CyberCrime & Doing Time: What the Bad Guys Know: We’ll Click on ANYTHING!

Posted in Online Business,Security by ebs4pos on February 27, 2010

For years the bad guys have been working to perfect the perfect social engineering schemes. By “social engineering” we are talking about the fact that in most situations the biggest security risk present at a computer has nothing to do with technology and everything to do with the human at the keyboard. The bad guys have made a science out of sending various malicious links and malware attachments to people and determining what message is required to make the human at the keyboard do what they want them to do.

What message is required to make you open an attachment to your email? A few that bad guys have discovered work reliably are to tell you that its information about an undelivered package (such as the UPS, DHL, USPS, FedEx scams we’ve seen), or a message that says your email is going to be deleted unless you confirm you still want it. For years an obvious one has been to pray on male insecurity about their sexual prowess, promising that clicking their link will lead to a larger penis which will make the women you know beg you for sex every night!

But recently the bad guys have figured out that it really doesn’t matter what they type in the email, if they only need a few people to buy their product or follow their link. The current round of Zeus spam doesn’t have a meaningful subject, and doesn’t contain any text at all! Only a link.

And people are clicking on it like mad to infect themselves! What mystery! I think I’ll click and see what it is!

The top email subjects right now are:

