LIVE · cybersecurity feed
Live wire
phishing

Ready-made $500 kit puts a crypto scam within anyone’s reach

A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and inflates fake balances to squeeze out more money, Malwarebytes found. Researchers discovered the scam project on May 16 and described it as an example of how social engineering, phishing, and financial fraud can be combined into a s

zeroday.news ·

A cybercrime forum vendor is offering a comprehensive scam kit for $500, enabling individuals with minimal technical skills to execute sophisticated cryptocurrency fraud. The kit, discovered by Malwarebytes researchers on May 16, provides a complete "scam-in-a-box" solution, integrating social engineering, phishing, and financial fraud into a single, ready-to-use package.

The vendor, operating under the alias "xrep" since March 2026, has established a positive reputation on the forum for delivering packaged tools. This particular kit includes all necessary technical infrastructure, phishing functionalities, a fake investment dashboard, victim tracking, and administrative controls.

The scam leverages a fabricated presale page for a cryptocurrency token named "$TSLA," designed to mimic an offering from Tesla. The page is multilingual and optimized for both desktop and mobile devices. It initiates with a fake eligibility check, requesting the visitor's X (formerly Twitter) username and then pulling their profile picture to personalize the scam.

The site employs various psychological manipulation tactics, including a self-advancing progress bar, a countdown timer, and urgent warnings about impending price increases, all designed to pressure victims into making hasty decisions. Once a victim believes the offer is legitimate, the site presents two methods for them to lose their funds. One method prompts users to connect a crypto wallet to claim a bonus, then requests a 12-word recovery phrase, which grants the scammer full control over the wallet. The alternative method bypasses wallet connection and directly requests transfers in Bitcoin, Ethereum, USDT, or Dogecoin to an address controlled by the scammer.

Malwarebytes researchers noted that victims are led to believe they are making a legitimate investment, but no actual tokens are purchased. Instead, the scammer receives the cryptocurrency, and the victim sees a fabricated balance displayed on the website.

A key feature of the kit is its sophisticated admin panel, which provides the scammer with extensive control over the operation. This panel allows the operator to monitor victims' navigation through the site, retrieve their X usernames, locations, and any entered recovery phrases. It also enables the scammer to assess the value of a stolen wallet before deciding whether to drain it further.

The fake balance displayed to victims is not static; the operator can inflate it at will, creating the illusion of a profitable investment and encouraging victims to send more funds. The admin panel further facilitates the management of fake purchase orders and direct communication with victims. Scammers can follow up with victims who have already sent money, claiming delays and demanding additional "network fees" to release funds, effectively attempting a second extraction from the same wallet.

Malwarebytes concluded that the availability of such a comprehensive kit significantly lowers the barrier to entry for cybercriminals. Individuals lacking the expertise to build phishing websites, develop administration systems, or create convincing investment interfaces can now purchase this kit and target victims with minimal effort.

phishingmalwarefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura

nation-state

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The a

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!

breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]