Rock Phish
Rock Phish refers to both a phishing toolkit/technique and the group behind it.
Rock Phish gang and techniques
At one time the Rock Phish group was stated to be behind "one-half of the phishing attacks being carried out. VeriSign reports them as a group of Romanian origin, but others have claimed that the group is Russian. They were first identified in 2004.Their techniques were sophisticated and distinctive, as outlined in a presentation at APWG eCrime '07.
History
In 2004 the first rock phishing attacks contained the folder path “/rock”, which led to the name of the attack, and group.Attackers employed wild card DNS entries to create addresses that included the target's actual address as a sub-domain. For example, in the case of a site appearing as