Friday, August 10, 2012

Nigerian Scam Swindles Victims by Offering Compensation for Being Scammed

Scam AlertSometimes you can’t help but to give scammers credit for being great storytellers.

Only a clever (and very greedy) cyberthief would think to send out a spam message offering money to compensate a scam victim JUST to lay the groundwork to scam them again.

Keep in mind that it’s highly unlikely for any money lost in a Nigerian scam to be recovered. So if you fall for one of many 419 scams floating around out there, it’s best that you consider your newfound knowledge and sense of internet security awareness as your “compensation.”

It will probably keep you from falling for Nigerian scam emails like the one below:
From: ECONOMICS AND FINANCIAL CRIMES COMMISSION (admin@efcc.nig.org)
Subject: PAYMENT OF COMPENSATION

The Economic and Financial Crimes Commission (EFCC)
15A Awolowo Road, Ikoyi, Lagos.
Nigeria
http://www.efccnigeria.org

Attention Victim,

The Federal Government of Nigeria through provisions in Section 419 of the Criminal Code came up with punitive measures to deter and punish offenders.The Advance Fee Fraud section deal mainly with cases of advance fee fraud(commonly called 419) such as obtaining by false pretense through different fraudulent schemes e.g. contract scam, credit card scam, inheritance scam, job scam, lottery scam, “wash wash” scam (money washing scam), marriage scam. Immigration scam, counterfeiting and religious scam. It also investigates cyber crime cases.

After proper investigations at Western Union Money Transfer and Money Gram office to know if you have truly sent money to fraudsters in Nigeria through Western Union Money Transfer or Money Gram, your name was found in Western Union Money Transfer database amongst those that have sent money through Western Union Money Transfer to Nigeria and this proves you right that you have truly been swindled by those unscrupulous persons by sending money to them through Western Union Money Transfer in the course of getting one fund or the other that is not real, right now we are working hand in hand with Western Union to track every fraudsters down, do not respond to their e-mails, letters and phone calls any longer, they are scams and you should be very careful to avoid being a victim to fraudsters any longer.

In this regard and in line with the meeting held in Geneva, Switzerland which mandated the Federal Republic of Nigeria through the Central Bank to compensate victims of scams defrauded by fraudsters in Nigeria, a sum of thirty thousand dollars ($30,000) has been deposited on your behalf at the Western Union office as compensation.

We have deposited your fund at Western Union Money Transfer agent location EMS Post office lagos, Nigeria. You are to contact the western union office with your details as directed, your fund has already been insured with your details to avoid misappropriation.

Contact the Western Union agent office through the email address stated below;

wuunionnig@aol.com

Yours sincerely,
Ibrahim Lamorde,
Chairman, Economic and Financial Crimes Commission (EFCC).

**************************************************************************************************

Please note that some fraudsters are claiming to be the Executive Chairman, Ibrahim Lamorde or staff of The Economic and Financial Crimes Commission have recently been sending phony e-mails/letters and also calling unsuspecting persons, with intent to defraud them. It is important to note that these fraudsters are criminals engaged in advance fee fraud. People throughout the world are falling victim to scams of various kinds. But remember - if it sounds too good to be true, it is probably a scam. In view of these, we unreservedly advice you to dissociate yourself from all correspondence and transactions entered into based on evidently fraudulent and fictitious claims.

**************************************************************************************************

What to Do If You Receive This Nigerian Scam Email


If you get your own copy of this email in your inbox, it’s recommended that you:

  • Do NOT reply to the email OR provide any personal or financial information.

  • Report the email to SpamCop.

  • Delete the email immediately.


Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet, “Like” us on Facebook or add us to your circle on Google+.

Wednesday, August 8, 2012

Spam Drags Olympic Gold Medalist Gabrielle Douglas’ Name in Dirt in Attempt to Spread Malware

Olympic Gold Medalist Gabrielle DouglasDon’t let your heart sink when an email drops in your inbox claiming that there’s a huge scandal surrounding Olympic Gold Medalist, Gabrielle Douglas – it’s all just a ploy to infect your PC with malware.

Barracuda Labs recently intercepted the following spam message, which demonstrates that cybercriminals never miss a beat and are currently trying to capitalize on the buzz surrounding the gymnast’s gold medal performance last week:
Subject: Huge scandal with the USA Women’s Gymnastics Team on the 2012 London Olympics

Recent Olympic gold medal winner, USA Women’s Gymnastics winner Gabrielle Douglas, faces a lifetime ban after reportedly testing positive to banned diuretic furosemide. With details of the case still emerging, British Olympics Committee has ordered a suspension of the athlete until final results arrive.

View the video on youtube now

Upon following the link, users will not be directed to YouTube.com, but a compromised third-party website dressed up to look like the popular video-sharing website.

Olympic Spam Links to Fake YouTube Site
Screenshot Credit: Barracuda Labs


In order to watch the [non-existent] video, users will be prompted to download a fake Flash Player update (adobe-flashplayer-update.exe), which is actually malware in hiding. Barracuda Labs identified the malware associated with this spam attack as a member of the Trojan.Clicker family.

This attack is only one of many ways cybercriminals have been looking to cash in on the Olympic games. In addition to pumping out malware-laced spam emails, cybercrooks have also taken to registering garbage Olympic domain names in order to generate revenue via advertisements and TV-to-PC scams.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

Shylock Trojan Swaps Bank's Number with Attacker's on Bank Websites

Bank IconWhoever is behind the Shylock Trojan is a big fan of chatting.

In February, Trusteer researchers discovered a configuration of the financial data stealing malware that used advanced web injection tactics to start live chat sessions between cybercriminals and their victims. This allowed fraudsters to obtain whatever information they wanted from targets in real-time.

Now Symantec researchers have stumbled upon a new variant of the Shylock Trojan that strives to spark up a conversation between victim and attacker by manipulating the bank’s contact information online, replacing the bank’s telephone number with the attacker’s.

Shylock Trojan Injects Fake Numbers on Bank Website
Photo Credit: Symantec


The numbers used by the attackers are disposable numbers, which can be easily created online. Hopefully anyone that’s presented with an injected fake telephone number gets the same results as Symantec researchers when they attempted to call: The first fake number Symantec researchers dialed instructed them to call a second number, and that second number rang without answer.

Despite not being able to reach the attackers, Symantec believes that the fake phone numbers are used by the bad guys to collect sensitive login or financial details from their victims and/or attempt to keep them from notifying their bank of any account issues.

The Shylock Trojan is said to target U.K. online banking websites, although their detection heat map (shown below) shows that the malware is present in other parts of the world.

Shylock Trojan Infection Heat Map
Photo Credit: Symantec



Protecting Your PC from Shylock


To minimize the chances of a Shylock Trojan infection, users are advised to:

  • Keep their operating system and installed software (especially Adobe Flash, PDF Reader and Java) fully patched and up-to-date.

  • Run antivirus software and keep the virus definitions current.

  • Exercise caution when browsing the web (that means no falling for social media scams or fake Adobe Flash updates) and checking email (no downloading files attached to emails from unknown sources).


[via Symantec]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

Tuesday, August 7, 2012

Scammers Phish for Victims While Impersonating Elderly Couple Who Won Lottery

Allen & Violet Large Win LotteryA few years ago, elderly couple Allen & Violet Large won the lottery and collected a cool $11.2 million dollars.

Instead of keeping their winnings all to themselves, they donated it to family members, charity groups and nearby businesses in their area.

While most of us simply appreciate idea that these folks chose to make such a generous decision to share their wealth with those around them, cybercriminals have decided to use the story as a gateway to yet another scam.

The scam starts off with an email similar to the one I received below:
From: Programa Jornal da Cultura (jornaldacultura@tvcultura.com.br)
Subject: Dear Lucky Winner….

I and my wife violet voluntarily decided to donate the sum of $500,000.00 USD to you as part of charity project to improve the lot of 10 lucky individuals worldwide.You can also verify the link below

http://www.dailymail.co.uk/news/article-1326473/Canadian-couple-Allen-Violet-Large-away-entire-11-2m-lottery-win.html

Send Your
Name..
Telephone..
Age..
Country..

To our private email: allen.violet-large01@live.com and please do not reply to this jornaldacultura@tvcultura.com.br

Good luck,
Allen and Violet Large

[Update 10/31/12: It seems scammers have bumped up the offerings to $750,000.]

As you can see, the scammers decided to throw in a link to the legitimate article to help build credibility (assuming you don't read the date).

Of course, this email was not sent by Allen or Violet Large, but a scammer that’s looking to make a quick buck through an advanced fee scheme, collect confidential information to commit identity fraud, or maybe both.

Bottom line is, don’t reply to this email (or any others like it) and definitely do NOT provide your personal or financial information.

Photo Credit: Daily Mail Online

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet, “Like” us on Facebook or add us to your circle on Google+.

Monday, August 6, 2012

Spam and Scams Hide Behind Large Number of “Olympic” Domains

2012 OlympicsKeep your guard up when browsing the internet for anything related to the Olympics.

Researchers at cloud-based antivirus firm Zscaler took a peek at the domains containing the string “Olympics” that have been accessed by their customers and noticed an alarming trend: a whopping 80% of the sites they observed were nothing more than spam or scams!

On the upside, none of the garbage Olympic sites involved sophisticated exploits and fell under one of the following categories:

  • Typosquatting Sites

  • TV-on-PC Scams

  • “Made for Adsense” Sites


Olympic Domain Typosquatters


Usually typosquatters will attempt to take advantage of spelling mistakes made when a user types in a domain by setting up survey scams to either collect information needed to dabble in identity theft or earn a commission for every completed survey through some sort of affiliate program.

For the most part, the Olympic typosquatters keep their junk domains parked and covered in advertisements and links, but a survey scam was spotted on olympics2012videoclips[dot]vidrr.net.

Example domains (based off the official nbcolympics.com domain):

  • nbcolympic.com

  • nbcolympics.org

  • nbolympics.com

  • mbcolympics.com


“TV on PC” Scams


Some cybercrooks are hoping to make a buck from people who are interested in watching the Olympics online via fake cable/satellite TV on PC subscriptions.

Example domains:

  • watchsummerolympics.com

  • watch-olympics-online.info

  • olympicstv.trueonlinetv.com

  • watcholympicslivestreams.us

  • olympic2012.livetelecast.us


"Made for AdSense" Sites


The only real focus for these types of sites is to get as much traffic to earn the scammer via Google AdSense ads. Sample site seen below.

Olympics Website Made for AdSense Ads


Screenshot Credit: Zscaler
Nothing much to see here, move along...


Zscaler did come across some malware posing as software necessary to see the Olympic games, so be careful not to download any files from untrusted/unknown sources.

Fyi, consider “streamolympicsonline.com” one of those “untrusted sources.”

For more examples of garbage Olympic domains and screenshots check out the Zscaler blog.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet, “Like” us on Facebook or add us to your circle on Google+

Friday, August 3, 2012

Buy of the Week: 15" Dell Vostro 1540 Laptop for $449

This offer expired on 8/10/12. Please check banner at the top of this page for active deals.


Dell Vostro 1540 LaptopKeep business running smoothly with the sturdy, budget-friendly and reliable 15.6" Vostro 1540 laptop. It offers essential mobility, brisk processing power, and vital security and IT support options.

Until August 10th, 2012, you can order a new 15.6" Dell Vostro 1540 laptop from Hyphenet for only $449, plus shipping!

Specifications for 15.6" Dell Vostro 1540 laptop

























































Display15.6" LED backlight
1366 x 768 (HD)
ProcessorIntel Core i3 380M / 2.53 GHz
Storage320 GB HDD (5400 RPM)
RAM2 GB DDR3 SDRAM
GraphicsIntel HD Graphics
Optical DriveDVD-Writer DL
Networking802.11n,
Bluetooth 3.0 HS,
Gigabit Ethernet
CameraIntegrated webcam
SoundStereo speakers,
microphone
Connection / Expansion3 x USB 2.0
HDMI
VGA
LAN
Microphone input
Headphone output
Audio line-out
3-in-1 Memory Card Reader
Operating SystemWindows 7 Home Premium 64-bit
Battery6-cell lithium-ion
48 Wh capacity
Warranty1 Year Limited Dell Warranty (on-site)

Don't miss out on this Buy of the Week! Call (619) 325-0990 to order your 15.6" Dell Vostro 1540 laptop today!


Buy of the Week offer valid through August 10th, 2012.

Note: Shipping and taxes apply.

Looking for something else? Check out our monthly deals or contact us to get a quote on the product you're searching for.

This offer expired on 8/10/12. Please check banner at the top of this page for active deals.

Thursday, August 2, 2012

AICPA Spam Threatens to Revoke License, Launches Malware Attack

AICPACybercriminals are sending out hoards of bogus emails purporting to be from the American Institute of Certified Public Accountants in an attempt to trick certified public accountants into visiting a malicious site to plant malware on their machine.

The email, spotted by internet security researchers at both Webroot and Barracuda Labs, claims that the recipient has been busted for their involvement in income tax fraud and warns that failure to refute the allegations within the allotted timeframe will result in their license being revoked.

That’s a pretty good lie to feed to someone who you want to click before thinking. The legitimate looking HTML layout probably doesn’t help either.

Here’s a copy of the email (note that the wording and number of days given to respond may vary from email to email):

AICPA Spam Malware Attack
Image Credit: Barracuda Labs



Subject: Your accountant CPA license termination

You are receiving this message as a Certified Public Accountant and a member of AICPA.
Having trouble reading this email? View it in your browser.

Revocation of Public Account Status due to tax return fraud accusations

Dear accountant officer,

We have received a complaint about your alleged assistance in income tax return fraud for one of your employers. According to AICPA Bylaw Section 700 your Certified Public Accountant status can be revoked in case of the occurrence of submitting of a misguided or fraudulent tax return for your client or employer.

Please be informed of the complaint below and respond to it within 14 days. The failure to respond within this time-frame will result in cancellation of your Accountant license.

Complaint.doc

The American Institute of Certified Public Accountants.

Email: service@aicpa.org
Tel. 888.777.7077
Fax. 800.362.5066

To no surprise, the “Complaint.doc” link in the email leads to a compromised WordPress site that displays a segment of the same speech to the user while the malware attack is silently performed in the background.

Should the attack be successful – which it may very well be if you don’t keep Adobe Flash and/or PDF reader fully patched and run antivirus on your system – then Worm:Win32/Cridex.E will be installed on your PC to partake in evil activities like traffic monitoring, data harvesting, arbitrary file downloading and whatnot.

Any login information grabbed by Cridex will be uploaded to a remote sever controlled by the attackers, which the malware religiously connects to every 20 minutes.

What to Do If You Receive AICPA Spam


If you receive an email similar to the one outlined above, you are advised to:

  • Avoid clicking on any of the embedded links.

  • Delete the email immediately.


The AICPA is aware of this phishing scheme and they have been in touch with law enforcement.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet, “Like” us on Facebook or add us to your circle on Google+