Posts

Showing posts with the label Scammers

Fake Versions of Apps Can Infect Your Systems with Malware

Image
Fake Apps with Malware Fake apps loaded down with malware are on the rise…again. What’s worse, new techniques are getting those malicious apps more and more visible, so that unsuspecting team members could easily download them without noticing anything’s wrong. This time there are two distinct elements you need to understand so you can keep your company and data safe. We’ll discuss the apps themselves first, then we’ll dive into SEO poisoning (the technique the bad guys are using to get these apps found). Problem #1: The Apps Themselves So what exactly are these apps? They look like apps your team needs to get work done, like WhatsApp, Chrome, and so on. Even apps we look at as extra secure, like Signal or Telegram, are getting spoofed. Of course, these aren’t the real versions of those apps. They won’t work well or fully, so eventually it might become obvious that something nefarious is happening. But maybe not: it could be that an unsuspecting user tries to install and open the app, ...

Successful Phishing Attempts TRIPLED in 2024

Image
Phishing Attacks Are Increasing...Are Your Employees Educated On What To Look For? We’re frequently warning our customers and readers about the risks of phishing scams and attacks, and it looks like we won’t be stopping anytime soon. A new report in Infosecurity Magazine reveals that the rate at which business users clicked on phishing links was up in 2024, nearly triple the rate from 2023. That’s what we in the industry like to call, well, really bad news. Before we get into why things are getting worse instead of better (and what you should do to limit risk), let’s quickly review how these scams are built. The Anatomy of a Phishing Scam A phishing scam starts with a message of some sort: traditionally it was an email, but it could also be a text message, online ad, or even a search result (though this is less common than other methods). The message appears to come from a legitimate source (in recent business attacks, Microsoft 365 and Docusign were the top companies the scammers pos...

Phishing Tactic Alert: Corrupted Word Docs

Image
Corrupt Word Attachments May Be a Scam Sigh… here we go again. The scammers keep innovating, and so we keep having to say it: there’s another new phishing tactic on the rise, and this one’s a stinker. This new phishing tactic has been getting past spam filters and tricking professionals worldwide, taking advantage of both human nature and advancing “good” tech to fool you and attack your business. Here’s what you need to know about how scammers are using corrupted file attachments to attack businesses like yours. How It Starts: A Corrupted Word File (or Similar) This new attack starts with a corrupted file, often a Microsoft Word document file (.docx). It looks like a real file, and it may even seem like it was sent by someone or some entity you trust. Now, if you’ve been at this a while, you already know the old advice not to trust email attachments. But that advice was largely about executables, those .exe files that would not-so-subtly install new malicious software onto your system...