mnemonic security podcast

The Economy for Phish

mnemonic

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 50:23

This episode, we’re joined by Ford Merrill, Senior Director of Research and Innovation at SEC Alliance, to discuss the evolution and sophistication of Phishing as a Service (PhaaS).

Merrill shares from his 11 years of experience working on security research in primarily the areas of phishing and DDoS botnets. In the episode, he talks about the shift from Russian to Chinese-speaking operators, who the developers of advanced kits like Darcula and Lighthouse are, and who actually uses them to impersonate brands for financial gain.

Merrill also outlines a complex ecosystem with supporting technologies and roles involving spammers, data brokers, and money launderers. He also shares what thinks needs to be done to respond this problem, and where he sees rays of hope already.

Related resources:

If you haven’t listened to our series on Darcula, a phishing-as-a-service operation targeting victims globally, check out episode 137 and 138 to hear Robby’s interview with mnemonic's security researchers Erlend Leiknes and Harrison Sand about the findings from their technical investigation into the phishing kit platform Magic Cat. And hear how this story progressed as Robby interviews investigative journalist Martin Gundersen from the Norwegian media agency NRK.

Send us Fan Mail

Speaker 2

From our headquarters in Oslo, Norway, and on behalf of all host , Robby Peralta. Welcome to the mnemonic security podcast.

Robby Peralta

I doubt they physically work underground, but there's not much public data around the phishing as a service industry. Similar to ransomware groups, though, they have developers, customer service representatives, partner networks, and quote unquote users. But the users are scammers. Sending us all these text messages that we're not supposed to click on. They prefer Telegram over LinkedIn, and even have their own industry influencers who flash their watches and fancy cars just like the Instagram ones, but are more likely to be in Southeast Asia than in the south of France. Unfortunately for us normal people though, we can't just unfollow them. Because they are following us. I'm guiltily fascinated by the sophistication of this dark part of the internet. And today's guest is one of the best in the world that give us an update on how that part of the internet looks in 2025. Ford Merrill, welcome to the podcast.

Ford Merrill

Thanks, man. It's good to be here.

Robby Peralta

It's kind of hard to research you because you don't have a LinkedIn.

Ford Merrill

Yeah, I'm uh I'm not the most public guy when it comes to social media and stuff like that. I gave up most of those things a number of almost a decade ago. I think I deleted everything. Facebook, LinkedIn, those kind of things.

Robby Peralta

No c correlation to the work you're doing.

Ford Merrill

Uh originally no. It was more just I think a rejection of the overall kind of state of affairs with regards to like the surveillance economy and all this sort of stuff. But yeah, it probably didn't help the type of work that I'm involved in nowadays, uh, that I wouldn't want to go back to it.

Robby Peralta

Yeah, exactly. So um I've seen you on stage uh at least once. Awesome presentation. It was a jam-packed room, but what was that, B-sides?

Ford Merrill

Yeah, I think B-sides Copenhagen, late 2024. Yeah, that was a pretty awesome time.

Robby Peralta

Yeah. For listeners that have not uh heard of you, who's uh who's Ford Merrill?

Ford Merrill

I am the senior director of research and innovation at a company called Sec Alliance or Security Alliance. We are a company delivering cyber threat intelligence services to banks, central banks, financial market uh infrastructures, government, EU agencies, stuff like that. And for the the past 11 years, basically, I've been working on security research uh in primarily in the areas of phishing, uh, some of the real areas of DDoS botnets and so on and so forth.

Robby Peralta

How did you get into this sort of stuff?

Ford Merrill

My background is in Linux uh systems architecture and administration. So I worked for many years in uh web hosting companies uh and data centers in the US and managing large fleets of Linux servers. And most of those at the time were used to host uh websites for large hosting companies. And through that work, when you're hosting shared servers, hosting, let's say, I don't know, but I think we hosted 30 million sites, you're providing these services to a lot of customers who don't really have any concept of security. And they're just installing like WordPress CMSs and Joomla and shopping cart software. And very often those sites would get exploited because they weren't patched or updated, and then they would have, you know, PHP shells or other sort of malicious stuff dropped on them and then used for either spam or SEO poisoning or other types of malicious stuff. And I just got more and more involved in researching those at the hosting providers and trying to take care of cleaning those things up, both for our network and also for our customers, that I really got interested in the world of security. And from there uh did a lot of research into DDoS botnets that were utilizing our servers at the time and went on to present about a pretty significant one that was attacking the American banking infrastructure in late 2012. And that kind of led me to to meet the guys in uh in Copenhagen that I would ultimately work for, which was CSIS Security Group, and that is where I worked for basically the last 10 years until we acquired uh Security Alliance and sort of to merge all our intelligence capabilities into the Sec Alliance brand.

Robby Peralta

In 2012, what did what did phishing look like?

Ford Merrill

Fairly Russian-speaking dominant groups that were involved in phishing back then, and it was usually primarily like credential phishing for things like email address and passwords before the use of like two-factor authentication was kind of ubiquitous. But I think overall the the way that they approached it was yeah, it's just far less sophisticated than it is today. They would impersonate your bank or they wouldn't impersonate a certain organization, but those were not necessarily the most convincing replicas of the pages. And you know, I think it yeah, when you look at those things now, it's it's a different class. But back then, pretty simple stuff. Yeah.

Robby Peralta

Fast forward today, we recently had those the two uh episodes on on Magic Cat, right? Where if I understood correctly, they have you know these kits that just impersonate brands and they're yeah, what does the modern sort of fishing smishing area look like?

Ford Merrill

Yeah, the modern kits, they uh especially from the Chinese-speaking world, which has has, I think, in many ways kind of driven the development and the advancement forward and been like at the leading edge in the past two years. Before that, like I said, it was very Russian-speaking oriented as far as the operators. And a lot of the Chinese-speaking kits are very similar nowadays. They seem to copy each other, they're not shy about copying uh features. When one actor figures out something that works well, they'll all start to implement it. Uh, and so you see a very common uh unified set of features. One of those nowadays is that, well, first things first, all the replicas of the sites they target are very convincing, right? If they if they report to be, for instance, United States Postal Service, and you go to that phishing site, it's gonna look and feel and animate and kind of move and slide and glide just like the real site does. And if I handed you a phone with it already on that site, you'd be hard pressed to know that it's not the real deal. Um and that's true for almost every single impersonation they have. Um, and that's number one is that they've gotten very good at uh at copying the way the sites work. Number two, they're all basically real-time, uh, and they support uh real-time human-driven interaction where the victim is gonna be interacting with the phishing page on one side, and the threat actor is able to interact with that victim live on the other side of the panel, uh, sort of on the back end. And that allows them uh one of the main reasons they do that is because for most modern types of fraud, they're gonna need to also bypass the victim's multi-factor authentication or their two-factor, right? Their OTP code. Uh, and they're gonna do that because they're gonna commit the type of fraud that's gonna require uh an MFA bypass. And so a human, at least for now, needs to be in the loop. We believe that they're working towards automating that system so that that's no longer necessary, but at least it's always possible for a human to intervene. Um, but that means that the the types of fraud that that are committed are usually very instantaneous in terms of as soon as you lose your details, a human on the other side is doing something with them. Um, that that's gonna mean they might not be charging your card right away, or you might not be uh incurring a loss right away, but they're setting it up so that you will uh at some point in the future, usually through digital wallet provisioning. Uh that's a whole rabbit hole we can probably go down separately. And then, I mean, as far as the brands, many of the fishing kits are polymorphic and modular in the sense that they can represent hundreds of different brands. I think you guys saw you know, Darcula around 230, maybe 250 uh supported brands, even as of last year. And so it's probably increased since then. We know Lighthouse, which is another major Chinese-speaking kit, uh, supports equally, I think around you know, 80 or 90 countries, and in each of those countries it will support multiple different brands. So package delivery services, sometimes multiple toll road scams, government impersonations, uh, things like tax refund scams and uh so on and so forth. And in some parts of the world, like a free points scam, right, where it's like you've got a number of free loyalty points at this company, and if you don't use them, you'll lose them, kind of thing. So they just have so many different ways to fool you. That that's one uh big point. And then um one of the things that they've all rotated sort of in mid-2024, we started to see is a real-time lifting of the victim's data. Basically, as soon as you type the characters into the page, the data is gone in the wind. So originally these kits would work where you would need to type in your personal details, and unless you hit submit on the form and posted the request, the threat actor wouldn't see your data. It would just remain like client side on the browser. Now they use like modern libraries like Ajax and different functionality, WebSockets and so on. So as soon as you start typing details into the form, it's already gone. And that's really important because a lot of times victims will get sort of a spidey sense or they'll get cold feet, right? As they're entering their details on the page, they might think that something's wrong and back out of the process before they click submit. And in their mind, because they didn't submit the form, they feel that they didn't actually lose the data. So they won't report it to the police or they won't report it to their financial institution. And that's really damaging because they really have lost whatever they typed in nowadays. So that's a a big step forward in sort of the usability and return on investment for the for the threat actors behind this kind of stuff. So yeah, those are some some common ones anyway now. Yeah.

Robby Peralta

When it comes to the copying of the sites, like the copying the brands, and you said they had like the same look and feel. Do you think that is like being automated through some AI stuff? Because yeah, how are they doing that so efficiently? And I'm assuming they're not using people on it.

Ford Merrill

Yeah, I mean, one of the things they can lean on is basically the real sites themselves. Uh, they can obviously use the the code that's prevented or presented to the client uh as a starting point. So just like storing that HTML response or all the response that the browser receives. Uh that's a good starting point. And then they already have the images, the assets as well to make it look convincing. Um, I believe it's I believe it was Darcula or Magic Cat that actually announced some support for some AI-related tools to help rip and clone these sites, if I'm not mistaken. I don't know if that was your research or another organization. Um so it wouldn't surprise me if they start using those kind of tools for ripping the sites. But I mean ultimately just pulling down a legit version of the page and making some small modifications is often enough to be convincing, yeah.

Robby Peralta

They they must have a lot of people doing this to actually be able to do stuff with that data in real time, because I guess time is of the essence for them.

