Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Hey #oss #security folks,

Hey #oss #security folks,

Scheduled Pinned Locked Moved Uncategorized
securityoss
2 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • analog_cafe@mas.toA This user is from outside of this forum
    analog_cafe@mas.toA This user is from outside of this forum
    analog_cafe@mas.to
    wrote last edited by
    #1

    Hey #oss #security folks,

    Someone is running a spear phishing attack against my tiny business, which feels unexpected given the size of my organization (just me).

    Could you recommend some simple ways I can stop the attack? It involves extremely well-designed emails from various compromised email addresses that impersonate the SendGrid system and use very plausible messages.

    My main concern is that this could evolve into something more sinister. I don't mind blocking all emails containing "SendGrid," but I would rather do something that could make those people move on and not come back.

    Thanks so much!

    chronovore@infosec.exchangeC 1 Reply Last reply
    0
    • analog_cafe@mas.toA analog_cafe@mas.to

      Hey #oss #security folks,

      Someone is running a spear phishing attack against my tiny business, which feels unexpected given the size of my organization (just me).

      Could you recommend some simple ways I can stop the attack? It involves extremely well-designed emails from various compromised email addresses that impersonate the SendGrid system and use very plausible messages.

      My main concern is that this could evolve into something more sinister. I don't mind blocking all emails containing "SendGrid," but I would rather do something that could make those people move on and not come back.

      Thanks so much!

      chronovore@infosec.exchangeC This user is from outside of this forum
      chronovore@infosec.exchangeC This user is from outside of this forum
      chronovore@infosec.exchange
      wrote last edited by
      #2

      @analog_cafe oof - tbh, not sure if there was a specific "do this and they disappear" remedy, sorry. Things to harden your org however. Short run - make sure your EDR is clued in to the issue either via IOCs you can harvest from the phish, or if its a managed service letting them know. The 'sinister evolution' will likely take the shape of loading RATs on your endpoints (especially if you're passwordless), which seems to be next pivot when attackers cannot obtain credentials. Be cautious even with 'safe' tools that aren't specifically RATs like teamviewer, or screenconnect for example.

      Other measures - alert on anomalous login. activity. What is anomalous depends on your org, but if its just you, then I would start by alerting on odd geographic logins from unexpected IPs/ASNs, novel UAs, even things outside of 'normal' business hours might be helpful. If you don't have that kind of telemetry then that's a good starting point. Also alerting on account changes; such as new forwarding rules is a great way to detect compromise

      Blocking on known bad indicators such as sendgrid will stem the issue for a bit, but attackers pivot, so its a bit of whack-a-mole. But if you're small enough, and whack enough moles, the attackers leave for easier targets. Unfortunately - one compromise makes never going away worth it.

      Likely you're already doing this, but strictly segregate and harden (MFA, alerting etc) your admin accounts from your user accounts - if attackers compromise your user account they won't get the keys to the whole kingdom.

      That's simply the low hanging fruit, I am certainly more capable security folks will chime in, but hopefully this get you to a relatively safe place.

      Hope this is helpful but otherwise good luck!

      1 Reply Last reply
      1
      0
      • R relay@relay.infosec.exchange shared this topic
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups