{"id":4926,"date":"2025-07-25T23:14:57","date_gmt":"2025-07-25T23:14:57","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=4926"},"modified":"2025-07-25T23:14:57","modified_gmt":"2025-07-25T23:14:57","slug":"phishers-goal-aviation-execs-to-rip-off-clients-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=4926","title":{"rendered":"Phishers Goal Aviation Execs to Rip-off Clients \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>KrebsOnSecurity lately heard from a reader whose boss\u2019s electronic mail account received phished and was used to trick one of many firm\u2019s prospects into sending a big fee to scammers. An investigation into the attacker\u2019s infrastructure factors to a long-running Nigerian cybercrime ring that&#8217;s actively concentrating on established corporations within the transportation and aviation industries.<\/p>\n<div id=\"attachment_71757\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-71757\" decoding=\"async\" class=\" wp-image-71757\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/shutterstock-airplanes.png\" alt=\"\" width=\"749\" height=\"535\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/shutterstock-airplanes.png 666w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/shutterstock-airplanes-100x70.png 100w\" sizes=\"auto, (max-width: 749px) 100vw, 749px\"\/><\/p>\n<p id=\"caption-attachment-71757\" class=\"wp-caption-text\">Picture: Shutterstock, Mr. Teerapon Tiuekhom.<\/p>\n<\/div>\n<p>A reader who works within the transportation business despatched a tip a couple of latest profitable phishing marketing campaign that tricked an govt on the firm into coming into their credentials at a faux Microsoft 365 login web page. From there, the attackers shortly mined the manager\u2019s inbox for previous communications about invoices, copying and modifying a few of these messages with new bill calls for that have been despatched to a number of the firm\u2019s prospects and companions.<\/p>\n<p>Talking on situation of anonymity, the reader stated the ensuing phishing emails to prospects got here from a newly registered area identify that was remarkably just like their employer\u2019s area, and that no less than certainly one of their prospects fell for the ruse and paid a phony bill. They stated the attackers had spun up a look-alike area only a few hours after the manager\u2019s inbox credentials have been phished, and that the rip-off resulted in a buyer struggling a six-figure monetary loss.<\/p>\n<p>The reader additionally shared that the e-mail addresses within the registration information for the imposter area \u2014 <strong>roomservice801@gmail.com<\/strong> \u2014 is tied to many such phishing domains. Certainly, a search on this electronic mail deal with at <strong>DomainTools.com<\/strong> finds it&#8217;s related to no less than 240 domains registered in 2024 or 2025. Nearly all of them mimic authentic domains for corporations within the aerospace and transportation industries worldwide.<\/p>\n<p>An Web seek for this electronic mail deal with reveals <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20220514070749\/https:\/\/hackware.ru\/?p=12106\" target=\"_blank\" rel=\"noopener\">a humorous weblog publish from 2020<\/a> on the Russian discussion board hackware[.]ru, which discovered roomservice801@gmail.com was tied to a phishing assault that used the lure of phony invoices to trick the recipient into logging in at a faux Microsoft login web page. We\u2019ll come again to this analysis in a second.<\/p>\n<h2>JUSTY JOHN<\/h2>\n<p>DomainTools exhibits that a number of the early domains registered to roomservice801@gmail.com in 2016 embrace different helpful data. For instance, the WHOIS information for <strong>alhhomaidhicentre[.]biz<\/strong> reference the technical contact of \u201c<strong>Justy John<\/strong>\u201d and the e-mail deal with <strong>justyjohn50@yahoo.com<\/strong>.<\/p>\n<p>A search at DomainTools discovered justyjohn50@yahoo.com has been registering one-off phishing domains since no less than 2012. At this level, I used to be satisfied that some safety firm certainly had already revealed an evaluation of this specific risk group, however I didn\u2019t but have sufficient data to attract any strong conclusions.<\/p>\n<p>DomainTools says the Justy John electronic mail deal with is tied to greater than two dozen domains registered since 2012, however we will discover tons of extra phishing domains and associated electronic mail addresses just by pivoting on particulars within the registration information for these Justy John domains. For instance, the road deal with utilized by the Justy John area <strong>axisupdate[.]internet<\/strong> \u2014 7902 Pelleaux Highway in Knoxville, TN \u2014 additionally seems within the registration information for accountauthenticate[.]com, acctlogin[.]biz, and loginaccount[.]biz, all of which at one level included the e-mail deal with <strong>rsmith60646@gmail.com<\/strong>.<\/p>\n<p>That Rsmith Gmail deal with is linked to the 2012 phishing area alibala[.]biz (one character off of the Chinese language e-commerce large alibaba.com, with a special top-level area of .biz). A search in DomainTools on the cellphone quantity in these area information \u2014 1.7736491613 \u2014 reveals much more phishing domains in addition to the Nigerian cellphone quantity \u201c2348062918302\u201d and the e-mail deal with <strong>michsmith59@gmail.com<\/strong>.<\/p>\n<p>DomainTools exhibits michsmith59@gmail.com seems within the registration information for the area <strong>seltrock[.]com<\/strong>, which was used within the phishing assault documented in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/web.archive.org\/web\/20220514070749\/https:\/\/hackware.ru\/?p=12106\" target=\"_blank\" rel=\"noopener\">the 2020 Russian weblog publish<\/a> talked about earlier. At this level, we&#8217;re simply two steps away from figuring out the risk actor group.<\/p>\n<p>The identical Nigerian cellphone quantity exhibits up in dozens of area registrations that reference the e-mail deal with <strong>sebastinekelly69@gmail.com<\/strong>, together with <strong>26i3[.]internet<\/strong>, <strong>costamere[.]com<\/strong>, <strong>danagruop[.]us<\/strong>, and <strong>dividrilling[.]com<\/strong>. A Internet search on any of these domains finds they have been listed in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/github.com\/pan-unit42\/iocs\/blob\/master\/silverterrier\/domains.csv\" target=\"_blank\" rel=\"noopener\">an \u201cindicator of compromise\u201d record on GitHub<\/a> maintained by <strong>Palo Alto Networks<\/strong>\u2018 <strong>Unit 42<\/strong> analysis crew.<span id=\"more-71635\"\/><\/p>\n<h2>SILVERTERRIER<\/h2>\n<p>In accordance with Unit 42, the domains are the handiwork of an unlimited cybercrime group primarily based in Nigeria that it dubbed \u201c<strong>SilverTerrier<\/strong>\u201d again in 2014. In <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/silverterrier-nigerian-business-email-compromise\/\" target=\"_blank\" rel=\"noopener\">an October 2021 report<\/a>, Palo Alto stated SilverTerrier excels at so-called \u201c<strong>enterprise e-mail compromise<\/strong>\u201d or <strong>BEC<\/strong> scams, which goal authentic enterprise electronic mail accounts by way of social engineering or laptop intrusion actions. BEC criminals use that entry to provoke or redirect the switch of enterprise funds for private achieve.<\/p>\n<p>Palo Alto says SilverTerrier encompasses tons of of BEC fraudsters, a few of whom have been arrested in varied worldwide legislation enforcement operations by <strong>Interpol<\/strong>. In 2022, Interpol and the Nigeria Police Power <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.interpol.int\/en\/News-and-Events\/News\/2022\/Nigerian-cybercrime-fraud-11-suspects-arrested-syndicate-busted\" target=\"_blank\" rel=\"noopener\">arrested 11 alleged SilverTerrier members<\/a>, together with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/operation-delilah-business-email-compromise-actor\/\" target=\"_blank\" rel=\"noopener\">a distinguished SilverTerrier chief<\/a> who\u2019d been flaunting his wealth on social media for years. Sadly, the lure of simple cash, endemic poverty and corruption, and low boundaries to entry for cybercrime in Nigeria conspire to supply a continuing stream of recent recruits.<\/p>\n<p>BEC scams have been the seventh most reported crime tracked by the FBI\u2019s <strong>Web Crime Grievance Middle<\/strong> (IC3) in 2024, producing greater than 21,000 complaints. Nevertheless, BEC scams have been the second costliest type of cybercrime reported to the feds final 12 months, with <em>practically $2.8 billion in claimed losses<\/em>.\u00a0In its <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.afponline.org\/training-resources\/resources\/survey-research-economic-data\/Details\/payments-fraud\" target=\"_blank\" rel=\"noopener\">2025 Fraud and Management Survey Report<\/a>, the <strong>Affiliation for Monetary Professionals<\/strong> discovered 63 % of organizations skilled a BEC final 12 months.<\/p>\n<p>Poking at a number of the electronic mail addresses that spool out from this analysis reveals a variety of Fb accounts for individuals residing in Nigeria or within the United Arab Emirates, lots of whom don&#8217;t seem to have tried to masks their real-life identities. Palo Alto\u2019s Unit 42 researchers reached an identical conclusion, noting that though a small subset of those crooks went to nice lengths to hide their identities, it was normally easy to study their identities on social media accounts and the main messaging providers.<\/p>\n<p>Palo Alto stated BEC actors have change into much more organized over time, and that whereas it stays simple to search out actors working as a gaggle, the observe of utilizing one cellphone quantity, electronic mail deal with or alias to register malicious infrastructure in help of a number of actors has made it much more time consuming (however not unimaginable) for cybersecurity and legislation enforcement organizations to kind out which actors dedicated particular crimes.<\/p>\n<p>\u201cWe proceed to search out that SilverTerrier actors, no matter geographical location, are sometimes linked by way of just a few levels of separation on social media platforms,\u201d the researchers wrote.<\/p>\n<h2>FINANCIAL FRAUD KILL CHAIN<\/h2>\n<p>Palo Alto has revealed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/unit42.paloaltonetworks.com\/operation-falcon-ii-silverterrier-nigerian-bec\/#protections-and-mitigations\" target=\"_blank\" rel=\"noopener\">a helpful record of suggestions<\/a> that organizations can undertake to attenuate the incidence and impression of BEC assaults. Lots of these suggestions are prophylactic, resembling conducting common worker safety coaching and reviewing community safety insurance policies.<\/p>\n<p>However one advice \u2014 getting acquainted with a course of generally known as the \u201c<strong>monetary fraud kill chain<\/strong>\u201d or FFKC \u2014 bears particular point out as a result of it affords the only greatest hope for BEC victims who&#8217;re looking for to claw again funds made to fraudsters, and but far too many victims don\u2019t realize it exists till it&#8217;s too late.<\/p>\n<div id=\"attachment_71758\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-71758\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-71758\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/ffkc-fbi.png\" alt=\"\" width=\"749\" height=\"786\"\/><\/p>\n<p id=\"caption-attachment-71758\" class=\"wp-caption-text\">Picture: ic3.gov.<\/p>\n<\/div>\n<p>As defined in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/elderjustice\/media\/1364056\/dl?inline\" target=\"_blank\" rel=\"noopener\">this FBI primer<\/a>, the Worldwide Monetary Fraud Kill Chain is a partnership between federal legislation enforcement and monetary entities whose objective is to freeze fraudulent funds wired by victims. In accordance with the FBI, viable sufferer <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.ic3.gov\/CrimeInfo\/BEC\" target=\"_blank\" rel=\"noopener\">complaints filed with ic3.gov<\/a> promptly after a fraudulent switch (typically lower than 72 hours) might be robotically triaged by the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Financial_Crimes_Enforcement_Network\" target=\"_blank\" rel=\"noopener\">Monetary Crimes Enforcement Community<\/a> (FinCEN).<\/p>\n<p>The FBI famous in its <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2024_IC3Report.pdf\" target=\"_blank\" rel=\"noopener\">IC3 annual report<\/a> (PDF) that the FFKC had a 66 % success fee in 2024. Viable ic3.gov complaints contain losses of no less than $50,000, and embrace all information from the sufferer or sufferer financial institution, in addition to a accomplished FFKC type (offered by FinCEN) containing sufferer data, recipient data, financial institution names, account numbers, location, SWIFT, and any further data.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>KrebsOnSecurity lately heard from a reader whose boss\u2019s electronic mail account received phished and was used to trick one of many firm\u2019s prospects into sending a big fee to scammers. An investigation into the attacker\u2019s infrastructure factors to a long-running Nigerian cybercrime ring that&#8217;s actively concentrating on established corporations within the transportation and aviation industries. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":4928,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[4274,896,4275,262,4273,1325,211,70],"class_list":["post-4926","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-aviation","tag-customers","tag-execs","tag-krebs","tag-phishers","tag-scam","tag-security","tag-target"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4926"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4926\/revisions"}],"predecessor-version":[{"id":4927,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4926\/revisions\/4927"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/4928"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4926"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4926"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-21 00:25:59 UTC -->