8 ms·
Smishing
- jb1991 4y agoIt's one thing to smish a man, but it's even better if you can teach him how to smish.
- paywallasinbeer 4y agoIt would be great if a section about BEC [0] was included. At $WORK we see a lot of "Smishes" that pretend to be our CEO/CTO that ask for the user to send them money. E.g. "Hello it's $CEO, I'm in a meeting currently and need your help. Can you send me 300 dollars in apple gift cards?" [0] https://www.fbi.gov/scams-and-safety/common-scams-and-crimes/business-email-compromise https://www.fbi.gov/scams-and-safety/common-scams-and-crimes...
- cookie_monsta 4y agoI know this sounds cold, but I feel like some of these scams are really just a stupidity tax. How do people operate in the outside world if they believe that the CEO would be hitting them up for gift cards?
- paywallasinbeer 4y agoIt's definitely a stupidity tax. I don't think our world is very hard to operate in though... George Carlin said "think of how stupid the average person is, then realize that half of them are stupider than that" https://www.youtube.com/watch?v=AKN1Q5SjbeI https://www.youtube.com/watch?v=AKN1Q5SjbeI
- bobro 4y agowhat are the consequences of what youre saying? is it better if these scams mostly affect stupid people? should we care less about whats happening to stupid people?
- quesera 4y agoI agree with you, but you might not be aware of some of the crap that happens in small companies with certain kinds of CEOs and salespeople. Others too, but the pubic-facing staff are always the problems. The harried assistants and lower-level functionaries in those companies regularly field requests like "I'm in a sales meeting/airport terminal/Dunkin Donuts and need to demo something, and I need you do something stupid the wrong way". So, it's a stupidity tax indeed, and even on the right people (CEO), but it's the assistants who get blamed and/or feel responsible. Even at bigger and well-run companies, the assistants have stories that would shock you. CEO-speak can often tend toward illiterate and nonsensical, and their requests unreasonable -- even if they can be interpreted correctly. In contrast, COOs and CFOs are pretty reliable. And CTOs run the gamut, I'm sorry to say. :)
- edm0nd 4y agoIt's all about spray and pray aka sending volume. We had a sales woman fall for it. The email said from our CEO that said he was at a conference and needed her to go out and buy 10 $100 Visa gift cards and send him the numbers bc he wanted to use them as giveaways. The issue is that our CEO actually WAS at a conference on that day! She actually went to the closest CVS and bought them and thankfully mentioned something about it to me when she got back. I paused for a moment and then was like wait a second how did you hear about this request? Email only? so I called our CEO to confirm. Was able to go back to CVS and get them all refunded and the scammer got nothing. But, that being said, I can see how people fall for it. Employee and user training and awareness are key to prevent these types of things.
- caitlinface 4y agoIt is cold. And I think it's harmful to infer that the people that fall for these are stupid. It does nothing to help the situation. If the prevailing thought is that you're stupid for falling for a scam, then the victim is less likely to share and inform, and then education does not spread. All it does is make them feel awful, which is not helpful and just even more hurtful. I think we have to come at it from the angle of the scammers are tactical and that it's okay if you are a victim. It sucks, of course, but no blame necessary on the victim. I know someone who got a similar message from her priest asking for gift cards. The scammer got a hold of the church directory and used that to send out messages. The person thought she was doing a favor for her priest and wanted to help; it is not her fault that the red flags weren't as strong as they should've been. Not everyone operates on suspicion mode. I know another who was almost a victim of the the sobbing phone call: "Granpda, I'm in jail! Please send me bail. Also don't tell anyone!" These types of scams target emotions and kindness. That's how these people operate in the real world. It's not that these people are stupid, it's more that they are unaware and not sensitive to the red flags.
- edm0nd 4y agoA good read, https://citizenlab.ca/2022/04/catalangate-extensive-mercenary-spyware-operation-against-catalans-using-pegasus-candiru/ https://citizenlab.ca/2022/04/catalangate-extensive-mercenar...
- cestith 4y agoI disagree that so many things in tech need to be intentional spoonerisms. It's still "phishing" to me no matter what the medium.
- mdp2021 4y agoTo the puzzled: 'Smishing' = 'SMS' ∩ 'phishing' > Signs that you are getting "Smished": [...] when you receive a message from bigger service providers, (f.e. banks, post offices, or delivery services) they will mostly have their company names displayed instead of their numbers The formulation in the article may lead to a very bad advice: in some areas, scammers do display a "company name", regularly. So: a numeric sender string increases the chances of the SMS being a scam; an alphanumeric sender string /does not/ decrease the chances of the SMS being a scam.
