United States
U.S. law firms
Google and the FBI have warned U.S. law firms about a ransomware gang that has escalated its tactics by, in some cases, sending fake IT workers directly to victims’ offices.
On June 5, Google’s Mandiant and Google Threat Intelligence Group published a report detailing attacks by the Silent Ransom Group between January and May that targeted dozens of organizations. According to the report, the group used physical, in-person access to facilitate attacks, including planting insiders, bribing employees and gaining entry to office buildings to support cyber operations.
Just last month, the FBI warned that the Silent Ransom Group was targeting law firms through phishing and social engineering campaigns while impersonating IT support staff. In some incidents, attackers reportedly sent fake IT personnel to victims’ offices, where they connected to employee devices and used USB drives or remote access tools to steal contracts, Social Security numbers, financial records and tax information.
How it could affect your business
Impersonating IT or technical support staff has become an increasingly common tactic used by cybercriminals to gain access to sensitive systems and data. Under the guise of resolving a security or technical issue, attackers build trust and persuade targets to join screen-sharing sessions. They then attempt to bypass security controls by convincing victims to install remote access software or use screen-sharing features built into applications such as Zoom and Microsoft Teams. Users should always verify the identity and legitimacy of anyone requesting access to their devices or sensitive information before taking any action.
