Research

The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign

Attackers posed as executives, moved conversations to WhatsApp and personal email, and forged acquisition documents to set up international wire transfers. When they targeted Gen, researchers played along, exposing a wider M&A scam.

Published

Read time

14 Minutes

The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign

Written by

Malware Researcher

Security Evangelist at Gen

Published

Read time

14 Minutes

The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign

    Related article

     WordlistLoader Delivering Amatera via ClearFake Campaigns

    Share this article

    It started with an innocent WhatsApp message.

    “Hi David, I hope you are well. Are you at the office?”

    The sender claimed to be a real Gen executive based in Dublin. The profile used his name, photograph and an Irish telephone number. Nothing in the opening message mentioned money, urgency or an acquisition. It was simply designed to establish whether the recipient was available and willing to respond.

    The recipient, whom we will call David, worked in Gen’s legal team and knew the colleague being impersonated. The unfamiliar telephone number raised suspicion, and the first phone conversation confirmed it: the caller’s voice did not match.

    David knew he was dealing with a scam. Every subsequent message, call and document formed part of a controlled effort to understand how the operation worked and gather evidence about the people behind it.

    What followed involved a second impersonated identity, forged legal documents, a fictitious confidential acquisition and a request to transfer €626,735.45 to a company in Hong Kong.

    What began as an attack against Gen’s legal team soon revealed a wider pattern. Our researchers found four additional targeted individuals who had received closely related NDA documents. The companies, advisers and acquisition narratives changed, but the structure, communication rules and document fingerprints remained remarkably consistent.

    We call the campaign Phantom Deal.

    A real person, but neither his number nor his voice

    The first persona claimed to be someone from inside the company. The attacker had selected an identity that made sense in the context of Gen’s international operations and used a phone number with the correct country code to reinforce the illusion.

    The deception did not survive the first call. David knew the person being impersonated, and the voice on the other end was not his.

    After the initial exchange, a second person entered the conversation. This time, the attacker impersonated a genuine professional associated with PwC and asked the target to provide a private email address.

    That request was not incidental.

    The forged NDA that followed instructed the recipient to keep all communication related to the acquisition on WhatsApp and personal email. The attackers tried to keep the entire exchange outside corporate communication channels before introducing any payment request.

    The attackers had also studied Gen’s history. The acquisition narrative referenced Avast Software and NortonLifeLock Ireland Limited, drawing on the real acquisition of Avast by NortonLifeLock in 2022 and the subsequent creation of Gen Digital. The names were familiar, the corporate relationship had existed, and an intercompany transaction could appear plausible to someone operating under pressure and secrecy.

    This was not a generic message sent to thousands of employees. The story had been adapted to its target. The targeting was tailored, but the execution was not flawless. David quickly identified inconsistencies in the explanation for why Avast should make a payment on behalf of NortonLifeLock Ireland Limited. His legal background and familiarity with internal transaction processes made those gaps easier to spot. A more coherent payment narrative could have made the same playbook considerably more convincing.

    Figure 1. The initial WhatsApp approach used two impersonated identities. Names and identifying details have been changed or redacted.

    Figure 1. The initial WhatsApp approach used two impersonated identities. Names and identifying details have been changed or redacted.

    The NDA was not supporting material

    The next stage was a professional-looking NDA branded as a document from PwC.

    Fake legal documents are common in corporate fraud, but the NDA served a more important role than simply making the acquisition story look credible. It established the rules under which the victim was expected to operate.

    The document introduced a confidential acquisition, imposed a strict disclosure regime and set a near-term date for the supposed public announcement. Most importantly, it required communication to take place through WhatsApp and personal email.

    Under normal circumstances, instructions to avoid company systems and exclude colleagues from a major transaction would be obvious warning signs. Inside the fiction created by the NDA, the same behaviour could be presented as a legal obligation.

    The attackers were attempting to turn the company’s own confidentiality culture against it.

    The target was encouraged not to involve colleagues, not to discuss the transaction through normal channels and not to verify the instructions with Legal, Finance, Treasury, Compliance or Corporate Development. A recipient who treated the NDA as genuine would become increasingly isolated from the colleagues most likely to challenge the story.

    The NDA was not an accessory to the attack. It was the payload.

    Figure 2. Anatomy of Phantom Deal, from trusted-person impersonation and forged NDAs to a controlled investigation that exposed a wider M&A-themed campaign.

