Russian hackers turn trusted online stores into phishing pages

Russian hackers turn trusted online stores into phishing pages Russian hackers turn trusted online stores into phishing pages

According to SlashNext findings, PhishWP employs advanced tactics, such as stealing the OTP sent during a 3D Secure (3DS) check. By capturing this code, attackers can impersonate users, making their fraudulent transactions appear legitimate.

“With the OTP in hand, cybercriminals bypass one of the most critical safeguards in digital transactions, making their fraudulent activities look alarmingly legitimate to both banks and unwitting shoppers,” Soroko said.  “Many people have been trained to believe that one-time passcodes (OTP) help a system to be more secure, but in this case, they are merely handing over the keys to their adversary.”

Other key features offered with the plugin include customizable checkout pages, auto-response emails, multi-language support, and obfuscation options.

Add a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use