Live data from Hacker News

How are cyber criminals rolling in 2025?

vin01.github.io

81–90 of 97 posts

Re: How are cyber criminals rolling in 2025?

#81

Earlier quoted context omitted.

The misspellings/shitty grammar are on purpose.

I have heard that theory from some cybersecurity experts online but have never seen it substantiated in any way (by interviewing some scammers, for example) and frankly don't believe it. The misspellings and grammatical errors (used to?) continue on the fake sites that are created to steal credentials, and the excuses for most of the reasoning regarding emails do not hold there.

Why wouldn't you believe it? It makes economic sense. The most expensive part for a scammer in any automated scam is the part which can't be automated, where a human has to get involved for e.g. a phonecall.

Economically, the scammer wants to do everything they can to get rid of smart or diligent people who might be harder to scam at the expensive part. It feels like it would cost scammers to not have typos.

Also, anecdotal, but the rise of autocorrect, spell checking and LLMs doesn't seem to have made any impact on the quality of spelling in my spam folder over the past 20 years.

Re: How are cyber criminals rolling in 2025?

#82
post #55
post #9

I've noticed on some scam forums and subreddits I frequent that scammers have been using target site's own support searches to redirect users to scam phone numbers. On both Ticketmaster and Facebook, and many other sites, when you perform a search on their support site it spits back your query in big letters at the top of the page. If you craft the correct search and then buy Google Ads pretending to be Ticketmaster,…

FWIW I sent this to a friend on the dev team at Ticketmaster and they escalated it.

Terry Davis would never have let this slide

Re: How are cyber criminals rolling in 2025?

#83

> Norton, Kaspersky, Zscaler, F-secure, NordVPN, Virustotal, Palo Alto: all of them marked these links as safe. This is sad to see, these tools are forced down so many companies in name of "compliance" while totally not worth the maintenance and cost overhead. Apparently they haven't got any better in the last decade.

I work for a cybersecurity company, and I think that the method they used to check these links with the mentioned security companies was not a reflection of how they detect. I'm sure that many of these companies do not have these domains in their DBs of bad sites but if you were to run these products and then visit the site then heuristic detection would have likely flagged the sites.

I would have expected at least Virustotal to flag them if that were the case. It does more than just looking up in a database of known malicious URLs and I think the reputation of the domains is the key factor here.

https://www.virustotal.com/gui/url/6dd23e90ee436e1ff066725aa...

> BitDefender - government

> Sophos - government

> Forcepoint ThreatSeeker - government

- https://docs.virustotal.com/docs/how-it-works

Re: How are cyber criminals rolling in 2025?

#84
post #54

Earlier quoted context omitted.

Because most of the ads are created by external ad agencies, and the people involved are not competent enough to do any verification. Source: I've also thought this was ridiculous and asked someone working on the adsense team. Apparently tried enforcing some domain verification mechanism in an experiment, but most companies and agencies struggled to get the verification done and of course the $ metrics on this launch…

Maybe a partial solution here would be to offer some kind of "domain locking" option? Allow sites that are heavy targets of this kind of scam - like ticketmaster - to add a "AdSense: locked" line to their robots.txt (or similar) - if that line is present then advertisers have to go through an additional domain verification step in order to place an ad.

[deleted]

Re: How are cyber criminals rolling in 2025?

#85
post #76

Earlier quoted context omitted.

> The entirety of redit.com seems to be just a broken honeypot to get you to use the app instead. I just can’t fathom how a company can be that broken. It's their intention to have the website be a funnel so that they can get more mobile users. I sometimes use https://old.reddit.com , though it doesn't look that great on mobile, maybe there are some other alternatives.

I still don't understand why mobile users are so much more valuable to them, is it just the inability to block ads?

Your phone has sensors and superior data they can track/sell

Re: How are cyber criminals rolling in 2025?

#86

Among the common vulnerabilities listed: > Outdated Wordpress plugins and CMS systems No surprise, having worked in edu the following scenario was very common: 1) Researcher gets a grant for a project 2) Grad student sets up a Drupal site for the project 3) Things are maintained and updated for a couple of years 4) Grant runs out, project wraps up, student graduates, everyone forgets about the server which sits unatt…

At my old university ~15 years ago, all IPs of all computers were public IPV4 addresses . Any computer plugged in to any ethernet port on campus was given such a "quasi-static" IP address. All normal ports were open - ssh, http(s), you name it. It was the OG zero trust architecture.

MIT and their /8?

Re: How are cyber criminals rolling in 2025?

#87

Earlier quoted context omitted.

So, I craft a search where the search query is “call 1 800 scam”, then I buy a google ad with key word of “ticketmaster help”, the ad links to real ticketmaster with my query, and google shows that ad to someone having trouble and hey presto they call my scam line at 4 quid a minute from their mobile? Yuck all round. I mean ticketmaster is just a sin eater for greedy popstars but yuck ..

> Yuck all round. Yes, but also it's an impressive digital Jedi mind trick on a website. signs a question mark with hand "This is the support number you're looking for." And the victim is extra primed here because so many companies make it nearly impossible to talk to a human. Yikes! Almost seems like there's room here for a grey hat to come in and use this trick to do a good faith job trying to help the customer thr…

> Then tell them at the end that a recent anti-trust suit requires them to...

Bonus points if you point to the actual anti-trust suit!

https://www.justice.gov/archives/opa/pr/justice-department-s...

Re: How are cyber criminals rolling in 2025?

#88
post #33

Earlier quoted context omitted.

Exactly. And when you try and help these people and explain that you didn't actually call Ticketmaster support they will tell you that they found the phone number on the official Ticketmaster website and Google said it was a verified link. Here's a real example from the same thing happening on FB (don't call that number) https://i.redd.it/w9htjqflgjle1.jpeg

Completely unrelated tangent: Jesus Christ Reddit is such a cesspit. Tried tapping that link on mobile, got a screen to view the corresponding post. Tapped it, and I got taken to the App Store. No thanks, force quit the App Store and go back. Now I get a full screen notice on the original Reddit tab saying “didn’t go where you expected? Next time try the long press!” With instructions to not use private browsing and…

Using Reddit on the laptop seems ok if you set it to the old version.

All websites seem to freak out over you not getting their damn app if you visit on a phone. I just don't use the phone for browsing if I can help it.

Re: How are cyber criminals rolling in 2025?

#89

I am surprised no one mentioned using LLMs to spell and grammar check their emails and vibe-code bank landing-pages to continue a more polished version of scamming elderly people out of their life savings.

The misspellings/shitty grammar are on purpose.

I think the time for that has passed. The trend of the last few years has been scarily realistic phishing emails.

Re: How are cyber criminals rolling in 2025?

#90
post #54

Earlier quoted context omitted.

Maybe a partial solution here would be to offer some kind of "domain locking" option? Allow sites that are heavy targets of this kind of scam - like ticketmaster - to add a "AdSense: locked" line to their robots.txt (or similar) - if that line is present then advertisers have to go through an additional domain verification step in order to place an ad.

I like this idea. I would love to hear from Google why they would not do this. Anyone know why Google / Facebook et al would not want to do this?

Money
Post reply on HN