Internet

Microsoft Office 365 and Onedrive Vulnerability Still Open To Ransomware attacks

Cybercriminals are now hunting SharePoint and OneDrive accounts to encrypt data and extort users. While this is primarily “lucrative” for businesses, it can also affect individuals. That’s what they are doing now Proofpoint Security Researchers In the past week, researchers revealed a vulnerability in a Microsoft 365 feature that opens up new cloud-based attack vectors for hackers. Proofpoint’s findings explain how malicious actors can use basic functions in the applications to encrypt files and make ransom demands. This vulnerability gives hackers another way to attack cloud-based data and infrastructure.

It all starts with access to the cloud

The vulnerability is based on a four-step attack chain that begins with a user’s identity being compromised. For example, user accounts can be compromised by brute force or phishing attacks, improper authorization via third-party OAuth apps, or hijacked user sessions.

The attacker then uses the person’s credentials to access their SharePoint or OneDrive accounts. There it changes the version control setting and encrypts the files multiple times so that no unencrypted version of the compromised files is left behind. Once files are encrypted, they can only be accessed with the correct decryption keys – and that can get expensive.

Document changes logged

Versioning is a feature in SharePoint and OneDrive that creates a record for each file, logging all document changes and the users who made those changes. Users with appropriate permissions can view, delete, or restore previous versions of the document.

The number of versions tracked is determined by the version settings in the application. These version settings do not require administrator rights and are therefore easy for hackers to change.

More changes than saved versions

Changing the number of document versions preserved is key to this exploit. The attacker configures the version settings to keep only a desired number of versions per file. The files are then encrypted more times than the number of saved versions, leaving no recoverable backup versions.

Encryption is not the only way that version control can be exploited. Another option is to re-modify files for so long and for so long that no original file is left behind. In all cases, only the attackers can access an original and try to extort victims into paying the ransom.

Recent Posts

Navigating the Digital Frontier: How Mobile Proxy Infrastructure Empowers Modern Technology Journalism and Enterprise Data Mining

For tech analysts, software engineers, and digital journalists tracking real-time market shifts on platforms like…

20 hours ago

Decoupling Digital Identity: How Modern App Ecosystems Rely on Virtual Telecommunications Architecture

Modern mobile security models treat phone numbers as default digital passports, forcing tech consumers and…

20 hours ago

Top Extended Detection and Response Platforms for Large Enterprises: A Vendor Comparison Guide

Large enterprises have a lot of security data, but identifying the signals that truly matter…

21 hours ago

5 Lab Methods Scientists Use to Find What’s Really in Tap Water

A glass of tap water reveals little about its chemical makeup. Clear water may still…

2 days ago

Medical Technology Leadership Programs and Industry Collaborators: The Essential Resource Roundup

In today’s healthcare landscape, collaboration between academic programs and corporate leaders fuels both technological innovation…

3 days ago

Smartphone ban: Italy will soon pay for distracted pedestrians

Italy is cracking down on cell phone use in traffic and will soon be targeting…

3 days ago