The hacker "industry" appears to have found a new stronghold for its attacks. This is demonstrated by a recent campaign of attacks targeting some of the leading private equity firms in the United States, among other American companies in other sectors.
According to Reuters , which analyzed data compiled by Google's security arm, a group of hackers developed attacks targeting employees of asset management firms such as Blackstone , Apollo Global Management , KKR , TPG Capital , and Bain Capital .
In addition to focusing on these private equity giants, the list of targets for these threats includes names such as the hedge fund manager Bridgewater Associates , the trading platform CME Group, and the credit rating agency Moody's .
In the campaign, which took place last month, hackers created 72 malicious websites to steal passwords from employees of these companies. According to Google, which did not reveal names, some of these companies paid ransoms to the cybercriminals.
The attacks also involved phone calls, an older and less advanced technique, especially in a context where artificial intelligence is already being used by cybercriminals to sophisticate their threats. Whatever the tactic, the fact is that there will always be a weak link in this chain.
“Since the security system is now so sophisticated and high-tech, all we have to do is trick the guard into opening the gate for us,” said Lee Clark, production manager of cyber threat intelligence at Retail and Hospitality ISAC, an industry analytics and information-sharing group.
Clark added, "That human element is consistently the reason why this blew up the way it did," he stated.
Reuters reverse-engineered some of the many "traps" used by criminals, based on websites listed by Google in its report. Austin Larsen, principal analyst at Google Threat Intelligence Group, told the agency that not all of the hackers' attempts were successful.
He also highlighted what put these companies in the crosshairs of cybercriminals. "They think that these companies or organizations possess enough sensitive data that, if it were stolen, they would pay to prevent it from happening."
Google also noted that the hackers used "meticulous social engineering tactics," contacting employees on their personal cell phones, pretending to call from the companies' call centers. Often, they even displayed the correct number for those call centers.
In these calls, they told victims that there was an urgent directive from the IT department to update passwords and directed employees to a malicious website. If the employee followed the subsequent steps, the hackers were able to hijack their account before the end of the call.
At this point, Larsen again drew attention to the fact that this technique is not particularly advanced. But he added a caveat. "Sophisticated isn't the right word," he stated. "It's simply very effective."