{"id":19207,"date":"2022-05-31T12:10:10","date_gmt":"2022-05-31T20:10:10","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/05\/31\/news-12940\/"},"modified":"2022-05-31T12:10:10","modified_gmt":"2022-05-31T20:10:10","slug":"news-12940","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/05\/31\/news-12940\/","title":{"rendered":"Runescape phish claims your email has been changed"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 31 May 2022 20:08:04 +0000<\/strong><\/p>\n<p>A Runescape-themed missive landed in our email inbox today, claiming action is required to secure our account. <\/p>\n<p>The malicious email and the scam behind it are perfect examples of one of the more reliable tactics in the world of phishing\u2014fooling a victim into thinking they need to take some action as part of a larger, ongoing process. With this tactic, phishing email recipients could ask themselves: Is this a mis-sent mail? Should I jump in halfway through whatever&#8217;s being proposed and course correct? Will I be sent additional worrying emails if I don&#8217;t?<\/p>\n<p>As bait, it&#8217;s perfect.<\/p>\n<h2>The scam<\/h2>\n<p>This email is being fired out to random addresses; it&#8217;s not a targeted attack. The phisher is simply hoping that of all the recipients, a few have an account with the service they&#8217;re imitating. In this case, the mail is spoofing players of Runescape, the popular free MMORPG title from Jagex. It reads as follows:<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"57028\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/runescape-phish-claims-your-email-has-been-changed\/attachment\/fake-runescape-mail\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-mail.png\" data-orig-size=\"654,807\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"fake-runescape-mail\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-mail-243x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-mail-486x600.png\" width=\"486\" height=\"600\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-mail-486x600.png\" alt=\"\" class=\"wp-image-57028\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-mail-486x600.png 486w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-mail-243x300.png 243w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-mail.png 654w\" sizes=\"auto, (max-width: 486px) 100vw, 486px\" \/><figcaption>&#8220;Your email address has been changed&#8221;<\/figcaption><\/figure>\n<blockquote class=\"wp-block-quote\">\n<p><em>YOUR EMAIL ADDRESS<br \/>HAS BEEN CHANGED<\/em><\/p>\n<p><em>You have successfully changed the registered email address for your RuneScape and Old School RuneScape account.<\/em><\/p>\n<p><em>Your account log-in details remain unchanged but your registered email address for all future password resets will be: [email removed]<\/em><\/p>\n<p><em>To cancel this change, please click on the button below.<\/em><\/p>\n<p><em>CANCEL CHANGE<\/em><\/p>\n<p><em>Button not working for you? Copy the URL below into your browser:<\/em><\/p>\n<\/blockquote>\n<p>Recipients may panic that their address has been accidentally added to someone else&#8217;s account and want to fix it as soon as possible. Alternatively, they may actually <em>have<\/em> a Runescape account and worry at the sight of seeing an unfamiliar email address as the &#8220;new&#8221; address for the account. Either way, people will click the link to see what this is all about.<\/p>\n<h2>The scam site<\/h2>\n<p>The site claims to be Old School Runescape, making use of a URL similar to the <a href=\"https:\/\/oldschool.runescape.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">real thing<\/a>. It asks visitors for a variety of data. First up is email \/ username and password.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-attachment-id=\"57029\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/runescape-phish-claims-your-email-has-been-changed\/attachment\/fake-runescape-site\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-site.png\" data-orig-size=\"641,638\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"fake-runescape-site\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-site-300x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-site-600x597.png\" loading=\"lazy\" width=\"600\" height=\"597\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-site-600x597.png\" alt=\"\" class=\"wp-image-57029\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-site-600x597.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-site-300x300.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-site-150x150.png 150w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-site.png 641w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption>Bogus login request<\/figcaption><\/figure>\n<p>Secondly, it asks for the visitor&#8217;s authenticator code. Lastly, the site asks for their bank PIN.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" data-attachment-id=\"57030\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/runescape-phish-claims-your-email-has-been-changed\/attachment\/fake-runescape-pin-request\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-pin-request.png\" data-orig-size=\"354,480\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"fake-runescape-pin-request\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-pin-request-221x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-pin-request.png\" loading=\"lazy\" width=\"354\" height=\"480\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-pin-request.png\" alt=\"\" class=\"wp-image-57030\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-pin-request.png 354w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/fake-runescape-pin-request-221x300.png 221w\" sizes=\"auto, (max-width: 354px) 100vw, 354px\" \/><figcaption>&#8220;Enter the bank pin&#8221;<\/figcaption><\/figure>\n<p>In Runescape, the &#8220;bank&#8221; is where the player stores their items. Someone with access to all of this can perform a fairly comprehensive clean-out of the victim&#8217;s account.