A physical threat: hackers pose as IT support
The Google Threat Intelligence Group is sounding the alarm: a new threat situation is emerging in which cybercriminals extend their digital attack methods with physical components. The hacker group UNC3753, also known as Luna Moth, Chatty Spider or Silent Ransom Group, poses as IT technicians and gains direct access to company premises. The attackers then siphon off sensitive data directly from the endpoints using USB sticks.
This development marks a dangerous escalation in cybercrime. While attackers normally operate remotely via phishing emails or other digital methods, they are now switching to direct, physical attacks when their remote tactics fail.
Targets and modus operandi of the attackers
The hacker group UNC3753 focuses primarily on law firms in the USA, but also attacks insurance, financial and healthcare companies. Its focus is on legal agreements, personal data and financial records that are later to be used for extortion.
The attack begins digitally
The criminals follow a carefully devised scheme. First they research contact details on company websites and contact their victims by telephone or email. In doing so they pose as employees of the company's own IT or security department.
The attackers alert the victim to supposed security vulnerabilities or offer help with invented data migration projects. Through these deceptive manoeuvres they systematically build trust and try to persuade their victims to join remote maintenance sessions.
Use of legitimate software
Especially insidious is the use of common screen-sharing software such as Zoom, Microsoft Terminal Services, Microsoft Teams or Quick Assist. In one documented case, an attacker held five conversations with his victim via Teams within three days.
In addition, the criminals try to get their victims to install specific remote software, including AnyDesk, Bomgar or Zoho Assist. In one case a user was even asked to download a "SuperOps RMM agent" via cURL.
Data transfer and physical attacks
Digital data theft
Once the attackers have won their victims' trust, the actual data extraction begins. They log in to file-sharing accounts directly in the victim's browser and upload files – either themselves or by instructing the victim. In doing so they even imitate the target company's branding.
Programs such as WinSCP or Rclone are used for the data transfer. In one documented case the attackers transferred around 1.7 gigabytes of data from a local OneDrive folder to a Google Drive account. They also instructed victims to send files from the legal software iManage to the hackers directly by email.
Physical infiltration as a last resort
If their remote tactics fail, the attackers go a step further and try to obtain the data physically. The FBI already warned of this development at the end of May. The criminals again present themselves as IT support and pretend that they need to create a backup. For this purpose they use external hard drives or simple USB sticks.
Once the data has been extracted successfully, extortion follows: the hackers send a blackmail email to the affected company and threaten to publish the stolen information.
Protective measures and prevention strategies
Access control and staff training
The FBI recommends strict control of the authorisations of everyone entering company premises. Professional access control can help to identify unauthorised individuals and restrict access to sensitive areas.
At the same time, staff training is of decisive importance. Employees must be made aware of social engineering attacks and learn to recognise suspicious approaches. Restricting the ability to connect external drives is another important protective measure.
Technical monitoring and control
Google advises strict monitoring of outbound data traffic and of the network. The exfiltration of several gigabytes of data should not go unnoticed. Companies should block unauthorised file-sharing services and record the volumes of transferred data in their firewall logs.
Particular attention should be paid to SSH traffic on port 22, which should be checked specifically for bulk transfers. Regularly created backups offer additional protection against data loss.
What this means for corporate security
This new attack method shows that cybersecurity today extends far beyond the purely digital domain. The combination of social engineering, digital attacks and physical intrusion calls for a holistic security concept.
Companies must rethink their security strategies and implement both digital and physical protective measures. The threat posed by UNC3753 makes clear that criminals are willing to invest considerable effort to get hold of valuable data.
The warnings from Google and the FBI underline the urgency of building security awareness and implementing appropriate protective measures. Only through a combination of technical solutions, organisational measures and trained employees can companies protect themselves effectively against this novel threat.