Insurer Ratings

Hacking wave targets major financial firms

Hacking wave targets major financial firms

Google LLC’s Threat Intelligence Group has identified a wave of vishing attacks targeting private equity firms, law firms, and financial services companies, including Blackstone Inc., KKR & Co. Inc., and CME Group Inc.. The attacks are tied to the BlackFile crew, which has been active in June and July.

The group, tracked as UNC6671, has previously targeted manufacturers, real estate firms, hospitals, and insurers. They are now targeting firms with live merger documents or litigation files, as these firms may be more willing to pay quietly to avoid disclosure.

The phishing campaign involves voice phishing calls to employees on their personal mobile phones, with the caller claiming to be from the corporate IT help desk. The caller requests a FIDO2 passkey enrollment or update to multifactor authentication, and provides a link to a subdomain that resembles the employer’s website.

Behind the link is an adversary-in-the-middle proxy that harvests the password and live session token. Once inside, the crew cleans up after itself, deleting password reset confirmations and alerts that would otherwise notify colleagues of changes to multifactor authentication configurations.

The target list includes Apollo Global Management Inc., Paul Hastings LLP, and Greenberg Traurig LLP. None of the firms have confirmed a breach, and Greenberg Traurig has stated that no breach occurred.

Related: Atlassian shares surge on cloud growth rebound

The attempts on hedge funds surfaced on August 5, when journalists on the scene reported attempted intrusions at Point72 Asset Management LP, Citadel LLC, Millennium Management LLC, and Two Sigma Investments LP.

Point72 told investors it had seen no early sign that client information was taken.

Two Sigma stated that its security team responded quickly to the attempted vishing campaign, with no impact to its systems or data.

Jeremiah Fowler, a researcher at Black Hills Information Security Inc., said the economics explain the target list. “When the goal of cyber criminals is financial gain, it is only logical that investment firms that manage sensitive financial information are attractive targets,” he said.

Phil Wylie, senior consultant and evangelist at Suzu Labs, said the fix is procedural, and that verification steps that do not rely on an employee recognizing a familiar voice are what stop the call.

Google’s hardening advice leans on hardware, including roaming FIDO2 keys and platform authenticators such as Okta FastPass.

Related: Claude AI model hacks three organizations internally

The rest of the list covers shorter sessions, daily reauthentication, and blocking logins from unmanaged personal devices, all to prevent attacks like the BlackFile crew.

The crew behind the attacks has been linked to 18 wallets, with approximately $10.7 million flowing into them between January 7 and May 12.

Demands typically started at $1 million to $3 million, with roughly half the negotiations ending near $750,000.

Domain registration has sped up, with Google counting 28 phishing domains across April and May.

The pace rose to one every 1.6 days through June and July, indicating an increased effort by the BlackFile crew.

Leave a Comment

Your email address will not be published. Required fields are marked *