CoGUI phishing platform sent 580 million emails to steal credentials
ID: 6df138bd-94ec-5774-8b45-9b029e487b04
STIX ID: report--6df138bd-94ec-5774-8b45-9b029e487b04
Feed Name: Bleeping Computer
Proofpoint researchers uncovered the CoGUI phishing kit, used since at least October 2024 to send more than 580 million phishing emails between January and April 2025 (with ~172 million in January alone), primarily targeting Japanese users. The campaign impersonates major brands and uses pre-defined targeting criteria (IP location, browser language, OS, screen resolution, device type) to serve convincing fake login pages that harvest credentials and payment data; operators also ran smishing campaigns in the U.S. and the kit is attributed to multiple China-linked cybercriminal actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
