Cybercriminals are executing the 'Phantom Deal' campaign, using deep reconnaissance to trick mid-level employees into making massive fraudulent financial transfers under the guise of M&A deals.
A sophisticated new wave of social engineering is sweeping through large enterprises, known as the 'Phantom Deal' campaign. In this highly orchestrated scheme, threat actors are leveraging deep-dive research into target companies to manipulate employees into authorizing massive, fraudulent financial transfers under the pretext of confidential merger and acquisition (M&A) activities.
The cybersecurity giant Gen, parent company of Norton and Avast, recently narrowly escaped a devastating attack. Attackers targeted a member of Gen's legal team, impersonating a senior executive via WhatsApp. By utilizing real corporate history—such as the 2022 acquisition of Avast by NortonLifeLock—the criminals constructed a narrative so plausible that it could have easily bypassed standard scrutiny.
Why This Matters
BozokMedia analysis shows that these attacks are shifting away from brute-force technical hacks toward psychological manipulation. By using publicly available information, attackers create a 'veneer of legitimacy' that makes even seasoned professionals question their own instincts. This represents a critical evolution in cyber risk management where human intelligence becomes the primary battleground.
'Scams are becoming so convincing that even the most trained eye can have trouble spotting them.' - Luis Corrons, Gen Security Evangelist.
The attackers didn't stop at impersonating executives; they also masqueraded as intermediaries from top-tier professional services firms like PricewaterhouseCoopers (PwC). They provided fraudulent Non-Disclosure Agreements (NDAs) branded with PwC logos, instructing employees to keep all communications on private platforms like WhatsApp to evade corporate IT monitoring systems. The ultimate goal was a specific transaction of €626,735.45 to an entity in Hong Kong.
The scheme only collapsed when a vigilant employee noticed discrepancies in the executive's voice during a phone call. This human intervention allowed the security team at Gen to pivot from defense to investigation, using a fake transaction confirmation email to track the attackers' metadata and identify four other targeted companies across various sectors, including mining and energy.
Frequently Asked Questions
1. How do attackers gain such detailed information about companies?
They perform extensive reconnaissance using public websites, LinkedIn, and news reports to learn names, roles, and historical deal structures.
2. What is the best defense against social engineering?
Strict adherence to multi-channel verification and ensuring that no financial transaction can be authorized through unofficial communication channels like WhatsApp.