惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Cisco Talos Blog
Cisco Talos Blog
P
Privacy & Cybersecurity Law Blog
I
Intezer
Y
Y Combinator Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
N
Netflix TechBlog - Medium
The Hacker News
The Hacker News
AWS News Blog
AWS News Blog
aimingoo的专栏
aimingoo的专栏
A
About on SuperTechFans
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Stack Overflow Blog
Stack Overflow Blog
Hacker News: Ask HN
Hacker News: Ask HN
酷 壳 – CoolShell
酷 壳 – CoolShell
量子位
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
B
Blog
T
Tor Project blog
C
Cybersecurity and Infrastructure Security Agency CISA
云风的 BLOG
云风的 BLOG
博客园_首页
V2EX - 技术
V2EX - 技术
T
Threat Research - Cisco Blogs
腾讯CDC
宝玉的分享
宝玉的分享
博客园 - 叶小钗
罗磊的独立博客
S
Securelist
The Last Watchdog
The Last Watchdog
Google Online Security Blog
Google Online Security Blog
Scott Helme
Scott Helme
博客园 - 司徒正美
W
WeLiveSecurity
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Secure Thoughts
NISL@THU
NISL@THU
N
News and Events Feed by Topic
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
雷峰网
雷峰网
大猫的无限游戏
大猫的无限游戏
K
Kaspersky official blog
IT之家
IT之家

Comments for Securelist

Telegram phishing bots and channels: how it works An unknown actor distributes malicious VBS scripts via WhatsApp MiniPlasma: detecting exploitation Argamal: Malware hidden in hentai games Containers on fire: from container escapes to supply chain attacks What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and Free Internet Kimsuky targets organizations with PebbleDash-based tools State of ransomware in 2026 Copy Fail: root on virtually any Linux Popular DAEMON Tools software compromised Congratulations, you’ve won! The reality behind online lotteries Operation ShadowHammer: a high-profile supply chain attack PhantomRPC: A new privilege escalation technique in Windows RPC Operation Triangulation: The last (hardware) mystery Scammers’ delivery service: exclusively dangerous Operation Triangulation: iOS devices targeted with previously unknown malware Anatomy of a Cyber World Global Report 2026 Operation Triangulation: iOS devices targeted with previously unknown malware TGIF(P) - Thank god it’s fried phish TGIF(P) - Thank god it’s fried phish The Flame: Questions and Answers Story of the year: the impact of AI on cybersecurity Story of the year: the impact of AI on cybersecurity The game is over: when “free” comes at too high a price. What we know about RenEngine The game is over: when “free” comes at too high a price. What we know about RenEngine The game is over: when “free” comes at too high a price. What we know about RenEngine Arkanix Stealer: a C++ & Python infostealer Tusk: unraveling a complex infostealer campaign
‘Nigerian’ Letters - Now With a Syrian Twist
Manuela Rijk · 2026-04-26 · via Comments for Securelist

Spam and phishing

Spam and phishing

minute read

The continuing conflict and the complex political situation in Syria have created the perfect conditions for new ‘Nigerian’ scams. In recent months, there has been a surge in the number of Nigerian letters that contained some sort of reference to Syria; scammers sent messages both in the names of ordinary citizens of that country and on behalf of representatives of banks and humanitarian organizations. The texts of the messages made frequent use of words such as “turmoil”, “crisis” or “revolution”.

The scam messages, written in the names of representatives of reputed Syrian and UK banks, stated that their clients would like to transfer their multi-million savings from their accounts because of the unrest in Syria, and were looking for a partner who would help them to do so. Naturally, “compensation” was offered, of which the scammers were ready to tell the recipient either immediately or once they had received a reply. The scammers gave a contact phone number and an email address; the latter could be either the sender’s address or the personal email of the “bank’s client” who allegedly needed help. The scammer’s aim was to entice the victim into an email exhange. After all details of the future partnership are discussed, the victim will most probably be asked to perform a service, e.g. transfer a small amount of money to pay for the mediator’s services. When the money is transferred, the scammers will vanish just as suddenly as they appeared.

The scammers posed as members of the International Committee of the Red Cross, and told the sad story of an oil trader who had died in the Syria turmoil, and whose fortune was saved by a Red Cross employee. As you might expect, the sender asks for help in transferring and looking after the money. The recipient of the letter would supposedly receive the promised millions in a parcel that would first be delivered to Iraq and then to the recipient’s country of residence. For his or her help, the recipient is promised half of the money. In addition, the scammers state they would welcome any advice or assistance on how to make a profitable investment. The scammers give a personal email address for contacting them.

Some of the emails we have seen appear to have been sent using the names of ordinary people, and came in a variety of flavors. For instance, a “teacher from Syria” asked in one message to help orphaned children who had inherited a large sum from their parents to leave the country and invest the money.

Other Nigerian letters are allegedly written on behalf of people who are critically ill and who would like to donate some of their money. The letters ask their potential victims to help them do so. Other messages are very brief, contain no proposals for cooperation and only suggest getting to know the recipient better. This is a trick aimed at getting the victim’s attention and enticing them into further communication.

The Nigerian scammers use a wide variety of tricks; one thing they have in common, however, is that all messages take advantage of people’s natural desire for “easy” money and to help people in distress. The scammers concoct all sorts of stories – at times, far-fetched – and use the names of well-known people and major events to make the victim believe them. Of course, users should not respond to these types of emails. Otherwise, once you find yourself in communication with a Nigerian scammer, you risk losing your money.

  • Latest Webinars
    Reports

    Kaspersky researchers analyze updated CoolClient backdoor and new tools and scripts used in HoneyMyte (aka Mustang Panda or Bronze President) APT campaigns, including three variants of a browser data stealer.

    Kaspersky discloses a 2025 HoneyMyte (aka Mustang Panda or Bronze President) APT campaign, which uses a kernel-mode rootkit to deliver and protect a ToneShell backdoor.

    Kaspersky GReAT experts analyze the Evasive Panda APT’s infection chain, including shellcode encrypted with DPAPI and RC5, as well as the MgBot implant.

    Kaspersky expert describes new malicious tools employed by the Cloud Atlas APT, including implants of their signature backdoors VBShower, VBCloud, PowerShower, and CloudAtlas.