    Figure 2. Anatomy of Phantom Deal, from trusted-person impersonation and forged NDAs to a controlled investigation that exposed a wider M&A-themed campaign.

    A deal that had to remain secret

    The attackers presented the acquisition as a tightly controlled transaction coordinated by a reputable adviser, with only a small group involved and an announcement approaching fast.

    The victim was told that the transaction would become public on June 19, 2026. The NDA had been presented only days earlier.

    That short window created pressure while providing a ready-made explanation for why the operation could not be discussed more broadly.

    The supposed adviser then sent payment instructions asking Avast Software s.r.o. to transfer money on behalf of NortonLifeLock Ireland Limited.

    The amount was precise: €626,735.45.

    The beneficiary was a company in Hong Kong, with the payment described as an “Advance Retainer for Professional Services.” The document stated that the amount would be recorded as an intercompany receivable and reimbursed when the acquisition was formally announced.

    It was a classic advance-payment fraud wrapped in the language of M&A, legal privilege and internal corporate accounting.

    “I need a SWIFT MT103”

    Once the payment instructions had been delivered, the tone changed.

    The attacker began following up for confirmation that the transfer had been completed. The target was asked to provide a SWIFT MT103, the banking message used as evidence that an international transfer has been executed.

    “I need a swift MT103, it’s an official proof of wire transfer to attached to the package.”

    Later, after receiving what appeared to be a confirmation email, the attacker complained that the link would not open and asked for the document as a PDF. He then added another requirement: the confirmation should contain the UETR number, a unique reference used to track a payment through the SWIFT network.

    The request for the MT103 and UETR confirmed the objective. The attackers wanted proof that the funds were moving and the information needed to monitor the transfer, potentially reducing the time available for the company or its bank to intervene.

    Figure 3. The attacker repeatedly followed up for an MT103, then requested the UETR after the tracking link failed to open. Identity details have been redacted.

    Figure 3. The attacker repeatedly followed up for an MT103, then requested the UETR after the tracking link failed to open. Identity details have been redacted.

    Turning the attack into intelligence

    Once David had identified the scam, the objective shifted from verification to intelligence gathering. Working with our researchers, he continued the exchange while the team controlled the material being sent and monitored how the operation responded.

    A fake account statement was prepared, showing what appeared to be the requested payment and the remaining company balance. The document contained a hidden marker that could identify whether it was opened on a system protected by one of our products.

    When the attackers requested formal MT103 confirmation, the team also created a fake Citibank-style confirmation email. It contained the transaction amount, beneficiary and payment reference expected by the criminals, together with a link to view the full transaction details.

    The link did not lead to real banking information. It contained a canary token, allowing our researchers to record when it was opened.

    When he reported that the link was not working, the team suggested that his VPN might be causing the problem and asked him to disable it. Further access attempts followed within minutes.

    The token recorded 49 HTTP requests from 43 IP addresses over 24 days. Most of the activity in the first minutes came from automated scanners, cloud services and redirect-analysis systems, so the raw count does not represent 49 actions by the attacker.

    After filtering that noise, the remaining data showed repeated interaction through VPNs, proxy services and several non-hosting internet connections. Some visits were separated by hours or days and used different browser profiles, behaviour consistent with a person returning to the link and attempting to retrieve the promised payment information.

    The network data helped us separate scanner traffic, proxy infrastructure and repeated manual access, but it was not enough to attribute the operation. Some later visits came from ordinary ISP ranges, although those connections show where the traffic exited, not necessarily where the fraudsters were located. 

    The later visits showed repeated manual access by someone connected to the fraud operation, including long after the supposed transfer should have been completed.

    Figure 4. The controlled response included a fake account statement and a fake payment-confirmation email containing the tracked link. Sensitive banking and identity details have been redacted.

    Figure 4. The controlled response included a fake account statement and a fake payment-confirmation email containing the tracked link. Sensitive banking and identity details have been redacted.

    From one attack to a wider campaign

    The controlled interaction gave us visibility into the live fraud attempt, while the forged NDA gave us something else: a set of document fingerprints we could hunt for.

    Using its structure, wording and embedded identifiers, the team found four additional NDA samples connected to other targeted individuals.

    The organizations and professions varied. The targets included senior people in private equity, industrial finance, sales, mining and energy. For each of them, an acquisition or strategic investment narrative would have been credible enough to justify initial engagement.

    The advisers also changed. Some documents impersonated PwC, while others used KPMG or Ogier branding. There is no indication that any of these firms were compromised or involved in the operation. Their names and identities were being abused to make the documents appear legitimate.

    Despite the different branding, the documents followed substantially the same sequence of sections and reused the same legal language. They all imposed confidentiality, directed communications towards WhatsApp and personal email, and introduced a short period between the NDA date and the supposed public announcement.

    They also contained the same unusual numeric identifier across documents attributed to different firms and prepared for unrelated recipients. This kind of residue is common when criminals reuse document templates. Names, dates, logos and transaction references may be changed, while less visible elements remain untouched.

    The repeated structure suggests that the attackers were not building each operation from scratch. They had developed a reusable M&A fraud package that could be adapted to different people and companies.

    In the Gen case, we observed the complete chain, from WhatsApp contact to payment request and demand for MT103 confirmation. For the other four targets, we found the malicious NDA documents carrying the same core narrative and document fingerprints, but did not observe the later payment stage.

    Taken together, the evidence points to a wider M&A-themed fraud campaign built around the same narrative and document toolkit. It does not establish that every target received identical payment instructions or that every document was operated by the same individual.

    No malware, no compromised mailbox

    Phantom Deal did not require an exploit, malicious attachment or stolen corporate email account.

    The operation drew on publicly available information, real names, photographs, company history and familiar business procedures. WhatsApp made the contact immediate, the forged NDA justified secrecy, and the acquisition narrative created the urgency needed to move the victim towards payment. The financial request appeared only after the surrounding story had been established.

    A security team searching only for malware or suspicious email links could miss the entire operation.

    The attack was designed to induce a process failure rather than exploit a technical vulnerability. The criminals attempted to convince the target that bypassing normal controls was necessary to protect a confidential deal.

    The warning signs appeared well before the Hong Kong bank account. Keeping a sensitive corporate transaction on WhatsApp and personal email was already enough to require independent verification.

    How companies can interrupt the chain

    Confidential transactions require restricted access, but secrecy should never remove independent verification.

    Organizations can reduce exposure by establishing a small number of rules that apply even to the most sensitive acquisitions, investments and restructuring projects:

    • Payment instructions must be verified through an independently established channel, not through contact details supplied during the transaction.
    • No executive, adviser or board member should be able to override payment controls through WhatsApp, personal email or a confidentiality claim.
    • Legal, Finance, Treasury and Corporate Development teams should have a defined escalation route for unexpected transaction requests.
    • Staff involved in payments should be trained to recognize requests for MT103 documents, UETR references and other confirmation data as part of the fraud chain, not merely as administrative follow-up.
    • External advisers should be contacted using verified directory information whenever their identity or instructions are in doubt.
    • Changes of communication channel, especially from corporate systems to private accounts, should trigger additional scrutiny.

    The same rules must apply when the request appears to come from the CEO, a board member or someone already known to the recipient.

    An NDA can limit who is told about a transaction. It should never prevent the transaction from being authenticated.

    Real details, false transaction

    Phantom Deal drew credibility from genuine information. The people, companies and advisers were real, as was the acquisition history connecting Gen and Avast. International payments, professional retainers and intercompany receivables are also normal elements of large corporate transactions.

    The transaction tying those details together was fabricated, and the execution was uneven. The caller’s voice did not match the colleague being impersonated, while the explanation for the payment contained inconsistencies that a lawyer familiar with the company’s processes could identify quickly. A more coherent story might have been considerably more dangerous.

    Why try this against a security company? Probably for the same reason they try it anywhere else: a security company is still a company. It has money, confidential transactions and employees whose jobs do not involve analysing scams. The attackers were not trying to defeat our security technology. They were trying to find one person who might accept the story and step outside the normal process.

    In this case, they chose someone who knew the colleague, recognized that the voice did not match and understood that the payment explanation made no sense. From that moment, the supposed victim was no longer following their script. He was helping us investigate it.

    There is also some irony in how it ended. After spending days building a narrative around trust, secrecy and urgency, someone connected to the fraud operation repeatedly interacted with the fake payment confirmation we placed in front of them.

    The NDA was intended to keep the operation confidential. Its reused language, structure and identifiers ultimately helped expose the campaign behind it.

    More on this topic

    Malware Researcher

    Security Evangelist at Gen

    At Gen, Luis tracks evolving threats and trends, turning research into actionable safety advice. He has worked in cybersecurity since 1999. He chairs the AMTSO Board and serves on the Board of MUTE.

    Follow us for more