
DEF CON 32 - Smishing Smackdown: Unraveling the Threads of USPS Smishing and Fighting Back - S1nn3r
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 30:36
A security researcher investigates a USPS text message phishing scam after his wife falls victim, uncovering a China-based operation called the "Submission Triad" 1:01. The researcher exploits vulnerabilities in scam websites, revealing a massive criminal operation selling scam kits for $200/month 9:30.
Key Takeaways:
• The fake USPS sites loaded resources from the official USPS website to appear legitimate 1:40
• Path reversal vulnerability allowed access to scammers' databases and systems 3:00
• Investigation uncovered a Telegram channel with 3,700+ subscribers promoting scam tools 10:10
• The scammer double-dipped by stealing from customers who purchased his kits 16:00
• Data collection revealed 1.2 million credit card entries from 73,000 unique IP addresses 24:00
The researcher shared findings with banks and postal inspectors, helping identify and protect over 880,000 victims 28:20.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
good morning hey how's everyone doing excited to be here second day all right so thank you all for coming to my talk today on submission Smackdown and ring the threads of the United States Postal Service Mission SMS fishion in figh him back so to start off just going to cover a little bit about who I am uh so I worked full-time as a red team operator I recently graduated University uh first first full-time job kind of Lucky with that um well in University found around $10,000 in various bug Bounty programs that's how I got started in web application testing and various certifications blah blah blah uh and I also recently founded a company Phantom Security Group with a friend of mine so who here to show of hands got one of these text messages oh okay okay a little bit more I expected um exp…