In a concerning revelation, cybersecurity researchers have unearthed a growing trend among cybercriminals who are ingeniously merging the sinister world of voice phishing (vishing) with One-Time Password (OTP) grabber services to amplify their illicit activities. The findings, detailed in a report by CloudSEK, a cybersecurity firm, have shed light on an evolving threat landscape.
Vishing, short for voice phishing, is a manipulative technique where individuals are coerced into divulging sensitive information over the phone. What sets vishing apart is the human touch it adds to cyberattacks, making victims more susceptible to trust the caller on the other end of the line. These attackers employ highly sophisticated tactics, including interactive voice response (IVR) systems, authentic voice recordings, or even real-time calls that convincingly mimic trusted companies. Through these means, unsuspecting victims are deftly maneuvered into disclosing their one-time passwords, typically delivered through text messages, CloudSEK reported.
Recent research brought to light a chilling advertisement on SpoofMyAss.com (SMA), where cybercriminals can access OTP bot escalation and SMS senders, significantly bolstering their capacity to execute large-scale vishing attacks. SMA's toolkit includes the extraction of OTPs, the ability to conduct global calls in a multitude of languages, personalization features, anonymous calling capabilities, and the creation of bot templates - all telltale signs of vishing endeavors.
What's even more disconcerting is that SMA lures users with free sign-ups and a welcoming $1 balance. It classifies its services into OTP Bot Spoofer and SMS Sender. The OTP Bot Spoofer is a call service with the capability to
Read more on tech.hindustantimes.com