- New SMS phishing campaign targeting the UK posing as parking penalty charges
- It has borrowed assets from UK.GOV sites to look legit
- It uses qrco[.]de shortening links
- It redirects to stockx[.]com if you are not the intended target
- The sites are protected by Cloudflare and registered through NameSilo
- It gets the target to enter their number plate then presents the "fine" and then asks for payment data (for fraud)
- Quite a few UK councils have warned about it:
- https://x.com/BasingstokeGov/status/1837098101967888489
- https://x.com/HertsmereBC/status/1836677045150998624
- https://x.com/cardiffcouncil/status/1836330416476705094
- https://x.com/lbbdcouncil/status/1835952461443408226
- https://x.com/LBRUT/status/1834940304723419205
- https://x.com/Derbyshirecc/status/1834258216630309034
- https://x.com/coventrycc/status/1834162608695357493
- https://x.com/ConwyCBC/status/1833528143757402504
- Regex:
/parking(?:gov|ukgov)[a-z]{1,2}\.(?:top)/
Known IOCs
parkinggovgbg[.]top
parkinggovgbd[.]top
parkingukgovt[.]top
parkinggovgbf[.]top
parkinggovgba[.]top
parkingukgovy[.]top
parkingukgovf[.]top
parkingukgovv[.]top
parkingukgovo[.]top
parkingukgovl[.]top
parkingukgovq[.]top
parkingukgovr[.]top
parkingukgovm[.]top
parkingukgovx[.]top
parkingukgovg[.]top
parkingukgova[.]top
parkingukgovc[.]top
parkingukgovw[.]top
parkingukgovu[.]top
parkingukgovk[.]top
parkingukgovi[.]top
parkingukgove[.]top
parkingukgovb[.]top
parkingukgovh[.]top
parkingukgovp[.]top
parkingukgovn[.]top
parkingukgovj[.]top
parkingukgovs[.]top
parkingukgovd[.]top
- VTE Query:
entity:domain registrar:NameSilo,LLC whois:carlos.ns.cloudflare.com ssl_issuer:"Google Trust Services"
- Look for the ones with
parking
in the name
- Thanks to @banthisguy9349 for finding the Phishing Kit's Admin Panel
- Thanks to @g0njxa for finding the Phishing Kit Admin's Telegram Account
- The creators of this phishing kit appear to be Chinese-speaking cybercriminals
- They pivoted to
/admin#/auth/login
to find the panel
More....
gov.carfine-uk[.]uk
gov.ukcarfine[.]uk
gov.allowance-uk3[.]uk
gov.allowance-uk4[.]uk
gov.uk3allowance[.]uk
gov.uk4allowance[.]uk
gov.parkingsuk[.]uk
gov.parkingzuk[.]uk
gov.allowance-uk[.]uk