Joe Security's Blog
Google Phishing Kit: When Phishing Becomes a Real-Time Remote Browser
IntroductionMost of the phishing pages are mere static clones of the login form, whereas sophisticated phishing kits implement adversary-in-the-middle techniques that perform authentication in real-time. In particular, the design being analyzed below fits into the Browser-in-the-Middle (BitM) scheme where the victim-facing page becomes the client for the browser session running at the backend of the phishing operation.The captured network traffic and the extracted client-side artifacts demonstrate the functioning of the BitM session. The backend streams complete Google authentication views and subsequent DOM updates to the victim over Socket.
Read more...
Inside ScarfaceStealer's Sandbox-Aware Anti-Analysis System
IntroductionIn this blog post, we examine a multi-stage ScarfaceStealer infection chain delivered through an Electron-based application packaged with NSIS.The investigation began with a Joe Sandbox Cloud Basic analysis https://www.joesandbox.com/analysis/1915862/0/html that produced only limited behavioral indicators, suggesting that the sample did not fully expose its intended execution path.
Read more...
Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign
In this blog post, we examine a multi-stage phishing campaign targeting staff members of the Punjab Safe Cities Authority (PSCA) and PPIC3 in Pakistan. The attack leveraged two distinct infection vectors, both relying on the same underlying infrastructure.The phishing email was analyzed by Joe Reverser in the report available here:https://www.joesandbox.
Read more...