Namecheap hosted 25%+ of fake UK govt phishing sites last year – NCSC report
- Reference: 1620635414
- News link: https://www.theregister.co.uk/2021/05/10/ncsc_active_cyber_defence_report/
- Source link:
This stat can be found in the centre's fourth annual Active Cyber Defence report, which [1]boasts how much digital filth it cleansed from the internet. These included 700,000 scam sites stretching across 1.4 million URLs, or so the NCSC tells us.
It also encountered the usual COVID-themed ones we’ve all become familiar with over the last year – fake copies of the NHS Test and Trace app laced with malware – plus sites impersonating Capita TV Licensing, the outsourced subscription sales arm of the BBC. Email scams were also popular, with 26,000 being shut down after netizens flooded the NCSC’s [2]email reporting portal with complaints of four million suspicious messages.
[3]
[4]
[5]
The Active Cyber Defence programme is very much the NCSC’s bread and butter, and largely involves protecting the public sector. It also spilling over into protecting the general public, thanks to certain areas of the programme focusing on telecoms.
Alpha energy
One area where the NCSC hopes to make an immediate and positive difference is by killing off scam texts that appear to be sent from alphanumeric names such as UK_Gov. These are possible by design; UK mobile networks support the use of alpha tags in place of phone numbers but until very recently, there wasn’t much in the way of security for those tags.
Alpha tag scamming is easy if you know how, as infosec bod Jake Davis showed The Register last year by [6]sending SMSes appearing to be from the Irish government saying “it looks like you’ve got the old cheeky corona.” The NCSC is now beginning to crack down on and register British Government-themed tags (plus the telly tax agency, unusually) to prevent their reuse by scammers and ne’er-do-wells through a [7]relatively new thing: the SMS SenderID Protection Registry.
Other telecoms security work included tightening up UK telcos’ use of SS7, with unspecified vulnerabilities including one “serious” one being spotted over the last year. SS7, being an ancient protocol written just 14 years after the dawn of recorded time*, is [8]wide open to abuse by anyone with access to a telco’s inter-carrier backend.
What’s going on here, Namecheap?
The NCSC also highlighted how one host in particular had featured in its takedowns of phishing sites this year: Namecheap.
[9]
Top 10 hosters of UK government-themed phishing campaigns, highlighting NameCheap and GoDaddy who saw greater volatility in their monthly totals in 2020
The NCSC said in today’s Active Cyber Defence report that Namecheap took an average of 47 hours to disable gov.UK-themed phishing sites, and hosted a 28.8 per cent share of known UK government-themed phishing sites; the second biggest harbourer of such scams last year, GoDaddy, KO’d them within about 37 hours and had an 11.2 per cent share. We understand that in 2019 Namecheap only accounted for two or three per cent of this type of phishing website targeting the UK.
We have asked Namecheap for comment. Earlier this year its chief exec, Richard Kirkendall, got into a Twitter spat with a fed-up Reg reader who publicly asked the company why it was hosting yet another scam site. Kirkendall’s response was rather revealing when placed side-by-side with today’s NCSC statistics.
More than 9 out of 10 abuse reports submitted to us are false or incorrect. We processed/investigated 1.1 million abuse claims/reports in 2020 and only 100k of them were actually found to be linked to abuse. Less than 1 percent of domains registered with us. Submit a ticket. — Richard Kirkendall (@NamecheapCEO) [10]March 9, 2021
Back in 2018 Namecheap apologised after [11]accidentally letting criminals run fraudulent subdomains of other people’s websites, while in early 2020 [12]Facebook sued it for allegedly hosting imposter sites.
"Looking specifically at the number of campaigns hosted by NameCheap against its monthly median attack availability, we see that by mid-year the median takedown times were consistently in excess of 60 hours," said the NCSC report's author, who also added that by December 2020 a full 60 per cent of gov.UK-themed phishing was found on Namecheap infrastructure.
"This" said the NCSC, referring to the takedown times increasing, "undoubtedly made NameCheap an attractive proposition to host phishing and may explain the rise in monthly hosted campaigns that followed for UK government-themed phishing."
[13]
Whatever is driving the hosting firm’s popularity among scammers, let’s hope it’s fixed soon.
