Cyberespionage Campaign Targets UN Relief Agencies, International Red Cross: Researchers

Among the targets were UNICEF, the UN World Food Program, the UN Development Program, the International Federation of the Red Cross, and Red Crescent Societies, according to Lookout.

Advertisement
By Associated Press | Updated: 25 October 2019 10:59 IST

A coordinated cyberespionage campaign using phishing to harvest passwords from mobile phones and computers has targeted UN relief agencies, the International Red Cross and other non-governmental organisations groups for the past 10 months, a cyber-security firm reported. The San Francisco-based security company Lookout said it doesn't know who is behind the campaign, which was still active Thursday. It added that there are indications some of its targets may have been members of the international community in North Korea.

Among the targets were UNICEF, the UN World Food Program, the UN Development Program, the International Federation of the Red Cross and Red Crescent Societies, Lookout said.

Also targeted were think tanks and research organisations including The United States Institute of Peace, the Heritage Foundation, the Social Science Research Council, the East-West Center and the University of San Diego.

Advertisement

The cyberespionage campaign's Internet infrastructure has been hosted by a company called Shinjiru, which protects client identities and lets customers pay in anonymity-shielding cryptocurrency, said Jeremy Richards, a Lookout researcher.

Advertisement

Lookout discovered Internet sites designed to mimic actual UN webpages in hopes of tricking users into entering their login credentials, Richards said. All were physically hosted in Malaysia. The company has notified the targeted organisations it identified.

After obtaining the credentials of an employee already compromised by the attacks, the perpetrators would typically mine that person's email to identify their colleagues and try to infect them.

Advertisement

"We know that the typical attack path here is to get credentials from one individual in the organization and use that as a point of leverage to compromise laterally," Richards said.

He said researchers had not been able to obtain copies of phishing emails or text messages used in the campaign.

Advertisement

Two documents found by Lookout researchers may offer clues to those behind the campaign. Both documents were designed to be automatically sent to people fooled by the phishing sites and were tailored for members of the international community in Pyongyang, the North Korean capital, Richards said. Lookout provided The Associated Press with copies.

One purports to come from the Romanian Embassy and contained an invitation to a May 9 reception to mark "Europe Day." The other included a "North Korea Watchers - Introductory Survey," which purported to come from an academic at Yonsei University in South Korea.

The North Korea survey was conducted last year and widely promoted on social media, said Jeffrey Robertson, the political science professor who conducted it.

"I assume this is why the 'coordinated campaign' has used it as a front to serve their objectives," he told the AP in an email exchange.

Lookout discovered the phishing infrastructure through routine scans it does daily of the internet seeking anomalies that could be engaged in malicious activity, Richards said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: UN, cyberespionage
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Fusion India Launch Teased; Might Launch With This Chip
  2. Xiaomi Teases a New Computing Device, New Tablet Expected to Launch Soon
  3. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  4. Samsung Galaxy S26 Series Roundup: Here's Everything That We Know So Far
  5. Poco X8 Pro, X8 Pro Max Colour Options, Design Leaked Online
  6. Tipster Leaks Details of the Oppo Find X9 Ultra, Vivo X300 Ultra Cameras
  1. Astronomers Find ‘Impossible’ Galaxy ACDG-2 With Virtually No Stars and a Massive Dark Matter Core
  2. Google Pixel Call Recording Reportedly Available in Additional Regions Ahead of Global Expansion
  3. Oppo Find X9 Ultra, Vivo X300 Ultra Leak: Tipster Shares Details of Anticipated 200-Megapixel Cameras
  4. Redmi A7 Could Launch Soon as Handset Bags Thailand’s NBTC Certification
  5. Poco X8 Pro, Poco X8 Pro Max Design and Colour Options Seen in Leaked Renders
  6. Hello Bachhon OTT Release Date: When and Where to Watch Vineet Kumar Singh Starrer Online?
  7. Xiaomi Teases India Launch of New Computing Device; New Tablet With Keyboard or Laptop Expected
  8. Realme C83 5G India Price, RAM and Storage Configurations Leaked Online
  9. Xiaomi 17 Series Global Launch Date Announced; Xiaomi 17, Xiaomi 17 Ultra Expected to Debut
  10. Google Blocked 266 Million Risky App Installs, Prevented 1.75 Million Policy-Violating Apps in 2025
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.