Hackers planning phishing attack with fake MOM e-mails, warns cybersecurity firm

Published Fri, Jun 19, 2020 · 09:50 PM

    Singapore

    HACKERS could target Singapore businesses on Sunday with a spoofed Ministry of Manpower (MOM) e-mail promising additional subsidies for their employees, a cybersecurity group warned on Thursday.

    Singapore and Tokyo-headquartered Cyfirma said that an online threat assessment it conducted between June 1 and 16 revealed that prominent hacker group Lazarus Group was planning a phishing campaign targeting over five million people and businesses worldwide.

    The targets are in six countries whose governments have announced fiscal support to individuals and businesses in light of the pandemic: Singapore, Japan, South Korea, India, the US and the UK.

    The Cyber Security Agency of Singapore said in a statement late on Friday that it has notified "relevant parties" about the potential phishing campaign, and has issued an advisory to be on the lookout.

    "Opportunistic cyber criminals have been using the Covid-19 situation to conduct malicious cyber activities, and, with the increasing reliance on the Internet during this period, it is important to be vigilant," it added.

    Meanwhile, MOM said it had "received information regarding a potential phishing campaign that will be targeting businesses during this period". It added: "Please use only the official MOM website for all info and transactions on MOM matters."

    Investigations by Cyfirma into Lazarus Group's activities found seven e-mail templates impersonating government agencies, departments and trade associations tasked with overseeing the disbursement of such forms of fiscal aid.

    For Singapore, the hackers - who claim to have 8,000 business contact details - will target businesses with a phishing email on June 21, the cybersecurity platform said. This e-mail will be sent from a spoofed MOM account announcing a fake government initiative to give businesses an additional one-time subsidy of S$750 per employee. Recipients will then be directed to fake websites, where they will be tricked into divulging personal and financial information, according to Cyfirma.

    The cybersecurity firm revealed that as at Thursday, it had not detected such fake websites, but added its research showed the hackers were planning to set them up within the next 24 hours.