Full Report
Group-IB uncovers one thousand (and one) fake domains part of a scam campaign targeting users in KSA
Analysis Summary
# Incident Report: Large-Scale Scams Targeting Saudi Arabia (KSA)
## Executive Summary
Group-IB identified a massive scam campaign involving over 1,000 fake domains targeting users in the Kingdom of Saudi Arabia (KSA). The attackers impersonated government agencies, postal services, and major brands to steal personal information and financial credentials. The operation utilized sophisticated social engineering via social media and messaging apps to lure victims to fraudulent websites.
## Incident Details
- **Discovery Date:** Early 2023 (Continuous monitoring reported in May 2023)
- **Incident Date:** Ongoing throughout 2022-2023
- **Affected Organization:** Multiple (Impersonated entities include Saudi Post - SPL, Ministry of Commerce, and various private brands)
- **Sector:** Government, Logistics, E-commerce, and Finance
- **Geography:** Kingdom of Saudi Arabia (KSA)
## Timeline of Events
### Initial Access
- **Date/Time:** 2022 – 2023
- **Vector:** Social Engineering via Social Media (Facebook, Twitter, Instagram) and Messaging Apps (WhatsApp, Telegram).
- **Details:** Attackers distributed links to fake websites promising government grants, employment opportunities, or claiming issues with postal deliveries to lure victims.
### Lateral Movement
- **N/A:** As this was a consumer-facing scam campaign rather than a traditional network intrusion, the "movement" involved redirecting users through a series of intermediary domains to evade automated detection systems.
### Data Exfiltration/Impact
- **Data Stolen:** Personal identifiable information (PII), including full names, phone numbers, addresses, and highly sensitive financial data (credit card numbers, CVV, and One-Time Passwords).
### Detection & Response
- **Detection:** Group-IB’s Digital Risk Protection (DRP) team identified a surge in registered domains mimicking Saudi Arabian official entities.
- **Response Actions:** Proactive monitoring and issuing of takedown requests for the fraudulent domains to hosting providers and registrars.
## Attack Methodology
- **Initial Access:** Social engineering; lures via SMS (Smishing) and social media advertisements.
- **Persistence:** Use of over 1,000 domains to ensure that if one is blocked, the campaign remains active via others.
- **Defense Evasion:** Use of URL shorteners, domain hopping, and registering domains that closely mimic official URLs (Typosquatting/Homograph attacks).
- **Credential Access:** Phishing pages designed to look like official login or payment portals.
- **Discovery:** Scammers monitored social media trends and local news in KSA to tailor their lures (e.g., specific government programs).
- **Collection:** Forms on fake websites designed to harvest user input in real-time.
- **Exfiltration:** Data submitted by users was sent directly to attacker-controlled C2 (Command and Control) panels or Telegram bots.
- **Impact:** Financial theft from individual bank accounts and brand reputation damage for the impersonated organizations.
## Impact Assessment
- **Financial:** High potential for individual financial loss; millions of SAR estimated at risk across the victim pool.
- **Data Breach:** Large-scale theft of citizen PII and banking credentials.
- **Operational:** Significant strain on customer support for impersonated agencies (e.g., Saudi Post).
- **Reputational:** Eroded trust in official digital services and government portals.
## Indicators of Compromise
*Note: Due to the volume (1,000+), representative patterns are listed.*
- **Network Indicators:**
- `spl-online[.]net` (Defanged)
- `saudi-post-tracking[.]com` (Defanged)
- `mci-gov-sa[.]pro` (Defanged)
- Various domains using `.top`, `.xyz`, and `.info` TLDs.
- **Behavioral Indicators:**
- Redirects from social media ads to unofficial URLs.
- Requests for CVV or OTP on pages that should only require a tracking number.
## Response Actions
- **Containment:** Group-IB initiated the blocking of identified fraudulent domains.
- **Eradication:** Identification of the infrastructure providers used by the threat actors to prevent rapid re-registration.
- **Recovery:** Public awareness campaigns by Group-IB and affected Saudi authorities to educate users on verifying official links.
## Lessons Learned
- **Volume as a Tactic:** The sheer number of domains (1,001) shows that attackers are moving away from single-site phishing to massive, automated infrastructure.
- **Regional Targeting:** Attackers are increasingly localizing content (Arabic language, local branding) to increase success rates.
- **Verification Gaps:** Users continue to trust social media advertisements as "verified" sources of information.
## Recommendations
- **For Users:**
- Always verify URLs against official government portals (e.g., ending in `.gov.sa`).
- Use multi-factor authentication (MFA) but never share OTPs on non-official sites.
- **For Organizations:**
- Implement continuous Digital Risk Protection (DRP) to monitor for brand impersonation.
- Establish a streamlined process for reporting and taking down phishing sites.
- Educate customers/citizens specifically about the communication channels the organization will *never* use (e.g., asking for card details via WhatsApp).