Share

FIRSTonline Banner

Web pirates are on the attack. They're even stealing OTP codes using artificial intelligence.

Not even two-factor authentication and smartphone transaction validation protect us. This is the new trap of new e-commerce sites that faithfully replicate the real thing and turn us into unwitting accomplices to the scam. But we can, and must, protect ourselves.

Web pirates are on the attack. They're even stealing OTP codes using artificial intelligence.

All-purpose angel or sneaky demon? double soul Artificial Intelligence is not having a good time. While its pitfalls even make some of its members tremble, authoritative operator Here's yet another proof of the disaster. Are AI's abilities at the service of hackers, or even thieves of our identities on the Web and our money? Exactly. Because Artificial Intelligence is also behind it.criminal organization baptized DoppelCart, which marks a quantum leap in digital scams: it continues to strike us even today despite its techniques having been largely reconstructed and interpreted.

We know how the DoppelCart cyber-battle works, but it survives. It captures us with the classic techniques of Phishing, simulating a multitude of e-commerce sites counterfeit, steals our banking credentials and even manages to bypass more sophisticated security measures, those that should protect individual transactions thanks to the OTP codes that arrive on our smartphone.

And what about the latest automatic attack, just documented with a relationship published on September 8 by Google Threat Intelligence Group, which, again using Artificial Intelligence, stole in less than six hours nearly 24.000 professional credentials that allow IT managers to access their archives and work procedures.

Attacks are increasingly sophisticated, defenses are increasingly difficult, especially for non-professionals. It's worthwhile to better understand the characteristics of at least the first of the two cases we mentioned, the one that is still hitting ordinary users hard. citizen consumersA truly emblematic case of the new operating methods of cybercriminals who rely on artificial intelligence. And it is definitely worth updating your good tips of defense, increasingly indispensable.

The fake e-commerce site turns us into accomplices

They are crooks. We are their unwitting accomplices, as much as it may seem. paradoxicalThe DoppelCart scam works like this, as can be seen from the detailed technical explanation provided by analysts at The SoftwareThe first step is the classic phishing trap: we receive a message offering a huge discount, over 50%, on an item we might be interested in through an e-commerce site. Which site? Maybe a site we're familiar with, or maybe a lesser-known one, or maybe an unknown one but...appearance truly professional. Because, according to analysts at Il Software, there are as many as 119.000 domains created in this way, limiting real online stores.

Different, multifaceted sites, which embrace very different types of products. But with a sole direction, say the experts investigating. And there's a common feature: they're fake, counterfeit, and copy the real thing. They distribute scams by inviting people to click on a link provided directly by the digital scammers.

So far, nothing new compared to the scams we are sadly accustomed to. The novelty lies in two elements. The first is the technique of forgery The site's sophisticated approach: clicks take us directly to the catalogs of the real site, or to a perfect copy, continually updated and duplicated with the help of artificial intelligence algorithms. The criminals, kindly, add a "discount code" that in most cases reaches a whopping 65%.

The temporary double validation pin trick

The extremely dangerous innovation, however, lies in the second element: if we decide to complete the purchase, the scammers do not limit themselves to the already known technique of making us pay a sum through a credit card transaction, without obviously sending us anything. The novelty is deadly trap It happens in parallel: while we're completing our transaction, the criminals have stolen our credit card number and its validation code. The very sensitive one found on the back of the card. And this alone allows me to commit who knows what and how many crimes. But the best (or, rather, the worst) comes now.

Our transaction is usually protected by a code sent to our cell phone. And here's the super trap: we enter the OTP code we just received and complete the transaction. And so we give the corresponding money to the criminals. Meanwhile—here's the new twist—we receive further request Validation with a new "confirmation" code. It's our bank. Why not trust it? We type it in. It should be encrypted, secret, invisible to anyone: the regulations require it. And yet, criminals see it. And use it. Because in the meantime, they're using our credit card's verification code with instant precision to buy something, undoubtedly much more expensive, from a "real" e-commerce site.
Our second type code is used to validate this transaction. The deadly game is done. With a double rip-offThe fake purchase made with them, at our expense. And the real purchase, much more generous, made by them with our money.

Caution and countermeasures. They are now an absolute necessity.

Defending ourselves and preventing it is an imperative obligation at this point. Faithfully following all, without exception, the measures that have gradually entered our lives, perhaps piecemeal. paraphernalia to combat digital traps.
First tip: be wary of any commercial offers that don't come directly from the e-commerce sites you're used to using.

Second tip: never click on a link offered to you. A seemingly innocuous name that faithfully reproduces a well-known and certified e-commerce site could be masking a completely different website, perhaps disguised as the authentic one. Nor should we trust the HTTPS wording preceding the domain name that appears: even free hosting services on the web allow criminals to create, perhaps temporary, sites with fully valid HTTPS security certificates. What should we do? Let's try typing the site name ourselves, without clicking anything.

Third tip: carefully note the usual validation procedure used by your bank for online purchases. Any deviation, any exception to this procedure, has the distinct tang of a trap.

comments