Phishing scam takes $950k from DoorDash drivers

0
[ad_1]

We take a look at a phishing scam that cost 700 DoorDash drivers a combined total of roughly $950k.

A particularly nasty slice of phishing, scamming, and social engineering is responsible for DoorDash drivers losing a group total of around $950k.

DoorDash drivers are contractors who pick up food deliveries from stores and restaurants and deliver the products to the customer. A 21 year old man named David Smith, from Connecticut, allegedly figured out a way to extract large quantities of cash from drivers with a scam stretching back to 2020. Incredibly, this means it all began when he was 18. There’s picking up a new hobby, and then there’s this.

The theft would begin by placing a bogus DoorDash order, receiving the driver details, and then contacting said driver by text and / or phone claiming to be DoorDash support. From here, the driver would be convinced to hand over banking details or log in to a fake portal. The end result would be a loss of funds, and potentially not being able to do their job.

Considering that this took place during the pandemic, targeting drivers may have had a significant impact on vulnerable people whose only way to get food was via services like DoorDash. As with so many scams of this nature, the impact ripples out from the initial victim and never quite stops where you expect it to.

A typical example of how the scam would play out is highlighted in the Stamford Advocate. One driver on her way to a supermarket received a text which advised her not to complete her current order. A call followed, with the individual claiming to be from DoorDash support. He claimed a scam was being perpetuated by drivers, and he needed to make sure that she wasn’t involved.

He sent her a link to verify her identity, and then said she wouldn’t be able to access her earnings / account for roughly four days. Thankfully a reference to a fictitious DoorDash promo tipped her off that something wasn’t right, and she altered her login credentials just in time. Others were not so lucky, with one driver named in the Stamford article losing close to $5,000. A third lost somewhere in the region of $2,000 after being tricked by three scams in a row.

1,750 transactions in total ensured a steady stream of ill-gotten gains for the individual allegedly at the heart of the scheme. Variations on this scam included calls from “DoorDash security” which eventually resulted in banking details being handed over. In some cases, victims may never be identified due to the way some of the reports of theft have been stored in DoorDash’s systems.

It seems the only reason law enforcement has a name for this case at all is by sheer chance, after stumbling upon $700,000+ inside lockboxes while investigating an unrelated incident. At this point in time, it’s not clear that all of the 700 drivers will get their lost funds back.

The Stamford Advocate notes that Smith faces charges of “first-degree larceny, third-degree identity theft, two counts of second-degree forgery, trafficking in personal identifying information and first-degree computer crime”.

The court appearance is scheduled for July 6.

DoorDash mentions that drivers are trained to look out for scams and attacks, but this one managed to sneak in under the radar. While most people wouldn’t dream of targeting gig economy workers during a pandemic, unfortunately some people aren’t most people. All it took here was one individual with a game plan to cheat 700 folks out of close to a million dollars.

How to avoid phishing

  • Block known bad websites. Malwarebytes DNS filtering blocks malicious websites used for phishing attacks, as well as websites used to spread or control malware.
  • Don’t take things at face value. Phishing attacks often seem to come from brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Take action. If you receive a phishing attempt act work, report it to your IT or security team. If you fall for a phish, make your data useless: If you entered a password, change it, if you entered credit card details, change the card.
  • Use a password manager. Password managers can create, remember, and fill in passwords for you. They protect you against phishing because they won’t enter your credentials into a fake site.
  • use a FIDO 2FA device. Some forms of two-factor authentication (2FA) can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.

Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Best accessories for the Samsung Galaxy S23 Plus

0
[ad_1]

The Galaxy S23 Plus is the forgotten-middle child of the Galaxy S23 series, as was the case with the S22 series last year. But it is still a really good option for those that want a larger phone, with better battery life, but don’t necessarily need a S Pen or a larger display like what the Ultra provides. So those that did buy the Galaxy S23 Plus, you’re going to want to check out this buyers guide. This has every accessory that you might want to pick up for your new Galaxy S23 Plus.

Best Samsung Galaxy S23 Plus accessories

In this list, you’ll find things like smartwatches, chargers, cables, and so much more. What you won’t find here are cases. We already have a nice roundup of the very best cases for the Galaxy S23 Plus, which you can check out here.

