<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Research Laboratory &#8211; Bitfinance</title>
	<atom:link href="https://bitfinance.news/en/etiqueta/research-laboratory/feed/" rel="self" type="application/rss+xml" />
	<link>https://bitfinance.news</link>
	<description>Fintech &#38; new economy info</description>
	<lastBuildDate>Mon, 01 Sep 2025 13:27:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://bitfinance.news/wp-content/uploads/2025/01/favicon-64.png</url>
	<title>Research Laboratory &#8211; Bitfinance</title>
	<link>https://bitfinance.news</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Investor scams on social media are on the rise with the help of artificial intelligence</title>
		<link>https://bitfinance.news/en/investor-scams-on-social-media-are-on-the-rise-with-the-help-of-artificial-intelligence/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Mon, 01 Sep 2025 13:00:52 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Financial security]]></category>
		<category><![CDATA[Alert]]></category>
		<category><![CDATA[Camilo Gutiérrez Amaya]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Cyberscams]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[deception]]></category>
		<category><![CDATA[ESET Latin America]]></category>
		<category><![CDATA[ESET Venezuela]]></category>
		<category><![CDATA[increase in fake ads]]></category>
		<category><![CDATA[Investor scams on social media]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[promises of profits]]></category>
		<category><![CDATA[protection]]></category>
		<category><![CDATA[Research Laboratory]]></category>
		<category><![CDATA[Safeguard]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Warning]]></category>
		<category><![CDATA[with the help of artificial intelligence]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=115699</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1244" height="700" src="https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="El incremento de anuncios falsos, deepfakes y promesas de ganancias busca engañar incluso a las personas más cautelosas. ESET advierte de un crecimiento del 335% en las amenazas del troyano tipo Nomani, lo que llevó al bloqueo más de 8.500 dominios relacionados" decoding="async" fetchpriority="high" srcset="https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R.jpg 1244w, https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R-300x169.jpg 300w, https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R-1024x576.jpg 1024w, https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R-768x432.jpg 768w" sizes="(max-width: 1244px) 100vw, 1244px" /></div><p>Faced with financial doubts and concerns, it&#8217;s no surprise that people are looking for alternatives to make their money go further. This leads users with little investment experience to become interested and take their first steps. ESET, a leading company in proactive threat detection, warns that scammers are taking advantage of this curiosity or need [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/investor-scams-on-social-media-are-on-the-rise-with-the-help-of-artificial-intelligence/">Investor scams on social media are on the rise with the help of artificial intelligence</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1244" height="700" src="https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="El incremento de anuncios falsos, deepfakes y promesas de ganancias busca engañar incluso a las personas más cautelosas. ESET advierte de un crecimiento del 335% en las amenazas del troyano tipo Nomani, lo que llevó al bloqueo más de 8.500 dominios relacionados" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R.jpg 1244w, https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R-300x169.jpg 300w, https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R-1024x576.jpg 1024w, https://bitfinance.news/wp-content/uploads/2025/09/Imagen-referencial-Aumentan-las-estafas-a-inversores-en-redes-sociales-con-la-ayuda-de-la-inteligencia-artificial-Suministrada-por-ESET-y-Comstat-R-768x432.jpg 768w" sizes="(max-width: 1244px) 100vw, 1244px" /></div><p style="text-align: justify;">Faced with financial doubts and concerns, it&#8217;s no surprise that people are looking for alternatives to make their money go further. This leads users with little investment experience to become interested and take their first steps. <strong><a href="https://www.eset.com/latam/" target="_blank" rel="noopener">ESET</a></strong>, a leading company in proactive threat detection, warns that scammers are taking advantage of this curiosity or need with increasingly sophisticated scams on social media. It also warns that AI-powered scams produce fake ads, deepfakes, and promises of profits that seek to deceive even the most cautious users.</p>
<p style="text-align: justify;"><em>“Could you distinguish between a real investment ad and a fake one? It&#8217;s becoming increasingly difficult to do so. Threat actors today have various tactics to make their scams more credible, including deepfake videos generated with artificial intelligence. While there are many tactics, techniques, and procedures (TTPs) associated with this type of fraud, most begin with malicious or deceptive ads circulating on social media. They are often used as a lure to trick the victim, either into providing personal information or directly directing them to an investment scam,”</em> says <strong>Camilo Gutiérrez Amaya, Head of the ESET Latin America Research Lab.</strong></p>
<p style="text-align: justify;">According to the <a href="https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf" target="_blank" rel="noopener">FBI</a>, investment scams have been the main source of income for cybercriminals for several years. At last count, they earned nearly $6.6 billion, and that&#8217;s just from crimes reported to the federal government. This figure dwarfs the $2.8 billion earned by the second-largest scam, <a href="https://www.welivesecurity.com/2022/04/26/trouble-bec-how-stop-costliest-scam/" target="_blank" rel="noopener">business email compromise</a> (BEC).</p>
<p style="text-align: justify;">An <a href="https://bitfinance.news/en/vegetable-production-in-venezuela-increased-30/" target="_blank" rel="noopener">example of this type of campaign</a> was identified in June 2025, when Instagram ads impersonated legitimate banks. Some used tempting offers, such as high-interest accounts, in an attempt to persuade the victim to click and enter their banking information. In other cases, they used deepfake Instagram stories featuring banking investment strategists to collect personal information and/or lure them into WhatsApp groups about investment scams. A 2024 campaign spread a fake video of <a href="https://bitfinance.news/en/china-secures-oil-supplies-from-russia/" target="_blank" rel="noopener">Lionel Messi to promote supposed investments</a> through an app that promised high returns.</p>
<p style="text-align: justify;">Also in 2024, <a href="https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22024.pdf#page=17" target="_blank" rel="noopener">ESET observed the Nomani Trojan campaign</a>. The ad content and the phishing websites they linked to were designed to impersonate local news outlets and other organizations. Or, it could be a generic financial-themed visual with frequently changing names like &#8220;Quantum Bumex, Immediate Mator, or Bitcoin Trader.&#8221; Some of the characteristics of the Nomani campaign (and other similar campaigns) include:</p>
<ul style="text-align: justify;">
<li>Highly localized content to attract specific regional victims.</li>
<li>Distribution via fake ads on Facebook, Instagram, X, YouTube, as well as Messenger and Threads.</li>
<li>Deepfake video testimonials potentially using celebrities, often displayed in low-quality videos and with unnatural keyword repetition.</li>
