Phishing-as-a-Service Campaign Impersonating RingCentral for M365 Credential Theft
Threat actors are leveraging a phishing-as-a-service platform to conduct spearphishing attacks impersonating RingCentral, targeting Microsoft 365 credentials.
What's new
- 1. new IOCs Aug 6, 21:19 via mandiant
Security researchers have identified an active phishing-as-a-service campaign that impersonates RingCentral communications to facilitate the theft of Microsoft 365 user credentials. This campaign relies on the delivery of deceptive emails that mimic legitimate RingCentral notifications, redirecting users to malicious phishing pages designed to capture authentication tokens and passwords. By utilizing a phishing-as-a-service model, threat actors are able to scale these campaigns effectively, bypassing traditional email filters by leveraging legitimate brand trust associated with RingCentral. The primary objective is the compromise of enterprise accounts, providing attackers with a foothold for lateral movement, data exfiltration, or further social engineering within the target organization. This threat is significant due to the prevalence of Microsoft 365 in enterprise environments and the difficulty of detecting high-quality brand impersonation via standard email security gateways.
Impact
The campaign facilitates the unauthorized access to corporate Microsoft 365 accounts. Successful compromise allows attackers to gain access to sensitive internal communications, documents, and corporate data. While specific victim numbers are not disclosed, the use of a phishing-as-a-service platform indicates the threat is widespread and designed for high-volume targeting across various business sectors.
Recommendation
- Implement and enforce phishing-resistant Multi-Factor Authentication (MFA), such as FIDO2/WebAuthn, for all Microsoft 365 accounts to mitigate credential harvesting success.
- Enable and configure Microsoft 365 Defender for Office 365 "Safe Links" and "Safe Attachments" to detect and block malicious URLs at the time of click.
- Review and harden organizational email security policies, ensuring SPF, DKIM, and DMARC are strictly enforced for inbound mail.
- Train employees to verify the sender address and hover over links in incoming communications, specifically those referencing urgent "RingCentral" notifications.
Immediate actions
Review M365 sign-in logs for anomalous login patterns linked to newly provisioned MFA devices or impossible travel.
Mitigations
Enforce phishing-resistant MFA across the M365 tenant.
M365 Account Compromise
Indicators of compromise
10
domain
| Type | Value |
|---|---|
| domain | passkeyhelpdesk.com |
| domain | portalpasskey.com |
| domain | addssopasskey.com |
| domain | passkeyms.com |
| domain | mysecurepasskey.com |
| domain | passkeydeploy.com |
| domain | oskeysync.com |
| domain | keysyncos.com |
| domain | setupsso.com |
| domain | idokta.com |