<?xml version="1.0" encoding="UTF-8" ?>

<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <atom:link rel="self" href="https://www.okta.com/pt-br/blog/threat-intelligence.rss"/>
        <link>https://www.okta.com/pt-br/blog/threat-intelligence</link>
        <title>Threat Intelligence | Blog | Okta</title>
        <description>
            <![CDATA[As equipes de Inteligencia de Ameacas e Defesa Cibernetica da Okta fornecem inteligencia de ameacas oportuna, indicadores de comprometimento e contramedidas tecnicas contra ataques baseados em identidade.]]>
        </description>
        <pubDate>Fri, 28 Aug 2026 21:40:50 +0000</pubDate>
        
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/intrusion-actors-self-serve-their-way-into-accounts/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/intrusion-actors-self-serve-their-way-into-accounts/</link>
                <title>How to stop attackers from self-serving their way into accounts</title>
                <description>
                    <![CDATA[&lt;h2&gt;Executive Summary&lt;/h2&gt;
&lt;p&gt;Over the last 12 months, Okta Threat Intelligence has observed a growing number of attacks in which users are tricked into approving attacker-initiated MFA enrollments and password resets.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We have observed numerous related clusters of activity in which threat actors have tested, iterated on, and scaled these social engineering attacks.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;One in five of the proactive notifications Okta sent to customers over the last month related to phishing domains that included the string &#34;passkey&#34;. The most recent campaign observed (&lt;a href=&#34;https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/&#34;&gt;O-UNC-066&lt;/a&gt;) used a passkey enrollment pretext to gain persistent access to Entra accounts.&lt;/p&gt;
&lt;p&gt;Strengthening MFA enrollment and account recovery now needs to be a priority for every identity team, irrespective of platform or use case.&lt;/p&gt;
&lt;h2&gt;Threat Analysis&amp;nbsp;&lt;/h2&gt;
&lt;p&gt;Until 2025, the largest share of social engineering activity we observed was impersonating IT support and other helpdesk staff to trick users into entering their password and OTP on attacker-controlled phishing sites.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This category of credential phishing is rendered ineffective when organizations require the use of &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/phishing-resistant-auth.htm&#34;&gt;phishing resistant authenticators&lt;/a&gt; in policy. Under phishing resistant policy conditions, even when a user is tricked into visiting an attacker-controlled site, the user is unable to share their access credentials.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Several clusters of threat activity have since adapted to their target&#39;s adoption of phishing resistance by using methods of attack that bypass the need to steal and replay a user&#39;s credentials.&lt;/p&gt;
&lt;p&gt;The list of threat activity clusters below, presented chronologically from oldest to most recent, highlights some of these tactics.&lt;/p&gt;
&lt;table border=&#34;1&#34; cellspacing=&#34;1&#34; cellpadding=&#34;1&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;&lt;p&gt;Threat Actor&lt;/p&gt;
&lt;/th&gt;
&lt;th&gt;&lt;p&gt;Targeted Process&lt;/p&gt;
&lt;/th&gt;
&lt;th&gt;&lt;p&gt;TTPs&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/mapping-a-phishing-as-a-service-operation-to-extortion-campaigns&#34;&gt;O-UNC-025&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Enrollment (passkey enrollment)&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Attacker impersonates the security team of the targeted organization to drive users to a phishing page that encourages them to set up a passkey.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/voice-based-social-engineers-target-crm&#34;&gt;O-UNC-028&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Recovery (password reset)&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Attacker impersonates the employer&#39;s IT helpdesk, lures targets to a phishing page and/or to authorize an attacker-controlled application.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/vishing-operators-synchronize-phishing-sites-to-their-script-for-hybrid-social-engineering-attacks&#34;&gt;O-UNC-045&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Enrollment&lt;br&gt;
(passkey or authenticator app enrollment)&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Attacker impersonates the employer&#39;s IT helpdesk in voice calls to drive targets to credential phishing sites.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/it-support-impersonated-in-requests-for-password-resets&#34;&gt;O-UNC-053&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Recovery (password reset)&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Attacker impersonates the employer&#39;s IT helpdesk, and uses urgency around the need for a password reset as a pretext.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/vishing-actors-target-microsoft-entra-passkey-enrollment&#34;&gt;O-UNC-066&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Enrollment (passkey enrollment)&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Attacker impersonates the employer&#39;s IT team in voice calls to drive targets to credential phishing sites, uses stolen credentials to enroll an attacker-controlled passkey in the user&#39;s account.&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/self-service-recovery-abused-using-vishing&#34;&gt;O-UNC-067&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Recovery (password reset)&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Attacker simultaneously triggers the &amp;quot;forgot password&amp;quot; flow while on the call, socially engineers the user into approving the reset&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;Notably, we have yet to observe the threat actor Okta tracks as &lt;b&gt;O-UNC-067&lt;/b&gt; using credential phishing kits in order to take over accounts.&lt;/p&gt;
&lt;p&gt;This intrusion actor, active since at least June 2026, selectively targets organizations configured to allow self-service password reset (SSPR).&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The threat actor first performs reconnaissance on targets to assess whether a link to trigger a password reset is accessible, and to determine what MFA challenges apply to verify the user&#39;s identity when this password reset is triggered. If a SSPR option is enabled and the user is able to verify their identity during that flow using MFA factors that are not phishing resistant, the attacker calls their target while simultaneously triggering the password reset flow.&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Breaking down the account recovery process&lt;/h2&gt;
&lt;h3&gt;Minimum viable defense&lt;/h3&gt;
&lt;p&gt;Irrespective of whether a social engineering campaign targets authenticator enrollment (e.g., O-UNC-066) or targets authenticator recovery (e.g., O-UNC-067), the success or failure of the attack hinges on the target&#39;s org-level account management policies.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In the weakest account management configuration:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;A password reset link is available on a public sign-in page&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;MFA enrollment policies allow verification of the user&#39;s identity via any MFA factor&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;MFA enrollment policies allow verification from any IP address&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This configuration may be appropriate for some customer identity use cases, but less so for workforce customers. An attacker that has engaged a targeted user on the phone can trigger the password reset from their device while convincing the user to share an OTP or accept a push request to approve the reset event.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Okta administrators can very easily add friction directly in the MFA enrollment policy by:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Requiring additional verification (beyond a single factor challenge) to initiate the reset, and&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Restricting the ability to use self-service features to trusted IP ranges.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This adds friction that prevents opportunistic attacks, but would not withstand a determined adversary. A social engineering actor that triggers the self-service event is in a position to select from a list of available verification challenges during recovery, and will always choose the weakest, most &#34;phishable&#34; method of authentication.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;That&#39;s why every Okta customer should be taking a close look at Okta account management policies.&lt;/p&gt;
&lt;h3&gt;Applying phishing resistance to authenticator enrollment&lt;/h3&gt;
&lt;p&gt;Okta &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/oamp.htm&#34;&gt;account management policies&lt;/a&gt;&amp;nbsp;(AMPs) were originally introduced to support the authenticator lifecycle requirements of organizations that use passwordless authentication. Increasingly, these policies should also be viewed as a configuration tool that protects all authenticator enrollment and recovery flows from social engineering attacks.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;AMPs offer administrators the same rich set of policy constraints to account recovery that were previously only available to authentication. AMPs can be used to require verification using phishing resistant factors, managed devices, trusted networks or a range of other criteria, effectively applying &#34;zero trust&#34; to the account recovery process.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Okta Threat Intelligence recommends the use of Okta account management policies to apply phishing resistance to authenticator enrollment and recovery. AMPs can require a user to verify their identity using a phishing resistant authenticator before they add or modify an authenticator.&lt;/p&gt;
&lt;p&gt;In the strongest account management configuration available, user accounts are bootstrapped using &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/onboard-with-preenrolled-yubikey.htm&#34;&gt;pre-registered physical security keys&lt;/a&gt;, and the account management policy always requires that the user verifies their identity using a phishing resistant factor before they can add or modify an authenticator. This neutralizes attacks on both authenticator enrollment and recovery. Where (rare) edge cases emerge, Okta integrates with &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/idvs-as-idps.htm&#34;&gt;identity verification services&lt;/a&gt; that require a user to provide a government-issued ID and satisfy a liveness check to initiate recovery.&lt;/p&gt;
&lt;p&gt;The next strongest approach is to use Okta AMPs, groups and event hooks to gradually raise the enrollment assurance bar for workforce users that are not already enrolled in a sufficient number of phishing resistant authenticators.&lt;/p&gt;
&lt;p&gt;Under such a scenario, the top (first evaluated) AMP rule might allow a user to add or modify a factor if the request comes from a managed device and the user satisfies a phishing-resistant MFA challenge. The aim should be for all users to progressively be added to the group in scope for this rule and subsequently be constrained to only using phishing resistant factors during factor lifecycle events. Users that trigger policy rules beneath it should be prioritized for migration.&lt;/p&gt;
&lt;p&gt;The next rule might constrain a user in whatever way possible until the user has enrolled in a sufficient number of phishing resistant authenticators. Users may be required to satisfy an Identity Verification (IdV) challenge, for example, or be temporarily allowed to verify their identity using weaker authenticators for their first few days of onboarding if they enroll from a trusted network. Event hooks or Okta Workflows can also be used to automatically advance users into groups with stronger assurance requirements as they meet the necessary criteria.&lt;/p&gt;
&lt;p&gt;Always remember to add a catch-all deny as the final (bottom) rule in any policy, to prevent any unintended access scenarios.&lt;/p&gt;
&lt;h3&gt;Applying phishing resistance to authenticator recovery&lt;/h3&gt;
&lt;p&gt;The key to phishing resistant recovery is to enroll users in a sufficient number of phishing resistant authenticators to account for any loss or disruption of a single device.&lt;/p&gt;
&lt;p&gt;One of the greatest strengths of the Okta Verify client is that there is zero marginal cost for a user to enroll multiple devices in their Okta Verify account. A user can enroll from their managed laptop and smartphone, for example.&lt;/p&gt;
&lt;p&gt;When every workforce user is enrolled in multiple phishing resistant factors (Okta Verify installs) across more than one device, the number of account recovery events that require the helpdesk falls considerably. If a user loses a device or if the device is unresponsive, they will still have strong, phishing-resistant authenticators enrolled on a second device (e.g., smartphone vs laptop) or via an external security key which they can use to enroll a new or replacement device.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Subsequently there is no need to include a &#34;forgot password&#34; link on the sign-in page, and there is no need to offer weaker account management policies.&lt;/p&gt;
&lt;h2&gt;Indicators&lt;/h2&gt;
&lt;p&gt;Indicators associated with the clusters of activity discussed above are all available to the security contacts of Okta customers at:&amp;nbsp;&lt;br&gt;
&lt;a href=&#34;https://security.okta.com/?product=oktathreatintelligence&#34;&gt;https://security.okta.com/?product=oktathreatintelligence&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Recommendations&lt;/h2&gt;
&lt;table border=&#34;1&#34; cellspacing=&#34;1&#34; cellpadding=&#34;1&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;&lt;p&gt;ATT&amp;amp;CK technique&lt;/p&gt;
&lt;/th&gt;
&lt;th&gt;&lt;p&gt;Tactic&lt;/p&gt;
&lt;/th&gt;
&lt;th&gt;&lt;p&gt;Control&lt;/p&gt;
&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;T1590 / T1591&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Reconnaissance&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Restrict recovery operations for workforce users to behind authenticated user settings. If a workforce organization is configured to support self-service recovery (the &amp;quot;forgot password&amp;quot; flow), consider restricting the IP range from which the sign-in page can be accessed to a known or trusted network using Okta network zones.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;T1583 / T1584&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Resource Development&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Deny requests from known anonymizing services and proxies using &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/network/about-enhanced-dynamic-zones.htm&#34;&gt;enhanced dynamic zones&lt;/a&gt;.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;T1566 / T1598&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Phishing / Vishing&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Enroll users in strong authenticators such as &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/fp/fp-main.htm&#34;&gt;Okta FastPass&lt;/a&gt;, &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-passkeys.htm&#34;&gt;passkeys&lt;/a&gt; or &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/smart-card-authenticator.htm&#34;&gt;smart cards&lt;/a&gt; and enforce phishing resistance in policy. Establish, communicate and evangelise methods of verifying the identity of helpdesk personnel when they contact users. Apply &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/oamp.htm&#34;&gt;Okta account management policies&lt;/a&gt; that constrain the ability to modify authenticators. Apply &lt;a href=&#34;https://sec.okta.com/articles/2025/12/account-recovery-without-password-resets/&#34;&gt;temporary access codes&lt;/a&gt; as a preferred method for recovering access after identity verification.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;T1078&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Valid Accounts (Initial Access)&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Okta authentication policies can be used to restrict access to user accounts based on a range of customer-configurable prerequisites. We recommend administrators restrict access to sensitive applications to devices that are &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/managed-main.htm&#34;&gt;managed&lt;/a&gt; by Endpoint Management tools and &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/edr-integration-main.htm&#34;&gt;protected by endpoint security tools&lt;/a&gt;.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;T1621&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;MFA Request Generation&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Enroll users in strong authenticators such as Okta FastPass, FIDO2 WebAuthn, and smart cards and enforce phishing resistance in policy.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;T1098.005&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Account Manipulation - Device Registration&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Apply &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/oamp.htm&#34;&gt;Okta account management policies&lt;/a&gt; that constrain the ability to modify authenticators.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;&lt;b&gt;Nick Connolly &lt;/b&gt;contributed to this article.&lt;/p&gt;
]]>
                </description>
                <pubDate>Thu, 09 Jul 2026 16:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,iam,social-engineering</category>
                
                <dc:creator>Brett Winterford</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/</link>
                <title>Vishing actors target Entra passkey enrollment</title>
                <description>
                    <![CDATA[&lt;h2&gt;Executive Summary&lt;/h2&gt;
&lt;p&gt;Since April 2026, a threat actor tracked as O-UNC-066 (also known as &amp;quot;Pink&amp;quot; by Palo Alto Networks Unit 42) has deployed a panel-controlled phishing kit targeting the passkey enrollment process for Microsoft 365 customers.&lt;/p&gt;
&lt;p&gt;Okta has observed the targeting of enterprise organizations across the food and beverage, technology, healthcare, automotive, construction, and aviation industries by this cluster of activity. The primary motivation of the threat actors is data extortion.&lt;/p&gt;
&lt;p&gt;The threat actor registers domains that incorporate the word passkey as part of a voice-enabled phishing (&#34;vishing&#34;) scheme. The threat actor then calls targeted users on the phone in an attempt to persuade them that they need to register a new passkey. &lt;/p&gt;
&lt;p&gt;Users are directed to a phishing kit that closely mimics the Microsoft passkey enrollment process. It appears engineered to convince a targeted user they are in the process of enrolling a passkey with Microsoft, while the threat actor simultaneously registers their own passkey in the targeted user&#39;s Microsoft account.&lt;/p&gt;
&lt;p&gt;This pretext is well-timed - as of May 2026, Microsoft administrators have been able to create &lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/whats-new#general-availability---support-for-passkeys-in-microsoft-entra-id-registration-campaign&#34;&gt;passkey registration campaigns&lt;/a&gt; that remind or &#34;nudge&#34; users to enrol in passkeys at sign-in, and in &lt;a href=&#34;https://mc.merill.net/message/MC1221452&#34;&gt;some circumstances&lt;/a&gt; these nudges are on by default.&lt;/p&gt;
&lt;p&gt;Threat actors have used this well-intentioned security upgrade as a pretext for abusing the enrolment process to further their objectives.&lt;/p&gt;
&lt;p&gt;Our analysis of the phishing kit revealed that it does not attempt to handle federation to third-party Identity Providers such as Okta. Subsequently, we have not observed the compromise of Microsoft accounts directly.&lt;/p&gt;
&lt;h2&gt;Threat Analysis&lt;/h2&gt;
&lt;p&gt;In the threat activity we observed, the threat actor creates per-target subdomains that mimic Microsoft Entra ID login pages. The pages are customized using each victim organization&#39;s legitimate branding. Generic Microsoft styling is loaded from Microsoft&#39;s Content Delivery Network, while the branding elements relevant to each victim organization (logo and background) is pre-staged per subdomain as part of the configuration for any given target and served from the backend of the phishing kit.&lt;/p&gt;
&lt;p&gt;The kit is not a transparent Adversary-in-the-Middle (AitM) proxy, one of the most frequently seen types of phishing kits designed to collect credentials, MFA tokens and session tokens. It is an operator-controlled PHP panel in which a threat actor steers victims through various stages of authentication in close to real-time using a 1-second heartbeat polling mechanism. The operator can use the kit to adapt the user experience to each victim&#39;s MFA requirements (TOTP, push notification with number matching, SMS OTP) during the session. This operational design is consistent with the vishing tradecraft documented in Okta&#39;s November 2025 public blog post &amp;quot;&lt;a href=&#34;https://www.okta.com/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/&#34;&gt;Phishing kits adapt to the script of callers&lt;/a&gt;.&amp;quot; The caller can control and adjust in real time what phishing pages and notifications a targeted user sees.&lt;/p&gt;
&lt;p&gt;It is likely that the threat actor uses the kit to takeover the user account and trick the user into approving an attacker-initiated registration of a passkey.&lt;/p&gt;
&lt;p&gt;Okta Threat Intelligence used code derived from the phishing kit to recreate the following flow, which closely resembles the passkey registration process for Microsoft Entra.&lt;/p&gt;
&lt;p&gt;The first page of the phishing kit (&lt;b&gt;/gate&lt;/b&gt;) reveals a page loading icon while the phishing kit performs anti-analysis checks. The second page (&lt;b&gt;/identify&lt;/b&gt;) requests a username. The phishing kit did not redirect to a federated Identity Provider at the time of our analysis.&lt;/p&gt;
&lt;p&gt;The next page (&lt;b&gt;/password&lt;/b&gt;) challenges the user for a password. The captured credentials are sent in a POST request with a timestamp and Id to an operator panel at &lt;b&gt;/backend.php&lt;/b&gt;.&lt;/p&gt;
&lt;p&gt;Our assumption is that a phishing kit operator (which may be a different individual to the caller on the phone) captures the credentials of the targeted user within a few seconds and enters them at the legitimate Microsoft sign-in page for the targeted tenant.&lt;/p&gt;
&lt;p&gt;The targeted user then sees a (&lt;b&gt;/processing&lt;/b&gt;) page that presents another loading screen while the phishing kit awaits the operator&#39;s next instruction. Our assumption is that this small delay is required for a threat actor to authenticate to the user&#39;s legitimate Microsoft account using the stolen credentials, to observe what MFA challenges are presented, and select the next page of the phishing kit to present to the user.&lt;/p&gt;
&lt;p&gt;next page of the phishing kit to present to the user.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If the operator chooses or is forced to complete an SMS OTP challenge, the user is directed to a page called &lt;b&gt;/submit-otp&lt;/b&gt;. The captured OTP is sent in a POST request to the operator panel at &lt;b&gt;/backend.php&lt;/b&gt;.&lt;/li&gt;
&lt;li&gt;If the operator chooses or is forced to complete a TOTP challenge, the user is directed to a page called &lt;b&gt;/submit-authenticator&lt;/b&gt;. The captured OTP is sent in a POST request to the operator panel at &lt;b&gt;/backend.php&lt;/b&gt;.&lt;/li&gt;
&lt;li&gt;If the operator chooses or is forced to complete a Push MFA challenge, the user is directed to a page called &lt;b&gt;/approve-authenticator &lt;/b&gt;(see image below) and asked to enter the number supplied by the operator into their authenticator app.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;At this stage of an attack, the user has been tricked over the phone into approving the attacker&#39;s access to their Microsoft 365 account.&lt;/p&gt;
&lt;p&gt;In keeping with the passkey pretext, threat actors can then direct users to the &lt;b&gt;/passkey/register&lt;/b&gt; page, which asks the user to create a passkey.&lt;/p&gt;
&lt;p&gt;The phishing kit appears to prey on lack of user familiarity with passkey authentication. In a real passkey registration ceremony, the user might expect a system dialog to register a passkey on their device. The passkey pages in this phishing kit appear to mimic this process without registering a passkey.&lt;/p&gt;
&lt;p&gt;At the &lt;b&gt;/passkey &lt;/b&gt;page, the targeted user is presented with a Microsoft-branded page that encourages the user to &#34;save your recovery key&#34; from an attacker-controlled list of BIP-39 phrases. This closely resembles the methods used in some cryptocurrency applications to generate memorable seed phrases.&lt;/p&gt;
&lt;p&gt;A subsequent &lt;b&gt;/passkey/check&lt;/b&gt; page asks the user to verify the final word used in the seed phrase.&lt;/p&gt;
&lt;p&gt;We are not aware of any direct applicability of BIP-39 seed phrases to Microsoft Entra or its passkey registration process. An attacker that has already gained unauthorized access to a user account can create their own recovery codes using a process that does not require any input from the real account holder.&lt;/p&gt;
&lt;p&gt;It is likely that these passkey-themed pages are available to the phishing kit operator as a sleight of hand. It is a distraction to keep a user occupied on a task while the threat actor enrolls their own passkey in the legitimate Microsoft user account.&lt;/p&gt;
&lt;p&gt;The &lt;b&gt;/done &lt;/b&gt;page confirms that a passkey registration was successful. An unsuspecting user that does not fully understand how a passkey is enrolled may genuinely believe that they registered one with Microsoft simply by completing these otherwise meaningless tasks.&lt;/p&gt;
&lt;p&gt;The operator can choose when to push the &lt;b&gt;/done&lt;/b&gt; page to the user. At minimum it helps the phishing operation maintain the original pretext. Any time a user enrolls a passkey with Microsoft, the owner of the compromised account receives a legitimate Microsoft email to notify them that a new passkey had been registered in their account. During an attack, the passkey was actually enrolled by the threat actor directly with Microsoft, and the threat actor is in a position to name the passkey with something the targeted user would view as benign (perhaps even borrowing from the seed phrase selected by the targeted user). The passkey enrollment setup the targeted user experienced on the phishing site, by contrast, is likely to only exist to trick the user into thinking the attacker&#39;s enrollment was their own.&lt;/p&gt;
&lt;h2&gt;Infrastructure&lt;/h2&gt;
&lt;p&gt;Threat actors were observed creating subdomains for any given targeted entity under the following domains:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;assignpasskey[.]com (2026-06-14, Internet Domain Service BS Corp., DDoS-Guard)&lt;/li&gt;
&lt;li&gt;deploypasskey[.]com (2026-04-21, Tucows, DDoS-Guard)&lt;/li&gt;
&lt;li&gt;passkeydeploy[.]com (2026-04-23, Internet Domain Service BS Corp, DDoS-Guard)&lt;/li&gt;
&lt;li&gt;passkeyadd[.]com (2026-05-08, Tucows, DDoS-Guard)&lt;/li&gt;
&lt;li&gt;setpasskey[.]com (2026-05-23, IQWeb FZ-LLC)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So a campaign targeting &amp;quot;exampleentity&amp;quot; might be something like:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;exampleentity[.]setpasskey[.]com&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;The phishing infrastructure observed by Okta Threat Intelligence was hosted on DDoS-Guard (AS57724, Russia) and IQWeb FZ-LLC (AS59692, US).&lt;/p&gt;
&lt;h2&gt;Impact&lt;/h2&gt;
&lt;p&gt;The data extortion actors associated with the Pink phishing kit published a leak site on May 31, 2026. This site is used to extort and apply pressure to compromised entities in the public domain.&lt;/p&gt;
&lt;h2&gt;Recommendations&lt;/h2&gt;
&lt;p&gt;While this cluster of threat activity has not been observed impersonating Okta, similar campaigns have combined voice-based social engineering and operator-controlled phishing kits:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Public Blog Post&lt;/b&gt; (&lt;i&gt;publicly available&lt;/i&gt;)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.okta.com/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/&#34;&gt;Phishing kits adapt to the script of callers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Flash Advisory &lt;/b&gt;(&lt;i&gt;Okta customers only&lt;/i&gt;)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/it-support-impersonated-in-requests-for-password-resets&#34;&gt;IT Support Impersonated in Requests for Password Resets&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Threat Advisory &lt;/b&gt;(&lt;i&gt;Okta customers only&lt;/i&gt;)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/vishing-operators-synchronize-phishing-sites-to-their-script-for-hybrid-social-engineering-attacks&#34;&gt;Vishing Operators Synchronize Phishing Sites to their Script for Hybrid Social Engineering Attacks&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The recommendations below are specific to the defence of Okta customers.&lt;/p&gt;
&lt;table cellpadding=&#34;1&#34; cellspacing=&#34;1&#34; border=&#34;1&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;ATT&amp;amp;CK&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Tactic&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Control Recomendation&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;T1566&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Phishing&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Enroll users in strong authenticators such as Okta FastPass, passkeys or &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/smart-card-authenticator.htm&#34;&gt;smart cards and enforce phishing resistance in policy.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Establish, communicate and evangelise methods of verifying the identity of helpdesk personnel when they contact users.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;T1078&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Phishing&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Deny requests from locations where your organization does not offer services. Okta &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/network/about-enhanced-dynamic-zones.htm&#34;&gt;network zones&lt;/a&gt; allow administrators to set policies that deny access to Okta-protected applications by geolocation (country), ASN, IP, or other criteria.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;T1078&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Valid Accounts&amp;nbsp;&lt;br&gt;
&lt;span&gt;(Initial Access)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Okta authentication policies can be used to restrict access to user accounts based on a range of customer-configurable prerequisites. We recommend administrators restrict access to sensitive applications to devices that are &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/managed-main.htm&#34;&gt;managed by Endpoint Management tools&lt;/a&gt; and &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/edr-integration-main.htm&#34;&gt;protected by endpoint security tools.&lt;/a&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;T1078&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Valid Accounts&amp;nbsp;&lt;br&gt;
&lt;span&gt;(Initial Access)&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Notify users of every authenticator (factor) lifecycle event using &lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/healthinsight/notifications-factor-enroll.htm&#34;&gt;end user notifications.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;T1098&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Account Manipulation (Device Registration)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Apply &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/oamp.htm&#34;&gt;Okta Account Management Policies&lt;/a&gt; that constrain the ability to add or modify authenticators based on network context, device management status and enrolled authenticators.&lt;/p&gt;
&lt;p&gt;Specific guidance is provided in a supplementary note attached to the customer-only version of this threat advisory at:&lt;br&gt;
&lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/vishing-actors-target-microsoft-entra-passkey-enrollment&#34;&gt;https://security.okta.com/product/oktathreatintelligence/vishing-actors-target-microsoft-entra-passkey-enrollment&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Sun, 05 Jul 2026 16:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-insights,iam,social-engineering,phishing</category>
                
