A dangerous spam scam designed to trick the unwary
We have, for many years, been recipients of fraudulent emails from South Africa, many of which use a fake address pretending to be from a bank.
This one arrived, purporting to be from Nedbank, a bank with which we do not have and have never had an account.
It fakes the address Nedbank Credit Card monthly Charges eStatement <ConsumerStatements@mail.nedbank.co. za>
The subject is Nedbank Credit Card monthly Charges eStatement
The body of the e-mail is
Dear Cardholder
We attach your card e-statement, which is password-protected to ensure confidentiality. To view your e-statement you'll need Adobe Reader, which you can download from adobe.com if you don't already have it.
The password to open the document is the identity or password number you used to open your account.
If you have any questions, call us on 0800 555 111 or 011 710 4710.
For more information on your credit card benefits or other Nedbank products, visit nedbank.co.za.
Kind regards
The Nedbank TeamHow to verify the integrity and origin of this email
1Check whether the message has been signed by the sender.
2Be on the lookout for a security warning when opening this email to alert you that the message might have been tampered with, or that it might not come from the supposed sender.
3Simply click on the red ribbon icon and choose the option to view the digital identity or the certificate to verify the sender's digital identity.
Disclaimer | nedbank.co.za | Contact us
T & Cs apply.Nedbank Ltd Reg No 1951/000009/06. Licensed financial services and registered credit provider (NCRCP16).
There is an attachment "Nedbank Statement.html". To open such a document is risky, for the same reason as it is risky to allow html mail to be displayed in your email account. It is much safer to decline to open any html document, be it email or an attachment.
In this case, we disabled the active text in the document so we could inspect it. If you don't know exactly what you are doing, don't try that at home, or work.
The document includes many "assets" directly copied, actually imported when the document is opened as a webpage, from Nedbank's official website.
It also incudes an active script which, interestingly, suggests that the script, intended to create a copy of that website, has been in use for some time as it includes references to material that is covid19 specific. Very few websites still include such references.
Importantly, no credentials are required to view the document's source code. Amusingly, it contains a line "protect yourself from the latest SARS scams" - in South Africa, SARS is not a disease: it's the South Africa Revenue Service i.e. the tax office. There is also the line "There has been an increase in online fraud in the banking industry with some of the latest scams involving fraudsters prompting you to click on a link in an email or SMS."
Buried amongst many adverts is a login form. It takes the logo from the "secured" part of the Nedbank site. More than 800 lines into the document, is the part the criminals want you to get to.
"Please enter your Nedbank ID username and password to log in." The form is generated locally, on your PC, it is not generated on the bank's server and transmitted to you. There is no obvious validation: the form accepts whatever you enter, as it must because it is not connected to the bank's records.
Somewhere in the 1344 lines of code, there will be somewhere that the data is sent. We found links to a telegram account, to an account on Google and several others but have not identified which one or ones would get your login name and password.
Fraudsters are helped by some of the things you think of as convenient, or just pretty.
The lesson here is as is often made in SAFE WORD: NO. Never allow HTML email to display on your device and never click on an attachment unless you know what it is and are expecting it.



