New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

How phishing kits are enabling a new legion of pro phishers

New York Tech Editorial Team by New York Tech Editorial Team
December 2, 2021
in Cybersecurity
0
How phishing kits are enabling a new legion of pro phishers
Share on FacebookShare on Twitter

Some cybercriminals are motivated by political ideals, others by malice or mischief, but most are only interested in cold, hard cash. To ensure their criminal endeavors are profitable, they need to balance the potential payday against the time, resources and risk required.

phishing kits pro

It’s no wonder then that so many use phishing as their default attack method. Malicious emails can be used to reach many targets with relative ease, and criminals can purchase ready-made phishing kits that bundle together everything they need for a lucrative campaign.

After analyzing three months of phishing email traffic, we found that most attacks follow the money to either big tech or leading financial firms. Facebook, Apple and Amazon were the most popular tech brands being spoofed in phishing URLs. On the financial side, Charles Schwab was by far the most popular target, and was the most used brand URL overall, accounting for 13.5 percent of all cases. Chase Bank – an American subsidiary of JP Morgan Chase & Co – RBC Royal Bank and Wells Fargo were also widely used in phishing URLs.

Our investigation found that Chase has received a growing level of attention from cyber criminals over the last year, so we took a deeper dive into the tactics being used to target the bank’s customers.

The shift to mobile

One of the most prominent trends apparent in our investigation was the growing focus on mobile devices as part of phishing attacks. SMS text messages, WhatsApp and other mobile messaging services are increasingly used to launch attacks.

Attackers are adopting these methods in response to stronger email security solutions. The average mobile device is less likely to be well secured against phishing compared to a desktop endpoint. Even if the mobile device has a business email application on it, channels such as SMS and WhatsApp will bypass any anti-phishing protection it might have.

Threat actors may also mix email and mobile messaging in a single attack, for example sending a phishing email which includes a QR code that must be scanned by a smartphone, thereby jumping the attack over to the mobile endpoint. We have seen an uptick in QR-based attacks as the relatively overlooked technology became more popular during the pandemic. These attacks are again effective at evading traditional email security tools, as the QR code itself is not a malicious asset and its link destination cannot be read by detection technologies optimized for text URLs and virus signatures.

Mobile-based phishing attacks are also harder to identify due to mobile devices’ smaller screen and simplified layout, compounding the lack of security solutions on mobile.

How phishing kits mean anyone can phish like a pro

Not only are phishing approaches continually evolving to counter email security solutions, but even non-technical criminals can also easily take advantage of new techniques thanks to phishing kits. Mirroring out-of-the-box software bundles used by legitimate businesses, these kits provide a collection of tools that enable would-be criminals to quickly create and launch their own phishing campaigns.

Widely available on the dark web, such kits typically include email templates, graphics and scripts, along with a simple interface to manage the attack. Criminals can also easily purchase databases of potential target email addresses, likely sourced from previous data breaches.

Our analysis found that these kits are often highly sophisticated, configured to launch campaigns that will harvest credit card details, social security numbers, and other personal information, as well as the standard target of login credentials. The criminal community has also evolved its techniques to counter multi-factor authentication, with some kits providing the ability to capture one-time use authentication codes.

One of the most prominent kits we examined was the Chase XBATLI, which has been available for some time but has seen increased usage in targeting Chase and Amazon customers. The kit allows criminals to create their own phishing page mimicking the bank, after which they contact customers and prompt them to update their details.

Victims are asked to enter their login credentials and then confirm their personal and financial information. This ensures the perpetrators can not only access the victim’s account, but also furnishes them with other information that can be used for fraud or sold on the dark web. As a finishing touch, the XBALTI kit redirects the target to the genuine Chase landing page at the end, reinforcing the veneer of legitimacy.

XBALTI and other phishing kits we analyzed in recent months also employed evasive tactics, for example using dynamic domain services like Duck DNS to frequently change the destination of the URL. This enables them to continually use the URL even if the web server is taken down or blacklisted.

How can businesses defend against phishing attacks?

Most attacks still rely on the same handful of tactics because they keep on working.

First and foremost, always assume that if something seems fishy, it probably is phishy. Phishing emails have largely moved on from the garbled, error-ridden messages of the past, but there will still be things that give them away. Inconsistencies around language and design should be red flags, and users should always check the sender display name matches the email address. URLs should also be checked before they are opened, and company contact information can be quickly confirmed via official sites and mobile apps, or simply via search engines.

Businesses should also be supporting their workers and customers by providing an accessible channel for reporting phishing. Customers should be able to easily report suspicions to the brand, and employees should have a direct line to their IT security team, ideally through a specialized anti-phishing and remediation solution.

As criminals continue to pursue phishing as the most accessible and lucrative path to cybercrime, individuals and businesses alike need to keep up with the latest trend, as well as keeping their eyes open for the same old tricks.

Credit: Source link

Previous Post

Open source cloud native security analyzer Terrascan embeds security into native DevOps tooling

Next Post

Embrace the change. How Alibaba changed the Russian e-commerce and fintech landscape.

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Embrace the change. How Alibaba changed the Russian e-commerce and fintech landscape.

Embrace the change. How Alibaba changed the Russian e-commerce and fintech landscape.

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026
Employee Time Tracking

What is an Employee Time Tracking Solution? A Definite Guide for 2026

March 31, 2026
Voltify founders

Voltify Raises $30 Million Seed Round as It Challenges $1 Trillion Rail Electrification Model

March 31, 2026

Recommended

laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media