Mandiant's brute-forced X account exposes perils of skimping on 2FA
- Reference: 1704992408
- News link: https://www.theregister.co.uk/2024/01/11/mandiant_x_account_brute_forced/
- Source link:
The natural reaction to this would be to ask why two/multi-factor authentication didn't prevent this from taking place. Well, Mandiant's carefully worded response basically said it wasn't implemented.
"Normally, 2FA would have mitigated this, but due to some team transitions and a change in X's 2FA policy, we were not adequately protected," it [1]posted via its [2]now recovered account . "We've made changes to our process to ensure this doesn't happen again."
[3]
That's as much detail as the company was willing to dish out. It didn't specifically point to the policy change X (then called Twitter) announced in February 2023, which was to disable SMS-based 2FA for users who didn't pay for Twitter Blue, but some have [4]speculated that this may be the reason a brute force attack was achievable.
[5]
[6]
Mandiant does not have an X account with any kind of verification, a consumer-grade blue tick, or a big org yellow tick, which means it does not pay X and if it did rely on SMS-based 2FA, it would have been removed when the policy change took place in March 2023.
X still allows free accounts to use 2FA, as long as it's app-based or uses security keys, both of which are considered safer than SMS-based 2FA, which is vulnerable to SIM swapping.
[7]
According to X's [8]data taken from 2021, just 2.6 percent of users enabled any form of 2FA on their accounts and 74.4 percent of those who did used an SMS-based implementation.
"Humans being human and avoiding additional work, many didn't take an additional step on [March 20, 2023] to re-set up MFA using a different free option," [9]said Rocahel Tobac, CEO at Social Proof Security.
Google's [10]data from 2019 indicated that SMS-based 2FA can block up to 100 percent of automated attempts to hijack accounts, 99 percent of bulk phishing attacks, and 66 percent of targeted attacks.
[11]
This means even the least-effective form of 2FA is certainly better than no 2FA at all.
The Register approached Mandiant for clarity on the matter but the company did not respond.
Mandiant did confirm in a [12]blog covering the incident's investigation that there is no evidence to suggest there was a compromise of the systems at Mandiant or its parent Google Cloud.
The postmortem into the account hijack comes days after the US Securities and Exchange Commission (SEC) also had its X account taken over by what is believed to be a SIM-swapping attack.
After being compromised, attackers used their access to the account, which has 746,600 followers, to push news about Bitcoin ETFs being approved for listing on national exchanges.
The SEC quickly passed this off as fake news before announcing today that, actually, [13]it was true after all .
Drainer-as-a-service scams on the rise
As it revealed the cause of the hijack, Mandiant also [14]blogged about the scam the hijackers pushed in the hours they had control of the account, an attack that's been growing in popularity in the last few months.
The scam, Mandiant says, was pushing the CLICKSINK drainer-as-a-service (DaaS) – a toolkit comprising malicious scripts and smart contracts to steal digital assets like cryptocurrencies and NFTs from web3 enthusiasts.
[15]Infoseccers think attackers backed by China are behind Ivanti zero-day exploits
[16]Fidelity National now says 1.3M customers had data stolen by cyber-crooks
[17]Uncle Sam tells hospitals: Meet security standards or no federal dollars for you
[18]Be honest. Would you pay off a ransomware crew?
CLICKSINK is just one of the many [19]draining campaigns that have been wreaking havoc on digital wallets in [20]recent months .
DaaS offerings like CLICKSINK operate using a model that followers of El Reg's ransomware coverage may be familiar with – developers build a toolkit and ship it off to affiliates, collecting a cut of whatever each affiliate is able to rake in.
Mandiant believes CLICKSINK campaigns alone have netted cybercrims $900 million since December 2023, and its developers typically collect between 5 and 25 percent of every successful attack.
"While we do not have direct insight into why there is such a wide variance, it may depend on various factors, such as special partnerships or reduced fees for more successful affiliates," Mandiant said.
Victims are lured by cryptocurrency-themed phishing pages often claiming to offer an airdrop – a common marketing scheme run to raise awareness of new crypto tokens, offering free tokens in exchange for a little publicity.
Due to crypto's well-known propensity for gaining huge value in a short space of time, these schemes naturally attract quite an audience.
At the start of this year, Bill Lou, co-founder of security-focused Nest Wallet (the irony is not lost on anyone), admitted in a series of [21]posts to X that he too fell for an airdrop-themed drainer attack, losing 52 Lido Staked Ether (stEth) tokens, equivalent to around $140,000 by today's conversion.
Rather than seeing a dodgy link posted on social media, Lou followed a seemingly legitimate article that allegedly appeared at the top of Google's search ranking for whatever term he used.
These phishing pages lure users into connecting their wallets to receive what they believe is free crypto, only to have it drained after signing a transaction.
The stEth token itself has soared in value recently – 20 percent in the last month and 98 percent in the past year, according to Coinbase.
