Phishing AI Used for ARERA Damage: Uses the Theme of Water Social Bonus

Phishing AI Used for ARERA Damage: Uses the Theme of Water Social Bonus
CERT-AGID identified and disrupted a fraudulent website impersonating ARERA to trick users into revealing personal and financial data through a fake refund tied to the social water bonus. The site used typosquatting and a staged flow that led victims from a phone-number check to a bogus credit card verification page. #ARERA #CERT-AGID #bonussocialeidrico

Keypoints

  • CERT-AGID identified a fraudulent site that copied the name and logo of ARERA.
  • The scam used the social water bonus as a lure, presenting it as a real refund opportunity.
  • The first page asked users to enter their phone number to check eligibility for the benefit.
  • Victims were then shown a fake available amount of €100,93 and a practice summary.
  • The final step requested “credit card verification,” collecting cardholder name, card number, expiration date, and CVV.
  • The malicious domain was taken down, and the relevant entity was informed.
  • IOC information related to the campaign was distributed through the CERT-AGID feed to accredited organizations.

MITRE Techniques

  • [T1036 ] Masquerading – The site impersonated a trusted public authority by copying its name and logo to appear legitimate (‘the fraudulent site reproduces the name and logo of ARERA’).
  • [T1583.001 ] Acquire Infrastructure: Domains – The attack relied on a malicious domain created to host the fake ARERA pages (‘the malicious domain was shut down’).
  • [T1566.002 ] Phishing: Spearphishing Link – Users were guided through a deceptive web flow intended to capture sensitive data via a fake eligibility check and payment form (‘inviting the user to enter their phone number’, ‘verification of the credit card’).
  • [T1056 ] Input Capture – The site solicited personal and payment details directly through web forms to harvest sensitive information (‘name, card number, expiration date and CVV are the requested information’).
  • [T1621 ] Multi-Factor Authentication Request Generation – The fake verification step induced the victim to submit additional sensitive payment information under the guise of processing a payout (‘to be able to receive the amount’).

Indicators of Compromise

  • [Domains] fraudulent ARERA-lookalike site – the malicious domain used for the scam, and the related takedown notice
  • [Web Pages / URLs] fake bonus water page and credit card verification page – the homepage imitating ARERA’s bonus section, and the subsequent payment verification page
  • [Amounts] fake payout amount shown to victims – €100,93
  • [Organizations] impersonated and responding entities – ARERA, CERT-AGID


Read more: https://cert-agid.gov.it/news/phishing-ai-danni-di-arera-utilizza-il-tema-bonus-sociale-idrico/