Hackers impersonate U.S. government agencies in BEC attacks
ID: 1cc3dabb-4c68-5651-8b21-b9929bfe2653
STIX ID: report--1cc3dabb-4c68-5651-8b21-b9929bfe2653
Feed Name: Bleeping Computer
TA4903, a financially motivated BEC actor active since at least 2019 and intensified since mid-2023, is impersonating U.S. government agencies and small businesses in large-scale email campaigns. The group sends themed PDF attachments containing QR codes that redirect victims to phishing sites mimicking official portals to harvest O365 credentials; it previously used the 'EvilProxy' reverse proxy to bypass MFA. Organizations—particularly U.S. targets—should apply multi-layered defenses to detect and mitigate these phishing and BEC tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
