TL;DR
A targeted campaign against US law firms was identified, revealing a gap in cybersecurity defenses against sophisticated social engineering attacks. The threat group UNC3753 employed voice phishing (vishing) and deception techniques to steal sensitive data.
✦ Why It Matters
Understanding these tactics can help engineers enhance security protocols against sophisticated phishing attacks.
Key Takeaways
How It Works
UNC3753's attack begins with benign emails to establish trust, followed by vishing calls where they impersonate IT staff. They guide targets to download screen-sharing applications, bypassing security measures.
Once access is gained, they quickly search for sensitive data and exfiltrate it using various methods, including cloud storage and FTP utilities.
Related