{"id":18881,"date":"2022-04-28T07:10:53","date_gmt":"2022-04-28T15:10:53","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/04\/28\/news-12614\/"},"modified":"2022-04-28T07:10:53","modified_gmt":"2022-04-28T15:10:53","slug":"news-12614","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/04\/28\/news-12614\/","title":{"rendered":"Fake USA for UNHCR site wants your Ukraine donations in Bitcoin"},"content":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Thu, 28 Apr 2022 14:35:53 +0000<\/strong><\/p>\n<p>Since Russia began invading Ukraine in late February, many organizations have set up donation pages to aid the most heavily affected: Families who were forced out of their homes due to bombings and children separated from grown-ups who decided to stay and take arms.<\/p>\n<p>We&#8217;ve also seen a considerable amount of scams preying on those who want to bring help to the helpless. During these times of struggle, donation and phishing scams abound, too.<\/p>\n<h2>There&#8217;s a spam campaign encouraging you to donate to or support Ukraine<\/h2>\n<p>Our email honeypot snagged dozens of samples belonging to a campaign that spoofed an email that receivers were meant to believe came from the United Nations or United Humanitarian.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"55882\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/fake-usa-for-unhcr-site-wants-your-ukraine-donations-in-bitcoin\/attachment\/spam-mail-2\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/spam-mail.png\" data-orig-size=\"472,251\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"spam-mail\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/spam-mail-300x160.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/spam-mail.png\" width=\"472\" height=\"251\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/spam-mail.png\" alt=\"\" class=\"wp-image-55882\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/spam-mail.png 472w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/spam-mail-300x160.png 300w\" sizes=\"auto, (max-width: 472px) 100vw, 472px\" \/><\/figure>\n<p>Our Threat Intelligence Team took a closer look and found that the actual senders are work email addresses of individuals linked to legitimate services in Bangladesh. The emails appeared to be compromised.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55901\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/fake-usa-for-unhcr-site-wants-your-ukraine-donations-in-bitcoin\/attachment\/ukraine-dono-spam\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/ukraine-dono-spam.png\" data-orig-size=\"980,465\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"ukraine-dono-spam\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/ukraine-dono-spam-300x142.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/ukraine-dono-spam-600x285.png\" loading=\"lazy\" width=\"600\" height=\"285\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/ukraine-dono-spam-600x285.png\" alt=\"\" class=\"wp-image-55901\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/ukraine-dono-spam-600x285.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/ukraine-dono-spam-300x142.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/ukraine-dono-spam.png 980w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure>\n<\/div>\n<pre class=\"wp-block-code\"><code>Hello  We stand with our friends and colleagues in Ukraine during this heinous assault on their freedom, their independence and their lives. We are actively supporting our resilient team and are doing what we can to insure their safety, click on the Link to see more updates or photos and videos of the invasions from Russian. Donate and Support Ukrainian now to save lives.  Visit: {redacted URL}        {redacted URL}  Thanks for your support. Regards UNITED HUMANITARIAN<\/code><\/pre>\n<p>Clicking the links in the email body, or copying and pasting them to your browser, opens this legitimate looking website:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55837\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/fake-usa-for-unhcr-site-wants-your-ukraine-donations-in-bitcoin\/attachment\/01-ukphish\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-ukphish.png\" data-orig-size=\"982,968\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"01-ukphish\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-ukphish-300x296.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-ukphish-600x591.png\" loading=\"lazy\" width=\"600\" height=\"591\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-ukphish-600x591.png\" alt=\"\" class=\"wp-image-55837\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-ukphish-600x591.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-ukphish-300x296.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-ukphish.png 982w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure>\n<\/div>\n<p>We inspected the URL using a domain registrant and found it was created on April 19 2022, two days before we started receiving the spam emails. <\/p>\n<h2>Be extra vigilant with &#8220;mirrored&#8221; sites<\/h2>\n<p>The scam page looks slick, professional, and not what you may expect from a bogus donation portal. There\u2019s a good reason for this. The entire site has been copied&nbsp;from <code><i>unrefugees.org<\/i><\/code> using HTTrack, a free website copier.