Transcript
Thank you for joining us today and welcome to this Lookout Threat Briefing on a most recent discovery by our Lookout Threat Intelligence team. The phishing kit we're going to be talking about today is called Crypto Chameleon, as characterized by this spooky-looking chameleon in a hoodie with a cell phone. So it all makes sense once we go through it, and we're excited that you're joining us here today. Thank you for doing so, and please feel free to ask any questions throughout the session. We'll answer them throughout, or we can follow up with you afterwards. So just to introduce today's speakers. So my name is Hank Schless. I'm Director of Product Marketing, and Savio D.R., I'll let you guys introduce yourselves quickly. Okay. Hi, I'm Savio. I'm a Senior Self-Security Intelligence Researcher with Lookout, so I mainly deal with the phishing issues that our customers need to deal with. And I'm David Richardson. Everyone calls me D.R. I'm VP of Endpoint Threat Intelligence here at Lookout. Awesome. Well, thank you guys both for joining us today. So a quick bit about Lookout for those of you who aren't familiar with us. So Lookout really comes from a mobile heritage. D.R. was actually one of, what were you, D.R., about our 11th employee many, many years ago? Yeah, 14 years ago. So he's seen it grow. Yeah, there you go. He's seen it grow. He's seen how we've evolved and really how we've become the leader in mobile security really with that unrivaled expertise and this whole thing backed by the industry's largest data set of mobile security data. And that's fed by over 220 million devices that have been protected by Lookout and over 300 million apps that Lookout has observed. And then relevant to this particular session, which I don't have in this bullet here, is that we've observed over 400 million malicious and risky URLs, websites, web items, whatever you want to call them. So the goal here is really we want to make sure that we are securing the devices that your employees are using the most, which is the mobile device. With all of this, we have an industry-leading threat intelligence team, which Savio is a proud member of. And as proven by this discovery and many others, we are constantly able to find the latest and most threatening issues out there targeting the mobile device and the mobile user. This could range from an advanced phishing kit like CryptoChameleon to something like nation-state backed spyware or anything in between. The way we're able to do this is with that data set that I just mentioned, we're able to basically identify threats as they're being built. What we're able to do is look at characteristics of known malicious apps, malicious sites, look for those artifacts in new apps, new things that are being developed. And we're also tracking what the threat actors behind these pieces of malware, behind these campaigns, are doing in order to be able to identify things, again, as I said, as they're being built, which is, again, relevant to what we're going to talk about today and how that helped us identify this threat well ahead of time. And then the last piece here is that what type of data are you accessing from a mobile device? You're accessing cloud data. And so we see it as mobile being really the most vulnerable point of compromise to access cloud data. So we're going to look at that more modern kill chain and what that looks like these days and understand where the mobile device fits into that. So to really help make sure that we're not just protecting the device that's being used to access this data, but also the data itself, we have expanded into a secure services edge to really help protect that data. So if someone is successfully phished, then you have those safeguards in place to be able to protect the data, even if they are able to get past that step. So I mentioned it really briefly there just a second ago, but this idea of the modernized kill chain. So the way that we look at it, there are basically five steps. Some of these may seem familiar to that more traditional kill chain that Lockheed Martin put out many years ago. But the way that we look at it is that things are evolving. So the first thing is that attackers, as they always have, are doing that recon, right? So it's changed because they're using public data sources to be able to understand what apps your teams are using, maybe who your head of IT is so that they can impersonate that individual when contacting someone lower on the totem pole or a head of a support team when reaching out to a customer and pretending to be a member of that support team, basically gathering that data so that they can socially engineer their targets, these individuals, your employees, to fall for the attack that they're trying to carry out. The second piece of it really is that social engineering part. So by gathering that information and coming off as somebody who is familiar or is trustworthy, they're basically able to gain that trust, right? They're able to do things like use a combination of SMS messages and voice phishing to reach out to the employee, pretend like they are the member of a support team or a help desk or whatever it may be. And this is one of the biggest ways that we see folks getting, or folks, the bad guys getting around things like MFA, multi-factor authentication, and single sign-on solutions as well. So from there, once they've captured those credentials, once they've bypassed that MFA solution, they gain that initial access into the infrastructure. And this is really where the crossover into your cloud and private data starts to really come out, right? So they've moved from using the mobile device as the initial vector into now moving into your cloud apps and data. As we all know, that single sign-on is usually, is frequently the one point of authentication. So moving between apps, moving laterally, being able to identify and steal that data becomes a lot easier if they're doing it under the guise of being a legitimate employee. And then they basically have all sorts of ways of extorting you, your company, whatever it may be, into paying a ransom, whatever it may be, and essentially exploit and extort your individual employees or your company as a whole. So that's what we see as the modern kill chain. And to sort of put it into something a little more old versus new here, you're seeing that it used to be a number of steps for someone to deliver, whether it was a virus in an email or a phishing email or whatever it was, there were a number of steps to get from the bad guy to the employee, right? Nowadays, the threat actors can deliver banking trojans, malicious text messages, malicious files, links, whatever it may be, through so many different aspects of the mobile device to so many of your employees at once that the odds of them successfully being able to get one of those people to fall for it are much higher than they were when they had all these steps to go through before. Now, obviously, you want your employees to be using mobile devices so that they are productive from anywhere so that they can get things done on the go. It's a part of our everyday lives. My phone is right next to me right here, right? We're all constantly connected. So this has been recognized. It's now really the preferred tactic, especially when you look at it in the context of that modern kill chain and the initial steps that are being used to basically create the guise that this individual is a legitimate employee and accesses your infrastructure without throwing any red flags. Yeah. And when you go directly to the mobile device, you're able to circumvent many of the controls or visibility that an organization would typically have in place, right? By going directly from SMS message to employee's phone number, you're bypassing any corporate firewall, any secure email gateway, any existing security solution that you might have in place. And for many organizations that haven't deployed any sort of mobile threat defense solution or secure web gateway to extend it to mobile devices, they wouldn't have any visibility that any of that was occurring on those devices if you were under this kind of attack. Exactly. Thank you, DR. So I think that's it for me for now, and I'll hand it over to DR and Savya. All right. Sounds good. So let's talk about Crypto Chameleon. So first, we're going to talk a little bit about how we discovered it. So the way that we discover things is ultimately we are ingesting data from a ton of different sources every single day. So if any lookout user browses to a new site, we discover a new domain, we discover a new URL. We go and we analyze that through our automated machine learning techniques to try to classify whether or not this is a phishing or malicious site or not. We import third-party threat intelligence. We monitor all new domains as they get registered, all new SSL certs as they get generated. And in this case, we discovered an interesting new domain get registered. We saw fcc-okta.com get registered. This is one character different from the legitimate fcc-okta login page. And it immediately triggered a bunch of different rules and patterns that we had put in place to try to automatically classify these types of domains. But furthermore, in addition to the fact that we saw this domain register, we already knew a lot about this site and about the phishing hit that was deployed to it because we had been tracking this threat actor for some time. So we had already been monitoring some of the command and control infrastructure in place, some of the whois information and other things like that that Savio will provide more insight in on a second here. Naturally, Lookout customers, they're protected from this site, actually even before it came online because of some of the advanced automation we had put in place, as well as the tracking that was already in place for this threat actor where any non-protected user who went to these sites could potentially have their credentials get stolen. And we'll talk more about it in a second here. We were actually able to see some of the data that the attacker got access to, including things like usernames, passwords, photos of IDs, device reset URLs for changing, resetting a password, bypassing MFA, those kinds of things. So let's look at the site. So the site itself, when you first land on it, if you were to go to FCC-Octa.com while it was still up, of course, I'll say as a disclaimer here, do not go visit this site. It's not a good thing for you to do unless you really know what you're doing. You would see, the first thing that you would see is a CAPTCHA that was put in place. This is a legitimate CAPTCHA. It actually does require you to, you know, if you access this through a VPN or you access it through certain traffic patterns that make you look like a bot, you know, it's going to require you to actually complete a CAPTCHA. And you know, this is something that attackers put in place to prevent automated analysis. So it makes it harder for this site to be automatically classified as a phishing site. Once you pass the CAPTCHA, then you're brought to a page that looks like a, I would say pretty darn good impersonation of the legitimate Octa page for the FCC. And you know, it asks for a username and password. And then one thing that's particularly interesting about this attack is that once you enter in that information, you're actually brought