Story image

Malaysians urged to watch out for clickbait and 'fake news' as election season approaches

27 Mar 2018

Quann Malaysia is warning Malaysians to be vigilant and watch for clickbait phishing links as the 14th Malaysian General Elections approach.

The security firm believes that there will be an increase in ‘fake news’ this year. This will result from clickbait phishing websites or emails with attachments that feature ‘exclusive’ or ‘shocking’ stories, used to bait users into providing personal information

Quann Malaysia general manager Ivan Wen says that when news sounds too good to be true, it is likely fake news.

“Once clicked, users are led to a phishing site that tricks victims into giving their personal data such as email addresses, identity card numbers, and even credit card information. These could compromise critical financial information. These phishing emails can also launch ransomware attacks that encrypt important information on the device. In a worst-case scenario, this can become a national threat.”

Wen says that the phishing links could automatically be shared with people’s contacts if attackers get access to a device, which means contacts may be put in harm’s way as well.

Quann says there have been two major country elections that spawned clickbait links and cybersecurity threats.

The first was the 2016 United States Election. According to Quann, a phishing campaign by a Russian intelligence agency was launched against a US company that was involved in developing election systems.

“Fake Google alert emails were send to employees which when clicked took them to a legitimate looking Google site where hackers were able to steal their data,” Quann states.

“Using information obtained in the attack, the hackers sent 122 phishing emails containing Microsoft Word document attachments to local government agencies offering ‘election related products and services’. These documents had been ‘trojanized’ with a Visual Basic script that once connected to the internet, downloaded an unknown payload to the device, to steal and access the victim’s information.”

 In 2017, threat actors also targeted several UK parliament MPs that compromised personal emails, Quann adds.

“Juicy news is hard to resist, but the possibility of losing your critical data, or worse, your money is not worth succumbing to curiosity conjured by the unbelievable clickbait news or offer titles,” Wen says.

Wen advises people to be wary of clickbait and take the following precautions:

  • Key in the address of a legitimate news site instead of directly clicking links sent to you. This avoids being tricked and misdirected to a fake website. 
  • Before clicking, hover your mouse pointer over the link to view the link address. Do not click website links that are unfamiliar, even if they came from someone you know. Their accounts could have been compromised. 
  • Install an anti-phishing toolbar and antivirus that run quick checks on sites you visit to ensure they are safe to visit 
  • Only access secure sites that begin with “https” with a closed lock icon near the address bar.
  • Regularly monitor your online accounts to ensure they have not been hacked. Use strong passwords and regularly change them.
  • Regularly update your browsers with the necessary security patches 
  • Beware of pop-up windows masquerading as legitimate extensions of a website. Often they are used to target users visiting a website that has been compromised.
ESET researchers break down latest arsenal of the infamous Sednit group
At the end of August 2018, the Sednit group launched a spear-phishing email campaign, in which it distributed shortened URLs that delivered first-stage Zebrocy components.
Container survey shows adoption accelerating while security concerns remain top of mind
The report features insights from over 500 IT professionals.
Google 'will do better' after G Suite passwords exposed since 2005
Fourteen years is a long time for sensitive information like usernames and passwords to be sitting ducks, unencrypted and at risk of theft and corruption.
Fake apps on Google Play scamming users out of cryptocurrency
Fake cryptocurrency apps on Google Play have been discovered to be phishing and scamming users out of cryptocurrency, according to a new report from ESET.
Hackbusters! Reviewing 90 days of cybersecurity incident response cases
While there are occasionally very advanced new threats, these are massively outnumbered by common-or-garden email fraud, ransomware attacks and well-worn old exploits.
SEGA turns to Palo Alto Networks for cybersecurity protection
When one of the world’s largest video game pioneers wanted to strengthen its IT defences against cyber threats, it started with firewalls and real-time threat intelligence from Palo Alto Networks.
Forrester names Trend Micro Leader in email security
TrendMicro earned the highest score for technology leadership, deployment options and cloud integration.
LogRhythm releases cloud-based SIEM solution
LogRhythm Cloud provides the same feature set and user experience as its on-prem experience.