Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

06 November 2014

New technique makes phishing sites easier to create, more difficult to spot.


Posted on 05 November 2014.

Researchers have spotted a new technique used by phishers which could trick even more users into believing they are entering their information in a legitimate web form.

Instead of replicating as faithfully as possible a legitimate website - for example an e-commerce site - the attackers need only to set up a phishing page with a proxy program which will act as a relay to the legitimate site, and create a few fake pages for when users need to enter their personal and financial information.


"So long as the would-be-victim is just browsing around the site, they see the same content as they would on the original site. It is only when any payment information is entered that modified pages are displayed to the user," Trend Micro Senior Threat Researcher Noriaki Hayashi explains.

"It does not matter what device (PC/laptop/smartphone/tablet) or browser is used, as the attacker proxies all parts of the victim’s HTTP request and all parts of the legitimate server’s response."

In the spotted attack, users are directed to the malicious site by clicking on a search result they got by entering a product's name. The attackers used a number of blackhat SEO techniques to make the URL appear in the results. But spam emails and messages can also be used to lure potential victims to the malicious site.

The actual attack begins when the user clicks on the “Add to Basket” button on the legitimate site - the attacker has re-written the function so that the user is redirected to a spoofed e-cart page that leads to more fake pages simulating the checkout process.

The first page asks the victims to enter their personal information (name, address, phone number) as well as their email address and password. The second one requests the entry of credit card information (including the card's security code). The third one asks for additional information that is sometimes required to authorize a transaction.

Once the victims have submitted all this information, they will receive a fake confirmation email for the purchase to the email address submitted - and the illusion is complete.

"So far, we have only identified this attack targeting one specific online store in Japan. However, if this attack becomes more prominent, it could become a very worrying development: this makes phishing harder to detect by end users, as the phishing sites will be nearly identical to the original sites," Hayashi noted.

This approach makes phishing websites much easier to set up, and very difficult for the owners of the legitimate websites to detect. 

Undoubtedly, we'll be seeing more similar attacks in the future.



12 October 2014

How To Protect Yourself From Phishing Scams


By: Nadia_Kovacs            Posted: 30-Sep-2014 | 10:16AM 

October is National Cyber Security Awareness month. Phishing is one of the oldest tricks in the Internet book that tries to trick you out of divulging your personal information. This is part 4 in a series of blog posts we will be publishing on various topics aimed at educating you on how to stay protected on today’s Internet landscape.

Phishing is essentially an online con game and phishers are nothing more than tech-savvy con artists and identity thieves. They use SPAM, malicious web sites, email messages and instant messages to trick people into divulging sensitive information, such as bank and credit card accounts, usernames and passwords.

How Do You Know It’s A Scam?

There are different forms of phishing tactics. Criminals may try to trick you into giving away your personal information via emails, Social Media messages, IMs, text messages, and even Internet chat rooms. Sometimes criminals may try to fool you into installing a malicious program, known as spyware, which can track and record the information you enter into your computer. Below are some of the commonly used tactics and warning signs you should be on the lookout for:

  • Phishers, pretending to be legitimate companies, may use email to request personal information and direct recipients to respond through malicious websites. Phishers have been known to use real company logos, and will also use a spoofed email address, which is an email address that is similar to the actual company’s address. However, the address may be misspelled slightly or come from a spoofed domain.
  • Emails may come in the form of a help desk support ticket, a message from your bank, or from someone soliciting money via a 419 scam.
  • Phishers tend to use a call to action. You may get a notice that an account is being shut down and you need to log into it to avoid that from happening. They may also request personal information in order to verify your identity.
  • Phishing websites can look remarkably like legitimate sites because they tend to use the copyrighted images the original sites.
  • Fraudulent messages are often not personalized and will often have misspellings of words and company names.

How Do You Know If You Have Spyware?

Spyware can be downloaded from web sites, email messages, instant messages, and from direct file-sharing connections. Additionally, a user may unknowingly receive spyware by installing a software program, and the spyware piggybacks onto that installation as additional suggested software. Users may also be unaware that some browser add-ons contain spyware.

Spyware frequently attempts to remain unnoticed, either by actively hiding or by simply not making its presence on a system known to the user. However, sometimes there can be signs that you may be infected:

  • Your computer starts to run slower than usual.
  • You start to receive an unusual amount of pop up ads.
  • There are new toolbars on your browser that you did not install.
  • Your browser’s home page has changed to a page that you are unfamiliar with.
  • Your web searches become redirected to other spam sites.

How Do I Avoid Spyware?

  • Be selective about what you download to your computer.
  • Watch out for anti-spyware scams.
  • Beware of clickable ads.
  • Use Norton Security to provide anti-spyware protection and proactively protect from other security risks.
  • Do not accept or open suspicious error dialogs from within the browser.
  • Spyware may come as part of a "free deal" offer - do not accept free deals.
  • Keep software and security patches up to date.

How Do I Protect My Privacy?

If you happen to run across any of these red flags, here are some tips to keep yourself safe and protect your privacy:

  • Never give out any personal information via email, social media platforms, text messages or instant messages.
  • If the call to action is to click on a link and sign into the site with your username and password, never click on the link. Instead, go to your web browser and type in the website’s URL. Be sure to look for the verified https:/ at the beginning of the URL in the task bar.
  • Never download a program or file from a suspicious email. These may contain programs such as spyware and keyloggers.

How Can You Help?

Please contact the Symantec Security Response team if:

This is part 4 of a series of blogs for National Cyber Security Awareness Month (link is external).

For more information on various topics, check out:
5 Ways You Didn't Know You Could Get a Virus, Malware, or Your Social Account Hacked
How To Choose a Secure Password
How To Avoid Identity Theft Online
How To Protect Yourself From Cyberstalkers

21 March 2012

Phishing gang steals victim's life savings of $1.6M



The 12 men and two women were detained on Thursday morning in raids in London and the West Midlands. More arrests may follow in the coming days, according to Metropolitan Police Central eCrime Unit (PCeU) head Charlie McMurdie.


