{"id":14131,"date":"2018-12-20T15:31:15","date_gmt":"2018-12-20T23:31:15","guid":{"rendered":""},"modified":"2018-12-20T15:31:15","modified_gmt":"2018-12-20T23:31:15","slug":"news-7898","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/12\/20\/news-7898\/","title":{"rendered":"These Christmas gifts and greetings are the worst"},"content":{"rendered":"<p><strong>Credit to Author: Tatyana Shcherbakova| Date: Thu, 20 Dec 2018 13:24:53 +0000<\/strong><\/p>\n<p>All holidays involve some fuss and bother, and Christmas and New Year are probably the fussiest of all: You have to buy gifts, plan gatherings, cook food a week in advance, and remember well-wishes for family and friends. For scammers, it&#8217;s also a holiday \u2014 and a more enjoyable one at that. Because people are rushing round trying to do a million things at once, they relax their vigilance and become sitting ducks. In this post we look at two money-making schemes being used by scammers this season against people distracted by Christmas preparations.<a target=\"_blank\" href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/12\/20075945\/christmas-card-malware-featured.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-25062\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/12\/20075945\/christmas-card-malware-featured.jpg\" alt=\"\" width=\"1460\" height=\"960\" \/><\/a><\/p>\n<h2>Gift card malware<\/h2>\n<p>These days, gift cards are a universal solution to gift-giving quandaries. If you don&#8217;t know what to give someone, a gift card for a popular store will do nicely. And if you get a card for a store you never use, you can always regift it.<\/p>\n<p>So when you receive a message saying that an unknown someone has given you an Amazon or Apple gift card, that seems like a nice surprise. But shouldn&#8217;t you stop and wonder why a stranger would go to the trouble and expense?<\/p>\n<p>The first thing that should arouse suspicion is the address the letter was sent from. The message might look as if it came from Apple, Amazon, or some other store, yet the sender&#8217;s address clearly indicates a public mail service such as Gmail or Hotmail.<\/p>\n<p>The second reason to be doubtful is the document attached to the letter. The message says that you can receive your shiny new gift card by following the instructions in the DOC file attached \u2014 but it&#8217;s not a set of instructions; it&#8217;s a Trojan. <a target=\"_blank\" href=\"https:\/\/threats.kaspersky.com\/en\/threat\/Trojan-PSW.Win32.Azorult\/\">Trojan-PSW.Win32.Azorult<\/a>, to be precise.<\/p>\n<p>Don&#8217;t think that DOC attachments are harmless \u2014 they can contain macros for downloading malware. E-mail attachments with all kinds of extensions (ZIP, RAR, PUB, PIF, ACE, etc.) have been going around recently in spam, and if the extension looks unfamiliar to you or, on the contrary, if you often work with such files, extreme caution is called for.<\/p>\n<p>It may be the season of goodwill, but it&#8217;s unlikely that a kind-hearted stranger sent you a gift card; the chances that scammers are trying to slip you malware are somewhat higher. If downloaded, the Trojan will try to steal your accounts and personal data, which is probably not what you want from Santa. Ignore such messages as <a target=\"_blank\" href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/spam\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=termin-explanation\">spam<\/a>.<a target=\"_blank\" href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/12\/20082327\/christmas-card-malware-screen1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-25067\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/12\/20082327\/christmas-card-malware-screen1.png\" alt=\"Sample gift card scam that appears to be from Amazon or Apple. File attachment contains Azorult malware\" width=\"972\" height=\"714\" \/><\/a><\/p>\n<h3>Malicious e-cards<\/h3>\n<p> <\/strong><\/p>\n<p>Electronic greetings cards are popular with Internet users \u2014 one e-card with a standard platitude sent to all contacts is a great time-saver. Don&#8217;t be offended by such an impersonal greeting, be thankful it doesn&#8217;t contain something worse. Under the guise of e-cards, cybercriminals can send malicious files, such as <a target=\"_blank\" href=\"https:\/\/threats.kaspersky.com\/en\/threat\/Trojan-Banker.Win32.Emotet\/\">Trojan-Banker.Win32.Emotet<\/a>.<\/p>\n<p>To spot a fake, first check out the sender&#8217;s address. If it looks unfamiliar, it&#8217;s a good idea to delete the message right away \u2014 and never, ever open any attachments. If the address is known to you, but the message is not typical for the sender, don&#8217;t hastily open the attachment either. In most cases, regrettably, it&#8217;s not that hard to hack someone&#8217;s account, and sending malicious e-mails to your contacts is even simpler. In general, be wary of e-cards, especially any that are not just a JPEG or PNG image.<a target=\"_blank\" href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/12\/20082326\/christmas-card-malware-screen2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-25066\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/12\/20082326\/christmas-card-malware-screen2.png\" alt=\"Sample e-card containing the Emotet banking Trojan\" width=\"972\" height=\"514\" \/><\/a><\/p>\n<p>Handy services help users send bulk e-cards to friends, family, and acquaintances \u2014 but they work just as well for cybercriminals, who artfully exploit them. For scammers, well-known companies are a means for netting victims, and the popularity of such greetings only improves the chances of success. Besides, faking messages from well-known services is not very complicated.<\/p>\n<p>So, if you received an e-card supposedly from a well-known service, but the sender&#8217;s address looks odd or the card itself is in an attachment (plus the message doesn&#8217;t say who it came from), it&#8217;s better to delete it and stay well clear of the attachment. It is likely to contain malware, such as <a target=\"_blank\" href=\"https:\/\/threats.kaspersky.com\/ru\/threat\/Backdoor.Win32.Androm\/\">Backdoor.Win32.Androm<\/a>, which turns your computer into a part of a global botnet.<a target=\"_blank\" href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/12\/20082314\/christmas-card-malware-screen3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-25065\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/12\/20082314\/christmas-card-malware-screen3.png\" alt=\"A sample Hallmark e-card, sender unclear; opened, it spreads Backdoor.Win32.Androm, which zombifies computers.\" width=\"974\" height=\"912\" \/><\/a><\/p>\n<h3>What to do<\/h3>\n<p>To stop scammers from spoiling your Christmas dinner, we advise you to remain vigilant and follow these rules:<\/p>\n<ol>\n<li>Be very cautious and do not open attachments in suspicious e-mails, even if they contain seemingly innocuous gift or greetings cards. Consider a message suspicious if it was sent anonymously or by someone unknown, or if it seems to come from a known service but the sender&#8217;s address indicates otherwise.<\/li>\n<li>Don&#8217;t trust messages about unexpected gifts or prizes during the holiday season (or ever). It&#8217;s just another cybercriminal ruse. The exception is messages from official stores with discounts, bonuses, and coupons (but they will never offer you anything completely free).<\/li>\n<li>Use <a href=\"https:\/\/www.kaspersky.com\/advert\/security-cloud?redef=1&#038;THRU&#038;reseller=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____ksc___\" target=\"_blank\">robust security solutions<\/a> with antispam capability.<\/li>\n<\/ol>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"ksc-trial-generic\" \/> <br \/><a href=\"https:\/\/www.kaspersky.com\/blog\/christmas-card-malware\/25060\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Tatyana Shcherbakova| Date: Thu, 20 Dec 2018 13:24:53 +0000<\/strong><\/p>\n<p>Why you shouldn\u2019t open messages with e-cards from strangers, or believe that someone gave you an Amazon gift card for Christmas.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[],"class_list":["post-14131","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14131"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14131\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14131"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}