Cybercriminals Send Malicious Cards Before Medovy Spas
Cybercriminals are distributing malicious files and phishing links disguised as holiday greeting cards ahead of the Russian Orthodox holiday of Medovy Spas, targeting users via messengers and social media.
Consensus
- Cybercriminals are sending malicious files and phishing links via messengers and social media before Medovy Spas.
- The malicious content is disguised as holiday greeting cards.
- Users are advised not to open attachments from unknown senders or click on suspicious links.
- Common phishing tactics include prompts to 'download a price list', 'open a card', or 'check an order by number'.
- The holiday of Medovy Spas is observed on August 14 according to the Orthodox calendar.
- The National Front's 'Moshelovka' platform reported on the scam.
Points of divergence
- Mothers are being targeted with fake notifications about drone attack alerts through fraudulent websites. — vm
- Phone scammers typically call using three pretexts: suspicious bank transactions, need to renew service contracts, phone number blocking, or unauthorized loan applications. — vm
- Scammers are promoting fake fuel cards and vouchers through fraudulent websites resembling real fuel company sites. — kommersant
- Phone scammers use claims of suspicious money transfers or unauthorized loan applications as conversation starters. — kommersant
Coverage (2 sources)
- Scammers before Honey Saving send malicious files under the guise of cards — Вечерняя Москва
- Scammers started sending malicious files under the guise of postcards — Коммерсантъ