The Microsoft Threat Intelligence Podcast 8.12.26
Ep 75 | 8.12.26

Shifts We Are Seeing Across Social Engineering, Post-Disruption Impact Report

Transcript

Elliot Volkman: Hello, and welcome back to the Microsoft Threat Intelligence Podcast. I am obviously not Sherrod, and if you want a little bit of context of that, please go back into your podcast or video feed for the previous episode where we unfortunately have a little farewell episode for her. So with that being said, I am Elliot, the director for Microsoft Threat Intelligence. I have been behind the scenes for a little bit, and we are going to just jump right into the threat landscape with, fortunately, a guest who has been around social engineering and the cybersecurity research world for quite some time, Crane Hassold, who is a principal threat intelligence analyst/researcher here over at Microsoft. And we are going to be talking about what we are seeing across the, I don't want to say email threats, because it is so much more than that. It's maybe social engineering and phishing. Is that the right way to put that, Crane?

Crane Hassold: Yeah, I think so. I think, you know, what I look at, what, you know, our team looks at on a daily basis is, you know, while email obviously I think everyone knows is still the primary threat vector, primary attack vector, for most attacks, you know, we do look at the overall social engineering threat landscape to understand how people are being exploited to fulfill technical goals.

Elliot Volkman: All right. Yeah, that sounds about right. In fact, maybe I'm going to pull at that and we'll have a little philosophical conversation here in a minute. But I do want to just drop some stats that we had published through the Threat Intelligence blog most recently with you and some of your peers. But it looks like in support of that, QR code phishing has increased about 55% month over month in March as of when we last tracked it. CAPTCHA gated phishing has more than doubled. And then if you had been following our Digital Crime Unit, or DCU, action or disruption several months ago or maybe in the last month, time is always a bit of a blur here, they had a disruption activation and activity against Tycoon2FA. And after that, I believe there was a decline of around 92% of their activity that we have been tracking. Obviously, once you disrupt an actor or the mechanisms behind it, they redirect their energy. But that's just some interesting little nuggets that we have published. You can, of course, read Crane's blog for a little bit more details. But what I want to actually pull on is what I was poking at before, which is based on the numbers and the data that we're seeing here, Crane, is I don't think we're actually seeing social engineering and phishing just being an email concern anymore. Do you feel like maybe the perspective has shifted where we're seeing this move beyond that? It is phishing, it is phishing. We're seeing QR code attacks. Is social engineering shifting their energy majority-wise outside of email, or is it still the bread and butter?

Crane Hassold: So it's still the bread and butter in so far as, you know, email for most people at least is still the primary communication mechanism when people do business conversations. And because it's still the primary way that people communicate in the enterprise, it's still the way that the attackers are sort of trying to initiate their conversations, trying to initially attack their victims. That being said, we are definitely seeing sort of the scope of attack vectors open up pretty dramatically, not super quickly, but it's definitely there. For example, Microsoft Teams, we've started to see a good amount of traction for attackers pivoting over to Microsoft Teams to try to impact users that way. A lot of what we see with Teams are through things like mail bombing attacks, where, you know, a user may get, you know, all of a sudden get hundreds of emails, usually like legitimate emails, you know, usually spammy emails, things like signing up for newsletters, stuff that's not inherently malicious. But what happens is the attacker will then use that as a pretext to contact a user saying, hey, we've seen some weird behavior with your email, what's going on, blah, blah, blah, blah. A vast majority of the mail bombing attacks that pivot over to Teams that we've seen end up impersonating like an internal IT help, help support type, help desk type of attacks, like a persona. And they'll say, hey, we need, you know, we've seen that you need, we've seen some weird things. How can we help? If you can do me a favor, could you just download this tool? And the tool in itself is usually like a remote access, a remote management tool, which is, you know, in itself, you know, benign. It's a legitimate tool. But the attackers are then using that as a pretext to then once they have access to a victim's computer, then download malware to the machine. So Teams is definitely a way that we've seen some attackers start exploiting victims. SMS text messages is definitely another avenue that we've seen where -- a lot of that has to do with the fact that attackers want to either get users off of email or target them directly through email to begin with because they know that it's not as hard as a hardened platform than something like an email on a work device might be. So, you know, targeting -- and usually when we see those types of attacks, a lot of those are business email impersonation attacks. A majority of those are like eventually end up with, you know, asking someone to go buy gift cards. But we've also seen a rise in the types of attacks that have links in them. And then on the other side of that link, they're trying to compromise credentials. And so what's interesting about that is that you have victims and you have attacks that are compromising corporate credentials outside of the, you know, corporate visibility. And then the first time an enterprise might actually see those being used is when they're being tried and being attempted to be used by the attacker and they never actually see the compromise to begin with because this is happening, the compromise is actually happening on a personal device. So we've seen that. But, really, as we move forward, wherever people communicate for business purposes is where the attackers are going to, you know, continue to move. You know, I think eventually email, especially with, you know, a younger generation, probably will not be the preferred way to communicate with anyone at some point. So, you know, eventually email will sort of go the way of the dinosaurs. But until then, it still will be email until all of that gets phased out.

Elliot Volkman: That makes sense to me. So if I were to like sum that up, path of least resistance is always still the effective driver of like what option they're going to go for and then impact scalability of where they can reach those. Okay, that lines up. So let me maybe tee up a philosophical conversation here. Because I feel like you have a lot of interesting takes on how we position things or talk about things. So the main way that I would ask this, I guess, is phishing still the right term when the attack is ultimately successful through maybe identity permissions rather than just malware? Because if the entry point is not, you know, it is basically an entry point, but yeah, is it a phishing attack, or are we repositioning how this should be defined?

Crane Hassold: So that's a good question. I think phishing is one of those, you know, the cybersecurity terms that has been, you know, thank you, people like you, Elliot, marketing folks.

Elliot Volkman: You're welcome.

Crane Hassold: Made them such a generic term that they mean many different things. But I always think of phishing as a, you know, essentially, it's an outreach from an attacker through a communication platform for the purposes -- generally the end result is to either exploit a technical device, usually going to be a computer, or to compromise credentials. That's the general way that I sort of see phishing, the term phishing. And that is a little bit different than what we've seen with things like business email impersonation attacks, where there is no technical exploitation at the end of the chain. It's pure social engineering. But when I think of phishing, it's, you know, it's social engineering for the purpose of some technical goal at the end of the day. So I think that's a good general definition and way to think about it.

Elliot Volkman: Okay, that makes sense. Yeah, I'm glad that you brought up BEI because that's a whole nother topic of debate for another day. So I think maybe before I spin off to the disruption actions that we've sort of briefly covered, I do want to maybe pull back and highlight any guidance that you're seeing as a top priority organization should look at based on our most recent findings. Now, we have the obvious caveat here is everyone's threat model is going to be different. But based on the findings that you have identified in the last couple of quarters in phishing and social engineering and email-based threats, is anything coming top of mind where organizations should maybe like rethink a couple of, you know, items? And please don't tell me security awareness training, because I know you wouldn't.

