That’s oddly specific, I am sure you have 100x better way to harvest passwords. Like run a free proxy server.

It depends on what is your target. No enterprise will tolerate that their employees set up a proxy (and even so clever employees are not the target).

However I’ve seen a lot of people using free web based tool to replace pretty basic dumb stuff such as assembling pdf.

Would’nt it be nice for a concurrent company to buy all pdf assembled by your employees using this web service based on company IP?

Of course nerd might find out that pdf is uploaded (most probably however he will use offline FOSS solution because he know better). But the basic employee that use this « because someone send them a link to this awesome tool » will never even thought of it...

I have no proof this scheme is used by scammers, but it seems highly plausible to me.

