Large corporations are being targeted by sophisticated social engineering attacks that aim to convince mid-level employees into initiating large financial transfers under the guise of fake merger & acquisition (M&A) deals. The campaign, dubbed “Phantom Deal,” has already claimed several victims, with at least five companies in its crosshairs.
Threat actors behind Phantom Deal have done their homework, studying the target companies’ internal structures and identifying potential employees who might be involved in M&A negotiations. They then use this information to craft personalized phishing messages that appear to come from a company executive or lawyer. These messages are often sent via WhatsApp or personal email addresses, making it harder for corporate monitoring systems to detect them.
In one notable case, the attackers targeted Gen, the parent company of cybersecurity brands Norton and Avast. The threat actors impersonated an executive and sent a message to a member of Gen’s legal team, claiming that they were facilitating a major corporate acquisition involving the company’s subsidiaries. The details were vague, but the attacker built on real corporate history to create a plausible M&A context.
The attackers’ methodology was quite sophisticated, but their individual scenario was imperfect. They asked for an oddly specific €626,735.45 Euro transaction to be sent to a company in Hong Kong to facilitate the deal. Luckily, the employee and the attackers got on the phone, and the employee recognized that the impersonated executive’s voice was wrong. At that point, the attackers became the attack-ees.
The Phantom Deal campaign is a classic example of an advance fee scam, where attackers convince their targets to send money upfront under false pretenses. The stakes are higher than ever, with companies facing massive losses if they fall victim to these scams. According to Luis Corrons, Gen’s security evangelist, “Scams are becoming so convincing that even the most trained eye can have trouble spotting them.”
The researchers were able to identify four other targets of the same campaign using metadata from the fake NDA and tracking the attacker’s actions and connections. The targets were all senior employees belonging to companies from different sectors: private equity, industrial finance, sales, mining, and energy.
Phantom Deal highlights the importance of employee education and awareness in preventing such attacks. Companies need to ensure that their employees are aware of these tactics and know how to identify suspicious messages or requests. It’s also crucial for companies to have robust monitoring systems in place to detect and prevent such attacks.
In conclusion, Phantom Deal is a sobering reminder of the ongoing threat posed by sophisticated social engineering attacks. Companies must remain vigilant and take proactive measures to protect themselves against these types of threats. As Corrons warns, “The same playbook could have been much more dangerous with a more coherent story.”
Source: Dark Reading — 2026-09-03