Showing posts with label SonicWall. Show all posts
Showing posts with label SonicWall. Show all posts

Monday, November 6, 2023

Pig Butchering. China cracks down on Internet scammers based in Myanmar

The term Pig Butchering refers to the victims of scammers. The scammers nurture relationships with their targets before luring them in for the kill.

Armies of scammers operating from lawless corners of Southeast Asia—often controlled by Chinese crime bosses—connect with people all over the world through online messages. They foster elaborate, sometimes romantic, relationships, and then coax their targets into making bogus investments. Over time, they make it appear that the investments are growing to get victims to send more money. Then, they disappear.

This is not a new technique, but it is a problem for societies all around the world. It was used by Nigerian scammers during the war on terror who would pose as US servicemen and target gullible victims with fake photos and love letters often coaxing the victims to send money.

There are regions around the world whose strengths lie in language, targeting/scamming societies more closely related to them. The border region shared by China with Myanmar sounds like the problems the US southern border experiences with the Mexican cartels. The differences are there is not the endless stream of unvetted, unvaccinated migrants streaming into China, plus China is doing something about it. I mean who wants to go to communist China anyway?

The link below to a WSJ article in today's paper details the issue and how China is trying to shut down the illicit scam centers.

https://www.wsj.com/world/asia/china-unleashes-crackdown-on-pig-butchering-it-isnt-what-you-think-d623ada3?st=7ej1gyz60xwmdmz&reflink=desktopwebshare_permalink

India with its large English-speaking population is home to villages whose sole industry is internet scamming. I watched a documentary about this. The internet and smartphones have brought the tools for scamming to very smart and desperate people. The gulf between haves and have nots is very great in India even with-it growing prestige and power. Whether its right or wrong does not mean a lot to a poor village.

India has long held a reputation as a home to online scammers targeting victims in far richer nations such as the United States. Last year, federal prosecutors in Georgia announced the indictment of multiple India-based call centers and their directors, charging them with conspiring to forward tens of millions of scam calls to American consumers.

https://www.latimes.com/world-nation/story/2023-03-15/online-scammers-find-a-fertile-market-in-india-as-the-internet-spreads

In summation, be extra vigilant and check the email, test message sources. Check that the email address used by the sender is the correct address associated with that sender if possible. Check the spelling of the domain name in the email address.

Your email address is on hundreds if not thousands of devices. Every client, firm, or friend you deal with has your email address and phone number.  All internet connected devices should have anti-viral software installed but sometimes that is not enough. My larger clients have SonicWALL, anti-virus as well as MS365 protections in place. Does everyone you deal with have the same protections in place?

Be careful.

BTW, I run a Sandbox which is a Virtual Machine that I monitor email for my larger clients 24/7. If an infection occurs within the VM, I can shut it down without any consequences to my machine. If you need help verifying an email, feel free to contact me.

 

 

 

 

 

 

 

 

 

 


Tuesday, May 18, 2021

Ransomware Attacks. Take advantage of all layers of protections afforded you.

Turn on anti-ransomware feature in Windows 10.

In light of the most recent high profile ransomware attack on the Colonial pipeline, what can you do to protect your organization from falling victim to a ransomware attack?

According to Firewall manufacturer SonicWall, Ransomware threats increased a massive 62 percent in 2020 compared to 2019 and it is showing no sign of slowing down.  How many attacks?... over 304 million ransomware attacks in 2020 with the average payout over $220,000.

Of course, those are mainly businesses forking over that kind of money to attackers who are holding their data hostage. Small businesses in particular are disproportionately targeted, but facilitators of ransomware do also go after individuals.

One may think that if they can hack through the protection manned by large corporations what can I do?  The large corporations have deep pockets that make them lucrative targets.  However as stated above, individuals are targeted as well.

Windows 10 as well as most Security software firms have protections that provide extra layers of security but you must enable or properly configure them to work effectively.

You should routinely back up any important data, and as always, following smart computing habits (like not clicking on links in unsolicited emails) to tip the odds in your favor.

Read about steps you can take below if you are running Windows 10 and if you own Kaspersky security software.

Tuesday, November 27, 2018

Malware and Phishing attacks on the rise as Holidays approach

Phishing attacks and Malware attacks are ubiquitous.  Almost everyday I see some myself or receive emails from users wanting to know if this is real.  One I want to warn about is the "efax notification", eFax Notification Delivers Hancitor Malware.  If you received an email reference an efax, beware of attachments and/or links within these emails.

Fake Ransomware just overwrites MBR but demands payment

There is a fake ransomware trojan circulating that overwrites the MBR (Master Boot Record) and then restarts your machine.  The MBR is the code stored in the first sectors of a hard disk drive that contains information about the disk’s partitions and launches the operating system’s boot loader. If the MBR is corrupt or altered, the computer doesn’t know which partitions contain an OS and how to start it.

Upon reboot, the following ransom text is displayed and the machine is unable to boot as normal:



The message says;

Oooops!  Your OS is locked.  The harddisks of your computer have been encrypted with an military grade encryption algorithm.  There is way to restore your data without a special instrucrion for unlocking your computer.  You can buy the instruction.  To do this, you need to send $200 to Monero wallet: "a monero address" (This is a Monero address)

The claim that it has encrypted your files is fake.  According to SonicWall;

The only modification to the filesystem is the overwritten MBR.  No files have actually been encrypted and there is no encryption functionality present in the malware.  Although files can easily be restored by mounting the filesystem using a live OS booted via a memory stick, most users will likely consider their files gone and perform a full reinstall.  There is no contact information provided to “restore” files and no way of verifying if paying the $200 in Monero will suffice.

https://securitynews.sonicwall.com/xmlpost/fake-ransomware-just-overwrites-mbr-but-demands-payment/

https://www.pcworld.com/article/3133181/security/free-tool-protects-pcs-from-master-boot-record-attacks.html


Tips to Prevent virus and malware from Infecting Your System:

  1. Enable your popup blocker: Pop-ups and ads on the websites are the most adoptable tactic used by cybercriminals or developers with the core intention to spread malicious programs.
    So, avoid clicking uncertain sites, software offers, pop-ups etc. and Install a powerful ad- blocker for ChromeMozilla, and IE
  2. Keep your Windows Updated: To avoid such infections, we recommend that you should always keep your system updated through automatic windows update.By doing this you can keep your device free from virus.  According to the survey, outdated/older versions of Windows operating system are an easy target.
  3. Third-party installation: Try to avoid freeware download websites as they usually install bundled of software with any installer or stub file.
  4. Regular Backup: Regular and periodical backup helps you to keep your data safe in case the system is infected by any kind of virus or any other infection.Thus always backup important files regularly on a cloud drive or an external hard drive.
  5. Always have an Anti-Virus: Precaution is better than cure. We recommend that you install an antivirus like ITL Total Security or a good Malware Removal Tool like Malware Crusher.



Thursday, April 22, 2010

Spammers Get Smarter by the Second

Every week I am asked about solutions to prevent spam. I am also questioned about why the sudden increase in spam in recent weeks. Computer Reseller News has a great column about why spam is on the increase and the costs organization incur in lost productivity and employing means to stop the spam.

http://www.crn.com/security/224202449;jsessionid=20XRD5EP2MUNRQE1GHOSKHWATMY32JVN?pgno=1

Today there are several methods being employed to prevent spam from entering e-mail inboxes. Some are cloud based, some software, others are hardware and some are a hybrid of all the above.

An example of Cloud prevention would be when a company has their e-mail auto routed to a 3rd party who scans the e-mail for spam, eliminating it before forwarding the e-mail to the IP address of the company's mail server or gateway. This alleviates a company from having to deploy software/hardware themselves but requires a monthly fee based on number of users. In the case of a large organization with an Exchange Server, this solution prevents all that spam from ever reaching the Information Store which has storage limits.

A software solution would be any of the anti-virus/spyware/spam software which scans your e-mail as it comes into your e-mail client/server and places it into a folder separate from the inbox. One could have the e-mail automatically deleted however this is not an ideal choice since good e-mail invariably becomes swept up with the bad sometimes. The main con with these programs is that most are resource intensive and maintenance has to be performed on each machine.

Last is the hardware solution that monitors incoming e-mail at the gateway. This is a good solution that prevents the spam from reaching individual inboxes like the cloud solution but it requires upfront hardware costs and generally a subscription to maintain up to date filtering definitions.

Spam today is being employed for more sinister purposes including download of rogue ware, zombie bot-nets and phishing, all this along with the usual pharmaceutical, Russian Bride and Acai Berry scams that are received each day.

No matter which of these solutions that are employed, one still has to pore through the junk e-mail to guard against valid e-mails from being caught in the spam filters. With the Cloud solution one would log into a website and check the junk mail. The software solution creates a junk e-mail folder that has to be monitored within the user’s mailbox or PST file. The hardware solution would provide a folder either internally or on a server that users would have to monitor to make sure legit e-mails are not being caught.

The costs are high, in addition to monitoring the junk folder, users have to be added to safe senders list and the spam that does slip through has to be added to the blocked lists.

Please contact us today about a solution that is right for you.

Phil Gilbert
Driving Force Software
dforce@drivingforce.net
www.sonicwall.com/us/

TEST