Tuesday, March 4, 2014

Watch Out For This Netflix “tech support” Scam

A security researcher has found a new twist on the traditional security hoodwink.

 
Jerome Segura has been tracking tech support scams for a year, documenting the ploys he's encountered. But even this one found him unprepared.

"Combining a phishing scam with a fake tech support call center is something that I'd never seen before," the Malwarebytes senior security researcher told Wired.co.uk. A video of the find shows Segura trying to enter a fake Netflix login on the streaming service's homepage, only to be presented with a notice telling him the account has been suspended, and telling him to call a fake tech support number.

He dutifully called up and was asked to download "Netflix Support Software"—really the remote control software TeamViewer, which allowed the scammer access to his system. Once he had hopped on, the hacker told Segura he'd been hacked. In fact, the scammer said he'd been hacked nine times, with one coming from Serbia, four from Russia, three from China, and one from Italy. It's all part of a tactic to instill fear and get the user to comply, explains Segura. Like when the helpful voice on the other end of the phone showed him a scan of apparent hacker activity—which was really just custom-made Windows batch script.

"By running their own tool, which looks authentic, the crooks can detect 'problems' that do not exist," says Segura. "Finally, showing those scan results adds to the fear factor, as well as creating a sense of urgency to fix the issue."

As well as scraping plenty of personal information from Segura's system, including a file named "banking 2013," the scammers continued by attempting to secure a payment of $389.97 (with a generous $50 Netflix discount) for Microsoft support to fix the problem. (He was repeatedly told that the problem happened because his security software is not up to scratch).

Then comes a little "fixing" after the call is passed on to a technician. This time, it's designed to induce the victim's comfort—"I can also see that these hackers were trying to access some of your personal information like documents and pictures. Do you have any pictures?" asked the helpful hacker, before proceeding to recover them for him.

Perhaps the most bizarre and unusual part, the "Microsoft technician" asked Segura to hold up a photo ID with his credit card information, because they are doing the transaction over the Internet and Microsoft wants to make sure he's the cardholder.

"The Neftlix theme was well thought out—from the suspended account ploy to the discount coupon if you agree to fix the issue, the bad guys have planned their approach in detail," Segura tells us. "Requesting a photo ID, as well as a snapshot of my credit card, was completely novel too. Despite being the untrustworthy ones, it is ironic they are trying to make sure the mark is not playing them. Aside from the fact that it is creepy, it creates a huge identity theft risk."

READ MORE/ VIDEO....

No comments: