Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Brevo Supply-Chain Attack: A Global Malware Epidemic




A global malware epidemic was unleashed when attackers exploited a vulnerability in Brevo's SAML SSO system, gaining access to numerous accounts and using a compromised Cloudflare API key to spread malware across over 100,000 websites. The attack highlights the risks of supply-chain attacks and the importance of maintaining a strong security posture. Learn more about this significant threat and how it can be prevented in our in-depth article.

  • Over 100,000 websites were affected by a malware spread after a Brevo supply-chain attack.
  • Attackers exploited a vulnerability in Brevo's SAML SSO system to gain access to 138 accounts, including one belonging to Trezor.
  • The attackers sent phishing emails to 347,000 addresses tied to crypto wallet vendor Trezor.
  • A malicious Cloudflare API key was used to create malicious Cloudflare Workers that injected code into Brevo's websites and other sites.
  • The attack highlighted the risks of supply-chain attacks and the importance of maintaining a strong security posture.
  • The attack was contained on September 15th after Brevo revoked the compromised key and deleted the attacker's hostnames.



  • The cybersecurity landscape has witnessed a significant threat in recent times, courtesy of a Brevo supply-chain attack that compromised Cloudflare access, leading to the spread of malware across over 100,000 websites. This attack, carried out by attackers who exploited a vulnerability in Brevo's SAML SSO system, gained access to 138 accounts, including one belonging to cryptocurrency hardware wallet maker Trezor. The breach exposed sensitive information, including phishing emails sent to 347,000 addresses tied to crypto wallet vendor Trezor.

    The attack began on September 10th, when attackers exploited the vulnerability in Brevo's SAML SSO system, gaining access to numerous accounts, including some belonging to high-profile clients such as eBay, Louis Vuitton, and Michelin. The attackers used the compromised accounts to send phishing emails to 347,000 addresses tied to crypto wallet vendor Trezor. The breach was further complicated by the fact that the attackers had obtained a long-lived Cloudflare API key, which was stored in the application source code and was used to create malicious Cloudflare Workers that injected code into Brevo's websites and three JavaScript files embedded in customer sites.

    The malicious code was served to visitors and users of websites relying on Brevo's services, putting over 100,000 sites at risk. The attackers had created a malicious WordPress plugin that was installed when site administrators visited their own sites, and a clickfix overlay that was shown to everyone browsing a customer site or clicking an unsubscribe link in a Brevo-sent campaign email. The attackers had also modified Brevo's chat widget and tracking scripts to load an additional script from sendibt1.com, a domain owned by Brevo, which allowed them to reach a large number of sites without compromising them individually.

    The attack was particularly sinister because it targeted logged-in WordPress administrators, who were tricked into running a malicious command by a fake "prove you're human" prompt. The malware was designed to hide from normal plugin lists, persist through the must-use plugins folder, and communicate with its command-and-control server. The attackers had also used the compromised Cloudflare API key to deploy a malicious Cloudflare Worker that injected code into Brevo's websites, which was served to visitors and users of websites relying on Brevo's services.

    The attack was eventually contained on September 15th, when Brevo revoked the compromised key, pulled the hardcoded credential out of its source code, deleted the attacker's hostnames, and flushed its edge caches. The attack highlighted the risks of supply-chain attacks, which offer attackers enormous reach. The attackers had not needed to compromise each customer or trick every victim individually, as the trust was already built into the websites through a simple








    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us