The insecure storage of API keys presents a range of risks, each of which are explored below.&lt;/p&gt;
&lt;hr&gt;

&lt;p style=&#34;text-align: right;&#34;&gt;[2] &lt;a href=&#34;https://blog.virustotal.com/2025/06/what-17845-github-repos-taught-us-about.html?m=1&#34;&gt;What 17,845 GitHub Repos Taught Us About Malicious MCP Servers&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Risks associated with insecure storage of API keysKeys uploaded to software repositories&lt;/h2&gt;
&lt;h3&gt;Keys uploaded to software repositories&lt;/h3&gt;
&lt;p&gt;Most documentation for local MCP server implementations do not warn developers or other users about the risks of storing plaintext credentials for production resources in configuration files. It is assumed that developers will securely vault the credentials, such that the configuration file only references a credential stored in a secure location.&lt;/p&gt;
&lt;p&gt;We observed some scenarios in which the MCP configuration was not able to fetch the credential at runtime unless it was stored in plaintext in the configuration file.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Research by &lt;a href=&#34;https://blog.gitguardian.com/a-look-into-the-secrets-of-mcp/&#34;&gt;Gaetan Ferry at GitGuardian&lt;/a&gt; of repositories cloned from the unofficial &lt;a href=&#34;https://smithery.ai/&#34;&gt;Smithery.ai&lt;/a&gt; MCP server registry found 202 examples that contained at least one secret (5.2% of all repositories scanned). Static API tokens (see &amp;quot;x-api-key&amp;quot;) featured prominently[3].&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr&gt;

&lt;p style=&#34;text-align: right;&#34;&gt;[3] &lt;a href=&#34;https://blog.gitguardian.com/a-look-into-the-secrets-of-mcp/&#34;&gt;A Look Into the Secrets of MCP: The New Secret Leak Source&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Keys are exposed in container metadata&lt;/h3&gt;
&lt;p&gt;Running MCP servers in containers shifts rather than mitigates the issue. The secret must be passed to the container in a format that the MCP server supports.&lt;/p&gt;
&lt;p&gt;Reviewing container configuration provides a direct reference to a cleartext secret - whether that&#39;s in the form of a file on the host, or from being able to identify the relevant environment variables in a container which can be exposed by running&amp;nbsp;docker inspect, a command line tool that allows for inspection of docker resources.&lt;/p&gt;
&lt;h3&gt;Keys accessed by malware&lt;/h3&gt;
&lt;p&gt;Commodity infostealer malware is designed to locate specific paths and file types where credentials are stored. &lt;/p&gt;
&lt;p&gt;For example:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Windows infostealers, such as Vidar Stealer, will search for secrets stored at&lt;b&gt; ~\AppData\Roaming&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;MacOS infostealers, such as Atomic Stealer, search for secrets stored at &lt;b&gt;~/Library/Application Support&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It is highly likely that the insecure storage of static API tokens in these locations will result in impactful events. Where a session token stored in this location provides a brief window of time in which an attacker can gain user- level access to a resource, a static API Token provides persistent access to organization-wide resources.&lt;/p&gt;
&lt;h3&gt;Keys backed up to external systems&lt;/h3&gt;
&lt;p&gt;Keys are exposed in backup volumes if administrators fail to exclude sensitive folders (such as &lt;b&gt;~\AppData\Roaming&lt;/b&gt; on Windows or &lt;b&gt;~/Library/Application Support&lt;/b&gt; on MacOS).&lt;/p&gt;
&lt;h3&gt;Workstations shared between multiple users&lt;/h3&gt;
&lt;p&gt;Given configuration files were found to be world-readable, keys stored by one user on a shared device are also accessible to other users that log-in to the same device.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Secure alternatives for local credential storage&lt;/h2&gt;
&lt;p&gt;The recommendations section of this document outlines tactical solutions that minimize these credential storage risks.&lt;/p&gt;
&lt;p&gt;Alternatively, organizations experimenting with MCP can take a &amp;quot;secure by design&amp;quot; approach and use solutions developed with these threats in mind.&lt;/p&gt;
&lt;p&gt;Take the &lt;a href=&#34;https://auth0.com/blog/announcement-auth0-mcp-server-is-here/&#34;&gt;Auth0 MCP server&lt;/a&gt;, for example [4]. The Autho MCP server offers administrators the ability to authorize access to Autho resources from local Claude Desktop, Cursor or Windsurf applications using the OAuth 2.0 Device Code Authorization flow.&lt;/p&gt;
&lt;p&gt;By default, credentials are stored in the MacOS Keychain after authentication and are removed from the keychain whenever the administrator signs out of the MCP server. &lt;/p&gt;
&lt;p&gt;Further, no scopes are selected by default: an administrative user is asked to select them.&lt;/p&gt;
&lt;hr&gt;

&lt;p style=&#34;text-align: right;&#34;&gt;[4] &lt;a href=&#34;https://autho.com/blog/announcement-auth0-mcp-server-is-here/&#34;&gt;The Auth0 MCP Server is here&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Remote MCP servers&lt;/h2&gt;
&lt;p&gt;A remote MCP server operates as a web service. If the MCP specification is implemented faithfully, an MCP client establishes a long-lived HTTP connection with the server, with session management handled by token- based authentication.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&#34;https://modelcontextprotocol.io/specification/2025-03-26/basic/authorization&#34;&gt;March 26, 2025&lt;/a&gt; release of the Model Context Protocol specification stipulated that where authorization is required, OAuth 2.1 is the appropriate method:&lt;/p&gt;
&lt;p&gt;&lt;i&gt;MCP auth implementations MUST implement OAuth 2.1 with&amp;nbsp;appropriate security measures for both confidential and public clients.&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;Atlassian was among the first enterprise software vendors to offer a r&lt;a href=&#34;https://www.atlassian.com/platform/remote-mcp-server&#34;&gt;emote MCP server&lt;/a&gt; for customers. This offers a simple, OAuth-capable alternative to a community server that preceded it by several months.&lt;/p&gt;
&lt;p&gt;A comparison between the official remote MCP server and the local &amp;quot;community&amp;quot; developed local server is instructive.&lt;/p&gt;
&lt;p&gt;When the community server discovers authentication methods available in a local .env (configuration) file, any passwords configured for basic authentication takes precedence over any configured Personal Access Tokens, which in turn take precedence over OAuth credentials.&lt;/p&gt;
&lt;p&gt;The authors of this plugin plainly state that they have optimized for developer convenience over security.&lt;/p&gt;
&lt;p&gt;Atlassian&#39;s official remote MCP server, by contrast, includes &lt;a href=&#34;https://community.atlassian.com/forums/Atlassian-Remote-MCP-Server/Atlassian-Remote-MCP-Server-beta-now-available-for-desktop/ba-p/3022084&#34;&gt;localhost support&lt;/a&gt; in order to deliver OAuth-based log-in and consent for all users, including those connecting from local IDEs like Cursor.&lt;/p&gt;
&lt;p&gt;This effectively removes the need for developers to copy and paste secrets into local configuration files. The configuration file simply references the remote service, and the user is asked to complete an OAuth Consent after successful authentication.&lt;/p&gt;
&lt;p&gt;And unlike Microsoft Copilot, which optimised for choice of authentication methods rather than a specific security outcome, OAuth is the only available authentication method in Atlassian&#39;s remote MCP server. Atlassian is also allowlisting which hosts (Al applications) are able to connect to this remote MCP server.&lt;/p&gt;
&lt;h2&gt;Securing agentic Al&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;The only question is which OAuth flow to use!&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;While remote MCP servers based in OAuth provide a more secure and standardized approach than proprietary plugins, the path ahead is far from settled. 20 Some of the remaining security challenges are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;How can we authorize Al agents to access protected resources, while always keeping the interactive (human) user in the loop?&lt;/li&gt;
&lt;li&gt;How can we reduce the management burden of writing authorization rules for each individual resource at the service provider level?&lt;/li&gt;
&lt;li&gt;How can we provide centralized policies and auditing of authorization grants?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In the remote MCP servers we assessed, Al agents were authorized with the same level of access to services as the user that authorized them. They are acting &amp;quot;on behalf of&amp;quot; a user to the fullest extent of what the user is authorized to do.&lt;/p&gt;
&lt;p&gt;This may not meet the bar for CISOs concerned about the risks of connecting Al agents to data they are duty-bound to protect. Enterprise administrators will not be content to let service providers be the final authority on what tools the MCP server provides.&lt;/p&gt;
&lt;p&gt;A centralized administrator can&#39;t, in the Atlassian example, write policies that allow users to authorize Al agents to read and write Confluence wiki pages, but deny the ability to modify Jira tickets. Administrators can&#39;t choose specific projects that they don&#39;t want Al agents to access. If the user can access it, so can the agent.&lt;/p&gt;
