{"id":29780,"date":"2019-05-03T14:19:44","date_gmt":"2019-05-03T13:19:44","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2019\/05\/03\/kaspershy-expert-on-the-enemy-in-your-pocket-large-scale-sim-swap-fraud\/"},"modified":"2019-05-08T15:32:34","modified_gmt":"2019-05-08T14:32:34","slug":"kaspershy-expert-on-the-enemy-in-your-pocket-large-scale-sim-swap-fraud","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/05\/03\/kaspershy-expert-on-the-enemy-in-your-pocket-large-scale-sim-swap-fraud\/","title":{"rendered":"Kaspersky expert on the enemy in your pocket: large-scale SIM swap fraud"},"content":{"rendered":"<p><em><strong>With mobile phone payments now hugely popular, cybercriminals have been targeting the market in a wave of attacks. With SIM swap fraud nowadays conducted on a large scale, Fabio Assolini, Senior Security Researcher, Global Research and Analysis Team, Kaspersky Lab, tells Intelligent CIO how cybercriminals complete the fraud and the best ways to avoid being the next victim.<\/strong><\/em><\/p>\n<p>Mobile payment is huge worldwide. Mobile phone-based money transfers allow users to access financing and micro-financing services, to deposit, withdraw and pay for goods and services easily with a mobile device. In some cases, almost half the value of a country&#8217;s GDP goes through mobile phones.<\/p>\n<p>But nowadays these mobile payments are suffering a wave of attacks and people are losing their money \u2013 all powered by SIM swap fraud. Such attacks are nowadays conducted on a large scale.<\/p>\n<p>SIM swap fraud is a type of account takeover fraud that generally targets a weakness in two-factor authentication and two-step verification, where the second factor or step is a SMS or a call placed to a mobile telephone. The fraud centres around exploiting a mobile phone operator\u2019s ability to seamlessly port a telephone number to a new SIM.<\/p>\n<p>This feature is normally used when a customer has lost or had their phone stolen. Attacks like these are now widespread, with cybercriminals using them not only to steal credentials and capture OTPs (one-time passwords) sent via SMS but also to cause financial damage to victims.<\/p>\n<p>If someone steals your phone number, you\u2019ll face a lot of problems, especially because most of our modern two-factor authentication systems are based on SMSs that can be intercepted using this technique.<\/p>\n<p>Criminals can hijack your accounts one by one by having a password reset sent to your phone. They can trick automated systems &#8211; like your bank &#8211; into thinking they\u2019re you when they call customer service. And worse, they can use your hijacked number to break into your work email and documents. And these attacks are possible because our financial life revolves around mobile apps that we use to send money, pay bills, etc.<\/p>\n<figure id=\"attachment_29906\" aria-describedby=\"caption-attachment-29906\" style=\"width: 1000px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-29906\" src=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/05\/Fabio-Assolini-1000-1.png\" alt=\"\" width=\"1000\" height=\"1500\" srcset=\"https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/05\/Fabio-Assolini-1000-1.png 1000w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/05\/Fabio-Assolini-1000-1-200x300.png 200w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/05\/Fabio-Assolini-1000-1-768x1152.png 768w, https:\/\/www.intelligentcio.com\/eu\/wp-content\/uploads\/sites\/20\/2019\/05\/Fabio-Assolini-1000-1-683x1024.png 683w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><figcaption id=\"caption-attachment-29906\" class=\"wp-caption-text\"><em><strong>Fabio Assolini, Senior Security Researcher, Global Research and Analysis Team, Kaspersky Lab<\/strong><\/em><\/figcaption><\/figure>\n<p>&nbsp;<\/p>\n<p><a name=\"_Toc6332022\"><\/a><a name=\"_Toc6331909\"><\/a><strong>How the cybercriminals do it<\/strong><\/p>\n<p>The scam begins with a fraudster gathering details about the victim by using phishing emails, by buying information from organised crime groups, via social engineering or by obtaining the information following data leaks.<\/p>\n<p>Once the fraudster has obtained the necessary details they will then contact the victim\u2019s mobile telephone provider. The fraudster uses social engineering techniques to convince the telephone company to port the victim\u2019s phone number to the fraudster\u2019s SIM, for example, by impersonating the victim and claiming they have lost their phone. They then ask for the number to be activated on a new SIM card.<\/p>\n<p>After that the victim\u2019s phone loses its connection to the network and the fraudster receives all the SMSs and voice calls intended for the victim. This allows the fraudster to intercept any one-time passwords sent via SMS or telephone calls made to the victim; all the services that rely on an SMS or telephone call authentication can then be used.<\/p>\n<p>We have found that some of the processes used by mobile operators are weak and leave customers open to SIM swap attacks. For example, in some markets in order to validate your identity the operator may ask for some basic information such as full name, date of birth, the amount of the last top-up voucher, the last five numbers called, etc.<\/p>\n<p>Fraudsters can find some of this information on social media or by using apps such as TrueCaller to get the caller name based on the number. With a bit of social engineering they also try to guess the voucher amount based on what\u2019s more popular in the local market. And what about the last five calls? One technique used by the fraudsters is to plant a few \u2018missed calls\u2019 or to send an SMS to the victim\u2019s number as bait so that they call back.<\/p>\n<p>Sometimes the target is the carrier and not the customer. This happens when a carrier\u2019s employees working in branches in small cities are sometimes unable to identify a fraudulent or adulterated document, especially branches located in kiosks or shopping malls, allowing a fraudster to activate a new SIM card.<\/p>\n<p>Another big problem is insiders, with some cybercriminals recruiting corrupt employees, paying them $10 to $15 per SIM card activated. The worst attacks occur when a fraudster sends a phishing email that aims to steal a carrier\u2019s system credentials.<\/p>\n<p>Ironically, most of these systems don\u2019t use two-factor authentication. Sometimes the goal of such emails is to install malware on the carrier\u2019s network \u2013 all a fraudster needs is just one credential, even from a small branch from a small city, to give them access to the carrier\u2019s system.<\/p>\n<p>The interest in such attacks is so great among cybercriminals that some of them decided to sell it as a service to others. Normally, a criminal can conduct an attack in two or three hours without much effort, because they already have access to the carrier\u2019s system or an insider.<\/p>\n<p>The fraudsters fire in all directions; sometimes their attacks are targeted, sometimes they\u2019re not. All a fraudster needs is your number, and it\u2019s very easy to find it by searching through leaked databases, buying that database from data brokers (some of them are legal), or using apps like\u00a0<a href=\"https:\/\/www.truecaller.com\/name-search\">TrueCaller<\/a>\u00a0and other similar apps that offer caller ID and spam blocking, but which also have some\u00a0<a href=\"https:\/\/fatsecurity.com\/article\/apps-like-truecaller\">privacy issues<\/a>\u00a0and a name-based search for subscribers. Sometimes your number can be found by simply doing a Google search.<\/p>\n<p>The first sign that something is not quite right is when you lose your smartphone signal somewhere that normally has a strong signal.<\/p>\n<p>WhatsApp is the most popular instant messenger in a number of countries where the app is used by fraudsters to steal money in an attack known as \u2018WhatsApp cloning\u2019. After a SIM swap, the first thing the criminal does is to load WhatsApp and all the victim\u2019s chats and contacts.<\/p>\n<p>Then they begin messaging the contacts in the victim\u2019s name, citing an emergency and asking for money. In some cases, they feign a kidnapping situation, asking for an urgent payment \u2013 and some of the contacts will send money.<\/p>\n<p>The fraudsters performed a SIM swap, activating the victim\u2019s number on another SIM card. Then, on a smartphone with the pag! app installed, the fraudsters used the app\u2019s password recovery function and a code was sent via SMS, allowing the bad guys to gain total control of the user\u2019s account in the app.<\/p>\n<p>Once this access is obtained the fraudsters performed several illegal payments with the credit card issued in the app in the name of the victim. Some victims reported losses of US$3,300 in fraudulent transactions.<\/p>\n<p><a name=\"_Toc6332023\"><\/a><a name=\"_Toc6331910\"><\/a><strong>How not to be the next victim<\/strong><\/p>\n<ul>\n<li><a name=\"_Toc6332028\"><\/a><a name=\"_Toc6331915\"><\/a> <strong>Voice and SMS must be avoided as authenticity mechanisms<\/strong><\/li>\n<\/ul>\n<p>When possible, we recommend users avoid two-factor authentication via SMS, opting instead for other ways, such as generating an OTP in a mobile app (like Google Authenticator) or using a physical token. Unfortunately, some online services don\u2019t offer an alternative; in that case, the user needs to be aware of the risks.