Crane Hassold: I mean, the -- number one is making sure you're taking care of the basics. Like we still see phishing attacks today, especially email-based attacks, there's still like a vast majority of them are, like, they're targeting the basics. And they're hoping that enterprises and companies are not just like doing the lowest possible amount of work in order to get it done. And so these are really cyber criminals we're talking about. So they're also trying to do the least amount of work possible in order to sort of have some sort of financial gain. So one is like, make sure you're keeping the basics. Like DMARC, DKIM, SPF, make sure all those are up to date. I can't tell you how many, you know, just still spoofing attacks that we see on a day-to-day basis where there's an organization that doesn't have DMARC enabled. And so therefore, you know, their domain can be spoofed rather easily. So, and make sure, you know, make sure you have the basic, you know, user impersonation, domain impersonation, those policies and those types of things turned on. So one, make sure you're, you know, at least making it somewhat hard for the attackers to do their jobs. Two is sort of understanding the types of attacks that we're seeing more and more often. You know, we've tracked QR code and CAPTCHA-gated phishing attacks over the past year because they have been sort of two of the tactics that we've seen being used, you know, more frequently and by some of the larger -- sort of the larger phishing-as-a-service groups out there like Tycoon. That being said, we do see an ebb and flow in the volume of those types of tactics every single month. You know, for example, since -- Tycoon was a disproportionate driver of both of those types of attacks. And since the disruption, which I'm sure we'll talk about, we've seen both of those go down, but not to the level of, hey, it was only Tycoon using these types of tactics. You know, it's very clear that there are other services and tools and actors that are using these same services. But Tycoon definitely had an impact on them. I will also say, things like device-code phishing, which we don't really talk about in our latest landscape report, but we will as we move forward into sort of this current quarter and moving forward. Device-code phishing is one of those things that really has been around for a bit now but really came on the scene earlier this year with something like EvilTokens, where, you know, it's trying to exploit that, you know, the devices that people get on their phone and sort of get in the middle of that transaction to be able to compromise credentials and sort of bypass multi-factor authentication. So -- and there are really easy ways to get rid of that. There's easy policies that I don't have, that I don't know off the top of my head what they're called. But there are policies that enterprises can use to simply turn that capability off, and that will sort of mitigate that entire potential issue. So, yeah, I think those are some of the things that if organizations should pay attention to as we move into, you know, the latter part of the year.

Elliot Volkman: Cool. So I appreciate you brought up the disruption to Tycoon2FA, because that's where I want to go next. Which is, it's always kind of an interesting debate of like how much impact does it actually offer? And obviously the numbers here make it pretty clear that there is a sizable disruption to that activity, especially through those tactics. But this does beg the question, it's sort of like Hydra, where you cut off one head, you have two emerge. But is that activity -- do you see that activity by chance fragmenting? Is it moving anywhere else? Is it shifting elsewhere? Because it is difficult to disrupt a longevity system versus like an immediacy.

Crane Hassold: Yeah. So what's interesting about Tycoon is, and this is -- when it gets into things, the phishing-as-a-service, that entire landscape, what's important to remember about Tycoon is that they are a tool that customers are using to facilitate their attacks. So Tycoon, for those who don't know, is a service that allows customers, anyone across the world, to do two things. One, they can use a template that is offered, like an email template, that's offered by Tycoon to sort of, you know, make realistic-looking attacks. And then also, it provides, Tycoon also as-a- service, provides infrastructure that allows customers to use to host the phishing sites at the end of the day. What Tycoon doesn't do is they don't offer the capability to mail, to send the actual emails themselves. Customers need to use a separate tool, a separate mailer, in order to make that possible. And it's important as we go into the overall impacts of what the Tycoon disruption actually did and how it's persisted over time. So when we look at what happened, so the Tycoon disruptions, you know, started, it was Microsoft, it was really dozens of organizations, both in the private sector as well as the public sector, law enforcement, really all around the world, sort of helped out with this, which was a great demonstration of how all of these organizations can come together for a positive, to make a positive impact. But what -- after the -- so the mitigation -- the disruption was focused on disrupting Tycoon's infrastructure, where the final, you know, these final phishing sites were being hosted. And what was interesting is right after the disruption, we've been monitoring the numbers and what was actually going to happen. And, you know, a few weeks went by, and we didn't really see that much of a decrease. It went down a little bit, but it wasn't like someone flipped a switch and then all of a sudden Tycoon's, you know, volume went down by a ton. It wasn't like that. It started going down a little bit, but not too much. There was actually a pretty massive campaign a week, I think it was a week after our disruption activities happened, which actually caused a spike in what we saw from what we observed through Tycoon. But what's important to keep in mind is that when we're identifying these campaigns and these messages, they're the emails that are getting sent out. That's important because I guarantee that there were a ton of Tycoon customers that had no idea that any of this disruption activity had actually happened. And so they're just sending out their campaigns, you know, like they would any other day. But what happened was the email campaigns would go out, we would see them, we would, you know, put a little tick on our board and say, hey, here's a new Tycoon campaign, or a campaign that's leading to Tycoon infrastructure. But when you look at the phishing page, anyone who receives those, if they do receive them, they're not going to be able to get to the final page. So that's where the early impact came into play. We didn't see, you know, there wasn't an observable volume impact right away. But we could easily see that there was an impact in the actual number of victims that were being hit with Tycoon, that were actually being compromised by Tycoon. That was the early impact. And now over the past couple of months, we've seen the overall volume of just messages that lead to Tycoon related domains has gone down just -- has gone off a cliff. So let's see. So we saw just in June, we saw 1.2 million messages that were linking to Tycoon infrastructure. Which still seems like a lot, but it's actually, that's 92% lower than what we had seen in, what, March or February. Just to give, you know, a sort of a comparison there, at the end of the average -- at the end of the last half of 2025, the average number of messages that we saw in any given month that we could confirm were Tycoon was about 15.1 million. So, you know, 1.2 million sounds like a lot, but it's significantly less than what it used to be. And it's also not driving as much of the notable, sort of notable tactics that we've seen. So just, you know, I've mentioned, we've mentioned the CAPTCHA-gated phishing attacks and the QR code phishing attacks. Just to give you some numbers there. So back in December of last year, Tycoon was responsible for about 76%, so three-fourths, of all CAPTCHA-gated phishing attacks. Whereas in June, that number had gone down to 12%. And then also QR code phishing back in November of last year, it had peaked at about one-third of all QR code phishing attacks were related to Tycoon. That's now down to about 14%. And so that's obviously also had an impact on the overall volume of those tactics being used. But again, those tactics aren't decreasing by the same amount of just taking Tycoon out of the equation. It's very clear that there are some services and other tools that are sort of filling in those gaps. But, you know, what's great -- this is like why we do what we do when it comes to disruption. It's always great to, one, put a lot of work into setting up a disruption campaign. You know, Tycoon, before this, was easily the biggest driver of most malicious email traffic that we had seen for a good year or so. And, you know, since over the past, what, three, four months now, you know, seeing that volume and their overall impact of this tool that was so disproportionately impactful has gone down significantly. You know, obviously you mentioned someone coming to take their place, and I have no doubt that there will be some other tool that customers are just going to go to. Because again, you -- the ones that are sending the email campaigns, it's not Tycoon, it's the customers of Tycoon and customers of other phishing-as-a-service tools. And so those customers are going to go somewhere else at the end of the day. But we're still trying to figure out, you know, which of the many, many, many surfaces out there, many platforms out there are these phishing actors going to go to.

Elliot Volkman: Thank you for walking through that with such great depth and also including the numbers piece of the equation. Because I feel like there's -- it might have been a conversation with you or otherwise, but if you maybe go for a disruption against a specific actor, the weight on that is a little bit different than actually taking out the infrastructure and the systems that organizations rely on, especially if, you know, their customers are essentially still using it to a dead end. So that's always a fun little benefit, I'm sure, that makes just taking their lures out -- off the table pretty quick.

Crane Hassold: Yeah, but one of the great things about this is that -- you know, and I've seen disruption operations happen in the past where, you know, you may see a very short blip in volume decrease because the actors behind the scenes are just pivoting to something else that they've either have already had staged in the chance that there is some sort of disruption, or they're able to easily sort of pack up what they've done and move somewhere else. That has -- because of the way that the whole operation went down and sort of the, you know, what we were targeting and how we were targeting it, that really wasn't an option for Tycoon. So being able to see not only was there an impact, a short-term impact, but it's been pretty consistent and long-lasting over the past four months that they haven't -- that the tool hasn't come back in force that we sometimes see with other types of mitigation operations.

Elliot Volkman: Excellent. All right. Well, Crane, thank you again for coming on here and sharing a little bit of your expertise and your understanding of the threat landscape. For anyone who's interested in a little bit more in-depth breakdown, feel free to go to the Microsoft Threat Intelligence blog, where as of mid-July, somewhere mid-July, that is when we published the most recent one. I believe there's at least one or two other ones based on Crane and team's finding and research. All right, thank you all. We will see you at Black Hat if you're going to be there. And that is it for this episode of the Microsoft Threat Intelligence Podcast.