Image: media.kasperskycontenthub.com · rights & removal
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
Reporting by ThreatpostRead the original at threatpost.com
Executive Summary
A sophisticated phishing campaign dubbed 0ktapus has compromised nearly 10,000 accounts across 130 organizations globally, including high-profile targets like Twilio and Cloudflare. The attackers utilized a multi-stage approach, beginning with the targeting of telecommunications firms to acquire phone numbers. This enabled the delivery of SMS-based phishing links that mimicked Okta authentication pages, allowing actors to harvest both identity credentials and multi-factor authentication (MFA) codes.
The ultimate objective appears to be the infiltration of customer-facing systems or mailing lists to facilitate broader supply-chain attacks. This was evidenced by a related incident at DoorDash, where stolen vendor credentials led to the theft of personal data from customers and drivers. While the scale of the campaign is not yet fully known, the events highlight a critical vulnerability in common MFA implementations. Experts suggest moving toward FIDO2-compliant security keys and enhancing user education to counter these evolving threats.
Facts Only
* Threat actors known as 0ktapus targeted employees at Twilio and Cloudflare.
* 9,931 accounts across more than 130 organizations were compromised.
* 114 impacted firms are based in the United States.
* Victims are located across 68 additional countries.
* 5,441 multi-factor authentication (MFA) codes were compromised.
* Attackers used text messages containing links to phishing sites mimicking Okta authentication pages.
* DoorDash reported unauthorized access to internal tools via stolen vendor credentials.
* DoorDash customers' and delivery personnel's names, phone numbers, emails, and delivery addresses were stolen.
* Threat actors targeted mobile operators and telecommunications companies to obtain phone numbers.
* Recommended mitigations include FIDO2-compliant security keys and URL/password hygiene.
Full Take
The strongest version of this narrative is a warning about the "illusion of security" provided by traditional MFA. It correctly identifies that moving from passwords to SMS or app-based codes does not eliminate phishing; it merely shifts the target. By targeting the telecom infrastructure first, 0ktapus bypassed the perimeter not through a software flaw, but through a human and systemic one.
The root cause here is a reliance on "shared secrets"—codes sent over insecure channels—which maintains a fragile trust model. This echoes the historical pattern of security chasing the adversary: as defenses harden, attackers move "left" in the kill chain, targeting the identity provider or the telecom carrier rather than the end application.
The implications for human agency are sobering. When the very tools designed to protect us (MFA) are weaponized against us, the burden of vigilance shifts entirely to the individual user. The cost is borne by the customer whose data is leaked, while the benefit of "security theater" often accrues to the vendors who sell these basic MFA implementations.
If this were a coordinated influence campaign, the playbook would involve manufacturing a "security crisis" to drive urgent procurement of a specific high-end security product. The actual content does not match this; it provides general industry standards (FIDO2) rather than a branded solution.
Patterns detected: none
Bridge Questions:
1. If SMS-based MFA is fundamentally phishable, why does it remain the industry standard for most consumer and enterprise services?
2. How does the centralization of identity through firms like Okta create a single point of failure for the entire global supply chain?
3. To what extent is "user education" a viable defense, or is it a way for organizations to shift liability onto the employee?
From the original · Threatpost
Targeted attacks on Twilio and Cloudflare employees are tied to a massive phishing campaign that resulted in 9,931 accounts at over 130 organizations being compromised. The campaigns are tied to focused abuse of identity and access management firm Okta, which gained the threat actors the 0ktapus moniker, by researchers.Read the full story at threatpost.com
Sentinel — Human
The article shows some signs of a machine-generated nature, such as uniform sentence structure and occasional formulaic language. However, it does not exhibit clear evidence of fabrication.
