Cybercriminal groups are successfully employing traditional voice phishing, or vishing, techniques by calling employees at major U.S. financial and investment firms. According to a recent security report by Google, the attackers pose as IT support staff or colleagues to trick targets into submitting their credentials on spoofed websites.
Linked to a broader collective tracked as UNC6671, these threat actors steal sensitive corporate data and subsequently extort victims for large ransom payments in Bitcoin. By focusing on organizations involved in high-stakes capital deployment and mergers, the hackers maximize their leverage and financial extortion demands.
- Hackers use phone calls to impersonate IT staff and target firm employees.
- Victims are tricked into entering credentials on fake login websites.
- Stolen data is used to extort companies for massive Bitcoin ransoms.
- Google associates these activities with the UNC6671 collective.
Sources:
