Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Xeon Sender Tool uses cloud APIs for large-scale SMS phishing attacks
Global Security

Xeon Sender Tool uses cloud APIs for large-scale SMS phishing attacks

AdminBy AdminAugust 19, 2024No Comments3 Mins Read
SMS Phishing Attacks
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


August 19, 2024Ravi LakshmananCloud Security / Threat Intelligence

SMS phishing attacks

Attackers use a cloud-based attack tool called Xeon Sender to conduct large-scale SMS phishing and spam campaigns, abusing legitimate services.

“Attackers can use Xeon to send messages through multiple software-as-a-service (SaaS) providers using valid credentials for the service providers,” SentinelOne security researcher Alex Delamotte. said in a report shared with The Hacker News.

Examples of services used to facilitate bulk SMS messaging include Amazon Simple Notification Service (SNS), Nexmo, Plivo, Proovl, Send99, Telesign, Telnyx, TextBelt, Twilio.

It is important to note here that this activity does not exploit the weaknesses inherent in these providers. Most likely, the tool uses legitimate APIs to carry out mass SMS spam attacks.

Cyber ​​security

It combines tools such as SNS sender which are increasingly becoming a way to bulk ship smiling messages and ultimately capturing sensitive information from targets.

Spread through Telegram and hacker forums, one of the older versions mentions a Telegram channel dedicated to promoting hacked hacking tools. The latest version, available for download as a ZIP file, attributes itself to a Telegram channel under the name Orion Toolxhub (oriontoolxhub), which has 200 members.

Orion Toolxhub was created on February 1, 2023. It has also made other brute force attack software, reverse IP lookup, and more available for free, such as a WordPress site scanner, a PHP web shell, a bitcoin clipper, and a program called YonixSMS that allegedly offers unlimited SMS capabilities.

Xeon Sender is also called XeonV5 and SVG Sender. Early versions of the Python-based program were discovered as early as 2022. Since then, several threat actors have repurposed it for their own purposes.

“Another incarnation of the tool is hosted on a web server with a graphical interface,” Delamotte said. “This hosting method removes a potential barrier to access, allowing less skilled entities that may be uncomfortable working with Python tools and removing their dependencies.”

Xeon Sender, regardless of the variant used, offers its users a command-line interface that can be used to communicate with the server APIs of the chosen service provider and organize mass SMS spam attacks.

It also means that the threat actors already have the necessary API keys needed to access the endpoints. The generated API requests also include the sender ID, message content, and one of the phone numbers selected from a predefined list present in the text file.

Cyber ​​security

Xeon Sender, in addition to SMS sending methods, includes functions to verify Nexmo and Twilio account credentials, generate phone numbers for a given country code and city code, and verify that the phone number is valid.

Despite the lack of subtlety associated with the tool, SentinelOne said the source code is littered with ambiguous variables, such as single letters or a letter plus a number, to make debugging much more difficult.

“Xeon Sender makes heavy use of vendor-specific Python libraries to make API requests, which creates interesting discovery challenges,” Delamotte said. “Each library is unique, as are the vendor’s journals. It can be difficult for teams to detect abuse of this service.”

“To protect against threats like Xeon Sender, organizations should monitor activity related to evaluating or changing permissions to send SMS or abnormal changes to mailing lists, such as large downloads of new recipient phone numbers.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025

Initial Access brokers

May 9, 2025

Google unfolds on the AI ​​Defense device to detect scam in Chrome and Android

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025

Initial Access brokers

May 9, 2025

Google unfolds on the AI ​​Defense device to detect scam in Chrome and Android

May 9, 2025

Chinese hackers operate SAP RCE LINK

May 9, 2025

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.