A large-scale phishing campaign dubbed ‘0ktapus’ has wreaked havoc compromising more than 130 organisations across the world, including companies like Twilio, Best Buy and Doordash.
During the attack, login credentials belonging to nearly 10,000 individuals were stolen by the attackers who imitated the popular single sign-on service Okta, which was used by all the compromised companies.
The targets of the phishing campaign were sent text messages which redirected them to a phishing site which was manipulated by the attackers.
Tasked with the investigation of these attacks is Cybersecurity outfit Group-IB, which stated: “From the victim’s point of view, the phishing site looks quite convincing as it is very similar to the authentication page they are used to seeing.”
Consequently, the victims were asked for their username, password and a two-factor authentication code.
This information was then sent to the attackers who used these credentials to launch targeted attacks on several organisations in a coordinated effort.
Attack objectives
The primary objective of the attack was to obtain login credentials and two-factor authentication (2FA) codes from users of the targeted organisations.
Subsequently, with this information in hand, the attackers could gain unauthorised access to any enterprise resources the victims have access to.
Group-IB adds: “This case is of interest because despite using low-skill methods it was able to compromise a large number of well-known organizations.”
Once the attackers were in the systems, they were able to side-step and launch further attacks exploiting the organisations’ digital infrastructure even further.
Attack methodology
Who are the targets?
The 0ktapus phishing campaign is believed to have kicked off around March this year.
To date, it is estimated that around 9,931 login credentials have been stolen across 136 organisations around the world.
The attackers have spread their net wide, targeting multiple industries, including finance, gaming and the telecommunication sectors.
The majority of these attacks were launched at companies headquartered in the US, with one undisclosed Australian firm in the mix as well.
Companies like Twilio, Best Buy and Doordash have been already vulnerable to the attacks, with Cloudfare being able to thwart the threat.
Domains cited by Group-IB as targets (but not confirmed breaches) include Microsoft, Twitter, AT&T, Verizon Wireless, Coinbase, Best Buy, T-Mobile, Riot Games and Epic Games.
Geolocations of the company's
Who is behind these attacks?
During Group-IB’s investigation, it discovered that code in the hacker’s phishing kit revealed configuration details of the Telegram bot that the attackers used to drop compromised data.
Analysing the phishing kit, the researchers have concluded that the attackers are “inexperienced”, however, the scale at which the attacks were conducted was “massive”.
Group-IB identified one of the Telegram group’s administrators who goes by the handle 'X', whose GitHub and Twitter handles suggest they may reside in North Carolina.
Twitter handle of 'X'.
Cash appears to be at least one of the motives for the attacks, with researchers stating, “Seeing financial companies in the compromised list gives us the idea that the attackers were also trying to steal money."
Furthermore, some of the targeted companies provide access to crypto assets and markets, whereas others develop investment tools.”