DIRECTORY

  • Alerts
  • APTs
  • Blog
  • Books
  • Certifications
  • Cheat Sheets
  • Courses
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Definitions
  • Domains
  • Entertainment
  • FAQ
  • Frameworks
  • Hardware Tools
  • Incidents
  • Malware
  • News
  • Papers
  • Podcasts
  • Quotes
  • Reports
  • Tools
  • Threats
  • Tutorials
No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Get Help
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
Get Help
CyberMaterial
Home Alerts

Digital Smoke: Fraud Network Uncovered

February 28, 2023
Reading Time: 2 mins read
in Alerts

 

A cybersecurity firm called Resecurity has discovered a large investment fraud network known as “Digital Smoke”. The group of bad actors have set up a massive infrastructure to impersonate popular Fortune 100 corporations in order to defraud consumers in regions such as Australia, Canada, China, Colombia, the European Union, India, Singapore, Malaysia, United Arab Emirates, Saudi Arabia, Mexico, and the US.

They use high-demand investment areas such as financial services, oil & gas, renewable energy, EV batteries, electric vehicles, healthcare, semiconductors, and world-recognized investment corporations and funds with a global presence.

The bad actors create fake domain names with similar brand spelling and promote them on social media and instant messenger apps to attract investors.

The group is known for its focus on oil markets and renewable energy products, a unique aspect of their campaign, and has impersonated multinational providers of drilling and major oil corporations such as Shell, Glencore, Ovintiv, Lukoil and others.

scams offer victims the opportunity to invest in new oil fields, construction of petroleum stations, and technologies related to the renewable energy sector. Digital Smoke has also targeted state-owned organizations, including the India Brand Equity Foundation, a Trust established by the Government of India, and copied the profile of the Minister of State for Foreign Trade in the United Arab Emirates to defraud users.

Investment fraud causes serious damage to investors beyond monetary losses, including health, marital, and trust problems resulting from financial scams, according to a FINRA survey. Businesses also experience significant damage in customer loyalty and brand reputation, negatively affecting sales and market profile.

The FTC reported that people reported losing $8.8 billion to scams in 2022 alone, with investment fraud, including ponzi and pyramid schemes, exceeding $5.8 billion in the US and over $77 billion worldwide. The Digital Smoke group used thousands of related domains for “cloaking” (Black SEO), hidden redirects, and short URLs for the protection of the payment gateway used to collect payments from victims, leveraging AliPay (China) and Unified Payments Interface (UPI) along with cryptocurrencies.

The Digital Smoke case highlights how investment scams have become more sophisticated than before. Fraudsters are investing large amounts of time and effort to prepare high-quality resources which look almost identical to their well-known investment product counterparts.

For each investment scam they ran, they also created a separate mobile app with a unique design. The bad actors registered multiple fake domain names, which had similar brand spelling, and asked victims to make a deposit by sending payment to an account registered in India.

The information about Digital Smoke, along with the identities of key actors, has been shared with the Indian Cybercrime Coordination Center and the US Law Enforcement, and many of the scam projects have been terminated.

Read More

Tags: AlertsAlerts 2023Digital SmokeFake WebsitesFebruary 2023PhishingResecurityScamTyposquatting
0
VIEWS
ADVERTISEMENT

Related Posts

TOR installers target crypto users

TOR installers target crypto users

March 29, 2023
ABB Security Advisory: RCCMD Vulnerability

ABB Security Advisory: RCCMD Vulnerability

March 29, 2023
Flaw in WiFi protocol allows plaintext leak

Flaw in WiFi protocol allows plaintext leak

March 29, 2023
Europol warns about AI abuse

Europol warns about AI abuse

March 29, 2023

More Articles

Incidents

Entity Will Pay $4.3 Million Settlement in 2nd Big Hack Case

January 27, 2023
Alerts

Red Hat security advisory (AV22-090)

February 22, 2022
Cyber101

Personally Identifiable Information (PII)

March 10, 2021
Alerts

New Advanced Android Malware Posing as “System Update”

April 6, 2021

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
  • Report Cyber Incident
  • GET HELP

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.