Discussion about this post

User's avatar
Emiliano L. Compassi's avatar

The multi-layer evasion architecture here is what stands out to me, particularly the combination of trusted cloud platforms (Framer, Cloudflare Workers, GitHub) at each stage of the delivery chain. The fact that only 1 out of 94 VirusTotal vendors flagged the Framer page speaks for itself. The Blob URL payload injection is a clever touch: it never hosts the final phishing page as a file, removing almost all network-observable indicators. Defenders looking at traffic just see encrypted JSON. The admin WebSocket system hidden behind keyboard-triggered authentication is something I hadn't seen documented before in a phishing kit. The potential client-side privilege-escalation vulnerability you noted is ironic: a security flaw in the attacker's own infrastructure.

Great write-up!

ToxSec's avatar

“The presence of AI-generated artifacts and tutorial-style documentation provides strong evidence that this campaign was built using AI coding assistants rather than developed entirely by experienced programmers.”

love the approach here. this was a chunky post it took me a bit to get through but its pact with good material and kept my interest the whole time. 10/10 great work.

No posts

Ready for more?