OTP bot
An automated calling service that impersonates a bank or provider to trick victims into reading out their one-time codes. MFA bypass, sold as a subscription.
Why it matters to you
"We have MFA" is a mitigation rather than an immunity. Codes that humans can read out, humans can be talked out of, so prefer phishing-resistant factors for crown jewels.
Where we meet it
OTP bots are sold with scripts per bank, in the local language and accent. A new script for your institution appearing in a channel is a campaign in its setup phase.
Connected terms
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.
Fullz
A complete identity kit for one person (name, national ID, date of birth, address, banking details) packaged for fraud. Sold per record, priced by country and completeness.
Drop
A money or goods mule: the recruited (sometimes unwitting) person whose bank account or address launders the proceeds. Recruited openly, in "work" channels, at scale.
SIM swap
Moving a victim's phone number onto an attacker's SIM, usually by persuading or paying someone at the carrier. Every code sent to that number now arrives at the attacker instead.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.