Which bothers me. I’ve spent a lot of time arguing awareness training isn’t where the real controls live. Here I can’t find the control, and the answer is the old-fashioned one.
Two hundred AI voice calls impersonating Apple Support cost the operators $19.24.
Ten cents a call, three languages, no human on the line.
#AISecurity#Phishing#Vishing#InfoSec
https://t.co/TNZXZK8Vfw
The work ID password we can reset, and that’s a reasonable trigger on a lost device report. The Apple ID is the user’s to change and won’t help much, since the operation is built around getting them to hand over whatever the current one is.
When a personal device goes missing we remote wipe the corporate profile, and that does what it’s designed to do. Keychain lives on the personal side though, outside the managed container, so the wipe can’t reach it.
This gets covered as consumer crime, and on the surface it is. But an Apple ID gets you iCloud backups and Keychain, and people save work passwords in Keychain whether policy allows it or not.
Then it contacts the owner using the details they put in Lost Mode. The victim gets a call from “Alice from Apple Support” walking them through confirming their passcode, Apple ID, and 2FA codes.
SOCRadar published research on the platform behind them. AnonyMousKIT, built for one job: getting Activation Lock off stolen iPhones. Thief enters the serial or IMEI, it pulls the model and live Find My status.
The takeaway I keep landing on: when the entry point is a legitimate feature, the useful control sits one step past the entry point. Not at the door. At what happens after someone walks through it.
Most write-ups on Teams helpdesk impersonation describe the attacker talking someone into installing AnyDesk or Quick Assist.
The attempts we’ve seen don’t bother with that.
#Microsoft#Teams#InfoSec
https://t.co/p73qVO77PY
One went from first contact to encrypted files in under 17 hours. Calls averaged about two and a half minutes. Legal is being targeted deliberately, and Mandiant tracked a separate group running this against dozens of US law firms Jan through May.
Sophos documented the same pattern in STAC4749, Feb through June. Operators used PowerShell to download payloads from attacker servers after establishing the remote session. Dozens of North American orgs hit, three ending in Chaos ransomware.
That’s the moment the attack needs something new to exist on disk. First point where a control can actually say no. PowerShell ringfencing or application control stops the download and the chain ends there.
It breaks down at the next step. Once they have hands on keyboard, they open PowerShell and run an Invoke-WebRequest to pull the payload from their own infrastructure.
They use Teams screen sharing and request remote control. Native feature, already approved, already running. Nothing to install, nothing that looks out of place.
We can pull the email from the mailbox afterward, but if the assistant already read it, we’re cleaning up after the fact.
Anyone found a training angle that works here? Ours only speaks to the human, and the human isn’t first in line anymore.
We spent years teaching people to slow down and check an email before trusting it.
Check the sender. Hover the link.
None of that helps when the AI assistant reads it first.
#AISecurity#EmailSecurity#InfoSec
https://t.co/5206qP6oAK
Here’s what I keep landing on. Awareness training works because a person can learn to be suspicious. An assistant can’t. It reads everything, it reads it before we do, and it has no instinct for “this feels wrong.”
PortSwigger showed at Black Hat how you hide the text. CSS that makes it invisible on screen but readable to the model. Worked in Outlook, Gmail, and Proton.
Worse than it sounds: the assistant still does what the user asked. It just also does the attacker’s part quietly alongside it. Nothing looks wrong to the person reading the output.