Diwali is just around the corner and people are busy purchasing, especially online shopping, as its cool, fast and easy.
Though online shopping has turned out to be easier mode of purchase which is less time consuming and comes with better bargains, it has only become an easy hunting ground for cyber criminals.
Below are some sample cases that illustrate how the spammers have conducted a thorough study of India's online shopping environment, and customized their campaigns accordingly.
Subject: This Diwali Gift Bxxxx - A Rare Collection of Modern & Stylish Home Utility Products
From: "Bxxxx"
The spammer has garbed the domain to show that the message is from an Indian brand. They also used a top level domain in the 'From' line, to trick the user.
In the second sample message, the spammer tries to woo the user by offering a very big discount on branded watches. Similarly, an Indian brand is spoofed to disperse spam using third party mailers.
Subject: DIWALI DHAMAKA Upto 80% Off On Watches, Clothing & Accessories
From: "BXXX TXXXX" admin@XXXXX.org
The spamming process does not stop here. Once the user has started flipping pages on the spammy website, and has chosen items to purchase, spammers shift their gear to phishing, where the user falls into the trap of paying for chosen items in the cart with their debit/credit card details.
Before going on an online shopping spree, Symantec advises users to pay attention to the following:
· Avoid shopping at unknown websites
· Be careful while clicking on offers from forwarded messages
· Do not fall for discounts that turn out to be scams
· Be attentive when doing payments
· Unsecured personal smartphones and mobile devices make online shopping more dangerous
· Beware of third party online shopping applications for your hand held devices that can infect it with malware
· With the increasing use of such utility devices to do online purchases, booking of tickets, shopping, payments, and storage of personal data on-the-go.