Google Threat Intelligence Group (GTIG) has recorded a worrying trend: ransomware hackers from the UNC6671 group have radically changed their tactics and are now deliberately targeting private investment funds, law firms, and rating agencies linked to Wall Street. This is not about a trivial hack, but a high-tech campaign using voice phishing (vishing) that threatens the financial elite of the United States.

How the new attack scheme works

The attackers' methodology is sophisticated and multi-stage. Calls are made directly to employees' personal mobile phones, where hackers, posing as IT support staff, convince the victim to urgently "update the security system." The victim is redirected to fake authentication portals that are visually indistinguishable from corporate ones.

A key feature is the use of adversary-in-the-middle (AiTM) systems. These platforms intercept in real time not only logins and passwords, but also multi-factor authentication (MFA) tokens, negating additional protection. After gaining access, hackers launch automated scripts to exfiltrate data from cloud services, including Microsoft 365 and Okta.

"All attacks use individualized vishing impersonating IT support, AiTM interception panels, and subsequent theft of information from SaaS applications," the report emphasizes.

Shift in targets: from technology to finance

Notably, until June of this year, the group hunted for trade secrets and source code in the technology, transportation, and hospitality sectors. However, in July, there was a sharp pivot toward the financial sector. Giants such as Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's came into the attackers' sights.

My colleagues and I conducted an independent analysis of the attackers' infrastructure. By cross-referencing 72 published internet addresses through DomainTools and urlscan services, we were able to identify subdomains belonging to each of the listed companies. This confirms that the attacks were not random, but carefully planned operations against specific targets.

According to available data, some companies have already paid the ransom, but the names of the victims have not been disclosed. It remains unclear how many organizations managed to repel the intrusion.

My comment: This attack is a vivid example of how cybercriminals adapt to defensive measures. The use of social engineering to bypass MFA is a serious signal for the entire financial sector. Investment funds need to review employee verification protocols and implement hardware security keys rather than relying solely on software-based authentication methods.