Ford Merrill

Yeah, there's so many thousands of different participants in the different Chinese-speaking sort of fraud ecosystem that we see surrounding this, and of course, a lot of it is prevalent on Telegram. And there's just so many different communities and actors, and and some of those channels, I mean, many of those channels have thousands, if not tens of thousands of members. And yeah, just just people who are kind of, I think you you mentioned it or somebody mentioned it in one of your previous podcasts, like scam influencers, people who are are kind of leading the way, giving tutorials on how to do this type of crime for normal people. So, yeah, 24-7 operations for various pieces of the ecosystem. We've seen evidence to support that, not just on the fishing side of things, but on the money laundering sides of things and all the supporting technologies that are needed for that. Uh, it's global and yeah, 24-7 for sure.

Robby Peralta

It was Martin, I think, who was talking about the the industry itself. Like you have the influencers and like you have all these different groups of people focusing on certain parts of if if I can call it the value chain, the scam chain. Um can you dive into that a little bit more? Tell us some more about the industry and all that's you know different paths.

Ford Merrill

Yeah, for sure. Um to kind of start somewhere where we know um the fishing as a service developers themselves. So people like Darcula or uh Lao Wang, who who develops Lighthouse, or some of these other ones, um, of which I think we track around eight major Chinese-speaking uh fishing as a service kit developers. So they provide the tooling, uh, let's say, for you to host and run your own site. Their customers will be, you know, sort of phishing as a service operators. So they'll actually set up the sites on their own servers, run them. But those actors will be customers of spammers. So spammers who specialize in sending iMessages, specialize in sending RCS messages and uh traditional SMS as well. And, you know, I think a lot of originally when we started researching this, a lot of people thought that the same people that developed the phishing kits are the same people that are stealing your card information, are the same people that are sending you these messages, and that's not true, right? There's uh everything has become very syndicated and specialized because you need a very specific set of equipment and skills and and um know-how to do each part of it. So they'll pay, you know, for instance, the the phishing as a service operators will pay the kit developers for a right to run the software, they'll set up the sites, they will uh acquire lists of precision targeting data from basically data brokers that trade in compromised data, compromised credentials, personally identifiable info, like they know your name, your street address, sometimes your date of birth, and your social security number. And then they will filter these lists. Uh, for instance, if they want to send a toll road scam to American victims, if the kit that they are running is, for instance, like uh Easy Tag or Texas tag, they know that they need to pick pick victims in American area codes that are in Texas are in the correct geographies for those specific toll road operators, and they'll work with a data broker. So, like, give me a bunch of Texas numbers, and then they will further refine that by identifying which numbers support iMessage, which numbers support RCS, and which ones only support SMS, so that when they purchase from their spammers, they will give the list of uh iMessage supported numbers to their iMessage spammers, they'll give the list of RCS supported ones to their Android spammers, and so on and so forth, right? Because most of these spammers also specialize in one or the other uh because you need a big farm of iPhones to send iMessages or a big phone of Androids to send RCS, and normally they don't do both. So that those are like kind of three obvious and major components of the thing, but then you have sort of the whole money laundering side of it as well, because if you obtain PII and card information, it's not useful unless you can launder and get money out of that. Uh and so there's a whole slew of folks that are involved in, for instance, the gift card trade. So buying, selling, and laundering gift cards. Uh, that's a very popular one. Physical goods as well, doing uh mule operations. So taking those stolen cards and providing a way for mules to go into stores and buy physical goods and buy gift cards from those stores. That's a whole area of specialization. And then those folks are going to be supported by people that do, for instance, that create NFC relay software. So you've heard of Ghost Tap and the ability to relay a tap-to-pay payment around the world. There's like many forms of that type of software now. And so that's a whole specialization in and of itself, right? Like developers that just provide these Android apps that can function as a way to magically relay a tap-to-pay transaction around the world. And that supports this whole mule story uh as well. And, you know, there's there's others that do like point-of-sale terminal laundering. So these will be people that have obtained um physical point-of-sale machines like you would see at your normal retailer where you would tap to pay on them, but instead they will use them to take stolen cards that have been provisioned to a digital wallet and basically just tap to pay themselves with invoices with victims' stolen cards, and that's a way that they do laundering. Um there's online merchant laundering, so these are folks that set up things like Stripe accounts, PayPal accounts, Zettel accounts, and then they will create fake invoices and then basically pay themselves using the victim's digital wallet sort of provisioned card as well. So there's a lot of that. And then when you look at kind of the operational side of the things, the things that support making the phish uh better or more effective and stuff like that, we know that there are residential proxy providers. So these are going to be people who maintain uh generally like unwanted applications or malware type installs where maybe they provide some software that allows you to do a free VPN so you can watch something on Netflix in the region you want, but it creates a proxy on your machine where threat actors can then just connect from your machine to anywhere and you know send out traffic, send out spam or or do web browsing or whatever it is they need to do. And this is important because if you if you have a lot of, let's say, American victims cards, you're gonna want to come from American IPs when you purchase things online from them. Uh so the whole residential proxy thing is big. There are anti-safe browsing services in the ecosystem. So one of the things that you'll run up against as a fisher is that as soon as your site gets listed in something like Google Safe Browsing, it's usually kind of game over for that particular domain because when victims try to go to it, they'll get a big red page that says warning, you're about to go to a page that's you know malicious. You probably don't want to do this. And if you're really sure you want to do this, you should click through. But um, of course, when most people see that, that's they they're not gonna continue to get scammed. So there are services that will do uh they will work to improve your site's geofencing, which is sort of blocking victims from connecting to the site unless they're from the correct geography. Uh, they will work to improve uh like anti-bot measures and anti-scrapers. So these are things where they're gonna prevent researchers and security companies from sort of connecting to the phishing site to observe what it is and make sure that they know that yes, this is a malicious site. Um, and that is sort of all in an effort to reduce that site uh from being, or you know, prevent that site from being listed in something like a Google safe browsing. Um there are, yeah, a few of the other ones that are kind of interesting uh are the people that specialize in the creation of iCloud and Google accounts. So there are specialists that do nothing but sort of do new account fraud to sign up new email addresses with Apple and Google to create new accounts there. And that is uh a specialization because nowadays you usually need SIM cards that are attached to the correct region or geography to create, for instance, a US region-locked iCloud account. And so they'll need SIM cards, they'll need other backing email addresses. So they'll do new account frauds with things like Hotmail or Yahoo or so on and so forth, and then they'll use those email addresses as a backer for the Apple accounts or for the Google accounts. And they're important in the ecosystem because they will provide those accounts to things like the spammers. Because, of course, for them to send iMessage spam, they need to log into many different iPhones with many different iCloud accounts, and those will get banned after a number of messages and they need to constantly recycle that. And they also need those accounts to add stolen cards to digital wallets, right? So they'll need an iCloud account to have on an Apple device so that when they steal a card, they can add it to Apple wallet on that device. Um, so that's a whole interesting sort of area of the ecosystem. And then physical device specialists or providers, uh, most likely, I mean, there are going to be people who who are involved in the sale and trade of used phones. Um, maybe they originally started like as a legitimate business, but these customers who are criminals, particularly the spammers, they need a lot of phones uh to do what they need to do. Uh so they'll be buying older iPhones, older Android devices as well, uh, in an attempt to load SIM cards into them and send spam, uh, as well as they'll need these devices to add these cards to digital wallets. Uh, so that's a whole kind of area. And uh SIM card providers, of course, uh clean SIM cards for various networks and various geographies are going to be needed uh to set up a lot of these accounts. So you have people that that maybe work or or travel to different countries and buy you know a tremendous amount of SIM cards, or have somebody that's an insider at a telco that can provide them with SIM cards that they can then take back to uh Asia and maybe you know just attach them as roaming. So technically they'll be on one of the Chinese uh mobile networks, but they will be on there with a US SIM or a European SIM card and stuff like that. So yeah, that's kind of a quick uh as quick as I can make it, like a like an overview of of all the things that we look at in this ecosystem.

Robby Peralta

You're not bored at work, are you?

Ford Merrill

No, not at all. Not at all.

Robby Peralta

So, first of all, these um it kind of reminds me when you're talking about like the scale of this operation and all the different specialties. It's kind of like ransomware gangs and initial access brokers and that whole ecosystem. Do you think they're the same organized crime groups, or this is you said China, and there's I know that the r ransomware industry is kind of Russian, or is there like sort of spillover from those two gangs? I mean that I don't know.

Ford Merrill

I don't try to get too much into anything that I can't really prove. So I'm just kind of looking at what's in front of my eyes. Part of my theory though is that the the Russian operators in general, in terms of all forms of cybercrime and fraud, I think in general they have a higher level of OPSEC. So they're more careful about exposing themselves, they're more careful about their identity. And so because of that, you know, it's harder to find more information about their ecosystems, about their activities in in general. Whereas it seems that most of the Chinese actors that we see, uh, especially the ones on Telegram, are very brazen, right? They don't seem to have any fear or worry about getting caught. They're very open about what they say that they do and what services they offer. In many cases, we also see actors that share, you know, sort of photos of themselves in different areas, maybe with their face blurred or covered with something, but you know, these are still things that give clues away as to who you are and can later be used to sort of link things up. I believe there are also Russian-speaking actors that are doing this type of crime, but my guess is that they're being much more careful about it and perhaps simply not as large of a scale, like not as large of a scale, or if they are, they're just being very careful about it. I I think in general, that's kind of the way I look at it. Now, I I do believe that the Chinese actors are are perpetrating a lot more of this uh than than the Russians when uh the Russians are at this time. And that might just be like you said, I mean, Russians historically or Russian-speaking actors have historically had a bias towards it seems like ransomware, and they see that as a clean way to get to the money. And the Chinese actors maybe see it a little bit differently. I can see the benefits from from their point of view to both, right? One of them you have a clean getaway with crypto that pretty much once you have it in your wallet, I mean, there's not much additional that needs to be done. Whereas with this type of fraud, with smishing and obtaining card information, you then need to add that to a digital wallet, you then need to spend that somewhere on some services, you need to launder that forward. I mean, there's a lot of a lot more moving parts to it. So maybe uh maybe that's a reason that other actors aren't as interested in it because it's just so much work.

