Windows bug can expose secrets

Published August 27, 2026

A scam campaign called Phantom Deal uses a friendly WhatsApp message from a fake executive, then a fake acquisition NDA, to talk employees into wiring large sums of money to outside accounts. Gen Digital caught an attempt against its own Avast legal team before any money moved.

Report priority
Medium
Targets
Avast Software

How it works

An attacker opens a casual WhatsApp chat pretending to be a real company leader, then a second fake persona posing as a PwC professional asks for a personal email and sends a branded NDA describing a secret acquisition, telling the target to keep the deal off normal channels before asking for a wire transfer.

What to do

Verify any such contact or wire-transfer request by calling the person on a known number and routing it through your normal legal and finance approval process, as Gen Digital recommends in its report.

Never send money without verifying the request in person or through official channels. Report suspicious messages to your IT or security team immediately.

Technical details

Affected software: Avast Software

An attacker messages a Gen Digital legal team member on WhatsApp, posing as a Dublin-based executive, and starts with a harmless question about whether they are in the office. A second impersonator, claiming to work for PwC, asks for a personal email address and sends a polished fake NDA describing a secret acquisition. The NDA tells the employee to discuss it only over WhatsApp and personal email and to keep colleagues out of it, then payment instructions ask for a transfer of 626,735.45 euros to a Hong Kong company.

Phantom Deal used no malware, stolen mailbox, or malicious attachment. Attackers built a fake acquisition using two impersonated identities and a PwC-styled NDA template that instructed the target to bypass legal, finance, treasury and compliance review. Gen Digital researchers sent a controlled reply with a tracked link and fake payment confirmation, logging 49 HTTP requests from 43 IP addresses over 24 days.

After a transfer, the operators asked for the SWIFT MT103 message and UETR tracking reference, which would let them follow the payment's progress. At least four other people at different companies received closely related fake NDAs, pointing to a reusable fraud template rather than a one-off attempt.

References