A new sort of phishing assault employing the ngrok platform has been spotted targeting Indian banking customers.
Scammers are utilising an unique phishing attack to gather sensitive information such as internet banking credentials, mobile number, and OTP from banking customers in India in order to carry out fraudulent transactions, according to the country’s cyber security agency’s latest advisory.
According to the advisory, the malicious activity is carried out through the ngrok platform, a one-of-a-kind web application.
According to the advisory issued by CERT-In on Tuesday, “It has been observed that Indian banking customers are being targeted by a new type of phishing attack using ngrok platform.”
“The malicious actors have abused the ngrok platform to host phishing websites impersonating internet banking portals of Indian banks,”
The Indian Computer Emergency Response Team, or CERT-In, is the government’s technical arm for combating cyber attacks and protecting the cyber space from phishing, hacking, and other online attacks.
Phishing is a type of fraud in which an attacker poses as a trustworthy entity and convinces a victim to click on malicious links in order to steal passwords, login credentials, and One-Time Passwords (OTP).
According to the advisory, “malicious actors” are stealing sensitive information from users such as online banking passwords, mobile number, and OTP to make “fraudulent transactions” through these phishing websites.
The advisory stated that the phishing attempts have been seen to be triggered via SMSes having web links that end in ngrok.io/xxxbank.
The advisory outlined this with the help of a sample SMS.
“Dear customer your xxx bank account will be suspended! Please Re KYC Verification Update click here link http://446bdf227fc4.ngrok.io/xxxbank”.
When a victim clicks on this URL and logs in to the phishing website with their internet banking credentials, the attacker creates an OTP for two factor authentication, which is sent to the victim’s phone number.
The advisory said “The victim then enters this OTP in the phishing site, which the attacker captures,”
Finally, the attacker uses the OTP to obtain access to the victim’s account and conduct fraudulent transactions.
The cyber security agency has proposed various “best practises” for preventing these attacks, the most essential of which is: “Look for suspicious numbers that don’t look like real mobile phone numbers as scammers often mask their identity by using email-to-text services to avoid revealing their actual phone number.”
“Genuine SMSes received from banks usually contain sender id (consisting of bank’s short name) instead of a phone number in sender information field.”
The advisory further suggested online banking users to “only click on URLs that clearly indicate the website domain.”
It said “When in doubt, users can search for the organisation’s website directly using search engines to ensure that the websites they visited are legitimate,”
The specific safeguard against such attacks is “exercising caution towards shortened URLs, such as those involving bit.ly and tinyurl.”
It said “Users are advised to hover their cursors over the shortened URLs (if possible) to see the full website domain which they are visiting or use a URL checker that will allow the user to enter a short URL and view the full URL,”
The advisory stated that the shortening service preview feature can also be used to obtain a preview of the full URL.
The advisory noted that online banking customers should pay “particular attention to any mis-spelling and/or substitution of letters in the URLs of the websites they are browsing.”
Other counter-measures mentioned in the advisory include the frequently-repeated principles for safe browsing on the internet.
“Install and maintain updated anti-virus and anti-spyware software, filtering tools (anti-virus and content-based filtering), firewall, and filtering services.”
It stated that spam filters should be updated with the most recent spam mail contents.
“Customers should report any unusual activity in their account immediately to the respective bank,” it said.
The advisory concluded “Phishing websites and suspicious messages should be reported to the CERT-In at incident@cert-in.org.in and respective banks with the relevant details for taking further appropriate actions,”
