Full Report
This highly targeted scam scheme uses advanced phishing and social engineering cues, rely on brand recognition, event-based campaigns and emotional manipulation to defraud victims twice.
Analysis Summary
# Incident Report: "Double-Tap" Brand Exploitation Scam
## Executive Summary
This incident involves a sophisticated, multi-stage phishing and social engineering scheme designed to defraud victims twice through emotional manipulation and brand impersonation. Attackers utilize high-fidelity clones of legitimate brands (e.g., SNCF, Zenith Bank) and event-based lures to harvest payment credentials and subsequently execute follow-on "recovery" or "verification" scams. The campaign's success relies on advanced phishing cues and the abuse of legitimate third-party infrastructure.
## Incident Details
- **Discovery Date:** Recent (Active Investigation)
- **Incident Date:** Ongoing
- **Affected Organization:** Multiple (Impersonated brands include SNCF, Zenith Bank, etc.)
- **Sector:** Transportation, Finance, E-commerce
- **Geography:** Global (Significant activity noted in EU/France and Africa)
## Timeline of Events
### Initial Access
- **Date/Time:** Variable (Campaign-based)
- **Vector:** Phishing (Email, SMS/Smishing, and Social Media)
- **Details:** Victims receive communications regarding "limited-time offers," "account issues," or "card renewals" featuring brand-accurate logos and tone.
### Lateral Movement
- **N/A:** As this is an external scam scheme, the "movement" refers to the transition from initial data harvesting to direct interaction with the victim's banking or personal environment via social engineering.
### Data Exfiltration/Impact
- **Data Stolen:** Full Name, Email, Phone Number, Credit Card Details (CVV/Expiry), and login credentials for impersonated services.
- **Secondary Impact:** Fraudsters use harvested phone numbers to contact victims, posing as "bank security" to authorize fraudulent transactions.
### Detection & Response
- **Detection:** Identified through Group-IB Digital Risk Protection and Threat Intelligence monitoring.
- **Response actions taken:** Domain takedown requests initiated; threat intelligence shared with financial institutions; defanging and publication of IOCs for defensive use.
## Attack Methodology
- **Initial Access:** Brand-impersonation phishing emails and smishing.
- **Persistence:** Not applicable to victim host; however, attackers maintain infrastructure via rotating DGA-like subdomains and fast-flux hosting.
- **Privilege Escalation:** Use of social engineering to obtain OTPs (One-Time Passwords) from victims to bypass MFA.
- **Defense Evasion:** Use of legitimate Cloudflare infrastructure, URL shorteners, and "look-alike" domains to bypass basic email filters.
- **Credential Access:** Highly realistic phishing landing pages (e.g., `sncf-espaceoffres[.]com`).
- **Discovery:** Scammers use leaked databases to target specific demographics likely to use the impersonated brands.
- **Lateral Movement:** N/A.
- **Collection:** Form-grabbing scripts on phishing pages.
- **Exfiltration:** Data sent via encrypted API calls or Telegram bots to attacker-controlled servers.
- **Impact:** Financial theft and identity compromise.
## Impact Assessment
- **Financial:** Significant per-victim losses; potential for thousands of euros stolen per successful "double-tap" interaction.
- **Data Breach:** High volume of Personally Identifiable Information (PII) and PCI-DSS sensitive data.
- **Operational:** Increased load on brand customer support and fraud departments.
- **Reputational:** Erosion of trust in the impersonated brands (SNCF, Zenith Bank, etc.).
## Indicators of Compromise
### Network Indicators
- `avantages-promotion-sncf[.]com`
- `sncf-espaceoffres[.]com`
- `sncf-offre-avantages[.]com`
- `promotion-avantages[.]com`
- `sncf-avantage[.]com`
- `sncfcarte-avantages[.]com`
- `45[.]125[.]66[.]34`
- `185[.]161[.]209[.]176`
- `91[.]215[.]85[.]183`
- `35[.]241[.]18[.]84`
### Email/Behavioral Indicators
- `merci[@]mail-sncf-connect[.]com`
- `newsletter[@]zenithbank[.]com`
- Usage of "urgent" time-sensitive language in SMS.
- Calls from "agents" requesting OTP codes or transaction approvals via banking apps.
## Response Actions
- **Containment:** Blocked identified phishing domains at the DNS level.
- **Eradication:** Reported fraudulent email accounts (`rahulshitole[@]yahoo[.]fr`, etc.) to service providers.
- **Recovery:** Advised affected users to freeze compromised credit cards and reset credentials.
## Lessons Learned
- **Secondary Fraud:** Attackers are increasingly moving from "passive" data theft to "active" social engineering (calling the victim) immediately after the phishing attempt.
- **Infrastructure Abuse:** Scammers are effectively leveraging legitimate cloud services (Stripe, HubSpot, etc.) to increase the perceived legitimacy of their emails.
## Recommendations
1. **Implement DMARC/SPF/DKIM:** Organizations should strictly enforce email authentication to prevent domain spoofing.
2. **User Awareness:** Educate customers that legitimate organizations will never ask for an OTP or full credit card details over the phone.
3. **Digital Risk Protection (DRP):** Employ real-time monitoring to detect and take down look-alike domains before they are used in large-scale campaigns.
4. **MFA Hardening:** Encourage the use of app-based authenticators or FIDO2 keys over SMS-based OTPs.