Robby Peralta

Why can they be so brazen? You know, the but the ransomware gangs, they say that they have like um there's a Russian word for it, but like coverage. They have somebody higher up that kind of as long as you're giving me some information and helping me do my job, then it will look the other way. I wouldn't assume that's like that in China, but it it must be, right?

Ford Merrill

Um, I don't know. I mean, I I don't I don't like too much to speculate about all this because it always that's one of the questions that people often ask me is is this state sponsored or is there some relation to the Chinese government? And we haven't ever seen any proof um to sort of support that idea. That said, I can kind of theorize that if these folks are not targeting Chinese victims and therefore the Chinese government doesn't really see it as a problem for them, then it it may not necessarily be so important for them to look out for like what these folks are doing, targeting people abroad. So maybe just simply not a priority for them. There are various takes that you can obviously get even more, let's say, cynical about that, right? And some people would say that, well, if they're targeting Western victims and they're bringing money into China, it's sort of aligning with all the geopolitical goals, right? It's damaging the West or Western victims, it's improving the situation for China. So is that some of it? I don't know. I I don't really want to speculate or sort of like make claims there that aren't founded in in something, but I guess it's maybe best an exercise for the listener to decide like what you know why they think that is. But yeah, we we certainly haven't seen any real fear of seeming fear of law enforcement. Although one thing that you have to keep in mind is most of these threat actors they choose to tell to communicate on Telegram. And I think that one of the reasons they do that is that they feel that it's sort of out of the reach of you know the the Chinese government as well. Like they're not uh conducting this activity as far as we know on WeChat and other very Chinese platforms. So it very well may be that simply the Chinese government doesn't have good visibility into this particular activity. I would be shocked that they didn't, but I mean it stranger things have happened, right?

Robby Peralta

Now I was just thinking you named the uh developer behind Lighthouse, Lao M Wang or whatever you said, and then you know, the guy behind Darcula. They got I don't want to say docs, but they like we know what they look like, we know their names. But they haven't been arrested as far as I know. The guy with Lighthouse, do you know what happened to him or is he is he like in hiding, or he's apparently since you know his name, he must be still going.

Ford Merrill

Well, we know his Telegram handles, right? His telegram, okay, that's right. La Wang is is sort of his his moniker, the creator of Lighthouse. No, he's still, as far as we know, he's still active. And yeah, we don't know too much about his physical identity. But yeah, I read, of course, the research that you guys did on Darcula, and of course the piece that I think NRK did as well. Um yeah, I don't know. I mean, why why isn't some action taken? Again, that's kind of a mystery to me.

Robby Peralta

I was gonna say, like, what can what can we do about this? But it's kind of only like the telco providers in the banks that can actually do anything about this.

Ford Merrill

Everybody wants one clean, easy answer where it's like, okay, you just go to the banks and they solve this problem for you, and you never have to worry about it again. The problem is this is so complex and it and it has so many different parts and touches so many different sorts of ecosystems that you you need a hybrid approach, kind of a defense in-depth approach to this, because there's so many players involved. So take the telcos, for example. Uh, one of the original sort of I'll call it a naive assumption is okay, the telcos can fix this by preventing the messages from from being received or from being sent, right? And all of these actors nowadays use end-to-end encrypted messaging to deliver their messages to the victims. So it'll be like an iMessage or an RCS message instead of a traditional SMS. And the reason they do that is because the telecoms providers can't see the message, they can't actually inspect the traffic, therefore they can't block it. And what it means is that the victims have to report, you know, as soon as you get that message, you need to click report junk. And by the way, I recommend everybody does that. When you know it's a scam, click report junk because that'll go directly to Apple or to Google, and their teams will incorporate the sending device, the sending account, we believe, into some sort of threat calculations or some trustworthiness calculations. And if enough of those reports come in, that account gets banned, right? But not before a number of messages have been sent from it. And that's what they're banking on. So, what can the telecoms providers do there? Not a lot, right? They they can stand up uh reporting channels for their customers to also report those type of scams to them as well as to Apple and Google, which is good because those providers do have reach within messaging networks. So that is one thing that I know some of them are working towards. One of the other things that telecoms providers need to really, I think, be mindful of, and and I have been for a while, regardless of this situation, is the issuing of SIM cards in bulk or you know, sort of not doing appropriate KYC for SIM cards and basically providing threat actors a way to get a lot of phone numbers and and accounts. That's a big one. But again, that's not a silver bullet on its own. The banking side of things, that's one where I think is a pretty positive, a positive story and a bit of a ray of hope because uh from the very beginning, those are, you know, we work with with a lot of banks and those are are some of our primary customers, and therefore we provided a lot of this research all throughout sort of the history of it to them, and they were always very interested in sort of what they could do to make this story better for their customers and to fight this type of fraud. And so I know for sure that in terms of digital wallet provisioning, the story is continues to get better and better globally. So it used to be that when you would receive one of these messages, you would lose your personal details and your credit card, and then they would add it to like an Apple wallet or a Google wallet. And pretty much they're they were successful a vast majority of the time. Uh nowadays there are many different sorts of uh controls that I think are are being implemented where many of the threat actors are sort of scraping the bottom of the barrel in in some respects, where a lot of the major issuers and banks, they cannot successfully provision those cards anymore on certain types of devices, in certain geographies and stuff like that. And so, you know, it's always a cat and mouse game, but from the beginning, when this was kind of wide open because digital wallets were a very new thing and digital wallet fraud was like an unexplored area. Now it's been known about for at least two years, and the banks have had a lot of time to think about how they they view controls related to allowing a card to be provisioned on a wallet. And likewise, same with we believe Apple and Google, right? That they've had the time to also work on this problem as well. So I think there the story from both the banks and the technology providers continues to get better. That said, these tools that the threat actors have are very interesting because even if let's say we get to a point where all digital wallet provisioning is no longer possible except for the valid card holders on the real devices, and so therefore these actors can't steal cards and put them on digital wallets anymore. Well, they have a great set of tools for account takeovers and like traditional phishing, plus they support real-time MFA bypass. So things like adversary in the middle, where you get pished for your Microsoft's credentials, and then you provide your MFA and validate that attacker to log into your corporate environment. Or, you know, we're seeing them rotate into things like account takeovers of brokerage accounts. So I think Darcula and uh Lighthouse, or Magic Cat and Lighthouse, depending on how you look at it, they both support major brokerages like Fidelity, Schwab, Merrill Lynch, Interactive Brokers, a number of Japanese ones as well. Uh, and the goal for those is to uh they'll send a text message to the victim that's like, hey, your Schwab account has been frozen due to some security review, you need to log in and sort this stuff out. And so the victim will basically provide the threat actors the ability to log into their account, and then they will use those for like a twist on a traditional pump and dump scheme, where instead of trying to wire the money out of the account because the controls are too good at the investment uh institutions, instead they will do things like buy a bunch of Chinese IPO stocks all at the same time, or buy some penny stocks that they hold in other accounts or that they hold options uh against in other accounts. So, you know, I think once the digital wallet, let's say, problem is is solved, we'll move on to a world where these tools are just used for other types of things.

