Full Report
Group-IB unveils three groups of fraudsters behind delivery scams in Singapore
Analysis Summary
# Threat Actor: Group 1, Group 2, and Group 3 (Delivery Scammers)
## Attribution & Identity
* **Actor Identification:** Three distinct, unnamed groups of fraudsters specializing in delivery-themed scams.
* **Aliases:** Referred to by Group-IB as **Group 1**, **Group 2**, and **Group 3**.
* **Known Associations:** Group 3 shows overlaps in website templates indicating they likely target European and American brands across various industries in addition to Singaporean targets.
## Activity Summary
The groups were identified conducting large-scale "delivery scams" impersonating **SingPost** (Singapore Post). Victims receive SMS or email notifications claiming a package is held due to unpaid shipping fees or incorrect addresses. The primary goal is the theft of credit card information and personal data.
## Tactics, Techniques & Procedures
* **Phishing/Smishing:** Sending fraudulent SMS and emails to victims.
* **Sender Spoofing:** Technical spoofing of legitimate sender numbers and email addresses to bypass suspicion.
* **Personalization:** Using victim names and personal data (likely acquired from underground leaks) to establish trust.
* **Evasion:** Short-lived phishing domains and infrastructure rotation to avoid detection.
* **User Interaction:** Requiring users to click links, enter sensitive financial information, and in some cases, bypass security warnings.
* **Social Engineering:** Creating a sense of urgency regarding parcel delivery or extra charges.
**MITRE ATT&CK IDs:**
* **T1566.001:** Phishing: Spearphishing Attachment (Emails)
* **T1566.002:** Phishing: Spearphishing Link (SMS/Emails)
* **T1598:** Phishing for Information
* **T1036:** Masquerading (Impersonating brands like SingPost)
## Targeting
* **Sectors:** Logistics, Postal Services, E-commerce, Retail.
* **Geography:** Primarily **Singapore** (specifically SingPost customers); Group 3 also targets **Europe** and the **United States**.
* **Victims:** General public/consumers expecting deliveries and users of brand names like SingPost.
## Tools & Infrastructure
* **Malware:** While primarily web-based phishing, the report mentions attempts to have users allow installations from **third-party sources** (potential mobile malware/APKs).
* **Infrastructure:**
* Short-lived phishing domains (e.g., mimicking singpost[.]com).
* Automated scam website templates.
* *Note: Specific defanged IPs/URLs were not explicitly listed in the provided text, but the activity involves automated domain registration.*
## Implications
These campaigns pose a significant risk to brand reputation and consumer trust. The ability to spoof legitimate sender IDs makes these scams highly effective. For brands, the lack of proactive monitoring leads to prolonged exploitation of their identity, resulting in customer churn and financial loss for the public.
## Mitigations
* **For Individuals:**
* Verify parcel status only through official apps or manually typed official websites.
* Never click links in unsolicited SMS or emails.
* **Disable installations from third-party sources** on mobile devices.
* Report suspicious activity to platforms like **scamalert[.]sg**.
* **For Organizations:**
* Implement **Digital Risk Protection (DRP)** to monitor for brand impersonation and newly registered domains.
* Utilize machine-learning systems to automate the detection and takedown of fraudulent infrastructure.
* Educate customers on official communication channels and legitimate payment methods.