Inside a Cybercrime Scam Operation

Inside a Cybercrime Scam Operation

Source: YouTube · John Hammond · published Jun 20, 2023 · 23:07

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video provides an inside look at WordPress phishing scams by analyzing server-side code that reveals how cybercriminals create and sell malicious scripts to steal credentials 0:04-0:13.

Key Takeaways:
• Scammers sign their malicious scripts with online handles like "Spock's coder" and "grills" to take credit for their work 0:44-0:49
• The scripts include anti-bot measures that detect and block web crawlers by returning 404 errors 3:50-4:10
• Cybercriminals use Telegram bots to exfiltrate stolen data like usernames, passwords, and IP addresses 8:05-8:13
• These threat actors operate in Telegram communities where they share hacking tools, stolen credentials, and cybercrime-as-a-service offerings 15:01-15:33

The analysis exposes the surprisingly organized business model behind these phishing operations, where even criminals seek recognition for their malicious work 22:00-22:11.

Sources:

  • 0:04-0:13 Introduction to the phishing scam analysis
  • 0:44-0:49 Explanation of scammers signing their scripts
  • 3:50-4:10 Anti-bot detection mechanisms in the code
  • 8:05-8:13 Data exfiltration using Telegram bots
  • 15:01-15:33 Cybercriminal communities on Telegram
  • 22:00-22:11 Conclusion about the business model behind scams

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

in a previous video we got a behind the scenes look at a digital online scam because a viewer who happened to be a WordPress hosting provider and administrator was willing to share some server-side code PHP HTML everything on the back end that anyone wouldn't be able to see unless they had access to the server the computer the device itself and that was awesome enough as it is but something even more incredible is that they sent us even more take a look at this email no honor among Thieves they are signing their WordPress scripts to get credit hey I came across a few interesting things lately when battling the WordPress phishing sites I'd email you the full archive but it looks like Gmail doesn't like me sending these hey we got to get this individual uh spun up with some password protecte…