Phishing
Cyber-crooks can now launch phishing attacks at no cost whatsoever

Cyber-crooks bank on free phishing kits

Downloadable tools found on the web

Written by Clement James

The number of phishing attacks increases due to the simplicity of the tools

Luis Corrons PandaLabs

Security experts have discovered free phishing kits on the internet which allow cyber-crooks to send fraudulent emails.

Panda Security's PandaLabs said that the tools allow cyber-crooks to spoof bank pages, online pay platforms, Gmail and Yahoo Mail accounts, online games and blogs.

"The really amazing thing is that these kits are free," said Luis Corrons, technical director of PandaLabs.

"The number of phishing attacks increases due to the simplicity of the tools, causing companies and consumers large losses. A recent Gartner study found that phishing attacks caused US consumer losses of $3.2bn in 2007."

After accessing a URL that contains the kits, the criminal can obtain two files to create a fraudulent mail.

One file allows them to spoof emails from banks and pay platforms, and the other allows them to create a fraudulent page that resembles the original. The kit also includes a free PHP program to send emails from the spoofed page.

The rest of the process is similar to other phishing attacks. The false email is sent to several mail addresses with a link to a malicious page at which users are requested to enter personal data such as email addresses and banking passwords.

"Cyber-crooks buy lists of addresses on the internet, although some are free, " said Corrons. "If we add free hosting services, the result is that cyber-crooks can launch phishing attacks at no cost whatsoever."

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

GoogleSecurity

Phishers target Google AdWords users

Attack designed to steal sensitive data 06 May 2008

 

Third of UK surfers banking online

Brits seem unfazed by security concerns 29 Apr 2008

Infosec: Surfers wary of using credit cards online

Confidence plummets as attacks soar 24 Apr 2008

Infosec: Rock Phish threat deepens

Hugely successful malware gets a new twist 23 Apr 2008

Bogus Facebook page harvests login details

Fraudulent URL tricks users into revealing credentials 17 Nov 2009

Security firm uncovers Facebook hacking site

Site charges $100 per hacked account - or is it a scam? 18 Sep 2009

Hacked Hotmail contacts used for phishing attacks

Contact lists on compromised webmail accounts being used to con people into releasing personal information 09 Oct 2009

related white papers

today's top stories

Interview: Jos Creese, chief information officer, Socitm

Head of Socitm, the body for local authority IT professionals, discusses how to get the most from IT services at a time when budgets are being cut to the bone. Dawinderpal Sahota listens in 09 Sep 2010

Implementing cloud computing

UK firms are looking for on-demand, pay-as-you-go IT services, applications and infrastructure, writes Martin Courtney 08 Sep 2010

When business brains turn to crime

Cyber criminals are far better organised and more sophisticated than most legitimate e-commerce operations, writes Stuart Sumner 08 Sep 2010

Copyright agreement draft leaked again

ACTA workings published after Washington DC negotiating round 07 Sep 2010

Lloyd's Of London takes Facebook to the board

Peter Hambling, CIO of Lloyd’s of London, the venerable insurer, has made Facebook a priority for customer communications that required board approval.... 07 Sep 2010

Advertisement

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

The Chinese Market

The Chinese Market

Is your company considering expansion into the Chinese market?

View poll results

Latest audio and video articles

A microphoneAudio

Computing Podcast: Tech Talk episode 5

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT self-service. Will it provide value? 27 Aug 2010

A microphoneAudio

Computing podcast: Tech Talk episode 4

Join Tech Talk for an overview of the week's top IT stories, and a debate on IT skills. Is the UK slipping behind? 20 Aug 2010

Latest in-depth articles

Picture of Google logoAnalysis

Will IPv6 boost search engine rankings or is that wishful thinking?

Will search engine providers consider web-server IPv6 support to rank content in the future? 09 Sep 2010

Jos CreeseFeatures

Interview: Jos Creese, chief information officer, Socitm

Head of Socitm, the body for local authority IT professionals, discusses how to get the most from IT services at a time when budgets are being cut to the bone. Dawinderpal Sahota listens in 09 Sep 2010

Primary Navigation