If you’re looking to buy or sell phishing kits, looking to learn more about how phishing works, or just looking to enter the fray on a voluntary basis, your best bet is to go exploring on Telegram groups.
This is according to a new report from cybersecurity researchers Kaspersky, which claims the popular encrypted instant messaging platform has become quite the breeding ground for this particular cohort of cybercriminals.
By infosecbulletin
/ Friday , May 9 2025
Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
By infosecbulletin
/ Thursday , May 8 2025
The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
By infosecbulletin
/ Thursday , May 8 2025
SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
By infosecbulletin
/ Thursday , May 8 2025
From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
By infosecbulletin
/ Thursday , May 8 2025
Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an attempted attack against an organization...
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Hackers are exploiting an unauthenticated remote code execution vulnerability in the Samsung MagicINFO 9 Server to take control of devices...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
CISA added the Langflow vulnerability, CVE-2025-3248 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog. Langflow is a popular tool...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
Google has released its monthly Android security updates, addressing 46 vulnerabilities, including one that has been actively exploited. CVE-2025-27363 (CVSS...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
The Cyber Security Club, representing the Department of Computer Science and Engineering at the University of Asia Pacific (UAP), has...
Read More
The researchers say that right at this moment, one can find Telegram groups where hackers are offering free phishing kits paired with pre-packaged tools that allow new entrants to create phishing pages and pose as popular brands. There are also groups where free phishing kit contents are being shared, as well as automated phishing page creation. Also, a cybercrime aficionado could head over to Telegram and find premium pages with customizable interfaces, anti-bot systems, geoblocking, URL encryption, and social engineering elements. However, for these premium services, one can expect to pay between $10 and $300.
Kaspersky also uncovered an interesting detail on Ransomware-as-a-Service encryptors: the kit encrypts the stolen data even for the operators, as a safeguard measure to make sure the ransomware’s creators get their share. In other words, even
ransomware(opens in new tab) operators are being held for ransom, for the data they’ve stolen.
Phishing is currently one of the most popular cybercriminal activities out there, second only to Business Email Compromise (which in itself is a form of phishing) and ransomware.
A recent Cofense report stated that there has been a 569% increase in phishing attacks in 2022, compared to the year before. Reports related to credential phishing were up 478% last year, as well.