{"id":18894,"date":"2022-04-29T03:10:06","date_gmt":"2022-04-29T11:10:06","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/04\/29\/news-12627\/"},"modified":"2022-04-29T03:10:06","modified_gmt":"2022-04-29T11:10:06","slug":"news-12627","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/04\/29\/news-12627\/","title":{"rendered":"Warning! Instagram Stories hides a scam in plain sight"},"content":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Fri, 29 Apr 2022 10:18:30 +0000<\/strong><\/p>\n<p>When someone finds their social media account compromised, they first think about letting their followers know. And they do. They warn others from reading any strange posts, usually containing a rogue link, before they sort out the matter behind the scenes.<\/p>\n<p>Some curious followers who missed these posts backtrack the feed\u2014only to find that nothing appears out of place. So where are they?<\/p>\n<p>Clever attackers are using platform functionality to appear invisible. This way, the chances of catching them are small. Apart from the victims themselves, nobody may realize that something dubious was in full view of everybody in the first place.<\/p>\n<h2>You don&#8217;t see it&#8230;<\/h2>\n<p>Here\u2019s a hijacked Instagram page.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"56028\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/warning-instagram-stories-hides-a-scam-in-plain-sight\/attachment\/created-with-gimp-34\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-instastories.jpg\" data-orig-size=\"870,872\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-instastories-300x300.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-instastories-600x600.jpg\" width=\"600\" height=\"600\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-instastories-600x600.jpg\" alt=\"\" class=\"wp-image-56028\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-instastories-600x600.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-instastories-300x300.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-instastories-150x150.jpg 150w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/02-instastories.jpg 870w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption><em>Well, you know what they say about cakes&#8230;<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Despite warnings by the account owner to avoid being ripped off by whoever took over their account, the page looks absolutely, positively <em>normal<\/em>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"56027\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/warning-instagram-stories-hides-a-scam-in-plain-sight\/attachment\/created-with-gimp-33\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-instastories.jpg\" data-orig-size=\"843,159\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-instastories-300x57.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-instastories-600x113.jpg\" loading=\"lazy\" width=\"600\" height=\"113\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-instastories-600x113.jpg\" alt=\"\" class=\"wp-image-56027\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-instastories-600x113.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-instastories-300x57.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/01-instastories.jpg 843w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption><em>Warning from the panic-stricken account owner posted on Facebook. But there doesn&#8217;t seem to be cause for panic.<\/em><\/figcaption><\/figure>\n<\/div>\n<pre class=\"wp-block-code\"><code>Instagram page is still hacked!! This is not me ..... I do not have a spare \u00a3150 to give to 5 winners unfortunately........ If you reply you will be messaging some {redacted}. please just report the account if you can and you're on my instagram page. Instagram are sorting it although very slowly!!!<\/code><\/pre>\n<p>There are no odd links in the Bio; the photographs are untouched; the user name hasn\u2019t been changed to anything peculiar. The page itself is acting as it should.<\/p>\n<p>So what is the problem here?<\/p>\n<h2>&#8230;and then you do<\/h2>\n<p>Instagram has a feature called Stories, first <u><a href=\"https:\/\/about.instagram.com\/blog\/announcements\/introducing-instagram-stories\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">introduced in 2016<\/a><\/u>. It&#8217;s a quick and easy way to upload zinger-style posts, short clips, or anything else that&#8217;s supposed to be a passing thought. Stories only last for 24 hours and then self-delete.<\/p>\n<p>A Story is designed to be evanescent\u2014don&#8217;t log on to Instagram for 24 hours and you&#8217;ll miss it entirely.<\/p>\n<p>As a result, people with bad intentions often hide their bogus postings in the Stories section instead of putting them directly onto the Instagram grid. This has a couple of advantages for the account hijacker:<\/p>\n<ul>\n<li>The self-delete feature is the perfect way for scammers to hide their tracks. Why clean up the mess when the platform does it for you after 24 hours? The only evidence left behind is direct messages or communication away from the platform.<\/li>\n<li>Account hijackers lure people into taking action. It might be blackmail, a promise of wealth, or a veiled malware download. Regardless, having these posts somewhat hidden away makes it feel more exclusive. If the offer sounds too good, they can argue that the take-up isn&#8217;t as significant as a victim may expect because only the lucky chosen few have spotted it.<\/li>\n<\/ul>\n<h2>Clouds in my coffee (in my cake, too)<\/h2>\n<p>Let\u2019s go back to the Instagram page we were looking at previously.<\/p>\n<p>Ignore the well-done cakes, and instead, let\u2019s click the profile&#8217;s Stories.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"56029\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/warning-instagram-stories-hides-a-scam-in-plain-sight\/attachment\/created-with-gimp-35\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/03-instastories.jpg\" data-orig-size=\"1110,711\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/03-instastories-300x192.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/03-instastories-600x384.jpg\" loading=\"lazy\" width=\"600\" height=\"384\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/03-instastories-600x384.jpg\" alt=\"\" class=\"wp-image-56029\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/03-instastories-600x384.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/03-instastories-300x192.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/03-instastories.jpg 1110w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption><em>The scam hidden in plain sight<\/em><\/figcaption><\/figure>\n<\/div>\n<pre class=\"wp-block-code\"><code>Everyone is getting this wrong... an ex policeman...lost his house, his car, and his girlfriend, what did he lose first???!! The winner get \u00a3150. Need just 5 winners.<\/code><\/pre>\n<p>This post is only visible for a few seconds, sandwiched between other Story images on the user&#8217;s &#8220;roll.&#8221; I do love a good riddle and decided to try my luck.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"56030\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/warning-instagram-stories-hides-a-scam-in-plain-sight\/attachment\/created-with-gimp-36\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/04-instastories.jpg\" data-orig-size=\"672,699\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/04-instastories-288x300.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/04-instastories-577x600.jpg\" loading=\"lazy\" width=\"577\" height=\"600\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/04-instastories-577x600.jpg\" alt=\"\" class=\"wp-image-56030\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/04-instastories-577x600.jpg 577w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/04-instastories-288x300.jpg 288w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/04-instastories.jpg 672w\" sizes=\"auto, (max-width: 577px) 100vw, 577px\" \/><figcaption><em>\u201cSend your PayPal or bank details,\u201d they say.<\/em><\/figcaption><\/figure>\n<\/div>\n<p>At this point, we dropped communications and reported the account.<\/p>\n<h2>Don&#8217;t fall for sleights of hand or risk losing money<\/h2>\n<p>Sending this person your PayPal or phone number will undoubtedly not end there. If your email address isn&#8217;t secure, they could try and compromise and gain control of associated accounts. They could send you funds that may be stolen or try to tie you up in money mule scams.<\/p>\n<p>Handing a stranger your bank details could land you in a <u><a href=\"https:\/\/www.which.co.uk\/consumer-rights\/advice\/i-think-i-may-have-given-a-fraudster-my-bank-details-aIIlU5o8cxGn\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">similar situation<\/a><\/u>. There&#8217;s always the risk of follow-up questions aimed at revealing more than you bargained for. Enough information provided could <u><a href=\"https:\/\/www.bbc.co.uk\/news\/business-55158687\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">result in bogus direct debits<\/a><\/u>. This also doesn\u2019t exclude the possibility of them asking for credit card information at some point.<\/p>\n<p>Next time you see a friend or stranger mention that their Instagram page has been hijacked, you\u2019ll know exactly where to look if you can&#8217;t readily see the evidence.<\/p>\n<p>Stay safe out there!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/warning-instagram-stories-hides-a-scam-in-plain-sight\/\">Warning! Instagram Stories hides a scam in plain sight<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/warning-instagram-stories-hides-a-scam-in-plain-sight\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Fri, 29 Apr 2022 10:18:30 +0000<\/strong><\/p>\n<p>Scammers are taking advantage of an Instagram feature that cleans up after them.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/warning-instagram-stories-hides-a-scam-in-plain-sight\/\">Warning! Instagram Stories hides a scam in plain sight<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[2143,25446,25897,10574],"class_list":["post-18894","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-instagram","tag-instagram-scam","tag-instagram-stories","tag-scams"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18894","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18894"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18894\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18894"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}