PhaaS-Phishing as a Service: HackShit made Phishing easy ever
Crimeware as a service is
not new for the cyber criminal. After Katyusha Scanner- Fully automated SQL vulnerabilities
scanner a new platform introduced Hackshit.
The Hackshit is a Phishing
as a Service (PhaaS) platform provide low cost phishing campaign and
marketplace. They offer free trial of their service for limited set of
attempts. They allow beginner scammer to launch phishing campaign without
knowledge of hacking.
You can buy hacking tools - mass
senders, spam-page generators, crypters, surveillers, spywares, RAT and trojan in
their Marketplace. You can easily create phishing page of famous site like
facebok, google, twitter etc. Here you can also trade logs in which you get by
your campaign in the marketplace to earn money from ready buyers all over the
world and get to meet professional hackers to earn digital currency (Bitcoin / Perfect
money).
Hackshit, that records the credentials of the phished victims. The phished bait pages are packaged with base64 encoding and served from HTTPS websites with “.moe” top level domain (TLD) to evade traditional scanners. “.moe” TLD is intended for the purpose of ‘The marketing of products or services deemed’. The victim’s credentials are sent to the Hackshit PhaaS platform via websockets.
“When dozens buy it and
initiate attacks every day, the potential fallout will be significant,”
Recorded Future director of advanced collection Andrei Barysevich said.
“The scale of attacks which
is available to criminals is quite unprecedented now. And the convenience of
this; someone who wants to engage in this type of activity doesn’t have to be a
hacker, he doesn’t have to know how certain tools operate or what exploit packs
they should be using. The tool will do everything for them.”
Comments
Post a Comment