Googleβs Threat Intelligence Group (GTIG) is tracking a voice phishing (vishing) campaign thatβs targeting hedge funds and financial firms. The researchers attribute the attacks to βUNC6671,β an extortion group formerly known as βBlackFile.β The attackers pose as IT staff informing employees of urgent, mandatory migrations.
Normal view
Voice Phishing Attacks Target Hedge Fund Employees
Attackers Use Vishing Attacks to Distribute New Android Malware
Attackers are distributing a new Android malware called βWindRelayβ via phone-based social engineering attacks, according to researchers at Group-IB. The attackers call the victims, impersonating bank employeesΒ and instruct them to install a malicious app. In one instance observed by Group-IB, the scammers carried out the entire attack in just thirteen minutes.
Report: Vishing and Device Code Phishing Are Surging
Social engineering remains a central part of modern cyberattacks, according to a new report from CrowdStrike. Attackers are increasingly turning to voice phishing because it bypasses traditional security controls and leaves little forensic evidence, since the social engineering takes place over the phone.
Warning: Vishing Attacks Open the Door to Ransomware Gangs
An initial access broker for ransomware gangs is targeting organizations with voice phishing (vishing) attacks through Microsoft Teams, according to researchers at Zscalerβs ThreatLabz.
Apple Warns Users to be Wary of Unsolicited FaceTime Calls
Apple is warning users to be wary of unsolicited FaceTime calls amidst a wave of scams impersonating Apple Support, Malwarebytes reports. The scammers inform the user that thereβs been fraudulent activity or a technical problem associated with their account, and trick the victim into handing over payment card details, banking credentialsΒ or Apple ID logins.