HomeSecurityBEC phishing attacks: New hacking group targets major companies

BEC phishing attacks: New hacking group targets major companies

phishing

A new hacking-phishing group targeting large companies around the worldhas been discovered. BEC (Business email compromise) scams can be extremely profitable for criminals. Victims can lose hundreds of millions of dollars a month if they are tricked into sending money to accounts belonging to criminals.

The hacking group was discovered and analyzed by security firm Agari. The researchers named it Cosmic Lynx. The phishing campaign has targeted individuals in 46 countries, across six continents. The group researches target organizations and their executives well and sends phishing emails about topical issues, such as COVID-19.

Researchers say the infrastructure behind the phishing operation is linked to the Trickbot and Emotet, however several changes have been made.

It is important to note that a criminal group is turning to BEC attacks. This means that more and more hackers are realizing that it is worth investing in these attacks because they can be more profitable than the others, which are also based on emails.

“Unlike traditional BEC groups, Cosmic Lynx can develop much more complex and creative attacks that set them apart from other more general BEC attacks we see every day,” said Crane Hassold, director of research at Agari.

BEC

In most cases, the individuals targeted by the hacking group are high-ranking company executives (vice presidents, general managers, etc.). The attack begins with phishing emails, which appear to come from the CEO of the targeted company.

In almost all cases, the initial phishing emails describe in detail the alleged acquisition of an Asian company. The attacker tells the victim that it is a secret matter and that they should not tell anyone else.

Researchers note that unlike other BEC attacks, the emails are well-written and contain business and financial terms.

After the initial phishing email, the “CEO” emails a lawyer to help complete the financial transaction. The emails from the “lawyer” are also sent by Cosmic Lynx.

"It's very rare for a BEC team to do double impersonation. This shows the extra effort Cosmic Lynx puts into attacks to make them more realistic," Hassold said.

After the “lawyer” gets involved, the victim is usually convinced to transfer hundreds of thousands or even millions of dollars to accounts in Hong Kong, which end up in the hands of the fraudsters.

Researchers believe the group has been running phishing campaigns for at least a year. It is not possible to say how many organizations have fallen victim to BEC attacks or how much money the criminals have made. However, the campaign is still active.

If someone believes they may be the target of a BEC phishing attack, it is a good idea to contact the person the email appears to be from. As we said, the attacker is impersonating a co-worker or even an acquaintance. Therefore, there should be contact to confirm that the email actually came from them.  

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS