2017-25: Professional & Sustained Phishing Attack on Civil Liberties Activists in the States
The Electronic Frontiers Foundation
has just published a chilling description
of a determined spearphishing campaign targeting civil
liberties activists at two organisations in the US. During a one month period
over the summer the EFF logged almost 70 spearphishing attempts against
employees of internet freedom NGOs Fight for the Future
and Free Press
, all
coming from the same attackers. The campaign appears to have been aimed at stealing
credentials for various business services including Google, Dropbox
and LinkedIn
— at least one account was compromised and used to send out additional
spearphishing emails to others in the organization. Here are some extracts from the article. Take Heed (watch out)!
Other attacks involved sending clickbait headlines to try to get the targets’ interest. Some of the headlines are designed to appeal to the political interests of the targets... While others are lurid clickbait, presumably designed to embarrass the recipient into clicking a fake unsubscribe link such as … ‘Reality show mom wants to hire a hooker for her autistic son.’ The combination of headlines which would appeal to leftist activists and tabloid clickbait which is embarrassing to be found in one’s work email seems well designed to attract the attention of the targets. Each of the emails contained an ‘unsubscribe’ link which lead the user to a gmail credential phishing page such as the one above.
At one point the attackers got extremely creative, preying on anxiety about pornographic content showing up in work email. The attackers sent emails titled ‘You have been successfully subscribed to Pornhub.com’ and ‘You have been successfully subscribed to Redtube.com’ to the victims. This was followed up minutes later with several emails all disguised as coming from Pornhub or Redtube with explicit subject lines. Each of the emails contained an unsubscribe link which directed the target to a Google credential phishing page.
The sophistication of the targeting, the accuracy of the credential phishing pages, the working hours, and the persistent nature of the attacks seem to indicate that the attackers are professionals and had a budget for this campaign. The working hours, as determined by the times the emails were sent seem to indicate that the attackers are working for hire out of an office, they took Saturday and Sunday off… A login IP from the only account that was compromised successfully did not reveal the physical location of the attackers, as it belonged to AirVPN.
Although this phishing campaign does not appear to have been carried out by a nation-state actor and does not involve malware, it serves as an important reminder that civil society is under attack. It is important for all activists, including those working on digital civil liberties issues… to be aware that they may be targeted by persistent actors who are well-informed about their targets’ personal and professional connections.”










