A business email compromise (BEC) group called “Crimson Kingsnake” has emerged, impersonating well-known international law firms to trick recipients into approving overdue invoice payments.
The hackers pose as lawyers and send invoices for services that the victim organization supposedly received a year ago.
By impersonating major law firms in their messages, scammers can easily intimidate their recipients and lay the foundation for a successful BEC attack.
See also: LockBit ransomware: Gang threatens to leak Continental data

Unfair legal practices
Abnormal security discovered the Crimson Kingsnake group in March 2022 and has since identified 92 different domains associated with the threat actor. All of these domains closely resemble law firm websites.
With this typosquatting approach, BEC perpetrators can send emails to victims from an address that initially appears legitimate.
See also: New clipboard stealer Laplas Clipper replaces crypto wallet addresses with similar ones
The emails contain the logos and letterheads of the personified entities and are professionally crafted, with precise handwriting.
Some of the law firms that have impersonated Crimson Kingsnake are:
- Allen & Overy
- Clifford Chance
- Deloitte
- Dentons
- Eversheds Sutherland
- Herbert Smith Freehills
- Hogan Lovells
- Kirkland & Ellis
- Lindsay Hart
- Manix Law Firm
- Monlex International
- Morrison Foerster
- Simmons & Simmons
- Sullivan & Cromwell
These multinational companies have a global reach, so cybercriminals rely on their targets recognizing the company name and assuming the email is legitimate.
Crimson Kingsnake Attacks
Phishing emails are “blind BEC attacks” that do not target specific countries or industries, according to Abnormal Security.
If someone responding to the pricing request falls for the bait, Crimson Kingsnake will provide a false description of the alleged service.
In some cases, when BEC perpetrators encounter resistance, they add a fake “response” from an executive at the target company to approve the transaction.
See also: Black Basta ransomware group linked to FIN7 group
According to a report by Abnormal Security, when the Crimson Kingsnake team encounters resistance from the employee they are targeting, they occasionally adapt tactics and impersonate a company executive.

Even if an email initially appears to come from someone outside the company, it could be a scam. If there are no mailbox filters or alert systems in place, the targeted employee is at risk.
BEC attacks are constantly increasing
BEC attacks are only a small portion of all the daily phishing emails circulating in global inboxes, but even at these low volumes, it's still a multi-billion dollar problem.
Various reports indicate that from 2016 to 2019, BEC fraud resulted in the loss of $43 billion in funds. In 2021 alone, IC3 noted that 19,954 entities reported total losses of $2.4 billion due to these types of fraud.
Abnormal Security's H1 2022 Email Threat Report reports that BEC attacks have increased by 84% year-over-year. They estimate that, on average, 0.82 emails per 1,000 incoming messages are malicious.
According to the report, if your organization has over 50,000 employees, you have a 95% chance of receiving a BEC email every week.
Information source: bleepingcomputer.com
