BlackFile Group Targets Retail and Hospitality with Vishing Attacks
ID: 0019bac9-5a06-5d65-bbfc-d0f91acfd733
STIX ID: report--0019bac9-5a06-5d65-bbfc-d0f91acfd733
Feed Name: Infosecurity Magazine (News)
Threat Score
Palo Alto Networks Unit 42 and RH-ISAC published a report on April 23 detailing BlackFile (activity cluster CL-CRI-1116), a financially motivated extortion group targeting retail and hospitality that uses vishing and credential phishing to register devices and bypass MFA, then abuses legitimate APIs and SSO sessions to scrape and exfiltrate sensitive data from SharePoint and Salesforce before demanding large ransoms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
