• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

Supermouth Ultim8 electric toothbrush review: Gentle giant

August 20, 2025

Samsung Galaxy Watch 8 Review: A solid albeit unexciting smartwatch

August 19, 2025

Huawei MatePad 11.5 review: iPad rival that’s missing a trick

August 17, 2025
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Security»0ktapus phishing campaign has attacked over 130 companies
Security

0ktapus phishing campaign has attacked over 130 companies

August 26, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Apple Lockdown mode adds ‘extreme’ protection to your iPhone, iPad and Mac
Share
Facebook Twitter LinkedIn Pinterest Email

Over 130 organizations, together with Twilio, DoorDash, and Sign, have been doubtlessly compromised by hackers as a part of a months-long phishing marketing campaign nicknamed “0ktapus” by safety researchers. Login credentials belonging to almost 10,000 people had been stolen by attackers who imitated the favored single sign-on service Okta, in line with a report from cybersecurity outfit Group-IB.

Targets had been despatched textual content messages that redirected them to a phishing website. Because the report from Group-IB states, “From the sufferer’s perspective, the phishing website appears to be like fairly convincing as it is extremely much like the authentication web page they’re used to seeing.” Victims had been requested for his or her username, password, and a two-factor authentication code. This info was then despatched to the attackers.

Regardless of the marketing campaign’s success, Group-IB’s evaluation means that the attackers had been considerably inexperienced

Apparently, Group-IB’s evaluation means that the attackers had been considerably inexperienced. “The evaluation of the phishing package revealed that it was poorly configured and the way in which it had been developed offered a capability to extract stolen credentials for additional evaluation,” Roberto Martinez, a senior menace intelligence analyst at Group-IB, told TechCrunch.

However inexperienced or not, the size of the assault is very large, with Group-IB detecting 169 distinctive domains focused by the marketing campaign. It’s believed that the 0ktapus marketing campaign started round March 2022 and that up to now, round 9,931 login credentials have been stolen. The attackers have unfold their web large, focusing on a number of industries, together with finance, gaming, and telecoms. Domains cited by Group-IB as targets (however not confirmed breaches) embody Microsoft, Twitter, AT&T, Verizon Wi-fi, Coinbase, Greatest Purchase, T-Cell, Riot Video games, and Epic Video games.

See also  Shares of companies that went public via SPAC fall more than 50% – Startup

Money seems to be no less than one of many motives for the assaults, with researchers stating, “Seeing monetary corporations within the compromised checklist provides us the concept that the attackers had been additionally making an attempt to steal cash. Moreover, among the focused corporations present entry to crypto property and markets, whereas others develop funding instruments.”

Group-IB warns that we possible received’t know the total scale of this assault for a while

Group-IB warns that we possible received’t know the total scale of this assault for a while. With a purpose to guard towards comparable assaults like this, Group-IB provides the standard recommendation: at all times be sure you verify the URL of any website the place you’re coming into login particulars; deal with URLs acquired from unknown sources with suspicion; and for added safety, you need to use an “unphishable” two-factor safety keys, akin to a YubiKey.

This current string of phishing assaults is likely one of the most spectacular campaigns of this scale up to now, in line with Group-IB, with the report concluding that “Oktapus exhibits how susceptible trendy organizations are to some primary social engineering assaults and the way far-reaching the consequences of such incidents could be for his or her companions and clients.”

The size of those threats isn’t prone to lower any time quickly, both. Research from Zscaler exhibits that phishing assaults elevated by 29 % globally in 2021 in comparison with the earlier 12 months and notes that SMS phishing particularly is rising sooner than other forms of scams as individuals have began to raised acknowledge fraudulent emails. Socially engineered scams and hacks were also seen rising during the COVID-19 pandemic, and earlier this 12 months, we even noticed that each Apple and Meta shared knowledge with hackers pretending to be regulation enforcement officers.

See also  AT&T, Verizon, and T-Mobile’s passwordless future has slipped away

Source link

0ktapus attacked campaign companies Phishing
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Human composting startup Recompose launches crowdfunding campaign to raise $5M – Startup

March 22, 2023

Tech Companies Are Cutting Staff in Droves

March 15, 2023

After a four-day work week, more companies aren’t going back

February 24, 2023

Seattle mayor encourages companies to hire people of color at inaugural Black Tech Night – Startup

February 24, 2023
Add A Comment

Comments are closed.

Editors Picks

Google has fired the AI engineer who said its chatbot is sentient

July 24, 2022

10 Apps to Improve Your Financial Situation

December 12, 2023

Popular FPS ‘Doom’ is Now Playable on Apple Network Server

June 4, 2025

Clash: Artifacts of Chaos is delayed to 2023

July 8, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Supermouth Ultim8 electric toothbrush review: Gentle giant

Samsung Galaxy Watch 8 Review: A solid albeit unexciting smartwatch

Huawei MatePad 11.5 review: iPad rival that’s missing a trick

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.