Hackers targeting nongovernmental humanitarian groups, including UN groups like UNICEF, sought to steal login credentials using sophisticated phishing sites, according to a new report by mobile security firm Lookout.

Why it matters: Lookout doesn't attribute attacks to specific actors, but the lures used to draw targets to the phishing sites were links only of interest to workers following North Korea issues. That suggests North Korea is a likely suspect here.

What they found: The phishing sites used a number of clever tricks.

  • For one, if users reached the phishing sites through any path other than the phishing URL, it forwarded the user to a legitimate site. That limits the hackers' exposure.
  • While most people believe a site won't see the login data they type into a website unless they hit submit, the sites used key loggers to steal login data even if they didn't.
  • Like many modern phishing campaigns, the site used SSL certificates — the encryption measures that produce the lock icon in the URL bar, which less sophisticated users are sometimes told to look for to thwart phishing. Also, the sites used long URL names, making it harder for people on mobile phones to notice inconsistencies there.

The sites were hosted by the Malaysian firm Shinjiru, Lookout's Jeremy Richards told Axios.

  • Shinjiru is a so-called bulletproof hosting service offering technical and legal protections for hackers. Using providers like Shinjiru raises an automatic red flag in Lookout's machine learning system.

Go deeper

Updated 29 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Annelise Capossela/Axios

  1. Global: Total confirmed cases as of 3 p.m. ET: 20,158,258 — Total deaths: 738,063 — Total recoveries: 12,388,686Map.
  2. U.S.: Total confirmed cases as of 3 p.m. ET: 5,116,791 — Total deaths: 164,137 — Total recoveries: 1,670,755 — Total tests: 62,513,174Map.
  3. States: Florida reports another daily record for deaths State testing plans fall short of demand.
  4. Axios-Ipsos poll: 1 in 2 has a personal connection to COVID-19.
  5. Business: Moderna reveals it may not hold patent rights for vaccine.
  6. 🏈 Sports: Big Ten scraps fall football season due to coronavirus.
36 mins ago - Sports

Big Ten postpones fall sports due to coronavirus

Photo: Joe Robbins/Getty Images

The Big Ten announced Tuesday that it has voted to postpone its 2020 fall sports season, including football, due to risks posed by the coronavirus pandemic, hoping instead to play in the spring.

Why it matters: The move from one of the most prominent conferences in college sports will almost certainly prompt other Power Five leagues to follow suit.

13 of Biden's former rivals to appear together at Democratic convention

Democratic presidential candidates at the primary debate in Charleston, SC. Photo: Win McNamee/Getty Images

In a show of unity at the Democratic National Convention, 13 of Joe Biden's former 2020 challengers will appear via video to talk about the party's vision for the country and how they'll work with Biden to get it done.

Why it matters: Coalescing around Biden and his eventual running mate will help Democrats head into the general election against President Trump with a united front — unlike what they did in 2016.