{"id":24432,"date":"2024-05-02T08:10:24","date_gmt":"2024-05-02T16:10:24","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/05\/02\/news-18162\/"},"modified":"2024-05-02T08:10:24","modified_gmt":"2024-05-02T16:10:24","slug":"news-18162","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/05\/02\/news-18162\/","title":{"rendered":"Watch out for tech support scams lurking in sponsored search results"},"content":{"rendered":"\n<p><em>This blog post was written based on research carried out by J\u00e9r\u00f4me Segura.<\/em><\/p>\n<p>A campaign using sponsored search results is targeting home users and taking them to tech support scams.<\/p>\n<p>Sponsored search results are the ones that are listed at the top of search results and are labelled &#8220;Sponsored&#8221;. They&#8217;re often ads that are taken out by brands who want to get people to click through to their website. In the case of malicious sponsored ads, scammers tend to outbid the brands in order to be listed as the first search result.<\/p>\n<p>The criminals that buy the ads will go as far as displaying the official brand\u2019s website within the ad snippet, making it hard for an unsuspecting visitor to notice a difference.<\/p>\n<p>Who would, for example, be able to spot that the below ad for CNN is not legitimate. You\u2019ll have to click on the three dots (in front of where we added malicious ad) and look at the advertiser information to see that it\u2019s not the legitimate owner of the brand.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"701\" height=\"240\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/05\/Search_results.png\" alt=\"fake CNN sponsored ad\" class=\"wp-image-110016\" \/><\/figure>\n<p>Only then it becomes apparent that the real advertiser is not CNN, but instead a company called Yojoy Network Technology Co., Limited.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"571\" height=\"521\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/05\/Advertiser.png\" alt=\"Google Ads Transparency Center entry for Yojoy Network Technology\" class=\"wp-image-110017\" \/><\/figure>\n<p>Below, you can see another fake advertisement by the same advertiser, this time impersonating Amazon.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"777\" height=\"654\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/05\/Amazon_fake_ad.png\" alt=\"Another fake ad by Yojoy impersonating Amazon\" class=\"wp-image-110018\" \/><\/figure>\n<p>In our example, the scammers failed to use the correct CNN or Amazon icons, but in other cases (like another recent discovery by <a href=\"https:\/\/www.threatdown.com\/blog\/corporate-users-targeted-via-malicious-ads-and-modals\/\">Jerome Segura<\/a>), scammers have even used the correct icon.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"702\" height=\"264\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/05\/WSJ_icon.png\" alt=\"fake ad for Wall Street Journal\" class=\"wp-image-110019\" \/><\/figure>\n<p>The systems of the people that click one of these links are likely to assessed on what the most profitable follow-up is (using a method called fingerprinting). For systems running Windows, we found visitors are redirected to tech support scam websites such as this one.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"939\" height=\"680\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/05\/Scam_page.png\" alt=\"Typical Fake Microsoft alert page with popups, prompts all telling the visitor to call 1-844-476-5780 (tech support scammers)\" class=\"wp-image-110020\" \/><\/figure>\n<p class=\"has-text-align-center\"><em>Tech Support Scam site telling the visitor to call 1-844-476-5780 <\/em><\/p>\n<p>You undoubtedly know the type. Endless pop-ups, soundbites, and prompts telling the visitor that they should urgently call the displayed number to free their system of alleged malware.<\/p>\n<p>These <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2016\/05\/tech-support-scams\">tech support scammers<\/a> will impersonate legitimate software companies (i.e. Microsoft) and charge their victims hundreds or even thousands of dollars for completely bogus malware removal.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-getting-help-if-you-have-been-scammed\">Getting help if you have been scammed<\/h2>\n<p>Getting scammed is one of the worst feelings to experience. In many ways, you may feel like you have been violated and angry to have let your guard down. Perhaps you are even shocked and scared, and don\u2019t really know what to do now. The following tips will hopefully provide you with some guidance.<\/p>\n<p><strong>If you&#8217;ve already let the scammers in<\/strong><\/p>\n<ul>\n<li>Revoke any remote access the scammer has (if you are unsure, restart your computer). That should cut the remote session and kick them out of your computer.<\/li>\n<li>Scan your computer for malware. The miscreants may have installed password stealers or other Trojans to capture your keystrokes. Use a program such as&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/pricing\" target=\"_blank\" rel=\"noreferrer noopener\">Malwarebytes<\/a>&nbsp;to quickly identify and remove threats.<\/li>\n<li>Change all your passwords. (Windows password, email, banking, etc.)<\/li>\n<\/ul>\n<p><strong>If you&#8217;ve already paid<\/strong><\/p>\n<ul>\n<li>Contact your financial institution\/credit card company to reverse the charges and keep an eye out for future unwanted charges.<\/li>\n<li>If you gave them personal information such as date of birth, Social Security Number, full address, name, and maiden name, you may want to look at some form of <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection-row\">identity theft protection<\/a>.<\/li>\n<\/ul>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n<h2 class=\"wp-block-heading\" id=\"h-reporting-the-scam\"><strong>Reporting the scam<\/strong><\/h2>\n<p><strong>File a report<\/strong><\/p>\n<ul>\n<li>In the US:&nbsp;<a href=\"https:\/\/reportfraud.ftc.gov\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">File a complaint<\/a>&nbsp;(FTC)<\/li>\n<li>In Canada:&nbsp;<a href=\"http:\/\/www.antifraudcentre-centreantifraude.ca\/index-eng.htm\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact law enforcement<\/a><\/li>\n<li>In the UK:\u00a0<a href=\"http:\/\/www.actionfraud.police.uk\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report fraud<\/a>\u00a0|\u00a0<a href=\"http:\/\/www.tpsonline.org.uk\/tps\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report a cold call<\/a><\/li>\n<li>In Australia:&nbsp;<a href=\"http:\/\/www.scamwatch.gov.au\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report a scam<\/a><\/li>\n<\/ul>\n<p><strong>Shut down their remote software account<\/strong><\/p>\n<ul>\n<li>Write down the TeamViewer ID (9-digit code) and send it to&nbsp;<a href=\"https:\/\/www.teamviewer.com\/en\/global\/support\/customer-support\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">TeamViewer\u2019s support<\/a>. They can later use the information you provide to block people\/companies.<\/li>\n<li>LogMeIn:&nbsp;<a href=\"https:\/\/secure.logmeinrescue.com\/Customer\/ReportAbuse.aspx\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report abuse<\/a><\/li>\n<\/ul>\n<p><strong>Spread the word<\/strong> <\/p>\n<p>You can raise awareness by letting your friends, family, and other acquaintances know what happened to you. Although sharing your experience of falling victim to these scams may be embarrassing, educating other people will help someone caught in a similar situation and deter further scam attempts.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identit<\/strong>y<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">identity protection<\/a><\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/05\/watch-out-for-tech-support-scams-lurking-in-sponsored-search-results\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Our researchers found fake sponsored search results that lead consumers to a typical fake Microsoft alert site set up by tech support scammers. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[31318,5588,8200,32,10574,28474,10577,11997,31319],"class_list":["post-24432","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-1-844-476-5780","tag-amazon","tag-cnn","tag-news","tag-scams","tag-sponsored-ads","tag-tech-support-scams","tag-wall-street-journal","tag-yojoy-network-technology"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24432","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24432"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24432\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24432"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24432"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24432"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}