These Aren't the Droids You're Looking For

Depositphotos_92724852_s-2019Researchers at Kaspersky have identified sixty-five malicious files masquerading as online copies of Star Wars: The Rise of Skywalker, TechRepublic reports. The files are spread via phishing sites and social media accounts that pose as official movie pages. In addition to distributing malware, the sites also ask users to enter their credit card data before they can watch the film.

The phishing sites contain detailed descriptions of the movie in order to bump the site higher up in search results. The attackers also spread links on social media sites like Twitter. They intentionally manipulate their SEO so that their phishing sites show up when a user is searching for a free version of a movie or show. For example, searching for “rise of skywalker watch free” will likely turn up a number of malicious results near the top.

Tatiana Sidorina, a security researcher at Kaspersky, said in a statement that attackers frequently take advantage of popular movies and shows to spread malware.

“It is typical for fraudsters and cybercriminals to try to capitalize on popular topics, and Star Wars is a good example of such a theme this month,” Sidorina said. “As attackers manage to push malicious websites and content up in the search results, fans need to remain cautious at all times. We advise users to not fall for such scams and instead enjoy the end of the saga on the big screen.”

Kaspersky recommends that users confirm the legitimacy of sites before visiting them. Trying to watch pirated movies online is always a bad idea, and you’re very likely to get your computer infected with malware. While some of the phishing sites in this case posed as official movie pages, common sense dictates that a legitimate version of a movie like Star Wars isn’t going to be released online for free while it’s still in theaters. New-school security awareness training can help your employees avoid falling for these schemes by teaching them to recognize the hallmarks of social engineering.

TechRepublic has the story:

Don’t get hacked by social media phishing attacks!

Many of your users are active on Facebook, LinkedIn, and Twitter. The bad guys use these platforms to scrape profile information of your users and organization to create targeted spear phishing campaigns in an attempt to hijack accounts, damage your organization's reputation, or gain access to your network.

KnowBe4’s Social Media Phishing Test is a complimentary IT security tool that helps you identify which users in your organization are vulnerable to these types of phishing attacks that could put your users and organization at risk.

SPT-monitorHere's how the Social Media Phishing Test works:

  • Immediately start your test with your choice of three social media phishing templates
  • Choose the corresponding landing page your users see after they click
  • Show users which red flags they missed or send them to a fake login page
  • Get a PDF emailed to you in 24 hours with your percentage of clicks and data entered

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

Subscribe To Our Blog

Ransomware Has Gone Nuclear Webinar

Get the latest about social engineering

Subscribe to CyberheistNews