Tech support scams target victims via their ISP - 22 June 2016
http://www.bbc.com/news/technology-36084989
A new scam, in which fraudsters pose as legitimate internet service providers to offer bogus tech support, either via the phone or on the net, is on the rise, the BBC has found.
It is a twist on an old trick which involved cold-calling a victim - often claiming to represent Microsoft - and charging for fake tech support. The new variants have been spotted in the UK and US. BT said that it was investigating the issue.
The online version of the scam involves a realistic pop-up that interrupts a victim's normal browsing session with a message that appears to be legitimate and seems to come from the victim's real ISP. US security firm Malwarebytes has spotted several from US and Canadian ISPs, including ComCast and AT&T. It has also seen webpages created for UK ISPs, including TalkTalk and BT.
The pop-up contains a message saying that the ISP has "detected malware", and urging victims to call a number "for immediate assistance".
Jerome Segura, a consultant at security firm Malwarebytes, has been investigating tech support scams for years but when he came across the latest iteration, he nearly fell for it. "It caught me by surprise and I almost thought that it was real. It was a page from my ISP telling me my computer was infected. It was only when I looked in closer detail that I saw it was a scam," he told the BBC. He is not surprised scammers have found new methods to fool people.
"Cold calls are very wasteful and after years of being told, people are starting to realise it is a scam so the scammers have to find new ways to make it personalised and legitimate. It is more cost-effective and efficient than cold-calling," said Mr Segura.
How do scammers know your ISP?
In the case of cold calls it may just be a lucky case of guessing a common ISP but in the case of pop-ups, there is an altogether cleverer way for fraudsters to glean information that can help them.
How it works
Big ad networks allow users to win ad space on websites by bidding at a particular price
Criminals are taking advantage of this to place adverts which are infected with a single "bad" pixel
This pixel can redirect users and infect them in the background when they are browsing on a perfectly legitimate site - they do not even need to click on the ad. The malware in the ad redirects users to a website in the background - invisible to the user - which checks their computer and discovers their IP address. From the IP address it is easy to find out which ISP owns which IP address.
Victims will be served a pop-up tailored for their specific ISP which warns them their computer is infected and gives them a number to call
Article continues via link above ......
Last edited: