LogoKit Phishing and Victim-Specific Login Pages

LogoKit Builds Phishing Pages Around Each Victim

Barracuda says the phishing kit pulls company logos and website imagery into fake login pages, then sends stolen credentials through Telegram.

LogoKit, a phishing kit that generates fake login pages, is using victims’ email addresses to build customized corporate login pages in real time, according to new research from Barracuda.

The attack starts with a phishing link containing the victim’s email address. Code on the fake page reads the email domain to identify the victim’s employer, then pulls in the organization’s logo and a screenshot of its legitimate website.

Barracuda found LogoKit using legitimate services including Thum.io, Clearbit, Google Favicon, ImageKit and Microlink to assemble those pages.

The technique allows attackers to tailor each page to the organization associated with the victim’s email address rather than rely on a single generic login page, according to Barracuda.

Once a user enters credentials, LogoKit sends them to a Telegram bot. The victim is then redirected to the legitimate website, potentially making the failed login appear routine.

Barracuda said the activity shows phishing becoming “increasingly automated, personalized and cloud-based.”

LogoKit is not new. RiskIQ researchers were tracking the phishing kit in 2021, when they found it operating across hundreds of domains and targeting users of Microsoft SharePoint, OneDrive and Adobe Document Cloud.

Microsoft documented similar attacks in 2019 that used a victim’s email address to retrieve company-specific logos, text and background images. Hornetsecurity found phishing kits using screenshots of victims’ corporate websites as login-page backgrounds in 2020.

Barracuda said newer LogoKit campaigns rely more heavily on automation and legitimate cloud services to construct phishing pages on demand.

Earlier versions could replace logos and other page elements based on the victim being targeted. The latest activity adds website screenshots and other content pulled from online services as the phishing page loads.

The use of automated, repeatable infrastructure extends beyond credential phishing. Malwarebytes researchers on Wednesday disclosed more than 120 fake Walmart storefronts built from the same WordPress and WooCommerce template. The sites copied Walmart branding, advertised steep discounts and collected victims’ credit card numbers, expiration dates and security codes.

Both operations show how attackers can reuse legitimate web tools and standardized infrastructure to produce convincing scams at scale. Verizon’s 2026 Data Breach Investigations Report found successful mobile social-engineering attacks rose 40%.

Legitimate cloud platforms are also giving attackers ready-made infrastructure for credential theft. The GitBait phishing campaign targeting Mexican bank customers used GitHub Pages to host fake banking sites and a cloud spreadsheet service to collect stolen credentials.

Barracuda recommends phishing-resistant authentication, including FIDO2 security keys and passkeys.

Those authentication methods do not send a reusable password to a website. Instead, the credential is cryptographically tied to the legitimate site, making a copied login page far less useful to an attacker.

Image by Daniel Skovran from Pixabay

Total
0
Shares
Previous Article
Diagram showing OpenAI's logo connected by a line through Hugging Face's logo to Modal Labs' logo, with a cracked fracture point between them

OpenAI's Rogue Test Agent Hacked a Second Company, Modal Labs Confirms

Next Article
Aerial view of circular tanks and treatment basins at a water and wastewater facility.

Cyberattack Hits 30+ Minnesota Water Systems

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading