CERT-AGID identified a phishing campaign using the Ministry of Health’s name and branding to trick victims into revealing personal data and payment card details through a fake €278.26 refund notice. The fraudulent emails spoof the sender [email protected] and direct users to malicious pages that collect identity, contact, and card information for further abuse. #CERT-AGID #MinisteroDellaSalute #fondisanitari.gov.it
Keypoints
- The phishing campaign impersonates the Italian Ministry of Health using its name and graphics.
- Victims receive an email with the subject “Hai diritto a un rimborso” claiming a €278.26 reimbursement for a supposed double payment of a health ticket.
- The sender address [email protected] is spoofed to make the message appear to come from public administration.
- The malicious site guides victims through four steps to harvest fiscal code, date of birth, personal contact details, address, and card data.
- The payment card form requests cardholder name, card number, expiration date, CVV, and notes that 3-D Secure is required.
- Collected information can be used for unauthorized card transactions and future smishing, vishing, or banking phishing campaigns.
- CERT-AGID asked for the malicious domain to be taken down and shared IOCs with public administrations and accredited organizations.
MITRE Techniques
- [T1598.001 ] Phishing for Information: Spearphishing via Email – Used to deliver the fraudulent reimbursement message through email impersonating the Ministry of Health [’email che utilizza il nome e le grafiche del Ministero della Salute’]
- [T1036.005 ] Match Legitimate Name or Location – The sender identity and branding were made to look official by spoofing a public administration address [‘Il mittente [email protected] viene falsificato attraverso tecniche di spoofing’]
- [T1585.001 ] Establish Accounts: Social Media Accounts – Not mentioned
- [T1566.002 ] Phishing: Spearphishing Link – Victims were urged to click a button that led to a malicious website [‘cliccare su un pulsante “Conferma i tuoi dati” che lo conduce al sito malevolo’]
- [T1078 ] Valid Accounts – Not mentioned
- [T1110 ] Brute Force – Not mentioned
- [T1005 ] Data from Local System – The site collected extensive personal and payment data entered by the victim [‘inserire codice fiscale e data di nascita’; ‘nome e cognome, indirizzo email, numero di cellulare’; ‘numero della carta, data di scadenza e CVV’]
Indicators of Compromise
- [Email address ] spoofed sender used in the phishing email – [email protected]
- [URL/domain ] malicious website hosting the fraudulent refund pages – malicious domain (download available via IoC link)
- [Email subject ] lure used to entice victims – “Hai diritto a un rimborso”
- [Monetary amount ] fake reimbursement amount shown to victims – €278.26
- [Button text ] call-to-action leading to the phishing site – “Conferma i tuoi dati”
- [Card data fields ] payment data requested on the fake form – cardholder name, card number, expiration date, CVV