ParityNews.com: ...Because Technology Matters

Switch to desktop Register Login

Spammers Using Shortened .gov URLs

Cyber-scammers have started using the 1.usa.gov links in their spam campaigns in a bid to fool gullible users into thinking that the links they see on a website or have received in their mail or newsletter are legitimate US Government website.

Spammers have achieved these shortened URLs through a loophole in the URL shortening service provided by bit.ly. USA.gov and Bit.ly have collaborated thus enabling anyone to shorten a .gov or .mil URL into a trustworthy 1.USA.gov URL. Further, according to an explanation provided by HowTo.gov, USA.gov short URLs do not require any log in.

As pointed out by Symantec, beyond the legitimate users, cyber scammers and spammers have found this method of shortening URLs very lucrative. Symantec notes, “By using an open-redirect vulnerability, spammers were able to set up a 1.usa.gov URL that leads to a spam website.”

Giving an example of how this works, a shortened URL:

"[http://]1.usa.gov/[REMOVED]/Rxpfn9"

would actually redirect to
"[http://]labor.vermont.gov/LinkClick.aspx?link=http://workforprofit.net/[REMOVED]/?wwvxo"

which in turn would lead to "[http://]workforprofit.net/[REMOVED]/?wwvxo"
that is actually a scam website with a news website like front end.


Symantec’s analysis reveals that in the last week alone there were well over 43,000 clicks that were made through 1.usa.gov shortened URLs that redirected users to 10 spam domains, most of where were from the US.

Parity Media Private Limited. All rights reserved. 2013

Top Desktop version