“Being Annoying” as a Social Engineering Approach



“Being Annoying” as a Social Engineering Approach in MFA AttacksAttackers are spamming multifactor authentication (MFA) prompts in an attempt to irritate users into approving the login, Ars Technica reports. Both criminal and nation-state actors are using this technique. Researchers at Mandiant observed the Russian state-sponsored actor Cozy Bear launching repeated MFA prompts until the user accepted the request.

Ars Technica quotes Mandiant’s researchers as saying, “Many MFA providers allow for users to accept a phone app push notification or to receive a phone call and press a key as a second factor. The [Nobelium] threat actor took advantage of this and issued multiple MFA requests to the end user’s legitimate device until the user accepted the authentication, allowing the threat actor to eventually gain access to the account.”

The Lapsus$ criminal hacking group is also making use of this method. A member of Lapsus$ said on the group’s Telegram channel the technique is particularly effective late at night.

“No limit is placed on the amount of calls that can be made,” the individual said. “Call the employee 100 times at 1 am while he is trying to sleep, and he will more than likely accept it. Once the employee accepts the initial call, you can access the MFA enrollment portal and enroll another device.”

Ars Technica notes that there are multiple variations to this approach.

  • “Sending a bunch of MFA requests and hoping the target finally accepts one to make the noise stop.
  • “Sending one or two prompts per day. This method often attracts less attention, but ‘there is still a good chance the target will accept the MFA request.’
  • “Calling the target, pretending to be part of the company, and telling the target they need to send an MFA request as part of a company process.”

New-school security awareness training can teach your employees to follow security best practices so they can avoid falling for social engineering attacks.


Find out if your organization's MFA solution
can be hacked by cybercriminals now!

Did you know that all MFA mechanisms can be hacked, and in some cases it's as simple as sending a phishing email? That's why it's important to know the exact security risks your MFA solution has and how your users' accounts may be compromised.

masareport-thumbHere's how MASA works:

  • You will receive a custom link to take your assessment
  • Answer a series of technology questions relevant to your MFA solution
  • Get an instant high-level snapshot of potential risks with your MFA
  • Receive your in-depth report packed with actionable insight and detailed analysis on specific MFA attacks and tips for your top defenses 

Assess My MFA Solution Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/multi-factor-authentication-security-assessment



Subscribe To Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews