<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>Spam Wars Dispatches</title>
<link>http://spamwars.com/</link>
<description></description>
<copyright>Copyright 2020</copyright>
<lastBuildDate>Tue, 28 May 2019 16:22:39 -0800</lastBuildDate>
<generator>http://www.movabletype.org/?v=3.121</generator>
<docs>http://blogs.law.harvard.edu/tech/rss</docs> 

<item>
<title>We Need You. Let Us Ravage Your Network</title>
<description><![CDATA[<p>Most online crooks are not picky about what company they want to infest with malware. The key is to trick some poor soul at the company to double-click the attached file to get the malware installed on anybody's PC at the company with an internet connection.</p>

<p>Once the malware is installed, some crooks sell access to that malware to other crooks who then root around the personal computer on which the malware is installed and to whatever local area network the PC might be connected. Because the malware easily snarfs up the PC user's username and password for email or other services, it is then a walk in the cyberpark to find other services running on the network. Sometimes it's product development details, sometimes it's bank account access, and sometimes it's payroll activity or emails (remember Hillary?). Or, depending on the crook, they might encrypt the entire network storage system, holding the data hostage until your company pays ransom.</p>

<p>So, once the crook's email message gets past whatever filtering might be on the email server, how does a crook get past the first line of defense: the hapless employee who wants the company to succeed? Simply make up a story that lets the employee think he or she will be a hero by responding to a new customer hungry for the company's products or services.</p>

<p>[By the way, the "hapless employee" is just as likely to be a top executive as a low-level worker. In fact, the Chief Whatever may believe that he or she is smarter than the average drone, and wants to be just as big a hero. Know-it-alls are the first to be compromised.]</p>

<p>That's the idea behind the following malware delivery email message. The Subject: line reads:</p>

<blockquote>
AW: Tender - 24-2019 Your Inquiry Ref.: 24-2019 dated 28.05.2019
</blockquote>

<p>This was a little unfortunate for the crook because the "AW" in the front is German for "RE", for a typical email message reply. He's trying to make it look as though the recipient has already had some communication with the guy, and everything is safe.</p>

<p>Here's the entire message:<br />
<blockquote><br />
<img src="http://spamwars.com/image/dispatch05_28_19.jpg" alt="Malware lure email message"><br />
</blockquote></p>

<p>The body is a decent example of a slightly distorted English message one might expect from a correspondent in India. And then there's the official-looking logo art and full identification block with physical address, phone numbers, and web site of a real company by that name. Unlike some crook invasions, it doesn't appear as though the actual Indian company's web site has been hacked because no nefarious links to the web site are embedded in this message. Instead, the bad stuff is all in the attachment.</p>

<p>The attachment is a file with an .iso extension. This type of file is an image of a mountable Windows disk volume. I have no idea what's on that volume, but double-clicking the file and allowing it to mount would be as dangerous as plugging in an unknown thumb drive into your PC. There is likely self-executing code that installs all the necessary loaders to let others clog up the works and start grabbing data.</p>

<p>Unfortunately, as I write this, VirusTotal shows detection of this file as malware in only five antivirus programs. My guess is that this file has been slightly modified from a tried-and-true piece of malware, but just enough to avoid signature detection by antivirus programs (called a zero-day attack).That's how an email message like this could get past malware filters on email servers and antivirus programs on PCs whose user double-clicks on it. </p>

<p>There is nothing new here, but it's important to keep this type of activity fresh in your mind to be <strong>highly suspicious</strong> of any email message containing an attachment you weren't expecting. In this case, you wouldn't be the hero saving your firm, but rather the goat that lost the company valuable private data and perhaps payroll for the next pay period. Your colleagues won't be too happy about that.</p>]]></description>
<link>http://spamwars.com/archives/2019/05/we_need_you_let.html</link>
<guid>http://spamwars.com/archives/2019/05/we_need_you_let.html</guid>
<category></category>
<pubDate>Tue, 28 May 2019 16:22:39 -0800</pubDate>
</item>
<item>
<title>Fake CIA Sextorion Scam</title>
<description><![CDATA[<p>Here's a new one I saw today. It claims to come from someone at the CIA who has advanced knowledge of an international pedophilia case they're supposedly working on. The recipient's email address and details were found in the course of their "investigation." This fellow has access to the files and will scrub them of your info for a $10,000 bribe (in BitCoin, of course). </p>

<blockquote>
<img src="http://spamwars.com/image/dispatch03_19_19.jpg" alt="CIA Sextortion Scam Email">
</blockquote>

<p>The From: address is tu-odom@hccz.gov-cia.tk, disguising as a Turkish-based CIA office, I suppose. Phony baloney.</p>

<p>In any case, this letter is well crafted, and will probably raise the adrenalin of many recipients, especially those who participate in that kind of illegal stuff on the Internet. Despite all the colorful CIA seals at the bottom of the letter, this one is from a crook in his bedroom or ramshackle apartment in a far away land.</p>]]></description>
<link>http://spamwars.com/archives/2019/03/fake_cia_sextor.html</link>
<guid>http://spamwars.com/archives/2019/03/fake_cia_sextor.html</guid>
<category></category>
<pubDate>Tue, 19 Mar 2019 13:08:45 -0800</pubDate>
</item>
<item>
<title>Heartless Scam</title>
<description><![CDATA[<p>The email below appeared in my inbox this morning. It's a total scam, of course, but not everyone would recognize it as such. There's a bit of a complicated story behind the brand name and everyday consumers' understanding. The outfit that advertises most and asks for donations is St. Jude's Children's Research Hospital. But the outfit referenced in the email is St. Jude Medical, a hospital group that has recently been acquired by Abbott, a medical device company. I doubt 5% of Americans would know the difference, while the rest associates "St. Jude" with the children's health care organization.</p>

<p>That's what really aggravates me about the scam in this email. It's a phony receipt, made to look like a credit card receipt printout for a St. Jude Medical facility in Canada. The amount is fairly substantial, especially if you think it's real and that you're about to be charged for this amount.</p>

<p>Remember that every email scam entices its recipients to act in some way. In this case, it's to click on the Payment details link. A harmless mouse rollover reveals the link is to a clothing company, whose web site has been hacked to include a page redirecting visitors to the crook's actual Evil Page.</p>

<p>It doesn't matter whether the destination page is for credit card phishing or malware installation (or both). The point is to avoid the temptation to perform the act that the crook wants you to perform. Each non-visit to the destination represents a failure, and further enticement to find a hobby other than conning innocent people with phony return address identities.</p>

<blockquote>
<img src="http://spamwars.com/image/dispatch08_02_18.jpg" alt="Phony Saint Jude receipt">
</blockquote>
]]></description>
<link>http://spamwars.com/archives/2018/08/heartless_scam.html</link>
<guid>http://spamwars.com/archives/2018/08/heartless_scam.html</guid>
<category></category>
<pubDate>Thu, 02 Aug 2018 12:48:55 -0800</pubDate>
</item>
<item>
<title>The Extortion Trick Must Be Working</title>
<description><![CDATA[<p>I'm genuinely sad to say that the recent rapid spread of the Bitcoin extortion scams described <a href="http://spamwars.com/archives/2018/07/another_bitcoin.html">here</a> and <a href="http://spamwars.com/archives/2018/04/bitcoin_extorti.html">here</a> indicates that enough recipients are being fooled into paying the ransom to encourage more crooks around the world to use the same scam. </p>

<p>On the other hand, if you know that these messages are pure horse hockey, the various machine translations by non-English speakers are somewhat entertaining. Here are two I received in the past two days:</p>

<blockquote>
Subject: You're my victim<br>

<p>Hi, victim.<br />
I writе you bеcause I put а mаlware оn thе wеb pagе with роrn whiсh yоu have visitеd.<br />
My virus grabbed all your рersonal infо and turnеd оn yоur camerа whiсh cаptured the prосess оf your onаnism. Just аfter that the soft sаvеd your соntaсt list.<br />
I will dеlеte thе cоmрromising vidео аnd info if you рay me 300 USD in bitcоin. This is аddress fоr рayment : 1KGJEVP5ygu5XPKbXC3X7BZ8YMXqppQGUV<br />
 <br />
I givе you 30 hоurs after you оpеn my messаge for mаking thе transасtion.<br />
Аs soon as you rеad thе message I'll sее it right awаy.<br />
It is nоt neсessary to tеll me thаt you hаve sent monеy to mе. This аddress is сonnеctеd tо yоu, my systеm will deletе еvеrything automаtically аftеr trаnsfer cоnfirmаtiоn.<br />
If yоu nеed 48 h just rеply оn this letter with +.<br />
You can visit the роlice station but nobody саn help you.<br />
If yоu try tо dесеivе me , I'll sеe it right аway !<br />
I dоnt livе in yоur сountry. So thеy саn not track my lоcаtiоn еven for 9 mоnths.<br />
Goоdbye. Dоnt forgеt abоut thе shame and to ignоrе, Yоur lifе cаn be ruinеd.<br />
</blockquote></p>

<blockquote>
Subject: Tickеt#928540465: 16/07/2018 07:53:17 Ῐts up to you to make a right decision<br>

<p>Hope you will not care about my language sentence structure, considering that i am from Denmark. I toxified your system with a virus and now have all of your personal information from your computer system. </p>

<p>It was set up on a mature web site then you've picked the online video and clicked on it, my software quickly got into your computer. </p>

