Email Authentication Vulnerability in Public Prosecution Office of Oman
A critical vulnerability in the Public Prosecution Office of Oman's email servers allows attackers to send fraudulent cryptocurrency-related campaigns from official addresses.
Executive Summary
Dymo discovered a critical email authentication vulnerability in the Public Prosecution Office of Oman. Attackers can exploit this flaw to send convincing fraudulent emails from official prosecution addresses, specifically targeting victims with cryptocurrency-related scams.
Affected Organization
- Name: Public Prosecution Office (النيابة العامة)
- Country: Oman
- Type: Judicial/Prosecutorial Authority
- Domain: Official government email systems
Technical Analysis
Vulnerability Type
Email Infrastructure Misconfiguration
Severity
High (CVSS 8.1)
Technical Findings
The vulnerability stems from:
- Absent DMARC Policy: No protection against domain impersonation
- Weak SPF Configuration: Multiple unauthorized sending sources
- No DKIM Signing: Emails lack cryptographic verification
- Infrastructure Gaps: Legacy systems without modern security controls
Exploitation Pattern
Observed cryptocurrency fraud campaigns:
- Fake legal notices demanding cryptocurrency payments
- Phony refunds or settlements in crypto
- Impersonation of prosecutors requesting Bitcoin
- Fraudulent investment opportunities from "prosecution projects"
Impact Assessment
The high authority of the Public Prosecution makes these attacks particularly effective:
- Fear-based manipulation: Threats of legal action
- Authority exploitation: People trust official prosecution emails
- Financial targeting: Cryptocurrency adds complexity to tracing
- Cross-border scope: Can target international parties
Responsible Disclosure
Reported to:
- Public Prosecution IT Security
- Oman Computer Emergency Response Team (OMANCERT)
- Ministry of Technology and Communications
Mitigation Strategy
Immediate actions required:
- Implement DMARC with strict enforcement
- Deploy DKIM for all official email
- Audit and restrict SPF records
- Establish email authentication monitoring
- Create public awareness about official communications
This vulnerability was identified through Dymo's automated email security scanning.