AI 中文总结
该研究分析1300个2020-2023年的钓鱼工具包,发现多数功能相似、代码复用度高,仅少数具备高级功能,其可预测性或便于大规模检测钓鱼攻击。
AI 中文摘要
钓鱼攻击一直是攻击者欺诈用户、绕过现代防御机制并渗透关键系统的常用手段。在促成成功钓鱼攻击的所有要素中,钓鱼工具包(Phishkits)是关键参数。钓鱼工具包通常用于创建和部署具有吸引力的钓鱼页面,实现规避策略,并与远程攻击者建立和维护后门以交换泄露的数据。本研究对2020年至2023年间收集的1300个现代钓鱼工具包进行了分析,研究了它们的架构、源代码、通信渠道以及与攻击者共享的泄露数据的性质。我们识别出作为规避和隐匿机制一部分的动态重定向和入站网络流量归因机制,还观察到钓鱼工具包严重依赖当前的消息服务来与攻击者交换被盗数据。我们的分析显示,具备高级功能的钓鱼工具包数量相当少,共识别出284个(占比21.8%)未使用任何形式规避机制的钓鱼工具包。此外,尽管不同钓鱼工具包的实现细节存在差异,但维持钓鱼页面运行的主要组件在各工具包中非常相似甚至完全相同。代码复用程度高,且大量依赖已知技巧构建预打包的钓鱼页面,使得大量案例具有可预测性,这可能会在大规模场景下更容易检测这些对抗性操作。
英文摘要
Phishing attacks have always been a favored vector for adversaries to defraud users, bypass modern defense mechanisms, and penetrate critical systems. Among all the elements contributing to the creation and deployment of successful phishing attacks, phishkits stand out as a crucial parameter. Phishkits often facilitate creating and deploying compelling phishing pages, implement evasion strategies, and establish and maintain backdoors with remote adversaries for exchanging leaked data. In this work, we performed an analysis of 1,300 modern phishkits collected from 2020 to 2023. We analyzed the architecture, source code, communication channels, and the nature of leaked data shared with adversaries. We identified mechanisms for dynamic redirection and attributing incoming web traffic as part of the evasion and cloaking mechanism. We also observed heavy reliance on current messaging services for exchanging stolen data with phishers. That said, our analysis shows that the number of phishkits with advanced functionalities is quite small. We identified 284 (21.8%) phishkits that did not use any form of evasion mechanism. We also observed that while there were differences in the implementation details of phishkits, the major components that keep phishing pages functional were very similar or even identical across kits. The level of code reuse and heavy reliance on known tricks to build pre-packaged phishing pages make a large number of cases predictable, which can potentially make the detection of these adversarial operations even easier at scale.