news.mlab.sh
Back to the feed
threat-intel

Hundreds of fake government websites target users in Central Asia

Medium
Summary

Cybercriminals are creating hundreds of fake government websites targeting citizens in Central Asia – Uzbekistan, Belarus, and Tajikistan – to trick users into providing personal information and installing malware, ultimately aiming to steal money and sensitive data. The campaign leverages trust in legitimate government programs and social initiatives to deceive victims.

Cybercriminals are launching a sophisticated campaign targeting citizens in Central Asia, specifically Uzbekistan, Belarus, and Tajikistan, by creating numerous fake government and news websites. These fraudulent sites mimic legitimate government portals and news outlets to build trust and encourage users to submit their contact details. The primary goal is to collect personal information, which is then used to target victims through phone or email, promising cash payments or passive income under false government programs. In Uzbekistan, for example, victims are lured with the promise of weekly payments of 15 million Uzbek sums (approximately $1,300).

Many of the sites are simple landing pages prompting users to fill out a form, while others are more complex, replicating the look and feel of regional news websites and even publishing fake stories about government assistance programs before directing readers to questionnaires. Once users submit their details, scammers typically call them, posing as personal managers, and may ask victims to pay a commission or processing fee to receive the promised money, or attempt to obtain more personal information and gain access to their devices.

In some cases, victims are instructed to install a mobile application supposedly needed to register for the program or verify their identity. This application is actually malware capable of giving attackers control over the device and potentially allowing them to steal money from victims’ accounts. The scammers can also request scans of passports, which they can then use for further fraud, including taking out loans in victims’ names or carrying out phishing attacks.

Researchers at cybersecurity firm F6 have identified over 360 fraudulent domains linked to this campaign. They have not yet identified the group behind the operation, and the exact number of victims remains unknown. The campaign highlights the increasing use of social engineering tactics by cybercriminals to exploit citizens’ trust in government programs and social initiatives.

Read the full article at The Record