Phishing attacks in name of Aarogya Setu app increasing: Cyber agency

Image
Press Trust of India New Delhi
Last Updated : May 16 2020 | 6:02 PM IST

Phishing attacks in the name of Aarogya Setu mobile application are witnessing a "high rise" as online scamsters are taking advantage of the increased inquisitiveness of internet users during the COVID-19 pandemic, India's cyber security agency said on Saturday.

It said attackers are also impersonating tools linked to the World Health Organisation and popular video-conferencing platforms like Zoom to steal sensitive data.

"Aarogya Setu app-focused phishing have seen high rise. Scammers impersonate as HR department, CEO, or any other known person and target users by spreading messages like 'your neighbour is affected', 'see who all are affected', 'someone who came in contact with you tested positive', 'recommendations to self-isolate', 'guidelines to use Aarogya Setu' among others," the CERT-In said in a latest advisory accessed by PTI.

The Aarogya Setu application uses bluetooth and GPS to alert users who may have encountered people who later tested positive for the coronavirus.

Phishing denotes to the cyber term of luring and cheating an internet user through a fake SMS or email and thereby breaching their privacy to steal sensitive information.

"In recent trends, threat actors are taking advantage of pandemic situation to trick the users to give up their sensitive information by taking advantage of the interest associated with recent novel coronavirus activities, news, and information," the advisory said.

The Computer Emergency Response Team of India (CERT-In) is the national technology arm to combat cyber attacks and guarding of the Indian cyber space.

It said cyber attackers (threat actors) impersonate popular video platforms like Zoom, Google Meet, Microsoft Teams, Aarogya Setu app and WHO to send phishing messages through SMS (smishing), WhatsApp (whishing) or phishing emails to steal identities and engage in other nefarious activities during the COVID-19 pandemic.

The cyber attackers, it said, are using fake domains to impersonate popular apps to first lure the victims and then send them links such as "relief package", "safety tips during corona", "corona testing kit", "corona vaccine", "payment and donation during corona".

It said the name of the WHO was also being impersonated.

"Cyber criminals are sending phishing emails impersonating WHO and e-mails appear to be originating from the domain of WHO. Such e-mails may contain malicious file and URLs (universal resource locators)," it said.

The cyber agency suggested come counter-measures to check this online menace:

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: May 16 2020 | 6:02 PM IST

Next Story