A 500 Dollar Phishing Panel Built to Relay Card Details and One Time Codes
A seller posting as PAL1T is advertising a live phishing panel at 500 dollars, presented as version 1.0 and aimed at capturing card data together with one time passcodes. The design is built around working a victim in real time: entries appear in the panel and in a messaging bot at once, each carries an online presence check and a countdown showing how recently the code was refreshed, and the operator can push the victim onward to the genuine site or mark the attempt as declined or successful. It also offers up to five read only guest accounts with instant revocation, bulk export, and paid customisation. Domain and hosting are not included. Capabilities are as advertised and unverified.
▣Listing details
!What the listing claims
- Live view of victim sessions
- Card data capture
- One time code capture
- Entries mirrored to a messaging bot
- Two way sync between bot and panel
- Code freshness countdown
- Online presence check per entry
- Redirect to the genuine site
- Manual or automatic outcome status
- Declined and successful states
- Counters for waiting and active victims
- Quick copy of individual fields
- Bulk export of captured rows
- Database deletion control
- Up to five guest accounts
- Guest access is view only
- Instant revocation of guest access
- Optional sound alerts
◱Screenshots
☷Mapped techniques
Mapped from the seller's own description. Advertised, not confirmed.
- Initial access T1566 Phishing Stated The product is a hosted phishing front end, sold without the domain or server the buyer must supply.
- Credential access T1557 Adversary in the middle Stated The operator watches the session live and can hand the victim back to the genuine site once the data is captured.
- Credential access T1111 Multi factor authentication interception Stated Codes are surfaced with a countdown showing how recently each was received, which only matters if they are being used before expiry.
- Collection T1056.003 Web portal capture Stated Submitted card and authentication fields are stored, exportable in bulk and individually copyable.
⚠Potential impact
The countdown timer is the tell. A panel that tracks how fresh each code is exists to use those codes inside their validity window, which is what defeats card authentication and SMS based verification. At 500 dollars, with guest accounts and outcome tracking, this is tooling for a small team working victims in shifts rather than a single operator. The defensive conclusion is the familiar one: anything delivered as a code to a phone can be relayed in real time, and only phishing resistant authentication removes the attack.
iStatus Unverified
Everything here is a sales claim, with no live instance, screenshots of the panel or artefacts published, so there is nothing defenders can turn into a detection signature. The seller account has a light history and little standing. Dark Web Informer has not obtained the panel and is not linking the seller's contact channel.
Dark Web Informer // Threat Intelligence