Joint Warning Details Email-Theft Methods

The advisory outlines methods for gaining access, staying inside networks and taking emails and credentials.

A joint FBI, Cybersecurity and Infrastructure Security Agency and National Security Agency advisory details methods used to enter networks and steal information, CyberScoop reports. The warning describes password attacks on Microsoft Exchange servers, continued access through VPN software, and theft of emails and credentials.

According to CyberScoop’s account, the advisory specifically identifies password spraying and cross-site scripting attacks alongside scanning tools. It also describes scripts used to take emails and credentials. These details cover both gaining entry and maintaining access afterward.

DOJ’s Office of Public Affairs said the warning includes indicators of compromise to help network defenders identify and respond to intrusions. CyberScoop reports that agencies released the advisory alongside court-authorized seizures targeting the Microscan and FishHub hacking tools. The seizures were authorized in the Western District of Pennsylvania.