Maritime companies that provide ship and port management services hit by a spear-phishing attack

Year

2017

Month

June

Reference number

20170604

Impact area

Shore

Incident location

South Korea, Japan, Singapore, Philippines, Norway, the US, Egypt, Saudi Arabia, Colombia

Incident country

South Korea, Japan, Singapore, Philippines, Norway, the US, Egypt, Saudi Arabia, Colombia

Victim country

South Korea, Japan, Singapore, Philippines, Norway, the US, Egypt, Saudi Arabia, Colombia

Victim identity

Maritime companies that provide ship and port management services

Victim Type

Shipping Company

Method

Spear phishing

Attacker country

Nigeria

Summary:

Maritime companies that provide ship and port management services hit by a spear-phishing attack in 2017-2018. The attackers took advantage of the industry’s lax security and the use of outdated computers. Business email compromise (BEC) and business email spoofing (BES) fraud to dupe their victims into parting with funds. The attackers are focusing on global maritime shipping businesses and their customers. Messages are crafted to appear to be legitimate employees, contacts, or other companies, are utilized to lure victims into a false sense of security. These kinds of scams will often attempt to persuade users to download malicious documents containing malware payloads or to visit malicious web pages which harvest credentials. When these credentials are stolen, threat actors can then intercept genuine business email exchanges, alter orders or financial details, and quietly reap the rewards. The threat actors use a wide range of tools after they have compromised accounts belonging to these companies. These include remote access software, keyloggers, and password stealers, many of which are available online publicly and with little investment. The threat actor utilizes tools including EmailPicky to scrape fresh victims from email contact lists, Predator Pain, PonyStealer, Agent Tesla, and HawkEye keyloggers. When it is time for payment details to be relayed to the buyer through an invoice, the threat actor intercepts the seller’s email and changes the destination bank account on the invoice to their money mule account. The attackers allegedly stole hundreds of thousands US dollars. They attempted to steal a minimum of $3.9 million U.S. dollars from maritime shipping businesses and their customers, while theft attempts average $6.7 million per year. The group behind this attack is called the Gold Galleon Group (Nigeria), consisting of 20 cybercriminals.

Reference URL

zdnet.com/article/gold-galleon-hackers-target-maritime-shipping-industry/
https://www.transnav.eu/files/A%20Retrospective%20Analysis%20of%20Maritime%20Cyber%20Security%20Incidents,1144.pdf
https://threatpost.com/gold-galleon-hacking-group-plunders-shipping-industry/131203/
https://www.secureworks.com/research/gold-galleon-how-a-nigerian-cyber-crew-plunders-the-shipping-industry https://www.legit.ng/1165719-nigerian-hackers-steal-thousands-dollars-shipping-firms-security-group-laments.html