Showing posts with label scams. Show all posts
Showing posts with label scams. Show all posts

Saturday, 10 September 2011

Cybercrooks prey on 9/11 anniversary

Malware, 'commemorative coin' auctions and fake charity donation



Cybercrooks are gearing up for the 10th anniversary of the 9/11 attacks with a range of malware traps and hacking attempts both on social networks and the wider internet, net security firm BitDefender warns.

The first wave of these attacks comes in the form of the newly established websites offering supposed content such as "Bin Laden alive", "in depth details about the terrorist attack", "police investigation results" and "towers going down" to attract the curious.
The sites are filed with links to scareware and phishing sites. Others have created fraudulent charity donation sites that serve only to line their greedy pockets at the expense of genuine gift-giving sites.

In addition, fraudsters are running fake auctions and sales of items supposedly linked to the devastating attacks such as shards of metal from the twin tower or even "commemorative coins" supposedly minted from silver collected at the attack site.

More scam, perhaps involving malware, can be expected to follow over the coming days.

“Because of the advancement of hacking and spamming technology over the past decade, plus the significance of the anniversary and increased media coverage, Sept 11 this year may prove hectic on the malware front,” said Catalin Cosoi, head of the Online Threats Lab at Bitdefender.

BitDefender says many of the scams likely to be on show are similar to those seen during anniversaries of the London bombings of July 2005.

Cybercrooks marked remembrances of the 7/7 attacks with fake donation requests, spamming of viruses disguised as supposed videos of the assaults and advanced fee fraud email scams. ®

[TheRegister]

Tuesday, 12 April 2011

DHL Express spam campaign leads to fake AV

A new spam campaign impersonating the popular mail service DHL Express is currently underway, warn Bkis researchers.

The email in question looks like this:



Once the user downloads and opens the attachment, the worm contained in it downloads a fake AV solution from a server located in Russia.

The fake AV ("XP Home Security") immediately starts its work and tries to trick the user into buying a full version that will supposedly remove all the infections it found.

Users are warned to be careful when reviewing emails purportedly coming from DHL express or any of the other well-known express mail services - more often than not, they are fake emails containing malicious attachments.

[net-security]

Ransom Trojan locks Windows

Ransomware is slowly becoming quite a problem, and the latest one spotted by F-Secure tries a rather innovative approach: it locks the victims out of Windows and doesn't allow them boot Windows in either normal or Safe mode until they have entered a code to "complete activation":



Posing as a legitimate Microsoft action, the scammers claim that the activation is "absolutely free and is simply a formality." The victims are offered six phone numbers to which they can place a call, enter a given code and once they receive an activation key, enter it and gain access to their computer again.

The note says that the call from the victim's county is free of charge, but that's a complete lie. The calls purportedly go to Microsoft call centers, but these numbers belong to rogue call centers seemingly located in countries such as the Dominican Republic or Somalia - i.e. countries with expensive phone rate.

But, these rogue call centers are actually located in countries the calls to which are much cheaper than to the previously mentioned ones, so the scammers and the owners of these call centers split the difference in the fee.

F-Secure's Mikko Hypponen demonstrated how the scam works, and says that no matter how many times and to which of the offered numbers one makes the call, one is forced to listen to a four minutes long prerecorded message that reveals at the end always the same activation code: 1351236.

You Windows can be unblocked only by entering the code or formatting your hard drive and restoring its contents from your backup - there is no other way.

[net-security]

Facebook Scam Alert: ‘Everyone do check what she did on cam’ Spreading

We’re monitoring an on-going Facebook scam campaign that seems to be spreading faster than any campaign we’ve come across before.
What did this girl do on her webcam?
What did this girl do on her webcam?
The scam starts with a user being tagged in a photo such as the one above. The photograph is posted in an album called “BBC News” to give it authenticity. It typically has over 100+ people tagged in it and it contains the following text: “Everyone do check what she did on cam …. — [URL]”

An example of what it would look like to see your friends tagged in this photo
An example of what it would look like to see your friends tagged in this photo
The short URL typically redirects the users to a .info domain, which then takes the user to a Facebook Application Installation page.
Short URL redirects to the following Application Install Page
Short URL redirects to the following Application Install Page
When a user allows the application, the scam continues with that user posting the same photo, tagging over 100 users in it and helping it propagate.
Over 100 Friends tagged in this scam
Over 100 Friends tagged in this scam
Users are also redirected to another .info domain, which contains a video that is gated by another form of a survey scam:
Facebook Verification Spam Bot - Freudian Slip?
Facebook Verification Spam Bot – Freudian Slip?
The scammers have managed to be nimble enough to switch the campaign from one Short URL service to another. At first, this was spreading via Bit.ly:
Bit.ly Stats as this scam was first spreading
Bit.ly Stats as this scam was first spreading
Over the course of an hour, this particular URL received over 80,000 clicks.  However, the scam has since shifted to the Goo.gl Short URL service:
Goo.gl Short URL Statistics for this scam
Goo.gl Short URL Statistics for this scam
In less than an hour, the goo.gl version of the scam has reached over 125,000 clicks.
Recommendations: First and foremost, don’t click on the link included in the description of the photograph. One of the things you can do to prevent your friends/family members from falling for this is to untag yourself from the photograph:
You can untag yourself from any photo
You can untag yourself from any photo
Additionally, you can report the image so that Facebook can take action against it (this is an important step):
You can help prevent this scam from spreading by reporting it
You can help prevent this scam from spreading by reporting it
If you’ve been tricked into installing the application, visit the Privacy Settings page and click on ‘Edit Your Settings’ under Apps and Websites.  Locate the Rogue Application under the Apps and Websites section (typically has the word “news” in it). Once you’ve located it under the  ‘Apps You Use’ section, click on ‘Edit Settings’ in order to remove the application.
Scammers are finding new ways to trick users. The key here is to be aware and to keep your friends and family members in the loop about scams like this one.  We can’t stress that enough.
Update: The goo.gl short URL has now logged over 220,000 clicks.
Over 220,000 clicks on the goo.gl short URL
Over 220,000 clicks on the goo.gl short URL
Additionally, the scammers have also moved to TinyURL:
Scammers are also using tinyurl to lead users to the scam application
Scammers are also using tinyurl to lead users to the scam application

Thursday, 24 March 2011

‘Granny Scam’ Uses Facebook to Target Seniors

The good hearts and generosity of grandparents are being exploited in a cruel new scam.

The “grandparent scam” occurs when an unsuspecting senior citizen receives an urgent phone call from someone claiming to be a grandchild. The impostor tells the grandparent that he is seriously hurt, or in jail, and desperately needs hundreds or thousands of dollars wired to him immediately.

Believing the caller to be their grandchild, the frightened grandparents wire money to the scammer.

“Scams in which criminals prey on senior citizens, manipulating their fears and stealing their savings, are among the most malicious in our society,” New Jersey Attorney General Paula Dow said.

Yesterday (March 23), Dow, with the N.J. State Division of Consumer Affairs and the Consumer Federation of America, launched a campaign to combat and educate against the grandparent scam.

While many traditional frauds – the Nigerian 419 scam, for example – are easy to detect and avoid, the grandparent scam comes with an air of authenticity that adds a frightening element of reality to an otherwise phony phone call.

Social networking sites offer a wealth of family information – often including the grandparents and grandchild’s name, address and date of birth -- that a scammer can use to effectively pose as the victim’s grandchild. Armed with those details, a frantic “Grandma, I need help” call creates an extremely vulnerable victim.

Speaking at the New Jersey campaign launch, Jim and Dorothy, a couple from Wayne, N.J., told the story of how they received a call on Feb. 15 from a young person pretending to be their grandson. He said he had broken his nose in a car accident, and was now in jail in Canada and needed $2,800 for bail. The scammer used specific family details obtained from the grandson’s Facebook page.

“We thought our grandson was injured, in trouble and in need of money and we wanted to help him,” Jim told CBS New York. Thankfully, before they wired any money, Jim and Dorothy contacted their daughter — the alleged grandson’s mother — and found their real grandson was in school — not in Canada — and that they’d been scammed.

To steer clear of the grandparent scam, the Consumer Federation of America urges people to ask detailed questions of the caller, questions no impostor could know – “the name of the person’s pet, for example, or the date of their mother’s birthday.”

It’s important also to report the scam to the money-wiring service the grandchild wants the victim to use.

[SecurityNewsDaily]

Wednesday, 23 March 2011

The Seven Deadly Sins of Cybercrime Victims

Like athletes and chess players, cybercriminals are skilled at identifying their targets’ weak points.
Today’s increasingly online and social world offers a host of techniques for preying on potential victims and their weaknesses.
Following are seven weaknesses that you need to watch out for to avoid falling prey to these scams — whether they take the form of emails, social networking chats, or phone calls.
  • Lust: Scammers try to tempt users into action by masquerading as an attractive man or woman, particularly on social networks. You should assume that a flirtatious advance from someone you don’t know has a less-romantic purpose behind it.
  • Greed: Like the adage says, “If something is too good to be true, it probably is.” If you receive a free iPod offer, or a percentage of a Nigerian wire transfer, resist the urge to make a deal.
  • Vanity: Scammers often try to convince potential victims that they have been chosen, that they’re winners, or that they are somehow part of a select group on the receiving end of an exclusive offer. As harsh as it may sound, you should assume you’re not that special.
  • Misplaced Trust: In some scams, cybercriminals attempt to convince you that they represent a high-profile brand and therefore can be trusted. Other times, scammers pretend to be a “friend of a friend” so that your trust for your friend extends to this unknown person. Question any message or phone call that plays on a trust relationship.
  • Sloth: Criminals rely on our laziness to ensure that poorly written messages and shortened URLs don’t rouse suspicion. For instance, many users will click on a link in an email from their “bank”, instead of calling the bank or visiting the bank’s website to determine if the email is legitimate.
  • Excess Compassion: In 2009, one of the most successful scams on Facebook involved criminals hijacking users’ accounts, then posting status updates claiming that the account holder was stranded somewhere and needed money. Many kindhearted people fell for this ploy. Other similar scams involve requesting donations to nonexistent nonprofits when a major disaster occurs, such as the earthquake in Haiti. Maintain a high level of skepticism toward these types of messages.
  • Urgency: Hand-in-hand with compassionate pleas are scams that insist on a fast response and tell you to “act now” or “time is running out.” Double-check these requests with the sender or a colleague, and don’t feel pressured to respond immediately.
Excerpted and adapted from the Cisco 2010 Annual Security Report


[InfoSecIsland]

Monday, 21 March 2011

Twitter users are not smarter than Facebook users - Profile views scam spreading fast

Hey Tweeple... yeah, those of you who like to dump on Facebook users all the time and prefer to trade your gossip on Twitter, I'm talking to you.

Thousands of Twitter users are falling once again for a scam that requires victims to grant access to a malicious application.

Today's scam seems to be a continuance of a trend in which the scammers are adapting their ego-driven bogus Facebook apps to operate on Twitter.

Just like on Facebook, Twitter users seem to be blindly allowing these apps to post to their accounts. The bogus app posts the following to the feeds of its victims:
"My profile was viewed ### times JUST TODAY! Click here to see how many views you got! http://tiny.cc/"
Twitter scam messages
We observed a similar scam earlier this month, so we expect to see increasing scams as Twitter gains more and more traction in the social networking space.
Twitter profile views page
If you accept the application, not only will it post to your Twitter feed, it will also display an image with a random number that supposedly represents the number of people who have viewed your profile.

Not surprisingly, the revenue generating opportunity for these scammers is a fake IQ test that suggests you could win a free iPad.

Upon completion of the test, you are asked for your mobile number, and if you read the small print you find out that they will send you a trivia question via SMS 4 times per week at $2 per question... about $32 a month. There is always a reason they want to trick you into propagating their scam and it is almost always money.

Twitter survey popup

The advice remains the same as for Facebook. Be cautious of which games/apps you approve and carefully audit the authorization page to see if an app wants control of your account or permission to post.

If you're an IT administrator and would like some free tools to help educate your users about safe usage of social media, download our Social Media Security Toolkit.

Oh, and if you're on Twitter and want to learn more about security threats, be sure to follow Naked Security's team of writers.


Creative Commons image of Twitter cigarette pack courtesy of CarrotCreative's Flickr photostream.


[NakedSecurity]

Scammers Pushing Fake AV Via Skype

Skype malwareRogue anti virus software companies have decided to "reach out and touch someone," according to a new report from Krebsonsecurity.com.

Groups responsible for pushing the bogus anti malware programs are using Internet-based phone calls over the Skype network to trick unsuspecting users into downloading their fraudulent wares, the site reports.

Skype users are reporting they’re getting automatic calls from vendors pushing rogue anti-virus, according to a post on Krebsonsecurity.com. The scam is not unlike an unwanted telemarketer call, with users asked to follow instructions given by the mechanized call. Those who fall for the ruse find themselves hit with a ubiquitous scareware page, warning them that their computer is infected and advising them to erase the threats from their computer. After clicking through the warning, users are sent to a “shopping cart” which convinces them to purchase their “professional online repair service.”

Previously spammers have used Skype to peddle their malware via online notifications, while larger projects, like spam campaigns and worms, have become more commonplace with the software.

[Krebs on Security] via [ThreatPost]

Sunday, 20 March 2011

Top Five Online Scams

#1 Nigerian Scams:


While these types of scams are generally understood to be Nigerian in nature and origin, and are in fact named after the 419 Nigerian code that made them illegal, advanced-fee scams happen right here in the good old USA by Americans presenting to offer jobs or may ask help to transfer money.


#2 Romance Scams:

If you ever hear talk like this, run far and fast: “In me sweetheart you are going to find the most passionate, loving and romantic man you have ever met. There are very few promises in life but this is one of them! ROMANCE is the key to my happiness and to my heart and soul!”


#3 Classified Ad Scams:

This story caught my eye: “An online scam targeting pet-lovers is circulating the web, and it could cost you more than a new pet. An ad posted to a local online classified website by a man who claimed he was living in Florida. He was willing to give the Labrador Retriever puppy named Dely away for the cost of shipping, which was $220.”


#4 Phishing:

Phishing continues to become more sophisticated, more effective, and more prevalent. In one example, criminal hackers waited until Pennsylvania school administrators were on vacation, then used simple money transfers to liquidate over $440,000 out of the districts accounts.


#5 Spear Phishing:

Spear phishing occurs when the scammers concentrate on a localized target, usually an individual with control over a company’s checkbook.

This insidious type of phishing occurs when a recipient clicks a link, either in the body of an email or on the spoofed website linked in the email, and a download begins.

Don’t be taken. Keep your head up and recognize when someone’s trying to take advantage of you.


Robert Siciliano personal and home security specialist to Home Security Source discussing home security and identity theft on TBS Movie and a Makeover.


[InfoSecIsland]

New teacher from behind Facebook likejacking attack leads to survey scam

This broken record continues to play. Yes, Facebook likejacking scams continue to plague Facebook users' walls. This one spreads to walls saying:
"New teacher from behind"
"(BADURL) When our new teacher terns towards a blackboard students are go haywire. VIDEO: New Teacher from behind"
Teacher from behind wall post
Unlike some of these likejacking scams, this one is using many different URL shorteners, including goo.gl, tiny.cc, tinyurl.com and even direct URLs to domains registered in .info and .ro top-level domains. At the time of this writing, over 6,000 people have fallen victim to the scam and the numbers continue to climb.
Teacher from behind clickjack
In a trend we are seeing more often in web-based attacks, this attack only requires that you are using a modern browser and are logged into a Facebook account. It works regardless of the operating system your device uses, including Windows, OS X, Linux, iOS, Android and more.

The best defense against clickjacking attacks is to use the Firefox browser with the NoScript add-on.
Otherwise, to avoid these types of attacks, the only remedy (which isn't exactly practical) is to be sure you are not logged in to Facebook when clicking unknown URLs. If you are not logged into Facebook, you are presented with a pop-up window asking you to login, which is an indication that it is an attempt to likejack your account.

Personally, I use one browser just for Facebook and a different browser for all of my normal internet activities. If I choose to follow a URL from a Facebook wall, I use my non-Facebook browser so I can be alerted to the attack, as well as having protection from NoScript on my side.

For more best practices on Facebook security, visit the Sophos Security Hub where we have our guide to Facebook security. To stay up to date with all the latest security news you can follow Sophos on Facebook.

