{"id":9125,"date":"2017-09-06T16:10:46","date_gmt":"2017-09-07T00:10:46","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/09\/06\/news-2898\/"},"modified":"2017-09-06T16:10:46","modified_gmt":"2017-09-07T00:10:46","slug":"news-2898","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/09\/06\/news-2898\/","title":{"rendered":"Nigerian scams without the Nigerians"},"content":{"rendered":"<p><strong>Credit to Author: William Tsing| Date: Wed, 06 Sep 2017 23:00:09 +0000<\/strong><\/p>\n<p>Users in English speaking countries are quite familiar with the Nigerian scam: an important guy in Nigeria needs your help getting his money out of the country and if you assist with some transaction fees, a chunk of his fortune could be yours. But what about non-English speaking countries? What forms the baseline level of internet crap? Today we\u2019re going to look at the Chinese version \u2013 the seminar scam.<\/p>\n<h3>Step 1: the pitch<\/h3>\n<p>This is actually more common via SMS, presumably due to limited mobile spam tools. The subject line will reference upcoming training for generic business skills like project management, book keeping, or HR.<\/p>\n<p>\u9879\u76ee\u9886\u5bfc\u529b\u603b\u7ed3&#8212;8\u670823-24\u65e5\u5b66\u5427 \u300a\u9879\u76ee\u9886\u5bfc\u529b\u300b<\/p>\n<p>This particular message we received is advertising a &#8220;project leadership&#8221; seminar.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-19577\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/09\/initial-600x195.png\" alt=\"\" width=\"600\" height=\"195\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/09\/initial-600x195.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/09\/initial-300x97.png 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>These pitches vary in topic, generally staying around vague business topics and are so common that almost any Chinese internet user is likely to see one eventually. The provided mobile number doesn&#8217;t show any results besides more spam and the QQ isn&#8217;t registered to any notable groups. Generally, the accounts associated with these emails are used exclusively for the scam.<\/p>\n<h3>Step 2: the form<\/h3>\n<p>Naturally, we want to attend said seminar, so we sent a response asking how to register. Within a day, the scammer responded:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-19575\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/response-600x121.png\" alt=\"\" width=\"600\" height=\"121\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/response-600x121.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/response-300x61.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/08\/response.png 1256w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>He&#8217;s referencing a file that has a detailed agenda, as well as registration info. He also wants our Weixin, so that we can &#8220;maintain a long-term relationship.&#8221;<\/p>\n<p>The attached, clean file includes a \u201cregistration form\u201d requiring the following:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-19576\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/09\/form-600x277.png\" alt=\"\" width=\"600\" height=\"277\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/09\/form-600x277.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/09\/form-300x139.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/09\/form.png 840w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li>Company name, address, and bank with account number<\/li>\n<li>Attendee\u2019s name, phone number, and email addresses.<\/li>\n<\/ul>\n<p>This is the point where generic business spam begins to edge closer to malicious. Scammers will take the target&#8217;s money, and PII as well for use in further scams. Should a user actually fill this out, they will be signed up for every spammer&#8217;s list in perpetuity.<\/p>\n<h3>Step 3: the payment<\/h3>\n<p>Just in case we were wondering about receipts, the form lets us know that we can pick up our tickets the day of the \u201ctraining,\u201d and then provides a bank account that we can wire money directly to.<\/p>\n<p>Given that we didn\u2019t pay the guy and we did not go to Shanghai to check out the \u201cvenue\u201d, there&#8217;s still a possibility that this may be legit. That said:<\/p>\n<ul>\n<li>We responded from a free Chinese webmail, offering no company affiliation. This did not faze the scammer.<\/li>\n<li>There are estimates that up to 40% of Chinese private educational institutions (training centers, job skills, etc.) are unlicensed and\/or fraudulent<\/li>\n<li>The price of this training is 1800 yuan, which makes up a significant portion of the average Chinese monthly wage of 2300 yuan.<\/li>\n<\/ul>\n<p>The odds are fairly good that there either isn\u2019t any training, or the venue specified actually hosts a pyramid scheme that will train members on how to recruit new marks. Much like a Nigerian scam, this form of advance fee fraud is very common and familiar. Its familiarity is actually a plus, as anyone who responds to such an obvious pitch more or less preselects themselves as a vulnerable and easily manipulated target. And similar to the 419 scam&#8217;s exploitation of underdeveloped financial institutions in Nigeria, the seminar scam exploits a void in regulation in the Chinese adult education market. Seminar scams are a great reminder that regardless of the language or culture used, scammers will exploit the same weaknesses online, wherever they are.<\/p>\n<h3>Conclusion<\/h3>\n<p>So how do you defend yourself against seminar scams? First, don&#8217;t respond to the email and definitely don&#8217;t disclose any personal information. But also ask yourself, &#8220;Have I heard of this institution? Does it have a local reputation?&#8221; As well as &#8220;What reputable organization advertises in this way?&#8221; Probably not too many. Stay safe: be vigilant.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/09\/nigerian-scams-without-the-nigerians\/\">Nigerian scams without the Nigerians<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/09\/nigerian-scams-without-the-nigerians\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: William Tsing| Date: Wed, 06 Sep 2017 23:00:09 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/09\/nigerian-scams-without-the-nigerians\/' title='Nigerian scams without the Nigerians'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/09\/shutterstock_180970511.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Many in the United States are familiar with Nigerian scams, but what kind of scams are going on in non-English countries? Take a look at the Chinese version \u2013 the seminar scam.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/419-scam\/\" rel=\"tag\">419 scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/china\/\" rel=\"tag\">china<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/chinese-scam\/\" rel=\"tag\">Chinese scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fraud\/\" rel=\"tag\">fraud<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/scam\/\" rel=\"tag\">scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/seminar-scam\/\" rel=\"tag\">seminar scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spam\/\" rel=\"tag\">spam<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/09\/nigerian-scams-without-the-nigerians\/' title='Nigerian scams without the Nigerians'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/09\/nigerian-scams-without-the-nigerians\/\">Nigerian scams without the Nigerians<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[14360,402,14477,4503,9751,3985,14478,10510,10518],"class_list":["post-9125","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-419-scam","tag-china","tag-chinese-scam","tag-cybercrime","tag-fraud","tag-scam","tag-seminar-scam","tag-social-engineering","tag-spam"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=9125"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9125\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=9125"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=9125"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=9125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}