{"id":15220,"date":"2021-11-30T17:51:56","date_gmt":"2021-11-30T22:51:56","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=15220"},"modified":"2023-04-10T10:36:59","modified_gmt":"2023-04-10T14:36:59","slug":"attacker-exploits-fbi-website-vulnerability-to-send-hoax-email","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/attacker-exploits-fbi-website-vulnerability-to-send-hoax-email\/","title":{"rendered":"Attacker Exploits FBI Website Vulnerability to Send a Hoax Email"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-when-it-comes-to-exploiting-web-and-email-vulnerabilities-no-one-including-the-u-s-federal-government-is-impervious-to-cybercriminals-attacks\">When it comes to exploiting web and email vulnerabilities, no one \u2014 including the U.S. federal government \u2014 is impervious to cybercriminals\u2019 attacks\u2026<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Earlier this month, the U.S. Federal Bureau of Investigation\u2019s (FBI) legitimate IT infrastructure was fraudulently used to send hoax emails to tens of thousands of individuals and organizations. The phony email contained a message from the Department of Homeland Security (DHS), stating that the agency allegedly detected a sophisticated chain attack and identified a threat actor who was responsible for it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While the FBI reports that no data is compromised, it still leaves us wanting answers to a few important questions: What the heck happened? How did this situation occur in the first place? And what can you learn from the FBI\u2019s security incident that can help your organization avoid falling prey to similar attacks?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-breaking-it-all-down-an-overview-of-what-occurred\">Breaking It All Down: An Overview of What Occurred<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In a nutshell, on Nov. 12, an attacker capitalized on a basic vulnerability within the FBI\u2019s IT infrastructure to send out phony emails to recipients that warned of fake cyber attacks. But what makes the situation particularly scary is that the messages were sent via an email address \u201ceims@ic.fbi.gov\u201d \u2014 this is a legitimate email domain that hails from servers controlled by the Bureau. This means that the attacker was able to use their IT infrastructure against them to send out emails from their legitimate domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The next day, the <a href=\"https:\/\/www.fbi.gov\/news\/pressrel\/press-releases\/fbi-statement-on-incident-involving-fake-emails\">FBI released a brief official statement<\/a> on the matter, saying that they were aware of the incident regarding the FBI email account and had taken the affected hardware offline. Of course, there\u2019s a certain level of irony considering that in the same breath, they also warned people to \u201cbe cautious of unknown senders\u201d and to report suspicious activity to either ic3.gov or cisa.gov. Since the emails were sent using an official email address by exploiting a webmail form vulnerability, that point is quasi moot in this case.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two days after the initial faux emails went out, the FBI posted an update, stating that a threat actor gained temporary access to their law enforcement portal to send the hoax warning emails due to a \u201csoftware misconfiguration.\u201d (Brownie points if you remember this later.) The Law Enforcement Enterprise Portal, or LEEP, is part of the IT infrastructure that the Bureau uses to communicate with local and state law enforcement partner agencies. According to the Bureau:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cWhile the illegitimate email originated from an FBI operated server, that server was dedicated to pushing notifications for LEEP and was not part of the FBI\u2019s corporate email service. No actor was able to access or compromise any data or PII on the FBI\u2019s network.<\/em> <em>Once we learned of the incident, we quickly remediated the software vulnerability, warned partners to disregard the fake emails, and confirmed the integrity of our networks.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The statement is a mix of bad and good news: Sure, the server in question was operated by the FBI. But it wasn\u2019t used to house sensitive information. Rather, it was used to push messages to law enforcement partners.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The big takeaway in all of this is that the email messages were sent by a legitimate application on the FBI server. Since the FBI didn\u2019t secure the API access, it allowed an unauthorized user to send out the hoax emails in their name.<\/p>\n\n\n<span style=\"--tl-form-height-m:966.781px;--tl-form-height-t:989px;--tl-form-height-d:989px;\" class=\"tl-placeholder-f-type-shortcode_12768 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-did-the-emails-say-here-s-a-look-at-the-hoax-messages\">What Did the Emails Say? Here\u2019s a Look at the Hoax Messages<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Okay, now that you have an idea of what this situation entails, it\u2019s time to actually take a look at the message. <a href=\"https:\/\/www.spamhaus.org\/\">The Spamhaus Project<\/a>, an international threat intelligence organization, posted screenshots of one of these warning emails on its Twitter page:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"772\" height=\"912\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/spamhaus-project-email-example.png\" alt=\"A screenshot of a Spamhaus Project tweet that showcases the attacker's phony email message\" class=\"wp-image-15222\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/spamhaus-project-email-example.png 772w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/spamhaus-project-email-example-254x300.png 254w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/spamhaus-project-email-example-768x907.png 768w\" sizes=\"auto, (max-width: 772px) 100vw, 772px\" \/><figcaption class=\"wp-element-caption\"> A tweet from The Spamhaus Project that contains a screenshot of one of the hoax emails that was sent by the attacker. <\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">It says the following:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cOur intelligence monitoring indicates exfiltration of several of your virtualized clusters in a sophisticated chain attack. We tricked to blackhole the transit nodes used by this advanced persistent threat actor, however there is a huge chance he will modify his attack with fastflux technologies, which he proxies trough multiple global accelerators. We identified the threat actor to be Vinny Troia, whom is believed to be affiliated with the extortion gang TheDarkOverlord, We highly recommend you to check your systems and IDS monitoring.