LogoKit Phishing Kit Screenshots Victim Sites in Real Time

A new phishing-as-a-service platform called LogoKit is using real-time screenshots of target websites to create highly convincing, personalized login pages. By leveraging commercial cloud services and APIs, the attackers can bypass traditional static detection methods.
Why it matters
This evolution in phishing tactics demonstrates how attackers are using legitimate cloud infrastructure to increase the sophistication and success rate of credential harvesting.
A phishing-as-a-service (PaaS) platform has been observed building a unique login page for each victim in real time, pulling a live screenshot of the target organization's own website to use as the page background.
According to new research from Barracuda published on July 29, recent LogoKit campaigns extracted the victim's email address from the phishing URL, used the domain to identify their employer, then called commercial web services to assemble a matching page on the fly.
RiskIQ, which named the phishing kit in 2021, found it was already pulling brand logos from Clearbit and already carrying the victim's email address in the URL.
What has changed is the live website screenshot, which Barracuda described as a shift from brand impersonation to environment impersonation, recreating parts of the victim's genuine web environment rather than serving a generic replica.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in