#phishingkit
EvilTokens-phishingkit misbruikt Microsoft-aanmeldingsproces voor grootschalige

Sinds februari 2026 is de kwaadaardige tool EvilTokens actief, een phishingkit die zich richt op het Microsoft-aanmeldingsproces met apparaatcodes. Deze kit wordt verkocht aan andere cybercriminelen, onder meer...
EvilTokens-phishingkit misbruikt Microsoft-aanmeldingsproces voor grootschalige fraude
Sinds februari 2026 is de kwaadaardige tool EvilTokens actief, een phishingkit die zich richt op het Microsoft-aanmeldingsproces met apparaatcodes. Deze kit wordt verkocht aan andere cybercriminelen, onder meer via Telegram, voor een initiële prijs van $1.500 en een maandelijkse vergoeding van $500. De tool is gericht op het plegen van Business Email Compromise (BEC)-fraude. Onderzoek van Microsoft heeft aangetoond dat campaigns met deze kit wereldwijd meer dan 12.000 e-mailinboxen van meer dan 10.000 organisaties hebben gecompromitteerd. Microsoft-onderzoekers hebben EvilTokens gelinkt aan de groep Storm-2992, die wordt beschouwd als een sleutelspeler in de opschaling van BEC-aanvallen. De...
newsfacts.info
September 23, 2026 at 11:30 AM
🚀 Hum, you know what?

📢 We've just reached 8️⃣0️⃣0️⃣ PhishingKit-Yara-Rules made freely available to everyone!

❓ These rules detect phishing kits targeting 3️⃣0️⃣0️⃣ of the world’s best-known brands and trade names.

-> Check this: github.com/t4d/Phishing...

#phishing #phishingkit #infosec #cyber
February 5, 2025 at 4:28 PM
🚀 There's now 850 phishing kit yara rules available on our free and opensource project: github.com/t4d/Phishing...

#phishing #yara #opensource
GitHub - t4d/PhishingKit-Yara-Rules: Repository of Yara rules dedicated to Phishing Kits Zip files
Repository of Yara rules dedicated to Phishing Kits Zip files - t4d/PhishingKit-Yara-Rules
github.com
June 11, 2025 at 7:03 AM
📣 Meet Thomas Damonneville - our founder - at the #M3AAWG organized by the Messaging, Malware, Mobile Anti-Abuse Working Group in Lisbon next week for his presentation entitled: “Hunting for phishing URLs, kits and business”.

👋 In partnership with Signal Spam

#phishing #phishingkit #cybersecurity
February 15, 2025 at 6:20 PM
😤 Yeah that's right, stop scam-baiting the scammers!

Everyone already knows about this scam!

... it's been implemented in the PhishingKit-Yara-Rules project for detection since... January 2025!

This is outrageous!!!!
March 9, 2026 at 7:06 AM

🔥 5 new PhishingKit Yara rules, dedicated to detect phishing kits impersonating:

✅ Ledger
✅ Nickel
✅ Telegram Messenger
✅ PayPal
✅ Elster

👉 There is now 7️⃣7️⃣3️⃣ Yara rules available for free.

github.com/t4d/Phishing...

#Phishing #phishingkit #fraud #SOC #CSIRT #yara #stalkphish #freesoftware
GitHub - t4d/PhishingKit-Yara-Rules: Repository of Yara rules dedicated to Phishing Kits Zip files
Repository of Yara rules dedicated to Phishing Kits Zip files - t4d/PhishingKit-Yara-Rules
github.com
December 3, 2024 at 7:05 AM
✨ Batch N°2️⃣4️⃣1️⃣ of PhishingKit Yara rules! ✨

Rules for triage/detection of #phishing kits targetings users/customers of:

📌 ​​​​​​​American Express
📌 Cetelem
📌 FedEx
📌 Midland States Bank
📌 Royal Credit Union

github.com/t4d/Phishing...
GitHub - t4d/PhishingKit-Yara-Rules: Repository of Yara rules dedicated to Phishing Kits Zip files
Repository of Yara rules dedicated to Phishing Kits Zip files - t4d/PhishingKit-Yara-Rules
github.com
May 7, 2025 at 7:00 AM
✨ 5️⃣ new PhishingKit Yara rules! ✨