<li>Use of fake and hacked accounts to run the ads (including, in one case, an <a href="https://www.welivesecurity.com/en/scams/hijacked-hacked-youtube-channels-scams-malware/" target="_blank" rel="noopener">actor with 300,000 followers</a>).</li>
<li>Shared templates and callbacks pointing to the same hosting infrastructure.</li>
</ul>
<p style="text-align: justify;">In this campaign, according to ESET, the intended objective is to persuade the victim to provide their personal information, which the scammers use to contact them directly. They use this method to trick them into signing up for an investment scam, <a href="https://www.welivesecurity.com/en/scams/borrower-beware-common-loan-scams/" target="_blank" rel="noopener">taking out a loan</a>, or even installing remote access software on their device. <strong>ESET observed a 335% increase in Nomani threats between H1 and H2 2024, and blocked more than 8,500 related domains.</strong></p>
<p style="text-align: justify;">While these techniques seem like clear indicators of fraud, they can be much more difficult to detect, especially if you are looking for opportunities to alleviate financial pressures. ESET states that the <a href="https://www.welivesecurity.com/2022/05/12/10-reasons-why-we-fall-scams/" target="_blank" rel="noopener">continued effectiveness of these types of scams</a>, such as fraudulent financial ads, is due to the following:</p>
<ul style="text-align: justify;">
<li>Times are tough, and the prospect of quick and easy financial gain is attractive.</li>
<li>Attention spans are decreasing, especially on mobile devices, so warning signs may not be detected in time.</li>
<li>Many people are unfamiliar with the latest threat TTPs, such as the use of deepfake videos, which makes them more vulnerable.</li>
<li>Many of these threats are localized, use legitimate (hijacked) accounts, and can appear at the top of search results.</li>
<li>Banks&#8217; traditional anti-fraud mechanisms often don&#8217;t work if the manipulation is also carried out socially via telephone to invest in a fraudulent scheme.</li>
</ul>
<h3 style="text-align: left;">Investment scams are very common, and ESET points out that it&#8217;s necessary to pay attention to these warning signs</h3>
<ul>
<li style="text-align: justify;">Flashy ads (which may leverage legitimate brands) offering returns that are too good to be true or unusually high interest rates.</li>
<li style="text-align: justify;">Celebrity endorsements are often the hook to give the product a certain legitimacy. Always check if the endorsement is legitimate.</li>
<li style="text-align: justify;">Videos that don&#8217;t look entirely right, for example, with visual glitches, poor audio and video synchronization, low resolution, or robotic or overly polished voices.</li>
<li style="text-align: justify;">Pressure to act quickly and secure the investment.</li>
<li style="text-align: justify;">Guaranteed return on investment.</li>
</ul>
<p style="text-align: justify;">They also advise staying alert to warning signs, resisting the temptation to click on ads about finance or investments, even if they appear to be promoted by legitimate brands and individuals, searching online for reviews of a specific investment plan or group to verify their authenticity, not investing in financial products without having thoroughly researched them and understanding how they work, ignoring any unsolicited third-party offers, never sharing personal and/or financial information after clicking on an online ad, and always checking the information circulated with the supposedly issuing entity through official channels. Finally, <strong>use security software</strong> <strong>on all your devices </strong>from a trusted provider <a href="https://bitfinance.news/en/vegetable-production-in-venezuela-increased-30/" target="_blank" rel="noopener">like ESET</a>, which will help block scams.</p>
<p style="text-align: justify;">“In times of economic uncertainty, it&#8217;s understandable that we look for alternatives to improve our financial situation. But scammers are exploiting this very need with increasingly sophisticated tactics. Therefore, being wary of what&#8217;s easy, recognizing the warning signs, and protecting your personal data is essential to avoid falling for this type of scam,” concludes the ESET researcher. ESET invites you to learn more about cybersecurity by visiting:  <a href="https://www.welivesecurity.com/es/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://www.welivesecurity.com/es/&amp;source=gmail&amp;ust=1756810847233000&amp;usg=AOvVaw2ji62LZTXjdo6UzrkQHffK">https://www.welivesecurity.com/es/</a>.</p>
<p style="text-align: justify;">For other useful preventive information, it is also available in Venezuela:  <a href="https://www.eset.com/ve/" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://www.eset.com/ve/&amp;source=gmail&amp;ust=1756810847233000&amp;usg=AOvVaw0tO0ykjxd09rJ178m-eJ5P">https://www.eset.com/ve/</a>, and on its social media channels @eset_ve. Also, available on Instagram (<a href="https://www.instagram.com/esetla/" target="_blank" rel="noopener">@esetla</a>) and Facebook (<a href="https://www.facebook.com/ESETLA" target="_blank" rel="noopener">ESET</a>).</p>
<p style="text-align: justify;"><em>Bitfinance.News</em></p>
<p>With information and reference image provided by ESET and Comstat Rowland</p>
<p><em>Visit our news channel on </em><a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener"><em><strong>Google News</strong></em></a><em> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on </em><a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener"><em><strong>X/Twitter</strong></em></a><em> and </em><a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener"><em><strong>Instagram</strong></em></a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/investor-scams-on-social-media-are-on-the-rise-with-the-help-of-artificial-intelligence/">Investor scams on social media are on the rise with the help of artificial intelligence</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Betting on video games: a worrying trend on children and adolescents</title>
		<link>https://bitfinance.news/en/betting-on-video-games-a-worrying-trend-on-children-and-adolescents/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Mon, 02 Sep 2024 12:00:59 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Financial security]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[Other topics]]></category>
		<category><![CDATA[addictions]]></category>
		<category><![CDATA[Camilo Gutiérrez Amaya]]></category>
		<category><![CDATA[children and adolescents]]></category>
		<category><![CDATA[Comprehensive health]]></category>
		<category><![CDATA[ESET Latin America]]></category>
		<category><![CDATA[gambling]]></category>
		<category><![CDATA[Gambling on video games]]></category>
