10 ms·
Don’t plug in that free Microsoft Office USB drive you got in the mail
- serverlessmom 4y agoThe grifts are certainly getting more elaborate
- rootsudo 4y agoWow, that is an excellent social engineering method.
- ocdtrekkie 4y agoBrilliant, but arguably not as brilliant as selling idiots grey market keys on StackSocial or SlickDeals for $30, which appear to activate but aren't legitimate for individual sale. Hint: If you didn't pay out the a** for it, it's not a legit Microsoft product key.
- cable2600 4y agoI just use LibreOffice instead of MS-Office. https://www.libreoffice.org/ https://www.libreoffice.org/ I am not a big fan of MS-Office being forced software that takes over Windows and activates a key online and steals info on the user.
- ocdtrekkie 4y agoI don't use Office at home (I use Sandstorm apps instead), and I've convinced a few folks to use LibreOffice instead of paying for new Office versions recently, but I still deal with Microsoft licensing pretty regularly, so the prevalence of grey market keys on deals sites is of great irritation to me.
- dopeboy 4y agoWouldn’t enough disputed charges result in the credit card processor blacklisting this merchant? I would think a better scam to be selling fake av software in this scenario.
- cowtools 4y agoMalware with a strong command-and-control network will be able to change the merchant. Additionally, this blacklisting effect can be used strategically to target business you don't like by using the malware to perform a false-flag attack.
- netsharc 4y agoThey probably use the card number to buy stuff from legitimate online stores, e.g. gift cards, to ensure that the transaction is hard to reverse/they get to keep their "winnings" even if the CC company does a chargeback.
- unnouinceput 4y agoQuote: "You plug the USB drive into your PC and it immediately tells you that you have a virus, and you need to call “Microsoft Support.”" Well, that's a badly configured PC then. Stop having AutoPlay enabled and this won't happen. Then next step is to format that USB drive and voila!, free thumb drive.
- banana_giraffe 4y agoI am curious what's on that USB stick. Is it a flash drive/HID thing like a rubber ducky that types something in to run a payload? Or, just bad phrasing on the article?
- iforgotpassword 4y agoAutorun.inf plus some html file or simple app displaying a msgbox.
- banana_giraffe 4y agoI thought Autorun was no longer a thing since Vista or so.
- pyuser583 4y agoI thought plugging a thumb drive in can deliver malware without opening files. Something about full memory access before block level … or is that PCIe?
- josephg 4y agoUSB doesn't have implicit DMA (Direct Memory Access), so it can't install malware on your computer without getting past your operating system. (Though just enabling autoplay will do the trick - and I have no idea whether thats turned on by default these days.) Firewire used to have DMA access via how the port was physically wired, but afaik it was fixed before being phased out. Thunderbolt also gets access to the PCIe bus (and also by extension, DMA). I'm not sure what the security situation is there. As others have mentioned, USB devices can also do physical damage to your computer if they want to, by charging a capacitor over a few seconds then discharging it all at once. Its generally a bad idea to plug mystery USB devices into your computer.
- boomboomsubban 4y agoThis makes me wonder if anyone ever leveraged an America Online CD for malware.
- aaaaaaaaata 4y agoDepending on your definition of malware...AOL?
- surfpel 4y agoWow. I expected that it would install a keylogger or something, but this is so low tech that I'm both impressed and disappointed. Impressed because it's (a) so elaborate for what it is, (b) it's cheaper than procuring an actual virus, and (c) it is supported by existing scam infrastructure. Disappointed because I expected some exciting new attack vector.
- iforgotpassword 4y agoYeah like, I see that it's cheap to run those scam ads on fishy websites and just wait until someone is tricked into calling, or run a robocaller and wait until someone presses 1. But having all this designed, ordered, packaged and shipped, just so maybe the receiver calls seems way too much effort. How does this scale? I'd see this make sense for targeted attacks, but like this? Wow.
- sigmoid10 4y agoI don't really see the design or packaging as an issue, after all that can be done for cents apiece in high volume productions. But the USB drives are definitely interesting. Even when ordered in large batches from cheap chinese manufacturers, they will probably cost a dollar per drive. So if you send that to 10k people, you have to expect a very high payout. The approach is certainly more effective than a spam mail, but then again sending an email costs several orders of magnitude less. So I wonder if this is really orders of magnitude more likely to capture people. Perhaps with strong pre-selection.
- surfpel 4y ago$1 per drive for how much storage? I’m sure these don’t even need a single Gig. Probably could get lots of super cheap ones during liquidation events or salvage operations and what not.
- sigmoid10 4y agoI just looked it up: Even if you accept less than 1 GB you'll have a hard time finding drives below $3. The USB controller chip alone is about $1 and you need some actual storage and a casing as well. Even if you're really proficient at acquisition and manage to get them for 10% of that price, it's still orders of magnitude more expensive than email based spam.