logo

'CoGUI' Phishing Kit Helps Chinese Hackers Target Japan

ID: c3472687-20c3-543c-a5e1-1f1a0eba35dc

STIX ID: report--c3472687-20c3-543c-a5e1-1f1a0eba35dc

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-05-08

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Proofpoint research reveals CoGUI, a China-linked phishing kit used in dozens of high-volume email campaigns that sent hundreds of millions of credential-phishing messages, concentrated on Japanese users; the kit fingerprints victims (IP, OS, language, browser, device type/size), impersonates major brands (Amazon, Apple, Rakuten, financial agencies), and uses diverse sender addresses to evade spam filters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.