{"id":2070,"date":"2025-02-19T03:00:20","date_gmt":"2025-02-19T03:00:20","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/19\/how-phished-data-turns-into-apple-google-wallets\/"},"modified":"2025-02-19T03:00:20","modified_gmt":"2025-02-19T03:00:20","slug":"how-phished-data-turns-into-apple-google-wallets","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/19\/how-phished-data-turns-into-apple-google-wallets\/","title":{"rendered":"How Phished Data Turns into Apple &amp; Google Wallets"},"content":{"rendered":"\n<div>How Phished Data Turns into Apple &#038; Google Wallets<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Carding \u2014 the underground business of stealing, selling and swiping stolen payment card data \u2014 has long been the dominion of Russia-based hackers. Happily, the broad deployment of more secure chip-based payment cards in the United States has weakened the carding market. But a flurry of innovation from cybercrime groups in China is breathing new life into the carding industry, by turning phished card data into mobile wallets that can be used online and at main street stores.<\/p>\n<div id=\"attachment_70443\" style=\"width: 490px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" loading=\"lazy\" aria-describedby=\"caption-attachment-70443\" decoding=\"async\" class=\"size-full wp-image-70443\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/tollpassphishing.png?resize=480%2C630&#038;ssl=1\" alt=\"\" width=\"480\" height=\"630\"><\/p>\n<p id=\"caption-attachment-70443\" class=\"wp-caption-text\">An image from one Chinese phishing group\u2019s Telegram channel shows various toll road phish kits available.<\/p>\n<\/div>\n<p>If you own a mobile phone, the chances are excellent that at some point in the past two years it has received at least one phishing message that spoofs the <strong>U.S. Postal Service<\/strong> to supposedly collect some outstanding delivery fee, or an SMS that pretends to be a local toll road operator warning of a delinquent toll fee.<\/p>\n<p>These messages are being sent through sophisticated phishing kits sold by several cybercriminals based in mainland China. And they are not traditional SMS phishing or \u201c<strong>smishing<\/strong>\u201d messages, as they bypass the mobile networks entirely. Rather, the missives are sent through the <strong>Apple iMessage<\/strong> service and through <a href=\"https:\/\/en.wikipedia.org\/wiki\/Rich_Communication_Services\" target=\"_blank\" rel=\"noopener\">RCS<\/a>, the functionally equivalent technology on <strong>Google<\/strong> phones.<\/p>\n<p>People who enter their payment card data at one of these sites will be told their financial institution needs to verify the small transaction by sending a one-time passcode to the customer\u2019s mobile device. In reality, that code will be sent by the victim\u2019s financial institution to verify that the user indeed wishes to link their card information to a mobile wallet.<\/p>\n<p>If the victim then provides that one-time code, the phishers will link the card data to a new mobile wallet from Apple or Google, loading the wallet onto a mobile phone that the scammers control.<\/p>\n<h2>CARDING REINVENTED<\/h2>\n<p><strong>Ford Merrill<\/strong>\u00a0works in security research at\u00a0<a href=\"https:\/\/www.secalliance.com\/\" target=\"_blank\" rel=\"noopener\">SecAlliance<\/a>, a\u00a0<a href=\"https:\/\/www.csis.com\/\" target=\"_blank\" rel=\"noopener\">CSIS Security Group<\/a> company. Merrill has been studying the evolution of several China-based smishing gangs, and found that most of them feature helpful and informative video tutorials in their sales accounts on Telegram. Those videos show the thieves are loading multiple stolen digital wallets on a single mobile device, and then selling those phones in bulk for hundreds of dollars apiece.<\/p>\n<p>\u201cWho says carding is dead?,\u201d said Merrill, who presented about his findings at the <a href=\"https:\/\/www.m3aawg.org\/upcoming-meetings\" target=\"_blank\" rel=\"noopener\">M3AAWG<\/a> security conference in Lisbon earlier today. \u201cThis is the best mag stripe cloning device ever. This threat actor is saying you need to buy at least 10 phones, and they\u2019ll air ship them to you.\u201d<\/p>\n<p>One promotional video shows stacks of milk crates stuffed full of phones for sale. A closer inspection reveals that each phone is affixed with a handwritten notation that typically references the date its mobile wallets were added, the number of wallets on the device, and the initials of the seller.<\/p>\n<div id=\"attachment_70436\" style=\"width: 759px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-70436\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-70436\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/phishingphones.png?resize=749%2C567&#038;ssl=1\" alt=\"\" width=\"749\" height=\"567\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/phishingphones.png 1160w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/phishingphones-768x581.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/phishingphones-782x591.png 782w\" sizes=\"(max-width: 749px) 100vw, 749px\"><\/p>\n<p id=\"caption-attachment-70436\" class=\"wp-caption-text\">An image from the Telegram channel for a popular Chinese smishing kit vendor shows 10 mobile phones for sale, each loaded with 4-6 digital wallets from different UK financial institutions.<\/p>\n<\/div>\n<p>Merrill said one common way criminal groups in China are cashing out with these stolen mobile wallets involves setting up fake e-commerce businesses on <strong>Stripe<\/strong> or <strong>Zelle<\/strong> and running transactions through those entities \u2014 often for amounts totaling between $100 and $500.<\/p>\n<p>Merrill said that when these phishing groups first began operating in earnest two years ago, they would wait between 60 to 90 days before selling the phones or using them for fraud. But these days that waiting period is more like just seven to ten days, he said.<\/p>\n<p>\u201cWhen they first installed this, the actors were very patient,\u201d he said. \u201cNowadays, they only wait like 10 days before [the wallets] are hit hard and fast.\u201d<span id=\"more-70276\"><\/span><\/p>\n<h2>GHOST TAP<\/h2>\n<p>Criminals also can cash out mobile wallets by obtaining real point-of-sale terminals and using tap-to-pay on phone after phone. But they also offer a more cutting-edge mobile fraud technology: Merrill found that at least one of the Chinese phishing groups sells an Android app called \u201c<strong>ZNFC<\/strong>\u201d that can relay a valid NFC transaction to anywhere in the world. The user simply waves their phone at a local payment terminal that accepts Apple or Google pay, and the app relays an NFC transaction over the Internet from a phone in China.<\/p>\n<div style=\"text-align: center;\"><iframe loading=\"lazy\" title=\"YouTube video player\" src=\"https:\/\/www.youtube.com\/embed\/ekqZjPAxB4c?si=hYLqGPIBrNthAg9_\" width=\"750\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/div>\n<p>\u201cThe software can work from anywhere in the world,\u201d Merrill said. \u201cThese guys provide the software for $500 a month, and it can relay both NFC enabled tap-to-pay as well as any digital wallet. The even have 24-hour support.\u201d<\/p>\n<p>The rise of so-called \u201cghost tap\u201d mobile software was <a href=\"https:\/\/www.threatfabric.com\/blogs\/ghost-tap-new-cash-out-tactic-with-nfc-relay\" target=\"_blank\" rel=\"noopener\">first documented in November 2024<\/a> by security experts at <strong>ThreatFabric<\/strong>. <strong>Andy Chandler<\/strong>, the company\u2019s chief commercial officer, said their researchers have since identified a number of criminal groups from different regions of the world latching on to this scheme.<\/p>\n<p>Chandler said those include organized crime gangs in Europe that are using similar mobile wallet and NFC attacks to take money out of ATMs made to work with smartphones.<\/p>\n<p>\u201cNo one is talking about it, but we\u2019re now seeing ten different methodologies using the same modus operandi, and none of them are doing it the same,\u201d Chandler said. \u201cThis is much bigger than the banks are prepared to say.\u201d<\/p>\n<p>A November 2024 story in the Singapore daily <em>The Straits Times<\/em> <a href=\"https:\/\/www.straitstimes.com\/singapore\/scam-syndicates-sending-foreigners-into-singapore-to-cheat-retailers-like-apple-store-and-best-denki\" target=\"_blank\" rel=\"noopener\">reported<\/a> authorities there arrested three foreign men who were recruited in their home countries via social messaging platforms, and given ghost tap apps with which to purchase expensive items from retailers, including mobile phones, jewelry, and gold bars.<\/p>\n<p>\u201cSince Nov 4, at least 10 victims who had fallen for e-commerce scams have reported unauthorised transactions totaling more than $100,000 on their credit cards for purchases such as electronic products, like iPhones and chargers, and jewelry in Singapore,\u201d <em>The Straits Times<\/em> wrote, noting that in another case with a similar modus operandi, the police arrested a Malaysian man and woman on Nov 8.<\/p>\n<div id=\"attachment_70459\" style=\"width: 863px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-70459\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-70459\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/thestraitstimes.png?resize=853%2C567&#038;ssl=1\" alt=\"\" width=\"853\" height=\"567\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/thestraitstimes.png 853w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/thestraitstimes-768x510.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/thestraitstimes-782x520.png 782w\" sizes=\"(max-width: 853px) 100vw, 853px\"><\/p>\n<p id=\"caption-attachment-70459\" class=\"wp-caption-text\">Three individuals charged with using ghost tap software at an electronics store in Singapore. Image: The Straits Times.<\/p>\n<\/div>\n<h2>ADVANCED PHISHING TECHNIQUES<\/h2>\n<p>According to Merrill, the phishing pages that spoof the USPS and various toll road operators are powered by several innovations designed to maximize the extraction of victim data.