Security researchers have observed that hackers are increasingly using legitimate services, such as Google Forms and Telegram, to collect user data stolen from phishing sites. Email remains the preferred method for malicious actors to exfiltrate stolen information, but these channels highlight a new trend in the evolution of phishing kits. Alternative data collection methods help cybercriminals keep data “safe” and start using it immediately.
Analyzing phishing kits over the past year, researchers from cybersecurity firm Group-IB noticed that most of these tools allow the collection of stolen user data via Google Forms and Telegram. These are considered alternative methods for obtaining compromised data and represent almost 6% of what Group-IB analysts found, a percentage that is likely to increase in the near future. Storing information in a local file on the phishing resource is also part of the alternative removal methods and represents the highest percentage of all.
Read also: Brazil: First in phishing attacks. Which countries follow?

The use of Telegram is not an unprecedented phenomenon, as hackers have turned to the service because they can maintain their anonymity, while it is an easy-to-use service.
A scam-as-a-service that has been used by at least 40 hacking gangs to spoof popular classifieds also relied on Telegram bots to deliver fraudulent websites.
Sending stolen data collected from phishing sites to Google Forms is done via a POST request to an online form, the link to which is embedded in the phishing kit.
Group-IB told Bleeping Computer that compared to email, which can be blocked or hacked and logs lost, this is a more secure method for removing information.
See also: Telegram: How to enable 2-step verification?

Another trend the researchers noticed was that phishing kit creators were double-dipping to increase their profits by adding code that replicates the flow of stolen data to their network's host computer.
Group-IB researchers also noticed that the creators of the phishing kits hide web shells in the code, which allows them to gain remote access to the resource.
In terms of lures, the company identified more than 260 unique brands, most of which were for online services (30.7% – online tools for viewing documents, online shopping, streaming services and more), email clients (22.8%), and financial institutions (20%), which are the typical targets.

Proposal: Huge victory for Google in the legal dispute with Oracle!
Users of Microsoft, PayPal, Google and Yahoo products were the top targets of these attacks, according to researchers..
Yaroslav Kargalev, Deputy Director of the Group-IB Security Incident Response Team (CERT-GIB), said that cybercriminals are now using automation to replace blocked phishing sites faster. A direct consequence of this is the spread of “more sophisticated social engineering used in large-scale attacks,” Kargalev says, which requires blocking the attacker’s entire infrastructure, not just phishing sites.
Information source: bleepingcomputer.com