[NakedSecurity]

Wednesday, 9 March 2011

Sloppy spelling scuppers DHL malware spam attack

Thank heavens for the poor education of cybercriminals!

If they had paid more attention to spelling and grammar at school (rather than mugging younger kids for their dinner money and inflicting chinese burns behind the bicycle sheds) then maybe some of their scams would be harder to spot.

Take this malware campaign that we are seeing being spammed out right now, for instance.

DHL malicious spam
Subject: DHL notification
Message body:
Dear customer.
The parcel was send your home address.
And it will arrice within 7 bussness day.
More information and the tracking number
are attached in document below.
Thank you.
2011 DHL International GmbH. All rights reserverd.
The email doesn't really come from DHL, of course. This is just the latest in a long line of instances where cybercriminals have distributed malware attacks posing as communications from a delivery firm such as UPS or FedEx.

But take a closer look. There are 37 words in the body of that message, four of which are spelt incorrectly. That's an almost 11% failure rate!

If the spelling mistakes and lack of professionalism weren't enough to get your security sixth sense jangling, then hopefully your anti-virus would have identitifed that the attached DHL_document.zip file contains malware.

Sophos products detect the ZIP file proactively as Mal/BredoZp-B, and its Trojan horse contents as Troj/Agent-QQG.

I, for one, vote against improving the grammar and spelling of cybercriminals. We can't rely on every malicious hacker being a poor communicator, but it certainly can help the general public identify when a message should be treated with suspicion.

[NakedSecurity]

Tuesday, 8 March 2011

Nigerian 419 scammer gets 20 years in jail

Nigerian national Peter Maxson Anyanyueze has just been sentenced to 20 years in prison by the National Prosecuting Authority (NPA) at Germinston Regional Court in South Africa.

According to several media reports, Anyanyueze received the following sentence: ten years for fraud, ten years for money laundering, and two additional years, which will run concurrently, for contravention of the Immigration act.

The scam seems fairly typical: Anyanyueze sent out emails requesting help to manage his cash. The scammer claimed he earned 10.5 million bucks from precious metal sales. His millions, he claimed in the email, were being held in a security company in South Africa, and he needed a third-party to move it out and invest it in Europe.

Saudi Arabian Dr Abdulazziz Alheiraqi Nwasser received this scam email and responded, probably thinking this sounded like a solid investment opportunity.

Instead of transferring the money into Nwasser's account, the scammer requested that he make small payments into nominated bank accounts, based in different countries around the globe.

Nwasser did just that, to the tune of almost $300,000!

I don't know about you, but it doesn't seem like a small amount of money. In any case, Anyanyueze never deposited the millions, so our victim Nwasser found himself seriously out of pocket.

So, what can we learn about this?

First, there is nothing really new here. Scams, where someone tries to dupe another, have been around as long as humans have. 419 scams simply take advantage of people though emails that try to pique recipients' greed or pity. The goal is always money, though that is not always immediately obvious.

If you don't know the person who has emailed you, and/or the email is promising riches for some small investment on your part, go on high alert. The simplest approach is to delete it, though you may also want to report it to your ISP so they can look into blocking these emails in future. Do not respond. You will only be confirming the validity of your email address to an unknown and probably dodgy third party.

***

Quite interesting side fact #1
According to Nigerian-law.org, it seems the Advance Fee Fraud act was established in 2006, three years after Anyanyueze was accused of doing this scam. He was however arrested in 2007, a year after the act was put in place. Hmmmm....

Quite interesting side fact #2
According to this report, the National Prosecuting Authority (NPA) spokesperson
"revealed Anyanyueze had fraudulently entered into a marriage of convenience with a female South African to obtain citizenship. 'The state proved in court that the accused and the female person were never in a bona fide spousal or marital relationship, as the female was living with her South African boyfriend with whom she had a child at the time of the said marriage.'"
As a result of this, they tapped on two extra years to his sentence, which he can serve concurrently with the other twenty.

[NakedSecurity]

10 scammers charged with running 419 scam

Ten people were arrested and are now facing charges of wire fraud in US federal court following a successful investigation that has them pegged as perpetrators of an advanced fee scam.



