Jump to content

It'(wa)s 2019 and people still fall for spelling mistakes - Microsoft takes down 50 North Korean phishing sites

williamcll

image_phishing.gif

Multiple people were fooled into providing their credentials to websites named rnicrosoft. The hacking group has also compromised systems with malwares named “BabyShark” and “KimJongRAT.”.

Quote

Microsoft has taken control of fifty sites reportedly linked to cyberattacks originating from North Korea. The Windows maker has been successful in a court bid to take down fifty domains used for spear phishing attacks that would both steal personal data and upload malware to infect IT systems.

 

The attacks apparently came from a hacking group known as Thallium, which has been accused of being affiliated with the North Korean government. The court action, filed in Virginia last month, came after both the US Digital Crimes Unit (DCU) and the Microsoft Threat Intelligence Center (MSTIC) teams finalised a long-term investigation into Thallium and its activities, which looked to target employees of governments, international agencies, as well as university staff, mostly based in the US, Japan and South Korea. The spoof emails claimed that the user’s account was compromised, advising them to login to change their account details - but clicking on a link that offered to do so would take the victim to fake phishing sites hosted on one of the malicious domains, which would look to steal personal login details.

The hackers were also able to set up a command to silently copy any new emails to the user without their knolwedge, even if the account password had been changed.

 

Microsoft says that the court decision has now allowed it to take control of the fifty domain names used in the attacks, which have all now been removed.

 

Source:https://www.itproportal.com/news/microsoft-sees-50-north-korean-phishing-sites-taken-offline/

https://blogs.microsoft.com/on-the-issues/2019/12/30/microsoft-court-action-against-nation-state-cybercrime/

Thoughts: You did think microsoft's own phishing filter is smart enough to clear these emails but I guess some still slip pass. Honestly I think the apple phishing mails were more authentic. I bet there emails out there right now originating from "Pomhub" or something silly.

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, williamcll said:

Multiple people were fooled into providing their credentials to websites named rnicrosoft

wonder if modern companies factor in fonts when considering their company names to avoid this

I WILL find your ITX build thread, and I WILL recommend the SIlverstone Sugo SG13B

 

Primary PC:

i7 8086k - EVGA Z370 Classified K - G.Skill Trident Z RGB - WD SN750 - Jedi Order Titan Xp - Hyper 212 Black (with RGB Riing flair) - EVGA G3 650W - dual booting Windows 10 and Linux - Black and green theme, Razer brainwashed me.

Draws 400 watts under max load, for reference.

 

How many watts do I needATX 3.0 & PCIe 5.0 spec, PSU misconceptions, protections explainedgroup reg is bad

Link to comment
Share on other sites

Link to post
Share on other sites

I physically zoomed into my monitor (by leaning forward) to see that.

mY sYsTeM iS Not pErfoRmInG aS gOOd As I sAW oN yOuTuBe. WhA t IS a GoOd FaN CuRVe??!!? wHat aRe tEh GoOd OvERclok SeTTinGS FoR My CaRd??  HoW CaN I foRcE my GpU to uSe 1o0%? BuT WiLL i HaVE Bo0tllEnEcKs? RyZEN dOeS NoT peRfORm BetTer wItH HiGhER sPEED RaM!!dId i WiN teH SiLiCON LotTerrYyOu ShoUlD dEsHrOuD uR GPUmy SYstEm iS UNDerPerforMiNg iN WarzONEcan mY Pc Run WiNdOwS 11 ?woUld BaKInG MY GRaPHics card fIX it? MultimETeR TeSTiNG!! aMd'S GpU DrIvErS aRe as goOD aS NviDia's YOU SHoUlD oVERCloCk yOUR ramS To 5000C18

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Fasauceome said:

wonder if modern companies factor in fonts when considering their company names to avoid this

Not with common browser supported fonts it doesn't. Maybe possible if you turn on dyslexia support.

 

 

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

People still believe Indians from "New York" who need to access their bank accounts to get an Amazon refund for something that's not on their account because of "hackers".

 

They're likely targetting the older people with half farked eye sight who won't notice the difference.

Link to comment
Share on other sites

Link to post
Share on other sites

The spelling mistakes and bad grammar are sometimes there intentionally.  These phishing attacks don't actually target  average or higher intelligence people who tend to catch on quicker increasing the chance of things not working.  They want the  people who will still think they haven't been fooled for a week or two so they can get the money and be home free before anyone of significance is informed.   By including the mistakes and poor grammar effectively filters out majority of the respondents that won't net them any return.

 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

15 hours ago, Curious Pineapple said:

People still believe Indians from "New York" who need to access their bank accounts to get an Amazon refund for something that's not on their account because of "hackers".

"hello, yes this is the IRS, you own us money, and the only way you can pay us is with itunes gift cards. Also don't tell anyone this is what you're buying them for, otherwise they will call the police and have you arrested for tax-evasion"

 

how people STILL believe this is legit will forever be beyond me

🌲🌲🌲

 

 

 

◒ ◒ 

Link to comment
Share on other sites

Link to post
Share on other sites

The IRS will never call you - They just show up and that's it.

