Tykit is a credential-stealing phishing kit/malware reported by ANY.RUN in 2025. The provided content states it is used to serve fake Microsoft 365 login pages and steal credentials. It is described as a phishing threat demonstrating how small defensive gaps can lead to major impact. The observed lure/theme is Microsoft 365 credential harvesting, including SVG-based Microsoft 365 credential theft. No specific threat actor, industry targeting, malware family relationship, or concrete indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-stealing malware that highlights the risks posed by minor security lapses.
Phishing kit delivering fake Microsoft 365 login pages via SVG attachment lures that run trampoline JavaScript and pass Cloudflare Turnstile; includes basic anti-debugging and redirects victims to legitimate pages after credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.