If you’re looking to buy or sell phishing kits, looking to learn more about how phishing works, or just looking to enter the fray on a voluntary basis, your best bet is to go exploring on Telegram groups.
This is according to a new report from cybersecurity researchers Kaspersky, which claims the popular encrypted instant messaging platform has become quite the breeding ground for this particular cohort of cybercriminals.
By infosecbulletin
/ Thursday , October 10 2024
Palo Alto Networks released a security advisory (PAN-SA-2024-0010) about several high-severity vulnerabilities in its Expedition migration tool, with CVSS scores...
Read More
By infosecbulletin
/ Wednesday , October 9 2024
In its recent Patch Tuesday release, Microsoft fixed 118 vulnerabilities, including five zero-day flaws, two of which are currently being...
Read More
By infosecbulletin
/ Tuesday , October 8 2024
The Cyber Threat Intelligence (CTI) Unit at BGD e-GOV CIRT has discovered a malware campaign involving the Lumma Stealer family....
Read More
By infosecbulletin
/ Monday , October 7 2024
Qualcomm's October 2024 Security Bulletin reveals critical vulnerabilities in several chipsets, including the popular Snapdragon mobile platforms and FastConnect solutions....
Read More
By infosecbulletin
/ Sunday , October 6 2024
BGD e-GOV CIRT is excited to announce the Financial Institutions and Critical Information Infrastructure (CII) Cyber Drill 2024, designed for...
Read More
By infosecbulletin
/ Saturday , October 5 2024
National Attack Surface (NAS) report for the first half of 2024 reveals that 56.6% of cyberattacks in Bangladesh targeted educational...
Read More
By infosecbulletin
/ Saturday , October 5 2024
A new ransomware campaign is targeting individuals and organizations in the UK and US. The "Prince Ransomware" attack uses a...
Read More
By infosecbulletin
/ Friday , October 4 2024
CISA has issued an urgent alert about critical vulnerabilities being exploited in Synacor’s Zimbra Collaboration and Ivanti’s Endpoint Manager (EPM)....
Read More
By infosecbulletin
/ Friday , October 4 2024
ISACA 2024 survey report reveals that 66% of cybersecurity professionals find their jobs more stressful now than five years ago....
Read More
By infosecbulletin
/ Friday , October 4 2024
A recent study by ISACA shows that almost two-thirds of cybersecurity professionals report increasing job stress. The 2024 State of...
Read More
The researchers say that right at this moment, one can find Telegram groups where hackers are offering free phishing kits paired with pre-packaged tools that allow new entrants to create phishing pages and pose as popular brands. There are also groups where free phishing kit contents are being shared, as well as automated phishing page creation. Also, a cybercrime aficionado could head over to Telegram and find premium pages with customizable interfaces, anti-bot systems, geoblocking, URL encryption, and social engineering elements. However, for these premium services, one can expect to pay between $10 and $300.
Kaspersky also uncovered an interesting detail on Ransomware-as-a-Service encryptors: the kit encrypts the stolen data even for the operators, as a safeguard measure to make sure the ransomware’s creators get their share. In other words, even
ransomware(opens in new tab) operators are being held for ransom, for the data they’ve stolen.
Phishing is currently one of the most popular cybercriminal activities out there, second only to Business Email Compromise (which in itself is a form of phishing) and ransomware.
A recent Cofense report stated that there has been a 569% increase in phishing attacks in 2022, compared to the year before. Reports related to credential phishing were up 478% last year, as well.