← Back to list

NTSA Fines Phishing Campaign

As cybercriminal operations continue to evolve, phishing campaigns are becoming increasingly targeted, deceptive, and mobile-focused. This…

Chemiron Adam · 2026-05-23 07:05 · 0 claps · 4.9 min read
#phishing #kenya #ntsa #social-engineering #brand-impersonation
Open on Medium ↗
Wiki topics: MKT · Marketing · General 🔒 · Cybersecurity ⏱️ · Productivity

NTSA Fines Phishing Campaign

As cybercriminal operations continue to evolve, phishing campaigns are becoming increasingly targeted, deceptive, and mobile-focused. This article analyzes a high-confidence NTSA impersonation phishing operation designed to harvest personally identifiable information (PII) and potentially facilitate payment fraud.

What makes this campaign particularly concerning is not just the convincing branding or fake traffic fine narrative, but the deliberate technical measures used to evade detection and specifically target smartphone users.

Summary of the Threat

Key Technical Findings

  1. Malicious Infrastructure indicators

The URL sent out to unsuspecting victims is:

ntsa[.]grmvn[.]sbs

At first glance, the victim will only see the first word and click on the link, but this is not part of legitimate NTSA infrastructure. Official NTSA services only operate under:

  • ntsa[.]go[.]ke
  • serviceportal[.]ntsa[.]go[.]ke

Attackers often craft domains that look convincing at first glance but reveal clear signs of fraud when analyzed. In this case, several red flags stand out:

  • .sbs TLD abuse. The .sbs extension is frequently abused in phishing/fraud campaigns
  • Random root domain (grmvn) - nonsensical strings are a hallmark of disposable phishing infrastructure
  • Brand prepending (ntsa) - classic impersonation tactic to trick users into believing the site is official
  • Mobile-only rendering — the site is designed to show content only on smartphones, technique used to evade desktop-based scanners and target mobile users directly.

Interestingly enough, the URL was registered on 18th May 2026 and had been flagged as malicious by one security vendor at the date of this report. See VirusTotal and WHOIS results below:

VirusTotal findings

VirusTotal findings

WHOIS information on the domain

WHOIS information on the domain

  1. Social Engineering Design Analysis

The general flow of the attack is as follows:

A user receives a shortened URL link on their mobile device and clicks it, which leads to the phishing domain ntsa[.]grmvn[.]sbs. When accessed from a desktop environment, the same URL conditionally redirects to the legitimate NTSA website, likely to evade suspicion and analysis.

On mobile, the phishing site presents a traffic-fine scam. It prompts the user to enter vehicle registration details and a national ID number, claiming there is an outstanding KSh 500 fine for an alleged speeding violation dated 21 April. The page uses urgency and intimidation tactics, including warnings about overdue payment penalties, to pressure immediate action.

After the initial input, the user is redirected to a second page designed to harvest financial credentials. This page requests sensitive banking information, including full name, card number, expiry date, and CVV, under the pretense of processing the fine payment.

Landing page of the URL

Landing page of the URL

Sequence of requests for the victim to enter details

Sequence of requests for the victim to enter details

This is highly sensitive information that attackers can use for identity theft, SIM swap preparation, M-Pesa social engineering, account recovery abuse, targeted scams and/or NTSA/eCitizen impersonation.

c. Mobile-only Targeting

This is one of the strongest malicious indicators and clearest red flags of malicious activity. Attackers often design harmful websites to behave differently depending on the device being used. Specifically, they target Android and iPhone user agents while deliberately blocking browsers. This is important to an attacker for the following reasons:

  • They hide from desktop users by blocking desktop browsers which would prevent casual discovery.
  • Bypass security checks from security tools that typically run in virtual machines or sandboxes that mimic desktop environments. Blocking desktops helps attackers slip past these defenses.
  • Evade automated scanners: most security crawlers often use desktop user agents i.e. Chrome, Mozilla, Edge etc.; excluding them reduces detection.
  • Deliver mobile-specific payloads i.e. malicious APK files, fake M-PESA flows or credential theft pages disguised as mobile login screens.

Threat Actor Trade Craft Assessment

MITRE ATT&CK Mapping of the attack

MITRE ATT&CK Mapping of the attack

The observed operation shows a moderately organized phishing actor rather than a low skill opportunistic scam. It demonstrates several hallmarks of organized phishing infrastructure such as targeting mobile devices, anti-analysis awareness through blocking of desktop browsers, institutional awareness by mimicking NTSA branding and efficient workflows to harvest sensitive data quickly.

The actor shows intent, resource investment, and tradecraft maturity.

Recommendations

  1. Verify NTSA websites carefully and only use official NTSA services through:

Be cautious of domains that:

  • Add extra words before or after “NTSA”
  • Use unusual endings like .sbs
  • Arrive via SMS, WhatsApp, Telegram, or social media links

A website that looks “professional” is not necessarily legitimate.

  1. Never Enter Banking Details from SMS or WhatsApp Links. Government agencies generally do not request:
  • Card CVV numbers
  • Full debit/credit card details through external links
  • Immediate payments via suspicious messages

If you receive a fine notification:

  • Open NTSA manually in your browser
  • Log into your official account directly
  • Verify fines independently

Do not trust unexpected links.

  1. Be Cautious of Urgency and Fear Tactics. The phishing site uses pressure tactics such as:
  • “Outstanding violation”
  • “Overdue payment”
  • “Penalty increases”
  • “Immediate action required”

Attackers rely on panic to short-circuit careful thinking. Pause and verify through official channels.

  1. Protect your National ID and Vehicle Information. National ID numbers and vehicle registration details are highly sensitive as they can be abused for identity fraud, SIM swap attacks, social engineering, fake account recovery attempts, and impersonation scams. Only provide this information on verified government portals.

  2. Use Mobile Security Protections. Since the campaign specifically targets smartphones:

  • Keep phones updated
  • Use reputable mobile security apps
  • Enable browser safe-browsing features
  • Avoid installing APKs from unknown links
  • Disable installation from “unknown sources”

Mobile users are increasingly targeted because many people trust phones more than desktops.

What To Do If You Already Entered Information

If someone submitted details to the phishing site, they should immediately do the following things:

  1. If banking details were entered:
  • Contact the bank immediately
  • Freeze or replace the affected card
  • Monitor for unauthorized transactions
  1. If national ID details were entered:
  • Monitor for suspicious calls or impersonation attempts
  • Be cautious of account recovery scams
  1. If M-PESA or phone details were shared:
  • Contact your mobile provider
  • Enable SIM swap protection if available
  • Watch for suspicious OTP requests

This campaign shows attacker increasingly tailoring scams for mobile-first populations. Time is critical to reducing fraud impact.

Stay safe out there!


메타데이터
post_id
f4d82eeb71b0
slug
ntsa-fines-phishing-campaign-f4d82eeb71b0
url
https://medium.com/@chemiron2020/ntsa-fines-phishing-campaign-f4d82eeb71b0
canonical_url
https://medium.com/@chemiron2020/ntsa-fines-phishing-campaign-f4d82eeb71b0
author_url
https://medium.com/@chemiron2020
status
ok
fetched_at
2026-06-09 15:37:30