logo

Hackers impersonate U.S. government agencies in BEC attacks

ID: 1cc3dabb-4c68-5651-8b21-b9929bfe2653

STIX ID: report--1cc3dabb-4c68-5651-8b21-b9929bfe2653

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-03-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

TA4903, a financially motivated BEC actor active since at least 2019 and intensified since mid-2023, is impersonating U.S. government agencies and small businesses in large-scale email campaigns. The group sends themed PDF attachments containing QR codes that redirect victims to phishing sites mimicking official portals to harvest O365 credentials; it previously used the 'EvilProxy' reverse proxy to bypass MFA. Organizations—particularly U.S. targets—should apply multi-layered defenses to detect and mitigate these phishing and BEC tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.