Threat Intelligence Brief
Curated summary with source attribution
Source: techcrunch.com
Threat Risk: High
Victim: US financial and investment firms
Incident: A coordinated vishing campaign targeting high-profile financial organizations for data theft and extortion.
Impact: Significant financial losses through ransom payments and the potential exposure of sensitive corporate intellectual property.
Attacker: UNC6671 (including subgroups Falcon, Helix, Pink, and Redact)
Analysis: Threat actors are leveraging voice phishing (vishing) to bypass multi-factor authentication by manipulating employees via personal phone calls. This coordinated effort suggests a sophisticated operation aimed at high-net-worth sectors to exfiltrate sensitive data. The attackers utilize a ‘Phishing-as-a-Service’ model to scale their extortion attempts.
Recommendations: Implement strict identity verification protocols for all internal IT support requests; Educate employees on the dangers of providing MFA codes or credentials over the phone; Transition to hardware-based MFA (such as FIDO2) to eliminate the effectiveness of spoofed login sites
Source: TechCrunch
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source