phishing via dns redirection

Maduro’s government carries out a phishing attack via CANTV against the Héroes de la Salud platform

Between late March and late April 2020, in the midst of the COVID-19 pandemic, the opposition platform Héroes de la Salud (heroesdesaludve.info)—created by Juan Guaidó’s interim government to provide financial aid to healthcare workers—was the target of a state-sponsored phishing campaign. CANTV, the main state-owned internet provider, manipulated DNS responses to redirect its users from the legitimate site to a malicious clone (heroesdesaludve.co) that captured national ID numbers, addresses, email addresses, places of work, and job titles, as well as images of official documents. The case was documented by VEsinfiltro, Efecto Cocuyo, and Freedom House.

Impact details

VE sin Filtro documented a DNS redirect from CANTV to a cloned “Heroes de la Salud” website designed for phishing, which collected confidential registration data from healthcare workers during the COVID-19 pandemic.

recordhome addressemailworkplacepositionimages of official documents

Classification & severity

Category
Fraud
Subtype
phishing via dns redirection
Confidence
High

Unfiltered VE and corroborating sources documented DNS manipulation and the redirection of CANTV traffic to phishing clones that collected personal data.

Severity assessment

High
Functional impact
None
Information impact
Sensitive personal data
Affected scope
Multiple users
Critical service
Potential
Public confidence
Moderate
Recoverability
Not recoverable

Cases of DNS-based phishing targeting civic and healthcare registration platforms have been confirmed, resulting in the exposure of sensitive personal data and posing political and security risks.

Data exfiltration· Confirmed Confidentiality

Timeline

Discovery

VEsinfiltro identifies a phishing campaign targeting users of the healthcare worker registration platform.

Compromise

CANTV's DNS begins redirecting traffic from heroesdesaludve.info to the malicious clone heroesdesaludve.co.

Publication

VEsinfiltro publishes its preliminary report, and Efecto Cocuyo reports on the attack.

Update

An alternative domain (saludvzla.com) has also been compromised.

Evidence & sources

3 sources