Skip to content

Logokit: Phishing Kit Generates Deceptively Authentic Login Pages in Real Time

The Point: Logokit leverages commercial APIs to generate target-specific phishing pages in real time and forwards stolen credentials via Telegram bot, eliminating the need for downstream infrastructure.

The Phishing-as-a-Service platform Logokit creates individual login pages for each victim at the moment of access. This significantly complicates automated detection, as no static templates exist anymore.

The Logokit platform has fundamentally changed its attack method. When clicking on a prepared phishing link, the victim’s email address is read from the URL. Embedded code uses the domain to identify the target organization and dynamically customize the phishing page. Instead of using pre-built templates, Logokit calls multiple commercial services during page retrieval: Thum.io generates a current screenshot of the legitimate company website as a background, while Clearbit, Google Favicon, ImageKit, and the Microlink API provide matching logos and icons.

Each generated page is thus created anew at the moment of access and corresponds deceptively precisely to the appearance of the actual company login page. Security systems that rely on static indicators can barely detect these pages automatically. When the victim enters credentials, they are immediately transmitted to a Telegram bot. By doing so, attackers dispense with their own backend infrastructure that could potentially be discovered. The victim is then redirected to the legitimate website and often assumes they simply mistyped something – which further delays detection of the attack.

Barracuda has documented Logokit campaigns in English, German, French, Spanish, Chinese, and Korean. Attackers use classic pretexts such as expiring passwords, certificate renewals, account lockouts, or notifications about time tracking. Sachin Meti, Threat Analysis Associate at Barracuda, summarizes the development: “Logokit has evolved from brand imitation to real-time environment imitation. At the same time, attackers require less infrastructure for their attacks, making them more convincing and harder to detect.”

Barracuda recommends a multi-layered security approach: automated threat detection, phishing-resistant multi-factor authentication (particularly FIDO2 security keys and passkeys), as well as risk-based access controls that assess device trustworthiness, location, and user behavior. Additionally, suspicious links should be opened in isolated remote environments and automatically checked before they are executed on user devices.


Source: www.it-daily.net · Published 31 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: