Year2017 |
MonthJune |
Reference number20170604 |
Impact areaShore |
Incident locationSouth Korea, Japan, Singapore, Philippines, Norway, the US, Egypt, Saudi Arabia, Colombia |
Incident countrySouth Korea, Japan, Singapore, Philippines, Norway, the US, Egypt, Saudi Arabia, Colombia |
Victim countrySouth Korea, Japan, Singapore, Philippines, Norway, the US, Egypt, Saudi Arabia, Colombia |
Victim identityMaritime companies that provide ship and port management services |
Victim TypeShipping Company |
MethodSpear phishing |
Attacker countryNigeria |
Maritime companies that provide ship and port management services hit by a spear-phishing attack in 2017-2018. The attackers took advantage of the industry’s lax security and the use of outdated computers. Business email compromise (BEC) and business email spoofing (BES) fraud to dupe their victims into parting with funds. The attackers are focusing on global maritime shipping businesses and their customers. Messages are crafted to appear to be legitimate employees, contacts, or other companies, are utilized to lure victims into a false sense of security. These kinds of scams will often attempt to persuade users to download malicious documents containing malware payloads or to visit malicious web pages which harvest credentials. When these credentials are stolen, threat actors can then intercept genuine business email exchanges, alter orders or financial details, and quietly reap the rewards. The threat actors use a wide range of tools after they have compromised accounts belonging to these companies. These include remote access software, keyloggers, and password stealers, many of which are available online publicly and with little investment. The threat actor utilizes tools including EmailPicky to scrape fresh victims from email contact lists, Predator Pain, PonyStealer, Agent Tesla, and HawkEye keyloggers. When it is time for payment details to be relayed to the buyer through an invoice, the threat actor intercepts the seller’s email and changes the destination bank account on the invoice to their money mule account. The attackers allegedly stole hundreds of thousands US dollars. They attempted to steal a minimum of $3.9 million U.S. dollars from maritime shipping businesses and their customers, while theft attempts average $6.7 million per year. The group behind this attack is called the Gold Galleon Group (Nigeria), consisting of 20 cybercriminals.