Fraud targeting second-hand shopping platforms detected
Kaspersky experts have recently uncovered a fraud attempt targeting users of a popular e-commerce platform in Turkey that focuses on second-hand goods.
AA
To initiate the attack in question, criminals must first make contact with a potential victim. To do this, they leave a comment on some products for sale on the e-commerce platform. They state that they are interested in purchasing the item in question and ask the seller to contact them via a phone number they share in return.
After contact is established by phone, the targeted individual is told that an error occurred while attempting to complete the purchase. To resolve the issue, the seller is asked to activate two-factor authentication via a link shared with them. The shared link redirects the person to a phishing website that appears to be a version of the e-commerce application with two-factor authentication enabled and contains an application package for Android. Thus, the victim invites a risky application onto their Android smartphone that can access the content on the phone screen, interact with other applications, and infect the device with other similar malware.
POPULAR PLATFORMS ARE ALSO UNDER THREAT
In a statement, Kaspersky Security Researcher Mert Değirmenci noted that popular e-commerce platforms attract the attention of cybercriminals who try to exploit the low digital literacy of potential victims through phishing, which remains one of the most popular types of fraud.
Değirmenci stated, "If you are using a specific e-commerce platform, it is recommended that you keep the conversation there and do not follow links to other websites. It is also very important to be careful, not to rush to sell or buy something, and to double-check all messages, especially those containing links. Otherwise, the planned transaction could result in financial loss or the infection of your device with malware."
Kaspersky experts recommend the following to avoid falling victim to phishing traps:
"Only open emails or messages and click on links if you are sure you can trust the sender. If a sender appears legitimate but the content of the message seems strange, contact the sender through an alternative communication channel to verify the situation. If you are using a specific e-commerce platform, keep the conversation there and do not follow links to other websites.
If you suspect you are facing a phishing page, check the spelling of the website's URL. The URL may contain errors that are difficult to notice at first glance, such as a 1 instead of an I or a 0 instead of an O. Use a proven security solution on all your personal devices. With access to international threat intelligence sources, these solutions have the ability to detect and block spam and phishing campaigns."