phishing via dns redirection

The Venezuelan government carries out a phishing attack via CANTV against the VoluntariosXVenezuela platform and exposes registrants' data

In February 2019, the state-owned ISP CANTV (using infrastructure from Movilnet and CONATEL) manipulated DNS responses to redirect users of the opposition-backed humanitarian aid platform voluntariosxvenezuela.com to an almost identical phishing clone (voluntariovenezuela.com) that collected names, ID numbers, email addresses, and phone numbers. Days later, pro-government accounts published the personal data of those who had registered, which DFRLab cross-referenced with the CNE’s voter registry. Conservative estimates suggest there were tens of thousands of victims.

Impact details

VE sin Filtro/DFRLab documented a DNS redirect to a fake VoluntariosXVenezuela website and the subsequent publication of personal data by pro-government accounts, including national ID information cross-checked against CNE records.

namesrecordemailphone numberRegistration data for political or humanitarian volunteersDNS resolution

Classification & severity

Category
Fraud
Subtype
phishing via dns redirection
Confidence
High

Unfiltered VE and corroborating sources documented DNS manipulation and the redirection of CANTV traffic to phishing clones that collected personal data.

Severity assessment

High
Functional impact
None
Information impact
Sensitive personal data
Affected scope
Multiple users
Critical service
None
Public confidence
Moderate
Recoverability
Not recoverable

Cases of DNS-based phishing targeting civic and healthcare registration platforms have been confirmed, resulting in the exposure of sensitive personal data and posing political and security risks.

Data exfiltration· Confirmed Confidentiality

Timeline

Compromise

The malicious domain voluntariovenezuela.com is registered, and its first promotion is observed on social media.

Compromise

CANTV activated DNS response injection, redirecting users from voluntariosxvenezuela.com to the phishing clone even when they were querying external servers such as 8.8.8.8.

Disclosure

VE sin Filtro publishes an alert documenting DNS manipulation by CANTV and the collection of personal data.

Publication

Pro-government accounts begin posting lists containing the personal information of users registered on the platform.

Update

DFRLab confirms the publication of data and cross-checks the ID cards against the CNE’s voter registry (22 out of 24 match).

Evidence & sources

3 sources