Robby Peralta

Wow. What a world. It's but it's always been like that, right? It's always cat and mouse, just constantly evolving, and and we get better at defending one thing, and then people find new ways to exploit things that we haven't thought about yet. Uh and that's the beauty of it, right? Yeah. I want to say, at least in our neck of the woods, this is kind of like a victimless crime most of the time, right? Because if we get scammed and we realize it that we've, you know, lost the money, usually and in Norway the banks have to pay for it. It's probably like that in Denmark too, right?

Ford Merrill

I don't look at it as victimless because even if the bank makes the customer whole, right, that money doesn't come out of thin air. So I mean, somebody is losing, whether that's the the state that's supporting the banks or whether that's the investors that take the loss in in the in the bank. And when you look at the things like um like the money laundering where they're buying gift cards and they're buying physical goods, I like to explain this to people that that's one of the most interesting forms of laundering for the criminals. But it's also one of the scariest forms of laundering for the the banks, the victims, the retailers, the merchants, because once somebody's gone into the store and bought physical goods with, for instance, an NFC relayed digital wallet, uh, once the goods have left the building, there's no recouping that loss. It means that either the merchant is gonna take the loss, or the bank that's gonna have to deal with the chargeback or you know, whatever making the merchant whole is gonna have to deal with the loss, or the bank passes it on to the victim who's their card holder, they're gonna take the loss, right? But somebody's gonna lose there. So yeah, and in some ways, people saw these traditional fishing, I think in China as well, some of the people who perpetrate this type of crime, they think of it as a very bland white-collar crime or some sort of like in a way, maybe not victimless, but that it's not a serious form of crime in in some ways. I guess I get that impression that they think this is kind of low-level stuff. And maybe individually, on an individual case-by-case basis, it doesn't seem that big, but when you look at the scale of it, I mean we're talking very likely in the billions, if not tens of billions of dollars globally. This is you know, this is huge.

Robby Peralta

Yeah, this is that's why they say that the um uh cybercrime is generating more money than drugs because of these. This is like one of the biggest uh uh factors that I would assume. But I guess this is better than uh pig buttering.

Ford Merrill

Yeah, the investment scam stuff and and elder fraud abuse. I mean, yeah, that stuff is really painful for the victims, and also it's just painful to see from the outside, like somebody that you know is retired and and you know loses in everything that they've ever worked for and owned and saved, and there's really just no recourse for it at all. That's heartbreaking to see. And I do think that that is terrible stuff, but I don't think for a minute that the people behind this wouldn't do that if they had the chance, or if they, you know, if they're willing to steal $2,000 from you, they'd be willing to steal a million. It's just a question of they're not able to, right? Or they don't have the uh ability to or the know-how to. Now, we've seen some of the actors in the Chinese space that have moved on to things like investment scams and account takeovers are in and are and are involved in things like that. Um, and they've had the perfect training and tool set to do it. They have the tools that are convincing that can fish a victim in real time for any data they want. They can represent any brand that they want, and they can go after any data that they need. Um, so for instance, like they're not spraying and praying. They are sending like they're they're doing precision targeting of victims through uh data brokers where they'll say, okay, give me 2,000 American numbers that are in Texas, and I'll send a text message to them for United States Postal Service or um toll road scams, something like that. But imagine if instead they did like spear phishing with this, where they knew you and they had a lot of your details already and they wanted to log into your bank account or they wanted to log into uh your telecom provider to facilitate like a sim swap. One of the things they could do is send you a message with like a package delivery scam. And then you would think, you know, I mean, you might already know about you obviously already know about it, so you hopefully you wouldn't click it. But if you weren't aware of it and you fell for it, you would start putting your PII in, you would start putting your card information in. And in your mind, you would think, okay, like what's the worst that can happen? Just my credit card is going to be lost and uh uh some dollars that my bank will reimburse. But then once you get to the two-factor authentication page where you're putting your OTP code in there, you're also in your mind thinking that that OTP code has to deal with that credit card and it's related. But on the back end, they could simply be logging into your to your actual bank account, or they could be logging into your telecom provider and requesting and that's why you're receiving the OTP that you'll give them. So in your mind, you just got kind of completely hoodwinked. You even at a best case scenario, and you thought it really was a scam, you thought the worst you were going to lose was the money attached to that card or something, but instead the OTP went to facilitate a sim swap for your account. And now they reset your Gmail, locked you out of your Gmail, now they reset all your other passwords, logged into your crypto exchanges and you know, all this kind of stuff. They have the tools available to do it. It's just that right now the digital wallet angle is sort of the lowest hanging fruit and the the the easiest thing for them to monetize uh very quickly.

Robby Peralta

So that must be your uh you feel like that's their roadmap. They're gonna be going towards those more big big hunting. What do they call that in ransomware? Big game hunting. Big game hunting, yeah.

Ford Merrill

I would be shocked if they didn't. Um, or at least not everyone, because uh again, like I say they. Um it's important again, I think, for people to realize there may be eight major fishing as a service developers that provide the technology that we know about, Chinese ones, anyways, that I'm speaking, that we know about that sell this technology. But for each of those, they have thousands, if not tens of thousands, of customers. So imagine you probably have let's call it 30 to 50,000 individuals that are buying access to these services committing these crimes, and not every single one of those individuals is the same person or has the same TTPs or the same MO. They may use different hosting services, they might use different domain name registration patterns, they may target different geographies, uh, they may be very European focused or US focused or Southeast Asia, so on and so forth. Each of them may have individual brands that they like to represent or you know, target. They'll have different message bodies that they like to send that they have success with, um, and so on and so forth. So when you think about like all those different people, some of them are hardened cyber criminals that know a lot about the game and have been doing this for a long time. But we also believe from what we observe is that many of them are likely normal people that are caught up in sort of this uh work hustle, like 996, like toxic work culture of China. They're not making very good money, and they're seeing these scam influencers on social media show that, hey, there's a way for you to make a lot of extra money just um, you know, scamming some chumps out of you know their credit card information, and you can buy my course to learn how to do it for like $750, and you'll learn how to do this. So these people maybe have no real background in cybercrime and they're introduced to it by like a step-by-step guide. Now that sets them on a path to learning, right? As soon as they learn how to do that, depending on what their appetite is for growth and and sort of moving up in the ladder of this kind of community, they might very well say, Well, this is really cool. What about crypto scams? What about investment scams? How do I do these other types of things? And now they have some understanding of hosting, of DNS, of phishing, of you know, bypassing MFA and so on. So that's what I I think when I think some people have already started to move in that direction. That's why we're seeing the brokerage scams already. We're also starting to see like more bank account-related lures again, instead of packages and toll roads and and government scams. But I I think for a good part, uh a chunk of those, that'll be the direction that it moves once digital wallets finally fizzles out or is too difficult for them to monetize.

Robby Peralta

Well, you have a job for the foreseeable future, Ford.

Ford Merrill

Cybersecurity. It's just constantly cat and mouse, and uh and we always gotta just uh stay ahead of the of the attackers, right? And uh that's always challenging.

Robby Peralta

Right. Um I'm actually going to interview uh I think her name is Erin West. She is the used to be a district attorney now. She's uh going after pig butchering. She calls it butchering, she doesn't like to call it pig butchering. Um so that'll that'll be interesting because I'm I'm wondering if there is like a connection between all this sort of organized crime command china. There must be. And those bit butchering that those guys are making serious money.

Ford Merrill

So um yeah. Yeah, especially on a per victim basis. I think the numbers are are are really crazy on those um those type of scams. And um Yeah, I don't know what the sort of politically correct wording for for it is, because I don't really like the term either. It implies that the victim is is sort of something about the victim, which which I don't love. But then again, um I guess it's just what became very popular. But that'll be an interesting I'm looking forward to hear hearing that interview as well to see what's being done in that space.

Robby Peralta

We're young-ish, right? I'm sure we've talked to our parents about, you know, don't click on anything, but it's kind of like the future is like don't trust anything from anybody.

