The campaign, identified by Google’s Threat Intelligence Group, relies on a deceptively simple method: calling employees on personal phones while mimicking company IT support. Attackers often spoof legitimate help-desk numbers to create a sense of urgency, pressuring staff to visit malicious websites designed to capture passwords and multifactor authentication codes in real time. Once an employee enters their credentials, the hackers hijack the account before the call ends.
Google researchers linked the operation to various aliases, including Redact, Pink, Falcon, and Helix. While experts emphasize that the technical barrier for these attacks is low, the impact is significant. Austin Larsen, a principal threat analyst at Google, notes that these groups are motivated by clear financial calculations, targeting organizations that hold data sensitive enough to warrant a ransom payment. Although Google confirmed that some unnamed companies have already paid, it remains unclear which specific firms suffered successful breaches. KKR, Bain Capital, CME, TPG, and Apollo declined to comment on the findings, while Blackstone, Bridgewater Associates, and Moody’s did not respond to inquiries.




Comments (0)
No comments yet. Be the first!