Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Vendor Email Compromise (VEC): The Classic Business Email Compromise (BEC) Scheme wit
#1
Exclamation 
Quote:
[Image: heimdal-logo.svg]

How Cybercriminals Behind VEC Attacks Operate

A new email fraud scheme has taken Business Email Compromise (BEC) to a whole new level of sophistication. The recently discovered type of email scam has been dubbed Vendor Email Compromise (VEC) and as its name suggests, the attackers prey on employees working at vendor companies.

A new cybercriminal group, identified as Silent Starling by researchers at Agari, ran these malicious email campaigns. The fraudsters hacked the email accounts of employees working in the target’s finance department and gathered as much information as they could from their inboxes. In the end, the scammers sent them perfectly timed payment requests accompanied by fake invoices.

Since late 2018, over 700 employee accounts from more than 500 companies in the United States and over a dozen other countries have been compromised. Consequently, more than 20,000 sensitive emails have been harvested.

Vendor Email Compromise, a new milestone in the evolution of BEC attacks

Traditionally, a BEC attack is based upon what is commonly referred to as CEO fraud or the impersonation of an upper or middle-management employee. In this case, fraudsters contact their “colleagues” from the financial department, requesting an urgent payment and providing all the necessary details for the money to be transferred. Since the email comes from a superior and the message is transmitted with a sense of urgency, employees are likely to fall for this scam, being completely unaware the money will end up in a cybercriminal’s account.

And now, through this social engineering tactic, impostors are targeting a new niche: vendors.

More precisely, scammers are preying on employees working in a vendor’s finance department, with the ultimate goal of gathering intelligence on customers they interact with.

Who are the attackers behind Silent Starling?

The criminal group originates from West Africa and has been involved in fraudulent practices since 2015. First, they engaged in romance scams and check fraud and transitioned to BEC attacks in mid-2016, Agari writes. In their first two years of BEC, they focused on wire transfer requests and gift card attacks, only at the end of 2018 shifting their focus to VEC scams.

Three main malicious actors belonging to the cyber-gang have been identified, but at least eight other group members may have been involved. Each of these individuals was in charge of certain tasks, such as collecting leads to be targeted, finding mule accounts or hijacking and scanning compromised email accounts in search of relevant information.

How do Vendor Email Compromise attacks work?

Similarly, as I’ve briefly mentioned above, both BEC and VEC scams are based on social engineering. But what sets them apart is that VEC attacks are targeting a supplier’s customers, who receive what looks like realistic payment requests for an actual service they are expecting to pay for.

But how do VEC scams actually work?

Since they are highly elaborate schemes, they are conducted through multiple stages. Below you can see the main phases of Vendor Email Compromise attacks:

Quote:Attack Phases / Description

Phase 1 The first phishing wave / Target: Vendors
Phase 2 Account takeover
Phase 3 Inbox monitoring
Phase 4 The second phishing wave / Target: The vendors’ customers
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
ThunderSoft Photo Gallery Creator [for ...
ThunderSoft Photo Ga...ismail — 09:51
DVDFab Photo Enhancer AI [PC]
DVDFab Photo Enhance...ismail — 09:47
Smart Game Booster 5 Pro [for PC]
    Your Gaming E...ismail — 09:46
Ashampoo Home Design 9 [for PC]
  Home plannin...ismail — 09:37
MobiKin Transfer for Mobile 4.1.17
MobiKin Transfe...ismail — 09:33

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (49)Toligo

[-]
Online Staff
There are no staff members currently online.

>