UNC6671 is carrying out data theft campaigns that begin with a phone call. The group poses as an IT helpdesk, claiming an urgent security migration is necessary. A convincing call and a fake sign-in page can turn an ordinary session into an entry point. The calls create urgency before employees can verify the request independently. The campaign is dangerous because it does not need to crack a password. It captures credentials and a live authentication token. That token lets an intruder act as the employee in Microsoft 365 or Okta, to access mail, files and other stored corporate data. Analysts at Google Cloud identified the activity during ongoing data theft and extortion. Google Cloud said in a report shared with Cyber...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!