A phishing campaign using the LogoKit kit abused open redirect vulnerabilities on trusted services, including Snapchat, to deliver credential-harvesting pages while evading spam filters and security checks. Resecurity said the activity targeted Office 365 users in the United States and Latin America, relying on trusted-looking redirect chains, compromised web resources, and hosting on platforms such as Fleek to make malicious links appear legitimate.
The kit dynamically customized phishing pages with victim-specific branding and prefilled email addresses, then exfiltrated credentials through AJAX before redirecting victims to legitimate corporate sites to reduce suspicion. Researchers linked the operation to infrastructure spread across hundreds of domains and impersonating brands including Bank of America, GoDaddy, Virgin Fly, Firebase, and Office 365, underscoring LogoKit's continued use as a long-running phishing platform.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Around November 2021, more than 700 domains were identified in campaigns leveraging LogoKit. The report describes the number of domains used by LogoKit campaigns as continuously growing.
The report states that the LogoKit phishing kit has existed in underground use since at least 2015. This establishes the earliest known activity for the kit referenced in the campaign analysis.
Over the past week, Resecurity identified LogoKit on more than 300 domains, and over the past month on more than 700 sites. The infrastructure included domains impersonating brands such as Bank of America, GoDaddy, Virgin Fly, Firebase, and Office 365.
Resecurity observed a spike in LogoKit activity around the beginning of August. The increase coincided with the registration of multiple new domains impersonating popular services.
Resecurity described a phishing campaign identified on July 13 targeting Office 365 users in the United States and Latin America. The campaign used open redirect vulnerabilities, including one on Snapchat, to route victims to credential-harvesting pages.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.