Friday, June 3, 2016

The Right to be Forgotten

Who Is The Target? Anonymous? | CyberHarassment and the CyberBullies

Who Is The Target? Anonymous? | CyberHarassment and the CyberBullies
Anon So Fucking Hard 

Who Is The Target? Anonymous?

Anyone can become a target of cyberbullies whether you're just an individual hanging out with personal friends and family on social media or whether you're a social activist. All that really has to happen is for you to cross paths with people like those named in this blog, trigger some paranoid delusion of theirs and you're on their hit list.

The entire point of this blog is to send out the message that people are standing up to these bullies by exposing their deceptions when they target and harass people.

Of course when you do that the bullies almost always accuse their targets of bullying by either playing the victim card themselves or falsely accusing them of bullying others. In their bizarre and twisted minds, it's bullying to defend yourself against bullying. Lol.

I believe that one of the reasons that many teenagers who are the victim of this crime end up committing suicide is that we, as a society, disempower them. We tell these victims to just 'ignore it and it will go away'.

Those of us who have been targets of this crime know perfectly well that harassers, bullies, and stalkers whether they're online or in real life do not just go away. They become empowered and enabled when you try to ignore them and will go to more and more extreme lengths to get your attention. They might get distracted by someone else for periods of time or they might stop for periods of time but you will never be off their hit list once you're on it. You have to have good strategies to make them go away.

In my previous blog post I talked about a person who is being effectively framed by these harassers as a pedophile. He does ignore them for the most part and yet he has been targeted in the most vicious way imaginable.

The 'ignore it and it will go away' approach only works in normal situations where normal people have normal fights with each other. In those situations it's best for both parties to separate and cool off and even if only one party does it, the other party will often just move on.

What differentiates those situations from situations which involve full-blown harassment, is that the people engaging in full-blown harassment, for the most part, do actually suffer from some sort of anti-social personality disorder and they do it because they get pleasure out of seeing people hurt and suffering. They enjoy destroying lives and that is their goal.

The phenomenon that we're seeing on the Internet is that those same people no longer have to be in close physical proximity to get together and engage in their abuse. As a result we are seeing the development of entire groups of people getting together who have similar histories of harassment and bullying and those people are working together. Sweeney talks about this phenomenon in his book, Hackers on Steroids.

There are several groups running around on Facebook right now who are focusing on and targeting social activists who are associated with Anonymous and their friends. Most of the social activists targeted are anti-pedophilia activists who are identifying and reporting pedophiles both on FaceBook and on DarkNet.

Some are just associated with individuals on the list but refused to drink the harassment kult kool-aid and ended up on the their hit list.

Since many Anons have objected to the behavior of these harassers they are now claiming that they are 'not Anons' nor do they support Anonymous, yet they join numerous Anonymous groups under numerous socks and by doing so create the implication that they are Anons or at the very least support Anonymous.

If they're not Anons and don't support Anonymous then why do they care what anyone does who is involved in or supports Anonymous or engages in social activism under the Anonymous banner? Do they think Anons are too stupid to locate pedophiles in their own ranks by themselves and deal with them? What business do they even have joining Anonymous groups?

One of the impacts of their actions has been that a lot of very good people are talking about removing their support for Anonymous and walking away because these crazies are creating so much disruption with their deceptions, threats and harassment that those targeted are finding it difficult to even focus on the causes they've given their hearts to.

Some are people who are solid social activists and who have contributed a great deal under the Anonymous banner all of which presents a positive public face to Anonymous.

If these good people start leaving, the name Anonymous will become solely tied to and associated with cyberharassment, cyberbullying and cyberstalking all of which are criminal acts with no socially redeeming qualities, because frankly that's who'll be left.

Then, it will just be a question of time before these groups start fighting with each other or targeting individuals in their own ranks. Some of that has already started. Maybe we'll get lucky and they'll focus on each other instead of targeting innocents. Since they all enjoy it so much they could have a lot of fun destroying each other. Now there's a thought.:)

Will that end the harassment of those individuals currently on their hit lists. Probably not but it will mean that new people will not be so easily accessible to them once this reputation gets established for Anonymous and it's well on it's way to establishing that reputation for itself thanks both to the cyberharassers and those Anons who repeatedly take the position that they 'don't want to get involved in the drama.'

They are involved in the drama whether they like or not because these cyberharassment groups have dragged everyone into the drama and done so quite successfully. Silence is assent.

