Researchers uncover Phishing Kits Used In Scamming Thousands Of People

Share post:

Researchers from vpnMentor have discovered two slightly modified versions of the same phishing kits that attackers use to defraud thousands of people worldwide.

The first scam involves a criminal outfit that uses the phishing kit to send text messages that appear to be from well-known global courier service UPS.

The second scam targets customers of Crédit Agricole, a French bank that is the world’s largest co-operative financial institute. Those behind the scam hacked a website unrelated to Crédit Agricole, modified it to mirror the company’s website and inserted code for the phishing kit.

The victims of the UPS scam were Israeli residents who were sent a text message claiming they had a package ready to be picked up.

Their activities were exposed after they failed to secure their server and forgot to disable a ‘directory listing’ running the phishing kit. Most of the 4,400 people whose records were stored in the directory listing were Israeli citizens. Other target countries are the U.S., Brazil, Saudi Arabia and countries in Europe.

Researchers believe the attacker is an Israeli criminal gang, as the scripts for the text sent to Israeli targets were written in broken Hebrew.

The sources for this piece include an article in VPNMENTOR.

SUBSCRIBE NOW

Related articles

Exploited ChatGPT Vulnerability Poses Risks to Organizations

A server-side request forgery (SSRF) vulnerability in OpenAI's ChatGPT infrastructure, tracked as CVE-2024-27564, is being actively exploited by...

Free Online File Converters Found Installing Malware: Malwarebytes Sounds the Alarm

Cybersecurity company Malwarebytes is urging internet users to exercise caution when seeking free online file conversion tools, warning...

Researchers Crack Akira Ransomware Using High-End GPUs

The Akira ransomware group emerged in 2023 with a mix of dark humour and ruthless tactics, famously requesting...

DOGE Staffer Sends Unencrypted Personal Data

Court documents reveal that Marko Elez, a staff member of the Department of Government Efficiency (DOGE), breached Treasury...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways