Transcription of The 2020 Outbound Email Security Report
1 One click away: Why Outbound Email is your biggest riskThe 2020 Outbound Email Security ReportPhishing-as-a-service: How cybercrime went commercial060304091214 Inside the reportIntroduction Phishing-as-a-service (PhaaS) explainedLowering the barrier of entry to cybercrime Can PhaaS be stopped? Egress tips on staying safe Phishing kits: All you need for a hack2 Phishing-as-a-service: How cybercrime went commercialIn 2011, venture capitalist Marc Andreeson famously claimed that software is eating the world . Today, you could argue it s been eaten. Gartner forecasts that by the end of 2022, spending on software-as-a-service will reach $172bn. Including the likes of other cloud services (platform-as-a-service, infrastructure-as-a-service, etc.), they predict the total spend to reach $482bn. The success of the as-a-service model has been nothing short of phenomenal.
2 Is it really any surprise then, that criminal gangs have followed suit? In recent years, there s been a growing trend of cybercriminals diversifying and selling their software and/or expertise to lesser-skilled prospective hackers. In this Report , we ll outline the new and ever-expanding world of phishing-as-a-service (PhaaS), including how phishing kits work and real-life examples from PhaaS marketplaces. We ll also cover how this has lowered both the financial and skills barrier to cybercrime and opened phishing up to a wider pool of criminals than ever , we ll explore what can be done to clamp down on the PhaaS industry, look at how your organization can protect itself from phishing emails, as well as offer up tips on what your people can do to avoid being phished in their personal lives. Introduction3 Phishing-as-a-service: How cybercrime went commercialPhishing-as-a-service explained The Phishing-as-a-service (PhaaS) industry works in a similar way to the legitimate SaaS one.
3 Instead of trying to do everything themselves, criminal gangs have diversified and specialized, becoming experts in one area and selling that expertise to others. Other cybercriminals can then pick and choose what they need as one-off purchases or subscription-based modern business might have accounting, communications, productivity, and cybersecurity software all bought from SaaS vendors, rather than using technology they ve developed themselves. Likewise, a prospective cybercriminal can purchase Email templates from one vendor, open-source intelligence (OSINT) from another, and hosting services to launch attacks from a third. Many of these interactions take place on the dark web but it s a misconception that they all do. The Amazon scam page in Figure 1 was on sale via 16 Shop on the clear web (area of the web accessible via public search engine).
4 Criminal gangs have diversified and specialized, becoming experts in one area and selling that expertise to : How cybercrime went commercial[Pull quote:]Criminal gangs have diversified and specialized, becoming experts in one area and selling that expertise to Figure 1, the seller highlights an interesting feature: automated checking of IP addresses that reach the phishing domain using a service called antibot[.]pw. This prevents automated Security tools and bots from checking the phishing domain prior to people being redirected to it. It s indicative of a wider trend of phishing kits adding advanced Security evasion to their products to ensure victims fall for the phishing 2: Black Friday sale for stolen accountsFigure 1: 16shop s capabilities page for their Amazon phishing kitIn another similarity to legitimate businesses, PhaaS sellers are quick to exploit both topical events and seasonal situations.
5 Egress research turned up a Russian-speaking forum participant (Figure 2) using Black Friday to promote the sale of stolen accounts for a variety of fintech companies and cryptocurrency exchanges. This would help the buyer to avoid Know Your Customer (KYC) and anti-money laundering (AML) processes. Although unconfirmed for this seller, these accounts were likely obtained via social engineering techniques like phishing or via breached credentials of third-party : How cybercrime went commercialPhishing kits Phishing kits: All you need for a hack A popular sales tactic is to group PhaaS products together into a comprehensive phishing kit . They usually contain Email templates and the back-end code for spoofed websites designed to harvest login details or download malware. They can closely resemble real brands sites and look seriously convincing.
6 Once you ve completed the desired action (such as submitting credentials or payment details), most will also refresh and put you onto the real site, which makes it even harder to realize you ve been : How cybercrime went commercialPhishing kit costs can vary and they can be bought as a one-off or as part of an ongoing subscription service. For example, FishPanel (Figure 3) advertise a premium subscription service costing $499 upfront and a monthly subscription fee of $199. This gives buyers access to a platform with over 20 pre-loaded phishing kits that target various financial institutions and retail brands. Subscribers also receive an extra 15 phishing kits that are added to the platform each month. Buyers can request custom pages from the platform operators, which are advertised as hand-made from scratch (Figure 4). This means HTML code isn t duplicated, helping to further avoid detection from blocklists and secure Email gateways (SEGs).
7 Figure 3: FishPanel buyers have a variety of phishing kits to choose from on the platformFigure 4: FishPanel dark web post specifying custom page creation capabilitiesPhaaS providers will use similar sales tactics to legitimate : How cybercrime went commercialThe platform also allows buyers to customize the information-farming forms displayed to victims on the phishing pages, with the option to be notified via Telegram when new victims have been successfully phished (Figure 5).Figure 5: FishPanel operators showing off their Telegram integrationFigure 6: Black Friday sale for an inbox validation toolPhaaS providers will use similar sales tactics to legitimate businesses. Our research has uncovered a post on a dark web forum (Figure 6) that showed a user applying a Black Friday discount to a custom inbox validation tool, reducing it to almost half price.
8 The tool is likely used by cybercriminals to anonymously access Email inboxes and validate the credentials they ve stolen via : How cybercrime went commercialLowering the barrier of entry to cybercrime One reason for the general spike in cybercrime is the fact it s become so easy to get started. The PhaaS and wider crime-as-a-service (CaaS) marketplace has allowed criminal gangs to diversify, specialize, and sell their knowledge and software to anyone in the world. This has greatly lowered the technical and monetary barriers of entry to online marketplaces operate in a similar way to legitimate ones. Sellers market the features and benefits of their products, sometimes sweetening the offer with added extras or time-sensitive deals. Buyers can make requests on forums for specific products and they can leave reviews and feedback about sellers profiles and : How cybercrime went commercialSellers are dedicated to making things as easy as possible for prospective customers.
9 In Figure 7, you can see phishing kit operator FreakzBrothers is offering a polished PhaaS product for just $40. There are also examples of customers making requests to sellers. We were able to find cybercriminals registering interest for specific types of phishing kit, as demonstrated by the following post on a Russian-language cybercriminal forum (Figure 8). The hacker expresses interest in purchasing phishing kits or landing pages that are on the theme of Black Friday and provides their Telegram handle for further 7: FreakzBrothers listing for their latest Amazon phishing kitFigure 8: Dark web forum post about purchasing Black Friday phishing pagesOne reason for the general spike in cybercrime is the fact it s become so easy to get : How cybercrime went commercialCustomers are also able to customize campaigns and see detailed reporting.
10 One vendor showed off their reporting dashboard (Figure 9) that can be used to easily track campaigns, victims, and harvested information. Figure 10 shows how sellers offer instructional messages to make sure buyers set up their phishing kits correctly for maximum 10: 16 Shop tutorial for registering phishing domains on the platformFigure 9: Reporting platform for reviewing phishing statistics11 Phishing-as-a-service: How cybercrime went commercialCan PhaaS be stopped? Phishing kits are tricky to clamp down on. Modern kits can be sophisticated and avoid initial detection by traditional anti-phishing tools. Most tend to be live for around 36 hours before they re caught which is plenty of time to fool a wide range of are persistent and well-aware of the short lifespan of a phishing kit. Once one has been shut down, they simply put another up in its place and the clock can learn to spot the signs of phishing, and many organizations spend thousands training their employees to do so.