Scammers Exploited Official EU Website for ‘Piracy’ Scams

Scammers exploited a subdomain of the European Food Safety Authority to actively redirect people to piracy scams and other dubious ploys. The pages that promised free content, including Super Bowl streams, appeared high in Google’s search results. After being alerted, the EU agency swiftly addressed the vulnerability, but further vigilance is advised.

From: TF, for the latest news on copyright battles, piracy and more.

eu digitalIn an effort to make online piracy less visible, search engines actively downrank and de-index pirate site domains.

This works, in the sense that it makes it harder for prospective pirates to bump into these sites though searches. It also created new problems and exacerbated others in the process.

Scams Galore

Since the top positions in search results are relatively free of well-known and generally more trusted pirate sites, malicious actors use this void to get piracy-related scams featured instead. To do so, they create keyword-filled pages using titles of high-demand content, paired with keywords such as ‘download’, ‘stream’, ‘free’, and so forth.

To increase the effectiveness of this tactic, the scammers try to get their shady promotions featured on reputable domain names, such as universities, IMDb, and social media platforms.

This is a problem we’ve highlighted previously, including frequent targeting and abuse of official European Union websites (europa.eu). The EU is taking countermeasures to limit the abuse but ending it permanently appears to be a challenge.

EU Subdomain Exploited

This week we discovered what is likely one of the more egregious exploits of the Europa.eu domain. As it turns out, scammers found a way to use a subdomain of the European Food Safety Authority (EFSA) website, mgmt-test.efsa.europa.eu, to promote their dubious schemes.

What was particularly concerning was the automatic redirection of users who clicked the link, to a scam website where they could ‘sign up‘ for an account. Those sites typically ask for credit card details, which may then be abused in the future.

Over the weekend, a site offering free access to a Super Bowl stream was particularly popular. Different variations appeared in search results, as shown below.

Super Bowl scam

super bowl scam

Similar promotions were seen from the same EFSA subdomain, linking to adult content including Onlyfans leaks, and traditional copies of pirated movies. Needless to say, people who stumbled upon these through search engines, didn’t get what they were looking for.

Moana

moana

Previous scams typically involved uploaded PDF files or user-generated content containing links to scam sites. The recent exploit redirected visitors automatically, which presumably made it more effective.

EFSA Leak Fixed

After alerting EFSA, the organization was quick to address the issue and the affected subdomain was taken offline in a matter of hours. At the time of writing, the redirects are no longer active, and the associated pages have started to disappear from search engines.

Of course, this doesn’t mean that all will be fine from now on. Caution is certainly advised. Over the past few days, dubious content has been posted to other EU websites as well, including the European Social Fund+ and the Interoperable Europe website. And there will likely be more holes to patch going forward.

More Problems (all addressed)

other domains

This problem isn’t limited to the EU websites either. GitHub continues to be targeted, and it wasn’t hard to spot these scams on other reputable sites, including those of the University of Melbourne and Taylor County in Texas.

Looking at the big picture, it’s ironic that piracy downranking measures by search engines like Google have inadvertently created an opportunity for scammers. They are now leveraging those same search engines by exploiting third-party sites.

From: TF, for the latest news on copyright battles, piracy and more.

Qualcomm Snapdragon 6 Gen 4 is coming to mid-range phones

Qualcomm’s new Snapdragon 6 Gen 4 is a mid-range smartphone chip with support for features including cameras up to 200MP, 4K game upscaling, and lossless Bluetooth audio. It’s also the first Snapdragon 6 series processor to support on-devic…

Qualcomm’s new Snapdragon 6 Gen 4 is a mid-range smartphone chip with support for features including cameras up to 200MP, 4K game upscaling, and lossless Bluetooth audio. It’s also the first Snapdragon 6 series processor to support on-device generative AI capabilities. The chip maker says the first phones powered by the chip should be available […]

The post Qualcomm Snapdragon 6 Gen 4 is coming to mid-range phones appeared first on Liliputing.

Måke Califørnia Great Ægain: Lego-Manager sollen Silicon-Valley-Kauf verhandeln

Eine Petition fordert den Kauf des “am meisten ruinierten Bundesstaats der USA” durch Dänemark. Besser als in Grönland ist das Wetter dort allemal. Eine Glosse von Mike Faust (Crowdfunding, Lego)

Eine Petition fordert den Kauf des "am meisten ruinierten Bundesstaats der USA" durch Dänemark. Besser als in Grönland ist das Wetter dort allemal. Eine Glosse von Mike Faust (Crowdfunding, Lego)

After Putin sacked Russia’s space chief, the rumor mill is running red-hot

The Ukraine war has exacerbated Russia’s decline in space.

After a relatively short period of just two and a half years, the chief of the Russian space corporation Roscosmos, Yuri Borisov, was dismissed from his position last week. The Kremlin announced he would be replaced by 39-year-old former Deputy Minister of Transport Dmitry Bakanov.

An economist by training, Bakanov has worked in the past for a satellite communications company named Gonets. However, he is largely an unknown entity to NASA as the US space agency continues to partner with Russia on the operation of the International Space Station.

NASA had developed a reasonably good relationship with Borisov, who brought a much more stable presence to the NASA-Roscosmos relationship after his pugnacious predecessor, Dmitry Rogozin, was sacked in 2022.

Read full article

Comments

(g+) Columnstore-Indizes: Mehr Performance für relationale Datenbanken

Indizes in relationalen Datenbanken beschleunigen den Datenzugriff. Columnstore-Indizes im Speziellen legen noch einen drauf. Wir zeigen, wie es gemacht wird. Ein Deep Dive von Michael Bröde (Datenbank, Cloud Computing)

Indizes in relationalen Datenbanken beschleunigen den Datenzugriff. Columnstore-Indizes im Speziellen legen noch einen drauf. Wir zeigen, wie es gemacht wird. Ein Deep Dive von Michael Bröde (Datenbank, Cloud Computing)

If it moves, it’s probably alive: Searching for life on other planets

Scientists find a way to look for alien life that doesn’t need elaborate equipment.

The search for extraterrestrial life has always been a key motivator of space exploration. But if we were to search Mars, Titan, or the subsurface oceans of Europa or Enceladus, it seems like all we can reasonably hope to find is extremophile microbes. And microbes, just a few microns long and wide, will be difficult to identify if we’re relying on robots working with limited human supervision and without all the fancy life-detecting gear we have here on Earth.

To solve that problem, a team of German researchers at the Technical University in Berlin figured that, instead of having a robot looking for microbes, it would be easier and cheaper to make the microbes come to the robot. The only ingredient they were lacking was the right bait.

Looking for movement

Most ideas we have for life detection on space mission rely on looking for chemical traces of life, such as various metabolites. Most recent missions, the Perseverance rover included, weren’t equipped with any specialized life-detecting instruments. “On Mars, the focus was on looking for signs of possible ancient life—fossils or other traces of microbes,” says Max Riekeles, an astrobiologist at the Technical University Berlin. “The last real in-situ life detection missions were performed by Viking landers, which is quite a while back already,”

Read full article

Comments