And there is going to be an inevitable fall out to Anonymous as a result.

That's something that those who are actively supporting and advocating the concept of Anonymous should give some thought to when they tell those social activists who have been unjustly targeted that 'they don't want to get involved in the drama'. Just saying …

Two very good people, who have worked very hard and shown a great deal of dedication to the Anonymous anti-pedophilia cause are Brian Johnson and Jay Marshall.

Brian Johnson is a hacktivist and Jay Marshall is an Anonymous supporter like myself.

While Jay's name and dox haven't appeared on the hit list web site yet he's constantly dealing with harassers who are trying to convince him to go along with their harassment of the individuals on the hit list

Since he consistently refuses to go along with it he gets targeted with vicious rumors on an ongoing basis.

Brian Johnson has been placed on the hit list web site and has been lied about repeatedly as the cyberharassers desperately dig for dirt and constantly misrepresent innocent situations and relationships because they can't find any real dirt on him.

The minor things that they have found and are exaggerating are laughable given their personal backgrounds and histories. Therein lies their own shameless hypocrisy in all of this.

That is, they'll self-righteously pontificate about the evils of a person getting arrested for having weed while some of them have similar backgrounds, far worse backgrounds, or are into far stronger drugs.

And what would that have to do with the social activism that the person is involved in anyway. Absolutely nothing. It's nothing more than an attempt to smear the person in an as many ways as possible.

Antonio F. Lopez, the 30 year old American who is impersonating UK teen Kree Love online, has been digging deep for dirt on me as well and has found nothing. So he employs the same strategies that have been used against Brian and others by both him, members of his little harassment cult as well as other little harassment cults.

The general strategy employed and one which has been used on all of us to one degree or another is:

1. Do an Internet search on the target

2. Collect any identifying information that will also help you identify family, friends, employers (past and present), organizations the person supports or is involved in, etc.

3. Use both 1 and 2 (by contacting people directly) to dig up dirt on the person.

4. If you find something and it's 'evil' you're golden. If you find something and it's minor, exaggerate it way out of proportion. If you find nothing take what you have and see if you can fabricate some negative spin on it. If there's nothing fabricate something. If people don't buy it, frame the person.

5. After they're done brown-nosing your family and friends for dirt on you, they will then proceed to target them by posting their pictures in memes all over the place, making harassing phone calls, etc. and often far worse.

Antonio has added a new component to this by going to my past employers and lying to them despite the fact that I no longer work there. Don't ask me what the point of that was. These people are completely nuts. They are beyond the ken of normal people.

He is also the one that has initiated these frame-ups which he tries to keep quiet so that those he targets can't defend themselves. The fabricated evidence is distributed behind the persons back.

The pro-pedophilia web site that was created in one of the victims names was never posted publicly that I'm aware of, just in private groups where they thought we wouldn't find out about it. It has also been given to people privately as alleged evidence.

He claims that he has caught me stalking children. Given the frame-up of the person with the pro-pedophilia site I can't even imagine what despicable frame-up he's fabricated involving me and is distributing to people behind my back. Whatever it is, I have no doubt I could refute it in the 5 minutes it took me to expose and refute the pro-pedophilia site. I have never stalked children or anyone else.

As Sweeney mentioned in his book, a few years ago the RIP trolls consisted of a couple of hundred people on Facebook. Thanks to his hard work those groups broke up and the numbers dwindled, especially after a few people started getting arrested and faced substantial prison terms for their crimes. Thank You UK.

It looks to me like Antonio F. Lopez using the Kree Love alias misses those days and is trying to recreate those harassment groups. The only difference now is that he's focusing on social activists rather than the grieving families and friends of dead children and the harassment is extending beyond Facebook and on to other social media groups as well as the Internet at large.

Aside from the numerous hate blogs created by the seriously obsessive Michael Babcock, one of which is listed under a domain name which uses the name of the target they use to lure in recruits and bait them into targeting others, Babcock floods sites like paste-bin with all sorts of defamatory libel, private emails, chats, etc. and floods torrent sites with gigabytes of useless irrelevant data he calls 'evidence' for his and the other harassment groups defamatory libel. His obsessions are quite extreme.

Before the Anonpaste.me site got shut down and confiscated by Interpol, Babcock had flooded it with literally thousands of defamatory libelous doxes. That is not normal behavior by any definition.

These cyberharassers try to establish some street credibility by claiming that they're just trolls, 4channers and doing it for the 'lulz' but frankly, I don't recall trolls or 4channers running around the Internet doing this sort of stuff. I'm in IT and my previous career was in libraries. I've been on the Internet or exposed to it for far longer than most.

On the rare occasions when someone appeared online and did this sort of stuff they didn't last long because the good guys dealt with them. This activity was never allowed to expand to the proportions it's expanding now since the general public has come online.

This is a recent phenomenon and it's nothing more than a bunch of people with severe to mild anti-social personality disorders getting together in groups for the like-minded, hiding behind the troll/4chan/Anonymous names to give themselves some Internet credibility so that they can rationalize their abuse of innocent people.

They are criminals committing criminal acts daily and should be treated as such. The fact that these crimes are occurring on the Internet doesn't make them less of a crime than in real life.

If treatments exist for the type of anti-social personality disorders these people display then they should also receive the mental health intervention that they appear to so desperately need.

They're behavior really says it all where that's concerned.

To those Anons who say they want to stay out of the drama: Silence is assent and they're in the middle of the drama whether they want to be or not.

To Anonymous: Do you really want the Anonymous name dragged through the mud like this. It is happening irrespective of their claims.

I'll leave with Brians words, expressed in a moment of frustration but reflecting the reality of what is happening to Anonymous because of these idiots.

Brian Johnson

Brian Johnson



^ed 

Українські ЗМІ атакують за допомогою Black Energy

Українські ЗМІ атакують за допомогою Black Energy
US CERT STATEMENT ON BLACK ENERGY 


Українські ЗМІ атакують за допомогою Black Energy

09/11/2015

blackenergy1Нещодавно декілька українських ЗМІ у дні проведення місцевих виборів було атаковано невідомими зловмисниками. Про це у мережі оприлюднювалась досить дозована інформація про успішні хакерські атаки, напрямлені на них. До CERT-UA також звернулись з цього приводу і ми вважаємо за важливе повідомити про деякі деталі.

Загалом, хотілося б відмітити те, що загроза має характер добре спланованого замовлення з метою показати спроможність порушення працездатності скомпрометованих корпоративних мереж ЗМІ за допомогою такого інструменту хакерів, як Black Energy (Win32/Rootkit.BlackEnergy, Backdoor.Win64.Blakken), яке використовується для проведення APT-атак. Про захист від атак цього типу ми писали раніше.

24 та 25 жовтня 2015 року (день виборів) на серверному обладнанні Телеканалу Х було зафіксовано атаку внаслідок виходу з ладу декількох серверів. Деякі телеканали не публікували і не розголошували додаткових подробиць, проте наявні у нас дані свідчать, що постраждала значна кількість відеоматеріалів та інші види інформаційних матеріалів. Власне розслідування спеціалістів з безпеки Телеканалу Х показало наявність на уражених серверах файлів з назвами: ololo.exe, trololo.exe та інших.

Дане шкідливе програмне забезпечення виконує деструктивну функцію (від англ. eraser), функціонал якого полягав у спробі отримати повноваження привілейованого користувача операційної системи. У разі, якщо це не вдавалось, на зараженій системі починали створюватись файли розміром 16 мегабайт у папці c://Windows/TEMP та заповнюватись довільно обраною літерою:

blacken 

Можливо, це робиться з метою звернути увагу системного адміністратора на завершення дискового простору і примушення його виконати входження під обліковим записом привілейованого користувача.

Також, eraser видаляв завантажувач, що у сукупності призводило до неможливості запуску операційної системи у подальшому. Крім того, даний eraser шукав на ПК файли з таким розширеннями.

Скоріш за все, eraser був завантажений Black Energy на заражену систему за допомогою драйверів:

[aliide.sys][956246139f93a83f134a39cd55512f6d]
[amdide.sys][979413f9916e8462e960a4eb794824fc]

які виступали у якості шлюзів для подальшого завантаження іншого шкідливого функціоналу Black Energy.

Згідно проведеного аналізу, цей драйвер призначений для x64 архітектури процесора та має перевірений сертифікат. Оскільки завантажувач BlackEnergy встановлює свій драйвер під випадково вибраним ім'ям, який бере у невикористаного в момент установки існуючого драйвера в ОС Windows, наприклад, %system32%\drivers\aliide.sys, то не можна знайти його в системі за певним іменем. Однак, в 64-розрядних системах використовується самоподпісанний драйвер, і цей факт дозволив деяким жертвам ідентифікувати шкідливий файл.

BlackEnergy використовує один із перерахованих нижче імен файлів для зашифрованих сховищ плагінів і мережевих налаштувань. Вони постійні і служать в якості стабільних індикаторів компрометації:

%system32%\drivers\winntd_.dat

%system32%\drivers\winntd.dat

%system32%\drivers\wincache.dat

%system32%\drivers\mlang.dat

%system32%\drivers\osver32nt.dat

%LOCALAPPDATA%\adobe\wind002.dat

%LOCALAPPDATA%\adobe\settings.sol

%LOCALAPPDATA%\adobe\winver.dat

%LOCALAPPDATA%\adobe\cache.dat

Для забезпечення персистентності (постійності в системі) BlackEnergy також використовує наступний шлях в автозагрузці системи:

Users\user\AppData\Roaming\Microsoft\Windows\Start

Menu\Programs\Startup\{random_name}.exe

Також відомі такі наступні імена файлів, які можуть використовуватися даним зразком BlackEnergy:

%USERPROFILE%\NTUSER.LOG

%LOCALAPPDATA%\FONTCACHE.DAT

Стосовно IP-адреси, з якої було можливе завантаження шкідливого програмного забезпечення, то нам поки що не вдалося отримати журнальні файли від провайдера. Правоохоронні органи України також попереджені.

За результатом аналізу виявлено більше 30 унікальних ІР-адрес у мережі Інтернет, які слугують у якості серверів контролю та управління Black Energy. Це значить, що даний інструмент АРТ-атак знов проявляє себе і працює переважно проти Польщі та України.

Оскільки під час розбору атаки було виявлено компрометацію серверу 1C-бугалтерії, можливо, що первинним джерелом потрапляння BlackEnergy до мереж була електронна пошта на адресу фінансового підрозділу.

 

Ще раз наголошуємо на неприпустимості відкриття вкладень, отриманих засобами електронної пошти (без попереднього підтвердження факту надсилання електронного листа його відправником).

Системним адміністраторам і адміністраторам безпеки слід звернути увагу на фільтрацію вхідних/вихідних інформаційних потоків, зокрема, поштового і веб-трафіку.

Користувачам електронної пошти слід бути уважними при відкритті атачментів, навіть якщо вони надійшли від відомих адресатів.



^ed 

HALP!'n BlackEnergy trojan strikes again: Attacks Ukrainian electric power industry

BlackEnergy trojan strikes again: Attacks Ukrainian electric power industry

DailyDDoSe © June 3, 2016

HALP @Cyber 


THIS IS WHAT I HAVE!!! The Eset Hack via Amazon. 

Totally bricked and wiped my devices, took admin privileges and remote remote access to every thing from the printer, the TV to the god damned sink. 


Help is on the way. At least I sure hope so. Xoxo 📧










BlackEnergy trojan strikes again: Attacks Ukrainian electric power industry

On December 23rd, 2015, around half of the homes in the Ivano-Frankivsk region in Ukraine (population around 1.4 million) were left without electricity for a few hours. According to the Ukrainian news media outlet TSN, the cause of the power outage was a "hacker attack" utilizing a "virus".

Looking at ESET's own telemetry, we have discovered that the reported case was not an isolated incident and that other energy companies in Ukraine were targeted by cybercriminals at the same time.

Furthermore, we found out that the attackers have been using a malware family on which we have had our eye for quite some time now: BlackEnergy. Specifically, the BlackEnergy backdoor has been used to plant a KillDisk component onto the targeted computers that would render them unbootable.

(Un)related events?

The BlackEnergy trojan has been used for various purposes in the past few years. At the Virus Bulletin conference in 2014, we discussed a series of cyber-espionage attacks against high-value, government-related targets in Ukraine. The malware operators have used numerous spreading mechanisms to infect their victims, including the infamous PowerPoint 0-day CVE-2014-4114. While the primary objectives of the 2014 attacks appeared to be espionage, the discovery of BlackEnergy trojan-droppers capable of infecting SCADA Industrial Control Systems hinted that the gang might be up to something more dramatic.

In the recent attacks against electricity distribution companies in Ukraine, a destructive KillDisk trojan was downloaded and executed on systems previously infected with the BlackEnergy trojan.

