Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/6/2019
04:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

How Attackers Used Look-Alike Domains to Steal $1 Million From a Chinese VC

Money meant to fund an Israeli startup wound up directly deposited to the scammers.

Some cyberattacks involve extremely sophisticated tools and cutting-edge exploits. Others, not so much.

A case in point is an incident involving a Chinese venture capital firm and an Israeli startup that it had agreed to fund. Nearly all it took for scammers to walk away with a cool $1 million in cash — meant for the startup from the investment firm — was two Web domains and 32 emails.

Check Point Software, which investigated the scam on behalf of the Israeli firm, this week described the incident as starting with a compromise of the Israeli startup's email server. A few months before the transaction was scheduled to happen, the attackers noticed an email thread containing information about a multimillion-dollar seeding fund from the Chinese VC.

Rather than simply monitoring the thread and having emails forwarded to them, the attackers registered two domains. One of the domains was a look-alike of the Chinese investment company's domain; the other was a spoof of the Israeli firm's domain. In both instances, the threat actors simply added an "s" to the end of the original domain name.

The next phase of the scam involved the attackers sending two emails with the same subject header as the original email thread about the planned seed funding.

The attackers used the Israeli firm's look-alike domain to send an email to the Chinese VC firm that appeared to be from the startup's CEO. They also used the Chinese firm's look-alike domain to send an email to the Israeli company that purported to be from the email account of the manager in charge of the transaction at the investment firm.

"This infrastructure gave the attacker the ability to conduct the ultimate Man-In-The-Middle (MITM) attack," Check Point said in a blog describing the incident.

Thus, all email communication that both sides carried out in response to those two initial emails were being sent directly to the attackers first. The threat actors would review each email, make whatever changes they felt they needed to make, and then forward the messages from the look-alike domains to the original destination.

In total, the attacker sent 14 emails to the Israeli side and 18 to the Chinese VC firm using the look-alike domains. Over the course of these communications, the attackers managed to change the bank account information for the VC firm and replace it with their own, so any money that the VC firm sent to the Israeli firm would end up with the attackers instead.

Brazen Scam
According to Check Point, the attackers were so brazen they even managed to cancel a scheduled meeting in Shanghai between the CEO of the Israeli company and the Chinese VC firm. They basically sent emails with different excuses to both sides using the rogue domains. The goal in thwarting the meeting apparently was to minimize the risk of the bank account number switch being discovered.

"This operation was unique because the threat actor successfully spoofed both sides of the transaction and was able to disrupt physical meetings between the parties involved," says Tim Otis, team leader, incident response operations at Check Point.

Such scams highlight the need for organizations to have a capability in place to scan for look-alike domains, Otis says. They also show why secondary protection mechanisms — like verbal confirmation — are necessary when making high-value transactions, he says.

Look-alike domains have become an increasingly popular tactic among online scammers and those seeking to pull off impersonation schemes. In many cases, attackers set up look-alike domains for well-known brands and use the domains to try and trick users into sharing passwords, payment card info, and other sensitive data. The trend is especially noticeable during the holiday shopping season.

Security vendor Venafi recently looked into the explosion of such sites and discovered over 100,000 lookalike domains for just the top 20 retailers in the US, UK, France, Germany, and Australia.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "10 Security 'Chestnuts' We Should Roast Over the Open Fire."

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
AshiSalami
50%
50%
AshiSalami,
User Rank: Apprentice
2/23/2020 | 3:49:28 PM
Re: Domain spoofing
Great post, also am very appreciative of the anti-spam measures that are being taken on this site. Donald

 
casun_darkread
50%
50%
casun_darkread,
User Rank: Author
12/16/2019 | 12:04:01 PM
Domain spoofing
The amount of typosquatting and domain spoofing attacks used nowadays to trick users is alarming. Organizations should be closely monitoring any Domain and Certificate registrations that are a close match to the real domain. 
joshuaprice153
50%
50%
joshuaprice153,
User Rank: Apprentice
12/10/2019 | 11:08:51 PM
How Attackers Used Look-Alike Domains
Your way of putting things together is admirable. Unfortunately, Im still quite in the dark about all of this so I'll probably come back when I can contribute a more decent comment. kitchen remodeling Orlando
 
RyanWeeks
50%
50%
RyanWeeks,
User Rank: Author
12/10/2019 | 3:09:47 PM
Takedown Services
Thanks for sharing! A seasoned look alike domain takedown service is a must have in a secops and threat management programs these days. Even with the best SPF, DKIM and DMARC and Anti-Spoofing policies in place a well baked look-alike domain has the potential, when weaponized, to open an organization up to damaging phishing attacks. Definately a key capability to invest in.
attrapereves
50%
50%
attrapereves,
User Rank: Apprentice
12/8/2019 | 9:46:53 AM
Re: Pending Review
Great post, good job!
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15208
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension of the first tensor, malicious attackers can ...
CVE-2020-15209
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one....
CVE-2020-15210
PUBLISHED: 2020-09-25
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and ...
CVE-2020-15211
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices f...
CVE-2020-15212
PUBLISHED: 2020-09-25
In TensorFlow Lite before versions 2.2.1 and 2.3.1, models using segment sum can trigger writes outside of bounds of heap allocated buffers by inserting negative elements in the segment ids tensor. Users having access to `segment_ids_data` can alter `output_index` and then write to outside of `outpu...