Hackers reportedly targeted govt’s 2-factor authentication system
By MYBRANDBOOK
A recent study by Secureonix found that threat actors were targeting the government’s email system, Kavach. It is reportedly said that this attack was similar to methods used by SideCopy, a threat actor attributed to Pakistan. Kavach is a 2-factor authentication system that was implemented last year to strengthen the government’s email infrastructure.
According to Secureonix, the first stage of the process included a phishing campaign. When a government official clicks a link in one of the phishing emails, .LNK files (attached to those emails) would execute code, resulting in the execution of a remote access trojan.
The cybersecurity firm said, “Like with many attacks we see today, the initial infection begins with a phishing email containing a compressed file attachment (11222022.zip). When opened by the user, the file contains a single shortcut file designed to trick the user into opening it. The email’s shortcut file appears to be a harmless image file from websites such as Income Tax Delhi. “The purpose of the shortcut file is to appear simply as ‘scanimg.png’ to the user, thus tempting them into thinking they are opening a harmless image file.”
This is not the first time Kavach has been targeted. Talos Intelligence discovered that SideCopy/Transparent Tribe targeted Kavach by deceiving government officials into installing malware that posed as an installer or updater for Kavach.
Talos Intelligence said, “This campaign, which has been ongoing since at least June 2021, uses fake domains mimicking legitimate government and related organizations to deliver malicious payloads, a common Transparent tribe tactic.”
Legal Battle Over IT Act Intensifies Amid Musk’s India Plans
The outcome of the legal dispute between X Corp and the Indian government c...
Wipro inks 10-year deal with Phoenix Group's ReAssure UK worth
The agreement, executed through Wipro and its 100% subsidiary,...
Centre announces that DPDP Rules nearing Finalisation by April
The government seeks to refine the rules for robust data protection, ensuri...
Home Ministry cracks down on PoS agents in digital arrest scam
Digital arrest scams are a growing cybercrime where victims are coerced or ...
ICONS OF INDIA : SUNIL VACHANI
Sunil Vachani is the Chairman of Dixon Technologies (India) Ltd. Under...
ICONS OF INDIA : SANTHOSH VISWANATHAN
Santhosh Viswanathan is the the Vice President and Managing Director f...
Icons Of India : MADHABI PURI BUCH
Madhabi Puri Buch is the first-female chairperson of India’s markets...
TCIL - Telecommunications Consultants India Limited
TCIL is a government-owned engineering and consultancy company...
IREDA - Indian Renewable Energy Development Agency Limited
IREDA is a specialized financial institution in India that facilitates...
RailTel Corporation of India Limited
RailTel is a leading telecommunications infrastructure provider in Ind...
Indian Tech Talent Excelling The Tech World - JAYASHREE ULLAL, President and CEO - Arista Network
Jayshree V. Ullal is a British-American billionaire businesswoman, ser...
Indian Tech Talent Excelling The Tech World - Satya Nadella, Chairman & CEO- Microsoft
Satya Nadella, the Chairman and CEO of Microsoft, recently emphasized ...
Indian Tech Talent Excelling The Tech World - George Kurian, CEO, Netapp
George Kurian, the CEO of global data storage and management services ...