{"id":23958,"date":"2024-02-15T09:10:08","date_gmt":"2024-02-15T17:10:08","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/02\/15\/news-17688\/"},"modified":"2024-02-15T09:10:08","modified_gmt":"2024-02-15T17:10:08","slug":"news-17688","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/02\/15\/news-17688\/","title":{"rendered":"Massive utility scam campaign spreads via online ads"},"content":{"rendered":"\n<p>For many households, energy costs represent a significant part of their overall budget. And when customers want to discuss their bills or look for ways to save money, scammers are just a phone call away.<\/p>\n<p>Enter the <a href=\"https:\/\/consumer.ftc.gov\/articles\/scammers-pretend-be-your-utility-company\">utility scam<\/a>, where crooks pretend to be your utility company so they can threaten and extort as much money from you as they can.<\/p>\n<p>This scam has been going on for years and usually starts with an unexpected phone call and, in some cases, a visit to your door. Obviously the phone call side of the scam is much more scalable and means the scam can be done from overseas.<\/p>\n<p>However, criminals know that victims are more likely to be tricked if they were the ones who initiated the call. In a recent investigation, we discovered a prolific campaign of fraudulent ads shown to users via Google searches. To give an idea of scale, the number of ads we found exceeds what we have found in previous malvertising cases.<\/p>\n<p>This blog post has two purposes: the first one is to draw awareness to this problem by showing how it works. Secondly, we&#8217;ve collected and shared as many ads and fake sites as we could in the hope that action will be taken, with hopefully some cost for the scammers.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-fraudulent-utility-scam-ads\">Fraudulent utility scam ads<\/h2>\n<p>The scam begins when a user searches for keywords related to their energy bill. The ads are shown to mobile devices only, which makes sense given how often people use their phones. Also, the ads are geolocated, so that they are relevant to the user&#8217;s location.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"736\" height=\"782\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/02\/image_3338d2.png\" alt=\"\" class=\"wp-image-103944\" \/><\/figure>\n<p>We found 28 advertisers with over 300 ads, most of them registered by individuals from Pakistan. We have also seen legitimate but hacked advertiser accounts belonging to US entities that were abused. We didn&#8217;t investigate further into the whereabouts and identities of the scammers, but we should note that Pakistan is a possible location.<\/p>\n<p>In most cases, tapping on the ad will not open a new website, but instead will prompt you to dial a phone number. This is exactly what the crooks want as many people will have no idea that an ad approved by Google could possibly be fraudulent.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"736\" height=\"780\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/02\/image_ad7c2c.png\" alt=\"\" class=\"wp-image-103941\" \/><\/figure>\n<p>The utility scam often works by threatening and scaring victims into making poor decisions. An unpaid bill, or an offer that is too good to be true and must be accepted immediately are some of their tactics. Once you&#8217;ve made that phone call, you&#8217;re already in their hands and very close to losing a significant amount of money.<\/p>\n<p>The scammers may even redirect you to their website to &#8220;prove&#8221; that they are legitimate. Those sites are often credible enough for a victim to feel like they are doing the right thing, but that couldn&#8217;t be further from the truth.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-large-scamming-infrastructure\">Large scamming infrastructure<\/h2>\n<p>The crooks have registered dozens of different domains names and built templates that appear related to energy or utility savings. The sites are quite simple and consist of one main page with some customer-centric text and one or multiple phone numbers.<\/p>\n<p>We can usually deduce they are fraudulent by looking up their registration date as well as connecting them with search ads.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"933\" height=\"503\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/02\/image_35ed6b.png\" alt=\"\" class=\"wp-image-103968\" \/><\/figure>\n<p>However, that might not be enough to have them suspended without going through the whole process of calling the scammers, recording the interaction and showing that evidence. This type of investigation requires time and resources to be done properly. Perhaps one of the many scambaiters out there will look into it in the future.<\/p>\n<p>In the meantime, we have tracked and reported as many domains as we could to the relevant registrars in the hope that some may take action and suspend them.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"606\" height=\"692\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/02\/image_fdb928.png\" alt=\"\" class=\"wp-image-104184\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-keep-your-identity-and-money-safe-from-scammers\">Keep your identity and money safe from scammers<\/h2>\n<p>This scam is widespread, and so our advice right now is to avoid clicking on any ad from search as the malicious ads largely outnumber the legitimate ones. You can tell it&#8217;s an ad as it will be labelled &#8220;Sponsored&#8221; or &#8220;Ad&#8221;. <\/p>\n<p>Here are some additional tips:<\/p>\n<ul>\n<li><strong>Watch out for a sense of urgency<\/strong>. Scammers will often threaten to cut your power immediately. This and similar scare tactics are meant to pressure you into making hasty decisions. Take the time to look things up or speak to a friend before you do anything.<\/li>\n<li><strong>Never disclose personal details<\/strong> over the phone without being absolutely certain you are talking to the right person. If in doubt, hang up the phone and look for the official phone number from your energy company, perhaps from a past bill. Do not trust any phone number that appears on an online ad.<\/li>\n<li><strong>Beware requests for money transfers or prepaid cards<\/strong>. These are a huge sign you are dealing with criminals. Again, take your time to think it over even if just for a few hours. Scammers tend to be so impatient they will make all sorts of claims to act right now, which should be a dead giveaway.<\/li>\n<li><strong>Contact your bank immediately<\/strong> if you think you&#8217;ve been scammed and wired money,. Change all your passwords and add a notice with your utility company that someone may attempt to impersonate you.<\/li>\n<li><strong><a href=\"https:\/\/consumer.ftc.gov\/articles\/scammers-pretend-be-your-utility-company#report\">Report<\/a> the scam<\/strong> to the proper authorities, which may be the FTC.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"h-malwarebytes-protection\">Malwarebytes protection<\/h2>\n<p>Malwarebytes is working with its partners to go after these scammers. We also provide protection if you are using our <a href=\"https:\/\/www.malwarebytes.com\/ios\">iOS app<\/a> via the ad blocking feature which will disable search ads and other ads that may be targeting you.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"605\" height=\"645\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/02\/image_84f6c7.png\" alt=\"\" class=\"wp-image-104183\" \/><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-indicators-of-compromise\">Indicators of Compromise<\/h2>\n<p><strong>Google advertiser accounts<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table>\n<tbody>\n<tr>\n<td><strong>Advertiser name<\/strong><\/td>\n<td><strong>Advertiser ID<\/strong><\/td>\n<td><strong>Number of ads<\/strong><\/td>\n<\/tr>\n<tr>\n<td>Telesoft<\/td>\n<td>N\/A<\/td>\n<td>1<\/td>\n<\/tr>\n<tr>\n<td>Digitron<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR04170244641179828225?origin=ata&amp;region=anywhere\">04170244641179828225<\/a><\/td>\n<td>4<\/td>\n<\/tr>\n<tr>\n<td>Syed muhammad Adnan<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR08157637715521699841?origin=ata&amp;region=anywhere\">08157637715521699841<\/a><\/td>\n<td>15<\/td>\n<\/tr>\n<tr>\n<td>Progressix<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR02149758434478653441?origin=ata&amp;region=anywhere\">02149758434478653441<\/a><\/td>\n<td>2<\/td>\n<\/tr>\n<tr>\n<td>Umair Jameel<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR11899369518209695745?region=anywhere\">11899369518209695745<\/a><\/td>\n<td>1<\/td>\n<\/tr>\n<tr>\n<td>Laiba Mazhar<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR14248337572488019969?region=anywhere\">14248337572488019969<\/a><\/td>\n<td>1<\/td>\n<\/tr>\n<tr>\n<td>Syed Shahmeer Hussain<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR12265272419404480513?region=anywhere\">12265272419404480513<\/a><\/td>\n<td>6<\/td>\n<\/tr>\n<tr>\n<td>Snow Tech<\/td>\n<td>N\/A<\/td>\n<td>1<\/td>\n<\/tr>\n<tr>\n<td>Muhammad Pirzada<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR12480474916866490369?region=anywhere\">12480474916866490369<\/a><\/td>\n<td>145<\/td>\n<\/tr>\n<tr>\n<td>Eco Designs (Private) Limited<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR17013467067027816449?region=anywhere\">17013467067027816449<\/a><\/td>\n<td>5<\/td>\n<\/tr>\n<tr>\n<td>Right Path Solutions<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR11370048952557633537?region=anywhere\">11370048952557633537<\/a><\/td>\n<td>21<\/td>\n<\/tr>\n<tr>\n<td>Rehman Munawar<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR06906645958470139905?region=anywhere\">06906645958470139905<\/a><\/td>\n<td>1<\/td>\n<\/tr>\n<tr>\n<td>ANDREW PAUL GUZMAN<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR09045338907926855681?region=anywhere\">09045338907926855681<\/a><\/td>\n<td>17<\/td>\n<\/tr>\n<tr>\n<td>Economical Deals<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR09045708721790910465?region=anywhere\">09045708721790910465<\/a><\/td>\n<td>4<\/td>\n<\/tr>\n<tr>\n<td>Qasim Ahmed<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR15768816743289454593?region=anywhere\">15768816743289454593<\/a><\/td>\n<td>20<\/td>\n<\/tr>\n<tr>\n<td>Summaira<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR14596269127925497857?region=anywhere\">14596269127925497857<\/a><\/td>\n<td>3<\/td>\n<\/tr>\n<tr>\n<td>Citrex Solutions (Private) Limited<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR16648988995463675905?region=anywhere\">16648988995463675905<\/a><\/td>\n<td>19<\/td>\n<\/tr>\n<tr>\n<td>Get Energy Promo<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR08074609881656590337?region=anywhere\">08074609881656590337<\/a><\/td>\n<td>6<\/td>\n<\/tr>\n<tr>\n<td>Brightboost LLC<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR07744256527850012673?region=anywhere\">07744256527850012673<\/a><\/td>\n<td>5<\/td>\n<\/tr>\n<tr>\n<td>AA DIGITAL LABS (SMC-PRIVATE) LIMITED<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR10871392529253662721?region=anywhere\">10871392529253662721<\/a><\/td>\n<td>1<\/td>\n<\/tr>\n<tr>\n<td>Malik Muhammad Shahroz Ibrahim<\/td>\n<td>N\/A<\/td>\n<td>1<\/td>\n<\/tr>\n<tr>\n<td>HongKong AdTiger Media Co., Limited<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR14567350391567024129?region=anywhere\">14567350391567024129<\/a><\/td>\n<td>1<\/td>\n<\/tr>\n<tr>\n<td>Mah Noor<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR07681945004880691201?region=anywhere\">07681945004880691201<\/a><\/td>\n<td>12<\/td>\n<\/tr>\n<tr>\n<td>Usama Ashfaq<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR06711852389684477953?region=anywhere\">06711852389684477953<\/a><\/td>\n<td>2<\/td>\n<\/tr>\n<tr>\n<td>Ali Raza<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR04534984293432164353?region=anywhere\">04534984293432164353<\/a><\/td>\n<td>15<\/td>\n<\/tr>\n<tr>\n<td>Muhammad Usman Tariq<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR17723433991509377025?region=anywhere\">17723433991509377025<\/a><\/td>\n<td>5<\/td>\n<\/tr>\n<tr>\n<td>SHABNUM FATIMA SHAH<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR02536959185141104641?region=anywhere\">02536959185141104641<\/a><\/td>\n<td>4<\/td>\n<\/tr>\n<tr>\n<td>QASMIC L.L.C-FZ<\/td>\n<td><a href=\"https:\/\/adstransparency.google.com\/advertiser\/AR11321807192694194177?region=anywhere\">11321807192694194177<\/a><\/td>\n<td>1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>Phone numbers<\/strong><\/p>\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-layout-1 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.34%\">\n<p>888[-]960[-]3984<br \/>888[-]315[-]9188<br \/>888[-]715[-]1808<br \/>888[-]873[-]0295<br \/>888[-]317[-]0580<br \/>888[-]316[-]0466<br \/>888[-]983[-]0288<br \/>888[-]439[-]0639<br \/>888[-]312[-]2983<br \/>844[-]967[-]9649<br \/>855[-]200[-]3417<br \/>888[-]842[-]0793<br \/>888[-]207[-]3713<br \/>833[-]435[-]0029<br \/>888[-]494[-]4956<\/p>\n<\/p><\/div>\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.34%\">\n<p>888[-]928[-]6404<br \/>888[-]374[-]1693<br \/>888[-]834[-]1050<br \/>888[-]497[-]3560<br \/>888[-]960[-]2303<br \/>888[-]430[-]0128<br \/>800[-]353[-]5613<br \/>888[-]407[-]1004<br \/>855[-]216[-]2411<br \/>844[-]679[-]7635<br \/>888[-]483[-]2851<br \/>888[-]657[-]2401<br \/>888[-]580[-]0106<br \/>888[-]326[-]7299<br \/>888[-]870[-]2661<\/p>\n<\/p><\/div>\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<p>888[-]203[-]1692<br \/>855[-]428[-]7345<br \/>888[-]641[-]0108<br \/>888[-]960[-]0688<br \/>888[-]347[-]7462<br \/>888[-]448[-]0550<br \/>888[-]834[-]0998<br \/>888[-]470[-]8496<br \/>888[-]554[-]0461<br \/>855[-]980[-]1080<br \/>888[-]539[-]0722<br \/>866[-]685[-]0355<br \/>888[-]715[-]1806<br \/>888[-]960[-]2550<br \/>888[-]641[-]0096<br \/>888[-]996[-]5133<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p><strong>Scammer domains<\/strong><\/p>\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-layout-2 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.34%\">\n<p>360billingservices[.]com<br \/>aadigital[.]online<br \/>citrexsolutions[.]co<br \/>digitelcare[.]com<br \/>eco-designs[.]store<br \/>economical-deals[.]co<br \/>electricenergybundle[.]com<br \/>electricenergyservice[.]com<br \/>electricpowerdeal[.]com<br \/>energpaybill[.]com<\/p>\n<\/p><\/div>\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.34%\">\n<p>energybilling[.]net<br \/>energybillservice[.]online<br \/>energycredits[.]online<br \/>energyhelpcenter[.]com<br \/>energypayment[.]shop<br \/>energypoweroffer[.]com<br \/>globalenergysolutionz[.]com<br \/>homeutilityservices[.]com<br \/>makeabillpayment[.]com<br \/>paysenergy[.]online<\/p>\n<\/p><\/div>\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<p>powerelectricoffers[.]com<br \/>qasmic[.]com<br \/>rebornsolutions[.]co<br \/>telecombilling[.]us<br \/>telecomcredits[.]us<br \/>thepowerpayllc[.]org<br \/>uenergyproviders[.]store<br \/>utilitybillsolution[.]site<br \/>utilitybillspayments[.]org<br \/>utilitydiscounts[.]store<br \/>utilityservices[.]us<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"wp-block-separator alignfull has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don\u2019t just report on phone security\u2014we provide it<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your mobile devices by\u00a0<a href=\"https:\/\/www.malwarebytes.com\/ios\">downloading Malwarebytes for iOS<\/a>, and <a href=\"https:\/\/www.malwarebytes.com\/android\">Malwarebytes for Android<\/a> today.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intelligence\/2024\/02\/massive-utility-scam-campaign-spreads-via-online-ads\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Malwarebytes researchers have discovered a prolific campaign of fraudulent energy ads shown to users via Google searches. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10574,12040],"class_list":["post-23958","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-scams","tag-threat-intelligence"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23958","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23958"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23958\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23958"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23958"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23958"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}