Hackers Tricked 3 British Private Equity Firms

enovise.com

Published On 15 Feb 2022

Enovise

Summary

In a highly targeted business email compromise attack, the Florentine Banker group tricked three British private equity firms into wiring $1.3 million — approximately $700,000 permanently lost — using man-in-the-middle tactics and lookalike domains to intercept and manipulate financial communications.

In a recent highly targeted BEC attack, hackers managed to wire up three British private equity firms, with fraudulent access to bank accounts totalling $1.3 million — while officials thought they had closed an investment deal with a startup. According to cyber security firm Check Point, nearly $700,000 of the total transferred amount has been permanently lost to the attackers; the balance was recovered after Check Point alerted the targeted companies in time.

The Florentine Banker Group

Dubbed "The Florentine Banker", the sophisticated cybercrime gang behind this attack "seems to have perfected techniques through multiple attacks spanning at least several years of activity, and has proved to be a resourceful adversary, quickly adapting to new circumstances."

The lookalike domain technique presents a serious threat — not only to the organisation originally attacked, but also to third parties with whom those lookalike domains were used to communicate. Check Point's previous investigations linked the same group to attacks targeting the manufacturing, construction, legal, and finance sectors across the US, Canada, Switzerland, Italy, Germany, and India.

How the Attack Worked

The fraud scheme operated as a carefully planned man-in-the-middle (MITM) attack:

1. Attackers sent phishing emails to gain control over email accounts within the targeted organisations and conducted detailed reconnaissance on the business and key personnel.

2. Attackers tampered with victims' Outlook mailboxes, diverting related emails into an RSS feed folder or another folder not typically monitored.

3. Attackers registered lookalike domains that closely mimicked the legitimate domains of all entities involved in the email correspondence. For example, if correspondence existed between 'Finance-firm.com' and 'banking-service.com', attackers registered 'Finance-firms.com' and 'banking-services.com'.

4. The Florentine Banker sent emails to each counterparty from the spoofed domain, inserting themselves into the conversation. Each email sent by a legitimate party was received by the attacker, who reviewed it, edited content where necessary, and forwarded it from the relevant lookalike domain to its original destination.

5. With this setup in place, attackers injected fraudulent bank account information — linked to accounts in Hong Kong and the UK — into emails to interrupt money transfers and initiate new fraudulent wire requests.

Source: Tech Rander / Check Point Research