Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

This was posted elsewhere and it was suggested that a new thread be started, so here it is...

---

I was contacted by someone seemingly wanting to know if I could produce something and a link was provided, to what one would assume would be a picture or example. Replying resulted with, "The user name is not a valid Etsy user." Red flag, right there. Send such messages to you SPAM folder and think nothing more of them.

Anyway...

Be VERY cautious with links pointing to sites external to Etsy. In most cases, don't click them. That said, I'm former IT and possess capacity for operating in and downloading to a sandboxed environment. I was curious, so the link was clicked.

It pointed to a self-extracting zip archive containing a single batch script. Code obfuscation had been implement using a boatload of assigned variables, and in the end, the intent was to start Windows powershell in the background and initiate a few downloads, uploads, and modifications to user/system files. Chrome would be started and a site loaded, presumably to grab the user's attention while it all took place.

Someone's trying to steal credentials and gain access to user accounts, guising the attempt as a request and potential order... or perhaps it's a ransomware or keylogging attempt. I dunno and don't care to dig any further into it.

Not being a Windows user in the first place, it wouldn't have been effectual on my end anyway, and ought not be effectual on a properly configured Windows system, but there it is.

Be wary, folks.

Regards.

Translate to English There was a problem fetching the translation.
23 Likes
18 Replies

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

Thank you for posting, it is a good reminder for new sellers never to click on links within messenger or emails.

These scammers are so active at the moment and for months there have been warnings in the forum on a daily basis as well as warnings within the messenger dashboard, not sure why people are not seeing it or taking notice

Translate to English There was a problem fetching the translation.
2 Likes
Reply
Loading...

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

Another thing to consider is that once a link is clicked, unless you're using a proxy, VPN, TOR, or some other anonymity utility, the entity on the other end will then have your public-facing IP address.

That's not good, as they can then probe for open/insecure ports and potentially gain direct access to your private network and everything attached to it.

Translate to English There was a problem fetching the translation.
0 Likes

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

Thanks for this new information. It explains how some sellers could be getting their accounts hacked.

Translate to English There was a problem fetching the translation.
3 Likes
Reply
Loading...

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

In this instance, I'm wunnerin' how a message is sent via a non-valid account in the first place.

Perhaps an account was created, the dirty deed done, then the account deleted. If so, it'd all have to have been executed rapidly in short-order, as I replied (tried to reply) within minutes of receiving the message.

<shrugs>

 

 

Translate to English There was a problem fetching the translation.
2 Likes

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

@StickIt2M 
Scammer creates an account on Etsy, sends multiple messages through Etsy trying to scam someone.
When they sent the message their account was a "valid" account.

Then some program that Etsy has in places FLAGS that message as spam/scam and Etsy is the one that deletes that account.

Rinse and repeat a gazillion times, etsy deletes that one account then 10 more or 100, 1000's more are created. 

The person that created the account is not the one deleting it.

 

Translate to English There was a problem fetching the translation.
4 Likes

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

@StickIt2M 

They also hack legitimate buyer and seller accounts, change the picture (Etsy logo) and name, and send their fraudulent messages through these accounts.

These scammers use a variety of different methods for different purposes to make tracing more difficult. But all these individual scams are somehow linked. 

Translate to English There was a problem fetching the translation.
0 Likes

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

I was one who suggested you post this as a new thread. Thank you so much and I hope people will read!

Translate to English There was a problem fetching the translation.
2 Likes
Reply
Loading...

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

Yup... replied to ya on the other thread.

You're welcome and a thanks backatchya.

Translate to English There was a problem fetching the translation.
2 Likes

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

@vintageNCtreasures

That's it.

Some of the URI's to which the script pointed are now dead and without those files one can't say for sure, but I suspect what's happening is that the user's machine is being setup so that nothing occurs until after a restart, when a rootkit and keylogger get busy.

For anyone like me, having a machine that stays up 24x7 with infrequent restarts, the actual exploiting could take place days or weeks after the malicious files get put in place.

It could be the message received 2 weeks ago that gets ya instead of the dozens received since.

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
ChillwolfArt
Conversation Maker

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

Thank You for the Warning.  Too many Sellers are being targeted, and have been Hacked as well; funds stolen, as well as banking information.

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

Thank you for posting this. I received a similar message today. However it stated that they wanted to know more about one of my products and I thought the link led to whichever product they were interested in. I clicked it only to find a zip file download. I replied to find an invalid account. I immediately deleted the zip file, the chat box and my chrome cache. I also ran a security check that said nothing was wrong. Is it alright or should I take some other precautions?

PS: this was on my phone. 

I'm feeling anxious if I lost any data. I don't have a lot of technical knowledge regarding this and would like to know what I should do about it.  

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

@ShylockedHerShop 

We are not safe clicking any links in messages or in emails. If you ran a virus scan on your phone and deleted the zip file, that is good. Perhaps someone else will have more suggestions for what else you may need to do.

Translate to English There was a problem fetching the translation.
1 Like

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

@ZehOriginalArt Thank you for writing back. I did not realise etsy chat was prone to scam. I am learning about this from articles in the community. But, I definitely know better now to be more careful moving forward. 

Translate to English There was a problem fetching the translation.
1 Like

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

I second @ZehOriginalArt  and say you're probably good to go.

A few more messages were sent my way, all slightly different but with the same goal in mind - to compromise Windows systems, older ones, seemingly. Some of the exploits involve applications included with older versions that didn't ship with Win10/11.

That isn't to say there's nothing out there intended for OS X, iOS, Android, or Linux... but these attempts aren't (not if what the zip holds is a .bat file).

Windows is the most widely used, and thus most misused, desktop OS - the pond with the most fish, so to speak - so that's what's being targeted.

From now on out, the first thing I'd do is see if replying is possible. If it isn't, send the message to spam and go on about your day.

Regards.

 

 

Translate to English There was a problem fetching the translation.
1 Like

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

@StickIt2M This makes a lot of sense. I'll definitely try replying first and be more cautious of reviewing chats on my desktop too. Thanks for all the info! 

Translate to English There was a problem fetching the translation.
1 Like
ARIENgifts
Inspiration Seeker

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

Thank you so much for sharing all these info. It just happened to me too. I got these messages: 

Hi ,I looked at the store ARIENgifts. 

I need these these iteams for my upcoming birthday. Here is the product video ..... here was the link which I don't want to paste here ..... 

Can I pay and place an order today? 

Looking forward to your early reply , thanks you !

 

Luckily, I didn't click the link because as soon as I see someone is sending me a link it's like an alarm for me in my head. I tried to reply just in case if they can send me a screenshot of what product are they talking about. But I got the red message info that the person is not on etsy list so I can't send the message.

And then I found this thread here so I thought I will share this experience. Really big thank you to all members in this forum for keeping each other safe from all the scammers. It does really happens a lot to me these days - from someone who is pretending to be Etsy support to just random names pretending to be customers.

Stay safe all wonderful sellers

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

Thank you for posting, it is a good reminder for new sellers never to click on links within messenger or emails.

These scammers are so active at the moment and for months there have been warnings in the forum on a daily basis as well as warnings within the messenger dashboard, not sure why people are not seeing it or taking notice

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Nefarious activity aimed at sellers -- "The user name is not a valid Etsy user"

Scammers have been exceptionally busy this past few days for both shops. 

Usually I get a message from (fake etsy accounts) claiming they need a certain item (inserting a link) ASAP for their upcoming (birthday/anniversary/etc) party & is it possible to purchase and have it shipped immediately...

They seem to really be crawling out of the woodwork lately.  Reminders are good for everyone - especially during a time when shop owners may be a little more anxious about slow sales.

Translate to English There was a problem fetching the translation.
0 Likes
Reply
Loading...
Reply
You must log in to join this conversation.
Remember that posts are subject to Etsy's Community Policy.