
According to security Group-IB, a hacking group, active since mid-2019, compromised email accounts belonging to high-ranking executives from more than 150 companiesas part of a spear-phishing campaign.
The group, called PerSwaysion, mainly targets the financial sector (about half of its victims) but also companies in other industries.
PerSwaysion's operations are not particularly sophisticated, but they have been extremely successful. Group-IB says the attackers did not use vulnerabilities or malware in attacks , but relied on a classic spear-phishing technique.

They sent emails to high-ranking executives at targeted companies in the hopes of tricking them into entering Office 365 credentials on fake pages.
Group-IB said the spear-phishing attack on executives consisted of three steps:
- Victims receive an email containing a clean PDF as an attachment. If victims open the file, they will be asked to click on a link to view the actual content.
- The link redirects users to a Microsoft Sway (newsletter service) page, where a similar file asks the victim to click on another link.
- This last link redirects the executive to a page that mimics the Microsoft Outlook login page. If executives enter their credentials, the hackers will steal them.
PerSwaysion hackers acted quickly after the credentials were stolen and managed to gain access to the compromised email within a day.
“After sending the credentials to their command and control servers, PerSwaysion hackers log in to the compromised email accounts,” Group-IB said.
“Finally, they create new phishing PDF files with the victim’s full name, email address, and legal company name. These files are sent to new individuals, outside the victim’s organization, who hold important positions.”
Group-IB also said that once hackers send the new spear-phishing emails from a compromised account, they delete the emails from the outbox folder to avoid detection.
At this time, Group-IB does not yet know exactly what the hackers once they steal the emails.
They may sell access to other criminal groups and much more.
Group-IB said the PerSwaysion group appears to be made up of members based in Nigeria and South Africa and using a phishing toolkit developed by a Vietnamese developer. The group's "leader" is believed to be named "Sam."
The security firm has opened a sitewhere executives can check if accounts have been compromised by the hacking group.
