Logokit phishing kit evolves into a real-time, cloud-based deception platform
Attackers use legitimate web services to dynamically recreate each victim’s corporate login experience
Over the past year, the Logokit phishing-as-a-service (PhaaS) platform has evolved from a standard phishing kit into a real-time deception platform that generates customised phishing pages for individual targets. In a new report, Barracuda researchers explain how, instead of directing every target to the same fake login page, the platform uses legitimate commercial web services to instantly recreate a victim’s corporate login experience. Stolen credentials are then exfiltrated via Telegram and other cloud services. These techniques make phishing attacks more convincing and harder to detect.
From brand impersonation to environment impersonation
The attack begins when the victim clicks a phishing link that contains their email address within the URL.
Code embedded in the phishing page extracts the victim’s email address and uses the email domain name, such as company.com, to identify the victim’s organisation and tailor the phishing page accordingly.
The toolkit uses commercial web services to retrieve the company logos and favicons and capture a real-time screenshot of the victim’s legitimate website. The result is a phishing page that closely mirrors the look and feel of the victim’s actual login experience.
Advertisement
When the victim enters their credentials, the information is sent directly to a Telegram bot, eliminating the need for traditional, attacker-controlled backend infrastructure. The victim is then redirected to the real website, making compromise more difficult to spot and investigate.
Logokit’s phishing attacks can be deployed in multiple languages. Barracuda researchers identified campaigns in English, German, French, Spanish, Chinese, and Korean.
Despite these technical advances, Logokit campaigns still rely on familiar social engineering lures, including password expiration notices, certificate renewal warnings, account restrictions, delivery failures, and timesheet notifications.
“Logokit has shifted from brand impersonation to real-time environment impersonation, while reducing the infrastructure attackers need to operate, making attacks more convincing and harder to detect,” said Sachin Meti, Threat Analysis Associate at Barracuda. “As attackers increasingly adopt the tools and practices of modern software development, organisations need security controls that can detect and stop attacks even when the fraudulent page appears legitimate.”
The findings highlight how phishing-as-a-service platforms are becoming more automated, personalised and reliant on cloud services. To defend against this, researchers recommend a layered security approach that combines automated threat detection, phishing-resistant multi-factor authentication (MFA) such as FIDO2 security keys and passkeys, and conditional or risk-based access controls. These measures help limit attacker access even if credentials are stolen, by taking factors such as device trust, user location and behavioural patterns into account.
Security teams should also consider opening suspicious links in isolated remote environments before they reach users’ devices and automatically analysing all URLs for potential threats. While security awareness training remains important, increasingly realistic phishing attacks mean that robust security technologies and policies are becoming essential.
Advertisement