The ten are allegedly all part of the same gang that took advantage of the gullibility of their victims and convinced them to send modest - and not so modest - amounts of money in order to expedite the settlement of a huge inheritance in their name.

Usually dubbed "Nigerian" or "419" scam, it involves scammers posing as government officials or attorneys who are in charge of finding the heirs of wealthy people and settling the disbursement of munificent inheritances. The victims are taken in by their own greed and naiveté.

25-year-old Claudio Uche Dibe, of of Gardena, California, stands accused of being the ringleader of the gang and sending thousands of spam e-mails to potential victims. He is charged with 15 counts of wire fraud, as are 25-year-olds Bright Amesi, of Gardena, and Briceson Loving, of Lawndale. All three of them have been charged and plead not guilty to the charges.

Of the remaining seven, four have plead not guilty, and three are still waiting to be arraigned. All seven are facing charges on 10 counts of wire fraud each.

Among the evidence that supports the charges is and e-mail between the scammers noting that one victim was claiming after the initial small payment that he didn't have any more money, but that the sender believed him capable of sending "big money, which is what we are all after.”

[Net-Security]

Sunday, 6 March 2011

Fake HMRC website offers bank refunds

A friend sent me this link, which is an interesting spin on the old “HMRC tax refund” scam – a fake HMRC claiming your bank wants to issue a refund instead.




Click to Enlarge

As you can see below, they have a large selection of banks to choose from (in keeping with more common phish attacks):




Click to Enlarge

Everybody from NatWest and HSBC to Santander and Halifax are in there. Most of the bank specific pages all ask for the same kind of personal information, but if one of the banks asks for something unique to them (such as a banking PIN or other security feature) the phishers have taken care to include those too. If your bank isn’t included, no problem: they have a generic “catch-all” page for you to sign up to years of identity theft and a couple of days worth of “Who bought all this stuff on iTunes”?

Here’s a sample of the information asked for on the Barclays page:




Click to Enlarge

Deep breath: name, address, phone number, email (and email password!), national insurance number, information related to your parents, how long you’ve lived at your address, employment status / income, your full card details (of course) and everything related to your online banking account.

I think “Ouch” is the word we’re looking for.

HMRC do not issue tax refunds by email, they most certainly do not have websites where banks want to issue you with refunds, and they also know how to spell “being” (take another look at that second screenshot).

Avoid like the plague.

[ComputerSecurityArticles]

Saturday, 5 March 2011

Guy who took a picture of his face for 8 years FouTube Facebook scam


Guy who actually did take a photo every day for 8 yearsFacebook scammers have been at this game for a while now. They take an interesting YouTube clip that is gaining notoriety and try to cash in on the popularity by spamming it out on Facebook before most people have heard of it.

In the past we have seen it with the "I can't believe a GIRL did this because of Justin Bieber" and "Anaconda coughs up a hippo?" Facebook likejacking attacks based on popular YouTube videos.

This Facebook scam sends out messages on victims walls with the title "This Guy Took A Picture Of His Face Every Day For 8 Years" and includes a link to a scammer domain.

Facebook Wall post about guy who took his picture for 8 years
When you click the link you are lead to a FouTube page that is a near identical replica of the real YouTube site with a fake video player dominating the page.

FouTube likejacking page
Of course when you go to click the video it is actually just an image. The image links to some obfuscated JavaScript that displays a popup claiming it needs to verify your age.

Age Verification likejackWhat is actually happening is that you are clicking an invisible "Like" button hidden underneath the link you think you are clicking. This will post the message to your wall to continue the viral spread of the message to your friends.

Funny enough, there really is a video on YouTube of a man who actually took a photo of himself every day for eight years and it's pretty cool.

What is new about this attack is that they have managed to likejack you and lead you to a survey which will enroll you in a program to charge you for an SMS several times a week all in one click.

Stay vigilant, and if you are a Facebook user consider following us on Facebook.

[NakedSecurity]

Christina Aguilera got arrested video scam spreads virally on Facebook

Christina AguileraAnother day, another clickjacking scam on Facebook. This certainly seems to be becoming a successful model for scammers who want to earn some cash - and while it's working so well, why should they change their methodology?

