* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, May 17, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Dive into the Exciting World of Lark’s Entertainment: Your Ultimate Fun Destination!

    Discover the World’s Richest Musician with a Fortune Close to $3 Billion – Can You Guess Who?

    Lincoln Adult Entertainment Store Hit by Burglars Twice in Less Than a Month

    From Raines to Reel Life: How This Creative Trailblazer is Transforming the Entertainment Industry

    Starz Entertainment Officer Granted 6,338 RSUs Vesting Through 2029

    Why Are Popular Netflix Shows Like ‘The Lincoln Lawyer’ and ‘Outer Banks’ Getting Cut Short?

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Vanguard Group Inc. Boosts Investment in Tactile Systems Technology, Inc. $TCMD

    Disguise and Creative Technology Join Forces to Elevate Eurovision’s Stunning Visuals

    Revolutionizing Connectivity: Gi-Fi Technology Market Set to Soar by 2033

    Friday Harbor Becomes First Mortgage Tech Provider to Achieve AI Governance Compliance Certification

    Is Now the Ideal Time to Invest in People & Technology Inc.?

    How Minute Changes in RNA Powerfully Transform Our Innate Immune Defense

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Dive into the Exciting World of Lark’s Entertainment: Your Ultimate Fun Destination!

    Discover the World’s Richest Musician with a Fortune Close to $3 Billion – Can You Guess Who?

    Lincoln Adult Entertainment Store Hit by Burglars Twice in Less Than a Month

    From Raines to Reel Life: How This Creative Trailblazer is Transforming the Entertainment Industry

    Starz Entertainment Officer Granted 6,338 RSUs Vesting Through 2029

    Why Are Popular Netflix Shows Like ‘The Lincoln Lawyer’ and ‘Outer Banks’ Getting Cut Short?

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Vanguard Group Inc. Boosts Investment in Tactile Systems Technology, Inc. $TCMD

    Disguise and Creative Technology Join Forces to Elevate Eurovision’s Stunning Visuals

    Revolutionizing Connectivity: Gi-Fi Technology Market Set to Soar by 2033

    Friday Harbor Becomes First Mortgage Tech Provider to Achieve AI Governance Compliance Certification

    Is Now the Ideal Time to Invest in People & Technology Inc.?

    How Minute Changes in RNA Powerfully Transform Our Innate Immune Defense

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Cozy Bear hijacks SME Microsoft 365 tenants in latest campaign

August 4, 2023
in Technology
Cozy Bear hijacks SME Microsoft 365 tenants in latest campaign
Share on FacebookShare on Twitter

Lubos Chlubny – stock.adobe.com

Microsoft shares intelligence on a newly observed Cozy Bear campaign that saw the APT take over genuine Microsoft 365 tenants and subvert them to try to phish its victims

Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 03 Aug 2023 15:57

A new campaign of social engineering activity targeting organisations of interest to Russian intelligence has been observed in the wild, in which already-compromised Microsoft 365 tenants owned by legitimate small businesses are being used to ensnare victims through bogus Microsoft Teams messages.

The activity is attributed to the advanced persistent threat (APT) group most popularly known as Cozy Bear, which under Microsoft’s revised terminology was recently rebranded from Nobelium to Midnight Blizzard, but also goes by APT29 and UNC2452 depending on whose report you read. The group is arguably most famous for the 2020/1 SolarWinds incident.

In a new advisory posted on 2 August, Microsoft revealed how Cozy Bear exploited unwitting SMEs to create new domains using the legitimate onmicrosoft.com subdomain. These domains would have appeared to a casual observer to be technical support entities and used cyber security-themed terminology.

The group was then able to add a new user associated with the fraudulent domain and use that identity to send Teams messages to potential targets, by means of which it attempted to steal credentials by engaging the user and getting them to approve multifactor authentication (MFA) prompts.

“Our current investigation indicates this campaign has affected fewer than 40 unique global organisations,” said Microsoft.

“Spearphishing attacks target individuals with access to specific information… As with your email, you should be sceptical of unsolicited approaches from anyone external to the organisation trying to reach out through Teams”

Andy Garth, ESET

“The organisations targeted in this activity likely indicate specific espionage objectives by Midnight Blizzard directed at government, non-government organisations (NGOs), IT services, technology, discrete manufacturing and media sectors.