Rules for triage/detection of #phishing kits targetings users/customers of:

📌 Visa
📌 Telstra
📌 MBH Bank
📌 Alibaba Group
📌 CaixaBank

Find more on our #Opensource #Freesoftware repository:
github.com/t4d/Phishing...
GitHub - t4d/PhishingKit-Yara-Rules: Repository of Yara rules dedicated to Phishing Kits Zip files
Repository of Yara rules dedicated to Phishing Kits Zip files - t4d/PhishingKit-Yara-Rules
github.com
March 19, 2025 at 7:10 AM
✨️ Batch N°2️⃣5️⃣5️⃣ of PhishingKit Yara rules! ✨️

👉️ Rules for triage/detection of #phishing kits targetings users/customers of:

📌 Netflix
📌 ANTAI
📌 Itaú Unibanco
📌 M&T Bank
📌 Nedbank

This free and #OpenSource project is now 8️⃣7️⃣️5️⃣ Yara rules available!

github.com/t4d/Phishing...
December 29, 2025 at 7:09 AM
May 4, 2025 at 6:13 PM
✨ New batch of PhishingKit Yara rules

Rules for triage/detection of #phishing kits targetings users/customers of:

📌 E-ZPass IAG
📌 Huntington National Bank
📌 Charles Schwab
📌 Avida Finans AB
📌 SFR

github.com/t4d/Phishing...
GitHub - t4d/PhishingKit-Yara-Rules: Repository of Yara rules dedicated to Phishing Kits Zip files
Repository of Yara rules dedicated to Phishing Kits Zip files - t4d/PhishingKit-Yara-Rules
github.com
April 28, 2025 at 3:52 PM
✨ Second batch of PhishingKit Yara rules for 2025! ✨

Rules for triage/detection of #phishing kits:

📌 AT&T
📌 PayPal
📌 SumUp
📌 SBB CFF FFS (SwissPass)
📌 Indonesiabaik.id

This free and #OpenSource project is now:
✅ 7️⃣8️⃣7️⃣ Yara rules available!
✅ 2️⃣3️⃣0️⃣ Commits
✅ 5️⃣ years old

-> github.com/t4d/Phishing...
January 15, 2025 at 8:22 AM
🪝🚨 New ‘Spiderman’ phishing kit makes it trivial to clone major EU bank logins and steal credentials and OTPs in real time. If you get unexpected bank‑login links, double‑check before typing anything.

Read: hackread.com/spiderman-ph...

#Phishing #Cybersecurity #BankFraud #Spiderman #PhishingKit
Spiderman Phishing Kit Targets European Banks with Real-Time Credential Theft
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
December 9, 2025 at 10:20 PM
✨ Batch N°2️⃣5️⃣0️⃣ of PhishingKit Yara rules! ✨

Rules for triage/detection/investigation on #phishing kits.
This free and OpenSource project is now 8️⃣6️⃣0️⃣ Yara rules available!

github.com/t4d/Phishing...
September 3, 2025 at 6:23 AM
⚠️🪝 Bluekit phishing kit is now active at scale, using Browser-in-the-Middle attacks, bot checks, and fake CAPTCHA pages to steal logins while evading detection.

Listen or read: hackread.com/bluekit-phis...

#CyberSecurity #Phishing #InfoSec #PhishingKit #Bluekit
Bluekit Phishing Kit Uses Browser-in-the-Middle Attacks to Evade Detection
Bluekit phishing kit is active at scale, using browser-in-the-middle attacks, bot checks, and fake CAPTCHAs to steal logins while dodging security scans.
hackread.com
June 29, 2026 at 9:54 AM
Bluekit phishing kit integrates 40+ templates, AI assistant, voice cloning, anti-bot cloaking, 2FA spoofing, automated domain registration, and Telegram data theft. Active development with campaign management tools. #PhishingKit #AItech #Varonis
New Bluekit Phishing Kit Features AI Assistant
Bluekit is a newly discovered phishing kit that bundles over 40 templates, an AI assistant, automated domain registration, anti-bot cloaking, spoofing, voice cloning, and uses Telegram for data exfiltration. Varonis accessed Bluekit’s control panel and found integrated domain and campaign management, session tracking, and rapid feature updates, though the kit remains...
www.hendryadrian.com
May 2, 2026 at 3:45 PM
Nieuwe Phishingkit Omzeilt Microsoft 365-beveiliging Zonder Wachtwoorden te Stel

Analisten van eSentire hebben eind augustus 2026 een nieuwe phishingkit, genaamd GhostCode, geïdentificeerd. Deze kit omzeilt de beveiliging van Microsoft 365 door accountovername te bewerkstelligen zonder de w...
Nieuwe Phishingkit Omzeilt Microsoft 365-beveiliging Zonder Wachtwoorden te Stelen
Analisten van eSentire hebben eind augustus 2026 een nieuwe phishingkit, genaamd GhostCode, geïdentificeerd. Deze kit omzeilt de beveiliging van Microsoft 365 door accountovername te bewerkstelligen zonder de wachtwoorden van gebruikers te stelen. De aanvalsmethode maakt gebruik van een tactiek die lijkt op 'business-email-compromise' om de verzoeken routineus te laten lijken. De campagne startte met berichten via zakelijke contactformulieren, waarbij aanvallers zich voordeden als inkopers. Vervolgens werden ontvangers verleid tot het ondertekenen van een geheimhoudingsverklaring (NDA) via een WeTransfer-link met een wachtwoordbeveiligde HTML-bijlage. Deze bijlage bevatte een lokmiddel voor...
newsfacts.info
September 16, 2026 at 3:01 PM
N0va tricks you into approving a real Microsoft login - handing attackers your MFA-backed SSO session. https://intel.threadlinqs.com/threat/TL-2026-2537 #ThreatIntel #N0va #Nova #PhishingKit
September 16, 2026 at 1:22 PM
フィッシングキット
urlscan.io/result/01a04...
#phishingkit
August 27, 2026 at 9:16 AM
August 13, 2026 at 1:58 PM
Greatness-platform omzeilt e-mailbeveiliging en steelt Microsoft 365-toegang

Het Greatness-platform, oorspronkelijk een phishingkit, is geëvolueerd tot een geavanceerde phishing-as-a-service dienst. Het biedt kant-en-klare lokmiddelen, configureerbare domeinen en tools om accounts van M...
Greatness-platform omzeilt e-mailbeveiliging en steelt Microsoft 365-toegang
Het Greatness-platform, oorspronkelijk een phishingkit, is geëvolueerd tot een geavanceerde phishing-as-a-service dienst. Het biedt kant-en-klare lokmiddelen, configureerbare domeinen en tools om accounts van Microsoft 365, iCloud, Yahoo en Google Workspace te compromitteren. Het platform is speciaal ontworpen om toegang te verkrijgen tot Microsoft 365 door het vastleggen van geldige inlogtokens. Recentelijk werd een campagne waargenomen die nagemaakte e-mails gebruikte die zich voordeden als RingCentral. Deze e-mails, die verwezen naar voicemail of prestatiebeoordelingen, verzochten ontvangers om een vermeende opname of beoordeling te openen. De aanvalsleveringsketen begint met het imitere...
newsfacts.info
August 5, 2026 at 3:00 PM
Fake insurance portals now race your OTP back to the real site before it expires. https://intel.threadlinqs.com/threat/TL-2026-1679 #ThreatIntel #InsureOTP #Telegram #PhishingKit
July 25, 2026 at 12:10 PM
A cheap phishing kit clones nearly every Turkish bank, and its Meta ads vanish before anyone can report them. https://intel.threadlinqs.com/threat/TL-2026-1313 #ThreatIntel #Unnamed #Turkish #PhishingKit
July 14, 2026 at 3:23 PM