"If you ever need anything please don't hesitate to ask someone else first"..... Nirvana
"Whadda ya mean I ain't kind? Just not your kind"..... Megadeth
Speaking of things being "All Inclusive", Hell itself is too.

 

Link to comment
Share on other sites

Link to post
Share on other sites

31 minutes ago, Arika S said:

"hello, yes this is the IRS, you own us money, and the only way you can pay us is with itunes gift cards. Also don't tell anyone this is what you're buying them for, otherwise they will call the police and have you arrested for tax-evasion"

 

how people STILL believe this is legit will forever be beyond me

They make it that dumb so the ones that fall for it literally don't tell anyone even after the fact.  It is intentionally a con job aimed at those with an IQ below 85.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Arika S said:

"hello, yes this is the IRS, you own us money, and the only way you can pay us is with itunes gift cards. Also don't tell anyone this is what you're buying them for, otherwise they will call the police and have you arrested for tax-evasion"

 

how people STILL believe this is legit will forever be beyond me

i love the irs calls. so much fun but dammit they changed their tactics. now when they call its a automated message saying for you to call them before there is a live person lol. i wont call them. easy chance for outside charges

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, Arika S said:

"hello, yes this is the IRS, you own us money, and the only way you can pay us is with itunes gift cards. Also don't tell anyone this is what you're buying them for, otherwise they will call the police and have you arrested for tax-evasion"

 

how people STILL believe this is legit will forever be beyond me

Older people usually fall for that out of fear and out of not understanding new technologies.

 

Its sad. One almost got my grandma last year (not as dumb as sending gift cards but she almost gave her bank details). But thankfully she mentioned it to a friend who saved her.

 

Theres a special place in hell for these people and i wouldnt piss on them if they were on fire. 

Link to comment
Share on other sites

Link to post
Share on other sites

I've noticed a huge increase in the amount of phishing emails I've been getting for the last few months. I get up to 5 a day every day from Microsoft, Amazon, Netflix, Apple, Google and others. They all say the same thing too, its always either your account is suspended for unusual activity or purchase/delivery failed.

 

I can't even filter them as they come from a new domain every single time. Its actually starting to get annoying. Sometimes I fuck with them and fill out their form using fake details.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, Arika S said:

"hello, yes this is the IRS, you own us money, and the only way you can pay us is with itunes gift cards. Also don't tell anyone this is what you're buying them for, otherwise they will call the police and have you arrested for tax-evasion"

 

how people STILL believe this is legit will forever be beyond me

I had one yesterday saying my car had been involved in an accident, I wasted about 30 minutes of his time before telling him I suffer from a degenerative eye disease, am registered as semi blind and I am not allowed to drive by law. He called me a shit head then hung up very quickly :D

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

22 hours ago, Master Disaster said:

I had one yesterday saying my car had been involved in an accident, I wasted about 30 minutes of his time before telling him I suffer from a degenerative eye disease, am registered as semi blind and I am not allowed to drive by law. He called me a shit head then hung up very quickly :D

interesting..i havent heard of that one

Link to comment
Share on other sites

Link to post
Share on other sites

I am a simple man. I do not click links in emails and if a site says I have issues I will direct myself to the site on another tab to confirm. 99.9% of the time they are fake. 

Link to comment
Share on other sites

Link to post
Share on other sites

I got a call last year from a roadside assistance company I had been forced to join back in 2017 (car broke down as I travelled to my wedding, priorities kinda shift when that happens). Apparently my membership fee "had not been processed."

 

The company must have had a data breach because the caller not only called from the country where the roadside assistance company has its main office (for reference, I'm Dutch and the car broke down in England. The call came from France) and they knew down to the month when my car had broken down. It seemed just legit enough until I noticed that they kept asking me leading questions. The icing on the cake was that they offered to "help me settle the matter right away if I just gave them my credit card info."

 

I "looked around for my credit card" for a good 20 minutes before telling them that they had my credit card info on file.

 

It used to be that their voice and bad English was a dead giveaway but in this case it was a lady working for a French company that sounded like a French person speaking English. She knew enough to be a plausible employee of a company with which I had had actual dealings and she knew a few details about these dealings. It's a far cry from the call I received a few years ago where "Microsoft" informed me of "the virus that was affecting my computer" where the dude legit sounded like Apu Nahasapeemapetilon and it was interesting that Microsoft had contacted me since I did not own a Windows machine at the time.

Link to comment
Share on other sites

Link to post
Share on other sites

On 1/5/2020 at 11:50 AM, Master Disaster said:

I had one yesterday saying my car had been involved in an accident, I wasted about 30 minutes of his time before telling him I suffer from a degenerative eye disease, am registered as semi blind and I am not allowed to drive by law. He called me a shit head then hung up very quickly :D

Yeah I have had people call with that credit card account phone scam saying there is something wrong with your account. I didn't have a credit card at the time lol. 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×