“Microsoft has mitigated the actor from using the domains and continues to investigate this activity and work to remediate the impact of the attack. As with any observed nation-state actor activity, Microsoft has directly notified targeted or compromised customers, providing them with important information needed to secure their environments.”

Cozy Bear’s latest ruse is another example of the APT’s remarkable consistent and persistent approach to operational targeting, and its determination to stay one step ahead of defenders by constantly innovating its tactics, techniques and procedures (TTPs).

It has often been observed using somewhat novel methods to entice its victims into making a mistake. Last month, Palo Alto Networks’ Unit 42 caught it piggybacking on an advert for a used BMW, posted online by a Polish diplomat in Kyiv.

My1Login CEO Mike Newman said this latest technique would have been almost impossible for the untrained eye to spot.

“Because the attackers were using a legitimate Microsoft domain, it would only have taken a very curious and security-savvy user to investigate the prompts further and realise they were fake. As a result of this, even despite the low number of organisations targeted, this attack would have picked up many victims,” he said.

“Businesses therefore need to take their own remediation action against these threats, and one of the best ways to do this is by removing passwords and credentials from users’ hands. This means even when highly sophisticated scams do reach user inboxes, users can’t be tricked into handing over their credentials because they simply do not know them.”

ESET government affairs director Andy Garth added: “Spear phishing attacks target individuals with access to specific information, thus requiring the attackers to undertake background work to hone their approach, gain the confidence of their victims and lure them. As with your email, you should also be sceptical of unsolicited approaches from anyone external to the organisation trying to reach out through Teams.”

Read more on Hackers and cybercrime prevention


Cozy Bear lures victims with used BMW 5 Series

AlexScroxton

By: Alex Scroxton


cyber espionage

AlexanderGillis

By: Alexander Gillis


Russia’s Turla falls back on old malware C2 domains to avoid detection

AlexScroxton

By: Alex Scroxton


Top 10 cyber security stories of 2022

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366546793/Cozy-Bear-hijacks-SME-Microsoft-365-tenants-in-latest-campaign

Tags: hijacksMicrosofttechnology
Previous Post

UK government recruits panel to focus on semiconductors

Next Post

Plexal takes on new cohort for cyber security leadership scheme

South Carolina’s Drought Puts Boaters and Local Ecosystems at Risk

May 17, 2026

Incredible 150-Million-Year-Old Stegosaur Skull Challenges What We Know About Dinosaur Evolution

May 17, 2026

Sunday Science: Unlocking the Secrets of the UV Index and How It Affects You

May 17, 2026

After a Week with the Bose Lifestyle Ultra Speaker, Sonos Faces Its Toughest Rival Yet

May 17, 2026

Earn $6,000 a Night Renting Your Home During the World Cup-Plus Top Tips to Keep It Safe

May 17, 2026

Israel’s Economy Dips in Q1 but Gears Up for a Powerful Comeback After Iran Conflict

May 17, 2026

New Ebola Outbreak Strikes Democratic Republic of the Congo as Global Response Intensifies

May 17, 2026

Dive into the Exciting World of Lark’s Entertainment: Your Ultimate Fun Destination!

May 17, 2026

How Political Divides Are Driving Health Outcomes Across America

May 17, 2026

Vanguard Group Inc. Boosts Investment in Tactile Systems Technology, Inc. $TCMD

May 17, 2026

Categories

Archives

May 2026
M T W T F S S
 123
45678910
11121314151617
18192021222324
25262728293031
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,219)
  • Economy (1,241)
  • Entertainment (22,118)
  • General (21,568)
  • Health (10,274)
  • Lifestyle (1,253)
  • News (22,149)
  • People (1,242)
  • Politics (1,261)
  • Science (16,455)
  • Sports (21,738)
  • Technology (16,225)
  • World (1,232)

Recent News

South Carolina’s Drought Puts Boaters and Local Ecosystems at Risk

May 17, 2026

Incredible 150-Million-Year-Old Stegosaur Skull Challenges What We Know About Dinosaur Evolution

May 17, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version