Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

LogoKit

LogoKit is a phishing kit first identified in 2021. It is characterized by phishing URLs that embed the victim’s email address and by dynamically personalizing lure pages through real-time brand asset retrieval, including logos from Clearbit’s Logo API and favicons from Google’s S2 Favicon service. Reported LogoKit pages impersonate trusted organizations and prefill the victim’s email address in the login form to increase credibility and improve credential theft success.

Recent reporting describes ongoing LogoKit-based phishing campaigns that hosted phishing pages on trusted infrastructure such as Amazon S3 and used Cloudflare Turnstile to create a false sense of legitimacy while harvesting credentials. One documented lure impersonated HunCERT, Hungary’s national CERT, and submitted stolen credentials to attacker-controlled PHP endpoints on mettcoint[.]com, including /js/error-200.php; a related WeTransfer-themed flow posted credentials to /css/nk/error-404.php. Victims were then shown fake submission errors. An open directory on mettcoint[.]com reportedly exposed multiple phishing components, and the domain was described as a credential collection domain used in broader phishing activity.

The campaign was reported as globally targeted, including banking and logistics organizations, with examples impersonating HunCERT, Kina Bank in Papua New Guinea, the Catholic Church in the United States, and logistics companies in Saudi Arabia. Reported infrastructure and IOCs associated with this activity include mettcoint[.]com, flyplabtk[.]s3.us-east-2.amazonaws.com, jstplastoss-bk.s3[.]us-east-2.amazonaws.com, chyplast[.]onrender.com, and ecowhizz.co[.]za/ecowhizz.co.zaza/he-opas.html.

Separate research also used LogoKit as the basis for a proof of concept showing how a phishing page with LogoKit-like behavior could be generated dynamically at runtime via client-side calls to LLM services. In that discussion, the original LogoKit behavior was described as using static JavaScript to personalize the lure from the victim’s email address in the URL and exfiltrate captured credentials to an attacker-controlled server.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

2 techniques
T1584.004ServerEvidence1

"The phishing pages were hosted on Amazon S3 (AWS)... using Amazon S3 buckets to appear trusted and stay under the radar"

T1588.002ToolEvidence1

"These phishing links were built using the Logokit phishing kit... first identified in 2021"

Initial Access

2 techniques
T1566PhishingEvidence2

the lure typically begins with an email that is aimed to create a sense of urgency or curiosity – something designed to make you click quickly without thinking twice.

T1566.002Spearphishing LinkEvidence2

Figure 1. Example of a malicious email with a link leading to a fake login page

Stealth

1 technique
T1036MasqueradingEvidence2

the credential-harvesting page queries sources such as business data aggregators and simple favicon lookup services to fetch the logo and other branding elements of the company being impersonated, sometimes even adding subtle visual cues or contextual details that further boost the ploy’s aura of authenticity.

Credential Access

2 techniques
T1056Input CaptureEvidence1

the credential-harvesting page queries sources such as business data aggregators and simple favicon lookup services to fetch the logo and other branding elements of the company being impersonated

T1056.003Web Portal CaptureEvidence1

"The victim’s credentials are being sent to mettcoint[.]com/js/error-200.php... credentials are uploaded to mettcoint[.]com/css/nk/error-404.php"

Collection

2 techniques
T1056Input CaptureEvidence1

the credential-harvesting page queries sources such as business data aggregators and simple favicon lookup services to fetch the logo and other branding elements of the company being impersonated

T1056.003Web Portal CaptureEvidence1

"The victim’s credentials are being sent to mettcoint[.]com/js/error-200.php... credentials are uploaded to mettcoint[.]com/css/nk/error-404.php"

Command and Control

1 technique
T1568Dynamic ResolutionEvidence1

"The Clearbit Logo API is used to fetch the logo... Google S2 Favicon... retrieve the Favicon icon by extracting the domain from the email address"

Exfiltration

1 technique
T1567Exfiltration Over Web ServiceEvidence1

The login details are sent in real time to the attackers via an AJAX POST request.

INDICATORS OF COMPROMISE

IOCs tracked for this family

4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app1 year ago
domain●●●●●●●●●●●●View more in app1 year ago
domain●●●●●●●●●●●●View more in app1 year ago
uri●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching4

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.