CERT-AGID identified a phishing campaign that impersonates “Il Portale dell’Automobilista” through the typosquatted domain illportaledelautomobilista[.]org, which appears prominently in Google search results. The fake site steals personal and driver-license data such as codice fiscale, numero patente, and expiration date, while CERT-AGID has requested takedown actions and alerted Google and the Ministry of Infrastructure and Transport. #CERTAGID #IlPortaledellAutomobilista #MinisterodelleInfrastruttureeDeiTrasporti #illportaledelautomobilistaorg
Keypoints
- CERT-AGID discovered a new phishing campaign abusing the branding and graphics of “Il Portale dell’Automobilista”.
- The fraudulent site is hosted on illportaledelautomobilista[.]org, a typosquat using .org instead of the legitimate .it domain.
- The fake page ranks as the second Google result for the query “il portale dell’automobilista,” increasing the likelihood of victim visits.
- The malicious page closely imitates the real portal, but the “Verifica Patenti Rilasciate dal 22 al 26 Aprile 2021” form is used to collect sensitive data.
- The site asks for codice fiscale, numero patente, and patente expiration date, then displays a false “Dati non trovati” message while the data is stolen.
- Stolen information can be used for identity theft, targeted follow-up phishing, underground resale, and bypassing secondary verification checks.
- CERT-AGID shared IOCs with accredited public administrations, requested domain takedown, reported the site to Google, and informed the Ministry of Infrastructure and Transport.
MITRE Techniques
- [T1566.003 ] Phishing: Spearphishing Link – The campaign lures users to a fraudulent portal hosted on a typosquatted domain and reachable through search results. [‘the site appears as the second Google result’ and ‘the fraudulent site is hosted on illportaledelautomobilista[.]org’]
- [T1583.001 ] Acquire Infrastructure: Domains – The attackers use a lookalike domain to host the fake portal and impersonate the legitimate service. [‘a typosquat of the legitimate domain, with a change of extension: .org instead of the correct .it’]
- [T1036.005 ] Masquerading: Match Legitimate Name or Location – The page reproduces the layout, logos, and menus of the real portal to look authentic. [‘It faithfully reproduces the layout, logos and menus of the real portal’]
- [T1115 ] Clipboard Data? – Not mentioned in the article; no applicable technique identified.
- [T1056.002 ] GUI Input Capture: GUI Input Capture – The malicious form collects identity and license details entered by the victim. [‘it requires the user to enter codice fiscale, numero patente, and date of patent expiration’]
- [T1036 ] Masquerading – The page shows a legitimate-looking “data not found” message to avoid suspicion after submission. [‘it returns the message “Dati non trovati. Verifica i campi inseriti” to avoid raising alarm’]
Indicators of Compromise
- [Domain ] phishing host – illportaledelautomobilista[.]org, and legitimate reference domain .it
- [Brand/Target Name ] impersonated service – Il Portale dell’Automobilista, Ministero delle Infrastrutture e dei Trasporti
- [Form Fields ] stolen identity data – codice fiscale, numero patente, data di scadenza della patente
- [Search Engine Result ] discovery vector – Google search for “il portale dell’automobilista”