New SBA Phish Relies on Social Engineering, Not Malware

Attackers are once again impersonating the US Small Business Administration (SBA), this time with a campaign that avoids malicious payloads entirely. Instead of relying on malware or credential harvesters, the phish uses a benign PDF attachment and a carefully crafted message to trick recipients into replying with sensitive banking information.

The campaign targets businesses awaiting SBA Economic Injury Disaster Loan (EIDL) approvals, a population already primed to respond to official-looking correspondence. The email impersonates the SBA Disaster Customer Service account, with a sender address that appears legitimate at first glance. The target's full name appears in the body, and the message is free of typos or formatting errors that might raise suspicion.

BLOG-1428 Embedded Image - L0N1Zs

The key deception is in the Reply-To header. While the FROM header is spoofed to match the SBA's legitimate [email protected] address, replies are routed to disastercustomerservice@gov-sba[.]us, a look-alike domain registered just days before the campaign launched. Whois records for this domain show bogus registration information, a common pattern for attackers who operate with disposable infrastructure.

Domain Name: gov-sba[.]us
Registry Domain ID: D18007599F1554B3DAA9B6AFEA0F4235C-NSR
Registrar WHOIS Server:
Registrar URL: www.psi-usa.info
Updated Date: 2020-08-05T06:22:13Z
Creation Date: 2020-07-31T06:22:09Z
Registry Expiry Date: 2021-07-31T06:22:09Z
Registrar: PSI-USA, Inc. dba Domain Robot
Registrar IANA ID: 151
Registrar Abuse Contact Email:
Registrar Abuse Contact Phone:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registry Registrant ID: C186298DF566447488A165F7E4F5B8F60-NSR
Registrant Name: Krikor Derabrahamian
Registrant Organization:
Registrant Street: Rotenloewengasse 15
Registrant City: Wien
Registrant State/Province: US
Registrant Postal Code: 1090
Registrant Country: US
Registrant Phone: +44.7418440320
Registrant Email: [email protected]
Registrant Application Purpose: P5
Registrant Nexus Category: C31/US
Registry Admin ID: C5DF36C6EB720453A8CB08A1FC96AB740-NSR
Admin Name: Krikor Derabrahamian
Admin Organization:
Admin Street: Rotenloewengasse 15
Admin City: Wien
Admin State/Province: AT
Admin Postal Code: 1090
Admin Country: AT
Admin Phone: +44.7418440320
Admin Email: [email protected]
Admin Application Purpose: P5
Admin Nexus Category: C31/AT
Registry Tech ID: C5651DB7CEC1B420BAE1B3F7BE7E214B0-NSR
Tech Name: Gerald Auer
Tech Organization: World4You Internet Services GmbH
Tech Street: Hafenstrasse 47-51
Tech City: Linz
Tech State/Province: OOE
Tech Postal Code: 4020
Tech Country: AT
Tech Phone: +43.73293035
Tech Fax: +43.7329303510
Tech Email: [email protected]
Tech Application Purpose: P5
Tech Nexus Category: C31/AT
Name Server: ns2.world4you.at
Name Server: ns1.world4you.at
DNSSEC: unsigned

Newly registered domains (NRDs) are a favored attack vector because they have little to no history, allowing them to slip past blocklists employed by Secure Email Gateways (SEGs). Campaigns leveraging such domains are often ephemeral, active for 48 hours or less, making them difficult to track reactively.

To further the illusion, the message itself includes the recipient's full name and references the EIDL application process. The attached SBA - Disaster Loan Assistance Form.pdf closely mirrors the legitimate SBA Business Information form, including a valid Office of Management and Budget (OMB) form number and an oath certifying the information is true under penalty of perjury. The attacker's objective is clear: collect account numbers and routing details from businesses desperate for loan status updates.

BLOG-1428 Embedded Image - 04XdVl

Even the email's transport headers are engineered to evade detection. The attacker inserted an SMTP HELO command instructing the receiving server to treat the message as if it originated from the SBA's domain. In reality, the connection came from a different domain (990w8b[.]myvserver[.]online) and IP address (64[.]44[.]141[.]5). This tactic has proven effective against legacy email security solutions that trust the HELO identity without verifying the actual source.

Authentication-Results-Original: 990w8b.myvserver.online;	spf=pass (sender IP
 is 64.44.141.5) [email protected]
 smtp.helo=sba.gov
Received-SPF: pass (990w8b.myvserver.online: connection is authenticated)
Reply-To: "U.S. Small Business Administration (SBA)" <[email protected]>
From: "U.S. Small Business Administration (SBA)" <[email protected]>

For most recipients, the forgery is undetectable. The only clues are hidden deep within the PDF's document properties: the file was produced with Skia, an open-source graphics engine, rather than the Adobe PDF Library used for legitimate SBA forms. The document's timestamp also reveals it was created on July 31st, 2020, well after the legitimate EIDL form was published.

BLOG-1428 Embedded Image - dbWjvM

Mitigating the Threat

Detection of such campaigns requires more than signature-based scanning. Effective defenses analyze email headers for mismatches between the display name and the true sender domain, validate SPF, DKIM, and DMARC records, and check for indicators like recently registered domains and look-alike domain names. Lexical analysis of message body and subject lines can also flag financially driven attacks even when no malware is present.

The SBA will never proactively contact applicants for loan information. If an email requests additional details regarding an existing application, it should reference a matching application number. Suspicious messages should be reported to the SBA Office of Inspector General Hotline at 800-767-0385 or through the SBA's website.

Indicators of Compromise

  • Reply-To Address: disastercustomerservice@gov-sba[.]us
  • Malicious look-alike NRD: gov-sba[.]us
  • Sender IP: 64[.]44[.]141[.]5
  • Sender Domain: 990w8b[.]myvserver[.]online