Showing posts with label charge. Show all posts
Showing posts with label charge. Show all posts

Thursday, August 18, 2011

Twitter: “ Twitter Might Start to Charge in October, Sign This Petition to Keep the Service Free ” Scam is Spreading Fast

By Cesar Ortiz
In this variation of the “scares” scam, hackers are attempting to steal your user name and your password and in turn, your private credentials, and in effect, take control of your account for hidden criminal actions. Users will receive a message from one of their friends passing up the “news” of a possible monetary charge for the social service. Hackers are using human social engineering in making sure they are not mentioning a final determination to charge, but rather they mention that there is a “possibility”. Users will think that there is no harm to sign such a petition. The research firm Sophos warned of the scam originally. In the scam scenario,one of your friends that already have fallen in the scam will unknowingly send you a message post that will say:

"Twitter might start to charge in October, sign this petition to keep the service free! -URL- http:/bitly.zxxx[Link]”

Let’s pretend for a moment you are the victim user. When you click on the short link to access your petition, a problem “appears” to happen. You are then presented with a very, very Twitter professional looking frame with logo and perfect colors and typefaces (a fake). In the window you are warned that your session has timed out and that you need to "re-authenticate" and login again. Users will “need” to proceed and type their password and user name in the Twitter fake window. As soon as the user clicks the login button, a hidden script will propagate the same message received about the scam to all his or her friends, therefore propagating the scam. The same script will record your credentials.

Needless to say, the “petition” is not shown anywhere. Unsuspecting users that clicked the short link may expect that many other unknown actions will take place from that point on, since the criminals have the user name and password. Users who fall into this trap should move quickly and do the following:

(1) Change your password immediately.

(2) Go to the Twitter Web Site using a PC, if you can, and revoke any application with a related name to the scam and revoke and delete any unknown posts, photos, API’s and any post, friends or anything else that does not look familiar to you. Remember, the scammers had full access to your account and a malicious script can create and post anything using a hidden malware. Be on the look out for scam e-mails and scam phone calls. Take your time on this task. Twitter is aware of this scam and is taking measures to block, warn users and mitigate the scam damage, but scammers will change the location of their DNS servers and URL’s sites very fast to keep the scam alive.

(3) Notify your friends of the scam and help them clean up the mess, make sure that you mention that you did not send the scam related post willingly, but rather unknowingly.

(4) Run your anti virus in full scan mode and make sure you set the anti virus program menu to "Real Time" scan.

Sunday, June 19, 2011

Facebook “ The president is finally taking charge!! !" Scam Spreading Virally

By Cesar Ortiz
In this malicious attack, scammers are after your Facebook user name and your password. Since the scam is spreading at an alarming rate and thousands of Facebook users have fallen into the trap, the scammers will make thousands of US dollars by selling in bulk, the users name and passwords. The actual price for a single Facebook user name and password in the black market bids web pages fluctuates from $1.50 to $1.75.

The scam begins with a very “Facebook looking” message from one of your friends, already a victim of the attack. The message looks like a YouTube video of President Obama at a press conference. At the left of the message is a photo of the president framed by a YouTube interface with all the video controls showing. The text reads as follows:

“The president is finally taking charge!!

statistics.mit.edu (Link)

Is this is really for real?”

The image looks like a thumbnail but if a user clicks on it, the following events will happen behind the scenes; (please assume you are the victim) you are redirected, using a malicious script, to a real MIT webpage and immediately, automatically taken to a very, very,  professional looking, but phony, Facebook login page. This page is designed to steal your username and password from you. In the background, the malicious script is also sending the same message you received to all your friends therefore propagating the scam. Your user name and password are stolen from you the moment you click the blue "Login" button in the fake screen.

By the time you read this post, Facebook will have blocked the original scam addresses, but hackers quickly change to alternate sites to keep the scam alive as much as they can. Anti-virus and malware detection and cleaning software providers will come out with a detection and removal update. All this counter actions take about a week or more, enough for the criminals who run the scam to make money.

If you or a friend has been victimized with this scam, the following actions have to be taken. (1) Change the Facebook password immediately (2) Run a full scan, not a quick one, of your anti-virus or malware detection software (3) Notify the friend that sent you the scam (unwillingly) (4) Notify all your friends that you sent them the scam message unwillingly. Since we don’t have the hacker’s scripts, we don’t know what the script will do in your Facebook account. Look for changes in your contents, but most of all, run the anti-virus and malware detection tools in full mode to detect any malicious script injected in your computer and or Facebook page and change your password immediately.