Beware very neat phishing scam by eGov-KYC

In the last few days, a very sophisticated scam targeting Greek users has been circulating on the internet. The email is supposed to come from eGov-KYC or Introduce Yourself – Know Your (eGov-KYC)

screenshot 2023 07 19 19 33 43

All the email states

screenshot 2023 07 19 19 36 25

The government "Introduce yourself" (KYC- Know Your Customer) according to the official website, (https://www.gov.gr/upourgeia/upourgeio-psephiakes-diakuberneses/psephiakes-diakuberneses/kyc) offers a digital alternative to presenting your documents to your bank, to confirm your details within the Anti Money Laundering (AML) regulation.

The service draws on your behalf:

a) Identity information
b) Contact details
c) Income details
d) Details of professional activity

The data is drawn from the Government's primary information systems and is not stored in eGov KYC. Their provision always requires your express consent.

Access to the service is possible from your bank's Web Banking.

But the phishing link (https://gov.kyc-update.xyz/gr/) displays the following web

screenshot 2023 07 19 19 07 50

If you now go ahead and click on "Contact Service Provider" a new page opens (https://gov.kyc-update.xyz/gr/bank.php) which contains the names and links for many Greek (and not only) Banks.

screenshot 2023 07 19 19 11 40

screenshot 2023 07 19 19 12 07

With each click on the above links, a specially configured page is opened which is supposed to be in the bank mentioned. Let's look at the national team

 

screenshot 2023 07 19 19 15 22

If you notice the links they all start from one (gov) of kyc-update.xyz.

A whois of kyc-update.xyz shows us that the attackers are hidden behind Cloudflare proxy nameservers.

Name Server: RAINA.NS.CLOUDFLARE.COM
Name Server: HARLEY.NS.CLOUDFLARE.COM

Anyway, right now the scam is running normally and collecting , from users who don't check the links in their emails.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.
phishing, eGov-KYC

Written by newsbot

Although the press releases will be from very select to rarely, I said to go ... because sometimes the authors are hiding.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).