Google says hackers are calling financial firm employees to hack and extort victims
Google says hackers are calling financial firm employees to hack and extort victims
谷歌称黑客正通过电话联系金融公司员工进行入侵与勒索
Even in the age of AI-powered autonomous cyberattacks, the crude, tried and tested hacking techniques of tricking victims into doing things they shouldn’t are still producing great results. Groups of unknown hackers are targeting and breaking into large financial and investment firms in the United States with the goal of stealing sensitive data to extort the victims with the threat of publishing it, Google’s security researchers wrote in a report on Thursday.
即便在人工智能驱动的自动化网络攻击时代,那些诱骗受害者进行违规操作的原始且久经考验的黑客手段依然“战果丰硕”。谷歌安全研究人员在周四发布的一份报告中指出,多个不明黑客组织正针对美国大型金融和投资公司进行渗透,旨在窃取敏感数据,并以公开数据为要挟对受害者进行勒索。
The company did not name the victims, but Reuters reported that among them there are leading private equity firms such as Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. The hacking groups, which Google dubbed Falcon, Helix, Pink, and Redact, are using an old-fashioned technique to break into those firms: phone calls to employees’ personal cellphones in which the hackers pretend to be co-workers or IT helpdesk staffers, during which they try to trick targets into entering their credentials and multi-factor codes on spoofed websites, according to Google. In cybersecurity parlance, this technique is known as voice phishing, or vishing.
谷歌并未点名受害者,但据路透社报道,其中包括阿波罗全球管理公司(Apollo Global Management)、贝恩资本(Bain Capital)、黑石集团(Blackstone)、桥水基金(Bridgewater Associates)、芝加哥商品交易所集团(CME Group)、KKR、穆迪(Moody’s)和德太投资(TPG)等领先的私募股权公司。据谷歌称,这些被其命名为 Falcon、Helix、Pink 和 Redact 的黑客组织正使用一种老派手段入侵这些公司:拨打员工个人手机,冒充同事或 IT 服务台人员,诱骗目标在伪造的网站上输入登录凭据和多因素验证码。在网络安全术语中,这种技术被称为语音钓鱼(vishing)。
Some of the groups identified by Google run websites where they publicize their hacks and threaten to leak the stolen data as a way to extort the victims into paying a ransom, a common strategy among cybercriminals.
谷歌识别出的部分组织运营着专门的网站,用于公开其黑客行为并威胁泄露窃取的数据,以此勒索受害者支付赎金,这是网络犯罪分子常用的策略。
“We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage, deliberate stalling, or failure to honor an agreement,” read one of the sites. “Respond promptly and in good faith, and the matter is resolved without further incident.”
“我们以专业的态度进行每一次谈判。公开你们的数据绝非我们首选的解决方案;这是拒绝沟通、蓄意拖延或未能履行协议的后果,”其中一个网站上写道。“请及时且真诚地回应,此事便可和平解决,不再有后续影响。”
Google researchers said that the different groups may all be part of a larger umbrella collective the company tracks under the name UNC6671. But it’s unclear if they are affiliates, splinter groups, or they all use the same Phishing-as-a-Service infrastructure. “We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout,” read the report.
谷歌研究人员表示,这些不同的组织可能都隶属于一个更大的集合体,谷歌将其追踪代号定为 UNC6671。但目前尚不清楚它们是附属机构、分支组织,还是都在使用相同的“钓鱼即服务”(Phishing-as-a-Service)基础设施。报告称:“我们认为,这很可能反映了一个协同运作的威胁行为者群体,他们运营着多个公开的勒索品牌,目的可能是为了实现运营隔离、隐藏整体入侵规模,并隔离任何谈判带来的负面影响。”
According to Google, the hacking groups have also previously targeted large companies in the manufacturing, real estate, healthcare, and insurance sectors, as well as tech, transportation, and hospitality companies with the goal of stealing “valuable intellectual property, software source code, or sensitive VIP client data.” More recently, the hackers have targeted legal and financial organizations such as private equity firms. “Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands,” wrote Google’s researchers.
据谷歌称,这些黑客组织此前还曾针对制造业、房地产、医疗保健和保险行业的大型公司,以及科技、交通和酒店业公司,旨在窃取“有价值的知识产权、软件源代码或敏感的 VIP 客户数据”。最近,黑客将目标转向了法律和金融机构,例如私募股权公司。谷歌研究人员写道:“专注于涉及并购、资本配置和诉讼的组织,可能反映了一种针对高价值企业机密数据的策略,旨在最大化勒索筹码。”
Google said that one cryptocurrency wallet associated with one of the hacking groups received around $10 million in bitcoin in the first few months of this year, and that the hackers usually demand from $750,000 to $3 million from victims.
谷歌表示,与其中一个黑客组织相关联的一个加密货币钱包在今年头几个月收到了约 1000 万美元的比特币,黑客通常向受害者索要 75 万至 300 万美元不等的赎金。
Laurie Bischel, a spokesperson for CME Group, declined to comment. Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, KKR, Moody’s, and TPG did not respond to a request for comment.
芝加哥商品交易所集团发言人 Laurie Bischel 拒绝置评。阿波罗全球管理公司、贝恩资本、黑石集团、桥水基金、KKR、穆迪和德太投资均未回应置评请求。