Initial access brokers (IABs) use phishing tactics to call or text employees' personal devices This article explores intricacies phishing attempts. . Since May, researchers at Microsoft have identified two threat actors, named Storm 3032 and Storm-3121, who are exploiting personal devices to completely bypass companies' authentication security measures.
However, this approach often results in encountering the company's security measures, such as email security gateways and endpoint detection and response (EDR) systems, designed to prevent unauthorized access. Related: Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites Significantly more important than any specific detail of the phishing process is the fact that virtually none of it occurs on actual corporate systems.
As Microsoft pointed out in its blog post, "In many investigations, the employee's recollection of a phone call or text message becomes the earliest and sometimes the only evidence explaining how the compromise began. As a result, investigators must often reconstruct the attack by connecting these reports with subsequent sign-ins, device code authentication events, token activity, and authentication method changes." Threat actors are incorporating additional intricacies into their phishing attempts, such as malicious domains like "company[.]add-passkey[.
]com" that blend victims' employer names with security-related phrases. For personal device security, they advocate for stronger authentication and authorization measures, including requiring phishing-resistant MFA for all sign-ins, blocking unnecessary device code authentication flows, limiting access to managed devices, and so on.












