{"id":7074,"date":"2017-03-22T08:10:25","date_gmt":"2017-03-22T16:10:25","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/03\/22\/news-865\/"},"modified":"2017-03-22T08:10:25","modified_gmt":"2017-03-22T16:10:25","slug":"news-865","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/03\/22\/news-865\/","title":{"rendered":"SMS phishing for the masses"},"content":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Wed, 22 Mar 2017 15:00:27 +0000<\/strong><\/p>\n<p>Phishing remains one of the top threats that affects both consumers and businesses thanks to ever\u00a0evolving tricks. While &#8216;classic&#8217; phishing emails remain a problem, they can somewhat be thwarted via spam filters, whereas SMS phishing scams are much more difficult to protect against.<\/p>\n<p>Case in point, here&#8217;s a fraudulent\u00a0text message\u00a0purporting to be from RBC, a Canadian financial institution, which made it through our phone without getting blocked:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-16920 aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/SMS_phish.png\" alt=\"\" width=\"390\" height=\"216\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/SMS_phish.png 608w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/SMS_phish-300x166.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/SMS_phish-600x333.png 600w\" sizes=\"auto, (max-width: 390px) 100vw, 390px\" \/><\/p>\n<p>Text message:<em> Activities on your RBC Account is unsual. click\u00a0 http:\/\/www1.royalbank.com.cgi-bin-rbaccess-rbunxcgi.gq to secure<\/em><\/p>\n<p>If you followed the instructions and visited\u00a0the link, you&#8217;d be redirected to a decoy site looking almost exactly like the real one.\u00a0The crooks have designed the template to harvest as many\u00a0credentials as they can (i.e. driver&#8217;s license, phone number, all three security questions) in order to gain illegal access to your account:<\/p>\n<p> <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/social-engineering-cybercrime\/2017\/03\/sms-phishing-for-the-masses\/#gallery-16916-1-slideshow\">Click to view slideshow.<\/a> <\/p>\n<p>It is pretty scary to think that within minutes you could give crooks all the information they need to perform all sorts of illegal activity on your bank account, as well as perpetrate additional identity theft by impersonating you.<\/p>\n<p>Checking the IP address where the phishing page resides (<em>166.62.36.128<\/em>), we find another\u00a0phish for Bank Of Montreal (BMO), but also a domain (<em>chatfellow.com<\/em>) used to host the PHP panel of\u00a0an application called &#8220;Sendroid&#8221;.<\/p>\n<p>Sendroid is a framework to help you manage your bulk SMS campaigns and in itself is not malicious. Users are required to have a proper SMS provider in order to actually start sending text messages.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/sendroid_sms.png\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-16926\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/sendroid_sms.png\" alt=\"\" width=\"936\" height=\"614\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/sendroid_sms.png 936w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/sendroid_sms-300x197.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/sendroid_sms-600x394.png 600w\" sizes=\"auto, (max-width: 936px) 100vw, 936px\" \/><\/a><\/p>\n<p>However, some user comments\u00a0left on Sendroid&#8217;s purchase page show how it could be easily abused by spammers:<\/p>\n<blockquote>\n<p>\u00a0I have like 4000 contact to send sms to. And my gateway batch size is set to 200. Does this mean that, the sendroid portal will only allow me to send sms to 200 people out of the 4000?<\/p>\n<\/blockquote>\n<p>That&#8217;s a lot of contacts, but who knows&#8230; could be a popular guy.<\/p>\n<p>It would be interesting to know the success rates of such phishing campaigns. Much like regular\u00a0spam, it&#8217;s all about volume and even getting a small fraction of marks is enough to make it profitable.<\/p>\n<p>Please be on the lookout for such fraudulent SMS text messages. The &#8220;intimacy&#8221; of receiving a message on a phone makes this scheme even more dangerous because we are more likely to have our guards down and fall for it.<\/p>\n<p>This campaign was reported to RBC and the website has been\u00a0blacklisted.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/social-engineering-cybercrime\/2017\/03\/sms-phishing-for-the-masses\/\">SMS phishing for the masses<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/social-engineering-cybercrime\/2017\/03\/sms-phishing-for-the-masses\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Wed, 22 Mar 2017 15:00:27 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/social-engineering-cybercrime\/2017\/03\/sms-phishing-for-the-masses\/' title='SMS phishing for the masses'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2014\/01\/photodune-5032556-mobile-phone-keypad-m.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>This post looks at a recent SMS phishing scam for the RBC bank and a tool the attackers may have used to bulk send fraudulent SMS messages.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/bank-of-montreal\/\" rel=\"tag\">Bank of Montreal<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/bmo\/\" rel=\"tag\">BMO<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing\/\" rel=\"tag\">phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/rbc\/\" rel=\"tag\">RBC<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/royal-bank\/\" rel=\"tag\">Royal Bank<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/sendroid\/\" rel=\"tag\">Sendroid<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/sms\/\" rel=\"tag\">sms<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/social-engineering-cybercrime\/2017\/03\/sms-phishing-for-the-masses\/' title='SMS phishing for the masses'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/social-engineering-cybercrime\/2017\/03\/sms-phishing-for-the-masses\/\">SMS phishing for the masses<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11701,11702,3924,11703,11704,11705,11706,10510],"class_list":["post-7074","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-bank-of-montreal","tag-bmo","tag-phishing","tag-rbc","tag-royal-bank","tag-sendroid","tag-sms","tag-social-engineering"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7074","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7074"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7074\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7074"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7074"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7074"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}