E-mail Warning about Scams is a Scam
It never fails to surprise me when the 419ers [the Boys and Girls from Lagos who run the Advance-Fee-Frauds, aka Nigerian scams] try and get a potential mark [victim] to trust that the e-mail, letter or fax is genuine, by either using well known company names, grand sounding personal titles, such as Queen this, Princess that, General other, or trying to pass themselves off as professionals, such as Doctors, Lawyers, government officials, bank staff or ministers of religion. They have also been known to ‘borrow’ names of famous or infamous people.
Occasionally they change tactics, such as trying to make you believe that the deal being offered is not a scam, by stating that it is ‘100 percent legal‘ or stating ‘this is not a scam‘.
The latest twist in their tactics is ‘borrowed’ from the malware authors, in that the scam e-mail itself warns against scams, rather ironic I would say!
Here’s a screenshot of the e-mail:

Probably the best know case of malware using this tactic is Swen [screenshot below] which arrived as an e-mail claiming to come from Microsoft warning you about the holes which it warns could be used by malicious code. The beautifully formated HTML e-mail had the required ‘patch’ attached, which was in fact the malware itself. The e-mail was very believable, so it was not surprise that lots of people ran the attachment and infected their computers.

This latest twist just reinforces that the ‘bad guys and girls’ are learning from each other. Phishers are learning from the 419ers, who are learning from the malware authors, who are learning from spyware authors, who are learning from the phishers…..round and round we go!
Let’s hope some of them get dizzy and fall off into the waiting arms law enforcement, who will sit them down, read them their rights and then let have their day in court.
Hopefully they will get ‘a real sentence’ that will finally send out the right message that cyber-crime does not pay, rather than the more common ’slap-on-the-wrist’ being handed out that we have seen in the vast majority of cases so far.
I know, I can dream…
Please note that this blog has now moved to my own hosted domain here: http://momusings.com/momusings/.
A full RSS/ATOM feed can be found there.
All the data up to the end of December 2006 will be left here, however all postings from the 1st of January 2007 onwards will only be available at this blogs new home.
ALL future postings will only be available at the new site.

