惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
博客园 - 司徒正美
J
Java Code Geeks
aimingoo的专栏
aimingoo的专栏
A
About on SuperTechFans
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
T
The Blog of Author Tim Ferriss
D
Docker
大猫的无限游戏
大猫的无限游戏
D
DataBreaches.Net
腾讯CDC
V
Visual Studio Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
C
Check Point Blog
M
MIT News - Artificial intelligence
Jina AI
Jina AI
I
InfoQ
雷峰网
雷峰网
The Cloudflare Blog
美团技术团队
Engineering at Meta
Engineering at Meta

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Cybercriminals cash in on black market vaccine schemes
Intel 471 · 2021-10-20 · via Intel 471 Blog

If you look back through all of the research Intel 471 has released on cybercriminals making money on stolen digital assets, a major takeaway is that the cyber underground will adopt any scheme, as long as it results in money being made. With the world trying to move past the global COVID-19 pandemic, another opportunity for illegal gains has struck.

Intel 471 has observed numerous actors on various underground forums selling fake COVID vaccine certifications, as well as several forums hosting advertisements for COVID-19 vaccines. While these advertisements have proliferated for months, we have observed these schemes growing on underground forums that are rooted in the cybercrime ecosystem.

Of those fake vaccine passes being advertised, we have seen the concentration placed on the United States’ Centers for Disease Control and Prevention’s vaccination card, which is a paper form, and the European Union’s vaccine passport, which is issued in both digital and paper forms. On one particular cybercrime forum, an actor has listed several advertisements for fake vaccination cards that parrots a lot of the misinformation that surround the various COVID-19 vaccines.

“We do this to help people who are in critical situations and want to travel urgently,” the advertisement reads. “Watch out and stay away from the vaccine; it’s poisonous. Kindly pass out the message to those who are still blind out there, so many secrets are hidden from us. The minority ruling are trying to destroy mankind.”

The actor has set up several communication channels for anyone interested: potential customers can reach out via encrypted messaging services Telegram, WhatsApp, and Wickr, or encrypted email service ProtonMail.

Another advertisement on the same forum offers fake CDC cards. These falsified documents are focused on the European and French documents and associated false QR codes. The website, accessible via the TOR browser, shows what the final QR code product will look like:

[Image: Screen Shot 2021 10 08 at 10 46 30 AM - An example of a fake French digital COVID passport taken from an underground website. (Intel 471)]

With regards to the actual vaccine, an actor’s advertisement that Intel 471 observed claimed to be able to send potential buyers numerous different vaccines currently on the market: AstraZeneca, Johnson & Johnson, Moderna, Pfizer, and Sputnik V. Buyers were then directed to visit a particular website set up for sales. However, that e-commerce website was not working at the time this blog post was published.

There have been numerous reports that this falsified document practice has been going on for months. However, we have seen the market change as the virus causes different issues in various parts of the world. Actors will:

  • Read open-source news to determine which countries are not getting enough, or any, deliveries of the vaccine.
  • Market the illegal vaccine to these developing countries since these nations have no private way of obtaining vaccines and must instead rely on COVAX distribution.
  • Undermine the pharmaceutical companies’ efforts to distribute the vaccine, putting people in danger since they have very little recourse to determine if the vaccines are legitimate.

Be it underground vaccine sales or counterfeit vaccine passes, actors are monetizing the fear and misinformation around COVID-19, creating a new market that has been constructed partly by pushing people who have never purchased anything illicit to buy things off of the underground. While the schemes carried out in this blog do not directly impact an organization’s cybersecurity defenses, it can hurt pharmaceutical companies by robbing them of consumers and damaging their brand reputations. In addition, fake vaccine passports harm healthcare, erodes government trust with false information, and can disrupt local and national economies.

No matter the damage wrought, it shows that cybercriminals and the forums where they gather online will take on any scheme, no matter how technical, in order to make money.