Hired hand: Scammers mimic Saudi manpower provider
ID: 587a3bb4-6258-5c64-8003-ecd63ed07ddc
STIX ID: report--587a3bb4-6258-5c64-8003-ecd63ed07ddc
Feed Name: Group-IB Blog
Group-IB uncovered a large-scale scam campaign (started April 2021, peaking early 2022) in which attackers impersonated a leading Saudi manpower provider using over 1,000 rogue domains, fake social media pages and ads to lure victims into phishing pages. Victims were social-engineered via ads and WhatsApp to provide personal data and make a bogus processing payment, then redirected to pages emulating 11 regional banks or a government portal where credentials and 2FA codes were harvested; attackers used the collected data to drain bank accounts. The report documents infrastructure clustering, domain-registration patterns, attacker resale of domains, and provides user and rightsholder mitigation recommendations including continuous digital risk protection and takedown processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
