HomeSecurityOne-Click Fraud Targets Hong Kong, 8,000 Attacks Blocked

One-Click Fraud Targets Hong Kong, 8,000 Attacks Blocked

One-Click fraud

Cybercriminals are carrying out One-Click frauds aimed at expanding their operations in Hong Kong, successfully attacking thousands of users in the past month.

The scam is similar to ransomware, displaying a persistent pop-up window that, in order to "unlock" the computer screen, requests a monetary payment to register on an adult website.

Although, this type of scam has been attracting victims for over 10 years now, it was somewhat geographically limited, as the most targeted were Japanese users.

However, new findings from security firm Symantecshow that cybercriminals are now targeting the Chinese market, and are adapting their scam by writing it in traditional Chinese characters in Hong Kong.

"It appears that the One-Click have decided to go multilingual in an effort to broaden their horizons and explore new market opportunities," Himanshu Anandon Thursday.

Anand also states that Symantec's products stopped over 8,000 attacks during the previous month, which could have deceived users with damages greater than 5 dollars/euros and 4,460,000 Hong Kong dollars.

In this particular One-Click fraud, the potential victim is required to download an  HTML application (HTA), which if granted permission, executes a malicious script. The file appears innocuous and is offered when the user browses a website with adult content, accessing a video playback window or age gate.

According to Anand, the subscription pop-up restarts the computer and is designed to force the victim to pay so that it is removed from the screen.

However, the One-Click fraud attack only affects Internet Explorer users , as HTA files rely on the mshta.exe engine , which is only present in Microsoft 's web browser , to execute code .

Since HTAs were released as fully trusted applications and are not isolated in the sandbox, cybercriminals could compromise the victims' computer in a much worse way than this, such as stealing personal data, turning the system into a botnet to spread spam, or performing DDoS.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS