Kaspersky has identified a scam campaign exploiting the Israeli-Hamas conflict. Attackers are attempting to capitalise on people's willingness to aid those impacted by deceiving potential victims into making donations, ultimately leading to the theft of their money. To date, cybercriminals have disseminated over 500 scam emails and created fraudulent websites to expedite the money transfer process. Kaspersky urges users to remain vigilant and take proactive steps to verify the recipients of their donations.
Fake charity scams frequently occur, often exploiting real disasters or emergencies. Regrettably, the Israeli-Hamas conflict is no different. Kaspersky experts observed a surge in scam emails written in the English language, falsely seeking donations for those affected by the conflict.
Attackers use advanced social engineering techniques to exploit people's desire to help and their compassion, trying to lure potential victims into making fake donations to steal money. Scammers impersonate charitable organisations and use emotional language to entice users to click on a scam website link, where they are prompted to contribute. These deceptive emails come from various addresses.
"In these emails, scammers try to create multiple text variations to evade spam filters. For instance, they use various call-to-donate phrases like 'we call to your compassion and benevolence' or 'we call to your empathy and generosity,' and substitute words like 'help' with synonyms such as 'support,' 'aid,' etc. Besides, they alter links and sender addresses. Robust cybersecurity solutions guard against these tactics," says Andrey Kovtun, a security expert at Kaspersky.
The links used in the emails lead to a scam website. This website provides users with context about the conflict, displays photos, and encourages them to make donations. Fraudsters facilitate easy money transfers, offering options for various cryptocurrency transactions – Bitcoin, Ethereum, Tether, and Litecoin.
Using wallet addresses, Kaspersky experts discovered other fraudulent web pages, claiming to collect aid for other various groups in the conflict area.
Sadly, scam pages can swiftly multiply, altering their design and targeting diverse groups. To avoid scams, it is worth scrutinising pages thoroughly before donating. Fake sites often lack essential information about charity organisers, recipients, legitimacy documentation, or lack transparency regarding fund usage. It is worth implementing the following security measures:
Courtesy: Kaspersky, a global cybersecurity and digital privacy company founded in 1997.