According to cybersecurity experts at ESET, internet users are increasingly aware of the threats lurking during online shopping. Hackers are also aware of this, so the anatomy of their planned attacks is becoming increasingly sophisticated. What mechanisms might they use during the exceptionally unusual pre-Christmas shopping frenzy of 2020?
This year's pre-Christmas online shopping season promises to be exceptionally intense, partly due to the situation related to the coronavirus. Hackers are also preparing intensively for it – planning attacks that take into account current user behaviour and knowledge levels. To this end, they may use techniques such as typosquatting, homographic attacks, or phishing that touches on security themes.
– Cybercriminals and cybersecurity experts are engaged in a constant game with each other. The work we do, raising awareness among users and educating them about online behaviour, has not gone unnoticed by hackers. They know perfectly well that more and more internet users make sure not to click on unknown links or use public Wi-Fi networks. There is also a lot of talk about not buying from unfamiliar e-shops with unusually attractive prices or via Facebook or OLX with payment in advance. In the mechanisms of some popular attacks, one can therefore notice an attempt to go one step further and predict the behaviour of even more aware internet users. Professional security packages are continuously being developed to detect, among other things, new suspicious sites, fake certificates, etc. – says Kamil Sadkowski, senior threat analyst at ESET.
Hackers' traps, designed with more aware internet users in mind:
Typosquatting: taking over a mistyped URL
– Typosquatting (so-called taking over a mistyped URL) – More and more internet users are aware that some banners or pop-ups may use the names and visual identity of popular shops or sales platforms, luring people to fake addresses. The solution is to type the URL of the chosen site directly into the browser field. Cybercriminals exploit this behaviour, basing their attacks on typical mistakes and typos we might make while doing so. A domain registered by them with a deceptively similar name may look identical to the legitimate one we wanted to reach. Its sole purpose is, for example, to steal payment card data. In the shopping frenzy, therefore, one should carefully verify the correctness of the addresses typed into the address bar.
Homographic attacks: a URL trap
Cyber security during Black Friday and Cyber Monday 2020
– Homographic attacks – Before making a payment on a website, one should of course make sure that the connection is encrypted. The padlock icon on the left side of the browser address bar indicates an encrypted connection to the server using an SSL certificate (https). However, it should not completely lull your vigilance. The certificate may be authentic, but the site may still be fake. Homographic attacks exploit the possibility of placing characters from alphabets other than Latin in URLs. Some alphabets, such as Cyrillic or Greek, contain similar or even identical characters to those we use in the Latin alphabet and URLs. A site whose address contains, for example, the character "ω" instead of "w" can then be registered, legitimised with a certificate, and used to steal data. How to avoid such attacks? Pay attention to warnings in web browsers and antivirus programs – they usually contain tools that detect this type of sophisticated technique.
Phishing exploiting security themes
– Phishing touching on security themes – Phishing attacks are among the most widespread scams. Criminals also raise security-related themes in them. One popular strategy is to send messages impersonating popular online shops, informing recipients, for example, that a problem has occurred and that, for the security of the transaction, it must be repeated. In the next step, the user is asked to provide their personal data, including credit card number and address. Cybercriminals have more and more tools at their disposal to make such a message credible. For example, thanks to the continuous development of online translation tools, even attacks carried out by foreign hackers increasingly rarely contain obvious linguistic errors that used to be a warning sign. Be wary of fake security stories and always verify them at the source.
Summary
ESET experts warn that the upcoming Black Friday and Cyber Monday 2020 shopping season will be particularly intense online, mainly due to the coronavirus pandemic, which is prompting hackers to use more sophisticated attack methods than before. Instead of simple tricks, cybercriminals are increasingly resorting to typosquatting, which exploits typos in URLs, and homographic attacks, based on characters from other alphabets such as Greek or Cyrillic. Specialists emphasise that even the presence of an SSL certificate or padlock icon is no longer a guarantee of security, and criminals are becoming increasingly effective at impersonating shops by raising transaction security themes in fake messages. It is therefore crucial to remain vigilant and verify communications at the source.