📢 Welcome to Cyber Secure Pakistan Month!details →
PISA PakistanPISA PakistanCommunity CERT — Notified by Government of Pakistan

← 🏛️ Cyber Security for Government Organizations

1. Anatomy of a Government Spear-Phish

⏱ 8 min

Why government offices are prime targets

Foreign and criminal actors target Pakistani institutions with lures timed to real events: pay-scale notifications, election circulars, audit notices, conference invitations. The attachment is usually a double-extension file (Notice.pdf.exe) or an HTML smuggling file that steals stored credentials — often infostealer malware feeding access brokers.

Detection habits for every officer:

  1. Sender domain forensics: gov.pk addresses are official; 'gov-pk.org', 'finance-gov[.]net', 'estatement-services@gmail.com' are not. Read the FULL address, not the display name.
  2. Attachment extensions ON: Windows Explorer → View → Show → File extensions. '.pdf.exe', '.iso', '.lnk', '.html' from unknown senders = quarantine.
  3. Dispatch verification: every real circular has a dispatch number verifiable through your section's official register/channel. No dispatch trail = treat as hostile.
  4. Urgency + confidentiality requests ("don't forward, this is sensitive") are manipulation, not classification.

Reporting chain: suspicious email → departmental IT/focal person → PKCERT incident report (pkcert.gov.pk) → NCCIA 1799 for criminal referral. Forward as attachment (not inline) to preserve headers. Never "test" the attachment by opening it.

Next →