This week sees the NCSC’s CyberUK conference taking place. This year’s edition is a series of YouTube lectures, the pandemic not having receded far enough to risk it in-person. Billed to speak at the conference, which is positioned as a forum for online security matters, is [14]the virulently anti-encryption Home Secretary Priti Patel. The Register will be recording her remarks for posterity. ®
Timenote
* 1 January 1970, as any fule kno.
Get our [15]Tech Resources
[1] https://www.ncsc.gov.uk/report/acd-report-year-four
[2] https://www.theregister.com/2020/04/21/ncsc_email_scam_takedown_address/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJkEO5xnpsdF7j@EtUKh1QAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJkEO5xnpsdF7j@EtUKh1QAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJkEO5xnpsdF7j@EtUKh1QAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2020/10/12/ireland_covid_advice_sms_spoofable/
[7] https://mobileecosystemforum.com/2018/11/27/sms-senderid-protection-registry-announced/
[8] https://www.theregister.com/2017/05/03/hackers_fire_up_ss7_flaw/
[9] https://regmedia.co.uk/2021/05/07/ukgov_phishing_host_graph_ncsc.jpg
[10] https://twitter.com/NamecheapCEO/status/1369273660519964678?ref_src=twsrc%5Etfw
[11] https://www.theregister.com/2018/02/07/namecheap_subdomain_security_hole/
[12] https://www.theregister.com/2020/03/06/facebook_namecheap_ads/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJkEO5xnpsdF7j@EtUKh1QAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://www.theregister.com/2021/04/19/uk_anti_encryption/
[15] https://whitepapers.theregister.com/
"a 28.8 per cent share of known UK government-themed phishing sites"
Methinks that NameCheap is going to be forced to clean up their act if they don't manage to do it on their own.
Now that they have been named and shamed by a government report, Kirkendall is not going to be bale to brush it off like an angry Twitter rant.
If you regularly host government scam sites, there's a good change the government is going to come and have a word with you.
Re: "a 28.8 per cent share of known UK government-themed phishing sites"
Not a problem at all. All the CEO of NameCheap needs to do is become a donor to the Conservative party then all of his problems will go away.
Re: "a 28.8 per cent share of known UK government-themed phishing sites"
I wonder if the fact that they accept Bitcoin as payment has anything to do with it?
Even if it doesn't, the powers that be might think that it does.
Re: "a 28.8 per cent share of known UK government-themed phishing sites"
"there's a good change the government is going to come and have a word with you."
As HMRC is one of the frequent sites spoofed I look forward to Namecheap, its management and board being subject to frequent and searching audits by them.
It took NameCheap about 2 weeks to take down a fake Royal Mail website that I received an SMS spam for.
only a hundred thousand
It's amazing how much hard work that "only" is doing when Namecheap say
"only 100k of [abuse claims/reports] were actually found to be linked to abuse".
The one email address I have that receives frequent spam - which gets reported - is an old Hotmail address. Apart from SEO and the like service offerings* the phishing spam it receives is almost entirely pretending to be from one of the numerous Microsoft email brands. A check in the server spam folder shows that almost all other phishing spam such as advance payment scams is trapped and virtually none of the fake Microsoft mail is trapped. I'd have thought that there should be sufficient reports for NCSC to start having a quiet word with Microsoft to tighten up.
NCSC need to have words with their own marketing department. Earlier this year the responses to reports started including links to their own puffery making them look just like phishing emails. The link in TFA to the report is non-functional with JavaScript blocked. Given the point made in the report about JavaScript framework poisoning they really should know better than to (a) depend on JavaScript so heavily on their own site and (b) send out emails pointing to it.
* These generally get a response pretending to be a supplier questionnaire designed to suck them in before gently leading them to the conclusion that they've paid good money for a crap spam list.
Not Surprised...
...about NameCheap.
Friends had their domain and email hosting with them. The domain account was hijacked and spam was being sent from NameCheap's servers, despite password changes, etc. NameCheap (when they responded at all) refused to take any action and claimed it was my friends submitting the emails.
I transferred the domain to another registrar and miraculously the spam sending stopped instantly.