Device Cloning & E-commerce Fraud: How Hackers Exploit Systems


Device cloning and clustering is a technique that is done by hackers where they send suspicious links to gain access to the device when clicked. These sessions are used for creating virtual machines that has unique IP, device name and configuration. These machines are used for looting the referral money in dollars. New Company pays each referral small amount of money for promotion of their newly launched apps or ecommerce website. Each session is capable of creation of 10000 virtual machines or more. In this way they can refund larger amount of money. Some people go randomly with engineered POS machine where they generate QR code, when scanned the device is then compromised and is accessed remotely when user is at sleep.

Sim swapping is also used in which once the session is established then UPI apps are being used for changing the sim from the target device then UPI transaction are done and in such a case customers don’t get bank notification of the debit on their mobile number. They also have a technique of IMEI duplication where the device registration can also be masked without leaving any footprints. This makes them completely invincible.

Second strategy is that they order innumerable articles on the different address locally on different dates with cash on delivery options. There is delay in the transit as location or owner cannot be found. Then delivery agent cancels the order from their end. Using this they publish ai generated video and register complaint that the product is not delivered properly displaying all the order details. In this way ask for compensation and in pressure many company start sending expensive items for free. Logistic loophole detection is what they understand and take benefit. They use it as a tool of defamation of company and ask ransom and extortion money. They also take benefits from rival companies for doing such activities and tell them that they will never utter their names in public if caught.

Sometimes they send promotional banners where they ask customers to claim for the prize they won and call centre agents ask them for paying money to process their prize. At initial stage the amount is less, but they increase the prize slowly and loot the customers till their account balance goes zero.

In order to combat such a scenario, we need to build an extra protection software for ecommerce websites that is capable of detecting the animalities, unexpected traffic on site, track down the creation of account details effectively for generating proofs against court of law and help police or administration for tracking the hackers location and help them getting caught red handed thereby securing the customer's data and savings in their bank account.





Post a Comment

0 Comments