The Economy for Phish

The Economy for Phish

Update: 2025-08-18
Share

Description

This episode, we’re joined by Ford Merrill, Senior Director of Research and Innovation at SEC Alliance, to discuss the evolution and sophistication of Phishing as a Service (PhaaS).

Merrill shares from his 11 years of experience working on security research in primarily the areas of phishing and DDoS botnets. In the episode, he talks about the shift from Russian to Chinese-speaking operators, who the developers of advanced kits like Darcula and Lighthouse are, and who actually uses them to impersonate brands for financial gain.

Merrill also outlines a complex ecosystem with supporting technologies and roles involving spammers, data brokers, and money launderers. He also shares what thinks needs to be done to respond this problem, and where he sees rays of hope already.

Related resources:

If you haven’t listened to our series on Darcula, a phishing-as-a-service operation targeting victims globally, check out episode 137 and 138 to hear Robby’s interview with mnemonic's security researchers Erlend Leiknes and Harrison Sand about the findings from their technical investigation into the phishing kit platform Magic Cat. And hear how this story progressed as Robby interviews investigative journalist Martin Gundersen from the Norwegian media agency NRK.

Send us a text

Comments 
loading
In Channel
Agentic Browsers

Agentic Browsers

2025-11-2419:04

Dark Web Roast

Dark Web Roast

2025-11-1044:56

The Quiet Conflict

The Quiet Conflict

2025-10-2740:06

Prompt Engineering

Prompt Engineering

2025-10-0626:26

Pig Butchering

Pig Butchering

2025-09-0142:00

The Economy for Phish

The Economy for Phish

2025-08-1850:23

Agentic

Agentic

2025-08-0456:19

Proofing for Quantum

Proofing for Quantum

2025-06-1827:49

Magic Cat (Part 1)

Magic Cat (Part 1)

2025-06-0201:01:54

Magic Cat (Part 2)

Magic Cat (Part 2)

2025-06-0244:49

Negotiation

Negotiation

2025-05-1933:33

Personal Leadership

Personal Leadership

2025-05-0533:23

Exposure Management

Exposure Management

2025-03-1734:42

AV and IoT

AV and IoT

2025-03-0335:36

loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

The Economy for Phish

The Economy for Phish

mnemonic