
How many times has a friend of yours posted on Facebook “My account has been hacked, don’t click on any messages from me”?
A massive phishing campaign that utilized Facebook messenger was recently uncovered. This campaign served two purposes for the attackers.
* Serve ads to victims to earn money on ad clicks
* Compromise account credentials using phishing sites with fake log-in pages to further the phishing campaign.
Usually, the message came from someone you know who already had their account compromised. The original article is on Bleeping Computer (link below).
Massive Facebook Messenger phishing operation generates millions
Transcript
0:00
People are the weakest link in any cybersecurity plan. We’re distracted, exhausted, and often unmotivated. It’s time to change the approach used to protect our businesses, technology, identity and data. The human element has to be front and center in a war against data breaches and ransomware attacks it’s time to educate.
0:52
Welcome to the human element podcast, visit our website at the human element dotnet for more content to help you strengthen your awareness of the people problem in cybersecurity. I am Scott Gombar. Owner and Washtech a client-focused security-minded proactive IT service provider. Hello and welcome to episode nine phishing through social engineering. And we’re going to use bleeping an article from bleeping computer again this week. I don’t like I don’t usually go for the same source twice. But bleeping computer is a really good site. They don’t talk a lot about social engineering, but they do a little bit and obviously, so we have a couple of two weeks in a row now podcasts with social engineering ties on bleeping computer. And this article is massive Facebook Messenger phishing operation generates millions. And this really shouldn’t come as a surprise to anybody who’s familiar with social engineering. Many of us get scammed on Facebook, Instagram, Twitter, and not so much on LinkedIn, but it can happen on LinkedIn and other platforms. A lot. It happens a lot. And while I have not been successfully scammed on any of those platforms, I certainly get my fair share of attempts. And how so how does it happen in this article, talks about how it happens a little bit. And it says researchers have uncovered a large-scale fishing operation that abused Facebook and messenger, which means that you could conceivably think WhatsApp as well. And I have gotten messages on WhatsApp as well. To lower millions of users to phishing pages, tricking them into entering their account credentials and seeing advertisements. The campaign operators used these stolen accounts to send further phishing messages to their friends generating significant revenue via online advertising commissions. So while it’s not you would think, okay, they’re just, you know, they’re just getting people to click on ads, and they’re making money off of that you can, you know, sign up as an affiliate and make money off of ads. I’ve done this with AdSense in the past and not currently doing it anywhere. I’ve done this with Amazon as well. Of course, my methods are a little more ethical, these are not ethical methods. So they send in, send you a message from somebody who claims to be your friend. In reality, that account has been compromised, and And chances are, you’re clicking on, as it says you’re clicking on a link in and logging in. They’re stealing your credentials, too. So now they’re going to use your account to do the same thing. So how does this happen?
Jun 16, 2022
21 min

