Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label online safety tips. Show all posts

New Phishing Scam Uses Fake Credit Card Emails to Spread Info-Stealing Malware

 

A new wave of phishing emails is targeting unsuspecting users with what appears to be a harmless message from their credit card company—but behind that official-looking facade lies a dangerous malware threat.

According to a report by Cybernews, cybercriminals are sending fake emails that warn recipients about recent credit card activity, urging them to confirm or verify a transaction. These emails mimic genuine alerts from financial institutions and appear convincing at first glance. However, the real danger lies within the attachment or link included in the message.

Rather than a standard PDF or receipt, the attachment hides a .LNK file—commonly used for Windows shortcuts—disguised as an HTML page or pop-up. When clicked, it redirects the user to a seemingly legitimate website designed to hold their attention. Meanwhile, in the background, a multi-stage malware infection quietly begins.

One of the key techniques used in this attack is known as Reflective DLL Injection, which loads malicious code directly into the system's memory—specifically targeting Chrome browsers. This allows hackers to bypass traditional antivirus detection and gain deep access to the user’s device.

“The hackers can then proceed with any additional attacks including keylogging, data theft and creating a backdoor on the infected computer,” the report notes.

Once compromised, the infected device becomes a goldmine for attackers. They can log keystrokes, steal browser history, capture passwords, harvest credit card numbers, and even take over accounts—leading to financial fraud or identity theft.

To avoid falling victim, users are advised to exercise caution with any unexpected email that urges action, especially those involving money or security. Instead of clicking on links or attachments, visit the company’s official website by manually entering the URL, or access your account via their official app.

Additional cybersecurity measures can offer crucial layers of protection:

  • Enable two-factor or multi-factor authentication to block unauthorized access even if credentials are stolen.
  • Use a password manager to create and securely store complex, unique passwords across all online accounts.
  • Install trusted antivirus software with features like browser protection, real-time scanning, and a VPN to guard against shady websites and network threats.

As phishing scams continue to evolve, staying alert and informed is the best defense. If an email seems too urgent, too alarming, or too convenient—pause, verify, and protect your data.

YouTube: A Prime Target for Cybercriminals

As one of today's most popular social media platforms, YouTube frequently attracts cybercriminals who exploit it to run scams and distribute malware. These schemes often involve videos masquerading as tutorials for popular software or ads for cryptocurrency giveaways. In other cases, fraudsters embed malicious links in video descriptions or comments, making them appear as legitimate resources related to the video's content.

The theft of popular YouTube channels elevates these fraudulent campaigns, allowing cybercriminals to reach a vast audience of regular YouTube users. These stolen channels are repurposed to spread various scams and info-stealing malware, often through links to pirated and malware-infected software, movies, and game cheats. For YouTubers, losing access to their accounts can be distressing, leading to significant income loss and lasting reputational damage.

Most YouTube channel takeovers begin with phishing. Attackers create fake websites and send emails that appear to be from YouTube or Google, tricking targets into revealing their login credentials. Often, these emails promise sponsorship or collaboration deals, including attachments or links to supposed terms and conditions.

If accounts lack two-factor authentication (2FA) or if attackers circumvent this extra security measure, the threat becomes even more severe. Since late 2021, YouTube content creators have been required to use 2FA on the Google account associated with their channel. However, in some cases, such as the breach of Linus Tech Tips, attackers bypassed passwords and 2FA codes by stealing session cookies from victims' browsers, allowing them to sidestep additional security checks.

Attackers also use lists of usernames and passwords from past data breaches to hack into existing accounts, exploiting the fact that many people reuse passwords across different sites. Additionally, brute-force attacks, where automated tools try numerous password combinations, can be effective, especially if users have weak or common passwords and neglect 2FA.

Recent Trends and Malware

The AhnLab Security Intelligence Center (ASEC) recently reported an increase in hijacked YouTube channels, including one with 800,000 subscribers, used to distribute malware like RedLine Stealer, Vidar, and Lumma Stealer. According to the ESET Threat Report H2 2023, Lumma Stealer particularly surged in the latter half of last year, targeting crypto wallets, login credentials, and 2FA browser extensions. As noted in the ESET Threat Report H1 2024, these tools remain significant threats, often posing as game cheats or software cracks on YouTube.

In some cases, cybercriminals hijack Google accounts and quickly create and post thousands of videos distributing info-stealing malware. Victims may end up with compromised devices that further jeopardize their accounts on other platforms like Instagram, Facebook, X, Twitch, and Steam.

Staying Safe on YouTube

To protect yourself on YouTube, follow these tips:

  • Use Strong and Unique Login Credentials: Create robust passwords or passphrases and avoid reusing them across multiple sites. Consider using passkeys for added security.
  • Employ Strong 2FA: Use 2FA not just on your Google account, but also on all your accounts. Opt for authentication apps or hardware security keys over SMS-based methods.
  • Be Cautious with Emails and Links: Be wary of emails or messages claiming to be from YouTube or Google, especially if they request personal information or account credentials. Verify the sender's email address and avoid clicking on suspicious links or downloading unknown attachments.
  • Keep Software Updated: Ensure your operating system, browser, and other software are up-to-date to protect against known vulnerabilities.
  • Monitor Account Activity: Regularly check your account for any suspicious actions or login attempts. If you suspect your channel has been compromised, follow Google's guidance.
  • Stay Informed: Keep abreast of the latest cyber threats and scams targeting you online, including on YouTube, to better avoid falling victim.
  • Report and Block Suspicious Content: Report any suspicious or harmful content, comments, links, or users to YouTube and block such users to prevent further contact.
  • Secure Your Devices: Use multi-layered security software across your devices to guard against various threats.