Threat Spotlight: LogoKit phishing service becomes a cloud-based, real-time deception platform
Recent innovations in LogoKit signpost the future of phishing-as-a-service (PhaaS).
Key takeaways
- LogoKit has evolved from a standard phishing kit into a real-time deception platform that builds customized phishing pages for each victim.
- The platform uses legitimate commercial web services to recreate a victim’s corporate login experience, making phishing attacks more convincing and harder to detect.
- LogoKit shows how phishing-as-a-service is becoming more automated, personalized and cloud-based, reducing attacker costs while increasing effectiveness.
The evolution of LogoKit highlights how phishing platforms continue to evolve and what this means for defenders and their security strategies.
Barracuda researchers have analyzed recent LogoKit campaigns. The attacks feature common phishing themes, such as warnings about passwords or certificates expiring or other access restrictions, delivery failures, timesheet updates, and ICANN email verification notices — but the techniques used are very different.
Inside a LogoKit attack: From static fakes to real-time environment impersonation
LogoKit has moved beyond static fake login pages, such as pre-built replicas of popular brands, to the creation and use of real-time, highly personalized phishing experiences. Every victim effectively receives a uniquely branded phishing page, making generic indicators of compromise harder to identify.
The attack starts when the victim clicks a phishing link, which includes their email address in the URL. For example:
hxxps[:]//inquisitive45tg-sfus88qnn0aklna8q8q9[.]glitch.me/<victimemail.com>
JavaScript on the phishing page extracts the victim's email address from the URL. It then uses the email domain (for example, company.com) to identify the victim’s organization and customize the phishing page accordingly.
The toolkit dynamically builds phishing pages tailored to each victim, using commercially available tools to retrieve the company logo and capture a real-time screenshot of the victim’s legitimate website. In the attacks analyzed by Barracuda, LogoKit used the commercial Thum.io service to create full, legitimate website screenshots for the phishing background and Clearbit to add legitimate brand logos.
The attackers also use legitimate services including Google Favicon, ImageKit and Microlink APIs to dynamically load authentic logos and website imagery in real time.
This moves beyond traditional “brand impersonation” into “environment impersonation” — where attackers recreate elements of the victim’s real web environment, making phishing pages look much closer to the organization’s genuine login experience.
The screenshots below show the web code of a phishing page, with instructions to inject a screenshot of the victim’s legitimate website domain site in the background, as well as the company logo.
Web code instructions for dynamically inserting the victim organization’s Google Favicon
When the user enters their login credentials into the phishing page, the data is sent directly to a Telegram bot, bypassing the need for a traditional backend server. The victim is then redirected to the real website, making the phishing attempt harder to detect and trace.
By relying on cloud-based services such as Telegram rather than attacker-controlled servers, phishing campaigns become easier to deploy, more resilient and harder for investigators to disrupt.
Credential data exfiltration using Telegram bots
After the victim’s credentials are stolen, the victim is redirected to the legitimate website and may just assume they’d entered their details incorrectly the first time and that everything is now correct.
Multi-language campaigns
LogoKit’s phishing infrastructure can be deployed in multiple languages. Barracuda researchers found attack emails in English, German, French, Spanish, Chinese, and Korean.
How to stay safe
Phishing is an ever-evolving threat, but there are some essential measures that will help keep your organization and employees protected and cyber resilient against both known and emerging risks.
1. Deploy phishing-resistant multifactor authentication (MFA), such as FIDO2 security and passkeys. These are connected to the legitimate website domain. Even if a phishing page perfectly mimics a login portal, the authentication process will fail because the fake domain cannot present the correct cryptographic challenge.
2. Implement access restrictions, including conditional access and risk-based authentication (such as the “impossible travel” rule) — which means that even if credentials are stolen, access for attackers is still restricted based on device trust, user location and behavior and any other signs of an anomalous login.
3. Use browser isolation to open suspicious links in a remote environment before they reach the user’s endpoint.
4. Implement URL and link analysis. These are phishing filters that are focused on known malicious domains. To effectively catch real-time phishing, these filters need to be able to detect newly created domains, lookalike domains, URL fragments containing email addresses, dynamic phishing infrastructure, and suspicious redirects.
5. Verify providers and check for brand impersonation. Many phishing kits abuse legitimate services, so it is important to have security measures in place that verify hosting providers for their domain reputation, page content, user behavior and more — and security that can detect even sophisticated brand impersonation.
6. Train users to verify unusual requests before clicking. At the same time, don’t rely on users spotting bad emails. Real-time phishing attacks look realistic and error-free, so security tools must do more of the detection heavy lifting.
7. Most of all, use continuous, automated, intelligent layered security.
Conclusion
LogoKit illustrates a broader shift in cybercrime: Phishing attacks are becoming increasingly automated, personalized and cloud-based. As attackers adopt the tools and techniques of modern software developers, organizations need security controls that can detect and stop attacks even when the phishing page appears entirely legitimate.
2026 Email Threats Report
Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected
Subscribe to the Barracuda Blog.
Sign up to receive threat spotlights, industry commentary, and more.
The Managed XDR Global Threat Report
Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit