Google's security researchers have uncovered an extensive hacking operation dubbed UNC6671 that targets large financial institutions through sophisticated voice phishing (vishing) attacks. The hackers use social engineering tactics like impersonating IT staff or colleagues over the phone to trick employees into revealing their credentials and MFA codes on fake websites. This data is then used for extortion, with threats of public disclosure unless hefty ransoms are paid. One cryptocurrency wallet linked to these groups has received around $10 million in Bitcoin this year alone. The hackers typically demand between $750,000 and $3 million from their victims.
LightSpy, a sophisticated spyware platform, now targets victims in more than a dozen countries across Europe and the US. This modular system can steal sensitive information such as precise location data, chat messages, screen recordings, and stored passwords from various devices including smartphones, Apple devices, Linux servers, and Windows PCs. The spyware also infects routers to gain network-wide access, with some compromised routers linked to NATO member countries. Researchers identified a Chinese contractor after an operator used the LightSpy panel to place an order. This platform is operated by a single threat actor catering to governments, enterprises, and militaries. Let's dive deeper…
In today's ContentBuffer update: