Barracuda researchers reported that the LogoKit phishing-as-a-service platform has evolved into a real-time deception system that builds a unique login page for each target. The kit extracts the victim’s email address from the URL, identifies the employer’s domain, and assembles branded content on demand, including a live screenshot of the organization’s legitimate website as the page background. Researchers said the shift moves phishing beyond simple brand spoofing toward environment impersonation, while the victim is often redirected to the real site after submitting credentials, reducing suspicion.
The campaigns were observed in multiple languages, including English, German, French, Spanish, Chinese, and Korean, and rely heavily on legitimate cloud services such as Thum.io, Clearbit, Google Favicon, ImageKit, and Microlink. Stolen credentials are exfiltrated through Telegram bots rather than attacker-hosted infrastructure, making the operation easier to deploy and harder to disrupt or detect with traditional indicator- and template-based defenses. Barracuda recommended phishing-resistant MFA such as FIDO2 security keys and passkeys, along with conditional access, browser isolation, provider and brand impersonation checks, and URL filtering for newly registered domains and links containing email addresses in the path.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Barracuda reported that recent LogoKit campaigns generated a unique phishing login page for each victim in real time by extracting the victim's email address, identifying the employer's domain, and assembling branded content dynamically. The research also found the kit using live screenshots of legitimate sites as backgrounds, relying on services such as Thum.io, Clearbit, Google Favicon, ImageKit, and Microlink, and exfiltrating credentials via Telegram bots before redirecting victims to the real website.
RiskIQ identified and named the phishing kit LogoKit. Its earlier analysis found the kit pulled brand logos from Clearbit and carried the victim's email address in the phishing URL.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourceblog.barracuda.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.