Fake News Weaponized by Cyber Phishing Scammers

Tags: , , ,

By Steve King, LifeZette:

Hackers use sensationalized click bait to hit unsuspecting users with malware

A large, looming, and largely unrecognized risk from fake news is not the political impact of stories unfounded in reality or un-supported by fact — instead, it’s the impact a fake news story has as an attack vector for phishing campaigns. Fake news provides another way into your personal, private, and sensitive information.

Almost everyone understands now that there is no Nigerian prince seeking to transfer tens of millions into your checking account, but what of a “news” story that claims a political candidate you hate has committed a crime? Would you click on that?

The recent weaponization of news, often attributed to Russian intelligence services, plays on our obsession to follow and click on news stories that support our point of view. Sensational headlines are a compelling form of click-bait that entice even the most paranoid observers to dive into some apparent evidence that their hatred for let’s say, President Donald Trump, is indeed well-founded.

There are several effective ways to get there. A cyber-manipulator can compromise a legitimate news outlet and transform it into a watering-hole full of malicious links or they can purchase inexpensive banner ad space on a legitimate site and capture user clicks there. The trick is to be sensational yet nuanced. Sort of like The New York Times.

But the danger goes beyond your own private information. A fake news story is not asking you for your bank account. Modern malware is persistent and polymorphous. It can easily bypass perimeter defenses, filters, and end-point detection. Its whole purpose is to penetrate and set up camp somewhere inside your network so that it can do the same thing inside your company’s network when you log on there.

The fake news story that you click on using your iPhone during your morning commute will become a network infection within your organization by lunchtime. You won’t know it nor will your network administrators. But, after you log on to your network with your iPhone, it will be there.

Malware is insidious. It needs neither a file nor a document to act as host. Once in place, it begins scanning and monitoring your network for vulnerabilities. It looks in operating systems, applications, files, hardware, and the cloud. It catalogs the vulnerabilities it finds and sends that list back to its command and control center. Most people these days think this is located in Russia or Iran or China. But, it could just as easily be two teenagers in Scranton.

The command and control center figures out which vulnerabilities it wants to attack and then sends instructions to the malware to begin gathering data and to prepare for exfiltration. This may occur over days, hours, weeks, or months. But you won’t know it is happening. Your network specialists and security analysts will most likely not know it is happening either. Without advanced behavioral analytics, which very few people are using, today’s malware is almost impossible to detect.

And just think, a simple click on a news story that appears to run in The New York Times Online edition started the whole thing.

We live in a full-on 24/7 assault environment where we are constantly bombarded with news, fake news, advertising, marketing theater, digital entertainment and information of all varieties. No matter how diligent we are, it is almost impossible to avoid a tawdry click, a gut reaction to an offensive headline, or a visceral response to a story that proves our point. Clicks will happen.

 

The current debate over fake news and the adversarial use of news by extremist groups on the far Right and Left actually distracts from the reality that weaponized information is being used to deliver malicious code into networks of all sizes and varieties. That malware will allow global attack networks to penetrate critical U.S. infrastructure, steal intellectual property, impose disruptions like the Internet outage last October and more lethally cripple physical distribution components on which we rely for power, water and transportation.

The proliferation of weaponized information has broad implications as a true existential threat that goes beyond political systems and seats of power.

These slopes have momentum of their own and right now, the bad guys are winning at a remarkable rate. The Trump administration needs to take immediate and bold steps to undermine these cyberattackers, impose cybersecurity mandates across all government agencies, empower smart people to move swiftly toward advanced offensive and defensive weaponry so that we can aggressively tilt the playing field back in our favor before we run out of runway all together.

Steve King is the COO and CTO of Netswitch Technology Management.

Read related content at LifeZette.

Paul: ‘Obamacare Lite’ Will Divide GOP

Yes, Jimmy Buffett ‘Retires’ — His Way

  • RSS WND

    • Biden unveils $3 billion for push to replace all lead pipes in 10 years
      Nick Pope Daily Caller News Foundation The Biden administration announced $3 billion in funding for its initiative to get rid of every lead pipe in the U.S. over the next ten years on Thursday. The Environmental Protection Agency (EPA) unveiled the funding, which comes from the bipartisan infrastructure package of 2021 and is part of… […]
    • Productivity data delivers more bad news about Biden's economy
      By Will Kessler Daily Caller News Foundation U.S. productivity growth slowed in the first quarter of 2024, casting doubt on the American economy’s future growth, according to data released by the Bureau of Labor Statistics (BLS) on Thursday. Growth in U.S. business productivity slowed to just 0.3% in the first quarter of 2024, below economists’… […]
    • Midwest state becomes latest to take on Biden's illegal alien crisis
      By Jason Hopkins Daily Caller News Foundation Oklahoma’s Republican governor signed a sweeping immigration enforcement bill into law, making the Sooner State the latest to confront the border crisis through legislative action. Gov. Kevin Stitt signed House Bill 4156 into law on Tuesday, one week after the Republican-controlled legislature sent it to his desk. The… […]
    • Principal replaced, officials on leave after viral video shows drag queen performing at prom
      (THE BLAZE) – School officials are in hot water after parents found out about a drag queen performance at a high school prom in New Mexico. Channell Segura, Chief of Albuquerque Public Schools, admitted to parents that the drag queen performed at the Atrisco Heritage Academy on April 20. A viral video on social media… […]
    • Cost of Biden's student debt cancellation could reach $1.4 trillion
      (JUST THE NEWS) – A new report estimates that President Joe Biden's plans to cancel student debt for some borrowers could cost taxpayers up to $1.4 trillion, depending on how the plans are implemented. The nonpartisan Committee for a Responsible Federal Budget estimated all Biden's recent debt cancellation efforts would cost a combined $870 billion… […]
    • Protest-afflicted university urges professors to cancel final exams, move testing remote
      Kate Anderson Daily Caller News Foundation Columbia University announced Wednesday that professors should consider making exams optional or forfeiting them altogether as the school has been rocked with escalating protests, according to the Columbia Spectator. Police arrested over 100 individuals camped out on university property after they defied the school’s mandate to clear the area,… […]
    • Lawsuit alleges pro-Palestinian groups behind campus protests collaborate with Hamas
      Jake Smith Daily Caller News Foundation American and Israeli victims of the Hamas terrorist attacks against Israel filed a lawsuit on Wednesday against pro-Palestinian and Muslim advocacy groups over their alleged promotion and support for Hamas. Hamas attacked Israel on Oct. 7, killing roughly 1,200 people and kidnapping hundreds of others, which prompted sweeping pro-Palestinian… […]
    • 2nd Boeing whistleblower dies suddenly after claiming safety flaws ignored
      (NEW YORK POST) – A Boeing whistleblower who raised concerns about one of the carrier’s suppliers ignoring production defects died suddenly on Tuesday — just two months after another employee who sounded the alarm about the embattled company died by alleged suicide. Joshua Dean, 45, a former quality auditor at Spirit AeroSystems, died Tuesday morning… […]
    • Satanic Temple announces plans to deploy ministers in schools
      (DAILY FETCHED) – The Satanic Temple (TST) has announced plans to deploy its ministers as chaplains in schools across Oklahoma following the House’s recent legislation. Senate Bill 36, which allows volunteer chaplains within educational institutions, passed the House and now awaits Senate approval. If it passes the Senate, Oklahoma could see the bill enacted as… […]
    • AI priest defrocked after going rogue
      (METRO U.K.) – A Catholic charity who launched an AI priest had to defrock him only a week later after he went rogue, taking confession and giving odd interpretations of scripture. ‘Father Justin’ told one user he was a real priest, saying: ‘Yes, my friend. I am as real as the faith we share.’ Get… […]
  • Enter My WorldView