• Skip to main content
  • Skip to site footer

Tell the Community Your Story

Submit your Fraud Alert HERE

FIND OUT HOW!
Fraud Alert

Fraud Alert

Post Your Fraud Alert Here

  • Home
  • Advice
    • Fraud Schemes
  • Add
  • Contact / Take Down
You are here: Home / Fraud Alerts / Phishing / Wannabe Crooks Fooled by Backdoored Phishing Kits Advertised …

Wannabe Crooks Fooled by Backdoored Phishing Kits Advertised …

11/26/2016 by Fraud Alert

There’s a growing trend in the cybercrime landscape, and the trend is for malware authors to distribute backdoored malware using promotional videos and hacking tutorials on YouTube.

While backdoored malware isn’t anything new, the trend of using YouTube videos is, and the main reason is because of YouTube’s reach and the site’s appeal to non-technical users and wannabe hackers.

This wasn’t always the case. For many years Google employees have patrolled the site for illegal content and removed it after reports. Things got out of hand in the last year, and the number of hacking-related “tutorials” and “demos” has gotten out of hand.

Your reporter has noticed this rise in hacking tutorials, presentation demos, and how-to use malware videos in the past few months.

Searching YouTube for “exploit wordpress” yields over 40k videos. This explains why so many WP sites get hijacked pic.twitter.com/H6DHPEUQYr

— Catalin Cimpanu (@campuscodi) September 3, 2016

There are 186,000 search results on YouTube for the word “keylogger” …. I wonder where so many skids get the idea that “hacking is easy” pic.twitter.com/7uy7qWkDVY

— Catalin Cimpanu (@campuscodi) October 19, 2016

Most of these videos contain links in their description that drive traffic and wannabe crooks to websites where they can purchase or download for free the hacking tools and malware they’ve just seen used in the video.

YouTube videos have become a solid alternative to driving potential customers to commercial malware and is now just as reliable as threads on underground hacking forums, ads on Dark Web marketplaces, and IRC or Jabber spam.

YouTube videos lead to backdoored phishing kits

But not all these YouTube videos lead to “professional” malware. Researchers from US security firm Proofpoint have uncovered a large number of these videos that advertise backdoored malware.

In a series of cases they present on their blog, researchers break down and analyze the source code of various phishing kits you can download from links spread via YouTube videos.

Phishing kits are packages of ready-made login pages for various online services, ranging from Gmail to Amazon, and from Microsoft to PayPal.

Crooks download phishing kits and deploy them with various campaigns, with the aim of collecting the login credentials of their targets.

Proofpoint says that a large number of phishing kits advertised via YouTube contain hidden code that sends the stolen credentials to the phishing kit’s creator, not only the crook that bothered downloading, customizing and deploying the phishing kit.

Backdoored phishing kit code (Credit: Proofpoint)

Some clever malware authors are taking advantage of fellow crooks and wannabe hackers, and they’re making a living on the side.

This trend doesn’t affect only phishing kits. The same is also true for more complex malware such as keyloggers, RATs, and others. For example, when the Darktrack RAT was released online for free over the summer on an underground hacking forum, the first question asked was if someone inspected the source code for backdoors.

While no doubt a veteran hacker would have examined the source code for backdoors, newcomers to the world of cybercrime are in for a surprise and may end up doing all the heavy lifting for some malware author sitting in the shadows.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Category: PhishingTag: alert, fraud, identity, passwords, phishing
  • Brazilians targeted in free Olympic ticket giveaway phishing scam
    Date
    08/20/2016
  • Russian speaking hacking group targets banks in Sub-Saharan Africa: report: News
    Date
    01/27/2020
  • Increase in targeted spam and phishing attacks via e-mail
    Date
    01/15/2013
  • Simple phishing emails were behind the biggest North Korean hacks
    Date
    09/09/2018
  • Simple phishing emails were behind the biggest North Korean hacks
    Date
    09/09/2018
  • Phishing the phishers: Sneaky crooks put backdoors into kits for wannabe fraudsters
    Date
    01/10/2018
Next Page

About Fraud Alert

Previous Post:Fidel Castro Dead at 90
Next Post:Police warn Nova Scotian shoppers of phishing and smishing scams …

Copyright © Fraud Alert · Gqeberha (Port Elizabeth), South Africa | Privacy Policy