HomeSecurityUSA: Seizure of domains that spoof COVID-19 vaccine development companies

US: Seizure of domains that spoof COVID-19 vaccine development companies

The US Department of Justice (DoJ) has seized two domains that spoofed the official websites of biotech companies Moderna and Regeneron, which are involved in developing vaccines to combat COVID-19. The domains seized by the federal government were used for a variety of malicious purposes, including running scams, infecting visitors with malware , and collecting sensitive information through phishing attacks.

The US Department of Justice said at the end of last week that anyone visiting these sites now will see a message that the site has been seized by the federal government and will be redirected to another site for additional information.

US: Seizure of domains that spoof COVID-19 vaccine development companies

The U.S. Attorney for the District of Maryland, Robert K. Hur, said the following after the seizure of the domains: "I urge citizens to remain vigilant. Do not provide personal information or click on sites or links contained in spam emails. Do not become a victim."

The investigation into the two domains – mordernatx[.] Com and regeneronmedicals[.] Com – followed a report by cybersecurity and an ongoing investigation into malicious sites. In both cases, visitors who wanted to go to the “Contact Us” on the now-closed sites were redirected to a form that asked them to either provide sensitive personal information, such as their name, company/institution, title, phone number and email, or to communicate via VOIP.

US: Seizure of domains that spoof COVID-19 vaccine development companies

The domain mordernatx [.] Com was registered by a company from Kuala Lumpur, Malaysia, on December 8, and regeneronmedicals [.] Com on December 6 by an individual from Onitsha Anambra, Nigeria.

The U.S. Department of Justice said that by seizing these domains, the government prevented third parties from obtaining the names and using them to commit additional crimes, while also preventing third parties from continuing to access the sites in their current form. In addition, Homeland Security Investigations Special Agent in Charge John Eisert noted that these individuals exploited the fear and confusion caused by the global COVID-19 health crisis and attempted to steal personal information for malicious purposes.

As reported by BleepingComputer, over 275,000 Americans have reported financial losses exceeding $211 million, after scams related to COVID-19 since the beginning of the current year, according to the U.S. Federal Trade Commission (FTC). Cybercriminals have also targeted organizations involved in COVID-19 research and the cold chain of vaccines.

US: Seizure of domains that spoof COVID-19 vaccine development companies

For example, vaccine development organizations from Canada, the United Kingdom and the United States have been targeted throughout the year by the Russian state hacking group “APT29”, aiming to collect information related to the development and control of the vaccine.

Additionally, hackers affiliated with the People's Republic of China have been involved in similar attacks, according to a joint statement issued by the FBI, DHS, and CISA.

Finally, Microsoft has also removed domains that were used in COVID-19-related cybercrime, such as the collection of sensitive information, which was later used in BEC (Business Email Compromise) attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS