Top Tweets for #LogoKit
๐จ That "DocuSign notification" in your inbox? It might be a sophisticated #phishing attack.
Group-IB experts have identified a growing wave of DocuSign impersonation attacks using #LogoKit a phishing framework that dynamically loads your organization's branding to create highly convincing fake login pages.
The email looks legitimate. The page looks like yours. But it's designed to steal credentials.
Our latest Email Protection Spotlight reveals how this attack works and how Group-IB's #BusinessEmailProtection stops the growing wave of #DocuSign impersonation before users are exposed.
Protect your organization. Read the full story: https://t.co/8uDDsKTw15

CRIL analyzes an ongoing LogoKit phishing campaign that pulls brand assets from Clearbit and Google Favicon.
https://t.co/HkhBWxNRCe
#CredentialTheft #BrandMonitoring #Phishing #SocialEngineering #LogoKit #ThreatIntel

๐ฏ Analysis of the latest LogoKit #phishkit โ #ExploreWithANYRUN
โ ๏ธ #LogoKit is a comprehensive set of phishing kits, known for using services that provide company logos and screenshots of target websites
โก๏ธ The background is retrieved via request to a website screenshot service, using the following template:
hxxps://thum[.]io/get/width/<DPI>/https://<Domain>
โก๏ธ The company's logo is fetched from a legitimate logo storage service:
hxxps://logo.clearbit[.]com/<Domain>
Example: https://t.co/tnjZiMbIYj
๐ The domain chain is led by a decoder-redirector:
hxxps:// asiangrocers [.]store/fri/?haooauvpco=bWlubmllQGRpc25leS5jb20
It is a fake Asian food store website built on a #WordPress template, with a domain age of around four years. The template contains email addresses filled with typos
๐ The decoder-redirector shields the page from analysis and redirects the victim to the actual #phishing page
In this case, the real content of the #phish page and the associated scripts are hosted on the #Cloudflare Pages platform. They are stored in the assets/ folder, which contains styles, images, and scripts
๐จ Three scripts with random 10-character names are designed to protect the page from analysis and send stolen data to the threat actors:
assets/js/e0nt7h8uiw[.]js
assets/js/vddq2ozyod[.]js
assets/js/j3046eqymn[.]js
The stolen authentication data is sent to a remote Command and Control (#C2) server controlled by the attackers via an HTTP POST request containing the following parameters:
fox=<E-mail>&con=<Password>
๐จโ๐ป Take a look at another sandbox session:
https://t.co/WhBetsYmGM
๐ Hurry up to get #ANYRUN's Black Friday deals: get a license bundle, double your TI Lookup search requests, or get a custom offer
๐ https://t.co/6a0jqsxDGS
![anyrun_app's tweet photo. ๐ฏ Analysis of the latest LogoKit #phishkit โ #ExploreWithANYRUN
โ ๏ธ #LogoKit is a comprehensive set of phishing kits, known for using services that provide company logos and screenshots of target websites
โก๏ธ The background is retrieved via request to a website screenshot service, using the following template:
hxxps://thum[.]io/get/width/<DPI>/https://<Domain>
โก๏ธ The company's logo is fetched from a legitimate logo storage service:
hxxps://logo.clearbit[.]com/<Domain>
Example: https://t.co/tnjZiMbIYj
๐ The domain chain is led by a decoder-redirector:
hxxps:// asiangrocers [.]store/fri/?haooauvpco=bWlubmllQGRpc25leS5jb20
It is a fake Asian food store website built on a #WordPress template, with a domain age of around four years. The template contains email addresses filled with typos
๐ The decoder-redirector shields the page from analysis and redirects the victim to the actual #phishing page
In this case, the real content of the #phish page and the associated scripts are hosted on the #Cloudflare Pages platform. They are stored in the assets/ folder, which contains styles, images, and scripts
๐จ Three scripts with random 10-character names are designed to protect the page from analysis and send stolen data to the threat actors:
assets/js/e0nt7h8uiw[.]js
assets/js/vddq2ozyod[.]js
assets/js/j3046eqymn[.]js
The stolen authentication data is sent to a remote Command and Control (#C2) server controlled by the attackers via an HTTP POST request containing the following parameters:
fox=<E-mail>&con=<Password>
๐จโ๐ป Take a look at another sandbox session:
https://t.co/WhBetsYmGM
๐ Hurry up to get #ANYRUN's Black Friday deals: get a license bundle, double your TI Lookup search requests, or get a custom offer
๐ https://t.co/6a0jqsxDGS](https://pbs.twimg.com/media/GeB5saJWcAAYnDn.jpg)
Cosmetics Logo Design
.
๐ด Contact us if you need AWESOME LOGO / BRANDING DESIGN!!
๐ฑWhatsapp Me:+8801608684359
๐งEmail:[email protected]
.
.
#logodesign #logodesigner #logodesigns #logodesigners #logodesigning #logokit #brandkitdesign
#designernishad

Brand Board Templates. All templates are fully customizable using Canva. Edit the colors, fonts, & images to match your branding. https://t.co/IpIEwtvrDZ
#DIYBrandingPackage #LogoKit #BusinessLogo #Template #Editable #BrandBoard #DIY #LogoDesign #LogoMaker #LogoDesign

#ThreatProtection #Phishing landscape sees a #LogoKit activity increase. Read more about Symantec's protection: https://t.co/2EF4TYUrdw #Spam #Cybercrime #Cybersecurity
#Hackers managed to exploit Open Redirect #vulnerabilities to conduct #LogoKit #phishing campaigns.
#CyberSecurity #infosec #cybercrime
https://t.co/5WKstWj3QG

Hackers Exploit Open Redirect Vulnerabilities to Conduct LogoKit Phishing Campaigns.
https://t.co/QxjwFo8rSG #hackers #infosec #cybersecurity #vulnerability #exploit #logokit
@RESecurity #LogoKit update โ The #phishing kit leveraging Open Redirect Vulnerabilities
https://t.co/EuUkzaJCY9
#securityaffairs #hacking
@LizJocelyne Thank you for the info, just as a I suspected this is likely the same gang/group/operators of a campaign tracked by @RiskIQ as #LogoKit the hostname websites these kits are hosted on are almost identical
"Messages delayed" #phishing with #LogoKit
URL(https): /web-host.live/home/index.html
@urlscanio https://t.co/JO9VegnaA1
@Hostwinds @malwrhunterteam @Spam404 @PhishStats @ActorExpose

ICYMI: RiskIQ's @SEGinty recently joined the @thecyberwire to talk about #LogoKit, a pervasive #phishing tool that enables even novice threat actors to executive effective campaigns: https://t.co/LehIJDNBTG
RiskIQ's @SEGinty recently joined the @thecyberwire to talk about #LogoKit, a pervasive #phishing tool that enables even novice threat actors to executive effective campaigns: https://t.co/tQKtjNrnRq
The business of #crimeware: RiskIQ researchers analyze a thriving #phishing economy and the expert marketers behind the sale of #LogoKit, a simple, modularized, and adaptable phish kit running on thousands of domains: https://t.co/EjjMsISlSv
Via @DarkReading, find out what makes the #LogoKit #phishing kit ingenious in its simplicity and a valuable tool for threat actors of all skill levels: https://t.co/p53SZhcyvZ
#phishing with #LogoKit
URL(https): /institutoaxioma.com.ar/ #(emailaddress)
URL(http): /email25.godaddy.com-sign-realm.getforge.io/ #(emailaddress)
@urlscanio https://t.co/VIFcdjGESF
@Spam404 @101domain @malwrhunterteam @illegalFawn

Hungarian account suspended #phishing mail with #LogoKit
URL(https): /reliable-factual-tuna.glitch.me
@urlscanio https://t.co/ulQKzy9TUc
@malwrhunterteam @whitehoodie4 @Spam404 @AmazonHelp @ActorExpose @PhishStats @PhishKitTracker

Last Seen Hashtags on Sotwe
ุงูุญูุงุฉ_ุงูุฒูุฌูุฉ
้ฟ็ฑณๅจ
Seen from United States
เธเนเธกเธเธทเธเนเธกเน
Seen from Thailand
WECALLIBS
Seen from United States
surfacert
Seen from United States
ipcam
akivili
Seen from United States
ใฟใจใใ
Seen from Pakistan
Pink #Deltarune
Seen from United States
SigSauer238
Seen from United States
Most Popular Users

Elon Musk 
@elonmusk
241.6M followers

Barack Obama 
@barackobama
119M followers

Cristiano Ronaldo 
@cristiano
114.2M followers

Donald J. Trump 
@realdonaldtrump
111.8M followers

Narendra Modi 
@narendramodi
107.2M followers

Rihanna 
@rihanna
98.7M followers

NASA 
@nasa
92.4M followers

Justin Bieber 
@justinbieber
91.8M followers

KATY PERRY 
@katyperry
89.9M followers

Taylor Swift 
@taylorswift13
83.8M followers

Lady Gaga 
@ladygaga
75.3M followers

Virat Kohli 
@imvkohli
73.1M followers

Kim Kardashian 
@kimkardashian
70.8M followers

YouTube 
@youtube
68.8M followers

Neymar Jr 
@neymarjr
66.1M followers

Bill Gates 
@billgates
65M followers

Selena Gomez 
@selenagomez
62.9M followers

The Ellen Show
@theellenshow
62.3M followers

CNN 
@cnn
61.8M followers

X 
@x
60.7M followers













![BushidoToken's tweet photo. #Phishing recently w/ storageapi[.]fleek[.]co
Some BoA-themed docs, what looks to be #LogoKit, a generic login page, plus O365
https://t.co/57lBJkShHj https://t.co/DiyxwV0jYq](https://pbs.twimg.com/media/FMNpNm2X0AUiIli.png)
![BushidoToken's tweet photo. #Phishing recently w/ storageapi[.]fleek[.]co
Some BoA-themed docs, what looks to be #LogoKit, a generic login page, plus O365
https://t.co/57lBJkShHj https://t.co/DiyxwV0jYq](https://pbs.twimg.com/media/FMNpKZtXIAY7Sfh.png)
![BushidoToken's tweet photo. #Phishing recently w/ storageapi[.]fleek[.]co
Some BoA-themed docs, what looks to be #LogoKit, a generic login page, plus O365
https://t.co/57lBJkShHj https://t.co/DiyxwV0jYq](https://pbs.twimg.com/media/FMNpC2TXEAEDypG.png)
![BushidoToken's tweet photo. #Phishing recently w/ storageapi[.]fleek[.]co
Some BoA-themed docs, what looks to be #LogoKit, a generic login page, plus O365
https://t.co/57lBJkShHj https://t.co/DiyxwV0jYq](https://pbs.twimg.com/media/FMNo0wnWQAAxxG-.jpg)
![BushidoToken's tweet photo. #LogoKit #Phishing campaign is back
๐Append any Email address to the end of the URL and the Logo appears
outlook-mail-authentication[.]web[.]app
(https://t.co/faV6ngHCGx is owned by @Firebase)
https://t.co/Z1HKpWzr4c
cc @RiskIQ @SteveD3 @JCyberSec_ https://t.co/BWX4dPP1uE](https://pbs.twimg.com/media/FLRGNRPXMAAvILS.png)

