A new version of the "PhishNet" phishing kit has been observed for sale on a criminal forum, with the author claiming compatibility with online banking portals for 12 regional financial institutions (names withheld pending vendor notification). This version, labelled v4.2, adds automatic OTP bypass functionality using a real-time relay architecture.
Key Capabilities
PhishNet v4.2 includes:
- Automatic TLS certificate provisioning for convincing HTTPS phishing pages
- Real-time credential relay - entered credentials and OTP codes are forwarded to the actual banking site in real time, allowing the attacker to perform transactions while the victim believes they are logging in normally
- Telegram-based control panel for credential delivery to the kit operator
- Anti-bot and anti-researcher checks (geolocation, user-agent filtering, headless browser detection)
Availability
The kit was listed at approximately $120 USD and has received multiple reviews on the forum, suggesting active purchases. This is not a novel capability - real-time phishing relays have been documented since 2020 - but the low price point and ease-of-use packaging increases the threat surface.