US Secret Service court documents reveal new tactics in antivirus renewal phishing scam

Court document shows phishing tactics are only getting more complex

When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.

Newdocuments submittedby the US Secret Service as part of a recent seizure warrant have revealed an all-new form of phishing scam techniques centered around antivirus renewal.

In this instance, a scammer stole $34,000 after emailing the victim stating that there was an auto-renewal of $349.95 on their account that would be charged unless cancelled.

The victim then called the scammers to do so, and was told to provide remote access to their laptop in order to ensure the refund went through.

Executed Warrant

Executed Warrant

The warrant, submitted by Special Agent Jollif of the United States Secret Service, hopes to return the $34,000 to the victim as the funds are currently suspended in a JP Morgan Chase suspense account due to the detection of a potentially fraudulent transaction.

The scammer, identified as “Bingsong Zhou” in the warrant application, tricked their victim into installing remote access software which Zhou then used to transfer the funds from the victims savings account into their own while disguising their actions under an overlaid bluescreen.

Jollif stated in the document that while tactics like this have existed for several years, they are seeing increasing use. In the document, Jollif states, “Criminals are posing as legitimate representatives of real companies and, through a series of impersonations, are negotiating the transfer of funds via wire transfers from a victim bank account to an account controlled by the criminal.

“Once the criminal receives the fraudulently obtained funds, it is common practice to move the funds rapidly between accounts to prevent law enforcement detection.”

Are you a pro? Subscribe to our newsletter

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

ViaBleepingComputer

More from TechRadar Pro

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division),  then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

HPE reveals critical security bug affecting networking access points

Cybersecurity is business survival and CISOs need to act now

New Secretlab Skins Lite let you overhaul the look of your chair for under $100