• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Advanced Phishing Scams Target Middle East and Impersonate UAE Ministry of Human Resources

You are here: Home / General Cyber Security News / Advanced Phishing Scams Target Middle East and Impersonate UAE Ministry of Human Resources
July 5, 2022

CloudSEK researchers have recognized an considerable phishing marketing campaign in which danger actors (TA) were impersonating the Ministry of Human Resources of the UAE authorities.

Spotted through the company’s synthetic intelligence (AI) digital risk monitoring platform XVigil, the new risk would goal several government and company entities throughout the finance, vacation, clinic, lawful, oil and gasoline and session industries.

“The actors developed a bogus web page […] that resembles the legit area […] to defraud people,” CloudSEK wrote in an advisory.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The security experts’ investigation indicates this is a substantial-scale phishing marketing campaign, largely qualified at personal work seekers and businesses and exposing them to 419 and BEC scams.

“Upon observing the sample of the email handle used to register the domains, area identify, and hosting infrastructure, it can be inferred that a solitary menace actor or a danger actor team owns all these phishing domains and internet websites,” CloudSEK reported.

Further investigation of the email handle also led to the discovery of 43 domains that shared the similar registrant details.

“During the program of our investigation into the phony domain, CloudSEK scientists found many other domains on the Open up Source Internet (OSINT) that have been claimed on websites […] as frauds, targeting job seekers.”

In accordance to the security industry experts, the earlier mentioned phishing tasks could also be utilized by other threat actors to concentrate on particular consumers and steal their passwords, files, crypto wallets and other sensitive data.

To mitigate the effect of these attacks, CloudSEK claimed businesses and men and women must stay clear of downloading suspicious files from unfamiliar resources or clicking on suspicious backlinks.

Further, the business stated the visibility of file extensions really should be enabled (on Windows units) to location data files with not known file extensions ahead of downloading them.

Ultimately, CloudSEK concluded that equally multi-factor authentication (MFA) and the use of up-to-date antivirus and anomaly detection resources could also help cut down the influence of these state-of-the-art phishing cons.


Some components of this report are sourced from:
www.infosecurity-journal.com

Previous Post: «researchers uncover malicious npm packages stealing data from apps and Researchers Uncover Malicious NPM Packages Stealing Data from Apps and Web Forms
Next Post: NIST Acknowledges First Four Quantum-Resistant Encryption Tools Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New Variant of Banking Trojan BBTok Targets Over 40 Latin American Banks
  • How to Interpret the 2023 MITRE ATT&CK Evaluation Results
  • Iranian Nation-State Actor OilRig Targets Israeli Organizations
  • High-Severity Flaws Uncovered in Atlassian Products and ISC BIND Server
  • Apple Rushes to Patch 3 New Zero-Day Flaws: iOS, macOS, Safari, and More Vulnerable
  • Mysterious ‘Sandman’ Threat Actor Targets Telecom Providers Across Three Continents
  • Researchers Raise Red Flag on P2PInfect Malware with 600x Activity Surge
  • The Rise of the Malicious App
  • China Accuses U.S. of Decade-Long Cyber Espionage Campaign Against Huawei Servers
  • Cyber Group ‘Gold Melody’ Selling Compromised Access to Ransomware Attackers

Copyright © TheCyberSecurity.News, All Rights Reserved.