to, this is one where the slide's actually in the wrong order here, you're actually brought to this please wait page that you see on the right side here. And what happens is, and we'll go into more detail in a second, but what happens is essentially this seems like a manually operated phishing kit that you get to a point in the process where the threat actor decides which page to send you to next. So you get to this please wait page. And then depending on what information the threat actor needs to get into your account, they will redirect you to, you know, whatever page they might need. So they might need an SMS-based one-time password token that they're going to send to your phone number ending in 34. And so they'll send you to a page that asks for that very specific information. So with that, I'm going to hand it off to Savio here, who's a researcher on my team who can go into some of the details on the phishing kit. So this one thing about this particular phishing kit is that they didn't protect the data too well. So we're able to look into the different directories and yeah, and we're able to see the traffic. So one thing is that we saw mostly manual control, as DR has mentioned. So when the user logged into a page, once they give the username and password, the operator has many different pages to choose from to send back what's going on. And by having the open directories, we were able to see the kit has many functionality. It was able to mimic the Octa pages of FCC, Binance, and Coinbase. So those would be most of these employees, they have pages against many other crypto exchanges on there, and also SSO platform, Octa, Microsoft, Google, and also Apple. And it also mimics the whole service flow at different crypto exchanges. So for example, two of the things that we saw is for folder reset. So if people haven't accessed the account for a while, then they will be asked for a copy of the folder ID. So the victims were sending those in, and they were able to capture those through monitoring the traffic. The other one is that certain flows ask for the seed phase for the cryptocurrency. So some victims were sending those, and I mean, with the seed phrase, once it's obtained, the threat actor can access the account info. So yeah, let's take a look at the next page, talking about the different directories. So the two main pages in the phishing kit that tells us a lot more. So one is cons.js, it lists the mixed seed locations. So for a lot of these, early on, we're tracking was using called the official server.com. And starting at around February 24th, we were seeing the threat actor actually improving the kit as it goes along. So the other API URL, so that prevents from seeing some of the messaging going through. And during this time, we also saw that they were testing some new servers. Some of them were test ones, they have also a new one that they're using now. The other page is init.js, it has the listing of many different amine panels. So that's where we got the intelligence about the single sign-on pages, about the different pages, the threat actor can use to send the users, it uses the Socket.io library to communicate. That's how we are able to listen to traffic. And it actually has a heartbeat setup. So it will know that the user is on the page or not. So the next part is about, yeah, a little bit about our automatic protection. As Dier mentioned, we monitor many different feeds, many different data points every day. So one thing is that we already know this cryptocurrency phishing actor, and we already blocked the backend server, official server.com, many days before the FCC was set up. And yeah, all these automated protection comes from a FIFO intelligence. Basically with all the things that we ingest, we look for patterns that are in a different phishing case, whether it's coming from the phishing page themselves, the URL patterns, the whois registration information, the IP, the hosting. So we gather all this information, we identify the pieces, and we add them to our rules. Any site, when we ingest it, when it hits the rules, it gets automatically classified. And as we classify new sites to protect our customers, if new features come out, then these are highlighted, and we add them so that as the fraud actor evolves, when it changes the features, we'll continue to track them and classify sites and protect our customers. So over to Dio. Thanks. Yeah, thanks, Xavier. So just to touch a little bit on the operator tactics here, and one thing that I want to mention here as well is, you know, this is obviously, this is one of many phishing kits that we follow, created by one of many threat actors that we're tracking. The thing that made this become very interesting to us was some of the unique tactics that this operator was using, as well as the fact that they pivoted from exclusively targeting, you know, consumers trying to take over their accounts, trying to steal their cryptocurrency, to targeting employees at Coinbase and Binance, and then eventually employees at the FCC. So that obviously is a very interesting change in tactic, one that sort of, you know, sounds familiar to many security professionals around, you know, scattered spider. So we saw sort of a similar set of tactics that are emerging here. Although in this case, I will, I do want to be clear, we do not believe that this group is directly associated with scattered spider. We saw enough differences in the phishing kit that was being used and in some of the other tactics that were in place to say that we believe that this to be a distinct group, but maybe rather more of a copycat kind of actor. So let's go into a few details about what's unique about this. So first