A coordinated law enforcement operation by Interpol and the Nigerian Police Force (NPF) has resulted in the arrest of 11 members allegedly belonging to a Nigerian cybercrime gang involved in performing business email compromise (BEC) attacks targeting more than 50,000 victims in recent years.
The disruption of the BEC network was done as a result of a ten-day investigation dubbed Operation Falcon II undertaken by the Interpol along with participation from the Nigeria Police Force’s Cybercrime Police Unit in December 2021.
Cybersecurity firms Group-IB and Palo Alto Networks’ Unit 42, said that six of the 11 suspects are believed to be a part of a prolific group of Nigerian cyber actors known as SilverTerrier (aka TMT).
BEC attacks are sophisticated scams that target legitimate business email accounts through social engineering schemes to infiltrate corporate networks and subsequently leverage their access to initiate or redirect the transfer of business funds to attacker-controlled bank accounts for personal gain.
Interpol stated that one of the arrested suspects was in possession of more than 800,000 potential victim domain credentials on his laptop. While another suspect had been monitoring conversations between 16 companies and their clients and diverting funds to ‘SilverTerrier’ whenever company transactions were about to be made.
SilverTerrier was linked to 540 distinct clusters of activity to date and were adopting remote access trojans and malware packaged as Microsoft Office documents to mount their attacks. Unit 42, in a report published in October 2021, said it identified over 170,700 samples of malware directly attributed to Nigerian BEC actors since 2014.
Unit 42 researchers said that BEC remains the most common and costly threat facing their customers. Over half a decade, global losses have increased from $360 million in 2016 to a shocking $1.8 billion in 2020.
In order to mitigate such financial attacks, the organizations are recommended to review network security policies, periodically audit mail server configurations, employee mail settings, and conduct employee training to ensure that wire transfer requests are validated using verified and established points of contact for suppliers, vendors and partners.
Image Credits : Journal of Democracy
















Comments