"These were dawn raids," McMurdie told ZDNet UK. "Enquiries are still ongoing regarding potential further arrests."

The phishing gang sent out unsolicited emails with links to a fake banking website. It used a series of bank accounts assigned to individual 'money mules' to launder £1m siphoned from the life-savings account of one woman who had divulged her details. The cash was transferred via the internet, the Metropolitan Police said in a statement.

"The stolen money was spent over a three-day period, after suspects embarked on a spending spree during the Christmas sales," the Met said. "The victim, a UK citizen currently living abroad after relocating to care for an ill relative, saw her savings disappear overnight after her bank account details were illegally obtained and unauthorised access to the account was gained."

The suspected 'money mule' launderers received between £9,000 and £75,000 each from the account. All of the 14 suspects were in custody at the time of writing, according to the Met.
 
Around 150 police officers were involved in the operation. They included members of the PCeU, 50 special constables, and police from three regional e-crime hubs in the East Midlands, York and Humber, and the North West.

"We wanted to make the best use of resources in relation to where the suspects were located," McMurdie said.

The police said the "sophisticated" phishing operation highlighted the need for people to take care when doing banking online, warning the public not to click on links in unsolicited emails.


"This is an example of how cybercrime creates real victims through the indiscriminate actions of the criminals involved," Detective Inspector Stewart Garrick said in the PCeU's statement.

Article Source.
Dawn raids net 14 suspects in £1m phishing thef
Security Threats | ZDNet UK http://goo.gl/MYzKu

15 February 2012

Identify a Phishing Message in Five Steps

From IT Business Edge

Spear phishing, a type of email spoof, targets individuals or departments within organizations and attempts to elicits a desired action that could install malware, compromise login names and passwords and steal data. Use Paul Mah's simple checklist to spot potential phishing messages.

From the network breach at RSA to theft of intellectual property in Operation Aurora, it is no secret that some of the most visible hacking involves the use of spear phishing. A targeted form of phishing that is custom-made for a specific organization, a spear phishing email message seeks to elicit a desired action that could result in a Trojan being loaded, or the unintended leaking of confidential or privileged data.
As Paul Mah has written in the past, defending against spear phishing is a challenging task that mandates some amount of user training. To assist organizations on this front, Paul has come up with a simple checklist to help identify a potential phishing message.

To have access to  Paul's  checklist visit the following URL:
http://goo.gl/lmpZR


14 February 2012

This February 14 be a Valentine not a Victim

As Valentine’s Day approaches, Better Business Bureau of Southern Arizona warns that Cupid’s arrow may be aimed directly at consumers’ wallets. Those who find themselves awash in love’s emotion should remember that con artists thrive on the fact that emotion can trump logic.

There are three categories of scams that we all should be aware of at this romantic season as well as throughout the year.

Online Dating
Their photo may be attractive and their story may sound compelling but that person you met through an online dating site may turn out to be the very opposite of your soul mate. Photos, profiles and stories can be easily faked on dating sites. One common tactic is to claim to be a successful overseas businessperson with no family.

After what seems like sincere conversation in which many questions are asked of you, the scammer can skillfully employ psychology to say precisely what you want to hear.

Once the ice is broken and a comfort level has been reached on your part, the heart of the matter is arrived at: they need financial assistance. They may want you to cash a check for them or otherwise help them out of a financial difficulty. It could be travel expenses, medical expenses or some other type of debt. At any rate it is your money less than your heart that they are after. MoneyGram, one of the major global money transfer companies, has estimated that romance scams defraud victims of over $10,000 for each occurrence. For those so victimized, whatever the amount, a website called romancescams.org can be helpful.

Online Florists
When love is in bloom many rely on the traditional symbol of thoughtfulness, the bouquet, to convey their feelings for that special person. But be aware that online florists are not always reliable. If the flowers that are actually received by your loved one are inferior arrangements from those ordered, or even not delivered at all, it can be a wilting experience.

Scammers may send you emails saying that the flowers you ordered cannot be delivered unless you log in to their site and re-enter your credit card information. These emails are sent out in large numbers hoping to eventually find the inboxes of someone who has really sent flowers to their sweetheart. They are playing on consumers emotions by planting the fear that the bouquet may not reach the intended and that person will feel forgotten on Valentine’s Day. If you think the message may be legitimate, go to the florist’s website or give them a phone call, using the original site from which you ordered rather than the link on the email.

The best way to assure that flowers reach your beloved just as you ordered them is to rely on a local florist. A website devoted to uncovering florist scammers can be found at floristdetective.com.

E-card Scams
Phishing attempts abound around the e-card industry. A frequently used technique is to email a message saying you have a card waiting to be viewed. You are then directed to a fake website that resembles a popular site like Hallmark or American Greetings.

Once you are there a prompt tells you to download the latest version of Flash Player in order to view the e-card. Click that link and a virus is quickly downloaded and attacks your computer. Instead of having your loved one steal your heart, a scammer has stolen your identity.

Consumers should always exercise care in opening emails, links or attachments from those you do not know. Especially suspicious are unsolicited messages with subject lines saying “Someone just sent you an e-card” or “Send your loved one a Valentines Card today.”

Avoid becoming victimized by scammers who rely on the old adage that “love is blind.” Keep a clear head and open eyes this Valentine’s Day. Contact BBB by calling (520)888-5353 with questions or concerns if you think someone is going less for your heart and more for your wallet.

Source Article: http://goo.gl/zaSED by   

13 February 2012

Hackers Ask 'Will You Be My Valentine?'

by Tony Bradley (PC World (US online))

With Valentine's Day around the corner, cyber criminals are ramping up spam, phishing, and other attacks targeting the lover's holiday.

There are only five days to Valentine's Day. Those of you who are shocked by that revelation are prime targets for Valentine's Day related spam and phishing attacks as hackers hope to catch you with your guard down for this day of romance.

Messages targeting Valentine's Day are expected to quadruple globally in the coming days -- in part because cyber criminals are adept at targeting holidays and current events as bait for attacks. An offer for a dozen roses for $5 might get some traction any time of the year, but with the clock quickly counting down to Valentine's Day it has much higher odds of duping frantic lovers in search of a last minute gift.

