Russian hackers bypass 2FA by annoying victims with repeated push notifications
Full article602 words · extracted from therecord.media · click to collapse
Nobelium, the Russian cyber-espionage group that has orchestrated the SolarWinds 2020 supply chain attack, has continued to carry out new attacks throughout 2021, and according to security firm Mandiant, has been using a clever trick to bypass two-factor authentication in order to access some of its targets' accounts. The technique, detailed in a report published on Monday, involves abusing the push notification feature of some online accounts. 2FA (two-factor authentication) or MFA (multi-factor authentication) push notifications are typically used as an alternative to receiving one-time codes via SMS or email, and they take the form of a popup that appears on a smartphone. When a user logs into an account with valid credentials, a push notification is shown on their smartphone, with details about the type and IP address of the device trying to access the account and asking for permission to allow the operation to go through. 2FA push notifications aren't widely adopted, but they are considered safer than email or SMS as a 2FA method because attackers would need physical access to a victim's smartphone in order to bypass it. But on Monday, Mandiant researchers said they'd investigated several incidents where Nobelium members gained access to a user's valid login credentials, and they repeatedly attempted to log into the account, triggering repeated 2FA push notifications on the victim's device until the target eventually accepted the request. It is unclear if these victims accepted the push notification by accident; because they thought it might have been a bug; or by sheer annoyance. Because Nobelium often uses IP proxies in the same geographical area as the victim to avoid triggering a target's scrutiny over login requests from strange IPs, this might explain why some victims accepted the attacker's into their accounts. All in all, the Mandiant report paints the picture of an apex threat actor that continues to showcase "top-notch operational security and advanced tradecraft," and will certainly not be defined by the SolarWinds hack as its sole successful operation. Among the group's most recent tactics and operations, Mandiant also highlighted: In April this year, the White House formally linked the Nobelium threat actor to the Russian Foreign Intelligence Service, also known as the SVR, the same agency which security experts believe is behind the APT29 (Cozy Bear) threat actor.Nobelium continues to operate with advanced tradecraft
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russian-hackers-bypass-2fa-by-annoying-victims-with-repeated-push-notifications