Shared SSH Keys Expose Phishing Infrastructure Targeting Kuwait
Essential information
- Published
- 16/05/2025 16:33
- Modified
- 21/05/2025 20:56
- Tags
- 2025-05-16 credential harvesting domain impersonation fisheries infrastructure insurance kuwait phishing ssh keys telecommunications
- Related entities
- 77 observables, 8 techniques (mitre), 4 others
Description
An ongoing phishing campaign targeting Kuwait's fisheries, telecommunications, and insurance sectors has been identified, utilizing over 100 domains for credential harvesting. The operation, observed since early 2025, employs cloned login portals and impersonated web pages. The infrastructure shares operational fingerprints, including reused SSH authentication keys and consistent ASN usage, allowing related assets to be linked. The campaign primarily targets the National Fishing Company of Kuwait, automotive insurance sector, and Zain telecommunications. The actors use brand-inspired domain names and transliterations rather than direct typosquatting. Mobile payment lures targeting Zain customers have also been observed, potentially enabling further social engineering attacks.