Popular Tools
Zphisher
Zphisher is a popular open-source phishing tool that automates the creation of phishing pages for various online services. It provides over 30 pre-built templates that mimic login pages of popular websites like Facebook, Google, Instagram, Yahoo, PayPal, Netflix, and more, making it a powerful tool for conducting phishing attacks.
Key Feature
Zphisher is primarily designed for educational and cybersecurity awareness purposes. However, unauthorized use for malicious activities is illegal and unethical. It is strongly advised to use this tool only for ethical hacking, security testing, and educational demonstrations.
Installation
Step 1 : Installation
First, you’ll need to install Zphisher by following these commands in your terminal:


The installation script will handle setting up the necessary dependencies for Zphisher.
Step 2: Launching Zphisher
Once installed, launch Zphisher by running the following command in the terminal:
This will start the Zphisher tool and present you with a menu of options.
Step 3: Selecting a Target Template
Zphisher provides a variety of phishing page templates. Choose a template by entering its corresponding number from the menu

Step 4: Setting Up the Phishing Page
Choose one of the following phishing page

then select cloudflare tunnel to generate link

Step 5: Sending Phishing Links
Zphisher will generate a phishing link based on the selected template and customization. Share this link with your targets through email, messaging apps, or other communication channels and wait for logins to appear on your screen. Utilize a bit of social engineering if you want to get more credentials.

Step 6: Collecting Credentials
Monitor the Zphisher console for captured credentials and other relevant data in real-time as targets interact with the phishing link.

After simulating the phishing attempt, you’ve now seen how simple victims can fall for this type of cybersecurity attack. Document the different ways the attack is spread, what ways one can quickly identify and report the attack, and share that knowledge(awareness) with your friends to make sure they never fall victim of such attempts.