PULSE NAME
London Calling: Two-Factor Authentication Phishing From Iran
WHITE AlienVault 2015-08-27 Modified: 2017-08-24
14
IOCs
MEDIUM VOLUME
(Citizen Lab) This report describes an elaborate phishing campaign against targets in Iran’s diaspora, and at least one Western activist. The ongoing attacks attempt to circumvent the extra protections conferred by two-factor authentication in Gmail, and rely heavily on phone-call based phishing and “real time” login attempts by the attackers. Most of the attacks begin with a phone call from a UK phone number, with attackers speaking in either English or Farsi. The attacks point to extensive knowledge of the targets’ activities, and share infrastructure and tactics with campaigns previously linked to Iranian threat actors. We have documented a growing number of these attacks, and have received reports that we cannot confirm of targets and victims of highly similar attacks, including in Iran. The report includes extra detail to help potential targets recognize similar attacks. The report closes with some security suggestions, highlighting the importance of two-factor authentication.
Indicators of Compromise (14)
All domain hostname email
TYPEINDICATORDESCRIPTIONCREATED
domain service-logins.com 2017-08-24
domain services-mails.com 2017-08-24
domain signin-verify.com 2017-08-24
domain login-users.com 2017-08-24
domain account-user.com 2017-08-24
domain signin-users.com 2017-08-24
domain bluehostsupport.com 2017-08-24
hostname support.qooqlemail.com 2017-08-24
hostname login.setting.verification.configuration.user.action.first.step.edit.check.privacy.view.document.setting.verification.configuration.user.login.logins-verify.com 2017-08-24
hostname reuters.users.check.login.newsia.my 2017-08-24
hostname login.logins-verify.com 2017-08-24
email bijan.yazdani2002@gmail.com 2017-08-24
email kavaliulinovich@gmail.com 2017-08-24
email reply@support.qooqlemail.com 2017-08-24