LogoKit Builds Real-Time Fake Login Pages

Infosecurity Magazine · High sophistication
Last updated July 30, 2026

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the victim organization’s real website and uses legitimate online services to make the phishing page look familiar, then steals credentials and redirects victims to the real site.

How the attack worked

LogoKit is a phishing-as-a-service platform that generates a distinct fake login page for every recipient at the moment they click the link. Rather than relying on a pre-built template, the kit extracts the victim's email address from the phishing URL and uses the domain portion to identify their employer. It then calls legitimate commercial web services, including live website screenshot tools and brand or logo APIs, to assemble a page that mirrors the real organization's website in real time. Stolen credentials are exfiltrated through a Telegram bot, and victims are redirected to the genuine site afterward.

Why it succeeded

This approach represents a shift from simple brand impersonation to what has been described as environment impersonation, recreating parts of the victim's genuine web environment rather than serving a generic replica. Because each page is built on demand using live data, there is often no static template for defenders to fingerprint or blocklist. The final redirect to the real website adds another layer of deception: a victim who enters the wrong credentials on the fake page and lands on the real login screen may simply assume they mistyped their password, rather than suspecting they were phished.

Lures used to drive victims to these pages were routine and low-key, covering password and certificate expiry warnings, access restrictions, delivery failures, timesheet updates, and ICANN verification notices. Campaigns were also observed in multiple languages, including English, German, French, Spanish, Chinese, and Korean, widening the pool of potential targets.

What to watch for

  • A login page that looks familiar and matches your organization's branding, but is not hosted on your real domain.
  • A link where the URL path contains your own email address, a sign the page was personalized for you specifically.
  • Generic, urgent notices about password expiry, certificate renewal, delivery failures, or account access that push immediate login.
  • Unusual language or phrasing that doesn't match how your organization normally communicates internally.
  • Being redirected to your organization's real website after logging in, which can be used to mask that credentials were just stolen.

Building resistance

Organizations can reduce the impact of this kind of attack by prioritizing phishing-resistant multifactor authentication, such as FIDO2 keys and passkeys, which bind authentication to the legitimate domain so a fake page cannot present the correct cryptographic challenge. Complementary controls include conditional access rules, browser isolation, and URL filtering capable of flagging newly registered domains and links that carry an email address in the URL path. Employee awareness should reinforce that a convincing, familiar-looking login page is not proof of legitimacy, and that a successful redirect to the real site afterward does not mean the earlier page was safe.

Key findings

  • LogoKit campaigns extract the victim’s email address from the phishing URL and use it to identify the victim’s employer domain.
  • The kit builds a per-victim phishing page on demand using legitimate services (e.g., live website screenshots and brand/logo APIs).
  • Victim credentials are harvested through a Telegram bot and victims are then redirected to the real site, potentially reducing suspicion.
  • Because pages are assembled at request time, there may be no static template to fingerprint or blocklist.
  • Barracuda recommends phishing-resistant MFA (FIDO2/passkeys) and controls like conditional access, browser isolation, and URL filtering for newly registered domains and URLs containing email addresses.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, HR, IT/Helpdesk, Operations, Executives.
  • Affected industries: Cross-industry (any organization with a public website and email users).
  • Attack channels: email, website.
  • Impersonated: The target organization’s sign-in/IT portal (environment impersonation using the org’s real website background), IT/Security notifications or administrative services (as implied by the lure themes).

Red flags to watch for

  • The link contains the recipient’s email address in the URL path.
  • The login page looks familiar but is not on the organization’s real domain.
  • After entering credentials, the page redirects to the real site (a common tactic to reduce suspicion).
  • Generic urgent “warning” themes that push immediate login.
  • Unexpected language variations (multi-language campaigns) that don’t match normal internal communications.
  • A highly “authentic” page background that may be a live screenshot rather than a real portal.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is LogoKit?

LogoKit is a phishing-as-a-service platform that builds a unique login page for each victim in real time, pulling a live screenshot of the target organization's own website to use as the page background.

How does LogoKit personalize each phishing page?

It extracts the victim's email address from the phishing URL, uses the domain to identify their employer, then calls commercial web services to assemble a matching page on the fly.

Why do victims redirect to the real website after entering credentials?

After credentials are harvested, victims are redirected to the genuine site, where they would likely assume they had mistyped their password the first time, which can reduce suspicion.

How can organizations reduce the impact of LogoKit-style phishing?

Barracuda recommends phishing-resistant MFA such as FIDO2 keys and passkeys, along with conditional access rules, browser isolation, and URL filtering for newly registered domains and links carrying an email address in the path.

Read the video transcript

You click an email: “Your access is restricted, sign in to confirm your account details.” The login page looks exactly like our site. Behind that page is LogoKit, a phishing kit that grabs your email from the link, pulls a live screenshot of our real site, and builds a fake login just for you, then sends your password out over Telegram. Here’s the trap: you type your password, hit enter, and it instantly redirects you to the real site. You assume you just mistyped, but LogoKit already stole your credentials. A familiar page means nothing, only the domain does. If a link login page isn’t on our exact official domain, stop and report it to Security immediately.

Similar attacks