		<category><![CDATA[Gamer's Day]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[Research Laboratory]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=108756</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="798" src="https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="En el contexto del Día del Gamer, celebrado el 29 de agosto, ESET advirtió que nuevas dinámicas en los videojuegos abren una puerta peligrosa a la adicción" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes.jpg 1200w, https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes-1024x681.jpg 1024w, https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes-768x511.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p>The world of video games has changed its income dynamics: it is no longer enough to buy the game, but now a range of possibilities opens up for users to acquire certain items to progress or obtain benefits, which has a second or dangerous side that grew after the pandemic and that many families are [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/betting-on-video-games-a-worrying-trend-on-children-and-adolescents/">Betting on video games: a worrying trend on children and adolescents</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="798" src="https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="En el contexto del Día del Gamer, celebrado el 29 de agosto, ESET advirtió que nuevas dinámicas en los videojuegos abren una puerta peligrosa a la adicción" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes.jpg 1200w, https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes-1024x681.jpg 1024w, https://bitfinance.news/wp-content/uploads/2024/09/Imagen-referencial-Apuestas-en-videojuegos-una-tendencia-que-preocupa-en-ninos-y-adolescentes-768x511.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p style="text-align: justify;">The world of video games has changed its income dynamics: it is no longer enough to buy the game, but now a range of possibilities opens up for users to acquire certain items to progress or obtain benefits, which has a second or dangerous side that grew after the pandemic and that many families are already dealing with: <strong>gambling.</strong></p>
<p style="text-align: justify;">In the context of<strong> Gamer&#8217;s Day,</strong> August 29, <a href="https://www.eset.com/latam/" target="_blank" rel="noopener"><strong>ESET</strong></a>, a leading company in proactive threat detection, analyzes the world of betting and video games, the addiction it can generate in children and adolescents, and the role of influencers They benefit when users lose. In addition, it shares what measures countries are taking in response to this situation and <strong>what actions mothers and fathers can take to help and guide their children.</strong></p>
<p style="text-align: justify;"><em>“Not many years ago, video games used to be a one-time purchase: that already guaranteed the complete experience. But currently, companies in the industry often offer their users video games for free, with </em><a href="https://es.egamersworld.com/blog/skins-betting-everything-you-need-to-know-hbO8CD6mAi" target="_blank" rel="noopener"><em>“loot boxes”</em></a><em> and other in-game transactions being the most important source of income,” </em>says <strong>Camilo. Gutiérrez</strong> <strong>Amaya</strong>, Head of the <strong>ESET Latin America Research Laboratory.</strong></p>
<p style="text-align: justify;">“LOOT BOXES” are a specific monetization dynamic that is represented in products that can be purchased at some specific stage of a game. They can hide elements or rewards highly valued by the communities. Of course, they have a cost and their content is random. They acquired such an important status that an economy even emerged based on them, and they can even be used to bet on third-party sites.</p>
<figure id="attachment_108754" aria-describedby="caption-attachment-108754" style="width: 855px" class="wp-caption alignnone"><img decoding="async" class="wp-image-108754 " src="https://bitfinance.news/wp-content/uploads/2024/09/1.png" alt="Example of Loot Boxes, or loot boxes. Source: www.gov.uk" width="855" height="533" srcset="https://bitfinance.news/wp-content/uploads/2024/09/1.png 484w, https://bitfinance.news/wp-content/uploads/2024/09/1-300x187.png 300w" sizes="(max-width: 855px) 100vw, 855px" /><figcaption id="caption-attachment-108754" class="wp-caption-text">Example of Loot Boxes, or loot boxes. Source: www.gov.uk</figcaption></figure>
<p>&nbsp;</p>
<p style="text-align: justify;">Something that began as a game, over time, became a great concern for parents and even governments because its <a href="https://www.mundovideo.com.co/marketing-para-casinos/como-los-skin-estan-revolucionando-la-industria-de-las-apuestas-online" target="_blank" rel="noopener">casino-style betting</a> format to obtain and market them encourages addictive consumer spending. This is also enhanced by the great accessibility that mobile devices allow and the little (or no) control that exists regarding the age of majority of users on these platforms.</p>
<h3 style="text-align: left;"><span style="color: #000080;">Child and adolescent gambling</span></h3>
<p style="text-align: justify;">The consequences can be very serious: from generating an addictive habit in users, such as <a href="https://www.clarin.com/tecnologia/nene-gasto-1-800-dolares-videojuegos-papa-vender-auto-pagar-tarjeta_0_QLlNsTuFP.html" target="_blank" rel="noopener">debt for large sums of money</a>, often unknown to the parents themselves. Thus,<strong> child and adolescent gambling addiction</strong> emerges as a gambling addiction in minors, which manifests itself in compulsive behaviors in video games and online betting, among others.</p>
<p style="text-align: justify;">Beyond this, large video game franchises such as Candy Crush, Fornite, FIFA, League of Legends, or Final Fantasy continue to launch titles whose income to offset the cost of developing the game itself depends largely on “loot boxes.” or microtransactions. So much so that recent studies estimate that by 2025 “loot boxes” will generate more than <a href="https://as.com/meristation/2021/03/10/noticias/1615367483_569117.html" target="_blank" rel="noopener">$20 billion</a>.</p>
<p style="text-align: justify;">“The “loot box” mechanics literally work like any casino: the user must replenish the account with monetary funds, then place their bet, and finally wait for the graphics to spin to find out if they won or lost. This is how the service that video games have offers <a href="https://www.abc.es/tecnologia/videojuegos/abci-cajas-botin-videojuegos-apuestas-online-segun-regulador-juegos-azar-espanol-201809180946_noticia.html" target="_blank" rel="noopener">alarming similarities</a> with the characteristics of an online casino: in fact, they imitate roulette and even slot machines,” adds the ESET researcher. The fundamental difference between casinos and the dynamics proposed by video games is that the latter do not have a gaming license from any official body and, in many cases, they do not offer reliable verification that prevents those under 18 years of age from placing their bets. . It is worth remembering that it is illegal for a minor to place bets.</p>
<p style="text-align: justify;">The link between video games and betting is, in certain cases, enhanced by the figure of influencers, who play a key and at the same time ambiguous role in the growth of this problem. This is because many of them promote betting platforms or give recommendations that, directly or indirectly, lead their followers to make bets that logically can end in losing money.</p>
<p style="text-align: justify;">What stands out within this dynamic is that there are several influencers who receive payments and commissions from these betting platforms, but based on the money losses of their followers. The conflict of interest is as clear as it is controversial, influencers have a financial incentive for their followers to lose money instead of earning it.</p>
<h3 style="text-align: left;"><span style="color: #333333;">A serious problem</span></h3>
<p style="text-align: justify;">A real example of this was <a href="https://www.bbc.com/news/technology-36702905" target="_blank" rel="noopener">what happened in 2016</a> with YouTubers TmarTn and Syndicate, who promoted Counter Strike skin betting sites and were accused of not disclosing that they had their financial interests in the pages they promoted. In both cases they earned money from visits to each of their videos, but also from users&#8217; losses on the betting sites they promoted and which they even owned.</p>
<p style="text-align: justify;">To counteract this trend, many countries have taken this scenario as a serious problem, and that is why they have begun to enact laws and regulations against the operation of sites that operate in a gray zone, without official license or adequate controls.</p>
