Smishing on INPS: Possible A/B Testing Attempts

Smishing on INPS: Possible A/B Testing Attempts
CERT-AGID identified new smishing campaigns abusing INPS branding, logos, and graphics to steal personal data and payment card information through fake debt-payment pages. The campaigns use two distinct page designs and payment amounts, suggesting possible A/B testing, affiliate distribution, or targeted sending to different victim lists. #INPS #CERT-AGID

Keypoints

  • CERT-AGID detected new smishing campaigns impersonating INPS to trick citizens into handing over personal and payment card data.
  • The malicious links lead to fake websites that mimic the INPS “Visualizzazione indebiti” section.
  • The attack unfolds in three phases: identity entry with Codice Fiscale, fake debt visualization, and card payment data collection.
  • Two different site templates were observed, one “institutional” and one minimal, with very different requested amounts: 385.40 euro and 6.60 euro.
  • The large amount may target users with significant contributions, while the small amount may lower suspicion and increase click-through and payment rates.
  • Possible explanations include A/B testing, use of a Phishing-as-a-Service kit by multiple affiliates, or sending different SMS batches to separate victim lists.
  • CERT-AGID requested takedown of the malicious domains and shared the indicators of compromise with accredited entities.

MITRE Techniques

  • [T1566.002 ] Spearphishing Link – Victims receive SMS messages containing a malicious link that leads to the fake INPS site (‘Il link contenuto nella comunicazione iniziale conduce a un sito web…’).
  • [T1036 ] Masquerading – The site imitates the official INPS portal and uses its name, logo, and graphics to appear legitimate (‘sfruttano il nome, il logo e le grafiche di INPS’ / ‘imita la sezione “Visualizzazione indebiti” del portale ufficiale INPS’).
  • [T1071.001 ] Web Protocols – The attack relies on a web page to collect data through an online form and display a fake payment workflow (‘conduce a un sito web’ / ‘vengono richiesti tutti i dati della carta’).
  • [T1110 ] Brute Force – Not mentioned.
  • [T1584.001 ] Compromise Infrastructure – Malicious domains were used and then requested for takedown (‘ha richiesto la dismissione dei domini malevoli’).
  • [T1204.001 ] User Execution: Malicious Link – The victim is pushed to click the SMS link and interact with the fraudulent page (‘Si raccomanda… di non cliccare sul link’).
  • [T1119 ] Automated Collection – The fake form collects personal and card data entered by the victim (‘vengono richiesti… tutti i dati della carta di pagamento elettronico’).

Indicators of Compromise

  • [Domains ] Malicious phishing sites impersonating INPS and hosting the fake debt-payment pages – multiple malicious domains (takedown requested), and other N unspecified domains
  • [Branding/Impersonation Elements ] Fake INPS identity used in the campaign – INPS name, INPS logo, INPS graphics
  • [Page/Template Types ] Distinct phishing page variants observed – one rich “institutional” layout and one minimal layout
  • [Requested Payment Amounts ] Fake debt amounts shown to victims – 385.40 euro, 6.60 euro
  • [Payment Data Fields ] Information requested on the fake payment form – cardholder name, card number, expiration date, CVV, phone number
  • [Identifiers/Reference Fields ] Initial identity verification on the fake portal – Codice Fiscale, finto codice di pagamento elettronico (IN)


Read more: https://cert-agid.gov.it/news/smishing-a-tema-inps-possibili-tentativi-di-a-b-testing/