
Addressing Social Media Fraud: Insights from Netcraft's Robert Duncan In this weekend edition of Cybersecurity Today, host Jim Love discusses the growing issue of fraud in the cybersecurity landscape. Jim interviews Robert Duncan, VP of Product...
Loading summary
A
Welcome to Cybersecurity Today, the Weekend Edition. I'm your host, Jim Love. We've talked about the prevalence of fraud as part of the cybersecurity landscape and how fraud is many times the size of other cybercrimes, like ransomware, that seem to get a lot more attention. And so when this study crossed my desk, I had to pursue it and find out more about it. So today we have an interview with Robert Duncan. He's the VP of product strategy for a company called Netcraft. Welcome, Robert.
B
Hi. Hi, Jim. How are you?
A
Good, good. You're in, you're in the uk.
B
That's right.
A
But good for you. Yeah.
B
Okay, so I want to check out.
A
Tell us a little bit about who Netcraft is. I hadn't heard of you before until this report crossed my desk.
B
Sure. So Netcraft, we're a cybersecurity company focused on combating Internet cybercrime. So we've kind of two main focuses. One is on detection, the second is on taking action. So disruption and takedown. We're a global company and we work with governments and companies across the world trying to make the world a safer and better place to be online.
A
Great. Yeah. So you've been doing searches for fraudulent activity on social media platforms. Does that. And this led you to think about social media scams and you had a particular focus on truth social. But let's back up just for a second and talk about the overall fraud that you see going on on social media. What is the state of that right now?
B
Yeah, so it's a pretty interesting field. So it's a big space and there's a lot of variety across different platforms, different mechanisms. But if I can kind of give you a bit of background how we're operating and how we come across this kind of stuff. We've been thinking about scams that happen through conversations for about two years and they're distinct from lots of other different types of cybercrime that we see. So if you think about phishing, when you see a phishing website, it's fairly clear cut that something fraudulent is going on if you know where to look. So if you look at the URL, you can see. Actually that's not what I expect. You can say, well, actually, this probably isn't my bank if it's, you know, banklogin123xyz rather than the kind of what you're expecting. The difference here with these conversational scams is they really only unfold once you start a conversation.
A
So.
B
So you don't know, necessarily at the start. Some of these scams can really start with very, very simple messages like hi, or you know, is this Steve? And then you're kind of starting into a wrong number scam. They can really start in very innocuous ways and they work quite differently. You can't go out and find a scam like this in the same way that you could, for example, search the Internet to try and find a domain name that looks particularly suspicious. In this case, the scams, you really have to interact and you really have to be in the right space. The kind of same scam operates through text messages, through emails. It's really a way of talking to somebody one on one. And criminals would exploit whichever way they can to get that, that kind of level of interaction.
A
And this is a big deal. I mean, I was reading your report, Your report mentions 1 in 4Americans reported that they've lost money to fraud and that totaled about $2.7 billion. Is that all from social media?
B
I mean, not all of it's necessarily from social media. Different estimates vary. I think those estimates are talking about all online scams, many of which start on social media. But I don't want to pick on any individual social media platform too much because the plat, the problem is everywhere. It's not necessarily the case that one platform is the cesspit and everywhere else is clean. It's really quite a challenging space to operate in.
A
But you particularly pointed out Truth Social on this particular.
B
We started looking at Truth Social because it has a few interesting properties that are a little bit different to other platforms. There's really two main thrusts of what we were looking at. One was this type of conversational scam where you're receiving messages that are from scammers or criminals. And then the kind of scam evolves from there. There's a second element to that, which is the kind of more traditional phishing and malware type crime that's also prevalent on the platform. So really we kind of were taking a look at the platform from the perspective of what happens as a new user. So we didn't necessarily go into this looking for scams. One of our members of our team started investigating the platform and almost immediately was receiving inbound messages that turned out to be scams. So in the first hour, we got more than 30 messages that were scams. So we know that because we continued the conversations and so we could then be confident in saying, you know, this is a scam and we know what happened, we know what the scam was trying to do. And we can use that. That kind of talks to how our technology works on other platforms for how we interact with these scams at scale. So that's a particularly novel thing that we saw on Truth Social, and we think that's because the way that you start when you're a new user on the platform is a little bit different. So you end up being asked to join groups, and within these groups, when you're added, you can see a list of all the other members. And so that's kind of fertile ground for a criminal to say here I've got a big list of users that I know are interested in topic X. And that's a very good source of being able to then start sending messages to those users with the aim of trying to scan them. That's a little bit different to platforms like X or others, where the mechanism is quite different.