A hallmark of the recent DaaS campaigns is to target owners of tokens that are rapidly rising in value. CLICKSINK, for example, targets Solana (SOL) owners since its value is one of the fastest-growing of all tokens in recent months.
Considering the success of such operations in recent years, Mandiant expects the attacks to continue for some time.
"The wide availability and low cost of many drainers, combined with a relatively high potential for profit, likely makes them attractive operations for many financially motivated actors," it said.
"Given the increase in cryptocurrency values and the low barrier to entry for draining operations, we anticipate that financially motivated threat actors of varying levels of sophistication will continue to conduct drainer operations for the foreseeable future." ®
Get our [22]Tech Resources
[1] https://twitter.com/Mandiant/status/1745173897220432331
[2] https://www.theregister.com/2024/01/04/mandiant_restores_hijacked_x_account/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZaBzGToFZTNmWSs9I6KkDQAAAA4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://twitter.com/RachelTobac/status/1745253912985403624
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaBzGToFZTNmWSs9I6KkDQAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaBzGToFZTNmWSs9I6KkDQAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaBzGToFZTNmWSs9I6KkDQAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://transparency.twitter.com/en/reports/account-security.html#2021-jul-dec
[9] https://twitter.com/RachelTobac/status/1745251588497912301
[10] https://security.googleblog.com/2019/05/new-research-how-effective-is-basic.html
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaBzGToFZTNmWSs9I6KkDQAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://www.mandiant.com/resources/blog/solana-cryptocurrency-stolen-clinksink-drainer-campaigns
[13] https://www.reuters.com/technology/bitcoin-etf-hopefuls-still-expect-sec-approval-despite-social-media-hack-2024-01-10/
[14] https://www.mandiant.com/resources/blog/solana-cryptocurrency-stolen-clinksink-drainer-campaigns
[15] https://www.theregister.com/2024/01/11/china_backed_ivanti_exploits/
[16] https://www.theregister.com/2024/01/10/fidelity_data_disclosure/
[17] https://www.theregister.com/2024/01/10/us_hospitals_security_rules/
[18] https://www.theregister.com/2024/01/10/ransomware_kettle/
[19] https://www.theregister.com/2023/11/10/justin_sun_poloniex_reward/
[20] https://www.theregister.com/2023/11/08/monero_project_developers_announce_breach/
[21] https://twitter.com/BillLou95/status/1742098683133612370
[22] https://whitepapers.theregister.com/
This is why I ignore the 2FA naysayers.
Even pisspoor 2FA is better than none.
Re: This is why I ignore the 2FA naysayers.
Not quite, if you're a scammer, but nearly. You can talk the mark's provider into a SIM-swap or you just go ahead and steal the phone.
Remember folks, if you rely on mobile-based 2FA whoever holds your phone[number] is you, even if it's not you.
Re: This is why I ignore the 2FA naysayers.
How common are SIM-swap attacks for regular people? Doesn't someone basically have to socially engineer an attack on the cell provider? In most cases, that should be difficult enough that only high-value targets would be worth going after. In terms of stealing the phone, my phone is locked, and the moment I realized it was gone, I would find my device and, if it was not in a location I recognized, I would remote-wipe it. My phone (as with most people's) is locked most of the time, anyway, so I'm mostly unconcerned with the possibility of a random thief breaking into it.
Pointing out that there are flaws with the SMS approach don't negate the reality that it's still better protection than a password alone.
Re: This is why I ignore the 2FA naysayers.
Not sure that's true where SMS based 2FA is concerned, given how easy it is to overcome.
National Savings wrote to me to ask me to fill in a form to sign up for Internet access to my account.
I wrote on the form:
NEVER
NEVER
NEVER
and sent it back to them.
Haven't heard back.
That's nice, granddad. Go back to listening to your phonograph.
Brute forced?
So their password was quite simple or very short, because you cannot brute force a 20 chars random password in a decent time, at least in my opinion.
Re: Brute forced?
Why wasn't the account locked after the 3rd failure ?
Re: Brute forced?
It depends how many options you go through and how many nodes you test from. A truly random 20-character password would be hard, but a predictable 20-character password is less difficult. This is why they usually block people from doing brute force attacks, but that either wasn't in place or didn't work in this case.
Deary me
Is there any less useful claim than “up to 100%”? Terrible that they may not block attacks that do not exist ;)
Not to mention, signing a transaction for free crypto??? Was it offered by a Nigerian??
Gimme your phone number
Google's data from 2019 indicated that SMS-based 2FA can block up to 100 percent of automated attempts to hijack accounts, 99 percent of bulk phishing attacks, and 66 percent of targeted attacks.
Well, Google would say that, wouldn't they? How else would they grab the phone numbers and link that to the personal data of iPhone users? It already has that for Androids, so if you have one of those, may as well use 2FA. But I had a fun conversation with my bank requesting a new dongle. Why not use the app on my 'smart phone'. What's the most stolen device, I wonder..
Bit of a Hobson's Choice though, minimise the risk of targeted attacks, if you accept the massively increased risk of targeted spam.