If you receive a "text message" saying you've been signed up for a dating service (automatically billed to your cell phone) "take a deep breath" before following their instructions.
The Internet Crime Complaint Center (IC3) is reporting:
The FBI has been alerted to a newly discovered malware located at http://www.irrealhost.com. Malware is software designed to infiltrate or damage a computer system without the owner's consent.
The identified malware lures victims to the site through the receipt of an SMS message on their cellular phone. An SMS message is a Short Message Service that permits the sending of short messages, also known as text messages. The message thanks the recipient for subscribing to a dating service, which is fictitious, and states the subscription fee of $2.00 per day will be automatically charged to their cellular phone bill until their subscription is canceled at the online site.
Recipients visiting the site http://www.irrealhost.com to cancel their subscription are redirected to a screen where they are prompted to enter their mobile phone number, then given the option to run a program which is supposed to remove their subscription to the dating service.
When the run option is selected on the Web site, the executable adds several files to the host and changes registry settings to open a backdoor port and lower Windows security settings. The host file is modified to prevent the victim from browsing to popular anti-virus Web sites. The executable also turns the infected computer into a "zombie" network, which can be remotely controlled by the hackers.
For the alert link, here.
In case, you are like me and need clarification on some of the "technical terms," here are descriptions. New terms for computer fraud, such as "vishing" come about all the time and it's hard for the average person to keep up.
Wikipedia is probably the best (most up to date) reference (for new IT terms), I have found, thus far.
Malware is sometimes called crimeware and zombie networks (botnets) are known to be used by cybercriminals for nefarious purposes.
A keylogger could even be installed by visiting one of these "rogue websites." These programs record all the "keystrokes" on a computer and send them (electronically) to the person who installed them on a system. Keyloggers are actually legal and marketed as a means to spy on your loved ones, or anyone else. Criminals use them to record your access information to financial accounts and then steal the money out of them.
If you spot this activity - besides taking a deep breath and not following through with the request - the best thing to do is report it. You can report it to the Internet Crime Complaint Center (IC3), here.
The sad thing is that those of us who know - often just ignore the attempt - which leaves those of us (who don't know) vulnerable.
Wednesday, July 19, 2006
Tuesday, July 18, 2006
Vishing - The New Way to Lose Your Identity
The security media is reporting a new scam called "vishing," ( phishing by telephone). In vishing, a person is called, or directed to call a number and tricked into giving up their personal details. Note that the call might have someone give up information over the telephone, or direct them to a fraudulent website (like they do in phishing). The intent of these (vishing) scams is to steal personal information, which are used in "identity theft" schemes.
Of course using the telephone to rip-off people is nothing new. Telemarketing scams have been around for years.
The lures used to "dupe" innocent people are normally the same ones used in phishing, like telling you an account has been compromised. It's even possible they might already have some of your information (a lot of it has already been compromised) and be trying to get a credit card's CVC code, or obtain a password to an account.
According to a recent BBC article, the recent bouts with "vishing" started with spam e-mails directing someone to call a number, where they would be prompted to give up personal information. The scam has now mutated (they always do) and now people are being called by "autodialers," which dial number after number and leave a recorded message.
The rise in popularity of Voice over Internet Protocol (VoIP) is being cited by security experts as the reason why vishing is becoming a problem. VoIP has made calling long distance cheap, which means that vishing crosses borders; making it hard to trace and or prosecute.
The BBC article also states that it is relatively easy to spoof "caller-id" with VoIP. Security Focus recently did an article that supports this contention. In the article, a hacker easily showed the reporter how it was done.
For anyone unfamiliar with "spoofing caller id," fraudsters aren't the only ones who do it. In fact, many legitimate corporations use "caller id spoofing services" to trick people (my own words) into picking up the telephone.
For a post, I wrote about this, link here.
So far as how to protect yourself from this sort of scam, I would highly recommend that if you receive any telephone calls (or a e-communication to call a number) asking you to "verify" personal, or financial information that you take a "deep breath" before proceeding. Most of us have access to legitimate telephone numbers with places we do business with. The key to protecting yourself is to always verify who you are talking to and make sure they are entitled to the information in question.
And remember that since "vishing" is relatively new, financial institutions might now be the only organizations impersonated. The history of phishing tells us that sometimes government institutions are also impersonated. In the past couple of years, we have seen the IRS and even the FBI impersonated in phishing schemes. As a matter of fact in October, 2005 - I did a post on the Jury Duty Scam - where fraudsters (we might now term as "vishers") were calling up to verify personal information.
Maybe "vishing" isn't as new as we thought it was?
Of course using the telephone to rip-off people is nothing new. Telemarketing scams have been around for years.
The lures used to "dupe" innocent people are normally the same ones used in phishing, like telling you an account has been compromised. It's even possible they might already have some of your information (a lot of it has already been compromised) and be trying to get a credit card's CVC code, or obtain a password to an account.
According to a recent BBC article, the recent bouts with "vishing" started with spam e-mails directing someone to call a number, where they would be prompted to give up personal information. The scam has now mutated (they always do) and now people are being called by "autodialers," which dial number after number and leave a recorded message.
The rise in popularity of Voice over Internet Protocol (VoIP) is being cited by security experts as the reason why vishing is becoming a problem. VoIP has made calling long distance cheap, which means that vishing crosses borders; making it hard to trace and or prosecute.
The BBC article also states that it is relatively easy to spoof "caller-id" with VoIP. Security Focus recently did an article that supports this contention. In the article, a hacker easily showed the reporter how it was done.
For anyone unfamiliar with "spoofing caller id," fraudsters aren't the only ones who do it. In fact, many legitimate corporations use "caller id spoofing services" to trick people (my own words) into picking up the telephone.
For a post, I wrote about this, link here.
So far as how to protect yourself from this sort of scam, I would highly recommend that if you receive any telephone calls (or a e-communication to call a number) asking you to "verify" personal, or financial information that you take a "deep breath" before proceeding. Most of us have access to legitimate telephone numbers with places we do business with. The key to protecting yourself is to always verify who you are talking to and make sure they are entitled to the information in question.
And remember that since "vishing" is relatively new, financial institutions might now be the only organizations impersonated. The history of phishing tells us that sometimes government institutions are also impersonated. In the past couple of years, we have seen the IRS and even the FBI impersonated in phishing schemes. As a matter of fact in October, 2005 - I did a post on the Jury Duty Scam - where fraudsters (we might now term as "vishers") were calling up to verify personal information.
Maybe "vishing" isn't as new as we thought it was?
Labels:
identity theft,
Phishing,
spoofing caller id,
telemarketing scams,
vishing,
VoIP
Monday, July 17, 2006
Armed Robbers Pose as Craigslist Customers
This story reaffirms something we should all know, which is be wary of anyone you know only from the Internet. In a story released on SFGate.com, a seller on Craigslist, selling "hooded jackets" was talked into meeting someone at a local mall. When they arrived for the meeting, they were relieved of their merchandise at gunpoint.
The good news is that the only loss was the "hooded jackets!"
For the full story on SFGate.com, link here.
In my opinion, Craig and Craigslist - who provide a "mostly" free service - have been extremely honest and proactive about protecting their "users" from crime.
Although, I could find nothing about this (new and frightening scam) - here is a link to their warnings about some of the scams attempted on their site. Hopefully this one will make their list soon.
The dangers of meeting someone that you have met only over the Internet have been well documented. Although primarily written in the context of "romance encounters," anyone meeting someone they meet on the Internet needs to be careful and verify (via a trusted source) who they are dealing with before proceeding.
For a resource from the University of Oklahoma (The Police Notebook), which covers this subject - link here.
The good news is that the only loss was the "hooded jackets!"
For the full story on SFGate.com, link here.
In my opinion, Craig and Craigslist - who provide a "mostly" free service - have been extremely honest and proactive about protecting their "users" from crime.
Although, I could find nothing about this (new and frightening scam) - here is a link to their warnings about some of the scams attempted on their site. Hopefully this one will make their list soon.
The dangers of meeting someone that you have met only over the Internet have been well documented. Although primarily written in the context of "romance encounters," anyone meeting someone they meet on the Internet needs to be careful and verify (via a trusted source) who they are dealing with before proceeding.
For a resource from the University of Oklahoma (The Police Notebook), which covers this subject - link here.
Bid Reaper, "TELLING IT LIKE IT IS" on eBay
Over the past year, I've written more than one post about problems on eBay. Recently, my friend and partner in "Digging A Little Deeper," Paul Young was able to get the "Bid Reaper" to give me honorable mention on his site.I'll have to admit, I had never been exposed to the "Bid Reaper" before. I found the site to be extremely informative, and a "informative" read for anyone trying to navigate the "sometimes" murky waters of Internet auctions.
Bid Reaper's motto is - Telling "IT" like it is - and it details what is going wrong on eBay - right now.
I plan to continue my visits to "Bid Reaper" and highly recommend that anyone interested in protecting themselves on eBay - do so - also!
And the pictures (see above) are very "interesting," to say the least. The very vision of the "Bid Reaper" should instill fear in auction fraudsters - as well as - eBay's marketing department.
To visit the "Bid Reaper," click here.
Labels:
auction fraud,
auction scams,
bid reaper,
ebay,
prying1
Subscribe to:
Posts (Atom)