A
Yeah, it seems to be. They seem to be set up for that. Also, with the numbers that you've shown, it does seem to be a population that is ripe for. For the picking for these fraudsters. Did you find anything unique about the audience of Truth Social that might have contributed to this?
B
So one element of this is many of these scams rely on crypto. Crypto is a really great tool, both for legitimate use and for illegitimate use, because once you've made a payment on crypto, there's no going back, it's gone. And so that's a great tool for criminals because once the payments with them, they're free and dry, they can run away and launder the proceeds elsewhere. I mean, certainly some conjecture might be that certainly with the positioning from Trump and others, that you might expect a user on Truth Social may be more likely to have already have some familiarity with crypto. Maybe it's something that's less scary for them. Again, that's kind of conjecture from our side. There's no evidence necessarily to suspect that. And certainly that may be true on other platforms too. But certainly that's one element that might be a factor there.
A
Yeah, and I, you know, I mean, your report says that being Truth Social, people expect this to be truth on there, and that I think that's pretty. That's a fair expectation. It's not that they didn't go to Lies Social, they went to Truth Social. I think a lot of them are going there thinking, I'm going to find out the real story here. And I think that's a. And by the way, I'm not making fun of people on Truth Social. There's a ripe audience in social media everywhere. That is, as P.T. barnum said, one more in every minute. And you can't get into victim shaming here. But, but there are people who are more susceptible to these messages and, and they do tend to aggregate in social media.
B
I mean certainly that, yeah, there's some elements to that. I think from, from our perspective in the research, I don't think there was necessarily anything different to how the scams operated. We've definitely seen these scam paradigms everywhere. So I'm fairly confident that the threat actors that are working on Truth Social are equally happy to work on other platforms. They're kind of going to wear their user bases effectively. Yeah, we certainly expect that. When we think about cybercrime, it's a business and the criminals are making decisions based on cost and roi. So it's a case of once they've found a platform that works where they're able to send messages and they get outcomes that becomes easier to justify more investment into the platform from their perspective, very much like a traditional business, certainly from our, our understanding of how that.
A
Operates and the primary ways that they're doing this. Cash advances and you. Was one you talked about in the report and that's.
B
Yeah, there's a whole gamut of different ways of doing this ranging from gift cards. So a kind of fairly traditional scam involves asking the victim to send gift cards from well known stores to the criminal for them to then launder the money. The second way of doing so is using crypto payments. A third way of doing so is wire transfers. The way that that's being done is fairly well structured. So there's a kind of escalation from the easiest things to launder to the hardest things to launder. And that shows up in the scams that we interact with on other platforms as well. I'm kind of thinking about general picture of conversational scams that we see. This is kind of how it escalates in that order. When a wire transfer happens, that's fairly high risk for a criminal. Whereas gift cards and crypto, they're very low risk in terms of the consequences of being captured or caught. The payment being stopped is kind of fairly low. They just don't get the payment. There's no additional consequence to those.
A
And so, and I guess being social media, the conversational aspect of this is really the root of it. I start talking to you, I get to know you, then we start to introduce the scam slowly. I think one of the pig butchering scams that I, I just, and I'VE been, you know, I've been pitched this before as well, where somebody will come back to you and say there's going to be great returns in, in this, you know, so just invest a little bit in this crypto and, and then they'll show you great returns. I, I didn't go into it, but I know people would be attracted for that. You, you know, you put down a small, relatively small amount in there and then you see a return. Woo. I made this much money. I'm invest more and more. This extends to it. I was talking to someone in a police. This extends to a lot of money. I mean, some of these people are taken for substantial amounts. I, I, I find it just astounding. Sometimes hundreds of thousands, some of them lose their entire retirement savings.
B
Yeah. Operating in, in this way, we're kind of operating with these conversations. You tend to only see the first payment request. You don't see those because we never make, we're not making the payments. So we don't see, you know, payment two, payment three, payment four, payment five. Where you're building to these really big numbers. But you certainly see the star, the seeds of this. So part of the kind of threat intel that we can extract from this thing like these websites, these fake investment platforms that are being used for these pig butchering scams kind of comes out of the woodwork through the conversation. In many cases they can be sites that you wouldn't necessarily be able to find if you were starting from scratch. Sometimes they have usernames and passwords that get shared in these conversations that you aren't able to predict. So if you came across the website as a cyber security company or a good system trying to find bad stuff online, sometimes you can't find them because they're behind passwords and only the victims have access. So only the victims have access to the site. And then that makes it very hard to find these except through mechanisms. By having conversations and being able to run these scams through. That's kind of where there's a pretty interesting use case there.
A
So these sites are hiding behind pretty good security. At least they've got good passwords.
B
Well, some of them yes, some of them no. So there's a mix. And we certainly see that mix through other types of cybercrime. Like thinking about phishing, you can really go from a threat actor who has no technical experience at all, has copied a phishing kit from somewhere or purchased a phishing kit, pushes a button and they, you know, they're off. It's that easy. The downsides of that approach is that obviously those of lower technical sophistication, they're easier to detect, easier to find, easier to decide that those are bad. That can really go to very sophisticated actors who are spear phishing. They're sending a handful of emails to a handful of selected people that they've worked very hard to research and they can provide very sophisticated resources to. That's kind of the same thing.
A
Are you seeing any, any real use of deep fakes? We hear a lot about it. Are you encountering a lot of that in your research?
B
That will vary. So most of the research we're doing is through messages. So we're sending and receiving messages. So there will be images in there that are either deep fakes or they've been modified in some way. There definitely are cases of, you know, I've seen certainly in industry research and media some pretty sophisticated examples of deep fakes. Like many have heard of the incident in Hong Kong where certainly was tricked into making very large corporate payments through deep faked video. That's certainly something that exists, something that we certainly didn't see in the context of this, this research here on Truth Social. Not to say that it doesn't exist, but certainly not something we came across.
A
I saw a story yesterday and sometimes you just got to give yourself a shake and wonder how people believe these. But there was a person who was taken in by deep fakes of Brad Pitt thinking that he had a relationship with her. I mean, these are lonely people who get taken advantage of. Doesn't social media have a responsibility to do more on this?
B
I mean that's a. It's pretty easy to say, yes, that there's lots of opportunities to improve. When you get into the detail, it can become a lot blurrier about where that line is between impersonation and where that line is between parody. Many of these platforms, when the peer to peer communication is encrypted, the platform themselves don't actually know what's being said between these two parties. And so it becomes a much more challenging environment to think about how you know, who should do what. It becomes a lot more challenging to say, well okay, the providers should stop that. It's a lot harder than that.
A
I hear you, but I'm going to challenge on that. I've got Google email and it's encrypted from my browser to whoever goes there. And, and yet Google will warn me to say, hey, this person isn't in your network. Or are you sure you really want to say this? This is something that These platforms could implement, but they just don't seem to want to.
B
I think that there's also a big difference in her jurisdiction behavior. Certainly if you, you read the news media, many of these large platforms have different behavior in, in different jurisdictions and that's in response to government legislation that directs these providers to act in a certain way. So I certainly think that there's precedent for having different or more stringent approaches in different geos. So for example, in Australia they're talking about banning under 16s from social media. And that's something that many of these platforms, if they want to have Australian business will be forced to implement. And I would expect that, that that would be functionality that they only deploy in Australia because that's where they've been asked to do that. And certainly the same thing's true in the uk, the us, eu, there's different frameworks in place and certainly some platforms have very different approaches to these. I mean, I'm not the right person to comment on platform publicly, but certainly there's a big range in behavior.
A
Yeah, I know. Well, Mark Zuckerberg famously dropped moderation in the US because they don't need. I'm sorry, I'll be, I, I'm too cynical about this. I, my trust of Mark Zuckerberg's motives is, I must admit, not, not great.
B
There's actually something interesting in that announcement that there was going to be more focus on fraud. So that's a double edged sword potentially. So there's a difference I guess between content moderation on political topics and fraud. Fraud is, is quite different and there's I think precedent for that being kind of a carbide for potentially those kind of changes in policy.
A
They're good to point that out. Yeah, like I said, I'm quite critical of Zuckerberg just because, but I noted that the point was that although they dropped the moderation in the US Brazil jumped in and said not a chance. And they're saying, well, we're only going to drop the moderation in the US for now. And I think European regulation tends to be a little more strict than that in the US as well. So they can adapt if I guess maybe if they're not doing this voluntarily, maybe the way to go is regulation to say you've got to have some sort of protection for people. I get upset about this because like I said, I hear about these stories and like I said, we do programs with law enforcement as well. And when you see somebody's lost their entire retirement savings, you could say you're Silly or you're stupid or whatever. But that's not fair. These people, some of them are taken advantage of and lose everything they have. A company may be able to recover even from paying something like this or a loss or maybe insured, but most of these individual people on social media don't have that protection.
B
I think it's very important not to victim shame. I think there's lots of circumstances where even experts can be tricked. Certainly in many cases I've seen that be true. So social engineering works because people are people, people are built. Maybe Truth Social is actually a good example here because people are thinking, well, I'm looking for truths and they're thinking about it from a open frame of mind that they default trust people. And that behavior is unfortunately quite dangerous on the Internet. Default trust is probably a natural human disposition, but is actually quite dangerous on some platforms in some, some parts of the Internet.
A
Yep. Your report also pointed out a lot of brand impersonation going on as well. And yeah, there were. One of the things was, and we've all seen these sites where you pretend to be a brand and you know, and log people in and what they probably don't notice is any, any password and email will work. You know, they don't probably check the, the password, but then they try and get your banking information. Pretty classic scam. Is the, is this something you're seeing more and more of or is this, is it growing? Is it the same?
B
The True Social aspect of this is quite interesting. So yeah, that type of brand impersonation and phishing and other types of attacks is not shrinking. So that is not going away. The use here, I think of Truth Social is quite interesting because in essence it's being used as a tool to hide the real destination of a link. So the use case we've seen is that there's certainly one product we've been tracking, likely French speaking, probably in France. And they are using Truth Social as a way to disguise the destination of a link. So they'll send out a phishing email. You know, the standard security advice is to hover over the link to see where it goes. And in this case you'll see truesocial in there. You won't see the destination site because they've used Truth Social to redirect visitors from the link through to the phishing attack. The ability to kind of hide that redirect through True Social is not something that's necessarily unique to the platform. Many of the platforms have these of link shorteners. I think what's different here is that the behavior is quite, quite well adapted to hiding what is happening based on how it operates.
A
If you're using a Link shortener on LinkedIn for instance, it warns you you're leaving the platform. Are you saying that Truth Social doesn't do that?
B
No, I mean many, many other, you know, there's many tools that work in the same way. The difference here is that it's fairly obvious and transparent. If you look at that particular threat actors profile, they've just got a big, big list of malicious URLs in their, in their profile and it's a pretty effective way of hiding the destination. So many of the particularly there's some technical details about how that redirect happens that make it quite hard for, you know, recipients of those mails to work out what's going on. In other cases some of those redirects can be followed automatically and you can kind of get to the end site and know where that's going to go. For Truth Social that's a lot harder because you need to be using a specific set of browsers configuration to be able to actually follow those links. So most denote carts won't be able to follow those links. So you click browser and you're off to the fish sign. And you didn't really have any expectation that would happen.
A
Is there more that companies could be doing to protect people from brand impersonations?
