Wells Fargo & Company
Incident posture
Linked entities
- Victim
- Wells Fargo & Company
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A phishing campaign known as Operation DoppelBrand targeted major financial and technology firms, including the specified victim, using lookalike domains and cloned login portals to harvest user credentials. Discovered by SOCRadar, the operation employed counterfeit banking websites, fake OneDrive interfaces, and automated infrastructure with short-lived SSL certificates and wildcard DNS records to lure victims and exfiltrate sensitive data to attacker-controlled Telegram bots. Beyond credential theft, the financially motivated threat actor deployed legitimate remote management tools to establish persistent, unattended access on compromised systems, reportedly operating as an initial access broker. The campaign affected hundreds of domains and leveraged phishing panels to sell or transfer compromised accounts to affiliates, generating modest illicit proceeds in cryptocurrency.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Between December 2025 and January 2026, a financially motivated phishing campaign identified as Operation DoppelBrand targeted major United States financial and technology firms, including Wells Fargo. Cybersecurity researchers at SOCRadar attributed the activity to a threat actor tracked as GS7 and noted that the infrastructure supporting the campaign showed links to earlier operations dating back to 2022. The campaign primarily focused on Fortune 500 companies, with English-speaking markets in the United States and Western Europe accounting for the bulk of observed victim activity. Targets spanned major US financial institutions, investment firms, insurance providers, and global technology and healthcare brands, suggesting a broad effort to harvest credentials from organizations holding sensitive customer data.
The attack relied on lookalike domains and cloned login portals designed to closely imitate the legitimate websites of banks, insurance companies, and technology providers. SOCRadar identified more than 150 domains tied to the latest wave of activity, along with nearly 200 additional domains displaying similar characteristics. These domains were registered through rotating registrars such as Namecheap and OwnRegistrar, hosted behind Cloudflare, and equipped with short-lived SSL certificates issued by Let's Encrypt or Google Trust Services within hours of registration. The domains typically carried one-year registration terms and relied on wildcard DNS records to enable rapid subdomain creation, with brand-specific subdomains crafted to mimic the appearance of genuine banking, insurance, and technology services.
Victims were lured through phishing emails that directed them to counterfeit login pages replicating the visual elements of legitimate sites, including logos, CSS styles, and login form layouts. In some cases, victims were first routed through fake OneDrive interfaces before being presented with spoofed banking portals, a tactic intended to build trust before credential collection. When victims submitted their login information, the harvested data, which included IP address, geolocation, and device details, was forwarded to Telegram bots and groups controlled by the attacker. This allowed the operator to filter, prioritize, and manage incoming credential submissions in near real time.
Beyond credential theft, the operation escalated to deploying legitimate remote management and monitoring software onto compromised systems in order to establish persistent access. Installers for software such as LogMeIn Resolve were delivered as MSI files, often accompanied by small VBS loaders that handled privilege escalation, silent installation, and cleanup of artifacts. Researchers observed that the attacker appeared to function as an initial access broker, selling or transferring compromised accounts to affiliates for further exploitation. In a direct exchange with SOCRadar, the individual claiming to be GS7 stated that they had been operating for roughly ten years and provided screenshots of phishing panels bearing their handle, lending further visibility into the operation's tradecraft.
The financial scale of the campaign, as observed through blockchain analysis, remained relatively modest. A cryptocurrency wallet shared during the investigation was found to have received approximately 0.28 BTC, a sum equivalent to between $25,000 and $32,000 depending on the prevailing market price at the time of the transactions. This figure suggests that the immediate financial returns from the credential harvesting operation were limited, though the longer-term value likely lay in the resale or downstream exploitation of compromised accounts. Wells Fargo, as one of the named targets, was among the financial institutions whose branding and login interfaces were cloned as part of the broader effort to deceive customers and employees into surrendering their credentials.
Sources
Sources available to members: 1 source.