Phone calls from people posing as corporate help-desk staff were used in a ransom campaign targeting some of the biggest names in US finance. The callers paired company-specific fraudulent websites with instructions intended to make employees surrender passwords and additional security codes.
The businesses placed in the hackers’ crosshairs included Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s. The websites were tailored to individual companies and designed to capture employee login credentials.
Get breaking news anytime, anywhere. Download the TOI app now!
Reuters reported, citing Google and internet intelligence data it reviewed, that dozens of prominent US financial institutions and other businesses had been targeted over the past month. The hackers operated under several names, including Redact, Pink, Falcon and Helix, according to a Google blog post published on Thursday.
Google said some unnamed companies had paid ransoms to the attackers.
Cybersecurity experts said the use of telephone calls showed that relatively simple tactics remained highly effective despite sophisticated security systems and the growth of AI-driven threats. A successful breach could expose information held by some of the largest US private equity firms, which provide capital to companies.
“Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us,” said Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, an industry information-sharing and analysis group.
“That human element consistently is why this has exploded in the way it has,” Clark said.
Attackers follow the money
Google, a unit of Alphabet, said the hackers had recently shifted their attention to private equity companies, law firms and financial ratings agencies.
Austin Larsen, principal threat analyst at Google’s Threat Intelligence Group, said the hackers generally chose industries after assessing the financial value of their data and had often succeeded. “Really, it’s a money thing,” Larsen said. “They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it.”
Google did not identify any of the targets by name. Reuters examined the 72 malicious websites listed in Google’s report using the internet intelligence platforms DomainTools and urlscan, which flagged malicious subdomains tailored to individual firms. “They all were likely used in attempted intrusions,” Larsen said of the subdomains, while cautioning: “They were not all successful.”
How the fake help-desk calls worked
Google said the hackers used “meticulous social engineering tactics” to contact employees on their personal cellphones while pretending to represent their companies’ IT help desks.
In some instances, the correct telephone number of the company help desk appeared on the employee’s screen.
The callers told their targets that an urgent IT directive required them to update their passkeys or multifactor authentication. Employees were then directed to booby-trapped websites carrying domain names such as “passkeyhelpdesk” or “secure-passkey”.
After an employee entered a password, the hackers sought the fail-safe security code during the same call. The code was typically sent by text message or generated by an app.
The attackers would then try to use the password and code to hijack the employee’s account before the call ended. Larsen said the method should not be regarded as technologically advanced.
“Sophisticated is not the right word,” he said. “It is just really effective.”
Hackers use shifting identities
Redact, which previously operated under the name Blackfile, said on its darknet website that its hackers “are not politically or morally motivated” and were “not currently taking questions from the press”.
Larsen said it remained unclear who the hackers were or how the different groups were connected. Although they used several aliases, he said they appeared to share common infrastructure. “There are still some unknowns here,” he said.
Campaign causes concern on Wall Street
The attempted intrusions have caused concern on Wall Street. Some of the hacking efforts were previously reported by Bloomberg.
Point72 Asset Management informed investors on Wednesday that it had been targeted by hackers, according to a source familiar with the matter.
That source and another person familiar with the matter said the hackers had also tried to breach Two Sigma Investments and Citadel. The names of both hedge funds appeared in the data reviewed by Reuters.
More than 200 companies targeted
Before turning their attention to financial institutions, the hackers built traps for businesses across several other industries, according to Google’s blog post and the internet intelligence data.
The cybercriminals created digital traps for more than 200 companies in the past five weeks alone.
The targets included ride-hailing company Uber, online broker Zillow and jeans brand Levi Strauss. Law firms Paul Hastings and Greenberg Traurig were also among the businesses for which traps were created.
Greenberg Traurig said it “did not have a data breach given the layers of security protocols we have in place to protect client data and the firm”. It did not elaborate.