This article covers a real case that occurred this week.
1. The SMS That Starts It All
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
The user receives a message claiming they must renew their health card. The text includes:
- A link that is shortened or uses an unrecognizable domain.
- A message of urgency such as "renew now" or "avoid losing coverage."
This type of SMS is very effective because:
- The health card is a document that almost everyone possesses.
- The procedure seems routine and believable.
The trusting user clicks on the link.
2. The Fake Page: Legitimate Appearance, Malicious Intent
The website they reach perfectly imitates an official portal. It usually includes:
- Institutional colors and logos copied from the real website.
- Forms requesting personal data and health card information.
- A fake payment gateway where credit card details are requested.
Small payment amounts, if requested, are not the primary goal. The true objective is:
- To steal credit card data.
- In many cases, to install malware on the user's device.
In this case, the user completes the payment without noticing anything strange.
3. The Bank's Warning: A Suspicious Operation
Shortly after, the bank detects an attempted charge of €1,500 and preemptively blocks the card. This behavior is common:
- Scammers first test with a small charge (like those €2).
- If the payment goes through, they attempt a much larger charge.
- The bank's anti-fraud systems can detect this pattern and block the transaction.
Thanks to that block, the financial fraud does not materialize. However, the problem does not end there.
4. The Team's Analysis: Banking Malware Infection
When the user seeks help, their device is reviewed and something more serious is detected: banking malware installed on the system.
This type of malware usually:
- Intercepts online banking credentials and other services.
- Redirects traffic to fake websites that mimic official ones.
- Manipulates secure connections to steal sensitive information.
- Blocks access to antivirus or cybersecurity pages.
In this case, the malware had modified the system's hosts file, a classic technique to prevent the user from accessing:
- Antivirus websites.
- Cybersecurity services.
- Technical support or help pages.
This explains why the user had difficulty consulting reliable resources and verifying if the SMS or the website were fraudulent.
5. What Would Have Happened if the Message Had Been Analyzed First
This case serves as a reminder of the importance of analyzing any suspicious message before clicking. A link scanner or a URL reputation service could have shown:
- An unofficial domain, with no relation to the health administration.
- A hosted server in a country or provider unusual for a public body.
- A recent or doubtful SSL certificate.
- A history of phishing reports associated with that URL.
- A high risk level or clearly fraudulent status.
Analysis tools like ORTSLAB detect these types of pages in seconds.
6. Key Lessons From the Case
6.1. What Every User Should Remember
- Distrust SMS messages that ask to renew official documents via a link.
- No administration typically requests payments of €1–3 via SMS for procedures of this type.
- Do not enter card data on websites accessed from an unexpected message.
- Always check the domain: if the procedure is real, it can be done from the official website, not from a link received.
- Take bank warnings seriously: if a suspicious operation is notified, you must act immediately.
6.2. What a Technician Should Review
- Status of the hosts file to detect malicious redirections.
- Presence of banking malware or specialized Trojans.
- Browser extensions installed without consent.
- Fake certificates installed on the system.
- Malware persistence mechanisms at system startup.
7. Conclusion
This case demonstrates how an apparently simple attack can escalate quickly:
- A fake SMS that arrives at the right time.
- A convincing website that mimics the official one.
- A small payment that builds trust.
- Theft of card data and fraudulent use.
- Attempted high-value charge detected by the bank.
- Infection of the device with banking malware.
The good news is that prevention works. Analyzing a link before opening it, distrusting urgent procedures, and always checking the domain can prevent situations like this.
Next time you receive an unexpected message asking you to act fast, remember this real case: a single click can be the start of a chain of risks, but it can also be avoided with a prior analysis.
Fraude BEC: análisis forense real de una estafa por suplantación de proveedor de 79.500€How a Company Fell Victim to Supplier Impersonation Fraud: A Real BEC Case Analysis