[SANS ISC] “Serverless” Phishing Campaign

[SANS ISC] “Serverless” Phishing Campaign

I published the following diary on isc.sans.edu: “‘Serverless’ Phishing Campaign“:

The Internet is full of code snippets and free resources that you can embed in your projects. SmtpJS is one of those small projects that are very interesting for developers but also bad guys. It’s the first time that I spot a phishing campaign that uses this piece of JavaScript code.

To launch a phishing campaign, most attackers deploy their phishing kits on servers (most of the time compromised). These kits contain the HTML code, images, CSS files, … but also scripts (often in PHP) to collect the information provided by the victim and store it into a flat file or send them to another service… [Read more]



Source link

The post [SANS ISC] “Serverless” Phishing Campaign appeared first on SecuritNEWS.


Published by SecuritNEWS

SecuritNEWS is a news aggregating site. We aggregate news from publicly available RSS fields. Please contact us for copyright concerns. SecuritNEWS depends on ad networks and Amazon.com affiliate programs for monetization.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

Create your website with WordPress.com
Get started
%d bloggers like this: