Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

LogoKit Phishing Kit Screenshots Victim Sites in Real Time

July 29, 2026

Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

July 29, 2026

Just 1% of AI-Discovered Vulnerabilities Exploited in the Wild

July 29, 2026
Facebook X (Twitter) Instagram
Wednesday, July 29
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»LogoKit Phishing Kit Screenshots Victim Sites in Real Time
News

LogoKit Phishing Kit Screenshots Victim Sites in Real Time

Team-CWDBy Team-CWDJuly 29, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A phishing-as-a-service (PaaS) platform has been observed building a unique login page for each victim in real time, pulling a live screenshot of the target organization’s own website to use as the page background.

According to new research from Barracuda published on July 29, recent LogoKit campaigns extracted the victim’s email address from the phishing URL, used the domain to identify their employer, then called commercial web services to assemble a matching page on the fly.

RiskIQ, which named the phishing kit in 2021, found it was already pulling brand logos from Clearbit and already carrying the victim’s email address in the URL.

What has changed is the live website screenshot, which Barracuda described as a shift from brand impersonation to environment impersonation, recreating parts of the victim’s genuine web environment rather than serving a generic replica.

Read more on phishing kit evasion: Starkiller New Commercial-Grade Phishing Kit Bypasses MFA

Legitimate Services Doing the Work

Barracuda found the kit using Thum.io, a commercial screenshot service, to capture the victim’s real website for the phishing background, and Clearbit to supply the matching brand logo.

Google Favicon, ImageKit and Microlink APIs loaded further authentic imagery as the page rendered.

Lures were routine, covering password and certificate expiry warnings, access restrictions, delivery failures, timesheet updates and ICANN verification notices.

Campaign emails appeared in English, German, French, Spanish, Chinese and Korean.

No Server, No Template, No Signature

Credential harvesting ran through a Telegram bot rather than an attacker-controlled backend. Victims were then redirected to the genuine site, where Barracuda suggested they would likely assume they had mistyped their password the first time.

Leaning on cloud services rather than owned infrastructure made campaigns easier to deploy, more resilient and harder for investigators to disrupt.

The per-victim approach also erodes conventional detection. Because each page is assembled at request time from live data, there is no static template for vendors to fingerprint and no stable indicator to blocklist, the same difficulty Abnormal researchers flagged with the Starkiller kit in February.

Barracuda urged organizations to deploy phishing-resistant multifactor authentication (MFA) such as FIDO2 keys and passkeys, which bind authentication to the legitimate domain so a fake page cannot present the correct cryptographic challenge.

It also recommended conditional access rules, browser isolation and URL filtering able to flag newly registered domains and links carrying an email address in the path.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAndroid Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
Team-CWD
  • Website

Related Posts

News

Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

July 29, 2026
News

The Average Cost of a Data Breach Rises to $5 Million

July 29, 2026
News

How Synthetic Identity Fraud is Coming for Machine Identities

July 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

A quick guide to recovering a hacked account

March 21, 2026

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

Why cybercriminals want to break into your email account

June 29, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.