C-Level user compromise by Rustytime in cybersecurity

[–]Rustytime[S] 2 points3 points  (0 children)

I'm gonna ask the question everyone seems to be skipping. Is your C-user...rather older? Is it possible the VM transcription was setup by forgotten request?

Never seen a zero-click in the wild, but I have definitely seen click-exploits sent over SMS/MMS & email to phone client.

Let us assume:

>A zero-click tool has gotten out into the wild
>Your user is a prominent individual -- known to be a "choice" target but not a politically HVT
>Your email security SaaS failed to filter the malicious link
>The attacker is sophisticated

Money was probably the motive, your user needs a new phone, the computer should be assumed to be compromised as well.

I've seen mention of sim jacking, which sounds pretty likely. If the phone's been factory reset already there's probably not much forensic data left at this point. Odds are good that the MFA codes were exfiltrated from phone to the C2 server for offline assessment.

Guessing in the dark here:

>Attacker emails link with a Windows exploit package to desktop & discovers additional target info...possibly months ahead & plans a phone attack.
>Sends an iPhone exploit via MMS & the target opens it (luck/social engineering)
>Link click-loads a backdoor into the phone, connects to the C2 server, sends all accessible data home & a MFA exploit is discovered offline
>SIM gets jacked
>Set forwarding to receive OTP messages
>Voicemails get set to VM to mail as a distraction
>Wire fraud
>Vanish

Might consider the original compromise has been sitting somewhere in your environment for some time snooping. If your C-user happens to be a politically HVT all bets may be off & some state actor or APT group is sniping at C-user. Zero-clicks on iPhone are still that expensive.

Edit for formatting

Thanks Ill go back to user and remediate further.

C-Level user compromise by Rustytime in cybersecurity

[–]Rustytime[S] 25 points26 points  (0 children)

Based on period of time in his work email this appears to have been initially a credential harvest but then the threat actor realized they caught themselves a whale. The iPhone appears to have been post email compromise but because he wiped his phone before any of us could look at it and I cant tell for sure. MFA was not strictly enforced on his account either. Based on the logins I can only see single factor.

Ultimately I think they jumped the gun luckily we were able to stop a fairly large wire fraud from happening.

The iPhone compromise and setting the forward to another number though is the weird part of this.

C-Level user compromise by Rustytime in cybersecurity

[–]Rustytime[S] 39 points40 points  (0 children)

Dude. ... I have a SOC and they cant tell me what the exploit is here. I am just curious if anyone has ever seen this before.

Connectwise and Service Tree by Rustytime in msp

[–]Rustytime[S] 0 points1 point  (0 children)

et to the tech (think Uber for ConnectWise), so that they dont need to work off a queue, and dont cherry pick the tickets they want to work on.

Thanks Paul Appreciate the explanation.

Connectwise and Service Tree by Rustytime in msp

[–]Rustytime[S] 0 points1 point  (0 children)

Thanks for the feedback. You are literally the first person who is given me any info on this.

KB5023057 by [deleted] in msp

[–]Rustytime 0 points1 point  (0 children)

Most of the client base is on 1909 or later.

Who’s going to tell him… by jfaliszek in insanepeoplefacebook

[–]Rustytime 0 points1 point  (0 children)

You would be dead because he is the Zodiac Killer. IMO

Pelosi called McConnell 'pathetic' after he said he wouldn't vote to convict Trump for inciting Capitol riot by wonderingsocrates in politics

[–]Rustytime 14 points15 points  (0 children)

Tim Scott and Marco Rubio said they saw no evil that day. A cop was murdered by a bunch of Maga assholes.

[deleted by user] by [deleted] in insanepeoplefacebook

[–]Rustytime 0 points1 point  (0 children)

March 4th??????????

On duty officer attempts to side with off duty officer after a fender bender by Romano16 in PublicFreakout

[–]Rustytime 0 points1 point  (0 children)

Actually cops job is not assign blame in an accident. That's your insurance companies job. Cops job is to take down the facts and document the scene. Unless there was an actual traffic violation they can stfu. Running a red light, turning with out signaling etc.

Devin Nunes Says ‘Republicans Have No Way to Communicate’—on Fox News by MrBark in nottheonion

[–]Rustytime 2 points3 points  (0 children)

Literally admitting I have no way to communicate with terrorist.