chartingshow / crypto-firewall

🎁 Blocks browser-based crypto mining, cryptojacking, banking and crypto malware and phishing websites, apps and hackers command-and-control (C2) servers.
GNU General Public License v3.0
7 stars 0 forks source link

Block `V3B phishing kit` a banking phishing service #512

Closed summercms closed 1 week ago

summercms commented 3 weeks ago

Enhancement idea

Description

A cybercriminal group that is equipping fraudsters with sophisticated phishing kits to target banking customers in the EU. These kits are designed to intercept sensitive information, including credentials and OTP codes. The attackers use various social engineering tactics to trick victims into revealing their sensitive information. The kit is provided through Phishing-as-a-Service (PhaaS) model, and is also available for self-hosting.

One of the key actors, also known under alias "Vssrtje", launched operations in March 2023, promoting the kit called "V3B" on Telegram and Dark Web communities. They have since built a client base focused on targeting European financial institutions. Currently, it is estimated that hundreds of cybercriminals are using this kit to commit fraud, leaving victims with empty bank accounts. Their Telegram channel has over 1,255 members, a significant indicator of the scale and scope of the malicious activity being promoted by the group.

V3B phishing kit supports over 54 financial institutions featuring customized and localized templates to mimic authentication and verification processes of online banking and e-commerce systems in the EU.

Links

https://www.resecurity.com/blog/article/cybercriminals-attack-banking-customers-in-eu-with-v3b-phishing-kit

IOC

I2P websites

n/a

IPFS websites

n/a

Tor2web websites

n/a

TOR websites

n/a

URL's

n/a

Folders

n/a

Sub-Domains

n/a

Domains

abn-amro-gobal.com
app-lnloggen.online
belastingdienst-schuld.nl
belastingoverzicht.info
bezoeknummer0734859938.info
bezoeknummer48912543221.info
black-loans7.shop
bunq-app-nl.net
bvstigveriapp.online
gemiste-aanmaning.com
ics-beveiligde-verificatie.com
ics-cards.org
icscards-nl.com
icscardsvoorschriften.nl
kontoaktualisierer-nl.com
kundenaktualisierungen.cc
lcs-valideren.online
lnloggen-app.online
nl-appverifi.com
nl-bunq-bijwerkerking.com
nl-csdki.com
nt8zd3.ru
reaktivieren-icscard.nl
reaktivieren-icsservice.nl
redirect-bunq-client.ru
valideren-mijn-ics-web1.online
verifieer-gegevens.com
verifieer-nu.com

IP's

n/a

ASN's

n/a

Emails

n/a

Wallet addresses

n/a

Mining pool addresses

n/a