Google Search

Showing posts with label bogus. Show all posts
Showing posts with label bogus. Show all posts

Wednesday, September 4, 2013

An unholy alliance - Fake Anti-Virus, meet Bogus Support Call!

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

I'm sure you're familiar with fake anti-virus scams, or scareware.

That's the stuff that pops up, usually while you're browsing, to warn you about potential security risks.

Would you like a free scan?

Of course you would, and of course there are threats: viruses, spyware, dangerous cookies, sometimes dozens of terrifying malware items that your current security software must have missed.

Would you like to clean up (recommended)?

Well, why not?

Hmm. The cleanup isn't free: you have to pay, but when you do, all the "threats" magically disappear.

Of course, there's no magic, just deceit: the software simply stops lying to you about threats, and sets a configuration setting to remind itself, "This victims's paid up, pretend they're clean."

And I'm sure you're familiar with fake support call scams.

Your phone rings, and it's a surprisingly pushy chap who claims to be "working with Microsoft," or something like it, who has spotted suspicious network activity emanating from your PC.

"Would you like to do a free check for viruses, using diagnostic software built into Windows?"

Of course you wouldn't - who on earth does this guy think he is, calling you out of the blue? - but he's not taking no for an answer, and it's free, and you've got a virus, and what if you get sued for infecting other people, and...

So you reluctantly do the diagnostic test, and of course there's a diabolical virus that your current security software must have missed.

"Would you like to clean up?"

You do? That'll be $275 please. But, look! That terrible virus has gone!

In both cases, you've been offered advice you weren't seeking, from sources you didn't know, that used scare tactics to trick you into paying money for absolutely nothing. Deceit, extortion, fraud.

But it's not all plain sailing for the scammers.

The problem with the cold callers is that, by and large, they're hideously rude bully-boys who sound just as dodgy as they are.

Click. Down goes the phone.

And the problem with scareware popups is that people are getting wise (or at least inured) to their fanciful lies.

Click. Away with the warning dialog.

So it was amusing to have my attention drawn, thanks to Naked Security reader Alain Roy, to a scareware campaign that deliberately, if rather haplessly, tries to fuse these two approaches.

Don't waste your time calling 10,000 people until you find one who is scared enough that you can intimidate them into paying up!

Pre-select your victims by getting them to call you:

(Windows must be more pervasive and perspicacious at finding scareware than I thought - that's Safari on OS X!)

Then you get the traditional bogus security scan you're used to from scareware:

And there's even the legalistic smoke-and-mirrors like the cold callers use. (You'll notice that they hardly ever actually say outright that they work for Microsoft - it's always with Microsoft, or in Windows support, as though that somehow mitigates the arrant dishonesty of everything else they tell you.)

Well, now you know.

The scareware dialog is "not to be taken literally," and has been "modified in multiple ways."

Of course, on the real fake site, the disarmingly accurate Terms and Conditions appear in about 6-point black letters on a dark blue background, and the main way the "story" has been "modified" is to remove all vestiges of truth...

...but it nevertheless brought a wry smile to my weekend.

If you have friends or family who have been pestered to the point of worry by fake support callers, here's a short podcast you might like to get them to listen to.

We make it clear that these guys are scammers (and why), and offer some practical advice on how to deal with them.

(05 November 2010, duration 6'15", size 4.5MB)

Follow @duckblog


View the original article here

Sunday, September 23, 2012

Attacks on Java security hole hidden in bogus Microsoft Services Agreement email

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Globe. Image from ShutterstockOnline scammers are using a recent email from Microsoft as bait in a widespread spam campaign that exploits vulnerabilities in Oracle’s Java software to install malicious programs on vulnerable systems.

Experts at The SANS Institute's Internet Storm Center warned on Saturday that operators there received multiple reports of a spam campaign that uses a recent Microsoft email regarding changes to its Services Agreement for products such as Hotmail and Skydrive to fool users.

The attacks have prompted renewed calls for internet users to disable Java on their systems pending a new update from Oracle Corp. to fix critical, remotely exploitable vulnerabilities in the ubiquitous web technology.

According to SANS, the malicious email is based on an August 27 communication from Microsoft titled "Important Changes to Microsoft Services Agreement and Communication Preferences."

The phishing email replaces links in the original messages with malicious links that send unwitting readers to websites that install a new variant of the Zeus malware, ISC handler Russ McRee warned in a post on September 1st.

The actual Microsoft message, dated August 27, can be viewed here.

It details changes in the terms of a services agreement for users of a wide range of products, including Hotmail, Windows Live Messenger, Microsoft Photo Gallery and SkyDrive, the company’s hosted storage offering.

Blackhole, courtesy of ShutterstockThe malicious websites in question are running the latest versions of the Blackhole Exploit Kit, a kind of Swiss Army Knife for compromising vulnerable computers.

The Blackhole Exploit Kit is capable of analyzing the configuration and software installed on machines visiting web sites on which the exploit kit is installed, and then serve up just exploits that are likely to work against the intended target.

The recent addition of exploit code for the Java vulnerability has more than doubled the success rate of Blackhole exploits, compromising tens of thousands of new systems, according to data from the security firm Seculert.

This isn't the first phishing email that has been linked to attacks on the Java vulnerability. Last week, experts at SophosLabs discovered malicious emails purporting to including information on a tax rate increase that contained links to websites exploiting the Java hole.

Database giant Oracle acquired Java when it bought Sun Microsystems in 2009 and has faced criticism from security experts for failing to respond quickly to security vulnerabilities in the ubiquitous web technology before.

The latest security holes haven’t improved the company's image. It was forced to rush out a patch for the Java security hole last week and received withering criticism after the polish security consultancy Security Explorations disclosed that it reported the critical security hole to Oracle in April, four months earlier.

The company's image was further damaged when the patch Oracle released to fix the flaw failed to fully close the security hole. Security Explorations said that it informed Oracle on Friday that systems running the patched Java 7 Version 7 could be circumvented in a similar manner to earlier versions, allowing for "complete Java sandbox bypass."

Oracle has confirmed receipt of that report and is investigating, Security Explorations said.

In the meantime, ISC and others are advising users to disable Java until the next update is ready.

For those who want to keep Java running, SANS ISC said that email recipients should scrutinize the hyperlinks in any email messages by hovering their mouse cursor over the link prior to clicking on it and by inspecting email headers for suspicious messages.

Sophos experts Paul Ducklin and Chet Wisniewski offer more easy-to-understand advice about Java in the latest Techknow podcast: "All about Java".

Follow @paulfroberts

Blackhole and Globe image, courtesy of Shutterstock

Tags: BlackHole, Blackhole exploit kit, Internet Storm Center, ISC, Java, Malware, Microsoft, Microsoft Services Agreement, SANS, Spam, vulnerability


View the original article here