HomeSecurityHacker puts his YouTube channel inside a Phishing website code

Hacker puts his YouTube channel inside a phishing website code

Everyone loves an "epic fail" every now and then, and the latest one in the world of INFOSEC was done by a scammer who thought it would be a good idea to place some of his credentials, like his YouTube channel, to brag about within the source code on one of his phishing websites.

Hacker puts his YouTube channel inside a phishing website code

The discovery, made by Symantec phishing expert Nick Johnston, concerns a brand new phishing campaign that Symantec has encountered in recent days.

Apparently, the “phisher” left a lot of information in the source code of the page, thinking that no one would “ever” look there. The hacker wrote his name, his campaign ID, website , and even a link to his YouTube channel.

1

The naivety of this gesture is on the same level of incompetence as a case three years ago, when an Italian phishing tools developer thought it would be a great idea to put a bright blue background on his phishing page, depicting nothing more than fish. Probably no one told him that the origin of the word “phishing” actually comes from “fishing” and “phreak”, an older term for hackers.

Either way, his fish was a meaningless giveaway that his page was actually a phishing website.

In this last case, the Symantec also noted that the scammer had created a YouTube channel where he advertised his tools.

2

It's nothing new to us that cybercriminals use YouTube to host demonstrations of their malicious code, but they usually keep these links secret and only share them on underground forums.

The reason for this is to avoid exposure and companies like Symantec catching on to their latest work by dismembering it and blackballing it inside their security products. And that's exactly what happened this time with the tools developed by Noureddine ElmGhreBi (the hacker).

His channel still exists and he advertises some phishing tools and a brute-force tool that finds PHP Web shells. However, Symantec and other security firms are now aware, rendering these tools useless.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS