Duel’s investigations team says the hacker behind the Revolut incident used compromised Italian government email accounts, infostealer logs, and careful deletion of traces to sustain a five-month fraud campaign. Hudson Rock’s analysis suggests the attacker likely relied on pre-compromised pec.interno.it credentials rather than directly infecting the victims themselves. #Revolut #RevolutBankUAB #pecinternoit #ItalianMinistryoftheInterior #HudsonRock #Duel
Keypoints
- The attacker accessed government email accounts using infostealer data.
- They added a recovery email and monitored inboxes around the clock.
- Messages were deleted quickly to avoid detection by the real account owners.
- The hacker targeted Revolut Bank UAB because it had to respond to European Investigation Orders.
- Hudson Rock believes the attacker likely used existing compromised pec.interno.it logins.