Phantom Deal Hackers Impersonate Executives and Use Fake NDAs to Steal Corporate Wire Transfers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Cybercriminals are using fake acquisition deals to steer employees toward large wire transfers. The campaign, called Phantom Deal, begins with a believable WhatsApp message from someone appearing to be a known executive.

It turns everyday corporate safeguards into barriers that the victim is told must be avoided to protect a confidential transaction. The operators used no malware, stolen mailbox, or malicious attachment.

Instead, they combined real names, photographs, company history and familiar deal language to make a fictional transaction seem routine. The case shows how a financial attack can develop inside ordinary business conversations.

Analysts at Gen Digital identified the campaign after an attacker contacted a member of its legal team while posing as a Dublin-based executive.

The employee recognised that the caller’s voice did not match the colleague being copied, then worked with researchers to document the attempt rather than send funds.

The initial WhatsApp approach used two impersonated identities (Source - Gen Digital)
The initial WhatsApp approach used two impersonated identities (Source – Gen Digital)

Gen Digital said in a report shared with Cyber Security News (CSN) that the investigation also found four other targeted individuals who had received closely related non-disclosure agreements, or NDAs.

Their employers and supposed advisers differed, but the documents reused the same structure, confidentiality requirements and template traces. The repeated pattern suggests a broader, reusable fraud package directed at people close to corporate transactions.

Phantom Deal Hackers Impersonate Executives and Use Fake NDAs

The opening WhatsApp message was intentionally harmless, asking whether the recipient was at the office.

After contact was established, a second impersonated person, presented as a professional associated with PwC, requested a personal email address. The next step was a polished, PwC-branded NDA describing a secret acquisition and strict disclosure rules.

The NDA was not simply supporting paperwork. It directed the recipient to discuss the acquisition only through WhatsApp and personal email, while keeping colleagues out of the conversation.

Restricted access can be normal in a real deal, but moving an important request away from approved channels is a warning sign also seen in WhatsApp CEO fraud tactics.

Payment instructions then asked Avast Software s.r.o. to transfer €626,735.45 to a Hong Kong company as an “Advance Retainer for Professional Services.”

Anatomy of Phantom Deal (Source - Gen Digital)
Anatomy of Phantom Deal (Source – Gen Digital)

The criminals said the sum would be recorded as an intercompany receivable and reimbursed after the announcement. In reality, the language wrapped a straightforward advance-payment fraud in terms familiar to legal and finance teams.

The attackers later demanded a SWIFT MT103, the banking message that proves an international transfer was executed.

They also requested the UETR payment-tracking reference, potentially allowing them to monitor the transfer and reduce the time available for the company or bank to intervene.

Independent Checks Break the Chain

Researchers found no evidence of a compromised corporate mailbox or a technical exploit. The fraud instead targeted a business process: convince one employee that confidentiality required bypassing legal, finance, treasury, compliance and corporate-development controls.

Security teams that search only for suspicious attachments or links could therefore miss the operation from its first contact. During the controlled exchange, researchers sent a fake payment-confirmation email containing a tracked link.

The controlled response included a fake account statement and a fake payment-confirmation email (Source - Gen Digital)
The controlled response included a fake account statement and a fake payment-confirmation email (Source – Gen Digital)

It recorded 49 HTTP requests from 43 IP addresses over 24 days, though automated scanners, cloud services and redirect-analysis systems raised the raw count. After filtering, the team still observed repeat access through VPNs, proxies and non-hosting internet connections.

Companies should verify any payment instruction through a contact method independently established before the transaction, rather than details supplied in the conversation. When an adviser’s identity or request is uncertain, staff should use an official directory to confirm it.

That discipline matters as criminals increasingly send authenticated phishing messages that can look more trustworthy than conventional spam.

The core lesson is straightforward: an NDA can limit who is told about a transaction, but it cannot remove the need to authenticate it. Independent confirmation before any cross-border transfer can stop the scheme before money leaves the account.

Recent action against business email compromise infrastructure underlines why that control remains vital, even when a scam begins outside an inbox.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Phantom Deal Hackers Impersonate Executives and Use Fake NDAs to Steal Corporate Wire Transfers appeared first on Cyber Security News.