How Threat Actors Bypass FIDO2 MFA in the PoisonSeed Phishing Attack: What You Need to Know

Admin

How Threat Actors Bypass FIDO2 MFA in the PoisonSeed Phishing Attack: What You Need to Know

The PoisonSeed phishing campaign is shaking up online security by bypassing standard FIDO2 protections. It does this by misusing the cross-device sign-in feature in WebAuthn, tricking users into approving fake login requests.

Known for its aggressive tactics, PoisonSeed often targets financial accounts. In previous attacks, they distributed emails with crypto seed phrases that led to drained wallets.

A recent report from Expel shows how the PoisonSeed actors don’t exploit vulnerabilities in FIDO2 security but leverage its legitimate features. This is both alarming and eye-opening for many users.

Cross-device authentication allows users to sign in on one device using an authentication key or app from another, often via Bluetooth or QR code instead of a physical key. However, this feature can be manipulated.

In the attack, users are led to fake sites that mimic real corporate portals, like those from Okta or Microsoft 365. When users input their login details, the attackers secretly access these details on the actual site in real-time.

Instead of asking for the user’s physical FIDO2 key to complete multi-factor authentication, the phishing backend orchestrates a cross-device authentication process. The legitimate site then generates a QR code that’s sent back to the phishing page, displaying it for the user to scan. This scan unwittingly authorizes the attacker’s login attempt.

By using this technique, PoisonSeed bypasses key security features. As Expel clarified, they’re not exploiting a flaw but misusing a built-in feature.

To help users stay safe, experts suggest a few strategies:

  • Restrict login attempts based on geographic locations, requiring registration for remote access.
  • Regularly verify newly registered FIDO keys from unfamiliar locations or brands.
  • Implement Bluetooth-based authentication as a strict requirement to enhance security during cross-device authentication.

Interestingly, there was another case where an attacker registered their own FIDO key after hijacking an account. This incident underscores how clever and persistent cybercriminals can be, often discovering new methods to outsmart security measures.

Overall, the PoisonSeed campaign showcases a worrying trend in phishing tactics. As security evolves, so do the methods used by attackers. Staying informed and vigilant is essential to avoid falling victim to these schemes.



Source link