In the context of information security, “spoofing” refers to the act of someone or something impersonating another entity in an effort to trick us into believing it is something else, obtain access to our systems, steal information or financial information, or disseminate malicious software. Attacks using spoofing can take numerous forms, including the following:
• Forging of email addresses
• Misrepresentation of a website’s URL or both
• Falsifying caller ID information
• Spoofing of text message content
• GPS spoofing
• Attacks involving a “man in the midst”
• Hoaxing the extension system
• Spoofing an Internet Protocol
• Impersonation of the face
Therefore, how are the cybercriminals able to trick us? When we hear the name of a well-known and respected company or organization, we tend to respond favorably and are more willing to provide information or take some kind of action. For instance, a counterfeit email purporting to come from PayPal or Amazon can question about transactions you have never made on either of those websites. Because you could be worried about your account, you might feel compelled to click the link that was given.
Scammers will lead you to a website that either contains malware for download or a false login page, replete with a recognizable logo and a URL that has been spoofed, with the intention of stealing your username and password. This dangerous link will take you to the phony login page.
A spoofing attack can be carried out in a great number of different ways. Fraudsters count on their victims falling for the false in each and every one of these schemes. If you never question the veracity of a website and never consider the possibility that an email might be forged, you run the risk of falling victim to a spoofing attack at some point in the future.
To that purpose, the spoofing topic is covered in great detail on this page. We will provide you with education on the different sorts of spoofs, how spoofing works, how to differentiate between legitimate emails and websites and false ones, and how to prevent becoming a target for fraudsters.
Different kinds of spoofing
spoofing in email systems
The act of sending emails with phony sender addresses is known as email spoofing. This is typically done as part of a phishing assault, which is an attempt to steal your information, infect your machine with malware, or just beg you for money. Malicious emails typically carry payloads of ransomware, adware, cryptojackers, Trojans (like Emotet), or malware that enslaves your machine in a botnet. These are some examples of typical payloads (see DDoS).
However, a forged email account is not always sufficient to trick the typical individual. Imagine receiving a phishing email that appears to have been sent from a Facebook address in the sender field. The body of the email, however, is written in plain text and does not contain any design or HTML in any form; there is not even a logo included. This is not the kind of message we often get from Facebook, so the fact that we did receive it should raise some red flags. As a consequence of this, phishing emails will generally contain multiple false characteristics, including the following:
• A sham sender address that makes it appear as though the message came from a person or organization that you are familiar with and can put your faith in, such as a friend, coworker, family member, or corporation that you do business with.
• If the recipient is already familiar with the firm or organization, the email may include recognizable elements of the brand, such as the logo, colors, typeface, and call to action button, among other things.
• Spear phishing attacks are directed at a specific individual or a small group of employees within a firm. These attacks will use personalized language and will address the receiver by name.
• There are a lot of typos. Email con artists rarely spend a significant amount of time editing their own work, despite their best efforts to trick us. Email hoaxes frequently contain mistakes or give the appearance of having been translated using Google Translate by the perpetrator. Be aware of strange sentence structures; it is highly improbable that large corporations such as Facebook or PayPal would make such errors in the emails they send to their clients.
Sextortion scams rely heavily on faking emails as their primary method of communication. These cons lead us to believe that malware has been installed on our webcams and that they are being used to record us when we watch pornographic content. It is a really strange thing to say, but the counterfeit emails will state something along the lines of “I’ve been watching you watch porn.” Who exactly is the creepy one in this situation? Scammers will then demand a certain quantity of Bitcoin or another cryptocurrency, threatening that if they do not receive payment they will release the video to everyone you know. In order to provide the idea that the emails come from a legitimate source, they might additionally contain an old password that was compromised in a previous data breach. The spoofing technique is utilized by the con artists when they alter the sender field of the email to make it appear as though it is coming from your supposedly compromised email account. You may relax because it’s quite unlikely that someone is truly observing your every move.
Website spoofing
The process of making a malicious website appear to be an authentic one is known as “spoofing” the website. The faked website will appear to be the login page for a website that you frequently visit, right down to the branding and the user interface. It will even have a spoofed domain name that first appears to be the same as the legitimate website. Spoofed websites are used by cybercriminals to steal your username and password (also known as login spoofing) or to download malicious software onto your computer (a drive-by download). In most cases, a faked website will be used in conjunction with a falsified email, in which the email will contain a link to the spoofed website.
It is also important to keep in mind that a hacked website and a faked website are not the same thing. Hacking a website means that the actual website has been corrupted and taken over by hackers; there is no spoofing or fakery involved in this type of attack. In a similar vein, malvertising is its own distinct variety of malware. In this particular instance, fraudsters have used authorized advertising channels in order to serve harmful advertisements on reputable websites. Malware is covertly installed on the victim’s PC through these advertisements.
spoofing of caller ID numbers
Scammers can engage in caller ID spoofing when they make a phone call appear to originate from a location other than the one from which it actually originates. Scammers have discovered that if the caller ID displays an area code that is the same as or close to your own, you are more likely to pick up the phone when it rings. In other instances, con artists can even fake the first few digits of your phone number in addition to the area code to give the appearance that the call is coming from your local region. This is done to make the victim believe that the call is coming from someone in their immediate vicinity (aka neighbor spoofing).
Phishing through text message
Text message spoofing, often known as SMS spoofing, is the act of sending a text message using the phone number or sender ID of another person. If you have ever sent a text message from your computer, you have impersonated your own phone number in order to do so, because the text did not truly come from your phone. This is known as “spoofing” your own phone number. For the purposes of marketing and providing convenience to the customer, businesses routinely spoof their own numbers. This is accomplished by replacing the lengthy number with a short alphanumeric sender ID that is simple and easy to remember. Scammers often use the same tactic, which consists of concealing their genuine identity by using an alphanumeric sender ID and, most of the time, pretending to be a reputable business or organization. The counterfeit texts will typically contain download links for malware or connections to sites that conduct SMS phishing (also known as smishing).
Scammers who send messages to victims can take advantage of the current state of the employment market by pretending to be staffing firms and providing victims links to job offers that are too good to be true. A “Brand new Toyota Corrola” was one of the perks that came with a work-from-home position at Amazon, for instance. To begin, if one is working from home, there is no reason why they should be provided with a corporate car. Second, is a Toyota “Corrola” the same thing as a Toyota Corolla or is it a different model altogether? Con artists, you made an attempt.
GPS spoofing
While you mislead the GPS on your device into thinking that you are in one area when you are actually in another location, this is known as “GPS spoofing.” Why on God’s green earth would anyone want to spoof their GPS location? Just one acronym: Pokémon GO. Cheaters are able to trick the popular smartphone game Pokémon GO into believing they are close to a virtual gym so that they can take control of it by using a technique called GPS spoofing (winning in-game currency). In point of fact, the cheats are located in an entirely different region or perhaps a foreign nation. In a similar vein, videos can be found on YouTube demonstrating how users of Pokémon GO caught a variety of Pokémon without ever having to leave their homes. Even though spoofing a GPS signal can seem like child’s play, it is not hard to conceive that threat actors might utilize this approach for more sinister purposes than simply gaining mobile game gold.
Attack known as “Man in the Middle” (MitM).
When you use the free Wi-Fi at a neighborhood coffee shop, you put yourself at risk of being attacked by a “Man in the Middle” (MitM). Have you given any thought to what may occur if a hacker gained unauthorized access to the Wi-Fi network or established an additional fake Wi-Fi network in the same location? In either scenario, the conditions are ideal for a man-in-the-middle attack, which gets its name from the fact that malicious actors can monitor the online traffic that occurs between two different parties. Spoofing is utilized when thieves modify the communication between the parties in order to redirect payments or request sensitive personal information such as credit card numbers or login credentials.
A remark in this regard is that while man-in-the-middle attacks typically steal data from the Wi-Fi network, there is another type of MitM attack that steals data from the browser. An assault such as this is known as a man in the browser attack (MitB).
The spoofing of extensions
When hackers seek to conceal executable malware files, they resort to a technique known as extension spoofing. The practice of naming a file anything along the lines of “filename.txt.exe” is a popular example of extension spoofing that is used by criminals. The thieves are aware that Windows has a setting that hides file extension by default, and as a result, this executable file will appear to the average Windows user as “filename.txt.”
spoofing of an IP address
When someone wishes to conceal or mask the location from which they are transmitting or requesting data online, they will utilize a technique known as IP spoofing. Spoofing an IP address is a technique that is utilized in distributed denial of service (DDoS) attacks. The purpose of this technique is to conceal the location of the attacker while preventing harmful information from being filtered out.
Putting on a false face
Because of the consequences that it bears for both the future of technology and for our own lives, facial spoofing may be the most personal form of identity theft. The current state of facial identification technology is not particularly advanced. We use our faces to access our mobile devices and laptops, and not much else. However, in the not-too-distant future, we might find ourselves using our visage to make payments and sign legal documents. Imagine the implications that would arise if you were able to open a credit line simply by showing your face. This is very eerie. Researchers have revealed how 3D facial models constructed from your photographs on social media can already be used to break into a computer using facial identification if the device is locked using that method. To take things a step further, Malwarebytes Labs discovered that deepfake technology was being used to make fake news videos as well as fake sex tapes, each of which featured the voices and likenesses of prominent politicians and celebrities.
How does spoofing work?
We have investigated the many guises that spoofing can take, but we have only scratched the surface of its underlying mechanisms. Spoofing an email address, on the other hand, presents a few additional challenges that are worth discussing. An email fake can be used by cybercriminals in a number different ways, each of which allows them to conceal their genuine identities. The option with the highest chance of success is to hack into an unsecured mail server. Technically speaking, the email is being sent from the person who is being represented as the sender in this instance.
The “From” column is where you should simply type in any address you like as a low-tech alternative. If the victim responds to the email or if the email cannot be delivered for some reason, the response will be forwarded to whoever is designated in the “From” box; the attacker will not receive it. This is the sole drawback. Spammers frequently employ this strategy in order to use real emails in order to avoid being caught by spam filters. If you have ever received responses to emails that you have not sent, this is one of the possible reasons why, in addition to the possibility that someone has hacked into your email account. Backscatter, often known as collateral spam, is another term for this phenomenon.
Homograph attacks, also known as visual spoofing, refer to the practice in which an attacker creates a fake email by registering a domain name that is visually similar to the legitimate email address they are attempting to impersonate. Take, for instance, the domain name “rna1warebytes.com.” Take note that the letter “l” has been replaced with the number “1” in this instance. Take note, too, of the way the letters “r” and “n” have been employed to pretend to be the letter “m.” This provides the attacker with an added benefit in that they now have a domain that they can utilize to create a faked website using.
Whatever the purpose of the spoof may be, it is not always sufficient to just release a bogus website or email into the public and hope that no one would notice the difference. To pull off a convincing spoof, you need to combine the act of spoofing with elements of social engineering. The term “social engineering” refers to the techniques that cybercriminals employ to mislead us into handing over our personal information, clicking on a dangerous link, or opening an attachment that is packed with malware. There are a lot of different plays that can be used for social engineering. Cybercriminals are depending on the human frailties that we all have, such as fear, naiveté, greed, and vanity, in order to trick us into engaging in behavior that we really shouldn’t be engaging in. If you’ve been victimized by a sextortion fraud, for example, you might send the con artist Bitcoin out of concern that your personal business would be exposed for the world to see.
Vulnerabilities inherent to the human condition are not always a negative thing. Criminals love to prey on victims who display curiosity and empathy, even though these are often regarded as positive attributes to possess. An example of this would be the “stranded grandkids” scam, in which a loved one is either imprisoned or hospitalized in a distant nation and urgently requires financial assistance. It could read like this in an email or a text: “I’m sorry, Grandpa Joe, but I’ve been arrested in [insert the name of the country here] for importing drugs. Please give money, but be sure to keep this a secret from your parents. You are the greatest [three smiley faces with winking eyes emoji]!” Scammers are banking on the grandparent’s overall lack of awareness regarding the whereabouts of his grandchild at any one time in this particular scenario.
How can I tell if someone is spoofing me?
Here are some of the telltale symptoms that your account is being faked. If you observe any of these symptoms, you should immediately delete the page, click the back button, exit your browser, and do not proceed further.
Website spoofing
• No lock icon or green bar. An SSL certificate is required for every website to be considered trustworthy and safe. This certificate proves that a third-party certification body has confirmed that the website address in question belongs to the entity that is being validated. Keep in mind that nowadays, SSL certificates may be obtained without cost and with little effort. The presence of a padlock on a website is not sufficient evidence that it is the genuine article. Just keep in mind that nothing on the internet can be considered completely risk-free.
• The files on the website are not encrypted in any way. The Hypertext Transfer Protocol, also known as HTTP, has been around almost as long as the Internet itself, and it refers to the guidelines that are followed when exchanging files over the web. When transmitting data back and forth, legitimate websites will nearly always use HTTPS, which is an encrypted form of HTTP. If you are on a page that requires you to log in, yet the address bar of your browser displays “http” rather than “https,” you should be wary about the site.
• You should make use of a password manager. When you store the login information for a genuine website in the password vault of a password manager such as 1Password, the manager will automatically fill in your login credentials for that website. If, on the other hand, you visit to a website that has been spoofed, your password manager will not recognize the page and will not automatically fill in the login and password fields for you. This is an indication that you are being spoofed.
spoofing in email systems
• Check the sender’s address more than once. Scammers will register bogus domains that are very similar in appearance to authentic ones, as was previously described.
