Maria Varmazis, host of the N2K daily space show, T-Minus, discusses the evolving tactics of ransomware attackers towards psychological manipulation. The podcast also covers bank scammers using genuine push notifications, North Korean social engineering attacks through email security loopholes, and a listener's experience with a fake email from the U.S. Social Security Department.
Ransomware attacks evolving to psychological tactics for payments.
Scammers using genuine push notifications for bank scams and exploiting email security loopholes for social engineering attacks.
Deep dives
DMARC Policy Enforcement and Email Spoofing
DMARC, SPF, and DKIM are key technologies used to prevent email spoofing and unauthorized sending of emails. These tools allow domain owners to specify authorized sending servers, digitally sign messages, and set policies for email validation. Improperly configured DMARC records can lead to successful email spoofing attacks by malicious actors like the North Korean group Kim Suki targeting policy analysts.
False Social Security Number Suspension Scam
A phishing email masquerading as the US Department of State warns recipients of a Social Security Number suspension due to alleged fraudulent activities in Texas. The email cites criminal offenses and financial fraud, urging recipients to contact a provided number. The email contains grammatical errors, inconsistent information, and attempts to create urgency and fear to manipulate recipients.
Inconsistent Claims and Government Agency Misrepresentation
The phishing email falsely claims association with government agencies like the Department of Justice and Federal Trade Commission, displaying a lack of accuracy and coherence in legal citations and procedures described. The use of legal jargon, threats of legal action, and an urgent tone aim to exploit recipients' fear and confusion to elicit a response or further personal information.
Attempted Email Scam with Legal Intimidation Tactics
The fraudulent email attempts to intimidate recipients by alleging legal complaints, money laundering, drug trafficking, and IRS fraud tied to their identity. By creating a sense of urgency and threat of imminent legal action, the scam email aims to coerce recipients into contacting the provided number or responding with personal information, highlighting the manipulative tactics used in phishing schemes.
This week we are joined by Maria Varmazis, host of the N2K daily space show, T-Minus. Maria shares an interesting story about how ransomware infections are beginning to change to form a more psychological attack against victims' organizations, as criminals are using personal and aggressive tactics to force them to pay. Dave and Joe share some listener follow up, from Bob, who writes in to share how he shares stories with his family members, and mentions one specifically on a Best Buy Geek Squad scam. Dave share's a story on bank scams, and how scammers are using genuine push notifications to trick their victims. Joe shares a story regarding email security loopholes, and how these loopholes are the latest path for North Korean social engineering attacks. Our catch of the day is from our follow up listener Bob, as he shares the story of trying to figure out the difference between a real email from the U.S social security department and a fake one.
Please take a moment to fill out an audience survey! Let us know how we are doing!