Online Romance Scams Spike Under Lockdown

Online Romance Scams Spike Under Lockdown

Police and banks are celebrating after revealing that £19 million in fraud was stopped in the first half of the year, although romance scams are reportedly on the rise.

Over 600 reports of romance scams each month were made in June, July and August, contributing to a 26% year-on-year increase in cases recorded by Action Fraud, according to Sky News.

These are typically confidence tricks where a vulnerable individual is contacted via a dating site and financially exploited or unwittingly used as a money mule.

Over 19,400 such crimes were logged with the FBI last year, making it the second highest earner for cyber-criminals after business email compromise (BEC). Over $475 million was lost to romance scammers in 2019, the law enforcement agency said.

In the UK, losses are said to have exceeded £66 million between August 2019 and August 2020. As a result, various dating sites, banking groups and police are running a “Take Five” awareness campaign designed to warn users of the dangers posed by internet scammers.

The spike in romance scams coincided with COVID-19 lockdowns in the UK and much of the rest of the world, and a subsequent shift in crime and fraud online.

Action Fraud claimed it saw an increase in reported attacks in the first month of lockdown, to nearly 4000. UK Finance last month claimed that fraudsters are increasingly shifting their operations online.

However, Action Fraud also revealed this week that millions of pounds worth of fraud has been prevented so far this year thanks to a Banking Protocol first introduced three years ago.

The initiative enables banking staff in branches to alert their local police force when they suspect a customer is being scammed, for example if they are transferring or withdrawing large sums of money. It has been used to good effect to stop romance fraud, and impersonation scams, Action Fraud claimed.

In addition to the £19.3 million in fraud allegedly prevented, 100 arrests were made in the first half of the year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fake News Named Biggest Global Cybercrime Concern

Fake News Named Biggest Global Cybercrime Concern

Cybercrime is one of the biggest concerns of the global populace, with fake news ranking highest among such risks, according to a new report from Lloyd’s Register Foundation.

The UK charity, funded by the eponymous technical and business services organization, this week released the results of its first World Risk Poll, compiled from interviews with 150,000 individuals in 142 countries.

Some 71% of respondents cited cybercrime as one of their biggest concerns, with almost all internet users fearful about some aspect of it.

The biggest concern in this category was fake news (57%), which came ahead of online fraud (45%) and cyber-bullying (30%). Unsurprisingly the results were slightly different depending on country and region.

For example, in the UK more respondents were concerned about fake news (62%) and online fraud (69%). Other Western European countries were even more likely to worry about internet fraud, including Portugal (78%), France (74%) and Spain (71%).

Concerns over cyber-bullying were strongest in low income economies thanks to their large population of youngsters. Around a third (34%) of respondents between the ages of 15 and 29 said they worry about online bullying, compared with about a fifth (21%) of those aged 65 and older. Women (32%) were slightly more concerned then men (28%) in this regard.

Lloyd’s Register Foundation CEO, Richard Clegg, said the poll represents the views of 98% of the world’s population, including many people whose voices have never been heard before.

“Knowing what people think will help us to identify gaps between peoples’ thoughts about risk and their experiences of threats to their safety,” he added.

“We can use this data to work with communities and empower people to take action most likely to reduce harm — that saves lives and helps them feel safe.”

Another global poll out this week, from the World Economic Forum (WEF), also cited cyber-threats as one of the biggest concerns, this time for business leaders.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Trojan Malware Targets Trump Supporters

Trojan Malware Targets Trump Supporters

Bad actors have launched a phishing campaign that aims to infect supporters of President Donald Trump with a dangerous banking Trojan. 

The malicious campaign was detected by Area 1 Security on August 21. Victims are enticed to open messages that appear to be from legitimate political action committees (PACs) but are in fact fake.

The messages refer to highly publicized political issues and events and feature subject lines prefaced with “Fwd:” and “RE:” Deceived victims who take the bait have their system attacked by Emotet malware. 

“The attacker forwards a legitimate PAC mailer to develop a false sense of legitimacy, with entirely authentic content throughout the body of the message,” noted researchers. “Every link works and leads to benign web pages of the impersonated PAC.”

The Emotet downloader is contained in a Microsoft Word document attached to the malicious email.

Attackers were observed seeking to leverage media attention on the president’s decision to temporarily withhold funding from the World Health Organization pending the outcome of a formal investigation into the global health agency’s response to the Covid-19 pandemic. 

Researchers said: “Like a Wolf in sheep’s clothing, the attacker cleverly disguises their Emotet delivery mechanism as messaging about timely and highly publicized, hot-button issues in politics.”

One email, sent with the subject “Fwd:Breaking: President. Trump suspends funding to WHO,” called for recipients who agreed with the suspension of funding to click a button labeled “Stand with Trump.” The attacker used Display Name Spoofing in an effort to hide the sender’s real address. 

While the sender addresses used to spread the WHO-themed phishing messages varied, all were observed to have come from a legitimate account that had been compromised by the attacker. This tactic allowed the attacker to successfully pass email authentication protocols such as DMARC.

Using hijacked legitimate email addresses would also have made it very difficult for victims to grasp the fact that they were being duped by a cyber-criminal. 

Researchers found that compromised email accounts of several small businesses around the world were used in each wave of the campaign that lured victims with the same stolen PAC email content.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Seizes Domains Used to Spread Disinformation

US Seizes Domains Used to Spread Disinformation

The United States has seized nearly a hundred domains that it alleges were used by Iran’s Islamic Revolutionary Guard Corps (IRGC) to engage in a global disinformation campaign.

According to the seizure documents, four of the 92 websites that were seized purported to be genuine online news outlets. The US alleges that they were actually propaganda machines controlled by the IRGC and used to spread disinformation that aimed to influence American foreign and domestic policy. 

The remaining domains were allegedly used to spread Iranian propaganda around the world to countries other than the United States. Among the domains seized were “newsstand7.com,” “usjournal.net,” “usjournal.us,” and “twtoday.net.”

“We will continue to use all of our tools to stop the Iranian Government from misusing US companies and social media to spread propaganda covertly, to attempt to influence the American public secretly, and to sow discord,” said Assistant Attorney General for National Security John Demers.  

“Fake news organizations have become a new outlet for disinformation spread by authoritarian countries as they continue to try to undermine our democracy.”

An investigation into the domains was launched after a tip-off from American multinational technology company Google.

Agent John F. Bennett, the Federal Bureau of Investigation’s special agent in charge, said: “This investigation, initiated by intelligence we received from Google, was a collaborative effort between the FBI and social media companies Google, Facebook, and Twitter.”

Bennett said that yesterday’s successful seizure operation underscored the importance of having a cooperative relationship between tech leaders and law enforcement.

“This case is a perfect example of why the FBI San Francisco Division prioritizes maintaining an ongoing relationship with a variety of social media and technology companies,” said Bennett.

“These relationships enable a quick exchange of information to better protect against threats to the nation’s security and our democratic processes.”

Bennett called for social media users to join in the battle against misinformation on the worldwide web. 

“The FBI also urges the public to remain vigilant about the information they find and share on social media,” said the agent. “Every citizen must do their part to use a critical eye and look for trusted sources of information. 

“We all have a role to play in protecting the American democratic system from foreign adversaries.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Family of Deceptive Gaming Apps Discovered

New Family of Deceptive Gaming Apps Discovered

A new family of gaming apps that uses out-of-context (OOC) ads to deceive users has been discovered on the Google Play Store. 

While fulfilling their advertised function to varying degrees, the apps run ads that appear to be coming from popular applications and social media platforms including YouTube and Chrome.

The brood of more than 240 deceptive Android apps was detected by the White Ops Satori Threat Intelligence and Research Team. Many of the apps are little more than Nintendo emulators that researchers say were “ripped from legitimate sources or low-quality games.”

