United Services Automobile Association
Incident posture
Linked entities
- Victim
- United Services Automobile Association
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A financially motivated threat actor known as GS7 conducted a large-scale phishing campaign called Operation DoppelBrand, targeting Fortune 500 financial, insurance, and technology companies including USAA. Between December and January, the operation used more than 150 lookalike domains and cloned login portals to harvest employee credentials, routing stolen data such as IP addresses, geolocation, and device details to attacker-controlled Telegram bots. Beyond credential theft, GS7 deployed legitimate remote monitoring tools to establish persistent, unattended access and acted as an initial access broker, selling compromised accounts to affiliates. The infrastructure relied on automated domain registration, short-lived SSL certificates, and Cloudflare hosting, enabling rapid subdomain creation. A shared cryptocurrency wallet received approximately 0.28 BTC during the campaign, indicating illicit financial gain.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Between December 2025 and January 2026, cybersecurity researchers at SOCRadar identified a large-scale phishing campaign that targeted major financial and technology firms, including United Services Automobile Association (USAA) and Wells Fargo. The operation, dubbed Operation DoppelBrand by the researchers, was attributed to a financially motivated threat actor tracked as GS7, whose infrastructure showed links to earlier activity dating back to 2022. The campaign focused on Fortune 500 companies across banking, insurance, investment, technology, and healthcare sectors, with English-speaking markets, particularly the United States and Western Europe, accounting for the bulk of the observed activity.
The attackers registered more than 150 domains tied to the latest wave of activity, with nearly 200 additional domains exhibiting similar characteristics. These domains used one-year registration terms and relied on rotating registrars such as Namecheap and OwnRegistrar, Cloudflare hosting, and short-lived SSL certificates issued by Let's Encrypt or Google Trust Services within hours of domain registration. Wildcard DNS records enabled rapid subdomain creation, allowing brand-specific subdomains to mimic legitimate banking, insurance, and technology providers.
Victims were lured through phishing emails and redirected to counterfeit login portals that closely imitated legitimate websites. The phishing pages replicated visual elements of the genuine sites, including logos, CSS styles, and login form layouts. In some cases, victims were routed through fake OneDrive interfaces before being presented with spoofed banking portals. Once credentials were submitted, the data was transmitted to Telegram bots controlled by the attacker, which also captured additional information such as IP address, geolocation, and device details, allowing the attacker to filter and prioritize targets.
Beyond credential theft, GS7 deployed legitimate remote management and monitoring software, specifically LogMeIn Resolve, to establish persistent, unattended access to compromised systems. Installers were delivered as MSI files, often accompanied by small VBS loaders that handled privilege escalation, silent installation, and cleanup. Researchers noted that the attacker appeared to act as an initial access broker, selling or transferring compromised accounts to affiliates. In a direct exchange with SOCRadar, an individual claiming to be GS7 reportedly stated they had been operating for around ten years and provided screenshots of phishing panels bearing their handle.
Blockchain analysis of a cryptocurrency wallet shared during the investigation showed roughly 0.28 BTC received, equivalent to between $25,000 and $32,000 depending on the market price at the time. SOCRadar published its findings on February 16, 2026, detailing the tactics, techniques, and procedures used by the threat actor. The report highlighted the highly automated nature of the infrastructure and the use of trusted brand names as lures to increase the success rate of credential theft against targeted organizations and their customers.
Sources
Sources available to members: 1 source.