                
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/disrupting-shieldguard--a-security-extension-primed-to-drain-cry/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/disrupting-shieldguard--a-security-extension-primed-to-drain-cry/</link>
                <title>Disrupting ShieldGuard: a security extension primed to drain crypto wallets</title>
                <description>
                    <![CDATA[&lt;h2&gt;Executive summary&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence has discovered and helped industry partners to take down the infrastructure of a cryptocurrency scam called &#34;ShieldGuard&#34;.&lt;/p&gt;
&lt;p&gt;ShieldGuard claims to be a blockchain project that offers - through its promotion of a browser extension - a capability that blocks known threats to cryptocurrency wallets, such as phishing or malicious smart contracts.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The project was promoted using a multi-level marketing campaign in which users would be rewarded for early use of the extension (via a cryptocurrency &#34;airdrop&#34;) and for promoting the capability to other users.&lt;/p&gt;
&lt;p&gt;Our analysis of the browser extension, presented in detail below, revealed its true intent: ShieldGuard appears designed to harvest wallet addresses and other sensitive data for major cryptocurrency platforms including Binance, Coinbase, MetaMask, OpenSea, Phantom and Uniswap, as well as for users of Google services.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The extension also extracts the full HTML of pages after a user signs into Binance, Coinbase, OpenSea or Uniswap via their browser.&lt;/p&gt;
&lt;h2&gt;Threat analysis&lt;/h2&gt;
&lt;p&gt;ShieldGuard was promoted via a public website as a legitimate security application for users of Web3 services.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The creators of ShieldGuard also registered:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;A listing in the Google Chrome Store&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;A social media profile at x[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;A Telegram channel&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The web site and associated social media profiles for ShieldGuard claimed the extension would detect suspicious transactions prior to a user signing a request.&lt;/p&gt;
&lt;p&gt;The creators of the browser extension attempted to drive downloads by launching an &#34;airdrop&#34;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;An airdrop is a marketing campaign in which a blockchain-enabled service is &#34;bootstrapped&#34; by early adopters in the community. Early participants are issued coins or tokens that can be exchanged for some form of value if they sign-up prior to a specified date.&lt;/p&gt;
&lt;p&gt;Interested users were encouraged to download the browser extension and sign-up for a user account at a claim portal in order to be eligible for the distribution of these tokens.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The ShieldGuard website reassured potential users that the software would not need direct access to their crypto wallets: the extension would poll a central server for updates on known threats and identify them in the user&#39;s browser.&lt;/p&gt;
&lt;p&gt;Our analysis of the browser extension found that it includes a range of very different capabilities:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;The browser extension harvests cryptocurrency wallet addresses from any website a user visits, using the EIP-6963 wallet discovery protocol&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The browser extension exfiltrates full page content from cryptocurrency exchange and DeFi sites (which includes account balances, portfolio data, and transaction history)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The browser exfiltration is capable of executing arbitrary code on a device running the extension, as demonstrated through an ability to block access to legitimate websites on command and replace them with fake security warnings.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The browser extension tracks users via persistent UUIDs across all browsing sessions&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Malware analysis&lt;/h2&gt;
&lt;h3&gt;Analysis environment&lt;/h3&gt;
&lt;p&gt;To safely analyze the threat, we installed ShieldGuard browser extension and executed it within an isolated, containerized browser. Initial static analysis revealed that the extension&#39;s code was heavily obfuscated, a technique frequently employed by malicious actors to evade detection during review processes and to complicate reverse-engineering efforts.&lt;/p&gt;
&lt;h3&gt;Architecture and evasion techniques&lt;/h3&gt;
&lt;p&gt;ShieldGuard was revealed to be a sophisticated piece of malware designed to bypass the security restrictions of Chrome&#39;s Manifest V3. To achieve this, it bundles a complete custom JavaScript interpreter (vendor.js).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Bypassing Remote Code Execution Bans: Instead of using prohibited functions like eval(), the extension&#39;s background script fetches encoded script strings from a Command and Control (C2) server. It then uses its custom JS interpreter to parse and execute these scripts within the context of the victim&#39;s web pages. This allows the attackers to execute arbitrary remote code on demand without triggering Chrome&#39;s security policies.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Deceptive Permissions: Upon installation, the extension requests the permission to &amp;quot;Read and change all your data on all websites,&amp;quot; granting it full access to the victim&#39;s browsing activity.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Malicious payloads and data exfiltration&lt;/h3&gt;
&lt;p&gt;Dynamic analysis confirmed the following attack flow:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A user with the browser extension installed navigates to a web site&lt;/li&gt;
&lt;li&gt;The extension contacts the Command and Control server at shieldguards[.]net/scripts&lt;/li&gt;
&lt;li&gt;The server returns the EIP-6963 wallet discovery script&lt;/li&gt;
&lt;li&gt;The script discovers all installed wallets&lt;/li&gt;
&lt;li&gt;The script extracts the wallet addresses from discovered wallets&lt;/li&gt;
&lt;li&gt;All Ethereum addresses are extracted from discovered wallets&lt;/li&gt;
&lt;li&gt;If the user has navigated to Binance, Coinbase, OpenSea or Uniswap, the extension waits for a set period of time before capturing the full HTML of the page&lt;/li&gt;
&lt;li&gt;The HTML snapshot is exfiltrated&lt;br&gt;
&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Our analysis found that the C2 server at shieldguards[.]net actively delivers two primary payloads:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Payload 1: Wallet address harvester (all websites):&lt;/b&gt;&lt;br&gt;
A script is injected into every website the victim visits. It uses the EIP-6963 wallet discovery protocol to find all installed wallet extensions (e.g., MetaMask, Phantom, Coinbase Wallet), retrieve all associated Ethereum wallet addresses, and exfiltrate this list to the C2 endpoint at https://shieldguards[.]net/notifications.&lt;br&gt;
&lt;br&gt;
This provides the attackers with a comprehensive inventory of a victim&#39;s wallets and their browsing habits.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Payload 2: Page content snapshot (targeted crypto sites):&lt;/b&gt;&lt;br&gt;
For high-value targets, a second payload is delivered. After a five-second delay to allow the page to fully render, this script captures the entire page&#39;s HTML (document.documentElement.outerHTML) and sends it to https://shieldguards[.]net/snapshots. This allows the attackers to steal sensitive data directly from the DOM, including account balances, portfolio holdings, and transaction history.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Command &amp;amp; Control (C2) infrastructure&lt;/h3&gt;
&lt;p&gt;The browser extension communicates with a C2 server hosted at shieldguards[.]net, which is proxied through Cloudflare.&lt;/p&gt;
&lt;p&gt;The key C2 endpoints identified were:&lt;/p&gt;
&lt;table cellpadding=&#34;2&#34; cellspacing=&#34;2&#34; border=&#34;1&#34;&gt;
&lt;caption&gt;&amp;nbsp;&lt;/caption&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Endpoint&lt;/b&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&lt;b&gt;HTTP request method&lt;/b&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&lt;b&gt;Purpose&lt;/b&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/scripts&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;POST&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Delivers malicious JavaScript payloads.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/snapshots&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;POST&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Receives exfiltrated page HTML.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/notifications&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;POST&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Receives stolen data like wallet addresses.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/check/{domain}&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;GET&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Determines if a domain should be blocked or appear &amp;quot;safe&amp;quot;.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;/uninstall&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;GET&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Tracks when users uninstall the extension via a UUID.&lt;/p&gt;
&lt;br&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h3&gt;Attribution and linked campaigns&lt;/h3&gt;
&lt;p&gt;There is potential that the threat actors are Russian-speaking, based on a Russian error string (&amp;quot;??????: ?? ??????? ?????????? ?????&amp;quot;) and Cyrillic character support found within the custom JavaScript interpreter.&lt;/p&gt;
&lt;p&gt;The investigation also uncovered strong links to another malicious campaign known as &amp;quot;Radex.&amp;quot; We observed links between an administrative account used to set up an Auth0 tenant (radex4me@proton.me) and a Chrome extension ID associated with Radex (fkogigpebmhlbldifmjngmlooifljnif).&amp;nbsp; It is very likely that both campaigns are operatd by the same threat actor.&lt;/p&gt;
&lt;h2&gt;Disruption&lt;/h2&gt;
&lt;p&gt;&lt;br&gt;
Okta Threat Intelligence has worked with industry partners to:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Disable all sign-in functionality&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Remove the shieldguards[.]net domain from CDN services, revealing the website&#39;s origin server at Partner Hosting LTD, a bulletproof hosting provider&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Remove the shieldguards browser extension from the Google Chrome Store&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Remove the shieldguards[.]net domain from its domain registrar - which had the effect of disconnecting existing installs of ther browser extension from the C2 infrastructure.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Advice for end users&amp;nbsp;&amp;nbsp;&lt;/h2&gt;
&lt;h3&gt;Beware the &amp;quot;too good to be true&amp;quot; trap&lt;/h3&gt;
&lt;p&gt;While legitimate sign-up promotions exist, scammers frequently use the promise of free crypto or high returns to create a false sense of urgency. If an offer looks too good to be true, it almost certainly is.&lt;/p&gt;
&lt;h3&gt;Practice safer online browsing&lt;/h3&gt;
&lt;p&gt;Browser plugins are a common source of malware. Installing them gives unknown third parties full access to your browser&#39;s window, history, and potentially your passwords and session cookies.&lt;/p&gt;
&lt;p&gt;The best security advice is to limit if not eliminate browser plugins on the devices you use for access to sensitive accounts like crypto exchanges.&lt;/p&gt;
&lt;p&gt;If browser plugins are absolutely required, follow these strict guidelines:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Official Sources Only: Only install plugins from official storefronts (Chrome Web Store, Mozilla Add-ons, or Apple Safari Extensions). Do not rely on the presence of an extension in these stores or positive reviews in these stores as markers of trustworthiness. Malicious browser extensions can present a strong rating until such time as the access they provide is abused.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Restrict Permissions: Configure browser plugins to only activate when clicked, or restrict them to only run on specific, necessary websites.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Regular Audits: Regularly audit your installed extensions to remove or disable unnecessary ones.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Compartmentalize: Use a completely separate, clean browser (or a strict Private/Incognito mode where all plugins are disabled) exclusively for crypto transactions and sensitive work.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Protect your crypto wallets&lt;/h3&gt;
&lt;p&gt;Safeguard your digital assets against browser compromises by using a reputable offline hardware wallet, diligently double-checking pasted addresses and enabling phishing-resistant MFA.&lt;/p&gt;
&lt;h2&gt;Advice for Okta customers&lt;/h2&gt;
&lt;p&gt;We recommend allowlisting strategies that provide security teams the ability to control the execution of third-party code on any browser used for access to corporate resources. &lt;br&gt;
&lt;br&gt;
Two suggested approaches are provided below.&lt;/p&gt;
&lt;p&gt;1. Deploy Managed Chrome:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Restricting local admin rights on managed company devices&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Require a managed device for access to sensitive resources in Okta authentication policies&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Deploy a Managed Chrome browser to user devices&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Create an allowlist of approved browser extensions, removing the ability for users to add other extensions without admin approval&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Create a process for users to request new extensions&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;2. Advanced posture checks:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Require a managed device for access to sensitive resources in Okta authentication policies&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Deploy Okta Verify to user devices (&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/ov-installation.htm&#34;&gt;using the latest version available in the Okta Admin Console&lt;/a&gt;)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Use &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/device-assurance-adv-posture-check.htm&#34;&gt;advanced posture checks&lt;/a&gt; (part of Okta device assurance policies) to assess what browser extensions are running in the user browser at sign-in. Write authentication policies that allow access to sensitive resources from allowlisted browser extensions and deny access from all others.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Create &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/device-assurance-posture-check.htm&#34;&gt;custom remediation messages&lt;/a&gt; for users that are denied access to resources based on the extension running in their browser.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Create a process for users to request new extensions&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Indicators of Compromise&lt;br&gt;
&lt;br&gt;
&lt;/h2&gt;
&lt;table&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;b&gt;Type&lt;/b&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&lt;b&gt;Indicator&lt;/b&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;&lt;b&gt;Comment&lt;/b&gt;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;AS Number&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;AS215826&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Bulletproof host autonomous system serving malicious traffic&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Chrome extension ID&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;olnppmocapoaecjhkiilemmnkjbmabfj&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;ShieldGuard tools extension ID&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Chrome extension ID&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;fkogigpebmhlbldifmjngmlooifljnif&lt;/p&gt;
&lt;/td&gt;
&lt;td&gt;&lt;p&gt;Radex extension ID&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Mon, 16 Mar 2026 16:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,ciam,threat-insights,fraudulent-registration,identity-theft</category>
                
                <dc:creator>, Yang Wang, Simon Conant, Adam Smallhorn</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/vietnamese-cybercrime-operation-enables-fraudulent-account-signups/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/vietnamese-cybercrime-operation-enables-fraudulent-account-signups/</link>
                <title>Vietnam-based cybercrime markets enable account sign-ups at scale</title>
                <description>
                    <![CDATA[&lt;h2&gt;Executive summary&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence, working with our partners at the University of Cyprus, have connected a cluster of fraudulent account registration activity to a sprawling cybercrime ecosystem based in Vietnam.&lt;/p&gt;
&lt;p&gt;Fraudulent online accounts are more than just a nuisance; they are a critical tool for large-scale financial fraud. From spam to phishing to devastating interpersonal fraud scams, these accounts provide a veneer of legitimacy that allows criminals to abuse platforms and customers of those platforms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In late 2025, Okta Threat Intelligence&amp;nbsp;&lt;a href=&#34;/content/okta-www/br/pt-br/blog/threat-intelligence/opportunistic-sms-pumping-attacks-target-customer-sign-up-pages.html&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;investigated&lt;/a&gt; signup fraud campaigns using infrastructure clusters internally designated as O-UNC-036 that relied on disposable email addresses in order to execute SMS pumping attacks, which is also known as International Revenue Sharing Fraud (IRSF).&amp;nbsp; In this scheme, malicious actors automate the creation of puppet accounts in a targeted service provider. Fraudsters use these account registrations to trigger SMS messages to premium rate phone numbers and profit from charges incurred. This activity can prove costly for service providers who use SMS to verify registration information in customer accounts or to send multifactor authentication (MFA) security codes.&lt;/p&gt;
&lt;p&gt;In the course of this investigation, Okta Threat Intelligence and our partners observed links from O-UNC-036 to dozens of websites that cater to individuals who want to conduct online fraud. This cybercrime-as-a-service (CaaS) ecosystem provides paid infrastructure and services that make it easier for other individuals to conduct online fraud.&amp;nbsp; Many of these online storefronts sell user accounts that have been hijacked or created through automated means. This post will explain the threat that fraudulent registration poses to service providers, how it is executed and steps that can be taken to mitigate abuse.&lt;/p&gt;
&lt;h2&gt;Fuel for fraud&lt;/h2&gt;
&lt;p&gt;There is demand and a brisk trade for accounts on social media sites and services like LinkedIn, Instagram, Facebook, and TikTok. Fraudulent accounts can be leveraged in numerous ways that can impact the reputation of a service provider. Accounts can be used to send spam or to direct unsuspecting users to phishing sites. Fraudulent account registration is used to gain access to limited products such as concert tickets, to exploit free trials or manipulate product reviews. This all results in an erosion of trust in a service provider and a degraded experience for users.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Fraudulent accounts are also used to approach targets of interpersonal fraud scams:&amp;nbsp; cyber-enabled crimes that range from investment and cryptocurrency scams to romance and sextortion schemes. Often referred to as &#34;pig butchering,&#34; targets are persistently engaged online and over the phone in schemes designed to defraud them. These operations have exploded in recent years in southeast Asia, particularly in border areas near China, Myanmar, Thailand and Cambodia, and are run out of large compounds by organized criminal networks.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This activity has, according to an April 2025 &lt;a href=&#34;https://www.unodc.org/roseap/uploads/documents/Publications/2025/Inflection_Point_2025.pdf&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;report&lt;/a&gt; by the United Nations Office on Drugs and Crime, resulted in a &#34;surge of specialized service providers&#34; that feature a&amp;nbsp; &#34;range of merchants specializing in the sale of fraud kits, stolen data, malware, AI-driven tools, and various underground banking, money laundering and cybercrime services utilized by other criminals targeting victims globally.&#34;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This trade often happens in relatively open forums, on social networking sites, clear-web websites and on messaging platforms including Telegram. The tools enable fraud perpetrators to find targets, learn about them, gain their confidence and eventually cause them financial losses.&lt;/p&gt;
&lt;p&gt;&#34;When [scammers] use fake accounts to win the trust of people, they end up with a lot of personal data about them. They can do lots of damage to those victims,&#34; says &lt;a href=&#34;https://www.linkedin.com/in/hieu-minh-ngo-hieupc/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Hieu Minh Ngo&lt;/a&gt;, a Vietnamese cybercrime investigator who contributed to the U.N. report and runs &lt;a href=&#34;https://chongluadao.vn/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;ChongLuaDao&lt;/a&gt;, nonprofit scam-fighting cybersecurity awareness organization.&lt;/p&gt;
&lt;p&gt;The &#34;web shops&#34; we observed used website templates produced by a Vietnam-based web design and marketing company. We observed these cookie-cutter templates used for dozens of sites offering account-related products as well as other services used for fraud, such as falsely inflating the popularity of social media posts, &lt;a href=&#34;https://www.kcl.ac.uk/events/anatomy-of-a-phone-farm-hardware-platforms-infrastructure&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;phone farms&lt;/a&gt; for managing large numbers of accounts, residential proxies and &#34;anti-detect&#34; browsers, which are used to evade the tools used by security teams to detect account takeovers.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;While the activity we observed predominantly targets Vietnamese speakers, many of the fake account vendors using these e-commerce templates also seek English-speaking buyers, extending the reach of this threat beyond Vietnam.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In December 2023, Microsoft &lt;a href=&#34;https://www.microsoft.com/en-us/security/security-insider/risk-management/bold-action-against-fraud-disrupting-storm-1152&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;undertook legal action&lt;/a&gt; against a Vietnamese CaaS group that sold fraudulent created Outlook and Hotmail accounts. The group, Storm 1152, created and sold 750 million fraudulent Microsoft Outlook and Hotmail accounts that were used for fraud, ransomware and extortion.&amp;nbsp; The action temporarily disrupted Storm 1152. However, the group has since reformed, and Microsoft filed a second civil lawsuit in July 2024 in an effort to disrupt new infrastructure. We have not observed direct links between the activity we observed and Storm 1152.&lt;/p&gt;
&lt;h2&gt;Wanted: fake accounts&lt;/h2&gt;
&lt;p&gt;There is a chicken-and-egg problem fraudsters face when they need to create large numbers of synthetic user accounts with a service provider. Each new account requires a unique email address. Our insight into the fraudulent activity started with a set of disposable email domains used by O-UNC-036.&lt;/p&gt;
&lt;p&gt;There are a variety of email services that offer &#34;disposable&#34; email addresses to cater to users with privacy concerns. These addresses can be generated en-masse and the services are often designed to cater to users that will likely only use an account for a short time. Correspondence to an address is typically available via an online service, and the email address provided may only be functional for as little as 10 minutes before being disabled. For fraudulent registrations, this arrangement is fine, since users of the service have no intention of actually using the address and may need only to view its inbox once to receive a verification code.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Okta Threat Intelligence observed a flood of suspicious-looking account registrations using multiple disposable email domains, which given the nature of the services is a red flag that the registrations are not being used for legitimate purposes. Our analysis of email provider domains turned up visual similarities that led us to a sprawl of web-based storefronts hosted in Vietnam and involved in the sales of web-based accounts.&lt;/p&gt;
&lt;h2&gt;All about MMO (&#34;Make Money Online&#34;)&lt;/h2&gt;
&lt;p&gt;The website CMSNT.co appears similar to other marketing and website design services aimed at the e-commerce market.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&#34;We design websites for your online money-making ventures,&#34; the site reads. &#34;Automate your online money-making process.&#34;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;What follows is a series of tiles that advertise website templates.&lt;/p&gt;
&lt;p&gt;The website templates reveal a common theme: the sale of digital accounts for various types of services, including email providers, gaming sites, and social media services. However, there is no indication that CMSNT[.]co is involved itself in the sale of digital accounts or activity that could potentially violate computer crime laws.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Some templates are customized for the sale of accounts linked to video streaming, graphic design or AI chatbot service subscriptions, or for the sales of application software keys. Another template is a Social Media Marketing Panel, which appears to be designed as a storefront for a service that artificially boosts social media engagement on major social network sites. This inflation can include bogus &#34;likes&#34;, comments or views. CMSNT[.]co says that &#34;AI technology simulates real user behavior. No password required, just a public link. Trusted by over 15,000 customers.&#34;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Another template is customized for offering chron job services (scheduled tasks) using python, which can be used for tasks like web scraping.&lt;/p&gt;
&lt;p&gt;Our research revealed that CMSNT[.]co&#39;s templates are used by dozens of websites. But not everyone is paying CMSNT[.]co to use them. At some point the source code for some templates was &lt;a href=&#34;https://github.com/CMSNTSourceCode&#34; target=&#34;_blank&#34;&gt;leaked&lt;/a&gt;, resulting in some entities using the templates without paying for licenses.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;One of those freeloaders is Via17[.]com. &#34;Via&#34; is a slang term for hacked accounts, and it appears frequently on sites that are selling accounts. The compromised accounts may have been acquired using brute-force techniques, where attackers try different combinations of usernames and passwords, or from &#34;logs&#34; collected by information stealer (infostealer) malware. These types of malware logs, which can contain login credentials, payment card details, cryptocurrency wallet information and personally identifiable information extracted from infected devices, are routinely sold on underground forums and messaging platforms.&lt;/p&gt;
&lt;p&gt;In an &lt;a href=&#34;https://www.youtube.com/watch?v=jFGzpfAP8u8&#34; target=&#34;_blank&#34;&gt;instructional video&lt;/a&gt; on YouTube, a person affiliated with the site bills Via17[.]com as the &#34;#1 reputable website providing Facebook accounts.&#34; The video focuses on how people can access a Facebook account using a session token, which is a small data file that allows a user to remain signed into a website. Via17[.]com sells session tokens (also referred to as &#34;cookies&#34;) as part of some fake account offerings.&lt;/p&gt;
&lt;p&gt;One of the primary products at Via17[.]com is the resale of accounts from social networking sites. One package offers Vietnamese Facebook accounts with 10-50 friends with two-factor authentication enabled. More than 1,000 accounts are available at a price of 55,240 Vietnamese dong, or US$2.13 each. Other tiles advertise &#34;vintage&#34; Facebook accounts as old as 2006. Some accounts are listed as &#34;real&#34; accounts. It is unclear how Via17[.]com or its users have acquired them prior to sale.&amp;nbsp; &#34;Clone&#34; accounts are created by software, according to the site. Depending on the type of account purchased, the data provided includes a userid, password, the ability to collect 2FA codes or notifications, a recovery email address and session tokens.&lt;/p&gt;
&lt;p&gt;A similar account marketplace is nladsgiare[.]shop, which also runs the CMSNT[.]co website code. The advertisements for accounts on this site show the role that disposable email accounts play in the account trade. A section of the front page of the site advertises Facebook accounts that have Thai or &#34;foreign&#34; names that are linked to disposable email addresses from a service called mailclone[.]site.&lt;/p&gt;
&lt;p&gt;Anyone can generate an email address on mailclone[.]site. Content sent to the address - such as an email verification link - is visible directly on the site. The same style of verification is recommended for accounts on Via17[.]com, with the site recommending buyers get codes sent to accounts from another free, temporary e-mail service,&amp;nbsp; temp-mail[.]io.&lt;/p&gt;
&lt;p&gt;Via17[.]com recommends 11 other disposable email services that can be used for account registration.&lt;/p&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Preventing fraudulent account registration is a careful balance between preventing fraud and introducing undue friction on customers. (Users may be legitimately using masking or email forwarding services -&amp;nbsp; consider Apple&#39;s Hide My Email &lt;a href=&#34;https://support.apple.com/en-gb/guide/iphone/iphcb02e76f7/ios&#34; target=&#34;_blank&#34;&gt;feature&lt;/a&gt;). Organizations are typically prepared to tolerate a certain level of fraud to avoid events in which potential customers cannot complete a registration - this must be balanced against the risks an abundance of bogus accounts poses via a degraded customer experience.&lt;/p&gt;
&lt;h2&gt;Mitigations&lt;/h2&gt;
&lt;p&gt;&lt;b&gt;Auth0&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Auth0 customers have several tools at their disposal to mitigate fraudulent signups before, during and after the account creation process. Okta Threat Intelligence has written a&amp;nbsp; &lt;a href=&#34;https://auth0.com/docs/secure/attack-protection/playbooks/signup-attack-playbook&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;playbook&lt;/a&gt; to guide efforts to mitigate abuse.&lt;/p&gt;
&lt;p&gt;To protect their tenants from signup attacks, Auth0 customers can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Use &lt;a href=&#34;https://auth0.com/docs/secure/attack-protection/bot-detection&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Bot Detection&lt;/a&gt; to challenge bots with a CAPTCHA of your choice within the &lt;a href=&#34;https://auth0.com/docs/secure/attack-protection/bot-detection#configure-bot-detection&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;configured risk tolerance&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Tighten &lt;a href=&#34;https://auth0.com/docs/secure/attack-protection/suspicious-ip-throttling#signup-attempts&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Suspicious IP Throttling&lt;/a&gt; limits on signup to reduce the number of accounts attackers can make from individual IPs.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Create a &lt;a href=&#34;https://auth0.com/docs/secure/tenant-access-control-list&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Tenant Access Control List&lt;/a&gt; (ACL) rules, which denies observed malicious activity from sources based on indicators such as IPs, ASNs, geolocation values and JA3/JA4 signatures and has been &lt;a href=&#34;https://auth0.com/blog/tenant-access-control-list-prevent-signup-fraud/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;shown to help mitigate signup attacks&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href=&#34;https://support.auth0.com/center/s/article/Enforce-Email-Verification-With-Sending-Email-After-Each-Denied-Access&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Enforce email verification&lt;/a&gt; using post-login Actions or a one-time password.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href=&#34;https://support.auth0.com/center/s/article/How-to-combat-fradulent-signups-from-disposable-email-services&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Block registrations&lt;/a&gt; that use known disposable email domains with pre-user registration actions.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href=&#34;https://auth0.com/blog/detecting-signup-fraud-3-ways-to-use-auth0-logs-to-protect-your-business/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Detect signup attacks&lt;/a&gt; with Auth0&#39;s open source &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Security Detection Catalog&lt;/a&gt;, especially the rules detecting risks of signup fraud by &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/8b304980bb1b2ae0908c8d05a0e77dfae7f10ff8/detections/risk_of_signup_fraud_by_disposable_domains.yml&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;disposable domains&lt;/a&gt; and by &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/8b304980bb1b2ae0908c8d05a0e77dfae7f10ff8/detections/risk_of_signup_fraud_by_volume.yml&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;volume &lt;/a&gt;and &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/main/detections/many_unverified_accounts_created.yml&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;mass unverified account creation events&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Implement identity proofing tools, like those in the &lt;a href=&#34;https://marketplace.auth0.com/categories/identity-proofing&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Auth0 Marketplace&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;b&gt;Okta Customer Identity&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Okta Customer Identity also has controls that can be used to mitigate fraudulent sign up. Customers can block attackers before, during and after the signup process:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Identity Threat Protection, which is now in &lt;a href=&#34;/content/okta-www/br/pt-br/blog/product-innovation/identity-threat-protection-oci.html&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;early access&lt;/a&gt; for Okta Customer Identity, evaluates IP reputation and looks at behavioral signals to block scripted account signups and signins and detect when threat actors use compromised credentials to sign up for accounts.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Use Okta APIs or &lt;a href=&#34;https://marketplace.auth0.com/integrations/okta-workflows&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;Workflows&lt;/a&gt; to identify large batches of fraudulent registrations. Okta has published a sample &lt;a href=&#34;https://github.com/okta/customer-detections/tree/master/workflows/deactivate_ssr_users&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;workflow&lt;/a&gt; specifically to manage the abuse of self-service registration. The workflow compares the email address from a registration attempt and runs it against a customer-defined list of malicious or disposable domains. The workflow can be configured to deactivate these accounts.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Consider forcing verification of newly registered accounts via &lt;a href=&#34;https://developer.okta.com/docs/guides/authenticators-okta-email/aspnet/main/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;email link or OTP validation&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;Consider performing &lt;a href=&#34;https://help.okta.com/wf/en-us/content/topics/workflows/use-case-identity-proofing.htm&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;identity-proofing&lt;/a&gt; with specialist third-party providers for users of high value services.&lt;/li&gt;
&lt;li&gt;Consider blocking the most risky anonymizers and proxies by leveraging &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/network/about-enhanced-dynamic-zones.htm&#34; style=&#34;background-color: rgb(255,255,255);&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;enhanced dynamic network zones&lt;/a&gt;. This stops attackers from reaching registration pages from high-risk services. Network blocking is the most extreme response and may not be an option for some.&lt;/li&gt;
&lt;/ul&gt;
]]>
                </description>
                <pubDate>Sat, 28 Feb 2026 16:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,ciam,threat-insights,fraudulent-registration</category>
                
                <dc:creator>Mathew Woodyard, Angelos K. Marnerides, Michael Photiades, Jeremy Kirk</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/universities-contract-cheating-services/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/universities-contract-cheating-services/</link>
                <title>Universities exposed to account takeover risk from contract cheating services</title>
                <description>
                    <![CDATA[&lt;h2&gt;Executive Summary&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence has identified extortion campaigns that target university students.&lt;/p&gt;
&lt;p&gt;These operations often masquerade as &amp;quot;tutoring&#34; or &#34;proctoring&#34; services, but function as &lt;a rel=&#34;noopener noreferrer&#34; target=&#34;_blank&#34; href=&#34;https://www.teqsa.gov.au/preventing-contract-cheating/what-contract-cheating-and-methods-reduce-it&#34;&gt;contract cheating operations&lt;/a&gt; that feed sophisticated identity-theft and financial-crime rackets.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;These &lt;a rel=&#34;noopener noreferrer&#34; target=&#34;_blank&#34; href=&#34;https://www.insidehighered.com/news/students/academics/2024/03/28/sting-operation-fools-proctoring-service-blackmail-attempted&#34;&gt;extortion campaigns&lt;/a&gt; appear to first involve local and online recruiting efforts that seek students as clients.&lt;/p&gt;
&lt;p&gt;In order for third parties to complete academic work on behalf of a student, students are asked to facilitate access for the proctoring services to academic systems, in some cases by sharing authentication credentials.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;These third parties then press the students for further payment by threatening to expose the student for cheating.&lt;/p&gt;
&lt;p&gt;The extortionists have been observed logging in from VPNs, residential, and mobile IP addresses in Kenya.&lt;/p&gt;
&lt;p&gt;Okta Threat Intelligence has collaborated with several universities and people to study this activity, including Glen Woolley, Andrew Tolhurst, and Damien Mathieson of the Cyber Security Operations team at the University of Sydney.&lt;/p&gt;
&lt;p&gt;This is not merely a matter of academic integrity; it is a &lt;a href=&#34;https://www.qaa.ac.uk/docs/qaa/guidance/contracting-to-cheat-in-higher-education-third-edition.pdf&#34;&gt;threat to student safety and standards&lt;/a&gt;, the university&#39;s security perimeter and as one research institute posits, &lt;a href=&#34;https://www.lowyinstitute.org/the-interpreter/contract-cheating-how-academic-dishonesty-could-endanger-national-security&#34;&gt;national security&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;These extortion schemes target students across numerous universities in the English-speaking world, including the United States, Canada and Australia. Merely providing academic cheating services is illegal in some jurisdictions. For example, Australia criminalized contract cheating and &lt;a href=&#34;https://www.teqsa.gov.au/about-us/news-and-events/latest-news/websites-blocked-protect-students-and-academic-integrity-0#:~:text=TEQSA%20has%20blocked%20another%2080,for%20professional%20and%20academic%20staff.&#34;&gt;ordered ISPs to block 555 websites&lt;/a&gt; offering these services. Regardless of jurisdiction, extorting students under threat of exposure is illegal.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;There are broader risks to universities because of how the academic work is completed. Attackers demand full access to student accounts, which could mean the transfer of login credentials and approval of multifactor authentication challenges or other kinds of remote access. This grants threat actors an ongoing foothold within the university&#39;s environment.&lt;/p&gt;
&lt;p&gt;While Okta Threat Intelligence has not directly observed a pivot from extortion to other abuses of student access in the clusters we are tracking, threat actors could conceivably leverage and monetize their access to achieve objectives such as &lt;a href=&#34;/content/okta-www/br/pt-br/newsroom/articles/payroll-pirates-target-help-desks-to-siphon-employee-paychecks.html&#34;&gt;payroll piracy&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Okta is committed to helping customers, partners, and users understand the critical role identity security plays in these attacks.&lt;/p&gt;
&lt;h2&gt;From contract cheating to student extortion&lt;/h2&gt;
&lt;p&gt;In order to finish their academic work quickly with minimal effort, some students choose to engage third parties to complete academic tasks in their behalf.&lt;/p&gt;
&lt;p&gt;It is only after one of these third parties submits an assignment on behalf of a&amp;nbsp; student through university apps like Canvas and Blackboard that the extortion component of these campaigns commences.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For instance, a student may pay $75 for one assignment, but after the assignment is submitted, the threat actor demands a further payment of $1,000 under threat of reporting the student. In almost all cases where the victim doesn&#39;t pay, the malicious actor will report the student. The malicious actor records voice and video communications with the student and may send emails to administrators.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Critically, the extortionists have leverage against their victims. Identity and access management logs may indicate that someone else has been using the student&#39;s account. The IP logs could show &#34;impossible travel,&#34; meaning a student account was accessed locally and then some time later from a locale it would have been impossible for the student to now be located.&lt;/p&gt;
&lt;h2&gt;Lure mechanisms: the &#34;academic support&#34; facade&lt;/h2&gt;
&lt;p&gt;Threat actors use a multi-channel approach to find victims, often tailoring their language and platform to specific student demographics. The extortionists thrive in high-pressure moments, such as during finals week or mid-terms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;These services are advertised using both digital and physical channels.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;Digital channels&lt;/h3&gt;
&lt;p&gt;The most common lures are digital, designed to look like academic notifications or helpful peer-to-peer recommendations.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Marketing emails&lt;/b&gt;: Attackers send emails to students with subjects like &amp;quot;Struggling with your Final?&amp;quot; or &amp;quot;Expert Tutors Available - Guaranteed A+.&amp;quot; These often use professional-looking signatures to mimic official academic support messages.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Direct messaging (WeChat, WhatsApp, Telegram)&lt;/b&gt;: To overcome email controls enforced by many universities that are likely to block, flag or filter out spam, attackers also use popular messenger apps used by international student communities. These messages are often written in the student&#39;s native language.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Websites&lt;/b&gt;: Contract cheating services develop professional-looking websites to give themselves an air of legitimacy.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Physical channels&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Campus Postings&lt;/b&gt;: Accomplices of the attackers place physical flyers around campus.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Coerced referrals&lt;/b&gt;: Once a student is already being extorted, the threat actor may demand that the student recruits more classmates. This turns the victim into an accessory, spreading the lure through trusted peer networks.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Campaign Objectives&lt;/h2&gt;
&lt;p&gt;The primary objective of these campaigns is financial crime, achieved by extorting students based on evidence of authorized access.&lt;/p&gt;
&lt;p&gt;The observed activity demonstrates clear intent to put students in a compromising situation in which they are either forced to pay or risk consequences from their academic institution.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;Data collected by threat actors&lt;/h3&gt;
&lt;p&gt;The malicious actors try to collect as much personal information as possible to ensure the success of their extortion plot.&amp;nbsp; These actors collect data such as:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Personally identifiable information (PII)&lt;/b&gt;: Full name, home address, and phone number.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Institutional identifiers:&lt;/b&gt; Student ID number and official university email address.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Academic evidence:&lt;/b&gt; The assignment prompts, the student&#39;s personal notes, the completed assignment and even the course syllabus.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Proof of presence&lt;/b&gt;: Screen recordings or screenshots of the attacker logged into the student&#39;s portal (Canvas, Blackboard, etc.)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Risks beyond student extortion&lt;/h2&gt;
&lt;p&gt;Universities and Colleges are attractive targets for financially-motivated cybercriminal groups. We assess that contract cheating and extortion services have the potential to expose institutions to additional fraudulent activity if the extortionists we observed were to capitalize on the persistent access to systems granted by students.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href=&#34;/content/okta-www/br/pt-br/newsroom/articles/payroll-pirates-target-help-desks-to-siphon-employee-paychecks.html&#34;&gt;Payroll piracy&lt;/a&gt;: The same credentials used to access student portals may provide access to payroll systems in those circumstances where a student also performs work for the institution. With access to payroll accounts, attackers can change bank routing information before a pay cycle, redirecting a student&#39;s wages to attacker-controlled accounts.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Financial aid fraud: The same credentials used to access student portals may provide access to financial aid portals, providing opportunities to divert loan disbursements or apply for additional fraudulent grants in the student&#39;s name.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Phishing and spam: Threat actors may also choose to abuse the high reputation of a trusted .edu email address to bypass spam filters and target faculty, staff, or administration in an attempt to gain access to higher-privileged accounts.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Research and IP Theft: The same credentials used for access to student portals may provide access to proprietary university databases, journals, or sensitive research data in specialized fields like defense and biotechnology.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Student discount harvesting: Threat actors may abuse student identities to resell products and services purchased with a student discount.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Threat Response&lt;/h2&gt;
&lt;h3&gt;What we&#39;re doing&lt;/h3&gt;
&lt;p&gt;Okta is taking the following actions to mitigate this threat:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Proactively notifying institutions when we detect suspicious activity.&lt;/li&gt;
&lt;li&gt;Providing guidance and assistance to organizations to enhance the security of their Okta environments and assisting them to investigate any suspicious activity related to potentially compromised accounts.&lt;/li&gt;
&lt;li&gt;Maintaining ongoing working groups with higher education institutions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Detections&lt;/h2&gt;
&lt;p&gt;In order to reach their objectives, attackers must have persistent access to the student&#39;s account long enough to run their extortion operation.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If the university is using Okta as an Identity Provider, there are several technical indicators that can point to evidence of unauthorized account takeovers.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;What follows is a summary of detections available in the Okta platform.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Authenticator reuse&lt;/b&gt;: Attackers frequently register the same physical hardware such as a mobile phone to register as an MFA factor for multiple accounts that have been compromised. Analysts may see several student identities associated with the same device identifier in Okta logs, which is a strong sign of multiple account takeovers. Okta has a detection in the &lt;a href=&#34;https://sec.okta.com/articles/2025/05/leveraging-okta-syslogs-for-proactive-threat-detection/&#34;&gt;Customer Detection Catalog&lt;/a&gt;&amp;nbsp; on &lt;a href=&#34;https://github.com/okta/customer-detections&#34;&gt;GitHub&lt;/a&gt; for authenticator reuse &lt;a href=&#34;https://github.com/okta/customer-detections/blob/master/detections/device_registered_to_multiple_users.yml&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Session initiated by user, completed by attacker&lt;/b&gt;: This behavior involves the attacker logging in using the student&#39;s credentials from a remote location. However, the MFA prompt, such as a push notification, is accepted by the student from their normal IP geolocation. This creates a session where the root session ID originates from a suspicious IP while the successful authentication success comes from a trusted IP. Okta has created a detection for this scenario &lt;a href=&#34;https://github.com/okta/customer-detections/blob/master/detections/mismatch_between_source_and_response_okta_verify_push.yml&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Impossible travel&lt;/b&gt;: Student accounts that have been shared with contract cheating services will often show evidence of impossible travel. We routinely observe impossible travel scenarios where a student account logs in from their expected campus location but the event is followed almost immediately by a login from an IP address geolocated to Kenya, India or Pakistan. Often these aberrant IPs will solely login to Canvas, Blackboard or other assignment submission sites. Okta has a &lt;a href=&#34;https://github.com/okta/customer-detections/commit/55746694dcba24828f1b2a02b6e1c0900f16400e&#34;&gt;detection&lt;/a&gt; in the Customer Detection Catalog for impossible travel that is paired with a detection for a new device. Together, those are two key signals of a possible account takeover.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Intentional use of proxy services&lt;/b&gt;: Rather than merely being sloppy, we have observed threat actors intentionally use suspicious proxy services and IPs. This is part of their extortion operation: attackers leverage the impossible travel as evidence they can show university administrators. Use of IPs from unexpected locations, especially India and East Africa, can be indicative of an account takeover. Okta has a &lt;a href=&#34;https://github.com/okta/customer-detections/blob/master/hunts/hunt_sign_in_attempts_from_proxies.yml&#34;&gt;hunt&lt;/a&gt; in the Customer Detection Catalog for sign in attempts from proxies that customers can leverage.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Recommendations for Okta Customers&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Utilize authenticator enrollment policy to block device enrollment to specific geo-locations and to block enrollment from proxy services&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Block proxy services listed under the Network Indicators section below using&amp;nbsp;&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/network/about-enhanced-dynamic-zones.htm&#34;&gt;dynamic network zones&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Block login or require step-up authentication from high risk or unexpected locations.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Network Indicators&lt;/h2&gt;
&lt;p&gt;Okta Threat intelligence has observed suspicious patterns of account access originating from Kenyan IPs. These IPs are not contained within one ASN, but frequently are associated with known suspicious proxying services:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;RAYOBYTE_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;NEXUS_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;PROXYRACK_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;IPCOLA_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;KOOKEEY_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;PLAINPROXIES_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;LUMINATI_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;9PROXY_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;PROXYAM_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;IPIDEA_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;ABCPROXY_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;NETNUT_PROXY&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;A note on estimate language&lt;/h3&gt;
&lt;p&gt;Okta Threat Intelligence teams the following terms to express likelihood or&amp;nbsp;probability as outlined in the US Office of the Director of National Intelligence&amp;nbsp;Community Directive 203 - Analytic Standards.&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Likelihood&lt;/th&gt;
&lt;th&gt;Almost&lt;br&gt;
no&amp;nbsp;chance&lt;/th&gt;
&lt;th&gt;Very&lt;br&gt;
unlikely&lt;/th&gt;
&lt;th&gt;Unlikely&lt;/th&gt;
&lt;th&gt;Roughly&lt;br&gt;
even&amp;nbsp;chance&lt;/th&gt;
&lt;th&gt;Likely&lt;/th&gt;
&lt;th&gt;Very&lt;br&gt;
likely&lt;/th&gt;
&lt;th&gt;Almost&lt;br&gt;
certain(ly)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Probability&lt;/td&gt;
&lt;td&gt;Remote&lt;/td&gt;
&lt;td&gt;Highly&lt;br&gt;
improbable&lt;/td&gt;
&lt;td&gt;Improbable&lt;/td&gt;
&lt;td&gt;Roughly&lt;br&gt;
even odds&lt;/td&gt;
&lt;td&gt;Probable&lt;/td&gt;
&lt;td&gt;Highly&lt;br&gt;
Probable&lt;/td&gt;
&lt;td&gt;Nearly&lt;br&gt;
Certain&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Percentage&lt;/td&gt;
&lt;td&gt;1-5%&lt;/td&gt;
&lt;td&gt;5-20%&lt;/td&gt;
&lt;td&gt;20-45%&lt;/td&gt;
&lt;td&gt;45-55%&lt;/td&gt;
&lt;td&gt;55-80%&lt;/td&gt;
&lt;td&gt;80-95%&lt;/td&gt;
&lt;td&gt;95-99%&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Mon, 16 Feb 2026 08:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,identity-theft,ciam,threat-insights</category>
                
                
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/detecting-openclaw-advanced-posture-checks/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/detecting-openclaw-advanced-posture-checks/</link>
                <title>Detecting OpenClaw using advanced posture checks</title>
                <description>
                    <![CDATA[&lt;p&gt;OpenClaw is a free and open-source &#34;personal AI assistant&#34; that a user can connect to the local resources on their computer, messaging applications, calendars, and &lt;a href=&#34;https://www.okta.com/newsroom/articles/agents-run-amok--identity-lessons-from-moltbook-s-ai-experiment/&#34;&gt;anything else they want the agent to access&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Right now, at least one of your users is experimenting with a personal assistant like OpenClaw. How you feel about that depends largely on the risk appetite of your organization, and how quickly you can spin up resources to assess the risk of this week&#39;s AI buzztoy. This stuff is coming at us fast.&lt;/p&gt;
&lt;p&gt;A &#34;personal AI assistant&#34; doesn&#39;t need to be malicious or vulnerable for you to want to wrap some policy around its use on corporate-issued devices.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The facts are:&lt;br&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Personal AI assistants, by their nature, will seek broad system access - interacting with files, processes, and network resources - which makes it a powerful tool if it were ever abused.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Personal AI assistants may install persistence mechanisms like launchd services and binaries across multiple paths, making them difficult to fully remove.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The default listening port for these personal assistants could be exploited for remote access to your device or command-and-control.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The most conservative option would be to block the use of these technologies until your team has had some time to figure out how to use them safely. (See these &lt;a href=&#34;https://auth0.com/blog/five-step-guide-securing-moltbot-ai-agent/&#34;&gt;tips from the Auth0 team&lt;/a&gt; if you&#39;re experimenting with OpenClaw).&amp;nbsp;&lt;/p&gt;
&lt;p&gt;You may also want to make access decisions for specific resources based on whether an AI assistant is downloaded, installed, or actively listening on a device used to access enterprise resources.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;That&#39;s where Okta advanced posture checks can play a role. Advanced posture checks incorporates osquery-based posture evaluations on any device running admin-issued versions of the Okta Verify client.&lt;/p&gt;
&lt;p&gt;By integrating detection queries like the samples provided below into advanced posture checks, organizations can automatically evaluate device health at authentication time and enforce access policies that, for example:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Block or restrict sign-ins from devices where OpenClaw is detected&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Deny access to specific sensitive resources (apps) from devices where OpenClaw is detected&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Trigger workflows that notifies administrators of a detection.&lt;br&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In all cases, administrators can create customized remediation advice for the user. Users can be instructed to take the actions necessary to restore access to specific resources, without having to call the IT helpdesk.&lt;/p&gt;
&lt;h2&gt;Sample queries&lt;/h2&gt;
&lt;p&gt;Let&#39;s assume OpenClaw is the personal AI assistant you want to check for. There are a number of approaches to detecting its use on a MacOS device.&lt;/p&gt;
&lt;h4&gt;&lt;b style=&#34;font-family: adobe-clean, &amp;quot;Source Sans Pro&amp;quot;, -apple-system, BlinkMacSystemFont, &amp;quot;Segoe UI&amp;quot;, Roboto, Ubuntu, &amp;quot;Trebuchet MS&amp;quot;, &amp;quot;Lucida Grande&amp;quot;, sans-serif;&#34;&gt;Launchd&lt;/b&gt;&lt;/h4&gt;
&lt;p&gt;Let&#39;s start with persistent services/daemons by searching launchd for the term &#34;OpenClaw&#34;. OpenClaw can be configured to launch at startup before you&#39;ve even opened your terminal. This is part of the reason why personal AI assistants make people very, very nervous.&lt;/p&gt;
&lt;pre&gt;
SELECT 1 AS result FROM (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT path&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM launchd&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LIMIT 1);
&lt;/pre&gt;
&lt;h4&gt;&lt;b&gt;Files&lt;/b&gt;&lt;/h4&gt;
&lt;p&gt;Advanced posture checks can also search for the presence of configuration files and binaries in common installation paths.&lt;/p&gt;
&lt;pre&gt;
SELECT 1 AS result FROM (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT path&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM file&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE path LIKE &#39;/Users/%%/.openclaw/openclaw.json&#39;&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/%%/.openclaw/%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/Users/%%/.volta/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/Users/%%/.nvm/current/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/usr/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/usr/local/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/opt/homebrew/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/Applications/OpenClaw.app&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LIMIT 1);
&lt;/pre&gt;
&lt;h4&gt;Running processes&lt;/h4&gt;
&lt;p&gt;Perhaps you&#39;re less concerned by whether OpenClaw has ever run on the machine, and more concerned about whether it&#39;s running while a user is signing in to protected resources?&lt;/p&gt;
&lt;p&gt;SELECT 1 AS result FROM (&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT path&amp;nbsp;&lt;/p&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM processes&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR cmdline LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LIMIT 1
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;);
&lt;/pre&gt;
&lt;h4&gt;Homebrew packages&lt;/h4&gt;
&lt;p&gt;OpenClaw leans on Homebrew for access to system-level dependencies. The presence of a homebrew installation with the name &#34;OpenClaw&#34; is another breadcrumb to follow.&lt;/p&gt;
&lt;pre&gt;
SELECT 1 AS result FROM (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT path&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM homebrew_packages&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LIMIT 1
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;);
&lt;/pre&gt;
&lt;h4&gt;npm package checks&lt;/h4&gt;
&lt;p&gt;The presence of an npm package of the same name also offers a detection opportunity.&lt;/p&gt;
&lt;pre&gt;
SELECT 1 AS result FROM (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT path&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM npm_packages&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LIMIT 1
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;);
&lt;/pre&gt;
&lt;p&gt;&lt;h4&gt;Listening ports&lt;/h4&gt;
&lt;p&gt;By default, OpenClaw listens on several network ports:&lt;/p&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;18789 (TCP): The main port for the WebSocket Gateway, which coordinates connections between clients (CLI, web UI, mobile apps) and the AI agent.&lt;/li&gt;
&lt;li&gt;18791 (TCP): Used for browser-based control/dashboard access.&lt;/li&gt;
&lt;li&gt;9090: The application often defaults to using port 9090 for its service mode. Users frequently deploy OpenClaw using Docker containers, where mapping this port is necessary to access the service, commonly using 0.0.0.0:9090.&lt;/li&gt;
&lt;/ul&gt;
&lt;pre&gt;
SELECT 1 AS result FROM (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT path&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM listening_ports&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE port IN&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
(&#39;9090&#39;, -- Default OpenClaw self-hosted port.
&lt;/pre&gt;
&lt;pre&gt;
&#39;18789&#39;, -- The main port for the WebSocket Gateway.&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&#39;18791&#39; -- Used for browser-based control/dashboard access.
&lt;/pre&gt;
&lt;pre&gt;
 )
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR&amp;nbsp; path LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LIMIT 1
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;);
&lt;/pre&gt;
&lt;h4&gt;Installed applications&lt;/h4&gt;
&lt;p&gt;Advanced posture checks can also simply check if an app of this name is installed on the (MacOS) system.&lt;/p&gt;
&lt;pre&gt;
SELECT 1 AS result FROM (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT path&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM apps&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR bundle_identifier LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LIMIT 1
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;);
&lt;/pre&gt;
&lt;h4&gt;&lt;br&gt;
Docker images&lt;/h4&gt;
&lt;p&gt;Advanced posture checks can also check for whether OpenClaw is running in a container. Here is a check for Docker images that use the name &#34;OpenClaw&#34;...&lt;/p&gt;
&lt;pre&gt;
SELECT 1 AS result FROM (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT id&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM docker_images&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE tags LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LIMIT 1
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;);
&lt;/pre&gt;
&lt;h4&gt;Docker containers&lt;/h4&gt;
&lt;pre&gt;
SELECT 1 AS result FROM (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT id&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM docker_containers&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE image LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;LIMIT 1
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;);
&lt;/pre&gt;
&lt;h4&gt;All together now&lt;/h4&gt;
&lt;p&gt;Given many of these detections rely on mutable names, a single query (or even two) might be prone to false positives. You may find that a few in combination deliver more consistent results.&lt;/p&gt;
&lt;p&gt;The final query I&#39;ll leave you with attempts to detect the presence of OpenClaw on a macOS device by examining multiple system sources and combining the results into a single detection score.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Each source contributes a count of matches. These counts are summed into a final score:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Score ? 2&amp;nbsp; ? openclaw_detected = 0 (insufficient confidence of detection)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Score &amp;gt; 2 ? openclaw_detected = 1 (confident detection)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The threshold of 2 helps avoid false positives by requiring multiple indicators before flagging a device.&lt;/p&gt;
&lt;pre&gt;
WITH launch_claw AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT COALESCE(COUNT(*), 0) as total
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM launchd&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
),&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;file_claw AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT COALESCE(COUNT(*), 0) as total
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM file&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE path LIKE &#39;/Users/%%/.openclaw/openclaw.json&#39;&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;-- OR path LIKE &#39;/%%/.openclaw/%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/Users/%%/.volta/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/Users/%%/.nvm/current/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/usr/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/usr/local/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/opt/homebrew/bin/openclaw&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR path LIKE &#39;/Applications/OpenClaw.app&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;),
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;claw_process AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT COALESCE(COUNT(*), 0) as total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM processes&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR cmdline LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;),
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;homebrew_claw AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT COALESCE(COUNT(*), 0) as total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM homebrew_packages&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;),
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;npm_claw AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT COALESCE(COUNT(*), 0) as total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM npm_packages&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;),
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;netports_claw AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT COALESCE(COUNT(*), 0) as total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM listening_ports&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE port IN&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
(&#39;9090&#39;, -- Default OpenClaw self-hosted port.
&lt;/pre&gt;
&lt;pre&gt;
&#39;18789&#39;, -- The main port for the WebSocket Gateway.&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&#39;18791&#39; -- Used for browser-based control/dashboard access.
&lt;/pre&gt;
&lt;pre&gt;
 )
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR&amp;nbsp; path LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;),
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;apps_claw AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT COALESCE(COUNT(*), 0) as total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM apps&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE name LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;OR bundle_identifier LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;),
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;docker_image_claw AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT COALESCE(COUNT(*), 0) as total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM docker_images&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE tags LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;),
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;docker_container_claw AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT COALESCE(COUNT(*), 0) as total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM docker_containers&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHERE image LIKE &#39;%openclaw%&#39;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;),
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;final_score AS (
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;SELECT&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;+ file_claw.total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;+ claw_process.total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;+ homebrew_claw.total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;+ npm_claw.total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;+ netports_claw.total&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;+ apps_claw.total
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;+ docker_image_claw.total
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;+ docker_container_claw.total
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AS score
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;FROM launch_claw, file_claw, claw_process, homebrew_claw, npm_claw, netports_claw, apps_claw, docker_image_claw, docker_container_claw
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;)
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;SELECT&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;CASE&amp;nbsp;
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHEN score &amp;lt;= 2 THEN 0
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WHEN score &amp;gt; 2 THEN 1
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;END AS openclaw_detected
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;FROM final_score
&lt;/pre&gt;
&lt;pre&gt;
&amp;nbsp;;
&lt;/pre&gt;
&lt;h2&gt;More clawsome detections&lt;/h2&gt;
&lt;p&gt;Detecting the presence of a new and unverified application like OpenClaw is one of numerous ways in which advanced posture checks can be used to ensure resources are only accessed from devices exhibiting strong hygiene.&lt;br&gt;
&lt;br&gt;
Stay tuned for more!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
]]>
                </description>
                <pubDate>Mon, 09 Feb 2026 16:00:00 +0000</pubDate>
                
                    <category>blog-post,ai-agents,ai,threat-intelligence</category>
                
                <dc:creator>Rafa Bono</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/the-north-korean-on-your-payroll/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/the-north-korean-on-your-payroll/</link>
                <title>The North Korean on your payroll</title>
                <description>
                    <![CDATA[&lt;p&gt;In September 2025, Okta Threat Intelligence &lt;a href=&#34;https://www.okta.com/newsroom/articles/north-korea-s-it-workers-expand-beyond-us-big-tech/&#34;&gt;published research&lt;/a&gt; from a large-scale analysis into fraudulent employment schemes conducted by Democratic People&#39;s Republic of Korea (DPRK) IT Workers (ITW).&amp;nbsp;&lt;/p&gt;
&lt;p&gt;That research collated data from over 130 actors, conducting over 6500 interviews with 500 companies.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In this post, we look specifically at the activities of two individual personas. We selected these two examples from a large list of actors that we continue to track because they exemplify the typical tools, techniques and procedures (TTPs) employed by DPRK ITW actors. Additionally, each had novel observables that can further inform defenders against these efforts.&lt;/p&gt;
&lt;p&gt;These two actors reveal two interesting TTPs DPRK actors use to land employment: the abuse of legitimate LinkedIn profiles to pass reference checks, and the abuse of stolen identities.&lt;/p&gt;
&lt;h2&gt;#1 - Meet &#34;JJ&#34;&amp;nbsp;&lt;/h2&gt;
&lt;p&gt;The first of the two actors we will detail we&#39;ll refer to as &#34;JJ&#34;. This actor has prolifically interviewed for roles in multiple verticals over two years, with an overrepresentation of roles in AI and healthcare.&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;The email account used by this actor is similar in structure to other DPRK-linked actors, in that it utilizes a free webmail service and the account name incorporates references to software development and other randomized alphanumeric characters. Open-source intelligence (OSINT) research conducted into the email address used by this actor uncovered a number of online services accounts that are very typical of DPRK ITW actors. All of these accounts are used exclusively for job applications and associated tasks:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Job board and hiring platforms&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Scheduling platforms popular with recruiters&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Document organization workspaces with AI assistance&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Dynamic DNS services&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Online coding platforms&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While not observed with this specific actor, Okta Threat Intelligence has also used OSINT techniques to observe email addresses used by DPRK actors being registered to the following services:&amp;nbsp;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Freelancer employment platforms&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Article authoring and publishing platforms&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Document creation and managements&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Language learning platforms&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Online communications&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Software development social platforms&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Online PDF platforms&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Coding assessment platforms&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;DPRK actors use these online accounts and fabricated resumes to effectively create an artificial &#34;persona&#34;. These personas appear &amp;quot;out of thin air&amp;quot;, inheriting the online presence required for a professional applying for roles, but without any evidence of personal use of any internet services. The exclusive use of these specific services, combined with the absence of any personal online footprint, creates a pattern highly indicative of an artificial persona.&lt;/p&gt;
&lt;p&gt;Additional &#34;tells&#34; very common to these actors can sometimes be observed in the document properties of PDF resumes they provide. Okta Threat Intelligence can provide customers with further details on these methods of detection - please talk to your account manager to find out more.&lt;/p&gt;
&lt;h3&gt;Becoming JJ&lt;/h3&gt;
&lt;p&gt;During the two years of observed activity, our threat actor JJ created and subsequently abandoned several personas.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Until recently, JJ told recruiters that he did not have a LinkedIn profile. Okta Threat Intelligence occasionally observes LinkedIn profiles associated with the persona email addresses set up by DPRK ITW actors. The scarcity of connections, posts, recommendations, other content, and activity on these profiles can be used to identify a lack of authenticity. Often we discover that a LinkedIn profile listed by a DPRK ITW actor has been disabled thanks to the detection and enforcement efforts of the LinkedIn security team.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In September 2025, JJ was observed providing recruiters an active LinkedIn profile for the first time. The LinkedIn profile matched the inauthentic name they were using to apply for roles at the time, and doesn&#39;t feature a profile picture. At first glance, the LinkedIn profile appeared robust and realistic, unlike most LinkedIn profiles established for DPRK IT Worker fraud. For example, the profile had:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Almost 200 connections&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Links to a GitHub account with realistic content (see later in report for example of an unrealistic GitHub account)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Multiple &#34;skills&#34; listed, many of which were endorsed by multiple third-parties. The endorsing LinkedIn accounts appeared to be authentic.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;A happy false-positive&lt;/h3&gt;
&lt;p&gt;Our investigation determined that the person represented in the LinkedIn profile was, until recently, a genuine employee of the listed organization.&lt;/p&gt;
&lt;p&gt;Our assessment is that the actor has simply misrepresented a genuine Linkedin profile as their own, altering the name of their fraudulent persona to fit that of a real human to align with the employment criteria. Our confidence in this assessment was also based on the fact that the DRPK actor&#39;s email address was not the email address used for the legitimate LinkedIn profile. It was a form of &#34;stolen valour&#34; designed to increase their chances of employment.&lt;/p&gt;
&lt;h3&gt;A challenge for verification&lt;/h3&gt;
&lt;p&gt;This technique - creating a persona based on a real identity - reinforces the need for strong identity verification prior to any form of employment. Employers should not rely on a LinkedIn profile as a basis for determining employment history. Verification requests to current or recent employers, asking only if a person with that name was employed in the role in the timeframes listed on LinkedIn, will not reveal the fraud. It is trivial for a threat actor to employ this technique, or to generate resumes directly from a co-opted Linkedin profile using an online resume generator or an AI-augmented system that consumes a public profile as an input. The actor simply creates an altered email address and phone number and makes the task of an HR screener far more demanding.&lt;/p&gt;
&lt;p&gt;Prospective employers should incorporate identity verification techniques such as &lt;a href=&#34;https://auth0.com/docs/secure/mdl-verification&#34;&gt;mobile drivers license verification&lt;/a&gt;. If relying on knowledge factors, verifiers should only base assessments on definitively non-public information such as partially-redacted national ID number or the name of the last manager at the role. Employers cannot rely on date of birth for robust verification as this information is readily available in public data and people-search services.&lt;/p&gt;
&lt;h2&gt;#2 &amp;quot;EM&amp;quot; gets hired&lt;/h2&gt;
&lt;p&gt;We will refer to our second actor as &amp;quot;EM&amp;quot;. EM&#39;s employment fraud activity stretches back over a year, with hundreds of interviews again across all verticals, but very much favoring AI-related roles and organizations. Okta Threat Intelligence also observed EM interviewing with sensitive critical national infrastructure (CNI) organizations such as commercial aviation, communications providers, internet service providers, a voting technology company and intelligence and defense contractors.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;EM has a statistically high occurrence of succeeding in first interviews and being offered&amp;nbsp; multiple rounds of interviews with individual organizations, and is likely to have been hired by several organisations into software development roles.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We set out to discover some of the secrets to EM&#39;s success.&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;The co-opted persona used by EM appears to have been crafted based on an online photograph of a legitimate person who unfortunately also displayed enough information online to enable the DPRK (and potentially others) to co-opt his identity.&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;The real EM and an identity problem&lt;/h3&gt;
&lt;p&gt;EM claims to be a US citizen when asked about employment eligibility, and presents very realistic identity documents. Research into the name used by this actor finds that there is only one real person with this distinct name. We found photos of a person, holding up an identity document almost identical to the document our actor presents as his own, with a different photograph and signature.&lt;/p&gt;
&lt;h3&gt;The DPRK EM&lt;/h3&gt;
&lt;p&gt;EM&#39;s professed residential and employment history differs significantly from that of the real person whose identity was assumed. Okta Threat Intelligence observed EM offering two different contact phone numbers. Both are VoIP phones - ubiquitous with DPRK actors - and one has a Caller ID location that contradicts their professed biography. The LinkedIn profile listed in their resume has since been taken down by the team at LinkedIn.&lt;/p&gt;
&lt;pre&gt;
lookup cname = SEATTLE WA
lookup cname = WESTPORT WA
&lt;/pre&gt;
&lt;p&gt;DPRK ITW actors often create impressive-looking GitHub accounts to backstop their technical proficiency for job interviews. EM is no exception to this.&lt;/p&gt;
&lt;p&gt;A GitHub account used by EM has thousands of contributions, ostensibly dating back to 2011.&amp;nbsp;&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;However it appears that EM forged most of the commit dates .&lt;br&gt;
&lt;br&gt;
The actual earliest contribution date from EM in this account can be determined using the GitHub API (see request response below), which returns a date of December 2024, not 2011.&lt;/p&gt;
&lt;pre&gt;
?&amp;nbsp; ~ curl -s https://api.github.com/repos/em???????/D??????-W?????? | jq -r &#39;.created_at&#39;
&lt;/pre&gt;
&lt;pre&gt;
2024-12-14T??:??:00Z
&lt;/pre&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This actor simply changed the year of their unsigned commit date from 2024 to 2011.&lt;/p&gt;
&lt;h3&gt;The many (AI) faces of EM&lt;/h3&gt;
&lt;p&gt;The face of EM, as presented in various online profiles, is inconsistent. None of them are at all similar to the image used in EM&#39;s forged identity documents.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;They appear to the human eye as likely AI creations, and multiple online AI-detection tools offer mixed-high confidence assessments when asked if the profile pictures were AI generated.&lt;/p&gt;
&lt;p&gt;A third profile picture, likely sourced from a now-deleted LinkedIn account, lacks the necessary resolution to accurately determine if it was AI-generated. It is again clearly not the same as the forged identity or other AI-generated images used by the actor.&lt;/p&gt;
&lt;h3&gt;The other DPRK EM?&lt;/h3&gt;
&lt;p&gt;During the course of our research, Okta Threat Intelligence assessed two additional professional profiles with a distinctly different biography and profile picture that tools identified as likely not being AI-generated.&lt;/p&gt;
&lt;p&gt;As the table below shows, the two profiles show a very different story. This may be a different DPRK ITW actor using the same identity, or an earlier iteration of EM&#39;s fictional biography.&lt;/p&gt;
&lt;h3&gt;Your new (DPRK) hire&lt;/h3&gt;
&lt;p&gt;During our research, we often make assessments as to whether a DPRK ITW actor has successfully been hired into a role. In this case we can say with high confidence that EM has been hired: thanks to a LinkedIn post by their new employer, welcoming their newest hire.&lt;/p&gt;
&lt;p&gt;The photo used in this post is even more obviously AI-generated than any of the other photographs we analyzed.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Steps have been taken to contact this organization to inform them of our observations.&lt;/p&gt;
&lt;h2&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Just as with genuine candidates hunting for work, the vast majority of &lt;a href=&#34;https://www.okta.com/newsroom/articles/north-korea-s-it-workers-expand-beyond-us-big-tech/&#34;&gt;interviews with DPRK facilitators and agents&lt;/a&gt; do not progress to a second interview or job offer.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Some actors however seem to be more competent at crafting personas and passing screening interviews. Their skill isn&#39;t limited to an ability to impress a prospective employer, but also to the &lt;a href=&#34;https://sec.okta.com/articles/2025/04/GenAIDPRK/&#34;&gt;tools and techniques&lt;/a&gt; that DPRK ITW actors use to try to obfuscate their actual origins.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Given the vast quantities of job applications and interviews being conducted, the various operators in the IT Worker scheme are clearly &#34;learning from their mistakes&#34; - in many cases duplicating approaches (CV structure and elements, Linkedin profile construction and interview support technologies) that have succeeded in progressing one application over another. A kind of IT Worker natural selection is at play. The most successful actors are very prolific, and scheduled hundreds of interviews each. We consider it likely that they often act as &#34;interview brokers&#34; in order to land employment positions that are then handed over to other DPRK ITW actors.&lt;/p&gt;
&lt;h3&gt;The third-party contractor risk&lt;/h3&gt;
&lt;p&gt;Our research revealed a large number of DPRK IT Workers seek temporary contract work as software developers hired out to third-party organizations. We assess that these companies are potentially less likely to enforce rigorous background checks on these short-term fixed task employees than the companies that they are contracting to would for direct-hire employees.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This highlights the importance of performing such checks not only on direct-hire employees, but also on all individuals given access to company resources via third-party service providers.&lt;/p&gt;
&lt;h3&gt;Background checks can never be optional&lt;/h3&gt;
&lt;p&gt;In this report we&#39;ve highlighted an example of the deliberate co-option of the identity of a genuine person, together with their professional history. Rigorous background checking and employment verification will be needed to pierce this identity misrepresentation. Yet we also observed the hiring of an actor whose artificial identity would not stand up to even the most cursory use of a search engine.&lt;/p&gt;
&lt;p&gt;Organizations that unwittingly hire a DPRK actor&amp;nbsp; risk a potential de facto breach of sanctions obligations and associated legal exposure. Each compromised hire can also provide the DPRK with:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Direct financial gain (salary payments diverted to the regime)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Privileged internal access to sensitive systems, data, and networks&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Operational leverage for ransomware, extortion, or follow-on cyber activity&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Loss of commercially-sensitive corporate secrets&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strategic intelligence collection and access to support future offensive operations&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Organizations should therefore adopt a layered defense, including rigorous identity verification during recruitment, ongoing monitoring of the access and behaviour patterns of remote workers, and a clear incident response plan for managing insider or supply chain threats. When hiring for positions of elevated trust and access, in-person verification of identity and documents and collection/provision of equipment and access tokens is a relatively small cost given the risk the organization is taking on. Access for remote employees and especially third-party contractors should be strictly limited to the minimum required to perform their role.&lt;/p&gt;
&lt;h1&gt;Steps to take to counter this threat&lt;/h1&gt;
&lt;p&gt;Okta Threat Intelligence assesses that organizations across all verticals - particularly those advertising remote or contract roles - should adopt a layered and proactive approach to recruitment, onboarding, and insider-threat monitoring. Okta recommends that organizations:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;ol&gt;
&lt;h4&gt;1. Strengthen applicant identity verification&lt;/h4&gt;
&lt;/ol&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Require verifiable government-issued ID checks at multiple stages of recruitment and employment&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Cross-check stated locations with IP addresses (include VPN usage detection), time-zone behaviour, payroll banking information and delivery addresses provided for shipping hardware.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Use accredited third-party services to authenticate identity documents, prior employment, and academic credentials&lt;br&gt;
&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;2. Tighten recruitment &amp;amp; screening processes&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Train HR and recruiters to identify red flags. Encourage processes that would identify whether a candidate is swapped out between rounds of interviews. Teach them to identify behavioural cues such as poor knowledge of the area they claim to reside in, a refusal to meet in person, a refusal to turn on camera or remove background filters during interviews, or interviewing using a very poor internet connection. Identify duplicated resumes, inconsistent timelines, mismatched time zones and unverifiable references. Assess the candidate&#39;s online footprint and social media presence against the information provided. Where evidence of previous work is provided, investigate whether these projects were simply cloned from the repositories of legitimate user profiles.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Verify the history of edits to CVs and PDFs in document metadata and other technical &#34;tells&#34; associated with duplication and reuse.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Add structured technical and behavioural verification (live coding or writing performed under recruiter observation).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Require corporate email references (not free webmail) and confirm via outbound call to the main switchboard numbers of the reference organization. Ensure these references incorporate elements other than revealed in for example public LinkedIn profiles, such as last-manager&#39;s name.&lt;br&gt;
&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;3. Enforce role-based and segregated access controls&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Default new or contingent workers to least-privilege profiles and unlock additional access once probationary checks are complete.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Segment development, testing and production; require peer review and approval workflows for code merges and deployments.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Monitor for anomalous access patterns (large data pulls, off-hours logins from unexpected geos/VPNs, credential sharing).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Employ &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-governance/access-certification/ac-get-started.htm&#34;&gt;access certification campaigns&lt;/a&gt; to govern ongoing access.&lt;br&gt;
&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;4. Monitor contractors and third-party service providers&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Where possible, contractually mandate ongoing identity verification standards, background checks, strong authentication policies, device-security baselines and rights to audit.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Require named-user accounts (no shared logins or internal service accounts where possible) and separate tenant/project access for each client environment.&lt;br&gt;
&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;5. Implement insider-threat and security awareness programs&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Establish a dedicated insider-risk function or at least a working group spanning HR, Legal, Security, and IT.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Provide targeted training for recruiters, hiring managers, and technical leads on ITW tradecraft and screening controls.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Educate and empower hiring managers and staff members to observe and submit reports of potentially strange behaviour by their peers that raise questions as to their identity, goals, and locations.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Create safer reporting channels for suspicious behaviour or candidate concerns.&lt;br&gt;
&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;6. Coordinate with law enforcement and industry peers&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Share indicators of compromise and suspicious candidate patterns with national cybercrime units and ISAC/ISAO groups.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Develop methods for the &#34;insider-risk&#34; group to receive and action indicators (email addresses, IP addresses, VPN providers, document creation, and behavioural indicators) and be prepared to &#34;share back&#34; relevant findings.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Actively participate in information-sharing forums to track evolving ITW tactics and tooling.&lt;br&gt;
&amp;nbsp;&lt;/p&gt;
&lt;h4&gt;7. Conduct regular risk assessments and red-team exercises&lt;/h4&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Model insider and malicious contractor attack paths; quantify potential business impact.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Perform red team exercises that test the hiring pipeline (simulated DPRK application and interviews) to assess identity verification processes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Update incident response plans to include scenarios involving malicious insiders, compromised contractors, and expedited access revocation.&lt;br&gt;
&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Okta Threat Intelligence appreciates the assistance of &lt;a href=&#34;https://epieos.com/&#34;&gt;Epieos&lt;/a&gt; in the research for this post.&lt;/p&gt;
]]>
                </description>
                <pubDate>Wed, 28 Jan 2026 16:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,iam,threat-insights,identity-theft,fraudulent-registration</category>
                