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Beware this threat actor is currently working under inspection of the NCCIC, as we are dependent on some of his intelligence research we can not interfere physically within 4 hours, which could be enough time to cause severe damage to your infrastructure.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Stay safe.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>US Department of Homeland Security | Cyber Threat Detection and Analysis | Network Analysis Group\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">\u2026 Uh huh. Okay. The spelling, grammar, and punctuation issues aside, this confused warning email seems to take an unusual left turn by ragging on cybersecurity researcher Vinny Troia. In an article in <a href=\"https:\/\/www.washingtonpost.com\/nation\/2021\/11\/14\/fbi-hack-email-cyberattack\/\">The Washington Post<\/a>, Troia says he believes it was a smear campaign in response to research he\u2019d published that exposed a young hacker and their involvement in several hacking groups. &nbsp;&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Spamhaus Project also tweeted another screenshot of the email\u2019s sanitized header information as well for people to see:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"797\" height=\"694\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/spamhaus-project-email-header-example.png\" alt=\"A screenshot of a Spamhaus Project tweet that showcases the sanitized email header information\" class=\"wp-image-15223\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/spamhaus-project-email-header-example.png 797w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/spamhaus-project-email-header-example-300x261.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/spamhaus-project-email-header-example-768x669.png 768w\" sizes=\"auto, (max-width: 797px) 100vw, 797px\" \/><figcaption class=\"wp-element-caption\">A tweet from The Spamhaus Project\u2019s Twitter feed that shares the sanitized headers from the same sample email. <\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">In the screenshot above, note the CJIS references in the \u201cReceived: from\u201d fields \u2014 those stand for the Criminal Justice Information Services, which is a division of the FBI. &nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-the-form-mail-exploit-attack-occurred\">How the Form Mail Exploit Attack Occurred<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In an article on his blog <a href=\"https:\/\/krebsonsecurity.com\/2021\/11\/hoax-email-blast-abused-poor-coding-in-fbi-website\/\">krebsonsecurity.com<\/a>, Krebs said he interviewed the alleged attacker who goes by the username \u201cpompompurin.\u201d (Be sure to check out that article if you want a more in-depth look at how it occurred.) Pompompurin shared how he or she used the FBI\u2019s own email system against them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It all started with the LEEP web portal, which is intended to be used for government-authorized uses only by law enforcement and other related agencies.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"891\" height=\"646\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/leep-login-page-screenshot.png\" alt=\"A screenshot of the LEEP login page\" class=\"wp-image-15225\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/leep-login-page-screenshot.png 891w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/leep-login-page-screenshot-300x218.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/leep-login-page-screenshot-768x557.png 768w\" sizes=\"auto, (max-width: 891px) 100vw, 891px\" \/><figcaption class=\"wp-element-caption\">A screenshot we took from the CJIS website LEEP login page.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Until shortly after this incident, virtually anyone previously could set up an account on the law enforcement portal website. This process involved the FBI\u2019s email system automatically sending a confirmation to a new user\u2019s email account to confirm the new account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now when you hit the <strong>Apply for an Account<\/strong> button, it results in the following error message:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"954\" height=\"520\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/leep-new-account-error.png\" alt=\"A screenshot of an error message that results when you hit &quot;Apply for an Account&quot; on the LEEP login portal\" class=\"wp-image-15226\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/leep-new-account-error.png 954w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/leep-new-account-error-300x164.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/leep-new-account-error-768x419.png 768w\" sizes=\"auto, (max-width: 954px) 100vw, 954px\" \/><figcaption class=\"wp-element-caption\">A screenshot we took on the FBI&#8217;s CJIS division LEEP website portal.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Oops.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Remember how the FBI\u2019s statement pointed to a software misconfiguration as the cause of the security incident? Well, that not-so-little misconfiguration involved the system generating a client-side one-time code that it sent via an HTML POST request. (The POST request allows you to specify what information to include in an email and where to send it.) What this means is that the email gets generated in the browser where someone could \u2014 and apparently did \u2014 tamper with it and then the server would send the message.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>An attacker would receive confirmation code information that generated in their browser.<\/li>\n\n\n\n<li>They could change that information and put virtually whatever they wanted in the email\u2019s key fields \u2014 subject line, body, and recipient info.<\/li>\n\n\n\n<li>They could use the FBI\u2019s own webmail system to send the false message to whichever recipients they specified.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Using client-side code to send emails like this is <em>really<\/em> insecure and there\u2019s no reason why any site should use it \u2014 especially not a federal government website! To say it\u2019s insecure and dangerous is an understatement. &nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-the-email-attack-occurred\">Why the Email Attack Occurred<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There are plenty of reasons <em>why<\/em> the attack might have occurred \u2014 perhaps the attacker was just bored. Maybe they wanted to have a little fun at the expense of the FBI and Troia. Or, maybe, they\u2019re a <a href=\"https:\/\/www.thesslstore.com\/blog\/mysterious-russian-grey-hat-vigilante-patched-over-100000-routers\/\">grey hat hacker<\/a> who did something bad to do something that\u2019s ultimately good\u2026<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Krebs, Pompompurin said the reason why they decided to hack the FBI\u2019s email is that they wanted to call attention to a problem before someone else decided to exploit it for malicious reasons.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-you-should-care\">Why You Should Care<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">All of this goes to show that anyone \u2014 no matter whether you\u2019re a small business, a large corporation, or even the federal government \u2014 can become the target or victim of a cybercriminal. Your technological weaknesses can be discovered and will be exploited if they fall into the wrong hands. Unfortunately for you and your business, if a bad guy finds one of those vulnerabilities to exploit, they may not have good intentions and will use it to cause significant harm to your business and customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/threat-landscape-q1-2020\">Symantec reports<\/a> that as of Q1 2020, one in every 4,200 emails were phishing messages. Now, imagine how much that number has likely skyrocketed considering all of the COVID-19-related scams, riots, and other ongoing world events that cybercriminals can use to their advantage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At least, in this case, it doesn\u2019t appear that the threat actor (Pompompurin) was trying to cause harm to the email recipients since they could have but didn\u2019t. The emails weren&#8217;t sent out with any phishing links or attach malicious files. However, it\u2019s no secret that email communications are a major target for cybercriminals. Email is the way that organizations stay in touch with their employees, customers, vendors, partners, and other key entities. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If someone can impersonate a legitimate organization or authority by hijacking their systems, who\u2019s to say that they won\u2019t use those systems to do significantly worse harm than sending an obviously fake email?<\/p>\n\n\n<span style=\"--tl-form-height-m:140.667px;--tl-form-height-t:118.1042px;--tl-form-height-d:118.1042px;\" class=\"tl-placeholder-f-type-shortcode_12779 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-final-takeaways-how-to-make-email-communications-more-secure\">Final Takeaways: How to Make Email Communications More Secure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This particular cyber security situation for the FBI is one that was easily avoidable by following coding best practices and securing API access. But what other steps can you take to make your email communications more secure?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Follow secure coding practices on your website, forms and web apps.<\/li>\n\n\n\n<li>Remove any client-side scripting capabilities that aren\u2019t fully secure.<\/li>\n\n\n\n<li>Use <a href=\"https:\/\/www.thesslstore.com\/enterprise\/email-document-signing-certificates.aspx\">email signing certificates<\/a> to digitally sign all emails that are sent by your organization\u2019s authorized users from their individual devices.<\/li>\n\n\n\n<li>Use <a href=\"https:\/\/www.thesslstore.com\/blog\/verified-mark-certificates-the-bimi-standard-show-your-company-logo-in-your-customers-inbox\/\">BIMI and Verified Mark Certificates<\/a> to add your logo to verified emails.<\/li>\n\n\n\n<li>Implement cyber awareness training for your employees that help them recognize phishing emails and other scams.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>When it comes to exploiting web and email vulnerabilities, no one \u2014 including the U.S. federal government \u2014 is impervious to cybercriminals\u2019 attacks\u2026 Earlier this month, the U.S. Federal Bureau&#8230;<\/p>\n","protected":false},"author":17,"featured_media":15228,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,16],"tags":[7970,7387],"class_list":["post-15220","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-hashing-out-cyber-security","tag-email-security","tag-fbi","post-with-tags"],"views":10606,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/11\/fbi-hoax-email.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/15220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=15220"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/15220\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/15228"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=15220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=15220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=15220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}