Skip to main content
Mallory
Malware

AOHell

AOHell is an early AOL-focused phishing tool associated with the origins of automated phishing in the mid-1990s. The provided content states that Koceilah Rekouche created AOHell and that the term "phishing" was coined in the context of this software. AOHell enabled large-scale phishing campaigns on America Online and provided an automated mechanism for stealing AOL user passwords and credit card information, with the phishing functionality operating starting in January 1995. The content describes it as the first publicly available automated phishing tool for password and information theft and notes that it was widely adopted by amateurs, leading to countless phishing attacks. Attackers reportedly used it to impersonate AOL staff in order to harvest credentials. The content further states that AOHell influenced many later automated phishing systems and that phishing activity subsequently expanded beyond AOL to other networks, eventually becoming a major threat affecting individuals, corporations, and governments. No specific technical indicators of compromise are provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1078Valid AccountsEvidence1

AOHell, an outlaw program designed to exploit bugs in the online service, making it easy to ... create pirate accounts.

T1566PhishingEvidence1

"The history of phishing traces back in important ways to the mid-1990s when hacking software facilitated the mass targeting of people in password stealing scams on America Online (AOL)... The software provided an automated password and credit card-stealing mechanism starting in January 1995."

Persistence

1 technique
T1078Valid AccountsEvidence1

AOHell, an outlaw program designed to exploit bugs in the online service, making it easy to ... create pirate accounts.

Privilege Escalation

1 technique
T1078Valid AccountsEvidence1

AOHell, an outlaw program designed to exploit bugs in the online service, making it easy to ... create pirate accounts.

Stealth

1 technique
T1078Valid AccountsEvidence1

AOHell, an outlaw program designed to exploit bugs in the online service, making it easy to ... create pirate accounts.

Command and Control

1 technique
T1090ProxyEvidence1

To keep his identity secret, Da Chronic hides behind an anonymous remailer in Finland.

Impact

1 technique
T1499Endpoint Denial of ServiceEvidence1

“mailboxes flooded with multi-megabyte email bombs and their chat rooms disrupted with spam messages.”

Other

1 technique
T1656ImpersonationEvidence1

AOHell, an outlaw program designed to exploit bugs in the online service, making it easy to forge messages in chat rooms...

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.