Microsoft's Digital Crimes Unit last week disrupted a prolific cybercrime-as-a-service purveyor that it calls Storm-1152, which registered more than 750 million fraudulent Microsoft accounts to sell online to other cybercriminals - raking in millions of dollars in the process.
Fraudulent accounts tied to fake profiles offer cybercriminals an essentially anonymous launchpad for automated criminal activities like phishing, spamming, ransomware, and other types of fraud and abuse.
Storm-1152 is the top of the fake account creation heap, providing many of the most well-known cyber threat actors out there with account services.
According to Microsoft, these include Scattered Spider, which is the cybercrime group behind this fall's MGM Grand and Caesars Entertainment ransomware hits.
Hogan-Burney also wrote that the DCU identified the main ringleaders of the group, all based in Vietnam: Duong Dinh Tu, Linh Van Nguyễn, and Tai Van Nguyen.
Microsoft has since submitted a criminal referral to US law enforcement on all three perps.
Me, a website selling fraudulent Microsoft Outlook accounts.
1stCAPTCHA, AnyCAPTCHA, and NoneCAPTCHA, websites that sell identity-verification bypass tools for Microsoft and other technology platforms.
A Sophisticated Crimeware-as-a-Service Ring The fact that Storm-1152 was able to bypass security checks like CAPTCHAs and generate millions of Microsoft accounts tied to nonexistent people highlights the group's sophistication, researchers say.
Shutting Down Account Abuse To avoid becoming an unwitting accomplice to cybercrime, platforms can take a number of steps, including deploying advanced detection algorithms that can identify and flag suspicious activities at scale, preferably with the use of AI, the researchers noted.
Implementing strong multifactor authentication for account creation, especially those with escalated privileges, can significantly reduce the success rate of fraudulent account generation.
More work needs to be done on several fronts, according to Ontinue's Jones.
This Cyber News was published on www.darkreading.com. Publication date: Mon, 18 Dec 2023 22:10:20 +0000