Blacksec

Administrator
Staff member
ROOT
VIP
Phishing is the oldest hack that never dies — one fake page, one lazy click, and the whole account walks out the door. This guide tears down the entire machine: the kit, the lure, the harvest, the cashout, explained so clean a kid could describe it to his teacher.

TL;DR — A phishing page is a costume copy of a login. The victim types their real password into the costume. Everything after that — session theft, account takeover, cashout — is just plumbing. Full breakdown below.

1. THE COSTUME SHOP (KID VERSION)

Halloween costume rule: the scarier and more real it looks, the more candy you get. Phishing runs on the same rule with accounts instead of candy.

A phisher builds a page that looks EXACTLY like a login the victim already trusts. Same logo. Same fonts. Same green padlock — because the costume wears HTTPS too now. The victim sees their familiar login, muscle memory kicks in, and they type the password like they have a hundred times before.

The only difference between the real door and the costume door is the address bar. Nobody reads the address bar. That single laziness is the entire industry.

Kid version in one sentence: a fake school office that looks real, asking for your ID card, photocopying it, and handing it back smiling.

2. THE KIT — WHAT ATTACKERS ACTUALLY BUY

Nobody codes phishing pages from scratch anymore. Kits get sold — flat prices, update subscriptions, Telegram support, the works. One kit unpacks into:

Code:
index.php          loader + anti-analysis checks
login.php           harvests the submitted password
post.php            forwards credentials to collector
assets/             stolen logos, fonts, favicons
sources/            fake page source (the costume)
landing/            country-specific variants
config.php          where your data gets sent

Open a kit and it is boring PHP. The skill is not the code. The skill is the costume quality and the delivery. A lazy kit dies on sight — wrong favicon, broken spacing, dead links. A top-tier kit survives a suspicious victim's thirty-second inspection.

Modern kits add countermeats too: if the visitor arrives from a sandbox or the wrong country, they get bounced to the REAL site instead — the attacker never burns the costume on researchers.

3. THE LURE — HOW THE CLICK GETS MADE

The page is nothing without traffic. Four delivery channels feed it:

Email — "Your password expires in 24 hours." Panic plus deadline equals zero thinking. Mail filters get better daily, so lures get weirder — replies to real threads, invoices with HTML receipts, calendar invites.

SMS (smishing) — short, urgent, read on the go. Package delivery fakes and bank alert fakes dominate because everyone expects those texts.

Ads and SEO (angler phishing) — buy ads on the brand's own keywords. Victim Googles the brand, clicks the top result wearing the brand's clothes, logs in. Brand's own ad budget funds the attack.

In-platform messages — DMs inside games, social networks, marketplaces. The link arrives from a friend's compromised account, so the costume inherits the friend's trust.

One principle runs through all four: borrowed trust. The message rides a channel the victim already believes.

4. THE HARVEST — WHAT HAPPENS AFTER THE SUBMIT

Victim hits enter. Here is the plumbing, second by second:

The fake page saves the pair — username and password — to the collector. The page then REDIRECTS the victim to the real site and logs them in with the real credentials. The victim sees their real dashboard load and never suspects a thing. Smooth kits even replay the second factor: they ask for the OTP live, forward it to the real login in real time, and the session gets created in front of the victim's eyes.

That live-relay trick is why "I have 2FA" stopped being a shield. The attacker does not need to crack the code — they borrow the victim's finger to type it.

From the collector, the credentials get tested against the real service (fresh password check), sorted by account value, and either used directly — account takeover — or sold in bulk. Bank logins and crypto accounts go direct to cashout. Shop accounts join combo lists. Everything becomes inventory.

5. WHY PEOPLE STILL FALL (IT'S NOT STUPIDITY)

Smart people click. That is the fact the security industry hates admitting. The math behind a click:

Context beats content. The victim was already expecting a package, an invoice, a reset. The lure matches their mental slot, so the brain files it under routine.

Authority beats suspicion. A logo the brain recognizes short-circuits the part that would check the URL.

Urgency beats care. Twenty-four-hour deadlines disable the slow deliberate thinking that would have caught the mismatch.

Phishing does not outsmart people. It outpaces them. The click happens in the half-second before the conscious check would have fired.

6. THE DEFENSE LAYER (WHAT ACTUALLY STOPS IT)

What stops a costume attack: never trust the door, trust the address.

Type the address yourself. Need your bank? Type the bank. The costume only catches people who arrive through its door.

Hardware keys beat everything. FIDO2 keys are origin-bound — they physically refuse to talk to a lookalike domain. The costume can copy the page, never the origin check.

Manager autofill is a phish detector. Your password manager only fills on the REAL domain. Fake domain, no autofill, immediate alarm signal.

Treat every urgency message as hostile until verified through another channel. Bank says account locked? Call the number on the card, not the number in the message.

For operators and defenders both: passkeys are killing the classic harvest — no shared secret exists to steal. The kits are already adapting toward transaction signing and approval-fatigue attacks. The costume evolves. The rule stays: check the door, not the sign.

7. FIELD CHEAT SHEET

StageWhat it isTell
KitBought PHP package — costume + relay + collectorBroken spacing, dead favicon
LureUrgency message riding borrowed trustDeadline language, wrong channel
RelayLive forwarding including OTP replayOdd delays after submit
HarvestPair saved, victim bounced to real siteDashboard loads "too fast"
DefenseType URLs, hardware keys, manager autofillNo autofill = red alarm

The defense table reads obvious on paper and feels invisible at 2am with a deadline breathing on your neck, which is exactly why the polished kits keep winning - they do not attack your intelligence, they attack your attention, and the one second you spend actually reading the address bar end to end is the one second the whole setup collapses into a dead link.

— RELATED GUIDES —

Costume built, lure aimed, relay warm — the click is the only hard part and humans are the exploit. Kit anatomy memorized, delivery channels mapped, defense layer understood from both sides of the glass. Check the door, never the sign.
 
Last edited: