Brevo, a platform focused on customer engagement, recently experienced a significant security breach that compromised over 100,000 websites through a supply chain attack. This incident involved the injection of malicious code, raising concerns across the digital landscape.
Initial Breach and Exploitation
The breach began on September 10 when attackers uncovered a vulnerability in Brevo’s SAML SSO handling process. This allowed them unauthorized access to 138 accounts, notably including one from the cryptocurrency storage firm Trezor. The attackers exploited this access to send phishing emails from six accounts and exfiltrate contact information from 43 accounts.
Although Brevo quickly shut down this unauthorized access, the threat actors returned on September 14. Utilizing a compromised, long-term Cloudflare API key, they managed to deploy a worker that injected malicious scripts into Brevo’s domains and JavaScript files embedded in client websites.
Impact and Malicious Activity
These scripts tricked selected visitors with a counterfeit ‘Cloudflare, verify you are human’ page. This page employed a social engineering tactic known as ClickFix, prompting users to execute commands on their devices. On WordPress sites featuring a Brevo widget, the script attempted to install and execute a plugin if the user was logged in as an administrator.
The malicious activity persisted for about five and a half hours before Brevo successfully removed the compromised worker and invalidated the API key and credentials. Brevo’s investigation suggests that the API key was initially misused in late August, although no customer-facing pages were affected before September 14.
Response and Recommendations
According to cybersecurity firm Sansec, the malware was active for roughly four hours and potentially affected more than 100,000 websites. In response, Brevo advises all users to inspect their websites for signs of compromise, such as unauthorized plugin installations. Visitors exposed to the fake verification pages are encouraged to check their devices for malware.
Although Brevo has ceased serving malicious code, the risk of a backdoor on WordPress sites remains, potentially exposing customers to the ClickFix scam. Vigilance and thorough security checks are recommended to mitigate further risks.
This incident underscores the importance of robust security measures and timely response to vulnerabilities, highlighting the ongoing challenges in protecting digital assets from sophisticated cyber threats.