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" data-attachment-id=\"55836\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/fake-usa-for-unhcr-site-wants-your-ukraine-donations-in-bitcoin\/attachment\/00-ukphish\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/00-ukphish.png\" data-orig-size=\"554,112\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"00-ukphish\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/00-ukphish-300x61.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/00-ukphish.png\" loading=\"lazy\" width=\"554\" height=\"112\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/00-ukphish.png\" alt=\"\" class=\"wp-image-55836\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/00-ukphish.png 554w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/00-ukphish-300x61.png 300w\" sizes=\"auto, (max-width: 554px) 100vw, 554px\" \/><figcaption><em>This is inside the code of the fake refugee website helping Ukraine families flee. Website copiers can make a fake site a spitting image of its original counterpart.<\/em><\/figcaption><\/figure>\n<\/div>\n<p><code><i>Unrefugees.org<\/i><\/code> is the USA for UNHCR (United Nations High Commissioner for Refugees). It is a Washington-based, not-for-profit organization whose mission is to provide food, shelter, and medical care to those fleeing their homes due to conflict, persecution, or violence.<\/p>\n<p>While the fake site mirrors the legitimate site perfectly, it has one major exception:&nbsp;They switched out the genuine donation page for one of their own. The real site allows you to donate monthly via credit card, Google Pay, or PayPal. Donations made to the fake site, however, are made through Bitcoin.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55838\" data-permalink=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/fake-usa-for-unhcr-site-wants-your-ukraine-donations-in-bitcoin\/attachment\/02-ukphish\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-ukphish.png\" data-orig-size=\"1058,777\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"02-ukphish\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-ukphish-300x220.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-ukphish-600x441.png\" loading=\"lazy\" width=\"600\" height=\"441\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-ukphish-600x441.png\" alt=\"\" class=\"wp-image-55838\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-ukphish-600x441.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-ukphish-300x220.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-ukphish.png 1058w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption><em>This is the form donors would have to fill in.<\/em><\/figcaption><\/figure>\n<\/div>\n<p>We checked multiple sources for information on the Bitcoin address provided. It doesn\u2019t appear in scam databases or fraud reports and has neither sent nor received funds. This, combined with the site now failing to resolve, hopefully means the scammers got nowhere with their phishing attempt.<\/p>\n<h2>How to tell if a donation site is what it says it is<\/h2>\n<p>It&#8217;s very difficult to know at a glance which sites are real. This is especially true where donations are concerned. However, there are tools available to check.<\/p>\n<p>You can check for registered charities online in most cases, and <u><a href=\"https:\/\/give.org\/charity-reviews\/national\/Human-Services\/United-States-Association-for-UNHCR-in-Washington-dc-1998\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">the genuine site is listed here<\/a><\/u>\u00a0against the BBB (Better Business Bureau) record. You can find <u><a href=\"https:\/\/www.gov.uk\/find-charity-information\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">similar types of checks<\/a><\/u>\u00a0in other countries.<\/p>\n<p>There are very good reasons for making speedy donations. Even so, taking the time to ensure the site you\u2019re donating to is the real deal is the best course of action for both you and the people you\u2019ll be helping.<\/p>\n<p>Stay safe out there!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/fake-usa-for-unhcr-site-wants-your-ukraine-donations-in-bitcoin\/\">Fake USA for UNHCR site wants your Ukraine donations in Bitcoin<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/fake-usa-for-unhcr-site-wants-your-ukraine-donations-in-bitcoin\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Thu, 28 Apr 2022 14:35:53 +0000<\/strong><\/p>\n<p>Scammers are disguising their phishing page as a donation hub for Ukrainian refugees.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/social-engineering\/2022\/04\/fake-usa-for-unhcr-site-wants-your-ukraine-donations-in-bitcoin\/\">Fake USA for UNHCR site wants your Ukraine donations in Bitcoin<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[24851,20395,10490,14748,25865,3924,10510,25866,25867,25868],"class_list":["post-18881","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-bbb","tag-better-business-bureau","tag-bitcoin","tag-donation-scam","tag-fake-unhcr-site","tag-phishing","tag-social-engineering","tag-unhcr","tag-united-nations-high-commissioner-for-refugees","tag-usa-for-unhcr"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18881","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18881"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18881\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18881"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18881"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18881"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}