{"id":3566,"date":"2025-04-27T10:01:16","date_gmt":"2025-04-27T10:01:16","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/27\/new-power-parasites-phishing-attack-targeting-energy-companies-and-major-brands\/"},"modified":"2025-04-27T10:01:16","modified_gmt":"2025-04-27T10:01:16","slug":"new-power-parasites-phishing-attack-targeting-energy-companies-and-major-brands","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/27\/new-power-parasites-phishing-attack-targeting-energy-companies-and-major-brands\/","title":{"rendered":"New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands"},"content":{"rendered":"<p>    New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated phishing campaign dubbed \u201cPower Parasites\u201d has been actively targeting global energy giants and major brands since 2024, according to a comprehensive threat report released this week.<\/p>\n<p>The ongoing campaign primarily exploits the names and branding of prominent energy companies including Siemens Energy, Schneider Electric, EDF Energy, Repsol S.A., and Suncor Energy through elaborately crafted investment scams and fraudulent job opportunities.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiu_9gI1MpO0VtHXpp5jmu0v3r0aXKp5Ntt-Awx0P7eHxwk7q6bxi0gu8XCphyphenhyphenNE1Kr_ZdF-0sPsILbtIHmNQ_min7dRk5327Ukp6r7M7ODKYimQpxk0JxNRFdd_kckVPHc1i9D_rTEIuDwOvLdNCrUPIiTSxjCWiDTzx2_iArnIA0tUGpxzchNTnO71G0\/s16000\/Portion%2520of%2520a%2520document%2520used%2520in%2520the%2520hiring%2520scam%2520campaign%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Portion of a document used in the hiring scam campaign (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<p>The attackers have established an extensive network of over 150 active domains designed to impersonate legitimate companies, primarily targeting individuals across Asian countries including Bangladesh, Nepal, and India.<\/p>\n<p>Victims are approached through a combination of deceptive websites, social media groups, and Telegram channels, often with localized content in English, Portuguese, Spanish, Indonesian, Arabic, and Bangla to increase effectiveness.<\/p>\n<p>Silent Push researchers <a href=\"https:\/\/www.silentpush.com\/blog\/power-parasites\/#:~:text=Silent%20Push%20Threat%20Analysts%20are,and%20India%2C%20with%20job%20and\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that the threat actors employ a \u201cspray and pray\u201d methodology, simultaneously abusing multiple brand names while deploying numerous websites to maximize victim outreach.<\/p>\n<p>The campaign\u2019s infrastructure analysis revealed that the attackers utilize domain names containing keywords like \u201cSE\u201d (representing Siemens Energy) and \u201cAMD\u201d (for Advanced Micro Devices) combined with various domain suffixes, creating patterns such as \u201csehub.top\u201d and \u201camd-biz.mom\u201d.<\/p>\n<p>The primary infection vectors involve <a href=\"https:\/\/cybersecuritynews.com\/social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> through two distinct approaches. In the investment scam variant, victims are lured with promises of high returns through fake investment platforms supposedly backed by reputable energy companies.<\/p>\n<p>Meanwhile, the job scam variant entices victims with fraudulent employment opportunities at well-known corporations, requiring applicants to provide sensitive personal and financial information including bank account details, identification documents, and void checks during the \u201conboarding\u201d process.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism and Technical Infrastructure<\/strong><\/h2>\n<p>The Power Parasites <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-campaign-attacking-investors\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaign<\/a> employs an intricate technical infrastructure designed for maximum reach and minimal detection.<\/p>\n<p>Analysis of the deceptive websites reveals a consistent template pattern across domains, with login pages featuring an \u201cInvite code\u201d field-a classic technique used in investment scams to create a false sense of exclusivity.<\/p>\n<p>The campaign\u2019s promotion has extended to YouTube, where videos directing potential victims to <a href=\"https:\/\/cybersecuritynews.com\/1000-malicious-domains-mimic-reddit-wetransfer\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious domains<\/a> like \u201cse-renewables.info\u201d are published with enticing titles in multiple languages.<\/p>\n<p>One such video, translated from Bangla, promised viewers they could \u201cEarn free money from new sites,\u201d demonstrating the attackers\u2019 multilingual targeting strategy.<\/p>\n<p>Technical fingerprinting conducted by security researchers uncovered that these <a href=\"https:\/\/cybersecuritynews.com\/ebike-phishing-sites\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing sites<\/a> employ shared characteristics across their infrastructure, allowing them to rapidly deploy new domains when others are taken down.<\/p>\n<p>The campaign also leverages Telegram channels containing \u201csiemensenergy\u201d in their names to distribute malicious links, though many have since been banned or deleted.<\/p>\n<p>Siemens Energy has already published warnings about the fraudulent activities, explicitly stating they \u201cdo not operate any investment platforms\u201d and \u201cdo not ask for fees prior\/during\/after the application process.\u201d<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhU5SUfjRordAXrel-V0mTWOII8rfYeYFoyxIHnyo5pE3QtbN5W1kkLGgMpNCWZur6soXhD6D5hjz32TvO3kaiVoAM92AgomVQQBXxFUnmEmu2rHmiw1SnDz3qhJSUp-qwVegm3F7shCv3-oCetGuldFWtWU2-69dvyyCtHO6JEyZJpRNnuSVWs_9VIR3k\/s16000\/Repsol%2520phishing%2520website%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Repsol phishing website (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>Similarly, Repsol Energy has established a Fraud Alert page cautioning about schemes that use artificial intelligence to impersonate their executive team.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong><code>Malware Trends Report Based on 15000 SOC Teams Incidents, Q1 2025 out!-&gt;\u00a0<a href=\"https:\/\/any.run\/cybersecurity-blog\/malware-trends-q1-2025\/?utm_source=cyber-threat-intel_linkedin&amp;utm_medium=post&amp;utm_campaign=q1&amp;utm_content=blog&amp;utm_term=150425\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get Your Free Copy<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-power-parasites-phishing-attack\/\">New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-power-parasites-phishing-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Power Parasites Phishing Attack Targeting Energy Companies and Major Brands A sophisticated phishing campaign dubbed \u201cPower Parasites\u201d has been actively targeting global energy giants and major brands since 2024, according to a comprehensive threat report released this week. The ongoing campaign primarily exploits the names and branding of prominent energy companies including Siemens Energy, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-3566","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3566"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3566"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3566\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3566"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3566"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3566"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}