Fake Government Contracts from Cloned Department of Labor Site Hawks
A new phishing attempt is targeting prospective government vendors, posing as the US Department of Labor and inviting them to bid on several false governmental projects.
According to a recent analysis from threat researchers at INKY, emails posing as official communications from the Department of Labor contain malicious URLs that, rather than going to a government procurement portal, gather the credentials of anybody who attempts to login.
"The bulk of phishing attempts in this campaign had sender email addresses faked to seem like they originated from no-reply@dol[.]gov, which is the genuine DoL site," the INKY team said in a study released on Wednesday. "A tiny subset was spoofing to appear like they came from no-reply@dol[.]com, which isn't the genuine DoL domain, of course." Read More