Wall Street cybercriminals: new target — private investment funds
The analytical division of Google Threat Intelligence Group (GTIG) has recorded a troubling trend: the ransomware group UNC6671 has radically changed its tactics and is now targeting major financial institutions, including private investment funds and rating agencies. Instead of the usual phishing email campaigns, the attackers are employing sophisticated voice phishing (vishing) schemes aimed at company employees.
Attack Mechanics: From Call to Data Theft
The UNC6671 methodology is characterized by a high degree of social engineering. The attackers call employees on their personal mobile phones, posing as IT support specialists. Under the pretext of an urgent security system update, the victim is persuaded to navigate to a fake authentication portal. These sites use adversary-in-the-middle (AiTM) technology, which allows interception of not only logins and passwords but also multi-factor authentication (MFA) tokens.
Thus, even the additional layer of protection that was supposed to prevent a breach proves useless. After gaining access, hackers launch automated scripts to exfiltrate data from cloud services, including Microsoft 365 and Okta. "All attacks use individualized vishing impersonating IT support, AiTM interception panels, and data theft from SaaS applications," the report notes.
Shift in Priorities: From Tech to Finance
Until June of this year, the group targeted technology, transportation, and hospitality companies, stealing trade secrets and source code. However, in July, there was a sharp pivot. Now, UNC6671's infrastructure is aimed at private investment funds, law firms, and rating agencies. Giants such as Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's have come into the attackers' crosshairs.
According to available data, some companies have already paid the ransom, but the exact names of the affected organizations have not been disclosed. I have managed to establish that the attackers created 72 fake domains mimicking these organizations' portals, confirming the scale and thoroughness of the operation's preparation.
My comment: UNC6671's shift to the financial sector is not just a change of targets but a signal of the growing professionalization of cybercrime. Attacks via vishing and AiTM show that even corporate protection based on MFA is no longer a panacea. Investment funds and law firms operating with sensitive data should reconsider their security protocols and implement employee training to counter social engineering; otherwise, any major institution could be the next victim.