பாஸ்வேர்டு மட்டுமல்ல, OTP-யும் இனி போதாது — இந்த Attack-ஐ புரிஞ்சுக்கணும்
Basic phishing awareness நம்ம எல்லாருக்கும் தெரியும்: suspicious links click பண்ணாதே, fake websites-ல் பாஸ்வேர்டு enter பண்ணாதே, Two-Factor Authentication enable பண்ணு. அந்த last step — 2FA, உங்கள் போனுக்கு வரும் OTP — எல்லாமே wrong ஆனாலும் catch பண்ணும் safety net-ஆ இருக்கும்.
ஒரு phishing technique இந்த 2FA-ஐயும் completely defeat பண்றது. உங்கள் போனை hack பண்றதில்லை. OTP intercept பண்றதில்லை. ஆனா நீங்களே Microsoft-ஓட real website-ல் voluntarily ஒரு code enter பண்ணும்போது attacker-கிட்ட உங்கள் account-க்கு permanent access போகுது. இந்த attack-ஐ device code phishing-ன்னு சொல்வாங்க. 2026-ல் இது 37.5 மடங்கு grow ஆகியிருக்கு.
நீங்கள் அல்லது உங்கள் company Microsoft 365 — Outlook, Teams, SharePoint, OneDrive — use பண்றீங்களா? இது exactly எப்படி work பண்றது-ன்னு தெரிஞ்சுக்கணும்.
Device Code Phishing என்னன்னு — Simple-ஆ புரிஞ்சுக்கலாம்
OAuth 2.0 என்பது modern apps-ஓட login system — Google அல்லது Microsoft மூலம் sign in பண்ணும்போது background-ல் OAuth handle பண்றது. OAuth-ல் ஒரு specific part இருக்கு — Device Authorization Grant. இது keyboard இல்லாத devices-க்காக design ஆனது: smart TVs, printers, IoT sensors, streaming boxes. Netflix-ஐ TV-ல் sign in பண்ணும்போது TV ஒரு code காட்டி phone-ல் website-ல் enter பண்ணுங்க-ன்னு சொல்றது — அதுதான் device code flow.
Attackers இந்த flow-ஐ weaponize பண்றது discover பண்ணினாங்க. Attack step-by-step எப்படி நடக்குது-ன்னு பாக்கலாம்.
Attacker Microsoft servers-கிட்ட device code request அனுப்புகிறார். Microsoft legitimate code return பண்றது — ABCD-1234 மாதிரி. Attacker உங்களுக்கு ஒரு email அனுப்புகிறார் — Microsoft Teams, Adobe, DocuSign, SharePoint, அல்லது construction bid notification மாதிரி pretend பண்ணி. Email சொல்றது: உங்கள் identity verify பண்ண அல்லது shared document access பண்ண real Microsoft login page-ல் — microsoft.com/devicelogin-ல் — provided code enter பண்ணுங்க-ன்னு.
நீங்கள் real Microsoft website-க்கு போகிறீங்க. உங்கள் actual Microsoft credentials enter பண்றீங்க. 2FA complete பண்றீங்க — OTP வருது, enter பண்றீங்க. Microsoft எல்லாத்தையும் correctly verify பண்றது, access token மற்றும் refresh token create பண்றது — device code hold பண்றவருக்கு கொடுக்குது.
அது attacker. இப்போ அவருக்கு உங்கள் Microsoft 365 account-க்கு full access — Email, Teams messages, SharePoint files, OneDrive documents — எல்லாம். Worst part: நீங்கள் பிறகு பாஸ்வேர்டு change பண்ணாலும் இந்த tokens valid-ஆவே இருக்கும். Password reset attacker-கிட்ட இருக்கும் tokens-ஐ revoke பண்றதில்லை.
2026-ல் ஏன் Explode ஆனது — Phishing-as-a-Service Kits
Device code phishing 2020-ல் first document ஆனது — state-sponsored hackers மற்றும் financially motivated criminal groups use பண்ணியிருக்காங்க. 2026-ல் change ஆனது: accessibility. EvilTokens என்ற phishing-as-a-service (PhaaS) platform emerge ஆனது — technically less skilled criminals-கூட sophisticated device code phishing campaigns run பண்ணலாம், underlying OAuth mechanics understand பண்ணாம. Just subscribe, lure template pick பண்ணி, campaigns run பண்றாங்க.
EvilTokens alone இல்லை. குறைந்தது 11 different competing kits இப்போ circulation-ல் இருக்கு. VENOM device code phishing plus adversary-in-the-middle capabilities offer பண்றது. SHAREFILE document transfer themes use பண்றது corporate employees-ஐ trick பண்ண. CLURE SharePoint-themed lures anti-bot protection-உடன். LINKID Microsoft Teams மற்றும் Adobe themes Cloudflare pages மூலம். AUTHOV Adobe document-sharing lures. ஒவ்வொரு kit-உம் slightly different evasion techniques-உடன் compete பண்றது.
Scale already significant: ஒரே ஒரு documented campaign 340-க்கும் மேல் Microsoft 365 organisations-ஐ target பண்ணியது — United States, Canada, Australia, New Zealand, Germany-ல். DocuSign impersonation, voicemail notifications, Microsoft Forms pages use பண்ணி, February 19, 2026-ல் first spotted, accelerating pace-ல் cases தொடர்கின்றன.
Indian Corporate Users-க்கு ஏன் High Risk?
India world-ஓட largest Microsoft 365 user bases-ல் ஒன்று. IT services companies, BPO operations, financial services firms, healthcare providers, government contractors — Infosys, Wipro, TCS, HCL, thousands of smaller IT firms across Chennai, Bangalore, Hyderabad, Pune — Microsoft 365-ல் internal communication மற்றும் document infrastructure run பண்றது.
Device code phishing campaigns India-ஐ specifically target பண்றதில்லை — global Microsoft 365 users-ஐ target பண்றது, India-ஓட corporate users அந்த global pool-ல் part. DocuSign-themed lure அல்லது "shared document" notification corporate work பண்றும் யாருக்கும் convincing-ஆ இருக்கும்.
Financial stakes high: IT services company-ல் compromised Microsoft 365 account attackers-கிட்ட client project data, internal HR information, financial documents, email communication கொடுக்கும் — business email compromise fraud-க்கு use ஆகலாம். இது lakhs-ல் இருந்து crores வரை fraudulent wire transfers result பண்ணலாம். India-ஓட DPDPA (Digital Personal Data Protection Act) — organisations data breach suffer பண்ணினா regulatory liability create பண்றது — Teams அல்லது SharePoint compromise significantly more consequential ஆகியிருக்கு.
Target ஆகிறீங்களா-ன்னு எப்படி தெரியும்?
Device code phishing emails convincing-ஆ இருக்கும் — real Microsoft pages-க்கு direct பண்றது. Fake login page இல்லை — URL check பண்றது protection கொடுக்காது. ஆனா red flags இருக்கு.
முதல் red flag: நீங்கள் எந்த device-உம் connect பண்ண try பண்ணாம microsoft.com/devicelogin-ல் code enter பண்ணுங்க-ன்னு unsolicited email வருது. Legitimate device code prompts நீங்கள் physically new device connect பண்றும்போது மட்டும் appear ஆகும் — TV, printer, streaming device. Email-ல் code வந்தா, நீங்கள் device connect பண்றதில்லையா — அது attack.
இரண்டாவது red flag: urgency language. "உங்கள் account suspend ஆகும்", "Document 24 hours-ல் expire ஆகும்", "Immediately verify பண்ணுங்க". Think பண்றதற்கு முன்னாடி act பண்ண pressure create பண்றும் social engineering tactics.
மூன்றாவது red flag: email domain service-உடன் match ஆகல. DocuSign notification docusign.com-ல் இருந்து வரணும் — docusign-notifications.net அல்லது similar lookalike domains-ல் இல்லை.
உங்கள் IT Team இப்போவே என்ன பண்ணணும்
Individuals-க்கு: awareness — நீங்கள் personally generate பண்ணாத device code-ஐ enter பண்ணாதீங்க. Organisations-க்கு: Microsoft administrators device code flow-ஐ completely disable பண்ணலாம் — most corporate employees smart TVs அல்லது IoT devices Microsoft 365-ல் connect பண்றதில்லை, flow disable பண்றது attack surface remove பண்றது. Microsoft Entra ID-ல் Conditional Access policies restrict பண்ணலாம். Entra audit logs-ல் unusual token grants monitor பண்ணலாம்.
Critical point: Device code phishing attack already complete ஆகியிருந்தா, பாஸ்வேர்டு change பண்றது போதாது. IT team Microsoft Entra admin portal மூலம் OAuth tokens directly revoke பண்ணணும் — Settings, Users, affected account-ஓட active sessions — attacker-ஓட access invalidate ஆக. Password reset alone insufficient.
TamilTech-ஓட கருத்து
Device code phishing-ஓட 37x growth phishing-as-a-service economy-ஓட direct consequence — criminal infrastructure productised மற்றும் subscription-ல் sold, sophisticated attacks run பண்றும் technical barrier near zero. EvilTokens மற்றும் competitors account takeover-ஐ commodity service-ஆ turn பண்றது. Indian corporate IT teams-க்கு Microsoft 365 deployments manage பண்றவங்களுக்கு — இது Q1 2026-ஓட most important security alert. Attack password security மற்றும் 2FA-ஐ simultaneously defeat பண்றது, real Microsoft infrastructure target பண்றது URL checking protection offer பண்றதில்லை, password reset survive பண்றும் persistent access கொடுக்குது. Entra ID policies review பண்ணுங்க, device code flow unnecessary users-க்கு disable பண்ணுங்க, உங்கள் teams-ஐ personally generate பண்ணாத device code enter பண்ணாதீங்க-ன்னு train பண்ணுங்க.




கருத்துகள் (0)
Be the first to comment!