A new phishing as a service (PhaaS) called “Robin Banks” has been launched, offering ready-made phishing kits targeting customers of well-known banks and online services in the United States, as well as Canada, the United Kingdom and Australia. Targeted entities include Citibank, Bank of America, Capital One, Wells Fargo, PNC, US Bank, Lloyds Bank, Commonwealth Bank in Australia and Santander.

Additionally, the Robin Banks platform offers templates for stealing Microsoft, Google, Netflix, and T-Mobile accounts.
See also: Play Store: Malware apps have over 10 million downloads
The new phishing platform was discovered by IronNet, who published a report stating that Robin Banks has already been deployed in large-scale campaigns that began in the middle of last month, targeting victims via SMS and email.
Robin Banks phishing
The Robin Banks phishing platform is the work of a group of cybercriminals believed to have been active since at least March 2022. The platform appears to have been created to quickly create high-quality phishing pages to target customers of large banks and financial institutions.
It is sold in two price tiers: one offers individual pages and 24/7 support for $50 per month, and the second provides unlimited access to all templates and 24/7 support for $200 per month.
Upon registration, threat actors receive a personal dashboard containing reports on their activities, easy page creation, wallet , and options to create custom phishing sites.
See also: Ransomware attack prevented just because the intended victim was using MFA

The platform also provides users options such as adding reCAPTCHA or checking user agent strings to exclude specific victims from highly targeted campaigns.
“The Robin Banks website has a more sophisticated yet user-friendly webGUI than 16Shop and BulletProftLink — two well-known phishing kits that are also much more expensive than Robin Banks,” IronNet comments in the report.
Also, the new PhaaS platform constantly adds new templates and updates old ones to reflect changes in style and color scheme of the targeted entities.
These advantages have made Robin Banks popular in the cybercrime space, and many cybercriminals have adopted this phishing platform in the last two months.
Robin Banks phishing: There is an active campaign
In a campaign detected by IronNet last month, a Robin Banks operator targeted Citibank customers via SMS alerting them to “unusual use” of their debit card.
The message also contained a link to remove the supposed security restrictions, which leads victims to a phishing page (which appears legitimate) and asks them to enter their personal information.
When directed to the phishing site, the victim's browser is checked to determine whether they are on a desktop or mobile device and the appropriate version of the website is loaded.
Once the victim enters all the required details on the phishing site form, a POST request is sent to the Robin Banks API, which contains two unique tokens, one for the campaign operator and one for the victim.
See also: Hacker stole millions of dollars from blockchain music platform Audius
The phishing site sends a POST request for each web page the victim completes, which aims to steal as many details as possible, as the phishing process can be stopped at any time (if the victim realizes something is wrong or for some other reason).
All data sent to the Robin Banks API is visible from the platform's webGUI for both the operator and the platform administrators.
The Robin Banks phishing platform also allows the personal Telegram operator's

The emergence of this new PhaaS platform is not good for users , as it promotes phishing kits to cybercriminals who may not have as much knowledge and skills and increases attacks.
To protect yourself from these attacks, never click on links sent via SMS or email from people you don't expect , and try to confirm that the website you've visited (or been directed to) is the official one.
Finally, enable 2FA on all your accounts and use a private phone number to receive your passwords .
See more about the phishing platform in the IronNet report
Source: www.bleepingcomputer.com
