15.5.18

WannaCryptor: The curious tale of a ravenous cryptoworm



Do you still remember how WannaCryptor ran its – winding – course? It was a tale that revealed a number of intriguing plot lines amid the ransomworm’s numerous twists and turns.
You’ve no doubt heard about WannaCryptor, aka WannaCry or WCrypt, many times before, but there may still be things that have escaped you in the general hubbub of daily life. Here are a few tidbits that helped make WannaCryptor – and, indeed, the people involved with it in a good or bad way – stand out.
No need to play ball
First, unlike many of its malicious peers and contrary to initial reports, WannaCryptor did not rely on duping the target into clicking on a link in, or attachment to, a malicious email. Instead, the malware leveraged a software exploit known as EternalBlue. This tool, allegedly developed by the United States’ National Security Agency (NSA) and then stolen and dumped online by the Shadow Brokers hacking group, targeted a critical flaw in an outdated version of Microsoft’s Server Message Block (SMB) implementation, which is used mainly for file- and printer-sharing in corporate networks.
Having scanned the internet for machines with port 445 (conventionally associated with SMB) open, the attackers exploited the SMB flaw and went on to install another tool, DoublePulsar, thought to have been stolen from the NSA. This backdoor paved the way for the main payload that, once implanted and executed, encrypted the files.
Importantly, Microsoft released a critical security update for this vulnerability a full 59 days before the global outbreak. Furthermore, ports associated with any of the three SMB versions should never be exposed to the internet. In addition, Microsoft had advised a long time before the attack that the first version of SMB (SMBv1), which is some three decades old and for which the patch had also been released, should no longer be used. The bottom line? A compromise by WannaCryptor was completely avoidable even in the absence of an installed patch, simply by applying some basic security configurations. This, in fact, applies to measures against malware in general, as it often targets open ports and then exploits known software flaws.
Writhing worm and old’s cool
WannaCryptor’s worm-esque functionality had some eerie echoes of techniques from the days of yore (in computer terms, anyway). In fact, security folks had expected that ransomware would come to be paired with self-propagating worms to greatly aid and abet the main payload’s spread. Much like old-school worms – think Code Red in 2001, SQL Slammer in 2003, Sasser in 2004, and Conficker in 2008 – WannaCryptor, too, traversed vulnerable corporate networks voraciously, feeding off a security loophole for which a patch had been available for quite a while. This time, the malware packed a particularly powerful punch in that its main payload was ransomware that completely incapacitated the affected machines. “History doesn’t repeat itself, but it often rhymes”, as Mark Twain is sometimes believed to have said.
Once in a machine, WannaCryptor leveraged its worm functionality to feed on other vulnerable devices within the local network and on the open internet. As soon as another exposed machine was found and compromised courtesy of the same unpatched SMB loophole, it was abused for “paying it forward”, continuing the vicious cycle of compromising computers, encrypting files, and demanding ransom.
 The “deal” gone awry
Speaking of the main payload, ESET Senior Research Fellow David Harley recently pointed out that the malware’s operators were very unlikely to keep their side of the bargain even if the victims held up theirs. To elaborate on that point – there was no automated or practicable way for the attackers to know which victim had paid up and which had not. How can you possibly share an unlock code if you can’t ascertain if the victim has paid up?
In fact, the money side of things failed precipitously for the attackers considering the extent of the campaign and the damage it wrought – some 300,000 machines compromised, each in potential exchange for $300 (or, after three days, $600) for the decryption key. When the dust settled, the operators of the three Bitcoin wallets associated with WannaCryptor – to date unknown, by the way – emptied them in late July and early August, moving around some 52 bitcoin, worth US$140,000 at that time. If the attackers were indeed cashing out, it was hardly a windfall given the scale of the attack and the fact that many other ransomware campaigns rake in millions in profits with much less brouhaha and far fewer victims.
This, combined with some other quirks of WannaCryptor, has prompted many security practitioners to believe that the malware was never intended to be a money-grubbing machine. Instead, it has been called an elaborate disk trasher, or it may have been planned as a small operation that ended up getting out of hand.
Ten bucks
It’s not only in the Matrix that “everything that has a beginning has an end” (I left out “Neo” on purpose here). How did the WannaCryptor outbreak stop – for the most part, anyway? In a most anti-climactic fashion – with a “switch“.
As WannaCryptor was being foisted on users throughout the world, a 22-year-old malware analyst from England dived into samples of the code, noticing something peculiar about its behavior. The researcher, a Marcus Hutchins aka MalwareTech, saw that the malware tried to connect to a gibberish – and unregistered – domain.
Then, doing what those who track botnets for a living often do, he took possession of the domain for the sake of further insight into, and ultimately to stop, the attackers’ shenanigans. Except that this time, first, there was no botnet involved and, second, Hutchins apparently had no clue that, by buying the domain (for less than US$10) and making it “live”, the malware’s “kill switch” would be turned on. Thereafter, whenever WannaCryptor connected to the domain, the malware simply shut down, rather than starting its spreading and disk-encrypting routines. This was instrumental in slowing WannaCryptor’s propagation to a trickle within a few hours, earning Hutchins the possibly undeserved designation “[accidental] hero”.
In an odd twist – and much to the astonishment of many members of the security community – Hutchins was arrested at the Las Vegas airport in early August on charges that he had helped develop and spread a banking Trojan called Kronos (detected by ESET as Win32/Agent.QMH) in 2014 and 2015. The next month, security journalist Brian Krebs published a long piece, connecting Hutchins to several possibly unsavory online personas. Hutchins, who is now on bail pending trial and denies any wrongdoing, may face 40 years in jail.
On set
With WannaCryptor firmly in the rearview mirror, let’s hope … er, no, let’s not. “Hope is not a strategy,” as some prominent people, including film director James Cameron, have averred. Instead, let’s learn the lessons offered by the outbreak unless we want to provide fodder for a disaster movie. As far as I’m concerned, the tale of the WannaCryptor outbreak and much of what happened in its wake has all the makings of a Hollywood script.

13.5.18

Are firms and regulators prepared for GDPR?


The answer may hinge on if you’re a glass-half-full or glass-half-empty kind of person. While we’re at it, how about regulators’ level of preparedness, anyway?
With the enforcement of the General Data Protection Regulation (GDPR) just two weeks away on May 25 , organizations in the United Kingdom are further ahead in their preparations to comply with the law’s requirements than their peers elsewhere in the European Union and in the United States, a new survey by professional IT network Spiceworks reveals.
A total of 61 percent of UK-based firms said that they are or will be fully compliant with GDPR by the deadline. For the rest of the European Union, the ratio goes down to 46 percent. Meanwhile, only one in four US-based companies that are impacted by the new legislation will be ready in time.
What’s the reason for non-compliance? That depends on whom you ask. In Europe, more than 60 percent of the respondents that will not be compliant blamed a lack of time or resources. Across the pond, the most frequent reason – for 40 percent of respondents – was simply that GDPR was not a priority for their organization.
The survey polled 625 IT professionals in organizations in the United Kingdom, the rest of the EU, and in the United States in early April.
Over to you, regulators
A not-too-dissimilar picture is actually painted when it comes to those that are supposed to oversee the implementation and enforcement of greater privacy protections.
A Reuters survey has found that 17 out of 24 national or regional watchdog authorities or data protection officers in the EU that responded to the survey are ill-prepared to fulfill their GDPR-related duties when the law takes effect.
More precisely, the regulators said that they lack the necessary funding or powers to fulfill their GDPR duties. The shortage of authority is often because national governments have yet to update their laws to incorporate the Europe-wide rules. With that in mind, most respondents said that they would investigate complaints “on merit”.
In a nutshell, GDPR is intended to give power back to EU citizens over how their personal information is processed and used, including giving them “the right to be forgotten”. This means that individuals will be able to request that businesses delete their no longer necessary or accurate personal data. In addition, the law’s serious implications include data breach notification requirements and fines for non-compliance.
Further reading
We have previously covered the topic of GDPR extensively (including in a dedicated white paper) and will continue to do so as we get closer to the May 25 deadline.

11.5.18

One year later: EternalBlue exploit more popular now than during WannaCryptor outbreak



The infamous outbreak may no longer be causing mayhem worldwide but the threat that enabled it is still very much alive and posing a major threat to unpatched and unprotected systems
It’s been a year since the WannaCryptor.D ransomware (aka WannaCry and WCrypt) caused one of the largest cyber-disruptions the world has ever seen. And while the threat itself is no longer wreaking havoc around the world, the exploit that enabled the outbreak, known as EternalBlue, is still threatening unpatched and unprotected systems. And as ESET’s telemetry data shows, its popularity has been growing over the past few months and a recent spike even surpassed the greatest peaks from 2017.
The EternalBlue exploit targets a vulnerability (addressed in Microsoft Security Bulletin MS17-010) in an obsolete version of Microsoft’s implementation of the Server Message Block (SMB) protocol, via port 445. In an attack, black hats scan the internet for exposed SMB ports, and if found, launch the exploit code. If it is vulnerable, the attacker will then run a payload of the attacker’s choice on the target. This was the mechanism behind the effective distribution of WannaCryptor.D ransomware across networks.
Interestingly, according to ESET’s telemetry, EternalBlue had a calmer period immediately after the 2017 WannaCryptor campaign: over the following months, attempts to use the EternalBlue exploit dropped to “only” hundreds of detections daily. Since September last year, however, the use of the exploit has slowly started to gain pace again, continually growing and reaching new heights in mid-April 2018.
One possible explanation for the latest peak is the Satan ransomware campaign seen around those dates, but it could be connected to other malicious activities as well.
We must stress that the infiltration method used by EternalBlue is not successful on devices protected by ESET. One of the multiple protection layers – ESET’s Network Attack Protection module – blocks this threat at the point of entry. This can be compared to a silent knocking on the door at 2 a.m. testing if someone is still up. As such activity is most likely driven by malicious intentions, the entrance is securely sealed off to keep the intruder out.
This was true during the WannaCryptor outbreak on May 12, 2017 as well as all previous and subsequent attacks by malicious actors and groups.
EternalBlue has enabled many high-profile cyberattacks. Apart from WannaCryptor, it also powered the destructive Diskcoder.C (aka Petya, NotPetya and ExPetya) attack in June 2017 as well as the BadRabbit ransomware campaign in Q4 2017. It was also used by the Sednit (aka APT28, Fancy Bear and Sofacy) cyberespionage group to attack Wi-Fi networks in European hotels.
The exploit has also been identified as one of the spreading mechanisms for malicious cryptominers. More recently, it was deployed to distribute the Satan ransomware campaign, described only a few days after ESET’s telemetry detected the mid-April 2018 EternalBlue peak.
The EternalBlue exploit was allegedly stolen from the National Security Agency (NSA) probably in 2016 and leaked online on April 14, 2017 by a group dubbed Shadow Brokers. Microsoft issued updates that fixed the SMB vulnerability on March 14, 2017, but to this day, there are many unpatched machines in the wild.
This exploit and all the attacks it has enabled so far highlight the importance of timely patching as well as the need for a reliable and multi-layered security solution that can block the underlying malicious tool.


6.5.18

Google rolls out .app domains with built-in HTTPS



The move is part of the company’s HTTPS-everywhere vision for the internet


Google has rolled out .app, a new top-level domain (TLD) that is the first to require encrypted HTTPS connections for all .app websites, according to an announcement by the search giant’s CIO Ben Fried.
The company opened up .app domains for registration as part of the Early Access Program on Google Registry on May 1. The domains will be up for grabs for the general public through other registrars from May 8.
“A key benefit of the .app domain is that security is built in—for you and your users. The big difference is that HTTPS is required to connect to all .app websites, helping protect against ad malware and tracking injection by ISPs, in addition to safeguarding against spying on open WiFi networks,” reads the press release.
The domain is geared towards app developers in particular, although, in fact, Domain Name Wire quoted a Google representative as saying in March that the domain is not reserved exclusively for them. Some of the early adopters of .app domains are featured on get.app.

 “Even if you spend your days working in the world of mobile apps, you can still benefit from a home on the web. With a memorable .app domain name, it’s easy for people to find and learn more about your app. You can use your new domain as a landing page to share trustworthy download links, keep users up to date, and deep link to in-app content,” according to the announcement.
Google, which paid $25 million for .app in 2015, controls a total of 45 TLDs, including .how, .dad, .eat, .soy, or .google. According to the global domain name authority ICANN, the internet has 1,543 TLDs as of May 4.
The move is part of Google’s HTTPS-everywhere vision for the internet. In February, for example, the company announced that Chrome 68, due in July of this year, will mark all HTTP websites as “not secure”.
Finally, a quick note: HTTPS, or Hypertext Transfer Protocol Secure, encrypts web traffic, making sure that submitted data is safe from prying eyes while in transmission. It is, therefore, important to check for the presence of HTTPS in the browser’s address bar whenever we submit sensitive data to a website. However, the protocol’s presence alone does not automatically guarantee safety from a number of other threats. Even a site that has HTTPS can be malicious: phishing sites, for example, have been increasingly embracing HTTPS.

3.5.18

World Password Day: Recycling is a must, but why would you reuse your password?



World Password Day, celebrated on the first Thursday of every May, is a timely reminder of the fact that our passwords are the key to a wealth of personal information about us. However, poor password practices, including the use of the same password to access multiple accounts, can create serious risks and undermine our privacy and cybersecurity.
It would be nice to imagine that if the various contenders for “inventor of the password” had known how much of a hassle its computer variety would end up posing centuries later, they would never have bothered. Or maybe that inventor – perhaps a Gileadite or Roman soldier – just didn't care about the tradeoff between security and convenience that would plague us in the internet era. Either way, the legacy of the military watchword is here to stay.
Quipping aside, the routine works like this: you sign up with your username and password that only you know, and you’re golden. To log in again, you just need to recall and input your login credentials. Of course you knew this would happen, so you took some “precautions”: you set up the account with an easy-to-remember password.
And therein lies the problem. “Easy-to-remember” most often equates to short and simple, as well as easy to guess. That’s especially true for password-cracking software doing the bidding of an operator intent on brute-forcing his way into your account. Such software can open the trove of treasures just as magically as the phrase “Open Sesame!” does with the mouth of a cave in a well-known folk story.
On the flip side, a password that is long, complex and random is harder to crack, but also harder to remember. And therein lies the problem (yes, again!). Recalling many impossible-to-guess passwords and being able to remember to which particular online service each belongs is just too much of a tall order, unless you have the memory of an elephant.
Indeed, passphrases – say it with me, “I LOVE to Read WeLiveSecurity!” – may help both in terms of security and convenience (the latter being simply a proxy for memorability). However, is it reasonable to expect every user to remember a distinct passphrase or password for each and every online account?
Something’s got to give
What many people do – at least those who are not elephants – is skimp on their security, use an atrocious password (“123456”, anyone?) and go on their merry way. Until their accounts are hacked and their online personas are compromised or, worse, their identities and money are stolen. After all, it is human nature to disregard risk until disaster strikes.
Indeed, it feels like you can’t have it all; that is, many online accounts, each of which has a supremely strong, unique and memorable password or passphrase. It is little wonder that our patience wears thin and we take mental shortcuts. Enter another coping strategy that greases the wheels of hacking – password reuse.
While being antithetical to userland security, you can bet your last dollar that password recycling is invariably right up there with all the other most frequent and ill-advised offenses committed by users in the realm of authentication. Passwords created with another oft-used strategy, which involves slightly modifying the password for each account (“partial reuse”), tend to be predictable and, thus, just as easy to crack.
Why is password reuse so risky?
The neighborhood that is the internet can be rather less than neighborly in many ways, doubly so when data breaches are a reality of our age. The breaches often expose login details that – if you use them to access multiple accounts – can be successfully exploited for attacks known as credential stuffing. This becomes particularly troubling when an attacker uses stolen or leaked access credentials that belong to one account in order to break into another – often higher-value – account. Thanks to frequent password dumps, user/password combinations are easy to come by, and often at little-to-no cost at that.
If a breach hits and the credentials aren’t stored with advanced salted-hash functions (think, for example, a hack against Adobe in 2013), a strong password, or even a passphrase, may not be enough to thwart an account-takeover attack if you use that password to access multiple online services.
Factoring in another factor
Many account-takeover attempts can be foiled with two-factor authentication (2FA). An added authentication factor provides an extra layer of defense beyond the simple passcode/password/passphrase and, in a way, fixes some of the inherent human foibles that are routinely exposed by our poor password choices.
So far so good. However, many online service providers have yet to implement 2FA into their authentication schemes. (You can check the status of various websites vis-à-vis 2FA here: https://twofactorauth.org/.) Additionally, as shown by a recent report about the adoption rate of 2FA among active Google accounts (lower than 10 percent), even if such an option has been available for years, most users simply don’t take advantage of it, be it that they’re unaware of it or apparently have bigger fish to fry.
There are other forms of authentication, of course, that may take some of the weight off our shoulders (and brains), be it biometrics (e.g. fingerprint or iris recognition) or algorithms to measure behavioral characteristics (e.g. typing rhythm) or others. Their availability and, by extension, adoption are nowhere near widespread, however.
Is there another way, then?
Well, yes, although it actually flies in the face of much advice dispensed by security folks. In 2014, Microsoft Research released a paper that suggested a different tack. In thinking of various online accounts as somewhat of a continuum, the paper averred that some degree of password reuse is inevitable, but that it should be reserved for low-risk, low-value services. Put differently, the reasoning went that all accounts are not born equal and should, therefore, be divided into groups according to value. ESET Senior Research Fellow David Harley weighed in on this approach, while hinting at its potential pitfalls, in this insightful piece.
On a different note, chances are that you won’t cull your online accounts all the way down to whatever number you can manage easily with unique and strong passwords or passphrases. Nor will you probably be willing to engage in some serious mnemonics or aspire to eligibility for a memory competition.
With that in mind, the easiest thing to do is, arguably, to put all of your passwords (strong and unique, of course) into a kind of digital safe. That vault is dedicated password management software that, ideally, encrypts and stores all of your passwords locally and offline.
Indeed, password managers are all the rage in password security and, intuitively, it is hard to deny their merits. In addition, recent research found that password managers benefit both password strength and uniqueness, although apparently this strategy works only if the passwords are generated by the software.
Either way, assuming that you trust the implementation of your password manager – and you wouldn’t use it if you did not, right? – then its security is largely determined by the robustness of your master password. That’s doubly relevant if you consider that you’re effectively putting all your eggs, including some made of gold, into a single basket. That basket could, in fact, become a single point of failure.
They shall not pass
To be sure, passwords are flawed. Except that, in our internet era, there’s no other ubiquitous method of user authentication. Having their impending demise predicted back in 2004, passwords may well have outstayed their welcome. However, it appears that it will still be some time before they go the way of the dinosaurs.
All told, some things in computer security are beyond the control of a regular user, but why not go and fix those that are? In a way, the persistently poor password practices of many other people give you a chance to be ahead of the pack. What’s not to like?

WiFi or Ethernet: Which is faster and which is safer?


There is a lot of debate about WiFi speeds and whether they can offer higher potential speeds than a cable connection, but in practice Ethernet connections turn out to be not only faster but also safer.
The era of technology we exist in leads us (and in some cases forces us) to be connected at all times. One of the consequences of this connectivity can be clearly seen in communications and in how we have gotten used to things happening instantly. Nowadays, we, as users of technology, see it as only natural to be able to obtain information or communicate with another person immediately.
In this context, for the most part we have two options for getting online: The first is wireless, via WiFi, and the second is through a network cable, commonly known as Ethernet. Let’s analyze these two options to see the differences between them and also take a closer look at the belief that network cables are always the best option.
Accessing the Internet via a network cable: Is it faster?
Naturally, the arrival of wireless connectivity was a great benefit as it allows us to keep our physical space tidier and avoid the need for lengths of cable between connected devices. But besides the convenience offered by wireless, when it comes to pure speed, a debate has been raging for some time now leading to a lot of disagreement: Which is faster, WiFi or network cables? The answer is straightforward, though: cable. Although WiFi is a newer protocol, there are a lot of factors in play (in fact we will only look at a few in this article) that influence whether one connection can be faster than another. Perhaps the main issue is the saturation of channels and the large number of default connections, which makes data transmission speeds less stable and generally lower.
Added to this is the effect of building structures, for example, concrete walls, swimming pools, and other building materials which cause a loss of signal and a reduction in performance, which affects the speeds achievable from a WiFi connection. Generally speaking, the higher the frequency, the larger the rate of absorption by walls and floors.
Of course, it is almost impossible to notice these slight, almost imperceptible variations during normal browsing. However, the differences in performance are more obvious when it comes to activities like playing an online game, sharing files on the network, or streaming ultraHD content.
To summarize, we can say that while there are different norms and standards for each type of connection, in general, a correctly installed network cable connection ends up being faster than a WiFi connection. When we look at the speeds offered by each protocol, for example the 802.11ac standard,  we need to understand that its stated speed of 6.5 Gb/s is the maximum theoretical speed (which is faster than Ethernet 2.5 at 6 Gb/s), but that in most cases it cannot actually reach its maximum potential as it is affected by the obstacles we just mentioned. For their part, Ethernet connections offer a more stable performance, as they are not affected by these issues or other external factors. To finish off, it is worth highlighting that a couple years ago the Cat.8 Ethernet protocol was launched. Its use isn’t widespread due to its high costs, but it can reach speeds as high as 40 Gb/s.
Accessing the Internet via Ethernet is more secure than by WiFi
If we think in terms of secure communications, the argument in support of wireless connections loses immediately if we compare it to Ethernet. Numerous kinds of attacks can be carried out remotely, such as deauthenticating a device, or cracking the encryption key to get into the network. Furthermore, in the past year we have seen the emergence of vulnerabilities like KRACK, which affects WPA2 (one of the most robust and widespread protocols), and which was likely the trigger that led to the development of the new WPA3, although this has not yet been launched. As well as this, an attacker could also block wireless communications, with greater or lesser degrees of success, through the famous signal-blocking jammers.
Lastly, another very common type of attack is one which uses fake access points, whereby the victim connects to an open network which was created by the attacker, who then spies on the user’s traffic and steals their data. Of course, these attacks are impossible to carry out remotely through an Ethernet network, as an attacker would need physical access to do so. For these reasons, cable connections are more secure than wireless, or, in other words, they offer a lower risk of incidents if you do not make great efforts to apply some of the various security measures available.
So, more cables and less WiFi?
Having read this far, you may have started to think about whether to update your network architecture and connect everything via Ethernet. Of course, for devices like smartwatches, tablets, cell phones and smart lighting, this option is out of reach.
To conclude, it is logical that the best way to transfer files between devices at maximum speed is via an Ethernet cable. It is important to clarify that the Internet speed you agreed on in your contract with your ISP makes no difference in this case.
Clearly, the need for mobility will have an impact on our decision, as will the number of ports available in our router. If you use a laptop and are constantly moving from one desk to another within the range covered by your WiFi, it may be impractical to restrict yourself to a cable, which would force you to stay in the same spot. With a desktop, though, things are different. While desktops can be fitted with a wireless card, this is only recommended when connecting an Ethernet cable between the desktop and the router is not possible. For network sharing devices and media players, cable connections are also best.
While the dream of cable-free devices is already possible, in many cases it is not the best option if you love high speeds. In the end, then, it all comes down to a question of priorities.
https://www.welivesecurity.com/2018/05/02/wifi-ethernet-faster-safer/?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+eset%2Fblog+%28ESET+Blog%3A+We+Live+Security%29

1.5.18

This test will tell you how likely you are to fall for fraud



The questionnaire measures a range of personality traits to distinguish people who are more prone to taking the bait than others.
Researchers have devised a test that gauges a person’s susceptibility to falling for online scams and other types of internet crime.
The freely available questionnaire – called “Susceptibility to Persuasion – II” (StP-II) and developed by scientists at the Universities of Cambridge and Helsinki – asks the participants a series of questions that reveal how likely they are to succumb to persuasive techniques.
The test’s first version, StP-I, was actually released five years ago. The new version has been described as “far more comprehensive and robust” than StP-I, however. The nuts and bolts of the new test are described in an aptly-called paper, “We will make you like our research: The development of a susceptibility-to-persuasion scale”.
The test revolves around ten categories that are used as predictors of “scam compliance”, i.e. one’s falling for fraud. The attributes measure various personality traits due to which some people may be more prone to falling victim to con artists than others.
The categories include premeditation, consistency, sensation seeking, self-control, social influence, similarity, risk preferences, attitudes towards advertising, need for cognition, and uniqueness. Each of them has been proven to be a factor in one’s susceptibility to persuasion, obviously in varying degrees and at various stages during the process. Of all the variables, however, the failure to envisage the possible consequences of one’s actions has been found to be the strongest predictor of scam compliance.
Upon completion, the questionnaire taker receives an automated interpretation of the results.
The researchers noted that there is generally a three-step pattern in scams. First, the victim views the offer as believable, then he or she interacts with the scammer and, in the end, the victim loses something of value to the fraudster.
According to the researchers, their “generalized modular psychometric tool” could also be useful for recruitment in specific professions, for the screening of military personnel, or for establishing the psychological profile of cybercriminals.
“While there is a commonly held belief that an individual can either be a victim of a scam or not, there is a growing amount of evidence that this is perhaps too simplistic,” the researchers said.