HomeinetSymantec: hacked Gmail, Hotmail and Yahoo Mail accounts with simple SMS

Symantec: hacked Gmail, Hotmail and Yahoo Mail accounts with simple SMS

A new method that hackers are now using to deceive mobile phone victims is presented today by Symantec. Some of the most effective scams are often carried out in the simplest way, for example, we are shown a police officer asking us to hand over our car keys.Symantec sms scam symantec

The average person on the street will probably hand it over without a second thought or doubt. This scam is characterized by two significant elements that make it especially plausible. These are nothing but simplicity and the fact that people usually trust individuals who claim to be police officers or other public authorities. In the same way, cybercriminals operate today.

Recently, according to Symantec studies, an increase has also been observed in a specific type of phishing attack targeting mobile phone users. The ultimate purpose is ultimately access to the victim's e‑mail account. This social engineering attack is very persuasive and users easily fall into the trap.

To carry out the attack, hackers need to know the target's email address and their mobile phone number, data that can ultimately be obtained without much effort. The attackers make use of the password recovery feature provided by many e‑mail providers and thus «help» them gain access to their accounts, among other options, with a verification code they receive on their mobile phone (so the phone number is also required).

The majority of cases recorded by Symantec involve Gmail, Hotmail and Yahoo Mail users. Using Gmail as an example, the following steps describe how the attack works:
• The victim user registers their mobile phone number in Gmail, so that if they forget their password, Google sends a text message with a verification code and the user can access their account.
• The bad guy, the hacker, wants to break into the user’s account, but does not know their password. They know their email address and phone number. The hacker visits the Gmail login page and enters the user’s details (but not the password) and then seeks help via the “Need help?” link. This link is used when users have forgotten their login details.
• The system gives the hacker several options, including “Enter the last password you remember” and tap “Confirm password reset on my [MAKE AND MODEL] phone,” but skips these options until it gives you the option to “Get a verification code on my phone: [MOBILE PHONE NUMBER]” • The
hacker confirms the option and the victim user will now receive the six-digit verification code via SMS on their phone. •
The user receives a message that says “Your Google Verification code is [SIX-DIGIT CODE].”
• The hacker sends the user an SMS message that says something along the lines of: “Google has detected unusual activity on your account. Please respond with the code sent to your mobile device to stop unauthorized activity”. (Google has detected unusual activity in your account. Please respond with the code sent to your mobile device to stop unauthorized activity).
• The user believes that the message is trustworthy and responds with the verification code.
• The hacker uses the verification code to temporarily obtain a password and then attacks the email account and its data.

However, the «communication» of the hacker with his victims does not stop here. Many hackers continue to send messages to their victims when something goes wrong with the connection and the passwords. Of course, the messages remain simple and believable, thereby convincing the victims without much effort.

When the attacker now gains access to the user’s account, they can, for example, among other things, add an alternative email address to the account and thus receive copies of all messages that will be transmitted to that address.

Symantec actually states that hackers also send a «thank you» message to their victims, which usually takes the form “Thank you for verifying your Google account. Your temporary password is [TEMPORARY PASSWORD]” (Thank you for verifying your Google account. The temporary password is [temporary password] ”

This makes the phishing attack increasingly credible, as the victim considers all the correspondence legitimate and believes that his account is now secure.

Cybercriminals of this type of attacks do not appear to focus on financial gain, as is the case with credit card number theft. It seems they are trying to collect information about their victims, and not en masse, but targeting specific individuals. Their modus operandi is similar to the methods used by APT groups.

This simple yet highly effective attack method is much cheaper than traditional spear-phishing attacks, where an attacker has to register a domain and create a phishing website. In this case, the only cost borne by the hackers is the SMS message, and as a method it is also very difficult to detect since it must be carried out by specialized software for mobile phones or by the respective mobile carrier.

Symantec advises users to be wary of SMS messages requesting verification codes, especially if they did not request them themselves.

If we are not sure about the message we received, we check its origin with our email provider to confirm whether the message is legitimate.

Messages usually sent by password recovery services only contain the verification code and do not ask the user to reply in any way.

Always remember that even if someone looks like a police officer or a higher authority, this does not necessarily mean that we should hand over our information without asking for corresponding confirmation of their identity.
Watch an interesting video from Symantec showing how attacks on unsuspecting users are carried out in practice:

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS