Cyberespionage Campaign Targets UN Relief Agencies, International Red Cross: Researchers

Among the targets were UNICEF, the UN World Food Program, the UN Development Program, the International Federation of the Red Cross, and Red Crescent Societies, according to Lookout.

Advertisement
By Associated Press | Updated: 25 October 2019 10:59 IST

A coordinated cyberespionage campaign using phishing to harvest passwords from mobile phones and computers has targeted UN relief agencies, the International Red Cross and other non-governmental organisations groups for the past 10 months, a cyber-security firm reported. The San Francisco-based security company Lookout said it doesn't know who is behind the campaign, which was still active Thursday. It added that there are indications some of its targets may have been members of the international community in North Korea.

Among the targets were UNICEF, the UN World Food Program, the UN Development Program, the International Federation of the Red Cross and Red Crescent Societies, Lookout said.

Also targeted were think tanks and research organisations including The United States Institute of Peace, the Heritage Foundation, the Social Science Research Council, the East-West Center and the University of San Diego.

Advertisement

The cyberespionage campaign's Internet infrastructure has been hosted by a company called Shinjiru, which protects client identities and lets customers pay in anonymity-shielding cryptocurrency, said Jeremy Richards, a Lookout researcher.

Advertisement

Lookout discovered Internet sites designed to mimic actual UN webpages in hopes of tricking users into entering their login credentials, Richards said. All were physically hosted in Malaysia. The company has notified the targeted organisations it identified.

After obtaining the credentials of an employee already compromised by the attacks, the perpetrators would typically mine that person's email to identify their colleagues and try to infect them.

Advertisement

"We know that the typical attack path here is to get credentials from one individual in the organization and use that as a point of leverage to compromise laterally," Richards said.

He said researchers had not been able to obtain copies of phishing emails or text messages used in the campaign.

Advertisement

Two documents found by Lookout researchers may offer clues to those behind the campaign. Both documents were designed to be automatically sent to people fooled by the phishing sites and were tailored for members of the international community in Pyongyang, the North Korean capital, Richards said. Lookout provided The Associated Press with copies.

One purports to come from the Romanian Embassy and contained an invitation to a May 9 reception to mark "Europe Day." The other included a "North Korea Watchers - Introductory Survey," which purported to come from an academic at Yonsei University in South Korea.

The North Korea survey was conducted last year and widely promoted on social media, said Jeffrey Robertson, the political science professor who conducted it.

"I assume this is why the 'coordinated campaign' has used it as a front to serve their objectives," he told the AP in an email exchange.

Lookout discovered the phishing infrastructure through routine scans it does daily of the internet seeking anomalies that could be engaged in malicious activity, Richards said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: UN, cyberespionage
Advertisement

Related Stories

Popular Mobile Brands
  1. Lava Agni 4 Price Range, Features Leaked; Will Launch in These Colourways
  2. Apple's Low-Cost MacBook Launch Timeline, Price Leaked Ahead of Debut
  3. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 SoC, Slim 5.99mm Profile
  4. Moto G67 Power 5G Launched in India With 7,000mAh Battery: See Price
  5. Samsung Galaxy S26 Ultra Spotted in Leaked Renders With Rounder Corners
  6. Moto G Play (2026), Moto G (2026) With Dimensity 6300 SoC Launched
  7. Realme UI 7.0 Launched With Light Glass Design, AI Features
  8. OnePlus Ace 6 Pro Max Configurations Leaked; May Feature Up to 16GB of RAM
  9. Apple's iOS 26.2 Developer Beta Rolled Out With This New Safety Feature
  1. Steam Deck Gets a Display-Off Low-Power Mode for Downloads Three Years After Launch
  2. Realme Will Try to Absorb Increased Cost of Components Ahead of Upcoming Product Launches, Executive Says
  3. Motorola Edge 70 Launched With Snapdragon 7 Gen 4 Chipset, Slim 5.99mm Profile: Price, Specifications
  4. Researchers Unveil How Atomic Entanglement Enhances Light Bursts
  5. Lava Agni 4 Confirmed to Launch in Two Colourways; Tipster Leaks Price Range, Key Features
  6. Google Proposes Play Store Reforms in Settlement With Fortnite Maker Epic Games
  7. Scientists Recreate Cosmic ‘Fireballs’ in Lab to Solve Mystery of Missing Gamma Rays
  8. Realme UI 7.0 Launched With Light Glass Design, AI Notify Brief and AI Gaming Coach: See Eligible Phones, Beta Release Schedule
  9. iOS 26.2 Beta 1 Rolled Out to Developers With Enhanced Safety Alerts, Reminder Alarms
  10. Samsung Galaxy S26 Ultra Spotted in Leaked Design Renders That Hint at Rounder Corners
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.