The link between BlackEnergy and KillDisk was first reported by CERT-UA in November. In that instance, a number of news media companies were attacked at the time of the 2015 Ukrainian local elections. The report claims that a large number of video materials and various documents have been destroyed as a result of the attack.

Electricity distribution companies under attack

Currently we know of several electricity distribution companies in Ukraine (other than the medialized case of Prykarpattya Oblenergo, already picked up by the media) that have been targeted by cybercriminals. We can confirm that the BlackEnergy backdoor was used against some of them and that the destructive KillDisk component was also used in more recent cases observed during the week of Christmas Eve, 2015. Additionally, BlackEnergy was also detected at electricity companies earlier in 2015; while we have no indication of KillDisk being used at that time, it is possible that the cybercriminals were then at the preparatory stage of the attack.

The infection vector used in these attacks is Microsoft Office files containing malicious macros. We have observed the BlackEnergy gang using this common technique, also employed by Dridex and other gangs, throughout 2015.

The attack scenario is simple: the target gets a spear-phishing email that contains an attachment with a malicious document. The Ukrainian security company CyS Centrum published two screenshots of emails used in BlackEnergy campaigns, where the attackers spoofed the sender address to appear to be one belonging to Rada (the Ukrainian parliament). The document itself contains text trying to convince the victim to run the macro in the document. This is an example where social engineering is used instead of exploiting software vulnerabilities. If victims are successfully tricked, they end up infected with BlackEnergy Lite.

attackers

As explained in our Virus Bulletin talk, the BlackEnergy trojan is modular and employs various downloadable components to carry out specific tasks. In the case of the most recent attack in Ukraine, the Win32/KillDisk malware was found on the infected system.

As well as being able to delete system files to make the system unbootable – functionality typical for such destructive trojans – the KillDisk variant detected in the electricity distribution companies also appears to contain some additional functionality specifically intended to sabotage industrial systems.

Firstly, it was possible to set a specific time delay after which the destructive payload was activated. Then, apart from the regular KillDisk functionality, it would try to terminate two non-standard processes: komut.exe and sec_service.exe. The second process, sec_service.exe, may belong to software called ELTIMA Serial to Ethernet Connector or to ASEM Ubiquity, a platform commonly used in Industrial Control Systems (ICS). If this process is found on the target system, the trojan will not only terminate it but will also overwrite its corresponding executable file on the hard drive with random data in order to make restoration of the system more difficult.

Conclusion

Destructive malware is not a new phenomenon. While even some of the earliest viruses used to have destructive functionality intended mostly as a prank, today's cybercriminals use such components for a number of reasons, ranging from sabotage, or hacktivism, to covering their tracks after a successful cyber-espionage attack. The Flamer (a.k.a. Flame or sKyWIper) malware is one of the most notorious examples. A data-wiping component has, reportedly, also been used in the attack against Sony Pictures. It should be clear, though, that a trojan capable of 'wiping' files or a few sectors of a hard-drive is not exactly unique and if we take into account the imprecise nature of malware naming (many such trojans have been called 'Wiper', or a similar derivative of the word), then speculations, unsubstantiated correlations and linking of unrelated incidents are bound to happen.

Even the BlackEnergy malware family has used a dstr destructive plugin in 2014. However, unlike the recent KillDisk variants used in attacks against media companies and the electricity distribution industry, it appeared as a generic 'self-destruct' component and we are not sure of its intended purpose.

Our analysis of the destructive KillDisk malware detected in several electricity distribution companies in Ukraine indicates that it is theoretically capable of shutting down critical systems. However, there is also another possible explanation. The BlackEnergy backdoor, as well as a recently discovered SSH backdoor, themselves provide attackers with remote access to infected systems. After having successfully infiltrated a critical system with either of these trojans, an attacker would, again theoretically, be perfectly capable of shutting it down. In such case, the planted KillDisk destructive trojan would act as a means of making recovery more difficult.

We can assume with a fairly high amount of certainty that the described toolset was used to cause the power outage in the Ivano-Frankivsk region.

Although in Ukraine, Christmas is traditionally not celebrated on December 24th and 25th, a group of cybercriminals has chosen this time of year to deliver a dark 'present' to a few hundred thousand people and many more might have also been this 'lucky', had the malware not been detected.

