New Spiderman Phishing Kit Lets Attackers Create Malicious Bank Login Pages in Few Clicks
A newly identified phishing framework named "Spiderman" has been detected in cybercrime networks, significantly simplifying the execution of financial fraud.
A newly identified phishing framework named "Spiderman" has been detected in cybercrime networks, significantly simplifying the execution of financial fraud.
This toolkit, documented by Varonis, enables perpetrators with limited technical expertise to create accurate replicas of legitimate banking websites effortlessly.
The framework specifically targets users of various European financial institutions and cryptocurrency platforms, indicating an advancement in automated cybercrime technologies.
Distinguishing itself from conventional phishing scripts, Spiderman offers a comprehensive architecture with extensive automation. It allows attackers to conduct operations without needing web development or coding skills.
The toolkit integrates targeting for several prominent brands, such as Deutsche Bank, Commerzbank, ING (Germany & Belgium), and CaixaBank, into a unified platform.
This capability is part of a trend where feature-rich tools facilitate widespread attacks, streamlining complex processes into simple selection options.
Distinguishing itself from conventional phishing scripts, Spiderman offers a comprehensive architecture with extensive automation.
Cybercriminals can select a target institution, activate the "Index This Bank" option, and the framework generates a convincing clone complete with necessary login and authentication fields.
This functionality allows operators to switch between regions and brands efficiently, executing multiple simultaneous attacks across different countries.
The sophistication of Spiderman is evident in its ability to bypass modern security measures, including two-factor authentication. It captures PhotoTAN codes and One-Time Passwords (OTPs) in real time.
As credentials are entered on the fraudulent page, the attacker can monitor the session live, triggering additional requests for sensitive information.
The framework includes advanced filtering to evade detection, permitting traffic only from specific countries or device types while blocking known security entities and data centers.
This measure prolongs the operational period of phishing pages before they are flagged by browsers.
The toolkit also accommodates cryptocurrency theft, with modules designed to capture seed phrases from wallets like Ledger, MetaMask, and Exodus, indicating a comprehensive fraud strategy.
Spiderman's distribution is extensive, with a Signal messenger group associated with the seller reportedly hosting approximately 750 members.
As European financial entities enhance their online security, frameworks like Spiderman are anticipated to evolve, necessitating increased vigilance from security teams and consumers regarding verification practices.
Based on reporting by Cyber Security News.
