Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Tech Support Scammers Impersonate Apple Technicians
Malwarebyes ^ | October 20, 2015 | BY JÉRÔME SEGURA

Posted on 10/21/2015 11:34:13 AM PDT by Swordmaker

Remote assistance is becoming more and more popular to troubleshoot computer issues without the hassle of bringing the problematic machine to a store. Indeed, from the comfort of your own home you can let a Certified Technician remotely log into your PC and have them fix the issues you are facing.

Apple offers a screen sharing service part of its support center that puts you in touch with a remote advisor. The process is secure and requires a unique session key to authenticate into the system that the customer needs to enter at the following URL: https://ara.apple.com

apple-legit

In today’s post we will talk about how we discovered that crooks are abusing this feature and fooling Mac users into trusting them.

As we have been documenting it so many times on this blog, there has been an explosion of tech support scams via malvertising and fraudulent affiliates. All systems are targeted, not just Windows PCs and in fact, fraudulent warnings for Mac are getting extremely common.

Safari_alert

 

These pages are designed to scare people into thinking there is something wrong with their computer. Fraudsters will use all sorts of messages, audio warnings and other artifacts in order to social engineer marks into calling for assistance.

Typically scammers will have the victim browse to LogMeIn or TeamViewer and have them download the remote software necessary to take remote control. However, and especially in this case that involves Apple consumers, this step may seem unnatural, not part of the whole “Apple experience”.

For this reason, the crooks registered a website with a domain name that looks like the real Apple one (ara.apple.com) by calling it ara-apple.com. The site was registered through GoDaddy and resides on IP address 184.168.221.63.

whois

This domain is used for everything from linking to the remote programs the ‘technician’ will use:

programs_download

to processing payments (note how the ‘Secure Payment’ page is using regular, unencrypted HTTP)

secure-notsomuch

We have contacted both the registrar (GoDaddy) and hosting provider (Liquid Web) so that they can take appropriate actions in shutting down these fraudulent websites.

This particular case shows that tech support scammers are resorting to more elaborate ways to social engineer their victims. Perhaps Apple users are even more at risk because they may be less experienced at dealing with these kinds of “errors”.

As always, please be particularly suspicious of alarming pop ups or websites that claim your computer may be infected. Remember that Apple would never use such methods to have you call them or would never call you directly either.

For more information about tech support scams and a comprehensive list of known malicious sites and phone numbers, please check out our resource page.



TOPICS: Business/Economy; Computers/Internet
KEYWORDS: apple; applepinglist; applesecurity; internet; scam
Navigation: use the links below to view more comments.
first previous 1-2021-4041 last
To: Grampa Dave
I haven't seen/experienced any phishing attempts via my Android phone or Linux desktop.

Wife has a win 8.1 laptop that is polluted with malware to the point of being basically unusable. I need clean it up. She also has a macbook and just a week or two ago ran into an attack that locked up safari. Ended up having to resort to a command window and the good old "kill -9 ..." command. Then I had to research online how to start up safari and select an alternative page - kept restarting to the malware attack page - "you need to scan ... " yeah, right, scan this...

I've been in the software game for 30+ years and I absolutely hate people that waste their time & energy writing malware, viruses, etc. (in some ways even more than libtards) If I ever meet one of those {expletives} they had better hope there are too many witnesses around...

41 posted on 10/22/2015 9:31:53 AM PDT by ThunderSleeps (Stop obarma now! Stop the hussein - insane agenda!)
[ Post Reply | Private Reply | To 40 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson