Social engineers are trying to convince companies to make large-dollar transfers to their own accounts, under the guise of fake merger & acquisition (M&A) deals.

It’s one of the oldest gambits in cybersecurity — the advance fee scam — for a new generation, and with more on the line. Gen, the parent company of cybersecurity brands Norton and Avast, was targeted by a ruse masquerading as a corporate acquisition. Gen investigated the attempted attack and discovered the company was just one of at least five targets, all of which were at risk of losing massive sums of money.

“Scams are becoming so convincing that even the most trained eye can have trouble spotting them,” says Gen security evangelist Luis Corrons, who co-authored a report on the campaign with Martin Chlumecký, senior principal threat analysis engineer at Gen.

In this case, luckily, the company was saved by an attentive employee and some cracks in the attackers’ narrative. “The attackers’ methodology was quite sophisticated, but their individual scenario was imperfect,” Corrons says. “With a more coherent story, the same playbook could have been much more dangerous.”

Related:Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks

The Phantom Deal

The threat actors behind the campaign, dubbed “Phantom Deal,” did their homework. They identified a member of Gen’s legal team, referred to as “David,” who might be expected to have a role in whatever sort of corporate dealmaking was going on at the company. The first phishing message, via WhatsApp, was friendly and nondescript. An attacker impersonated one of the company’s executives. Their phone number correctly utilized the executive’s home country’s area code.

The executive had news for the employee, on the down low. They were facilitating a major corporate acquisition. The details were a little vague. It involved Gen’s subsidiaries and a big, fat check.

“They never gave David a completely coherent explanation of exactly who was acquiring whom,” Correns recalls. “What they did was build around real corporate history. NortonLifeLock acquired Avast in 2022, and the fraudulent payment instructions asked Avast Software to make a payment on behalf of NortonLifeLock Ireland Limited, supposedly connected to a confidential acquisition and reimbursable when the deal was announced. That was enough to create a plausible mergers and acquisitions (M&A) context, but if you looked closely, the story did not really add up.”

The story structure may have fallen short of The Odyssey, but every other operational detail was spot on. A second threat actor impersonated a middleman at PricewaterhouseCoopers (PwC). They had a non-disclosure agreement (NDA) written up, with PwC branding. The NDA cleverly swore the employee to secrecy — keeping other employees out of the ruse — and instructed them to limit all communications to WhatsApp and personal email addresses — keeping their suspicious messages away from the prying eyes of corporate monitoring systems. The secret deal narrative gave context to what otherwise would have been totally suspicious asks.

Related:EY Survey Finds Autonomous AI Implementation Outpaces Oversight

Then came the big ask: An oddly specific €626,735.45 Euro transaction needed to be sent to a company in Hong Kong to facilitate the deal.

The fiction only fell apart because the employee and the attackers got on the phone, and the employee recognized that the impersonated executive’s voice was wrong. At that point, the attackers became the attack-ees. Gen drafted a fake transaction confirmation email, keeping the bad guys thinking they were on the cusp of success. The email contained a link with a token, which tracked the attacker’s actions and connections.

With metadata from the fake NDA, researchers were able to identify four other targets of the same campaign. The targets were all senior employees, belonging to companies of all different sorts: private equity, industrial finance, sales, mining, and energy. For the most part, each attack was entirely customized to its target, even down to the professional services firm — PwC, KPMG, Ogier — used to facilitate their “phantom deal.”

Related:AI Agent Breaches Spanish Organization, Modifies Personal Data

How Companies Can Kneecap Social Engineers

Companies reveal a huge amount of information about themselves on the public Internet. What made Phantom Deal convincing was all of the detail the social engineers were able to gather about their target, using simple Web searches. Still, Corrons argues, the answer to fighting them isn’t to take that information off the Net.

“The attackers used names, photographs, job roles and acquisition history, most of which is legitimately public and, in many cases, needs to be public. Security through obscurity would not solve this problem,” he says. “I would not want companies relying on the attacker having incomplete information. Assume criminals can learn a great deal about your organization. The defense has to be that even somebody who’s done excellent reconnaissance still cannot talk an employee into bypassing verification and payment controls.”

It helps, too, if employees know better than to try bypassing those controls in the first place. The hero of Gen’s story, “David,” undressed an otherwise compelling attack through basic attention to detail. “First, he verified the person rather than trusting the identity presented on the screen. Second, he understood what a legitimate transaction should look like,” Correns notes.

The lesson for everyone else, he says, is: “Don’t just ask whether the person looks legitimate, ask whether the process they are asking you to follow is legitimate. For most employees, once they suspect something, the correct next step is to report it, not to continue engaging with the scammer. Even if you report it and it’s a legitimate transaction, your company will appreciate that you’re being safe.”





Source link

#

Comments are closed