Published June 4, 2023 | Version v2

OSINT and user search trend monitoring techniques enabling potential espionage and credential access against both military and citizen users during technological modernization periods

Authors/Creators

Description

This paper presents a comprehensive analysis of a sophisticated malicious campaign that strategically capitalized on heightened user interest in accessing the webmail service portal of the Italian Air Force. The campaign's origin and execution demonstrate a high level of planning and technical proficiency by threat actors seeking to exploit the trust and reliance placed on official government services.

Using Google Trends data, a substantial surge in search queries related to the Italian Air Force webmail service was observed during a specific period. The paper explores a range of potential causes for this surge, including accessibility issues, convenience factors, technical challenges, and updates or changes to the email service. However, the most plausible explanation is the adoption of a new webmail technology as officially announced by the Italian Air Force.

Further investigation revealed the presence of malicious websites closely mimicking the legitimate webmail portal. These websites employed sophisticated techniques to deceive users, including imitating the Fully Qualified Domain Name (FQDN) of the genuine service and utilizing portions of words related to the Italian Air Force identity. By visually imitating the legitimate portal and adopting OpenGraph properties, the malicious websites aimed to create an illusion of legitimacy and gain users' trust.

An examination of the HTML source code of the malicious website highlighted numerous references to the legitimate FQDN, reinforcing the intent to deceive users and evade detection. Additionally, the presence of an active advertising campaign with an abnormally high cost per click suggested an effective malvertising strategy, further enhancing the campaign's reach and potential impact.

The paper also explores the techniques employed by the malicious websites to compromise user security and privacy. Attempts to install malicious browser extensions on browsers, coupled with information gathering through telemetry and tracking scripts, demonstrate a multi-faceted approach. The malicious extensions targeted victims' browsing history, search engine preferences, and even acquired hardware information, potentially for reconnaissance purposes. Moreover, the paper discusses the presence of credential access tactics, as the malicious websites partially mimicked the appearance of the legitimate authentication portal. By capturing user credentials through deceptive login pages and transmitting them to a malicious collection infrastructure, the threat actors aimed to gain unauthorized access to users' accounts.

The potential impact of this malicious campaign on the large user base of the Italian Air Force, which includes non-digital native individuals, is a cause for concern.

Files