Kaspersky, a Russian cybersecurity, has discovered a new group of hackers-for-hire that appears to have been operating for a decade. This group, which Kaspersky has dubbed “Deceptikons,” has primarily targeted law firms, as well as fintech companies, according to Kaspersky researcher Vicente Diaz.
According to Diaz, the group appears to be more focused on stealing business and financial data than stealing government. He added that most of the group's targets are in Europe, but also in Middle Eastern countries such as Israel, Jordan and Egypt.

The most recent attacks by the “Deceptikons” group include a phishing campaign targeting numerous law and fintech firms, where the group deployed malicious PowerShell scripts to infect computers.
Kaspersky also explained that the group is not technically sophisticated, and does not appear to have carried out zero-day exploits. The Russian cybersecurity firm also described the group's infrastructure and malware as "smart, but not technically advanced ," with the group's primary goal being to gain access to infected computers.

Most of the “Deceptikons” attacks seem to follow a similar tactic, starting with spear-phishing that carries a maliciously modified LNK file (shortcut). If victims download and click on the file, the shortcut downloads and executes a PowerShell-based backdoor trojan
In the coming weeks, Kaspersky is set to publish a more detailed technical report, detailing more about the activities of “Deceptikons.”
It is worth noting that this is the second major hacker-for-hire group to come to light this year, as Citizen Lab previously revealed that Indian company BellTroX InfoTech Services was the group behind the Dark Basin APT.

However, Kaspersky has not yet linked “Deceptikons” to any specific entity.
