Une usurpation cible les services communication
An impersonation campaign is targeting businesses by mimicking Damien Bancal and ZATAZ to gain access to internal contacts and initiate a social engineering operation. The attacker uses a fabricated email chain to map out an organization’s structure and identify key personnel involved in fraud, security, or payment processing. The campaign leverages the legitimate roles of service presses and communications departments to gain access to internal contacts and build a more convincing second contact. ZATAZ emphasizes that they never contact companies directly via email and urges recipients to verify any communication against the official address and PGP signature.
An impersonation campaign is targeting businesses by mimicking Damien Bancal, a cybersecurity journalist, and ZATAZ, a cybersecurity expertise and analysis firm. The attacker’s approach bypasses technical defenses by exploiting the established roles within organizations, specifically targeting service presses and communications departments. The initial contact, often presented as a journalistic inquiry regarding two payment-processing sites, aims to elicit an email address from a specific individual involved in fraud, security, payments, or institutional relations.
This tactic relies heavily on social engineering, utilizing a credible scenario, a known identity, and a seemingly legitimate request. The attacker leverages the fact that ZATAZ has a ‘huge address book’ to build a second, more targeted contact. The campaign is not new and has been used by cybersecurity firms themselves to conduct their own operations.
Key indicators of a fraudulent message include: the absence of an official email address (no Proton, Gmail, Outlook, or ZATAZ.com addresses), the lack of a PGP signature, and the absence of attachments sent via email (Bluefiles is used instead). The attacker will then adapt their approach, referencing the initial contact and referencing a previous exchange to build a more convincing narrative.
ZATAZ stresses that they never contact companies directly via email and urges recipients to verify any communication against the official address and PGP signature. A simple test is to initiate a new message to the known official address, without responding to the initial email. This campaign highlights a core principle of cyber intelligence: attackers often don't seek to exploit software vulnerabilities; instead, they leverage habits, functions, and trust to reach their targets.
