Did you know your Outlook account can be easily hacked by known cybercriminals
Recently it was discovered that the hackers known under the appellation of Cozy Bear, classified as a persistent threat alias APT 29 have found a method to bypass the multiple authentication likely to protect your Microsoft 365 account.
In this context, your Outlook account is easily at the mercy of these hackers who are not amateurs.
This article will also interest you: 3 techniques to succeed in decrypting an Outlook account
This group of hackers is also known under the appellation of « Nobelium ». They are known as being cybercriminals whose actions can cause big damage to organizations both of the private and the public sector. They even have the reputation of being supported by the Russian government for whom, they often lead actions in order to attack any institution that would have aversions towards Russia and its government.
This new computer hacking campaign targets the whole of Microsoft 365, which includes Outlook accounts obviously is certainly a mission that they must fulfill for the account of the Russian government.
Why? Simply to surely collect a lot of sensitive data particularly in these periods of crises.
This new attack was detected by a company specialized in computer security named Mandiant. Thanks to this technique they can be seen realizing several types of malicious actions namely:
« It disables Purview Audit before engaging on Microsoft 365, via a compromised email account ; It forces the Microsoft 365 passwords that are not yet recognized by multifactor authentication (MFA). It conceals its traces by using Azure virtual machines (the subscription is done through compromised accounts) », explain the researchers.
« Purview Audit, is a high-level security function that records any access to an email account outside of the program (either via the browser, or via the Graph API, or via Outlook). In this way, the IT service of a company, an association or a collectivity can manage all the active accounts and make sure that there is no intrusive access putting in peril the security of the system. », add these latter.

« It is a critical log capable of determining if a cybercriminal accesses a particular mailbox, but also of judging the extent of the attack It is the only way to effectively restrict access to a messaging facing seasoned bypass techniques like identity theft on an application or via the Graph API. », describes, the cybersecurity company in its report.
The only positive note in this story is that the cybercriminals do not seem to be interested in Microsoft 365 users for individuals. It would seem that the hackers in question target particularly the big organizations and Western companies. But for now nothing is guaranteed. Microsoft has made no declaration on this subject. Surely, the American giant is looking for a way to plug the breach.
APT 29 is well aware of this protection, and makes sure to disable it before accessing any targeted messaging.
Now access an unlimited number of passwords!
