Khrislewis
Carding Novice
- Joined
- 30.03.23
- Messages
- 16
- Reaction score
- 2
- Points
- 3
Any one with success? I’m learning don’t be afraid to dm feds beware
Would you like to go info 4 info w me broThis and the cc sniffer are godlike tier info. I knew something about scamshops, but this really open my eyes.
Still have the sniffer idea on mind, waiting for the opportunity.
ty
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
Now we're going to up the ante with scamshops.
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps – they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
If you have, you're halfway there. If not, get over there and read it.
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverInstall Apache, MySQL, and PHP (LAMP stack)Download and unzip WordPressCreate a MySQL database for WordPressConfigure wp-config.phpRun the WordPress installationInstall and activate WooCommerce plugin
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
Don't worry about how much the shit cost – you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Ads
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
Now it's time to polish your digital turd. Write engaging product descriptions – use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable – 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
thank you
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
Now we're going to up the ante with scamshops.
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps – they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
If you have, you're halfway there. If not, get over there and read it.
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverInstall Apache, MySQL, and PHP (LAMP stack)Download and unzip WordPressCreate a MySQL database for WordPressConfigure wp-config.phpRun the WordPress installationInstall and activate WooCommerce plugin
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
Don't worry about how much the shit cost – you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Ads
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
Now it's time to polish your digital turd. Write engaging product descriptions – use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable – 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
the links for the plugin are dead. Can you update with a new one, please?
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
Now we're going to up the ante with scamshops.
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps – they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
If you have, you're halfway there. If not, get over there and read it.
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverInstall Apache, MySQL, and PHP (LAMP stack)Download and unzip WordPressCreate a MySQL database for WordPressConfigure wp-config.phpRun the WordPress installationInstall and activate WooCommerce plugin
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
Don't worry about how much the shit cost – you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Ads
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
Now it's time to polish your digital turd. Write engaging product descriptions – use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable – 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
thanks
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
Now we're going to up the ante with scamshops.
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps – they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
If you have, you're halfway there. If not, get over there and read it.
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverInstall Apache, MySQL, and PHP (LAMP stack)Download and unzip WordPressCreate a MySQL database for WordPressConfigure wp-config.phpRun the WordPress installationInstall and activate WooCommerce plugin
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
Don't worry about how much the shit cost – you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Ads
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
Now it's time to polish your digital turd. Write engaging product descriptions – use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable – 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
Este punto final es donde publicaremos los datos de nuestra tarjeta. Webhook.Site ofrece un panel que enumera todos los datos publicados en este punto final. Recuerde que este es solo un ejemplo, ya que será nuestro panel por el momento.
Reemplace la URL en el archivo class-bravo-sender.php con su nuevo punto de conexión. Coloque ese complemento en WordPress, actívelo y configúrelo como su procesador de pagos en WooCommerce.
Continúe y haga la prueba. Compre un artículo y realice el pago. Si hizo todo correctamente, debería ver los detalles de la tarjeta en el panel de su sitio Webhook.
Perfeccionamiento
Ahora nuestro complemento para capturar tarjetas hará el trabajo pesado, pero debemos asegurarnos de que la gente realmente llegue a ese punto.
En primer lugar, el pago en una sola página es tu nuevo mejor amigo. Ya es compatible con CheckoutWC. Cuantos menos clics haya entre "Comprar ahora" y "Gracias por los datos de tu tarjetade pedido", mejor.
Recuerda, estamos en 2024, no en 1999. Es mejor que tu proceso de pago funcione sin problemas en el móvil o perderás dinero. Prueba esa mierda en todos los dispositivos que tengas a mano.
Aquí tienes un truco: ofrece varias opciones de pago: PayPal, Apple Pay, lo que sea más popular. Por supuesto, no funcionarán, pero harán que tu sitio parezca legítimo. Además, te darán más oportunidades de tener problemas técnicos "accidentalmente" que obliguen a las personas a usar tu opción para robar tarjetas.
Por último, las ventanas emergentes de intención de salida. Sí, son muy molestas, pero funcionan. Cuando alguien esté a punto de abandonar tu proceso de compra, ofrécele un descuento de último momento o alguna tontería urgente. Los complementos como los que he enumerado ya son compatibles con esto. Te sorprendería saber cuántas personas puedes atrapar con esta red.
Todo ayuda. Luce legítimo, consigue más tarjetas. ¡Vamos!
Conclusión
View attachment 44756
¡Bien hecho! Ya tienes tu primera tienda fraudulenta en funcionamiento. Tienes una tienda que parece de marca, un producto que se propagará como una enfermedad y un proceso de pago que estafará a las masas incautas.
Pero no empieces a contar tu dinero todavía. Este es solo el comienzo de tu viaje hacia el engaño digital. En la segunda parte, profundizaremos en las técnicas para obtener más tarjetas y hablaremos sobre cómo promocionar tu tienda de estafas sin llamar la atención de los chicos de azul.
Recuerda, un gran poder conlleva una gran responsabilidad... no te dejes atrapar. Mantente frío y en el anonimato.
¡Hasta la próxima, feliz phishing! d0ctrine fuera.
Hey @d0ctrine , I'm new to this and everything I've learned here so far has been so informative that I cannot thank you enough.
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
Now we're going to up the ante with scamshops.
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps – they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
If you have, you're halfway there. If not, get over there and read it.
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverInstall Apache, MySQL, and PHP (LAMP stack)Download and unzip WordPressCreate a MySQL database for WordPressConfigure wp-config.phpRun the WordPress installationInstall and activate WooCommerce plugin
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
Don't worry about how much the shit cost – you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Ads
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
Now it's time to polish your digital turd. Write engaging product descriptions – use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable – 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
real good sauce
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
Now we're going to up the ante with scamshops.
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps – they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
If you have, you're halfway there. If not, get over there and read it.
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverInstall Apache, MySQL, and PHP (LAMP stack)Download and unzip WordPressCreate a MySQL database for WordPressConfigure wp-config.phpRun the WordPress installationInstall and activate WooCommerce plugin
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
Don't worry about how much the shit cost – you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Ads
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
Now it's time to polish your digital turd. Write engaging product descriptions – use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable – 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
thx broozy
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
Now we're going to up the ante with scamshops.
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps – they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
If you have, you're halfway there. If not, get over there and read it.
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverInstall Apache, MySQL, and PHP (LAMP stack)Download and unzip WordPressCreate a MySQL database for WordPressConfigure wp-config.phpRun the WordPress installationInstall and activate WooCommerce plugin
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
Don't worry about how much the shit cost – you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Ads
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
Now it's time to polish your digital turd. Write engaging product descriptions – use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable – 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
Thanks for the informations shared sir
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
Now we're going to up the ante with scamshops.
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps – they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
If you have, you're halfway there. If not, get over there and read it.
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverInstall Apache, MySQL, and PHP (LAMP stack)Download and unzip WordPressCreate a MySQL database for WordPressConfigure wp-config.phpRun the WordPress installationInstall and activate WooCommerce plugin
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
Don't worry about how much the shit cost – you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Ads
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
Now it's time to polish your digital turd. Write engaging product descriptions – use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable – 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.