PhaaS-Phishing as a Service: HackShit made Phishing easy ever


Crimeware as a service is not new for the cyber criminal. After Katyusha Scanner- Fully automated SQL vulnerabilities scanner a new platform introduced Hackshit.

The Hackshit is a Phishing as a Service (PhaaS) platform provide low cost phishing campaign and marketplace. They offer free trial of their service for limited set of attempts. They allow beginner scammer to launch phishing campaign without knowledge of hacking.

You can buy hacking tools - mass senders, spam-page generators, crypters, surveillers, spywares, RAT and trojan in their Marketplace. You can easily create phishing page of famous site like facebok, google, twitter etc. Here you can also trade logs in which you get by your campaign in the marketplace to earn money from ready buyers all over the world and get to meet professional hackers to earn digital currency (Bitcoin / Perfect money).

Hackshit, that records the credentials of the phished victims. The phished bait pages are packaged with base64 encoding and served from HTTPS websites with “.moe” top level domain (TLD) to evade traditional scanners. “.moe” TLD is intended for the purpose of ‘The marketing of products or services deemed’. The victim’s credentials are sent to the Hackshit PhaaS platform via websockets.

“When dozens buy it and initiate attacks every day, the potential fallout will be significant,” Recorded Future director of advanced collection Andrei Barysevich said.
“The scale of attacks which is available to criminals is quite unprecedented now. And the convenience of this; someone who wants to engage in this type of activity doesn’t have to be a hacker, he doesn’t have to know how certain tools operate or what exploit packs they should be using. The tool will do everything for them.”  

Comments

Popular posts from this blog

POS: Security Flaws allows hacker to change price, steal data

"FruitFly" Mac malware: longstanding Mac backdoor discovered

GOT: Star's Personal detail leaked from HBO