Skip to main content

Cyber criminals looking to exploit in the anniversary of WhatsApp

WhatsApp turned ten years old in 2019, and that fact has not escaped the attention of cybercriminals looking to exploit the anniversary.

Researchers from ESET have received a WhatsApp message offering 1000GB of free internet data by way of a WhatsApp birthday present to its users.

That message, unsurprisingly, is neither from WhatsApp itself as it purported to be, nor is the offer of 1000GB of free internet data genuine. It is a scam, and not a very convincing one assuming you know what to look for that is.

Unfortunately, given that this is the 10th anniversary year for WhatsApp and gifts to loyal members are not exactly unusual, it would be all too easy for the unwary user to get carried away by the fraudulent promotion.


What does the message say?

"WhatsApp Offers 1000GB Free Internet!" the message reads, with a link to click for more details. That link is the first real giveaway that all may not be as it seems; it isn't an official WhatsApp domain. However, given that many businesses still run their promotions through third party organizations, a practice that has the knock-on effect of validating fraudulent plays such as this one, it's easy to understand how people may still click through.

If they did, then they would find themselves at a landing page, carrying the WhatsApp logo, and announcing: "We offer you 1000 GB free internet without Wi-Fi! On the occasion of our 10th anniversary of WhatsApp." The poorly composed message is overlaid by a bright yellow countdown sticker warning that a limited number of rewards are left, and the first of several questions to answer regarding how you found out about the offer.As the user starts to answer the questions, a pop-up appears that explains the promotional message must be shared with at least 30 other WhatsApp users to qualify for the promotional giveaway.

Is any malware installed?

The ESET researchers said that there was no evidence that the link itself installed any malicious software, nor scraped personal information, that could be changed by the perpetrators at any time. For now, at least, it would seem that they are happy enough in "racking up bogus ad clicks that ultimately bring revenues for the operators" of the campaign, ESET stated.

Indeed, the domain being used by the WhatsApp scammers also hosts numerous other brand-led so-called promotional offers, including ones for Adidas, Nestle and Rolex.

Can WhatsApp prevent this kind of scam?

"This is a great example of how the digital marketplace has degenerated to the point of easy exploitation by malicious actors," Ian Thornton-Trump, head of cybersecurity for Amtrust International, says. Thornton-Trump argues that the "freemium" pricing strategy by which a product or service is provided free of charge has been detrimental to both privacy and cybersecurity.

Even though, As ESET has stated, the initial scam doesn't go phishing for credentials that is not to say this will not be a possibility. "The whole 1000GB for WhatsApp 10th birthday seems legit," Thornton-Trump says, "I mean who pays for WhatsApp? It's a great attack to phish for credentials to WhatsApp and then pivot to other services on the largely correct assumption a common password will be used across all the victim's accounts."

So could WhatsApp itself do anything to stop this kind of scam? "The only thing WhatsApp can do is start a cyber counterintelligence campaign," Thornton-Trump concedes, "get the word out publicly to all users and in social media that this is a scam as education is our only hope..."



reference : https://www.forbes.com/sites/daveywinder/2019/07/29/whatsapp-security-warning-over-1000gb-of-data-message/#611862527089

Comments

Popular posts from this blog

Asus ZenBook Pro Duo UX581, ZenBook Duo UX481

Asus on Thursday unveiled its dual-screen laptop series in India which comprises the ZenBook Pro Duo (UX581) and the ZenBook Duo (UX481) at a starting price Rs. 2,09,990 and Rs. 89,990, respectively. The company refreshed its ZenBook lineup with Intel 10th Gen Core processors - the ZenBook 13 (UX334), ZenBook 14 (UX434), and ZenBook 15 (UX534), for Rs. 84,990, Rs. 84,990 and Rs. 1,24,990, respectively. Asus also launched the VivoBook S431 for Rs. 54,990 and VivoBook S532 for Rs. 69,990. With the ZenBook Pro Duo and ZenBook Duo, the company says it has paved way to a new form factor for laptops and come equipped with both a keyboard and a secondary touchscreen for input.  "The need for the industry to evolve with the changing times necessitates innovation. As one amongst the industry incumbents, we realised it was both an opportunity and responsibility for us to push the envelope, disrupt the status quo, and come up with a magnificent offering," Arnold Su, Head of Cons

Is FaceApp Really a Privacy Threat

A few tweets about FaceApp, an AI photo editor developed by a Russian company, sparked a privacy freakout among those who'd uploaded their selfies. However, security researchers say the concerns are overblown. Should you be afraid of FaceApp , the photo editor out of Russia accused of vacuuming up photos of millions of Americans? According to security researchers, we all need to calm down. The app isn't trying to invade your privacy and mass upload all the photos from your phone. "We have found nothing out of the ordinary in this app," Aviran Hazum , a researcher at the antivirus company Check Point, said in an email. Hazum is among the experts who've analyzed FaceApp and found no major privacy violations in the software's processes. "I must say that this app seems to be developed in a good fashion—no greedy permissions, and it does what they claim it does," he added. So why did the app suddenly raise alarms? FaceApp has actuall

Top 7 Smartphones Under 10000 in 2020

Expensive smartphones are often more interesting from a feature and specification viewpoint, but the real volumes flow in the budget segment. With mobile data becoming more affordable, many more Indians can now afford to get onto the smartphone bandwagon. These days, even affordable smartphones come with all of the features you’d expect to see on more expensive devices, including high-resolution screens, good cameras, fingerprint sensors and 4G connectivity. We’ve put together a list of some of the best affordable smartphones - priced at under Rs. 10,000 - that you can buy today. 1. Realme 3 Pro The Realme 3 Pro is the company's latest flagship, designed to take on the Redmi Note 7 Pro from Xiaomi. It features some new colours options and the same small notch and slim bezels as its predecessor, the Realme 2 Pro. The 6.3-inch full-HD+ IPS display produces vivid colours and is very legible under direct sunlight. You also get two Nano-SIM slots and a dedicated spot for a microSD c