HomeSecurityPhishing campaign targets UN, UNICEF and Red Cross

Phishing campaign targets UN, UNICEF and Red Cross

Phishing attacks are very common these days. In recent months, a phishing campaign has targeted major organizations that work to protect human rights . Some of these include the Red Cross , UNICEF , and some UN programs (UN World Food and the UN Development).phishing

The attack was discovered by researchers at security firm Lookout. According to the company, the attack affected the sites and servers organizations'

It took a long time to identify the sites that had been affected.

None of the phishing sites that Lookout researchers discovered were in Google Safe Browsing, a database that includes malicious links and helps web browsers warn users. Therefore, users will not be notified if they visit any of these sites.

The researchers contacted the organizations to inform them of the attacks. They also notified law enforcement agencies.

A UN spokesperson said the organization advises members to enable multi-factor authentication .

Who is behind these attacks?

Researchers said this is not yet known. It could be a typical phishing campaign by a criminal group or it could come from hacking groups acting in the interests of governments.

"We can't speak with certainty about the origin," said Jeremy Richards, principal investigator at Lookout.

"The motive of the attack is to compromise credentials to gain access to them. Once they gain access, hackers can carry out attacks or steal information."

A member of one of these organizations stated that hackers often target such organizations.

Many governments pay hacking groups to carry out attacks on human rights organizations with the aim of stealing information about investigations, monitoring individuals who report incidents to the organizations, or obtaining information about the organizations' members.

However, it is not only governments that target these organizations. Such attacks are carried out by hackers who have financial motives (e.g. BEC scammers, who compromise accounts to steal money).

The phishing campaign is ongoing.

According to researchers, the campaign is still ongoing. The servers hosting the phishing pages are active. The phishing pages contain malicious code that records members' passwords.

In the table below you can see the pages affected by the attack:

Phishing campaign targets UN, UNICEF and Red Cross

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS