Breaking
January 30, 2025

Criminals are abusing top-level government domains across multiple countries | usagoldmines.com


  • Cofense report finds phishing threat actors abusing top-level domains (TLDs)
  • A significant number of .gov domains are used in open redirect attacks
  • Brazil is the leader in .gov domain abuse

Cybercriminals are exploiting legitimate government websites and domain services, particularly those with .gov top-level domains (TLD), experts have warned.

A report from cybersecurity experts Cofense Intelligence claims TLDs are being used for a wide variety of nefarious purposes, from credential phishing to command & control (C2) operations.

The paper states between November 2022 and November 2024, threat actors took advantage of vulnerabilities in .gov domains from over 20 countries.

Credential phishing

One of the things the domains are used for is open redirects, which became a key method for bypassing secure email gateways (SEGs).

Open redirects occur when a web application unintentionally allows a user-controlled input to direct traffic to an external site, which threat actors can manipulate. Using this tactic, attackers can redirect unsuspecting victims from legitimate .gov websites to fraudulent pages.

In the United States, .gov domains are among the most frequently exploited for these redirects, with more than 77% of attacks leveraging a specific vulnerability tied to the “noSuchEntryRedirect” parameter. This vulnerability, identified as CVE-2024-25608, impacts platforms like Liferay, widely used by governmental organizations. Although U.S.-based .gov domains made up only 9% of all .gov domains abused, they ranked third in overall usage.

Credential phishing remains the most common form of abuse tied to .gov domains, the paper explains. The majority of government domains used in phishing attacks hosted up to nine different files across various campaigns. These phishing attempts often mimic legitimate services such as Microsoft, with emails designed to appear as though they are sent from trusted sources.

The report also notes the abuse of .gov domains for credential phishing and redirection to malicious sites was seen across several countries. Brazil, in particular, stands out as the most targeted country, accounting for the bulk of abuse in .gov domains. However, a small number of domains within Brazil were responsible for the majority of these abuses, hinting that the attackers were focused on a handful of important government websites.

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Best laptops 2025: Premium, budget, gaming, 2-in-1s, and more | usagoldmines.com

OpenAI's Reasoning Model Is Now Free on Copilot Michelle Ehrhardt | usagoldmines.com

Apple Reports Best Quarter Ever in 1Q 2025 Results: $36.3B Profit on $124.3B Revenue Jordan Golson |...

Apple Now Has More Than 2.35 Billion Active Devices Worldwide Juli Clover | usagoldmines.com

Largest desktop hard drive ever breaks another record; 28TB Seagate Expansion desktop hard drive has...

Best VPN services 2025: Top picks for speed, price, privacy, and more | usagoldmines.com

Best gaming laptops under $1,000: Expert picks that won’t break the bank | usagoldmines.com

This Tool Lets You Trim Videos Without Converting Them Justin Pot | usagoldmines.com

My Favorite Amazon Deal of the Day: The iPad Air M2 Daniel Oropeza | usagoldmines.com

Apple Might Start Buying Ads on X Again Juli Clover | usagoldmines.com

Watch out Nvidia, a Linux leak revealing three new Intel Arc Battlemage GPUs may challenge the RTX 5...

Copyright Office suggests AI copyright debate was settled in 1965 Ashley Belanger | usagoldmines.com

ChatGPT’s advanced AI costs $200/mo. Now it’s free for Windows users | usagoldmines.com

Microsoft ports DeepSeek’s AI to Copilot+ PCs, and their NPUs | usagoldmines.com

This wireless, solar-powered Eufy security camera is 46% off today | usagoldmines.com

The Bose QuietComfort Headphones Are on Sale for $179 Daniel Oropeza | usagoldmines.com

Eight Questions You Should Ask Yourself When Decluttering Your Home Lindsey Ellefson | usagoldmines....

Why Some Gym Machines Feel Heavier Than Others Beth Skwarecki | usagoldmines.com

Eight Useful Mac Apps Worth Checking Out Juli Clover | usagoldmines.com

Google's New 'Ask for Me' Search Feature Uses AI to Make Calls Juli Clover | usagoldmines.com

Report: DeepSeek’s chat histories and internal data were publicly exposed Kevin Purdy | usagoldmines...

VGHF opens free online access to 1,500 classic game mags, 30K historic files Kyle Orland | usagoldmi...

Eight Questions You Should Ask Yourself When Decluttering Lindsey Ellefson | usagoldmines.com

DeepSeek on steroids: Cerebras embraces controversial Chinese ChatGPT rival and promises 57x faster ...

Wacom warns users their data may have been stolen in breach | usagoldmines.com

DeepSeek disappears from the Italian App Store and Google Play Store amid privacy complaint chiara.c...

In surprise move Microsoft announces DeepSeek R1 is coming to CoPilot+ PCs – here’s how to get it ha...

BioWare has quietly laid off long-time Dragon Age devs as it downsizes the studio and turns its focu...

Max rolls out a new multiview feature for 2025's NASCAR Cup Series that puts you in the driver's sea...

Annoyed Samsung fans have started a petition to bring Bluetooth back to the S Pen – and they have a ...

Wix's new AI tool aims to take you from idea to profit in record time | usagoldmines.com

I can’t believe the Samsung Galaxy S25 is still the only phone of its kind to have this one crucial ...

Vodafone makes 'world's first' satellite video call with a standard phone –here's why that's a big d...

Forget mega yachts, AI data centers are quickly becoming the next battleground for billionaires as Z...

North Korean Lazarus hackers launch large-scale cyberattack by cloning open source software | usago...

Amazon Prime Video has ads now. Here’s how to stop them | usagoldmines.com

U-tec Ultraloq Bolt Fingerprint Matter review: Now hear this? | usagoldmines.com

DEAL: Galaxy Ring for $149 When You Trade-in Any Smartwatch ($250 Off) Tim | usagoldmines.com

T-Mobile Brings Back Free MLS Season Pass Through Apple TV Kellen | usagoldmines.com

Your DeepSeek Chats May Have Been Exposed Online Jake Peterson | usagoldmines.com

Apple Highlights Hearing Health Issues Leading Up to Super Bowl LIX Eric Slivka | usagoldmines.com

Apple's Back to School Sale Launches in Japan With Apple Gift Cards Eric Slivka | usagoldmines.com

I agree with OpenAI: You shouldn’t use other peoples’ work without permission Andrew Cunningham | us...

OpenAI teases “new era” of AI in US, deepens ties with government Ashley Belanger | usagoldmines.com

Lenovo Legion 5i review: This speed demon is a bargain | usagoldmines.com

This Ryzen 7 mini PC with 32GB RAM hits its lowest price ever: $499 | usagoldmines.com

6 surprisingly helpful uses for the USB port on your router | usagoldmines.com

Is your VPN app really secure? Check for this new ‘verified’ symbol | usagoldmines.com

ATSC 3.0: The future of broadcast TV spent another year stuck in neutral | usagoldmines.com

Netflix now lets you download entire seasons with a single click | usagoldmines.com

That teeny-tiny Asus Zenbook A14 laptop from CES is now for sale | usagoldmines.com

ChatGPT update brings more knowledge and better image recognition | usagoldmines.com

Asus says don’t worry about GPUs scratched by Q-Release PCIe slots | usagoldmines.com

New Flappy Golf Title Soon Coming to Android and iOS Tim | usagoldmines.com

Microsoft now hosts AI model accused of copying OpenAI data Benj Edwards | usagoldmines.com

ATSC 3.0: The future of broadcast TV spent another year stuck in neutral | usagoldmines.com

Nothing Says the Nothing Phone 3a is Coming March 4 Kellen | usagoldmines.com

'Liked Songs Manager' Automatically Turns Your Spotify Likes Into Playlists Justin Pot | usagoldmine...

Comcast Just Gave Six Cities an Early Look at Lag-Free Internet Michelle Ehrhardt | usagoldmines.com

Watch out, your office phone could be hijacked into a Mirai botnet | usagoldmines.com

The Future Games Show returns in March for its spring showcase and will include live broadcast from ...

Microsoft says its revenue dropped by 7% in its Q2 2025 earnings while Xbox hardware sales dropped b...

Civ 7 requirements for PC, Steam Deck, Linux, and Mac | usagoldmines.com

DeepSeek just insisted it's ChatGPT, and I think that's all the proof I need lance.ulanoff@futurenet...

The fate of Nvidia’s GeForce RTX 50-series lies in DLSS 4’s hands | usagoldmines.com

This tiny 2K security camera is super cheap at just $25 right now | usagoldmines.com

Microsoft updates new Surface Pro, Laptop with Intel inside | usagoldmines.com

Nvidia’s GeForce RTX 5090 and 5080 sell out almost instantly | usagoldmines.com

NordVPN’s new protocol is designed to evade VPN restrictions | usagoldmines.com

Windows 11’s Auto HDR works again, but you have to manually update first | usagoldmines.com

This Video Doorbell Is $80 Right Now, and It Doesn't Need a Monthly Subscription Pradershika Sharma ...

Samsung Introduces Major Discounts on TVs, Monitors, and More Ahead of Super Bowl LIX Mitchel Brouss...

Microsoft’s new Surface for Business PCs have AI firmly at the core | usagoldmines.com

Why businesses must avoid ‘AI FOMO’ at all costs | usagoldmines.com

Netflix just released an ominous first teaser clip of You season 5, but I'm still recovering from se...

Stranger Things season 5's 12-month shoot yielded 650-plus hours of footage for its eight 'blockbust...

AI safety at a crossroads: why US leadership hinges on stronger industry guidelines | usagoldmines....

Bennu asteroid samples yield watery history, key molecules for life Timothy J McCoy and Sara Russell...

Microsoft updates Intel-based Surface PCs, but regular people still can’t buy them Andrew Cunningham...

If you hate passwords, switch to this other kind of login right now | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

Your Phone Makes a Great Reading Device, Actually Justin Pot | usagoldmines.com

It's About to Get Much Easier to Cancel Your Subscriptions Meredith Dietz | usagoldmines.com

Apple Continues to Be the World's Most Admired Company Hartley Charlton | usagoldmines.com

AI agents are proving remarkably popular - but firms still face many challenges | usagoldmines.com

New DeepSeek AI rival claims to be more powerful than both V3 and ChatGPT-4o – meet Qwen2.5-Max | u...

Netflix reveals June 2025 release date for Squid Game season 3, and its first clip teases a new mini...

RX 9070 GPU could theoretically be an RTX 5070 killer, I’m just worried that AMD may not go for Nvid...

Nvidia’s RTX 50-series could be a huge flop if gamers reject DLSS 4 | usagoldmines.com

Unlock hands-free Kindle reading with this $16 page-turner add-on | usagoldmines.com

Mark Zuckerberg just teased next-gen Ray-Ban smart glasses – here are 4 things I want to see hamish....

NYT Connections today — my hints and answers for Friday, January 31 (game #600) | usagoldmines.com

I was excited by Netflix’s Black Doves renewal, but Ben Whishaw’s disappointing season 2 update mean...

NYT Strands today — my hints, answers and spangram for Friday, January 31 (game #334) | usagoldmine...

Quordle today – my hints and answers for Friday, January 31 (game #1103) | usagoldmines.com

Marvel Rivals crosshairs: how to change and import them | usagoldmines.com

Where to buy Nvidia RTX 5090: launch day is today, and these are the retailers I'd check christian.g...

Tesla’s 2024 financial results are out—and they’re terrible Jonathan M. Gitlin | usagoldmines.com

Nvidia’s RTX 50-series could be a huge flop if gamers reject DLSS 4 | usagoldmines.com

50 iPhone Features Apple Added to iOS 18 Since September Tim Hardwick | usagoldmines.com

Leave a Reply