Connect with us

Hi, what are you looking for?

HEADLINES

Phishing scammers target Avengers fans, warns IT security firm

The release of the finale of the epic two-part movie featuring the Avengers has attracted lots of attention, shattering box office records.

Kaspersky Lab’s content filtering experts have found that cybercriminals could not resist the urge to use the movie for fraud and money theft.

To do so, they have created no less than a dozen websites, offering fans the opportunity to watch the new Avengers blockbuster free online in advance of national premieres.

Once a user agrees and clicks on the online-player icon, a short scene from the movie is shown, which is in fact just a part of the official trailer. After a few seconds, the video stops and the victim is redirected to registration and check out page that contains fields for bank card details including the CVV2 code. The site reassures the user that this is only for validation purposes, to prove that a user is a real person.  

Once the user has filled in the form with their payment details, the criminals can use them for stealing the user’s funds.

Advertisement. Scroll to continue reading.

“Social engineering methods are aimed at exploiting people’s emotions. An influential and much-loved franchise with an enormous global fan base seems like the perfect target. The temptation to take a few security shortcuts in order to be able to watch a long-awaited movie and not have to worry about spoilers or sold-out tickets can prove irresistible to loyal fans; that is what the attackers prey on,” says Tatyana Sidorina, a security researcher at Kaspersky Lab.

Kaspersky Lab advice for staying safe:

• Do not click on links in emails, texts, instant messaging or social media posts if they come from people or organizations you don’t know. Check for suspicious or unusual addresses when any personal or financial information is asked for, legitimate ones should start with ‘https’∙  

Phishers often exploit emotions. Signs that there could be phishers at work include messages that are unduly threatening (warning of a potential fine or other penalties, for example), demand immediate action, ask for vast amounts of very personal and seemingly irrelevant information, or simply sound too good to be true.

• Have a separate bank card and account with a limited amount of money specifically for online entertainment. This will help to avoid serious financial losses if your bank details are stolen.

Advertisement. Scroll to continue reading.

• Use a reliable security solution for comprehensive protection from a wide range of threats, such as Kaspersky Security Cloud

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

In a new report covering Q2 2024 – Q1 2025, Kaspersky has found over 250,000 cyberattacks disguised as popular anime among other shows and streaming platforms...

HEADLINES

From January to December 2024, Kaspersky solutions used by businesses here detected and blocked more than 53 million bruteforce attacks. 

HEADLINES

According to Kaspersky experts, 2024 saw over 3 billion malware attacks globally, with a daily average of 467,000 malicious files detected. Windows systems were...

HEADLINES

Cybercriminals target SMBs, schools, and other smaller organizations because they often have less robust security compared to large corporations and other institutions. 

HEADLINES

Sophos Counter Threat Unit revealed the NICKEL TAPESTRY threat group’s scheme involving fraudulent workers operating on behalf of North Korea (formally known as the...

HEADLINES

PRSP is a staunch advocate of communication based on honesty and integrity. While our role is to uphold and strengthen the reputation of our...

HEADLINES

Poor password management is compounded by a reliance on common combinations of names, dictionary words and numerals. Not only are these passwords relatively easy...

White Papers

This demonstrates that despite a slight improvement from last year, cybersecurity preparedness remains low as hyperconnectivity and AI introduce new complexities for security practitioners.

Advertisement