williamstrevi
Carding Novice
- Joined
- 09.03.25
- Messages
- 5
- Reaction score
- 0
- Points
- 1
Solid method as usual
very good my brother![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
<3![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
Δiα»m cuα»i nΓ y lΓ nΖ‘i chΓΊng ta sαΊ½ ΔΔng thΓ΄ng tin chi tiαΊΏt vα» thαΊ» cα»§a mΓ¬nh. Webhook.Site cung cαΊ₯p mα»t bαΊ£ng Δiα»u khiα»n liα»t kΓͺ mα»i dα»― liα»u ΔΓ£ ΔΔng lΓͺn Δiα»m cuα»i nΓ y. ΔΓ’y, vΓ hΓ£y nhα» rαΊ±ng ΔΓ’y chα» lΓ mα»₯c ΔΓch demo, sαΊ½ lΓ bαΊ£ng Δiα»u khiα»n cα»§a chΓΊng ta trong thα»i gian nΓ y.
Thay thαΊΏ URL trong tα»p class-bravo-sender.php bαΊ±ng Δiα»m cuα»i mα»i cα»§a bαΊ‘n. ThαΊ£ plugin ΔΓ³ vΓ o WordPress, kΓch hoαΊ‘t vΓ ΔαΊ·t nΓ³ lΓ m bα» xα» lΓ½ thanh toΓ‘n cα»§a bαΊ‘n trong WooCommerce.
HΓ£y tiαΊΏp tα»₯c vΓ thα» nghiα»m. Mua mα»t mαΊ·t hΓ ng vΓ thanh toΓ‘n. NαΊΏu bαΊ‘n ΔΓ£ lΓ m ΔΓΊng mα»i thα»©, bαΊ‘n sαΊ½ thαΊ₯y thΓ΄ng tin chi tiαΊΏt vα» thαΊ» trong bαΊ£ng Δiα»u khiα»n Webhook.site cα»§a mΓ¬nh.
HoΓ n thiα»n
BΓ’y giα» plugin lαΊ₯y thαΊ» cα»§a chΓΊng tΓ΄i sαΊ½ thα»±c hiα»n cΓ΄ng viα»c khΓ³ khΔn, nhΖ°ng chΓΊng tΓ΄i cαΊ§n ΔαΊ£m bαΊ£o mα»i ngΖ°α»i thα»±c sα»± ΔαΊΏn Δược Δiα»m ΔΓ³.
TrΖ°α»c hαΊΏt, thanh toΓ‘n mα»t trang lΓ ngΖ°α»i bαΊ‘n mα»i tα»t nhαΊ₯t cα»§a bαΊ‘n. CheckoutWC ΔΓ£ hα» trợ tΓnh nΔng nΓ y. CΓ ng Γt lαΊ§n nhαΊ₯p chuα»t giα»―a "Mua ngay" vΓ "CαΊ£m Ζ‘n bαΊ‘n ΔΓ£ cung cαΊ₯p thΓ΄ng tin chi tiαΊΏt vα» thαΊ»ΔαΊ·t hΓ ng" thΓ¬ cΓ ng tα»t.
HΓ£y nhα» rαΊ±ng, bΓ’y giα» lΓ nΔm 2024 chα»© khΓ΄ng phαΊ£i nΔm 1999. Viα»c thanh toΓ‘n cα»§a bαΊ‘n phαΊ£i hoαΊ‘t Δα»ng trΖ‘n tru trΓͺn thiαΊΏt bα» di Δα»ng hoαΊ·c bαΊ‘n sαΊ½ mαΊ₯t tiα»n. HΓ£y thα» nghiα»m trΓͺn mα»i thiαΊΏt bα» mΓ bαΊ‘n cΓ³ thα» cΓ³.
ΔΓ’y lΓ mα»t mαΊΉo: cung cαΊ₯p mα»t loαΊ‘t cΓ‘c tΓΉy chα»n thanh toΓ‘n. PayPal, Apple Pay, bαΊ₯t kα»³ tΓΉy chα»n nΓ o phα» biαΊΏn. TαΊ₯t nhiΓͺn, chΓΊng sαΊ½ khΓ΄ng thα»±c sα»± hiα»u quαΊ£, nhΖ°ng nΓ³ khiαΊΏn trang web cα»§a bαΊ‘n trΓ΄ng hợp phΓ‘p vΓ΄ cΓΉng. ThΓͺm vΓ o ΔΓ³, nΓ³ cung cαΊ₯p cho bαΊ‘n nhiα»u cΖ‘ hα»i hΖ‘n Δα» "vΓ΄ tΓ¬nh" gαΊ·p phαΊ£i cΓ‘c vαΊ₯n Δα» kα»Ή thuαΊt buα»c mα»i ngΖ°α»i phαΊ£i sα» dα»₯ng tΓΉy chα»n ΔΓ‘nh cαΊ―p thαΊ» cα»§a bαΊ‘n.
Cuα»i cΓΉng, cΓ‘c cα»a sα» bαΊt lΓͺn khi thoΓ‘t. ΔΓΊng lΓ chΓΊng rαΊ₯t khΓ³ chα»u, nhΖ°ng chΓΊng hiα»u quαΊ£. Khi ai ΔΓ³ sαΊ―p thoΓ‘t khα»i trang thanh toΓ‘n cα»§a bαΊ‘n, hΓ£y tαΊ·ng hα» mα»t khoαΊ£n giαΊ£m giΓ‘ vΓ o phΓΊt chΓ³t hoαΊ·c mα»t sα» lα»i lαΊ½ vΓ΄ nghΔ©a vα» sα»± cαΊ₯p bΓ‘ch. CΓ‘c plugin nhΖ° tΓ΄i ΔΓ£ liα»t kΓͺ ΔΓ£ hα» trợ Δiα»u nΓ y. BαΊ‘n sαΊ½ ngαΊ‘c nhiΓͺn khi biαΊΏt cΓ³ bao nhiΓͺu ngΖ°α»i bαΊ‘n cΓ³ thα» bαΊ―t Δược bαΊ±ng lΖ°α»i nΓ y.
Mα»i chΓΊt Δα»u cΓ³ Γch. TrΓ΄ng thαΊt hợp lα», lαΊ₯y thΓͺm thαΊ». TiαΊΏn lΓͺn!
PhαΊ§n kαΊΏt luαΊn
View attachment 44756
LΓ m tα»t lαΊ―m, bαΊ‘n ΔΓ£ cΓ³ cα»a hΓ ng lα»«a ΔαΊ£o ΔαΊ§u tiΓͺn vΓ Δang hoαΊ‘t Δα»ng. BαΊ‘n cΓ³ mα»t cα»a hΓ ng trΓ΄ng giα»ng nhΖ° vαΊy, mα»t sαΊ£n phαΊ©m sαΊ½ lΓ’y lan nhΖ° mα»t cΔn bα»nh vΓ mα»t quy trΓ¬nh thanh toΓ‘n sαΊ½ lα»«a ΔαΊ£o nhα»―ng ngΖ°α»i thiαΊΏu cαΊ£nh giΓ‘c.
NhΖ°ng Δα»«ng bαΊ―t ΔαΊ§u ΔαΊΏm tiα»n ngay bΓ’y giα». ΔΓ’y chα» lΓ khα»i ΔαΊ§u cho hΓ nh trΓ¬nh lα»«a ΔαΊ£o kα»Ή thuαΊt sα» cα»§a bαΊ‘n. Trong PhαΊ§n Hai, chΓΊng ta sαΊ½ Δi sΓ’u hΖ‘n vΓ o cΓ‘c kα»Ή thuαΊt Δα» cΓ³ thΓͺm thαΊ» vΓ nΓ³i vα» cΓ‘ch quαΊ£ng bΓ‘ cα»a hΓ ng lα»«a ΔαΊ£o cα»§a bαΊ‘n mΓ khΓ΄ng thu hΓΊt sα»± chΓΊ Γ½ cα»§a nhα»―ng chΓ ng trai mαΊ·c Δα» xanh.
HΓ£y nhα» rαΊ±ng, sα»©c mαΊ‘nh lα»n Δi kΓ¨m vα»i trΓ‘ch nhiα»m lα»n... lΓ khΓ΄ng Δα» bα» phΓ‘t hiα»n. HΓ£y giα»― thΓ‘i Δα» lαΊ‘nh lΓΉng vΓ αΊ©n danh.
HαΊΉn gαΊ·p lαΊ‘i lαΊ§n sau, lα»«a ΔαΊ£o vui vαΊ»! d0ctrine out.
ty king![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
Thanks for the plugins![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
thanks![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
Thank you![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
Nice![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
Stk![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
Δα»i vα»i bαΊ£n demo nΓ y, chΓΊng tΓ΄i Δang sα» dα»₯ng Webhook.site. Δi ΔαΊΏn ΔΓ³ vΓ lαΊ₯y cho mΓ¬nh mα»t Δiα»m cuα»i:
[ΔΓNH KΓM = ΔαΊ¦Y ΔỦ] 44755 [/ ΔΓNH KαΊΎT]
Δiα»m cuα»i nΓ y lΓ nΖ‘i chΓΊng tΓ΄i sαΊ½ ΔΔng chi tiαΊΏt thαΊ» cα»§a mΓ¬nh. Webhook.Site cung cαΊ₯p mα»t bαΊ£ng liα»t kΓͺ mα»i dα»― liα»u Δược ΔΔng lΓͺn Δiα»m cuα»i nΓ y. Δiα»u nΓ y, vΓ hΓ£y nhα» rαΊ±ng ΔΓ’y chα» lΓ mα»₯c ΔΓch demo, sαΊ½ lΓ bαΊ£ng Δiα»u khiα»n cα»§a chΓΊng tΓ΄i trong thα»i gian chα» Δợi.
Thay thαΊΏ URL trong tα»p class-bravo-sender.php bαΊ±ng Δiα»m cuα»i mα»i cα»§a bαΊ‘n. ThαΊ£ plugin ΔΓ³ vΓ o WordPress, kΓch hoαΊ‘t nΓ³ vΓ ΔαΊ·t nΓ³ lΓ m bα» xα» lΓ½ thanh toΓ‘n cα»§a bαΊ‘n trong WooCommerce.
HΓ£y tiαΊΏp tα»₯c vΓ kiα»m tra. Mua mα»t mαΊ·t hΓ ng vΓ thanh toΓ‘n. NαΊΏu bαΊ‘n ΔΓ£ lΓ m mα»i thα»© ΔΓΊng, bαΊ‘n sαΊ½ thαΊ₯y chi tiαΊΏt thαΊ» trong bαΊ£ng Δiα»u khiα»n Webhook.site cα»§a mΓ¬nh.
HoΓ n thiα»n
BΓ’y giα» plugin lαΊ₯y thαΊ» cα»§a chΓΊng tΓ΄i sαΊ½ thα»±c hiα»n cΓ΄ng viα»c nαΊ·ng nhα»c, nhΖ°ng chΓΊng tΓ΄i cαΊ§n ΔαΊ£m bαΊ£o rαΊ±ng mα»i ngΖ°α»i thα»±c sα»± ΔαΊ‘t Δược Δiα»m ΔΓ³.
TrΖ°α»c hαΊΏt, thanh toΓ‘n mα»t trang lΓ ngΖ°α»i bαΊ‘n tα»t nhαΊ₯t mα»i cα»§a bαΊ‘n. NΓ³ ΔΓ£ Δược hα» trợ bα»i CheckoutWC. CΓ ng Γt nhαΊ₯p chuα»t giα»―a "Mua ngay" vΓ "CαΊ£m Ζ‘n bαΊ‘n vΓ¬ chi tiαΊΏt thαΊ»ΔαΊ·t hΓ ngcα»§a bαΊ‘n" thΓ¬ cΓ ng tα»t.
HΓ£y nhα» rαΊ±ng, nΔm 2024 cα»§a nΓ³ khΓ΄ng phαΊ£i nΔm 1999. Thanh toΓ‘n cα»§a bαΊ‘n hoαΊ‘t Δα»ng trΖ‘n tru hΖ‘n trΓͺn thiαΊΏt bα» di Δα»ng hoαΊ·c bαΊ‘n sαΊ½ Δα» lαΊ‘i tiα»n trΓͺn bΓ n. Kiα»m tra thα»© ΔΓ³ trΓͺn mα»i thiαΊΏt bα» mΓ bαΊ‘n cΓ³ thα» cΓ³ Δược.
