Back in Business: Google Threat Intelligence Group Says Cybercrime Group Very Much Alive, Targeting Financial Services

MOUNTAIN VIEW, Calif.– A cybercrime group that purportedly shut down one of its extortion operations earlier this year remains active and has expanded into several other brands while increasingly targeting financial services and other businesses, according to Google Threat Intelligence Group.

In a blog post, Google Threat Intelligence Group, or GTIG, said the threat actor it tracks as UNC6671 continues to conduct attacks involving data theft and extortion despite the announced retirement of the BlackFile extortion brand in May.

Google said its telemetry and infrastructure analysis indicates the group has diversified its operations across several other extortion brands, including Redact, Pink, Helix and Falcon. The recent attacks have included targets in financial services, private equity and professional services.

The group continues to rely heavily on voice phishing, or “vishing,” in which attackers pose as corporate IT help desk employees and contact workers, frequently on their personal mobile phones.

‘Urgent Security Changes’

Attackers tell employees that urgent security changes are required and direct them to fraudulent login websites designed to resemble legitimate company portals. The sites use adversary-in-the-middle technology to intercept login credentials and multifactor authentication tokens.

Once attackers establish access, Google said, they use automated scripts to steal data from corporate cloud environments, including Microsoft 365 and Okta.

Google said attackers have recently added new techniques to make the schemes more convincing. In some cases, callers spoofed a company’s legitimate help desk telephone number and told employees they needed to enable FIDO2 passkeys or update their multifactor authentication enrollment.

Seeks to Conceal Identity

UNC6671 also has sought to conceal its activity after compromising accounts. Google said attackers have used hacked email accounts to initiate unauthorized password resets for applications and then deleted password-reset confirmations, security notifications and other alerts that could tip off victims.

The operation has generated millions of dollars in cryptocurrency payments, according to Google’s analysis.

GTIG reviewed 18 BlackFile Bitcoin wallet addresses that received 141.65 bitcoin worth approximately $10.69 million at the time of the transactions between Jan. 7 and May 12. Payments continued after the BlackFile data-leak site announced its shutdown May 11, indicating financial operations continued during the group’s rebranding, Google said.

The Initial Demands

Initial ransom demands generally ranged from $1 million to more than $3 million, but operators frequently accepted reductions of 50% to 75% during negotiations. In more than 53% of cases tracked during the period, final payments averaged about $750,000.

Google said the similarities among the operations could indicate a coordinated group using multiple public brands to compartmentalize its activities, obscure the overall number of breaches and isolate problems arising during ransom negotiations.

Other possibilities include former affiliates establishing separate operations, independent groups using the same phishing tools and infrastructure, or a core group outsourcing extortion and ransom negotiations to other actors.

One Consistent Factor

Regardless of the organizational structure, Google said the attacks consistently rely on help desk impersonation, interception of user sessions and theft of data from software-as-a-service applications.

Google recommended that organizations use phishing-resistant multifactor authentication, integrate critical cloud applications with single sign-on systems, shorten session durations, restrict authentication to trusted networks and corporate-managed devices, and closely monitor identity-provider logs and unusual data-access activity.

Google also said identified phishing domains have been added to Google Safe Browsing. The company cautioned, however, that attackers rapidly cycle through infrastructure and sometimes create and use malicious domains within minutes of registering them, limiting the effectiveness of relying solely on lists of known malicious addresses and domains.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.