Researchers at Gen Digital are tracking a sophisticated social engineering campaign that’s using phony NDA documents to trick employees into moving the conversation to WhatsApp and personal email accounts. The attackers targeted an employee at Gen itself, but the employee recognized that it was a scam and played along to see what the attackers would do.
The threat actors first impersonated a real Gen executive based in Dublin, who introduced a second impersonated person who claimed to work at PwC.
“After the initial exchange, a second person entered the conversation,” the researchers write. “This time, the attacker impersonated a genuine professional associated with PwC and asked the target to provide a private email address. That request was not incidental. The forged NDA that followed instructed the recipient to keep all communication related to the acquisition on WhatsApp and personal email. The attackers tried to keep the entire exchange outside corporate communication channels before introducing any payment request.”
The threat actors performed extensive research before launching the attack, referencing the history of the targeted company and coming up with a phony business deal that could have been real.
“The acquisition narrative referenced Avast Software and NortonLifeLock Ireland Limited, drawing on the real acquisition of Avast by NortonLifeLock in 2022 and the subsequent creation of Gen Digital,” the researchers write. “The names were familiar, the corporate relationship had existed, and an intercompany transaction could appear plausible to someone operating under pressure and secrecy.”
Fortunately, Gen’s employee noticed red flags associated with the request, but the attack could have been more convincing if the threat actors had ironed out these details.
“This was not a generic message sent to thousands of employees,” the researchers write. “The story had been adapted to its target. The targeting was tailored, but the execution was not flawless. David quickly identified inconsistencies in the explanation for why Avast should make a payment on behalf of NortonLifeLock Ireland Limited. His legal background and familiarity with internal transaction processes made those gaps easier to spot. A more coherent payment narrative could have made the same playbook considerably more convincing.”
Gen Digital has the story: https://www.gendigital.com/blog/insights/research/phantom-deal