<p>Then, your cam recorded you hand fucking, besides i captured a movie that you've looked at. </p>

<p>After a little while it also picked up every one of your social contact info. If you ever need me to erase your everything i have - transmit me 680 euros in btc it's a crypto-currency. It is my btc account transfer address : 1NxAmbD8p6ZtWa1e9Azjta5wk5MEZpqRQN </p>

<p>At this point you will have 27hours. to make a decision Once i will get the deal i'll wipe out this footage and everything completely. Otherwise, you should be sure that your footage would be forwarded to all your contacts.<br />
</blockquote></p>

<p>In my experience, you don't see criminal activity repeated online unless it is working. The cost for this kind of email campaign is negligible, All they need is a couple of suckers to pay up, and they've made it big.</p>

<p>Don't be a sucker.</p>]]></description>
<link>http://spamwars.com/archives/2018/07/the_extortion_t_1.html</link>
<guid>http://spamwars.com/archives/2018/07/the_extortion_t_1.html</guid>
<category></category>
<pubDate>Mon, 16 Jul 2018 10:45:54 -0800</pubDate>
</item>
<item>
<title>Another Bitcoin Extortion Scam</title>
<description><![CDATA[<p>I <a href="http://spamwars.com/archives/2018/04/bitcoin_extorti.html">reported back in April 2018</a> that an extortion scam was running around the email highways. Another one arrived today that might freak the bejeezus out of recipients because the message sender claims to have one of your passwords. Here's the message (with one word removed):</p>

<blockquote>
I know, [redacted], is your password. You do not know me and you are most likely thinking why you're getting this e mail, right? 

<p>actually, I actually setup a malware on the adult videos (porn material) website and you know what, you visited this website to experience fun (you know what I mean). While you were watching video clips, your browser began operating as a RDP (Remote control Desktop) having a key logger which provided me access to your display screen as well as cam. after that, my software collected all of your contacts from your Messenger, social networks, as well as email. </p>

<p>What exactly did I do?</p>

<p>I created a double-screen video. 1st part displays the video you were watching (you have a nice taste lmao), and next part shows the recording of your web cam. </p>

<p>What should you do?</p>

<p>Well, I believe, $2900 is a fair price tag for our little secret. You will make the payment by Bitcoin (if you don't know this, search "how to buy bitcoin" in Google). </p>

<p>BTC Address: 171GatjRZ9SpnrgKnTJuYsuDcA1gQwjVbJ<br />
(It is cAsE sensitive, so copy and paste it)</p>

<p>Important:<br />
You now have one day in order to make the payment. (I've a unique pixel in this message, and right now I know that you have read through this email message). If I do not get the BitCoins, I will, no doubt send out your video to all of your contacts including family members, co-workers, and many others. Nonetheless, if I do get paid, I'll erase the video immidiately. If you really want proof, reply with "Yes!" and I definitely will send your video recording to your 12 contacts. This is the non-negotiable offer, and so please do not waste my time and yours by replying to this email message.<br />
</blockquote></p>

<p>Other than the password business, the thrust of the message is the same as before: the "crook" claims to have installed malware on the recipient's computer that tracks browsing activity at a porn site and records the user's activity from the computer's built-in camera. It's easy for me to know this is a scam because I don't visit porn sites and my computer is protected by anti-virus software (I know, it's not always perfect, but it's better than nothing). </p>

<p>So what about the password thing?</p>

<p>It is well known that thousands of web servers have been hacked over the years, many of them yielding login credentials to the hackers. You can find dozens of databases/lists of username/password/email address combinations scattered around the web. It's a major reason you should not re-use the same credentials on multiple sites to prevent break-ins to multiple accounts you have created. Note that even a complex password created by password management software won't help in this case, because the hacker has grabbed that complex password from the hacked site. Using a different password for each site minimizes the potential for disaster. (Hackers will try stolen credentials on thousands of web sites to find access.)</p>

<p>It turns out that the username/password combo "revealed" in this crook's message was an old one that I used on a few non-critical sites (i.e., sites that did not contain any valuable personal information) in the early days. I have since updated all my passwords for critical sites to randomized strings that even I can't remember. I'll be in trouble if I should be captured like James Bond and strapped to a table where a laser slowly approaches my genitals to extract the secret passwords.</p>

<p>Just be aware: one or more of your login credentials are out in the public web for crooks to see. That's how they can try to get into your head with scam messages, such as this one.</p>

<p>One more note about this message. In the final paragraph, the crook claims to have included a "unique pixel" in the message that lets him know you've read the message. Unfortunately for him, the message was sent only in plain text (not HTML) form, so there was no remote image request made. And even it there were, I have my email client set to <em>not</em> automatically load remote content for all messages. These so-called beacon images are still used in HTML-formatted messages to confirm your email address as being actively viewed. </p>

<p>Protect yourself as best you can so you won't blow a gasket when you receive a scam email like this one.</p>]]></description>
<link>http://spamwars.com/archives/2018/07/another_bitcoin.html</link>
<guid>http://spamwars.com/archives/2018/07/another_bitcoin.html</guid>
<category></category>
<pubDate>Thu, 12 Jul 2018 12:44:12 -0800</pubDate>
</item>
<item>
<title>Another Day, Another Apple ID Phish</title>
<description><![CDATA[<p>The author of the phishing email below went to some effort in the design department; not so much in the English department. Even so, the tenor of the message seems dire to the unaware. That could lead the recipient to click on the Verify Your Account button, whose URL is to a bit.ly URL shortener address &mdash; always a sign of no goodness in this type of message. URL shorteners, such as bit.ly have their place, but not here. Apple would never utilize such a service.</p>

<blockquote>
<img src="http://spamwars.com/image/dispatch07_09_18.jpg" alt="Phony AppleID scam email message">
</blockquote>

<p>Your AppleID password is a valuable commodity. Guard it with your life!</p>]]></description>
<link>http://spamwars.com/archives/2018/07/another_day_ano_1.html</link>
<guid>http://spamwars.com/archives/2018/07/another_day_ano_1.html</guid>
<category></category>
<pubDate>Mon, 09 Jul 2018 10:04:22 -0800</pubDate>
</item>
<item>
<title>LinkedIn Phishing</title>
<description><![CDATA[<p>I am a LinkedIn member at the free account level, but I don't use it much. Thus, when I saw the following message in my Inbox, for a half-instant I wondered if LinkedIn was planning to bounce me for inactivity:</p>

<blockquote>
Message LinkedIn    YOUR ACCOUNT WILL BE TERMINATED!!!
</blockquote>

<p>In the next half-instant, I immediately figured the message was some kind of trick. Unless you start doing something illegal or rant with the "n" word, it's awfully hard to get an account terminated at social media sites. Even after you die or are abducted by aliens.</p>

<p>Here is the message in full:</p>

<blockquote>
<img src="http://spamwars.com/image/dispatch06_25_18.jpg" alt="LinkedIn phishing message">
</blockquote>

<p>Although the text is decent English with good spelling, there are plenty of other signals that this message is bogus. Can you spot them all?</p>

<ol>
<li>The From: address is a hotmail.com account, not linkedin.com</li>
<li>The text promises "full access" to LinkedIn as well as something about an upgrade via email. LinkedIn has multiple tiers, but anything other than the basic service is a paid, premium service. They don't give that stuff away.</li>
<li>You wouldn't know it about this particular message, but it was addressed to me at an email account I don't use for my LinkedIn account.</li>
<li>The message is copyrighted 2017, rather than the current year.</li>
<li>This message claims to come from LinkedIn Ireland. Now, the main company is based in Sunnyvale, CA and is owned by Microsoft. They may have an Irish branch, but why would that branch be concerned by my account?</li>
<li>Rolling the cursor atop the "Confirm your email" button reveals a link to a subdomain at a free web hosting service.</li>
<li>There is no LinkedIn logo art anywhere in the message. Highly unusual for any business communication from an online business.</li>
</ol>

<p>For such a short message, this phishing email stinks quite heavily. If you're sloppy in reusing passwords, think about how giving up your corporate email address and password can be. A crook could literally log into your company's system under your userID (probably the same as your email address before the @ sign), at which point a knowledgeable cracker could burrow deep inside the system to steal secrets or disrupt operations.</p>

<p>That, my friends, is why we must all stay on our toes with respect to incoming messages of any kind on any service.</p>]]></description>
<link>http://spamwars.com/archives/2018/06/linkedin_phishi.html</link>
<guid>http://spamwars.com/archives/2018/06/linkedin_phishi.html</guid>
<category></category>
<pubDate>Mon, 25 Jun 2018 09:48:32 -0800</pubDate>
</item>
<item>
<title>Netflix Phishing</title>
<description><![CDATA[<p>Another day, another phishing attempt.</p>

<p>This one is pretty run-of-the mill, but it attacks accounts held by lots of potential recipients. Unlike a phishing email I received yesterday targeting the comparatively tiny Bethpage Federal Credit Union, this Netflix attack would be much more likely to attract recipients in a massive scattershot mailing (which most phishing attempts are). </p>

<p>Here's the message:</p>

<blockquote>
<img src="http://spamwars.com/image/dispatch06_18_18.jpg" alt="Netflix phishing email message">
</blockquote>

