A voice phishing (vishing) campaign targeting financial services, private equity and professional services firms has adopted some new techniques since May, Google Threat Intelligence Group (GTIG) said in a Thursday (Aug. 6) blog post.
The campaign, which is being conducted by threat actor UNC6671 under several extortion brands, pursues compromises that lead to data theft extortion, according to the post.
The threat actors target enterprise employees through vishing, often via the employees’ personal mobile devices, and pose as IT helpdesk staff facilitating what they say are mandatory, urgent security migrations, the post said.
Through their calls, the threat actors lure victims to spoofed login portals and intercept the victims’ credentials and multi-factor authentication (MFA) tokens, per the post.
The threat actors then deploy automated scripts for data exfiltration from enterprise cloud environments, according to the post.
In the time since GTIG covered this vishing threat in a May blog post, UNC6671 has continued using these tactics while adding new ones, according to the Thursday post.
“UNC6771 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls,” GTIG said. “In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy. During these phone calls, operating under the false pretext of an urgent helpdesk mandate to enable FIDO2 passkeys or update multi-factor authentication enrollment, the caller directs the employee to a lookalike credential-harvesting subdomain.”
Since May, the threat actor has also increasingly used defense evasion to maintain account-level persistence and conceal its operations, per the post.
“In recent intrusions, the group used compromised email accounts to initiate unauthorized password resets for non-SSO enterprise applications,” GTIG said. “To prevent end-user detection or automated security alerts, operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations.”
Google’s cybersecurity organizations, GTIG and Mandiant, said in June that data theft extortion groups are targeting professional, legal and financial services organizations by impersonating IT support.
The National Retail Federation released research Friday (July 30) showing that criminals are shifting from shoplifting to other forms of “more sophisticated” theft, such as phone scams.