Showing posts with label scam. Show all posts
Showing posts with label scam. Show all posts

Monday, September 2, 2024

Team Firestorm Warns About Scammers

 
 
 On the Firestorm Viewer today, there was a popup message, warning about scam activity. 

Please be aware that there are currently no Firestorm versions 8, 9, or 10. The latest official release is Firestorm 7.1.9 (74745). For your safety, always download Firestorm from the official source: main firestormviewer.org domain. Make sure to type this address directly into your web browser or click the version number in the top-left corner of the Firestorm splash screen. Do not trust download links shared by non-team members. You can verify if someone is a Firestorm team member by checking their profile and looking for "Firestorm Support/Developer/[Staff]" in the payment information field - the "description" fields, groups list or "picks" do not count. This message will be displayed for a few days due to a recent increase in scam activity - please do not ask in support groups to remove it, or when exactly it will be gone.

While this message is just a temporary one, it's a reminder that scammers are always trying to ways to get into peoples' computers, either to try to find a way to steal something, such as Linden dollars, or just to wreck systems. So one needs to be careful. So as the warning says, don't download any viewer that says "Firestorm" anyplace else but https://www.firestormviewer.org/ . And be aware of other kinds of trickery as well, including friends suddenly acting strangely, repeatedly telling you to click on fishy-looking links - they've been hacked and the hacker is trying to hack you as well.

Bixyl Shuftan
 

Friday, July 12, 2024

Sneaky Discord Scam

 
 
 Been hearing about a diabolical scam on Discord. It's described as appearing as a very obvious one at first, but the REAL scam is the "dismiss message" link, which supposedly gives the scammer access to your computer. 

At the very least, it's a reminder to be a little careful with your computers. 

Tuesday, November 14, 2023

Phishing Scam Viewer Worries Get Linden Lab's Attention

 
It's a sad fact that the Internet is full of scammers. And unfortunately some have come to Second Life.  There's been some news going around recently about one particular phishing scam: a viewer that will supposedly give you unlimited Lindens, and allow you to build anywhere.

Hello,

Are you tired of spending your hard-earned Linden Dollars? We've got an exciting solution just for you! Introducing our SecondLive Viewer, where everything is not only free but also open for endless possibilities.

  • Unlock unlimited Linden Dollars (L$) for all your virtual adventures.
  • Fly to unlimited heights.
  • Build on any land of your choice, all for free.

But that's just the beginning.

Link: <Some URL, typically a tinyurl link>

We're sincerely thankful to everyone who joins us in our mission to make SecondLife completely free. Don't miss this incredible opportunity.

Best Regards.

Most residents would recognize right away these claims are bogus. Viewers can't create Linden dollars, only Linden Lab's computers can do that. One would have to hack into them, and keep hacking to get the virtual money, which would not only be extremely difficult, but easily discovered and traced. Nor can your viewer determine which land you can build on - the permissions of who can and can't are stored in the servers.

Firestorm would express worries of copybot viewers last month before I personally started hearing about the forementioned scam. The scam itself I first heard about when a few people passed me a link to a post made by FelixWolf on GitHub, who would be identified by Inara Pey of Modem World as Chaser Zaks of Team Firestorm who "risked taking a look under the covers of the code that is supplied."

What the viewer actually does is run a program called builddata.bat on your computer, which installs a number of remote administrative toolkits (or RATs). Once your machine is infested with these RATs, the scammer can:

Steal your Linden dollars and go through your inventory

Steal your password and hijack your account, and whatever they do, people (and Linden Lab) will think it's you.

Go into your computer and steal/delete your files.
 
Steal your banking and credit card information, and steal your real-world money, and possibly ruin your credit.
 
Discover real-life information on you, such as your city and street address. 
 
Activate your camera and take pictures of you and the contents of your room. If they get your real-life location, they may know where to find valuable items to steal. 

Last Thursday, Linden Lab would feel the need to remind it's residents of the dangers of phishing scams in general, "Ensuring A Secure Second Life Experience." It brought up this particular viewer, "
It is important to remember that downloading software from unknown sources has a very real risk associated with it. You could unintentionally allow someone to monitor your keystrokes or even gain complete control over your computer. It has the potential to expose not just your Second Life password, but all other important information you have on your computer. ... Be wary of suspicious links or attachments sent by other users. These may be attempts to compromise your account or computer. ... Only download and install the official Second Life viewer, or an approved Third-Party viewer directly from the links provided by our site."
 
So once again, a reminder that one needs to be a little wary when going about Second Life (and the Internet in general), and don't let yourself get a RAT infestation. 
 
Bixyl Shuftan 

Thursday, April 6, 2023

New Phishing Scheme on The Firestorm Viewer

 
There is a new phishing attempt that surfaced today. A dialog box will say you are about to be logged off, and that you should enter your password. Obviously you should not enter your password, but instead file an abuse report against the sender.
 
