6 ms·
I recognize that IP address! Your site is being used as a pawn in a rather sneaky attack, and I was hit by it recently. Those email addresses belong to the vict
by zenexer 4y ago
I recognize that IP address! Your site is being used as a pawn in a rather sneaky attack, and I was hit by it recently. Those email addresses belong to the victims—like me.
Let’s say I’m a hacker. I’ve gotten into Alice’s Amazon account and want to place a bunch of orders using her payment info. However, I don’t want her to notice until after I’ve received the ill-gotten goods.
To ensure she doesn’t notice the email notifications from Amazon, I want to “bury” those emails with spam. I can do this by entering her email into tons of online forms. Most will only send a single email—for example, your blog will probably only ask Alice to confirm her email—but once is enough.
This happened to me a couple weeks ago with Apple. Someone used the default billing and shipping info on my Apple account to place an order for an iPhone 14 Pro Max. I woke up to hundreds of emails from various blogs and other sites asking me to confirm my email. Being a security researcher, I knew that meant someone didn’t want me to see something else that had landed in my inbox.
I went through each one by hand. One included the IP address that submitted the form, which was interesting but not particularly useful. Eventually I found the receipt from Apple.
It’s not clear how the attackers intended to intercept the package; presumably, they would’ve tried to convince the courier to redirect it or retrieved the package from my doorstep, but Apple intervened and was able to stop the delivery before either of those happened.
It’s also not clear how the attacker got my billing and shipping info. Apple was able to confirm that my account wasn’t compromised and that nobody had contacted support pretending to be me. That billing info wasn’t used with many other companies.
Edit: You can see what this looks like from the victim’s side here: https://imgur.com/a/DHEJwKh https://imgur.com/a/DHEJwKh Note that the usernames have the same sort of gibberish.
- replwoacause 4y agoSounds like this is exactly what is happening to the OP.
- arbuge 4y agoParent comment is from a target victim. OP is actually one of the blogs being unwittingly used to spam those victims.
- meowface 4y agoI think you nailed it. It doesn't match vuln scanning/probing patterns, IMO, but it makes sense as what you describe and looks pretty much identical to what you received, with the same sort of base64 gibberish.
- tcmart14 4y agoHave not heard of this, but I also don't do much work in the security space. Good read and thank you for the share!
- arbuge 4y ago> It’s also not clear how the attacker got my billing and shipping info. This sounds like a real mystery. I wonder what happened here and how Apple is so confident that your account wasn't compromised, because it really sounds like it was. Either that or some other account with those same credentials was. It's also a bit of a mystery to me why the hackers would use your shipping info to begin with here. Why not some address where retrieving things would be easier for them? They must have been really confident they could intercept your package.
- maicro 4y agoIf I had to guess, the answer to both is some stolen session issue - either personal device or a device that the user was logged into once had saved login information, which the attacker gained access to. However, to reduce the chance of needing to verify any information/login again, they left the default shipping address (as changing it would have A] left an address trail, and B] been suspicious). But again, that's my guess - I'll leave solid answers to the actual security researched in the comment chain X)
- zenexer 4y agoThat was my guess, too. However, Apple seemed to think there was no relevant session activity on my account at the time. They stopped short of confirming that the payment and shipping info was entered manually. When I asked directly, they initially said they’d put me in touch with the fraud team, but the fraud team refused to talk directly to me and would only talk through another support rep. They refused to answer any questions about how the order was placed.
- zippergz 4y agoThis happened to me (this exact scam, with the email bomb, shipping and email matching my real addresses, etc.) a few years ago with a major electronics brand. My account was not compromised because I didn't have an account with them. But probably some other company got compromised, and they got my my matching info from one of those dumps.
- zenexer 4y ago
- gfd 4y agoawful thing about these kinds of attacks is that your inbox never really recovers. these unsuspecting services/blogs will keep sending you emails forever thinking you actually wanted to sign up.
- BenjiWiebe 4y agoIf they are legitimate services/blogs, they'll probably honor the unsubscribe link.
- gfd 4y agoA good chunk of them were from small blogs or mom and pop shops. They don't always have one click unsubscribe, especially the ones in other languages (I think requiring unsubscribe link is an american law?).
- jfengel 4y agoA good reason to revive an old habit: giving every web site a different email address. Easy enough when you own the domain; just monitor the catchall. I used to do it to be able to shut down inboxes that spammers got a hold of. I kinda stopped doing that when spam filters got good enough. But with this, I'd know who was the real target because the email address would tie it to the specific site.
- TAKEMYMONEY 4y agoMy host banned catchall addresses, which host do you use that allows this? (great advice btw, this has saved me too)
- YourDadVPN 4y agoI pay €1/month for Tutanota which lets me have five aliases, however using DNS redirection with my domain I can have a unique receive address per website.
- taoufix 4y agoProton mail allows this. A free alternative would be using the abc+websitename@domain.com trick. Gmail allows this, but unfortunately some websites wont accept the + sign as valid character in an email field.
- genewitch 4y agofastmail.com allows it. I'm apparently paying "legacy account" rates, which probably highly tempers my recommendation. I pay something like $5 or $12 a year for service. 500mb mailbox. I don't use calendar or anything else so i have no idea if those are restricted.
- MandieD 4y agoI'm on the $95/2 year plan, with about 30GB stoage, and have several domains attached, all set up for catchalls. Trying to explain to a business why their name is in the email address you just filled out on a form is fun sometimes, though, but the only complete rejection I've gotten for it though is the guy who runs the main groups.io for one of my amateur radio transceivers and can't wrap his head around my address not being some attempt at fraud.
- varun_ch 4y agoReading your comment, I think I got hit by the same attack (as a victim) recently.. but I can not find any original email they want to hide. It's been a few weeks and now I have thousands of spam emails. (the inbox is basically unusable) Any tips on how I should find the original email they want to bury? Also, mine wasn't random characters but instead Markov Chain like gibberish to hundreds of random sites. The signups and whatnot stopped, but now it's all the regular newsletters and other spam I get.
- zenexer 4y agoThey start the email bomb just prior to performing the rest of the attack. It’s possible the rest of the attack failed. I went through every email by hand, as I wasn’t willing to take any risks.
- dewey 4y agoI'm running a small online shop and I noticed that in the past days I had a lot of "recipient not found, email cannot be delivered" messages in my inbox. I realized that these are bounces of emails my shop sent. At first I paniced and thought the store was compromised and sending spam, but after some investigation I found that a lot of russian bots actually registered spam user accounts with mostly legit emails which then got all the spam. The only "customizable" parts these emails contained was the "From" field of the emails so they were all in the form of "PAYOUT_TO_YOUR_NAME_$3OOOO_HER example.com <mail@example.com>". After adding a captcha this went away, but it sounds like it was also part of a similar attack.
- folli 4y agoDamn!! That solves a riddle that has been bugging me the last two weeks or so! I'm in the same boat as OP (not a blog, but a web app, https://cubetrek.com https://cubetrek.com). I've received the same type of account registrations (gibberish username, valid email address) since two weeks. My web app sends out an account verification email, so it makes total sense. I've recently integrated Cloudflare Turnstile as captcha alternative, but the automated sign ups have not stopped (they just get ignored server side). I'll probably have to change the endpoint address as well. Since I'm receiving a dozen of apparently compromised email addresses every day, is there anything I can do? Informing the user via email is obviously not very practical. Not to give the bad actor any ideas, but why don't they use some fake names instead of gibberish? It would be less obvious.
- importantbrian 4y agoThis exact thing happened to me with Nike. It's apparently called email bombing. I didn't even realize I had a Nike account, but I guess I bought some shoes or something with it years ago. In my case they tried to buy a bunch of gift cards. Fortunately my bank flagged it as potential fraud and I didn't end up losing any money.
- terrycody 4y agoThis is really an interesting insight, good find! I guess there are no other explanations except this.
- the-mitr 4y agothanks for the explanation. > . I woke up to hundreds of emails from various blogs and other sites asking me to confirm my email. but if i don't approve the comments, then the emails won't go. right? or the mails will still go even if i don't approve them just to confirm from your side?