Find notable cyber news and cases, enriched with sources, timelines, and signals.

LogoKit real-time per-victim phishing campaign

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live screenshots of target sites, employer lookup from the phishing URL, and commercial web services to impersonate each victim’s environment more convincingly. The operation’s multilingual lures and Telegram-based credential collection show a scalable phishing workflow designed for resilience and evasion.

Related Happenings

Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking

Threat Actor Meta
H score36 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...

Google DoubleClick malspam campaign delivering DesckVB RAT

Campaign
H score33 First: 03.06.2026 19:29 Last: 03.06.2026 19:29 Sources 1

About this happening: A new malspam campaign is abusing Google's DoubleClick redirect path to evade detection and deliver DesckVB RAT, putting users and organizations at risk of malware inf...

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...

CypherLoc phishing-led browser scareware campaign

Campaign
H score49 First: 20.05.2026 13:00 Last: 20.05.2026 13:00 Sources 1

About this happening: The CypherLoc operation has driven around 2.8 million attacks since the start of 2026, using phishing emails to send users to malicious pages that lock browsers an...

OAuth device-code phishing campaign targeting SaaS accounts

Campaign
H score43 First: 04.04.2026 17:17 Last: 04.04.2026 17:17 Sources 1

About this happening: A device code phishing campaign now includes EvilTokens, a phishing-as-a-service kit sold on Telegram that uses the OAuth 2.0 device authorization flow to hija...

Timeline

  1. 29.07.2026 19:00 2 articles · 3h ago

    Barracuda details LogoKit per-victim phishing pages

    Initial Disclosure

    Barracuda published research on July 29, 2026 showing that LogoKit phishing-as-a-service builds a unique login page for each victim in real time by extracting the victim’s email from the phishing URL, identifying the employer from the domain, and assembling a matching page with commercial web services. The kit uses Thum.io for live website screenshots, Clearbit for brand logos, Google Favicon, ImageKit and Microlink APIs for additional imagery, routes credential harvesting through a Telegram bot, and redirects victims to the legitimate site after submission.

    Show sources