Security experts have discovered free phishing kits on the internet which
allow cyber-crooks to send fraudulent emails.
Panda Security's PandaLabs said that the tools allow cyber-crooks to spoof
bank pages, online pay platforms, Gmail and Yahoo Mail accounts, online games
and blogs.
"The really amazing thing is that these kits are free," said Luis Corrons,
technical director of PandaLabs.
"The number of phishing attacks increases due to the simplicity of the tools,
causing companies and consumers large losses. A recent Gartner study found that
phishing attacks caused US consumer losses of $3.2bn in 2007."
After accessing a URL that contains the kits, the criminal can obtain two
files to create a fraudulent mail.
One file allows them to spoof emails from banks and pay platforms, and the
other allows them to create a fraudulent page that resembles the original. The
kit also includes a free PHP program to send emails from the spoofed page.
The rest of the process is similar to other phishing attacks. The false email
is sent to several mail addresses with a link to a malicious page at which users
are requested to enter personal data such as email addresses and banking
passwords.
"Cyber-crooks buy lists of addresses on the internet, although some are free,
" said Corrons. "If we add free hosting services, the result is that
cyber-crooks can launch phishing attacks at no cost whatsoever."
Sutton, Surrey, United Kingdom | Royal Marsden Hospital NHS Trust
The Royal Marsden NHS Foundation Trust is a centre of excellence for research, development, education and care in the treatment of cancer. Analyst Programmers, Band 6, £23,458-£31,779 plus 15% HCAS, Sutton, Surrey We are ... more >
Milton Keynes, Buckinghamshire, United Kingdom | EDS
Job Description To be primarily an expert in a particular technology (Midrange UNIX), LINUX and use the knowledge to architect infrastructure solutions for clients. Role To produce customised midrange solutions for clients. Where solutioning cannot ... more >
Enterprise Infrastructure Architect, London Unique IT Architecture Opportunities MI5 is now recruiting for an Enterprise Infrastructure Architect with significant experience of IT Infrastructure solution design. As an Infrastructure Architect, you will ... more >
RUGBYFIRST PROJECT MANAGER, TWICKENHAM, c. £40,000 per annum 12 month fixed term RugbyFirst, the most modern administration system in British sport, is a game-wide internet-based tool to help run rugby at all levels, with the ... more >More job opportunities