IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Logokit phishing kit builds real-time fake login pages

Logokit phishing kit builds real-time fake login pages

Thu, 30th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

LogoKit has evolved from a conventional phishing kit into a cloud-based platform that generates customised phishing pages for individual victims in real time, according to new research from Barracuda.

The researchers said the phishing-as-a-service platform now creates tailored login pages by combining information from a victim's email address with content retrieved from legitimate commercial web services. The approach allows attackers to closely replicate an organisation's genuine online environment rather than relying on static copies of well-known brands.

The findings indicate a shift in phishing operations towards greater automation and personalisation. They also show how attackers are reducing infrastructure costs by relying on cloud services while making campaigns more difficult to identify and disrupt.

Attack method

A LogoKit attack begins when a target clicks a phishing link containing their email address within the URL.

JavaScript embedded in the phishing page extracts the email address and identifies the organisation by analysing the domain name. The platform then assembles a phishing page specifically for that organisation.

Instead of relying on pre-built login pages, LogoKit retrieves branding and website content dynamically. Barracuda observed the platform using commercial services to obtain company logos and current website imagery before displaying a page designed to resemble the victim's legitimate login environment.

Among the services identified were Thum.io for generating screenshots of genuine websites and Clearbit for retrieving company branding. Researchers also found the phishing kit using Google Favicon, ImageKit and Microlink APIs to load authentic logos and other website elements in real time.

The result is an attack that recreates elements of a company's actual web presence rather than simply imitating its visual identity.

Barracuda described this as a move from traditional brand impersonation towards environment impersonation, where phishing pages closely mirror the appearance of the genuine websites users expect to access.

Cloud delivery

Once a victim submits login credentials, the information is sent directly to a Telegram bot instead of a conventional attacker-controlled server.

The victim is then redirected to the legitimate website. This sequence reduces the likelihood that users will immediately recognise they have submitted credentials to a fraudulent page.

Researchers said the use of Telegram and other cloud-based services reduces the infrastructure required to operate phishing campaigns. It also makes operations more resilient because attackers no longer depend on maintaining dedicated backend servers that can be identified and taken offline.

The cloud-based architecture allows phishing campaigns to be deployed more quickly while complicating efforts by investigators to disrupt the underlying infrastructure.

The findings also suggest that phishing operators are increasingly adopting techniques commonly associated with cloud-native software development by integrating multiple third-party services into automated attack workflows.

Global reach

Barracuda found LogoKit campaigns operating across multiple languages, indicating that the platform is designed to support international phishing operations.

Attack emails examined during the research were written in English, German, French, Spanish, Chinese and Korean.

The multilingual capability allows operators to target organisations and users across different regions without requiring separate phishing infrastructures for each language.

Combined with dynamic branding and cloud-hosted components, this enables phishing campaigns to scale while maintaining a high degree of personalisation for individual victims.

Defensive measures

Barracuda recommends organisations deploy phishing-resistant multi-factor authentication, including FIDO2 security keys and passkeys, to reduce the impact of credential theft.

The company also advises implementing conditional access controls and risk-based authentication policies, including impossible travel detection, to identify suspicious login attempts.

Additional recommendations include browser isolation for suspicious links, URL analysis that focuses on newly registered and lookalike domains, and monitoring for phishing infrastructure that embeds email addresses within URLs or uses suspicious redirects.

Barracuda also recommends verifying service providers and checking for brand impersonation attempts while training users to confirm unexpected requests before interacting with links.

The researchers said organisations should rely on layered security controls capable of detecting phishing activity even when fraudulent pages closely resemble legitimate websites.