Brazil's World Cup 2014 Imminent – with Danger Everywhere

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Free tickets, Neymar da Silva Santos Júnior and Lionel Messi are being used as bait in current fraud gambits.
The world is waiting with bated breath for the 2014 FIFA World Cup to kick off in Brazil this week, and right on cue, fraudsters are hoping to deal unsuspecting fans a hat trick of scammery.

Anti-virus firm Symantec has already identified several World Cup scams, including dubious emails promoting free tickets to the tournament – which of course end up containing a malicious zip file instead. The latest campaign is serving up a remote administration tool (RAT) known as DarkComet.

“The most common scam around the World Cup involves free tickets,” explained Satnam Narang, a Symantec researcher, in a blog. “After all, what fan would not want an all-expenses paid trip to Brazil? Scammers know a dream come true is hard to pass up and circulate emails promising everything imaginable.”

Also, emails containing news and highlight reels about World Cup teams and players are being used to entice users to open up malicious attachments or click on malicious links.

“Emails are currently circulating about Neymar da Silva Santos Júnior, a young star player with the Brazilian national team,” Narang noted. “The email contains a malicious word document that exploits a known vulnerability in Microsoft Word. Interest in players like Neymar and others like Argentinian national star Lionel Messi are used as the bait by scammers targeting victims, whether through email or social networking services.”

Once the World Cup begins, Symantec warns to beware scams claiming to offer free live streams of the action. These may ask marks to fill out a survey or download and install software before they can unlock access to the live stream – all of which is a gateway to malicious activity.

“As we have observed in the past, once the World Cup begins, there will be scams circulating on social networks that claim to offer free live stream of various matches, especially the final games,” Narang said. “These scams may ask you to fill out a survey or download and install software before you can unlock access to the live stream. Be skeptical—these enticements are just tricks to put money into the pockets of the scammers.”


Read more: http://www.infosecurity-magazine.co...rld-cup-2014-imminent-with-danger-everywhere/
 

Littlebits

Retired Staff
May 3, 2011
3,893
Use Your Head: Do Not Fall For FIFA World Cup Scams:

With the 2014 FIFA World Cup in Brazil just around the corner, scammers have kicked off efforts to target fans of the international football event. World Cup fans everywhere should watch out for free ticket scams, news service scams, and online streaming scams. Symantec has already identified several email scams and we expect to see attempts to target fans on social networks.

Free tickets to the World Cup

The most common scam around the World Cup involves free tickets. After all, what fan would not want an all-expenses paid trip to Brazil? Scammers know a dream come true is hard to pass up and circulate emails promising everything imaginable.

Fifa%20World%20Cup%201.png


Figure 1. Scam email offers free tickets to 2014 World Cup in Brazil

Emails Symantec has identified in circulation contain a malicious zip file. Inside the zip file is an executable which, if executed, will allow your computer to be taken over by a remote administration tool (RAT) known as DarkComet.

Symantec protects customers against this malware with a Backdoor.Breut detection.

World Cup news and highlights

Besides free ticket enticements, news and highlight reels about World Cup teams and players can also be used to entice users to open up malicious attachments or click on malicious links.

Fifa%20World%20Cup%202.png


Figure 2. Scam email with malicious attachment targeting fans of Brazilian star Neymar

Emails are currently circulating about Neymar da Silva Santos Júnior, a young star player with the Brazilian national team. The email contains a malicious word document that exploits a known vulnerability in Microsoft Word.

Interest in players like Neymar and others like Argentinian national star Lionel Messi are used as the bait by scammers targeting victims, whether through email or social networking services.

Free online streams of World Cup matches

As we have observed in the past, once the World Cup begins, there will be scams circulating on social networks that claim to offer free live stream of various matches, especially the final games.

These scams may ask you to fill out a survey or download and install software before you can unlock access to the live stream. Be skeptical—these enticements are just tricks to put money into the pockets of the scammers.

Tips to keep a “clean sheet” against scammers

  1. Remember that free stuff is never free. If you receive an email or a link on a social network offering free tickets to the World Cup, recognize that it is most likely a scam.
  2. If you are interested in what is happening with your favorite World Cup teams or players, please visit the official news websites for information and avoid randomly found or unknown sources.
  3. Looking to watch the World Cup games online? ESPN will offer live streams for subscribers in the United States and the BBC has streaming for the UK. Check your local service providers to see where and when you can catch World Cup games online.
  4. Be sure to have applied all the latest patches and security updates for your operating system and software applications. An up-to-date system is less vulnerable.
  5. Add extra safety with antivirus protection.
Source
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top