The attacker repeatedly followed up for an MT103 | Image: Gen Digital
At a Glance
| Actor or group | Unidentified cybercrime actors (dubbed Phantom Deal operators) |
| Activity type | Executive impersonation, fake acquisition fraud, wire fraud |
| Targets or victims | Corporate legal, finance, and M&A executives |
| Scale | Claimed 626,735 euro transfer attempt; at least five corporate targets |
| Jurisdiction or law-enforcement status | Active investigation; no arrests announced |
| Source | Gen Digital |
TL;DR
Cybersecurity researchers at Gen Digital uncovered an executive impersonation scam dubbed the Phantom Deal campaign. The fraudsters impersonated company leaders and legal advisers to fabricate a confidential corporate acquisition. Ultimately, the attackers attempted to steal over 626,000 euros through fraudulent international wire transfers.
What Happened
Initial Contact on WhatsApp
The incident began when an employee in Gen’s legal department received an unexpected WhatsApp message. The sender claimed to be a company executive based in Dublin. In addition, the profile displayed the executive’s real name, photo, and an Irish telephone number. The message simply asked if the employee was currently at the office. However, the recipient knew the executive personally and noticed an unfamiliar phone number. A follow-up phone call quickly confirmed the suspicion because the caller’s voice did not match.
The Forged Non-Disclosure Agreement
Instead of ending the conversation, the legal employee collaborated with internal security researchers to track the fraudster. Soon after, a second actor entered the chat posing as an external legal adviser from PwC. This person requested a private personal email address to send confidential documents. The attacker then delivered a forged non-disclosure agreement. Crucially, the document ordered the employee to keep all deal discussions on WhatsApp and private email.
The contract referenced real corporate entities from Gen’s merger history, including Avast Software and NortonLifeLock. This backstory created a believable context for an urgent intercompany transaction. As Gen researchers noted in their report, “The NDA was not an accessory to the attack. It was the payload.” The attackers used the legal document to isolate the victim from standard corporate oversight channels.
Demands for International Wire Transfers
Next, the scammers sent specific payment instructions for a fictitious corporate acquisition. They instructed Avast Software to transfer 626,735.45 euros to a commercial bank account in Hong Kong. The attackers described this payment as an advance retainer fee for professional advisory services. Furthermore, they created artificial urgency by claiming the public deal announcement would happen within days.
Immediately after sending instructions, the threat actor aggressively demanded confirmation of the payment. Specifically, the scammer insisted on receiving a SWIFT MT103 document and a unique transaction reference number. The attacker wrote, “I need a swift MT103, it’s an official proof of wire transfer to attached to the package.” This banking documentation would allow the scammers to monitor the funds and quickly move the stolen money.
Turning the Fraud into Threat Intelligence
Rather than executing the payment, the security team sent back decoy financial documents. They created a fake payment confirmation email mimicking Citibank and embedded a tracking canary token. When the scammer opened the link, the token logged the visitor’s network data. Over 24 days, the token recorded 49 requests across 43 IP addresses. The data revealed that the attackers accessed the tracking link through virtual private networks and proxies.
Security analysts detailed the entire investigative operation in their analysis of the Phantom Deal campaign. They emphasized that this operation avoided traditional technical exploits entirely. According to the report, “The attack was designed to induce a process failure rather than exploit a technical vulnerability.”
Who Is Behind It
Impersonation and Attribution Clues
Investigators hold moderate confidence that an organized cybercrime syndicate runs the Phantom Deal operation. The actors rely on business email compromise tactics, corporate impersonation, and social engineering rather than software vulnerabilities. They conduct detailed open-source research on corporate leadership, historical mergers, and reporting structures before launching an attack. Furthermore, the operators frequently abuse trusted advisory brands, including PwC, KPMG, and Ogier, to fabricate legitimacy. None of these professional service firms were breached during the campaign.
Impact or Scale
Multiple Corporate Targets Identified
The Phantom Deal fraud extends well beyond a single attempt against Gen Digital. By analyzing the embedded formatting and unique numeric fingerprints of the forged agreements, researchers identified four additional corporate targets. These targets held senior leadership positions across private equity, industrial finance, energy, and mining sectors. In each case, the attackers adjusted the company names while reusing the identical legal text. Fortunately, rapid detection prevented financial losses in the observed Gen intrusion.
What Comes Next and How to Stay Protected
Verifying Sensitive Corporate Transactions
Threat groups will likely continue using fake legal documents to bypass corporate security controls. Organizations must enforce strict verification protocols for all outgoing wire transfers. First, finance teams must verify transaction requests through established, out-of-band channels. Never rely on phone numbers or email addresses provided inside incoming messages. Second, companies should prohibit staff from conducting official transaction business over private messaging apps. Finally, compliance rules must require multi-person authorization for major financial transfers. As the researchers concluded, “An NDA can limit who is told about a transaction.” They warned that confidentiality should never prevent proper transaction authentication.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!