• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Massive-Scale Phishing Marketing campaign Targets Protection and Aerospace Firms

Admin by Admin
March 27, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


A latest investigation by DomainTools Investigations (DTI) has uncovered an enormous phishing infrastructure concentrating on protection and aerospace entities, significantly these linked to the battle in Ukraine.

This subtle marketing campaign includes a community of mail servers supporting domains that mimic professional organizations, designed to steal important credentials from staff in these sectors.

The infrastructure depends on a handful of mail servers, every internet hosting a number of spoofed domains that carefully resemble real firm web sites.

These domains usually host webmail login pages, engineered to seize log-in credentials from unsuspecting customers.

Webmail login page hosted on kroboronprom[.]comWebmail login page hosted on kroboronprom[.]com
Webmail login web page hosted on kroboronprom[.]com

Notably, the investigation recognized a phishing web page on a site named kroboronprom[.com, which impersonates Ukraine’s largest arms producer, Ukroboronprom.

Domains Likely Related to kroboronprom[.]comDomains Likely Related to kroboronprom[.]com
Domains Seemingly Associated to kroboronprom[.]com

Key Findings

  1. Phishing Infrastructure Particulars
    • kroboronprom[.]com: This area, designed to spoof Ukroboronprom, was first detected on December 20, 2024. It hosts a webmail login web page constructed utilizing Mailu, an open-source mail server software program accessible on GitHub.
    • Related Domains: Upon additional evaluation, 9 different domains with the identical web site title have been recognized. These embody scooby-doo[.]xyz, lucky-guy[.]house, and santa-clause[.]on-line, amongst others. All have been registered with the Spaceship registrar and hosted on GHOSTnet VPS.
  2. Enlargement of Recognized Domains
    • A secondary search revealed three extra domains (space-kitty[.]on-line, stupid-buddy[.]mother, and hungry-shark[.]sit), which additionally host Mailu webmail login pages. These are suspected for use for credential theft.
    • These domains have been used as MX domains for mail servers supporting a big set of spoofed domains concentrating on protection, aerospace, and IT sectors. In complete, 878 spoofed domains have been recognized.

The attackers possible use these spoofed domains to ship phishing emails that seem to originate from throughout the focused group.

These emails comprise malicious hyperlinks or attachments directing recipients to faux webmail login pages designed to reap credentials.

Targets and Motivation

The marketing campaign focuses closely on protection and aerospace firms which have offered help to Ukraine’s navy efforts towards Russia.

This means a motivation rooted in cyber espionage, geared toward gathering intelligence associated to the continuing battle in Ukraine.

In addition to credential phishing, some domains have been linked to the distribution of malicious recordsdata.

The subdomain cryptshare.rheinemetall[.]com was used to facilitate file sharing, masquerading as a professional safe file retrieval service. This means a broader vary of malicious actions past credential theft.

Screenshot of cryptshare.rheinemetall[.]comScreenshot of cryptshare.rheinemetall[.]com
Screenshot of cryptshare.rheinemetall[.]com

Whereas the exact actor behind this marketing campaign stays unidentified, the emphasis on protection and aerospace entities and the techniques employed strongly counsel a cyber espionage motive tied to the Ukraine battle.

The in depth use of spoofed domains and webmail login pages underscores the sophistication and scale of this risk, highlighting the necessity for vigilance amongst these important sectors.

Are you from SOC/DFIR Groups? – Analyse Malware, Phishing Incidents & get dwell Entry with ANY.RUN -> Begin Now for Free. 

Tags: AerospaceCampaignCompaniesDefenseLargeScalePhishingtargets
Admin

Admin

Next Post
Victrix Professional BFG Tekken 8 Rage Artwork Version Controller Overview – Customizable, Comfy, however Missing in Methods – TouchArcade

Victrix Professional BFG Tekken 8 Rage Artwork Version Controller Overview – Customizable, Comfy, however Missing in Methods – TouchArcade

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025
Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025
Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

How authorities cyber cuts will have an effect on you and your enterprise

How authorities cyber cuts will have an effect on you and your enterprise

July 9, 2025
Namal – Half 1: The Shattered Peace | by Javeria Jahangeer | Jul, 2025

Namal – Half 1: The Shattered Peace | by Javeria Jahangeer | Jul, 2025

July 9, 2025
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved