What goes around comes around: Researchers find backdoor in pirated Apple phishing kit
Full article720 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Researchers at cybersecurity company Akamai Technologies have found a backdoor in a bootlegged version of 16Shop.
Criminals accustomed to planting backdoors in software may be getting a taste of their own medicine.
Researchers at cybersecurity company Akamai Technologies have found a backdoor in a bootlegged version of 16Shop, a popular phishing kit marketed to criminals targeting Apple users. The data leaks to a channel on the encrypted messaging service Telegram, meaning a victim’s data could be stolen by anyone using the pirated kit, but also by anyone accessing the channel.
“Someone spent a lot of time and effort to build a really good toolkit and to get more money out of that” by planting the backdoor, said Or Katz, principal lead security researcher at Akamai, which published research on 16Shop on Tuesday. The phishing kit consists of hundreds of files, including login pages that spoof targeted platforms.
Industry analysts have been tracking 16Shop since at least last year, and have traced the kit’s development to an Indonesian person known as Riswanda or ‘devilscream.’ While Riswanda may have questionable operational security, the kit’s success has come from giving its users the ability to avoid detection. For example, 16Shop can block a list of IP addresses communicating with it in an attempt to avoid the prying eyes of security researchers.
16Shop has an estimated market price of $50, according to Steve Ragan, a security researcher at Akamai. While it is unclear how many victims the phishing gear has claimed, it is being actively maintained, sold, and reused by criminals, according to Akamai.
“It’s a true multi-level kit, running different stages for different brands, depending on the information the victim provides,” Katz and his colleague Amiram Cohen wrote in a blog post. “It has the ability to change its layout and presentation depending on platform, so mobile users will see a website tailored to their device, while desktop users see something better suited to their situation.”
The data that 16Shop can funnel from a user is manifold; a victim’s Apple credentials are the first in a series of potential targets. By activating other features, an attacker could try to phish users of Gmail, Hotmail, and Yahoo, according to Akamai. A third stage of the attack spoofs the “Verified by Visa” login page to try to swipe users’ credit card data. The attacker can also ask a U.S. target victim for a Social Security number. The perpetrator can transmit or store the stolen data at each stage, or save it all for one data dump.
For Katz, 16Shop is an example of the “industrialism of phishing” – a way for criminals to scale malicious lures that goes beyond the aimless spraying used in less sophisticated approaches. And for that reason, he said, phishing kits like 16Shop cannot be ignored.
“In a way, phishing is the first step in a chain of a much more sophisticated attack that can happen,” Katz told CyberScoop. “The most important thing we can do as a security community is to create much more awareness around those types of attacks.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/16shop-backdoor-apple-phishing-kit-akamai-research/