<\/p>\n<p>For example, a would-be smishing victim might enter their personal and financial information, but then decide the whole thing is scam before actually submitting the data. In this case, anything typed into the data fields of the phishing page will be captured in real time, regardless of whether the visitor actually clicks the \u201csubmit\u201d button.<\/p>\n<p>Merrill said people who submit payment card data to these phishing sites often are then told their card can\u2019t be processed, and urged to use a different card. This technique, he said, sometimes allows the phishers to steal more than one mobile wallet per victim.<\/p>\n<p>Many phishing websites expose victim data by storing the stolen information directly on the phishing domain. But Merrill said these Chinese phishing kits will forward all victim data to a back-end database operated by the phishing kit vendors. That way, even when the smishing sites get taken down for fraud, the stolen data is still safe and secure.<\/p>\n<p>Another important innovation is the use of mass-created Apple and Google user accounts through which these phishers send their spam messages. One of the Chinese phishing groups posted images on their Telegram sales channels showing how these robot Apple and Google accounts are loaded onto Apple and Google phones, and arranged snugly next to each other in an expansive, multi-tiered rack that sits directly in front of the phishing service operator.<\/p>\n<div id=\"attachment_70435\" style=\"width: 528px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-70435\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-70435\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/phonesashtray.png?resize=518%2C688&#038;ssl=1\" alt=\"\" width=\"518\" height=\"688\"><\/p>\n<p id=\"caption-attachment-70435\" class=\"wp-caption-text\">The ashtray says: You\u2019ve been phishing all night.<\/p>\n<\/div>\n<p>In other words, the smishing websites are powered by real human operators as long as new messages are being sent. Merrill said the criminals appear to send only a few dozen messages at a time, likely because completing the scam takes manual work by the human operators in China. After all, most one-time codes used for mobile wallet provisioning are generally only good for a few minutes before they expire.<\/p>\n<p>Notably, none of the phishing sites spoofing the toll operators or postal services will load in a regular Web browser; they will only render if they detect that a visitor is coming from a mobile device.<\/p>\n<p>\u201cOne of the reasons they want you to be on a mobile device is they want you to be on the same device that is going to receive the one-time code,\u201d Merrill said. \u201cThey also want to minimize the chances you will leave. And if they want to get that mobile tokenization and grab your one-time code, they need a live operator.\u201d<\/p>\n<p>Merrill found the Chinese phishing kits feature another innovation that makes it simple for customers to turn stolen card details into a mobile wallet: They programmatically take the card data supplied by the phishing victim and convert it into a digital image of a real payment card that matches that victim\u2019s financial institution. That way, attempting to enroll a stolen card into Apple Pay, for example, becomes as easy as scanning the fabricated card image with an iPhone.<\/p>\n<div id=\"attachment_70439\" style=\"width: 407px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-70439\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-70439\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/02\/phish-cabelas.png?resize=397%2C488&#038;ssl=1\" alt=\"\" width=\"397\" height=\"488\"><\/p>\n<p id=\"caption-attachment-70439\" class=\"wp-caption-text\">An ad from a Chinese SMS phishing group\u2019s Telegram channel showing how the service converts stolen card data into an image of the stolen card.<\/p>\n<\/div>\n<p>\u201cThe phone isn\u2019t smart enough to know whether it\u2019s a real card or just an image,\u201d Merrill said. \u201cSo it scans the card into Apple Pay, which says okay we need to verify that you\u2019re the owner of the card by sending a one-time code.\u201d<\/p>\n<h2>PROFITS<\/h2>\n<p>How profitable are these mobile phishing kits? The best guess so far comes from data gathered by other security researchers who\u2019ve been tracking these advanced Chinese phishing vendors.<\/p>\n<p>In August 2023, the security firm Resecurity <a href=\"https:\/\/www.resecurity.com\/blog\/article\/smishing-triad-targeted-usps-and-us-citizens-for-data-theft\" target=\"_blank\" rel=\"noopener\">discovered a vulnerability<\/a> in one popular Chinese phish kit vendor\u2019s platform that exposed the personal and financial data of phishing victims. Resecurity dubbed the group the <strong>Smishing Triad<\/strong>, and found the gang had harvested 108,044 payment cards across 31 phishing domains (3,485 cards per domain).