Cost Where to buy
Samsung 45W USB-C Fast Charging Wall Charger $49 Samsung.com
Samsung Galaxy Buds 2 Pro $199 Amazon
PopSockets $15 Amazon
RAVPower Portable Charger 20000mAh PD 3.0 Power Bank $40 Amazon
Samsung USB-C Cable $7 Amazon
Samsung Galaxy Watch 5 $279 Amazon
Fitbit Versa 4 $229 Amazon
Anker PowerPort Atom PD 1 $28 Amazon
Spigen Kuel S40 Car Mount $18 Amazon
Samsung 15W Wireless Charger Duo $89 Amazon

Samsung 45W USB-C Fast Charging Wall Charger

EP TA845 001 Front Black USMod

If you purchased the new Galaxy S23 Plus, then this 45W wall charger is a must-buy. Even though the S23 Plus only supports up to 25W charging, this is going to future-proof you for a bit, as future phones will work with 45W or faster. Allowing you to fully charge it in about 40 minutes. Which is really useful.

Samsung 45W USB-C Fast Charging Wall Charger – Samsung.com

Samsung Galaxy Buds 2 Pro

71Ifk3YmN1L AC SL1500

The Galaxy Buds 2 Pro are the latest pair of earbuds from Samsung. These were announced last year, and were highly acclaimed. They offer better noise cancellation and better battery life, compared to the previous “Pro” model. Samsung has also included Hi-Fi sound here, so you’re going to get some really good audio quality on these, which is always nice to see.

Samsung Galaxy Buds Pro – Amazon

PopSockets: PopGrip

galaxy s21 accessories
PopSockets: PopGrip

The PopGrip from PopSockets is a really good accessory for really any phone. And the reason why this is the best PopSocket you can buy right now is because it does allow you to swap out the top. So if you want to change the color, you can do so.

PopGrip is really great because it allows you to hold onto your phone much easier, especially for larger phones, but even works great on smaller ones like the Galaxy S23 Plus. But it also doubles as a sort of kickstand for your smartphone. Allowing you to use it on long flights to watch a movie or two, without having to hold your phone the whole time. It’s a really genius invention, and it’s something that everyone should have.

You can attach the PopGrip to your case, so that it doesn’t ruin your phone too.

PopSockets: PopGrip – Amazon

Samsung USB-C Cable

41k2lMhzoqL AC SL1500 1

This is the same USB-C cable that Samsung includes in the box of the Galaxy S23 Plus. So there’s nothing special here, it’s just an additional USB-C cable that you can pick up and have in the car, at work, or even elsewhere in your home. It’s always good to have a second USB-C cable somewhere around, for when you need to charge your phone.

Samsung USB-C Cable – Amazon

Samsung Galaxy Watch 5

61X2Pl7752L AC SL1500

The Galaxy Watch 5 is the latest smartwatch from Samsung, and many might say its the best non-Apple smartwatch on the market. It’s definitely a stunning looking watch, and it starts at only $279. It does run on Google’s Wear OS, so you’re getting all of your usual apps that you know and love here. That also includes Google Assistant, Google Wallet and so much more.

Samsung Galaxy Watch 5 – Amazon

Fitbit Versa 4

61CZSoSnVPL AC SL1500

The Fitbit Versa 4 is a great fitness tracker to go along with other accessories for your Galaxy S23 Plus. Especially if you’re looking to get in shape this year.

The Versa 4 is the latest in the Versa line for Fitbit. It offers up all of the fitness tracking that you’d expect from Fitbit. Including the ability to track your steps, your workouts, calories burned and much more. It can also deliver some notifications to your wrist.

Fitbit Versa 4 – Amazon

Anker PowerPort Atom PD 1

614SyJ alnL AC SL1500
Anker PowerPort Atom PD 1

The Anker PowerPort Atom PD 1 is the perfect USB-C PD charger to use with the Galaxy S23 Plus. While it does still come with one in the box, it never hurts to have a spare somewhere in your home or at work.

This is a 30W charger – and yes, the Galaxy S23 Plus tops out at 25W but this will work on other devices too. It also uses Gallium Nitride or GaN, which makes this charger a lot smaller than you’re probably used too. Which is why we think it is the best option. Since you can easily toss this into your bag when you’re traveling – if we are ever able to do that again.

Anker PowerPort Atom PD 1 – Amazon

Spigen Kuel S40 Stealth Car Mount

pixel 5 accessories
Spigen Kuel S40 Stealth Car Mount

This is one of the most interesting looking car mounts out there, and it really doesn’t even look like a car mount.

The Spigen Kuel S40 stealth Car Mount is a minimalist car mount for those that don’t want to use magnets. This is a car mount that folds down when it is not in use. Just open it up and stick your phone in the mount, in landscape mode and you are good to go. It’s a good option, because it is fairly small when it is not in use, so that it is not blocking your view of the road all that much.

Spigen offers the Kuel S40 Stealth car mount in only one color. Which is black and blue, so it can blend in with your car a bit more.

Spigen Kuel S40-2 Turbulence Car Mount – Amazon

Samsung 15W Wireless Charger Duo

31C9DZk6siL AC SL1200

This is the new Wireless Charger Duo from Samsung, still capping out at 15W. And that is because Samsung’s phones only do up to 15W. This charger does come in both black and white, so you can choose the one that best fits in your home or office.

With this being a duo charger, you’re able to charge your Galaxy S23 Plus, as well as your smartwatch, or maybe your headphones too. Unfortunately, you can only charge one phone at a time here, as the other, secondary charger is slower. And meant for headphones or a smartwatch.

Samsung 15W Wireless Charger Duo – Amazon


[ad_2]
Source link

Apple bans ChatGPT for internal use

0
[ad_1]

Apple just joined the long list of companies that banned ChatGPT from being used internally. Prior to this, some other companies also prohibited employees from using ChatGPT over the leak of confidential materials.

As an AI-driven chatbot, ChatGPT uses natural language processing to generate responses to user queries. It was developed by OpenAI and has been widely used by companies for various purposes, including customer service and internal communication.

The chatbot may learn from the data it gets since it employs machine learning algorithms to respond. This might enable the chatbot to gain access to private information about Apple’s trade secrets. The company is known to be highly secretive about its operations. Any data breach could put Apple’s business and reputation at considerable risk.

Apple employees can no longer use ChatGPT internally

According to an internal document that The Wall Street Journal reviewed, the tech giant notified its employees about the ban and asked them not to share confidential data with the ChatGPT. GitHub’s automated coding tool, Copilot, is another tool hit with the Apple ban.

The news comes after Google also warned its employees about using AI chatbots and sharing data with them. Google even asks employees to be cautious when sharing data with the company’s AI chatbot Bard. In another instance, it was reported in early April that ChatGPT had leaked Samsung semiconductor information. All in all, Apple’s concerns seem justified.

The quality of the responses produced by ChatGPT may further justify the ban. The chatbot can produce accurate and pertinent responses, but there is always a chance that it can give inaccurate or misleading information. This could harm Apple’s business operations and confuse employees.

Apple’s plans for AI and chatbots remained vague. The sources constantly say Apple is working on a rival for ChatGPT while the company has not yet shown any clue. With OpenAI’s decision to launch the ChatGPT iOS app, Apple could face a serious setback in the future.


[ad_2]
Source link

Android spyware found hiding out in Play Store; delete these two apps now!

0
[ad_1]
A pair of malicious apps were discovered in the Google Play Store recently by cybersecurity firm Cyfirma. The latter said that the apps were used by state-sponsored threat actors to collect location data and contact lists from targeted devices. Cyfirma, with medium confidence, says that the attack comes from a hacking group in India called “DoNot.” The attacks have been spotted in Pakistan.
The two apps in the Play Store are nSure Chat and iKHfaa VPN. The latter copied code from a legitimate app called Liberty VPN (virtual private network used by those browsing the internet to avoid being tracked) and added additional code to access and collect the contacts list and discover the location of the target. The app also continued tracking the location of the target in real-time.

While most VPNs do not ask for permission to use location and contacts, iKHfaa VPN does. This made Cyfirma suspicious enough to dig deeper to find that “DoNot” was the attacker behind the malware. When installing the VPN app, it would also show a pop-up asking users to “turn on device location, which uses Google’s location service. If the GPS on the targeted person’s phone is on and active, the malicious app will be able to figure out the current location of the target. If not, the previous location will appear.

The two aforementioned apps, and a third one from the same developer (which does not appear to be malicious), remain in the Google Play Store. If you have either one installed on your phone no matter where you live, make sure to uninstall them as soon as possible. The name of the developer is SecurITY Industry and the number of downloads for the malicious apps is low which means that they are aimed at specific targets even though they appear in Google’s app storefront.

Remember, one of the best ways to prevent yourself from installing a malicious app on your phone to read the comments section. Look for red flags such as complaints from those who installed the app about their phones running too hot, running too slow, and suffering from rapid battery depletion. These are some of the signs that should make you run away from an app instead of installing it.


[ad_2]
Source link

GravityRAT Android Malware Variant Steals WhatsApp Backups

0
[ad_1]

Heads up, Android users! The latest GravityRAT malware variant now targets Android devices and steals WhatsApp chat backups. The malware reaches the devices by posing as a chat app. Again, this highlights the essentiality of downloading only known apps from trusted sources.

