New “Spiderman” Phishing Kit Lets Hackers Build Fake Bank Login Pages Instantly
## Cybersecurity: Emergence of the Spiderman Phishing Toolkit
Cybersecurity: Emergence of the Spiderman Phishing Toolkit
A new phishing toolkit known as "Spiderman" poses a significant threat to European banking customers. This toolkit enables cybercriminals to generate authentic-looking fake login pages for numerous financial institutions with minimal effort.
Framework Targeting Multiple Countries
The Spiderman phishing kit consolidates templates for login pages from several European banks and cryptocurrency platforms into a single interface. This differs from traditional kits that target individual institutions. The toolkit includes clones for major banks such as Deutsche Bank, Commerzbank, ING, and CaixaBank across five countries.
Security researchers have identified approximately 750 users in a Signal messenger group associated with the toolkit's seller, indicating its widespread distribution and use among cybercriminals.
The deployment of this kit is evident in large-scale phishing campaigns throughout Europe. Its automation allows attackers to launch sophisticated phishing operations without requiring web development expertise or technical knowledge.
A new phishing toolkit known as "Spiderman" poses a significant threat to European banking customers.
The toolkit enables criminals to select a target bank, generate a precise replica of its login page, and deploy phishing campaigns swiftly. The control panel monitors victim sessions in real-time, capturing sensitive information such as usernames, passwords, credit card details, PhotoTAN codes, and personal identification information.
According to Varonis, this multi-step approach is designed to bypass European banking security measures, including two-factor authentication systems. The toolkit's anti-detection features include country allowlisting, ISP filtering, and device-type restrictions, which help evade security scanners and automated detection tools.
Additionally, the kit targets cryptocurrency users with modules for harvesting seed phrases from Ledger, MetaMask, and Exodus wallets, indicating a shift toward hybrid banking and crypto-fraud operations.
Based on reporting by GBHackers.
