Cybersecurity researchers have uncovered a phishing campaign that uses events in Gaza and Israel to try to exploit people's charitable feelings . Cybercriminals targeted 212 individuals across 88 organizations , trying to convince them to help children in Palestine.

The attackers are posing as a group from “help-palestine[.]com”, and are urging victims to contribute financially, to a campaign that supposedly provides vital support to families in Palestine. The attackers asked for donations via crypto (Litecoin, Ethereum, Bitcoin), ranging from $100 to $5000.
To bolster the credibility of the alleged charity campaign, the attackers included three links to recent news articleshighlighting the impact of war on children.
See also: Dismantling of a vishing attack ring
According to Abnormal Security, this form of social engineering exploits people's heightened emotional response to such humanitarian crises, making individuals more susceptible to deception.
The attackers deliberately used emotionally charged language, emphasizing the challenges facing children in Palestine and using terms that aim to create a shared identity with the recipients.
From a technical perspective, the attackers used multiple tactics to hide their identity. They spoofed the legitimate email of Goodwill Wealth Management, an India-based company, and created a non-existent domain. The real email address was hidden in the reply field.
Abnormal's CISO, Mike Britton, said that detecting the phishing campaign using traditional email security tools was not easy, as the attackers used social engineering and the emails lacked obvious signs, such as payloads or grammatical errors.
See also: TA402 hackers use new IronWind downloader in phishing attacks
The expert added that legacy secure email gateways (SEGs) have difficulty distinguishing between genuine and malicious intent. It is necessary to use modern email security solutions with artificial intelligence.
“ AI-powered email security platforms are trained to detect social engineering tactics, so they recognize that this email is attempting to leverage emotional manipulation to convince the target to bypass rational thought and quickly transfer funds ,” Britton wrote . “ They can also detect and flag the mismatch between the sender’s email and the reply-to address, as this is a common attack tactic .”

To protect themselves from these charity scams, people and organizations can take the following steps:
- Research the charity: Before making any donation, research the organization to make sure it is legitimate and trustworthy. Check their website, history, and reviews from independent sources.
- Beware of unexpected communications: If you receive an unexpected email, text message, or phone call asking for a donation, you are likely dealing with a phishing scam. Do not respond or provide personal information without confirming the authenticity of the communication.
- Check transaction security: Before making any donation, make sure the website has SSL security and that payments are made through a secure payment gateway.
- Contact the charity directly: If you would like to donate, contact the organization directly using their official contact information. This will help you verify the authenticity of the organization and your donation.
- Beware of social engineering tricks: Cybercriminals may use such techniques (as in this case) to convince you to donate. Be cautious and always confirm the authenticity of requests before taking any action.
See also: Authorities “slammed” the phishing service BulletProftLink
By taking these precautions, people and organizations can reduce the risk of falling victim to charity fraud and phishing and ensure that their donations go to the real people and organizations that need them.
Source: www.infosecurity-magazine.com
