Spies hack Wi-Fi networks in far-off land to launch attack on target next door

Date:

Share:


While stalking its target, GruesomeLarch performed credential-stuffing attacks that compromised the passwords of several accounts on a web service platform used by the organization’s employees. Two-factor authentication enforced on the platform, however, prevented the attackers from compromising the accounts.

So GruesomeLarch found devices in physically adjacent locations, compromised them, and used them to probe the target’s Wi-Fi network. It turned out credentials for the compromised web services accounts also worked for accounts on the Wi-Fi network, only no 2FA was required.

Adding further flourish, the attackers hacked one of the neighboring Wi-Fi-enabled devices by exploiting what in early 2022 was a zero-day vulnerability in the Microsoft Windows Print Spooler.

The 2022 hack demonstrates how a single faulty assumption can undo an otherwise effective defense. For whatever reason—likely an assumption that 2FA on the Wi-Fi network was unnecessary because attacks required close proximity—the target deployed 2FA on the Internet-connecting web services platform (Adair isn’t saying what type) but not on the Wi-Fi network. That one oversight ultimately torpedoed a robust security practice.

Advanced persistent threat groups like GruesomeLarch—a part of the much larger GRU APT with names including Fancy Bear, APT28, Forrest Blizzard, and Sofacy—excel in finding and exploiting these sorts of oversights.

Volixity’s post describing the 2022 attack provides plenty of technical details about the compromise on the many links in this sophisticated daisy chain attack flow. There’s also useful advice for protecting networks against these sorts of compromises.



Source link

━ more like this

Trump’s 8pm Strait of Hormuz deadline is a binary market risk – London Business News | Londonlovesbusiness.com

Trump’s 8pm (ET) deadline on Hormuz is a major market event and investors are underestimating the binary risk, warns the CEO of one...

Top five outsourced and white label SEO for agencies packages compared – London Business News | Londonlovesbusiness.com

Your agency’s deal flow is healthy, but bandwidth is tapped. SEO requests pile up, and senior hires take months you don’t have. White-label...

How UK businesses are eradicating the administrative burden with Artificial Intelligence – London Business News | Londonlovesbusiness.com

For many UK businesses, growth does not fail because of weak demand or poor strategy. It slows down because teams are trapped in...

Greggs launches chicken roll as part of new ‘trilogy’ range – London Business News | Londonlovesbusiness.com

Greggs is adding a chicken version of its iconic sausage roll to menus nationwide, expanding its offering with a new permanent product. The “Chicken...

Artemis II astronaut puts all of our iPhone moon photos to shame

When NASA allowed Artemis II astronauts to take their smartphones with them, we already knew it could lead to some epic phone shots...
spot_img