A blog post from McAfee warns, "Many consumers look for a little romance on Valentine's Day, whether it is a thoughtful gift, a romantic getaway, or a heartfelt e-card, but if you're looking for these things online, beware."
McAfee points out a number of types of Valentine's Day themed threats you should be aware of:
 Phishing Scams

Attackers will send out spam promoting bargains for flowers, romantic dinners, jewelry, or other Valentine's Day gift related themes. Clicking on the offer might take you to a malicious site that could compromise a vulnerable PC, or it could take you to a site that looks legitimate, and asks for your credit card, and other personal information to "complete the order".
Malicious eCards

Any holiday that traditionally involves giving and receiving cards is a prime target for cyber criminals. Everyone loves to receive a personalized greeting card -- especially if it seems to be from someone that may be romantically interested.
Seriously, though, what are the odds that someone you don't know decided to send you an ecard for Valentine's Day out of the blue? Right.

Mr. (or Mrs.) Wrong

Another scam to watch out for are fake profiles on online dating sites. Cyber criminals create online dating profiles designed to be as attractive as possible to lure unsuspecting love seekers. The idea is to make connections, and establish trust as a means to further criminal activity.

McAfee outlines some additional threats to watch out for in its blog post. To steer clear of Valentine's Day cyber threats, follow the basic principles of online common sense. Don't open emails or file attachments, or click on links from people or sources you are not familiar with -- and even if you do know the sender, think twice about whether that person would really send you a Valentine's Day email.

Another basic rule is that if it sounds too good to be true, it probably is. Don't fall for unbelievable last minute Valentine's Day gift ideas no matter how desperate you are for a gift.

Protect your wallet, your identity, and your heart by avoiding Valentine's Day cyber scams. 

Source Article: http://goo.gl/NEVuU

10 February 2012

Free Email Providers Launch DMARC.org To Prevent Phishing Scams

Leading free email providers like Google, Microsoft and Yahoo are teaming up in an effort to prevent “phishing” scams. As WWJ’s Rob Sanford reports, the unprecedented effort was announced this week.

The companies have created a working group – DMARC.org – to promote a standard set of email technologies that they say will lead to more secure email.

According to its website, DMARC, which stands for “Domain-based Message Authentication, Reporting & Conformance,” standardizes how email receivers perform email authentication. This means that senders will experience consistent authentication results for their messages at AOL, Gmail, Hotmail, Yahoo! and any other email receiver implementing DMARC.

With the rise of the social internet and e-commerce, spammers have a tremendous financial incentive to compromise user accounts, enabling theft of passwords, bank accounts, credit cards and more. Email is easy to manipulate and criminals have found spoofing to be a proven way to exploit user trust of well-known brands. Simply inserting the logo of a well-known brand into an email gives it instant legitimacy with many users.
CNET executive editor Molly Wood said phishing is threatening the legitimacy of email.

“I think it’s hard sometimes for these companies to work together. They don’t always think it’s in their best interest to come together, but I think it’s gotten to the point now where phishing scams are so prevalent, that all of these companies are worried that their customers are going to stop trusting their legitimate email,” said Wood.

The arrangement will not stop all spam or phishing but will stop what they call a “significant chunk” of malicious messages sent.

DMARC helps email senders and receivers work together to better secure emails, protecting users and brands from painfully costly abuse. Find more information at DMARC.org.

Source: http://cbsloc.al/zhdnzo

08 February 2012

Sir Spamalot and Lady Phishing


I am a millionaire. Actually, I’m a multi-millionaire. Or rather I could be if I helped the honorable Mr. Nagumba get his money out of Nigeria, or helped Barbara get her money out of Brazil, or picked up my unclaimed lottery winnings, or helped another half dozen people in the last month. 

I have won $1500 several times a day for the last few months. I have won a new car. I have important packages waiting to pick up from FedEx and UPS. I am being audited by the IRS and they sent me an attachment that included an executable notice with instructions. I won a 15 day cruise if I qualified – they only needed a credit card number to confirm my identity and that I am over 18. I can get my teeth whitened or Lasik eye surgery for 80% off. I have qualified for a special deal on a new BMW 335 with experimental pricing, and can get in a brand new one for under $15,000. Two of my credit cards have been compromised so I needed to log onto the included website to verify and change my account information. As a matter of fact, another credit card that I don’t even have was also compromised, and I needed to log on there too. One of my bank accounts appears to have some out-of-date information associated with it. I can get really cheap Viagra (sic) cheap online, Heather thinks I’m hot, and there seems to be way too many people interested in my manhood.

Analyzing Spam
My personal spam folder is pretty thin. I try to trim spam aggressively. Just in the last 24 hours I have received 42 emails. Three from family, 21 advertisements from retailers (it’s beyond me why I need a daily reminder from a retailer telling me that they are still open and selling the same stuff they’ve been selling for the last five years), and 18 spam. Now, I have no idea how much spam my ISP trims before it even gets to me, but I assume it is a lot. A quick search shows unofficial estimates that spam is somewhere between 60 and 97% of all email sent. By the best accounts I can find, that means around 40 billion spam emails every day (give or take a few billion). The numbers are down slightly from 2010 partially because three botnets (Rustock, Lethic, and Xarvester) have been somewhat throttled. The closure of spam specialist Spamit helped as well. But, as we all know, spam has not gone away.

Unfortunately, spam means money. Spam brings with it a variety of issues, but it also delivers chunks of money and other opportunities to those who generate it. Pay-per-click sites still exist, and if you send 100 million spam messages and get 1% of recipients to click through – ka-ching! Say you send 50 million spam messages that contain a link for a free virus scan, and you can get .5% of those recipients to follow through with a fake purchase for ONLY $29.99 – that’s $7.5million – ka-ching! Credit card information is not worth what it used to be, but if you can send 100 million fake “change your password” notices to BigBlueBank customers, and 1% of them go through your fake link and update their password – ka-ching! And even if they can’t get something from you, maybe they can compromise some low percentage of recipients with a Trojan or sniffer. The numbers add up quickly because of volume.

But spam and phishing emails are not always obvious, are they? Well, some of them are. If the email subject line includes things like “Cialis” or “Replica Handbags” I think the chances it is spam is probably something around 100%. But do we always know? I included an example of a recent phishing email I received (names have been changed). It looks pretty good at a glance, but there is a lot wrong with it if you pay attention.

Let’s look through it in detail.
Spam Example
Let’s work on the premise that the logo and all the colors are correct, and that at a glance, this looks authentic – it appears to be an email from BigBlueBank, where you have an account registered with online access. What is wrong with the email?

1. BigBlueBank Online may be the correct name, but the chances that return email address is correct is low (read “low”, think “nonexistent”). Notice that it is @onlinesvc.com. If this was really from BigBlueBank chances are pretty good that it would be @BigBlueBank.com. If the return address just shows as BigBlueBank Online, hold your cursor over the name. The actual associated email address should show in a mouse-over or in the lower left corner of your browser.

2. “To: undisclosed-recipients” - If this was genuine, it would actually be to your specific email address, and NOT show as a bulk email with hidden addressees. Check what you bank emails you now – they are all to your real email address.

3. “UPDATE YOUR INFORMATION!” – This pushes an immediate sense of urgency. Not necessarily a blazing orange flag, but it should raise your skepticism when you get an email so obviously trying to raise your personal sense of alarm.

4. “This message is a critical one…” This is obviously a person to whom English is not their primary language. Normal English phrasing would be “This is a critical message…”. If BigBlueBank is based in South Carolina this should get your attention. If they are based in Germany, it probably still should, but not quite as much.

5. “It has come to our attentions,” “This require” - The extra “s” on attention and the missing “s” are perfect examples of disagreement in tense, and errors. These are strong indicators that the writer is not a natural English speaker, and that whoever sent the email did not spend enough time proof reading and editing the content. If BigBlueBank is a top 10 bank in the Americas, what are the chances that they would not have a proof reader check everything that went out (Hint: the answer is 0%).
6. “Your Account information” and “The Account update…” – What is with the random capitalization of “Account”? Errors like this should be blazing a hole in your brain by now.

7. “Is also a new BigBlueBank” – This is just an awkward sentence. Read the whole sentence from the email. Perhaps “the account update also includes” or something similar, but again, it is an error in grammatical construction that should tell you this is not a professional email.

8. “Services security statement…” – Again with the random capitalization of “Services”? Brain. Hole. Burning.

9. “Goes according” – Perhaps if it read “is in accordance” this would not raise alarms, but the misuse of the “ing” is a common error for a non-natural English speaker.

10. “On our terms of service” – “in” our terms of service would be appropriate for an English speaker, and even more appropriate in a professionally prepared communication.

11. 5:55 AM 20/01/2012 – This is actually the first thing I saw in the email that made me say “fake”. The date is shown as day/month/year, which is predominantly European or other international convention. Standard in the United States would be 01/20/2012. I know the other way sorts better, but it is aberrant construction in the U.S. If you are not from the U.S., this probably does not bother you as much as it did me.

12. “May result on a suspension of your account” – “on” is again wrong. A natural English speaker would say “in”. This also implies a threat designed to increase your sense of urgency and decrease your vigilance.
13. BigBlueBank Upgrade Home – Look at that. How convenient it was of them to include a link back to Bigbluebank for you. Just hold your mouse over the hyperlink (don’t bother; it won’t work on the example, since the hyperlink has been removed). By now you realize the chances that the link actually has anything to do with bigbluebank is exactly 0%. In the example of this email, it actually linked to something like the following – the fact that bigbluebank is not the domain should be an obvious clue: http//generalupdates.gh.ost.de/bigbluebank/account_update/index.php.

14. 1-888-XXX-XXXX – Very nice to have an included phone number. It really does help make the whole thing look better. Especially if you dial the number and someone in a call center answers it “Big Blue Bank – Customer Service, how can I help you?” First of all, check the provided number against the customer service number on your bank statements or against the number provided on Bigbluebank’s real website. It may be close but it will not match. Your second clue is that someone actually answered the phone and you did not have to go through a Voice Response system – when was the last time that happened?

15. “Will be helping” – there is that “ing” again. “This will help us” would not raise alarm, but the improper English should have your spinal column on fire by now. You should almost expect it say to “will to be helping us” like some alien speaking through an electronic translator.

If in doubt, bring up the genuine bigbluebank.com website by typing it into your browser yourself (completely ignoring their link, if you please), and check for information there. Locate their contact information to email, or call them to ask if they sent the information. Chances are that bigbluebank has its own security group that is interested in abuse and phishing emails. They may want you to forward a copy of the email to them for their own review if you feel like going that far.

Perhaps this was not the best example because this email was chock full o’ clues. But these are exactly the types of indicators you will see in many phishing emails. The fact that you even got this email should immediately raise your level of awareness, so everything else should follow.

06 February 2012

Be on the Lookout for Phishing Emails

Posted on: February 2, 2012 in Industry Issues by Chris Williams

If you keep up with tech news, you might have seen the story recently about a new technology standard developed by Microsoft, Yahoo, Google, and Facebook to cut down on spam emails and phishing attempts. It’s an exciting new technology that will help protect users by increasing checks and reporting on sent emails.

However, even with stricter standards for spam filtering, the occasional phishing email might still find its way to your inbox. Phishing emails are standard emails from people trying to convince you to give them information like passwords, usernames, credit card numbers, social security numbers, or other secure data. Every email user needs to know how to spot phishing emails so they can be deleted.

Here are five easy things to look for that you can use to spot phishing emails before you respond with sensitive information.
Emails from companies or people asking for information they should already have, such as accounts and passwords – a company will never ask you for your password.

Emails asking for personal identity information –  your date of birth, bank account information, social security number, or other personal information. There’s no reason to ever give personal information via email.
Emails with weird formatting, spelling mistakes, or bad grammar – most phishing attempts come from overseas, so they often contain mistakes a native English speaker wouldn’t make. Others are hurriedly prepared, so they may contain mistakes as well.

Links or attachments you didn’t request – never click on a link in an email, or open an attachment, if you didn’t request for a link or attachment to be sent to you.

Unknown senders or strange domain names – if the domain name of the sender looks strange, or the sender is unknown to you, learn more about the sender or company before you take action. If it looks strange, delete or report the email.
Here’s an example of a phishing email:
For more information on spotting a phishing email, check Microsoft’s support page. If you’re a Google user and receive phishing emails, you can learn how to report them to Google here.

Remember the first step is staying vigilant. Don’t provide personal or sensitive information through email if you can avoid it, especially to people you don’t know.

...don't forget to leave a comment... thanks.

27 January 2012

Phishing Attacks Can Happen On Your Mobile Phone Too



A few years ago most of the general public had never even heard of a phishing attack. These days it is better known. While still not a general knowledge question it has been exposed a little bit more by the media and web safety outfits. But just because the problem has seen a little bit more daylight does not mean that it has gone away. No, the problem of phishing attacks is still with us. And while that is still very much a problem, the bigger problem is that now it is starting to move to a new medium.

Phishing Attacks Can Happen On Your Mobile Phone Too

The mobile phone is becoming more and more the popular choice to surf the web. What better way to waste time than to surf the web while you are on the go. It is because of this activity that you are starting to see more web sites optimize for smaller screens. But it is not only the legitimate web sites that are focusing on the phone. The criminal web sites are as well.

Surfing the web on your mobile phone is no longer a time when you can have your defenses down. In the past when people would surf the web on their mobile phones they pretty much knew that the attacks that were directed at users of Windows and Apple computers could not hurt them. That is no longer the case. Hackers know how to code for the phones now. But it is the web based attacks like phishing that can hurt you no matter what platform you are on.

What is a phishing attack?

A phishing attack is when one web site pretends that it is another. A victim will go to that web site, thinking that they are safe but instead they are really giving up all of the information that they type in that site.

And that is why a phishing attack works on any platform no matter if it is your desktop or your phone. It is strictly a web based attack to obtain information. No matter how you give them the information it is still going to work. The platform of how you give them the information is secondary.

If you want to be able to avoid a phishing attack then the easiest way is to make sure that you pay attention to the web address of the site that you are on. Also, if you get an email and it says to click a link to go to the web site, instead just type the name of the web site in. Then you know exactly what site you are going to.

Source Article: Security-faqs

25 January 2012

How to Boost Your Phishing Scam Detection Skills



Phishing scams—the ones that try to get you to provide private information by masquerading as a legitimate company—can be easy to uncover with a skeptical eye, but some can easily get you when you let your guard down for just a second. Here's how you can boost your phishing detection skills and protect yourself during those times when you're not at full attention.


Want to test your phishing IQ and find out what kind of scams you're most likely to miss? Take this test.

What You Can Do

The way most phishing scams find victims is through email, but sometimes you'll come across a phishing site in the wild as well. Either way, here are the basic principles you want to follow to keep a cautious eye out for these malicious traps.

Check the URL

Phishing scams are designed to look like official emails and web sites from actual companies, but they aren't actually those things—they're just imitations. Because the emails and web sites are imitations they'll probably look a little different from what you'd expect in general, but more importantly those sites can't have the same URL as the web site they're pretending to because they are different sites. To check the URL, just hover of the link you're thinking of clicking. At the bottom of your window you should see the URL displayed. Once you do that, you have to figure out if it is a good URL or a bad URL.


Using PayPal as an example, you'll generally see http://www.paypal.com as part of the URL.

Sometimes you'll see something like http://subdomain.paypal.com as well. Both of these URLs are okay, because they end in paypal.com. A phishing URL, however, might look something like this: http://paypal.someotherdomain.com. In this case, "paypal" is attached to another domain name (someotherdomain.com). URLs like this are the ones you want to avoid.

Always Go Direct

How to Boost Your Phishing Scam Detection SkillsThe best thing you can do to avoid phishing scams is always go directly to the web site you want to visit rather than clicking a link. This way you don't have to figure out if the URL is safe or not because you'll be using a URL in your bookmarks (or your brain) that you already know is safe. Doing this can also help protect you from phishing scams when you let your guard down because you'll be in the habit of visiting sites directly rather than clicking links.
I fell for a phishing scam once when I read the email right after I woke up in the morning. It was from my bank and they'd sent me a lot of verification notices lately since I'd been traveling and using my debit card all over the place. When I got another one, I didn't even think about it because I'd just woken up. I went to the site, filled in my info, and then immediately realized I'd just provided that information to a phishing scam site. I called the bank to let them know right away and got a new card, but had I changed my default behavior to calling the bank of visiting the bank's web site this probably wouldn't have happened. Of course, that's what I do now and it hasn't been a problem since.

What Your Browser Can Do For You

Detecting phishing scams on your own mainly require the mild paranoia and the behavioral adjustment described above, but there are a few other things you can do to make your everyday browsing safer.


Turn Off Form Autofill

One great feature of many web browsers is the autofill feature. It makes it really easy to fill out forms using information already stored in the browser. It also makes it easy for you to ignore the form you're filling out and just submit it, causing you to potentially miss a phishing scam when you're rushing through the process. While this precaution isn't necessary, and you might prefer the convenience of autofill to the safety benefits that deactivating it can provide, turning it off will provide a little added protection.


Utilize Your Browser's Built-In Tools

Most browsers come with some phishing protection built-in to help protect you, but it isn't always enable by default. Google Chrome keeps track of common phishing sites and can alert you when you visit one, but you may need to go through the short setup process to make it work. Firefox also offers phishing and malware protection in a similar way, and you can enable it in the Security section of Firefox's preferences.

Bump Up Your Phishing Protection with Web of Trust

Web of Trust is one of our favorite browser extensions because it automatically lets you know if a web site is trustworthy or not. While it can't possible verify every single site on the internet, it can make you aware of potentially harmful sites and phishing scams. All you have to do is install the extension for your browser and it will display a trust rating in your browser's toolbar. (You can read more about this here.) Web of Trust is available to download for Google Chrome, Firefox, Internet Explorer, Opera, Safari, and as a bookmarklet for other browsers.

Source Article:  http://goo.gl/nhzSY

24 January 2012

Bait Your Users with the Simple Phishing Toolkit

By

 By now, most folks have heard of phishing scams, and know to be on the lookout for fake PayPal and bank sign-ons. But what happens when your co-workers get a link to a site that looks just like the corporate intranet? Using the Simple Phishing Toolkit (SPT) you can find out.
The concept behind SPT is pretty simple: Most companies spend a fair amount of money on trying to secure their environment. How much do they spend on educating users? Very little, and in many cases nothing at all. As the saying goes, an ounce of prevention is much better than a pound of cure.

Working with SPT

Basically, SPT is a PHP/MySQL package that is designed to create and run phishing campaigns. It should install on any current LAMP or WAMP stack in just a few minutes. If you've installed Drupal or WordPress or any other PHP/MySQL package, it shouldn't take more than a coffee break to set up. (Creating the database and MySQL user is the longest part of the process.)
From there, you can create campaigns to try to "hook" users and see if they're gullible enough to hand out credentials to a phishing site. You supply templates to SPT for the target site, and the list of users and the body of the email. It will send out the phishing emails and collect data when users respond.
Note that there are two ways to provide a template to SPT – provide a template that you've created, or scrape another site. In my tests of SPT, the scraping didn't work. You can find a Microsoft Outlook Web template on the SPT site, though. This might get you started right away if your organization uses Outlook.



You can also provide an "education package" so that users get schooled as soon as they fall for the phishing link. This can be triggered as soon as users click on the link, or after they provide data.

Could be Used for Good or Evil

The project is open source, available under the GPLv3. It's also extensible, so if it doesn't do everything you want there is the option of writing modules for it. The project is still relatively young, I tested the 0.4 release. Now might be a good time for IT departments to talk to their users about phishing, then plan a SPT campaign for later in the year.

phished.pngIt's worth noting that SPT could be used to run actual phishing campaigns, but those are going on already anyway. Yes, SPT promises to be a really easy way to set up a phishing attack, but that's all the more reason to start educating users.
Does SPT look like something you'd use in your business? Are you doing anything to educate users about phishing already? Would love to hear more ideas in the comments about educating users rather than just spending money on security measures.

Source Article: http://goo.gl/YxAvn

23 January 2012

Beware of fake Megaupload “comeback” phishing scams

By:



Megaupload is supposedly back, albeit without any functionality. An IP address which is dressed to look like Megaupload is being promoted, but evidence points to this as being 100% bogus. If this is legitimate, then Megaupload is one resilient company. The only problem is that this is almost certainly a phishing scam, which you’ll want to avoid like the plague.
Yesterday Megaupload’s domain and assets were seized by the Feds, with the company’s executives being placed under arrest.
As of now, nothing on this site claiming to be the “new Megaupload” works. Every link greets you with the same message, telling you that “this is the new Megaupload site.” The message (probably from a phisher) promises that the company is working to get back up again.
The site’s appearance looks legitimate enough. The familiar Megaupload logo, customary orange and white colors, fonts, and tabs are all there. These could all be easily faked, though — phishers do this with other sites every day. There is also a glaring typo (“beware to the pishing sites”).
Perhaps the biggest evidence against this site is that its IP address was recently directing to another company — which was already flagged as a phishing scammer. We’ll update if we get more information, but we’d advise you to stay far away from this. As long as Megaupload’s employees are in prison with their equipment under Federal control, we don’t expect to see any comebacks.

Source Article: http://goo.gl/2cQTz

20 January 2012

Ensuring Online Banking Security

Phishing Attacks Target Chase and Barclays Accounts
By Tracy Kitten, January 15, 2012.


Accountholders at Chase in the United States and Barclays in Britain have been the targets of a rash of targeted phishing schemes.

Researchers at security firm GFI Software last month discovered customers at Chase had been targeted by phishing e-mails that provided links to spoofed Web pages that requested users submit sensitive online banking details.

The firm also discovered phishing hits aimed at Barclays, though the nature of the attacks differed a bit. In Barclays' case, GFI reported that fraudulent warning e-mails about account suspensions had been sent to Barclays' users. The e-mails, feigning to be security alerts from the bank, claimed that attempts to access online accounts had exceeded limits set by the bank, suggesting hackers had been attempting to break in. Attachments contained in the e-mails asked recipients to provide confidential data to reactivate their online accounts.

The attacks against Chase and Barclays were not rare. Targeted schemes, better known as spear phishing, are common. Similar attacks have been waged against NACHA - The Electronic Payments Association and the Federal Deposit Insurance Corp., just to name two. [See FBI Warns of New Fraud Scam.]

Banks: Cyberfraudsters' Aim
Targeted attacks aimed directly at banks and banking accounts are becoming more standard as well. Last month, the Federal Bureau of Investigation and the U.S. Attorney for the District of Connecticut indicted 14 Romanians for their involvement in an identity-theft scheme that relied on phishing attacks to steal online banking credentials from customers at Connecticut-based People's Bank. Customers at Citibank, Capital One, Bank of America, JPMorgan Chase, Comerica Bank, Regions Bank, LaSalle Bank, U.S. Bank, Wells Fargo, eBay and PayPal also were targeted. [See 14 Indicted in Phishing Scheme.]

Recommendations and the Need for Layered Security
Fraudsters have proven they can get around basic authentication techniques, including two-factor authentication. [See Ramnit Worm Threatens Online Accounts.]

The need for enhanced user authentication served as the catalyst for updated online authentication guidance from the Federal Financial Institutions Examination Council, which took effect this month. Federal banking regulators say banks and credit unions need to ensure they layer security measures, meaning user authentication must go beyond mere logins and passwords.

But a greater concern is online user behavior, since most consumers use the same login names and passwords for multiple accounts, including bank accounts. [See The Real Source of Fraud.]

That universal use of logins and passwords allows cybercriminals to piece together information that can later be used to compromise online credentials. "User names for social websites are often searchable using typical search engines and often the corresponding e-mail addresses are in plain view for casual Internet users and thieves alike to see," says John Buzzard, who monitors phishing attacks and skimming trends for FICO's Card Alert Service.

Fortunately, most phishing schemes are relatively easy to thwart, if practical precautions are taken. "It's rather surprising to keep reading stories about phishing vulnerabilities since phishing varietals have been around since at least 2005," Buzzard says.


Banking institutions can mitigate risks associated with phishing schemes by implementing tried and true best practices that limit exposure to a variety of Internet fraud types. Buzzard recommends institutions:

Provide timestamps for online-banking sessions. Accountholders can look at timestamps to see when the last, and potentially, unauthorized log-in occurred.

Deliver daily account alerts. "Consumers love the ability to establish their own rules so that they can be alerted to ATM withdrawals and daily balances," Buzzard says.

Leverage online banking websites for the delivery of important consumer messages. "A simple email alerting the accountholder that a critical communication is waiting for them inside of their online banking account really is an effective means to ensure that the consumer cannot only view but trust the communication's content," he says.

Avoid e-mailing links. Financial institutions want to discourage consumers from clicking links. When e-mailing correspondence, just inform them to visit the official online-banking site. "Your customer knows how to find their online banking website and they already know how to reach you by phone," Buzzard says.

Source Article: Banking Info Security http://goo.gl/PH0vD


19 January 2012

Email and web scams: How to help protect yourself


When you read email or surf the Internet, you should be wary of scams that try to steal your personal information (identity theft), your money, or both. Many of these scams are known as "phishing scams" because they "fish" for your information.


How to recognize scams
New scams seem to appear every day. We try to keep up with them in our Security Tips & Talk blog. To see the latest scams, browse through our fraud section. In addition, you can learn to recognize a scam by familiarizing yourself with some of the telltale signs.

Scams can contain the following:

Alarmist messages and threats of account closures.

Promises of money for little or no effort.

Deals that sound too good to be true.

Requests to donate to a charitable organization after a disaster that has been in the news.

Bad grammar and misspellings.

For more information, see How to recognize phishing emails and links.

Popular scams
Here are some popular scams that you should be aware of:

Scams that use the Microsoft name or names of other well-known companies. These scams include fake email messages or websites that use the Microsoft name. The email message might claim that you have won a Microsoft contest, that Microsoft needs your logon information or password, or that a Microsoft representative is contacting you to help you with your computer. (These fake tech-support scams are often delivered by phone.) For more information, see Avoid scams that use the Microsoft name fraudulently.

Lottery scams. You might receive messages that claim that you have won the Microsoft lottery or sweepstakes. These messages might even look like they come from a Microsoft executive. There is no Microsoft Lottery. Delete the message. For more information, see What is the Microsoft Lottery Scam?

Rogue security software scams. Rogue security software, also known as "scareware," is software that appears to be beneficial from a security perspective but provides limited or no security, generates erroneous or misleading alerts, or attempts to lure you into participating in fraudulent transactions. These scams can appear in email, online advertisements, your social networking site, search engine results, or even in pop-up windows on your computer that might appear to be part of your operating system, but are not. For more information, see Watch out for fake virus alerts.

How to report a scam
You can use Microsoft tools to report a suspected scam.

Internet Explorer. While you are on a suspicious site, click the gear icon and then point to Safety. Then click Report Unsafe Website and use the web page that is displayed to report the website.

Hotmail. If you receive a suspicious email message that asks for personal information, click the check box next to the message in your Hotmail inbox. Click Mark as and then point to Phishing scam.

Microsoft Office Outlook. Attach the suspicious email message to a new email message and forward it to reportphishing@antiphishing.org. To learn how to attach an email message to an email message, see Attach a file or other item to an email message.

You can also download the Microsoft Junk E-mail Reporting Add-in for Microsoft Office Outlook.

What to do if you think you have been a victim of a scam
If you suspect that you've responded to a phishing scam with personal or financial information, take these steps to minimize any damage and protect your identity.

Change the passwords or PINs on all your online accounts that you think might be compromised.

Place a fraud alert on your credit reports. Check with your bank or financial advisor if you're not sure how to do this.

Contact the bank or the online merchant directly. Do not follow the link in the fraudulent email message.

If you know of any accounts that were accessed or opened fraudulently, close those accounts.

Routinely review your bank and credit card statements monthly for unexplained charges or inquiries that you didn't initiate.

Identity theft protection tools to help you avoid scams
Microsoft offers several tools to help you avoid phishing scams when you browse the web or read your email.

Windows Internet Explorer. In Internet Explorer, the domain name in the address bar is emphasized with black type and the remainder of the address appears gray to make it easy to identify a website's true identity.



The SmartScreen Filter in Internet Explorer also gives you warnings about potentially unsafe websites as you browse. For more information, see SmartScreen Filter: frequently asked questions.

Windows Live Hotmail. Microsoft's free webmail program also uses SmartScreen technology to screen email. SmartScreen helps identify and separate phishing threats and other junk email from legitimate email. For more information, see SmartScreen helps keep spam out.

Microsoft Office Outlook. The Junk E-mail Filter in Outlook 2010, Outlook 2007, and other Microsoft email programs evaluates each incoming message to see if it includes suspicious characteristics common to phishing scams. For more information, see How Outlook helps protect you from viruses, spam, and phishing.

Source Article: Microsoft http://goo.gl/3VjyL

05 January 2012

OLYMPIC TRUST LOTTERY Scam

The following is an example email for this lottery scam. Please forward all lottery emails to scams@fraudwatchinternational.com



OLYMPIC TRUST LOTTERY
Ref. Number: 639/898/116
Batch Number: 430456543-FD22


Sir/Madam,

We are pleased to inform you of the result of the OLYPIC TRUST LOTTERY International programs held on the 6th April 2004. Your e-mail address attached to ticket number 44676546546-2243 with serial number 8645-645
drew lucky numbers 9-43-76-44-31-85 which consequently won in the 1st
category, you have therefore been approved for a lump sum pay of US$ 1,000,000.00
(One Million United States Dollars)
CONGRATULATIONS!!!

Due to mix up of some numbers and names, we ask that you keep your
winning information confidential until your claims has been processed and your
moneyRemitted to you. This is part of our security protocol to avoid double claiming and unwarranted abuse of this program by someparticipants. All participants were selected through a computer ballot system drawn from over 20,000 company and 30,000,000 individual email addresses and names from all over the world. This promotional program takes place every three year.This lottery was promoted and sponsored by Bill Gates, President of the World Largest software, and other notable businessmen, we hope with part of your winning you will take part in our next year USD50 million International lottery.

To file for your claim, please contact our fiducial agent MR. VAN TOM of the, Standard Trust Agency TEL +31-612-187-410
Email: standardtrust101@netscape.net
Remember, all winning must be claimed not later than 15th of May 2004.
After this date all unclaimed funds will be included in the next stake. Please note in order to avoid unnecessary delays and complications

Please remember to quote your reference number and batch numbers in all correspondence. Furthermore, should there be any change of addresses do inform our agent as soon as possible.

Congratulations once more from our members of staff and thank you for
being part of our promotional program.

Note: Anybody under the age of 18 is automatically disqualified.

Sincerely yours,
Mrs. Claudia Betty
Lottery Coordinator

20 September 2010

Commonwealth Bank #Phishing #Australia

September 17th, 2010, 19:54 GMT| By Lucian Constantin

Security researchers from Sophos warn of an unusual phishing attack targeting Commonwealth Bank customers, which makes use of a DNS hijacking trojan to steal login details.

DNS hijacking trojan used in Commonwealth Bank phishing attackThe attack starts with spam emails abusing a real Commonwealth Bank email template, which includes the organization's logo, copyright notice and other identification elements.

The rogue messages come with a subject of “Update your Commonwealth Bank” and read: "This e-mail is to inform you that your account will be suspended within 48 hours due to your Account Inactivity."

The recipients are told that they need to confirm certain information associated with their account in order to continue using it.

A "Verify My Account Information" link is included in the email, but surprisingly, it doesn't lead to a phishing website.

Commonwealth Bank phishing email sampleInstead, it points to a file called CommBank.scr hosted on an external .cx (Christmas Islands) domain, which if ran, installs a computer trojan.

This malware's primary purpose is to phish credentials from users and it achieves this through two files dropped in the \drives\etc folder.

One is called pic.url and leads to a Commonwealth Bank phishing page. The other is a HOSTS file, which contains rogue DNS entries for the bank's domains.

This will cause all requests for commbank.com or commbank.com.au made from an infected computer to be redirected to a phishing website, which mimics the bank's login system.

Ironically, the trojan installer is also infected with a virus called Sality, suggesting that the computer of whoever is behind the phishing attack is affected by this threat.

"[…] It’s unlikely this is a deliberate measure, as we’ve seen uninfected variants of this phishing Trojan in the past (which we detect as Mal/RarHosts-A), and anyway the Sality doesn’t so much hide the Trojan as paint it in bright colours, making it even easier to spot and to block,explained Richard Cohen, a malware researcher at Sophos.

Follow the editor on Twitter @lconstantin
Copyright © 2001-2010 Softpedia. Contact/Tip us at 


09 September 2010

Gone #Phishing and your the fish!

Believe it or not, there are rascals inhabiting this very planet, their consequence emanates from under the woodwork everywhere, and arrives without warning at your inbox.
These communiqués, in the form of emails, are simply the result of people who have gone “phishing,” not to be confused with the term “gone fishing,” a practice no one seems to object to except maybe the fish. Still these rogues are after a fish, and the fish my friend is you!
Phishing employs both technical schemes and reliance on your lack of caution, to gain your personal identity and financial information data.
The way they hook their victim is through a cloaked link (the bait) leading their unsuspecting fish, that’s you, to a counterfeit website carefully designed to trick their catch (you) into divulging private financial data such as, credit card numbers, usernames, passwords, social security numbers, and so forth.
These traps are intermingled with everyday spam, or whatever passes as spam, littering your inbox. In reality, ordinary spam is merely bothersome at worst, requiring its disposal through excessive use of the delete key, yet phishing can be far more destructive.
These deceptive ploys fraught with harmful intentions are daily appearing in mail boxes everywhere, arriving from outside and inside the country highlighting the Internets lack of policing and our peril.
An email message can be a useful and handy tool, yet it’s tailor-made for this type of villain. The reminder you receive can appear as a genuine concern from a business you are doing commerce with, and have already entrusted your personal information.
The subject line of these bogus emails reads something like, “We suspect an unauthorized transaction on your account,” then sets the hook by declaring only “good intentions” by stating, “To ensure your account is not compromised, please click the link below and confirm your identity.”
Or, the phony email might assert that, “During our regular verification of accounts we couldn’t verify your information.” This phrase is calculated to put you into a panic, then comes the bait, please click here to update and verify your information.” And, if you do, they win!
And yes, I am not too proud to admit a close friend of mine, in his newbie days, fell prey to this blatant deception. Come to think of it, his name and description is curiously the same as mine. Oh well, I know it couldn’t have been me, as I wouldn’t fall for such a ruse. Then again!
Following this incident, I have developed a simple rule, I never respond through any email allegedly from anyone I’m doing business with, regardless of my lack of suspicion. Where I feel it’s of proper concern, I go directly through my browser to the site, enter and check it out.
This advice I offer you like a brother, never react directly with any message that poses a serious concern and provides a “convenient” link for you to deposit your critical information. It could be the most costly mistake of your life.
While there are sites where you can forward these poison pills, your only real protection, is you. Don’t rely on any company, notwithstanding their plausible concerns, for in the end, you retain the power of the delete button, use it wisely.
By the bye, phishing is often referred to as “spoofing,” what a harmless expression. As if, “sure I stole your identity, cleaned out your bank account, left you with huge financial losses to overcome, but hey, I was only spoofing!”

Source: