{"id":42794,"date":"2022-02-22T15:18:22","date_gmt":"2022-02-22T15:18:22","guid":{"rendered":"http:\/\/icloud.pe\/blog\/?guid=9c1402231eb2988dfe189e23f98862e6"},"modified":"2022-02-22T15:18:22","modified_gmt":"2022-02-22T15:18:22","slug":"novel-phishing-method-deceives-users-with-ubiquitous-it-support-tool","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/novel-phishing-method-deceives-users-with-ubiquitous-it-support-tool\/","title":{"rendered":"Novel phishing method deceives users with ubiquitous IT support tool"},"content":{"rendered":"<p><span class=\"field field-name-field-author field-type-node-reference field-label-hidden\"><br \/>\n      <span class=\"field-item even\"><a href=\"https:\/\/www.cloudpro.co.uk\/authors\/connor-jones\">Connor Jones<\/a><\/span><br \/>\n  <\/span><\/p>\n<div class=\"field field-name-field-published-date field-type-datetime field-label-hidden\">\n<div class=\"field-items\">\n<div class=\"field-item even\"><span class=\"date-display-single\">22 Feb, 2022<\/span><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"short-teaser\">\n<a href=\"https:\/\/www.cloudpro.co.uk\/\" title=\"\" class=\"combined-link\"><\/a><\/p>\n<div class=\"field field-name-body\">\n<p>A cyber security researcher has <a href=\"https:\/\/mrd0x.com\/bypass-2fa-using-novnc\/\"  data-cke-saved-href=\"https:\/\/mrd0x.com\/bypass-2fa-using-novnc\/\">documented<\/a> a novel phishing technique that involves cyber criminals harnessing <a href=\"https:\/\/www.itpro.co.uk\/mobile\/remote-access\/361544\/what-should-you-really-be-asking-about-your-remote-access-software\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/mobile\/remote-access\/361544\/what-should-you-really-be-asking-about-your-remote-access-software\">virtual network computing<\/a> (VNC) technology on a private server to launch a variety of attacks.<\/p>\n<p>Using the <a href=\"https:\/\/www.itpro.co.uk\/software\/28109\/what-is-open-source\" data-cke-saved-href=\"https:\/\/www.itpro.co.uk\/software\/28109\/what-is-open-source\">open source<\/a> noVNC client, the phishing technique allows successful attackers to launch malicious code into a victim\u2019s browser, plant a keylogger, and passively observe all user activity.<\/p>\n<p><span data-cke-copybin-start=\"1\">\u200b<\/span><\/p>\n<p>The researcher, who goes by the name\u00a0mr.d0x. claims the method of attack bypasses\u00a0<a href=\"https:\/\/www.itpro.co.uk\/security\/29982\/what-is-two-factor-authentication\">two-factor authentication<\/a> (2FA), including Google\u2019s 2FA protocol used for the likes of Gmail and Google accounts, and facilitates the stealing of credentials.\u00a0<\/p>\n<p>The phishing method effectively acts as a VNC client for the attacker to remotely monitor and access a user\u2019s environment, creating a man-in-the-middle (MITM) attack.<\/p>\n<p>The technology is common in modern businesses, with employees being familiar with <a href=\"https:\/\/www.itpro.co.uk\/agile-working\/31887\/how-do-i-best-support-my-remote-workers\">IT support teams accessing their computers remotely<\/a> to resolve technical issues.\u00a0<\/p>\n<p>The initial deception is achieved in a typical <a href=\"https:\/\/www.itpro.co.uk\/security\/29093\/what-is-phishing\">phishing<\/a> format &#8211; a strategically crafted email provides a link the user needs to click on. Once clicked, the user is taken to a direct server run by the attacker, rather than a malicious web page.<\/p>\n<p>The attack can be launched against individuals using any browser, theoretically including ones on mobile devices, though the researcher said they had difficulty in executing the attack on <a href=\"https:\/\/www.itpro.co.uk\/mobile\/20522\/best-android-smartphones\" >smartphones<\/a>.\u00a0<\/p>\n<p>There are some shortcomings with the method, the researcher said, including the issue whereby the attacker has to provide control of their machine to the victim in order for the attack to work.<\/p>\n<p>It\u2019s also possible that given the nature of VNC software, there may be some noticeable input lag for the victim, offering an indication that the website is not legitimate.<\/p>\n<div aria-label=\"Embedded entity widget\" class=\"cke_widget_wrapper cke_widget_block cke_widget_drupalentity cke_widget_selected\" contenteditable=\"false\" data-cke-display-name=\"Embedded YouTube\" data-cke-filter=\"off\" data-cke-widget-id=\"1\" data-cke-widget-wrapper=\"1\" role=\"region\" tabindex=\"-1\"><drupal-entity class=\"cke_widget_element\" data-cke-widget-data=\"%7B%22attributes%22%3A%7B%22data-editor-embed-uuid%22%3A%22300652621586591273%22%2C%22data-embed-button%22%3A%22youtube%22%2C%22data-entity-embed-display%22%3A%22view_mode%3Aparagraph.preview%22%2C%22data-entity-type%22%3A%22paragraph%22%2C%22data-entity-uuid%22%3A%22fb7174a9-86ae-4e2f-bd7c-2324db729c23%22%2C%22data-langcode%22%3A%22en%22%7D%2C%22hasCaption%22%3Afalse%2C%22link%22%3Anull%2C%22classes%22%3Anull%7D\" data-cke-widget-keep-attr=\"0\" data-cke-widget-upcasted=\"1\" data-editor-embed-uuid=\"300652621586591273\" data-embed-button=\"youtube\" data-entity-embed-display=\"view_mode:paragraph.preview\" data-entity-type=\"paragraph\" data-entity-uuid=\"fb7174a9-86ae-4e2f-bd7c-2324db729c23\" data-langcode=\"en\" data-widget=\"drupalentity\"><\/drupal-entity><\/p>\n<div class=\"embedded-entity\" data-editor-embed-uuid=\"300652621586591273\" data-embed-button=\"youtube\" data-entity-embed-display=\"view_mode:paragraph.preview\" data-entity-type=\"paragraph\" data-entity-uuid=\"fb7174a9-86ae-4e2f-bd7c-2324db729c23\" data-langcode=\"en\">\n<div class=\"paragraph paragraph--type--social-embed paragraph--view-mode--preview\">\n<div class=\"field field--name-field-social-provider field--type-entity-reference field--label-hidden field__item\">YouTube<\/div>\n<div class=\"field field--name-field-social-embed field--type-string field--label-hidden field__item\"><a href=\"https:\/\/www.youtube.com\/watch?v=EiyiaUoQvOU\">https:\/\/www.youtube.com\/watch?v=EiyiaUoQvOU<\/a><\/div>\n<\/div>\n<\/div>\n<p><span class=\"cke_reset cke_widget_drag_handler_container\"><img loading=\"lazy\" decoding=\"async\" class=\"cke_reset cke_widget_drag_handler\" data-cke-widget-drag-handler=\"1\" height=\"15\" role=\"presentation\" src=\"data:image\/gif;base64,R0lGODlhAQABAPABAP\/\/\/wAAACH5BAEKAAAALAAAAAABAAEAAAICRAEAOw==\" title=\"Click and drag to move\" width=\"15\" \/><\/span><\/p>\n<\/div>\n<p>This is currently a proof of concept style of phishing attack with no known actively exploited cases in the wild, though remote access to businesses is reportedly on the rise in a <a href=\"https:\/\/www.itpro.co.uk\/security\/cyber-security\/362262\/dark-web-criminals-are-becoming-increasingly-successful-at-selling\">string of burgeoning dark web operations<\/a>.<\/p>\n<p>\u201cBrowsers are more powerful than ever and the usage of browsers as clients for remote access provides new ways for attackers to steal credentials, bypass 2FA, and more,\u201d <a href=\"https:\/\/mrd0x.com\/bypass-2fa-using-novnc\/\">said<\/a> the researcher. \u201cI strongly believe that what I\u2019ve demonstrated in this article is only a small portion of what this technique can be used for.\u201d<\/p>\n<h2>noVNC attack breakdown<\/h2>\n<p>The attacker first needs to deploy a Linux machine via a <a href=\"https:\/\/www.itpro.co.uk\/cloud\/34557\/which-cloud-services-are-right-for-your-business\">cloud service provider<\/a>; any provider or <a href=\"https:\/\/www.itpro.co.uk\/operating-systems\/28025\/best-linux-distros-2021\">Linux distro<\/a> is fine. Firefox is good for this, the researcher said, but any browser with a kiosk mode will also work.<\/p>\n<div aria-label=\"Embedded entity widget\" class=\"cke_widget_wrapper cke_widget_block cke_widget_drupalentity cke_widget_selected\" contenteditable=\"false\" data-cke-display-name=\"Embedded Paragraphs\" data-cke-filter=\"off\" data-cke-widget-id=\"0\" data-cke-widget-wrapper=\"1\" role=\"region\" tabindex=\"-1\"><drupal-entity class=\"cke_widget_element\" data-cke-widget-data=\"%7B%22attributes%22%3A%7B%22data-editor-embed-uuid%22%3A%22694331878555272289%22%2C%22data-embed-button%22%3A%22paragraphs_inline_entity_form%22%2C%22data-entity-embed-display%22%3A%22view_mode%3Aparagraph.preview%22%2C%22data-entity-type%22%3A%22paragraph%22%2C%22data-entity-uuid%22%3A%22aa8ac734-356d-4ec6-a65f-9af4b49fbf01%22%2C%22data-langcode%22%3A%22en%22%7D%2C%22hasCaption%22%3Afalse%2C%22link%22%3Anull%2C%22classes%22%3Anull%7D\" data-cke-widget-keep-attr=\"0\" data-cke-widget-upcasted=\"1\" data-editor-embed-uuid=\"694331878555272289\" data-embed-button=\"paragraphs_inline_entity_form\" data-entity-embed-display=\"view_mode:paragraph.preview\" data-entity-type=\"paragraph\" data-entity-uuid=\"aa8ac734-356d-4ec6-a65f-9af4b49fbf01\" data-langcode=\"en\" data-widget=\"drupalentity\"><\/drupal-entity><\/p>\n<div class=\"embedded-entity\" data-editor-embed-uuid=\"694331878555272289\" data-embed-button=\"paragraphs_inline_entity_form\" data-entity-embed-display=\"view_mode:paragraph.preview\" data-entity-type=\"paragraph\" data-entity-uuid=\"aa8ac734-356d-4ec6-a65f-9af4b49fbf01\" data-langcode=\"en\">\n<div class=\"paragraph paragraph--type--featured-related-content paragraph--view-mode--preview\">\n<div class=\"field field--name-field-featured-related-content field--type-entity-reference field--label-above\">\n<div class=\"field__label\">Featured Related Content<\/div>\n<div class=\"field__item\"><a href=\"https:\/\/www.cloudpro.co.uk\/security\/ransomware\/361095\/the-best-defence-against-ransomware\">The best defence against ransomware<\/a><\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><span class=\"cke_reset cke_widget_drag_handler_container\"><img loading=\"lazy\" decoding=\"async\" class=\"cke_reset cke_widget_drag_handler\" data-cke-widget-drag-handler=\"1\" height=\"15\" role=\"presentation\" src=\"data:image\/gif;base64,R0lGODlhAQABAPABAP\/\/\/wAAACH5BAEKAAAALAAAAAABAAEAAAICRAEAOw==\" title=\"Click and drag to move\" width=\"15\" \/><\/span><\/p>\n<\/div>\n<p>Once the Linux instance is up and running, the attacker then needs to install VNC software such as TightVNC or TigerVNC before running some custom commands to ensure the environment is correctly configured for the attack. The noVNC javascript library and application can then be <a href=\"https:\/\/www.itpro.co.uk\/software\/development\/359246\/how-to-download-from-github\">downloaded from GitHub<\/a> and installed too.<\/p>\n<p>A web browser needs to be running in the deployment and displaying the authentication page from which the attacker wants to steal credentials, such as Google\u2019s login page. The attacker can use any browser, Firefox is good here, but it must be running in kiosk mode.\u00a0<\/p>\n<p>This technique is effective in <a href=\"https:\/\/www.itpro.co.uk\/software\/google-docs\/361922\/researchers-spot-spear-phishing-exploit-in-google-docs\">spear phishing campaigns<\/a> but will encounter issues if sent to multiple targets since they will be sharing the same VNC session.\u00a0<\/p>\n<p>However, the technique can be modified and automated so different users access different VNC sessions by assigning users to different ports.<\/p>\n<p><span data-cke-copybin-end=\"1\">\u200b<\/span> <\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>      Connor Jones<\/p>\n<p>        22 Feb, 2022    <\/p>\n<p>      A cyber security researcher has documented a novel phishing technique that involves cyber criminals harnessing virtual network computing (VNC) technology on a private server to launch a variety &#8230;<\/p>\n","protected":false},"author":507,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-42794","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/42794","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/507"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=42794"}],"version-history":[{"count":2,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/42794\/revisions"}],"predecessor-version":[{"id":42796,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/42794\/revisions\/42796"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=42794"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=42794"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=42794"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}