CampaignSMS

SMS Phishing Messages Targets UAE Citizens, Visitors – Dark Reading

Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa.
The text messages threaten fines if the victims don’t provide personal and financial details.
December 21, 2023
A malicious SMS campaign that harvests personal information and credit card details is targeting citizens and visitors to the United Arab Emirates.
The text-based campaign, run by the so-called Smishing Triad Gang, impersonates the United Arab Emirates Federal Authority for Identity and Citizenship, and claims to be on behalf of the General Directorate of Residency and Foreigners Affairs.
According to researchers from Resecurity, the SMS messages instruct the recipient to update their information "to avoid hefty fines." The link provided in the text message uses a URL-shortening tool to disguise the actual URL.
The Smishing Triad Gang previously ran campaigns impersonating the UAE's official parcel delivery service and global postal and delivery services, where the attackers also tried to collect personal and financial information.
The location of the Smishing Triad gang is unclear, but the fraudulent domains where details are collected are often registered in China.
To protect against detection, the attackers used geolocation filtering to ensure the phishing form will only appear when visited from UAE IP addresses and mobile devices.
Resecurity researchers believe the attackers may have access to a private channel where they obtained information about UAE residents and foreigners living in, or visiting, the country. The gang could have obtained it via third-party data breaches, business email compromises, or databases purchased on the Dark Web.
Read more about:
Dark Reading Staff
Dark Reading
Dark Reading is a leading cybersecurity media site.
You May Also Like
Empowering Developers, Automating Security: The Future of AppSec
Black Hat USA – Aug 3-8 – The Premier Technical Cybersecurity Conference – Learn More
Black Hat Europe – December 9-12 – Learn More
SecTor – Canada’s IT Security Conference Oct 22-24 – Learn More
Elastic named a Leader in The Forrester Waveâ„¢: Security Analytics Platforms, Q4 2022
2023 Global Threat Report
EMA: AI at your fingertips: How Elastic AI Assistant simplifies cybersecurity
Industrial Networks in the Age of Digitalization
Zero-Trust Adoption Driven by Data Protection
A Watershed Moment for Threat Detection and Response
SecOps Checklist
Shining a light in the dark: observability and security, a SANS profile
A Short Primer on Container Scanning
ESG E-Book: Taking a Holistic Approach to Securing Cloud-Native Application Development
Black Hat USA – Aug 3-8 – The Premier Technical Cybersecurity Conference – Learn More
Black Hat Europe – December 9-12 – Learn More
SecTor – Canada’s IT Security Conference Oct 22-24 – Learn More
Copyright © 2024 Informa PLC Informa UK Limited is a company registered in England and Wales with company number 1072954 whose registered office is 5 Howick Place, London, SW1P 1WG.

source

Leave a Reply

Your email address will not be published. Required fields are marked *