logo

LogoKit Being Leveraged For Credential Theft

ID: 76ce048e-c813-5464-889e-a195eb87342a

STIX ID: report--76ce048e-c813-5464-889e-a195eb87342a

Feed Name: Cyble Blog

Threat Score
60/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

This report details an ongoing LogoKit-based phishing campaign impersonating trusted entities (including HunCERT, Kina Bank and charities) that hosts credential-harvesting pages on Amazon S3, uses Cloudflare Turnstile and dynamic logo/favicon fetching via Clearbit/Google to increase legitimacy, and exfiltrates credentials to mettcoint.com; the domain was registered October 2024, active since February 2025, and currently has zero VirusTotal detections, with several phishing URLs and PHP endpoints provided as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.