Fake sites,stolen OTPs,and a 3-hour deadline:understand the new game of cyber fraud

0
4

 

In today’s digital age, the methods of cyber fraud are evolving daily. Cyber ​​fraudsters are no longer targeting people through phone calls, fake SMS, or fake bank websites, but are also using techniques that attempt to gain access to the victim’s smartphone. A similar case has come to light involving the misuse of Google’s Firebase platform.

Given the risk of cyberattacks, the government has directed Google to close hundreds of accounts on Firebase. According to media reports, the Indian Cyber ​​Crime Coordination Centre (I4C) sent notices to Google in August to remove at least 57 websites and databases hosted on Firebase. Some of these websites were phishing pages imitating institutions like SBI, ICICI Bank, and Axis Bank. According to I4C, in some cases, cyber fraudsters lure people into downloading fake apps by promising credit cards, reward points, or credit limit increases. Such apps can access sensitive information stored on phones.

According to a Reuters report, the government observed a pattern of Firebase misuse, in which attempts were being made to obtain sensitive information through fake banking and PM-KISAN apps. This raises questions: what exactly is Firebase, how are fraudsters using it, and how dangerous can malware like Android God Mode be once it enters a phone?

Google Firebase is Google’s cloud-based app and website development platform. Developers worldwide use it to build apps, manage backend databases, and host services. These days, cyber fraudsters have also begun using this platform for fraud. According to media reports, cyber fraudsters have adopted a new pattern by taking advantage of Firebase’s free plan, powerful database features, and easy hosting.

Fraudsters create phishing pages on Firebase by imitating fake banking pages like SBI, ICICI, and Axis Bank.

Malware is installed on people’s phones through fake apps or links. As soon as the victim installs the app on their phone, the malware is transferred to the phone. Any information the user enters or uses the banking app is then transferred directly to the cybercriminals’ backend database built on Firebase.

According to the I4C notice, of the 57 websites and databases identified for removal in August, seven were phishing pages that completely mimicked the websites of Indian banks like SBI, ICICI Bank, and Axis Bank. The rest included infrastructure used to obtain stolen information from victims’ phones, including credit card information and OTPs.

It’s important to note that neither Google nor Firebase has been held responsible for these fraudulent activities.

In the digital age, it’s becoming increasingly difficult to identify fake websites. Nowadays, cyber criminals design fake websites with a similar interface, logo, and color theme, making them extremely difficult for ordinary customers to identify. However, if you pay attention to a few things, you can easily distinguish between a fake and a real website.

Check the URL-Domain Name
The domain name of a genuine bank is always accurate, such as https://www.sbi.co.in. Scammers use similar spellings or incorrect extensions. Also, if a large company is using a .xyz, .top, or strange domain, be wary.

Offers
If a website features overly tempting offers, heavy discounts, or incorrect Hindi or English, it could be a fraud.

Second Page
If a link promises to increase your credit card limit, cash in reward points, or cashback, or directs you to an unknown page, it could be a fake.

Avoid Third-Party APKs
After visiting any bank’s website, if you find a link to an unknown .apk file to download an app, do not click on it even by mistake. Banks always recommend downloading apps from the Play Store/App Store.

According to a media report, in March this year, the government issued an advisory warning about dangerous malware like Android God Mode.

According to the government warning, malware known as Android God Mode misuses Android’s accessibility permissions. Such malware can masquerade as apps imitating banking, government, and utility services and trick users into installing them. Once users download these suspicious apps and grant the necessary sensitive permissions, the malware gains extensive control over the phone. Sometimes, the scammers gain complete control over your phone.

I4C’s August notice also stated that Android malware was being presented as legitimate banking services, specifically offering credit card users the lure of new cards, rewards, and increased credit limits.

This malware masquerades as a bank or other fake government app and tricks the user into enabling the phone’s Accessibility Services or other sensitive permissions. Once granted, the cybercriminal then proceeds to call and make a call.

They gain almost complete access. Not only this, this malware superimposes a fake screen over the original screen when the banking app is opened or tracks every character typed by the user.

The malware automatically reads the SMS and OTP received on the phone and silently sends it to the fraudsters’ Firebase database, so that the user does not even know that money has been deducted from their account.

Cyber ​​fraudsters avoid mentioning the names of banks and credit cards to win people’s trust. Instead, they mention government schemes. The names of government schemes can become a powerful social engineering weapon for fraudsters. According to a Reuters report, in this case, the name PM-KISAN was used in a scam. The fake website claimed to help people receive government payments and asked them to download an app.

The name of government schemes like PM-KISAN can be a powerful tool for fraudsters simply because it’s a government scheme. Users might believe they need a new app to receive payments, check their status, or apply for new payments. However, the real danger begins after downloading the app.

According to the report, such fake apps could collect user data and send it to a Firebase database controlled by fraudsters. Attackers could then attempt to access other information and apps on the phone, posing a potential fraud threat.

This means that online fraud isn’t just about having money withdrawn from your account through a credit card or OTP. An even greater danger is that fake apps can make your phone itself a gateway for attackers.

I4C has now sent three notices to Google, ordering the removal of at least 57 websites and databases. Even then, it remains difficult to stop them. Creating a new account or database on cloud platforms is very easy and free. Once a domain is shut down, criminals can create another link or database within minutes. This entire network can be controlled from various parts of the country and abroad.

Following the government’s notice, Google must block suspicious links and databases within three hours, otherwise Google could be held legally liable.

Google maintains that its policies strictly prevent phishing and financial fraud. Platforms like Google, Cloud, hosting, domains, and app stores work with automated AI detection and agencies like I4C to quickly identify suspicious accounts and permanently block them.

LEAVE A REPLY

Please enter your comment!
Please enter your name here