Researchers reported that Robin Banks is a phishing-as-a-service platform selling turnkey phishing kits aimed at financial institutions and user credentials in the United States, United Kingdom, Canada, and Australia. IronNet observed a large campaign in mid-2022 using SMS and email lures to steal Citibank financial information and Microsoft account credentials, and assessed that activity tied to the service had already enabled criminals to access more than $500,000. The kits include a customer dashboard, customizable phishing templates, anti-bot protections such as reCAPTCHA and user-agent filtering, and centralized API-based collection of stolen data, with exfiltrated information also shareable through Telegram.
The reporting warned that Robin Banks could also support corporate initial access because it harvests Google and Microsoft credentials in addition to banking data. Defensive guidance aligned with MITRE ATT&CK M1017 highlights user training and policy enforcement as key mitigations against phishing-driven credential theft, including verifying requests through independent channels, avoiding unknown links and attachments, distrusting certificate warnings, limiting risky browser extensions, and approving only legitimate MFA prompts.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
In mid-June 2022, IronNet observed a large-scale phishing campaign using Robin Banks via SMS and email to steal Citibank financial information and Microsoft account credentials.
IronNet reported that the newer Robin Banks platform discussed in the report had been operating since March or April 2022.
The report states that Robin Banks was first seen in March 2022 as a phishing-as-a-service platform selling ready-made kits targeting banks and credential providers.
IronNet assessed that activity or infrastructure associated with Robin Banks was linked to IP address 5.206.227[.]166 and may have been active since at least August 2020.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.