<p style="text-align: justify;">In Argentina, for example, the government of the city of Buenos Aires sent letters to <a href="https://buenosaires.gob.ar/noticias/la-ciudad-traves-de-lotba-denuncio-l-gante-y-al-streamer-joaquin-lopez-por-promocionar" target="_blank" rel="noopener">a large number of influencers because they advertised</a> on their social networks for online gambling platforms.</p>
<p style="text-align: justify;">In the United States, for their part, they took concrete actions to regulate young people&#8217;s access to online betting sites. In fact, there are laws that force these websites to implement more advanced age verification technologies and others that limit the amount of money that can be bet.</p>
<p style="text-align: justify;">Another case is that of the United Kingdom, a country in which the Betting Commission implemented very strict regulations that aim to <a href="https://www.gamblingcommission.gov.uk/licensees-and-businesses/guide/page/influencer-affiliate-and-agency-controls#:~:text=Affiliates%20and%20influencers%20must%20appropriately,and%20geo%20targeting%20is%20applied." target="_blank" rel="noopener">limit the advertising of games of chance</a> and access to minors, while in <a href="https://www.mdsocialesa2030.gob.es/comunicacion/noticias/derechos-sociales/20240604-consejo-ministros-loot-boxes.htm" target="_blank" rel="noopener">Spain</a> they prohibit the access of minors to the loot boxes to prevent addictive behavior and in Australia reforms were introduced whose main objective is to have stricter controls on the identity of users to also prevent the development of future addictions.</p>
<p style="text-align: justify;">To accompany the little ones in their interactions on the Internet, the first step is not to underestimate the underlying problems between video games and gambling. <a href="https://www.unir.net/actualidad/investigacion/los-menores-que-compran-cajas-de-botin-tienen-dos-veces-mas-riesgo-de-apostar-online-en-solo-medio-ano-segun-un-estudio-de-unir/" target="_blank" rel="noopener">Recent studies</a> suggest that “loot box” purchases and similar habits can lead to children and adolescents developing future gambling and other <a href="https://tn.com.ar/sociedad/2024/05/15/ludopatia-la-nueva-adiccion-de-los-chicos-el-riesgo-de-las-apuestas-online-y-la-promesa-de-ganar-plata-facil/" target="_blank" rel="noopener">severe problems</a>.</p>
<h3 style="text-align: left;"><span style="color: #008000;">Support and advice</span></h3>
<p style="text-align: justify;">To avoid this, ESET shares concrete actions that can be implemented to accompany and advise children in the midst of this worrying scenario:</p>
<ul style="text-align: justify;">
<li>Have conversations with children/teenagers about their online activities and interests.</li>
<li>Provide information about what gambling addiction is and its consequences.</li>
<li>Carry out a joint analysis of betting advertisements, so that they can make good decisions and incorporate good habits.</li>
<li>Encourage them to carry out recreational activities, without the mobile device.</li>
<li>As older people, set an example and give balanced use to devices.</li>
</ul>
<p style="text-align: left;">Contact coordinates with ESET in Venezuela: <a href="https://www.eset.com/ve/" target="_blank" rel="noopener">https://www.eset.com/ve/</a>. Also, their social networks: Instagram (<a href="https://www.instagram.com/esetla/" target="_blank" rel="noopener">@esetla</a>) and Facebook: (<a href="https://www.facebook.com/ESETLA" target="_blank" rel="noopener">ESET</a>).</p>
<p style="text-align: left;"><em>With information and reference image provided by ESET and Comstat Rowland</em></p>
<p style="text-align: left;">Visit our news channel on <a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener">Google News</a> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on <a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener">Twitter</a> and <a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener">Instagram</a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/betting-on-video-games-a-worrying-trend-on-children-and-adolescents/">Betting on video games: a worrying trend on children and adolescents</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Malicious banking applications: New phishing against Android and iOS users</title>
		<link>https://bitfinance.news/en/malicious-banking-applications-new-phishing-against-android-and-ios-users/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Mon, 26 Aug 2024 12:00:55 +0000</pubDate>
				<category><![CDATA[Financial security]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[Android and iOS users]]></category>
		<category><![CDATA[automated voice calls]]></category>
		<category><![CDATA[Camilo Gutiérrez Amaya]]></category>
		<category><![CDATA[criminal technique]]></category>
		<category><![CDATA[cybercrime attacks]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[ESET research team]]></category>
		<category><![CDATA[malicious ads]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[Research Laboratory]]></category>
		<category><![CDATA[SMS messages]]></category>
		<category><![CDATA[Warning]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=108610</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1331" height="861" src="https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET analizó campañas de phishing que combinan técnicas tradicionales con el uso de tecnologías de iOS y Android para instalar aplicaciones vulnerantes sin el consentimiento del usuario" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS.jpg 1331w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-300x194.jpg 300w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-1024x662.jpg 1024w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-768x497.jpg 768w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-210x136.jpg 210w" sizes="(max-width: 1331px) 100vw, 1331px" /></div><p>ESET, a leading company in proactive threat detection, identified a phishing campaign aimed at mobile users that targeted bank customers. This novel criminal technique installs a phishing application from a third-party website without the user having to allow the installation of applications, it affects both iOS and Android users. Most of the cases known at [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/malicious-banking-applications-new-phishing-against-android-and-ios-users/">Malicious banking applications: New phishing against Android and iOS users</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1331" height="861" src="https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET analizó campañas de phishing que combinan técnicas tradicionales con el uso de tecnologías de iOS y Android para instalar aplicaciones vulnerantes sin el consentimiento del usuario" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS.jpg 1331w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-300x194.jpg 300w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-1024x662.jpg 1024w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-768x497.jpg 768w, https://bitfinance.news/wp-content/uploads/2024/08/Imagen-referencial-Nuevo-metodo-de-phishing-adaptado-a-usuarios-de-Android-e-iOS-210x136.jpg 210w" sizes="(max-width: 1331px) 100vw, 1331px" /></div><p style="text-align: justify;"><strong><a href="https://www.eset.com/latam/" target="_blank" rel="noopener">ESET</a>,</strong> a leading company in proactive threat detection, identified a phishing campaign aimed at mobile users that targeted bank customers. This novel <strong>criminal technique</strong> installs a phishing application from a third-party website without the user having to allow the installation of applications, it affects both iOS and Android users. Most of the cases known at the moment have occurred in the Czech Republic, and applications were directed to the Hungarian bank OTP Bank and the Georgian bank TBC Bank.</p>
<p style="text-align: justify;"><strong>The ESET research team</strong> identified a series of phishing campaigns targeting mobile users that used three different <strong>URL delivery mechanisms: automated voice calls, SMS messages, and social media malvertising.</strong></p>
<p style="text-align: justify;"><strong>Voice call</strong> delivery was done via an automated call that warned the user about an outdated banking application and asked them to select an option on the keypad. After pressing the correct button, a phishing URL was sent via SMS.</p>
<p style="text-align: justify;">The initial approach by <strong>SMS</strong> was carried out by indiscriminately sending messages to Czech telephone numbers. The message sent included a phishing link and a text for victims to perform social engineering and visit the link.</p>
<p style="text-align: justify;">The spread through<strong> malicious ads</strong> was done by registering ads on Meta platforms such as Instagram and Facebook. These ads included a call to action, such as a limited offer for users to “download an update below.” This technique allowed threat actors to specify the target audience by age, gender, etc. The ads then appeared on the victims&#8217; social networks.</p>
<p style="text-align: justify;">After opening the URL delivered in the first stage, Android victims were faced with a <strong>high-quality phishing page that imitated the official Google Play Store page</strong> for the targeted banking app, or an imitation website of the app.</p>
<figure id="attachment_108607" aria-describedby="caption-attachment-108607" style="width: 899px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-108607 size-full" src="https://bitfinance.news/wp-content/uploads/2024/08/1.png" alt="PWA phishing flow" width="899" height="311" srcset="https://bitfinance.news/wp-content/uploads/2024/08/1.png 899w, https://bitfinance.news/wp-content/uploads/2024/08/1-300x104.png 300w, https://bitfinance.news/wp-content/uploads/2024/08/1-768x266.png 768w" sizes="(max-width: 899px) 100vw, 899px" /><figcaption id="caption-attachment-108607" class="wp-caption-text">PWA phishing flow</figcaption></figure>
<p>&nbsp;</p>
<p style="text-align: justify;">From there, victims are asked to install a “new version” of the banking app. Depending on the campaign, clicking the install/update button initiates the installation of a malicious application from the website, directly on the victim&#8217;s phone, either in the form of a <a href="https://web.dev/articles/webapks" target="_blank" rel="noopener">WebAPK</a> (Android users only), or as a Progressive Web App (PWA)<strong> for iOS and Android users.</strong> The highlight of this instance is that it bypasses traditional browser warnings to &#8220;install unknown apps&#8221;: this is the default behavior of <strong>Chrome&#8217;s WebAPK technology, which is abused by attackers.</strong></p>
<p style="text-align: justify;">The process is a little different for iOS users, as an animated pop-up tells victims how to add the phishing PWA to their home screen. The popup copies the look of native iOS messages. In the<strong> end, iOS users are not warned about adding a potentially harmful app to their phone.</strong></p>
<p style="text-align: justify;">Upon installation, victims are asked to enter their internet banking credentials to access their account through the new mobile banking application. All information provided is sent to the<strong> attackers&#8217; C&amp;C servers.</strong></p>
<p style="text-align: justify;">The malicious ads included a mashup of the bank&#8217;s official mascot (blue chameleon), as well as bank logos and text promising a financial reward for installing the app or warning users that a critical update had been released.</p>
<figure id="attachment_108608" aria-describedby="caption-attachment-108608" style="width: 750px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-108608 " src="https://bitfinance.news/wp-content/uploads/2024/08/2.png" alt="Example of a malicious ad used in these campaigns" width="750" height="694" srcset="https://bitfinance.news/wp-content/uploads/2024/08/2.png 485w, https://bitfinance.news/wp-content/uploads/2024/08/2-300x278.png 300w" sizes="(max-width: 750px) 100vw, 750px" /><figcaption id="caption-attachment-108608" class="wp-caption-text">Example of a malicious ad used in these campaigns</figcaption></figure>
<p>&nbsp;</p>
<p style="text-align: justify;">All stolen login information was recorded through a backend server, which then sent the banking login details entered by the user to a Telegram group chat. HTTP calls to send messages to the threat actor&#8217;s group chat were made through the official Telegram API. <strong>As mentioned by ESET: this technique is not new and is used in several phishing kits.</strong></p>
<h4 style="text-align: left;"><span style="color: #008000;">Warning</span></h4>
<p style="text-align: justify;"><em>“Because two drastically different C&amp;C infrastructures were used, we have determined that two different groups are responsible for the spread of phishing applications. More imitation apps will surely be created, since after installation it is difficult to separate legitimate apps from phishing ones. All sensitive information found during our investigation was quickly sent to the affected banks for processing. We also coordinate the dismantling of multiple phishing domains and C&amp;C servers,” </em>says <strong>Camilo Gutiérrez Amaya</strong>, Head of the<strong> ESET Latin America Research Laboratory.</strong></p>
<p style="text-align: justify;">Contact coordinates with ESET in Venezuela: <a href="https://www.eset.com/ve/" target="_blank" rel="noopener">https://www.eset.com/ve/</a>. Also, their social networks: Instagram <a href="https://www.instagram.com/esetla/" target="_blank" rel="noopener">@esetla</a>) and Facebook: (<a href="https://www.facebook.com/ESETLA" target="_blank" rel="noopener">ESET</a>).</p>
<p style="text-align: left;"><em>With information and reference image provided by ESET and Comstat Rowland</em></p>
<p style="text-align: left;">Visit our news channel on <a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener">Google News</a> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on <a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener">Twitter</a> and <a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener">Instagram</a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/malicious-banking-applications-new-phishing-against-android-and-ios-users/">Malicious banking applications: New phishing against Android and iOS users</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>SMEs: 7 common mistakes when using cloud services</title>
		<link>https://bitfinance.news/en/smes-7-common-mistakes-when-using-cloud-services/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Thu, 25 Jan 2024 12:00:07 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Financial security]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[Camilo Gutiérrez Amaya]]></category>
		<category><![CDATA[Cloud services]]></category>
		<category><![CDATA[common errors]]></category>
		<category><![CDATA[ESET Latin America]]></category>
		<category><![CDATA[proactive threat detection]]></category>
		<category><![CDATA[Research Laboratory]]></category>
		<category><![CDATA[SMEs]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=102671</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="813" height="553" src="https://bitfinance.news/wp-content/uploads/2024/01/Imagen-referencial-Pymes-7-errores-comunes-al-usar-servicios-en-la-nube.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET explica cómo eliminar errores y puntos ciegos para optimizar el uso de servicios en la nube sin exponerse a riesgos" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2024/01/Imagen-referencial-Pymes-7-errores-comunes-al-usar-servicios-en-la-nube.jpg 813w, https://bitfinance.news/wp-content/uploads/2024/01/Imagen-referencial-Pymes-7-errores-comunes-al-usar-servicios-en-la-nube-300x204.jpg 300w, https://bitfinance.news/wp-content/uploads/2024/01/Imagen-referencial-Pymes-7-errores-comunes-al-usar-servicios-en-la-nube-768x522.jpg 768w" sizes="(max-width: 813px) 100vw, 813px" /></div><p>Today, IT infrastructure, platforms and software are more likely to be offered as a service in a traditional on-premises setup. This is very attractive to small and medium-sized companies (SMEs), when compared to the majority, since it allows them to compete on equal terms with larger rivals, with more business agility and rapid scalability, without [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/smes-7-common-mistakes-when-using-cloud-services/">SMEs: 7 common mistakes when using cloud services</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="813" height="553" src="https://bitfinance.news/wp-content/uploads/2024/01/Imagen-referencial-Pymes-7-errores-comunes-al-usar-servicios-en-la-nube.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET explica cómo eliminar errores y puntos ciegos para optimizar el uso de servicios en la nube sin exponerse a riesgos" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2024/01/Imagen-referencial-Pymes-7-errores-comunes-al-usar-servicios-en-la-nube.jpg 813w, https://bitfinance.news/wp-content/uploads/2024/01/Imagen-referencial-Pymes-7-errores-comunes-al-usar-servicios-en-la-nube-300x204.jpg 300w, https://bitfinance.news/wp-content/uploads/2024/01/Imagen-referencial-Pymes-7-errores-comunes-al-usar-servicios-en-la-nube-768x522.jpg 768w" sizes="(max-width: 813px) 100vw, 813px" /></div><p style="text-align: justify;">Today, IT infrastructure, platforms and software are more likely to be offered as a service in a traditional on-premises setup. This is very attractive to small and medium-sized companies (SMEs), when compared to the majority, since it allows them to compete on equal terms with larger rivals, with more business agility and rapid scalability, without excessive investment. Thus, <a href="https://www.eset.com/latam/" target="_blank" rel="noopener">ESET</a>, a leading company in <strong>proactive threat detection</strong>, warns that digital transformation also entails risks regardless of the size of the company and shares key security tips to take into account to avoid errors.</p>
<p style="text-align: justify;"><em>“53 % of SMBs surveyed in a <a href="https://info.flexera.com/CM-REPORT-State-of-the-Cloud" target="_blank" rel="noopener">recent report</a> say they spend more than $1.2 million annually on the cloud, up from 38 % last year. Furthermore, security (72 %) and regulatory compliance (71 %) are the second and third most cited challenges by the SMEs surveyed. The first step in addressing these challenges is to understand the top mistakes smaller businesses make with their cloud deployments. In any case, these are not just mistakes that SMEs make in the cloud, larger companies with more resources are sometimes guilty of forgetting the essential ones. <strong>By eliminating these blind spots, your organization can take great steps towards optimizing its use of the cloud, without exposing itself to potentially serious financial or reputational risks”,</strong> </em>comments<strong> Camilo Gutiérrez Amaya,</strong> head of the <strong>ESET Latin America Research Laboratory</strong><em><strong>.</strong></em></p>
<h4><span style="color: #000080;">The 7 main cloud security mistakes that SMEs (and not so SMEs) make, according to ESET</span></h4>
<ol>
<li style="text-align: justify;"><strong>No multifactor authentication (MFA):</strong> Static passwords are inherently insecure, and not all companies follow <a href="https://www.welivesecurity.com/2023/05/04/creating-strong-user-friendly-passwords-tips-business-password-policy/" target="_blank" rel="noopener">a strong password creation policy</a>. Passwords can be <a href="https://www.welivesecurity.com/2022/01/05/5-ways-hackers-steal-passwords-how-stop-them/" target="_blank" rel="noopener">stolen in several ways</a>, such as phishing, brute force methods, or simply guessing. That is why it is necessary to add another layer of authentication (two-key or two-factor). MFA will make it much more difficult for attackers to access applications in your users&#8217; SaaS, IaaS, or PaaS accounts, mitigating the risk of ransomware, data theft, and other potential outcomes. Another option is to switch to alternative authentication methods, such as <a href="https://www.welivesecurity.com/2023/06/20/passwords-out-passkeys-in-ready-make-switch/" target="_blank" rel="noopener">authentication without password</a>, whenever possible.</li>
<li style="text-align: justify;"><strong>Placing too much trust in the cloud provider:</strong> Many IT managers believe that investing in the cloud effectively means outsourcing everything to a trusted third party. This is only partly true: there is <a href="https://www.ncsc.gov.uk/collection/cloud/understanding-cloud-services/cloud-security-shared-responsibility-model" target="_blank" rel="noopener">a shared responsibility model between the provider and the customer</a>, for securing the cloud. The type of service – SaaS, IaaS or PaaS – will determine what should be taken into account. While most of the responsibility falls on the provider, it is worth investing in additional third-party controls.</li>
<li style="text-align: justify;"><strong>Not making backups:</strong> Never assume that the cloud service provider (for example, for file storage/sharing services) has your back. You should think about the worst case scenario: a system failure or a cyberattack on your provider. It&#8217;s not just data loss what will impact your organization, but also the downtime and hit to productivity that could follow an incident.</li>
<li style="text-align: justify;"><strong>Not patching regularly:</strong> If you don&#8217;t patch, you expose your cloud systems to vulnerability exploitation. This, in turn, could lead to malware infections, data leaks, and much more. Patch management is a security best practice that is as important in the cloud as it is in other systems.</li>
<li style="text-align: justify;"><strong>Cloud disruption:</strong> Cloud service providers are an innovative bunch, but the sheer volume of new features and capabilities they release in response to customer feedback can end up creating an incredibly complex cloud environment for many SMEs. This makes it more difficult to know which configuration is the most secure. The most common mistakes are <a href="https://www.welivesecurity.com/2021/09/22/plugging-holes-how-prevent-corporate-data-leaks-cloud/" target="_blank" rel="noopener">configuring cloud storage</a> so that any third party can access it and not blocking open ports.</li>
<li style="text-align: justify;"><strong>Failing to monitor cloud traffic:</strong> Rapid detection and response are critical if signals are to be detected early, to contain an attack before it has a chance to impact the organization. This makes continuous supervision essential. It is worth thinking that it is not a question of “whether” the cloud environment will be breached, but “when”.</li>
<li style="text-align: justify;"><strong>Don&#8217;t encrypt your company&#8217;s crown jewels:</strong> No environment is 100 % breach-proof. So what happens if a bad actor manages to access your most sensitive internal data or highly regulated employee/customer personal information? Encrypting them at rest and in transit will ensure that they cannot be used even if they are obtained.</li>
</ol>
<h3 style="text-align: left;"><span style="color: #008000;">Experts advise</span></h3>
<p style="text-align: justify;">From ESET, they assure that the first step to address these security risks in the cloud is to <strong>understand what the responsibilities are and what areas the provider</strong> will be in charge of. It&#8217;s a matter of deciding whether to rely on cloud-native security controls or to enhance them with additional third-party products. Therefore, they advise the following:</p>
<ul style="text-align: justify;">
<li><strong><a href="https://www.eset.com/fileadmin/ESET/INT/Products/Business/ECOS/v02/Product-Overview-ESET-Cloud-Office-Security.pdf?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=seguridad-para-empresas&amp;utm_term=es" target="_blank" rel="noopener">Invest in third-party security solutions</a></strong> to improve cloud security and protection of email, storage and collaboration applications. In addition to the security features built into cloud services offered by leading service providers in the world cloud</li>
<li><strong>Add extended or managed detection and response (XDR/MDR) tools to drive rapid incident</strong> response and breach containment/remediation</li>
<li><strong>Develop and implement an ongoing risk-based patching program</strong> based on strong asset management (i.e. knowing what cloud assets you have and ensuring they are always up-to-date)</li>
<li><strong>Encrypt data at rest (at the database level) and in trans</strong>it to ensure its protection. This will also require effective and continuous data detection and classification</li>
<li><strong>Define a clear access control policy;</strong> require strong passwords, MFA, principles of the least privilege, and IP-based restrictions/allow access lists for specific IPs</li>
<li><strong>Consider adopting a <a href="https://www.eset.com/blog/enterprise/traveling-your-zero-trust-journey-with-eset/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=seguridad-para-empresas&amp;utm_term=es" target="_blank" rel="noopener">zero trust approach</a>,</strong> which will incorporate many of the above elements (MFA, XDR, encryption) along with network segmentation and other controls</li>
</ul>
<p style="text-align: justify;"><em>“Many of the measures above are the same best practices that one would expect to deploy in on-premise systems as well, with some details that will be different. The most important thing is to remember that cloud security is not only the responsibility of the provider and that control must be taken to prevent cyber risks”</em> concludes Gutiérrez Amaya from ESET.</p>
<p style="text-align: left;">For more details on computer security, you can visit the ESET portal: <a href="https://www.welivesecurity.com/es/" target="_blank" rel="noopener">https://www.welivesecurity.com/es/</a></p>
<p style="text-align: left;">Bitfinance.News</p>
<p style="text-align: justify;"><em>With information and reference image provided by ESET and Comstat Rowland</em></p>
<p style="text-align: left;">Visit our news channel on <a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener">Google News</a> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on <a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener">Twitter</a> and <a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener">Instagram</a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/smes-7-common-mistakes-when-using-cloud-services/">SMEs: 7 common mistakes when using cloud services</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>ESET: Malicious loan apps for Android multiplied in 2023</title>
		<link>https://bitfinance.news/en/eset-malicious-loan-apps-for-android-multiplied-in-2023/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Mon, 18 Dec 2023 12:30:47 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Financial security]]></category>
		<category><![CDATA[Innovation]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Bank clients]]></category>
		<category><![CDATA[banks]]></category>
		<category><![CDATA[Camilo Gutiérrez Amaya]]></category>
		<category><![CDATA[credit]]></category>
		<category><![CDATA[ESET Latin America]]></category>
		<category><![CDATA[malicious loan applications]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[Research Laboratory]]></category>
		<category><![CDATA[SpyLoan]]></category>
		<category><![CDATA[unsuspecting users]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=101805</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1000" height="669" src="https://bitfinance.news/wp-content/uploads/2023/12/Imagen-En-2023-crecieron-las-aplicaciones-de-prestamos-maliciosas-que-enganan-y-espian-a-usuarios-de-Android-Suministrada-por-Comstat-R-1.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Esta compañía líder en detección proactiva de amenazas tecnológicas, analizó el crecimiento en el año que culmina de las apps maliciosas que recopilan y exflitran datos confidenciales de las víctimas" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2023/12/Imagen-En-2023-crecieron-las-aplicaciones-de-prestamos-maliciosas-que-enganan-y-espian-a-usuarios-de-Android-Suministrada-por-Comstat-R-1.jpg 1000w, https://bitfinance.news/wp-content/uploads/2023/12/Imagen-En-2023-crecieron-las-aplicaciones-de-prestamos-maliciosas-que-enganan-y-espian-a-usuarios-de-Android-Suministrada-por-Comstat-R-1-300x201.jpg 300w, https://bitfinance.news/wp-content/uploads/2023/12/Imagen-En-2023-crecieron-las-aplicaciones-de-prestamos-maliciosas-que-enganan-y-espian-a-usuarios-de-Android-Suministrada-por-Comstat-R-1-768x514.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></div><p>“It is important to note that each instance of a SpyLoan application, regardless of its origin, behaves identically. If users download an app they will experience the same features and face the same risks, regardless of where they got the app from. It does not matter if the download comes from a suspicious website, from [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/eset-malicious-loan-apps-for-android-multiplied-in-2023/">ESET: Malicious loan apps for Android multiplied in 2023</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1000" height="669" src="https://bitfinance.news/wp-content/uploads/2023/12/Imagen-En-2023-crecieron-las-aplicaciones-de-prestamos-maliciosas-que-enganan-y-espian-a-usuarios-de-Android-Suministrada-por-Comstat-R-1.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Esta compañía líder en detección proactiva de amenazas tecnológicas, analizó el crecimiento en el año que culmina de las apps maliciosas que recopilan y exflitran datos confidenciales de las víctimas" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2023/12/Imagen-En-2023-crecieron-las-aplicaciones-de-prestamos-maliciosas-que-enganan-y-espian-a-usuarios-de-Android-Suministrada-por-Comstat-R-1.jpg 1000w, https://bitfinance.news/wp-content/uploads/2023/12/Imagen-En-2023-crecieron-las-aplicaciones-de-prestamos-maliciosas-que-enganan-y-espian-a-usuarios-de-Android-Suministrada-por-Comstat-R-1-300x201.jpg 300w, https://bitfinance.news/wp-content/uploads/2023/12/Imagen-En-2023-crecieron-las-aplicaciones-de-prestamos-maliciosas-que-enganan-y-espian-a-usuarios-de-Android-Suministrada-por-Comstat-R-1-768x514.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></div><p style="text-align: justify;"><em>“It is important to note that each instance of a SpyLoan application, regardless of its origin, behaves identically. If users download an app they will experience the same features and face the same risks, regardless of where they got the app from. It does not matter if the download comes from a suspicious website, from a third-party application store or even from Google Play: the behavior of the application will be the same in all cases,” </em>explains <strong>Camilo Gutiérrez Amaya</strong>, Head of the <strong>Research Laboratory from ESET Latin America.</strong></p>