Have you ever gone to Google to search for Microsoft Office to purchase and returned results that offer the entire Microsoft Office Suite for a one-time purchase of $30? Who could pass up that deal?
Well, you should pass on that deal but some will not because it’s human nature to want to save money and to trust Google.
That $30 Microsoft Office purchase is cracked software and likely contains malicious software. The $120 you saved could cost you in identity theft, credential theft, credit card theft, network takeover, data theft, ransom demands, and/or loss of your business.
So why do people still purchase it? Is it a lack of education? Or do they just not care?
In this episode, we discuss how attackers are using a cracked version of CCleaner Pro to install credential-stealing software on victim computers. People are choosing to “steal” the software rather than pay the $30 (currently $20) for CCleaner Pro. The $30 savings is costing them a lot more but why do people choose to do this?
Here’s the article on Bleeping Computer
Poisoned CCleaner search results spread information-stealing malware
Transcription
0:00
People are the weakest link in any cybersecurity plan. We’re distracted, exhausted, and often unmotivated. It’s time to change the approach used to protect our businesses, technology, identity and data. The human element has to be front and center in the war against data breaches and ransomware attacks. It’s time to educate.
0:52
Welcome to the human element podcast, visit our website at thehumanelement.net for more content to help you strengthen your awareness of the people problem in cybersecurity. I am Scott Gombar. Owner and Washtech a client-focused security-minded proactive IT service provider. Hey, everyone, it’s been a little bit of a while I apologize the IT world is insane. A little busy lately. This is episode eight. I may change the title later. But I’m going to call this the Google search problem. For now. We’ll call that a working title. And I’m using an article from bleeping computer. It’s one of my favorite sites for news, bleeping computer.com. And this one is called poisoned CCleaner search results spread information-stealing malware. Now the issue isn’t really CCleaner. And you’ll understand why once I’m done. I know in the past CCleaner has had malicious or had a vulnerability. I think it’s been a few years now. That vulnerability no longer exists unless you’re you know, you haven’t updated CCleaner in years. Hopefully, that’s not the case. Because that would be a different set of circumstances, I’m sure. Well, what is going on here is that attackers, malicious actors are using Google Search to get people to download CCleaner. Now you’re thinking alright, what does it have to do with the human element has a lot to do with the human element because Google accounts for I don’t know what the numbers are in 2022. But it’s always been very high. Around 90% of all internet search traffic now hasn’t changed much. Or maybe it’s gone down to 80%. I don’t really know. You know, the competition for Google, as far as search goes, hasn’t been really much of a competition, though DuckDuckGo has gained a little bit of ground, I think that’s a different topic. And DuckDuckGo now has its own set of issues, because they were actually, you know, DuckDuckGo advertises that they don’t track anything. But that’s not true. They were tracking for Google or for Microsoft, sorry.
Jun 10, 2022
19 min

It should come as no surprise that phishing attacks continue to increase in number. They’re also becoming more sophisticated utilizing multiple methods of phishing to improve their success rate. But why is phishing used so often? Who is doing the phishing? How do you prevent it?
We will discuss this in this episode of the Human Element. We review some statistics and thoughts from the below article.
Global Phishing Attacks Hit A New Record in 2021
Unedited Transcript
0:00
People are the weakest link in any cybersecurity plan. We’re distracted, exhausted and often unmotivated. It’s time to change the approach used to protect our businesses, technology, identity and data. The human element has to be front and center in a war against data breaches and ransomware attacks, it’s time to educate.
0:52
Welcome to the human element podcast, visit our website at the human element dotnet for more content to help you strengthen your awareness of the people problem in cybersecurity. I am Scott Gombar, owner and Washtech a client focused, security minded proactive IT service provider. Everyone welcome to episode seven. I am Scott Gombar. And we’re going to talk about global phishing attacks hit a new record in 2021. Before I get to that, I want to apologize and it’s been a few weeks. As you know, as you may know, if you own any business really but an IT business door ebbs and flows, and sometimes things get a little crazy. So haven’t had an opportunity to sit and record took on a new large client. So been very hectic, but here we are. And I’m reading this from software. It’s software.com. If you go to their new section, there is an article from April 27. So that’s yesterday, as I record this, that global phishing attacks hit a new record in 2021. And I’m not really surprised by this. But we’re gonna go through this nonetheless. And I will point out some things that that I think are important here, so global phishing attacks have hit a new high and 2021. As a new attack as new attack vectors and phishing as a service methods emerged. One of the reasons that this type of attack grows in prevalence every year is its low barrier to entry. Meaning, it’s not hard to send a phishing email, I could send a phishing, I don’t even need anything really to send a phishing email, just open up a fake Google account or a fake Outlook account or whatever. People are still using Hotmail, AOL free cable company email, or ISP, email, all of these things are still being used in then send a phishing email. I’ve literally done this to teach people what to look for. Moreover, cyber criminals take advantage of current events such as COVID-19 pandemic or cryptocurrency to trick victims to hand over their confidential data. Now, of course, we have a war in Ukraine. And the tools that are used to do a lot of this are actually available free to our Linux distributions that include these tools or if you’re inclined, you can download some of the tools and install them on your computer even if you use Windows download VirtualBox and and install kali linux or or parrot on your virtual box and use it from there. And they’re free to use and they’re not hard to learn. And that is what is meant by low barrier to entry. Now, a lot of times the phishing attacks are pretty obvious, you get emails that, you know, the grammar is really bad. And the links are poorly written and it’s sent to a whole bunch of people. And if you pay attention to where it came from, it came from a Gmail address. And if you go to the Nightwatch tech YouTube page, you’ll see a lot of phishing attack emails that we review.
Apr 28, 2022
20 min