<\/p>\n<ul>\n<li><a name=\"_Toc6332029\"><\/a><a name=\"_Toc6331916\"><\/a> <strong>The new era of biometrics<\/strong><\/li>\n<\/ul>\n<p>Some operators have implemented additional security mechanisms that require the user to authenticate through voice biometrics using a passphrase such as \u2018my voice is my password\u2019 \u2013 the technology works reasonably well, even detecting if the voice is a recording, or if the user has flu. However, the major stumbling block that we observed is the very low enrolment base. Besides, it\u2019s considered an expensive solution, especially for emerging markets, and requires some additional effort to integrate with backend systems.<\/p>\n<ul>\n<li><a name=\"_Toc6332030\"><\/a><a name=\"_Toc6331917\"><\/a> <strong>Automated SMS: \u2018Your number will be deactivated from this SIM card.\u2019<\/strong><\/li>\n<\/ul>\n<p>When a SIM change is requested, operators can implement an automated message that\u2019s sent to the number alerting the owner that there\u2019s been a SIM change request and if it\u2019s not authorised, the subscriber must contact the fraud hotline. This will not prevent the hijacking itself, it will instead alert the subscriber so that they can respond faster in the case of malicious activity. The main drawback is that the subscriber may be outside the coverage area.<\/p>\n<p>Some carriers have implemented an additional layer of confirmation for any case of SIM activation, offering the option of configuring a password in their systems. This password will be required for any changes associated with your number, such as big changes in your monthly bill or even when you need a new SIM card. Talk to your carrier to check if they already offer this additional security for your number.<\/p>\n<ul>\n<li><a name=\"_Toc6332031\"><\/a><a name=\"_Toc6331918\"><\/a> <strong>Process improvement<\/strong><\/li>\n<\/ul>\n<p>As we mentioned above, some processes contain weaknesses, especially in emerging markets. It\u2019s important to dissect all the stages of the process and understand what the underlying weaknesses are. In some countries, there\u2019s a thriving black market that makes it possible to obtain fake documents. These documents can then be presented to operators as proof of identity for SIM swaps.<\/p>\n<ul>\n<li><a name=\"_Toc6332032\"><\/a><a name=\"_Toc6331919\"><\/a> <strong>Activate 2FA on WhatsApp<\/strong><\/li>\n<\/ul>\n<p>To avoid WhatsApp hijacking, it\u2019s of paramount importance to activate\u00a0<a href=\"https:\/\/faq.whatsapp.com\/en\/android\/26000021\/\">2FA<\/a>\u00a0using a six-digit PIN on your device. In the event of hijacking, you\u2019ll have another layer of security that is not so easy to bypass.<\/p>\n<ul>\n<li><a name=\"_Toc6332033\"><\/a><a name=\"_Toc6331920\"><\/a> <strong>Request your number be unlisted from TrueCaller and similar apps<\/strong><\/li>\n<\/ul>\n<p>TrueCaller is a crowdsourced phone book. It allows people to be identified through their mobile number. However, as we mentioned before, fraudsters use this tool to find out more information about you. You can, and should, request that your number is\u00a0<a href=\"https:\/\/www.truecaller.com\/unlisting\">unlisted<\/a>\u00a0from this global phone book.<\/p>\n<p>Despite the fact that attacks on 2FA with the use of tools such as\u00a0<a href=\"https:\/\/breakdev.org\/evilginx-advanced-phishing-with-two-factor-authentication-bypass\/\">Evilginx<\/a> are becoming more sophisticated, software tokens still provide a reasonable level of security by today\u2019s standards. Whilst there is no silver bullet solution, we believe that declaring the death of SMS-based 2FA is the way to go. This is especially true when it comes to online banking, social media and email services.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With mobile phone payments now hugely popular, cybercriminals have been targeting the market in a wave of attacks. With SIM swap fraud nowadays conducted on a large scale, Fabio Assolini, Senior Security Researcher, Global Research and Analysis Team, Kaspersky Lab, tells Intelligent CIO how cybercriminals complete the fraud and the best ways to avoid being [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":29908,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,93],"tags":[1257,11957,6924,1542,11958,11959,11960,11961,4517],"class_list":["post-29780","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-top-stories","tag-cybercriminals","tag-fabio-assolini","tag-kaspersky","tag-mobile","tag-mobile-phone","tag-mobile-phone-payments","tag-sim-sim-swap","tag-sim-swap-fraud","tag-sms"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/29780","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=29780"}],"version-history":[{"count":17,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/29780\/revisions"}],"predecessor-version":[{"id":29909,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/29780\/revisions\/29909"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/29908"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=29780"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=29780"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=29780"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}