Scammers are still sending us their fake Robinhood security alerts
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解其主要信息。 文章讲的是一个网络诈骗,骗子冒充Robinhood投资应用,发送短信给用户,声称检测到账户异常,要求用户点击链接进行安全检查。链接实际上是钓鱼网站,会窃取用户的登录凭证和其他个人信息,比如税号和社会安全号码。 接下来,我需要找出关键点:诈骗方式、钓鱼网站的特征、如何防范等。然后用简洁的语言把这些点串联起来。 要注意的是,用户要求不要用“文章内容总结”之类的开头,直接描述即可。同时要控制在100字以内,所以需要精炼语言。 可能的结构是:骗子冒充Robinhood发短信警告异常活动,诱导点击假链接获取信息。提醒用户不要回复或点击链接,并建议采取安全措施。 现在把这些整合成一段话,确保信息完整且简洁。 </think> 骗子冒充Robinhood投资应用发送短信警告账户异常活动,并诱导用户点击钓鱼链接以获取登录凭证和其他个人信息。提醒用户不要回复或点击可疑链接,并建议采取安全措施保护账户。 2025-10-15 15:42:57 Author: www.malwarebytes.com(查看原文) 阅读量:8 收藏

Robinhood logo

A short while ago, our friends at Malwaretips wrote about a text scam impersonating Robinhood, a popular US-based investment app that lets people trade stocks and cryptocurrencies. The scam warns users about supposed “suspicious activity” on their accounts.

As if to demonstrate that this phishing campaign is still very much alive, one of our employees received one of those texts.

screenshot scam text message

“Alert!

Robinhood Securities Risk Warning:

Our automated security check system has detected anomalies in your account, indicating a potential theft. A dedicated security check link is required for review. Please click the link below to log in to your account and complete the security check.

Immediate Action: https://www-robinhood.cweegpsnko[.]net/Verify

(If the link isn’t clickable, reply Y and reopen this message to click the link, or copy it into your browser.)

Robinhood Securities Official Security Team”

As usual, we see some red flags:

  • Foreign number: The country code +243 belongs to the Democratic Republic of the Congo, not the US, where the real Robinhood is based.
  • Urgency: The phrase “Immediate Action” is designed to pressure you.
  • Fake domain: The URL that tries to look like the legitimate robinhood.com website.
  • Reply: The instructions to reply “Y” if a link isn’t clickable are a common phishing tactic.

But if the target follows the instructions to visit the link, they would find a reasonably convincing copy of Robinhood’s login page. It wouldn’t be automatically localized like the real one, but nobody in the US would know the difference. Logging in there hands the scammers your Robinhood login credentials and allows them to clean out your account.

According to Malwaretips, some of the fake websites even redirected you to the legitimate site after showing the “verification complete” message.

They also warned that some scammers will try to harvest additional personal data from the account, including:

  • Tax documents
  • Full name
  • Social Security Number (if on file)
  • Bank account information

How to stay safe

What to do if you receive texts like these

The best tip to stay safe is to make sure you’re aware of the latest scam tactics. Since you’re reading our blog, you’re off to a good start.

  • Never reply to or follow links in unsolicited tax refund texts, calls, or emails, even if they look urgent.
  • Never share your Social Security number or banking details with anyone claiming to process your tax refund.
  • Go direct. If in doubt, contact the company through official channels.
  • Use an up-to-date real-time anti-malware solution, preferably with a web protection component.

Pro tip: Did you know that you can submit suspicious messages like these to Malwarebytes Scam Guard, which instantly flags known scams?

What to do if you clicked the phishing link

Indicators of compromise (IOCs)

www-robinhood.cweegpsnko[.]net

www-robinhood.fflroyalty[.]com

robinhood-securelogin[.]com

robinhood-verification[.]net


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using identity protection.


文章来源: https://www.malwarebytes.com/blog/news/2025/10/scammers-are-still-sending-us-their-fake-robinhood-security-alerts
如有侵权请联系:admin#unsafe.sh