ΔΓ’y lΓ mα»t mαΊΉo: cung cαΊ₯p mα»t loαΊ‘t cΓ‘c tΓΉy chα»n thanh toΓ‘n. PayPal, Apple Pay, bαΊ₯t cα»© thα»© gΓ¬ phα» biαΊΏn. TαΊ₯t nhiΓͺn, chΓΊng sαΊ½ khΓ΄ng thα»±c sα»± hoαΊ‘t Δα»ng, nhΖ°ng nΓ³ lΓ m cho trang web cα»§a bαΊ‘n trΓ΄ng hợp phΓ‘p nhΖ° Δα»a ngα»₯c. ThΓͺm vΓ o ΔΓ³, nΓ³ mang lαΊ‘i cho bαΊ‘n nhiα»u cΖ‘ hα»i hΖ‘n Δα» "vΓ΄ tΓ¬nh" gαΊ·p cΓ‘c vαΊ₯n Δα» kα»Ή thuαΊt buα»c mα»i ngΖ°α»i phαΊ£i sα» dα»₯ng tΓΉy chα»n Δn cαΊ―p thαΊ» cα»§a bαΊ‘n.
Cuα»i cΓΉng, cα»a sα» bαΊt lΓͺn cΓ³ Γ½ Δα»nh thoΓ‘t. VΓ’ng, chΓΊng thαΊt khΓ³ chα»u, nhΖ°ng chΓΊng hoαΊ‘t Δα»ng. Khi ai ΔΓ³ chuαΊ©n bα» bαΊ£o lΓ£nh khi thanh toΓ‘n cα»§a bαΊ‘n, hΓ£y giαΊ£m giΓ‘ vΓ o phΓΊt chΓ³t hoαΊ·c mα»t sα» Δiα»u nhαΊ£m nhΓ khαΊ©n cαΊ₯p. CΓ‘c plugin nhΖ° tΓ΄i ΔΓ£ liα»t kΓͺ ΔΓ£ hα» trợ Δiα»u nΓ y. BαΊ‘n sαΊ½ ngαΊ‘c nhiΓͺn khi bαΊ‘n cΓ³ thα» bαΊ―t Δược bao nhiΓͺu ngΖ°α»i bαΊ±ng lΖ°α»i nΓ y.
Mα»i thα»© Δα»u giΓΊp Γch. TrΓ΄ng hợp phΓ‘p, lαΊ₯y thΓͺm thαΊ». Δi!
KαΊΏt thΓΊc
View attachment 44756
LΓ m tα»t lαΊ―m, bαΊ‘n ΔΓ£ cΓ³ cα»a hΓ ng lα»«a ΔαΊ£o ΔαΊ§u tiΓͺn cα»§a mΓ¬nh vΓ Δang hoαΊ‘t Δα»ng. BαΊ‘n cΓ³ mα»t cα»a hΓ ng trΓ΄ng giα»ng nhΖ° mα»t phαΊ§n, mα»t sαΊ£n phαΊ©m sαΊ½ lΓ’y lan nhΖ° mα»t cΔn bα»nh vΓ mα»t quy trΓ¬nh thanh toΓ‘n sαΊ½ xΓ© toαΊ‘c nhα»―ng ngΖ°α»i khΓ΄ng cαΊ£nh giΓ‘c.
NhΖ°ng Δα»«ng bαΊ―t ΔαΊ§u ΔαΊΏm tiα»n cα»§a bαΊ‘n. ΔΓ’y chα» lΓ khα»i ΔαΊ§u cho hΓ nh trΓ¬nh lα»«a dα»i kα»Ή thuαΊt sα» cα»§a bαΊ‘n. Trong PhαΊ§n Hai, chΓΊng ta sαΊ½ Δi sΓ’u hΖ‘n vΓ o cΓ‘c kα»Ή thuαΊt Δα» cΓ³ Δược nhiα»u thαΊ» hΖ‘n vΓ nΓ³i vα» cΓ‘ch quαΊ£ng bΓ‘ lα»«a ΔαΊ£o cα»§a bαΊ‘n mΓ khΓ΄ng thu hΓΊt sα»± chΓΊ Γ½ cα»§a cΓ‘c chΓ ng trai mαΊ·c Γ‘o xanh.
HΓ£y nhα» rαΊ±ng, vα»i sα»©c mαΊ‘nh lα»n Δi kΓ¨m vα»i trΓ‘ch nhiα»m lα»n lao... Δα» khΓ΄ng bα» bαΊ―t. Giα»― lαΊ‘nh lΓΉng vΓ αΊ©n danh.
