A group of threat actors formerly associated with BlackFile are linked to a wave of extortion attacks targeting private equity, financial-ratings agencies and law firms in recent weeks, according to a report from Google Threat Intelligence Group.
The threat cluster, tracked as UNC6671, has been targeting employees at various firms using voice-phishing techniques.
The hackers, pretending to be IT help desk workers, are calling the targeted employees on their mobile devices and luring them into adversary-in-the-middle infrastructure in order to steal credentials and multifactor access tokens.
“Once they establish initial access, they use automated scripts to exfiltrate vast corporate data repositories and then issue extortion demands,” Austin Larsen, principal threat analyst at GTIG, told Cybersecurity Dive.
The recent targeting follows the supposed retirement of BlackFile in May. Researchers said the group did not pack up and go home, but instead rebranded under various extortion front groups, including Helix, Redact, Pink and Falcon.
Reuters last week linked the extortion activity to a series of attacks targeting hedge funds and other private-equity firms.
Prior targeting in April and May focused on a range of sectors, including manufacturing, insurance, real estate and healthcare, based on an analysis of domain registration patterns. By the month of June, targeting had shifted to hospitality, technology and transportation.
Between January and mid-May, which is prior to the alleged shutdown of BlackFile, researchers found the equivalent of $10.7 million in ransom payments in a total of 18 Bitcoin wallets. Initial ransom demands typically ranged from $1 million to $3 million, but would drop by 50% to 75% over the course of a negotiation, according to GTIG researchers
The shift to financial sector firms represents a continued evolution of tactics in order to maximize leverage, according to Larsen.
“While these organizations obviously have capital, the primary driver is the extreme sensitivity of the transaction-related data they hold,” Larsen said. “Furthermore, these organizations often carry cyber insurance, which leads to a perception that they may be more likely to fulfill ransom demands.”