SECURITY
SECURITY
SECURITY
Google LLC’s Threat Intelligence Group today said the extortion crew behind the retired BlackFile brand has spent June and July working its way through private equity firms, law firms and financial services companies.
Reuters reports that the phishing domains registered for the campaign name their intended victims. Blackstone Inc., KKR & Co. Inc., Apollo Global Management Inc. and CME Group Inc. all turn up in the set, alongside the law firms Paul Hastings LLP and Greenberg Traurig LLP. None of the firms has confirmed a breach, and Greenberg Traurig told Reuters none occurred
The group is tracked as UNC6671. Earlier in the year, its operators went after manufacturers, real estate firms, hospitals and insurers in bulk. Google’s analysts read the newer target list as a play for leverage, since a firm sitting on live merger documents or litigation files has more reason to pay quietly.
Four public extortion brands now sit on top of that single intrusion cluster, according to the report. Redact, Pink, Helix and Falcon share phishing infrastructure, and in several cases, identical phishing templates went live on the same day across domains claimed by different brands. BlackFile announced its retirement on May 11. Bitcoin payments to its wallets were still landing the next day. Redact surfaced on June 27 with a statement claiming the BlackFile name had been “compromised and hijacked by an exiled affiliate.”
Employees get a voice phishing call on their personal mobile phones. The number is spoofed to match the corporate IT help desk, and the caller says a FIDO2 passkey enrollment or a multifactor update has to be done that day. The link leads to a subdomain built to resemble the employer’s, one example being [company].createssopasskey[.]com. Behind it sits an adversary-in-the-middle proxy that harvests the password and the live session token together.
Once inside, the crew cleans up after itself. Password reset confirmations get deleted. So do the alerts that would otherwise tell colleagues someone had changed an MFA configuration. Data then leaves Microsoft 365 and Okta tenants through automated scripts, pulling files at volumes no human browsing session would produce. The user agents left behind in the logs include python-requests and Windows PowerShell.
Google linked 18 wallets to BlackFile and tracked about $10.7 million flowing into them between Jan. 7 and May 12. Demands typically started at $1 million to $3 million. Roughly half the negotiations Google followed ended near $750,000.
Domain registration has sped up. Google counted 28 phishing domains across April and May, about one every 2.2 days. Through June and July, the pace rose to one every 1.6 days.
The attempts on hedge funds surfaced on Aug. 5, when Bloomberg reported attempted intrusions at Point72 Asset Management LP, Citadel LLC, Millennium Management LLC and Two Sigma Investments LP. Point72 told investors it had seen no early sign that client information was taken. Two Sigma said its security team “responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers,” with no impact to its systems or data. The Financial Industry Regulatory Authority has since contacted member firms.
Jeremiah Fowler, a researcher at Black Hills Information Security Inc., said the economics explain the target list. “When the goal of cyber criminals is financial gain it is only logical that investment firms that manage sensitive financial information are attractive targets,” he said in comments circulated to reporters. Victim profiles that once took a skilled operator weeks to assemble can now be pulled together from breach data and public sources in minutes, he added.
Phil Wylie, senior consultant and evangelist at security solution provider Suzu Labs, said the fix is procedural. Verification steps that do not rely on an employee recognizing a familiar voice are what stop the call, he said, and the speed at which these attempts were spotted shows what firms get out of sharing intelligence with each other.
Google’s hardening advice leans on hardware. Roaming FIDO2 keys and platform authenticators such as Okta FastPass bind an authentication to its origin, which is what breaks the proxy trick. The rest of the list covers shorter sessions, daily reauthentication and blocking logins from unmanaged personal devices. Google also wants bulk “FileAccessed” events from scripting user agents treated with the same suspicion as an outright download.
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.