A coordinated hacking campaign has breached over 200 organizations, including a roster of elite financial firms, by impersonating their own IT help desk staff to steal multi-factor authentication (MFA) credentials, according to a report by Security Affairs. The operation highlights a critical flaw in modern security: the exploitation of human trust to bypass even robust technical controls.

The threat group, tracked under aliases including Redact and UNC6671, constructed convincing phishing portals designed to mimic internal IT support environments. Their target list includes Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's, among dozens of other firms.

The campaign's success hinges on a social engineering playbook that preys on legitimate workplace processes. By posing as IT staff requesting routine password resets or access verifications, the attackers lower employee suspicion. This method demonstrates that the primary attack surface is often human psychology, not system vulnerabilities. Employees trained to comply with internal authority were socially engineered into willingly surrendering real-time MFA tokens, rendering standard protections ineffective.

Security researchers analyzing the attacks note the operational discipline suggests a well-resourced effort. The targeting of over 200 high-value financial entities points to objectives beyond simple credential theft, potentially seeking high-value intelligence or transactional access. The use of multiple group names has sparked analysis into whether this is a single actor using false flags or a coalition sharing infrastructure.

In response, security experts are urging a fundamental shift toward human-centric defenses. The recommended immediate action is a strict mandate for out-of-band verification. All credential or access requests must be confirmed through a separate, pre-established communication channel, such as a phone call to a known number, breaking the attacker's control over the interaction.

Beyond this procedural change, a migration to phishing-resistant authentication is critical. Organizations are advised to phase out vulnerable SMS and app-based MFA in favor of FIDO2/WebAuthn hardware security keys, which create a cryptographic bond to legitimate domains and cannot be phished. This move represents a shift to a more secure trust model aligned with zero-trust principles.

Complementing these technical and procedural upgrades, scenario-based security training is essential. Generic awareness modules must be replaced with role-play exercises that simulate help desk impersonation tactics, targeting both IT staff and general employees. Finally, proactive domain monitoring for corporate-lookalike sites, coupled with rapid takedown through threat intelligence networks, can disrupt phishing infrastructure early.

The full scope of the compromise is still under investigation, but the incident underscores a persistent gap. For security teams worldwide, it reinforces that securing the trusted interaction loops between employees and internal support functions is as vital as any network safeguard. Protecting critical infrastructure now demands adaptive authentication and continuous, realistic training to counter increasingly sophisticated social engineering.


根據Security Affairs的一份報告,一場協調的黑客攻擊行動已入侵超過200個組織,其中包括多家頂級金融機構。攻擊者透過冒充各機構自身的IT支援台人員,竊取多重身份驗證(MFA)憑證。此行動凸顯了現代安全體系的一個關鍵漏洞:利用人類信任來繞過即使是最強健的技術控制。

該威脅組織以Redact及UNC6671等別名進行追蹤,搭建了極具說服力的釣魚入口網站,用以模仿內部IT支援環境。其目標名單包括黑石集團(Blackstone)、橋水基金(Bridgewater Associates)、阿波羅全球管理(Apollo Global Management)、貝恩資本(Bain Capital)、KKR、TPG、芝商所(CME Group)、Clearlake Capital及穆迪(Moody’s)等數十家機構。

此次攻擊的成功,關鍵在於一套利用合法職場流程的社會工程學劇本。攻擊者偽裝成IT人員,要求進行例行密碼重置或存取權限驗證,藉此降低員工的戒心。這種方法表明,主要的攻擊面往往是人類心理,而非系統漏洞。員工被訓練成服從內部權威,結果在社會工程學手段下,自願交出了即時MFA令牌,使標準防護措施失效。

分析這些攻擊的安全研究人員指出,其行動紀律顯示這是一次資源充足的行動。針對超過200家高價值金融實體的攻擊,暗示其目標超越簡單的憑證竊取,可能意圖獲取高價值情報或交易存取權限。使用多個組織名稱引發了分析,探究這是否是單一攻擊者使用的偽裝,還是一個共享基礎設施的聯盟。

作為回應,安全專家敦促進行根本性轉變,轉向以人為本的防禦措施。建議的即時行動是嚴格規定必須進行帶外驗證。所有憑證或存取請求必須透過獨立且預先建立的通訊渠道(例如致電已知號碼)進行確認,以打破攻擊者對互動過程的控制。

除了程序上的改變,過渡到抗釣魚認證至關重要。建議各組織逐步淘汰易受攻擊的短訊(SMS)及基於應用程式的MFA,改用FIDO2/WebAuthn硬件安全密鑰。這種密鑰與合法網域建立加密綁定,無法被釣魚。此舉代表轉向一個更安全的信任模型,與零信任原則一致。

配合這些技術與程序升級,基於情境的安全訓練不可或缺。通用的意識培訓模組必須被角色扮演演習取代,模擬IT支援台冒充策略,針對IT人員及一般員工。最後,主動式網域監測以偵測仿冒企業的網站,並透過威脅情報網絡快速移除,有助於及早破壞釣魚攻擊的基礎設施。

此次入侵的完整影響範圍仍在調查中,但這起事件凸顯了一個持續存在的缺口。對全球的安全團隊而言,它再次強調了確保員工與內部支援功能之間的信任互動環節,與任何網絡防護措施同等重要。保護關鍵基礎設施現在需要自適應認證及持續、逼真的訓練,以應對日益精密的社會工程學攻擊。

新聞來源 / Original News Source