Interpol warns of alarming rise in cyberattacks during COVID

Cyberattack - Covid 19
Image source : geralt via Pixabay

In a new study of August 2020, INTERPOL measured the impact of COVID-19 on cybercrime. The results reveal that while the primary targets of cyberattacks usually remain individuals and SMEs, these have significantly expanded to large organizations and governments during the COVID period, revealing a new underlying trend.

The fact that working from home was massively implemented has obviously increased vulnerabilities which cybercriminals have been able to exploit seeking to take advantage of the situation.

According to this study, between January and April 2020, 907,000 spam messages, 737 malware incidents and 48,000 malicious URLs, all related to COVID-19 were detected.

The most common cyberattacks during the COVID-19 period were as follows:

  • Phishing
  • Ransomware
  • DDoS
  • Data harvesting malware
  • Cybersquatting / fraudulent domain names
  • Fake news

In Europe, two-thirds of member countries report a major increase in the number of cybersquatted domain names containing the keywords COVID or CORONA and ransomware deployments on critical infrastructures.

Cloning of official government websites is increasing massively as cybercriminals seek to steal sensitive data that can be used in future attacks.

In this report, you will discover all the measures implemented by INTERPOL.

It is more crucial than ever to secure your domain names carrying critical services and to protect your infrastructures.

Our consultants are, of course, at your disposal to assist you on these points.

COVID19.com – The domain name registered by a third party redirects to the website of the World Health Organization (WHO)

COVID19 domain name
Image source: geralt via Pixabay

“Domainers” are always a step ahead when it comes to taking advantage of a good or bad situation. For example, some will anticipate elections by registering the names of political figures, others by taking advantage of a sport or cultural event. Consequently, regarding domain names, there will be opportunities for speculative registrations.

In the case of “COVID19.com“, it seems clear that at the time of this domain name registration on February 11, 2020, the holder obviously wants to speculate on the “COVID 19” virus, a term that can generate multiple requests in any language. The name is available for sale for $10,000 USD.

However, instead of simply redirecting the domain name to commercial links, the holder chose to redirect this strategic name to the World Health Organization (WHO) website. Is this a citizen’s initiative? Unlikely, because given the current context, using such a name to make a direct profit through commercial links could lead to a violation of the Registrar’s registration conditions.

If the holder does not immediately benefit from this domain name, he will at least have the merit to draw our attention to him for the time of an article.

.ZA websites will have to propose a link towards the COVID-19 official website implemented by the government

South Africa - .ZA domain names - dot ZA
Image source: 12019 via Pixabay

Since last Thursday, the South African government has imposed to all websites using domain names in .ZA to propose a link that redirects towards the official Covid-19 information website implemented by the government:  www.sacoronavirus.co.za

This new rule applies to all .ZA websites, regardless of their content.

The two other extensions managed by ZADNA registry, JOBURG and .CAPETOWN are also affected by this rule.

In the same logic, the registry also invites Internet services providers to block any websites which spread fake news.

Lastly, it is interesting to note that the government’s COVID information website is not www.coronavirus.co.za but www.sacoronavirus.co.za. This is because the domain name www.coronavirus.co.za has been registered by a domainer who proposes on his website to resell the name in question.

Like all crisis or news, COVID-19 led to a massive registration of domain names containing the associated terms, some unscrupulous players seeking to take advantage of the situation.

Unsurprisingly, during this unprecedented and complicated period, there has been a high increase in the number of cybercriminal attacks of all kinds.

ICANN67 – COVID19 : 0-1

ICANN67 - COVID19 : 0-1
Image source: geralt via Pixabay

The 67th annual ICANN Summit, a summit dedicated to Internet naming regulations, was to be held in Cancún, Mexico, from 7th to 12th March. Often referred to by the acronym ICANN67, it is finally another acronym COVID19 that designates the now famous coronavirus that forced ICANN to reconsider all the logistics of this major event.

Since 1999, ICANN has organised three annual meetings devoted to the regulations applicable to Internet naming and a fourth devoted to more operational aspects, often referred to as the GDD Summit (Global Domain Division Summit). These meetings are an opportunity for participants from some 150 countries to discuss live the hot topics related to the Domain Name System (DNS).

For the past few weeks, however, world attention has focused on a completely different subject: the ongoing spread of the coronavirus, which according to the latest figures available has contaminated some 75,465 people in mainland China and caused the death of 2,236 people since its emergence in December in Wuhan, capital of Hubei province. While South Korea also now has more than 150 confirmed cases, the list of countries with confirmed cases keeps growing. More than 30 countries are now in this situation.

Quite logically, in recent weeks, behind the scenes of the ICANN organization, coronavirus has been rising as a major concern for the players in the domain name industry. More and more potential participants were talking about the fact that they would prefer not to travel for this event, which is important to them, while others were asking whether it was appropriate to hold this event in such a context. Recent cancellations of similar events have indeed echoed their concerns. Earlier this month, the GSMA, the organizers of the world’s largest mobile industry exhibition, Mobile World Congress 2020, effectively cancelled the event after more than 30 exhibitors and sponsors withdrew due to the outbreak. The Fintech Festival of India (IFF 2020) organised by the government of Maharashtra, the Ministry of Electronics and Information Technology (MeitY), the National Payments Corporation of India (NPCI) and the Fintech Convergence Council also similarly announced this week that it would postpone the event to a “more appropriate time” due to coronavirus-related issues. The event was scheduled to take place on 4-5 March 2020.

At the 19 February session of the ICANN Board, which was extended by one hour, ICANN finally decided :

« Resolved (2020.02.19.01), by virtue of the public health emergency of international concern posed by COVID-19, the daily evolving developments, and the high global risk still identified, the Board directs the ICANN President and CEO, or his designees, to take all necessary actions to not hold ICANN67 as an in-person meeting in Cancún, Mexico.

Resolved (2020.02.19.02), as the Board has determined to not proceed to Cancun, Mexico for ICANN67, the Board directs the ICANN President and CEO to move ICANN67 to ICANN’s first fully remote public meeting. »

The ICANN Board communiqué confirms that the summit, which is usually held in person, will for the first time be entirely managed remotely with means still to be clarified.

If the holding of such event in a remote mode is unprecedented, it should be noted that in the past ICANN has already changed the organization of its meetings for similar reasons. Indeed in June 2016, for example, ICANN decided to move ICANN56 from Panama City to Helsinki in Finland because of the Zika virus. The only difference is that their decision could have been anticipated earlier.

This is why ICANN has already taken up the subject for the holding of the following events : the GDD Summit planned in Paris in May and then the ICANN68 planned in Kuala Lumpur in Malaysia in June.