HomeSecurityInTheBox: Over 1,800 malicious phishing forms available

InTheBox: Over 1,800 malicious phishing forms available

A dangerous cybercriminal known as InTheBoxis advertising a collection of 1,894 web injections on Russian hacker forums. These malicious forms are used to obtain sensitive information and credentials from various banking services, cryptocurrency exchanges, and e-commerce applications.

See also: Consent-phishing attack passes Microsoft's 'Verified Publisher' checks

InTheBox

InTheBox forms have the ability to work with a variety of Android banking malware and can easily be confused with legitimate apps from major companies, which are used in many countries worldwide.

Web injects are pieces of malicious code that can be inserted into a website or application to manipulate the user experience. The code typically redirects the user to a different page than the one they intended to access, or it can change the page they see by adding additional information or changing existing content. In addition, web injects can be used to track and collect data about users visiting infected websites, such as their personal information, passwords, usernames, and other sensitive information.

With such large numbers available at bargain prices, hackers can now focus on more diverse aspects of their designs and malware creation, while simultaneously expanding the scope of their illegal activities across multiple regions.

In general, banking trojans examine the applications on an infected device and pull specific web injects related to those applications. Once the victim gains access to a target application, the malware quickly activates and mimics the interface of the legitimate product.

See also: Phishing attacks are becoming frighteningly sophisticated

phishing

Researchers from threat intelligence firm Cyble recently discovered that InTheBox offers the latest injects for hundreds of apps. According to latest report , as of January 2023, InTheBox had the following web inject packages as of October 2022:

  • 814 web injects compatible with Alien, Ermac, Octopus, and MetaDroid for $6,512
  • 495 Cerberus compatible web injects for $3,960
  • 585 Hydra compatible web injects for $4,680

InTheBox not only offers packages, but also sells its web injects individually for just $30! Users can also request custom injects for any type of malware. Most of the time, the injects have a second level that requires users to enter their credit card numbers, expiration dates, and CVV numbers.

Cyble found that InTheBox’s malicious forms allow malware operators to use the Luhn to verify the credit card information that victims, thus helping to identify invalid entries. Finally, the stolen data is converted into a string value and sent to a server owned by the operator running the Android banking trojan.

Since February 2020, InTheBox has been expanding its web injects for Android malware, continuously introducing new pages targeting a wider range of banking and financial apps.

See also: Google ads phishing attack targets Bitwarden users

Cyble revealed that the Android trojans 'Coper' and 'Alien' have exploited InTheBox web injects since 2021 and September 2022 respectively, with the most recent campaign taking place last January 2023, which targeted Spanish banks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS