Skip to content

Security1 publisher3 min readPublished

Vishing gets a product tier: Okta finds kits that steer the victim's browser mid-call

Okta Threat Intelligence says as-a-service phishing kits now let a caller change what the target sees in real time, synced to genuine MFA prompts. Push and OTP were not built to survive that.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Okta Threat Intelligence has detected and dissected multiple custom phishing kits that have evolved to meet the specific needs of voice-based social engineers (callers) in vishing campaigns.
  • The custom kits are made available on an as-a-service basis and are increasingly used by a growing number of intrusion actors targeting Google, Microsoft, Okta and a range of cryptocurrency providers.
  • The kits can intercept the credentials of targeted users while also presenting the supporting context required to convince users to approve MFA challenges or take other actions in the attacker's interest.
  • The kits can be adapted on the fly by callers to control what pages are presented in the user's browser, in order to sync with the caller's script and whatever legitimate MFA challenges the caller is presented with as they attempt to sign in.
  • The most critical feature is client-side scripts that allow threat actors to control the authentication flow in the browser of a targeted user in real time while they deliver verbal instructions or respond to verbal feedback from the target.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Okta Threat Intelligence says it has detected and dissected multiple custom phishing kits built specifically for the people making the calls in vishing campaigns [1]. The kits are sold on an as-a-service basis and are being used by a growing number of intrusion actors against Google, Microsoft, Okta and a range of cryptocurrency providers [2], which moves phone-based social engineering out of the realm of talented individuals and into tooling anyone can rent.

The interesting part is not credential capture. It is the plumbing. According to Okta, the kits intercept credentials while also presenting the supporting context needed to talk a user into approving an MFA challenge or taking other actions the attacker wants [3], and callers can adapt them on the fly to control which pages appear in the target's browser so that the screen matches both the caller's script and whatever legitimate MFA challenge the caller is being shown [4]. Okta attributes this to client-side scripts that let the actor drive the authentication flow in the victim's browser in real time while delivering verbal instructions or reacting to what the victim says [5]. Okta's researchers say the kits appear, based on common features, to have evolved from the same lineage [6].

The sequence Okta describes is unglamorous and repeatable. Reconnaissance establishes user names, the apps they use, and the phone numbers used in IT support calls [7]. The actor stands up a customised phishing page and calls the target while spoofing the company or its support hotline number [8], then uses an IT support or security pretext to get the user to browse to the page [9]. Credentials typed there are automatically forwarded to the actor's Telegram channel [10]. The actor enters them into the real sign-in page, sees which MFA challenge comes back [11], and updates the phishing site in real time with pages that back up the verbal request for an OTP, a push approval, or something else [12]. For push, Okta says the actor can pick an option in the command-and-control panel that sends the target's browser to a page implying a push has been sent, which lends plausibility to a prompt the user never initiated [13].

That is the whole argument against the current second-factor estate. Okta says these hybrid operations also defeat push with number matching, and states plainly that number matching is not phishing-resistant by definition, because a social engineer on the phone can simply tell the user which number to pick [14]. Moussa Diallo, a threat researcher at Okta Threat Intelligence, said the synchronisation between browser and script can be used to defeat any form of MFA that is not phishing-resistant [15]. Okta's published excerpt contrasts this with users required to sign in using phishing-resistant methods such as Okta FastPass, though the text we have breaks off mid-sentence [16]. Okta has issued a detailed customer advisory covering the capabilities of two of the kits [17].

Two things to watch. First, whether organisations that ticked the MFA box with number matching now treat that as a known-bypassable control rather than a finished project [14]. Second, the help desk: the recon step specifically collects the numbers used in support calls, and the call spoofs the hotline [7][8], so any process where the user is expected to judge whether the caller is real is already compromised. The kits do not break cryptography. They break the assumption that a user watching a familiar-looking screen is watching their own session.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories