Complex Made Simple

How spammers cash in on WannaCry to promote fraudulent services

In Q2 2017, cybercriminals involved in spam distribution tried to capitalise on public fears when the WannaCry ransomware epidemic struck in May.

Knowing that there are lots of people out there infected with the ransomware and are searching for ways to get their encrypted data back, fraudsters sent out spam and phishing emails, offering users different services to fight against the epidemic. This is one of the key findings of Kaspersky Lab’s Spam and phishing in Q2 2017 report.

Massive panic

The WannaCry attack affected more than 200,000 computers across the globe, resulting in massive panic that spammers instantly capitalised on.

Researchers detected a large number of messages offering services such as protection from WannaCry attacks and data recovery, as well as ‘educational workshops’ and courses for users.

In addition, spammers successfully implemented a traditional scheme of fraudulent offers to install software updates on affected computers.

However, links were redirecting users to phishing pages, where the personal data of victims would have been stolen.

Mass mails

One of the main trends in the past three months is the number of mass mailings targeted at corporate networks. Based on Kaspersky Lab research, these have expanded since the beginning of the year.

Spammers began to widely disguise malicious mailings as corporate dialogues, by using the identities of corporate mail services, including real signatures, logos and even banking information.

In archives attached to the email, cybercriminals sent out exploit packages targeted at stealing FTP, email and other passwords. Kaspersky Lab experts highlight that most attacks on the corporate sector have financial goals.

Trojan war

In addition, in the second quarter of the year researchers detected a growth in number of mass mailings with malicious Trojans, sent on behalf of international delivery services.

For example, spammers were sending shipping reports with information about non-existent parcel deliveries.

With the aim of infecting computers or stealing personal credentials, criminals were found spreading download links with malware, including the banking Trojan Emotet, which was first detected back in 2014.

B2B targets

Overall, the volume of malicious mass mailings has increased by 17 per cent, according to the new Kaspersky Lab report.

“During the second quarter of the year, we have seen that the main trends in spam and phishing attacks have continued to grow. The use of WannaCry in mass mailings proves that cybercriminals are very attentive and reactive to international events. Moreover, cybercriminals have started to focus more on the B2B sector, seeing it as lucrative. We expect this tendency will continue to grow and the overall number of corporate attacks and their variety will expand,” said Darya Gudkova, Spam Analyst Expert at Kaspersky Lab.

Other important trends and statistics in Q2, highlighted by Kaspersky Lab researchers, are below:

1. The average amount of spam has increased up to 56.97 per cent. Vietnam became the most popular source of spam, overtaking the US and China. The top ten countries include Russia, Brazil, France, Iran and the Netherlands

2. The Necurs botnet is still active. However, the experts spotted a decrease in the volume of spam sent from this botnet, as well as its instability

3. The country most targeted by malicious mail shots was Germany. The leader of the previous period, China, came second, followed by the UK, Japan and Russia. Other popular targets include Brazil, Italy, Vietnam, France and the US

4. The Kaspersky Lab Anti-Phishing system was triggered 46,557,343 times on the computers of Kaspersky Lab users. The largest percentage of affected users was in Brazil (18.09 per cent). Overall, 8.26 per cent unique users of Kaspersky Lab products worldwide were attacked by phishing

5. As in Q1, the main targets of phishing attacks remained the same and were primarily from the financial sector: banks, payments services and online stores