Full Report
Scammers attack users in Middle Eastern countries
Analysis Summary
# Incident Report: Multi-Year Social Engineering Campaign Targeting Middle Eastern Users
## Executive Summary
A long-standing threat group has been conducting large-scale fraudulent operations targeting users across the Middle East by impersonating government agencies and prominent brands. The campaign leverages a massive infrastructure of over 100 social media accounts and Blogspot pages to steal personal information and financial credentials. The group has shown remarkable persistence, with some infrastructure remaining active for over six years.
## Incident Details
- **Discovery Date:** Ongoing (Reported 2023)
- **Incident Date:** Active since at least 2013; 54% surge in activity observed in H1 2023.
- **Affected Organization:** Various (Impersonation of Middle Eastern government agencies and private brands).
- **Sector:** Government, Finance, Retail.
- **Geography:** Middle East (Multiple countries).
## Timeline of Events
### Initial Access
- **Date/Time:** 2013 - Present.
- **Vector:** Social Engineering via Social Media and Messaging Apps.
- **Details:** Attackers utilize social media advertisements, fake profiles, and mass messaging on platforms like WhatsApp to distribute links to fraudulent pages.
### Lateral Movement
- **Details:** Not applicable in a traditional network sense; the attackers move across platforms (Facebook, WhatsApp, Blogspot) to maintain engagement with victims and evade localized platform bans.
### Data Exfiltration/Impact
- **Details:** Theft of PII (Personally Identifiable Information) and banking credentials via phishing forms hosted on compromised or spoofed domains.
### Detection & Response
- **Detection:** Group-IB Digital Risk Protection identified a surge in fraudulent pages and linked them through shared infrastructure and Google statistics.
- **Response Actions:** Identification of over 100 threat group accounts; ongoing monitoring and takedown requests for fraudulent domains and social media pages.
## Attack Methodology
- **Initial Access:** Social media ads, fake celebrity endorsements, and WhatsApp mass messaging.
- **Persistence:** Use of long-term Blogspot accounts (some active for 6+ years) and rotating domain groups.
- **Privilege Escalation:** N/A (Focused on victim credential theft rather than system privilege).
- **Defense Evasion:** Use of legitimate hosting services (Blogspot), URL shorteners, and domain names that mimic official brands (typosquatting).
- **Credential Access:** Web-based phishing forms designed to harvest bank card details.
- **Discovery:** Scammers utilize social media analytics to target specific demographics in the Middle East.
- **Lateral Movement:** Interlinking between multiple fraudulent domains and social media profiles to redirect traffic.
- **Collection:** Harvesting user data entered into fake giveaway or government aid forms.
- **Exfiltration:** Data sent to attacker-controlled servers through web forms.
- **Impact:** Financial fraud, identity theft, and reputational damage to impersonated entities.
## Impact Assessment
- **Financial:** High (Direct theft from individual bank accounts; costs to brands for remediation).
- **Data Breach:** High (Volume of PII and financial data stolen over a decade).
- **Operational:** Low (Minimal impact to targeted brand infrastructure).
- **Reputational:** High (Significant brand erosion for impersonated government agencies and companies).
## Indicators of Compromise
- **Network:** Multiple interlinked domains mimicking Middle Eastern brands (specific URLs not provided in the snippet, but identified as a "group of domains").
- **File:** N/A (Web-based attack).
- **Behavioral:** WhatsApp messages promising "giveaways" or "government grants" leading to non-official `[.]blogspot[.]com` domains or typosquatted URLs.
## Response Actions
- **Containment:** Blocking of identified fraudulent accounts on social media platforms.
- **Eradication:** Flagging and takedown of Blogspot pages and associated phishing domains.
- **Recovery:** Customer notification programs by affected brands to warn of the scam.
## Lessons Learned
- **Infrastructure Longevity:** Scammers are successfully using free blogging platforms for long-term persistence (6+ years), defying the trend of short-lived phishing sites.
- **Platform Synergy:** The group effectively combines mass messaging (WhatsApp) with social media ads to create a cross-platform funnel that builds false trust.
- **Targeted Messaging:** The use of local themes (government aid/regional brands) significantly increases the success rate of the social engineering.
## Recommendations
- **For Users:**
- Verify all promotions through official, verified social media accounts.
- Check domain names carefully; look for subtle misspellings (e.g., `brand-support[.]com` vs `brand[.]com`).
- **For Organizations:**
- Implement Digital Risk Protection (DRP) to monitor for unauthorized use of trademarks.
- Establish a clear procedure for customers to report suspected phishing.
- Maintain an official "Verified Channels" page to help users distinguish legitimate communications from scams.