Find news published in the date range below
and and
and and
and and
Clear
Euro
Arrow
54,0188
Dollar
Arrow
44,7901
Sterling
Arrow
63,0635
Gold
Arrow
6253,6346
BIST 100
Arrow
10.729

New methods of scammers

Cybersecurity company ESET has examined how new attackers join Telekopye groups through advertisements on underground forums. It analyzed the entire fraud operation in detail from the attackers' perspective. Telekopye's capabilities include creating phishing websites, sending phishing SMS and emails, and generating fake screenshots.

Don't leave your news choices to an algorithm - decide for yourself what you read. Add 12punto to your preferred sources!
New methods of scammers

In a report shared in August, ESET researchers discovered and analyzed Telekopye, a toolkit that helps people with less technical knowledge carry out online scams more easily. With the second report it published, it focused on the onboarding process of scammers, a detailed view of the entire fraud operation, and an analysis of fraud scenarios.

THEY MANAGE RECRUITMENT PROCESSES THROUGH ADVERTISEMENTS

Telekopye groups recruit new "Neanderthals" through advertisements on many different channels, including underground forums. The purpose of these advertisements is clearly stated: to defraud users on online marketplaces. Prospective Neanderthals are required to fill out an application form answering basic questions such as the experience they have in this "business" field. If approved by existing group members with a sufficiently high rank, new Neanderthals can start using Telekopye to its full potential.

There are three main fraud scenarios: seller, buyer, and refund. In the seller scenario, attackers pose as sellers and try to convince unsuspecting victims to purchase a non-existent product. When the victim shows interest in the product, the "seller" convinces them to pay online instead of paying in person and sends a link to a phishing website that looks like a legitimate payment site. However, unlike a legitimate webpage, this page asks for online banking login credentials, credit card information (sometimes including the balance), or other sensitive information. The phishing website automatically steals this.

In the buyer scenario, attackers act as buyers and look for victims to target. They show interest in a product and claim that they have already paid through the provided platform. They then send the victim an email or SMS message (created via Telekopye) containing a link to a carefully prepared phishing website, claiming that the victim must click this link to receive their money from the platform. The rest of the scenario is very similar to the "seller" scam. In the refund scenario, attackers create a situation where the victim expects a refund and then send the victim a phishing email containing a link to a phishing website, which again serves the same purpose.

SCAMMERS HAVE AREAS OF EXPERTISE

ESET researcher Radek Jizba, who investigated Telekopye, says, "In almost every Neanderthal group, we can find references to manuals that include online market research from which the Neanderthals derive their strategies and results." Jizba adds, "For example, in the buyer fraud scenario, Neanderthals choose their targets based on the type of products they sell. For instance, some groups stay completely away from electronics. The price of the product also plays an important role. The manuals suggest that in the buyer fraud scenario, Neanderthals should choose products priced between €9.50 and €290." Additionally, attackers using Telekopye leverage web scraping tools to quickly review many online marketplace listings and select the "perfect victim" who is most likely to fall for the scam.

Telekopye attackers believe their groups are full of "snitches" (such as law enforcement or researchers). Therefore, they adhere faithfully to the rules; basically, no in-depth questions are asked that could reveal the identity of other members of the group. As a result of violating these rules, you can become banned. The golden rule: "Work more, talk less."

Although the main targets of the scammers are online marketplaces popular in Russia such as OLX and YULA, ESET has also observed targets that are not specific to Russia, such as BlaBlaCar and eBay, and even targets that have nothing in common with Russia, such as Jófogás and Sbazar.


News Source: 12punto

investigation cybersecurity