spamnation

@spamnation@noc.social
20 Followers
1 Following
133 Posts

News and views about #spam and #scams.

Once upon a time, ran the website spamnation.info. Might do again.

A new twist on an old trick. Scammers are sending out #spam emails pretending to be from the Social Security Administration, with the subject "Review Your Statement" and a PDF attachment. The attachment contains a link to a supposed ‘Adobe fraud prevention site’, which is actually a download site for Windows #malware.

#spam

The use of data from hacked sites to gain trust is troubling, but I'd think that requiring victims to copy and paste data to a shell window would limit the potential spread. Many people targeted might not know how to launch a shell.

I'm sure the messages sent by the hackers help them with that, but it's still a higher bar than “Just click here”.

But tell your friends & relatives: if you get a message that asks you to do something unusual on your computer, don’t.
https://mastodon.social/@arstechnica/115531088838802295

Another day, another 419 scam from ... Scott Bessent, Secretary of the Treasury?

Well, that's a new one.

"Scott" would probably be more convincing if he weren't mailing from a Taiwanese address, though.

#scams #spam

Affiliates Flock to ‘Soulless’ Scam Gambling Machine – Krebs on Security

I understand that spamming website contact forms with messages that say “Hi, I'd like to know your prices" is a necessary first step in running an overpayment scam.

And, obviously, translating it into different languages allows you to widen your pool of potential marks.

I humbly suggest, however, that translating the message into Latin is probably not worth it, unless you're specifically targeting webmasters at the Vatican.

#spam #scams

Well here’s an interesting new scam.

Over on BlueSky, ProPublica has a good thread about so-called “pig butchering" scams: international long con #scams in which scammers (sometimes victims of human trafficking) befriend strangers to try to convince them to invest in fake #cryptocurrency services.

Thread:
https://bsky.app/profile/propublica.org/post/3ltb3lashvs2y

Article:
https://www.propublica.org/article/whats-a-pig-butchering-scam-heres-how-to-avoid-falling-victim-to-one

ProPublica (@propublica.org)

1/ Ever received a random text or DM from a stranger looking to befriend you? Here's how a simple message could be a small piece of a global fraud machine that exploits some of the world's largest banks. THREAD 🧵

Bluesky Social

It used to be that you could tell people "No, Warren Buffett is probably not mailing you from a Hotmail address offering you a million dollars.”

But when you get an email claiming to be the Secretary of the Treasury and asking you to reply to ‘scottbessent1234 at gmail dot com’, the whole “important people don't use free webmail” credibility test breaks down.

Who's to say that Mike Waltz won't randomly mail you from an AOL account? Or J.D. Vance from Outlook? These days, anything is possible.

Google's response to abuse reports has been increasingly lackluster for a while, but now it looks as if they've given up the fight entirely. The ‘Report Phishing' and 'Report Malware’ links on safebrowsing.google.com now just lead to 404 pages.

#spam #abuse #google

I had to sign up for a #Microsoft account recently, and of course once they had my email address, they immediately started sending me junk.

The mails have no 'unsubscribe' link, and the usual handy ‘unsubscribe' button that my MUA offers didn't show up. I took a look at the headers and found out why.