Ford Merrill

Correct.

Robby Peralta

Right? Like, what are we supposed to do about that?

Ford Merrill

Yeah. I mean, unfortunately, that really is um has become sort of the advice is that if you didn't ask for it, don't trust it. I think the worst part about that advice is it's completely unrealistic and unsustainable. You cannot expect that a normal person can live their life at like a threat alert, you know, a DEF CON 10 all the time. You you just that it's not possible. Right? Is it yeah? I mean, A, it's unhealthy, but B, it's just it's simply not possible. Through fatigue, you will eventually start to let your guard down because it's just not possible to keep it up for that long. So I think, you know, be wary of everything you receive uh that you didn't ask for in terms of messages. It is uh a fair advice, but I think actually the most important one is when something is asking you about your two-factor codes or to authorize an action, to really give that an additional level of scrutiny and think about it is the place that I'm inputting this or authorizing this the legitimate site, or is what I'm authorizing what I expected to actually happen? And there's also the fatigue factor there, right? Because in Denmark we use Mid ID, which I think is similar to like bank ID that I believe you use in Norway, right? So instead of text-based codes for most important stuff, we open an application to say, like, hey, are you sure you want to do this? Yes or no. But the the weakest part is still the human, right? That's always the weakest link. So it even me, like when I'm doing transactions that like I'm sending somebody money uh and I need to authorize it, it's almost like I'm running on autopilot because I know I just requested a transaction, so I know I've just got a an MFA request. And so I have to stop myself from just automatically swiping on it and actually at least read it and say, okay, I know I just made a transaction. Is this the amount? Is this the correct thing that's happening? Move away from text-based OTPs on my important stuff when I can and just be mindful. Um if you're young and you have parents that are getting older, I mean, keep in touch with them, understand what's going on with their accounts, understand if like how they're doing their password management. Are they enrolled in MFA and stuff like that? And get involved and help them, right? Like I have family members where they look to me for advice, and for some of them, I actually just help manage that stuff for them, right? I log into their accounts on their behalf to make sure, kind of do a security checkup, see what systems they have in in place, right? Do they have MFA in place and so on? Um, and I think that's so important as sort of our parents get older because they didn't grow up with this technology the way that we did from the very beginning. They struggle, like living in this digital world where everything seems to almost be out to get them, and that's certainly not a good place to be. No.

Robby Peralta

I actually did that for my uh girlfriend's parents. It took me an hour and a half for them to turn on uh their two-factor for like their email and their Facebook.

Ford Merrill

Yeah.

Robby Peralta

And then uh yeah, I did that for my parents, and then my dad's calling me like, Yeah, I try to get a new phone, but I locked my sim and you made me do this, and just like damn it. It's uh it's a journey, but you know, it's better than the alternative, I guess.

Ford Merrill

So yeah, being tech support is tough. Yeah.

Robby Peralta

Yeah, right. Well, thank you for all the work you do in that uh space, Mr. Merrill. And last question for you. I'm mad at myself for deleting it, but I just got a text message from a an iMessage actually from a Y mail account. Uh and they were asking me to to do some sort of creative work for them to earn three thousand dollars a day doing this sort of work. Is that a scam that you're aware of currently going on?

Ford Merrill

Um, yeah, these relate to the more like work-at-home type of scams. Some of them are just recruitment scams where it's sort of a like we have a position for you and you've been considered, but in order to get the job, you need to pay like a small application fee. That's one of them. The other one we see regarding kind of like the work-at-home stuff, they'll be using you to do things like review washing or fake reviews on like Amazon products or things like that. Another one will be basically mule operations for packages. They'll ask you to like open a package, inspect it, make sure it looks good, or review it, make sure it's of high quality, and then repackage and send it on to a recipient. And all they're using you for is to sort of send you goods that they've purchased with like illicit funds or stolen goods, and then you're reshipping the item for them to bypass like customs controls or things like that. So there's there's a lot of little things like that where somebody is technically committing crimes, maybe without really knowing what they're doing. Those are those, usually those kind of text messages where they they have some offer for a job for you or something along those lines.

Robby Peralta

Yeah, I went crazy because I opened that and I was like, yeah, scam. Report junk and block and collar. But I think my finger touched the like the recording button, so then I just saw like the red, you know, like an eye message where it starts recording. And then I just set off my phone and I was like, wait, what? They have like some sort of campaign that could allow them to turn on the microphone. So then I went into my messages app and it was like turning off a microphone from messages, and that's it wasn't possible. So very suiting that I have this episode with you afterwards.

Ford Merrill

Yeah, that's funny.

Robby Peralta

If the listeners want to um follow you, since you're not on LinkedIn, do they just follow Sec Alliance?

Ford Merrill

Yeah, go to secalliance.com. Yeah, check us out. Reach out to me through there.

Robby Peralta

Thank you so much for your time today and keep up the fantastic, awesome work. Absolutely.

Ford Merrill

Thanks, man.

Robby Peralta

Thanks, Well, that's all for today, folks. Thank you for tuning in to the mnemonic security podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail at podcast at mnemonic.no. Thanks for listening. We'll see you next time.