Okta warns scammers are going after super admin privileges

ID theft
(Image credit: Shutterstock)

Criminals have been targeting Okta’s clients in an attempt to gain access to accounts with administrator privileges.

"In recent weeks, multiple U.S.-based Okta customers have reported a consistent pattern of social engineering attacks against IT service desk personnel, in which the caller's strategy was to convince service desk personnel to reset all multi-factor authentication (MFA) factors enrolled by highly privileged users," the company confirmed in a blog post.

The campaign was active between July 29 and August 19 2023, it was added. 

Muddled Libra

Apparently, the attackers (whom Okta did not want to name) have already obtained the target accounts’ username and password combination. However, as these accounts were protected by MFA, the threat actors had no other choice but to try and trick their way into resetting the tool.

If the attackers had succeeded, they would be granted the ability to assign higher privileges to other accounts, reset authenticators for other people, and even remove two-factor authentication if needed.

While Okta did not say who was behind the campaign, the media came to its own conclusion, based on the information provided. Thus, The Hacker News argues that this could be the work of Muddled Libra, an activity cluster partly overlapping with the likes of Scattered Spider and Scatter Swine. Google’s Mandiant tracks the group as UNC3944. They’re basing their conclusion on the fact that the group uses a commercial phishing kit called 0ktapus. Unit 42, on the other hand, argues that multiple groups are using 0ktapus, which means it’s not 100% certain Muddled Libra was behind the campaign. 

Muddled Libra is a threat actor known to target organizations in software automation, BPO, telecommunications, and technology industries. Between mid-2022 and early 2023, Unit 42’s researchers investigated “more than half a dozen” incidents related to this threat actor.

Via: The Hacker News

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
Representational image of a shrouded hacker.
Getting to grips with Adversary-in-the-Middle threats
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Hook on Keyboard
Fake DocuSign and HubSpot phishing emails target 20,000 Microsoft Azure accounts
Security padlock in circuit board, digital encryption concept
MFA alone won’t protect you in 2025: the new cybersecurity imperative
Latest in Pro
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Microsoft UK CEO Darren Hardman AI Tour London 2025
Microsoft - UK can help drive the global AI future, but only with the proper buy-in
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
AOC Graphic Pro U32U3CV during our review
I reviewed the AOC Graphic Pro U32U3CV and it's a staggeringly pro-grade monitor for the price
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day