Ransom-seeking hackers targeted dozens of prominent US financial institutions and other major businesses over the past month, according to a report.
Google disclosed the ongoing cyberattacks earlier this week, with Reuters reporting that the targeted firms included Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody’s.
The cybercriminals did their hacking the old fashioned way, simply calling up employees at those businesses, posing as company help desks, and then getting their unwitting targets to give up sensitive data, Google shared.
The tech giant noted that while several unnamed companies were successfully breached and paid ransoms, many of the targeted intrusions failed to bypass corporate security protocols.
Reuters said it could not establish which companies the hackers successfully compromised.
The hackers also built custom websites to steal passwords from staff at private equity firms and financial companies, Reuters reported.
Google indicated the attackers recently shifted their focus toward financial titans, law firms and financial ratings agencies — entities that tend to manage massive pools of capital, making them alluring targets.
Austin Larsen, principal threat analyst at the Google Threat Intelligence Group, explained the financial calculations driving the attackers.
“Really, it’s a money thing,” Reuters quoted him as saying. “They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it.”
Google noted some unnamed companies have already paid ransoms to the attackers.
The hackers’ technique for breaching corporate networks is known as “social engineering.”
Social engineering involves manipulating individuals into revealing confidential information rather than using technical software exploits.
The hackers call employees directly on their personal cellphone and pretend to represent the corporate information technology help desk, Google said.
The attackers are allegedly able to manipulate caller ID systems to display the legitimate internal help desk phone number, building immediate trust with the victim.
The attackers instruct workers to update their passkeys or multifactor authentication settings. Multifactor authentication represents a security protocol requiring users to provide two or more verification factors to access an account, typically combining a memorized password with a temporary code sent via text message.
The attackers steer the victims toward malicious, booby-trapped websites utilizing domain names such as “passkeyhelpdesk.”
The fake websites prompt employees to enter their primary passwords. The hackers then harvest the temporary, fail-safe passcodes live over the phone while speaking to the employee. The attackers then hijack the victim’s corporate account immediately before ending the call.
Larsen noted that the methods utilized by these attackers should not be confused with complex technical programming.
“Sophisticated is not the right word,” he said. “It is just really effective.”
Cybersecurity experts emphasize the persistent vulnerability of human employees. Lee Clark, a cyberthreat intelligence production manager with the Retail and Hospitality ISAC, highlighted the effectiveness of these low-tech tactics.
“Because the fence is now so fancy and high-tech, we just have to trick the guard into opening the door for us,” he said. “That human element consistently is why this has exploded in the way it has.”
Google identified several aliases the hackers utilize, including Redact, Pink, Falcon and Helix. Larsen noted the groups share common digital infrastructure.
The hacking campaign caused significant alarm across Wall Street.
Point72 Asset Management informed investors on Wednesday about a recent attack attempt. Anonymous sources quoted by Reuters confirmed the hackers also targeted hedge funds Two Sigma Investments and Citadel.
The cybercriminals built digital traps for more than 200 companies during the past five weeks. The attackers pursued ride-hailing company Uber, online real estate broker Zillow and clothing brand Levi Strauss.
The hackers also targeted law firms Paul Hastings and Greenberg Traurig. Greenberg Traurig released a statement confirming their security protocols successfully protected client data and prevented a data breach.
KKR, Bain Capital, Clearlake Capital, CME, TPG, Apollo, Point72 and Citadel declined requests made by the Reuters news agency for comment.
