Optery’s Post

View organization page for Optery, graphic

2,393 followers

Recent findings from Google Cloud's Mandiant threat intelligence team have spotlighted the activities of UNC3944, a sophisticated threat group leveraging personal data for social engineering attacks and physical threats. “Mandiant noted the threat actors spoke with clear English and targeted accounts with high privilege potential. Additionally, it has been noted that they already possessed the personally identifiable information (PII) of [their] victims to bypass help desk administrators' user identity verification. Mandiant observed use of verification information, such as the last four digits of Social Security numbers, dates of birth, and manager names and job titles with associated co-workers. The level of sophistication in these social engineering attacks is evident in both the extensive research performed on potential victims and the high success rate in said attacks.” “UNC3944 operators employed consistent social engineering tactics across various victims, often calling service desks to claim they were receiving a new phone, warranting a multi-factor authentication (MFA) reset. By interacting with service desk administrators, UNC3944 could not only reset passwords for privileged accounts but also bypass associated MFA protections. The social engineering techniques went beyond the call centers as extensive SMS phishing campaigns were also observed.” “Evidence also suggests UNC3944 has occasionally resorted to fearmongering tactics to gain access to victim credentials. These tactics include threats of doxxing personal information, physical harm to victims and their families, and the distribution of compromising material.” Since the attackers are conducting extensive reconnaissance on their targets and using personally identifiable information (PII) to bypass security protocols like user verification at help desks, conduct MFA reset scams, and make threats, organizations looking to proactively mitigate their risk of being targeted should reduce the availability of their employees’ exposed personal data. Removing this data from brokers and people search sites limits the ease with which threat actors can access and exploit this information in these kinds of attacks. https://lnkd.in/dSYQiCMA #socialengineering #PII #personaldataremoval

  • No alternative text description for this image

To view or add a comment, sign in

Explore topics