B
I mean certainly we would expect that platforms like this that are public facing and allow user generated content have some mechanism of disrupting fraud. So that can either be through mechanisms where security companies like ours can alert them to that being the case or in other cases they can be proactive and use tools to detect these types of threats and stop them before the victim is able to find that functionality. So there definitely are things that can be done in other platforms I'm aware of. Do think very carefully about how they think about linking out to external websites either like you said, going through a warning post saying actually you're leaving the platform, do you kind of know that you're doing that and do you want to do that? In other cases that I'm aware of, other platforms also use the same techniques to be able to automatically kind of block that event links. Wow.
A
So this is a pretty interesting piece of research and we'll, we'll put a link to it in our show notes. What's next for you guys? What are you, what are you looking at next?
B
Good question. We've got, we've got you know, five or six different topics coming next. So we're still thinking about threats just like these. So we're thinking about conversational scans, we're thinking about phishing, we're thinking about malware. There's, there's lots coming up. We definitely don't, don't see this stopping. Despite the good work that companies like ours and others are doing in this space, it's a never ending problem that is going to be hard to get rid of. Crime exists in the physical world. Crime exists in the electronic, digital world too. And I think it's going to be a battle that we have to keep fighting and we're pleased to do that.
A
Yeah, but it's great to bring attention to it. Like I said when we started this conversation out, we tend to focus on ransomware, we tend to focus on technical threats. Those make the news and behind this.
B
Is the big deal. Yeah, certainly. I remember some stats from the UK that more than half of all crime that's reported is fraud in some way.
A
And in many cases, unfortunately, you know, the policing funding, I don't know what it's like in the uk, in Canada, it's terrible. There's not enough funding going into this area. You can. Because street crime and things like that take precedence and other things take precedence. And these are the people who do this work are thought of as administrative and yet they are anything but. They are active feet on the Internet street of trying to prevent real crime. So bringing attention to this is a good thing. Thank you so much for doing that. Love to have you back when you get your next report out. So ping me and let me know. As I said, I'll put a link to this report in our show. Notes for everybody and thanks for coming by. My guest has been Robert Duncan, VP Product Strategy with Netcraft. And as I said, I'll put a link in the report. I'll put a link in the show. Notes to the report. Thanks again, Robert.
B
Thanks, Tim.
A
And thank you for tuning in and spending this time with us. We always love to hear your comments. You can reach me at editorialech Newsday and if you're one of our growing audience on YouTube, you can give us a comment there. I check them regularly and try to respond to everybody. I'm your host, Jim Love. Thanks for listening.
Cybersecurity Today: Social Media Fraud Targets Truth Social – Detailed Episode Summary
Episode Title: Social Media Fraud Targets Truth Social: Cyber Security Today Weekend with Netcraft's Robert Duncan
Release Date: January 18, 2025
Host: Jim Love
Guest: Robert Duncan, Vice President of Product Strategy at Netcraft
In this episode of Cybersecurity Today: Weekend Edition, host Jim Love delves into the escalating issue of fraud within the cybersecurity landscape. Shifting focus from widely publicized cybercrimes like ransomware, Love brings attention to the pervasive and often larger-scale problem of fraud. To explore this topic, he welcomes Robert Duncan from Netcraft, a leading cybersecurity firm specializing in combating internet cybercrime.
Robert Duncan introduces Netcraft's mission as a global cybersecurity company dedicated to detecting and disrupting internet-based cybercrimes. With a focus on working alongside governments and businesses worldwide, Netcraft aims to create a safer online environment by tackling various forms of fraud and malicious activities.
Robert Duncan [00:45]: "Netcraft, we're a cybersecurity company focused on combating Internet cybercrime. So we've kind of two main focuses. One is on detection, the second is on taking action. So disruption and takedown."
Duncan highlights the diversification of fraud tactics across different social media platforms, emphasizing that fraud often outpaces other cybercrimes in scale. Unlike phishing, which is more overt and identifiable through suspicious URLs, conversational scams unfold through personal interactions, making them harder to detect until trust is established.
Robert Duncan [02:23]: "The difference here with these conversational scams is they really only unfold once you start a conversation."
