New type of hoax messages takes advantage of war in Ukraine

11.03.2022 | 08:18

The State Information System Agency (RIA) warns against hoaxes exploiting Russia's war against Ukraine.

Hoax e-mails about the war are being used to try to collect people’s data and spread malware. The criminals also pose as charities and ask unsuspecting people to make donations in cryptocurrencies. Cyberspace is never quiet and cyber-attacks, or attempts at cyber-attacks, happen all the time, but Russia’s war in Ukraine has raised the level of such threats and they must be taken seriously.

For example, cybercriminals and national cyber groups send e-mails about the war with attachments containing a zip file with a virus. “An e-mail with such malware was received by the employees of a state agency, who reported it to the RIA,” said Tõnu Tammer, Executive Director of CERT-EE at RIA. “The e-mail attempted to mimic an international organisation based in the Czech Republic, of which the Estonian agency that received the e-mail is a member. The e-mail with the suspicious attachment was not opened and was sent to CERT-EE for analysis.

Criminals are also pretending to be charities that collect donations in order to get people’s money. “Last week, we received a report that e-mails mimicking the head of the Polish branch of UNICEF were circulating. The subject line of the messages was ‘URGENT: Children in Ukraine need help’. The e-mail, which exploited UNICEF messages, outlined how people can donate cryptocurrency (Bitcoin and Ethereum) to help Ukrainian children. These donations actually went to criminals,” added Tammer.

The RIA is not aware of any Estonian people falling victim to this fraud. “However, we may never find out about this: a bona fide donor thought they made a transfer to people in need, not to people committing financial fraud,” said the head of CERT-EE.

Other e-mails that are being spread at present are aimed at collecting people’s data. The RIA noticed e-mails that asked the recipients whose side they were on in the war. Another message offered cheap transport to Belarus and Russia. These absurd e-mails are an attempt to collect people’s data, only to abuse the information in other ways later.

If people enter their password on the fake page, it is very likely that attempts will be made to take over their accounts. If the same password is used everywhere, entering your password on a phishing site can give an attacker access not only to your personal e-mail account, but also to the institutions you are connected to, such as your work e-mail and school e-mail. A visible consequence occurs when your or your employer’s account shares false information and war propaganda. The unseen consequence, however, may be that you give the attacker easy access to your workplace’s systems.

It should not be assumed that only IT and cyber security experts can or should be able to deal with cyber threats.

SEIKO KUIK

Press Officer

open graph imagesearch block image