Phishing
Cyber-crooks can now launch phishing attacks at no cost whatsoever
R E L A T E D   C O N T E N T
ADVERTISEMENT

Cyber-crooks bank on free phishing kits

Downloadable tools found on the web

Clement James, vnunet.com 08 May 2008
ADVERTISEMENT

Security experts have discovered free phishing kits on the internet which allow cyber-crooks to send fraudulent emails.

Panda Security's PandaLabs said that the tools allow cyber-crooks to spoof bank pages, online pay platforms, Gmail and Yahoo Mail accounts, online games and blogs.

"The really amazing thing is that these kits are free," said Luis Corrons, technical director of PandaLabs.

"The number of phishing attacks increases due to the simplicity of the tools, causing companies and consumers large losses. A recent Gartner study found that phishing attacks caused US consumer losses of $3.2bn in 2007."

After accessing a URL that contains the kits, the criminal can obtain two files to create a fraudulent mail.

One file allows them to spoof emails from banks and pay platforms, and the other allows them to create a fraudulent page that resembles the original. The kit also includes a free PHP program to send emails from the spoofed page.

The rest of the process is similar to other phishing attacks. The false email is sent to several mail addresses with a link to a malicious page at which users are requested to enter personal data such as email addresses and banking passwords.

"Cyber-crooks buy lists of addresses on the internet, although some are free, " said Corrons. "If we add free hosting services, the result is that cyber-crooks can launch phishing attacks at no cost whatsoever."

See also:

GoogleAttack designed to steal sensitive data  06 May 2008
PhishingBrits seem unfazed by security concerns  29 Apr 2008
Infosec Europe 2008Confidence plummets as attacks soar  24 Apr 2008
Infosec Europe 2008Hugely successful malware gets a new twist  23 Apr 2008

All Hacking
Tags: Phishing

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Aberdeen, Grampian, United Kingdom | NET_ENF_ABR_JPH
About EDS EDS provides a broad portfolio of business and technology solutions to help its clients worldwide improve their business performance. EDS' core portfolio comprises information-technology and business process outsourcing services, as well as information-technology ... more >
Colindale (C1905), United Kingdom | NHS Blood and Transplant
 Operations Engineer, £28,313 - £37,326 pa plus High Cost Area Supplement, Colindale (C1905) About us The National Blood Service is an integral and vital part of the NHS. Our two million volunteer donors contribute 1.6 ... more >
Leeds, United Kingdom | UKCRN
Test Manager, Leeds You'll establish and manage a testing team so that all applications are fit for purpose. Specifically, you will need to establish a baseline position for all current applications with associated documentation and ... more >
United Kingdom | Sumisho Computer Systems (Europe) Ltd
 Assistant Manager (Network) Sumisho Computer Systems (Europe) Ltd provide customers with a world of enhanced IT solutions. The role will involve assisting the manager to run the communications systems section including planning and management of ... more >
More job opportunities