> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# A 500 Dollar Phishing Panel Built to Relay Card Details and One Time Codes
- URL: https://darkwebinformer.com/a-500-dollar-phishing-panel-built-to-relay-card-details-and-one-time-codes/
- Published: 2026-08-28T16:50:25.000Z
- Updated: 2026-08-28T16:50:25.000Z
- Author: Dark Web Informer
- Tags: Cybercrime

Tooling Listing Phishing Panel Card and OTP 500 USD 

## A 500 Dollar Phishing Panel Built to Relay Card Details and One Time Codes

A seller posting as **PAL1T** is advertising a **live phishing panel** at **500 dollars**, presented as version 1.0 and aimed at capturing **card data together with one time passcodes**. The design is built around working a victim in real time: entries appear in the panel and in a messaging bot at once, each carries an **online presence check and a countdown showing how recently the code was refreshed**, and the operator can push the victim onward to the genuine site or mark the attempt as declined or successful. It also offers **up to five read only guest accounts** with instant revocation, bulk export, and paid customisation. Domain and hosting are **not included**. Capabilities are **as advertised and unverified**.

Severity HIGH 

[ ![WhiteIntel, dark web exposure monitoring](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/whiteintel_io_banner.jpg) ](https://whiteintel.io/?utm%5Fsource=darkwebinformer.com&utm%5Fmedium=referral&utm%5Fcampaign=whiteintel) 

Price$500

Version1.0

TargetsCard and OTP

SellerPAL1T

### ▣Listing details

ProductLive phishing panel

TypeReal time credential relay

CountryNot stated

Price500 USD

ExcludedDomain and server

Version1.0, updates included

ObservedAug 27, 2026

SellerPAL1T

### !What the listing claims

- Live view of victim sessions
- Card data capture
- One time code capture
- Entries mirrored to a messaging bot
- Two way sync between bot and panel
- Code freshness countdown
- Online presence check per entry
- Redirect to the genuine site
- Manual or automatic outcome status
- Declined and successful states
- Counters for waiting and active victims
- Quick copy of individual fields
- Bulk export of captured rows
- Database deletion control
- Up to five guest accounts
- Guest access is view only
- Instant revocation of guest access
- Optional sound alerts

### ◱Screenshots

[ ![Forum listing advertising a live phishing panel for card and one time code capture, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/238095237657286935987623598762359786987.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/238095237657286935987623598762359786987.png) [ ![Second section of the same listing covering guest accounts, controls and price, August 2026](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/238095237657286935987623598762359786988.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/08/238095237657286935987623598762359786988.png) 

Forum listing advertising a live phishing panel, observed 27 August 2026.

### ☷Mapped techniques

Mapped from the seller's own description. Advertised, not confirmed.

- Initial access [T1566](https://attack.mitre.org/techniques/T1566/) Phishing Stated The product is a hosted phishing front end, sold without the domain or server the buyer must supply.
- Credential access [T1557](https://attack.mitre.org/techniques/T1557/) Adversary in the middle Stated The operator watches the session live and can hand the victim back to the genuine site once the data is captured.
- Credential access [T1111](https://attack.mitre.org/techniques/T1111/) Multi factor authentication interception Stated Codes are surfaced with a countdown showing how recently each was received, which only matters if they are being used before expiry.
- Collection [T1056.003](https://attack.mitre.org/techniques/T1056/003/) Web portal capture Stated Submitted card and authentication fields are stored, exportable in bulk and individually copyable.

### ⚠Potential impact

The countdown timer is the tell. A panel that tracks **how fresh each code is** exists to use those codes inside their validity window, which is what defeats card authentication and SMS based verification. At **500 dollars, with guest accounts and outcome tracking**, this is tooling for a small team working victims in shifts rather than a single operator. The defensive conclusion is the familiar one: **anything delivered as a code to a phone can be relayed in real time**, and only phishing resistant authentication removes the attack.

### iStatus Unverified

Everything here is a sales claim, with **no live instance, screenshots of the panel or artefacts published**, so there is nothing defenders can turn into a detection signature. The seller account has **a light history and little standing**. Dark Web Informer has **not obtained the panel and is not linking the seller's contact channel**.

Want everything on this listing? **Paid subscribers** get the full unredacted claim details and more. After subscribing, check out the [threat feed](https://darkwebinformer.com/threat-feed/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=live-panel-cc-otp-2026-08-27&utm%5Fcontent=threat-feed) and search there for this alert.

[View pricing →](https://darkwebinformer.com/pricing?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=live-panel-cc-otp-2026-08-27&utm%5Fcontent=pricing-button) 

[Dark Web Informer](https://darkwebinformer.com/?utm%5Fsource=alert&utm%5Fmedium=card&utm%5Fcampaign=live-panel-cc-otp-2026-08-27&utm%5Fcontent=footer) // Threat Intelligence