From Team Firestorm 

Image credit: Duchess of Trikassi

Correction: The scam does not appear to be limited to Firestorm, but may appear on any viewer.

Wednesday, January 22, 2020

Invisiprim Scammer Trick Story Going Around


In real life, many of us check ATM machines for "skimmers" before using them. To those of you who don't know, these are false fronts attached over an ATM's card slot by hackers, which scan the cards as they're going in and read account and PIN numbers. With this in mind, it was probably inevitable someone would find a way to scam Second Life shoppers. Yesterday, this was posted in one group I'm in, and saw something similar in the Second Life Friends Facebook group.

I have read in some groups that scammers are now going to events and stores. They place large invisible prims over the vendors, so when you pay the vendor for an item you want to purchase, you are actually paying money to the scammer and you will not receive the item you payed for. ALWAYS check and double check that you are paying the correct person.

One trick would be to 'Highlight Transparent' to see if there is anything transparent over the vendor. If you use Firestorm, go to the 'Advanced' menu ---> Highlighting and Visibility ---> Highlight Transparent (or 'Ctrl + Alt + T' on your keyboard). If you see a red semi-transparent prim hanging over the vendor you might want to cam in behind it to the actual vendor or not buy it until the prim has been removed.

You may also want to alert the real vendor.


So if anything seems amiss with the vendors while shopping, check them over.

Friday, August 26, 2016

Scammer Alert: Unauthorized Full Perm Item Resales Reported on Marketplace


By Bixyl Shuftan

Strawberry Singh recently wrote about an apparent problem on the Second Life Marketplace after being contacted by the maker of full permissions, or Full Perm, items which he sold on Second Life's Marketplace. Unscrupulous individuals are taking such items, and placing copies up for resale on Marketplace, not bothering to get permissions or give any kind of compensation to the content creators. Unless the offending party agrees to take down the items themselves after being contacted, the only recourse for the creators is to file a DMCA (Digital Millennium Copyright Act) takedown request with Linden Lab "over and over until they are taken down, but then they must also DMCA items that are being sold by people who have bought these illegal full perm items and are selling them in their stores thinking they have a legal copy of the item."

Unfortunately, while sometimes this is the end of the ripoff, sometimes it continues, "A DMCA take down usually takes a week to be taken down, but the next day, that account puts it right back on that same Marketplace as a new listing."

Strawberry offered the following suggestions of "some of the things that you should look for and be aware of before making a purchase."


Before purchasing look at the seller’s other listings. If there is a hodgepodge of brand names and the vendors all look different, they are most likely an illegal seller.

Purchase the items from the inworld store of the full perm creator instead of the marketplace, to ensure that you are not purchasing from an illegal seller.

Most of the illegal sellers have blank profiles. Real full perm sellers usually have a full profile filled with links to their websites, mainstores and marketplace stores.

Most Full Perm sellers have started using water marks on the vendor ads which say the name of the avatar that is supposed to be selling it. The illegal sellers are still using those ads, even with the watermark. So it is important to look at the name of the creator on the watermark, and if it isn’t that person selling it, don’t buy it.

Try to find a way to report these items, either to Linden Lab by flagging the listing or to the original creator of the items.



That among her suggestions is not using Marketplace to purchase these items, Hamlet Au, who also wrote about the issue, called this, "Ironic, because a key point of the Marketplace existing at all is it makes online shopping for virtual content much more convenient than having to go rooting around for items in the full 3D client." Hamlet would go on to say Strawberry felt Linden Lab's options for dealing with this problem were limited.

"I honestly don't think they can because for them it would be hard to tell who is a valid seller without someone informing them at first and that's why the DMCA needs to happen." She was quoted as telling Hamlet, "If they went around closing accounts of people they suspect might be doing this without someone claiming it first, then they could potentially close some innocent accounts."

One possible solution, Strawberry suggested, was closing the accounts of those DMCAs had been filed against. But the Lab would need to be careful about unfairly shutting down creators whom are the target of false reports. Doing to would take time and resources (and money)by the Lab. But as Hamlet put it, "doing that would cut into Second Life's steadily shrinking profit margin. Then again, alienating content creators by not giving them a secure market also is also a profit-limiting move."

Among those leaving comments after Hamlet's article, one resident compared the problem to selling real life goods if they were easily duplicated in a fast-operating and extremely cheap to operate 3D printer. The person felt if someone was selling something completely Full Perm, rather than copyable but not transferable or transferable but not copyable, the seller was taking a chance, except perhaps if such items were useful only as parts to make a more detailed good.

Sources: Strawberry Singh, New World Notes, Modem World

Bixyl Shuftan

Friday, August 19, 2016

Man Pleads Guilty to Second Life Land Fraud in Real Life Court


While the goings-on in virtual worlds are beyond the understanding of many in real life, the court system found a scam involving thousands of dollars done online clear enough to bring to real life court. In this case, a man plead guilty to swindling a woman in a Second Life real estate deal.

In April 2015, Joshua Bills was arrested and charged with fraud. The crime: a virtual real estate scam, "In the complaint, it stated that a loan agreement was made with Bills for $53,500 for the purposes of expanding his online real estate company. Bills was to use the money to purchase land that he would manage through his company, within the game Second Life, in exchange for a promissory note that would pay $10,000 for the investment within 24 months."

The woman whom was targeted had been renting a home in Second Life from Bills. Then, "He suggested she invest with him to buy more land within the game so he could manage it and make both of them money." But instead of investing the money as promised, the majority of it went to his E-Trade investment account.

Indiana Securities Commissioner Alex Glass commented in a statement, "This was certainly a unique case in that it dealt with online, virtual real estate. However, upon examination of the facts, this case is very similar to a conventional real estate investment scheme. Con artists are always finding new and unique ways to scam trusting individuals out of their hard earned money."

Bills plead guilty in Marion County Indiana court. He was sentenced in late July to three years probation, and ordered to repay the woman he defrauded in full.

Hamlet Au of New World Notes, which also wrote about the case, commented, "this conviction helps establish a legal precedent for future prosecution of other virtual scams."

Sources: Business Weekly, ind.gov 

Bixyl Shuftan

Thursday, August 29, 2013

Greed in Stores


For some in Second Life, shopping is a fun experience, and they take plenty of time to go about and see what places have what item for how much. While there's no shortage of customer-friendly stores and malls on the Grid, not everyone it seems has the buyer's interests at heart. Theonlyjohnny Resident writes about two places he came across which to him were charging a lot for just a little.

Read Theonlyjohnny's article in Extra.

Wednesday, August 21, 2013

Marketplace Problems


The Marketplace isn't always what it's cracked up to be. But sometimes one has to worry more about glitches. Theonlyjohnny has a few things to say about the trouble he had with shopping via the Marketplace from his search jammed full of demo items to being outright scammed.

Read Theonlyjohnny's article in Extra.

Friday, November 2, 2012

Phony Relay for Life "Agent" Scamming Well Meaning Residents

In the Relay for Life chat a few days ago, one of the Relayers had some news, "I need to report something to you all and ask you to watch out and spread the word. Giving you a heads up, there's been a newbie running around various sims that sponsor RFL, claiming he's an agent … and to please donate L$'s to him." "Him again?" groaned another member. It was mentioned that the Relay sponsoring sims were banning him, but, "The problem is if he goes to sims NOT connected to RFL, where he might (seem) more plausible."

While it's not normally illegal to solicit money for charity, claiming to do so as an "agent" of the Relay for Life when one isn't certainly counts as fraud. So this individual, and anyone else like him, is liable to have his account, alts and all, banned. And if the Lab sees fit to notify the police, there is the possibility of arrest and jail time.

But until he's caught, the Relayers remind all that they collect their Lindens through kiosks. And of course the Relay for Life is a fundraiser for the American Cancer Society.

Bixyl Shuftan

Thursday, October 25, 2012

Scam Alert

Be warned!!

There IS a scam going around of people claiming to be from Microsoft Corporation. That your computer is heavily infected and they want to assist you in removing this infection that is hindering or corrupting your computer.

There I was, just in from work and I get a unknown phone call showing a unknown number.

(Red Flag One)

The person introduced themselves as a service tech from Microsoft Corporation. That my computer was reported as one on their list as being heavily infected. 

(How would they know this?  Red Flag two) 

The gentleman, obviously from India with his accent proceeded to walk me through the steps of opening up my computer management window

Steps as Follows:
1)Click Start
2) Hover over my computer option and right click
3)Select “Manage”
The computer management window opens

 (Oh wow, neat. I had wondered where that was)

The gentleman proceeded to have me to look at the left side for the option of “Event Viewer”  once found to click and open that.  He then instructed me to look for an option of “Application”, once found to click it and open it. 

(This guy knows his stuff, ok I’ll play along)

He then had me to scroll down the middle window and look for errors and warnings.  This guy said “If you have more then 5 to 10 of these errors or warnings, that your computer has been compromised.” 

(I at this point was thinking, “Oh sh*t he’s right I got a bug in my system”)

This technician further proceeded to have me to look back to the left side under “Window Logs”  and look for “System”.  That I had to click and open that as well. The middle window populates and the tech again warns me not to click anything here, that I could inadvertently cause damage but to again look for errors and alerts. Again anything over 5 to 10 of these and it is confirmed that my system was compromised. As I scrolled down and looked at all these errors and alerts, I got pissed at myself because I had somehow allowed my computer to be infected.

This computer tech now tells me to minimize the computer management window and open my web browser. He was going to assist me in removing this infection.

(I at this point was like, “Cool, I gets help to rid myself and my computer of these problems”)

I opened my web based browser, Google Chrome and the tech tells me to type, “www.teamviewer.com” in the address bar. I being a naïve fool did so and went to the Teamviewer website.  As soon as I seen what this was I stopped. Teamviewer is one those pieces of software that you use to give complete access of your computer to somebody else. 

(Jazzy sense tingling and a HUGE red flag waving in my face)

I immediately opened another tab and googled “people calling from Microsoft claiming to be helping with errors” Now what you think I found there?

“Hoax Microsoft Windows security calls..”
“Beware cold calls from people claiming to be from Microsoft”
Scam Alert..”
I chose the 4rth option on the list “I received a phone call from Microsoft claiming I have a virus”

This window opens:

 http://answers.microsoft.com/en-us/windows/forum/windows_vista-security/i-received-a-phone-call-from-someone-claiming-i/4489f388-d6de-416d-9158-0079764bb001

Oh wow somebody else had the exact type of call and was cautious.  Scrolling down the list of answers I seen one statement that stood out that rang true.

“If you have not opened an incident (ticket for Support) with Microsoft, they do not contact you.”

Good ole Jazzy sense saves my bacon yet again.  I then asked the “tech” why after years of faithful service and all the tickets I’ve filed, that they decided to call and attempt to help now. Why I had to download Teamviewer, and why would I want to give complete  access of my computer to a complete stranger.

He sputtered, mumbled and tried to say again that he had my best interests in mind.  Sure he did.. bastard just wanted access to my computer, these same people have been reported to get access, make unwanted changes and to also leave a virus on your computer that gathers your personal information, your banking information and your browsing history and then send it to wherever in the world so they can steal your life, your funds and your livelihood. 

I was pissed at this point at both this “tech” for leading me on. At myself because I almost bought into his scam. Immediately I hung up and deleted the install file for the Teamviewer software that I had downloaded.  Used the suggestions given at answers.microsoft.com and did a complete scan on my computer

“Run the Microsoft Malicious Removal Tool

Start - type in Search box -> MRT  find at top of list - Right Click on it - RUN AS ADMIN.”

While that scan was running I read down further that I should report this scam to the proper authorities.

Needless to say now the Federal Trade Commission knows that these scammers have targeted my area.

Can go here for more information:
  http://www.ftc.gov/bcp/edu/pubs/consumer/telemarketing/tel19.shtm
 
Also while I had the lady on the horn, I had my number put on the National No Call Registry
https://www.donotcall.gov/

For an extra kick in the pants, tomorrow I’ll be making a call to my states Attorney General’s office to report this scam. Per the instructions of the lady that I spoke with of the FTC.

Listen folks, these people are good! They make themselves sound like the real deals but know that Microsoft WILL never call your home or place of business. Microsoft will never ask for access to your personal computer or business computer.

Watch for the red flags, unknown numbers, instructions for you to download any type of software that gives them complete access to your computer.  Once you see these, stop the call.. Stop the scam and report it right then.  Report it to your local law enforcement, the Federal Trade Commission.  Just let people know, all your friends and family; let them know to be on the watch for these scammers that would fleece them without thinking.  That scan I did of my system..no malicious software was detected.

Parting words:
Never, never, never, NEVER give a complete stranger access to your computer. Not through software or just sitting in front of it. You don’t know what they might do or leave you.

Jasmine Dawn Shuftan

Monday, January 9, 2012

Phishing Scam

Xymbers Slade recently found something in one of his groups, "Just got this out of one of the Mentor groups I'm a part of --- those scammers just never seem to give up. So spread the word, that this one's a scam."


Dear Second Life user,

Due our latest IP Security upgrades we have limited access to sensitive Second Life account features.
Protecting the security of your account is our primary concern
We understand that this may be an inconvenience.
Please understand that this temporary limitation is for your protection.

How can I restore my account access?

Please download the form attached to this email and open it in a web browser.
Once opened, you will be provided with steps to update your account.
We appreciate your understanding as we work to
ensure account safety.

If we detect a sign in with your username from another country we may decide that we want to
confirm that it's really you. You must complete all steps otherwise you will not be able to use
the online service until we have completed additional security checks.


We apologize for any inconvenience

Copyright 2011 Linden Research, Inc. Linden Lab 945 Battery St. San Francisco, CA 94111


It should be reminded that it's not just Mentor groups open to such swindels, but any with open enrollment.