Cyberespionage Campaign Targets UN Relief Agencies, International Red Cross: Researchers

Among the targets were UNICEF, the UN World Food Program, the UN Development Program, the International Federation of the Red Cross, and Red Crescent Societies, according to Lookout.

Advertisement
By Associated Press | Updated: 25 October 2019 10:59 IST

A coordinated cyberespionage campaign using phishing to harvest passwords from mobile phones and computers has targeted UN relief agencies, the International Red Cross and other non-governmental organisations groups for the past 10 months, a cyber-security firm reported. The San Francisco-based security company Lookout said it doesn't know who is behind the campaign, which was still active Thursday. It added that there are indications some of its targets may have been members of the international community in North Korea.

Among the targets were UNICEF, the UN World Food Program, the UN Development Program, the International Federation of the Red Cross and Red Crescent Societies, Lookout said.

Also targeted were think tanks and research organisations including The United States Institute of Peace, the Heritage Foundation, the Social Science Research Council, the East-West Center and the University of San Diego.

Advertisement

The cyberespionage campaign's Internet infrastructure has been hosted by a company called Shinjiru, which protects client identities and lets customers pay in anonymity-shielding cryptocurrency, said Jeremy Richards, a Lookout researcher.

Advertisement

Lookout discovered Internet sites designed to mimic actual UN webpages in hopes of tricking users into entering their login credentials, Richards said. All were physically hosted in Malaysia. The company has notified the targeted organisations it identified.

After obtaining the credentials of an employee already compromised by the attacks, the perpetrators would typically mine that person's email to identify their colleagues and try to infect them.

Advertisement

"We know that the typical attack path here is to get credentials from one individual in the organization and use that as a point of leverage to compromise laterally," Richards said.

He said researchers had not been able to obtain copies of phishing emails or text messages used in the campaign.

Advertisement

Two documents found by Lookout researchers may offer clues to those behind the campaign. Both documents were designed to be automatically sent to people fooled by the phishing sites and were tailored for members of the international community in Pyongyang, the North Korean capital, Richards said. Lookout provided The Associated Press with copies.

One purports to come from the Romanian Embassy and contained an invitation to a May 9 reception to mark "Europe Day." The other included a "North Korea Watchers - Introductory Survey," which purported to come from an academic at Yonsei University in South Korea.

The North Korea survey was conducted last year and widely promoted on social media, said Jeffrey Robertson, the political science professor who conducted it.

"I assume this is why the 'coordinated campaign' has used it as a front to serve their objectives," he told the AP in an email exchange.

Lookout discovered the phishing infrastructure through routine scans it does daily of the internet seeking anomalies that could be engaged in malicious activity, Richards said.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: UN, cyberespionage
Advertisement

Related Stories

Popular Mobile Brands
  1. Biggest Offers on Smartphones During Amazon Great Indian Festival Sale
  2. OTT Releases This Week: Mahavatar Narsimha, The Bads of Bollywood, and More
  3. Xiaomi 17 Series Pre-Orders Start in China
  4. Vivo X300 Series Official Images Surface Ahead of China Launch
  5. Samsung Galaxy A17 4G Goes Official With MediaTek Helio G99 SoC
  6. Amazon Sale 2025: Top Deals on Logitech, Dell, HP, and More PC Accessories
  7. Instamart Quick India Movement Sale 2025: Best Offers on Electronics
  8. Flipkart Big Billion Days Sale: iPhone 17 Available With 10-Minute Delivery
  9. iPhone 18 Pro Models Tipped to Retain iPhone 17 Pro Design
  1. Vivo, iQOO Smartphones Likely to Switch to Origin OS in India, Replacing Funtouch OS
  2. iPhone 18 Pro Models Tipped to Retain iPhone 17 Pro Design, Could Feature Transparent Back
  3. Tencent Says Sony 'Monopolising' Genre Conventions, Seeks Dismissal of Light of Motiram Lawsuit
  4. Samsung Galaxy A17 4G Launched With MediaTek Helio G99 SoC, 5,000mAh Battery: Price, Specifications
  5. Instamart Quick India Movement Sale 2025 Goes Live: Best Offers on Smartphones, Smartwatches and More
  6. Bitcoin Stabilises Near $116,900 as Altcoins Push Higher
  7. Mahavatar Narsimha Now Streaming on Netflix: Everything You Need to Know About This Animated Mythological Drama
  8. Nintendo Switch Online Adds First Third-Party Game Boy Advance Titles from Namco This September
  9. Big Billion Days Sale: Flipkart Minutes Promises Doorstep Delivery of iPhone 17, Galaxy S24 in 10 Minutes
  10. Amazon Sale 2025: Top Deals on Logitech, Dell, HP, and More PC Accessories
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.