Showing posts with label Phishing Site. Show all posts
Showing posts with label Phishing Site. Show all posts

Saturday, 21 November 2015

PayPal Phishing Site On World Bank Group Website



A website run by the World Bank Group, has this week been compromised. The site climatesmartplanning.org, which was provided with a valid Extended Validation SSL Certificate, appeared for a short time one hardly be distinguished from real phishing site with a PayPal login page.

Visitors were asked to sign in with their own PayPal information. The entries were processed and sent to the criminals.

After this gave the site gave a message that the account data is temporarily not available, and it required an additional verification. Visitors were invited to give their name, date of birth, address, telephone number and finally to give up your credit card number plus the CSV code, writes Netcraft. Those who had completed everything, was eventually transferred to real website of PayPal.

According to Netcraft, the criminals can take advantage of the smart Extended Validation SSL certificate that has the site climatesmartplanning.org. Made it seem as if the site was to be trusted. The EV certificate has been revoked.

The Climate Smart Planning Platform is an initiative led by the World Bank, to develop employees with tools, data and knowledge to be busy in developing countries with climate change.

Saturday, 7 November 2015

US Cable Operator Arranges Data Breach For 500,000 Euros


US cable operator Cox Communications has with the regulator FCC reached a settlement of the equivalent of more than 500,000 euros last year after an attacker via social engineering access to the customer database and managed to get some of the customer data placed online.

The attacker approached a customer service representative and a provider of Cox and did thereby posing as an employee of the IT department. In both cases, he asked to log on to a phishing site, which also took both victims. With these credentials the attacker got access to the customer database, including names, email addresses, secret questions and answers, PINs and partial social security numbers and drivers license numbers.

Some of the information was then placed by the attacker on the Internet. The FCC then started an investigation or the cable company did have secure customer data. This showed that the systems are not applied measures that could mitigate the impact of the stolen credentials. Cox has now reached a settlement and will pay $ 595 000 and all affected customers still inform about the attack, which took place last August. The security has been tightened. The US cable operator has about 6 million customers.

Tuesday, 8 September 2015

Fraudsters Masquerading As British Banking On Twitter


Fraudsters have created an account on Twitter where they occur as the helpdesk of a British bank, but in reality they send people to a phishing site. The scammers registered on September 4 the account "AskMetroBank" and copied one-to-one to the profile information of the real Twitter account of Metro Bank, which can be found at "MetroBank_Help".

From the fake Twitter profile respond to the scammers on people's real Twitter account of the bank had asked a question. It was always used the same answer, that people to a phishing site by referring to verify the credentials of online banking there.Some users had the fraud by. Eventually warned also the bank for the scammers. Although the phishing site has since been taken down, the Twitter account of the scam is still active.

Sunday, 6 September 2015

NetBIOS Is Still Risk For Windows Computers


Although the NetBIOS interface has been around for over 30 years it is still a problem for modern Windows computers. NetBIOS stands for Network Basic Input Output System and is an interface that allows systems to communicate within a local network.

The problem with NetBIOS is that it uses no form of security. On a local network, everyone can reply to NetBIOS request.Such request shall be sent if for example a website is being queried and the DNS (Domain Name System) is not working. In this case NetBIOS used as a fallback. An attacker on the network can respond to the request and that redirect user to another website, such as a website containing malware or a phishing site.

It is also possible to imitate hostnames and thus to steal login credentials via NetBIOS or the traffic of users, encrypted SSL traffic after, intercept and manipulate. According to security firm Kleissner & Associates NetBIOS is still supported everywhere. Even wifi routers in aircraft routing NetBIOS packets. The company advises users and administrators therefore to disable NetBIOS for all network adapters. Recently warned also another expert for the risks of NetBIOS.

Friday, 21 August 2015

Phishing Springboard Hidden In PDF Documents


PDF documents are often used to infect computers with malware, cyber criminals but the format now use to lure victims to phishing sites. Researchers at Kaspersky Lab discovered a PDF document that is distributed via an e-mail scam.

According to the email, the recipient of the message received $ 53,000 in his account. However, the recipient must confirm the transaction, which can be done via the enclosed PDF document. The PDF document contains only an illustration that states that the document is protected and offers the user a button to view the contents. The button, however, points to a phishing site which looks like a PDF document with transaction data.

To view the data, the user must then enter their email address and password. These data are sent to the criminals. According to analyst Dmitry Bestuzhev, this is an interesting technique that some phishing filters can mislead.

Wednesday, 15 April 2015

Criminals Steal Nearly $ 1 Million Through Android Malware


In Russia, five people arrested who used Android malware to steal nearly $ 1 million from Russian and Ukrainian banks. The malware was spread via SMS and posing as Adobe Flash Player. Once installed on smartphones and tablets could steal the criminals in different ways money. Initially the money was through SMS banking captured.


This is a way to make money with some specific text messages are sent to the bank. Later, the malware was modified and used to steal credit card information. Once users Google Play on their device had opened there by the malware loaded a separate window that asked for credit card details. The completed information was sent to the criminals.

Finally, the criminals used phishing sites for various Russian and Ukrainian banks. Once users on the infected machine had started their mobile banking app malware replaced the original window for a phishing site. Again completed data were sent to the criminals. Who were with the login information and access to perform the SMS kinds of transactions on the device, so says the Russian Group IB.