<p style="text-align: justify;">Since early 2023, researchers at <a href="https://www.eset.com/latam/" target="_blank" rel="noopener"><strong>ESET</strong></a>, a leading proactive threat detection company, have observed an alarming growth in deceptive Android applications that present themselves as legitimate personal loan services, promising quick and easy access to funds. These services are actually designed to scam users by offering them loans with high interest rates backed with misleading descriptions, while collecting their victims&#8217; personal and financial information to blackmail them and ultimately obtain their funds.</p>
<p style="text-align: justify;">ESET products recognize these applications using the detection name <strong>SpyLoan,</strong> which refers directly to their spyware functionality combined with loan claims.</p>
<p style="text-align: justify;">Such apps were previously available on Google Play but are currently marketed through social media and SMS messages, and can be downloaded from scam websites and third-party app stores. As a partner of the <strong>Google App Defense Alliance,</strong> ESET identified and reported to Google <strong>18 SpyLoan applications</strong> that had more than 12 million downloads on Google Play and 17 of them were subsequently removed. The last app identified by ESET is still available on Google Play, but since its developers changed its permissions and functionalities, it is no longer detected as a SpyLoan app.</p>
<p style="text-align: justify;">According to <strong>ESET telemetry,</strong> the executors of these apps operate mainly in <strong>Mexico, </strong>Indonesia, Thailand, Vietnam, India, Pakistan, <strong>Colombia, Peru, Chile,</strong> Philippines, Egypt, Kenya, Nigeria and Singapore. All of these countries have various laws that regulate <strong>private loans,</strong> not only their types, but also the transparency of their communication. Any detection outside these countries could be related to smartphones that have, for various reasons, access to a phone number registered in one of these countries.</p>
<h3 style="text-align: left;"><span style="color: #000080;">How SpyLoan apps work</span></h3>
<p style="text-align: justify;"><em>“There are several reasons for the rapid growth of SpyLoan applications. One of them is that its developers are inspired by successful FinTech services, which take advantage of technology to offer agile and easy-to-use financial services. FinTech applications and platforms are known for disrupting the traditional financial sector by offering convenience in terms of accessibility, allowing people, in a user-friendly manner, to perform various financial activities anytime, anywhere, using only their smartphones. On the contrary, the only thing that SpyLoan applications alter is trust in technology, financial institutions and similar entities,” </em>says Gutiérrez Amaya, from ESET Latin America.</p>
<p style="text-align: justify;">Once a user installs a SpyLoan app, they are asked to accept the terms of service and grant broad permissions to access sensitive data stored on the device. The app then requests user registration, which is typically done by verifying the one-time password via SMS to validate the victim&#8217;s phone number. These registration forms automatically select the country code, based on that of the victim&#8217;s phone number, ensuring that only people with phone numbers registered in the target country can create an account.</p>
<p style="text-align: justify;">Once the phone number is verified, users access the loan application function of the application. To complete this process, users are forced to provide a large amount of personal information, including address details, contact information, proof of income, bank account information, and even upload photos of the front and back of their documents identity, and even a selfie.</p>
<p style="text-align: justify;">SpyLoan applications pose a significant threat by stealthily extracting a wide range of personal information from <strong>unsuspecting users:</strong> they are capable of sending sensitive data to their command and control (C&amp;C) servers. Data that is usually leaked includes the list of accounts, call logs, calendar events, device information, lists of installed applications, local Wi-Fi network information, and even information about the files on the device. Additionally, contact lists, location data and SMS messages are also vulnerable.</p>
<h4 style="text-align: left;"><span style="color: #008000;">Legit vs. Malicious Loan Apps: How to Tell Them Apart</span></h4>
<p style="text-align: justify;">ESET shares a series of recommendations that users can use to protect themselves:</p>
<p style="text-align: justify;">– <strong>Go to official sources</strong>: Android users should avoid installing lending apps from unofficial sources and third-party app stores, and stick to trusted platforms like Google Play, which apply app review processes and security measures. Although this does not guarantee complete protection, it does reduce the risk of encountering fraudulent loan applications.</p>
<p style="text-align: justify;">– <strong>Use a security app</strong>: A reliable security app for Android protects the user from malicious lending apps and malware. Security apps provide an additional layer of protection by scanning and identifying potentially harmful apps, detecting malware, and warning users about suspicious activity.</p>
<p style="text-align: justify;">– <strong>Review scrutiny</strong>: When downloading apps from Google Play, it is important to pay close attention to user reviews. It is crucial to be aware of fake positive reviews. Borrowers should focus on negative reviews and carefully evaluate concerns raised by users, as they can reveal important information such as extortion tactics and the actual cost charged by the loan provider.</p>
<p style="text-align: justify;">– <strong>Privacy Policy and Data Access Review</strong>: Before installing a loan app, users should read its privacy policy, if available. This document often contains valuable information about how the application accesses and stores sensitive information. However, scammers can use misleading clauses or vague language to trick users into granting unnecessary permissions or sharing personal data. During installation, it is important to pay attention to the data to which the application requests access and ask whether the requested data is necessary for the functionality of the loan application.</p>
<p style="text-align: left;">To learn more about computer security, we invite you to visit the <strong>ESET</strong> news site: <a href="https://www.welivesecurity.com/es/investigaciones/app-prestamos-espian-usuarios-android/" target="_blank" rel="noopener">https://www.welivesecurity.com/es/investigaciones/app-prestamos-espian-usuarios-android/</a>.</p>
<p style="text-align: left;"><a href="https://www.eset.com/latam/podcast/" target="_blank" rel="noopener"><strong><em>Conexión Segura</em></strong></a>, your podcast with timely verified information about computer security in the world, can be heard at: <a href="https://open.spotify.com/show/0Q32tisjNy7eCYwUNHphcw" target="_blank" rel="noopener">https://open.spotify.com/show/0Q32tisjNy7eCYwUNHphcw</a>.</p>
<p style="text-align: left;"><em>With information and image provided by ESET and Comstat Rowland Comunicaciones Estratégicas Integrales</em></p>
<p style="text-align: left;">Visit our news channel on <a href="https://news.google.com/publications/CAAqBwgKMP_wxAswoozcAw?ceid=VE:es-419&amp;oc=3" target="_blank" rel="noopener">Google News</a> and follow us to get accurate, interesting information and stay up to date with everything. You can also see our daily content on <a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener">Twitter</a> and <a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener">Instagram</a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/eset-malicious-loan-apps-for-android-multiplied-in-2023/">ESET: Malicious loan apps for Android multiplied in 2023</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news/en">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