                <dc:creator>, </dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/</link>
                <title>Phishing kits adapt to the script of callers</title>
                <description>
                    <![CDATA[&lt;p&gt;Okta Threat Intelligence has detected and dissected multiple custom phishing kits that have evolved to meet the specific needs of voice-based social engineers (&#34;callers&#34;) in vishing campaigns.&lt;/p&gt;
&lt;p&gt;These custom kits are made available on an as-a-service basis and are increasingly used by a growing number of intrusion actors targeting Google, Microsoft, Okta and a range of cryptocurrency providers.&lt;/p&gt;
&lt;p&gt;The kits are capable of intercepting the credentials of targeted users, while also presenting the supporting context required to convince users to approve MFA challenges, or to take other actions in the interests of the attacker on the phone. They can be adapted on the fly by callers to control what pages are presented in the user&#39;s browser, in order to sync with the caller&#39;s script and whatever legitimate MFA challenges the caller is presented with as they attempt to sign-in.&lt;/p&gt;
&lt;p&gt;&#34;Once you get into the driver&#39;s seat of one of these tools, you can immediately see why we are observing higher volumes of voice-based social engineering,&#34; said Moussa Diallo, threat researcher at Okta Threat Intelligence. &#34;Using these kits, an attacker on the phone to a targeted user can control the authentication flow as that user interacts with credential phishing pages. They can control what pages the target sees in their browser in perfect synchronization with the instructions they are providing on the call. The threat actor can use this synchronization to defeat any form of MFA that is not phishing-resistant.&#34;&lt;/p&gt;
&lt;p&gt;Okta Threat Intelligence has published a &lt;a href=&#34;https://security.okta.com/product/okta/vishing-operators-synchronize-phishing-sites-to-their-script-for-hybrid-social-engineering-attacks&#34;&gt;detailed threat advisory&lt;/a&gt; for customers that provides an inside look at the capabilities of two such kits used by intrusion actors. This blog post summarizes the key features that make these kits so effective.&lt;/p&gt;
&lt;h2&gt;When all else fails, hit the phones&lt;/h2&gt;
&lt;p&gt;The phishing kits appear, based on common features, to have evolved from the same lineage to&amp;nbsp; specifically meet the needs of callers that are interacting with targeted users in real-time.&lt;/p&gt;
&lt;p&gt;The most critical of these features are client-side scripts that allow threat actors to control the authentication flow in the browser of a targeted user in real-time while they deliver verbal instructions or respond to verbal feedback from the targeted user. It&#39;s this real-time session orchestration that delivers the plausibility required to convince the threat actor&#39;s target to approve push notifications, submit one time passcodes (OTP) or take other actions the threat actor needs to bypass MFA controls.&lt;/p&gt;
&lt;p&gt;Attacks tend to follow a similar sequence:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;The threat actor performs reconnaissance on a target, learning the names of users, the apps they commonly use, and phone numbers used in IT support calls;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The threat actor sets a customized phishing page live and calls targeted users, spoofing the phone number of the company or its support hotline;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The threat actor convinces the targeted user to navigate in their browser to the phishing site under the pretext of an IT support or security requirement;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The targeted user enters their username and password, which is automatically forwarded to the threat actor&#39;s Telegram channel;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The threat actor enters the username and password into the legitimate sign-in page of the targeted user and assesses what MFA challenges they are presented with;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The threat actor updates the phishing site in real-time with pages that support their verbal ask for the user to enter an OTP, accept a push notification, or other MFA challenges.&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This real-time session orchestration provides a new level of control and visibility to the social engineer. If presented a push notification (type of MFA challenge), for example, an attacker can verbally tell the user to expect a push notification, and select an option from their C2 panel that directs their target&#39;s browser to a new page that displays a message implying that that a push message has been sent, lending plausibility to what would ordinarily be a suspicious request for the user to accept a challenge the user didn&#39;t initiate.&lt;/p&gt;
&lt;p&gt;It&#39;s worth noting that these hybrid phishing operations are also capable of bypassing push notifications that use number challenge/number matching as an additional method of verification. Push with number matching/challenge is not phishing-resistant by definition, as a social engineer interacting on the phone with a targeted user can simply request a user to choose or enter a specific number.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;By contrast, users that are required to sign in with&amp;nbsp;&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/phishing-resistant-auth.htm&#34;&gt;phishing resistant methods&lt;/a&gt;&amp;nbsp;such as Okta FastPass or FIDO passkeys are protected from these attacks.&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;This is how it&#39;s done now&lt;/h2&gt;
&lt;p&gt;Diallo predicts that we&#39;re only at the beginning of a wave of voice-enabled phishing attacks, augmented by tools that provide real-time session orchestration.&lt;/p&gt;
&lt;p&gt;&#34;Vishing is becoming such an in-demand area of expertise that, much like access to these kits, that expertise is also sold on an as-a-service basis,&#34; Diallo said.&lt;/p&gt;
&lt;p&gt;Further, he has observed the real-time session orchestration features of earlier kits being copied into new phishing kits designed exclusively to augment the needs of callers.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Where threat actors could once pay for access to a kit with basic features that targeted all popular Identity Providers (Google, Microsoft Entra, Okta etc) and cryptocurrency platforms,&amp;nbsp; a new generation of fraudsters are attempting to sell access to bespoke panels for each targeted service.&lt;/p&gt;
&lt;h2&gt;Recommendations&lt;/h2&gt;
&lt;p&gt;Thankfully there is absolutely no doubt about what defenders need to do.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&#34;In a workplace context, there is no substitute for enforcing phishing resistance for access to resources,&#34; said Diallo.&lt;/p&gt;
&lt;p&gt;When using Okta for workforce authentication, that would equate to enrolling users in Okta FastPass, passkeys or &#34;both for the sake of redundancy,&#34; he said.&lt;/p&gt;
&lt;p&gt;Social engineering actors can also be frustrated by setting&amp;nbsp;&lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/network/network-zones.htm&#34;&gt;network zones&lt;/a&gt;&amp;nbsp;or&amp;nbsp;&lt;a href=&#34;https://auth0.com/docs/secure/tenant-access-control-list&#34;&gt;tenant access control lists&lt;/a&gt;&amp;nbsp;that deny access via the anonymizing services favoured by threat actors.&lt;/p&gt;
&lt;p&gt;&#34;The key is to know where your legitimate requests come from, and allowlist those networks,&#34; Diallo said.&lt;/p&gt;
&lt;p&gt;Some&amp;nbsp;&lt;a href=&#34;https://monzo.com/help/monzo-fraud-category/monzo-call-status-web&#34;&gt;banks&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href=&#34;https://crypto.com/en/product-news/live-inapp-call-warning&#34;&gt;cryptocurrency exchanges&lt;/a&gt;&amp;nbsp;are also experimenting with live caller checks - in which a user can sign into a mobile app to find out whether they are on a phone call with an authorized representative at the time.&lt;/p&gt;
&lt;h2&gt;Read More&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence has published threat advisories on voice-enabled phishing campaigns in&amp;nbsp;&lt;a href=&#34;https://security.okta.com/product/okta/how-a-phishing-as-a-service-operation-enables-fraud-actors&#34;&gt;April 2025&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href=&#34;https://security.okta.com/product/okta/vishing-operators-synchronize-phishing-sites-to-their-script-for-hybrid-social-engineering-attacks&#34;&gt;January 2026&lt;/a&gt;&amp;nbsp;that are available exclusively to the security contacts of Okta customers.&lt;br&gt;
&lt;br&gt;
These threat advisories include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Indicators of Compromise (IoCs)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Analysis of multiple phishing kits&amp;nbsp;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;TTPs of intrusion actors conducting these attacks&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Detailed control recommendations&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To learn more about Okta&#39;s approach to phishing resistance,&amp;nbsp;&lt;a href=&#34;https://www.okta.com/sites/default/files/2024-02/Step-by-step%20guide%20to%20becoming%20phishing%20resistant%20with%20Okta%20FastPass.pdf&#34;&gt;start here.&lt;/a&gt;&lt;/p&gt;
]]>
                </description>
                <pubDate>Thu, 22 Jan 2026 08:00:00 +0000</pubDate>
                
                    <category>blog-post,mfa-downgrade,social-engineering,threat-intelligence,credential-phishing</category>
                
                
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/jobseekers-exploited-in-fake-recruiter-phishing-campaigns/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/jobseekers-exploited-in-fake-recruiter-phishing-campaigns/</link>
                <title>Jobseekers exploited in fake recruiter phishing campaigns</title>
                <description>
                    <![CDATA[&lt;h2&gt;Resumo Executivo &lt;/h2&gt;
&lt;p&gt;A Okta Threat Intelligence identificou multiplos clusters de atividade de phishing de alto volume, personificando equipes de recrutamento de varias empresas, usando mais de 400 dominios para facilitar o roubo de credenciais.&lt;/p&gt;
&lt;p&gt;Rastreamos essa atividade como O-UNC-038.&lt;/p&gt;
&lt;p&gt;Neste relatorio, detalhamos:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Uma campanha usando uma tecnica de &#34;navegador in the navegador&#34; (BitB) para imitar um login social do Facebook, usando bots do Telegram para exfiltracao de credenciais.&lt;/li&gt;
&lt;li&gt;Uma campanha direcionada especificamente a credenciais de contas corporativas do Google Workspace, usando Socket.IO para exfiltracao de credenciais&lt;/li&gt;
&lt;li&gt;Campanhas de phishing semelhantes com tema de recrutamento&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;O objetivo principal em todas essas campanhas e a coleta de credenciais.&lt;/p&gt;
&lt;p&gt;Embora campanhas mais sofisticadas possam alavancar tecnicas de Adversario-no-Meio (AitM) que capturam cookies de sessao para ignorar a Multi-Factor Authentication (MFA), as campanhas neste aviso conduzem a simples coleta de credenciais por meio de kits de phishing estaticos.&lt;/p&gt;
&lt;h2&gt;Analise de Ameacas&lt;/h2&gt;
&lt;h3&gt;Varias campanhas, segmentacao semelhante&lt;/h3&gt;
&lt;p&gt;Descobrimos e rastreamos varias campanhas que usam iscas de phishing com temas de recrutamento semelhantes e abusam dos mesmos servicos para entrega ou rastreamento de iscas.&lt;/p&gt;
&lt;p&gt;Em paginas de phishing associadas aos clusters de atividade descritos abaixo, observamos links de rastreamento associados ao Salesforce ExactTarget:&lt;/p&gt;
&lt;pre&gt;
cl.s12[.]exct[.]net/?qs=&amp;lt;UniqueIdentifierString&amp;gt;
&lt;/pre&gt;
&lt;p&gt;Atores de phishing comumente abusam de plataformas de e-mail marketing para enviar e-mails de phishing, seja configurando contas de teste para organizacoes falsas, seja assumindo as contas de clientes da plataforma de e-mail marketing. Os atores de phishing podem entao enviar para grandes listas de e-mail a partir de uma infraestrutura de e-mail confiavel.&lt;/p&gt;
&lt;p&gt;A Okta forneceu esses dominios e links de rastreamento para a Salesforce Threat Intelligence, que conseguiu suspender imediatamente as contas da Salesforce associadas e investigar as campanhas.&lt;/p&gt;
&lt;p&gt;Abaixo, detalhamos as diferentes iscas e funcionalidades de duas das campanhas.&lt;br&gt;
&lt;br&gt;
&lt;/p&gt;
&lt;h2&gt;Analise de Ameacas - Campanha 1&lt;/h2&gt;
&lt;h3&gt;Campanha de credenciais do Facebook de navegador no navegador (BitB) (&#34;Campanha 1&#34;)&lt;/h3&gt;
&lt;p&gt;Este primeiro cluster que analisaremos usa uma tecnica de navegador in the navegador (BitB) para adquirir credenciais do Facebook da vitima, exibindo uma janela de caixa de dialogo de login falsa.&lt;/p&gt;
&lt;p&gt;Um ataque BitB e uma tecnica avancada de phishing onde uma pagina da web maliciosa usa HTML, CSS e JavaScript para criar uma janela de navegador falsa dentro da janela real do navegador. Esta janela falsa e projetada para imitar um pop-up legitimo, como o prompt &amp;quot;Login com Facebook&amp;quot;, completo com uma barra de endereco falsa e um cadeado de seguranca. Quaisquer credenciais inseridas nesta janela falsa sao capturadas pelo atacante.&lt;/p&gt;
&lt;p&gt;Rastreamos 143 dominios associados a esta campanha especifica da tecnica Facebook/BitB. Tambem observamos alguma diversidade no alojamento, possivelmente sugerindo atores separados ou subcampanhas usando a mesma tecnica.&lt;/p&gt;
&lt;p&gt;Esta campanha normalmente usa o servico de front-end na nuvem Vercel ou registra nomes de dominio em registrar.eu e hospeda os sites com o Amazon web Services. Esta campanha tambem usa um bot do Telegram para exfiltracao de credenciais e para distribuir atualizacoes para os sites.&lt;/p&gt;
&lt;h3&gt;Exemplo: Recrutamento Falso da Meta&lt;/h3&gt;
&lt;p&gt;O exemplo de phishing de credenciais se passa por recrutamento da Meta em tres paginas distintas: uma pagina de destino inicial, um portal de pagina de inscricao de emprego e uma pagina de login falsa do Facebook.&lt;/p&gt;
&lt;h3&gt;Exemplo: Recrutamento Falso da Puma&lt;/h3&gt;
&lt;p&gt;A sequencia de tres imagens abaixo e outro exemplo, desta vez se passando pelo recrutamento da Puma:&lt;/p&gt;
&lt;h2&gt;Iscas de Phishing Observadas - Campanha 1&lt;/h2&gt;
&lt;p&gt;A campanha BitB utiliza software e servicos corporativos convincentes para enganar os usuarios e leva-los a inserir credenciais. Depois que as credenciais do usuario sao inseridas no site controlado pelo invasor, a pagina de envio simula um processo de travamento.&lt;/p&gt;
&lt;h2&gt;Analise de Ameacas - Campanha 2&lt;/h2&gt;
&lt;p&gt;Este cluster nao usa a tecnica de BitB como visto na Campanha 1, mas sim uma pagina de destino estatica que imita uma tela cheia de login de conta do Google.&lt;/p&gt;
&lt;p&gt;As paginas de phishing usadas nesta campanha rejeitam formatos de endereco de e-mail pessoal em uma tentativa de capturar credenciais corporativas.&lt;/p&gt;
&lt;p&gt;Observamos pelo menos 84 dominios relacionados para esta campanha, que abusa do Cloudflare para ofuscar o endereco IP de origem real e do Socket.IO para exfiltracao de credenciais roubadas.&lt;/p&gt;
&lt;h3&gt;Exemplo: Recrutamento falso da Sony Playstation&lt;/h3&gt;
&lt;p&gt;Quaisquer dados enviados no &#34;formulario&#34; abaixo sao ignorados, pois esta campanha apenas tenta capturar credenciais do Google.&lt;/p&gt;
&lt;p&gt;Depois que as credenciais sao inseridas, o fluxo de trabalho pode terminar usando um processo de suspensao semelhante ao Cluster 1 ou algum tipo de caixa de dialogo de erro.&lt;/p&gt;
&lt;h2&gt;Outros Clusters de Phishing com tema de Recrutamento&lt;/h2&gt;
&lt;p&gt;A nossa investigacao sobre os dois clusters de phishing distintos anteriores descobriu varias campanhas tematicas de recrutamento mais semelhantes, incluindo quase 200 dominios de phishing adicionais. &lt;/p&gt;
&lt;p&gt;Estes podem ser agrupados em grupos de combinacoes de infraestrutura e/ou tecnicas de nomenclatura, o que pode sugerir que varios atores independentes podem estar por tras dessas campanhas com temas semelhantes. &lt;/p&gt;
&lt;p&gt;Essas campanhas e infraestrutura se passam por varias empresas e servicos de recrutamento conhecidos, incluindo:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Adecco&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Adidas&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Aquent&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Calendly&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Calvin Klein&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Cisco&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;CocaCola&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Genpact&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Givenchy&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Google&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Hays&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Ikea&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Inditex&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Meta&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Playstation (Sony)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Puma&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Randstand&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Robert Half&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Robert Walters&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Salesforce&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Starbucks&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;youtube&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Zara&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Muitos desses dominios de campanha nao usam um host padrao / &#34;www&#34;, mas sim nomes de host especificos, como:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;aplicar.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;hire.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;carreiras.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;calendly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;caso.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;hr.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;vagas.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;join.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;kvn.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;recrutar.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;recruite.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;agendar.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;staff.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;start.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;threads.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;xds.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Isso pode reforcar um URL de aparencia valida para a vitima e tambem obscurecer as paginas de phishing no dominio para rastreadores ou pesquisadores que olham apenas para a raiz do dominio.&lt;/p&gt;
&lt;h2&gt;resposta a ameacas&lt;/h2&gt;
&lt;h3&gt;O que estamos fazendo&lt;/h3&gt;
&lt;p&gt;Estamos ativamente envolvidos nas seguintes atividades para mitigar esta ameaca:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Monitoramento continuo de novos dominios de phishing registrados e infraestrutura associada a esta campanha.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fornecer orientacao e assistencia as Organizacoes para melhorar a seguranca dos seus ambientes Okta e investigar qualquer atividade suspeita relacionada com contas potencialmente comprometidas.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Controles de Protecao&lt;/h2&gt;
&lt;h3&gt;Recomendacoes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Habilite o MFA (Autenticacao Multifator) resistente a phishing (FastPass/WebAuthn/chaves de acesso); desabilite SMS/voz para esses usuarios.&lt;/li&gt;
&lt;li&gt;Bloqueie e monitore dominios recem-registrados que imitem seu servico. Se o conteudo hospedado no dominio violar direitos autorais ou marcas legais, considere fornecer evidencias e emitir uma solicitacao de remocao junto ao registrador de dominio e/ou provedor de hospedagem web.&lt;/li&gt;
&lt;li&gt;Aplique DMARC/DKIM/SPF e alerte sobre e-mails de spoofing de recrutamento/contratacao.&lt;/li&gt;
&lt;li&gt;Ensine os usuarios a fazer login apenas em dominios conhecidos (digitar ou adicionar aos favoritos).&lt;/li&gt;
&lt;li&gt;Ensine os usuarios a identificar a falsificacao de BitB:&lt;ul&gt;
&lt;li&gt;Se um usuario tentar mover uma janela de login para fora de uma janela do site principal, devera ser capaz de move-la para qualquer lugar na tela do usuario. Uma caixa de dialogo de login falsa e um elemento fixo dentro da pagina host pai - ela so podera se mover dentro dos limites da janela da pagina host.&lt;/li&gt;
&lt;li&gt;Se um usuario minimizar a janela da pagina do host, uma caixa de dialogo de login real permanecera exibida independentemente da janela da pagina do host. Um elemento de login falso sera minimizado em sincronia com a janela da pagina do host.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Aconselhe os candidatos a emprego a utilizarem portais de carreiras oficiais e a rejeitarem solicitacoes ou links para se comunicarem por outras plataformas.&lt;/li&gt;
&lt;li&gt;Busque por IoCs (por exemplo, Chamadas de API do bot Telegram, t.me/, bot*getUpdates, sendMessage; Padroes CSS/JS do BitB).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Guia pratico de resposta&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Reportar e solicitar a remocao do site malicioso&lt;/li&gt;
&lt;li&gt;Redefina as credenciais (senhas, tokens de sessao) dos usuarios impactados e notifique, quando necessario.&lt;/li&gt;
&lt;li&gt;Revisar os registros de SSO dos usuarios afetados.&lt;/li&gt;
&lt;li&gt;Avalie se deve incluir informacoes sobre ataques &amp;quot;navegador-in-the-navegador&amp;quot; em seu programa de conscientizacao sobre seguranca.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Indicadores de comprometimento&lt;/h2&gt;
&lt;p&gt;Os contatos de seguranca dos clientes Okta podem fazer login e baixar os Indicadores de Comprometimento de security.okta.com no seguinte link:&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://security.okta.com/product/okta/jobseekers-exploited-in-fake-recruiter-phishing-campaigns&#34; target=&#34;_blank&#34;&gt;https://security.okta.com/product/okta/jobseekers-exploited-in-fake-recruiter-phishing-campaigns&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Uma nota sobre a linguagem de estimativa&lt;/h3&gt;
&lt;p&gt;As equipes do Okta Threat Intelligence usam os seguintes termos para expressar probabilidade, conforme descrito na Diretiva 203 da Comunidade de Inteligencia do Escritorio do Diretor de Inteligencia Nacional dos EUA - Padroes Analiticos.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Probabilidade&lt;/th&gt;
&lt;th&gt;Quase&lt;br&gt;
sem chance&lt;/th&gt;
&lt;th&gt;Muito&lt;br&gt;
improvavel&lt;/th&gt;
&lt;th&gt;Improvavel&lt;/th&gt;
&lt;th&gt;Aproximadamente&lt;br&gt;
chance igual&lt;/th&gt;
&lt;th&gt;Provavel&lt;/th&gt;
&lt;th&gt;Muito&lt;br&gt;
provavel&lt;/th&gt;
&lt;th&gt;Quase&lt;br&gt;
certo(a)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Probabilidade&lt;/td&gt;
&lt;td&gt;Remoto&lt;/td&gt;
&lt;td&gt;Altamente&lt;br&gt;
improvavel&lt;/td&gt;
&lt;td&gt;Inverossimil&lt;/td&gt;
&lt;td&gt;Aproximadamente&lt;br&gt;
probabilidades iguais&lt;/td&gt;
&lt;td&gt;Provavel&lt;/td&gt;
&lt;td&gt;Altamente&lt;br&gt;
Provavel&lt;/td&gt;
&lt;td&gt;Quase&lt;br&gt;
Certo&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Porcentagem&lt;/td&gt;
&lt;td&gt;1-5%&lt;/td&gt;
&lt;td&gt;5-20%&lt;/td&gt;
&lt;td&gt;20-45%&lt;/td&gt;
&lt;td&gt;45-55%&lt;/td&gt;
&lt;td&gt;55-80%&lt;/td&gt;
&lt;td&gt;80-95%&lt;/td&gt;
&lt;td&gt;95-99%&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Fri, 19 Dec 2025 08:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,ciam,iam,platform-abuse,social-engineering,credential-phishing,threat-insights</category>
                