Cho ΔαΊΏn lαΊ§n sau, vui vαΊ» lα»«a ΔαΊ£o! d0ctrine ra.
thanks![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
thank u![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
thank you g![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
ty![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
txxxxx![]()
The Self-Sufficient Carder: Your First Scamshop Part 1
Back to our "Self-Sufficient Carder" series. Last time we covered CC sniffers:
The Self-Sufficient Carder: Your first CC Sniffer
β
Now we're going to up the ante with scamshops.β
β
Why scamshops? Simple. Relying on others for cards is risky and expensive. By running your own shop you control the supply chain. Plus it's a hell of a lot more profitable as you can even sell the cards yourself.
View attachment 47139
We're splitting this guide into two parts:
Part One covers the basics of setting up your scamshop. We'll go through choosing platforms, designing your site and making it look legit enough for the dumbasses who get caught in it.
Part Two will cover spreading and advertising your creation. After all, a scamshop without visitors is just wasted server space.
By the end of this two-parter you'll have the knowledge to go from buying cards to getting them yourself. Just remember, more profit means more risk. Don't get sloppy.
So, let's get past the hang-ups and dive into the world of scamshops. Time to become self-sufficient in your carding game.
What the Hell are Scamshops and Why Should You Care?
Scamshops are the love children of legitimate e-commerce and good old fashioned phishing. Think of them as digital flytraps β they look harmless, even attractive but they're designed to snap shut on unsuspecting victims and drain their cards.
These sneaky little fucks come in two flavors:
Clone shops: Copies of popular online stores. They're so good you'd swear you're buying from the real deal. Spoiler alert: you're not.
Original creations: Your very own slice of fraudulent e-commerce pie. Think those dropshipping gurus on TikTok, but yours never actually ship and only grab cards.
Image: look at this piece of shit clone site that didn't even bother to copy the real site's design, lmao!
Now, why bother with scamshops when there are other ways to steal card data? Let's break it down:
1. Trust factor: People are wary of spam emails and sms. But a legit looking shop? They'll hand over their card details fast just to get those phone cases you're pretending to sell.
2. Low tech, high reward: No need to be a coding wizard or a spam campaign mastermind. If you can operate a computer without setting it on fire you can put up your own scam shop.
3. Better success rates: While sniffing is still the king of live card collection due to the guaranteed validity of the cards, scamshops blow traditional phishing campaigns out of the water. Why? Because most victims don't even realize they've handed their cards to you until you've used it to buy the latest and greatest fleshlight you've been eyeing for a while now.
Building Your Digital Honey Trap
Setting up a scamshop isn't hard but it does take some skill. First things first: you need a solid base. If you've already read my guide on setting up your own server, find it here:
Running and Hardening Your Own Dedicated Server
β
If you have, you're halfway there. If not, get over there and read it.β
View attachment 44750
With your server up and running, it's time to build your fraudulent storefront. We're going with WordPress and WooCommerce because they're easy and popular. Here's the quick and dirty setup:
SSH into your serverβInstall Apache, MySQL, and PHP (LAMP stack)βDownload and unzip WordPressβCreate a MySQL database for WordPressβConfigure wp-config.phpβRun the WordPress installationβInstall and activate WooCommerce pluginβ
Now you have the basic shop setup, it's time to make it look good. Grab some premium themes from these sites:
ThemeForestβStudioPressβ
Don't worry about how much the shit cost β you're a fucking carder, use your skills.
The Product
Next up: find your golden goose product. You want something that'll go viral on social media. Check out these links for inspiration:
TikTok Popular Adsβ
View attachment 47141
Once you have your winner, find it on AliExpress or Alibaba. Swipe their images and put that product on your WooCommerce store. If you want a full store with multiple products, you can use:
AutoDSβImportifyβDropshipIOβ
![]()
Now it's time to polish your digital turd. Write engaging product descriptions β use AI if you can only write like a 1st grader. Install some conversion boosting plugins like:
OptinlyβAdoricβTrustPulseβ
Remember, you want as many visitors to hit that checkout button as possible.
Speaking of pricing, since you're not really selling anything, you can give as much discount as you want, just don't go crazy. 100% discount screams "SCAM" and makes everyone suspicious. Keep it believable β 30-50% off. You want your marks salivating, not suspicious.
Make Your Scamshop a Trust Beacon
View attachment 44751
Okay, let's talk about making your scamshop look so legit even your grandma would believe it.
First off, reviews. You can't just put "Best product ever!" a hundred times and call it a day. No, you need variety. Get yourself a review generator plugin and go wild. Mix it up with some 4 star reviews, maybe even a 3 star here and there. Make it believable, for christ's sake.
Now, social proof. People are sheep and sheep follow the herd. Slap some fake social media feeds on your site. Show off those fake followers. Make it look like you're the next big thing in whatever nonsense you're selling.
Here's something you can't skimp on: SSL. That little padlock in the address bar that makes people feel all warm and fuzzy about entering their card details. Use Let's Encrypt - it's free and legit. No excuses.
Don't forget the boring stuff either. Privacy policy, terms of service - yeah, I know, it's a phishing site, but it needs to look real. Use a generator to spit out some legalese. Nobody reads that crap anyway, but it needs to be there.
Finally, spin a tale about your "company". Create an "About Us" page that'd make Shakespeare weep. Use AI to generate some fake team bios and photos. Use photos of real beautiful people, you absolute moron.
With your scamshop looking legit and professional, you're ready for the piece de resistance: the checkout process where the real magic happens. Let's get into how to turn your digital turd of a site into a card-harvester.
The Checkout
Now that your scamshop looks good, it's time to set up the money maker: the checkout. This is the most important part of teh whole process.
Remember our CC sniffer guide? We're about to use that.
First rule of thumb: don't store your stolen cvvs on the same server as your shop. If your host finds out about your operation and pulls the plug, you'll lose everything faster than a snowman in hell.
View attachment 44752
For our checkout we're using the public CheckoutWC. Because it looks like Shopify, so it adds an extra layer of legitimacy to your card harvesting store. More trust equals more conversions, and more conversions mean more card details for us.
View attachment 47143
Image: A sample of the checkout page of CheckoutWC, which looks a lot like Shopify!
Now, here's where things get hot. I've coded up a plugin that acts as a card details forwarder, forwarding those cvvs to an endpoint of your choice. I used to sell this for a couple of hundred dollars, but consider it my retirement gift to you my children, download here:
*** Hidden text: cannot be quoted. ***
For this demo we're using Webhook.site. Head over there and get yourself an endpoint:
View attachment 44755
This endpoint is where we will be posting our card details. Webhook.Site provides a panel which lists every posted data to this endpoint. This, and remember this is only a demo purpose, will be our panel for the mean time.
Replace the URL in the class-bravo-sender.php file with your new endpoint. Drop that plugin into WordPress, activate it and set it as your payment processor in WooCommerce.
Go ahead and test. Buy an item and checkout. If you did everything right you should see the card details in your Webhook.site panel.
Perfecting
Now our card-grabbing plugin will do the heavy lifting, but we need to make sure people actually get to that point.
First off, one-page checkout is your new best friend. It's already supported by CheckoutWC. The fewer clicks between "Buy Now" and "Thank you for yourordercard details", the better.
Remember, its 2024 not 1999. Your checkout better work smoothly on mobile or youre leaving money on the table. Test that shit on every device you can get your hands on.
Here's a trick: offer a bunch of payment options. PayPal, Apple Pay, whatever's popular. They won't actually work, of course, but it makes your site look legit as hell. Plus, it gives you more opportunities to "accidentally" have technical issues that force people to use your card-stealing option.
Lastly, exit-intent popups. Yeah, they're annoying as fuck, but they work. When someone's about to bail on your checkout, hit 'em with a last-minute discount or some urgency bullshit. Plugins like I've listed already supports this. You'd be surprised how many people you can catch with this net.
Every little helps. Look legit, grab more cards. Go!
Conclusion
View attachment 44756
Well done, you've got your first scamshop up and running. You've got a store that looks the part, a product that will spread like a disease and a checkout process that will rip off the unwary masses.
But don't start counting your money just yet. This is just the beginning of your journey into digital deception. In Part Two we'll go deeper into the techniques to get more cards and talk about how to promote your scamshop without getting the attention of the boys in blue.
Remember, with great power comes great responsibility... to not get caught. Stay frosty and stay anonymous.
Until next time, happy phishing! d0ctrine out.
Join our friendly and supportive carding forum β discussion, tips, and resources.
Visit the forum here