For further information on the situation, thoughts and takeaways, read this post on the SANS Industrial Control Systems Security Blog. Additional details on the malware used in the attacks and Indicators of Compromise can be found in our technical blog post.

Author Robert Lipovsky, ESET



^ed 

How did hackers cause a blackout in Ukraine? DailyDDoSe © June 3, 2016

How did hackers cause a blackout in Ukraine?
DailyDDoSe © June 3, 2016 

I wasn't kidding about blowing the transformers. 

Hackers and terrorists have joined forces and actively mapping the power grid so they can shut down power plants and disable other critical infrastructure.  

Stuxnet is a perfect example of how Israel and America joined forces to fuck the planet starting with Iran and Nuclear Power Plants. 

As an aside, when I found myself added to a Skype group where participants were actively planning to map out the power grid to bring about total disaster in America I knew I was in way too deep. 

I surrender the laptop and devices to authorities for forensics and reported the site to US CERT for terrorism. Several of the members have since been investigated and even deported from America for participating in terror related activities. 

This internet shit scares me.  How the fuck did this happen l? 

Just me, 

@ELyssaD 
 
DailyDDoSe © June 3,  2016


This is the scary-simple way hackers killed power to 700,000 homes

Ukraine power black out candleREUTERS/Pavel RebrovA Crimean Tatar carries firewood during a blackout orchestrated by anti-Russian saboteurs.

Hackers were able to cut the power to about 700,000 homes in Ukraine last month — marking the first time a cyberattack caused a blackout — and the way they did it was equal parts simple and scary.

Though the Dec. 23 attack on a power company in Ukraine's Ivano-Frankivsk region caused people to lose electricity for at least a few hours, it wasn't all that sophisticated. The hackers got malware called "BlackEnergy" onto the company's systems using little more than email.

"It was a targeted phishing email with an Excel spreadsheet attached," said Rohyt Belani, CEO of PhishMe, of emails designed to trick users into performing a task or giving up information. In the case of the Ukraine attack, Belani said those emails were sent to workers and tricked people into running malicious software.

It worked like this:

Cyberattackers conducted research on their target and identified people at the power company who might open and run their malware. Once identified, the attackers sent them a spoofed (faked as if it came from a different email address) message with an Excel spreadsheet attached.

ukraine attack malwareESET

After the user opened the Excel file, it told them the document was created in a newer version of Microsoft Office, and "Macros must be enabled to display the contents." It went on to show how a user could enable macros — a built-in feature that allows tasks to be automated in Office that hackers often use to insert malicious code.

Once macros were enabled, BlackEnergy was loaded onto the system, which gave the attacker the ability to control the computer, delete files, or make the system unbootable. In essence, there was very little "hacking" because users basically infected the machines themselves without even knowing it.

The hackers, which some believe to be a Russian-linked group dubbed Sandworm, then took some of the systems offline, triggering the blackout.

"It's certainly not surprising," Joanie Myers, a cybersecurity expert with Strategic Link Partners, told Tech Insider in a phone interview last month. "If you look at the power grid, it's a set of snapped-in associations ... an attack against one piece of it can cause multiple pieces to fail."

This style of attack is very common. Cybersecurity firm Trend Micro found a staggering 91% of targeted attacks involved spear-phishing emails, or emails that contained specifics on the person targeted.

"One of the things I find quite ironic," Belani said. "Is that we've been seeing this sort of script play out again and again. We're still dealing with a very similar issue with sort of catastrophic consequences."

Belani's company PhishMe specializes in helping companies avoid these types of attacks, offering phishing simulators and detection software. But even with plenty of training and expensive cybersecurity solutions, he says there is no "silver bullet."

In fact, even his own company has suffered from phishing attacks. Belani once received an email that apparently came from his CTO Aaron Higbee, warning that there was a massive software bug in their new product. "[The attackers] knew the right emotional triggers to get me," he said.

In the email was a PDF, but just before he was going to open it, Belani said he took a step back to analyze the situation. His suspicions were raised by the attachment and by the message starting with "Dear Rohyt" — two things his CTO would never put in an email.

That skepticism is what Belani recommends for everyone when dealing with emails. Hackers can make an email look like it came from a trusted friend, or ask users to perform a task. So before doing so, users should double-check the message contents, and be wary about opening any attachments.

"The user is so unconditioned that email is the means of transporting attacks," he said.



^ed