US-CERT- Enhanced Monitoring to Detect APT Activity Targeting Outlook Online

Started by Netwörkheäd, July 16, 2023, 12:07:08 AM

Previous topic - Next topic

Netwörkheäd

Enhanced Monitoring to Detect APT Activity Targeting Outlook Online

[html]

SUMMARY


In June 2023, a Federal Civilian Executive Branch (FCEB) agency identified suspicious activity in their Microsoft 365 (M365) cloud environment. The agency reported the activity to Microsoft and the Cybersecurity and Infrastructure Security Agency (CISA), and Microsoft determined that advanced persistent threat (APT) actors accessed and exfiltrated unclassified Exchange Online Outlook data.


CISA and the Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory to provide guidance to critical infrastructure organizations on enhancing monitoring of Microsoft Exchange Online environments. Organizations can enhance their cyber posture and position themselves to detect similar malicious activity by implementing logging recommendations in this advisory. Organizations that identify suspicious, anomalous activity should contact Microsoft for proceeding with mitigation actions due to the cloud-based infrastructure affected, as well as report to CISA and the FBI.


Download the PDF version of this report:

Let's not argue. Let's network!