Full Report
Uncover how cybercriminals in Colombia impersonate financial brands and exploit public data to craft convincing vehicle insurance scams.
Analysis Summary
# Tool/Technique: Colombian Vehicle Insurance Phishing Scams (SOAT Fraud)
## Overview
This is a sophisticated social engineering and phishing campaign targeting Colombian citizens. The operation impersonates major financial and insurance brands (such as Seguros Bolívar, AXA Colpatria, and Mundial de Seguros) to sell fraudulent Mandatory Compulsory Traffic Accident Insurance (SOAT). The attackers leverage public vehicle registration data to create highly personalized and convincing lures.
## Technical Details
- **Type**: Phishing / Brand Impersonation / Scam Framework
- **Platform**: Web-based (cross-platform), Mobile (WhatsApp)
- **Capabilities**: Credential harvesting, payment fraud, automated data scraping, and personalized social engineering.
- **First Seen**: Active throughout 2023-2024.
## MITRE ATT&CK Mapping
- **[TA0001 - Reconnaissance]**
- **[T1589.001 - Gather Victim Identity Information: Credentials]**
- **[T1591 - Gather Victim Network Information]**
- **[TA0007 - Discovery]**
- **[T1208 - Account Discovery (Public Data Scraping)]**
- **[TA0001 - Initial Access]**
- **[T1566.002 - Phishing: Spearphishing Link]**
- **[T1566.003 - Phishing: Voice/SMS/Messaging (WhatsApp)]**
- **[TA0002 - Execution]**
- **[T1204.001 - User Execution: Malicious Link]**
## Functionality
### Core Capabilities
- **Public Data Exploitation**: Attackers use publicly available vehicle information (license plates, ID numbers) to pre-populate phishing forms, increasing the appearance of legitimacy.
- **Brand Impersonation**: High-fidelity cloning of official insurance provider websites, including the use of official logos and color schemes.
- **Omnichannel Delivery**: Utilizing SEO poisoning, Google Ads, and automated WhatsApp messaging to direct victims to fraudulent portals.
- **Real-time Interaction**: Use of automated bots or human operators via WhatsApp to guide victims through the "purchase" process.
### Advanced Features
- **Phishing-as-a-Service (PhaaS)**: Use of kits that dynamically generate payment pages based on the brand the victim expects to see.
- **QR Code Redirection**: Use of malicious QR codes to bypass traditional URL filters and lead users to mobile-optimized phishing sites.
## Indicators of Compromise
*(Note: As this is a scam campaign, indicators are primarily domain-based and frequently rotate.)*
- **Network Indicators (Defanged)**:
- hxxps[://]soat-segurosbolivar[.]com
- hxxps[://]tramites-soat[.]online
- hxxps[://]pagos-soat-colombia[.]co
- hxxps[://]mundial-seguros-renovacion[.]com
- **Behavioral Indicators**:
- Redirects from Google Ads for keywords like "comprar SOAT barato."
- Unsolicited WhatsApp messages containing "urgent" insurance expiration notices.
- Payment portals requesting direct bank transfers (PSE) or Nequi/Daviplata transfers instead of standard credit card processing.
## Associated Threat Actors
- Localized cybercriminal groups operating within or targeting Colombia (specifically "Scammers" specializing in Latin American financial fraud).
## Detection Methods
- **Signature-based detection**: Monitoring for newly registered domains containing keywords like "SOAT," "Seguros," and "Bolivar."
- **Behavioral detection**: Identifying high-volume WhatsApp messaging patterns from unrecognized business accounts.
- **Web Analytics**: Detecting referral traffic coming from suspicious Google Ad campaigns directing to non-official top-level domains (TLDs).
## Mitigation Strategies
- **For Individuals**:
- Verify insurance validity only through the official **RUNT** (Registro Único Nacional de Tránsito) website.
- Avoid clicking on sponsored links in search engines for financial services.
- Never share OTPs or transfer money to personal phone numbers for official services.
- **For Businesses**:
- Implement **Digital Risk Protection (DRP)** to monitor and takedown impersonation domains.
- Use DMARC/SPF/DKIM to prevent email spoofing.
- Educate customers on the official payment channels supported by the brand.
## Related Tools/Techniques
- **SEO Poisoning**: Manipulating search results to place malicious sites at the top.
- **Typosquatting**: Registering domains similar to official brands (e.g., "segurosbolivaar" instead of "segurosbolivar").
- **Social Engineering**: Creating a sense of urgency regarding legal compliance and fines.