Full Report
Cybercriminals have created hundreds of fake government and news websites to target people in Uzbekistan, Belarus and Tajikistan with bogus offers promising cash payments or passive income. Researchers at cybersecurity firm F6 identified more than 360 fraudulent domains tied to the campaign. The sites are designed to collect victims’ contact details, which scammers then use…
Analysis Summary
# Incident Report: Multi-Domain Phishing Campaign Targeting Central Asia
## Executive Summary
A large-scale fraudulent campaign involving over 360 spoofed government and news domains has targeted citizens in Uzbekistan, Belarus, and Tajikistan. The attackers leveraged promises of government-backed cash payments and passive income to trick victims into providing contact details. This information is subsequently used for secondary social engineering attacks aimed at financial theft and device compromise.
## Incident Details
- **Discovery Date:** September 14, 2026 (Reported September 16, 2026)
- **Incident Date:** Ongoing as of September 2026
- **Affected Organization:** General Public (targeted via spoofed government/news entities)
- **Sector:** Government / Media (Spoofed sectors)
- **Geography:** Uzbekistan, Belarus, Tajikistan
## Timeline of Events
### Initial Access
- **Date/Time:** Identified in early September 2026.
- **Vector:** Deceptive web domains (Typosquatting/Spoofing).
- **Details:** Attackers stood up 360+ domains mimicking official government portals and news outlets to establish trust.
### Lateral Movement
- **N/A:** As this is a consumer-facing phishing campaign, lateral movement within a specific corporate network was not the primary mechanism; rather, it moved from web-based data collection to direct telephonic/email contact.
### Data Exfiltration/Impact
- **Details:** Personal contact details (phone numbers, emails) were harvested from web forms. These were then used for follow-up social engineering attempts to gain access to banking apps or install malware on victim devices.
### Detection & Response
- **Discovery:** Cybersecurity firm F6 identified the infrastructure during threat hunting/monitoring.
- **Response:** Public disclosure by F6 and news outlets (The Record/Threat Beat) to warn the affected populations.
## Attack Methodology
- **Initial Access:** Social Engineering via fake websites.
- **Persistence:** Not applicable for the initial web phase; secondary malware may provide persistence on mobile devices.
- **Privilege Escalation:** Exploiting user trust to gain administrative access to personal devices or banking credentials.
- **Defense Evasion:** Use of hundreds of different domains to circumvent simple URL blacklisting.
- **Credential Access:** Phishing forms designed to collect PII (Personally Identifiable Information).
- **Discovery:** Use of government social program themes to identify and lure financially vulnerable targets.
- **Lateral Movement:** N/A.
- **Collection:** Bulk harvesting of contact details via web forms.
- **Exfiltration:** Direct submission of user-entered data to attacker-controlled databases.
- **Impact:** Financial loss for victims and potential unauthorized access to personal devices.
## Impact Assessment
- **Financial:** High potential for individual financial loss, though total aggregate costs are not yet disclosed.
- **Data Breach:** Large-scale PII theft affecting thousands of users across three countries.
- **Operational:** Disruption of trust in legitimate government social aid programs.
- **Reputational:** Damage to the perceived security of the spoofed government and news agencies.
## Indicators of Compromise
- **Network indicators:** 360+ fraudulent domains (e.g., [fake-gov-portal].uz, [news-spoof].by - *specific URLs should be defanged in local blocklists*).
- **File indicators:** Potential malicious APKs or mobile installers delivered during follow-up calls (Not explicitly named in report).
- **Behavioral indicators:** Unsolicited calls or emails regarding "passive income" or "government payouts" requiring immediate PII entry.
## Response Actions
- **Containment:** Cybersecurity firm F6 identified and flagged the malicious domains.
- **Eradication:** Ongoing efforts to take down fraudulent domains through registrars.
- **Recovery:** Public awareness campaigns to educate citizens on verifying official government communications.
## Lessons Learned
- **Key Takeaways:** Attackers are increasingly targeting Central Asian nations with localized content to exploit regional economic anxieties.
- **Improvement Areas:** Faster detection of domain registrations mimicking government infrastructure is needed at the national ISP level.
## Recommendations
- **Prevention:** Implement and promote the use of official "Verified" checkmarks on social media and ensure all government services use a unified, secure top-level domain (TLD).
- **User Education:** Advise citizens that government agencies typically do not offer "passive income" schemes and will not request sensitive details via unofficial web forms.