The latest scam which innocent Facebook users are being tricked into clicking on involves a message about singer and actress Christina Aguilera, who earlier this week was arrested in Hollywood. Although Aguilera was later released, and told that she would not be charged, her boyfriend Matthew Rutler faces a drink-driving charge.

Here's what the scam looks like when one of your Facebook friends falls for it:
Christina Aguilera got arrested messages
WTF! I just saw a movie how Christina Aguilera got arrested which was minutes ago!! --> [LINK]
SHOCK!SICK! I just saw a movie how Christina Aguilera got arrested which was minutes ago!! --> [LINK]
WICKED! I just saw a movie how Christina Aguilera got arrested which happened minutes ago!! --> [LINK]
The links take your browser to a website which looks like a YouTube-style video portal, calling itself FbVideo.

Christina Aguilera got arrested video
As you're so interested in watching Christina Aguilera the worse-for-wear with drink, you might not hesitate to click on the video thumbnail. However, your click is being silently clickjacked into telling Facebook that you "Like" the webpage (thus spreading the scam virally) and you are presented with a survey which - if you complete it - will earn commission for the scammers.

A browser plugin like NoScript can prevent the clickjacking from taking place, but if you're not running something like that or not protected with software like Sophos then you may be unaware that you have reached a clickjacking page.

NoScript intercepts clickjacking
For many people who have left themselves unprotected, however, the damage is done and you have helped the bad guys spread their scam across Facebook.

Your Facebook profile has been updated to say that you "Like" the video, and your friends may also now be tempted into clicking on the link.

Christina Aguilera post
If you fell for the scam, you should clean-up your Facebook page as quickly as possible. Fortunately ot's not that tricky to remove the post from your newsfeed and unlike the page.

Unlike Christina Aguilera page
Make sure that you stay informed about the latest scams spreading fast across Facebook and other internet attacks. Join the Sophos Facebook page, where more than 60,000 people regularly share information on threats and discuss the latest security news.

You could also do a lot worse than check out our best practices for better privacy and security on Facebook guide.

[NakedSecurity]

Thursday, 3 March 2011

Beware Top 10 Profile stalkers on Facebook and Twitter

Following the “11.6 hours” scam which flourished on Twitter yesterday, you would hope that everyone would be wise to the threat of allowing unknown apps unfettered ability to post to your social networking account.

However, I wouldn’t be surprised if we see more and more scams which attempt to increase their chances of success by targeting both Facebook and Twitter users at the same time.

For example, here’s a scam which is spreading virally on Facebook right now.
Top 10 profile stalkers - Facebook
Cool,man I cannot believe that you can see who is viewing your profile. ! I just saw my top 10 profile stalkers and I am SHOCKED that my Ex is still viewing my profile :O ! You can see WHO VIEWED YOUR PROFILE here--[LINK]
If you click on the link you’ll ultimately share the link from your own account and be required to take a revenue-generating survey scam. We’ve discussed these sorts of scams many times before, of course, and provided details of how to clean-up your Facebook profile afterwards.

Meanwhile, earlier today, a very similarly phrased scam was spreading on Twitter with the same intention of making money for the bad guys.

Top 10 profile stalkers - Twitter
I just viewed my TOP 10 Profile STALKERS - [LINK]
The good news is that the links being used by this scam on Twitter appear to have now been blocked by bit.ly (although they may, of course, spring up again under a different guise). If you did manage to reach the destination that the scammers wanted, however, you would have been urged to connect a third-party application with your Twitter account.

Who viewed your Twitter profile?
Giving permission to such an app is just what the scammers want, and the app doesn’t waste any time exploiting the opportunity to post to your Twitter account – spreading its link even wider.

Scam tweets on Twitter
Meanwhile, the promise of discovering who are your top 10 profile stalkers on Twitter might be enough to tempt you into taking a survey which earns money for the scammers.

Who viewed your Twitter profile survey
Needless to say, you never do find out who has really viewed your Facebook page or Twitter profile – but you have helped put some cash in the pocket of the scammers.

Don’t encourage them to distribute scams like this, and always exercise caution about which third party apps you allow to connect with your social networking accounts.

If you’re on Twitter and want to learn more about threats, be sure to follow Naked Security’s team of writers. Meanwhile, Facebook users would be wise to join the Sophos Facebook page, where we give early warning about new threats.

[NakedSecurity]

What the bad guys like?

The answer is they like the like button itself and the most of all they like to make you to click on it when you think that it is something else.

Scheme of this scam is simple. Take one picture, add a shocking title for example "Look what happens when father catches doughter on her webcam" or "I cant believe a LITTLE GIRL did this because of Justin Bieber".

Clipboard01

Clipboard02
Do some black magic with the page code to make the facebook button hidden and moving on the background of that picture and you can be sure that your page will be liked like any other.

Clipboard07
Clipboard03
This technique is called the Clickjacking and is prevelant these day. Despite the fact AVG stops these attacks we recommend to be more careful while browsing and clicking and of course make sure your AVG is up to date.

[ComputerSecurityArticles]

Wednesday, 2 March 2011

Scam emails can now be forwarded to the Police


Action Fraud - the UK’s national fraud reporting centre run by the governmental National Fraud Authority - has recently set up a dedicated e-mail address to which users are encouraged to forward every scam e-mail they receive.

The e-mails sent to this address - email@actionfraud.org.uk - are forwarded to the National Fraud Intelligence Bureau run by the City of London Police, which then engages in analysis in order to extract possible evidence from the messages, to think up ways for fraud prevention, for disruption of links between fraudsters and victims and for targeting the fraudsters' networks in the future.

"The NFIB analyses this information, searching for patterns and similarities between reports, which come from across the country. Intelligence packages are formed from the data and sent to relevant law enforcement agencies such as the police and Serious Organised Crime Agency," says Action Fraud, and adds a few tips on how to spot fake e-mails:

Fake e-mails often (but not always) display some of the following characteristics:
  • the sender’s e-mail address doesn’t tally with the trusted organisation’s website address
  • the e-mail is sent from a completely different address or a free web mail address
  • the e-mail does not use your proper name, but uses a non-specific greeting like “dear customer”
  • a sense of urgency; for example the threat that unless you act immediately your account may be closed
  • a prominent website link. These can be forged or seem very similar to the proper address, but even a single character’s difference means a different website
  • a request for personal information such as user name, password or bank details
  • the e-mail contains spelling and grammatical errors
  • you weren't expecting to get an e-mail from the company that appears to have sent it
  • the entire text of the e-mail is contained within an image rather than the usual text format
  • the image contains an embedded hyperlink to a bogus site.
According to the National Fraud Intelligence Bureau, only four days after the setting up of the dedicated e-mail address it has already received 19,000 scam e-mails.

“We thank the general public for this overwhelming response and urge them to keep on forwarding us their scam emails," said Detective Superintendent Tony Crampton, Director of the NFIB. "These will all be analyzed at the NFIB and the resulting intelligence will be used to disrupt the architects of these crimes.”

Twitter 11.6 hours survey scam spreading virally

Twitter users should be vigilant following the outbreak of a scam that is spreading links from users' accounts without their knowledge. The scam, which has already caught thousands of Twitter users off guard today, dupes users into clicking on links, believing that it will reveal how many hours they have spent on Twitter.



The offending links are being circulated on Twitter in messages containing the following text:

"I have spent 11.6 hours on Twitter. How much have you? Find out here: [LINK]"

However, if users click on the bit.ly link being used in the message, they are taken to a page which attempts to connect a rogue application called 'Time on Tweeter' with the user's Twitter account.

The application instantly tweets a message from the victim's Twitter feed, claiming that they too have spent 11.6 hours on Twitter, while also directing the victim to a page which presents a revenue-generating survey on behalf of the scammers.

"Affected users need to revoke the rogue application's access to their Twitter account immediately, or it will be able to spew out more links from your Twitter page - which could promote spam sites or link to malicious webpages," advised Graham Cluley, senior technology consultant at Sophos. "Scams like this are very commonly encountered on Facebook, but are more rarely seen on Twitter - meaning that many users will be sitting ducks to this type of attack. Although Sophos is in contact with bit.ly about closing down the offending link, it's possible that the scammers will use other links and other names for their rogue applications. So be on your guard, and always think twice before allowing a third-party app to have access to your Twitter account."

[NetSecurity]