Classrooms have also become a playground for cybercriminals. Universities, students and recent graduates face a new type of fraud that takes advantage of the trust associated with the educational environment to attract victims. Job offers that promise rapid incorporation into the labor market, non-existent scholarships, supposed internship programs or financial aid are used as a decoy to obtain personal and banking information, collect amounts in advance or even access the accounts of those affected.

The problem takes on a special dimension in the university environment, where students and recent graduates constitute a particularly attractive group for scammers. The search for a first professional opportunity or financing to continue studies can lead to lowering one’s guard in the face of communications that imitate the visual identity of a university, a company or a public institution.

All of this provides opportunities to hijack contact lists, as well as leverage the authority of compromised accounts to create more credible hoaxes, extend attacks to personal inboxes, or commit identity theft.

Advance payment fraud

Cybersecurity company Proofpoint has detected malicious campaigns that begin with a deceptive email about a supposed account deactivation, requesting to verify or update the password through web forms in legitimate services such as Google Forms, Wix, Jotform, Zoho Forms and Microsoft Office.

“Many of these websites implement word filters in forms to prevent users from entering sensitive information, such as passwords, which is why cybercriminals tell the victim in which field to enter their password,” Proofpoint threat researchers point out. “The form doesn’t actually reset or update anything. The victim thinks they’ve completed a routine IT task, but now the attacker has valid credentials.”

This ecosystem matches well-known advance payment fraud tactics. To understand how cybercriminals monetize these scams, Proofpoint researchers have interacted directly with several fraudsters. First, they request a resume and ask if the victim has a printer and mobile banking. They then send a scanned check and ask you to deposit it, keep half, and use the rest to purchase gift cards whose codes you must also send them.

If the target did not follow their instructions, the attackers became increasingly insistent to obtain the money in any way possible, suggesting Bitcoin, PayPal and CashApp, to threatening legal action and making an arrest.

The purpose of monetizing any cyber attack

During these interactions with cybercriminals to understand the entire attack chain, Proofpoint researchers have sent several tracking links through Grabify, an IP address logging and URL shortening service that can extract information such as device data and IP addresses. Thus they have determined, according to the study, that these operations were carried out by cybercriminals in Nigeria.

“Although they may spoof their infrastructure, these fraudsters often use a real mobile network to carry out their crimes. Even if fraudsters use a VPN, they often continue clicking on researchers’ links from their own devices, due to their cross-platform communication style and their desire to monetize, despite possible deanonymization,” they detail from Proofpoint.

The good news is that these frauds can be prevented by requiring multi-factor authentication on all accounts, which prevents these users from being seen as easy targets; staying alert for unsolicited job offers, regardless of the platform or application on which they are received; and ignoring requests for money, cryptocurrencies, or payment for goods and services from individuals who claim to be employers.