meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, October 12th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 12 October 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Phishing Kits; Open Packaging; Analyzing MSGs; Cisco Flaws; Apple Flaws

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, October 12, 2020 edition of the Sandsenet Storm Center's Stormcast.

0:07.3

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:12.9

If you ever wondered how much work someone has to do to fish a particular website, well, it's actually not that difficult. Jan had a great diary on

0:24.9

Friday summarizing his search for fishing kits, which typically includes a website that

0:32.0

emulates a particular brand and then collects the credentials, and in some cases includes

0:37.4

email templates that can be used

0:40.1

then to direct victims to a particular fishing site.

0:44.3

Now, of course, you can Google for these fishing kits, but one kind of surprising place

0:50.0

where Jan found a lot of these fishing kits was on YouTube because well these fishing kits often

0:57.2

come with a little tutorial or advertisement video that will explain to a buyer how to use

1:06.8

the particular fishing kit and how to actually send the fishing emails.

1:13.1

All in all, Jan found about a hundred different fishing kits.

1:18.4

Now, the top ones are very familiar brands like PayPal, Outlook 365, Amazon, and Netflix.

1:27.1

The diary also includes a screenshot from essentially an online store where you can purchase

1:32.1

these fishing kits.

1:33.7

Some of the cheaper ones, an Apple letter inbox, as they call it, for $5 and an Amazon one

1:42.1

for $3.

1:44.0

More expensive one, well, a Chase bank one for $400. It also depends on

1:51.7

what exactly is included, whether it's just the web pages, whether the email template is included,

1:57.2

or whether even some email addresses of potential victims are included.

2:03.6

Jan also saw a little spike in new fishing kits being posted to YouTube around April, May,

2:12.6

sort of June of this year. Not really clear if there's anything like COVID related or so if that's just a matter

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.