Jump to content
  • Sign Up
×
×
  • Create New...

Recommended Posts

  • Diamond Member



Proofpoint exposes AFF scammers’ piano gambit

A

This is the hidden content, please
targeting, of all things, people who might be interested in buying a second-hand piano, may have netted the scam operation behind it over $900,000, according to researchers at email security specialist Proofpoint.

The email campaign seems to have started in January 2024, and is ongoing. It forms the precursor to an

This is the hidden content, please
(AFF) scam, a type of ****** usually targeting private individuals, rather than organisations, in which victims are offered money, products or services, offered the opportunity to take advantage of an incredible deal that never materialises, or asked for help retrieving funds from another country.

Generally, victims will be baited with elaborate stories into making a small payment – or advance fee – to receive the promised goods or services. Needless to say, once the victim has paid up, nothing ever materialises.

They are generally run by financially motivated cyber **********, and due to the fact so many of them seem to originate from Nigeria, are often known as 419 scams, after the relevant section of ********* law that deals with such matters.

They often exploit current concerns and events, which at first glance makes the use of such a specific lure somewhat unusual. However,

This is the hidden content, please
, comprising Tim Kromphardt and Selena Larson, there may be some specific targeting at play.

“Most of the messages target students and faculty at colleges and universities in North America, however other targeting of industries including healthcare and food and beverage services was also observed,” they wrote. “Proofpoint observed at least 125,000 messages so far this year associated with the piano scam campaigns cluster.

“In the campaigns, the threat actor purports to offer up a free piano, often due to alleged circumstances like a ****** in the family,” they continued. “When a target replies, the actor instructs them to contact a shipping company to arrange delivery. That contact address will also be a fake email managed by the same threat actor. The ‘shipping company’ then claims they will send the piano if the recipient sends them the money for shipping first.”

The ********** request payment via multiple options, including the likes of Apple Pay, Cash App,

This is the hidden content, please
or Zelle, or in cryptocurrency, and also try to collect the victim’s personal data, such as their mailing address or mobile phone number.

Kromphardt and Larson said they had identified at least one Bitcoin wallet used in the campaign by the scammers, which contained close to a million dollars, although they pointed out that the wallet is likely being used in the pursuit of more than one scam.

The original emails tend to comprise similar text with small variations each time, and originate from free webmail accounts, such as

This is the hidden content, please
Mail.

The researchers were able to trick one of the ********** into interacting with a redirect service they controlled, and during the course of the conversation were able to identify both their IP address and device information, as well as firm up links with cyber ********** operating in Nigeria.

“Proofpoint has previously published research on AFF campaigns using a variety of different themes to entice recipients to engage with them, including employment opportunities targeting university students and cryptocurrency ******,” wrote Kromphardt and Larson.

“In all cases, AFF relies on elaborate social engineering and the use of multiple different payment platforms. People should be aware of the common techniques used by threat actors and remember that if an unsolicited email sounds too good to be true, it probably is.”





This is the hidden content, please

#Proofpoint #exposes #AFF #scammers #piano #gambit

This is the hidden content, please

For verified travel tips and real support, visit: https://hopzone.eu/

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Vote for the server

    To vote for this server you must login.

    Jim Carrey Flirting GIF

  • Recently Browsing   0 members

    • No registered users viewing this page.

Important Information

Privacy Notice: We utilize cookies to optimize your browsing experience and analyze website traffic. By consenting, you acknowledge and agree to our Cookie Policy, ensuring your privacy preferences are respected.