- rockbruno 4y agoI always wondered how that worked. How does Apple knows to display a company name instead of the "small numbers that are not actual phone numbers" (IIRC they are called Large Accounts)?
- Nextgrid 4y agoNothing to do with Apple or software. The GSM protocol and upwards support alphanumeric SMS originators.
- d4mi3n 4y agoThis is odd and completely counter to my own anecdotal experience. SMS messages from large companies I interact with (My bank, cell phone provider) always come from fairly static short codes. The elephant in the room here is that SMS is not a medium where integrity or authenticity of a message can be guaranteed—which is one of the big reasons it’s such a popular medium for phishing.
- mr-wendel 4y agoMe thinks your gut is leading you correctly. Generally speaking, there are short codes, and long codes. Sometimes alphanumerics are allowed, but the rules vary regionally. Long codes resemble traditional phone numbers and tend to be treated as more disposable, low volume, and person-to-person. As such, they are typically easier to spoof with. Short codes tend to be more like car license plates: short random/vanity codes that require a more in-depth process to get access to. They are easier to verify ownership, suited for higher volume messaging, and tend to be backed by automation systems that respond to a set of automated commands like "HELP". These qualities make them less likely to be used for nefarious purposes. It's definitely a topic I'd love to understand more. Any corrections/additions are very much welcome!
- HL33tibCe7 4y ago> The number of the sender and that of the service provider they claim to be, do not match. Don't forget that the caller ID here can be spoofed. It's best to disregard it completely. One of the infographics in the article suggests looking up the number of the text, which I'd suggest is actively harmful advice - it gives you zero information and risks lulling people into a false sense of security. Assume that all texts are from scammers and act accordingly.
- csharpminor 4y agoYes and to add: if an SMS’ sender ID successfully spoofs another number, the message would appear threaded into an existing “legitimate” conversation.
- withinboredom 4y agoReminds me of the time in highschool when I would send my teacher an email from the principle to come see them immediately. The teacher would sit down at their computer and a few minutes later leave the class for about 10-15 minutes. The SMTP server totally trusted every device on the network and worked without any authentication whatsoever. Ah, the joys of the early internet.
- ffo 4y agoHaha or the good old netsend fun on school pcs ;-)
- prmoustache 4y agoexactly. Best practice is to not click on any link in an sms/whatsapp. I don't recall any useful link sent by SMS. Whenever it is important it is always a warning telling you to connect yourself via the offical app/website eventually using the token/parcel code/identifier sent on the actual sms.
- vitus 4y ago> As software capable of zero-click exploit, Pegasus requires no user interaction to operate: ... As a result of a simple click on the URL, the spyware was granted unlimited access to every information stored on the iPhone. That's a one-click exploit, no? Pegasus has demonstrated zero-click exploits (e.g. PDF embedded in GIF), but this is not one. edit: the provided CitizenLab link [0] describes two classes of attacks, "zero-click exploits and malicious SMSes". Looks like the author conflated the two? [0] https://citizenlab.ca/2022/04/catalangate-extensive-mercenary-spyware-operation-against-catalans-using-pegasus-candiru/ https://citizenlab.ca/2022/04/catalangate-extensive-mercenar...
- staticassertion 4y agoI'm not sure it's one-click. Visiting a page isn't exactly "clicking" - I'd expect a "click" in this sense to be like a browser asking "are you sure?" and you clicking through, or "play video". But it's not super clear cut. Like, let's say you had to open up a message on your phone for the exploit to work - you clicked the message, right? idk
- lalopalota 4y agoI'd say it is one-click when compared to older MMS exploits where just receiving the message would activate the exploit.
- staticassertion 4y agoYeah, fair
- usrn 4y agoAnything that has anything to do with the cellular network is irredeemably broken and should be avoided.
- DerekBickerton 4y ago> In many cases, simply clicking the provided link can initiate a download process of viruses or malware I imagine some payloads use JavaScript to infect a device upon clicking. They probably target Chrome, or god forbid the Samsung Internet browser. If you wanted to see the payload, just open the link in a secure sandbox environment and view the source. Congratulations to them, they just allowed you to see their 0day in the wild, and it's no longer a 0day.