USAA Phishing scam linked to 1500 domains
發佈時間:2010-11-03
瀏覽次數:4590次
AppRiver is warning users that a Phishing scam, targeting members of the U.S. Armed Forces and their families, has surfaced in the guise of a notification from USAA. They call the attack one of the more intricate and widespread campaigns that they’ve seen in some time.
For years, military personnel (active and former) and their families have used United Services Automobile Association (USAA), and subsidiaries like USAA Financial Planning Services, to manage insurance, banking, and other financial needs.
The latest Phishing attack noticed by AppRiver isn’t the first one to target USAA members. As is the case with the previous attacks, this latest one attempts to steal personal information and money. The emails are delivered with subjects related to security alerts and urgent messages, but they’re junk according to AppRiver and USAA. In short, they should be deleted or reported to abuse@usaa.com.
A link in the newest wave of Phishing attempts will direct the potential victim to a form that asks for USAA account details, including USAA card numbers, PIN, and other related security codes. This is in addition to personal information such as name and online banking ID. The website and the form itself is a near perfect mirror of the legitimate USAA site, making it harder to tell it apart from the real thing to the untrained eye.
However, according to USAA, you can spot a fake version of their site by looking at the address bar for a visual cue.
“Valid USAA websites use Extended Validation (EV) certificates which are an authentication method that turns the Web address bar green, helping you to establish you are visiting a legitimate website.”
In addition, although the e-mail includes a USAA logo and appears to be from USAA, “USAA will not ask for any personal or account information, including PINs or passwords, in an e-mail.”
Like other financial institutions, if USAA were to make changes or need information from you, they would contact you directly via postal mail or telephone.
“Although we do see Phishing attempts directed at USAA members among hundreds of other financial firms on a regular basis, this is one of the more intricate and widespread Phishing campaigns that we have seen in quite some time,” the AppRiver alert noted.
“Each unique domain is serving up a complete fake USAA website. At this time we are monitoring (and blocking) over 1500 unique domains that are all registered with the free .tk (tld).”
Update:
M86 notes that they have started seeing these emails as well. They make mention that they are being pushed by Cutwail, which is the spamming component installed by the Pushdo botnet.
"We have not seen one of these large scale phishing campaigns from Cutwail for some time, as the cybercriminals switched to spamming out links to the data-stealing Zeus malware. With the recent high profile arrests of several Zeus perpetrators, and all the subsequent public attention on Zeus, maybe phishing, where you politely ask for data instead of stealing it, will come back in fashion?"
Todaynic.com International Limited
ICANN CNNIC HKDNR Accredited Registrar
搜索








