
Hunting Phishing Kits
Source: YouTube · John Hammond · published Jun 11, 2025 · 19:05
Phishing kits are web pages designed to steal personal information through impersonation, funneling stolen data via Telegram or Discord APIs 0:00.
Key Takeaways:
• Phishing pages request login credentials, bank info, or other personal data and send it to threat actors via simple API integrations 0:00
• Many phishing kits use Telegram bots to collect stolen information, with API tokens often found in plain text within the source code 1:30
• These kits can be easily discovered using tools like URL Scan Pro by searching for Telegram API references 1:18
• Some sophisticated phishing kits also deliver malware, like remote access Trojans (RATs) disguised as legitimate applications 9:59
• Setting up a functional phishing kit requires minimal technical skill - just a Telegram bot token and basic HTML/JavaScript code 8:49
These threats are constantly evolving, making proactive security monitoring and education essential for protection 18:10.
Sources:
- 0:00 Explains how phishing kits work and what information they target
- 1:18 Demonstrates how to hunt for phishing kits using URL Scan Pro
- 1:30 Shows how Telegram APIs are used to collect stolen data
- 8:49 Explains how easy it is to create a Telegram bot for phishing
- 9:59 Shows how phishing kits can deliver malware like remote access tools
- 18:10(https://www.youtube.com/watch?v=sSuAKE7gj
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So fishing kits or web pages just like this are purpose-built and intentionally designed to try and steal your information. Oftentimes they're asking for your username or password to log into some application. But they could take like two factor codes or bank account information, credit card info, phone number, physical address, whatever it asks the user, you and you type in and you offer. This one was interesting. It even gave us a app to download. But if we were to continue verification, it would ask us to enter our email or phone number. In this case, it downloaded a rat remote access Trojan that ended up trying to maintain access. But providing information here, we'll just forward that along to the threat actor, the scammer, or the hacker server. Oh, now it's going to be asking for my …