Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

16Shop adds phishing kit to target cash app users

phishing freepik
March 4, 2021

The developer of the 16Shop phishing platform added a new component that targets users of popular Cash App mobile payment service, according to reports. 

16Shop is a phishing kit from a developer known as DevilScream, says BleepingComputer, and is available and localized in multiple languages. The new component lures potential victims, asking them to provide sensitive details that would allow fraudsters to access their accounts and payment information. 

ZeroFOX says the group is known for targeting high profile brands and has been active for nearly three years. The phishing kit being sold through 16Shop’s storefront was obtained by ZeroFOX on the 25th February, 2021 a day after the kit’s final compile time. Since adding detections for this variant of 16Shop, ZeroFOX has discovered multiple deployments of this kit within less than a day of its initial launch, indicating that the 16Shop customer base is active and eager to deploy this kit.

Justin Albrecht, Security Intelligence Engineer at Lookout, a San Francisco, Calif.-based provider of mobile security solutions, explains, “16Shop is a cautionary tale that reflects growing trends we’re seeing with other types of threats such as Banking Trojans, Spyware, and even private surveillance companies. The barrier to entry for cybercriminals is getting lower, which means we see more of them every day. These actors are adopting the SaaS model broadly, the prices are usually cheap, and the profits far outweigh the costs. In this case the increased adoption of a relatively new technology, mobile payments, creates an even greater threat as users are prone to falling for phishing links and social engineering.

"The continued success of the 16Shop kit and its expanded targeting provide the perfect example of growing trends across both the threat landscape and consumer behavior. The popularity of mobile payment applications such as Cash App is booming, which presents a tempting target to threat actors as mobile users are far more likely to fall victim to phishing attacks than desktop users." 

Albrecht says DevilScream has adopted a SaaS business model for providing phishing services. "This represents the growing trend of Malware-as-a-Service making it easier for non-technical criminals to become involved in cybercrime. Threat actors ranging from low-level criminals to nation states are taking advantage of malware developers shifting to a SaaS model. It’s being widely adopted because it provides both anonymity as well as reduced overhead for creating a campaign. 

Albreacht adds, "The malicious actors behind these phishing campaigns flip anti-bot and anti-crawler tools and techniques that were originally meant to prevent criminal behavior and use them to avoid detection. Some of these tools and techniques include:

  • CrawlerDetect (used by 16shop)
  • Antibot.pw checks (used by 16shop) 
  • BlackHole (open source bot trap)
  • VPN range filtering
  • User Agent filtering

"Another example of this, though not for 16Shop, is threat actors beefing up the SEO of compromised websites before staging malware to be delivered. Malicious SEO has been around for a while, but this represents another example of the flip of mainstream business or marketing practices to have increased success in criminal campaigns.”

 

KEYWORDS: cyber security phishing risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Person in red hoodie

When Metal Theft Becomes a Life Safety Crisis

Stacked books

Safe Learning 101 Program Supports Schools in Strengthening Campus Security

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

Nurse

Why De-Escalation Must Be Part of a Layered Safety Strategy in Healthcare

Two women consulting with a group in background

5 Skills That Will Serve You in Your Security Career

SEC 2026 Benchmark Banner

Events

May 21, 2026

From Referral to Response: Managing Domestic Violence Threats in the Workplace

Domestic violence remains a complex driver of workplace violence, creating high-risk scenarios that require coordination across departments without clear ownership. Learn how threat management teams can manage domestic violence referrals from the start.

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
Solutions by Sector webinar promo


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • databases-freepik1170.jpg

    Block confirms Cash app breach affecting 8m users

    See More
  • qr code

    QR code phishing scams target users and enterprise organizations

    See More
  • malware-cyber-crime-freepik.jpg

    New malware uses COVID-19 lure to target Android users

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing