LogoKit is a phishing kit and phishing-as-a-service offering used to build highly customized credential-harvesting pages that impersonate enterprise cloud services, financial institutions, logistics firms, and other trusted brands. Public reporting has tracked the kit since at least the mid-2010s, with broader industry naming and documentation emerging in 2021. It has been used in campaigns targeting users of Microsoft 365 and other major online services across multiple regions and languages.
A defining characteristic of LogoKit is per-victim dynamic page generation. Campaign URLs commonly embed the target’s email address, allowing the kit to derive the victim’s organization from the email domain, prefill the username field, and fetch matching visual assets such as logos, favicons, and in some cases live screenshots of the legitimate organization’s website. This produces phishing pages tailored to the specific recipient rather than a single static template, increasing credibility and complicating signature-based detection. Some observed variants also present fake verification elements or error messages and redirect victims to the legitimate site after credential submission to reduce suspicion.
LogoKit operators have relied heavily on legitimate third-party and cloud services for branding assets, screenshots, hosting, and delivery infrastructure. Campaigns have also abused open redirects on trusted services and compromised legitimate web resources to improve deliverability and evade filtering. Reported lures include password-expiry notices, certificate-expiry warnings, access restriction messages, delivery failure notices, timesheet updates, and domain verification themes.
The kit’s core function is credential theft. Captured usernames and passwords are transmitted to attacker-controlled collection points, including observed use of messaging-platform bots as an exfiltration channel. Obfuscation of client-side code and runtime assembly of phishing content have also been reported. LogoKit has been associated with broad opportunistic targeting rather than a single vertical, with observed impersonation spanning financial services, government-adjacent entities, logistics, and enterprise SaaS providers.
LogoKit is best understood as a web-based credential phishing framework rather than a traditional host-resident malware family. Its operational value lies in scalable impersonation, victim-specific customization, and delivery/evasion techniques that leverage trusted infrastructure and dynamically generated content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Should the victim then enter their password, LogoKit performs an AJAX request, sending the target's email and password to an external source
"The victim’s credentials are being sent to mettcoint[.]com/js/error-200.php... credentials are uploaded to mettcoint[.]com/css/nk/error-404.php"
the actors prefer to use domain names in exotic jurisdictions or zones with relatively poor abuse management process - .gq, .ml, .tk, ga, .cf or to gain unauthorized access to legitimate WEB-resources, and then use them as hosting for further phishing distribution.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service kit used for credential harvesting that dynamically builds a victim-specific login page in real time using the target organization's branding and live website screenshots, then exfiltrates captured credentials via Telegram bot workflows.
A phishing kit/campaign that uses JavaScript to transform a benign-looking web form into a brand-impersonating phishing page, personalizes content based on victim email, and exfiltrates captured credentials to an attacker-controlled server.
LogoKit is a phishing kit used to deliver credential-harvesting pages. It dynamically generates phishing content with JavaScript, changes impersonated branding and text in real time, fetches company logos from third-party services, pre-fills victim email addresses, captures submitted credentials via AJAX, and then redirects victims to legitimate corporate sites to reduce suspicion. The campaign described also used open redirect vulnerabilities and trusted domains to bypass spam filters and deliver the phishing pages.
A phishing kit used to generate credential-harvesting pages that dynamically pull victim-brand logos (e.g., via Clearbit Logo API and Google S2 Favicon) and often prefill the victim’s email in the URL/username field to increase credibility and scale campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.