Listen "The Economy for Phish"
Episode Synopsis
This episode, we’re joined by Ford Merrill, Senior Director of Research and Innovation at SEC Alliance, to discuss the evolution and sophistication of Phishing as a Service (PhaaS).Merrill shares from his 11 years of experience working on security research in primarily the areas of phishing and DDoS botnets. In the episode, he talks about the shift from Russian to Chinese-speaking operators, who the developers of advanced kits like Darcula and Lighthouse are, and who actually uses them to impersonate brands for financial gain.Merrill also outlines a complex ecosystem with supporting technologies and roles involving spammers, data brokers, and money launderers. He also shares what thinks needs to be done to respond this problem, and where he sees rays of hope already.Related resources:If you haven’t listened to our series on Darcula, a phishing-as-a-service operation targeting victims globally, check out episode 137 and 138 to hear Robby’s interview with mnemonic's security researchers Erlend Leiknes and Harrison Sand about the findings from their technical investigation into the phishing kit platform Magic Cat. And hear how this story progressed as Robby interviews investigative journalist Martin Gundersen from the Norwegian media agency NRK.Send us a text
More episodes of the podcast mnemonic security podcast
LLMalware
05/01/2026
Present and Future of MDR
01/12/2025
Agentic Browsers
24/11/2025
Dark Web Roast
10/11/2025
The Quiet Conflict
27/10/2025
Prompt Engineering
06/10/2025
State of the Union: Agentic AI
28/09/2025
Autonomous cyberattacks
15/09/2025
Pig Butchering
01/09/2025
Agentic
03/08/2025
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.