• You should Google the information contained in the email. If you do a short search, you should be able to determine whether or not a known phishing email is currently circulating on the internet.
• Embedded links have peculiar web addresses (URLs). Check the URLs of links before clicking on them by moving your cursor over them first.
• Incorrect spelling and grammar, as well as a strange syntax. Con artists frequently do not bother to edit their work.
• The information contained in the email seems impossible to believe.
• There are other materials attached. Be careful of any attachments you get, especially when they come from a sender you are not familiar with.
spoofing of caller ID numbers
• Caller ID may be fooled very easy. When our landlines have become a breeding ground for scam calls, it is a very unfortunate state of affairs. When you consider that the majority of individuals who still have landlines are older, the demographic that is the most susceptible to scam calls, this is an exceptionally disturbing fact to contemplate. Voice mail or an answering machine should be engaged whenever a call comes in from an unknown number to the landline.
How can I prevent someone from impersonating me?
Learning how to identify a spoofing attack should be your first and foremost priority. In the event that you passed over the section titled “How do I identify spoofing?,” you need to go back and read it immediately.
Put your anti-spam software to work. By doing this, you will prevent the vast majority of faked emails from reaching your inbox in the first place.
If you are not familiar with the sender of an email, you should not open any attachments or click on any links in the email. Confirm the information contained in the email by making direct contact with the sender through some other means if there is a possibility that the email is genuine.
Create a new tab or window and log in through there. Do not open the link provided if you receive a questionable email or text message that asks you to log in to your account and take some kind of action, such as verifying your details. The communication could be a scam. Instead, create a new tab or window, and go to the site straight from there. You can also sign in by using the specialized app on your mobile device, such as a smartphone or tablet.
Take the call when it comes in. In the event that you have gotten an ominous email that is purportedly from a person you know, you should not be hesitant to phone or text the sender in order to verify that it was in fact they who sent the email. This piece of advice is especially pertinent in situations in which the sender makes an unusual request, such as “Hey, could you kindly purchase one hundred iTunes gift cards and provide the card numbers to me through email? Thank you very much, Your Boss.”
Windows should display the file extension. You can change the default behavior of Windows so that it displays file extensions by going to the “View” tab in File Explorer and checking the box next to the option to display file extensions. By default, Windows does not display file extensions. Even though this won’t prevent cybercriminals from forging file extensions, at least you’ll be able to recognize when files have been tampered with and steer clear of opening any files that could be dangerous.
Make the investment in a reliable antivirus program. Do not worry if you accidentally click on a malicious link or attachment because a good antivirus program will be able to warn you about the danger, stop the download, and prevent malware from establishing a foothold on your computer system or network. For example, Malwarebytes offers free trials of its antivirus and anti-malware programs before requiring users to subscribe to the service.
The latest in spoofing news
• Con artists are using phony bank phone numbers to defraud unsuspecting customers.
• Scammers impersonate trustworthy cybersecurity training companies in order to generate clicks.
• Spoofed addresses and anonymous sending are two examples if how new flaws in Gmail make it easy to steal.
• When three is just the right number: The term “Man in the Middle” (MitM) assaults are broken down below.
• Methods of spoofing extensions that are less well known
Visit the blog maintained by Malwarebytes Labs for additional reading material on spoofing as well as the most recent information regarding online dangers.
The beginnings of spoofing
The act of spoofing is not novel in any way. In point of fact, the use of the term “spoof” to refer to an act of deception dates back more than a century. The online version of the Merriam-Webster dictionary states that the origin of the word “spoof” can be traced back to an English comic named Arthur Roberts who worked in the 19th century. Roberts is said to have invented a game that involved cunning and deception. The game’s guidelines have been forgotten over the course of its history. We can only speculate that the game wasn’t particularly entertaining or that the people living in Great Britain at the time didn’t appreciate being made fun of. Regardless of the circumstances, the name of the game has endured, even if it was not successful.
It wasn’t until the early part of the 20th century that the term “parody” came to be synonymous with “spoof.” For a number of decades, whenever the terms “spoof” or “spoofing” were used, they were in reference to something humorous and positive; for example, the most recent film spoof by Mel Brooks or the latest comedy album by “Weird Al” Yankovic.
Spoofing is the term that is used most frequently today when discussing crimes committed online. Spoofing refers to the act in which a con artist or other online threat poses as another person or organization that they are not.