                <dc:creator>Daniel López</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/phishing-campaigns-use-employee-benefits-lure-logins/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/phishing-campaigns-use-employee-benefits-lure-logins/</link>
                <title>Phishing campaigns use &amp;apos;Employee Benefits&amp;apos; lure to intercept Microsoft and Okta logins</title>
                <description>
                    <![CDATA[&lt;h2&gt;Resumo Executivo&lt;/h2&gt;
&lt;p&gt;O Okta Threat Intelligence identificou campanhas de phishing de varios estagios que visam Organizacoes que utilizam aplicativos da Microsoft e - onde o acesso a esses aplicativos e federado - o Okta como provedor de identidade (IdP).&lt;/p&gt;
&lt;p&gt;Nossas descobertas, primeiramente pesquisando uma campanha distinta que denominamos O-UNC-037, subsequentemente nos levaram a varias outras campanhas usando o mesmo kit de phishing e um tema de atracao muito semelhante. No entanto, a diversidade na infraestrutura e no estilo sugere que, embora estes usem o mesmo kit e tema, e provavel que sejam campanhas separadas executadas por outros agentes de ameacas. Este relatorio se concentra em O-UNC-037, embora compartilhemos detalhes das outras campanhas no apendice no final deste relatorio.&lt;/p&gt;
&lt;p&gt;A campanha O-UNC-037 esta ativa desde pelo menos outubro de 2025 e tem como alvo principal organizacoes de tecnologia e fornecimento industrial. Ela entrega e-mails de phishing usando uma isca tematica de &lt;b&gt;beneficios para funcionarios ou recursos humanos (RH)&lt;/b&gt; para enganar os usuarios a inserir suas credenciais em uma pagina falsa de login da Microsoft.&lt;/p&gt;
&lt;p&gt;A infraestrutura de phishing usa tecnicas de Adversario-no-Meio (AitM) para interceptar fluxos de autenticacao em tempo real, capturando credenciais, codigos de MFA e quaisquer tokens de sessao estabelecidos durante o evento de login. Essa capacidade pode ignorar a protecao de varios metodos comuns de MFA, como codigos SMS e senhas de uso unico (OTP) de aplicativos autenticadores. &lt;/p&gt;
&lt;p&gt;Para Organizacoes que usam o Okta para Single Sign-On (SSO), o ataque entao se intensifica para um segundo estagio, redirecionando as vitimas para uma reproducao maliciosa de uma pagina de Login Okta no dominio de phishing do segundo estagio, que atua como um servidor de retransmissao para, adicionalmente, capturar suas credenciais do Okta e roubar o cookie de sessao.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;Analise de Ameacas&lt;/h2&gt;
&lt;p&gt;Esta campanha de phishing usa uma tecnica de ataque de varios estagios. Ela tem como alvo especifico contas Microsoft e lida com o redirecionamento Okta SSO quando encontrado. A cadeia de ataque envolve varias etapas projetadas para direcionar os usuarios visados para uma pagina de coleta de credenciais AitM.&lt;/p&gt;
&lt;h3&gt;Taticas, Tecnicas e Procedimentos (TTPs) Observados:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Infraestrutura e acesso inicial:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;E-mails de phishing sao entregues com linhas de assunto personalizadas para incluir o nome do usuario e iscas como &#34;&lt;b&gt;Alerta de Beneficios para Funcionarios&lt;/b&gt;&#34; ou &#34;&lt;b&gt;mensagem segura do Departamento de RH&lt;/b&gt;&#34; para criar uma sensacao de urgencia.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;As campanhas usam dominios de redirecionamento para direcionar usuarios-alvo aos principais sites de phishing, evitando os controles de gateway de e-mail.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;As campanhas exigem que os usuarios resolvam um &lt;b&gt;Cloudflare CAPTCHA &lt;/b&gt;antes de apresentar a pagina de phishing.&lt;br&gt;
&lt;br&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Execucao e Roubo de Credenciais:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Usa &lt;b&gt;tecnicas de Adversario-no-Meio (AiTM) &lt;/b&gt;capturando credenciais, codigos de MFA e tokens de sessao, interceptando fluxos de autenticacao.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Implanta um ataque de phishing de varios estagios, primeiro visando credenciais da Microsoft e, em seguida, fazendo o pivot para o Okta SSO se a federacao for detectada.&lt;br&gt;
&lt;br&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Kit de Phishing e Atracao: &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Muito provavelmente, utiliza uma plataforma de&lt;b&gt;Phishing-as-a-Service (PhaaS)&lt;/b&gt; ou um kit de phishing altamente configuravel, evidenciado por parametros de URL para rastreamento de campanha e carregamento de modelo.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Usa uma isca de engenharia social generica, mas eficaz, de &amp;quot;Beneficios para Funcionarios&amp;quot;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;&lt;b&gt;Iscas de e-mail&lt;/b&gt;&lt;/h3&gt;
&lt;p&gt;O ataque comeca com um e-mail de phishing enviado ao alvo. Com base em suas caracteristicas visuais, essas iscas de e-mail altamente convincentes sao provavelmente geradas usando um modelo de linguagem de grande escala (LLM). Os e-mails usam nomes de remetentes e assuntos projetados para criar uma sensacao de urgencia e legitimidade relacionada a beneficios para funcionarios ou comunicacoes seguras.&lt;/p&gt;
&lt;p&gt;Exemplos de cabecalhos de e-mail observados:&lt;/p&gt;
&lt;pre&gt;
De: ADP BENEFITS &amp;lt;notifications[@]duobenefits[.]com&amp;gt;
Assunto: [Nome do Usuario]! Alerta de Beneficios para Funcionarios - Novas Alteracoes em Vigor Agora
&lt;/pre&gt;
&lt;pre&gt;
De: Secure Mail &amp;lt;noreply[@]mailsafe365[.]com&amp;gt;
Assunto: [Nome do Usuario]! Voce recebeu uma mensagem segura do Departamento de RH
&lt;/pre&gt;
&lt;p&gt;Tambem observamos exemplos do que parece ser abuso da plataforma de marketing por e-mail de terceiros de uma organizacao genuina, possivelmente por meio de uma conta comprometida:&lt;/p&gt;
&lt;pre&gt;
De: ADP Benefits &amp;lt;notifications_adp_com[@]emails[.]t??????s[.]Organizacao&amp;gt;
Assunto: Confidencial: [Nome do Usuario]! Seu Pacote de Beneficios Foi Atualizado
&lt;/pre&gt;
&lt;h3&gt;Links iniciais de redirecionamento em e-mails&lt;/h3&gt;
&lt;p&gt;Os usuarios sao direcionados primeiramente para a infraestrutura de phishing por meio de links de redirecionamento iniciais dentro dos e-mails. A maioria deles sao dominios recem-registrados de primeira parte, evitando problemas de reputacao historicos para contornar as medidas de seguranca de e-mail:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;benefits-alerts[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsapp001[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;qrcodelnk[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;302lnk[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;goto365[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;fastlink247[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;link24x7[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;fast2url[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;url247[.]link&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Tambem notamos um exemplo de link de redirecionamento abusando da conta legitima de uma organizacao em um servico de marketing por e-mail de terceiros para redirecionamento:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;t??????s[.]msg???[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Um exemplo de link de redirecionamento usa o site comprometido de uma organizacao genuina:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Marketing.s??????y[.].com&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Usar contas de servico de e-mail marketing comprometidas ou websites genuinos comprometidos e uma medida eficaz para alcancar maior entregabilidade durante campanhas de phishing.&lt;/p&gt;
&lt;p&gt;A camada de redirecionamento tambem oferece ao agente de ameacas a capacidade de substituir paginas de phishing de substituicao, caso alguma pagina de segundo estagio seja desativada.&lt;/p&gt;
&lt;h3&gt;Desafio de seguranca &lt;/h3&gt;
&lt;p&gt;Apos o redirecionamento para o site de phishing principal, o usuario e primeiramente apresentado a uma pagina intitulada &amp;quot;Verificacao de Seguranca&amp;quot;, empregando um CAPTCHA genuino do Cloudflare. Esta etapa foi projetada para aparentar legitimidade e atua como um &amp;quot;porteiro&amp;quot; para evitar a analise automatizada do site de phishing.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;Pagina inicial&lt;/h3&gt;
&lt;p&gt;Depois que o desafio CAPTCHA e concluido, o site exibe brevemente uma tela inicial com o tema adequado a isca mencionada.&lt;/p&gt;
&lt;h3&gt;Coleta de credenciais&lt;/h3&gt;
&lt;p&gt;Apos a tela inicial, um usuario-alvo e presenteado com a pagina de phishing de primeiro estagio, que se passa por um login da Microsoft e usa o ataque man-in-the-middle (AitM) para roubar credenciais de usuario e, se o usuario se autenticar com sucesso, todos os tokens resultantes.&lt;/p&gt;
&lt;h3&gt;Redirecionamento de segundo estagio para login Okta&lt;/h3&gt;
&lt;p&gt;Se o dominio de e-mail da vitima indicar que sua organizacao usa Okta para federacao de identidade, o script do site de phishing intercepta o fluxo de autenticacao legitimo. Ele substitui dinamicamente o URL de redirecionamento Okta legitimo por um malicioso (por exemplo, sso[.]oktacloud[.]io), enviando o usuario para uma pagina de phishing Okta semelhante para usar novamente o AitM para coletar suas credenciais SSO e roubar o cookie de sessao resultante. Detalamos essa tecnica em nossa analise de codigo, mais adiante neste relatorio. &lt;/p&gt;
&lt;h3&gt;Infraestrutura de campanha original&lt;/h3&gt;
&lt;p&gt;Nossa analise da campanha O-UNC-037 identificou a seguinte infraestrutura usada para hospedar as paginas falsas e maliciosas de login da Microsoft:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;benefitsemployeeaccess[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsquickaccess[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsworkspace[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitscentralportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsselfservice[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsmemberportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsgatewayportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitshubportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsadminportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsaccessportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;benefitsviewportal[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Os sites de phishing usam varios caminhos de URL para promover ainda mais a isca de &amp;quot;beneficios para funcionarios&amp;quot;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;/benefits/login/&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;/compensation/auth/&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;/rewards/verify/&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;/employee/access/&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Os usuarios federados sao redirecionados para as seguintes paginas de destino de segundo estagio apos fornecer as credenciais primarias para sua conta Microsoft. &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;sso[.]oktacloud[.]io&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;sso[.]okta-access[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Internal-networks[.]com&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A analise dos dominios de phishing de redirecionamento com segmentacao Okta nos levou a varias instancias usando Cloudflare Workers, que e uma plataforma sem servidor frequentemente utilizada por agentes de ameacas para hospedar e servir sites de phishing.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;sso[.]okta-proxy[.]workers[.]dev&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;okta[.]undermine[.]workers[.]dev&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;oktapage[.]oktamain[.]workers[.]dev&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;okta[.]eventspecial[.]workers[.]dev&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Infraestrutura de campanhas adicionais&lt;/h3&gt;
&lt;p&gt;Partindo da campanha de phishing O-UNC-037, descobrimos outras campanhas que utilizavam o mesmo kit de phishing e iscas muito semelhantes. A observacao dos detalhes da infraestrutura nesses outros exemplos sugere que e provavel que sejam operados independentemente por outros agentes maliciosos, possivelmente seguindo as instrucoes de um &amp;quot;metodo&amp;quot; compartilhado ou vendido. Incluimos uma lista desses dominios, juntamente com os dominios O-UNC-037, nos Indicadores de Compromisso, cujo link se encontra no final deste documento.&lt;/p&gt;
&lt;h3&gt;Analise de pagina de phishing&lt;/h3&gt;
&lt;p&gt;Esta campanha segue uma cadeia de ataque estruturada que combina engenharia social e tecnicas AitM capazes de roubar tokens de sessao do Microsoft 365 ou Okta. A analise dos URLs e paginas de phishing sugere que o ator esta usando um Phishing-as-a-Service (PhaaS) ou um kit de phishing altamente configuravel. &lt;/p&gt;
&lt;p&gt;Uma analise detalhada dos URLs de phishing revela um mecanismo de controle embutido em seus parametros de consulta, particularmente no parametro &#34;ht&#34;, que contem um objeto JSON codificado em Base64. &lt;/p&gt;
&lt;pre&gt;
https://benefitsemployeeaccess[.]com/rewards/verify/d582500e?s=3&amp;amp;ht=eyJpZCI6IjY2ZmI2OWMwNjA2N2RjOTM5Yzc5OTM1NWE0ODNjNzM3IiwidHlwZSI6ImhvcCIsImNhbXBhaWduX2lkIjoiY2FtcF82OGYyNjQ3YTlmYjE0IiwiaG9wX3RlbXBsYXRlIjoiYmVuZWZpdHMiLCJzdWNjZXNzX3RlbXBsYXRlIjoiYmVuZWZpdHNfZXJyb3IiLCJjcmVhdGVkIjoxNzYwOTM3NDcyLCJleHBpcmVzIjoxNzYwOTQ0NjcyLCJpcCI6IjExMy4yOS4yNDMuMSIsIm1heF91c2VzIjoxMDAwMDAwMCwidXNlcyI6MCwiaG9wX2NvdW50IjozLCJzZXNzaW9uIjoiZG9oNnBhbnE0Y3RhZTVsMjhvNWoyaTdoa3YifQ%3D%3D.bb0c9db57db67ff678edafb64f3cdc4fccfa93d4a8952e05ca2a3176e8134db5
&lt;/pre&gt;
&lt;pre style=&#34;text-align: left;&#34;&gt;


&lt;/pre&gt;
&lt;p&gt;Quando decodificado, esse objeto revela um conjunto abrangente de pontos de dados para rastreamento e controle de acesso. Contem informacoes detalhadas de rastreamento, incluindo um &amp;quot;campaign_id&amp;quot;, um &amp;quot;hop_template&amp;quot; para carregamento dinamico de conteudo, o endereco &amp;quot;ip&amp;quot; da vitima e um ID de &amp;quot;session&amp;quot; exclusivo. Simultaneamente, inclui os termos de acesso por meio de registros de data e hora de criacao e expiracao de links (&amp;quot;criado&amp;quot;, &amp;quot;expira&amp;quot;) e contadores de uso (&amp;quot;usos&amp;quot;, &amp;quot;usos_maximos&amp;quot;). Essa estrutura de dupla finalidade indica um sistema de backend que nao apenas funciona como um controlador para impor acesso estrito e com tempo limitado, mas tambem permite ao invasor rastrear campanhas individuais, carregar dinamicamente diferentes modelos de phishing e monitorar as interacoes com as vitimas. Essa capacidade permite ao agente adaptar facilmente suas iscas e alvos sem precisar reimplantar toda a infraestrutura.&lt;/p&gt;
&lt;pre&gt;
{
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;id&amp;quot;: &amp;quot;66fb69c06067dc939c799355a483c737&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;type&amp;quot;: &amp;quot;hop&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;campaign_id&amp;quot;: &amp;quot;camp_68f2647a9fb14&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;hop_template&amp;quot;: &amp;quot;benefits&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
    &amp;quot;success_template&amp;quot;: &amp;quot;benefits_error&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;created&amp;quot;: 1760973582,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;expires&amp;quot;: 1760980782,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;ip&amp;quot;: &amp;quot;?????&amp;quot;,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;max_uses&amp;quot;: 10000000,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;uses&amp;quot;: 0,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;hop_count&amp;quot;: 3,
&lt;/pre&gt;
&lt;pre&gt;
  &amp;quot;session&amp;quot;: &amp;quot;qa061c1uiht26gmtqcj49fsgci&amp;quot;
&lt;/pre&gt;
&lt;pre&gt;
}
&lt;/pre&gt;
&lt;p&gt;A analise da pagina inicial de phishing da Microsoft mostra o tratamento dado aos usuarios de organizacoes federadas pela Okta. Quando um usuario desse tipo insere seu e-mail, um portal de login legitimo do O365 normalmente retorna uma resposta JSON contendo um FederationRedirectUrl que aponta para o tenant Okta da empresa.&lt;/p&gt;
&lt;p&gt;A campanha usa JavaScript na pagina de phishing para interceptar este processo. O script esta configurado para:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Monitore as respostas de fetch do servidor.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Inspecione as respostas JSON em busca de chaves como FederationRedirectUrl, AuthURL ou RedirectUrl.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Verifique se o URL aponta para um tenant Okta legitimo (.okta.com, .oktapreview.com, etc.).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Se uma URL Okta legitima for encontrada, o script a substitui dinamicamente por uma URL que aponta para o dominio de phishing malicioso de segundo estagio do ator, por exemplo: sso[.]oktacloud[.].io.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;A resposta modificada e entao repassada ao navegador, redirecionando perfeitamente o usuario para a pagina de login falsa do Okta do ator.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;As credenciais capturadas e os cookies de sessao sao exfiltrados para um endpoint de API no servidor de phishing.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;O script inclui funcoes para preencher automaticamente o nome de usuario do hash da URL e clicar automaticamente nos botoes &amp;quot;Next&amp;quot; e &amp;quot;Stay signed in&amp;quot;, criando uma experiencia mais perfeita e menos suspeita para a vitima.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Essa interceptacao AitM permite que o agente sequestre o fluxo de autenticacao em tempo real, apresentando ao usuario uma replica da pagina de login do Okta para capturar as credenciais de Single Sign-On (SSO) e o cookie de sessao estabelecido.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;pre&gt;
     var _wd = &amp;quot;https://sso.oktacloud.io&amp;quot;;
&lt;/pre&gt;
&lt;pre&gt;
        var _iO = function (u) {
&lt;/pre&gt;
&lt;pre&gt;
            if (typeof u !== &amp;quot;string&amp;quot;) return false;
&lt;/pre&gt;
&lt;pre&gt;
            if (u.includes(&amp;quot;sso.oktacloud.io&amp;quot;)) return false;
&lt;/pre&gt;
&lt;pre&gt;
            if (u.includes(&amp;quot;/app/office365&amp;quot;)) return true;
&lt;/pre&gt;
&lt;pre&gt;
            if (u.match(/\.(okta|oktapreview|okta-emea)\.com/i)) return true;
&lt;/pre&gt;
&lt;pre&gt;
            if (u.match(/\/sso\/saml|\/sso\/wsfed|\/app\/[^\/]+\/sso/i)) return true;
&lt;/pre&gt;
&lt;pre&gt;
            return false;
&lt;/pre&gt;
&lt;pre&gt;
        };
&lt;/pre&gt;
&lt;h3&gt;Tentativas subsequentes de roubo da conta&lt;/h3&gt;
&lt;p&gt;Apos o comprometimento bem-sucedido de credenciais e roubo de token de sessao, os agentes de ameacas foram observados tentando e autenticando com sucesso a partir de IPs CloudFlare (AS13335). &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h2&gt;resposta a ameacas&lt;/h2&gt;
&lt;h3&gt;O que estamos fazendo&lt;/h3&gt;
&lt;p&gt;Estamos ativamente envolvidos nas seguintes atividades para mitigar esta ameaca:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Monitoramento continuo de dominios de phishing e infraestrutura recem-registrados associados a esta campanha.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Apresentar proativamente relat
rios de abuso aos registradores e provedores de hospedagem relevantes para iniciar solicita
es de remo
o para sites maliciosos identificados.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fornecer orientacao e assistencia as organizacoes para aprimorar a seguranca de seus ambientes Okta e investigar qualquer atividade suspeita relacionada a contas potencialmente comprometidas.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Controles Protetores&lt;/h2&gt;
&lt;h3&gt;Recomendacoes para clientes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Incentive os usuarios a se registrarem em autenticadores fortes, como Okta FastPass, FIDO2 WebAuthn e cartoes inteligentes, e aplique a resistencia ao phishing na politica.&lt;/li&gt;
&lt;li&gt;As politicas de acesso de aplicativos Okta (anteriormente &amp;quot;politicas de autenticacao&amp;quot;) tambem podem ser usadas para restringir o acesso a contas de usuario com base em uma variedade de pre-requisitos configuraveis pelo cliente. Recomendamos que os administradores restrinjam o acesso a aplicativos confidenciais a dispositivos que sao &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/managed-main.htm&#34; target=&#34;_blank&#34;&gt;gerenciados&lt;/a&gt; por ferramentas de Gerenciamento de Endpoint e &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/edr-integration-main.htm&#34; target=&#34;_blank&#34;&gt;protegidos por ferramentas de seguranca de endpoint&lt;/a&gt;. Para acesso a aplicativos menos confidenciais, exija dispositivos &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/fp/fp-main.htm&#34; target=&#34;_blank&#34;&gt;registrados&lt;/a&gt; (usando Okta FastPass) que &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/device-assurance.htm&#34; target=&#34;_blank&#34;&gt;exibam indicadores de higiene essencial&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Negue ou exija maior seguranca para solicitacoes de redes raramente usadas. Com o Okta Network Zones, o acesso pode ser controlado por local, ASN (Numero do Sistema Autonomo), IP e Tipo de IP (que pode identificar proxies de anonimato conhecidos).&lt;/li&gt;
&lt;li&gt;As avaliacoes de Comportamento e Risco do Okta podem ser usadas para identificar solicitacoes de acesso a aplicativos que se desviam dos padroes de atividade do usuario estabelecidos anteriormente. As politicas podem ser configuradas para aumento de nivel ou negar solicitacoes usando este contexto.&lt;/li&gt;
&lt;li&gt;Treine os usuarios para identificar indicadores de e-mails suspeitos, sites de phishing e tecnicas comuns de engenharia social usadas por invasores. Facilite para os usuarios relatarem problemas potenciais configurando &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/security_general.htm&#34;&gt;Notificacoes para o Usuario Final&lt;/a&gt; e &lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/suspicious-activity-reporting.htm&#34;&gt;Relatorios de Atividade Suspeita&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Documente, divulgue e siga um processo padronizado para validar a identidade de usuarios remotos que entram em contato com o pessoal de suporte de TI e vice-versa.&lt;/li&gt;
&lt;li&gt;Adote uma abordagem de &amp;quot;Zero privilegios permanentes&amp;quot; para acesso administrativo. Atribua aos administradores &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/custom-admin-role/custom-admin-roles.htm&#34;&gt;Funcoes de Administrador Personalizadas&lt;/a&gt; com as menores permissoes necessarias para as tarefas diarias e exija autorizacao dupla para acesso JIT (just-in-time) a funcoes mais privilegiadas.&lt;/li&gt;
&lt;li&gt;Aplique o IP Session Binding a todos os aplicativos administrativos para impedir a reproducao de sessoes administrativas roubadas.&lt;/li&gt;
&lt;li&gt;Ative &lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/admin-console-protected-actions.htm#:~:text=Protected%20actions%20are%20critical%20tasks,according%20to%20a%20configured%20interval.&#34;&gt;as Acoes Protegidas&lt;/a&gt; para forcar a reautenticacao sempre que um usuario administrativo tentar executar acoes confidenciais.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Observando e respondendo a infraestrutura de phishing:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Analise os registros de aplicativos (registros Okta, web proxies, sistemas de e-mail, servidores DNS, firewalls) em busca de qualquer evidencia de comunicacao com dominios suspeitos.&lt;/li&gt;
&lt;li&gt;Monitore os dominios regularmente para ver se o conteudo muda.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Se o conteudo hospedado no dominio violar direitos autorais ou marcas legais, considere fornecer evidencias e emitir uma solicitacao de remocao ao registrador de dominio e/ou provedor de hospedagem na web.&lt;/p&gt;
&lt;h2&gt;Indicadores de Comprometimento&lt;/h2&gt;
&lt;p&gt;Os contatos de seguranca dos clientes da Okta podem fazer login e baixar os Indicadores de Comprometimento como um arquivo CSV em security.okta.com no seguinte link:&lt;br&gt;
&lt;br&gt;
&lt;a href=&#34;https://security.okta.com/product/okta/phishing-campaigns-use-employee-benefits-lure-to-intercept-microsoft-and-okta-logins&#34; target=&#34;_blank&#34;&gt;https://security.okta.com/product/okta/phishing-campaigns-use-employee-benefits-lure-to-intercept-microsoft-and-okta-logins&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;h3&gt;Uma nota sobre a linguagem de estimativa&lt;/h3&gt;
&lt;p&gt;As equipes de Okta Threat Intelligence usam os seguintes termos para expressar a probabilidade, conforme descrito na Diretiva 203 da Comunidade de Inteligencia do Gabinete do Diretor de Inteligencia Nacional dos EUA - Padroes Analiticos.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Probabilidade&lt;/th&gt;
&lt;th&gt;Quase&lt;br&gt;
sem chance&lt;/th&gt;
&lt;th&gt;Muito&lt;br&gt;
improvavel&lt;/th&gt;
&lt;th&gt;Improvavel&lt;/th&gt;
&lt;th&gt;Aproximadamente&lt;br&gt;
chance igual&lt;/th&gt;
&lt;th&gt;Provavel&lt;/th&gt;
&lt;th&gt;Muito&lt;br&gt;
provavel&lt;/th&gt;
&lt;th&gt;Quase&lt;br&gt;
certo(a)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Probabilidade&lt;/td&gt;
&lt;td&gt;Remoto&lt;/td&gt;
&lt;td&gt;Altamente&lt;br&gt;
improvavel&lt;/td&gt;
&lt;td&gt;Improbable&lt;/td&gt;
&lt;td&gt;Aproximadamente&lt;br&gt;
mesmas chances&lt;/td&gt;
&lt;td&gt;Provavel&lt;/td&gt;
&lt;td&gt;Altamente&lt;br&gt;
Provavel&lt;/td&gt;
&lt;td&gt;Quase&lt;br&gt;
Certeza&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Porcentagem&lt;/td&gt;
&lt;td&gt;1-5%&lt;/td&gt;
&lt;td&gt;5-20%&lt;/td&gt;
&lt;td&gt;20-45%&lt;/td&gt;
&lt;td&gt;45-55%&lt;/td&gt;
&lt;td&gt;55-80%&lt;/td&gt;
&lt;td&gt;80-95%&lt;/td&gt;
&lt;td&gt;95-99%&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Tue, 21 Oct 2025 07:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,social-engineering,credential-phishing,token-replay,iam</category>
                
                <dc:creator>Houssem Eddine Bordjiba</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/opportunistic-sms-pumping-attacks-target-customer-sign-up-pages/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/opportunistic-sms-pumping-attacks-target-customer-sign-up-pages/</link>
                <title>Wide-scale, opportunistic SMS pumping attacks target customer sign-up pages</title>
                <description>
                    <![CDATA[&lt;h2&gt;Executive Summary&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence has identified a cluster of shared disposable email infrastructure and commodity proxy services, internally designated as O-UNC-036, that is being used to launch high-volume, automated attempts against public API endpoints.&lt;/p&gt;
&lt;p&gt;This infrastructure has been observed in multiple persistent, large scale and&amp;nbsp;financially motivated SMS pumping campaigns starting at least as&amp;nbsp;early as July 2025.&lt;/p&gt;
&lt;p&gt;To execute this attack, threat actors undertake the following sequence of&amp;nbsp;actions:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Create a new account using a disposable email address, often tied to a&amp;nbsp;set of domains&lt;br&gt;
&lt;/li&gt;
&lt;li&gt;Add an actor-controlled phone number as an authentication factor&lt;br&gt;
&lt;/li&gt;
&lt;li&gt;Send as many messages to the number as possible in order to achieve&amp;nbsp;their monetary objectives&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;These attacks generate significant financial costs for the target&amp;nbsp;organizations by running up bills with their telephony providers.&amp;nbsp;We have been able to track historical activity from this cluster of disposable&amp;nbsp;email domains back to at least March 2024, indicating a sustained, adaptive&amp;nbsp;effort. Due to the high financial risk and potential for service degradation, we&amp;nbsp;strongly recommend the immediate implementation of the protective&amp;nbsp;controls, monitoring and aggressive response outlined in this report.&lt;/p&gt;
&lt;h2&gt;Threat&amp;nbsp;Analysis&lt;/h2&gt;
&lt;p&gt;The primary objective of this campaign is opportunistic, large-scale account&amp;nbsp;creation in order to carry out SMS pumping campaigns. In these attacks,&amp;nbsp;threat actors profit by collaborating with high-cost international or premium-rate SMS providers. By exploiting the SMS delivery system of the target&amp;nbsp;identity platform, the attacker triggers messages to phone numbers they&amp;nbsp;control in high-cost regions. The victim organization is then billed for the&amp;nbsp;exorbitant volume and cost of these international or premium SMS&amp;nbsp;messages, with the cost of attacks potentially costing hundreds of&amp;nbsp;thousands of dollars in telephony bills.&lt;/p&gt;
&lt;p&gt;The attack follows a high-volume pattern:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Reconnaissance and Enumeration: &lt;/b&gt;Attackers identify multi-factor authentication (MFA) or user registration endpoints that trigger an SMS code.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Infrastructure Setup: &lt;/b&gt;Actors use commodity proxy services (VPNs, anonymizing proxies, residential botnets etc.) to distribute the source IP addresses of the traffic, reducing the efficacy of rate-limiting based solely on IP.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;High-Volume Requests: &lt;/b&gt;Automated scripts submit requests using known, high-cost phone country codes and rapidly generated, disposable email addresses.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Cluster Activity: &lt;/b&gt;The O-UNC-036 infrastructure is a key enabler. This cluster utilizes a revolving pool of shared disposable email domains to bypass email-based rate limits and tenant-level velocity checks, allowing them to rapidly cycle through accounts for message requests. Okta Threat Intelligence has tracked activity in this cluster back to at least March 2024.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Target Scope: &lt;/b&gt;We observed this activity in multiple tenants and organizations of both Auth0 and OCI, indicating a widespread, indiscriminate search for vulnerable endpoints that trigger SMS delivery. The same shared infrastructure is likely also used to attack organizations building their own customer sign-in pages or using alternative services.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For technical details of how to identify these attacks in your logs, see the&amp;nbsp;Detection and Indicators sections of this report.&lt;/p&gt;
&lt;h2&gt;Detection&lt;/h2&gt;
&lt;p&gt;Our research has not uncovered any legitimate use of emails under domains&amp;nbsp;listed in the indicators section of this report. Thus the existence of users with such&amp;nbsp;emails is sufficient to detect attacks. Given the potential duration of this&amp;nbsp;attack, it is critical that administrators look back as far as possible in their&amp;nbsp;logs to determine the scope of past and future impact.&lt;/p&gt;
&lt;h3&gt;Okta Customer Identity&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;High numbers of messages being sent to countries outside of your&amp;nbsp;company&#39;s normal operating regions.&lt;/li&gt;
&lt;li&gt;A spike in the following event types:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;system.sms.send_okta_push_verify_message
&lt;/pre&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;or&lt;/p&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;system.sms.send_factor_verify_message where result=DENY
&lt;/pre&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;and&lt;/p&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;reason=Toll Fraud Suspected
&lt;/pre&gt;
&lt;ul&gt;
&lt;li&gt;A spike in the following event type:&lt;/li&gt;
&lt;/ul&gt;
&lt;pre&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;system.email.new_device_notification.sent_message
&lt;/pre&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;as malicious account&#39;s alternative proxy providers&amp;nbsp;or ASNs every login.&lt;/p&gt;
&lt;p&gt;See the &#34;Monitoring of your Okta org&#34; section of our support article &#34;&lt;a href=&#34;https://support.okta.com/help/s/article/How-to-mitigate-toll-fraud-when-using-Okta-for-voice-authentication?language=en_US&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;How to&amp;nbsp;Mitigate Toll Fraud when Using Okta for Voice Authentication&lt;/a&gt;&#34; for a&amp;nbsp;comprehensive overview of detection strategies.&lt;/p&gt;
&lt;h3&gt;Auth0&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;ss events from the domains listed in the Indicators of Compromise&amp;nbsp;section. Administrators should refer to &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/a735af3848d4e22e9157ea9982578d21bc399100/detections/risk_of_signup_fraud_by_disposable_domains.yml&#34;&gt;detection rules&lt;/a&gt; provided in the FOSS Auth0 Security Detection Catalog and modify them as needed.&lt;/li&gt;
&lt;li&gt;Spikes in Guardian events, especially gd_enrollment_complete and gd_send_sms events. We advise administrators to use the &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/a735af3848d4e22e9157ea9982578d21bc399100/detections/risk_of_signup_fraud_by_volume.yml&#34;&gt;risk_of_signup_fraud_by_volume.yml&lt;/a&gt; and &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/a735af3848d4e22e9157ea9982578d21bc399100/detections/sms_bombarding.yml&#34;&gt;sms_bombarding.yml&lt;/a&gt; detection rules in the &lt;a href=&#34;https://github.com/auth0/auth0-customer-detections/blob/a735af3848d4e22e9157ea9982578d21bc399100/detections/risk_of_signup_fraud_by_disposable_domains.yml&#34;&gt;Auth0 Security Detection Catalog&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;A spike in &#34;&lt;a href=&#34;https://auth0.com/docs/secure/security-center#threat-behavior-trends&#34;&gt;MFA bypass&#34; events in Security Center&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;High numbers of messages being sent to countries outside of your company&#39;s normal operating regions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Protective&amp;nbsp;controls and&amp;nbsp;response&lt;/h2&gt;
&lt;p&gt;Okta Threat Intelligence has observed these attackers abandon a target&amp;nbsp;when frustrated by the introduction of controls. This makes aggressive&amp;nbsp;response and implementation of proper controls effective in stopping these&amp;nbsp;attacks.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;While ever sending SMS messages costs money, attackers will find a&amp;nbsp;way to skim off the top. This risk can only be fully mitigated by migrating to another authentication factor. We strongly recommend the adoption of FIDO Authentication (passkeys).&lt;/li&gt;
&lt;li&gt;Our research has not uncovered legitimate use of the domains provided in the &lt;b&gt;Identicators&lt;/b&gt; section of this document. Deactivate users that provided these emails after making your own assessment.&lt;/li&gt;
&lt;li&gt;Accounts created from the ASNs in the &lt;b&gt;Indicators&lt;/b&gt; section of this document are seldom legitimate. Administrators are advised to deactivate these accounts unless friction is a major concern.&lt;/li&gt;
&lt;li&gt;Disable sending messages to untrusted countries in your telephony provider.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Okta Customer Identity&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Implement &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-webauthn.htm&#34;&gt;FIDO Authentication with WebAuthn&lt;/a&gt; and migrate users&#39; factors away from SMS.&lt;/li&gt;
&lt;li&gt;Use &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-webauthn.htm&#34;&gt;passkeys&lt;/a&gt; instead of SMS or voice factors.&lt;/li&gt;
&lt;li&gt;Enable &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/itp/bot-protection-config.htm&#34;&gt;bot protection for enforcement&lt;/a&gt;. We recommend setting a Bot Likeliness threshold of Low and above or Always on Sign-up and Sign-in flows when you are under attack.&lt;/li&gt;
&lt;li&gt;Block anonymizers and proxies at edge by leveraging &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/network/about-enhanced-dynamic-zones.htm&#34;&gt;enhanced dynamic network zones&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Utilizing workflows to manage self-service registration users from malicious domains. An Okta Identity Defense generated workflow exists that can be utilized or expanded upon and can be found &lt;a href=&#34;https://github.com/okta/customer-detections/tree/cf328c23953bc3aab8f9007a41f895ca1fb2585a/workflows/deactivate_ssr_users&#34;&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Utilize the Okta API to quickly &lt;a href=&#34;https://developer.okta.com/docs/api/openapi/okta-management/management/tag/UserLifecycle/#tag/UserLifecycle/operation/deactivateUser&#34;&gt;deactivate&lt;/a&gt; large batches of identified users.&lt;/li&gt;
&lt;li&gt;Leverage &lt;a href=&#34;https://www.okta.com/identity-verification/&#34;&gt;identity proofing integrations&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;See our support article &#34;&lt;a href=&#34;https://support.okta.com/help/s/article/How-to-mitigate-toll-fraud-when-using-Okta-for-voice-authentication?language=en_US&#34;&gt;How to Mitigate Toll Fraud when Using Okta for Voice Authentication&lt;/a&gt;&#34; for a comprehensive overview of responses and preventative controls.&lt;/li&gt;
&lt;li&gt;Block suspicious activity using the tooling provided by your telephony provider.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Contact Okta Support to provide a list of allowed telephony countries if&amp;nbsp;you&#39;re confident in the specific list of countries servicing your customers.&amp;nbsp;You can also request to modify the rate limits on your organization.&lt;/p&gt;
&lt;h3&gt;Auth0&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Implement &lt;a href=&#34;https://auth0.com/docs/secure/multi-factor-authentication/fido-authentication-with-webauthn&#34;&gt;FIDO Authentication with Webauthn&lt;/a&gt; and migrate users&#39;&amp;nbsp;factors away from SMS or voice factors.&lt;/li&gt;
&lt;li&gt;Use &lt;a href=&#34;https://auth0.com/docs/authenticate/database-connections/passkeys&#34;&gt;passkeys&lt;/a&gt; instead of SMS or voice factors.&lt;/li&gt;
&lt;li&gt;Block requests from the ASes and TLS client fingerprints in the Indicators of Compromise section at edge with &lt;a href=&#34;https://auth0.com/docs/secure/tenant-access-control-list&#34;&gt;Auth0&#39;s Tenant Access Control List&lt;/a&gt; feature.&lt;/li&gt;
&lt;li&gt;Since these attackers are especially sensitive to friction, enabling &lt;a href=&#34;https://auth0.com/docs/secure/attack-protection/bot-detection&#34;&gt;bot detection&lt;/a&gt; and enforcing CAPTCHA can be an effective control.&lt;/li&gt;
&lt;li&gt;Block users from registering using the email domains listed in the&lt;/li&gt;
&lt;li&gt;Indicators of Compromise section with &lt;a href=&#34;https://auth0.com/docs/customize/actions/explore-triggers/signup-and-login-triggers/login-trigger#access-control&#34;&gt;Signup and Login triggers&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Disable sending messages to untrusted countries in your telephony provider.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://auth0.com/docs/troubleshoot/customer-support/operational-policies/rate-limit-policy#user-requests&#34;&gt;Lower your rate limits&lt;/a&gt; to lower the number of accounts attackers can create using the same IP address.&lt;/li&gt;
&lt;li&gt;Consider identity proofing integrations like those available in the &lt;a href=&#34;https://marketplace.auth0.com/categories/identity-proofing&#34;&gt;Auth0 marketplace&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;If you identify a large number of fraudulent users, engage Auth0 support for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;i&gt;Grayson Schermerhorn and Mathew Woodyard contributed to this research.&lt;/i&gt;&lt;/p&gt;
&lt;h2&gt;Appendix A: Indicators&lt;/h2&gt;
&lt;p&gt;This is an ongoing investigation, and additional Indicators may be identified as the campaign evolves. Organizations&amp;nbsp;are advised to remain vigilant and implement the recommended mitigation strategies.&lt;/p&gt;
&lt;table cellpadding=&#34;10&#34; cellspacing=&#34;0&#34; border=&#34;0&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th style=&#34;text-align: left;&#34; colspan=&#34;2&#34;&gt;Domain&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;ul&gt;
&lt;li&gt;2mails1box.com&lt;/li&gt;
&lt;li&gt;300bucks.net&lt;/li&gt;
&lt;li&gt;blueink.top&lt;/li&gt;
&lt;li&gt;desumail.com&lt;/li&gt;
&lt;li&gt;e-boss.xyz&lt;/li&gt;
&lt;li&gt;e-mail.lol&lt;/li&gt;
&lt;li&gt;echat.rest&lt;/li&gt;
&lt;li&gt;electroletter.space&lt;/li&gt;
&lt;li&gt;emailclub.net&lt;/li&gt;
&lt;li&gt;energymail.org&lt;/li&gt;
&lt;li&gt;gogomail.ink&lt;/li&gt;
&lt;li&gt;gopostal.top&lt;/li&gt;
&lt;li&gt;guesswho.click&lt;/li&gt;
&lt;li&gt;homingpigeon.org&lt;/li&gt;
&lt;li&gt;kakdela.net&lt;/li&gt;
&lt;li&gt;letters.monster&lt;/li&gt;
&lt;li&gt;lostspaceship.net&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;td&gt;&lt;ul&gt;
&lt;li&gt;message.rest&lt;/li&gt;
&lt;li&gt;myhyperspace.org&lt;/li&gt;
&lt;li&gt;mypost.lol&lt;/li&gt;
&lt;li&gt;postalbro.com&lt;/li&gt;
&lt;li&gt;protonbox.pro&lt;/li&gt;
&lt;li&gt;rocketpost.org&lt;/li&gt;
&lt;li&gt;sendme.digital&lt;/li&gt;
&lt;li&gt;shroudedhills.com&lt;/li&gt;
&lt;li&gt;specialmail.online&lt;/li&gt;
&lt;li&gt;ultramail.pro&lt;/li&gt;
&lt;li&gt;whyusoserious.org&lt;/li&gt;
&lt;li&gt;wirelicker.com&lt;/li&gt;
&lt;li&gt;writeme.live&lt;/li&gt;
&lt;li&gt;writemeplz.net&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Autonomous Systems Number (ASN)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;ul&gt;
&lt;li&gt;212238&lt;/li&gt;
&lt;li&gt;16276&lt;/li&gt;
&lt;li&gt;44477&lt;/li&gt;
&lt;li&gt;26548&lt;/li&gt;
&lt;li&gt;200373&lt;/li&gt;
&lt;li&gt;137409&lt;/li&gt;
&lt;li&gt;214483&lt;/li&gt;
&lt;li&gt;13213&lt;/li&gt;
&lt;li&gt;397368&lt;/li&gt;
&lt;/ul&gt;
&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;TLS Client JA4 Fingerprints are also available from an unredacted advisory that Okta customers can download at &lt;a href=&#34;https://security.okta.com/product/oktathreatintelligence/wide-scale-opportunistic-sms-pumping-attacks-target-customer-sign-up-pages&#34;&gt;security.okta.com&lt;/a&gt;.&lt;/p&gt;
]]>
                </description>
                <pubDate>Tue, 14 Oct 2025 07:00:00 +0000</pubDate>
                
                    <category>threat-insights,blog-post,threat-intelligence,ciam,fraudulent-registration</category>
                
                <dc:creator>Grayson Schermerhorn, Mathew Woodyard</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/the-s1ngularity-attack--when-attackers-prompt-your-ai-agents-to/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/the-s1ngularity-attack--when-attackers-prompt-your-ai-agents-to/</link>
                <title>The s1ngularity attack: When attackers prompt your AI agents to do their bidding</title>
                <description>
                    <![CDATA[&lt;p&gt;Em meados de setembro, um incidente na cadeia de suprimentos de software - comumente chamado de &#34;ataque s1ngularity&#34; - marcou um ponto de virada no uso de Inteligencia Artificial por adversarios. &lt;/p&gt;
&lt;p&gt;Embora o vetor de acesso inicial fosse familiar - um ataque de phishing direcionado a mantenedores de pacotes npm -, o malware resultante era inedito. Este e um dos primeiros ataques em que agentes de IA locais foram usados como arma para auxiliar no roubo de credenciais.&lt;/p&gt;
&lt;p&gt;Esta tecnica representa uma escalada ameacadora na engenhosidade do invasor, indo alem de simples scripts personalizados para alavancar os recursos de resolucao de problemas das ferramentas de IA ja disponiveis na maquina de um alvo.&lt;/p&gt;
&lt;p&gt;Eu me sentei com Paul McCarty, chefe de pesquisa da Safety Cybersecurity - que recentemente publicou uma analise detalhada do ataque - para discutir suas descobertas, incluindo os prompts de IA usados para procurar segredos e burlar as protecoes, e como essa ameaca poderia evoluir no futuro. Assista ao video acima ou continue lendo para ter uma visao geral do que conversamos.&lt;/p&gt;
&lt;h2&gt;A anatomia de um ataque pos-instalacao&lt;/h2&gt;
&lt;p&gt;Durante o ataque, atualizacoes maliciosas foram enviadas para pacotes npm populares, incluindo &lt;a href=&#34;https://www.npmjs.com/package/nx&#34; target=&#34;_blank&#34;&gt;nx&lt;/a&gt;, o que resultou no roubo de milhares de credenciais de desenvolvedores. Um componente-chave do malware era um script pos-instalacao que o invasor chamou de telemetry.js.&lt;/p&gt;
&lt;p&gt;A principal funcao deste script era ser executado imediatamente apos a instalacao e procurar no host comprometido por arquivos confidenciais e segredos. Crucialmente, o invasor introduziu um novo metodo de descoberta, verificando a presenca de agentes CLI locais para modelos de linguagem de grande escala (LLMs) populares - especificamente Claude, Gemini e AWS Q.&lt;/p&gt;
&lt;p&gt;McCarty descreve isso como uma clara evolucao da abordagem de &amp;quot;viver da terra&amp;quot;, onde os invasores abusam de ferramentas confiaveis pre-instaladas. Os desenvolvedores geralmente tem esses agentes de CLI instalados para agilizar os fluxos de trabalho de codificacao, tornando-os um alvo de alto valor e prontamente disponivel para um invasor.&lt;/p&gt;
&lt;h2&gt;Vivendo de prompts locais&lt;/h2&gt;
&lt;p&gt;O script malicioso telemetry.js nao apenas procurava passivamente por arquivos; ele usava agentes de IA para fazer o trabalho pesado por meio de um prompt.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Verificacao inicial:&lt;/b&gt; O script detectaria se um agente de IA suportado (app CLI) foi instalado e em qual plataforma (o malware visava principalmente hosts Linux e macOS).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;O prompt:&lt;/b&gt; O malware entao executava um prompt especialmente elaborado por meio do agente instalado. O objetivo principal do prompt era a enumeracao de arquivos: pedir a IA para pesquisar recursivamente o sistema de arquivos do host e gerar uma matriz abrangente de arquivos que poderiam conter segredos.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Segredos Alvo:&lt;/b&gt; Esta nao foi uma busca cega. O prompt focava em &amp;quot;arquivos suculentos&amp;quot;, como .env e .config arquivos, que normalmente conteriam segredos, como:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Tokens do GitHub e npm&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Credenciais da plataforma de nuvem (por exemplo, tokens da AWS)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Chaves SSH&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;O papel do agente de IA era usar os vastos dados de treinamento do LLM e o conhecimento contextual do ambiente do alvo para determinar os melhores locais para pesquisar. O agente de IA forneceu efetivamente ao invasor uma ferramenta de descoberta que poderia se adaptar dinamicamente ao ambiente do alvo.&lt;/p&gt;
&lt;h2&gt;Os agentes de IA sao imprevisiveis, mas confiaveis o suficiente em escala&lt;/h2&gt;
&lt;p&gt;A &lt;a href=&#34;https://www.getsafety.com/blog-posts/analyzing-nx-ai-prompt&#34; target=&#34;_blank&#34;&gt;analise da carga maliciosa feita por McCarty&lt;/a&gt; revelou uma visao fascinante do processo de pensamento do invasor. Varias atualizacoes sucessivas nos pacotes envenenados revelam pelo menos quatro versoes diferentes do prompt de IA.&lt;/p&gt;
&lt;p&gt;Essa rapida iteracao foi uma batalha ativa contra o nao determinismo e as protecoes inerentes aos aplicativos de IA. O invasor teve que experimentar continuamente para encontrar o prompt perfeito que:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Ignorar protecoes:&lt;/b&gt; Evitar as salvaguardas integradas do agente que rejeitam solicitacoes maliciosas obvias ou solicitacoes para acessar recursos do sistema de arquivos&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Maximize os resultados:&lt;/b&gt; Gere a lista mais abrangente de caminhos de arquivos confidenciais&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Otimize a velocidade: &lt;/b&gt;Reduza o foco para excluir arquivos de codigo-fonte comuns, acelerando o processo geral de coleta de dados&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Esse processo iterativo demonstra uma das deficiencias das ferramentas de IA: os usuarios geralmente precisam fazer a mesma pergunta varias vezes, de maneiras diferentes, para se aproximarem de um resultado bem-sucedido. Tambem destaca um risco crescente para os defensores: nao ha garantias de que os agentes de IA aderirao aos guardrails. Como o proprio teste de McCarty mostrou, os agentes de IA as vezes &#34;ignoravam os guardrails e simplesmente entravam no modo YOLO&#34;.&lt;/p&gt;
&lt;p&gt;Este incidente confirma que a IA agentica representa uma superficie de ataque nova e significativa. Quando conectados a estacoes de trabalho de Developers, eles podem ser transformados em um mecanismo poderoso de descoberta para a coleta de credenciais e outras informacoes confidenciais.&lt;/p&gt;
&lt;h2&gt;Leitura recomendada&lt;/h2&gt;
&lt;p&gt;Para uma analise tecnica aprofundada das quatro versoes de prompts de IA maliciosos e suas diferentes taxas de sucesso contra Claude e Gemini, recomendamos fortemente a leitura da analise completa de Paul McCarty e da equipe de Seguranca:&lt;a href=&#34;https://www.getsafety.com/blog-posts/analyzing-nx-ai-prompt&#34; target=&#34;_blank&#34;&gt; Analysing the AI used in the NX Attack&lt;/a&gt;.&lt;/p&gt;
]]>
                </description>
                <pubDate>Sun, 05 Oct 2025 22:00:00 +0000</pubDate>
                
                    <category>threat-intelligence,ai,malware</category>
                
                <dc:creator>Brett Winterford</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/evil-proxy-phishing-campaign/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/evil-proxy-phishing-campaign/</link>
                <title>EvilProxy phishing campaign leverages convincing impersonations of enterprise applications</title>
                <description>
                    <![CDATA[&lt;h2&gt;Resumo Executivo&lt;/h2&gt;
&lt;p&gt;A Okta Threat Intelligence identificou uma campanha de ataque de alto volume que, segundo pesquisas subsequentes, esta ativa desde pelo menos marco de 2025, utilizando o kit de ferramentas EvilProxy de phishing-as-a-service (PhaaS) para executar ataques de phishing em tempo real projetados para roubar credenciais de usuarios e cookies de sessao ativos. Rastreamos esta campanha como O-UNC-035.&lt;/p&gt;
&lt;p&gt;Esta operacao tem como alvo organizacoes em varios setores, incluindo financas, governo, saude e tecnologia, usando principalmente iscas altamente convincentes que se passam por ferramentas de negocios populares, como SAP Concur, e servicos de assinatura de documentos, como Adobe ou DocuSign.&lt;/p&gt;
&lt;h2&gt;Analise de Ameacas&lt;/h2&gt;
&lt;h3&gt;EvilProxy Phishing-as-a-Service&lt;/h3&gt;
&lt;p&gt;EvilProxy (O-TA-041) e um kit de ferramentas PhaaS que usa uma arquitetura de proxy reverso/adversario-no-meio (AitM) para interceptar logins e cookies de sessao das vitimas em tempo real, permitindo que os invasores burlem a autenticacao multifator (MFA) e sequestrem contas.&lt;/p&gt;
&lt;p&gt;Originalmente observado em 2022 e rapidamente transformado em produto nos mercados da dark web, o EvilProxy tem sido amplamente utilizado em campanhas direcionadas de roubo da conta e Business e-mail comprometimento porque ele faz o proxy de sites legitimos. Isso significa que os usuarios veem prompts de MFA reais e que o invasor e capaz de capturar tokens e cookies para que o invasor possa reproduzir. Como o EvilProxy e vendido e mantido como um servico, ele dimensiona ataques e diminui a barreira de habilidades para criminosos: os operadores podem iniciar grandes volumes de campanhas de phishing personalizadas.&lt;/p&gt;
&lt;h3&gt;Mecanismos de atracao&lt;/h3&gt;
&lt;p&gt;Observamos softwares e servicos Enterprise confiaveis sendo personificados para enganar os usuarios a clicar em links e inserir credenciais:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Servicos de assinatura de documentos (como Docusign, Adobe Acrobat, Adobe Sign, EchoSign): &lt;/b&gt;Um tema recorrente observado nesta campanha foi a personificacao de provedores de gerenciamento de documentos e assinatura eletronica. Os invasores utilizam a promessa de um documento compartilhado ou uma solicitacao de assinatura para atrair as vitimas.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Plataformas de despesas e aquisicao (como SAP Concur, Coupa):&lt;/b&gt; Esta foi a isca mais frequente observada nesta campanha. Ela tem como alvo funcionarios, personificando sistemas populares de gerenciamento de despesas e viagens, geralmente com prompts para aprovar um relatorio ou revisar uma despesa. Uma isca mais generica usa termos como expense, expensereport ou expensesolutions.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Microsoft SharePoint: &lt;/b&gt;A campanha tambem tem como alvo usuarios do ecossistema Microsoft 365, simulando um link para um documento compartilhado ou um site colaborativo.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Reunioes Online: &lt;/b&gt;Os invasores registraram dominios genericos que incluem palavras como &amp;quot;reuniao&amp;quot; para se passar por convites para plataformas de reuniao.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;KnowBe4: &lt;/b&gt;Os invasores se passaram por uma empresa de treinamento de conscientizacao de seguranca, em uma tentativa de induzir os usuarios visados a presumir que a isca de phishing fazia parte de um teste de phishing oficial.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Analise de codigo&lt;/h3&gt;
&lt;p&gt;A cadeia de redirecionamento da isca comeca com um link curto, no qual o endereco de e-mail da vitima e ofuscado dentro do caminho do URL. O usuario e entao redirecionado por meio de um redirecionador com a marca da empresa-alvo no subdominio e, finalmente, chega a uma pagina de phishing convincente com a marca Microsoft que rouba credenciais. O JavaScript no redirecionador extrai o e-mail do caminho, recodifica-o e cria um URL de redirecionamento personalizado que carrega essa identidade em cada salto.&lt;/p&gt;
&lt;h3&gt;Exemplo 1 de cadeia HTTP&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Link Inicial:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]expensereport[.]ch/[coded_string]
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;&lt;br&gt;
Redirecionador:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://][company][.]sapconcur[.]sa[.]com/expense/?uid=[uid]&amp;amp;hid=[hid]
&amp;amp;document=[document]&amp;amp;token=[token]&amp;amp;t=[t]
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;&lt;br&gt;
URL final (mostrando o site de login para a coleta de credenciais):&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://][32_characters_string][.]laurimarierefling[.]com/?uid=[uid]&amp;amp;hid=[hid]
&amp;amp;document=[document]&amp;amp;token=[token]&amp;amp;t=[token]&amp;amp;[string_7_characters]=[string_32_characters]
&lt;/pre&gt;
&lt;h3&gt;&lt;br&gt;
Exemplo 2 de cadeia HTTP&lt;/h3&gt;
&lt;p&gt;&lt;b&gt;Link Inicial:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]sapconcursolutions[.]pl/[coded_string]
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;&lt;br&gt;
Redirecionador:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://][company][.]sapconcur[.]sa[.]com/expense/?uid=[uid]&amp;amp;hid=[hid]
&amp;amp;document=[document]&amp;amp;token=[token]&amp;amp;t=[t]
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;&lt;br&gt;
URL final (mostrando o site de login para coleta de credenciais):&lt;br&gt;
&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://][32_characters_string][.]concurmgt[.]pl//?uid=[uid]&amp;amp;hid=[hid]
&amp;amp;document=[document]&amp;amp;token=[token]&amp;amp;t=[token]&amp;amp;[string_7_characters]=[string_32_characters]
&lt;/pre&gt;
&lt;h3&gt;&lt;br&gt;
Como o redirecionador decodifica e personaliza a vitima&lt;/h3&gt;
&lt;p&gt;As paginas de phishing aceitam o ultimo segmento de caminho e tentam o uso de varios decodificadores em sequencia - mapeamento de token personalizado, hex, Base32 e Base64 - ate que o resultado contenha &amp;quot;@&amp;quot;. Esse valor se torna o e-mail da vitima para uso downstream, como visto neste exemplo de codigo de pagina de isca inicial:&lt;/p&gt;
&lt;pre&gt;
let encodedValue = window.location.pathname.split(&#39;/&#39;).pop();
...
e-mail = decodeEmail(encodedValue); // custom tri-gram map
...
if (!decodingSuccessful &amp;amp;&amp;amp; isHexadecimal(encodedValue)) e-mail = hexToString(encodedValue);
if (!decodingSuccessful &amp;amp;&amp;amp; isBase32(encodedValue)) e-mail = base32ToString(encodedValue);
if (!decodingSuccessful &amp;amp;&amp;amp; isBase64(encodedValue)) e-mail = base64ToString(encodedValue);
&lt;/pre&gt;
&lt;pre&gt;
O decodificador personalizado substitui tokens de tres caracteres de volta em caracteres, usando um mapa como:
&lt;/pre&gt;
&lt;pre&gt;
const encodingMap = {
    &amp;quot;@&amp;quot;:&amp;quot;MN3&amp;quot;,&amp;quot;.&amp;quot;:&amp;quot;OP4&amp;quot;,&amp;quot;a&amp;quot;:&amp;quot;QR5&amp;quot;,&amp;quot;e&amp;quot;:&amp;quot;ST6&amp;quot;,&amp;quot;i&amp;quot;:&amp;quot;UV7&amp;quot;,
    &amp;quot;o&amp;quot;:&amp;quot;WX8&amp;quot;,&amp;quot;u&amp;quot;:&amp;quot;YZ9&amp;quot;,&amp;quot;s&amp;quot;:&amp;quot;ABO&amp;quot;,&amp;quot;n&amp;quot;:&amp;quot;CD1&amp;quot;,&amp;quot;r&amp;quot;:&amp;quot;EF2&amp;quot;,
    &amp;quot;d&amp;quot;:&amp;quot;GH3&amp;quot;,&amp;quot;I&amp;quot;:&amp;quot;JK4&amp;quot;
};
&lt;/pre&gt;
&lt;h3&gt;&lt;br&gt;
Portoes anti-analise&lt;/h3&gt;
&lt;p&gt;Antes de redirecionar, o script tenta evitar rastreadores e sandboxes:&lt;/p&gt;
&lt;pre&gt;
function isBot() {
    const botPatterns = [&#39;bot&#39;,&#39;spider&#39;,&#39;crawl&#39;,&#39;slurp&#39;,&#39;baidu&#39;,&#39;yandex&#39;,
        &#39;wget&#39;,&#39;curl&#39;,&#39;lighthouse&#39;,&#39;pagespeed&#39;,&#39;prerender&#39;,&#39;screaming frog&#39;,
        &#39;semrush&#39;,&#39;ahrefs&#39;,&#39;duckduckgo&#39;];
if (navigator.webdriver || navigator.plugins.length === 0 ||
    navigator.languages === &amp;quot;&amp;quot; || navigator.languages === undefined)
return true;
...
}
&lt;/pre&gt;
&lt;p&gt;Se um sinal de bot/headless for encontrado - ou se a organizacao &amp;quot;bloqueada&amp;quot; do operador aparecer - a pagina redireciona diretamente para o login legitimo da Microsoft, dando as equipes de triagem uma pagina limpa enquanto os usuarios reais continuam no phish. O servico api.ipify.org e usado para retornar o endereco IP publico da vitima, para comparar com uma lista de bloqueio de IP/faixa.&lt;/p&gt;
&lt;h3&gt;Dominios bloqueados&lt;/h3&gt;
&lt;p&gt;O codigo tambem contem dois dominios bloqueados que, se encontrados no endereco de e-mail da vitima, farao com que o fluxo de phishing saia em vez de ir para a pagina de login autentica da Microsoft:&lt;/p&gt;
&lt;pre&gt;
const blockedDomains = [&#39;belfius&#39;, &#39;baringa&#39;];
const emailDomain = email.split(&#39;@&#39;)[1].toLowerCase();

for (const blocked of blockedDomains) {
    if (emailDomain.startsWith(blocked)) {
        window.location.href = &amp;quot;https://login.microsoftonline.com/common/login&amp;quot;;
return;
    }
}
&lt;/pre&gt;
&lt;p&gt;A proveniencia do bloqueio desses dois dominios e desconhecida. O dominio &amp;quot;belfius&amp;quot; parece se referir a um banco belga, enquanto &amp;quot;baringa&amp;quot; parece estar associado a uma consultoria de gestao do Reino Unido.&lt;/p&gt;
&lt;h3&gt;Parametros de consulta&lt;/h3&gt;
&lt;p&gt;Em todas as amostras observadas, o redirecionador cria o mesmo URL parametrizado e apenas a familia de dominio varia. Dois parametros sao o e-mail da vitima em diferentes involucros; o restante sao nonces mais um timestamp:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;uid ? &lt;b&gt;Base64(e-mail)&lt;/b&gt;&lt;ul&gt;
&lt;li&gt;Pode ser decodificado usando uma &lt;a href=&#34;https://gchq.github.io/CyberChef/#recipe=From_Base64(%27A-Za-z0-9%2B/%3D%27,true,false)&#34;&gt;receita&lt;/a&gt;do CyberChef&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;hid ? &lt;b&gt;hex(Base64(e-mail))&lt;/b&gt;&lt;ul&gt;
&lt;li&gt;Pode ser decodificado usando uma &lt;a href=&#34;https://gchq.github.io/CyberChef/#recipe=From_Hex(%27Auto%27)From_Base64(%27A-Za-z0-9%2B/%3D%27,true,false)&#34;&gt;receita&lt;/a&gt;do CyberChef&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;document, token ? IDs aleatorios (semelhantes a nonce)&lt;/li&gt;
&lt;li&gt;t ? &lt;b&gt;Unix timestamp (ms)&lt;/b&gt;&lt;ul&gt;
&lt;li&gt;Pode ser convertido para uma data legivel usando a &lt;a href=&#34;https://gchq.github.io/CyberChef/#recipe=From_UNIX_Timestamp(%27Seconds%20(s)%27)&amp;amp;oeol=FF&#34;&gt;receita&lt;/a&gt;do CyberChef&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;fluxo de autenticacao&lt;/h3&gt;
&lt;p&gt;Dentro do fluxo de autenticacao, o nome da empresa personificada aparece em certos campos do redirecionador e do URL final. Alem disso, a estrutura de phishing preenche automaticamente o endereco de e-mail da vitima no campo de nome de usuario da pagina de phishing.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Link inicial:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]expensereport[.]ch/616c6578616e6465722e652e6261754073662e6672622e6f7267
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;Redirecionador:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]sf[.]sapconcur[.]sa[.]com/expense/?uid=...&amp;amp;hid=...&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;URL Final&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]299afcb76fac4238a0facad80c326230[.]concursolutions[.]asia/?uid=...&amp;amp;hid=...
&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...&amp;amp;u9pPUdqL=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;Link inicial:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]concursecure[.]pl/AB0ST6QR5CD1OP4kUV7CD1CD1MN3cST6CD1AB0YZ9AB0OP4gWX8v
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;Redirecionador:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]census[.]concursystem[.]cv/auth/?uid=...&amp;amp;hid=...&amp;amp;document=...
&amp;amp;token=...&amp;amp;t=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;URL Final&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]6b81e59848ba4a9d8cc3b4570b303a24[.]reports[.]sa[.]com/adfs/ls/?login_hint=
...&amp;amp;wa=wsignin1[.]0&amp;amp;wtrealm=...&amp;amp;wctx=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;Link inicial:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]expensereport[.]ch/phUV7JK4UV7ppQR5mQR5CD1CD1UV7xMN3tfJK4OP4gWX8vOP4YZ9k
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;Redirecionador:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]tfl[.]sapconcur[.]sa[.]com/expense/uid=...&amp;amp;hid=...&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;URL Final&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]b4f1341373f341d98f11caea1052d878[.]laurimarierefling[.]com/?uid=...&amp;amp;hid=
...&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...&amp;amp;...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;Link inicial:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]concursolution[.]de/UV7JK4QR5CD1_CD1ST6tzST6EF2MN3mcQR5fST6ST6OP4cWX8m
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;Redirecionador:&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]mcafee[.]concursystem[.]cv/auth/?uid=...&amp;amp;hid=...&amp;amp;document=...&amp;amp;token=...&amp;amp;t=...
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;URL Final&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
hxxps[://]3b2c66787c6349369fc9f90ecf789899[.]echosign[.]uk[.]com/
app/office365/.../wsfed/passive?login_hint=...&amp;amp;wa=wsignin1[.]0&amp;amp;...
&lt;/pre&gt;
&lt;h3&gt;Impersonificacao eficaz&lt;/h3&gt;
&lt;p&gt;Do ponto de vista do usuario, tudo parece um plano de fundo familiar do Microsoft, favicon e uma breve animacao de &amp;quot;por favor, aguarde&amp;quot; antes de um login. Enquanto isso, o kit &lt;b&gt;desofusca o e-mail da vitima, marca dinamicamente&lt;/b&gt; a pagina de atracao subsequente com o &lt;b&gt;nome da organizacao visada&lt;/b&gt; e carrega identificadores (uid/hid/document/token/t) atraves da cadeia para que quaisquer credenciais capturadas possam ser rastreadas de volta a uma campanha especifica. O &lt;b&gt;padrao de URL repetivel&lt;/b&gt;- um subdominio personalizado mais o conjunto de parametros estavel - juntamente com o trecho de codigo anti-bot simplificado e o carregador estilo Office, fornece deteccao e agrupamento confiaveis em toda esta familia.&lt;/p&gt;
&lt;h3&gt;Objetivos da campanha &amp;amp; modus operandi&lt;/h3&gt;
&lt;p&gt;O objetivo principal desta campanha e a &lt;b&gt;coleta de credenciais&lt;/b&gt;, com foco especifico na captura de credenciais de usuario e cookies de sessao ativos. A atividade observada demonstra uma clara intencao de ignorar ou capturar &lt;b&gt;codigos de autenticacao multifator (MFA)&lt;/b&gt;, indicando uma capacidade avancada alem do simples roubo de credenciais estaticas.&lt;/p&gt;
&lt;h3&gt;Verticais visados&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Financas, Seguros e Bancos:&lt;/b&gt; Este e o setor vertical mais visado. Os invasores estao visando funcionarios de grandes bancos, empresas de investimento e seguradoras.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Tecnologia e servicos de TI:&lt;/b&gt; Grandes empresas de tecnologia, software e consultoria de TI sao os principais alvos, provavelmente devido ao seu acesso a valiosa propriedade intelectual e infraestrutura critica.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Saude, Produtos Farmaceuticos e Biotecnologia: &lt;/b&gt;Este setor e visado por seus dados confidenciais e pesquisa critica.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Aviacao, Viagem e Logistica:&lt;/b&gt; Direcionar este setor pode dar acesso a logistica de viagens, informacoes de reservas corporativas e dados confidenciais de funcionarios.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Manufatura e Automotivo: &lt;/b&gt;Gigantes Globais de Manufatura e Automotivo Tambem Estao na Lista.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Varejo e bens de consumo: &lt;/b&gt;inclui cadeias de varejo e empresas de produtos de consumo conhecidas.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Governo e Setor Publico:&lt;/b&gt; Varias agencias governamentais e organizacoes de servico publico sao alvos.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Pagina de chamariz&lt;/h3&gt;
&lt;p&gt;A pagina raiz dos dominios usados nesta campanha parece ser um jogo inofensivo de uma pagina intitulado &amp;quot;Artistic One Page&amp;quot; ou &amp;quot;Archery Master&amp;quot; para obscurecer o proposito da infraestrutura. Observe que, por causa desses titulos, uma consulta de pesquisa que pode ser usada para localizar infraestrutura adicional nesta campanha no urlscan.io, por exemplo:&lt;/p&gt;
&lt;p&gt;page.title:(&amp;quot;Artistic One Page&amp;quot; OR &amp;quot;Archery Master&amp;quot;)&lt;/p&gt;
&lt;p&gt;Esta pagina de isca pede aos visitantes que insiram um nome de usuario antes de jogar. O cliente bloqueia certos nomes de usuario (por exemplo: administrador, test e um filtro curto de palavras obscenas). Para qualquer outro nome de usuario, o site inicia imediatamente um jogo de arco e flecha incorporado e uma experiencia de quadro de lideres.&lt;/p&gt;
&lt;h2&gt;resposta a ameacas&lt;/h2&gt;
&lt;h3&gt;O que estamos fazendo:&lt;/h3&gt;
&lt;p&gt;Estamos ativamente engajados nas seguintes atividades para mitigar essa ameaca:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Monitoramento continuo de dominios de phishing e infraestrutura recem-registrados associados a esta campanha.&lt;/li&gt;
&lt;li&gt;Apresentar proativamente relatorios de abuso a registradores e provedores de hospedagem relevantes para iniciar solicitacoes de remocao para sites maliciosos identificados.&lt;/li&gt;
&lt;li&gt;Fornecer orientacao e assistencia as organizacoes para aprimorar a seguranca de seus ambientes Okta e ajuda-las a investigar qualquer atividade suspeita relacionada a contas potencialmente comprometidas.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Controles Protetores&lt;/h2&gt;
&lt;h3&gt;Recomendacoes para clientes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Registre os usuarios em autenticadores fortes, como Okta FastPass, FIDO2 WebAuthn e cartoes inteligentes, e aplique a resistencia ao phishing na politica.&lt;/li&gt;
&lt;li&gt;As politicas de acesso de aplicativos Okta (anteriormente &amp;quot;politicas de autenticacao&amp;quot;) tambem podem ser usadas para restringir o acesso a contas do usuario com base em uma variedade de pre-requisitos configuraveis pelo cliente. Recomendamos que os administradores restrinjam o acesso a aplicativos confidenciais a dispositivos gerenciados por ferramentas de Endpoint Management e protegidos por ferramentas de seguranca de endpoint. Para acesso a aplicativos menos confidenciais, exija dispositivos registrados (usando Okta FastPass) que exibam indicadores de higiene basica.&lt;/li&gt;
&lt;li&gt;Negue ou exija maior garantia para solicitacoes de redes raramente usadas. Com o Okta Network Zones, o acesso pode ser controlado por local, ASN (Numero do Sistema Autonomo), IP e tipo de IP (que pode identificar proxies de anonimato conhecidos).&lt;/li&gt;
&lt;li&gt;As avaliacoes de Comportamento e Risco da Okta podem ser usadas para identificar solicitacoes de acesso a aplicativos que se desviam de padroes de atividade do usuario estabelecidos anteriormente. As politicas podem ser configuradas para aumento de nivel ou negar solicitacoes usando este contexto.&lt;/li&gt;
&lt;li&gt;Treine os usuarios para identificar indicadores de e-mails suspeitos, sites de phishing e tecnicas comuns de engenharia social usadas por invasores. Facilite para os usuarios relatarem problemas potenciais, configurando as &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/security_general.htm&#34;&gt;Notificacoes para o Usuario Final&lt;/a&gt; e o &lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/suspicious-activity-reporting.htm&#34;&gt;Relatorio de Atividade Suspeita&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Documente, divulgue e siga um processo padronizado para validar a identidade de usuarios remotos que entram em contato com o pessoal de suporte de TI e vice-versa.&lt;/li&gt;
&lt;li&gt;Adote uma abordagem de &amp;quot;Zero privilegios permanentes&amp;quot; para o acesso administrativo. Atribua aos administradores &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/custom-admin-role/custom-admin-roles.htm&#34;&gt;Funcoes de Administrador Personalizadas&lt;/a&gt; com as permissoes minimas necessarias para as tarefas diarias e exija autorizacao dupla para acesso JIT (just-in-time) a funcoes mais privilegiadas.&lt;/li&gt;
&lt;li&gt;Aplique o IP Session Binding a todos os aplicativos administrativos para impedir a reproducao de sessoes administrativas roubadas.&lt;/li&gt;
&lt;li&gt;Habilite as &lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/admin-console-protected-actions.htm#:~:text=Protected%20actions%20are%20critical%20tasks,according%20to%20a%20configured%20interval.&#34;&gt;Protected Actions&lt;/a&gt; para forcar a reautenticacao sempre que um usuario administrativo tentar executar acoes confidenciais.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Observando e respondendo a infraestrutura de phishing:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Revise os registros de aplicativos (logs Okta, web proxies, sistemas de e-mail, servidores DNS, firewalls) para qualquer evidencia de comunicacao com quaisquer dominios suspeitos.&lt;/li&gt;
&lt;li&gt;Monitore os dominios regularmente para ver se o conteudo muda.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Se o conteudo hospedado no dominio violar direitos autorais ou marcas legais, considere fornecer evidencias e emitir uma solicitacao de remocao com o registrador de dominio e/ou provedor de hospedagem na web.&lt;/p&gt;
&lt;h2&gt;Apendice A: Indicadores de Comprometimento&lt;/h2&gt;
&lt;p&gt;Esta e uma investigacao em andamento, e IOCs adicionais podem ser identificados a medida que a campanha evolui. As organizacoes sao aconselhadas a permanecer vigilantes e implementar as estrategias de mitigacao recomendadas. Abaixo estao os IOCs observados. &lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Indicador&lt;/th&gt;
&lt;th&gt;Comentario&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;acrobatsign[.]es&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;adobeacrobat[.]sa[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;adobesign[.]ceelegal[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;adobesign[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;adobesign[.]us[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;asir[.]co[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;blue-styles[.]cz&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;ceelegal[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;codemonkey[.]cc&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;comcursolutions[.]de&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;comcursolutions[.]eu&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;comcursolutions[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;comcursolutions[.]us&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concur[.]cv&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concur[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concurexpense[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concurmgt[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursap[.]netlify[.]app&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursecure[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolution[.]de&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolution[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]asia&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]at&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]ceelegal[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]ch&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]com[.]tr&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]cv&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]cz&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]de[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]es&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]in&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]mex[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]my&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]nl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]pt&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursolutions[.]re&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursystem[.]cv&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;concursystem[.]netlify[.]app&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;coupahost[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;crsign[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;cruisesaudi[.]sa[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;dfwcom[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;dnglobal[.]ca&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;echosign[.]cv&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;echosign[.]de[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;echosign[.]eu02-safelink[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;echosign[.]nl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;echosign[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;echosign[.]ru[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;echosign[.]uk&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;echosign[.]za[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;esign[.]sa[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;eu02-safelink[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;eumai1-docusign[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;excelpediatric[.]us[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;expense[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;expense[.]sa[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;expensereport[.]ch&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;expensereports[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;expensereports[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;expensereports[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;getadobesign[.]eu02-safelink[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;getconcur[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;khs[.]co[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;knowbe4[.]es&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;meeting[.]sa[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;myapps[.]sa[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;na4-6l9[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;na4[.]it[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;saferedirect[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;sapconcur[.]cv&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;sapconcur[.]pages[.]dev&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;sapconcur[.]sa[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;sapconcursolutions[.]pl&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;scality[.]us[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;secure[.]za[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;sharepoint[.]za[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;supancasign[.]netlify[.]app&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;sutheha[.]za[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;team[.]sa[.]com&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;ug4t5w[.]cfd&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;dominio&lt;/td&gt;
&lt;td&gt;wepp[.]website&lt;/td&gt;
&lt;td&gt;Pagina de destino suspeita&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h3&gt;Uma nota sobre a linguagem de estimativa&lt;/h3&gt;
&lt;p&gt;As equipes de Okta Threat Intelligence usam os seguintes termos para expressar probabilidade conforme descrito no US Office of the Director of National Intelligence, Intelligence Community Directive 203 - Analytic Standards.&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Probabilidade&lt;/th&gt;
&lt;th&gt;Quase&lt;br&gt;
nenhuma chance&lt;/th&gt;
&lt;th&gt;Muito&lt;br&gt;
improvavel&lt;/th&gt;
&lt;th&gt;Improvavel&lt;/th&gt;
&lt;th&gt;Aproximadamente&lt;br&gt;
mesma chance&lt;span style=&#34;font-weight: 400;&#34;&gt;&lt;/span&gt;&lt;/th&gt;
&lt;th&gt;Provavel&lt;/th&gt;
&lt;th&gt;Muito&lt;br&gt;
provavel&lt;/th&gt;
&lt;th&gt;Quase&lt;br&gt;
com certeza&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;b&gt;Probabilidade&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;Remoto&lt;/td&gt;
&lt;td&gt;Altamente&lt;br&gt;
improvavel&lt;/td&gt;
&lt;td&gt;Improbable&lt;/td&gt;
&lt;td&gt;Aproximadamente&lt;br&gt;
chances iguais&lt;/td&gt;
&lt;td&gt;Provavel&lt;/td&gt;
&lt;td&gt;Altamente&lt;br&gt;
Provavel&lt;/td&gt;
&lt;td&gt;Quase&lt;br&gt;
Certeza&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;b&gt;Porcentagem&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;1-5%&lt;/td&gt;
&lt;td&gt;5-20%&lt;/td&gt;
&lt;td&gt;20-45%&lt;/td&gt;
&lt;td&gt;45-55%&lt;/td&gt;
&lt;td&gt;55-80%&lt;/td&gt;
&lt;td&gt;80-95%&lt;/td&gt;
&lt;td&gt;95-99%&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Tue, 30 Sep 2025 07:00:00 +0000</pubDate>
                
                    <category>threat-intelligence,iam,blog-post,social-engineering,token-replay,credential-phishing,threat-insights</category>
                
                <dc:creator>Daniel López</dc:creator>
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/help-desks-targeted-in-social-engineering-targeting-hr-applications/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/help-desks-targeted-in-social-engineering-targeting-hr-applications/</link>
                <title>Help desks targeted in social engineering campaign targeting HR applications</title>
                <description>
                    <![CDATA[&lt;h2&gt;Resumo Executivo&lt;/h2&gt;
&lt;p&gt;A Inteligencia de Ameacas da Okta tem monitorado ativamente um grupo de atividades com motivacao financeira conhecido como &lt;b&gt;O-UNC-034&lt;/b&gt; desde agosto de 2025, que se aproveita da engenharia social da equipe de suporte tecnico para assumir contas e manipular dados em sistemas de folha de pagamento. &lt;/p&gt;
&lt;p&gt;O-UNC-034 foi observado visando funcionarios de organizacoes que operam em diferentes setores, incluindo, entre outros, Educacao, Manufatura e Industria, Varejo e Servicos ao Consumidor, e Produtos Farmaceuticos e Saude. E um dos varios grupos de atividades rastreados pelo Okta Threat Intelligence e outros pesquisadores de ameacas que visam aplicativos de RH e folha de pagamento. Variacoes sobre este tema incluem o uso de *malvertising* (O-TA-54) e *AitM phishing* (STORM-2657). &lt;/p&gt;
&lt;p&gt;O objetivo principal de O-UNC-034 e manipular os dados bancarios associados a usuarios-alvo em sistemas de RH e servicos relacionados a folha de pagamento.&lt;/p&gt;
&lt;p&gt;Este aviso detalha as Taticas, Tecnicas e Procedimentos (TTPs) observados e fornece Indicadores de Comprometimento (IOCs) relevantes associados a esta ameaca ativa. &lt;/p&gt;
&lt;p&gt;Estas informacoes sao fornecidas para fins informativos e de inteligencia, para permitir que as organizacoes compreendam e mitiguem os riscos representados por esta campanha.&lt;/p&gt;
&lt;h2&gt;Analise de Ameacas&lt;/h2&gt;
&lt;p&gt;O agente de ameacas esta utilizando tecnicas de engenharia social, se passando por funcionarios legitimos.&lt;/p&gt;
&lt;p&gt;Para o &lt;b&gt;Acesso Inicial&lt;/b&gt;, o agente de ameaca foi observado iniciando contato com a central de ajuda de TI da empresa-alvo, se passando por um funcionario. Eles usam essa personificacao para solicitar redefinicoes de senha para a conta do funcionario.&lt;/p&gt;
&lt;p&gt;Apos um evento de redefinicao de senha bem-sucedido, o agente de ameaca estabelece &lt;b&gt;persistencia&lt;/b&gt; ao registrar seu proprio autenticador MFA na conta comprometida. Observou-se que o agente de ameaca se inscreve no Okta Verify, autenticacao por chamada de voz, SMS ou manipula perguntas de seguranca, permitindo que o agente de ameaca ignore a autenticacao multifatorial (MFA) ou outros controles de seguranca.&lt;/p&gt;
&lt;p&gt;Apos um comprometimento de conta bem-sucedido, o agente se volta para aplicativos internos, visando especificamente:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;b&gt;Aplicativos de folha de pagamento&lt;/b&gt; como Workday, Dayforce HCM e ADPsuite. O acesso a estes sistemas e utilizado para manipular os dados bancarios da conta comprometida. &lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Gerenciamento de relacionamento com o cliente (CRM) e gerenciamento de servicos de TI (ITSM), como Salesforce e ServiceNow. O acesso a essas plataformas pode levar ao roubo de dados de clientes proprietarios, propriedade intelectual ou manipulacao de processos de suporte de TI.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Suites de Colaboracao e Produtividade: Office 365 e Google Workspace. O acesso a esses ambientes fornece uma grande quantidade de informacoes, incluindo comunicacoes internas, documentos e credenciais, facilitando outros ataques.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;O agente de ameacas foi observado tentando e autenticando com sucesso, a partir de uma combinacao de servicos de anonimato e enderecos IP residenciais, como:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;IPVANISH VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;CYBERGHOST VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;ZENMATE VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;EXPRESS VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;WINDSCRIBE VPN&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;VPN FORTE&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;ZENLAYER&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Enderecos IP geolocalizados na Nigeria&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Varios sistemas operacionais tambem estao associados a esta atividade, incluindo, entre outros:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Mac OS 14.5.0 (Sonoma)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Mac OS 15.5.0 (Sequoia)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Mac OS 13.1.0 (Ventura)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Windows 11&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;iOS (iPhone)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;resposta a ameacas&lt;/h2&gt;
&lt;h3&gt;O que estamos fazendo&lt;/h3&gt;
&lt;p&gt;Estamos ativamente engajados nas seguintes atividades para mitigar essa ameaca:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Monitoramento continuo da atividade do agente de ameacas.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fornecer orientacao e assistencia as organizacoes para aprimorar a seguranca de seus ambientes Okta e investigar qualquer atividade suspeita relacionada a contas potencialmente comprometidas.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Controles de Protecao&lt;/h2&gt;
&lt;h3&gt;Recomendacoes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Incentive os usuarios a se registrarem em autenticadores fortes, como Okta FastPass, FIDO2 WebAuthn e cartoes inteligentes, e aplique a resistencia ao phishing na politica.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Documente, divulgue e siga um processo padronizado para validar a identidade de usuarios remotos que entram em contato com a equipe de suporte de TI e vice-versa. Considere o uso de&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/idvs-as-idps.htm&#34;&gt; servicos de verificacao de identidade&lt;/a&gt; quando os usuarios estiverem bloqueados fora de suas contas.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Recomendamos a criacao de funcoes de administrador personalizadas para profissionais de help desk de linha de frente. Esta funcao personalizada nao deve ter as permissoes necessarias para modificar fatores (redefinir senhas de usuario, definir senhas temporarias ou redefinir ou inscrever fatores). Em vez disso, esses profissionais de help desk devem receber em sua funcao personalizada a permissao para emitir&lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-temporary-access-code.htm&#34;&gt; Codigos de Acesso Temporario&lt;/a&gt; depois que um chamador para o help desk verificar com sucesso sua identidade. Ao contrario de um token de redefinicao de senha, um codigo de acesso temporario pode ter tempo limitado (sujeito a expiracao), ser atribuido a grupos especificos de usuarios (NB: excluir administradores e outros alvos de alto valor), encadeado a outros autenticadores e sujeito a politicas de acesso de app que restringem seu uso por dispositivo ou local.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;As politicas de autenticacao do Okta tambem podem ser usadas para restringir o acesso a contas de usuario com base em uma variedade de pre-requisitos configuraveis pelo cliente. Recomendamos que os administradores restrinjam o acesso a aplicativos confidenciais a dispositivos que sao &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/managed-main.htm&#34;&gt;gerenciados&lt;/a&gt; por ferramentas de Endpoint Management e &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/edr-integration-main.htm&#34;&gt;protegidos por ferramentas de seguranca de *endpoint*&lt;/a&gt;. Para acesso a aplicativos menos confidenciais, exija dispositivos &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/fp/fp-main.htm&#34;&gt;registrados&lt;/a&gt; (usando o Okta FastPass) que &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/identity-engine/devices/device-assurance.htm&#34;&gt;exibam indicadores de higiene basica&lt;/a&gt;. &lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Negue ou exija maior garantia para solicitacoes de redes raramente usadas. Com as Zonas de Rede Okta, o acesso pode ser controlado por local, ASN (Numero de Sistema Autonomo), IP e Tipo de IP (que pode identificar proxies de anonimato conhecidos).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;As avaliacoes de comportamento e risco da Okta podem ser usadas para identificar solicitacoes de acesso a aplicativos que se desviam de padroes de atividade do usuario previamente estabelecidos. As politicas podem ser configuradas para aumento de nivel ou negar solicitacoes usando este contexto.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Treine os usuarios para identificar indicadores de e-mails suspeitos, sites de phishing e tecnicas comuns de engenharia social usadas por invasores. Facilite para os usuarios relatarem problemas potenciais, configurando as &lt;a href=&#34;https://help.okta.com/oie/en-us/Content/Topics/Security/Security_General.htm&#34;&gt;Notificacoes para o Usuario Final&lt;/a&gt; e o &lt;a href=&#34;https://help.okta.com/en-us/Content/Topics/Security/suspicious-activity-reporting.htm&#34;&gt;Relatorio de Atividade Suspeita&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Adote uma abordagem de &amp;quot;Zero privilegios permanentes&amp;quot; para acesso administrativo. Atribua aos administradores &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/security/custom-admin-role/custom-admin-roles.htm&#34;&gt;Funcoes de Administrador Personalizadas&lt;/a&gt; com as permissoes minimas necessarias para as tarefas diarias e exija autorizacao dupla para acesso JIT (just-in-time) a funcoes mais privilegiadas. &lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Aplique o IP Session Binding a todos os aplicativos administrativos para impedir a reproducao de sessoes administrativas roubadas.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Ative &lt;a href=&#34;https://help.okta.com/en-us/content/topics/security/admin-console-protected-actions.htm#:~:text=Protected%20actions%20are%20critical%20tasks,according%20to%20a%20configured%20interval.&#34;&gt;Acoes Protegidas&lt;/a&gt; para forcar a reautenticacao sempre que um usuario administrativo tentar executar acoes confidenciais.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Indicadores de Comprometimento&lt;/h2&gt;
&lt;p&gt;Os contatos de seguranca dos clientes da Okta podem fazer login e baixar os Indicadores de Comprometimento de security.okta.com no seguinte link:&lt;br&gt;
&lt;br&gt;
&lt;a href=&#34;https://security.okta.com/product/okta/help-desks-targeted-in-social-engineering-campaign-targeting-hr-applications&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;https://security.okta.com/product/okta/help-desks-targeted-in-social-engineering-campaign-targeting-hr-applications&lt;/a&gt;&lt;/p&gt;
&lt;h3&gt;Uma nota sobre a linguagem de estimativa&lt;/h3&gt;
&lt;p&gt;As equipes de Okta Threat Intelligence usam os seguintes termos para expressar a probabilidade, conforme descrito na Diretiva 203 da Comunidade de Inteligencia do Gabinete do Diretor de Inteligencia Nacional dos EUA - Padroes Analiticos.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;table cellpadding=&#34;5&#34; cellspacing=&#34;0&#34; border=&#34;0&#34; width=&#34;800&#34;&gt;
&lt;tbody&gt;&lt;tr&gt;&lt;th&gt;Probabilidade&lt;/th&gt;
&lt;th&gt;Quase&lt;br&gt;
nenhuma chance&lt;/th&gt;
&lt;th&gt;Muito&lt;br&gt;
improvavel&lt;/th&gt;
&lt;th&gt;Improvavel&lt;/th&gt;
&lt;th&gt;Aproximadamente&lt;br&gt;
igual probabilidade&lt;/th&gt;
&lt;th&gt;Provavel&lt;/th&gt;
&lt;th&gt;Muito&lt;br&gt;
provavel&lt;/th&gt;
&lt;th&gt;Quase&lt;br&gt;
certo(a)&lt;/th&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Probabilidade&lt;/td&gt;
&lt;td&gt;Remoto&lt;/td&gt;
&lt;td&gt;Altamente&lt;br&gt;
improvavel&lt;/td&gt;
&lt;td&gt;Improbable&lt;/td&gt;
&lt;td&gt;Aproximadamente&lt;br&gt;
mesmas chances&lt;/td&gt;
&lt;td&gt;Provavel&lt;/td&gt;
&lt;td&gt;Altamente&lt;br&gt;
Provavel&lt;/td&gt;
&lt;td&gt;Quase&lt;br&gt;
Certeza&lt;/td&gt;
&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Porcentagem&lt;/td&gt;
&lt;td&gt;1-5%&lt;/td&gt;
&lt;td&gt;5-20%&lt;/td&gt;
&lt;td&gt;20-45%&lt;/td&gt;
&lt;td&gt;45-55%&lt;/td&gt;
&lt;td&gt;55-80%&lt;/td&gt;
&lt;td&gt;80-95%&lt;/td&gt;
&lt;td&gt;95-99%&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
]]>
                </description>
                <pubDate>Mon, 29 Sep 2025 07:00:00 +0000</pubDate>
                
                    <category>blog-post,threat-intelligence,iam,social-engineering,threat-insights</category>
                
                
            </item>
        
            <item>
                <guid>https://www.okta.com/pt-br/blog/threat-intelligence/north-korea-s-it-workers-expand-beyond-us-big-tech/</guid>
                <link>https://www.okta.com/pt-br/blog/threat-intelligence/north-korea-s-it-workers-expand-beyond-us-big-tech/</link>
                <title>North Korea&amp;apos;s IT Workers expand beyond US big tech</title>
                <description>
                    <![CDATA[&lt;p&gt;A Okta Threat Intelligence conduziu uma analise em larga escala revelando que o esquema de trabalhadores de TI da Republica Popular Democratica da Coreia (RPDC) ameaca quase todos os setores que contratam talentos remotos.&lt;/p&gt;
&lt;p&gt;Embora os relatorios publicos tenham se concentrado principalmente em cidadaos da RPDC visando funcoes de desenvolvimento de software em grandes empresas de tecnologia dos EUA, nossa analise mostra que essa ameaca nao se limita ao setor de tecnologia, nem aos EUA. Trabalhadores de TI norte-coreanos (ITW) agora representam uma ameaca real para uma ampla gama de setores. Os setores afetados incluem financas, saude, administracao publica e Professional Services em um numero crescente de paises. Este esquema generalizado tem como objetivo obter emprego ilicito e - em alguns casos - roubar dados confidenciais.&lt;/p&gt;
&lt;p&gt;Qual a extensao dessa ameaca? Nossa analise de milhares de exemplos de nossa amostra de atividade DPRK ITW descobriu que organizacoes de &lt;a href=&#34;https://en.wikipedia.org/wiki/International_Standard_Industrial_Classification&#34; target=&#34;_blank&#34;&gt;Information and tecnologia&lt;/a&gt; representam apenas metade das entidades visadas. Tambem descobrimos que mais de um quarto (27%) das entidades visadas estao sediadas em paises que nao os Estados Unidos.&lt;/p&gt;
&lt;p&gt;A Okta Threat Intelligence observou exemplos de atores ligados a Coreia do Norte passando por varias entrevistas para as mesmas funcoes. Embora nao tenhamos acesso aos processos de contratacao e integracao de todas as organizacoes, evidencias de atividades corporativas pos-integracao foram observadas em varias organizacoes em diferentes setores, apoiando a teoria de que uma abordagem ampla de &amp;quot;tiro disperso&amp;quot; para candidatura a empregos e entrevistas tem sido bem-sucedida o suficiente para torna-la um esforco valioso para o regime da Coreia do Norte continuar e expandir. &lt;/p&gt;
&lt;p&gt;E essencial que organizacoes de todos os setores da industria e paises estejam cientes de que agentes ligados a RPDC se candidataram ou provavelmente se candidatarao a funcoes tecnicas remotas anunciadas e implementem as etapas extras cruciais necessarias para tornar sua organizacao um alvo mais dificil. &lt;/p&gt;
&lt;h2&gt;Dentro da investigacao: mais de 130 identidades e milhares de empresas visadas&lt;/h2&gt;
&lt;p&gt;Usando uma combinacao de fontes de dados internas e externas, o Okta Threat Intelligence rastreou mais de 130 identidades operadas por facilitadores e trabalhadores que participam do esquema DPRK ITW. Vinculamos esses atores a mais de 6.500 entrevistas de emprego iniciais em mais de 5.000 empresas distintas ate meados de 2025.&lt;/p&gt;
&lt;p&gt;Para evitar alertar os agentes de ameacas sobre como obtivemos visibilidade de suas atividades, a Okta Threat Intelligence esta deliberadamente retendo alguns detalhes sobre nossa metodologia de pesquisa. Nossa confianca nos dados foi validada por briefings continuos com pares do setor, agencias de aplicacao da lei e Organizacoes-alvo.&lt;/p&gt;
&lt;p&gt;Notavelmente, existem semelhancas superficiais entre os trabalhadores de TI da Coreia do Norte e os trabalhadores nao norte-coreanos de &#34;sobre-emprego&#34;, como padroes de trabalho remoto, motivacoes financeiras, tecnicas de decepcao e origens geograficas. A Okta avalia qualquer identidade como alinhada a Coreia do Norte com base em uma combinacao de indicadores tecnicos, padroes comportamentais e relatorios de empregadores em primeira mao. Alem disso, prevemos que as 130 identidades que o Okta Threat Intelligence esta rastreando reflitam apenas uma pequena amostra da atividade total de TIW ativa da Coreia do Norte.&lt;/p&gt;
&lt;h2&gt;Um problema crescente&lt;/h2&gt;
&lt;p&gt;Nos ultimos cinco anos, pelo menos, a RPDC, fortemente sancionada, mobilizou milhares de individuos para paises vizinhos, encarregando-os de &lt;a href=&#34;https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;obter empregos ilicitos em paises desenvolvidos&lt;/a&gt;. Os ITWs da RPDC dependem de fraude de identidade e da colaboracao de facilitadores em paises-alvo para ajuda-los a obter e manter o emprego. &lt;/p&gt;
&lt;p&gt;A pesquisa mais recente da Okta revela tanto a amplitude das industrias que estao sendo visadas quanto a duracao sustentada desta operacao, indicando um esforco de longo alcance e em evolucao para se infiltrar em empresas de todos os tipos em paises desenvolvidos. Um numero relativamente pequeno de pessoas foi capaz de identificar anuncios de emprego, gerar e enviar candidaturas personalizadas (incluindo CVs, cartas de apresentacao e materiais de apoio), passar pela triagem inicial de recrutadores ou RH e garantir entrevistas remotas em escala. &lt;/p&gt;
&lt;p&gt;Embora o objetivo principal do esquema ITW permaneca o ganho financeiro por meio do pagamento de salarios, ha inumeros relatos surgindo de &lt;a href=&#34;https://www.ic3.gov/PSA/2025/PSA250123&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;roubo de dados e tentativas de extorsao&lt;/a&gt; contra organizacoes que, sem saber, empregaram e posteriormente decidiram demitir esses trabalhadores. &lt;/p&gt;
&lt;p&gt;Incidentes ocasionais de exfiltracao de dados e extorsao - incluindo &lt;a href=&#34;https://www.justice.gov/archives/opa/pr/north-korean-government-hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;atividade relacionada a ransomware&lt;/a&gt; - destacam a natureza de uso duplo desta campanha. O acesso proporcionado pela colocacao de pessoal ligado a RPDC dentro de organizacoes ocidentais oferece uma capacidade significativa de inteligencia e disrupcao caso o regime da RPDC decida usa-la. O potencial de acesso mais amplo e coleta tecnica construidos atraves desta operacao de longa duracao deve ser uma preocupacao para governos e organizacoes em quase todos os setores da economia. &lt;/p&gt;
&lt;p&gt;Unidades DPRK ITW parecem estar aprendendo com erros anteriores e estao visando um numero maior de industrias em um numero maior de paises. Entidades visadas nesses paises agora enfrentam uma ameaca madura e experiente que alcancou o sucesso necessario para ter recebido um nivel de &#34;liberdade criativa&#34; sobre verticais visadas e as ferramentas, tecnicas e procedimentos que usam para obter emprego. &lt;/p&gt;
&lt;p&gt;E possivel que o aumento da conscientizacao sobre essa ameaca - bem como os esforcos colaborativos do governo e do setor privado para identificar e interromper suas operacoes - possa ser um fator adicional para que eles visem cada vez mais funcoes fora dos EUA e das industrias de TI.&lt;/p&gt;
&lt;h2&gt;A RPDC esta ampliando seus alvos, de grandes empresas de tecnologia a hospitais, bancos e outros.&lt;/h2&gt;
&lt;p&gt;Nossa pesquisa demonstra uma clara progressao nos setores e funcoes que estao sendo visados no esquema ITW.&lt;/p&gt;
&lt;p&gt;Embora a DPRK ITW busque esmagadoramente posicoes remotas de engenharia de software, nacionais da DPRK sao cada vez mais observados se candidatando a posicoes remotas de financas (processadores de pagamentos, etc.) e funcoes de engenharia. Isso sugere que funcoes remotas de qualquer tipo estao dentro do escopo do esquema. Enquanto a aplicacao, o processo de entrevista e o proprio trabalho puderem ser realizados remotamente, a DPRK tentara usar a oportunidade para coletar pagamento financeiro. &lt;/p&gt;
&lt;p&gt;Nossa analise confirma que as candidaturas de emprego se estendem por quase todos os principais setores verticais. Nos ultimos quatro anos, podemos observar um aumento constante no numero de setores onde o ITW se candidatou e compareceu com sucesso a entrevistas de emprego. Como esperado, as grandes empresas de tecnologia - especialmente aquelas que desenvolvem software - permanecem sendo os alvos de maior volume. No entanto, outros setores verticais - incluindo financas, saude, administracao publica e Professional Services - surgem consistentemente em nosso conjunto de dados, demonstrando uma campanha continua e abrangente. &lt;/p&gt;
&lt;p&gt;Existem varias explicacoes plausiveis para a distribuicao de entrevistas em verticais da industria:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;A distribuicao e uma funcao de quais setores anunciam mais vagas remotas de engenharia de software. Mesmo entre os setores que mais anunciam engenheiros de software, certas categorias de trabalhadores do setor de tecnologia - como tecnologias de blockchain ou inteligencia artificial - mostram um aumento na quantidade de entrevistas que parece proporcional ao aumento da demanda por Developers e engenheiros.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;A distribuicao reflete uma segmentacao deliberada de setores de interesse para o regime da RPDC para fins que nao sejam a geracao de receita e/ou as especializacoes ou experiencia de individuos especificos.&lt;br&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Nao podemos descartar a possibilidade de que esses individuos simplesmente tenham pouco interesse pela natureza ou negocio real das empresas visadas, alem da natureza remota da funcao.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As posicoes mais visadas permanecem em funcoes remotas de desenvolvimento de software (por exemplo, React, full stack, Java), com ocasionais outliers administrativos ou especializados, como contabilidade, processamento de pagamentos e suporte de engenharia. Nossa analise cronologica tambem revela distintos vales na atividade de entrevistas coincidindo com os periodos de feriados dos EUA e do Ocidente, provavelmente refletindo desaceleracoes sazonais nas contratacoes, em vez de uma mudanca na intencao do adversario.&lt;/p&gt;
&lt;h2&gt;Uma analise mais detalhada dos setores verticais visados pela RPDC&lt;/h2&gt;
&lt;p&gt;O Okta Threat Intelligence selecionou um subconjunto de verticais para uma analise mais profunda para ilustrar por que eles sao alvos e o impacto potencial de uma infiltracao bem-sucedida. Embora os exemplos sejam extraidos de setores especificos, as implicacoes se aplicam amplamente e servem como uma chamada para acao para todas as organizacoes.&lt;/p&gt;
&lt;h3&gt;Desenvolvimento de software e consultoria de TI&lt;/h3&gt;
&lt;p&gt;Os profissionais de TI da Coreia do Norte continuam a se concentrar esmagadoramente em funcoes remotas de desenvolvimento de software e consultoria de TI. Isso inclui nao apenas o emprego direto em empresas de tecnologia, mas tambem colocacoes em grandes provedores de terceirizacao e servicos. Essas posicoes oferecem salarios relativamente altos, acesso a bases de codigo, infraestrutura e pipelines de desenvolvimento de alto valor, alem de serem abundantes e frequentemente remotas.&lt;/p&gt;
&lt;p&gt;A pesquisa da Okta mostra que esses atores identificam sistematicamente as funcoes anunciadas, criam curriculos e cartas de apresentacao confiaveis, passam pela triagem inicial de RH e garantem entrevistas em escala. A combinacao de trabalho remoto, contratacao por contrato e equipes distribuidas cria um ambiente onde as verificacoes de antecedentes e a verificacao de identidade tradicionais podem ser mais fracas, e a verificacao de identidade continua ou recorrente inexistente. Essa exposicao e ampliada em consultorias de TI, onde os trabalhadores sao frequentemente incorporados a varias organizacoes clientes, aumentando o risco de acesso lateral. O Okta Threat Intelligence tambem observou o uso significativo de plataformas de mercado freelancer por esses atores.&lt;/p&gt;
&lt;h3&gt;Inteligencia artificial&lt;/h3&gt;
&lt;p&gt;Desde meados de 2023, a Okta observou um aumento acentuado em entrevistas de emprego ligadas a Coreia do Norte em organizacoes focadas em IA, incluindo empresas de IA &#34;puras&#34; e empresas que incorporam IA em produtos e plataformas existentes. Esse aumento coincide com a expansao mais ampla do setor de IA e a corrida para dimensionar as equipes de engenharia - condicoes que podem reduzir o rigor da triagem e integracao de candidatos.&lt;/p&gt;
&lt;p&gt;Embora parte desse aumento possa simplesmente refletir o boom geral na contratacao de IA, a exposicao de propriedade intelectual sensivel, dados de treinamento de modelos e algoritmos proprietarios torna este setor especialmente atraente para atores ligados ao Estado. A Okta avalia que os trabalhadores de TI da RPDC provavelmente estao se candidatando de forma oportunista ao numero crescente de vagas de IA, em vez de desviar recursos de outros setores. No entanto, o potencial de uso duplo do acesso a sistemas de IA - particularmente para manipulacao de modelos ou futuras operacoes ciberneticas ofensivas - aumenta o risco estrategico.&lt;/p&gt;
&lt;h3&gt;Assistencia medica e tecnologia medica&lt;/h3&gt;
&lt;p&gt;Mais surpreendentemente, observamos um numero constante de entrevistas de emprego ligadas a RPDC entre organizacoes de saude e tecnologia medica. A maioria das funcoes visadas se concentra no desenvolvimento de aplicativos moveis, sistemas de atendimento ao cliente e plataformas eletronicas de manutencao de registros (diretamente com provedores de tecnologia alinhados a area da saude, em vez de empresas de servicos genericas). Essas areas fornecem acesso potencial a informacoes de identificacao pessoal (PII) confidenciais, fluxos de trabalho clinicos e infraestrutura de dados de saude.&lt;/p&gt;
&lt;p&gt;A sobreposicao entre tecnologia e assistencia medica transformou o setor em um alvo de alto valor. Embora as organizacoes focadas em medicina geralmente possam ser bem versadas na deteccao de credenciais medicas falsas &#34;tradicionais&#34; ou de um historico de trabalho preocupante, os trabalhadores de TI e os codificadores contingentes podem nao ter o mesmo nivel de escrutinio inicial ou continuo. As organizacoes de saude podem ter poucos recursos na deteccao de ameacas internas para combater tentativas de emprego fraudulentas, contando com processos de recrutamento tradicionais que podem nao detectar impostores sofisticados.&lt;/p&gt;
&lt;p&gt;Nos EUA, contratar individuos ligados a paises sancionados para lidar com informacoes de saude protegidas pode ter implicacoes regulatorias significativas (por exemplo, violacoes do HIPAA).&lt;/p&gt;
&lt;p&gt;O Okta Threat Intelligence avalia que os trabalhadores de TI ligados a DPRK podem ainda nao estar visando sistematicamente a assistencia medica, mas estao explorando a abundancia de funcoes de desenvolvimento de software a medida que o setor se digitaliza - aumentando os riscos para a seguranca de dados e a privacidade do paciente. No entanto, a sensibilidade do PII de assistencia medica o tornaria particularmente vulneravel a roubo de dados e extorsao.&lt;/p&gt;
&lt;h3&gt;Servicos financeiros&lt;/h3&gt;
&lt;p&gt;Os trabalhadores de TI da RPDC consistentemente se candidatam a funcoes no setor financeiro global. As entidades-alvo incluem instituicoes bancarias tradicionais e empresas de seguros, bem como empresas FinTech modernas e organizacoes relacionadas a criptomoedas. &lt;/p&gt;
&lt;p&gt;Isso oferece a RPDC oportunidades de acesso direto a infraestruturas financeiras de alto valor, incluindo sistemas de processamento de pagamentos, dados de clientes e outros dados financeiros. &lt;/p&gt;
&lt;p&gt;As funcoes visadas se expandiram alem do desenvolvimento de software para incluir funcoes de back-office e processamento financeiro em areas como folha de pagamento e contabilidade. Essa mudanca indica uma compreensao por parte da RPDC de que existem outros tipos de tarefas, alem da engenharia de software, que oferecem oportunidades semelhantes: uma entidade visada deve estar preparada para contratar remotamente, e um profissional de conhecimento da RPDC deve ser capaz de demonstrar algum nivel de competencia para executa-la. &lt;/p&gt;
&lt;p&gt;A dependencia de servicos financeiros em recrutadores e prestadores de servicos terceirizados para talentos especializados cria um ambiente onde a verificacao de identidade nao e realizada diretamente pela organizacao contratante. Essa exposicao e particularmente aguda nos subsetores de Financas Descentralizadas (DeFi) e criptomoedas, onde uma cultura de contratacao rapida e remota pode criar lacunas significativas na verificacao, permitindo que os atores obtenham acesso confiavel a tesourarias de ativos digitais e protocolos essenciais.&lt;/p&gt;
&lt;h3&gt;Governo e administracao publica&lt;/h3&gt;
&lt;p&gt;A Okta observou um fluxo pequeno, mas persistente, de entrevistas de emprego entre trabalhadores de TI ligados a RPDC e departamentos do governo estadual e federal dos EUA entre 2023 e 2025, com exemplos adicionais em entidades governamentais do Oriente Medio e da Australia. Embora nossos dados nao confirmem se alguma dessas entrevistas resultou em emprego, as tentativas demonstram que as agencias governamentais nao sao imunes a campanha.&lt;/p&gt;
&lt;p&gt;Mais significativa e a exposicao a administracao publica por meio de prestadores de servicos, provedores de servicos e consultorias governamentais. Essas organizacoes geralmente tem amplo acesso a redes governamentais e projetos confidenciais, mas enfrentam grandes volumes de contratacao, prazos curtos e grandes grupos de trabalhadores remotos. Se a triagem ou os controles de acesso falharem, os atores da Coreia do Norte podem obter entrada indireta em sistemas governamentais ou repositorios de dados confidenciais. A Okta avalia que os governos e seus fornecedores terceirizados devem adotar verificacao de identidade inicial e continua rigorosa e segregacao de acesso para reduzir o risco de infiltracao.&lt;/p&gt;
&lt;h3&gt;Terceirizacao e provedores de servicos de TI&lt;/h3&gt;
&lt;p&gt;Grandes provedores de servicos de outsourcing e TI aparecem frequentemente nos dados da Okta, refletindo seu recrutamento constante para funcoes tecnicas remotas e baseadas em contrato - exatamente o tipo de posicoes que os trabalhadores de TI ligados a Coreia do Norte buscam. Essas organizacoes normalmente anunciam em grande escala e processam altos volumes de candidatos, aumentando a chance de um adversario passar despercebido.&lt;/p&gt;
&lt;p&gt;Embora muitas dessas empresas geralmente mantenham verificacoes de antecedentes e controles de seguranca robustos, o tamanho de sua forca de trabalho contingente e a natureza incorporada de sua equipe nos ambientes dos clientes criam um risco sistemico. Qualquer comprometimento em um provedor de servicos pode se estender a varias organizacoes de clientes, ampliando o impacto potencial. A Okta avalia que as Organizacoes devem tratar os prestadores de servicos e a equipe do provedor de servicos como potenciais ameacas internas e exigir de seus fornecedores verificacao de identidade, monitoramento e controles de acesso semelhantes aos usados para funcionarios diretos. Os processos de negocios e o acesso do fornecedor a dados e sistemas devem ser estritamente limitados ao minimo absoluto necessario, rigorosamente auditados e sujeitos a uma avaliacao de riscos rigorosa.&lt;/p&gt;
&lt;h2&gt;O alcance global da ameaca&lt;/h2&gt;
&lt;p&gt;A analise de Okta Threat Intelligence revela, como esperado, que a grande maioria das funcoes visadas (73%) foram anunciadas por empresas sediadas nos EUA. Exemplos da campanha de Trabalhadores de TI da RPDC foram identificados pela primeira vez nos EUA e continuaram la em grande escala. E provavel que tambem haja alguns vieses inerentes no conjunto de dados que analisamos que inclinam nossa amostra para alvos baseados nos EUA.&lt;/p&gt;
&lt;p&gt;Dito isto, nossa analise revela uma expansao significativa das operacoes de ITW para outros paises (27% do total/nao-EUA), muitas vezes pelos mesmos atores DPRK que normalmente tem como alvo funcoes nos EUA. Reino Unido, Canada e Alemanha respondem por mais de 2% do total de observacoes (cada um representando aproximadamente 150 - 250 funcoes).&lt;/p&gt;
&lt;h2&gt;Ameaca crescente de uma forca de trabalho madura&lt;/h2&gt;
&lt;p&gt;A Okta avalia que, a medida que o foco da operacao do Trabalhador de TI da RPDC se espalha globalmente, a ameaca aos empregadores em paises recem-visados e elevada. Anos de atividade sustentada contra uma ampla gama de setores dos EUA permitiram que facilitadores e trabalhadores alinhados a RPDC refinassem seus metodos de infiltracao. Consequentemente, eles estao entrando em novos mercados com uma forca de trabalho madura e bem adaptada, capaz de ignorar os controles basicos de triagem e explorar os pipelines de contratacao de forma mais eficaz. Novos mercados que podem ver o esquema ITW como um &#34;problema das grandes empresas de tecnologia dos EUA&#34; tem menos probabilidade de ter investido tempo e esforco no amadurecimento de seus programas de ameacas internas. Os aspectos educacionais, tecnicos e gerenciais de tal programa exigem algum tempo e esforco para se tornarem eficazes.&lt;/p&gt;
&lt;p&gt;A pesquisa da Okta Threat Intelligence mostra um grande volume de entrevistas de emprego iniciais concedidas a profissionais de TI ligados a Coreia do Norte em varios setores. Neste momento, temos menos confianca nas observacoes sobre quais aplicativos avancaram alem de uma primeira entrevista. Nossa amostra sugere que, no maximo, 10% desses candidatos progrediram para entrevistas de acompanhamento.  &lt;/p&gt;
&lt;p&gt;Essa taxa de sucesso nao deve ser tranquilizadora para os empregadores. A Okta analisou apenas um pequeno subconjunto do numero total compreendido de identidades fraudulentas ligadas as operacoes de DPRK IT Worker. Na escala desta atividade, mesmo um pequeno numero de candidatos que progridem com sucesso para a segunda ou terceira entrevista representa uma ameaca significativa. Basta uma contratacao comprometida - particularmente em uma funcao remota privilegiada ou de alto acesso - para permitir que os adversarios roubem dados, interrompam sistemas ou prejudiquem a reputacao e a confianca dos clientes. Funcoes de desenvolvimento de software geralmente exigem acesso elevado a dados e sistemas confidenciais, e essas permissoes sao frequentemente concedidas desde o inicio do emprego.&lt;/p&gt;
&lt;p&gt;Esses atores foram observados usando diversos servicos online de idiomas e educacao tecnica para reforcar suas habilidades empregaveis. Eles tambem &lt;a href=&#34;https://sec.okta.com/articles/2025/04/GenAIDPRK/&#34; target=&#34;_self&#34; rel=&#34;noopener noreferrer&#34;&gt;utilizam servicos de IA&lt;/a&gt; em suas tentativas de emprego.&lt;/p&gt;
&lt;h2&gt;Resposta a &#34;pressao do mercado&#34;?&lt;/h2&gt;
&lt;p&gt;Os agentes de ameacas no esquema ITW tem &lt;a href=&#34;https://www.dtexsystems.com/exposing-dprk/&#34;&gt;historicamente demonstrado&lt;/a&gt; menos sofisticacao tecnica do que suas contrapartes nas operacoes de espionagem e ransomware da RPDC. Isso nao diminuiu o sucesso deles. Os operadores de ITW da RPDC ganharam com sucesso dezenas de milhoes de dolares para o regime, e observamos variacao suficiente em suas taticas ao longo do tempo para concluir que agora desfrutam de autonomia significativa.&lt;/p&gt;
&lt;p&gt;Mas a operacao ITW agora enfrenta uma nova ameaca: uma conscientizacao crescente e uma interrupcao coordenada de suas atividades. O escrutinio do esquema DPRK ITW dentro de seu vertical mais visado, o setor de tecnologia dos EUA, provavelmente interrompeu sua geracao de receita. &lt;/p&gt;
&lt;p&gt;As unidades da DPRK encarregadas de operacoes de espionagem e ransomware agora veriam o modelo de contratacao ITW como um vetor nao para obter emprego e salarios incidentais, mas sim como uma oportunidade para roubo e extorsao de dados direcionados e persistentes. Ha indicacoes iniciais de que o acesso ITW ja esta sendo abusado para esses fins. &lt;/p&gt;
&lt;p&gt;As organizacoes que contratam esses individuos atualmente enfrentam riscos relacionados a sancoes e danos a reputacao. No futuro, elas podem enfrentar roubo de dados deliberado e direcionado e operacoes de extorsao que exploram o mesmo acesso.&lt;/p&gt;
&lt;h2&gt;Implicacoes principais para organizacoes visadas&lt;/h2&gt;
&lt;p&gt;As descobertas da Okta revelam que a operacao de TI Worker da RPDC nao e uma ameaca de nicho confinada a grandes empresas de tecnologia. E uma campanha generalizada e de longo prazo que visa organizacoes em quase todas as verticais. Isso significa que qualquer organizacao que ofereca funcoes remotas ou hibridas - especialmente em desenvolvimento de software, servicos de TI ou outras disciplinas de trabalhador do conhecimento - e um alvo potencial.&lt;/p&gt;
&lt;p&gt;A escala e a sofisticacao da operacao demonstram que os processos de recrutamento tradicionais, por si so, sao insuficientes para impedir a infiltracao. Cada contratacao comprometida pode fornecer a RPDC:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Ganho financeiro direto (pagamentos de salarios desviados para o regime)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Acesso interno privilegiado a sistemas, dados e redes confidenciais&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Alavancagem operacional para ransomware, extorsao ou atividade cibernetica de acompanhamento&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Perda de segredos corporativos sensiveis ao comercio&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Coleta de inteligencia estrategica e acesso para suporte a futuras operacoes ofensivas&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Alem disso, organizacoes que contratam inadvertidamente agentes da RPDC correm potencialmente o risco de violacao de fato das obrigacoes de sancoes e exposicao legal associada.&lt;/p&gt;
&lt;p&gt;As organizacoes devem, portanto, adotar uma defesa em camadas, incluindo verificacao de identidade rigorosa durante o recrutamento, monitoramento continuo dos padroes de acesso e comportamento de trabalhadores remotos e um plano claro de resposta a incidentes para gerenciar ameacas internas ou a cadeia de suprimentos.&lt;/p&gt;
&lt;h2&gt;Etapas a serem tomadas para combater essa ameaca&lt;/h2&gt;
&lt;p&gt;A Okta Threat Intelligence avalia que organizacoes em todos os setores verticais - particularmente aquelas que anunciam funcoes remotas ou de contrato - devem adotar uma abordagem em camadas e proativa para recrutamento, integracao e monitoramento de ameacas internas. A Okta recomenda:&lt;/p&gt;
&lt;h3&gt;1. Fortalecer a verificacao da identidade do candidato&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Exija verificacoes de identificacao emitidas pelo governo em varios estagios de recrutamento e emprego.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Verifique as localizacoes declaradas com enderecos IP (inclua a deteccao de uso de VPN), comportamento de fuso horario e informacoes bancarias da folha de pagamento.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Use servicos de terceiros credenciados para autenticar documentos de identidade, emprego anterior e credenciais academicas&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;2. Reforce os processos de recrutamento e triagem&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Treine o RH e os recrutadores para identificar sinais de alerta. Incentive processos que identifiquem se um candidato e substituido entre as rodadas de entrevistas. Ensine-os a identificar sinais comportamentais, como pouco conhecimento da area em que afirmam residir, recusa em se encontrar pessoalmente, recusa em ligar a camera ou remover filtros de fundo durante as entrevistas ou fazer entrevistas usando uma conexao de internet muito ruim. Identifique curriculos duplicados, cronogramas inconsistentes, fusos horarios incompativeis e referencias nao verificaveis. Avalie a presenca online e nas redes sociais do candidato em relacao as informacoes fornecidas. Onde forem fornecidas evidencias de trabalhos anteriores, investigue se esses projetos foram simplesmente clonados dos repositorios de perfis do usuario legitimos.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Verifique o historico de edicoes de curriculos e PDFs nos metadados do documento e outros &amp;quot;sinais&amp;quot; tecnicos associados a duplicacao e reutilizacao.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Adicione verificacao tecnica e comportamental estruturada (codificacao ou escrita ao vivo realizada sob observacao do recrutador).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Exija referencias de e-mail corporativo (nao webmail gratuito) e confirme por meio de uma chamada de saida para os numeros da central telefonica principal da organizacao de referencia.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;3. Impor controles de acesso segregados e baseados em funcao&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Defina novos ou contingentes trabalhadores para perfis de menor privilegio por padrao e desbloqueie acesso adicional quando as verificacoes probatorias forem concluidas.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Segmente desenvolvimento, teste e producao; exija revisao por pares e fluxos de trabalho de aprovacao para mesclagens e implantacoes de codigo.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Monitore padroes de acesso anomalos (grandes extracoes de dados, logins fora do horario de trabalho de geolocalizacoes/VPNs inesperadas, compartilhamento de credenciais).&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;4. Monitore os prestadores de servicos e provedores de servicos terceirizados&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Sempre que possivel, obrigue contratualmente padroes continuos de verificacao de identidade, verificacoes de antecedentes, politicas de autenticacao avancada, linhas de base de seguranca de dispositivos e direitos de auditoria.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Exija contas do usuario nomeadas (sem logins compartilhados ou contas de servico internas, sempre que possivel) e acesso separado de locatario/projeto para cada ambiente de cliente.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;5. Implementar programas de conscientizacao sobre ameacas internas e conscientizacao sobre seguranca&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Estabeleca uma funcao dedicada de risco interno ou, pelo menos, um grupo de trabalho que abranja RH, Juridico, Seguranca e TI.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Forneca treinamento direcionado para recrutadores, gerentes de contratacao e lideres tecnicos sobre as taticas de ITW e os controles de triagem.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Eduque e capacite os gerentes de contratacao e os membros da equipe a observar e enviar relatos de comportamentos potencialmente estranhos por parte de seus pares que levantem questoes sobre sua identidade, objetivos e locais. &lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Crie canais de relatorios mais seguros para comportamentos suspeitos ou preocupacoes com candidatos.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;6. Coordene-se com a aplicacao da lei e pares do setor&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Compartilhe indicadores de comprometimento e padroes de candidatos suspeitos com unidades nacionais de combate ao cibercrime e grupos ISAC/ISAO.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Desenvolva metodos para que o grupo de &#34;risco interno&#34; receba e acione indicadores (enderecos de e-mail, enderecos IP, provedores de VPN, criacao de documentos e indicadores comportamentais) e esteja preparado para &#34;compartilhar de volta&#34; as descobertas relevantes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Participe ativamente de foruns de compartilhamento de informacoes para rastrear as taticas e ferramentas de ITW em evolucao.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;7. Realize avaliacoes de risco e exercicios de red team regularmente&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Modele caminhos de ataque de insiders e prestadores de servicos maliciosos; quantifique o impacto potencial nos negocios.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Realize exercicios de red team que testem o pipeline de contratacao (aplicativo e entrevistas simuladas da RPDC) para avaliar os processos de verificacao de identidade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Atualize os planos de resposta a incidentes para incluir cenarios envolvendo agentes internos maliciosos, prestadores de servicos comprometidos e revogacao de acesso acelerada.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Conclusao&lt;/h2&gt;
&lt;p&gt;A analise da Okta demonstra que a campanha de Trabalhadores de TI da RPDC e uma operacao em grande escala e sustentada. Embora originalmente tenha como alvo empresas de tecnologia dos EUA, a campanha agora abrange quase todos os setores e varias regioes geograficas.&lt;/p&gt;
&lt;p&gt;A escala e a duracao da atividade indicam um esforco sistematico para obter recursos financeiros, acesso tecnico e inteligencia estrategica dentro das organizacoes visadas. Um numero relativamente pequeno de identidades alinhadas a RPDC gerou milhares de entrevistas, evidenciando tanto persistencia quanto maturidade do processo. Apesar da ampla conscientizacao sobre essa ameaca, as tentativas de entrevista, o direcionamento e a metodologia continuam a crescer e evoluir.&lt;/p&gt;
&lt;p&gt;Embora o desvio da folha de pagamento permaneca o motivador mais visivel, o risco estrategico se estende muito alem dos salarios. A colocacao bem-sucedida de ITW pode permitir a exfiltracao de dados, a interrupcao operacional e o estabelecimento silencioso de pontos de apoio de acesso interno que podem ser alavancados para espionagem, coercao ou futuras operacoes ciberneticas.&lt;/p&gt;
&lt;p&gt;Organizacoes que ainda veem isso como uma questao &#34;apenas para grandes empresas de tecnologia&#34; correm o risco de subestimar sua exposicao. A evidencia apresentada neste relatorio deve servir como uma chamada a acao para fortalecer os controles de recrutamento e verificacao de identidade, elevar o monitoramento de prestadores de servicos e fornecedores terceirizados e garantir que os planos de resposta a incidentes abordem explicitamente vetores de entrada internos e da cadeia de suprimentos.&lt;/p&gt;
&lt;p&gt;Com conscientizacao precoce, verificacao rigorosa e defesa coordenada, as organizacoes podem reduzir materialmente a probabilidade de contratar candidatos fraudulentos e limitar qualquer impacto potencial decorrente da infiltracao.&lt;/p&gt;
]]>
                </description>
                <pubDate>Sun, 28 Sep 2025 22:00:00 +0000</pubDate>
                
                    <category>threat-intelligence,threat-insights,fraudulent-registration,identity-theft,iam</category>
                
                <dc:creator>Simon Conant, Alex Tilley</dc:creator>
            </item>
        
    </channel>
</rss>
