{"id":1559,"date":"2022-07-06T12:00:00","date_gmt":"2022-07-06T10:00:00","guid":{"rendered":"https:\/\/lab52.io\/blog\/?p=1559"},"modified":"2022-07-06T12:01:38","modified_gmt":"2022-07-06T10:01:38","slug":"nato-summit-2022-the-perfect-pretext-to-launch-a-cybercampaign","status":"publish","type":"post","link":"https:\/\/lab52.io\/blog\/nato-summit-2022-the-perfect-pretext-to-launch-a-cybercampaign\/","title":{"rendered":"NATO Summit 2022: The perfect pretext to launch a cybercampaign"},"content":{"rendered":"\n<p>S2Grupo&#8217;s Threat Hunting team has carried out an investigation on the occasion of the NATO summit held in Madrid on June 29th and 30th on possible APT group campaigns that could have targeted this event.<\/p>\n\n\n\n<p>In this line, we have investigated those domains that had as part of the name any of the keywords provided by the Lab52 cyberintelligence team. In addition, they have been contextualized through WHOIS information.<\/p>\n\n\n\n<p>The graph below represents the time distribution of domain name creation and the keywords used in their name. The 15 most used keywords are shown. The time frame represented goes frome April 1st toJune 22nd.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"653\" height=\"253\" src=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image.png\" alt=\"\" class=\"wp-image-1560\" srcset=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image.png 653w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-300x116.png 300w\" sizes=\"(max-width: 653px) 100vw, 653px\" \/><figcaption>Figure 1. Domain names registered between April 1st and June 22nd<\/figcaption><\/figure>\n\n\n\n<p>The first thing to note is the shape of the graph. The lower peaks correspond to Saturdays and Sundays of each week. The most logical explanation for this phenomenon is simply that fewer domains are registered on weekends.<\/p>\n\n\n\n<p><strong>Keyword <\/strong><em><strong>nato<\/strong><\/em><\/p>\n\n\n\n<p>The second most used keyword in the SLD of the domains detected between April 1st and June 22nd is <em>nato<\/em>. In the graph below two peaks of domain registration can be observed. These peaks correspond to the dates April 11th and April 25th.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"811\" height=\"339\" src=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-1.png\" alt=\"\" class=\"wp-image-1561\" srcset=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-1.png 811w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-1-300x125.png 300w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-1-768x321.png 768w\" sizes=\"(max-width: 811px) 100vw, 811px\" \/><figcaption>Figure 2. Domains registered between April 1st and June 22nd with the keyword nato<\/figcaption><\/figure>\n\n\n\n<p class=\"has-text-align-left\">When investigating these results, the following is found, none of the 42 domains registered on April 11th containing <em>nato<\/em> in their SLD seem to be related to the North Atlantic Treaty Organization.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>chinatownone[.]com<\/td><td>didonatoroberto[.]com<\/td><\/tr><tr><td>doctoranatomy[.]com<\/td><td>donatoelectroshop[.]com<\/td><\/tr><tr><td>etnatoys[.]com<\/td><td>fascinators[.]info<\/td><\/tr><tr><td>genatonerscanner[.]com<\/td><td>guidedanatomy[.]com<\/td><\/tr><tr><td>hnsartesanato[.]com<\/td><td>homecareexterminators[.]com<\/td><\/tr><\/tbody><\/table><figcaption><em>Figure 3. Examples of domains registered on April 11th with the keyword nato in their SLD<\/em><\/figcaption><\/figure>\n\n\n\n<p>As for the peak on April 25th, several patterns have been observed in the registered domains:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Domains with the word <em>anatomy<\/em>:<\/li><\/ul>\n\n\n\n<p>There are 22 domains containing the word <em>anatomy<\/em>. They were registered by the same company, Ascio Technologies, Inc. Danmark and all of them registered in Norway. In addition, the word <em>leader<\/em> seems to be recurrent among these domain names.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"884\" height=\"344\" src=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-2.png\" alt=\"\" class=\"wp-image-1562\" srcset=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-2.png 884w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-2-300x117.png 300w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-2-768x299.png 768w\" sizes=\"(max-width: 884px) 100vw, 884px\" \/><figcaption>Figure 4. Registrars of the domains that contain the word anatomy in their SLD<\/figcaption><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Domains registered by <em>NameCheap, Inc<\/em>:<\/li><\/ul>\n\n\n\n<p>A large part of the domains registered on May 25th that have <em>nato<\/em> in their SLD were registered by NameCheap, Inc.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"886\" height=\"329\" src=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-3.png\" alt=\"\" class=\"wp-image-1563\" srcset=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-3.png 886w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-3-300x111.png 300w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-3-768x285.png 768w\" sizes=\"(max-width: 886px) 100vw, 886px\" \/><figcaption><em>Figure 5. Registrars of the domains registered on May 25<\/em>th that have <em>nato<\/em> in their SLD<\/figcaption><\/figure>\n\n\n\n<p>A closer look at these domains shows that they were registered in the United States and Iceland.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-4.png\" alt=\"\" class=\"wp-image-1564\" width=\"390\" height=\"365\" srcset=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-4.png 411w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-4-300x280.png 300w\" sizes=\"(max-width: 390px) 100vw, 390px\" \/><figcaption>Figure 6. Registrant&#8217;s country of the domains registered on May 25th that have nato in their SLD<\/figcaption><\/figure>\n\n\n\n<p>The domains registered in Iceland do not appear to be related or follow a pattern.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>ajinatoto[.]online<\/td><\/tr><tr><td>anatomyofguitartone[.]marketing<\/td><\/tr><tr><td>cltvedbugexterminator[.]com<\/td><\/tr><tr><td>thetubinator[.]com<\/td><\/tr><\/tbody><\/table><figcaption><em>Figure 7. Examples of domains registered <em>in Iceland<\/em> on April 25th with the keyword nato in their SLD<\/em><\/figcaption><\/figure>\n\n\n\n<p>However, those that were registered in the United States do appear to be related to each other. Moreover, they all seem to refer to the North Atlantic Treaty Organization. In a way, it seems that these domains are intended to masquerade as legitimate domains of the organization. All the domains are shown below.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>actnato[.]com<\/td><td>brandnato[.]com<\/td><td>econato[.]com<\/td><td>fnato[.]com<\/td><\/tr><tr><td>freenato[.]com<\/td><td>gamenato[.]com<\/td><td>historynato[.]com<\/td><td>insidenato[.]com<\/td><\/tr><tr><td>natobank[.]com<\/td><td>natoblog[.]com<\/td><td>natoconference[.]com<\/td><td>natodesign[.]com<\/td><\/tr><tr><td>natoexpo[.]com<\/td><td>natofinance[.]com<\/td><td>natofurniture[.]com<\/td><td>natogames[.]com<\/td><\/tr><tr><td>natohealth[.]com<\/td><td>natointelligence[.]com<\/td><td>natomap[.]com<\/td><td>natomarket[.]com<\/td><\/tr><tr><td>natopartner[.]com<\/td><td>natophone[.]com<\/td><td>natopost[.]com<\/td><td>natopress[.]com<\/td><\/tr><tr><td>natoq[.]com<\/td><td>natosecret[.]com<\/td><td>natosport[.]com<\/td><td>natostaff[.]com<\/td><\/tr><tr><td>natotoday[.]com<\/td><td>natotravel[.]com<\/td><td>natoworks[.]com<\/td><td>netnato[.]com<\/td><\/tr><\/tbody><\/table><figcaption><em>Figure 8. Domains registered by NameCheap in the United States on April 25th with the keyword nato in its SLD<\/em><\/figcaption><\/figure>\n\n\n\n<p>To avoid results for words containing the letters <em>nato<\/em> as in the previous case of domains with the word <em>anatomy<\/em>, another approach was to search for domains starting with the word nato. Those domains registered by NameCheap, Inc. have been excluded because they have been collected in the previous analysis. The graph shows a peak registration on June 6th.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"775\" height=\"339\" src=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-5.png\" alt=\"\" class=\"wp-image-1565\" srcset=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-5.png 775w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-5-300x131.png 300w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-5-768x336.png 768w\" sizes=\"(max-width: 775px) 100vw, 775px\" \/><figcaption>Figure 9. Domain names registered between April 1st and June 22nd that begin with the keyword nato<\/figcaption><\/figure>\n\n\n\n<p>Most of these domains were registered by PublicDomainRegistry in Poland. Both the SLD and TLD of these domains are suspicious and appear to be malicious.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>natofrontline[.]com<\/td><td>natofrontline[.]info<\/td><\/tr><tr><td>natofrontline[.]net<\/td><td>natofrontline[.]online<\/td><\/tr><tr><td>natofrontline[.]site<\/td><td>natofrontline[.]store<\/td><\/tr><tr><td>natofrontline[.]tech<\/td><td>website<\/td><\/tr><\/tbody><\/table><figcaption><em>Figure 10. Domains registered by PublicDomainRegistry in Poland on June 6th with the keyword nato at the begining of their SLD<\/em><\/figcaption><\/figure>\n\n\n\n<p><strong>Keyword <\/strong><em><strong>otan<\/strong><\/em><\/p>\n\n\n\n<p>After analysing the domains containing the keyword <em>otan<\/em>, any relation to NATO has been ruled out. Only two domains have been found that could be related: <em>otan[.]info<\/em> and <em>fuckotan[.]com<\/em>.<\/p>\n\n\n\n<p><strong>Keyword <\/strong><em><strong>summit<\/strong><\/em><\/p>\n\n\n\n<p>The graph below represents the time distribution of domain registration with the word <em>summit<\/em> in the SLD. Several peaks of domain registration can be seen.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"762\" height=\"343\" src=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-6.png\" alt=\"\" class=\"wp-image-1566\" srcset=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-6.png 762w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-6-300x135.png 300w\" sizes=\"(max-width: 762px) 100vw, 762px\" \/><figcaption><em>Figure 11. Domain names registered between April 1st and June 22nd with the keyword summit<\/em><\/figcaption><\/figure>\n\n\n\n<p>Most of the domains in the three peaks were registered by GoDaddy.com (55.72%) and in the United States (68.47%).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-7.png\" alt=\"\" class=\"wp-image-1567\" width=\"554\" height=\"427\" srcset=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-7.png 507w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-7-300x231.png 300w\" sizes=\"(max-width: 554px) 100vw, 554px\" \/><figcaption>Figure 12. Domain registrars<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-8.png\" alt=\"\" class=\"wp-image-1568\" width=\"499\" height=\"440\" srcset=\"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-8.png 441w, https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/image-8-300x265.png 300w\" sizes=\"(max-width: 499px) 100vw, 499px\" \/><figcaption>Figure 13. Registrant&#8217;s country<\/figcaption><\/figure>\n\n\n\n<p>Analysis of these domains has led to the conclusion that they are likely to be used for fraudulent activities. The SLDs were probably designed to get the victim&#8217;s attention and get them to access the domain. Here are some examples.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>newworldleadershipsummit[.]com<\/td><td>theworkplacesummit[.]com<\/td><\/tr><tr><td>blockchain-one-to-one-summits[.]com<\/td><td>audisummitforprogress[.]com<\/td><\/tr><tr><td>beautyrichsummit[.]com<\/td><td>biotech-summit[.]com<\/td><\/tr><tr><td>chemical-recycling-summit[.]com<\/td><td>globalmanufacturingsummit[.]org<\/td><\/tr><tr><td>munich-newspace-summit[.]org<\/td><td>womensinclusionsummit[.]org<\/td><\/tr><\/tbody><\/table><figcaption><em>Figure 14. Examples of suspicious domains<\/em><\/figcaption><\/figure>\n\n\n\n<p>Therefore, this research leads us to conclude that most of the domains identified as suspicious during the analysis will be used for malicious purposes, either as part of a Command and Control infrastructure or through disinformation campaigns. There is no doubt that the NATO summit held in Madrid during the last week of June has been used as a medium for cybercriminal purposes.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>S2Grupo&#8217;s Threat Hunting team has carried out an investigation on the occasion of the NATO summit held in Madrid on June 29th and 30th on possible APT group campaigns that could have targeted this event. In this line, we have investigated those domains that had as part of the name any of the keywords provided [&hellip;]<\/p>\n","protected":false},"author":22,"featured_media":1575,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-1559","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-uncategorised","8":"entry"},"featured_image_src":"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/Flag-North-Atlantic-Treaty-Organization-600x400.jpg","featured_image_src_square":"https:\/\/lab52.io\/blog\/wp-content\/uploads\/2022\/07\/Flag-North-Atlantic-Treaty-Organization-600x600.jpg","author_info":{"display_name":"Arubaro","author_link":"https:\/\/lab52.io\/blog\/author\/varit0\/"},"_links":{"self":[{"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/posts\/1559"}],"collection":[{"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/comments?post=1559"}],"version-history":[{"count":6,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/posts\/1559\/revisions"}],"predecessor-version":[{"id":1574,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/posts\/1559\/revisions\/1574"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/media\/1575"}],"wp:attachment":[{"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/media?parent=1559"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/categories?post=1559"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lab52.io\/blog\/wp-json\/wp\/v2\/tags?post=1559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}