A lot is made of adding MFA/2FA to everything you log in to. And you absolutely should do this.
What isn’t discussed enough are ways to circumvent MFA. Most of the methods for bypassing 2FA/MFA are social engineering tactics. What’s even scarier is the methods used to bypass MFA are not that complicated.
How are end-users being tricked into bypassing MFA and what can you do to protect yourself from potentially handing your account over to an attacker?
Mar 30, 2022
22 min

Ep 5 – All Your Passwords Are Belong to Us
A recent data breach of Nvidia revealed that employees were using really bad passwords like “nvidia” or “password“. Why do people continue to use weak passwords, and why are businesses not enforcing a stronger password policy?
We discuss this in detail, as well as what makes a strong password policy, in episode 5 of the Human Element podcast. The short answer is using and reusing weak passwords is a human problem. It’s easier and faster to use simple passwords, and use the same password across multiple platforms.
What if I told you your password is already on the internet, along with your username?
There is a solution. Listen to learn more.
Mar 24, 2022
20 min

Ep 4: The High Cost of Convenience – Zelle Phishing
Payment apps and digital wallets are fast and convenient. They are great tools to send and receive money to someone quickly. Apps like Venmo, Cash App, and Zelle make it possible to accept payments or send money to anyone else using the same app. Sounds great, right?
They are also convenient for thieves and attackers. In this episode of the Human Element, we recreate how an attacker tricks a Zelle user into sending money to a thief without even realizing that’s what they’re doing. This attack isn’t a real event but it is similar to other successful attacks.
Transcript of Ep 4: The High Cost of Convenience – Zelle Phishing
Mar 17, 2022
20 min

Ep 3: Ukraine Cyberwar is very real. Do you need to worry?
Episode 3 became necessary after I was asked at least a dozen times how to prepare for the potential of a cyberattack resulting from the war in Ukraine. I wasn’t going to podcast about the war as it is already receiving a lot of attention from mainstream media. I decided to do this to have a resource for people asking me questions, and because when I searched up what others were saying I saw that a lot of it was sensationalism.
Most of what I share is not new. In fact, read or listen to some of my previous content and you will see I have encouraged a strong password policy, 2fa, and not to click on links numerous times. Yet, there are a few things you should prepare yourself for.
Have a listen and leave a comment.
Transcript of Ep 3: Ukraine Cyberwar is very real. Do you need to worry?
0:00
People are the weakest link in any cybersecurity plan. We’re distracted, exhausted, and often unmotivated. It’s time to change the approach used to protect our businesses, technology, identity and data, the human element has to be front and center in the war against data breaches and ransomware attacks, it’s time to educate.
0:52
Welcome to the human element podcast, visit our website at thehumanelement.net for more content to help you strengthen your awareness of the people problem in cybersecurity. I am Scott Gombar. Owner Nwaj Tech is a client-focused, security-minded proactive IT service provider. Hey everyone, Scott Gombar Here, episode number three. And this isn’t really an episode I want to do. But I feel like I need to do it. And so last week, I did send an email out to all of my clients to help them identify what they need to be aware of. This week, I’m recording this podcast, as it looks like the war between Russia and Ukraine will continue on and they’re announcing for months or years. I really hope it doesn’t. And I really, it’s really sad to see that the entire world is telling Russia to back off. And this one man is just not listening. But this is not a political podcast. So I’m going to back away from the political component. And we’re going to start episode three, Russia, Ukraine, cyberwar is very real. But do you need to worry? So I saw a number of news articles, blog posts, just all kinds of things that discuss how to protect yourself during this war because of the potential of a cyber attack. So let’s start off by addressing and I have been asked as well, which is why I sent the email last week, but even since then, I’ve been asked a few times, again, how do I prepare myself for the potential of a cyber attack during this war, and we all know a lot of these advanced persistent threat groups exist in Russia, these the hacking groups, so they exist in Russia, I believe I saw somewhere that Ukraine was able to shut down Conte, which is one of the groups in Russia. But there are others and, of course, their nation-state-backed groups in Russia, that won’t ever admit to that, but they’re there. We know most of the cyber attacks that occur come, a lot of them come out of Russia is not the only country and there are other players in the game. And then there are some rogue cyber attack groups as well, that don’t have nation-states behind them. So it does happen, and I’m not going to say it won’t happen. Or that, you know, you’re too small, because I don’t believe anybody’s too small to be the victim of a cybercrime. It happens all the time small business owners. And usually, when it happens to a small business owner, they usually end up going out of business within six months. So the threat is very real. However, with this war, the Russian advanced persistent threat groups, and the hacker groups and or, you know,
Mar 10, 2022
22 min

Ep 2: Vishing Increases Phishing Success Rate by 3 Times
Episode 2 reviews an article on InfoSecurity Magazine. Phishing was the number 1 threat vector in 2021 closely followed by vulnerabilities. For clarity, vulnerabilities are defined as software and hardware glitches the manufacturer has issued patches or updates for which the owner of the software or hardware has yet to update.
What made the phishing statistic more interesting is that when a phishing attack included vishing (voice phishing) the success rate was nearly 3 times higher than phishing attacks without vishing. Of course, I have a real-world example of exactly how such an attack would work.
Here’s the original article on InfoSecurity Magazine
Transcript of Ep 2: Vishing Increases Phishing Success Rate by 3 Times
0:00
People are the weakest link in any cybersecurity plan. We’re distracted, exhausted, and often unmotivated. It’s time to change the approach used to protect our businesses, technology, identity, and data. The human element has to be front and center in the war against data breaches and ransomware attacks it’s time to educate.
0:52
Welcome to the human element podcast, visit our website at thehumanelement.net for more content to help you strengthen your awareness of the people problem in cybersecurity. I am Scott Gombar. Owner and Washtech is a client-focused, security-minded proactive IT service provider. Welcome to episode two vishing makes phishing campaigns three times more successful. Hello, everyone. Scott Gombar, owner of Nwaj Tech, we are back again with the second episode of the human element podcast where we talk about well the human element of data breaches and ransomware attacks and cyberattacks and all that fun stuff. And today, I’ve got an article on info security dash magazine.com info security magazine. And the title of the article is vishing makes phishing campaigns three times more successful by Phil Muncaster. And the article talks about the number one and number two threat vectors for 2021. Last year and number one probably shouldn’t come as a surprise given what podcast you’re listening to is Phishing. Phishing was 41% or globally. Phishing overtook vulnerability exploitation as the top pathway for compromise globally, in 2021, accounted for 41% of initial access attempts, which is up 33% from 33%, in 2020, so it went from 33% to 41%. And the number two threat vector was vulnerabilities and that is identified software holes, I guess you could say in different software and hardware. So in other words, if I have a Microsoft Windows computer, Windows 10 computer, and patch Tuesday rolls around, and I don’t apply those patches and some of those patches are for critical vulnerabilities are a zero-day. And I don’t apply those patches and my computer is now vulnerable. That’s a vulnerability and the number two threat vector for 2021 was vulnerabilities. So the number one phishing number two vulnerabilities and the number of vulnerabilities was 30. Or to go 33%. I think it was 33%. It’s interesting because I wrote an article not too long ago on my company’s website and nwajtech.com. And nwajtech.com. And the article was about the big four and talked about phishing, we talked about the Big Four, by the way, it was about the four easiest ways into a business into a network into technical or technology-based structure infrastructures. And we talked about the four easiest ways in. Two of them were phishing and unpatched software hardware. And in the article talks about some of the more common commonly exploited vulnerabilities one from 2021, which was a Java, Java, D serialization Volden vulnerability,
Mar 3, 2022
21 min

What happens when someone calls into the cable company, pretends to be a support rep, and gains access to the tools and customers' account information?
Feb 26, 2022
20 min
