Showing posts with label 419. Show all posts
Showing posts with label 419. Show all posts

Sunday, February 08, 2009

Spammers Love to Hurt Internet Users

Love is a many splendored social engineering tool and spammers are busy sending out a whole lot of their particular brand of love across the electronic universe.

An interesting blog post (Love Hurts) by Kevin Haley at Symantec points out that malicious code writers are busy spreading their work in attachments hidden in the millions of spam messages being spewed out by zombies (compromised computers). If you click on one of these attachments — and your machine isn't bulletproof — it also can become a zombie and used as part of a botnet to send out more spam. Botnets are groups of compromised computers used to form a super computer. Of course, downloading malware can also mean that all your personal and financial information will be stolen, too. Please note (as you will see below) that some forms of malware currently being sent out can do both.

Kevin's blog post came out at almost the same time Symantec issued it's monthly Spam Landscape Report. With Valentine's Day coming up, love is a predictable lure and it's probably a good idea to make sure you know who loves you before clicking on any links in an e-mail.

Another predictable finding in the report is that spam levels are continuing to rise to normal levels after they fell when McColo was shut-down. McColo (a Web service hosting provider) was shut down in November after it was discovered they were the source of a large number of botnets, which are used to send out spam. Last month, 79 percent of all e-mail was spam. The report also notes that the point of origin for spam is shifting a little. Although the United States is still number one, the number of active zombies in other countries is rising. While some of this is being attributed to McColo, the report points out that this might point to the fact that some of these countries have an increasing number of users accessing the Internet.

From a spam-commerce point of view, the report indicates weight loss products, counterfeit drugs, cheap watches and porn top the list of items available at super-cheap prices as Valentine's Day approaches.

Besides Valentine's Day, President Obama also continues to be used as a spam lure, according to the report. A lot of this spam contains malware with files names such as usa.exe, obamanew.exe, statement.exe, barackblog.exe and barackspeech.exe. The malware being spread in these spam e-mails is called the W32.Waledac, which is capable of both stealing sensitive personal and financial information and turning a machine into a zombie. It also establishes a backdoor to a machine so it can be remotely accessed.

Current events (and holidays) have been and probably will continue to be used as social engineering lures to snare the unwary.

Also noted was a rise in Russian spam hawking goods and services. With cheap long distance services using VoIP, the Russians have actually set up telephone numbers for their intended victims to call. My guess is that they will entice someone to send money, which can't be recovered when the person sending it discovers they've been scammed.

Chinese gambling spam is also mentioned as a new phenomenon in the report. It appears to be patterned after English language gambling spam, but is written in Chinese.

Last, but not least, Nigerian spam is mentioned. Nigerian or 419 spam is named after the section of the Nigerian penal code dealing with fraud. It normally is a come-on for lost riches or winning a lottery and has a lot of spelling and grammatical errors. Typically known as advance fee fraud, the victim is enticed in sending money across a border (wire transfer is preferred) to secure their fortune. Of course in the end, the victim never receives anything and is often left in financial ruin.

There are many twists to advance fee and one of them is to send a bogus financial instrument to a person with instructions to cash it. If the person doesn't get arrested for presenting it, they are instructed to send the money back to the scammer. Of course, the cashing institution eventually figures out the instrument is bogus and the victim is held liable for it.

A lot of people think that advance fee all comes from Nigeria, which isn't true. I've personally traced it to a lot of other places and called some of the telephone numbers. The person answering didn't sound Nigerian and I've spoken to a few people from Nigeria in my time. Naturally, this doesn't mean that scam activity is not coming from Nigeria and just that not all of it does.

Pam Dixon, of the World Privacy Forum, went on record recently that the spelling and grammatical errors aren't being seen as much in advance fee lures anymore. Obviously, advance fee scammers, wherever they hail from, are being more careful and have discovered spell check?

To close, the Anti-Phishing Working Group's recent report on phishing, which is delivered via spam, has noted that the number of crimeware-spreading URLs out there has increased 258 percent versus the same time period last year. It also noted a record high in the amount of hijacked and victimized brand names. Last but not least, it noted another record in the amount of malicious application variants being seen in the wild (on the Internet).

This would suggest that spam is getting more dangerous and the people sending it are becoming more sophisticated. The smartest thing to do with all spam is to delete it. Making sure your computer's security is updated with a known and reliable vendor is also a smart thing to do. After all, as I've speculated many times before, most fraud, phishing and financial misdeeds on the Internet start with spam.

Thursday, March 08, 2007

Nigerian (419) fraud is a worldwide problem

Nigerian (419) fraud is showing an alarming increase in India (900 percent) in one year. Pramit Pal Chaudhuri of the Hindustan Times is reporting:

The world's most widespread financial fraud, the Nigerian 419 scam, is finding new pastures in Asia. India is the third fastest growing market with the defrauders' earnings from Indians increasing nine-fold in one year, says a report by the Dutch firm Ultrascan Advanced Global Investigations.

Almost every cellphone and email user has been solicited by a 419 con man. The best-known ploy is a message claiming there are unclaimed fortunes in banks that can be accessed if someone puts up a little money upfront.

Pramit quoted some interesting figures in his article suggesting the worldwide bill for this type of fraud is $3.88 billion.

Pramit's (interesting) story, here.

Pramit cites intelligence from the Dutch firm Ultrascan Advanced Global Investigations. They have a lot of interesting facts about Nigerian fraud, here.

In October (2005), I did a post exploring how some rationalize this activity in Nigeria:

419 From the Other Side of the Fence

The post references a Nigerian pop singer (Osofia) and a song he did about the infamous scam:

"I go chop your dollar"

Perhaps, Osofia should update his song to include all the other currencies being chopped?

Monday, November 06, 2006

If You've Really Won the Lottery - Why Are They Asking You to Send Money?

I've written a lot about the various Advance Fee scams out there - and judging from my inbox - the lottery variation of the scam is huge.

I sometimes get four or five notifications that I've won a lottery, or sweepstakes, daily.

Last evening, I read an article written by Linda Leatherdale of the Toronto Sun about a grandmother losing a lot of her hard-earned money as a result of falling for them.

Linda Leatherdale writes:

But more than anything, she wanted to pay for a university education for her three grandchildren. So she entered the sweepstakes.

Lo and behold, a few months later she received a letter that she had won. Ecstatic, she read what she believed to be an authentic lottery letter, which asked her to send
in $25 to collect her prize.

CASH MAILED OFF

Not trusting giving out personal financial information, via cheques or credit cards, she sent cash. Then other letters arrived -- from the U.S., Australia, New Zealand and other parts of the world. Some invited her to play a new lottery, others said she'd won and to send money to collect her prize.


Toronto Sun story, here.

I've seen the lottery scams, where a high-dollar financial instrument is mailed to the "intended victim," along with instructions to wire the money back - but mailing the smaller amounts ($25 to $50) was an activity that was new to me.

With Spam software that sends these "winner notifications" by the millions - I can see, where this could be a lucrative enterprise for the fraudsters behind this.

I guess the moral of the story is to look for the behavior. I've never won the lottery (I play Mega Millions sometimes) - but if I did - I doubt anyone would be asking me to send money.

It would probably be the other way around, or they would be sending me money!

Linda's article mentions "Phonebusters" as a good resource to educate people on Internet scams. I agree and you can link to them, here.

Down here in the U.S., another good resource is the FTC, link here.

Please note that these "lottery scams" cross borders with the click of a mouse.

You can also report these scams at both of these sites, which is something I highly recommend!

Doing so might save another grandmother out there!

For another post about lottery scams and the sheer amount of spam circulating "winner notifications," link here.

Saturday, July 22, 2006

Aids Cure, Another Lure in the Internet Fraud Saga

Research has come a long way since Aids was discovered in the early 80's, but no cure has been found yet.

SophosLabs is reporting that a new advance fee (spam) e-mail is circulating claiming to have found a cure for aids. Here is what they have to say:

"However, Sophos warns computer users that this is a ruse to steal personal details, and that the fraudsters behind the scam campaign can use such information to steal money from bank accounts and commit identity fraud."

"People who receive this email may believe they are helping the world fight AIDS, as well as potentially make themselves some money from the proceeds of any distribution of a successful cure. However, the scammers are just using another method to try to dupe computer users into divulging sensitive information," said Carole Theriault, senior security consultant for Sophos. "It's particularly sick of the hackers to exploit human illness in their search for innocent computer users to fleece."

"This email con-trick is the latest of many 419 scams. These scams are named after the relevant section of the Nigerian penal code where many of the scams originated and are unsolicited emails where the author offers a large amount of money. Once a victim has been drawn in, requests are made from the fraudster for private information which may lead to requests for money, stolen identities, and financial theft."

There is a copy of the letter on the alert from Sophos.

Unfortunately, the alert - which contains the e-mail in question - is cut-off before it is clear exactly what the scam entails. It also makes references to stealing personal information (identity theft) - which can be done via "social engineering," or by visiting a "rogue website" and picking up some malware on your system.

I decided to "dig a little deeper" and used one of my favorite tools, "Google."

Sure enough, I was able to find more information on this - including "WHOIS" data regarding the origin of the e-mails. Interestingly enough, this version of the scam has been around for since February, 2005. The e-mail in the Sophos alert was dated this month (July).

This version was reported by Joe Wein, who runs a Japanese software company that sells spam and on-line fraud protection.

