Screen Scraping for Data Exfiltration

Screen Scraping or Web Scraping is a technique commonly used by both legitimate business and cyber criminals to collect data from web pages. Whilst screen scraping can be used perfectly legitimately, our research has found that cyber criminals use scraping in a variety of ways in order to steal data and commit fraud. There are a range of commercial and free tools available for those who want to screen scrape as well as some detailed guidance on what it is and how to to build tools. STORM have uncovered much discussion on a range of dark web forums relating to screen scraping and our investigation of many Business Email Compromise (BEC) incidents has led us to investigate the use of this tech

