Research

Back to Homepage
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
No items found.
Research
Credential Phishing Pages Mimicking Legitimate Webmail Login Portals

Since 1 August 2024, a likely India-nexus targeted intrusion actor has targeted entities in China and South Asia using credential phishing pages mimicking legitimate webmail login portals. Domain naming conventions as well as observed phishing pages reveal likely targeting of entities in the government and defense sectors. Observed tactics, techniques, and procedures and target scope are consistent with public reporting on Indian targeted intrusion actors.  

Details

Identified domains share the following similarities:

  • Registration via 1api registrar service
  • Use of Royalhost nameservers
  • Resolving to the IP address 65.21.85[.]206
  • Domain naming convention using webmail login or file download themes often combined with references to specific, likely targeted entities

The 65.21.85[.]206 IP address is a shared host resolving numerous domains likely unrelated to the India-nexus targeted intrusion activity. However, historical data from this host indicates the India-nexus actor has used 65.21.85[.]206 since at least April 2024 to host phishing domains.  

Figure 1. Example Credential Phishing Page from nepal-mofa[.]com

Analysis of this activity also shows one of the actor-registered domains (never-giveup.mail-downloadfiles[.]com) redirecting to a credential phishing page hosted on the cloud service Netlify (large-files-d0wnl0ad-session-expired.netlify[.]app). These domains are likely being used to target Chinese entities.

Figure 2. Chinese-language Credential Phishing Page Hosted on Netlify

IOCs

South Asia China
navy.lk.mails-gov[.]com (Sri Lanka) mod.gov.cn.inviation.mail-files-open-preview[.]com
mailbox-owa-bd[.]com (Bangladesh) never-giveup.mail-downloadfiles[.]com
nepal-mofa[.]com (Nepal) all-files.mail-sessionexpired[.]com
mail-sessionexpired[.]com
preview-files-login.mail-sessionexpired[.]com
proposal-pdf-login.mail-sessionexpired[.]com
securitychallenge-cetci.mail-sessionexpired[.]com
alitcn.mail-files-open-preview[.]com
app-all.mail-files-open-preview[.]com
attachments-secure-check.mail-files-open-preview[.]com
coremail-downloads.mail-files-open-preview[.]com
coremail-files-downloads.mail-files-open-preview[.]com
download-all.mail-files-open-preview[.]com
download-attachments.mail-files-open-preview[.]com
mail-files-open-preview[.]com
netease-secure.mail-files-open-preview[.]com
pla-navy-seecure-drive.mail-files-open-preview[.]com

Conclusion

This activity is consistent with targeted intrusion activity identified in previous public reporting. Naming conventions are generally consistent with activity from the group known as Sidewinder with domains spoofing webmail login portals and the targeting of entities in China and South Asia. The India-nexus targeted intrusion group known as Patchwork also historically exhibited a similar target scope. 

Learn More
Research
Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks

In a recent article from KrebsonSecurity, they detail that at least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week. Squarespace bought all assets of Google Domains a year ago, but many customers still haven’t set up their new accounts. Experts say malicious hackers learned they could commandeer any migrated Squarespace accounts that hadn’t yet been registered, merely by supplying an email address tied to an existing domain.

Read the research: https://krebsonsecurity.com/2024/07/researchers-weak-security-defaults-enabled-squarespace-domains-hijacks/

Learn More
Research
M-Trends 2024 Special Report

In this 15th edition, M-Trends provides an inside look at the evolving cyber threat landscape, with data drawn directly from frontline incident response investigations and threat intelligence findings of high-impact attacks and remediations around the globe.

  • The latest incident response metrics including dwell times, detection sources, initial infection vectors, and so much more
  • China-nexus attackers increasingly targeting edge devices and platforms that lack EDR
  • Trending adversary operations and motivations behind zero day attacks
  • The evolution of phishing techniques amidst modern security controls
  • How attackers are leveraging AiTM to compromise multi-factor authentication safeguards
  • The reasons and solutions behind growing cloud and hybrid cloud environment intrusions
  • How AI is effectively used in red and purple team operations to help boost cyber defenses

Read Anton Chavakin's take on the report: https://medium.com/anton-on-security/reading-the-mandiant-m-trends-2024-acb3208add80

Learn More
Research
2024 Data Breach Investigations Report

Another year has passed and that means another Verizon DBIR. For those that don’t want to read the full DBIR, here was our perspective from the Internet intelligence side of cybersecurity:

  • Median time for users to fall for phishing emails is 49 seconds
  • Pretexting is a more likely social action than Phishing
  • Ransomware was a top threat across 92% of industries (less representative than last year - median ratio of initially requested ransom and company revenue was only 1.34%)
  • The human element was a component of 68% of breaches


What do these threats all have in common? DNS!

https://www.verizon.com/business/resources/reports/dbir

Learn More
Research
‘The Manipulaters’ Improve Phishing, Still Fail at Opsec

The Resurgence of the “Manipulaters” Team - Breaking HeartSenders

In January 2024, The Manipulaters pleaded with Brian Krebs to unpublish previous stories about their work, claiming the group had turned over a new leaf and gone legitimate. But new research suggests that while they have improved the quality of their products and services, these nitwits still fail spectacularly at hiding their illegal activities.

https://krebsonsecurity.com/2024/04/the-manipulaters-improve-phishing-still-fail-at-opsec

Learn More