logo

CoGUI phishing platform sent 580 million emails to steal credentials

ID: 6df138bd-94ec-5774-8b45-9b029e487b04

STIX ID: report--6df138bd-94ec-5774-8b45-9b029e487b04

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-05-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Proofpoint researchers uncovered the CoGUI phishing kit, used since at least October 2024 to send more than 580 million phishing emails between January and April 2025 (with ~172 million in January alone), primarily targeting Japanese users. The campaign impersonates major brands and uses pre-defined targeting criteria (IP location, browser language, OS, screen resolution, device type) to serve convincing fake login pages that harvest credentials and payment data; operators also ran smishing campaigns in the U.S. and the kit is attributed to multiple China-linked cybercriminal actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.