Full Report
A deep dive into loan phishing scams in Peru and Latin America. Discover how scammers lure victims with fake loan offers, harvest sensitive banking credentials, and leverage advanced scripts to maximize fraud at scale.
Analysis Summary
# Tool/Technique: LATAM Loan Phishing Framework
## Overview
This is a sophisticated, large-scale phishing infrastructure targeting users in Peru and Latin America. The campaign utilizes social engineering, primarily through social media advertisements, to lure victims into fake "fast loan" schemes. The goal is to harvest sensitive personal information and banking credentials (PII/PCI) for financial fraud or resale on the dark web.
## Technical Details
- **Type:** Phishing Framework / Scams-as-a-Service
- **Platform:** Web-based (cross-platform, mobile-optimized)
- **Capabilities:** Credential harvesting, automated data validation, institution impersonation, and stealthy redirection.
- **First Seen:** Active monitoring reported in late 2023/early 2024.
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1566.002 - Phishing: Spearphishing Link] (Social media ads)
- **[TA0007 - Discovery]**
- [T1204.001 - User Execution: Malicious Link]
- **[TA0006 - Credential Access]**
- [T1559 - Inter-Adversary Communications] (Data exfiltration to C2)
- **[TA0010 - Exfiltration]**
- [T1041 - Exfiltration Over C2 Channel]
## Functionality
### Core Capabilities
- **Mass Impersonation:** Over 370 unique domains registered to spoof trusted local financial institutions in Peru and LATAM.
- **Data Harvesting:** Specialized forms designed to capture full names, national IDs, phone numbers, and online banking credentials.
- **Targeted Advertising:** Uses paid social media ads to target individuals seeking financial assistance, increasing the conversion rate of the scam.
### Advanced Features
- **Validation Scripts:** Employs advanced scripts and algorithms to verify the quality and format of harvested data in real-time. This ensures only "high-value" (valid) credentials are saved and exfiltrated.
- **Detection Evasion:** Once the data is successfully harvested, the script redirects the victim to the official website of the impersonated bank to mask the theft and delay the victim's realization of the compromise.
## Indicators of Compromise
- **File Hashes:** N/A (Web-based infrastructure).
- **File Names:** N/A.
- **Network Indicators:**
- Approximately 370 domains identified (e.g., variations of `banco-prestamos-peru[.]com`, `soluciones-financieras-latam[.]net`).
- Defanged Example: `hxxps[://]prestamos-rapidos-peru[.]top`
- **Behavioral Indicators:**
- Redirection from social media platforms (Facebook/Instagram/TikTok) to non-official banking domains.
- Forms that request both personal identity numbers and banking passwords on the same page.
## Associated Threat Actors
- Unknown; however, the scale and technical validation suggest a sophisticated cybercriminal group or "Phishing-as-a-Service" provider operating within or specifically targeting the LATAM region.
## Detection Methods
- **Signature-based:** Monitoring for the specific script patterns used to validate data on phishing pages.
- **Behavioral detection:** Identifying rapid domain registration spikes involving local banking keywords and SSL certificates issued by Let's Encrypt for misspelled financial brands.
- **URL Inspection:** Analyzing for look-alike domains (typosquatting) and checking against Group-IB's Threat Intelligence feeds.
## Mitigation Strategies
- **User Awareness:** Educating customers that financial institutions will never ask for credentials via social media ads.
- **Multi-Factor Authentication (MFA):** Implementation of hardware tokens or app-based TOTP (Time-based One-Time Password) to render harvested credentials useless.
- **Domain Monitoring:** Financial institutions should proactively monitor for brand impersonation and utilize takedown services for fraudulent domains.
- **Web Filtering:** Implementing DNS filtering to block access to newly registered domains or known phishing URLs.
## Related Tools/Techniques
- **Classiscam:** A similar automated scam-as-a-service widely used in Europe and Asia.
- **Typosquatting:** The registration of domains that resemble legitimate ones.
- **Social Media Malvertising:** The use of legitimate ad platforms to distribute malicious links.