├── Email_Templates ├── COVID-19_Base_Template.html ├── CactusCon_COIVD-19-Dress-Code-Demo-Template.html ├── Cactuscon_COVID-19-Survey-Demo-Template.html ├── Charity_Base_Template.html ├── Package_Pickup.html └── System_is_Out_of_Date.html ├── Landing_Pages ├── Instagram_Landing_Page.html ├── O-Three-Sixty-Five_Landing_Page.html └── Starbucks_Gift_Card.html └── README.md /Email_Templates/COVID-19_Base_Template.html: -------------------------------------------------------------------------------- 1 | 2 | 3 | 4 | 5 | 6 |

Dear all, 

7 | 8 |

COVID-19 continues to affect lives on a daily basis. As many of know, [CLIENT] is encouraging those of you who can work from home effectively to please do so. Staff considered critical to operations are still be required to work onsite in the upcoming weeks.

9 | 10 |

Due to the new safety standards introduced by the World Health Organization, [CLIENT] employees are now required to follow a strict new policy which can be located at: https://www.[CLIENT].com/employees/covid

11 | 12 |

Please contact your managers or HR with any questions you may have on this new policy. [CLIENT]  has also set up a 'frequently asked questions' page during this time to assist employees with any questions: https://www.[CLIENT].com/employees/faq

13 | 14 |

Thanks for your cooperation, 

15 | 16 |

[CLIENT]

17 | 18 |

{{.Tracker}}

19 | 20 | 21 | -------------------------------------------------------------------------------- /Email_Templates/CactusCon_COIVD-19-Dress-Code-Demo-Template.html: -------------------------------------------------------------------------------- 1 | 2 | 3 | 4 | 5 | 6 |

Dear all, We’re continuing to closely monitor updates around the coronavirus (COVID-19) outbreak. Due to the new safety standards introduced by the World Health Organization, Acme employees are now required to follow a strict new dress code policy which can be located at the following link: https://doesanybodyreadthelink.com/covid/dresscode Please contact your manager or reply to this email if you have any questions on these updates. Thanks for your cooperation, [CLIENT]

7 | 8 | 9 | -------------------------------------------------------------------------------- /Email_Templates/Cactuscon_COVID-19-Survey-Demo-Template.html: -------------------------------------------------------------------------------- 1 | 2 | 3 | 4 | 5 | 6 |

Dear {{.Email}},

7 | 8 |

[CLIENT] would like to encourage everyone to participate in an online survey to provide valuable feedback on [CLIENT]'s ongoing response to COVID-19. This survey is extremely important as ACME is committed to providing a safe work environment for everyone.

9 | 10 |

To begin your survey, please click here. Additionally, please reply to this email if you experience technical difficulties.

11 | 12 |

Thank you for your participation in the survey.

13 | 14 |

Kindest regards,
15 | Human Resources​

16 | 17 | 18 | -------------------------------------------------------------------------------- /Email_Templates/Charity_Base_Template.html: -------------------------------------------------------------------------------- 1 | 2 | 3 | 4 | 5 | 6 |

Dear all, 

7 | 8 |

As we discussed, or if you missed the chat, [CLIENT] is going to donate $10,000 directly to the [CHARITY] COVID-19 response fund as well as matching any employee contributions.  

9 | 10 |

If you feel you have the means and desire to donate, [CLIENT] will match 100% of your contribution. We are setting up a payroll deduction that will be ready for the next payroll cycle. All you need to do is email me with your desired contribution amount, and I will set it up for you. This contribution is post-tax.  

11 | 12 |

If you would prefer to donate directly to the COVID-19 response fund you can do so here. Please send a confirmation of your contribution and [CLIENT] will match it. Of course there is absolutely no obligation to participate.  

13 | 14 |

If you would like to volunteer, an online form is available here: www.[CHARITY].org/Covid19Response

15 | 16 |

Thank you and stay safe and healthy! 

17 | 18 |

{{.Tracker}}

19 | 20 | 21 | -------------------------------------------------------------------------------- /Email_Templates/Package_Pickup.html: -------------------------------------------------------------------------------- 1 | 2 | 3 | 4 | 5 | 6 |
7 | 8 |

Dear {{.Email}}, 

9 | 10 |

You've received a package! Your company has enrolled you in Your Package Pickup to simplify the mailroom process and get your package to you fast!

11 | 12 |

The details of your package are as follows:

13 | 14 |

Type: Parcel
15 | Carrier: Fed Ex
16 | Tracking Number: 231300687629630
17 | Method: 2-Day Express Saver
18 | Origin: Cincinnati, OH

19 | 20 |

TO get started, you'll need to log into your account. It only takes a minute to get going - you can use your corporate e-mail credentials to log in.

21 | 22 |

Set up your account now!
23 | Your Username: {{.Email}}
24 | https://www.yourpackagepickup.com/pickup

25 | 26 |


27 | Once you've set up your account online, you'll select how you'd like to receive your package. It's really that easy!

28 | 29 |

Let us know if you have any issues with your shipment at {{.URL}}.

30 | 31 |


32 | Best, 
33 | Your Package Pickup Care Team
34 | hello@yourpackagepickup.com

35 | 36 |


37 | Copyright 2019 YourPackagePickup. All rights reserved.
38 |  

39 | 40 |

{{.Tracker}}

41 | 42 | 43 | -------------------------------------------------------------------------------- /Email_Templates/System_is_Out_of_Date.html: -------------------------------------------------------------------------------- 1 | 2 | 3 | 4 | 5 | 6 |
 
7 | 8 |
9 | 10 |

{{.Email}},

11 | 12 |

The Information Technology Department has detected that your computer is critically out of date. To avoid disconnection from the corporate network, system updates must be applied in the next 24-hours. To update your system, perform the following actions:

13 | 14 |

1. SAVE and CLOSE any documents or files you're working on.
15 | 2. LOG IN to your corporate account at https://update.microsoft.com/windows and click "Apply Updates"
16 | 3. WAIT for updates to finish. This typically takes 5-10 minutes.
17 | 4. REBOOT YOUR COMPUTER if prompted. Some Windows updates do not require a reboot.

18 | 19 |

Please notify the IT Department if you have any questions or concerns. To extend your 24-hour deadline to 72-hours, click {{.URL}} and log in with your corporate credentials, then click "Delay My Updates."

20 | 21 |

Thanks,
22 | Information Technology Department

23 | 24 |

 

25 | 26 |

 

27 | 28 |

This mailbox is not monitored. Please do not reply.
29 | Remember,  the Information Technology department will never ask for your password via e-mail.

30 | 31 |

{{.Tracker}}

32 | 33 | 34 | -------------------------------------------------------------------------------- /Landing_Pages/Instagram_Landing_Page.html: -------------------------------------------------------------------------------- 1 |
2 | 3 | 4 | 5 | 120 | 121 | 122 |
6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 39 | 40 | 41 | 93 | 94 | 95 | 112 | 113 | 114 | 115 | 116 | 117 |
 
 
16 | 17 | 18 | 19 | 20 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 |
  21 | 22 | 23 | 24 | 25 | 26 | 27 |
28 |
 
   
38 |
42 | 43 | 44 | 45 | 89 | 90 | 91 |
46 | 47 | 48 | 49 | 50 | 51 | 52 | 85 | 86 | 87 |
   
53 | 54 | 55 | 56 | 81 | 82 | 83 |
57 | 58 | 59 | 60 | 61 | 76 | 77 | 78 | 79 |
    62 | 63 | 64 | 65 | 72 | 73 | 74 |
66 |

Hi {{.FirstName}},

67 |

Someone tried to log in to your Instagram account.

68 |

If this was you, please use the following code to log in:

69 |

823013

70 |

If this wasn't you, please reset your password to secure your account.

71 |
75 |
   
80 |
84 |
88 |
92 |
96 | 97 | 98 | 99 | 100 | 101 | 102 | 103 | 107 | 108 | 109 | 110 |
 
    104 |
© Instagram, Menlo Park, CA 94022
105 |
This message was sent to {{.FirstName}} and intended for {{.Email}}. Not your account? Remove your email from this account.
106 |
   
111 |
 
118 | 119 |
123 |
124 | -------------------------------------------------------------------------------- /Landing_Pages/O-Three-Sixty-Five_Landing_Page.html: -------------------------------------------------------------------------------- 1 | 2 | 3 | Sign in to Microsoft Online Services 4 | 5 | 6 | 7 | 11 | 12 | 20 |
Illustration for Microsoft Online Services 21 |
 
22 |
23 | 24 |
 
25 | 26 |
27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 |
36 |
37 | 38 |
39 | 40 | 41 | 42 | 43 | 100 | 101 | 102 |
103 |
104 | 105 | 106 | -------------------------------------------------------------------------------- /Landing_Pages/Starbucks_Gift_Card.html: -------------------------------------------------------------------------------- 1 | 2 | 3 | 4 | 5 | 6 |
7 | 8 | 9 | 10 | 12 | 13 | 14 |
Starbucks
11 | Hi {{.FirstName}},
15 | 16 | 17 | 18 | 19 | 30 | 31 | 32 |
"Just wanted to say thanks!" 20 | 21 | 22 | 23 | 26 | 27 | 28 |
From: Judy
24 |   25 |
29 |
33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 |
$10.00 USD
41 | 42 | 43 | 44 | 45 | 47 | 48 | 49 |
 
46 | Redeem Your eGift
50 |   51 | 52 | 53 | 54 | 55 | 56 | 57 |
58 | 59 | 60 | 61 | 62 | 65 | 66 | 67 |
Pay for your coffee, send a Starbucks eGift Card and more, right from the Starbucks App.
63 |
64 | For our full Terms & Conditions, click here.
68 |
69 |   70 | 71 | 72 | 73 | 79 | 80 | 81 |
Apple and the Apple logo are trademarks of Apple Inc., registered in the U.S. and other countries. App Store is a service mark of Apple Inc.
74 |
75 | Google Play is a trademark of Google Inc.
76 |
77 | Have a question about your eGift? We're here to help. Click here to access our customer support tools.
78 | Feel free to email us or call 1-800-782-7282 from 5AM – 8PM (PST) Mon-Fri and 6AM – 4PM (PST) Sat-Sun.
82 |
83 | 84 | 85 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # GoPhish Templates 2 | 3 | This repository includes several GoPhish templates that I have utilized for various engagements and now retired. 4 | 5 | When learning how to setup and use GoPhish I found that there was a lack of publicly available templates and landing pages. This repository is my attempt to give back to the InfoSec community by providing examples that I've used for generic phishing engagements. 6 | 7 | ## Clicking = Fail & Other Thoughts 8 | When launching a campaign with GoPhish my goal is to always try and obtain credentials from the user. While attacks can be executed from a user clicking a link (looking at you BeEF), 9/10 when I'm on a penetration test, credentials are what I am hoping for since dropping malware often isn't in scope. These campaigns are best paired with a good landing page or malicious download. 9 | 10 | I highly recommend you tailor these pretexts and landing pages to your client. That means you should clone a login portal from their external environment or create a convincing template relative to ongoing events to be used throughout more sophisticated campaigns. Remember, we potentially only need to win once to go masterhacker mode. 11 | 12 | However, I do want to state that users who click an email still provide me with some interesting information: 13 | 1. The email address is valid. 14 | 2. I know that the user has received the email and it has bypassed any protections in place. 15 | 2. I know that the user is active and can be targeted in additional campaigns. 16 | 17 | ## GoPhish 18 | Gophish is a powerful, open-source phishing framework. [GoPhish](https://getgophish.com) is avaialble for free. 19 | --------------------------------------------------------------------------------