Threatening emails are a commonly-used weapon in the malware distributor’s arsenal, but Pennsylvania drivers are being targeted by a phishing campaign unlike any that’s been seen before.
Typically, phishing emails are fairly generic. They might masquerade as a shipping notice or an overdue invoice. For even a semi-vigilant user with a decent eye for detail, that makes them easy to detect. Even more carefully-crafted campaigns fall apart if you know to look for typos in the domain name or sender’s email address.
What makes this new Pennsylvania phishing campaign stand out is the data they contain. Drivers are being told that they’ve been caught speeding, and they’re being shown accurate route information, dates and times, and even the posted speed limit and their actual speed. What’s more, the drivers receiving the emails were really caught speeding in the noted locations according to local police.
There’s something missing from the phishing emails, though: the photo of the offender’s license plate. It’s all part of the scam, of course, and the hope is that the information provided has convinced the victim that the email is legit and that he or she should click through to see the proof. At the other end of the link, predictably, is a malicious download.
So where did the attacker manage to dig up this data in the first place? Police aren’t sure yet, but one possibility is that it’s being harvested from a smartphone app. Another might be that their ticketing system has been breached.
The good news is that the emails give themselves away. The sender’s address doesn’t look at all like one that authorities would use to contact drivers about moving violations: citation@safe-browsing.com. It’s kind of amazing that an attack this sophisticated would use a sender’s email address that’s so transparent.
Photo by Jason Lawrence/Flickr
