Beware Thrones phishing scams

Beware Thrones phishing scams

Global TV sensation spawns scores of dodgy websites.

Among the phishing sites based on Game of Thrones is one masquerading as an official online store.
Among the phishing sites based on Game of Thrones is one masquerading as an official online store.

The final season of Game of Thrones is captivating TV viewers worldwide, but it has also given rise to phishing scams and other online misbehaviour through unlicensed, malicious or fraudulent sites.

Researchers with the cybersecurity vendor Check Point Software have found 42 such unlicensed, malicious or fraudulent sites bent on taking advantage of unsuspecting Game of Thrones fans.

For example, one such site uses the official branding of the show to promote what appears to be a legitimate competition for fans to win a special gift pack of GoT merchandise.

There is, however, no such prize and the site instead collects as many email and mobile phone details as possible that could possibly be used in future spamming campaigns.

Another site aims to dishonestly collect credit card details of users by posing as an official Game of Thrones merchandise store.

While many people may claim to be able to tell the difference between a real site and a fake site, the use of well recognised and trusted brands, like Game of Thrones, is the preferred method for suggesting to the user that the impersonated email or website is trustworthy.

Understanding the threat: The websites observed using the Game of Thrones brand can be split into two main categories: legitimate and fraudulent.

While both categories use the popularity of the brand to lure users in, their motivations are different.

The legitimate websites include fan pages, online games or small shopping sites, looking for potential customers or new community members.

The fraudulent websites, on the other hand, exploit the popularity of the brand to display ads, acquire personal information or convince the user to install an unwanted program.

These fraudulent websites mostly include sites requesting personal information for marketing opportunities, and fake streaming sites, requesting the user to download a browser add-on and provide personal information, while no streaming content is displayed at the end of the process.

How to avoid being a victim: There are ways to prevent being the next victim of a phishing attack. These include:

Think before you click.

Clicking on links on trusted sites should be totally fine. Links that appear in random emails and instant messages, however, often do not end well.

Hovering over links that you are unsure of before clicking on them will tell you if they lead to where you are expecting.

Make sure a site's URL begins with "https" and there is a closed lock icon near the address bar.

Check the site's domain name is the site you are expecting to visit and trust.

If it is not then you could be about to become the next victim of a phishing scam.

Make sure you have an advanced threat prevention solution.

Oren Koren and Hadar Waldman are analysts with Check Point Software.

Do you like the content of this article?

Private school switches to online learning as Covid cases surge

A renowned private boys' school in Silom area will shift to online learning next week, after Covid-19 infections among students and school personnel rose to more than 700 in two months.


Activists accuse Thai officials of conspiring with Myanmar after air intrusion

Activist groups on Thursday called on parliament to investigate whether Thai officials had conspired with the Myanmar military, which led to the intrusion of a Myanmar fighter jet on June 30.


Thai firms may sell record B1.2 tln of new bonds on rate concerns

Domestic companies may sell a record amount of new bonds this year as they aim to lock in borrowing costs before any further increase in interest rates, according to the Thai Bond Market Association (TBMA).