<\/p>\n<p>In August 2024, security researcher <strong>Grant Smith<\/strong> gave <a href=\"https:\/\/www.youtube.com\/watch?v=gLOv67LlIQs&amp;list=PL9fPq3eQfaaB2scbXRczwvjVH0ckX4bwt&amp;index=14\" target=\"_blank\" rel=\"noopener\">a presentation<\/a> at the DEFCON security conference about tracking down the Smishing Triad after scammers spoofing the U.S. Postal Service <a href=\"https:\/\/www.wired.com\/story\/usps-scam-text-smishing-triad\/\" target=\"_blank\" rel=\"noopener\">duped his wife<\/a>. By identifying a different vulnerability in the gang\u2019s phishing kit, Smith said he was able to see that people entered 438,669 unique credit cards in 1,133 phishing domains (387 cards per domain).<\/p>\n<p>Based on his research, Merrill said it\u2019s reasonable to expect between $100 and $500 in losses on each card that is turned into a mobile wallet. Merrill said they observed nearly 33,000 unique domains tied to these Chinese smishing groups during the year between the publication of Resecurity\u2019s research and Smith\u2019s DEFCON talk.<\/p>\n<p>Using a median number of 1,935 cards per domain and a conservative loss of $250 per card, that comes out to about $15 billion in fraudulent charges over a year.<\/p>\n<p>Merrill was reluctant to say whether he\u2019d identified additional security vulnerabilities in any of the phishing kits sold by the Chinese groups, noting that the phishers quickly fixed the vulnerabilities that were detailed publicly by Resecurity and Smith.<\/p>\n<h2>FIGHTING BACK<\/h2>\n<p>Adoption of touchless payments took off in the United States after the Coronavirus pandemic emerged, and many financial institutions in the United States were eager to make it simple for customers to link payment cards to mobile wallets. Thus, the authentication requirement for doing so defaulted to sending the customer a one-time code via SMS.<\/p>\n<p>Experts say the continued reliance on one-time codes for onboarding mobile wallets has fostered this new wave of carding. KrebsOnSecurity interviewed a security executive from a large European financial institution who spoke on condition of anonymity because they were not authorized to speak to the press.<\/p>\n<p>That expert said the lag between the phishing of victim card data and its eventual use for fraud has left many financial institutions struggling to correlate the causes of their losses.<\/p>\n<p>\u201cThat\u2019s part of why the industry as a whole has been caught by surprise,\u201d the expert said. \u201cA lot of people are asking, how this is possible now that we\u2019ve tokenized a plaintext process. We\u2019ve never seen the volume of sending and people responding that we\u2019re seeing with these phishers.\u201d<\/p>\n<p>To improve the security of digital wallet provisioning, some banks in Europe and Asia require customers to log in to the bank\u2019s mobile app before they can link a digital wallet to their device.<\/p>\n<p>Addressing the ghost tap threat may require updates to contactless payment terminals, to better identify NFC transactions that are being relayed from another device. But experts say it\u2019s unrealistic to expect retailers will be eager to replace existing payment terminals before their expected lifespans expire.<\/p>\n<p>And of course Apple and Google have an increased role to play as well, given that their accounts are being created en masse and used to blast out these smishing messages. Both companies could easily tell which of their devices suddenly have 7-10 different mobile wallets added from 7-10 different people around the world. They could also recommend that financial institutions use more secure authentication methods for mobile wallet provisioning.<\/p>\n<p>Neither Apple nor Google responded to requests for comment on this story.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    BrianKrebs<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/krebsonsecurity.com\/2025\/02\/how-phished-data-turns-into-apple-google-wallets\/\">Go to krebsonsecurity<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How Phished Data Turns into Apple &#038; Google Wallets Carding \u2014 the underground business of stealing, selling and swiping stolen payment card data \u2014 has long been the dominion of Russia-based hackers. Happily, the broad deployment of more secure chip-based payment cards in the United States has weakened the carding market. But a flurry of [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[188,794,795,276,571,574,796,163,797,576,55,798,580,799,581,582,207,800,370,801],"tags":[72],"class_list":["post-2070","post","type-post","status-publish","format-standard","hentry","category-a-little-sunshine","category-all-about-skimmers","category-andy-chandler","category-apple","category-csis-security-group","category-ford-merrill","category-ghost-tap","category-google","category-grant-smith","category-imessage","category-krebsonsecurity","category-m3aawg","category-rcs","category-resecurity","category-secalliance","category-smishing","category-the-coming-storm","category-threatfabric","category-web-fraud-2-0","category-znfc","tag-krebsonsecurity"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2070"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2070"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2070\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2070"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}