Voice Phishing Attacks Target Hedge Fund Employees
ID: eb709f8a-50de-5658-9c29-7650dd1edc35
STIX ID: report--eb709f8a-50de-5658-9c29-7650dd1edc35
Feed Name: KnowBe4 Blog
Google Threat Intelligence Group reports that UNC6671 (formerly BlackFile) is running a targeted vishing campaign against hedge funds and enterprise organizations, calling employees’ personal phones and spoofing helpdesk numbers to lure victims to lookalike authentication enrollment portals. The actors deploy Adversary-in-the-Middle infrastructure to intercept credentials and MFA tokens, establish session persistence, and run automated scripts to exfiltrate data from cloud environments (including Microsoft 365 and Okta); domain registration patterns and tailored subdomains indicate targeted, large-scale credential-harvesting activity across multiple industries observed in April–May 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
