Top 3 Scams – December 1, 2019

img placeholder security brief

1. Top Ten Most Impersonated Brands by Phishers in Q3

Since this will be the last scams alert of 2019, we thought this blanket warning would be most helpful to start with. There are still two distinct attacks to look out for below. And if you receive our newsletter, you already know about the Disney+ issue (and have hopefully changed your password).

  1. PayPal
  2. Microsoft
  3. Netflix
  4. Facebook
  5. Bank of America
  6. Apple
  7. Chase
  8. CIBC (Canadian Imperial Bank of Commerce)
  9. Amazon
  10. DHL

– Vade Secure Phishers’ Favorites Q3 report

Why does this matter to you?

2. Don’t Get Sway-ed

Malicious actors have apparently decided that the future of phishing lies in exploiting trusted online services. You have undoubtedly seen the upshot of that decision in your inbox: an endless stream of phishing emails pushing links to malicious content hosted on services like Dropbox, Sharepoint/OneDrive, and Evernote, to name a few. Now the bad guys have a new favorite online service to exploit: Microsoft Sway.

If you’re not familiar with it, “Sway is an app that makes it easy to create and share interactive reports, personal stories, presentations, and more,” according to Microsoft. Essentially, you can make mini websites quickly and easily.

So far these criminals have not yet fully exploited Sway’s integration with other online services, such as YouTube and Facebook. (Give them time.) What they are doing, though, is skillfully deploying Sway to leverage the inherent trust that users place in Microsoft in order to trick you into clicking through to slick, convincing web pages that offer an inviting opportunity to cough up your login credentials.

These phishing attempts appear to link to Microsoft Teams, company surveys, file sharing, and voicemail message centers, for example.

Stay safe with these tips:

3. Fake Browser Updates

Malware delivered via fake browser updates is back and more sophisticated than ever.

Leveraging vulnerable website content management platforms–typically older versions of WordPress, Drupal, etc., that can be exploited by non-updated security code or bugs–these attacks seek to trick users into installing malware under the guise that their web browser is out-of-date.

We all know that software, including your web browser, will eventually need to be updated. So, it’s not so out-of-the-ordinary for users to be notified that a newer version of Chrome or Firefox, for example, is available.

Generally, this kind of notification uses the operating system’s normal update mechanisms. But anyone not familiar with how updates usually work, or someone in a hurry, can easily fall for this attack.

The initial malicious webpage performs a ton of browser validation and then transparently navigates the victim’s browser to a malicious page that, in turn, redirects them to a browser update screen that says something like, “You are using an older version of Chrome.” Other details may be included, and then there is typically a big green or red button saying Update Chrome, or the name of your browser.

So how can you protect yourself?

Share these scams:

Request a Consult

Whether you know exactly what you need or you would like our help in figuring it out, fill out the form.
We promise to get back to you promptly.

Clients, please use our Support form to submit tickets.