Indian cyber-security agencies have detected a phishing fraud that “mimics” the official website of the Ministry of Defence to “harvest” the log-in credentials of officials to “steal” sensitive Government documents. An advisory issued this week by the National Informatics Centre (NIC) has identified two phishing links -mod.Gov.In.Aboutcase.Nl/publications.Html and mod.Gov.In.Army.Aboutcase.Nl/publications.Html.
“The communication says both the URLs seek NIC-provided log-in credentials of Government officials through a fake e-mail that comes attached with a “fake” document titled “Hackers Targeted Defence Personnel in Mass Cyber Attack”.
“Once individual credentials like log-in IDs and passwords are punched, the links re-direct the users to a “login-error.Html” page.
“”Both the phishing URLs have mirrored the original MoD website (www.Mod.Gov.In) to lure end users into believing they are legitimate MoD websites,” the communication says.
“The two links are “mimicking” the Department of Defence under the Ministry of Defence and the phishing campaign is primarily aimed at harvesting the NIC credentials of Government officials to steal sensitive documents pertaining to the Indian Government, the communication says.
The NIC serves as the backbone of Internet-based Government communication.
“A phishing attack is defined as the fraudulent practice of impersonating reputed and official names and identities through e-mails, text messages or phone calls to trick the victims into sharing sensitive personal information like banking and credit card details and login or identity information.