The assortment of deceptive apps was dubbed RAINBOWMIX by researchers as a nod to the vibrant 8–16bit color palette deployed in retro games. The family garnered more than 14 million downloads before being removed from the Google Play Store.

Researchers observed that at its peak, RAINBOWMIX had more than 15 million ad impressions per day.

Malicious actors bypassed certain security protocols by using packer software that saves space and obfuscates the final payload. 

“All of the apps discovered seem to possess fairly low detection ratings across AV engines, largely because of the packer being used,” noted researchers. 

The code responsible for the out-of-context ads was located in spoofed or illegitimate versions of legitimate SDKs (Software Development Kits), such as Unity and Android. Researchers did not detect any fraud directly tied to legitimate SDKs.

Among the apps found to contain the malicious SKD were com.colorisland.bubblebobble, com.zeldagames.n64emulator, and com.ninjasurvival.deathmatch.

Tell-tale signs that the apps were created with an ulterior motive were their sub-par operational capabilities and the ratings they received from users. 

“At first glance, RAINBOWMIX apps seem to work as advertised, although their quality likely leaves users wanting,” said researchers. 

They added: “Most of the RAINBOWMIX apps have a ‘C-shaped rating distribution curve’ (with primarily 1- and 5-star reviews), which is common with suspect apps.”

RAINBOWMIX tracked when users turned their screens on and off to determine the best moment for an ad to pop-up. Most of the ad traffic shown to users came from Brazil, Indonesia, Vietnam, and the United States.

Additionally, 53.3% of the traffic came from Chrome Mobile 84, while 3.6% came from Chrome Mobile 83.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

21% of UK Workers Feel More Vulnerable to Cybercrime During COVID-19

21% of UK Workers Feel More Vulnerable to Cybercrime During COVID-19

More than one in five (21%) UK workers feel more vulnerable to cybercrime since the start of the COVID-19 pandemic, according to a new study by PwC.

Stress or fatigue was the most common factor (35%) cited by those workers, followed by lack of skills and training to stay safe from cybercrime whilst working from home (19%).

Of the 1200 UK workers surveyed last month, nearly a third (32%) said they had observed an increase in speculative criminal activity, such as suspicious emails or malicious adverts and links.

Additionally, 22% revealed they considered themselves to be more vulnerable to a cyber-attack when they shared personal details with hospitality venues such as pubs and restaurants for contact tracing reasons. However, PwC noted the survey was conducted before the introduction of the UK government’s new NHS Test and Trace app, which will “hopefully allay some of the public’s fears.”

Daisy McCartney, cybersecurity culture and behaviour lead at PwC, commented: “Cyber-criminals are above all opportunistic and we are seeing them use the fear, uncertainty and stress around COVID-19 to target their victims and play on their emotions. As COVID-19 continues to dominate the news agenda, messaging related to vaccines, cures and financial relief will likely be used to target people.

“It is therefore understandable that people are feeling vulnerable to cybercrime, and according to our survey, 19% of people working from home during the pandemic do not feel that they have the necessary skills and training to keep safe from a cyber-attack. However, people should not feel helpless, there are simple steps they can take to protect themselves and just gaining an awareness of how criminals might seek to target them is a good start.”

McCartney added that with many workforces continuing to operate remotely amid the ongoing pandemic, it is vital that employers provide additional cybersecurity support and training for their staff at this time.

An increase in cybersecurity incidents has been observed this year, with malicious actors exploiting the major operational challenges faced by organizations. These have included COVID-themed phishing and malware attacks.

Chris Gaines, lead cybersecurity partner, PwC added: “We have seen a spike in cybersecurity incidents this year with criminals exploiting the challenges that people and organizations are facing from COVID-19. Many of these incidents were linked to ransomware attacks and some of them were accompanied by data breaches. Analysis by our Threat Intelligence team has shown that the pace and frequency of ransomware attacks is rising all the time.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk