CryptoChameleon

By Trilogy Financial
June 7, 2024
Share on:

CryptoChameleon is a phishing-as-a-service kit that makes it easier than ever for cybercriminals to create convincing phishing campaigns. Criminals often use it to impersonate reputable companies to steal passwords, account information, and other sensitive data.

 

A recent scam using CryptoChameleon targets LastPass, a popular password manager. Scammers pretend to be from LastPass, starting with seemingly authentic support calls. They later send follow-up emails with links to fake login pages, designed to look like legitimate LastPass sites. Once victims enter their master passwords on these fraudulent pages, scammers can access their password vaults and potentially lock them out of their accounts.

 

Reputable companies will never ask for your master passwords through phone calls, emails, or text messages. To protect yourself from these scams, remember to:

 

  • Hang up immediately if you receive a suspicious call claiming to be from LastPass or another reputable company.
  • Do not press any options in automated messages or clicking on links in emails from unfamiliar sources.
  • Report suspicious activity to the reputable company, including screenshots of suspect text messages and forwarded emails.

You may also like:

By
June Adams
May 10, 2021

Weak passwords can compromise the best security tools and controls. With a never-ending list of applications and services that users and consumers access, people may have dozens of passwords to maintain at any given time. Often, the temptation to use familiar terms such as pet names, favorite teams or the names of children or friends can cause risk since much of those details can be discovered by a simple examination of social media.

Creating strong passwords offers greater security for minimal effort. Weak passwords can compromise the best security tools and controls. With a never-ending list of applications and services that users and consumers access, people may have dozens of passwords to maintain at any given time. Often, the temptation to use familiar terms such as pet names, favorite teams or the names of children or friends can
cause risk since much of those details can be discovered by a simple examination of social media.

Under Lock and Key
You can buy a small padlock for less than a dollar—but you should not count on it to protect anything of value. A thief could probably pick a cheap lock without much effort, or simply break it. And yet, many people use similarly flimsy passwords to “lock up” their most valuable assets, including money and confidential information. Fortunately, everyone can learn how to make and manage stronger passwords. It is an easy way to strengthen security both at work and at home.

What Makes a Password ‘Strong’?
Let’s say you need to create a new password that’s at least 12 characters long, and includes numerals, symbols, and upper- and lowercase letters. You think of a word you can remember, capitalize the first
letter, add a digit, and end with an exclamation point. The result: Strawberry1!

Unfortunately, hackers have sophisticated password-breaking tools that can easily defeat passwords based on dictionary words (like “strawberry”) and common patterns, such as capitalizing the first letter.
Increasing a password’s complexity, randomness, and length can make it more resistant to hackers’ tools. For example, an eight-character password could be guessed by an attacker in less than a day, but a 12-character password would take two weeks. A 20-character password would take 21 centuries. You can learn more about creating strong passwords in your organization’s security awareness training. Your organization may also have guidelines or a password policy in place.

Why Uniqueness Matters
Many people reuse passwords across multiple accounts, and attackers take advantage of this risky behavior. If an attacker obtains one password—even a strong one—they can often use it to access other valuable accounts.

Here is a real-life example: Ten years ago, Alice joined an online gardening forum. She also created an online payment account and used the same password. She soon forgot about the gardening forum, but someone accessed her payments account years later and stole a large sum of money.

Alice did not realize the gardening forum had been hacked, and that users’ login credentials had been
leaked online. An attacker probably tried reusing Alice’s leaked password on popular sites—and
eventually got lucky.

Guarding Your Passwords & PINS. Passwords and PINS protect sensitive data and it's critical to keep them safe. Try these best practices to stay protected.

1. Do not write them down – Many make the mistake of writing passwords on post-it notes and
leaving them in plain sight. Even if you hide your password, someone could still find it. Similarly, do
not store your login information in a file on your computer, even if you encrypt that file.
2. Do not share passwords – You cannot be sure someone else will keep your credentials safe. At
work, you could be held responsible for anything that happens when someone is logged in as you.
3. Do not save login details in your browser – Some browsers store this information in unsafe
ways, and another person could access your accounts if they get your device.
4. Use a password manager – These tools can securely store and manage your passwords and
generate strong new passwords. Some can also alert you if a password may have been
compromised.
5. Never reuse passwords – Create a unique, strong password for each account or device. This
way, a single hacked account does not endanger other accounts.
6. Create complex, long passwords – Passwords based on dictionary words, pets’ names, or other
personal information can be guessed by attackers.

 

 

 

By
David McDonough
February 18, 2021

What is a fiduciary?

When selecting a Financial Advisor, it’s important to know they will be looking out for you and the money you worked hard for all your life. Not all financial advisors are the same. When considering a financial advisor to partner with, it’s important to know if they are fiduciaries, meaning they will be ethically obligated to work in your best interests to help you reach your goals.

Why choose Trilogy?

At Trilogy, we operate by suitability standards in offering advice and recommendations that are the most suitable to your needs. We aren’t just salesmen looking to sell products that earn the highest commission. We are dedicated Advisors, financial life planners, who use our expertise to guide you to make smart money decisions. We recommend investments and financial products that are the best fit for your life situation.

Trilogy Capital Inc. is a Registered Investment Advisor. We are a fee-based firm. That means some of our Advisors earn commissions from the sales of certain insurance or securities products. While this incentivizes our Advisors to be the best they can be at their job, be assured that they put people first to select the best solutions for you.

You have a team behind you

When you work with Trilogy, you don’t just have just one Advisor, you have a team who have an ethical duty to recommend what’s best for you. We are specialists with decades of experience in wealth management and protection.

Life planning

With our Advisors, you can be sure they have a fiduciary duty of care to work at the highest level of trust in creating and reviewing your Life Plan. When they make a recommendation, it’s because they feel strongly it’s the right fit for you and your needs, in the life stage you are now and for the future.

Investing for your future

Our financial professionals work in a fiduciary capacity with our investment platforms. We value our relationship with you and work to maintain your trust. We look at the big picture and consider all aspects of your life regarding your personal financial situation.

We know managing your finances can be a full-time job. That’s why our Advisors are there for you to ensure your investments are properly diversified for your risk tolerance. We also monitor other service providers working on components of your plan (including investment companies, record keepers and third-party administrators) to make sure they are catering to your needs and in a cost-efficient manner.

Managing risk

Your fiduciary Financial Advisor will review your personal situation to determine where the risk factors are when it comes to protecting your wealth and recommend insurance products that best fit your needs to add peace-of-mind protection. Whether it’s long term care or life insurance – we’re here to set you up for success so you have a solid plan for whatever comes your way in life.

In keeping with our fiduciary commitment to you, we are an independent financial planning firm. That means we don’t own any insurance products. We’ve done the legwork to find reputable insurance companies who have a proven track record of financial security and claims-paying ability, so you can be confident we recommend products that have the credibility you can count on.

A partner you can trust

When you work with Trilogy, you can finally take a breath in knowing you have a partner who will look out for your finances and do what is best for your life situation and help you meet your financial goals. You can get on with enjoying life, not worrying if you have the money to cover it.

Get Started on Your Financial Life Plan Today