{"id":18641,"date":"2022-03-31T11:10:06","date_gmt":"2022-03-31T19:10:06","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/03\/31\/news-12374\/"},"modified":"2022-03-31T11:10:06","modified_gmt":"2022-03-31T19:10:06","slug":"news-12374","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/03\/31\/news-12374\/","title":{"rendered":"Tech support scam campaign targets Japanese visitors to PornHub"},"content":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Thu, 31 Mar 2022 19:00:05 +0000<\/strong><\/p>\n<p>The Malwarebytes Threat Intelligence team has identified a malvertising campaign targeting Japanese users. The campaign they discovered was found to be using a cloaking technique to lure visitors of popular adult site PornHub to a decoy site at the domain mixhd[.]club. <\/p>\n<h2>Cloaking<\/h2>\n<p>Cloaking is a method which gives visitors and search engines the impression that a website carries content that is different from what users actually see. In this case, every visitor that was not geolocated in Japan was shown a decoy page with content stolen from a well-known Japanese adult site.<\/p>\n<p>The web server in this case decides what the visitor gets to see based on the information provided by the visitor like the <a href=\"https:\/\/blog.malwarebytes.com\/security-world\/technology\/2017\/08\/explained-user-agent\/\">user-agent string<\/a>, browser language, IP address, and cookies.<\/p>\n<h2>Japan<\/h2>\n<p>With a population of some 125 million and a high level of connectivity, Japan has the third highest number of Internet users after China and the US. However, we hardly ever hear about any tech support scams directed at this audience.<\/p>\n<p>In fact, the <a href=\"https:\/\/www.japantimes.co.jp\/news\/2022\/01\/18\/national\/crime-legal\/sammers-in-tokyo\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">first arrests for tech support scams in Japan<\/a> only happened in January this year, when Tokyo police announced that they had arrested three people in connection with an alleged scam where the suspects claimed to be providing technical support for malware-infected computers.<\/p>\n<h2>The campaign<\/h2>\n<p>Visitors to PornHub were shown an advertisement for another site with adult content. Users that followed the advertisement and that were fingerprinted as being Japanese were confronted with this <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/browlock-2\/\">browser lock<\/a> page.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"55408\" data-permalink=\"https:\/\/blog.malwarebytes.com\/tech-support-scams\/2022\/03\/tech-support-scam-campaign-targets-japanese-visitors-to-pornhub\/attachment\/scam_-1\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/03\/scam_-1.png\" data-orig-size=\"1407,753\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"scam_-1\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/03\/scam_-1-300x161.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/03\/scam_-1-600x321.png\" width=\"1407\" height=\"753\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/03\/scam_-1.png\" alt=\"browlock pretending to be Microsoft warnings\" class=\"wp-image-55408\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/03\/scam_-1.png 1407w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/03\/scam_-1-300x161.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/03\/scam_-1-600x321.png 600w\" sizes=\"auto, (max-width: 1407px) 100vw, 1407px\" \/><figcaption><em>Japanese<\/em> <em>browser lock page<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Popups and an <a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/03\/alert.mp3\">audio warning<\/a> on the page urge the victim to call Microsoft support, but shows telephone numbers that do not belong to Microsoft.<\/p>\n<p>The goal is to defraud the victims in a tech support scam. Typically, scammers will use remote control of the affected system to help the victim get rid of the browser lock and the pop-ups at a steep price. They will then try to convince the victims to sign expensive contracts. In the case where the arrests were made, for example, victims were charged around \u00a530,000 (US$ 245) for half-year contracts.<\/p>\n<p>While most tech support scams are operated out of India, in this case Japanese police arrested the alleged ring master, a Filipino man. Based on additional evidence we collected, we believe there is a collaboration between criminal groups in India and the Philippines, with the former providing the traffic, pop-up alerts and browser locker infrastructure. But this is not limited to Japan, as we <a href=\"https:\/\/blog.malwarebytes.com\/tech-support-scams\/2022\/03\/tech-support-fraud-is-still-very-much-alive-says-latest-fbi-report\/\">reported<\/a> a few days ago tech support fraud is still a growing market in the US. <\/p>\n<p>Stay safe, everyone!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/tech-support-scams\/2022\/03\/tech-support-scam-campaign-targets-japanese-visitors-to-pornhub\/\">Tech support scam campaign targets Japanese visitors to PornHub<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/tech-support-scams\/2022\/03\/tech-support-scam-campaign-targets-japanese-visitors-to-pornhub\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Thu, 31 Mar 2022 19:00:05 +0000<\/strong><\/p>\n<p>The Malwarebytes Threat Intelligence team has identified a malvertising campaign targeting Japanese users of PornHub.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/tech-support-scams\/2022\/03\/tech-support-scam-campaign-targets-japanese-visitors-to-pornhub\/\">Tech support scam campaign targets Japanese visitors to PornHub<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[25564,25565,6675,10544,10577],"class_list":["post-18641","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-browser-lock","tag-cloaking","tag-pornhub","tag-tech-support-scam","tag-tech-support-scams"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18641"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18641\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18641"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}