Cybercriminals are increasingly exploiting vulnerabilities in government websites to carry out phishing campaigns, leveraging the inherent trust users place in official domains.
A recent report by Cofense Intelligence shows that how attackers are weaponizing .gov top-level domains (TLDs) across multiple countries for malicious purposes, including credential phishing, malware delivery, and command-and-control (C2) operations.
One of the primary methods used by threat actors involves exploiting open redirect vulnerabilities.
Open redirects occur when a web application improperly forwards users to external sites based on user-controlled inputs.
Cofense researchers noted that all these vulnerabilities are particularly dangerous as they allow attackers to bypass Secure Email Gateways (SEGs), which often trust government domains by default.
The diagram below illustrates the anatomy of an exploited URL used in such attacks:-
Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar
From November 2022 to November 2024, over 20 countries were affected by these campaigns. Brazil led as the most targeted country, followed by Colombia and the United States. While U.S.-based .gov domains accounted for only 9% of total abuse cases, they ranked third globally.
In addition to open redirects, some compromised government email addresses were used as C2 servers for malware like Agent Tesla Keylogger and StormKitty in mid-2023 and early 2024. While these cases were limited, they underscore the risks posed by inadequate email security.
To counter these threats, experts recommend regularly updating software platforms like Liferay to address vulnerabilities such as CVE-2024-25608.
Implementing stricter input validation helps prevent open redirects, while user awareness training ensures individuals can identify phishing attempts and scrutinize URLs.
Additionally, enhancing Secure Email Gateway (SEG) configurations by adjusting policies to scrutinize even trusted domains further strengthens security measures.
The exploitation of government websites for phishing campaigns illustrates that how even trusted digital infrastructure can be weaponized against unsuspecting users.
Collect Threat Intelligence with TI Lookup to improve your company’s security - Get 50 Free Request
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…