thing I want to stress is, you know, Lookout customers were protected from this targeted threat before it even went live, because of a combination of the automation that we had in place, as well as the, you know, ruthless efficiency of tracking these threat actors and blocking all of the command and control infrastructure, tracking that infrastructure as it grows over time. You know, we were able to protect from this kind of targeted threat, even though there were, you know, anti-protection mechanisms in place, such as a cap shut, because we were able to connect the dots between this and the threat actor who we were already tracking, as well as, you know, the fact that we were already blocking this command and control server that was used to harvest the data. You know, the other thing that's unique here is, you know, this is really like a perfect recreation of the Okta sign-in pages, you know, for Coinbase, Binance, and the FCC. This isn't a generic impersonation of Okta. This is, you know, a customized, tailored impersonation. So time and effort was put in to copy a specific organization's Okta sign-in page to target employees of that organization. Then it's also really interesting that in this case, you know, we're seeing that this is something that's manually operated by the attacker. So, you know, essentially what appears to be happening here is the attacker is typing in the credentials that you're providing, that the victim's providing, into the, you know, legitimate Okta sign-in page in real time. And then they are seeing what they're being asked for next. And then depending on what they're being asked for next, they're redirecting the victim to a page that asks them for those, for whatever that exact next step is. And in this case, we see that this attack was launched primarily via SMS and voice calls. So again, going straight to the phone number of employees or end users of these various impersonated services. And one thing that was really surprising to me, you know, as we started to see really sensitive data flow through, you know, as we mentioned earlier, things like photo IDs, front and back of someone's ID and a selfie, you know, in some cases holding up a piece of paper that with today's date on it and, you know, saying, you know, past, before account recovery, you know, these were users who are clearly, they had clearly been tricked. And you know, we actually decided to reach out to some of these users, try to contact them. And from there, we learned that the attacker was actually on the phone with some of these victims while they were completing the phishing page. There was, you know, and the attackers described them as like American or British sounding individuals from call centers, like that they sounded like professional call center employees that were making these phone calls that had all the normal etiquette that you would expect. And, you know, in some cases they were even doing things like spoofing legitimate support phone numbers to impersonate, you know, specific organizations. So this is also a rapidly evolving phishing kit. So you know, you can see here just from the modified timestamps of, you know, the FCC specific example that the generic phishing capabilities were put in place, you know, last modified December 9th, then there was some generic Okta targeting capabilities that were added January 14th. And then on February 6th, which was one day before the attack itself went live, we saw FCC specific cloning added where it was then tailored to the specific organization that was being targeted. And these attackers were really, really good at exfiltrating extremely sensitive data. Usually when you get access to the exfiltration data from like a phishing campaign, there's so much garbage in there and there's very, and there's a lot of low quality passwords, like, you know, password one, two, three, like that kind of data in there. But we were seeing if someone visited the page, it was like a 50% or greater chance that they were entering a username and password and that it was looked like a password vault generated password, like these were savvy users generating good passwords. And then they were going and entering like OTP tokens, or even things like a full seed phrase for a crypto wallet, you know, things that you would definitely not expect a typical user to even be able to enter into a phishing page, let alone to enter with such a high success rate. And, you know, we believe that they were so successful at this because essentially the narrative story that they were weaving here. So if you go to the next slide here, you know, it is essentially a combination of phone and SMS based phishing that's occurring here. So the victims that we talked to, most of them were Coinbase users who were who were victimized by this same phishing kit. And what would happen is they would receive either in a automated phone call from an 800 or an 888 number, or they would receive a text message and they would essentially say something very similar. It would either say, you know, it's say something like your account's been accessed from a new device. And in this case, like Salt Lake City, Utah, if this wasn't you, you know, reply no to lock down your assets. Or in the automated phone call scenario, you know, it'd be like press one to allow, press two to block. And so, you know, of course, that's something we have all received before from a bank. You know, did you just swipe your credit card here? Did you just spend thirty five dollars at this gas station? That kind of thing. So this is a completely normal interaction for you to say, yes, I did or no, I didn't. And it seems totally harmless to say, no, I didn't do that. And then what happens is that's when, you know, in the phone scenario, they say, OK, someone from our security team, this is still an automated message. Someone from our security team will call you shortly to assist you in locking down your account. Also, a normal thing that happens with credit card fraud. Right. Or in the case of the SMS based attempts, you know, you reply no and they send you a phishing link to go and lock down your account. You know, as I mentioned before, when we talk to victims like they described, like as they were going through step by step, many of them, they received phone calls to help assist them through the process while they were on the phone with a real human on the other end who is helping them secure their account. They're sending them a link to a page that, you know, is is a phishing page. But you're distracted. You're on the phone. You are think your account's already been compromised. So you're trying to move as quickly as you can to kind of fix the situation. You click on that link. You're not necessarily paying as close attention as you would. And you get to a very good, you know, a very good phishing page. And some of the steps here, like if you look at the screenshot on the right here, it actually says to copy. It says that you're going to receive an email and to copy the link from that email and paste it in here. I mean, that's a complicated step for most users to follow. And, you know, the only reason why they're they're as successful at this as they are is because of the fact that they got that that, you know, direct one to one communication with that phone call with the user where they're able to help walk them through that process. And it's not the person on the other end of the phone asking for the password. It's the person on the other end of the phone verifying their identity by having them go through an extremely convincing phishing site, which is a somewhat normal process, you know, for for us to go through. I'm sure we've all experienced a support flow like that, where at some point, you know, I need to verify your identity. I'm going to text you something. I'm going to text you a link or something like that. And the other thing that was interesting is the narrative detail, like the fact that the device, you know, for example, if you're an iPhone user, they would tell you an Android device in Salt Lake City or if you're an Android user, they would tell you an iPhone in Salt Lake City or if you lived in Salt Lake City, they'd tell you Burbank, California. You know, this is all customizable. And the narrative flows through from the automated voice call that you get, the text message that you get, the phishing page itself and the person on the other end of the phone. They're all saying the same story to you. So it all seems perfectly connected together. And they're using that to build trust, you know, so that all of these things seem, you know, seem legitimately connected. But what's actually happening behind the scenes, if you go to the next slide here, is the operator is able to customize this experience in real time. So, for example. If they need a SMS message or if they're if you're going to receive a one time password via SMS, they can say, OK, it's it's was sent to a phone number ending in three, four, and it should be a seven digit code. So the operator who's on the other end of the phone with the victim can customize the phishing experience that they're seeing on their website that they're looking at in real time to whatever detail the operator needs to be able to get inside of that account. So it's like a fully customized experience and they can redirect them. You know, for example, they can customize what type of device it is or what location the unauthorized access was from so that they can, again, strengthen this story, build on this con and make it seem very legitimate, you know, that that you're that that this experience is actually happening to you and everyone's telling you a consistent story every step of the way. So just to give you if you go to the next slide here, just give you a sense of this scope and scale of this, I mean, this is even already like I'll say, go to our report for the latest IOC list. But I mean, there are hundreds of these sites that are being being stood up and it's rapidly evolving, more of them coming online every single day. You know, you can probably see here if you can read this small font, most of them, the majority of these sites are targeting crypto users, the vast majority of those trying to target Coinbase users. But the mixed in here are SSO impersonation sites, you know, as well targeting employees of, you know, Octa, Binance and or sorry, not Octa, the FCC, Binance and Coinbase by impersonating their Octa pages. So if you go to the report, we've got the full, you know, up to date list of both the phishing sites as well as the command and control servers that we're aware of. And we're constantly updating that as we're discovering new new information every single day. So obviously, this is a widely deployed phishing kit with a number of different motives. And this group appears to be quite successful based on the victims that I've talked to. You know, I've seen evidence to suggest that they've been able to steal upwards of fifty thousand dollars from individual users. And that's just a single victim. And we've seen hundreds of victims just from the exfiltration data that we were able to access. We've seen, you know, that there are hundreds of victims that have, you know, unfortunately, fallen victim to this very, very sophisticated, I would say, very sophisticated social engineering attempt. One thing that I think is really interesting about all of this is there was no exploit triggered anywhere here. Like there's no there's no security vulnerability that's being exploited to gain access, to move laterally, any of those kinds of things like that's not what's happening here. It's only that the humans, the humans are being exploited by being tricked to do things that they normally wouldn't do to give up credentials and other information so that attackers can go and easily bypass and take over their their identity, essentially, whether that be their personal identity to access their funds or their corporate identity to access whatever data they can legitimately access. So this, I think, perfectly maps to what Hank was talking about earlier around this idea of the modern kill chain, where it's ultimately about socially engineering users to be able to take over their accounts, get the access that they legitimately have access to move laterally within the organization from there and exfiltrate and, you know, eventually get to to the ransom step. All right, awesome, thank you, DR. Thanks for breaking that down. Thank you, Savio, for the more technical side of it. So we're coming up just with a few minutes left here. So we'll sort of start to wrap things up here. So there's sort of one thing I wanted to touch on here is what does all of this sort of indicate about the broader threat landscape, especially on the mobile side? But I think it's, you know, as as we're kind of talking about here, mobile is no longer sort of its own thing. It's sort of got to be it has to be thought of as part of that greater security strategy as you look at in the context of that modern kill chain and where it sits in the points of authentication and all that for anyone trying to to get into, you know, whether it's a legitimate or malicious actor trying to trying to get in. So the first thing here is that DR mentioned this at the start, right? The success of Scattered Spider, which is the group that successfully breached among many other organizations, MGM and Caesars last year, which made some big some big splashy news headlines. The success of that chain, basically that kill chain or that series of of of tactics and protocols, which we're seeing now with with this crypto chameleon kit will lead to more copycats. Right. Whenever you see the success of something, whether it's good or bad, people tend to copy it. Right. So it all makes sense. The second is that cybercrime groups are really branching out. Right. As as Savio mentioned, a lot of what we saw at the start and a lot of what we talked about here today was very focused on on crypto platforms. Right. Because it can be almost a quick smash and grab for these for these actors who want to make out like bandits with a few thousand dollars or like DR said, even some significant sums of money from individuals. So they're starting to understand that those same tactics, again, can be used to target the enterprise, as we saw with the fact that the FCC was was targeted, the employees that were targeted, we saw, you know, impersonations of like DR mentioned, the actual Coinbase employee login pages, things like that, where it's not just targeting consumers anymore. They're really moving to where there's more value, which is that enterprise data. And and like I mentioned at the start of this slide is really these modern phishing kits want to target or are being built to target mobile because we use mobile as, you know, the key second form of authentication whenever we log into, you know, our own our own corporate, whether it's Okta or whatever you use, if you want to either verify it, you get that notification on your phone when it gets pushed or if you're logging into something, you know, like for, you know, for example, like a crypto platform. I did the same last week when, you know, Bitcoin was going like crazy. I wanted to go look at how my various assets were doing. I logged in and went to the authenticator that I use, got the six, you know, the six number code. And and there you go. So it's such a key part of telling someone, yes, this is really me because the mobile device is so much a part of who we are and so much a part like it's just it's there all the time. It's next to us when we fall asleep at night. It's there when we wake up in the morning. It's in our pocket all day long. So you can understand why mobile is really becoming the key target for those initial couple steps in these attacks. Second, the last one here is that the combination of voice and SMS phishing is really becoming the norm. It used to be something that we would see in these sort of more sophisticated, you know, groups that really wanted to put more, you know, had maybe a little more money backing them or, you know, they were just kind of OK with taking a little more time. Now it's really becoming normal, right? Getting that that combination that DR mentioned of, you know, reply. And if you did not access your account from Salt Lake City, Utah, and we'll give you a call and then suddenly get a call from an unknown number, which, of course, we all ignore these days. But if you're expecting it, then you'll actually pick it up. And on the other end is somebody who sounds, you know, perfectly, you know, they basically hire native English speakers that sound like, you know, US or UK based professionals. And that's, again, becoming a norm. It's not it's not crazy. So it's just interesting that we're seeing this one particular use case as an indicator of broader things happening across the greater mobile threat landscape. So last thing we'll leave you with is how Lookout can help. So the first one is this, which is a free it's a mobile phishing risk assessment. So basically, in order to set this up, you would