<\/p>\n<h2>Discordant behaviour<\/h2>\n<p>The manner of sending the victim&#8217;s information is quite interesting. Looking at the code on the final submission page reveals the following reference to Discord:<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" data-attachment-id=\"57031\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/runescape-phish-claims-your-email-has-been-changed\/attachment\/discord-request\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/discord-request.png\" data-orig-size=\"900,514\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"discord-request\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/discord-request-300x171.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/discord-request-600x343.png\" loading=\"lazy\" width=\"600\" height=\"343\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/discord-request-600x343.png\" alt=\"\" class=\"wp-image-57031\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/discord-request-600x343.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/discord-request-300x171.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/05\/discord-request.png 900w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption>Discord Webhooks<\/figcaption><\/figure>\n<p>This is a technique where JavaScript is used to send <a href=\"https:\/\/dev.to\/oskarcodes\/send-automated-discord-messages-through-webhooks-using-javascript-1p01\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">automated messages to Bots in Discord channels via Webhooks<\/a>. The email, password, authenticator code, and bank PIN will in theory all be posted to whichever channel the Bot resides. From there, people may be sitting waiting for new messages to pop up and then steal the account manually before the authentication codes expire.<\/p>\n<h2>Avoiding Runescape phishing attempts<\/h2>\n<p>Runescape has plentiful support guides to help steer players away from harm. A list of the most popular scam attempts can be found on their <a href=\"https:\/\/secure.runescape.com\/m=forum\/forums?408,409,117,66094339\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">forum<\/a>. Note that &#8220;Your email address has been changed&#8221; is listed, along with the following explainer:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p><em>Note how a phishing email says the change will be made unless you click something. If someone tries to change your email, Jagex will send an email to confirm the change before any changes are made. No changes are made if you don\u2019t confirm it.<\/em><\/p>\n<\/blockquote>\n<p>There&#8217;s also a <a href=\"https:\/\/secure.runescape.com\/m=forum\/forums?254,255,624,66141790\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">dedicated phishing report centre<\/a>, and several support articles which cover:<\/p>\n<ul>\n<li><a href=\"https:\/\/support.runescape.com\/hc\/en-gb\/articles\/115001257125\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Suspicious emails<\/a><\/li>\n<li><a href=\"https:\/\/support.runescape.com\/hc\/en-gb\/articles\/115001258085\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Fake websites<\/a><\/li>\n<li><a href=\"https:\/\/support.runescape.com\/hc\/en-gb\/articles\/115001245149\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Staff impersonation<\/a><\/li>\n<\/ul>\n<p>For a more detailed dive into phishing and tips for avoiding all manner of phish attack techniques, read our <a href=\"https:\/\/www.malwarebytes.com\/phishing\">in-depth guide<\/a>.<\/p>\n<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/runescape-phish-claims-your-email-has-been-changed\/\">Runescape phish claims your email has been changed<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/runescape-phish-claims-your-email-has-been-changed\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 31 May 2022 20:08:04 +0000<\/strong><\/p>\n<p>We take a look at a Runescape-themed phishing mail targeting players of the smash MMORPG title, and explain how they steal the data.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/05\/runescape-phish-claims-your-email-has-been-changed\/\">Runescape phish claims your email has been changed<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[26360,26361,26362,13656,11260,26363,23650,10511,3924,11373,10574,12046,26364,26365],"class_list":["post-19207","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-authenticator","tag-automated","tag-bank-pin","tag-discord","tag-free","tag-jagex","tag-mmorpg","tag-phish","tag-phishing","tag-runescape","tag-scams","tag-server","tag-webhook","tag-webhooks"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19207","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19207"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19207\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19207"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19207"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19207"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}