ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

World Cup: Fake Tickets, Fake Giveaways, Real Attacks

highMalwareimportance 42

Indicators of compromiseAll →

TypeIndicatorContext
domainfifabr.comorld Cup tickets. Bad guys registered the fraudulent domain fifabr.com that is displayed among the first results as a sponsored li
Full article419 words · extracted from securelist.com · click to collapse

Spam and phishing

Spam and phishing

31 Jan 2014

minute read

The storm of phishing and malware attacks using the theme of the World Cup continues – some months ago we registered several malicious campaigns with this theme. To diversify the attacks and attract more victims, Brazilian cybercriminals decided to invest their efforts to spread fake giveaways and fraudulent websites selling tickets for the games at very low prices, tickets that in fact do not exist.

The attacks start when a user does a simple search on Google, looking for websites selling World Cup tickets. Bad guys registered the fraudulent domain fifabr.com that is displayed among the first results as a sponsored link:

The fraudulent website offers tickets for Brazil’s games at the price $ 70,00:

Kaspersky products are blocking several fraudulent domains daily; all of them are using the theme of the World Cup. Such attacks are focused totally on Brazilian users and the messages generally use the names of local credit card, banks, and big stores, etc.

Phishing messages with fraudulent giveaways are getting common as well – some offering free tickets, cash, or even free travel:

“Congratulations, you’re the winner of a free ticket to the World Cup”

To obtain the free ticket it is necessary to put all your personal data and your credit card number on the fraudulent website:

Neymar and Fuleco are waiting for your credit card data

Some bad guys have also created a fake giveaway that is valid even after the Games:

“We’re giving prizes After the World Cup” just another phishing domain

Up until the beginning of the games many other attacks may appear – but we’re prepared to block them. Do not risk trying to buy tickets for the games at unknown sites – it is safer to buy them on the FIFA website, the online sales will restart on the 12 March 2014.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/world-cup-fake-tickets-fake-giveaways-real-attacks/58233/