contact us and a member of our engineering team would work with you. And there are basically two levels of this. So what you do is that you work with our team and you can run simulated phishing tests via SMS. And the cool thing is that you can kind of two levels of it. Right. And again, it's all it's all the same. It's all just basically a free assessment on your part where you can do sort of a lower touch one where you just send them a link, you know, send them a link from an unknown number that maybe says, you know, hey, thanks for showing up at the conference. Tap this link to to get your free drink. Right. A lot of us are going through company or sales kickoffs right now. So maybe that's something you would do. The other one that we're that we're doing is that we're actually going a step further and seeing if someone will fall for something like what Crypto Chameleon does, where we ask for not just ask you to tap the link once you're in there, ask you to both log in and enter those SSO credentials. So this is something that's that's really valuable. You get a report back that says the percentage of employees that engaged, what devices they came from, how long it took them to actually tap the link, because that's something we see on mobile as we're all programmed to just receive the message, read it, tap the link and on we go. So so this is a great a great way to understand where your your own organizational risk may lie in mobile phishing. And then the last are three things here. So within our Lookout mobile endpoint security solution, we have phishing and content protection across all basically all offerings of that of that solution. So what it does is that protects anyone with Lookout MES on the device from mobile phishing attacks like this. It also enables admins to implement deny listed websites and content. So if you're already using something like a secure web gateway and you have a list of URLs that you don't want your employees going to, then you can drop that into the MES console. On the flip side, if you have our secure web gateway, you can take the sites that you've denied listed from the MES console and drop into the into the SWIG. So it works both ways. And then as Savio went over, there's a lot of automated protection that goes into this so that that's being pushed to these devices automatically, you know, over the air without needing to update the app or anything like that. The second is that we do have services tied to our threat intelligence team. So there are a few tiers of this. This is really to help enable, you know, a dedicated SOC team or a team that's really focused in on what's happening across across the organization and being able to access that data and that research data that even Savio and his team use within a research console in the app. So this is just it's something that, you know, we're we're seeing a lot of use from global organizations, especially those who operate maybe in riskier parts of the world, but also from teams who just really understand that mobile is a critical part of that greater security strategy of that EDR endpoint detection response strategy and need to to be able to extend there. The last part there is that you get advanced noticed on on activity of these advanced threat groups that we're tracking out tracking on a daily basis. The last one that I'll actually have DR go over real quick is our new digital forensic service or DFIR piece. So, DR, if you want to cover that real quick. Yeah, so look, we've obviously, you know, we've been mobile experts for quite some time now, and we've had many different organizations and individuals reach out to us over the years, you know, believing that they have been breached, that something had happened to their mobile device or something had happened to their organization. And, you know, we've now started to formalize that offering. So we now actually offer offer our own DFIR service offering. So, you know, if you believe that you've been breached or you believe that your mobile device has been compromised in some way, Lookout can help. If we can analyze that device, we can help determine what it is that that that's happened on that device. You know, we were intimately involved in this process for many high profile devices that have been infected with advanced surveillance where things like that in the past. And, you know, this can also be used to help understand, you know, especially in many of these cases, you know, there's sort of a in many of these sort of like modern breaches that we're that we're seeing. There's sort of a somehow the attacker got the credentials, but we're not quite sure how. And then they use those credentials to gain access to an account. We can help answer that early part of the question. We can help answer how did they get those credentials and, you know, and help, you know, put in help your organization put together a plan for how to prevent that from happening in the future. Awesome, thank you, D.R. All right, folks, we are up on time, so unfortunately we're not going to have time for Q&A kind of post session here, but we will if we didn't get to your question throughout the session, we will follow up with you directly. Also, please feel free to to reach out to us with any questions like D.R. mentioned, there is a technical blog that we wrote on the Lookout Threat Lab. So if you go to Lookout.com, you'll see there's a little button in the top right. This is Visit Threat Lab and you'll see the Crypto Chameleon link right there. So please do have a look at that. Again, thank you all for joining us. Thank you, D.R. and Savio for for being on. And thanks, everyone. Hope you have a great rest of the day. Thanks, everyone.