Threat Advisory

TA4903: Actor Spoofs U.S. Government, Small Businesses in Phishing attacks

Threat: Phishing Campaign
Criticality: High
[subscribe_to_unlock_form]

Summary:

A group of hackers identified as TA4903 has been conducting sophisticated Business Email Compromise (BEC) attacks by impersonating various U.S. government agencies. This tactic involves sending malicious files containing links to fake bidding processes to unsuspecting targets. Researchers has tracked the activities of this threat actor. The latest tactic observed involves the use of QR codes in PDF document attachments to redirect recipients to phishing sites designed to mimic official government portals.[/subscribe_to_unlock_form]

Summary:

A group of hackers identified as TA4903 has been conducting sophisticated Business Email Compromise (BEC) attacks by impersonating various U.S. government agencies. This tactic involves sending malicious files containing links to fake bidding processes to unsuspecting targets. Researchers has tracked the activities of this threat actor. The latest tactic observed involves the use of QR codes in PDF document attachments to redirect recipients to phishing sites designed to mimic official government portals.[emaillocker id="1283"]

The phishing emails sent by TA4903 contain PDF attachments themed after the spoofed organization, featuring consistent designs. Recipients scanning QR codes are redirected to phishing sites resembling official portals of impersonated U.S. government agencies, where they may be prompted to enter their credentials. While TA4903 previously used 'Evil Proxy' to bypass multi-factor authentication. The group's activities are financially motivated, targeting corporate networks and email accounts to gain unauthorized access, search for banking information, and execute BEC attacks by sending fraudulent payment requests.

TA4903 poses a significant threat to organizations globally, primarily targeting those in the U.S. with high-volume email campaigns. While initially spoofing U.S. government entities. The complexity of their BEC attacks underscores the need for organizations to adopt comprehensive, multi-layered security strategies to mitigate such threats effectively. By understanding the tactics employed by threat actors like TA4903 and implementing robust security measures, organizations can better defend against BEC attacks and safeguard their sensitive information.

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/hackers-impersonate-us-government-agencies-in-bec-attacks/

[/emaillocker]
crossmenu