In IT help desk schemes, threat actors claim they were locked out of their account, could not access their authenticator, lost their phone, or damaged their laptop. They may also create urgent or stressful scenarios, such as a business meeting starting shortly or an employee traveling on business, and request immediate access to the account. Once threat actors convince the IT help desk staff to reset the password or disable the original MFA token, they can register their own device, granting them complete, legitimate access to the network. Prominent and aggressive threat actors, such as Scattered Spider and O-UNC-034, have posed as employees or traveling executives to initiate account takeovers. Their main goal is to infiltrate networks, establish persistence, move laterally to critical assets, access internal applications or cloud services, exfiltrate data, and deploy ransomware.
|