ZPhisher — Advanced Lazy Automated Phishing Script

ZPhisher — Advanced Lazy Automated Phishing Script

ZPhisher is an advanced phishing tool-kit it is an upgraded version of Shellphish. It have the main source code from Shellphish but ZPhisher have some upgrade and have removed some unnecessary codes from Shellphish. It is devloped by HTR-Tech . ZPhisher can be run from Kali Linux and also can be run from Android devices using Termux. It is the all-in-one phishing framework in 2020.

ZPhisher -- Advanced Lazy Automated Phishing Script Kali Linux

ZPhisher have lots of phishing pages like:

1) Facebook

  • Facebook Normal Login Page
  • Fake Security Login Method (DarkSecDevelopers)
  • Facebook Voting Poll Method (DarkSecDevelopers)
  • Messenger Login Page (New)

2) Instagram

  • Normal Login Page
  • Instagram Auto Follower Phishing Page (thelinuxchoice)
  • Instagram Badge Verify Method (DarkSecDevelopers)

3) Google

  • Google Old Login Page
  • Google New Login Page
  • Google Voting Poll Method (DarkSecDevelopers)

4) Adobe Login Page

5) Badoo Login Page

6) CryptoCoinSniper Login Page

7) Deviantart Login Page

8) Dropbox Login Page

9) Ebay Login Page

10) Github Login Page

11) Linkedin Login Page

12) Microsoft Login Page

13) Netflix Login Page

14) Origin Login Page

15) Paypal Login Page

16) Pinterest Login Page

17) Playstation Login Page

18) Protonmail Login Page

19) Reddit Login Page

20) Snapchat Login Page

21) Spotify Login Page

22) Stackoverflow Login Page

23) Steam Login Page

24) Twitch Login Page

25) Twitter Login Page

26) Vk Login Page

27) Vk Poll Method (Hiddeneye)

28) WordPress Login Page

29) Yahoo Login Page

30) Yandex Login Page

 Zphisher also have 4 port forwarding options

  • localhost         (For local network/LAN)
  • Ngrok             (For World-Wide WAN)
  • Serveo.Net      (For WAN)
  • Localhost.run  (For WAN)

Installing on Kali Linux

First we need to clone ZPhisher from it’s GitHub repository by using following command:

git clone https://github.com/htr-tech/zphisher

The screenshot of the preceding command if following:

clonning zphisher

Then we need to go inside the zphisher directory using cd command:

cd zphisher

Here we need to give executable permission to the bash script by using following command:

sudo chmod +x zphisher.sh

The screenshot is following.

zphisher permissions

Now we are ready to run it. We can run it by using following command:

./zphisher.sh

Then this bash script lead us to the main menu of the ZPhisher tool as shown in following screenshot:

zphisher main page

Here everything is very clear. For an example we choose 1 for Facebook and press enter.

facebook in this tool

Here we can choose whatever we think easy to trick our victim. For an example we choose 3 for a “Fake Security Login Page”.

fake security login page

Now we can choose our port forwarding option. Here If we choose 1 then it will be for our local network (same WiFi or LAN) only, but we can choose the other options like ngrok serveo or localhost.run. (These are all free port forwarding services so sometimes some services may be down for overloading. In that case we need to choose other.)

Here  we choose 2 for ngrok.io. Then we wait for some seconds untill our link generated.

In the above screenshot we can see our link created on ngrok. Now we can send this link to our victim by SMS or mail or by any other way With some catchy social engineering technique.

If our victim opens it then he/she will see something like following screenshots:

phishing 2020
On Desktop
phishing mobile 2020
On Mobile Device

If our victim inputs the username and password then,

we got the password
BINGO!

 We got the credentials of our victim. Now it can be used to login victim’s Facebook account.

Installing on Android (Termux)

We also can use it on Android through Termux application. First we need to install Termux from Google Play Store. Then we can open it and run a single command to update download and run the ZPhisher. The single command is following:

apt update && apt install git php curl openssh -y && git clone https://github.com/htr-tech/zphisher && cd zphisher && chmod +x zphisher.sh && bash zphisher.sh

How to be safe from this Attack

  • We should not click on any link through sms/email/website/chatroom or text messages etc.
  • we need to check the link is driving to original Facebook, mean to say check the links is https://www.facebook.com/ or not. If not and the page is looking like Facebook, then this might be a phishing page.
  • Windows user should use anti-virus and web-security software , like
    norton or McAfee . Linux user should take care before clicking unknown
    links.

This this tutorial is for educational
purpose only. Phishing is a crime. If anyone do any
illegal activity then we are not responsible for that.

If you like our tutorial or got an issue regarding this post please
comment down, we always be happy to respond. If you liked our tutorials then
visit our website regularly and for the quick updates follow us on Twitter and Medium.

KP AKA Koushik Pal is a Security researcher and specialist focused on educating about Linux for cybersecurity and URL‑masking vulnerabilities. Creator of MaskPhish, a well‑known open‑source bash-based URL‑masking tool. Linux enthusiasts Active speaker, trainer, and advocate for secure web practices.

71 comments

comments user
Unknown

Why is my Kali Linux looking different? I enter the first line of code and it says it's not a command. I'm on windows 10, please help.

comments user
Kali Linux

you should install your Kali in proper way.. Uninstall it and read our installation guide.

A total Guide to install Kali Linux

comments user
Anonymous

Hi, generated links by zphisher is working of course, but… It's working only for me. Even if i try connect to generated link on another ip it is not working, can't connect. For what i need phishing if it is working only for me? 😀

comments user
Anonymous

Oh i forget to tell that im using a "ngrok.io" in zphisher

comments user
Kali Linux

You should try other methods also, like serveo.net or localhost.run

comments user
shanewarner

The post is written in very a good manner and it contains many useful information for me.

gexton security app

comments user
Programming kits

Please, I'm done with the command, everything is done but it's not showing any url

comments user
Kali Linux

you should try it on localhost. If the localhost is working on your own network then it is because of port forwarding services. The services are free so the servers goes down sometimes.. Wait for some hours and try again. nogrok is good you should try ngrok.

comments user
Pankaj Rawat

How to uninstall zphisher in termux

comments user
^Blank^

It is giving an error respiratory not found

comments user
Kali Linux

We think you have typing mistakes please check the command and try again.

comments user
Anonymous

I am using ngrok port but it is taking too much time to intialize and not giving me the link and others port is also not working

comments user
Kali Linux

These ngrok and other services are free to use so they are over-loaded many times. Try after some times or buy a paid service from ngrok. We usually use portmap for our own uses.

comments user
Unknown

it says that i dont have the php installed how can i fix that i am new to this

comments user
Unknown

I fixed that problem and the only problem i have now is that the link is not appearing

comments user
Kali Linux

Which port forwarding services you have tried? Serveo ? Serveo may be down you can try others? Or you can host them on localhost and run port forwarding services manually.

comments user
Anonymous

i downloaded kalilinux from microsoft store i tried ngork local host and servo.net but link remains blank sometimes it shows cannot read realtime clock invalid argument can u find a fix for this

comments user
Kali Linux

Yes it happens. The problem comes from Microsoft. You installation uses WSL (Windows Subsystem for Linux)method. Check the solution here.

comments user
Anonymous

i install te program but send a error

[~] Initializing…(localhost:5555)
[!] Error [!] Please Install All Packges.

the only error when i try to install is with the OPENSSH

comments user
Kali Linux

reinstall the tool & try again

comments user
Unknown

yes error h

comments user
Unknown

Is root necessary for android users?

comments user
Unknown

Ian vinay

comments user
Anonymous

I'm on 2020.3 with zsh, it seems i'm stuck on initializing

comments user
Anonymous

Edit: fixed

comments user
Kali Linux

Nice to hear that you solved this by own.

comments user
PHYTON BEGNER

and where the victim's password and name go

comments user
Kali Linux

It shown in the article, please read the article carefully.

comments user
Anonymous

How do I re-run zphisher, after sending link and it's opened, it doesn't show login details,

comments user
Unknown

How long does the link take to expire, or it doesn't and can be opened after days. If termux is closed, how do I retrieve the password if it was entered

comments user
Kali Linux

did target logged in?

comments user
Kali Linux

The time depends on the tunnel connection. Saying it very tough how much time connection will stay. Usually we have checked the connection stays for some hours didn't tried for a day. If you trying for it, then please give us your valuable feedback.
And if termux closed then you will not get the password. You can minimize it.
Thanks.

comments user
Erwin Rommel

For most of the phishing links I see three options –
1. serveo.net
2. ngrok.io
3. localhost.run

which among this is the best and reliable ?

Also what is the difference between them and NoIP ?

comments user
Kali Linux

It depends, when serveo is busy we choose localhostrun or ngrok. We suggest to use portmap.io, it is good.

Serveo/ngrok/localhost just creates tunnel to our localhost that we can access our localhost on the internet, with a port forwarded. no-ip is a different thing, no-ip makes dynamic ip to static ip. It can't help us on forwarding port.

comments user
Anonymous

Is there a way customize the url? I've heard that you can customize phishing links, but can't seem to figure it out.

comments user
come hack someone

bro you can use mask phish tool to customize a phishing link

comments user
Lfobia

can u tell me how to change website from Zphishr? if i want binance.com
can i change from sorce code?

comments user
Kali Linux

Yah you can change the source code for personal use. It's an open-source project. But an easy option will be "weeman" ssearch for 'weeman' on our website you will get this Thanks.

comments user
Unknown

After entering the link of git I'm ..it was compressing objects bt after that while I execute cd zphisher .it's not working it remain same.

comments user
Anonymous

For how much time the phishing link is valid? Like zshadow was having a time of 6 hours within this Timeperiod the victim has to login otherwise the link will be invalid.

comments user
Kali Linux

This creates a tunnel for port forwarding jobs. No defined time for this. With a super strong network we can use it for longer without closing the connection.

comments user
Mhfooz

Sir my insta is hacked how to open zphisher

comments user
Kali Linux

Please read the article carefully. It will guide you. You need any help? Will be happy to help you.

comments user
Anonymous

hello im trying ./zphisher and it doenst run lol

comments user
Anonymous

fixed it bash zphisher.sh works

comments user
Kali Linux

Glad that you fixed it by own.

comments user
Unknown

Hi sir I add all the commands after that it ask me for username and password kindly tell me what is the username and password?

comments user
Kali Linux

Thanks for noticing this. This tool got updated. We will update this article, but we need some time. Currently are working on some awesome articles. Please stay tuned. Thanks.

comments user
Unknown

Sir , Link Is Working Fine in My Andriod but when i send to my frnd it is not working . can you suggest me some methods or technique to overcome this ?

comments user
Kali Linux

You are using the ngrok url? The tunnel connection closes randomly. This is for educational things. Not to hack your friend. Please don't do any illegal activity. We don't support it.

comments user
Unknown

hi
i have been trying to use this software it works perfectly on my device but when I try it on another device on another network it says that the website is not found
is there any solution to this plz inform me if there is any solution to this

comments user
Kali Linux

Did you got the ngrok URL? Sometimes Ngrok closes the tunnel, of course free services don't give the stability when they have a premium one.

comments user
Unknown

Is zphisher a malware or virus of some sort? Because i am just testing it out with my own facebook login and stuff. And my dad allowed me to test his too. So i need to know if we will get a virus or malware, or just get hacked. 🙂

comments user
Kali Linux

No. It creates a login page just like Facebook. When you (victim) put your username and password there it will show it to you (attacker). In your case you are the victim as well as attacker.

We like you. Always take permissions before doing penetration testing.

Hope you understand what is zphisher do. For any more help we are always here. Thanks

comments user
TrozZ Sabin

can you help me out in zphisher? when i sent the zphisher made link to victim, the page didnot open. it opened only in the wifi that i am connected in. please help me

comments user
Kali Linux

That because you are hosting that page in our localhost. You need to forward your port on your router settings then your public IP with port will be your URL of the page. You can know more about port forwarding from YouTube. If you don't have an static IP then follow our this ssh article to make that page public.

You need to learn more about networking, to be a good cybersecurity expert. Thanks.

comments user
TrozZ Sabin

how to use portmap.io?

comments user
Kali Linux

We have an detailed article on it. Please read portmap tutorial. Thanks.

comments user
tell me something

I have generated the link but I can't send it in instagram. The instagram block the link if i try sending it to any of my friend who is in insta. How do I solve it.

comments user
Kali Linux

There is some solution.

But we will not help you in your case. You are suppose to do some illegal activity, we don't support it.

comments user
tell me something

I assure you my intentions are pure. There is nothing illegal in this. I am myself a tech guy and I am exploring things in zphisher. It's just for educational purpose.

comments user
Unknown

you can just use bit.ly or smth. Why is it difficult??

comments user
Kali Linux

Nice Idea. Please have a try. Social media sites definitely thinks it before you.

comments user
Kali Linux

Sending links by social media will not work. Think classically.

comments user
Anonymous

How do i run this on an iOS device

comments user
Kali Linux

Is there any Termux alternative on iOS? If you find that please let us know.

comments user
Anonymous

Does this run on Kali or Python?

comments user
Kali Linux

It's not written on Python. It's a BASH script. Will work on Kali. Thanks.

comments user
Anonymous

Link harmful showing how can I bypass

comments user
Anonymous

Dear brother
Plz tell me fb hack good level tools or link Whatsapp

comments user
Anonymous

how to see again all victims again of zphisher?

Post Comment