Vishing and SSO Attacks: How Attackers Bypass Your MFA
Vishing and SSO attacks let groups like Cordial Spider bypass MFA with AiTM phishing. Learn how the attack works and how to stay protected.
Yossi Pinhasov
YouCC Technologies
Vishing and SSO: How Attackers Bypass Your MFA
A troubling trend is worth knowing: threat groups such as Cordial Spider are breaching organizations through a sophisticated blend of SaaS abuse and human engineering. These vishing and SSO attacks bypass multi-factor authentication not by breaking the technology, but by tricking the person behind it. The result is a fully authenticated session in the attacker's hands, achieved through a convincing phone call rather than malware.
What happened / How the attack works
The attack unfolds in three stages:
- The call. The attacker phones an employee, impersonates IT help desk staff, and persuades them to log into a "corporate" security portal to resolve an issue.
- The bypass. The fake site acts as an Adversary-in-the-Middle (AiTM) relay. The user enters their password and MFA code, and the attacker harvests both in real time, then plants an authenticated session of their own.
- Entrenchment. Once inside, the attackers register a new device of their own and create mailbox rules that automatically delete security alerts, keeping them under the radar.
Why it matters
MFA is often treated as a finish line, but AiTM phishing turns it into just another credential the attacker can relay. Because the malicious flow rides legitimate SSO and SaaS infrastructure, it looks normal to most controls. The persistence techniques (new device registration, alert-deleting mailbox rules) are designed to suppress exactly the signals a defender would rely on, so the intrusion can go unnoticed long after the initial call.
How to stay protected
- Re-verify the caller. Received a call from support? Do not hand over any details. Hang up and call IT back yourself using the official number.
- Check the URL. Confirm the SSO address in your browser bar is the exact corporate domain. Even a single changed character is a sign of an attack.
- Watch your settings. Pay attention to alerts about new device registrations or changes to mailbox rules.
Ultimately, the best technology will not protect you against a convincing phone call. Stay alert. For the full technical write-up, see The Hacker News coverage.
Shared from the CSC - Cloud Security Community community, by Yossi Pinhasov.
Want more like this? Join the CSC - Cloud Security Community → https://youcc.co.il/community