[ad_1]
A new scam on WhatsApp uses the trademark O Boticario and aims to steal the personal data of users. Identified by dfndr lab, the developer of PSafe security applications, the criminal action uses social engineering and simulates a Christmas business promotion in which participants would win products from their product lines. Interested parties should share a message with friends who had to register on the platform.
In this case, the criminals acted in a more sophisticated manner, as the system was able to verify whether the notified PCF belonged to the name seized and thus offered a false sense of credibility. According to PSafe, six different links were found for the same move and together they added 40,000 detections in the last 24 hours. According to the company, malicious actions of the kind would have been behind 43.8 million detections in the third quarter of 2018.
WhatsApp imposes a limit on the message transfer tool
You want to buy cell phones, TVs and other products at a cheap price? Know the Compare TechTudo
"This is a separate scam and the cybercriminal had indeed a lot of work.Check registration and CPF store makes it very similar to a real brand promotion and is therefore extremely difficult for a user without technical knowledge to identify him as fake, "says Emilio Simoni, director of the laboratory dfndr. According to the security company, to perform this verification, it is necessary that the hacker has access to a database containing the information, which may have been disclosed on the Internet or collected during a coup d'etat previous.
In order to make the action even more realistic, the perpetrators still recorded 3,634 authentic stores so that the interested parties could supposedly withdraw the products that they earned. In addition, content shared with friends is personalized and includes the name of the person who sends it. The user can always check whether or not the links have been accessed by the contacts, encouraging them to click and participate in the supposed promotion, and thus communicate their data to cybercriminals.
False message shared in WhatsApp offers gifts of the brand O Boticário – Photo: Reproduction / TechTudo
Only
A fake shared message in WhatsApp offers gifts of the brand O Boticário – Photo: Reproducção / TechTudo
only This year, O Boticario has had its name sometimes involved in crimes of the type. In February, they promised free samples of the Nativa SPA product to anyone who accessed the site and answered three questions. Already in March, they had taken advantage of the International Women's Day campaign to offer a fake make-up kit to anyone who clicked at the address indicated in the message. In June, they offered a kit of products for boyfriends.
"It is essential that people take the security of their data very seriously, use a protection solution on their smartphones and always check if the promotion exists on official channels or on link control sites", explains Simoni.
WhatsApp itself suggests users pay close attention to receiving content labeled "Shared" at the top of the message bubble. "If the message seems suspicious or if its content is too good to be true, do not touch it, share it or pbad it on," the messenger's security team said.
In addition, the platform calls attention to texts containing click requests in any web address transmitting the message or requesting personal information (credit card number, bank account, date of birth, pbadword, etc.). When faced with such content, the user can report the account to WhatsApp without leaving the application. This is important because the social network does not have access to the content of the discussion because of the end-to-end encryption system.
WhatsApp: five tips to use the application safely