Summary
In the set of the new generation of attackers, phishers are a unique bunch. They are able to steal and abuse millions of identities even though most of them are not technically sophisticated. This is because it is not necessary to have technical talent to set up a website that looks like another website—in summary, that is what phishing is. The bar of entry to become a phisher is very low.
In this chapter, we noted how there is absolutely no notion of trust in the phishing underground. We studied actual phishing kits that most phishers rely on to help them quickly spawn their scam websites, and we realized how even phishers attempt to scam each other.
The boldness of the criminals in the phishing underground is staggering. Hundreds of message boards and websites freely advertise the sale of identities of actual citizens that can be abused to steal credit lines and thereby destroy the credit reputation of the victims. The chain of online criminal scams begins with the world of phishing, but continues further to include additional scams such as ATM skimming.
To understand the mentality of emerging attackers, it is important to study and keep in mind the personality, behavior, and workings of phishers, because they are able to cause damage without having to employ complicated exploitation techniques.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access