Researchers uncovered Phantom Deal, an M&A-themed business-email-compromise and advance-payment fraud campaign that impersonates executives and advisers to manufacture confidential acquisition transactions. In an attempted theft targeting Gen Digital's legal team, operators used WhatsApp, personal email, realistic corporate details, and a forged PwC-branded non-disclosure agreement to pressure Avast Software s.r.o. into wiring €626,735.45 to a Hong Kong company. The targeted employee identified an inconsistency in the impersonator's voice and did not send funds.
The attackers sought to isolate the employee from normal corporate channels, weaponizing deal secrecy to bypass legal, finance, treasury, compliance, and corporate-development review. During a controlled engagement, Gen researchers recorded repeated accesses to a canary-linked false payment confirmation; the fraudsters also requested SWIFT MT103 and UETR payment-tracking details. Analysis linked the operation to four additional targets and a reusable toolkit using PwC, KPMG, and Ogier branding, although investigators found no evidence that those firms were compromised or involved. Organizations should require independent out-of-band verification for executive-directed payments and confidential transaction requests.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
NortonLifeLock completed its acquisition of Avast in 2022, resulting in Gen Digital. Phantom Deal operators later referenced this real transaction to support their fabricated acquisition narrative.
Researchers matched document structure, language, and embedded identifiers to identify four additional people targeted with related fraudulent NDAs. The samples reused a suspected M&A-fraud package while varying names, dates, transaction details, and PwC, KPMG, or Ogier branding; Gen found no evidence those firms were compromised or involved.
After the scam was identified, the targeted employee and Gen researchers conducted a controlled exchange, supplying a fake account statement and a Citibank-style payment confirmation containing a canary link. The link recorded 49 HTTP requests from 43 IP addresses over 24 days; filtering indicated repeated VPN, proxy, and non-hosting-network access consistent with manual interaction, but telemetry did not support attribution.
A second persona posing as a PwC-associated professional sent a forged NDA that required WhatsApp and personal-email communications and discouraged consultation with internal controls. The fraudsters sought a €626,735.45 “Advance Retainer for Professional Services” wire transfer from Avast Software s.r.o. to a Hong Kong company and requested SWIFT MT103 and UETR details.
Operators contacted a Gen legal-team member on WhatsApp while impersonating a genuine Dublin-based Gen executive, using the executive's name, photo, and an Irish phone number. The employee identified the fraud after recognizing that the caller's voice did not match the impersonated colleague.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcegendigital.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.