Cyberespionage Campaign Targets UN Relief Agencies, International Red Cross: Researchers

Among the targets were UNICEF, the UN World Food Program, the UN Development Program, the International Federation of the Red Cross, and Red Crescent Societies, according to Lookout.

Advertisement
By Associated Press | Updated: 25 October 2019 10:59 IST

A coordinated cyberespionage campaign using phishing to harvest passwords from mobile phones and computers has targeted UN relief agencies, the International Red Cross and other non-governmental organisations groups for the past 10 months, a cyber-security firm reported. The San Francisco-based security company Lookout said it doesn't know who is behind the campaign, which was still active Thursday. It added that there are indications some of its targets may have been members of the international community in North Korea.

Among the targets were UNICEF, the UN World Food Program, the UN Development Program, the International Federation of the Red Cross and Red Crescent Societies, Lookout said.

Advertisement

Also targeted were think tanks and research organisations including The United States Institute of Peace, the Heritage Foundation, the Social Science Research Council, the East-West Center and the University of San Diego.

The cyberespionage campaign's Internet infrastructure has been hosted by a company called Shinjiru, which protects client identities and lets customers pay in anonymity-shielding cryptocurrency, said Jeremy Richards, a Lookout researcher.

Advertisement

Lookout discovered Internet sites designed to mimic actual UN webpages in hopes of tricking users into entering their login credentials, Richards said. All were physically hosted in Malaysia. The company has notified the targeted organisations it identified.

After obtaining the credentials of an employee already compromised by the attacks, the perpetrators would typically mine that person's email to identify their colleagues and try to infect them.

Advertisement

"We know that the typical attack path here is to get credentials from one individual in the organization and use that as a point of leverage to compromise laterally," Richards said.

He said researchers had not been able to obtain copies of phishing emails or text messages used in the campaign.

Advertisement

Two documents found by Lookout researchers may offer clues to those behind the campaign. Both documents were designed to be automatically sent to people fooled by the phishing sites and were tailored for members of the international community in Pyongyang, the North Korean capital, Richards said. Lookout provided The Associated Press with copies.

One purports to come from the Romanian Embassy and contained an invitation to a May 9 reception to mark "Europe Day." The other included a "North Korea Watchers - Introductory Survey," which purported to come from an academic at Yonsei University in South Korea.

The North Korea survey was conducted last year and widely promoted on social media, said Jeffrey Robertson, the political science professor who conducted it.

"I assume this is why the 'coordinated campaign' has used it as a front to serve their objectives," he told the AP in an email exchange.

Lookout discovered the phishing infrastructure through routine scans it does daily of the internet seeking anomalies that could be engaged in malicious activity, Richards said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: UN, cyberespionage
Advertisement

Related Stories

Popular Mobile Brands
  1. Qualcomm May Return to Samsung for New Snapdragon 8 Elite Gen 6 Chips 
  2. Motorola Edge 70 Pro Arrives With a 6,500mAh Battery at This Price in India
  3. Motorola Edge 70 Pro vs OnePlus Nord 6 vs Redmi Note 15 Pro+ Compared
  4. Vivo X300 Ultra, Vivo X300 FE Will Launch in India on This Date
  5. Sennheiser CX 80U, HD 400U With USB Type-C Connectivity Launched in India
  1. Control Ultimate Edition Arrives on iPhone and iPad With Touch Controls, Universal Purchase
  2. Asus ExpertBook Ultra With Intel Core Ultra X7 Series 3 CPU Launched in India Alongside ExpertBook P3, ExpertBook P5 Series
  3. Boat Aavante Prime X Soundbar Launched in India With Dolby Atmos, Wireless Satellite Speakers: Price, Features
  4. Qualcomm CEO Reportedly Visits Samsung Foundry in Korea to Discuss Producing 2nm Chips
  5. Coinbase Announces USDC-INR Trading Services for Users in India
  6. Redmi K Pad 2 Launched With 8.8-Inch 3K Display, Dimensity 9500 Chip: Price, Specifications
  7. OnePlus Watch 4 Launch Appears Imminent as Listing Confirms Snapdragon W5 Chip, OxygenOS Watch 8
  8. Sennheiser CX 80U, Sennheiser HD 400U With USB Type-C Connectivity Launched in India: Price, Features
  9. Elden Ring Film Adaptation Sets 2028 Release Date; Full Cast Revealed as Production Begins
  10. Honor 600 Pro and Honor 600 Launched With 7,000mAh Batteries, 200-Megapixel Cameras: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.