System accounts – security

October 29th, 2017 by Stephen Jones Leave a reply »

An Office 365-focused Botnet puts the spotlight on the security of System Accounts which are commonly overlooked

A botnet it dubbed “KnockKnock” aActive since at least May, and especially active from June through August, is relatively small botnet whose attack highly targeted for both: the types of accounts it attacks and the types of organizations. GThis is interesting is because it is trying to get into system accounts, that are commonly used to connect the Exchange Online e-mail system with marketing and sales automation software. In cases where the system accounts are compromised, KnockKnock exports data from the inbox, creates a new inbox rule and starts a phishing attack from the account against the rest of the organization.

The attacks analysed averaged only five e-mail addresses per customer. Additionally, the organizational targeting was extremely specific — aimed at infrastructure and Internet of Things (IoT) departments within the manufacturing, financial services, health care and consumer products industries, as well as U.S. public sector agencies.

Non-human system accounts are less likely to be protected by multi-factor authentication or security policies, such as recurring password reset requirements. Once such accounts are provisioned, they’re easy to overlook and can prove to be the weakest link in Office 365 and in general the security infrastructure.

Advertisement

Comments are closed.