<p>Although the message doesn't look very Netflixy to my eye, it has just enough polish to fool plenty, despite a couple of grammar/punctuation problems. Two main giveaways to the smell of this one are: 1) the From: email address (netflox.co!); and 2) rolling over the Update Account Details button shows a link to a domain that doesn't look anything related to Netflix.</p>

<p>As always, if you have even a tinge of concern about your account, visit the site via a previously saved bookmark, and log in like you normally do (you may be automatically logged into Netflix of you visit frequently enough). If there is a genuine problem with your account, you'll learn about it then.</p>]]></description>
<link>http://spamwars.com/archives/2018/06/netflix_phishin.html</link>
<guid>http://spamwars.com/archives/2018/06/netflix_phishin.html</guid>
<category></category>
<pubDate>Mon, 18 Jun 2018 15:12:55 -0800</pubDate>
</item>
<item>
<title>Luno Wallet Phishing</title>
<description><![CDATA[<p>I'm not a blockchain guy, so the email claiming to come from Luno Wallet asking me to verify my account was an immediate alarm to something sneaky. Here is the full text of the message:</p>

<blockquote>
From: Luno <br>
Subject: Verify Wallet

<p>Welcome to Luno<br />
 <br />
We have recently detected so many fraudulent SIGNUP on our website, we are hereby informing all Legit Luno users to immediately Validate their wallet by downloading attached Luno Validation form and verify your account is not a fraudulent Wallet.<br />
 <br />
<style color:red>Note: Unverified Wallet will be deleted, after 24hrs. Please ignore this mail to initiate immediate deactivation of account or Download attached FORM to keep your Luno wallet safe.</style><br />
 <br />
Thank You<br />
Team Luno<br />
</blockquote></p>

<p>The attachment was an HTML file, whose source code let me see what they're up to without even having to load the page (always a risky thing to do without prior inspection). The core portion of the form included fields for your email address, your email account password (!), your Luno password, and your phone number. The destination of the form submission was to a domain created last month, but whose identity is privacy blocked. </p>

<p>Those four little fields contain a ton of personal information that should never be in the hands of crooks. Besides, no third party ever has the need for your email account password. Giving that up means others have access not only to your sending server, but for IMAP-style accounts, also your entire server-stored archive. Blackmail, anyone?</p>

<p>Account verification scams are the leading phishing techniques, used for more than two decades. If you ever receive an email asking to verify one of your accounts, ignore the email, login to your account via a previously-saved bookmark, and see if the account needs attention. 99.99% of the time, you'll be in the clear without doing a thing.</p>]]></description>
<link>http://spamwars.com/archives/2018/06/luno_wallet_phi.html</link>
<guid>http://spamwars.com/archives/2018/06/luno_wallet_phi.html</guid>
<category></category>
<pubDate>Mon, 11 Jun 2018 09:33:30 -0800</pubDate>
</item>
<item>
<title>Apple-Branded Telephone Scam</title>
<description><![CDATA[<p>Although this blog is primarily about email and messaging spam or other crime, I believe the information below about a telephone scam is very important.</p>

<p>At the root of this scam is the fact that it's almost as easy to spoof Caller ID as it is the From: field of an email message. In this case, the scammers spoof Caller iD to look like a legitimate number belonging to Apple Technical Support (800-275-2273). This really is Apple's number, but only for calls going to Apple.</p>

<p>The call is a robocall, with a computerized voice saying something along the line of the following (plus or minus poor grammar):</p>

<blockquote>
This call is in regards to your Apple account. Our server has detected some suspicious hacking activity on Apple account. Please do not use your Apple devices until you speak with an Apple support representative. Please refrain using financial activity on devices. In order to speak with an Apple support representative right now, please press 1, or else call us back on our toll-free number 1-877-252-8067. I repeat at 1-877-252-8067. Thank you.
</blockquote>

<p>If you get tricked into pressing 1 or calling back on the provided number (note, it's different from the Caller ID number, and may vary from the one shown above), you will be guided to hand remote control of your device to the criminal, who will then lock up your machine and its data. To unlock the device, you will be instructed to buy gift cards, and provide the ID numbers to the crooks. </p>

<p>It's extortion, plain and simple, and it will ultimately require you to talk with the <em>real</em> Apple Support to reset your passwords. More than just your day will be ruined. </p>

<p>Some recipients of this phone message knew right away it was a scam because they had no Apple devices or accounts. They're the fortunate ones in this regard. But even lots of Windows users have iTunes accounts, and fear that they've been hacked&mdash;when, in truth, they have not.</p>

<p>So, how do you know if you've really been hacked without getting caught up in this scam? Simply log into whatever account(s) you might have that require your Apple ID via Apple software (e.g., iTunes, App Store, iBooks, iCloud, etc.). If there is a problem with your account, you'll find out about it there. But 99.999999% of the time, you'll experience no difficulty, and you have not been hacked. Ignore the phone message, and go on with your life.</p>

<p>Please spread this warning around far and wide. </p>]]></description>
<link>http://spamwars.com/archives/2018/05/applebranded_te.html</link>
<guid>http://spamwars.com/archives/2018/05/applebranded_te.html</guid>
<category></category>
<pubDate>Thu, 10 May 2018 14:04:16 -0800</pubDate>
</item>
<item>
<title>Elaborate iTunes Store Receipt Scam</title>
<description><![CDATA[<p>So many crooks are lazy, even the phishers who want to trick you into giving up your login credentials to valuable accounts. But the latest iTunes account credentials grifter created a nearly believable and sophisticated-looking email message designed (as is so often the case) to accomplish two things:</p>

<ol>
<li>Raise your blood pressure by tricking you into thinking someone has already hacked your account and ordered stuff you don't know about.</li>
<li>Trick you into clicking a link whose destination will prompt you to enter your Apple ID and password</li>
</ol>

<p>Your Apple ID can be pretty valuable, especially if you have preloaded your account with money of your own or gift cards. A determined crook can use your ID to get to other personal information, try to reset your email address and/or password, and even order stuff from the Apple Store (hardware goodies) shipped to them as a gift.</p>

<p>Without further ado, here is the phishing email that caught my attention:</p>

<blockquote>
<img src="http://spamwars.com/image/dispatch05_07_18.jpg" alt="iTunes Receipt Phishing email">
</blockquote>

<p>Adrenalin-pumped recipients may overlook the grammar and spelling mistakes out of fear for either being charged for stuff they didn't buy or that their iTunes or Apple Pay account may have been hacked. Neither is true, of course, and you can look at your list of purchased items in your iTunes account to prove it to yourself. Additionally, legitimate iTunes receipts never include a "Cancellation Order" link&mdash;getting a refund is a royal pain.</p>

<p>But the clincher, as shown in the image above by rolling the cursor atop one of the links, is that the links do not point to apple.com. On a touchscreen device, tap and hold your finger atop a link until the URL pops up for preview.</p>

<p>So, it's important not to freak out while your blood pressure rises with these kinds of scams. Take your time, study the message, and, whatever you do, don't click on any link or attachment.</p>]]></description>
<link>http://spamwars.com/archives/2018/05/elaborate_itune.html</link>
<guid>http://spamwars.com/archives/2018/05/elaborate_itune.html</guid>
<category></category>
<pubDate>Mon, 07 May 2018 20:56:14 -0800</pubDate>
</item>
<item>
<title>Bitcoin Extortion Scam/Spam</title>
<description><![CDATA[<p>Over the past year or two, mainstream news has reported incidents of ransomware, whereby a crook invades a personal or network computer, encrypts all data on the hard drives, and then demands payment in Bitcoin to retrieve the decryption key. If this happens to you, it can be very scary because there might not be a way to recover without paying ransom to some unknown, shadowy entity.</p>

<p>If you have heard of this real activity, you might be equally terrified to receive a spam email like this one:</p>

<blockquote>
From: Shame<br>
Subject: Read this carefully

<p>Hello.<br />
Dont pay attention on my illiteracy, I am from Belgium.<br />
 <br />
I put mine malicious program onto your device.<br />
 <br />
At present I thiefted all  personal background from your device. Moreover I have slightly more evidence.<br />
The most entertaining compromising which I stole- its a videotape with your masturbation.<br />
I put malicious software on a porn site and then you loaded it. The moment you selected the video and pressed play, my malware at once downloaded on your OS.<br />
After downloading, your front-camera shoot the video with you wanking,  additionally I captured exactly the video you masturbated on. In next week my malicious software captured all your social and work contacts.<br />
 <br />
If you wish to eliminate all the evidence- pay me 209 euro in Bitcoins.<br />
Here is my Bitcoin address -   1KdKczndv8p5TqmKniDh8Ut8oHpQ1NWaxR<br />
You have 20 h. to go from this moment. As soon as I receive transfer I will eliminate the evidence forever. Differently I will send the record to all your friends.<br />
</blockquote></p>

<p>Or another one of its relatives:</p>

<blockquote>
Subject: I collected very interesting content

<p>Good dаy.<br />
Do not mind on my illiteraсy, I am from Korеya.<br />
 <br />
I uploаded thе mаliсious рrogrаm оn your systеm.<br />
 <br />
Sinсe thаt moment I pilfеrеd all privy backgrоund from yоur systеm. Аdditiоnаlly I hаve some morе cоmрromising evidenсе. Thе most interеsting evidence that I stоle- its а videоtapе with your masturbаtion. I аdjusted virus оn a роrn wеb site аnd aftеr yоu lоaded it. Whеn you dеcided with the vidеo аnd tарpеd on а рlаy button, my deleteriоus sоft at оncе set up on your system. Аfter аdjusting, yоur cаmera shооt the vidеоtаpe with you sеlf-аbusing, in additiоn it sаvеd рrеcisеly the роrn vidеo yоu mаsturbatеd on. In nеxt fеw dаys my malwаre cоllеcted all yоur soсial and wоrk сontаcts.<br />
 <br />
If you need to destroy the records- transfer me 290 usd in Bitcoins.<br />
I provide you my Btc address -   1EpAQ1ERVhhQMnPx4k28Z8L3uH84Zc2u1Q<br />
You have 12 h. after reading. If I receive transaction I will destroy the videotape evermore. Differently I will forward the tape to all your contacts.<br />
</blockquote></p>

<p>Presuming you can work your way through the tortured English (which may be phony), these messages hit a lot of buttons: Malware, remote capture of your computer's camera, screen grabs, and the threat of, um, exposing your activity to everyone listed in your computer's address book. I'm sure that a lot of people receiving these messages did instant inventory-taking about the last times they downloaded porn to their computers and pressed the Play button. They probably also looked at their computer's camera to imagine what it might have captured, and then visualize what everyone in their address book will see if they don't pay up.</p>

<p>I knew these were fake messages because I don't download or watch porn on my computers. (You may wonder why I even <em>use</em> a computer.)  Even if this threat were real, the most shocking thing my computer's camera would catch is me struggling to get up from my desk chair with my arthritic knees. I was also curious why the crook wanted Bitcoin payments in amounts pegged to the Euro or US Dollar. Bitcoin values fluctuate so wildly hour-by-hour, I don't know how one could guarantee coming up with the exact amount to meet the demand (even after figuring out Bitcoin for the first time). </p>

<p>The bottom line on these messages is that they're empty extortion threats from lazy crooks. I don't even imagine there was any malware threat leading up to the sending of these messages. If there were, an up-to-date anti-virus package on your computers would be suitable protection. And for the truly paranoid, a Post-It sticker over the camera can add a bit of comfort (there are also some utility programs out there that block camera access, but I'm a little wary of them). </p>

<p>Also, avoid web sites that require you to download an unknown media player to view or hear their content. I've distrusted those for decades because installing such things is the same as intentionally loading malware onto your machine. You never know what else is piggybacked with the media player.</p>

<p>BTW, I normally block out identifying information associated with crooks, but I left the Bitcoin account numbers intact. Someone might try to hack and drain those accounts. That would be a shame.</p>]]></description>
<link>http://spamwars.com/archives/2018/04/bitcoin_extorti.html</link>
<guid>http://spamwars.com/archives/2018/04/bitcoin_extorti.html</guid>
<category></category>
<pubDate>Sat, 21 Apr 2018 15:25:39 -0800</pubDate>
</item>
<item>
<title>A Lure to Disaster</title>
<description><![CDATA[<p>It's a common pattern from evil senders, but one that will certainly trick lots of recipients to click the link in the message:</p>

<blockquote>
From: admin@supportbtc.com<br>
Subject: CONGRATS, You're ALL SETUP!<br>

<p>Hi there,</p>

<p>Thank you for becoming a loyal<br />
member of our group.</p>

<p>We have a very important gift for you:</p>

<p><span style="color: blue; text-decoration: underline">==>> Click here to download it right now</span></p>

<p>Be sure to keep this for yourself,<br />
as it's priceless, and we don't want<br />
it in the wrong hands.</p>

<p>Take care<br />
</blockquote></p>

<p>Some recipients, who think they're smart and tech-savvy, might equate the easily forged From: address domain to Bitcoin. They'd be wrong, of course, but the mistake gets the juices flowing that somehow this "group" wants to download some Bitcoin to your computer. It's priceless!</p>

<p>To the truly smart person, however, this message stinks to high heaven:</p>

<ol>
<li>You are not addressed by name in any way</li>
<li>You didn't apply to join this group (which you can't identify)</li>
<li>The group doesn't identify itself by name</li>
<li>The link goes to a URL signifying connection with Bolivia</li>
</ol>

<p>The link's site (I'm intentionally not revealing it for your safety) is so toxic, my virus protection software won't even allow a visit there. But if you were to manage to get through, the download would certainly be malware or worse (e.g., ransomware).</p>

<p><br />
</p>]]></description>
<link>http://spamwars.com/archives/2017/12/a_lure_to_disas.html</link>
<guid>http://spamwars.com/archives/2017/12/a_lure_to_disas.html</guid>
<category></category>
<pubDate>Thu, 07 Dec 2017 15:10:10 -0800</pubDate>
</item>
<item>
<title>Bad Old Spam Days</title>
<description><![CDATA[<p>Anyone who follows this blog knows I completely detest any kind of fakery, lying, and deceit. Olde tyme spammers used those tactics with abandon. Unfortunately, the CANSPAM law in the U.S. did not do nearly enough to get bad actors out of our inboxes, especially when the sources are outside the U.S.</p>

<p>I received the following message today, seeming to be a throwback to days gone by when spammers didn't care about their branding or honesty, because their goal is simply to get something of value from recipients without them even noticing it.</p>

<blockquote>
SUBJECT: Requesting Your Approval<br>

<p>DivTECH LLC wants to send you emails, but we need your permission before we do so.</p>

<p>We value your time and privacy, and will only be sending information that is relevant to your work. Messages could be in the form of promotions, updates, white papers and other awesome content.</p>

<p>However, we understand if you do not want to receive such emails. If this is the case, simply click on the blue "Opt Out" below, and we'll make sure that your email address is taken off the list.</p>

<p></p>

<p>Thank you for your time!</p>

<p>  </p>

<p>The information contained in this message is confidential. If you have received this message in error, please delete it or <span style="color: blue; text-decoration: underline">Opt Out</span> if you no longer wish to receive my emails. </p>

<p>If needed, you can reach us at DivTECH LLC, 181 Union St., South Weymouth, MA, United States, 02190. For my records, I show your contact information as: [removed]@dannyg.com.<br />
</blockquote></p>

<p>If this message had been framed according to the Subject: line and first line of text, I would take it to mean that they are simply asking me to confirm if I wanted to receive their messages, and doing nothing would stop it. But, as you see, the actual mechanism is the opposite. If I don't "Opt Out", I'll continue receiving their messages. BUT, the link of the Opt Out button leads to a completely different domain created just a couple of weeks ago. I have no idea where that opt out request ultimately goes. But I know it will confirm my address as being valid, ripe for additional spamming by untold hordes of spammers who rent the list of verified addresses.</p>

<p>I believe the mailer may have hijacked the DivTECH LLC identity as a cover for the mailing. The company does (or did) exist, and has a Facebook page that hasn't been touched since 2014. The link winds its way to a Canadian-owned domain (supposedly). </p>

<p>In any case, lots of recipients of this message will click on the link in the hope that they'll be opted out of this mailing. Nothing could be further from the truth.<br />
</p>]]></description>
<link>http://spamwars.com/archives/2017/11/bad_old_spam_da.html</link>
<guid>http://spamwars.com/archives/2017/11/bad_old_spam_da.html</guid>
<category></category>
<pubDate>Wed, 29 Nov 2017 11:00:32 -0800</pubDate>
</item>
<item>
<title>Fake Email Server Settings Warning</title>
<description><![CDATA[<p>Aside from a little formatting ugliness, the following email is an unfortunately decent attempt to phish for your email password (and, then, conceivably, to your account on the server and further server intrusions from there).</p>

<blockquote>
<img src="http://spamwars.com/image/dispatch11_09_17.jpg" alt="Fake email warning message.">
</blockquote>

<p>The Subject: line is pretty threatening:</p>

<blockquote>
Server settings failure is blocking incoming messages for [redacted]@dannyg.com - Please reset
</blockquote>

<p>To many typical computer users, the "Bounce reason" data would appear as gobbledygook, but to someone who also manages the personal or business email server (perhaps at your domain's ISP), it's very plausible gobbledygook. But even if you don't know what it means, the message goes on to provide a convenient link to follow to send a report to the mail team so they can fix the problem.</p>

<p>And that's where you get into big trouble.</p>

<p>If you follow my forever guideline to rollover any link before clicking it (something that would have saved John Podesta from a dumpster full of trouble), you'll see the destination URL is something you probably don't recognize. The URL includes your email address (the one used to get this message to you in the first place), so that if you follow the link, you reach a similar-looking page in your web browser that pre-fills a field with your email address. There's no magic to this feat: Any 12-year old with a little bit of JavaScript experience could do it. But the other, blank, field requests your email password. Fill that in and submit it, and you're toast.</p>

<p>BTW, there is another telltale sign to this American that the message comes from someplace other than my American-based ISPs: The body specifies a date in the dd-mm-yyyy format, rather than the expected mm-dd-yyyy format. The date was filled in by the crooked email bot sending the email from somewhere in the Eastern Hemisphere. I know this because my email server processed the message in the U.S. late in the evening of November 8.</p>

<p>Be careful out there.</p>]]></description>
<link>http://spamwars.com/archives/2017/11/fake_email_serv.html</link>
<guid>http://spamwars.com/archives/2017/11/fake_email_serv.html</guid>
<category></category>
<pubDate>Wed, 08 Nov 2017 21:36:45 -0800</pubDate>
</item>


</channel>
</rss>