In this version, the e-mail using a UK e-mail address from a IP address in Nigeria. The letter claims to be from an Indian doctor.

It appears Joe corresponded with the scammer and the lure to obtain personal information appears to be of a "social engineering" (human con) type. The e-mail asks for patients medical information, which in turn will probably be used for "identity theft" purposes.

The additional e-mails also mentions having the "aids drugs" sent to people. Please note that there also is a big problem with the sale of "useless" counterfeit drugs on the Internet. Most of us get spam e-mails about this all the time, at least in our spam filters.

In both of the e-mails, I was unable to find any "direction" to a "rogue site," which might install spyware, malware, or crimeware on a computer.

If you would like to view this version, link here.

Having the proper protection on your computer is extremely important, but being knowledgeable of "social engineering" is critical, also.

The term "buyer beware" (caveat emptor) is a good thing to think about before proceeding with a transaction on the Internet. A little "digging" and verifying facts is prudent, also.

"If it's too good to be true - it might not be."

Sunday, May 28, 2006

Is the Latest Congressional Scandal a Nigerian Fraud


The AP is now reporting the possible involvement of Nigerian Vice President Abubakar Atiku in the bribery scandal involving Congressman William Jefferson of Louisiana.

To try to get some commentary on this, I went to Congressman Jefferson's site. The only thing I found "interesting" was a message to the "Katrina Victims." Unfortunately, Katrina has now - ALSO - proven to be a fraud-ridden event.
Now the AP is briefly mentioning that the Vice President of Nigeria was the intended recipient of the bribe and the African Press is discussing it in more detail.

As reported by the AP:

While the name of the intended recipient of the $100,000 is blacked out, other details in the affidavit indicate he is Abubakar Atiku, Nigeria's vice president. He owns a home in Potomac, Maryland, that authorities have searched as part of the Jefferson investigation.


For the full story from the AP, courtesy of W-TOL in Toledo, Ohio, link here.

Nigeria has received a lot of bad press for being the "point of origin" for fraud schemes that have victimized people worldwide. In the past few years, President Olusegun Obasanjo has come down hard on fraud and with the help of his EFCC (Economic Financial Crimes Commission) prosecuted a lot of high profile cases, which were well publicized.

Here is a description of Nigerian fraud that I wrote in an earlier post:

"Nigeria is one of main sources for all sorts of Advance fee fraud (419) fraud scams. The Advance Fee scam is where a ruse is used to get a victim to send them money (nowadays normally wire-transfer) in anticipation of riches (or sometimes love) to come. The best known is the "Nigerian Letter," but the activity has mutated into romance, lottery, auction, check cashing, work at home and reshipping scams."
While the fraud that is exported from Nigeria is what we read about all the time, there is considerable evidence that fraud in Nigeria (at least historically) exists at all levels. The current President (Obasanjo) has led a very public campaign against corruption within Nigeria and is credited with making great strides in this area.

It will be interesting to see if the EFCC investigates the Vice President. AllAfrica.com is reporting the story, which quotes Atiku as saying Jefferson was name dropping and obviously committing a 419 (Nigerian Penal Code for Advance Fee) scam. In all fairness, most of the money was still in Congressman Jefferson's freezer, and he did indicate to the "informant" that the money had reached the intended recipient.
Please note that other fraudsters impersonating Nigerian fraud is nothing new. In the past, I've seen other groups do scams - which were made to look as if they came from Nigeria.
However, BiafraNigerianWorld.com wrote an article about the "mysterious" mansion in Potomac, and it's (legal) owner, Jennifer Douglas. According to BiAfra Nigerian World, the mansion was purchased after Atiku became Vice-President and Jennifer Douglas - who they describe as one of Atiku's many wives - is a student with no verifable income. Their article states that Ms. Douglas has left the United States and returned to Nigeria. The AP article states that this mansion, if they are one and the same, belongs to Atiku and makes no mention of Ms. Douglas.
BiAfra Nigerian World has a link to Maryland Property records showing Jennifer Douglas as the owner.
Another item mentioned in all the artices was a telecommunications deal with Nigeria, where the owner of the U.S. company in question has already pled guilty to giving Congressman Jefferson $400,000.00 to seal deals with Nigeria and "other African countries.
Link to the story from BiafraNigerianWorld.com, here.
The AP doesn't seem to come to any conclusions and the FBI isn't commenting yet, which could mean the matter is still under investigation.
The FBI recently added a page to their website, where the public can report government fraud.
Considering the recent activity with Tom Delay, Randy (Duke) Cunningham and now this investigation, they seem to be pretty busy in this arena.

Here are some previous posts, I've done on Nigerian Fraud:

419 From the Other Side of the Fence

Hard Drives for Nigeria

Nigerian Vice President Abubakar Atiku