[HN Gopher] Phishing sites targeting scammers and thieves
___________________________________________________________________
Phishing sites targeting scammers and thieves
Author : todsacerdoti
Score : 52 points
Date : 2021-08-09 15:32 UTC (7 hours ago)
(HTM) web link (krebsonsecurity.com)
(TXT) w3m dump (krebsonsecurity.com)
| 0xbadcafebee wrote:
| This reminds me of my friends that used to take over botnets and
| turn them on the C&C servers of other botnets. One guy tried to
| pay in bitcoin to get his botnet back. That would have been a
| couple million dollars worth these days... :-/
| unstatusthequo wrote:
| And unfortunately "hacking back" is still hacking according to
| the laws of the U.S. currently. Which might explain why cyber
| crime is way up. No downside for threat actors.
| wmf wrote:
| I think there have been a few exceptions where US authorities
| have authorized "technical action" against botnets and such.
| mrkramer wrote:
| Unauthorized computer access in still unauthorized doesn't
| matter if you hack back and take over a botnet from cyber-
| criminals.
|
| Yea there are exceptions where US authorities together with
| Microsoft sinkhole, takeover and shut down botnets. Why
| Microsoft? Because majority of botnets are botnets of
| compromised Windows computers.
| r00fus wrote:
| So do we need some "privateers" or would that be too
| dangerous?
| Y_Y wrote:
| Just live in Tunisia or Barbados like a real pirate.
| gricardo99 wrote:
| sounds fascinating, and fraught with peril. I'd be worried that
| either I'd make myself a target for these hackers/scammers, or
| law enforcement. Granted most of the hackers/scammers probably
| aren't very skilled, but if you crossed one that really knew
| what they were doing... yikes! I'd also be worried the FBI
| would eventually come knocking. I'm not so sure the FBI would
| distinguish between someone "liberating" a botnet and turning
| it against the original hacker, and the hackers/scammers
| themselves.
| mrkramer wrote:
| These are called honeypots.
| logshipper wrote:
| > DomainTools' record for briansclub[.]com says the domain was
| abandoned or dormant for a period in 2019, only to be scooped up
| again by someone in May 2020 when it became a phishing site
| spoofing the real BriansClub.
|
| Reminded me of the recent AskHN thread on the profitability of
| domain squatting: https://news.ycombinator.com/item?id=28106113
|
| I wonder if we'll see more of such criminal-scamming operations
| after the government sting operation that leveraged a compromised
| app: https://www.washingtonpost.com/world/2021/06/08/fbi-app-
| arre...
| j_walter wrote:
| Good! If people are too stupid to realize a scam like this or pay
| for something illegal then they deserve to get bilked for a few
| hundred bucks.
| burnished wrote:
| I just want to contest the "too stupid to realize a scam" bit,
| in part because of the idea that stupid people are deserving of
| mistreatment (they aren't), but mostly because stupidity has
| very little to do with it. Vulnerability has a lot to do with.
| Most of the time, most people aren't vulnerable to scams. Thats
| the trick though, a successful scam is about finding people who
| are temporarily vulnerable. And everyone is at some point in
| their lives.
| mannerheim wrote:
| I'd agree, but the victims in this case seem to be buying
| stolen credit cards. They fully deserve to get ripped off in
| this case, it's instant karma.
|
| Also the perfect victims - what are they going to do,
| complain to the police that their stolen credit card vendor
| ripped them off?
| lalaland1125 wrote:
| Most scam victims are elderly with cognitive problems.
| Eventually you too will probably be "too stupid to realize a
| scam like this".
|
| Assuming you live long enough of course.
| ectopod wrote:
| This is a scam against people who are actively seeking out
| stolen credit card details. Which doesn't seem like something
| an elderly person would start doing as as a result of
| cognitive decline.
| dylan604 wrote:
| unless its an older credit card scammer trying to offset
| their social security fixed income with something they used
| to do back in the day
___________________________________________________________________
(page generated 2021-08-09 23:01 UTC)