Contact us: info@tenendo.com

Targeted Phishing on Cloud Services Provider Admin infrastructure Case

OSCP · OSEP · CRTO certified operators In-house tooling & payloads PCI QSA & ISO 27001 LA
The Challenge
A red team engagement was conducted to evaluate the resilience of the security team against targeted phishing attacks. The objective was to assess both the response of the support team and the SOC team to phishing attempts that aimed to gain unauthorized access through AnyConnect/OVPN.
The Solution
A red team engagement was conducted to evaluate the resilience of the security team against targeted phishing attacks. The objective was to assess both the response of the support team and the SOC team to phishing attempts that aimed to gain unauthorized access through AnyConnect/OVPN.

How we did it

  • Social engineering tactics were used to craft convincing phishing emails targeting support engineers.
  • The attack exploited weak initial access controls, specifically AnyConnect/OVPN.
  • The phishing payloads executed commands on the engineer’s workstation, demonstrating a critical gap in endpoint detection.
  • SOC response was monitored to evaluate reaction time and effectiveness in containment.

Conclusion

The test revealed a significant gap in phishing detection and response mechanisms for the support team. The lack of alerts allowed the attacker to gain initial access undetected. The SOC team demonstrated a better response time but still had areas to improve.

Recommendations included:

  • Enforcing two-factor authentication (2FA) on all remote access solutions.
  • Strengthening endpoint detection (EDR) to flag unauthorised command execution.
  • Improving phishing awareness training for all employees.