{"id":44919,"date":"2021-08-16T10:18:32","date_gmt":"2021-08-16T02:18:32","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=44919"},"modified":"2021-08-16T10:18:34","modified_gmt":"2021-08-16T02:18:34","slug":"fake-deliveries-whatsapp-spam-among-new-scammer-tricks-in-q2-2021","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2021\/08\/16\/fake-deliveries-whatsapp-spam-among-new-scammer-tricks-in-q2-2021\/","title":{"rendered":"Fake deliveries, WhatsApp spam among new scammer tricks in Q2 2021"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>In Q2 2021, amidst continued disruption in supply chains and mail services, scammers sought to use this fact to steal money and credit card details.\u00a0<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since last year, scammers have been taking advantage of <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/usa.kaspersky.com\/blog\/covid-fake-delivery-service-spam-phishing\/21611\/\">disruption in deliveries<\/a> to convince users to open phishing links. This past quarter, not only has this trend continued, but the cybercriminals have become more adept at localizing their spam mailings. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Users experienced a surge in invoices in different languages asking for money related to anything from customs duties to shipment costs. With these mailings, victims are often taken to a fake website, where they risk not only losing money but also sharing bank card details.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh4.googleusercontent.com%2FxIn5tdjNepUJmgzvRpUHymgBgE4qZheBJieiJR-vkwu9KyHFDFeu0gnNd7vtDxouRF0d8TjqOvILHTMAjDO4kZH92TfGB1bPiiTBxXOpEeJvckhHHkicnvC5q0vMbqSqDkNy4eKe&amp;t=1629080132&amp;ymreqid=27f3344f-c727-c29c-1ce9-450034019200&amp;sig=1B9E8R38RtE0oo_AkJJKhQ--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Examples of fraudulent delivery emails&nbsp;<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybercriminals also launched websites that appeared to offer people the chance to buy parcels that could not reach the intended recipients. Such websites were set up like a lottery. Users were not aware of the contents of the package. They bid based on the weight of the package that\u2014if they \u201cwon\u201d\u2014never arrived, even after paying the winning bid.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another new trick from fraudsters this past quarter involved spam sent to WhatsApp requesting small amounts of money. These scams involved several different schemes. One asked that users take a survey about WhatsApp and send messages to several contacts to receive a prize. Another stated that the users already won a large prize\u2014all they needed to do to collect it is pay a small fee.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An additional scam took advantage of the debate surrounding <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.wired.com\/story\/whatsapp-facebook-data-share-notification\/\">WhatsApp\u2019s new privacy policy<\/a> that allowed it to exchange information with Facebook. Cybercriminals set up fake websites inviting users to a WhatsApp chat with \u201cbeautiful strangers\u201d. However, upon clicking the link to the chat room, the potential victim landed on a fake Facebook login page\u2014and risks giving up their personal information. Users also received links for fake WhatsApp messenger apps, putting them at risk of downloading malware.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh4.googleusercontent.com%2FdHMgMjkIkyCAd7lw3gyPflmaWVRUwES7Nq5PqP7Am5uJTa5WS_EF4tB1_5JAzuhMCreLRsKdn_-XdI1fZYnSH0tJh3QHhRsxYl-KbwAMszixesKHKTUZ7u2kLYu7b8VLnEAg-tX3&amp;t=1629080132&amp;ymreqid=27f3344f-c727-c29c-1ce9-450034019200&amp;sig=vY7spfvjlkX9m09MIWaRGQ--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>WhatsApp chat scam<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAs in the past, we\u2019re seeing attackers take advantage of new trends and disruptions to steal money and credentials, whether that\u2019s a growing user of messengers or continued problem with mail delivery amidst a pandemic. Spam and phishing schemes are still some of the most effective ways to launch successful attacks because they play on human emotion. The best thing users can do is be wary of any unexpected emails and be very careful about clicking on any email attachments or links\u2014go to the website directly,\u201d comments Tatyana Shcherbakova.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Learn more about spam and phishing in Q2 2021 on <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/spam-and-phishing-in-q2-2021\/103548\/\">Securelist<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To avoid falling victim to the aforementioned scams, Kaspersky experts recommend:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Check any links before clicking. Hover over it to preview the URL, and look for misspelling or other irregularities.<\/li><li>Even if a message or a letter came from one of your best friends, remember that their accounts&nbsp;could also have been hacked.&nbsp;Remain cautious in any situation.&nbsp;Even if a message seems friendly, treat links and attachments with&nbsp;attention.&nbsp;<\/li><li>It\u2019s better not to follow links from emails at all. Instead, you can open a new tab or window and enter the URL of your bank or other destination manually.&nbsp;<\/li><li>Install&nbsp;a trusted&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/internet-security\">security solution<\/a>&nbsp;and follow its recommendations.&nbsp;Then secure solutions&nbsp;will solve the majority of problems automatically and alert you if necessary.&nbsp;<\/li><li>It\u2019s safe practice to check the sender\u2019s address. Most spam comes from email addresses that don\u2019t make sense or appear as gibberish \u2013 for example, amazondeals@tX94002222aitx2.com or similar. By hovering over the sender&#8217;s name, which itself may be spelled oddly, you can see the full email address. If you\u2019re not sure if an email address is legitimate or not, you can put it into a search engine to check.&nbsp;<\/li><li>Consider what kind of information is being requested.&nbsp;Legitimate companies don\u2019t contact you out of the blue via unsolicited emails to ask you for personal information, such as banking or credit card details, your Social Security number and so on.<\/li><li>Be wary if the message is creating a sense of urgency.&nbsp;Spammers often try to apply pressure by creating a sense of urgency. For example, the subject line may contain words like \u201curgent\u201d or \u201cimmediate action required\u201d \u2013 to pressure you into acting.&nbsp;<\/li><li>Grammar and spelling&nbsp;check&nbsp;is&nbsp;the effective way to identify a scammer.&nbsp;Typos and bad grammar are red flags. So too are odd phrasings or unusual syntax, which might result from the email being translated back and forth through&nbsp;translators&nbsp;several times.&nbsp;<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Since last year, scammers have been taking advantage of disruption in deliveries to convince users to open phishing links. This past quarter, not only has this trend continued, but the cybercriminals have become more adept at localizing their spam mailings. <\/p>\n","protected":false},"author":6,"featured_media":44920,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[101,54],"class_list":["post-44919","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-kaspersky","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/44919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=44919"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/44919\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/44920"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=44919"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=44919"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=44919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}