LogoKit real-time per-victim phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live screenshots of target sites, employer lookup from the phishing URL, and commercial web services to impersonate each victim’s environment more convincingly. The operation’s multilingual lures and Telegram-based credential collection show a scalable phishing workflow designed for resilience and evasion.
Related Happenings
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Google DoubleClick malspam campaign delivering DesckVB RAT
Campaign
H score33
First: 03.06.2026 19:29
Last: 03.06.2026 19:29
Sources 1
About this happening:
A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
Google DoubleClick malspam campaign delivering DesckVB RAT
CampaignAbout this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...
CypherLoc phishing-led browser scareware campaign
Campaign
H score49
First: 20.05.2026 13:00
Last: 20.05.2026 13:00
Sources 1
About this happening:
The CypherLoc operation has driven around 2.8 million attacks since the start of 2026, using phishing emails to send users to malicious pages that lock browsers an...
CypherLoc phishing-led browser scareware campaign
CampaignAbout this happening: The CypherLoc operation has driven around 2.8 million attacks since the start of 2026, using phishing emails to send users to malicious pages that lock browsers an...
OAuth device-code phishing campaign targeting SaaS accounts
Campaign
H score43
First: 04.04.2026 17:17
Last: 04.04.2026 17:17
Sources 1
About this happening:
A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...
OAuth device-code phishing campaign targeting SaaS accounts
CampaignAbout this happening: A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...
Timeline
-
29.07.2026 19:00 2 articles · 3h ago
Barracuda details LogoKit per-victim phishing pages
Initial DisclosureBarracuda published research on July 29, 2026 showing that LogoKit phishing-as-a-service builds a unique login page for each victim in real time by extracting the victim’s email from the phishing URL, identifying the employer from the domain, and assembling a matching page with commercial web services. The kit uses Thum.io for live website screenshots, Clearbit for brand logos, Google Favicon, ImageKit and Microlink APIs for additional imagery, routes credential harvesting through a Telegram bot, and redirects victims to the legitimate site after submission.
Show sources
- LogoKit Phishing Kit Screenshots Victim Sites in Real Time — www.infosecurity-magazine.com — 29.07.2026 19:00
- LogoKit Phishing Kit Screenshots Victim Sites in Real Time — www.infosecurity-magazine.com — 29.07.2026 19:00