World Cup phishing emails spike in Middle Eastern countries
(2022/11/21)
- Reference: 1669063745
- News link: https://www.theregister.co.uk/2022/11/21/world_cup_phishing_emails/
- Source link:
Phishing attempts targeting victims in the Middle East increased 100 percent last month in the lead up to the World Cup in Qatar, according to security shop Trellix.
Its researchers documented a spike in these email-based attacks between September and October, when the volume of malicious emails doubled. Miscreants used FIFA and other football-related lures as the initial attack vector, and the security researchers detailed several email samples they found in the wild.
In one, the email purported to be from the FIFA transfer matching system (TMS) helpdesk and included a fake alert that the user's two-factor authentication had been deactivated. It then directed the user to an attacker-controlled website, which allows the crooks to then steal the users' credentials.
[1]
Another scam email impersonated David Firisua, the team manager for Auckland City FC, and requested confirmation of a FIFA payment, while yet another phish impersonated the FIFA ticketing office and tried to trick a victim into "urgently resolving" a payment issue by clicking on a malicious HTML attachment.
[2]
[3]
Trellix's phishing net also caught emails spoofing Snoonu, the official food delivery partner of the World Cup, that offered fake free match tickets and contained a malicious xlsm attachment.
"It is a common practice for attackers to utilize the important/popular events as a part of the social engineering tactics and particularly target the organizations which are related to events and more promising victims for the attack," the researchers [4]warned .
[5]
Trellix also highlighted World Cup-themed phishing pages that look like the legitimate FIFA pages they spoof, and warned that miscreants are using "multiple phishing kits where the post URL is either obfuscated, Base64 encoded or present in the ajax request instead of form action tags."
[6]Germany says nein to Qatari World Cup spyware, err, apps
[7]World Cup apps pose a data security and privacy nightmare
[8]Robin Banks crooks back at the table with fresh phish from Russia
[9]French-speaking voleurs stole $30m in 15-country bank, telecoms cyber-heist spree
Additionally, the top five malware families being used to target Middle Eastern countries are Qakbot (40 percent), Emotet (26 percent), Formbook (26 percent), Remcos (4 percent) and QuadAgent (4 percent), according to the security researchers.
And in a separate document
Trellix expects these phishing attacks to continue through January 2023, and noted that organizations directly related to the football tournament should remain "extra-vigilant."
Phished, snooped, or jailed?
Of course, the nearly 3 million people who bought tickets to attend a match in Qatar have a whole other set of cybersecurity threats to worry about once they are in the country — in addition to a litany or moral and ethical concerns related to attending the World Cup in a country with a [11]horrible human rights' record that built its stadiums using [12]migrant workers whose treatment has been described as " [13]modern slavery ."
Two World Cup apps have come under [14]increased scrutiny from security researchers and various countries' data protection agencies, which have labeled the apps spyware and encouraged visits to [15]use burner phones .
The two apps are [16]Ehteraz , a Covid-19 tracker from the Qatari Ministry of Public Health, and [17]Hayya from the government's Supreme Committee for Delivery & Legacy overseeing the Cup locally, which allows ticket holders entry into the stadiums and access to free metro and bus transportation services.
[18]
All of which makes watching the matches from the comfort of your own couch, where you can [19]drink a beer and [20]kiss your partner without fear of getting arrested, sound increasingly appealing. ®
Get our [21]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.trellix.com/en-us/about/newsroom/stories/research/email-cyberattacks-on-arab-countries-rise.html
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/11/16/germany_world_cup_apps/
[7] https://www.theregister.com/2022/11/11/world_cup_security/
[8] https://www.theregister.com/2022/11/08/robin_banks_phishing_service/
[9] https://www.theregister.com/2022/11/04/french_opera1er_group_ib/
[10] https://www.trellix.com/en-us/assets/docs/arab-fifa-campaigns-poc.pdf
[11] https://www.hrw.org/world-report/2022/country-chapters/qatar#eaa21f
[12] https://www.amnesty.org/en/latest/campaigns/2016/03/qatar-world-cup-of-shame/
[13] https://www.rollingstone.com/culture/culture-features/world-cup-built-on-modern-slavery-stadium-workers-blow-the-whistle-on-qatars-cover-up-of-migrant-deaths-1234627582/
[14] https://www.theregister.com/2022/11/11/world_cup_security/
[15] https://www.theregister.com/2022/11/16/germany_world_cup_apps/
[16] https://play.google.com/store/apps/details?id=com.moi.covid19&hl=en_GB&gl=US&pli=1
[17] https://play.google.com/store/apps/details?id=com.pl.qatar
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[19] https://www.npr.org/2022/11/18/1137817650/qatar-bans-beer-sales-at-world-cup-stadiums-two-days-before-it-begins
[20] https://www.politico.eu/article/european-team-ditch-pro-lgbtq-armband-qatar-world-cup/
[21] https://whitepapers.theregister.com/
Its researchers documented a spike in these email-based attacks between September and October, when the volume of malicious emails doubled. Miscreants used FIFA and other football-related lures as the initial attack vector, and the security researchers detailed several email samples they found in the wild.
In one, the email purported to be from the FIFA transfer matching system (TMS) helpdesk and included a fake alert that the user's two-factor authentication had been deactivated. It then directed the user to an attacker-controlled website, which allows the crooks to then steal the users' credentials.
[1]
Another scam email impersonated David Firisua, the team manager for Auckland City FC, and requested confirmation of a FIFA payment, while yet another phish impersonated the FIFA ticketing office and tried to trick a victim into "urgently resolving" a payment issue by clicking on a malicious HTML attachment.
[2]
[3]
Trellix's phishing net also caught emails spoofing Snoonu, the official food delivery partner of the World Cup, that offered fake free match tickets and contained a malicious xlsm attachment.
"It is a common practice for attackers to utilize the important/popular events as a part of the social engineering tactics and particularly target the organizations which are related to events and more promising victims for the attack," the researchers [4]warned .
[5]
Trellix also highlighted World Cup-themed phishing pages that look like the legitimate FIFA pages they spoof, and warned that miscreants are using "multiple phishing kits where the post URL is either obfuscated, Base64 encoded or present in the ajax request instead of form action tags."
[6]Germany says nein to Qatari World Cup spyware, err, apps
[7]World Cup apps pose a data security and privacy nightmare
[8]Robin Banks crooks back at the table with fresh phish from Russia
[9]French-speaking voleurs stole $30m in 15-country bank, telecoms cyber-heist spree
Additionally, the top five malware families being used to target Middle Eastern countries are Qakbot (40 percent), Emotet (26 percent), Formbook (26 percent), Remcos (4 percent) and QuadAgent (4 percent), according to the security researchers.
And in a separate document
[10]PDF
, Trellix listed malicious URLs, binaries and email addresses used in these recent World Cup-themed campaigns.Trellix expects these phishing attacks to continue through January 2023, and noted that organizations directly related to the football tournament should remain "extra-vigilant."
Phished, snooped, or jailed?
Of course, the nearly 3 million people who bought tickets to attend a match in Qatar have a whole other set of cybersecurity threats to worry about once they are in the country — in addition to a litany or moral and ethical concerns related to attending the World Cup in a country with a [11]horrible human rights' record that built its stadiums using [12]migrant workers whose treatment has been described as " [13]modern slavery ."
Two World Cup apps have come under [14]increased scrutiny from security researchers and various countries' data protection agencies, which have labeled the apps spyware and encouraged visits to [15]use burner phones .
The two apps are [16]Ehteraz , a Covid-19 tracker from the Qatari Ministry of Public Health, and [17]Hayya from the government's Supreme Committee for Delivery & Legacy overseeing the Cup locally, which allows ticket holders entry into the stadiums and access to free metro and bus transportation services.
[18]
All of which makes watching the matches from the comfort of your own couch, where you can [19]drink a beer and [20]kiss your partner without fear of getting arrested, sound increasingly appealing. ®
Get our [21]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.trellix.com/en-us/about/newsroom/stories/research/email-cyberattacks-on-arab-countries-rise.html
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/11/16/germany_world_cup_apps/
[7] https://www.theregister.com/2022/11/11/world_cup_security/
[8] https://www.theregister.com/2022/11/08/robin_banks_phishing_service/
[9] https://www.theregister.com/2022/11/04/french_opera1er_group_ib/
[10] https://www.trellix.com/en-us/assets/docs/arab-fifa-campaigns-poc.pdf
[11] https://www.hrw.org/world-report/2022/country-chapters/qatar#eaa21f
[12] https://www.amnesty.org/en/latest/campaigns/2016/03/qatar-world-cup-of-shame/
[13] https://www.rollingstone.com/culture/culture-features/world-cup-built-on-modern-slavery-stadium-workers-blow-the-whistle-on-qatars-cover-up-of-migrant-deaths-1234627582/
[14] https://www.theregister.com/2022/11/11/world_cup_security/
[15] https://www.theregister.com/2022/11/16/germany_world_cup_apps/
[16] https://play.google.com/store/apps/details?id=com.moi.covid19&hl=en_GB&gl=US&pli=1
[17] https://play.google.com/store/apps/details?id=com.pl.qatar
[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y3wDBXnLRZz3acZ7i2voDgAAAQ0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[19] https://www.npr.org/2022/11/18/1137817650/qatar-bans-beer-sales-at-world-cup-stadiums-two-days-before-it-begins
[20] https://www.politico.eu/article/european-team-ditch-pro-lgbtq-armband-qatar-world-cup/
[21] https://whitepapers.theregister.com/
Hypocrites
VoiceOfTruth
-> a litany or moral and ethical concerns related to attending the World Cup in a country with a horrible human rights' record that built its stadiums using migrant workers whose treatment has been described as "modern slavery."
Let's hear these same people say "we will not buy gas from Qatar nor supply it with weapons". They won't, of course. Nor do they have moral or ethical problems doing the same with the USA.
or you can do what I plan to do
and just ignore the whole mess until the World Cup is in a country not as obnoxious as Russia or Qatar. Allegedly 2026 will be in Canada/US/Mexico. I foresee trouble, not least playing at Azteca in the summer, or even the autumn. And if in the autumn, the good locations will be booked for American feetball, college and pro. And the weather might be interesting. This weekend there were several instances of heavy snow causing problems. A lot of the really good stadia are in places like Indiana (Notre Dame; massive snowfall this Saturday, the home team won 44-0 'cause they're used to Northern Indiana weather; the visitors wore all white, it's damn hard to make a pass when you can't see who you're passing to because he's wearing white against a white background) and New York State (the Buffalo Bills pro game had to be moved to Detroit because of snow https://www.npr.org/sections/pictureshow/2022/11/20/1137579787/buffalo-western-new-york-snow-photos) and if you make the games too early, places like Florida, Texas, and Louisiana may have a slight hurricane problem. California might have a slight wildfire problem, and Colorado is almost as bad as Azteca.
And, of course, there's always the chance that The Orange One returns to power. It's not a great chance, but it's there. The US will then be on a par with Russia and Qatar, and I'll probably be watching from Canada, if I watch at all.