HeadlinesBriefing favicon HeadlinesBriefing.com

Fraud Botnet Targets Citigroup, Idaho, Build-A-Bear

Hacker News •
×

A sophisticated phone-fraud botnet has been observed targeting a diverse range of organizations, including Citigroup, the State of Idaho, and Build-A-Bear.

These entities, along with others like Lockheed Martin and the Spanish National Police, were found to be part of a coordinated attack attempting to exploit the author's VoIP server for International Revenue Share Fraud (IRSF). Attackers used the author's server to dial premium-rate international numbers, pocketing a portion of the call revenue.

The coordinated nature of the attacks suggests a single command-and-control source, as multiple compromised networks attempted to dial the same number with spoofed caller IDs simultaneously. The author emphasizes that these organizations were likely unaware victims, with infections likely stemming from individual employee actions. A free API is available at api.knock-knock.net to check if networks have been involved in similar attacks.