False reimbursement of TARI used in new phishing campaigns targeting PagoPA

False reimbursement of TARI used in new phishing campaigns targeting PagoPA
CERT-AGID identified fraudulent sites impersonating PagoPA to steal personal data and payment card information by offering a fake TARI overpayment refund. The campaign used a staged online form to collect identity details, contact information, and card data for potential fraud and future phishing operations. #PagoPA #CERT-AGID #TARI

Keypoints

  • CERT-AGID detected malicious websites abusing the PagoPA name, logo, and graphics.
  • The fake pages lured victims with a supposed TARI refund for an alleged overpayment.
  • Users were prompted to enter identity verification data such as fiscal code or ID card number.
  • The campaign then collected extensive personal details, including address, phone number, and email.
  • In the final step, victims were asked for payment card details, including card number, expiry date, and CVV.
  • The stolen data could support fraudulent card transactions and future targeted phishing campaigns.
  • CERT-AGID began takedown actions against the malicious domains and shared the IOCs with accredited organizations.

MITRE Techniques

  • [T1583.001 ] Acquire Infrastructure: Domains – The attackers used malicious domains to host the fraudulent PagoPA-themed pages (‘i siti malevoli individuati’).
  • [T1583.006 ] Acquire Infrastructure: Web Services – The campaign relied on web-hosted phishing pages to collect victim data (‘seguire una procedura online’).
  • [T1566.002 ] Phishing: Spearphishing Link – Victims were directed to click through a fake refund workflow to submit data (‘Continua con la richiesta’).
  • [T1036 ] Masquerading – The sites impersonated PagoPA using its name, logo, and graphics to appear legitimate (‘utilizzano nome, logo e grafica di PagoPA’).
  • [T1110 ] Brute Force – No evidence in article.
  • [T1005 ] Data from Local System – The attackers requested identity and payment information from users (‘inserimento del codice fiscale’, ‘numero della carta di identità’).
  • [T1539 ] Steal Web Session Cookie – No evidence in article.

Indicators of Compromise

  • [Domains ] malicious pages impersonating PagoPA for fake TARI refunds – several fraudulent domains, and other N items (if applicable)
  • [URLs ] campaign landing pages and refund workflow pages – homepage of the malicious site, details page, and other N items (if applicable)
  • [Organization names ] impersonated and targeted entities – PagoPA, CERT-AGID, and other N items (if applicable)
  • [File names ] published IoC package – Download IoC


Read more: https://cert-agid.gov.it/news/falso-rimborso-tari-sfruttato-nelle-nuove-campagne-di-phishing-ai-danni-di-pagopa/