GravityRAT Android Malware Steals WhatsApp Backups

According to a recent report from ESET, a new GravityRAT malware variant has been actively targeting Android devices.

GravityRAT is a spyware known since 2015 as a potent remote access trojan targeting Windows, macOS, and Android systems. It has run numerous malicious campaigns with different iterations, each bearing more advanced malicious capabilities.

The recent GravityRAT variant targets Android devices and steals various files, including WhatsApp backups. To achieve this goal, the threat actors rolled out “BingeChat,” – a supposed chat app. The app offers numerous attractive features, including end-to-end encryption, voice chats, file sharing, an easy user interface, and free availability to lure users.

To further instigate curiosity and add a sense of legitimacy to the app, the threat actors have restricted the app download to an “invite-only” mode with registration requirements. This seemingly prevents the app analysis from potential researchers and ensures a targeted victim base.

Apparently, the app functions usually because the threat actors have developed it on the open-source Android messenger OMEMO IM. That’s how it avoids alarming users about the embedded GravityRAT malware in this trojanized app.

After being downloaded and installed, the app requests risky permissions, which any legit messaging app would request. These include access to SMS messages, contact lists, call logs, location, and device details. Once obtained, the app transmits all this information to the attackers’ C&C.

Alongside these capabilities, the new GravityRAT malware hidden inside the BingeChat app also receives commands regarding file deletion, call log deletion, and contact list deletion. Moreover, it steals files with various extensions, including crypt14, crypt12, crypt13, and crypt18 extensions that often represent WhatsApp chat encrypted backups.

SpaceCobra Identified As Possible Attacker

The researchers have shared a detailed technical analysis of this malware and the BingeChat campaign in their report.

For now, the exact identity of the threat actors behind this malware remains unknown. But ESET names the “SpaceCobra” group as the one behind GravityRAT.

While the recent campaign seemingly continues, it remains unclear how the attackers manage to reach their potential target users. That’s because the app doesn’t exist on the Google Play Store, which suggests that the attackers may be approaching their potential victims through other means, luring them into downloading the app from their domain.

Yet, the one thing that always saves users from such threats is to avoid downloading apps and clicking on links from unknown and untrusted sources.

Let us know your thoughts in the comments.


[ad_2]
Source link

US dangles $10 million reward for information about Cl0p ransomware gang

0
[ad_1]

Rewards for Justice (RFJ) is offering a reward of up to $10 million for information the Cl0p ransomware gang is acting at the direction or under the control of a foreign government.

The US Department of State’s national security rewards program, Rewards for Justice (RFJ), is offering a reward of up to $10 million for information linking the Cl0p ransomware gang, or any other malicious cyber actors targeting US critical infrastructure, to a foreign government.

This is not really new. RFJ’s statutory authorities offers rewards for information in four broad categories and one of them is:

Malicious Cyber Activity For information that identifies or locates any individual who, while acting at the direction or under the control of a foreign government, aids or abets a violation of the Computer Fraud and Abuse Act  (“CFAA”), 18 U.S.C. § 1030. This includes foreign election interference.

But the Tweet explicitly mentioning Cl0p is new. The gang is thought to be behind a recent ransomware spree that compromised a large number of organizations by exploiting a zero-day flaw in Progress’ MOVEit Transfer software.

With as many as 2,500 targets exposed on the Internet, the number of potential victims could be in the hundreds. Some of them have already confirmed, either by the firms themselves or by  being mentioned on the Cl0p leak site.

Campaigns like Cl0p’s abuse of the MOVEit vulnerability, or high profile attacks like the one on Colonial Pipeline in 2021, can trigger an extra focus on the specific ransomware group responsible. Perhaps aware of this, Cl0p took to its website to preemptively promise that it was not going to use data stolen from government organizations and would delete it instead.

It seems that was not enough to avoid getting in the cross-hairs of the US federal government, as we predicted just hours before. The tweet appeared shortly after our own Cybersecurity Evangelist, Mark Stockley, expressed his doubts that Cl0p’s plan would help them avoid unwanted attention from law enforcement.

“Cl0p’s approach supposes that the US government would react more strongly to sensitive data being leaked than it would to multiple simultaneous breaches by the same criminal organisation. This ignores the fact that by using zero-days to attack hundreds of targets simultaneously, including parts of the federal government, Cl0p has already made itself ransomware’s squeakiest wheel.”

And don’t think that all these ransomware operators sit safely out of reach, behind what used to be an iron curtain. The recent arrest of Ruslan Magomedovich Astamirov, a ransomware actor associated with LockBit, in Arizona, shows that the cybercriminals think they can hide anywhere if they are careful enough.

US Attorney Philip R. Sellinger for the District of New Jersey said:

“Astamirov is the third defendant charged by this office in the LockBit global ransomware campaign, and the second defendant to be apprehended. The LockBit conspirators and any other ransomware perpetrators cannot hide behind imagined online anonymity. We will continue to work tirelessly with all our law enforcement partners to identify ransomware perpetrators and bring them to justice.”

Also, some criminals can’t help themselves and need to show off how rich they are or how clever they think they are. The best example may be Mark Sokolovsky. This Ukrainian national and alleged cybercriminal loved posting selfies with fistfuls of cash. When the Russian invasion of Ukraine caused him to flee the country, his girlfriend posted pictures of the couple’s journey on her Instagram account. Sokolovsky was arrested in the Netherlands and is awaiting extradition to the US, accused of being a key player in the cybercrime operation behind Raccoon Stealer.

So, if you’re in the market for a $10 million reward, happy hunting. And for anyone eligible, I’m throwing in a free copy of Malwarebytes Premium. You’ll need it.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

The Google Home redesign has disappeared for some users

0
[ad_1]

Not too long ago, Google pushed a new design to Google Home, and it made for a better user experience. However, some people are opening the app to see that the Google Home redesign has suddenly disappeared.

Google was testing this new UI with users via an early access program, and it just hit the public this May. So far, it’s been going well. The new design gives the app a look more consistent with the modern Google app look. This means that it employs the Material You design language. However, if you haven’t updated your app to the new design, then you might want to wait until the next update hits the app.

The Google Home redesign is disappearing for some users

This issue is affecting users across both Android and iOS. People are starting up the app to find that it had reverted back to the old design. This is a weird thing to happen, but so are all software bugs.

We’re not sure what the reason behind this is, but there are some common threads. For starters, this issue seems to be tied to the latest version of the app to land. Version 3.2 was just released last week, so the issue might be within the latest update. If you haven’t updated, you might want to skip this version.

For some reason, this issue might be tied to the data that the app saves on your device. According to 9To5Google, if you go into the app’s settings and clear the storage, it will go back to the new UI. However, it will eventually revert back to the older version after some time.

There may be an actual solution

One common thread we’re seeing among the reports is that most of the people experiencing this problem signed up for the early access program. This is the beta program that allows people to try out new features early.

Leaving the program seems to solve the problem absolutely. We’re not seeing reports of the app reverting back after leaving it. If you’re enrolled in the program, and you’re experiencing this issue, try leaving it. After you leave it, you might want to uninstall and reinstall the app. If you’re still having the issue, then you might want to wait for the next update.


[ad_2]
Source link

Apple could be working on an AR/VR headset for iPhones

0
[ad_1]

Apple could be working on an AR or VR headset for the iPhone. The company just secured a patent for a Head Mounted Display device that you can slot iPhones into. According to a new report from ZDNet.

The patent, which Apple was awarded this week, describes how users could take their iPhone or iPad and place it in the head-mounted display to be worn like a VR headset. The accessory would have an adjustable strap for fastening the device to the wearer’s head. It’s also state that the patent describes the user’s iPhone or iPad should be able to detect that it’s being placed in the accessory to create a wireless connection.

This sort of design is an all-too common one these days as both Samsung and Google have been down this road. Samsung’s Gear VR series of devices and Google’s Daydream View worked in much the same way. You slot your phone into the headset and its screen acts as the display for the VR and AR experiences. Google also experimented with Google Cardboard before the Daydream headsets were released.

An iPhone-powered VR headset from Apple could be a lot cheaper

Phone-powered VR headsets weren’t exactly the most exciting. At least compared to what we have now. But there’s no denying they helped pave the way for today’s VR hardware. Even if only in small ways.

Gear VR and Google Daydream View walked so Apple’s potentially upcoming phone-powered VR headset could run so to speak. If it ever gets made. Securing the patent doesn’t necessarily mean Apple will use it. Or that a headset would make it to a production phase.

But another reason why phone-powered VR headsets might have their place is because they tend to be much less expensive than current options. Maybe not by leaps and bounds now with Quest 2 back down to $299. But for those in the Apple ecosystem, a VR headset powered by your iPhone would be a lot less than Apple’s recently announced Vision Pro. Which sits at a whopping $3,499.


[ad_2]
Source link

YouTube’s New 1080p Premium option starts showing up for Android and Google TV users

0
[ad_1]
YouTube is testing a new 1080p Premium tier with a enhanced bitrate for Android and Google TV users. This is a feature that is exclusive to YouTube Premium members and delivers videos in extra crisp quality.
The new tier was first spotted earlier this year when the option showed up for several users. It turned out that the feature was being tested for selected iOS users, which is the operating system that Google chose as a playground for this and several other features.
At the time, this sparked rumors that YouTube had plans to lock 1080p playback to its premium subscribers. It turns out, as confirmed by Google, that this feature is simply a perk that is being offered for premium subscribers.

The 1080p Premium tier offers a higher bitrate than the standard 1080p option, which means that videos will play with a higher quality and less buffering. This is especially beneficial for users with high-speed internet connections and large TVs.

Now, it appears that the feature is finally moving on from iOS and propagating to Android and Google TV devices, as reported by 9to5Google based on posts on Reddit and Twitter. However, it also looks like this is only live for a few select users at the moment.
It is clear that this feature is another way in which Google can promote subscriptions to YouTube Premium. That service in particular underwent a significant increase last year on the price of its family plan, which I can only imagine prompted some cancellations.


The introduction of the 1080p Premium tier, and the fact that it is now being expanded beyond iOS, is a sign that YouTube is committed to providing its users with the best possible viewing experience. It remains to be seen whether the new tier will be successful, but it is a welcome addition to the YouTube lineup.


[ad_2]
Source link

This Side-Channel Attack Exploits SMS Delivery Reports To Retrieve Location

0
[ad_1]

SMS delivery reports not only let the sender know about the message receipt, but can also leak the recipient’s location. This is what researchers have demonstrated in their recent study, showing how receiving a silent SMS message triggers a side-channel attack, letting the sender deduce the recipient’s location via message timings.

Retrieving Location Data Via SMS Delivery Reports

Researchers from different universities teamed up to devise a novel side-channel attack, exposing users’ location via SMS.

According to the details shared in their research paper, the attack method involves exploiting the SMS delivery reports. Using the stats obtained from these message timings, a sender can determine the recipient’s location across different countries with up to 96% accuracy.

About the attack

This attack primarily involves exploiting the GSMA network’s underlying weaknesses that drive the SMS message technology. Since it typically affects GSMA, this side-channel attack impacts almost all cellular networks across the globe.

SMS enticed the researchers for this study, given its popularity among the masses as a 2G communication method, despite the presence of 3G and 4G communication alternatives. The researchers observed that the inevitable SMS Delivery Reports generated upon receiving an SMS message trigger a timing-attack vector.

If a sender has enabled SMS Delivery Reports, knowing the timings of message delivery and calculating the time lapse during message sending and receiving can help the sender determine the recipient’s location. Since SMS Delivery Reports feature works beyond the recipient’s control, the recipient user cannot prevent the malicious use of this feature.

The technique basically leverages the timing signatures for a certain location. An adversary can collect various timing signatures by sending SMS messages to the target user at different timings and locations. Analyzing them later can let the sender deduce the receiver’s location.

Conducting this attack merely requires the adversary to know the target user’s mobile phone number. While tedious, a careful collection and analysis of these timing signatures can even empower the adversary to determine a previously unknown or new location of the target user. This works regardless of whether the user is in a domestic location or overseas. The time lapse between SMS sending and delivery can help here.

Attack Limitations And Countermeasures

While the researchers achieved much accuracy while performing this side-channel attack, it still has some limitations. That’s because numerous factors may impact the empirical measurements in a real-world exploit. Nonetheless, the yet-achievable >90% accuracy, even in a closed-world scenario, still poses a privacy threat.

Regarding the countermeasures, the researchers explained that the existing countermeasures to prevent related attacks do not apply on this novel side-channel attack. To tackle UE processing delays, possible countermeasures include not sending Delivery Reports or manipulating them with a random delay.

As for the network-based delays, altering SMS timings, deploying spamming filters on the core network, or at least disabling silent messages can help minimize the potentialities of such attacks. Nonetheless, disabling the delivery reports feature can be the only viable countermeasure.

Before making this study public, the researchers responsibly disclosed the matter to the GSMA. In turn, GSMA acknowledged their findings (identified as CVD-2023-0072) and considered numerous countermeasures.

Let us know your thoughts in the comments.


[ad_2]
Source link