{"id":14129,"date":"2018-12-20T15:30:58","date_gmt":"2018-12-20T23:30:58","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/12\/20\/news-7896\/"},"modified":"2018-12-20T15:30:58","modified_gmt":"2018-12-20T23:30:58","slug":"news-7896","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/12\/20\/news-7896\/","title":{"rendered":"This online quiz is now confirmed to be a phishing scam"},"content":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Thu, 20 Dec 2018 18:30:00 +0000<\/strong><\/p>\n<p>Ah, online quizzes. Many of us know that they can be somewhat dodgy and nonsense, really\u2014but that doesn\u2019t stop us from clicking the \u201cStart quiz\u201d button anyway. Besides, you have time to kill, and there are only three questions to answer, right?<\/p>\n<h3>The right kind of wrong<\/h3>\n<p>Phishing attacks don\u2019t always start in your email inboxes anymore. Whether you\u2019re on a desktop, laptop, tablet, or <a href=\"https:\/\/blog.malwarebytes.com\/101\/2018\/12\/something-else-phishy-detect-phishing-attempts-mobile\/\" target=\"_blank\" rel=\"noopener\">smartphone<\/a>, there are several other vectors where users can encounter phishing attempts. And believe me, they don\u2019t have a flashing neon sign that could easily alert users that they are\u00a0after your personal information.<\/p>\n<p>Phishers have been one of the most resilient cybercriminals\u00a0out there to date. And Or Katz, principal lead security researcher for Akamai Technologies, has proven this point once again.<\/p>\n<p>In a recently published white paper entitled <em><a href=\"https:\/\/www.akamai.com\/us\/en\/multimedia\/documents\/report\/a-new-era-in-phishing-research-paper.pdf\" target=\"_blank\" rel=\"noopener\">\u201cA New Era in Phishing\u2014Games, Social, and Prizes\u201d<\/a><\/em> [PDF], Katz has confirmed what many of us have already long suspected: those short quizzes shared on Facebook, Twitter, and other social media platforms are scams. And behind them are sophisticated and coordinated efforts that were designed for prolonged user exposure to fraud campaigns.<\/p>\n<p>Katz and his team have studied 689 customized phishing campaigns that banked on 78 popular names of brands across industries. These brands include United Airlines, Target, Disneyland, and Dunkin\u2019 Donuts. All quiz-based phishing pages follow a templated format: They ask three questions and, once a user answers them\u2014note that they don\u2019t have to be correct\u2014they promise quiz takers a prize associated with the brand they\u2019re impersonating. For example, if the quiz is about Disneyland, quiz takers could potentially \u201cwin\u201d free passes.<\/p>\n<p>Quiz takers are then directed to a web page that asks for personal information\u2014so they can claim the prize, of course\u2014like their email address, physical address, and age.<\/p>\n<h3>The toolkit behind these \u201cpositive\u201d phishing campaigns<\/h3>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/glossary\/phishing-kit\/\" target=\"_blank\" rel=\"noopener\">Phishing kits<\/a> are a staple to a serious phisher\u2019s fraud arsenal. These nifty and reusable tools are popular in the underground market because they do most of the work with little effort from the scammers. It also makes phishing campaign creation a lot faster.<\/p>\n<p>According to <a href=\"https:\/\/blogs.akamai.com\/sitr\/2018\/12\/quiz-phishing-one-scam-78-variations.html\" target=\"_blank\" rel=\"noopener\">this accompanying blog post<\/a> to the Akamai paper, the quiz-driven phish kits they studied use the following social engineering tactics to gain user trust:<\/p>\n<ul>\n<li>A customized \u201cbrand\u201d website, wherein they display logos and brands of trusted companies they use to lure in targets and get them comfortable to answer the quiz questions.<\/li>\n<li>A call to action, wherein they create a sense of urgency, so the target would likely complete the quiz or give out information without thinking. One example of this is claiming that the high-valued prize can only be won by a limited number of quiz takers, so they need to get a move on.<\/li>\n<li>Multiple fake endorsements in social media, wherein fake social network profiles are used to strengthen the legitimacy of the supposed brand\u2019s offer. By showing the target that several people have already won and claimed the prize, the target would doubt less. It\u2019s also required for the target to share the link to the quiz in social media channels\u2014a classic <a href=\"https:\/\/blog.malwarebytes.com\/?s=survey%20scam\" target=\"_blank\" rel=\"noopener\">survey scam.<\/a><\/li>\n<\/ul>\n<div id=\"attachment_26680\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"26680\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/online-quiz-now-confirmed-phishing-scam\/attachment\/3qs\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/12\/3qs.png\" data-orig-size=\"1344,861\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"3qs\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/12\/3qs-300x192.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/12\/3qs-600x384.png\" class=\"wp-image-26680 size-large\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/12\/3qs-600x384.png\" alt=\"\" width=\"600\" height=\"384\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/12\/3qs-600x384.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/12\/3qs-300x192.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/12\/3qs.png 1344w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p class=\"wp-caption-text\"><em>Screen captures of sample sites using the same phish kit for the Three Questions Quiz scam (Courtesy of Akamai Technologies)<\/em><\/p>\n<\/div>\n<h3>Other phishing campaign findings<\/h3>\n<ul>\n<li>The brands abused by phishers in their campaign are companies that belong to airlines, retail, and food and beverage industries.<\/li>\n<li>82 percent of the actual domains used in these phishing campaigns have leveraged <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/typosquatting\/\" target=\"_blank\" rel=\"noopener\">typosquatting<\/a>.<\/li>\n<li>Newer versions of the phishing kit include added features, such as automatic translation\u2014which makes the scam accessible to non-English speakers\u2014and new fake social network profiles\u2014which makes the scam more reliable and dynamic.<\/li>\n<li>Phishing campaigns that use social networks are more effective compared to traditional phishing.<\/li>\n<\/ul>\n<h3>A new phishing campaign to watch out for<\/h3>\n<p>Akamai has predicted that phishing campaigns of this nature\u2014or those that play on a positive aspect of instead of a negative one, as in traditional phishing\u2014will only increase in the future. Instead of using scare tactics, phishers have now learned to exploit game mechanics and further tap into people\u2019s curiosity and desire for freebies. In the process, phishers have made Internet users receptive to them, without users realizing it.<\/p>\n<p>Users are advised to be more vigilant and critical when it comes to offers of freebies online, regardless of the form they are presented in, until they have verified that the offers are legitimate. While it may be fun to waste time on quizzes a contact happens to have shared on Facebook, it would be wise to give it a pass, and perhaps warn the poor fellow via PM that he might have been duped to give up his personal information to scammers.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/online-quiz-now-confirmed-phishing-scam\/\">This online quiz is now confirmed to be a phishing scam<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/online-quiz-now-confirmed-phishing-scam\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Thu, 20 Dec 2018 18:30:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/online-quiz-now-confirmed-phishing-scam\/' title='This online quiz is now confirmed to be a phishing scam'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/12\/shutterstock_1214717467.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>It\u2019s dubbed the \u2018Three Questions Quiz\u2019 scam, and not only are people letting their guard down, but they\u2019re also freely sharing it on social media, too. Do you think you have been duped by this before? Read on.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/a-new-era-in-phishing\/\" rel=\"tag\">a new era in phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing-quiz\/\" rel=\"tag\">phishing quiz<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing-scam\/\" rel=\"tag\">phishing scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/quiz-based-phishing-scam\/\" rel=\"tag\">quiz-based phishing scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/survey-scam\/\" rel=\"tag\">survey scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/three-question-quiz-scam\/\" rel=\"tag\">three question quiz scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/typosquatting\/\" rel=\"tag\">typosquatting<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/online-quiz-now-confirmed-phishing-scam\/' title='This online quiz is now confirmed to be a phishing scam'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/online-quiz-now-confirmed-phishing-scam\/\">This online quiz is now confirmed to be a phishing scam<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[20505,4503,20506,10502,20507,10510,20508,20509,15550],"class_list":["post-14129","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-a-new-era-in-phishing","tag-cybercrime","tag-phishing-quiz","tag-phishing-scam","tag-quiz-based-phishing-scam","tag-social-engineering","tag-survey-scam","tag-three-question-quiz-scam","tag-typosquatting"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14129"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14129\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14129"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}