
Insurance Phish Turns OTPs Into Live Account Hijacks
Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The…
Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the victim organization’s real website and uses legitimate online services to make the phishing page look familiar, then steals credentials and redirects victims to the real site.
LogoKit is a phishing-as-a-service platform that generates a distinct fake login page for every recipient at the moment they click the link. Rather than relying on a pre-built template, the kit extracts the victim's email address from the phishing URL and uses the domain portion to identify their employer. It then calls legitimate commercial web services, including live website screenshot tools and brand or logo APIs, to assemble a page that mirrors the real organization's website in real time. Stolen credentials are exfiltrated through a Telegram bot, and victims are redirected to the genuine site afterward.
This approach represents a shift from simple brand impersonation to what has been described as environment impersonation, recreating parts of the victim's genuine web environment rather than serving a generic replica. Because each page is built on demand using live data, there is often no static template for defenders to fingerprint or blocklist. The final redirect to the real website adds another layer of deception: a victim who enters the wrong credentials on the fake page and lands on the real login screen may simply assume they mistyped their password, rather than suspecting they were phished.
Lures used to drive victims to these pages were routine and low-key, covering password and certificate expiry warnings, access restrictions, delivery failures, timesheet updates, and ICANN verification notices. Campaigns were also observed in multiple languages, including English, German, French, Spanish, Chinese, and Korean, widening the pool of potential targets.
Organizations can reduce the impact of this kind of attack by prioritizing phishing-resistant multifactor authentication, such as FIDO2 keys and passkeys, which bind authentication to the legitimate domain so a fake page cannot present the correct cryptographic challenge. Complementary controls include conditional access rules, browser isolation, and URL filtering capable of flagging newly registered domains and links that carry an email address in the URL path. Employee awareness should reinforce that a convincing, familiar-looking login page is not proof of legitimacy, and that a successful redirect to the real site afterward does not mean the earlier page was safe.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
LogoKit is a phishing-as-a-service platform that builds a unique login page for each victim in real time, pulling a live screenshot of the target organization's own website to use as the page background.
It extracts the victim's email address from the phishing URL, uses the domain to identify their employer, then calls commercial web services to assemble a matching page on the fly.
After credentials are harvested, victims are redirected to the genuine site, where they would likely assume they had mistyped their password the first time, which can reduce suspicion.
Barracuda recommends phishing-resistant MFA such as FIDO2 keys and passkeys, along with conditional access rules, browser isolation, and URL filtering for newly registered domains and links carrying an email address in the path.
You click an email: “Your access is restricted, sign in to confirm your account details.” The login page looks exactly like our site. Behind that page is LogoKit, a phishing kit that grabs your email from the link, pulls a live screenshot of our real site, and builds a fake login just for you, then sends your password out over Telegram. Here’s the trap: you type your password, hit enter, and it instantly redirects you to the real site. You assume you just mistyped, but LogoKit already stole your credentials. A familiar page means nothing, only the domain does. If a link login page isn’t on our exact official domain, stop and report it to Security immediately.

Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations,…

Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google…