Phishing Scam Targeting Drivers: Il Portale dell’Automobilista Ranked Among Google’s Top Results

Phishing Scam Targeting Drivers: Il Portale dell’Automobilista Ranked Among Google’s Top Results

CERT-AGID identified a phishing campaign that impersonates “Il Portale dell’Automobilista” through the typosquatted domain illportaledelautomobilista[.]org, which appears prominently in Google search results. The fake site steals personal and driver-license data such as codice fiscale, numero patente, and expiration date, while CERT-AGID has requested takedown actions and alerted Google and the Ministry of Infrastructure and Transport. #CERTAGID #IlPortaledellAutomobilista #MinisterodelleInfrastruttureeDeiTrasporti #illportaledelautomobilistaorg

Keypoints

  • CERT-AGID discovered a new phishing campaign abusing the branding and graphics of “Il Portale dell’Automobilista”.
  • The fraudulent site is hosted on illportaledelautomobilista[.]org, a typosquat using .org instead of the legitimate .it domain.
  • The fake page ranks as the second Google result for the query “il portale dell’automobilista,” increasing the likelihood of victim visits.
  • The malicious page closely imitates the real portal, but the “Verifica Patenti Rilasciate dal 22 al 26 Aprile 2021” form is used to collect sensitive data.
  • The site asks for codice fiscale, numero patente, and patente expiration date, then displays a false “Dati non trovati” message while the data is stolen.
  • Stolen information can be used for identity theft, targeted follow-up phishing, underground resale, and bypassing secondary verification checks.
  • CERT-AGID shared IOCs with accredited public administrations, requested domain takedown, reported the site to Google, and informed the Ministry of Infrastructure and Transport.

MITRE Techniques

  • [T1566.003 ] Phishing: Spearphishing Link – The campaign lures users to a fraudulent portal hosted on a typosquatted domain and reachable through search results. [‘the site appears as the second Google result’ and ‘the fraudulent site is hosted on illportaledelautomobilista[.]org’]
  • [T1583.001 ] Acquire Infrastructure: Domains – The attackers use a lookalike domain to host the fake portal and impersonate the legitimate service. [‘a typosquat of the legitimate domain, with a change of extension: .org instead of the correct .it’]
  • [T1036.005 ] Masquerading: Match Legitimate Name or Location – The page reproduces the layout, logos, and menus of the real portal to look authentic. [‘It faithfully reproduces the layout, logos and menus of the real portal’]
  • [T1115 ] Clipboard Data? – Not mentioned in the article; no applicable technique identified.
  • [T1056.002 ] GUI Input Capture: GUI Input Capture – The malicious form collects identity and license details entered by the victim. [‘it requires the user to enter codice fiscale, numero patente, and date of patent expiration’]
  • [T1036 ] Masquerading – The page shows a legitimate-looking “data not found” message to avoid suspicion after submission. [‘it returns the message “Dati non trovati. Verifica i campi inseriti” to avoid raising alarm’]

Indicators of Compromise

  • [Domain ] phishing host – illportaledelautomobilista[.]org, and legitimate reference domain .it
  • [Brand/Target Name ] impersonated service – Il Portale dell’Automobilista, Ministero delle Infrastrutture e dei Trasporti
  • [Form Fields ] stolen identity data – codice fiscale, numero patente, data di scadenza della patente
  • [Search Engine Result ] discovery vector – Google search for “il portale dell’automobilista”


Read more: https://cert-agid.gov.it/news/phishing-ai-danni-de-il-portale-dellautomobilista-indicizzato-tra-i-primi-risultati-google/