&lt;p&gt;The IETF draft &lt;a href=&#34;https://datatracker.ietf.org/doc/draft-parecki-oauth-identity-assertion-authz-grant/&#34;&gt;OAuth Identity Assertion Grant&lt;/a&gt;, authored by current and former Okta architects, aims to solve this problem. This grant combines two existing standards - the &lt;a href=&#34;https://datatracker.ietf.org/doc/html/rfc8693&#34;&gt;OAuth 2.0 Token Exchange&lt;/a&gt; and &lt;a href=&#34;https://datatracker.ietf.org/doc/html/rfc7523&#34;&gt;JWT Profile for OAuth 2.0 Authorization Grants&lt;/a&gt; into a grant that provides enterprise control and visibility. &lt;/p&gt;
&lt;p&gt;Using this approach, administrators are able to configure centralized policies that ensure an SSO-protected user can authorize an Al agent to access data in multiple applications where a trust relationship has already been established.&lt;/p&gt;
&lt;p&gt;The CISO would again be able to limit the scope of what clients (in this case, Al agents) can access in a protected resource. Okta is working with Independent Software Vendors (ISVs) to bring these capabilities to customers under the newly-announced &lt;a href=&#34;/content/okta-www/jp/ja-jp/newsroom/press-releases/okta-introduces-cross-app-access-to-help-secure-ai-agents-in-the.html&#34;&gt;Cross App Access&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Concluding remarks&lt;/h2&gt;
&lt;p&gt;As an industry we now have some important decisions to make in order to safely enjoy the benefits of connecting protected resources to agentic Al. &lt;/p&gt;
&lt;p&gt;We must resist the temptation to repurpose authentication methods that were already unsuited to connecting systems over the public internet, let alone systems that can act with autonomy. As Al agents seek and are granted broader sets of permissions, the &amp;quot;blast radius&amp;quot; of any single compromise will be greatly amplified. A single breach could expose significantly more data and critical systems than before.&lt;/p&gt;
&lt;p&gt;We must instead adopt flows that are built for the Al era - narrowly scoped, user-delegated access flows that use ephemeral, auditable tokens, providing the CISO with some long overdue control and visibility.&lt;/p&gt;
&lt;h2&gt;Appendix: Protective Controls&lt;/h2&gt;
&lt;h3&gt;Recommendations for Service Providers&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Embrace OAuth 2.1 as the minimum viable authorization model for Model Context Protocol (MCP) servers.&lt;/li&gt;
&lt;li&gt;Subscribe to updates on MCP to keep abreast of new developments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Recommendations for Developers&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Restrict the use of static API tokens to development and test environments only (no production data) and apply the minimum scopes required.&lt;/li&gt;
&lt;li&gt;When developing locally, use OS-level secret vaults (MacOS keychain, Windows Credential Manager) to dynamically fetch secrets at runtime.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Modify the permissions of .env and other configuration files as well as the local log files of Al applications such that only your user account can read or modify them.&lt;/li&gt;
&lt;li&gt;List all configuration and log files in .gitignore to guard against accidentally committing them to version control systems.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Recommendations for Security Teams&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Restrict development activities to corporate-issued, hardened workstations.&lt;/li&gt;
&lt;li&gt;Require phishing resistant authentication for access to corporate resources.&lt;/li&gt;
&lt;li&gt;Use dedicated secrets management solutions for production credentials.&lt;/li&gt;
&lt;li&gt;Manage and govern membership of groups with access to container resources, and ensure the docker daemon (process) is configured to avoid exposure.&lt;/li&gt;
&lt;li&gt;Require OAuth 2.1 flows to authorize client access to corporate resources.&lt;/li&gt;
&lt;li&gt;For use cases where the risks of using static API tokens are accepted:&lt;ul&gt;
&lt;li&gt;Educate developers about the risks of using with long-lived tokens.&lt;/li&gt;
&lt;li&gt;Allowlist requests using the token to the known IP range of the corresponding MCP server.&lt;/li&gt;
&lt;li&gt;Deny interactive access to applications using the service account linked to the API token, or in the very least require high-assurance multifactor authentication challenges to access it.&lt;/li&gt;
&lt;li&gt;Proactively hunt for tokens stored in plaintext on servers, in files, in code repositories, in logs and in messaging and collaboration apps.&lt;/li&gt;
&lt;li&gt;Monitor for abuse of tokens.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
]]>
                </description>
                <pubDate>Sun, 29 Jun 2025 16:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,threat-insights,ciam,iam,ai,malware,token-replay</category>
                
                
            </item>
        
    </channel>
</rss>
