Transcript
Modern day security strategies strive for a zero trust approach, building on the trust, but verify principle to a standard of never trust, but always verify. But even those with professional paranoias like myself and Tyler end up trusting some things more than others, and trust itself can become an attack surface that attackers look to exploit. In this episode, we're talking cow fishing, a rising trend where fishing lures are delivered via calendar invites. In a working world of never ending meetings, you start to trust your calendar, the 15 minute reminders and the forwarded chains of invitations. But that's just one part of the trust that it seeks to exploit, and equally interesting are the controls that it's able to evade. To help us understand the rise of calendar fishing, my co-host Tyler Wreggeley and myself Josh Davis are joined by Fortress security engineer and member of FIRE. On the Art of Security podcast for cow fishing, we have Daoud Jawad. Thank you for joining us. Hello. Thank you very much for having me. So I think I've kind of introduced you quite well there, but I think the one thing that maybe is left out is you're actually a member of our corporate security team. So a lot of our research comes from sometimes people doing, analysts doing work for customers as part of the services, but you're actually more focused on keeping our employees secure, right? Correct. Yes. So it's Fortra, Fortra corporate and all the companies underneath Fortra, but mainly internal. Nice. It's like keeping you busy with people trying to attack the security company. That's a nice supply chain compromise. You go for the cybersecurity company and then you can crawl anywhere really. So we definitely are quite a bit of a target, which is why we can get quite a bit of very nice intel. Awesome. So before we jump into the topic at hand, just to understand why we're here talking about this today, what kind of brought you to talk about this technique and get it out there in the public, I guess, and not just keep it in your run books in corporate security? I think it was important for this to be shared because this is, from what I see, a new full phishing technique. So we've seen a few variations of it, but realistically this could be used in a range of ways. And we've seen a big trend going up in the past year. So this is why I thought this is a very important thing to be shared out there and we're comfortable to share it further. Awesome. So calendar phishing. Tyler, where do you want to begin with this one? Or cow phishing? I think it rolls off the tongue a bit better. I oddly enough had somebody the other day as we were working on, so a little bit of a spoiler alert for people listening to this, but Dowd has actually written a blog post for us for cybersecurity awareness month that we'll be releasing on calendar phishing. And we were playing with some graphics and titles and it said cow phishing. And because people don't necessarily immediately go from cow to calendar, the first question I got was, why did you drop an L off of call? They thought it was a voice thing. So just an interesting little aside about cow phishing and how some people's minds go when they see that word written as one word. So I thought that was interesting, but calendar phishing fascinates me for a number of reasons, but it has for a while. And I think that's one of the things I want to talk about is how the surge that you're seeing right now differs from six, seven years ago when we first saw calendar phishing popping up a lot targeting like Google users and iCloud users. And what differences are you seeing between sort of that attack timeline and what we're seeing now? Yeah. So I think in terms of the difference and the timeline itself, I think one of the main vendors that I've seen was pretty much Google. I've seen it go quite far and then it sort of stopped being as popular, let's say. But I think recently the reason why this has happened is because first, email is quite hard to attack. There's lots of direct settings that are already enabled, default settings. People are more vigilant. They are more trained overall. So there's a lot more control into the email side. Calendar feels comfortable, feels cozy. You're sort of safe over there. You don't think that anything could happen over there, right? So it's a pretty easy way to abuse the trust of the calendar area. So it can be that, but also all the new features that are coming in into the calendar. The new features that just came, such as using HTML, actually having attachments into calendar invites, which lots of people don't know. Not being spoof checked, so you can actually spoof into the modified actual calendar attachment and spoof it quite easily. So some of the things that are into the email side already built in and quite well set up are not really that set up into the calendar side. So I think that's kind of the main reason why I'm seeing an uptick. So one of the things that you didn't mention, which was one of the things that came to mind for me, was assistants. Whether that's an AI assistant integrated into your Gmail, for example, or the big one for me, I'm an iPhone user, go iPhone. I'll quite often get the little prompt that says, I noticed you had this meeting with a very brief summary and just an add to calendar. And I don't even have to look at the full calendar invite. I don't even have to see it. It's just a little pop up that I'm somewhat trained now to just say yes, add to calendar. And do you think that those technology enhancers that are designed to ease our lives are creating this additional risk? Absolutely. Yeah. There have been so many proofs, especially regarding email and now calendar, that those can be poisoned, those can be misused. So yeah, I think that part can be quite abused as well. Yeah. It's almost like it's meeting you so often now. I mean, ever since we've gone post 2020 to a lot of online meetings, calendars are inundated. I think sometimes we could be saying we're drowning them, there's too many. But those reminders, I was going to be able to AI rant, but I'll hold myself back because I hate it when I finish a meeting and I start doing some research and it summarizes my last meeting with all the questions that I raised, that's not what I'm looking for in LM. But point being, it feels a bit like a reverse boy who cried wolf, and that we are getting so many interactions with calendars on such a regular basis that the guard is let down slightly. And so I think with these techniques, I'm either really excited, sometimes maybe wrongly so by the really complex exploits that chain various different attacks. I find that fascinating. And then I'm reminded, Tyler's in the back of my head saying, yeah, but what's the exploitability here? Is this actually something we should really care about? But this one is the complete opposite. This one almost feels so simple that I was quite surprised at what you were seeing though. So yeah, I think there was a bit of an evolution, right? The first ones you were seeing were the classic, hey, call to action, right? It was domain renewals. Yes, domain renewals. Exactly. Yeah. Yeah. And that still smelled a bit like fishing for me. But as we dug into it, you start to see some more subtle ones, which I think really lent into that exploitation of, because of, yeah, I'll still, if I get a calendar invite, it's saying something urgent. I'll still be a little bit alert, but if it's something more benign, I think that it doesn't set off the alarm bells. So yeah, tell us a little bit more about what you're seeing on the different types of lures before we get into how it takes you on to the objective. Yeah. So I've seen four main ones, realistically, variations to the four main call fishing types. One is legitimate vendor delivery. So Google Calendar is the most popular, has been, and possibly will be very popular. And the benefit of using that is that it can be sent from a fully-fledged vendor, clean source. Sometimes even the attachments that are referenced on the calendar can be hosted on Google servers. So basically the URL click just is free and you go straight into it. So that would be kind of the most popular one I've seen. Another one I've seen is actually body-focused. So the calendar invite itself, the body of the calendar is actually used as the lure. So it can be, it can have HTML. Not a lot of people know, but calendar invites can have HTML in the body. You can render a very nice tailored invite with a lot of information, maybe research on the exact user, have a nice content. And the target generally is a click in the actual body, in the HTML, you actually have the URL embedded and you just say, I don't know, review this attachment or something on those lines. Third one I've seen is attachment-based. So everything in the invite itself points you to the attachment. So calendar invites can actually pull from the email. The attachment itself is referenced in the ICS itself and everything is sort of pointing you to that attachment. Nothing in the body really, location might actually point to again, look at the attachment. So everything kind of points you over there. And the attachment generally would be, at least from what I've seen, an HTML attachment, which would open a fake page, input your credentials, sends it to an attacker-controlled server. And now the most interesting one, the last one is a spoofed-based attachment. So the attachment can actually be modified. Essentially an ICS file is just a number of instructions to the receiver client, which then gets auto-processed and actually creates the invite itself. That can be modified, can be changed. And generally you can actually, let's say, change the actual organizer to the CEO name and send it to anybody. It's not spoof-checked because it's not email, it doesn't have the email checks. So it can be sent, it's fully spoofed, and generally that would be not one. So the initial invite is just to kind of create that trust, maybe join a meeting, maybe reply in some way, that would be kind of the target. So the goal then, before we dive into some of those, is it often, is it always credential compromise or is it going to be, is there other instances or other objectives? Mostly credentials in some way, or not just credentials. It can be session tokens. We have seen consent-based device code phishing also being used. We have seen QR code-based phishing. So credentials in some way, or at least access to the account. Also it can be creating the trust for maybe getting information from the users. So actually information. So response stuff too, where they just kind of get that conversation going with you. Yeah. Yeah. Okay. So I think one of those ones that really stood out to me is the HTML kind of rendering in the invite. And I think you gave an example, or showed me one, which was rendering a kind of perfectly identical login page. And yeah, going back to that point at the top of my, the reason I introduced zero trust in the introduction, it's not just to try and get some more clicks and make the marketing team happy. I think that part of this is we verify ourselves and identity a lot more. I get a lot more logging prompts to make sure that it is still me who knows the password and has access to my MFA device. And somebody hasn't strolled in and started using my computer. And then that also desensitizes us to a degree to these very legitimate looking login pages. And I think in ConsentFix, they actually use the legitimate, you know, Microsoft.com or Google.com page, and then they steal the token afterwards. So those usual warning signs aren't there. But the evasion part I think is really interesting. And yeah, I talk to a lot of people who have these new browser-based protections, because a lot of what we're seeing is you click on a link, it renders in your browser, and they're like, hey, we'll stop it from stealing the credentials or stop from stealing the token or work out if it's a bad DNS request, and we'll sync it. This kind of bypasses that. So bypassing the new battlefield, which is the browser, and then also the previous one, which probably the endpoint was like EDRs. So yeah, I think that it seems very simple, but it's also a very clever way to evade the email filters by using the legitimate sender abuse. And then for the objective, it's exploiting our trust, but it's also evading the areas that were heaviest. So Tyler, maybe that's why we're seeing a resurgence of this now, because this old battleground actually is one that's been, I don't know if I want to say neglected, because actually it's a new feature, right? The HTML rendering that allows you to do this, but we're back again. It's almost like the fashion kind of recycles itself with slight iterations on it. Yeah, I agree. And I think maybe in the past, it wasn't that as popular because there weren't that many options to actually utilize it at the moment, because you can do all these new things. Obviously that gives the attackers a lot more bypasses, realistically. There still is, for one of them, there still is a web-based kind of reach out at the end to actually seal the credentials. But realistically, you're bypassing so many of the normal checks. And I have also seen that vendors have sort of responded even to the old ones, but not fully. They've seen some of the attacks. They've said, okay, you can actually now not accept from normal senders or senders that you don't know or are not regular on the Google side, or you can turn off the auto-processing. But now they're backtracking. For example, Microsoft removed the auto-processing disable on the user side. So in the new Outlook, you can't turn it off anymore. So it looks like there was some improvement for a while, and then they forgot, and now it's going back. So it makes sense why it becomes open. It's a balancing act. You can't block real invites, or the business can get upset, eh? Yeah. It's pretty tricky. That's one of the mitigation steps, and it's quite tricky. And I can understand why fully disabling is quite hard. But I do have also ideas on how it can be done safely as well. Should I run through one? And podcast-level recommendations. If you do want full recommendations, Dao's got a fantastic article that will give you loads of steps you can actually implement. What's the big win for you that you think you can tell everyone on how to stop these? Yeah. So as I said, disable auto-processing, you can do it. You can do it on a tenant level. So admins can actually do it for the whole group. Obviously, that's pretty tricky. I can see that some of the key teams that get a lot of these invites externally might not be able to implement that, such as sales, PR, things on those lines. So you can restrict, be quite constrained into what you restrict. But one idea that popped into mind was you can put a detection for anything that has ICSs, put them into a folder called calendar invites into every client, let's say Outlook. Disable auto-processing and users can go into this separate folder, review it, and accept which actually puts it into the main calendar. That will be an easy sort of middle ground between security and functionality. You're asking end users to do more work. I just hear... Yeah, I know. I know. It's not going to happen. Yeah, it's not going to happen. I know. I know. I just gave it. It's kind of a middle ground. We've, you know, I have a bit of an ego. I like to think that not just security folks listen to this, but that we have a lot of everyday viewers, if you will. I'd like to think that's true. If it is, leave a comment. But for those people, like, is this a risk to my mom sitting at home or to a college student sitting somewhere? Or is this a risk that only applies to those in a corporate setting? I think this is a risk to everybody. Anybody that has a calendar and sort of has invites in any way or reminders in any way is susceptible. Susceptible. Susceptible. Yeah. I don't know why I struggle with that word. It sounds fast. Susceptible to it. Yeah, the reason I ask, I don't know if anybody's seen this, I saw a mini doc on it and a couple articles on it. Has anybody been following the hyper-scheduling trend among college students? Oh, wait, is this like min-maxing and grindcore kind of stuff? So this is that it doesn't matter what it is, whether it's, you know, when you're going to sleep, when you're going to go for a walk, when you're going to do your laundry. You put it in your calendar. And it's gotten to such the point that there's a, we saw a news segment, my wife and I on this, where this is now how college students are asking each other out. They will send them a calendar invite that says, want to grab coffee. So they don't have to fear that immediate personal rejection. And it just, to me, that, that opens the door in so many ways to new attack vectors for cow fishing. Because if you're getting these random emails inviting you to, you know, on a date or for a coffee and just a, you know, a social interaction with a group of friends, even, it might be, Hey, let's play among us online, sign up for this server or something like that. And so it just, I think there's a lot of people out there using calendars in a non-corporate setting. And I want to make sure we get the point across to them that, Hey, this is a risk for you as well. And something you definitely need to be paying attention to. That's a really good point because I'll be, when you first posed that question, I'm glad you didn't ask me because I would have said it feels a bit more corporate. I think some of what we've talked about is, is the familiarity that we've had in the business world with emails and constant, constant calendar invites, sorry. And I thought maybe at worst you might get a, it'd be the notification that, Hey, brings up in 15 minutes before this, this is in your calendar. And that's the only time that someone might actually interact with it because you don't check your calendar. But I have, sounds like I am completely wrong if people are using their calendars in such a way. And I thought they were just using it to log their own stuff, like an empty invite. I do that often to structure, you try and block out some time, but wow, the dating world, we've gone, had Tinder. Now we've got calendar invites. I had no idea. I realized how old I was when I saw that new segment. That's what that told me. Same boat as you. Yeah. Yeah. Go ahead. Sorry. Yeah. So we also see, for example, now when you go and have a doctor appointment, um, GP appointment, you generally get a calendar invite as well. Go and you go to a concert as well. Would you like a reminder? Sure. You join a conference, you get the calendar invite as well. And you download that and you, you get it straight on, which is another thing that I was going to talk about, uh, which is the evolution, uh, of hell fishing, which is actually downloading it yourself as you do, for example, for conferences and you just put it in your, in your calendar yourself, you already gave it a bit of trust, right? You haven't even seen the calendar invite yet. No lure, no nothing. Maybe just obviously the webpage and you add it yourself. So there's loads of things I think that we legitimately get as well, but with this, um, calendar invite dating, I see it, I see it being used quite a bit. You can crawl the users, Instagram, Facebook, whatnot, see who they interact with, spoof, maybe the guy or the girl or whatever that they like. They get the invite from them. That's it. Calendar romance scams. Is that where we're headed? Because I get a lot of emails that just in my personal, it's just spam from all the marketing and vendors who have my email, but I don't get as many calendar invites. So you do tend to take more note of those and interact with them. And maybe you do a point of research because I have, we looked at some of our data that we have of in Fortra for all that, uh, suspicious email analysis service. So it's where the email hits the inbox and it was the top in the top three, the second biggest sender is Google calendar. And that, so that doesn't even include all the other calendar, uh, invite zoom or Microsoft and beyond. So it's, it's huge. The stuff that's hitting the inbox and actually getting reported as malicious as of right now. Next point, next thing we need to investigate is, uh, Hey, let's set up some of our university contacts, Tyler college contacts, see if they've got any information on their email service for us. That would be, that would be interesting to see. Definitely would be. And again, you can, even for, for students, I can see this as a, as a risk because loads of the current, um, losses, uh, even when I was at uni, they were still all in the calendar. You would get calendar invites or you can add them and you can very easily find where they're studying and just spoof that, send it through. So on the invite, join this meeting. That's it. It's, uh, you know, in, in sticking to the college one, cause I just, it made me think of it. Um, it, it shows how critical, uh, the compromise of a single professor's account could be because if, if I compromise my professor's account and then use that account to email every other student that that professor has contact with a calendar invite that steals credentials, I could harvest hundreds, if not thousands of credentials, you know, if they're those introductory classes of hundreds and hundreds of people, um, of credentials, because you're going to trust where it's coming from. And I think that that even adds more risk, right? Like you get a lot of random calendar invites that show up and yeah, they're, they're questionable. But when you get one compromised account that you trust sending you calendar invites now that just increases that risk even more. So it takes it to another level. Why chain calendar compromise is that so we should erase to define that term, maybe log it in MITRE. I think, yeah, it's, it could definitely head that way based on the popularity and the lack of response from some of the vendors. Yeah. Yeah. That could be very easily seen. So you flip it on its head as well, because I'm trying to think we focus on the younger generation, maybe, but the older generation, I'm just thinking of my parents, they love their physical calendar. You know, if I tell them something's happening, then they have to walk over and scroll on it a pen. So there's a level of affinity for calendars. I don't know how much they use the digital calendar, but I could see it. Yeah, I could see that step not being a huge, huge lurch. It's not drastically different concept that they might already be used to. So where do we think the risk is there? So I have a thought. And I think the interesting one goes back to the whole auto processing of calendar invites. Because if we take and I know you're much younger than me, Josh, this may not apply to your parents, but it does to mine. If we take senior citizens that are getting forgetful and we send them a malicious invite, this could actually be even more dangerous to say, hey, you have to bring your car in for repairs. And all of a sudden their phone pops up and says, don't forget garage appointment. And they drive to the garage. I mean, this could be, I don't know about everywhere else, but here in Toronto, car thefts are massively on the rise. There's carjackings. It feels like every single day. And now you can take people who are later in life and may have nicer vehicles as a result of that and send them down a set path where, you know, they're going to be to physically hire, you know, carjack them and remove their car because, you know, you've said that they're just driving along thinking they're going to a garage appointment, not paying attention. So to me that introduces a whole new physical risk to this. They have the skills to, you know, take that trust, never trust and always verify approach. I feel like everything feels untrustworthy to them. And so they, that kind of means that their alarm bells are never ringing it always. They always jump in and fill out the extra steps and don't know what's going on. So yeah, I'm kind of hesitant now because my parents are on that trajectory of getting a bit more forgetful and setting up reminders for them or sending invites to them. I might be a little bit more skeptical of doing that now. But yeah, this is the solution then that we, you talked about from a CorpseX side perspective rather how to kind of add controls to prevent this. Is awareness of this threat the way to combat it or should we expect as this kind of grows and grows that maybe these calendar companies need to take a little bit more of ownership, accommodate facilitators rather and help filter or stop these things being quite so convenient for us and for attackers? I think realistically user education in this case is going to be the most effective and the thing that we could actually do right now. Response, we have seen some response. And again, we have seen some backtracking as well when it wasn't used for some time from the actual vendors. So realistically, just the education, putting into context, even discussing as we are discussing right now and actually putting into context that kind of broadening what calendar can be used for, I think would be the most effective and useful. Always verifying, verifying by different channels, double checking, checking the URL where it goes, even though those are not reliable at the moment as well because everything is kind of trusted. So we can be spoofed, sender can be validated, URL can be clean, content can look perfect, right? So it's kind of, I think that's something I was going to turn to Tyler, you have a lot of, you have experience with security awareness training, which I believe is more focused on corporate, but also does cross over into people's personal lives. Have we conditioned people to look out for certain indicators? Like Daoud, you say something awesome, which I was hoping you're going to say today, where you say, yeah, they don't get you to trust the source, they get you to trust the workflow and pushing you into these legitimate senders and legitimate workflows. People are loaded to some false sense of security because they're more used to looking for urgency. They're more used to looking for like unusual senders. And these kinds of classical indicators aren't present in this type of, this evolution of this older calendar phishing threat. It's an interesting one because we've even, at this point, started to mistrain people for email phishing because of the improvements that AI has made. You can't say, hey, look for the typos, look for the phrases that don't make sense anymore because those don't exist because of AI. So we've already started to mistrain people and we need to, we need to reset the baseline and the baseline has to be built around what you can and can't trust and how to know, you know, trust but verify. You said it at the top of the episode and it really comes down to that. And I think, you know, for the younger generation, I just heard a story not long ago about two people being tricked into becoming drug mules and they had no idea until after they were home and they were like, oh, I was just asked to go pick up the suitcase and bring it to another location. And some of them are in jail right now as a result of it. And then the elderly who constantly fall for, I mean, there's a reason they're called grandparent scams, right? So we have to figure out a way to train. We truly do a really good job of training the corporate world and we do a really bad job of training society and we need to do something there. And I think we need to put to your point about, you know, it's got to come down to these calendar providers and I think I'm going to name them. There's three big ones, right? Google, Microsoft, and Apple. You're probably using a calendar provided by one of those three vendors. And I think we just need to issue a challenge. The race starts right now. Who's the first one who's going to put in calendar protections so that we're protecting society and it's not just people like Dowd protecting corporate environments, that we actually have the vendors protecting the end users at home. And until they step up and do something, we're going to find ourselves in a really bad place. Great. And that's an interesting place to be because it is the cat and mouse game where they get to alter their techniques. And I'm not sure if those companies quite have the agility that we need to deploy some of these things. But Tyler, you and I butt heads sometimes over Android versus Apple on the mobile phone thing. So I'm rooting for my corner. Hopefully when we do come to do an episode around that, I have a point to use against you. We all know Apple will win, that's okay. Okay. Well, it's really great to have you on. This conversation has gone a few areas I didn't quite expect it, but I think it's a great testament to how accessible this threat is that we were able to kind of stretch it beyond your corporate research and see what's attacking a security company and then expand that to how it could attack the rest of the world. No doubt it is, but the data just lacks a little bit there. So maybe that's something to make a prediction now. We might be able to point back to this episode. Point zero. We predicted it, we saw it. Are there any kind of key takeaways that you want to share with the world or kind of summary of this kind of threat or just a little bit of wisdom as to how both the corporate and personal world, we can all stay a little bit more security so that we kind of share that art of security and keeping yourself a little more secure. There's one evolution that I've seen, actually, which sort of uses calendar phishing in a way, but in the web, and I found it very clever, which is it uses a sort of tier trust of the internal users. And what the way this looks like is it will be a prospect that would reach out to somebody that is not sales related. They would ask for somebody in sales to actually to connect for this user to connect with the sales user. And the lure would be an actual book a meeting. So you press book a meeting. It goes to a web page with a calendar. You have to choose the date and time. It will be a Teams logo underneath. So it will give you the idea that it's Teams. And before you actually press accept, you have to sign into your Microsoft to sync your Teams, right? Is that how calendars work? Well, clearly, the recent ones, maybe. I don't know. No. Yeah, it's a very clever way of misusing this idea of syncing between apps and users can really fall for it. And I use the word tier trust because you're using an internal user to forward to another user. And you would assume as the end user that actually the first person validates the bid. So it's an actual legit prospect when in actuality probably isn't. To go back a bit, it's almost like when Tyler used that example of a professor's email being compromised and you trusting that sender. It's achieving that, but without having to compromise anyone's email account, just getting them to forward it on and you trust ex-colleague who sent it to you and disregard the original source. Yeah, exactly. And that brings me to my point, which is there has to be a bit of a zero trust mindset to everything, including, unfortunately, maybe your colleagues or the customer that you interacted with, your teacher. If something feels off or unexpected, maybe double check, validate, validate with somebody else that is in the loop, but not exactly the person that messaged you. So that would be a good double check of this. Okay, so I like that kind of takeaway. And I'm thinking that took me back a little bit to days first starting in the SOC and everyone playing ruthless but harmless pranks on each other whenever you left your machine open. So maybe the call to action is students, people in your personal lives, play pranks with each other's calendars. Let them know that, hey, this isn't a super safe space always. People can mess you up. So do it in a harmless way. Actually, maybe that's a great way we can get people to question and not always trust, but actually start verifying. I think it's a great conversation to have. I think I like how we moved on to this being more applicable than maybe where the research And I think that's the whole point of security research, right? You find it in one instance and then you scale out to where else it could be applicable so that we can all share from the learnings that you had in that corporate setting. So thanks for putting the work out there. We do have a few blogs from Daoud and from the FIRE team on the Fortra blog. So you can search cow fishing and those will start popping up. Yeah. Otherwise, I think this has been a great episode of the Art of Security. And Daoud, thank you very much for sharing your work and letting us have this conversation. Thank you very much. It was very fun. Thank you for having me.