• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 304-800 | Support: +49 5251 304-636
NoSpamProxy
  • PRODUCT
    • NoSpamProxy Cloud
    • NoSpamProxy Protection
    • NoSpamProxy Encryption
    • NoSpamProxy Large Files
    • NoSpamProxy Disclaimer
  • SOLUTIONS
    • M365 Mail Security
    • Managed Certificates
    • 32Guards
    • AS4
  • RESOURCES
    • Documentation
    • Forum
    • Webcast Training
    • Training Courses
    • Support
    • Software Download
  • PARTNERS
    • Finding Resellers
    • Becoming Reseller
    • Partner Portal
    • NFR Licenses
  • COMPANY
    • Contact
    • Testimonials
    • Team
    • Career
    • Events
    • Awards
  • PRICES
  • BLOG
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Die KfW-Bank als Phishing-Köder

KfW Bank as phishing bait

Micha Pekrul
Author: Micha PekrulProduct Managerhttps://www.linkedin.com/in/micha-pekrul/–Connect on LinkedIn

The discussions surrounding the possible introduction of a “digital euro” are currently being used as an attack vector for phishing campaigns. Among others, fake websites of the KfW development bank, the European Central Bank, the non-profit consumer organization Stiftung Warentest and the business magazine Capital are being used.

14.06.2024|Last edited:14.06.2024
KfW Phishing Mail

A fake website of the KfW development bank with links to Stiftung Warentest and Capital. An alleged ECB pilot program with unbelievable interest rate promises is advertised.

This appears to be an elaborate phishing campaign, as several websites have been created in this case. If you follow the link from the email, you will be redirected to a fake website of the KfW development bank, which advertises an alleged pilot program of the European Central Bank called “TFOM2426”. KfW Bank has published an official warning about fake websites and phishing emails.

KfW Phishing Stiftung Warentest Fake Webseite

A fake Stiftung Warentest website that gives the alleged pilot program top marks. Who could ever doubt that?

To increase the credibility of the phishing campaign, this website has links to Stiftung Warentest, where the pilot program is supposedly advertised as the “safest and best financial program 2024”.

KfW Phishing Capital Fake Website

The business magazine Capital has allegedly awarded the pilot program “TFOM2426” in an exclusive evaluation. This website is also fake.

But that’s not all: the spammers have also created and linked to another website that pretends to be the business magazine Capital and has already named the alleged pilot program the “safest investment product of 2024” before the official program launch.

KfW Phishing Europäische Zentralbank Digitaler Euro Fake Website

A fake ECB website where you can register as a participant. Also a phishing website.

The effort involved in phishing is enormous. In order to increase credibility in social engineering, trustworthy websites are copied and populated with false information. KfW, Capital and Stiftung Warentest all enjoy a good reputation in Germany. The ECB and the “digital euro” are certainly known to everyone in the country.

KfW Phishing Mail EZB Phishing Website

Only a few free places available: The criminals are building up pressure through artificial scarcity.

At the end of the fake ECB phishing website, the “social engineering” is intensified once again. There are, of course, only a limited number of places available. And there are only 431 places left, so be quick now! In addition to the too-good-to-be-true interest rates of 25.5%, there is clearly time pressure here. All the fake websites are designed to get you to sign up and disclose your details. The spammers don’t want you to miss out on this “opportunity” by thinking too long or checking the details. These are all “red flags”, which will hopefully come to light in time.

IoCs: Indicators of Compromise

The IoCs known to us are rated accordingly in 32Guards. The CERT-Bund has been informed and administrators should check the log files to see whether visits to the following websites have taken place and whether they have not yet been blocked by a security product such as a web gateway or firewall.

The following domains are currently known to be malicious:

  • ecb-digital[.]eu
  • the-future-of-money-ecb[.]com
  • stiftung-warentest[.]info
  • capltal[.]info

Not yet using NoSpamProxy?

With NoSpamProxy you can reliably protect your company from cyber attacks. Request your free trial version now!

Get your free NoSpamProxy trial now!
  • share 
  • share 
  • share 
  • email 

SEARCH

PRODUCT

  • All Topics
  • NoSpamProxy Cloud
  • NoSpamProxy Protection
  • NoSpamProxy Encryption
  • NospamProxy Large Files

You need support?

You can find more information about NoSpamProxy in our documentation and forum.

CATEGORY

  • All Topics
  • News
  • Product
  • Tech & Support
  • Events
RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

NoSpamProxy

  • NoSpamProxy Cloud
  • NoSpamProxy Encryption
  • NoSpamProxy Large Files
  • NoSpamProxy Disclaimer
  • Price request
  • Team
  • Career
  • General terms and conditions
  • Data Protection Information for Business Partners and Applicants
  • Cybersecurity (PSIRT)

Partners

  • Becoming a reseller
  • Partners
  • Order Certificates
  • Newsletter

Categories

  • All topics
  • News
  • Support
  • Updates
  • Order certificates

Latest News

  • Info Icon
    Limited support hours on Friday, May 16, 202513.05.2025 - 11:35
  • Was ist ein Zero Day Exploit Preview
    What is a Zero-Day Exploit?23.04.2025 - 14:00
  • Info Icon
    UPDATE: New Google email sender guidelines: What you need to do17.04.2025 - 12:00
IMPRINT • EULA • Privacy Policy • • © 2025 Net at Work GmbH
  • Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
Link to: Quishing: Phishing with QR codes Link to: Quishing: Phishing with QR codes Quishing: Phishing with QR codesWas ist QR-Code Phishing Quishing Preview Link to: it-sa 2024 – Secure your free tickets now! Link to: it-sa 2024 – Secure your free tickets now! it-sa 2022 Previewit-sa 2024 – Secure your free tickets now!
Scroll to top Scroll to top Scroll to top