Strox
offers more than just a phishing kit - it’s a vertical integration of the phishing process and consolidates all the different resources required for someone to begin phishing.
Strox Phishing Service & How It Works
![Strox Phishing Service & How It Works](https://lukeleal.com/research/strox.png)
McDonald’s Phishing Page Used to Steal Saudi Payment Data
![McDonald's Phishing Page Used to Steal Saudi Payment Data](https://lukeleal.com/research/saudi-mcd.png)
A unique phishing kit that targets
McDonald's
customers in Saudi Arabia
and has a convincing mobile/desktop responsiveness.
united81.com skimmer
![united81.com skimmer](https://lukeleal.com/research/united81-skimmer.png)
JavaScript code in the file
/media/js/js-color.min.js
on an infected Magento website loads a skimmer and then exfiltrates the stolen data to the malicious domain united81.com
.
jsdelivr.at skimmer
![jsdelivr.at skimmer](https://lukeleal.com/research/jsdelivr-at-skimmer.jpg)
A JavaScript injection found on a compromised Magento website loads a skimmer from
jsdelivr.at
and then exfiltrates the stolen data back.
cdn-fonts.com skimmer
![cdn-fonts.com skimmer](https://lukeleal.com/research/cdn-fonts-c.png)
A JavaScript injection in the Magento database table core_config_data loads a skimmer and then exfiltrates the stolen data to the malicious domain
cdn-fonts.com
.