Truth Social emerges as a significant target for fraud due to its unique user engagement mechanisms. New users are invited to join groups, providing scammers with access to large lists of interested individuals. This setup creates fertile ground for initiating scams through personalized messaging.
Robert Duncan [04:55]: "We're considering that Truth Social is being used as a tool to hide the real destination of a link."
Netcraft's research on Truth Social uncovered two primary scam vectors:
In their initial investigation, Duncan notes that within the first hour, over 30 scam messages were detected, showcasing the platform's vulnerability.
Robert Duncan [03:54]: "In the first hour, we got more than 30 messages that were scams."
Cryptocurrency plays a pivotal role in modern scams due to its irreversible nature. Once a payment is made via crypto, it cannot be retrieved, providing scammers with a secure means to launder illicit funds. Duncan speculates that Truth Social's user base may have a higher familiarity with crypto, making them more susceptible to such scams.
Robert Duncan [06:09]: "Crypto is a really great tool, both for legitimate use and for illegitimate use... they're free and dry, they can run away and launder the proceeds elsewhere."
While deep fakes are a growing concern in cybersecurity, Duncan indicates that their prevalence varies. In the context of Truth Social, deep fakes were not a significant finding, although they remain a potent tool in other cybercrime arenas.
Robert Duncan [13:21]: "We certainly didn't see [deep fakes] in the context of this research here on Truth Social."
A notable tactic involves scammers impersonating reputable brands to deceive users into divulging personal information or credentials. On Truth Social, threat actors exploit the platform's link handling to mask phishing destinations, making it challenging for users to identify malicious URLs.
Robert Duncan [20:50]: "The ability to kind of hide that redirect through Truth Social is not something that's necessarily unique to the platform, but it's quite effective here."
Duncan and Love discuss the complexities platforms face in moderating fraudulent activities without overstepping into content censorship. Encryption and jurisdictional differences further complicate the implementation of effective safeguards. While Jim Love advocates for more proactive measures akin to those employed by email providers like Google, Duncan emphasizes the diverse regulatory landscapes that platforms must navigate.
Jim Love [15:37]: "Google will warn me to say, hey, this person isn't in your network. Or are you sure you really want to say this?"
Robert Duncan [16:52]: "There's a big difference in her jurisdiction behavior... different frameworks in place."
Looking ahead, Duncan outlines Netcraft's commitment to addressing various cyber threats, including conversational scams, phishing, and malware. Acknowledging the perpetual nature of cybercrime, he emphasizes the necessity for continuous vigilance and adaptation in cybersecurity strategies.
Robert Duncan [23:39]: "There's lots coming up. We definitely don't see this stopping. Despite the good work that companies like ours and others are doing in this space, it's a never-ending problem."
Jim Love wraps up the discussion by underscoring the importance of recognizing and combating fraud as a central component of cybersecurity. He commends Netcraft's efforts in bringing these issues to light and encourages listeners to stay informed and vigilant.
Jim Love [24:42]: "These are the people who do this work are thought of as administrative and yet they are anything but. They are active feet on the Internet street of trying to prevent real crime."
Conversational Scams: Unlike traditional phishing, these scams develop through personal interactions, making them harder to detect until significant trust is established.
Truth Social's Vulnerability: The platform's group-based user additions facilitate large-scale scam attempts, with scammers leveraging features unique to Truth Social to disguise malicious activities.
Cryptocurrency as a Tool for Fraud: The irreversible nature of crypto transactions provides scammers with a reliable method for laundering illicit funds.
Brand Impersonation Techniques: Scammers must creatively exploit platform features, such as link handling, to mask phishing attempts and brand impersonations effectively.
Platform Moderation Challenges: Balancing user privacy, content moderation, and regulatory compliance poses significant challenges for social media platforms in combating fraud.
Ongoing Battle Against Cybercrime: The fight against cyber fraud is continuous, requiring persistent efforts from cybersecurity firms, platforms, and users alike.
For a deeper dive into the topics discussed, listeners are encouraged to access the full report linked in the show notes.