LogoKit Phishing-as-a-Service: Victim-Branded Credential Pages with Telegram Exfiltration
Source report →LogoKit is a phishing-as-a-service platform designed to generate tailored credential-harvesting pages for individual victims. Campaigns typically use phishing emails as the initial delivery vector, presenting routine administrative lures such as password expiry, access restriction, or email verification notices and directing recipients to a malicious link. When a recipient follows the link, JavaScript extracts their email address from the URL, isolates the domain associated with their organisation, and uses it to brand the credential-harvesting page.
At page load, LogoKit uses legitimate commercial APIs to retrieve branding assets and website imagery associated with the victim's organisation, creating a victim-specific imitation of its login environment rather than a generic phishing template. Credentials are exfiltrated directly from the victim's browser to a Telegram bot, without passing through an attacker-controlled server. The victim is then redirected to the legitimate website of the impersonated organisation, helping the interaction appear normal after credential submission.
Vega Threat Research developed a method for enumerating LogoKit infrastructure. While each victim receives a uniquely branded page, the underlying workflow used to produce it remains consistent. Across dynamically branded deployments, the same core sequence was observed: extract an email address from the URL, derive the organisation's domain, query third-party services for domain-specific branding, present a credential form, and exfiltrate submitted credentials through a separate channel such as Telegram. Vega pivoted on branding-service calls and credential-form behaviour exposed in client-side HTML and page-load requests, identifying deployments across multiple themes and hosting platforms. This approach targets functional characteristics of the kit rather than campaign-specific artefacts, enabling broader discovery across LogoKit variants without tying it to individual campaigns.
Vega queried public scanning and indexing services to identify candidate LogoKit pages, then validated them against the functional characteristics described above. This process identified 148 distinct hosts across a wide range of environments, including disposable hosting platforms, object storage, IPFS gateways, static-site and preview services, container platforms, and compromised legitimate websites. The analysis also recovered 117 distinct Telegram bot identifiers used for exfiltration, with limited reuse across hosts. This fragmentation suggests multiple independent users of a shared phishing service rather than a single operator, and makes exfiltration identifiers a useful clustering mechanism for separating individual LogoKit operations.
IOCs (109)
Scan your environment for IOCs →DOMAIN 109
inquisitive45tg-sfus88qnn0aklna8q8q9.glitch.mealldbgdhhdhhdhhhchhchdhdm-dp9hzij3r3mr.edgeone.devbnmasdcxzopqweuryuijdkdm127373u484900376.edgeone.devbrave-tan-h4doupvw.edgeone.devcancel-password-reset.edgeone.devcheerful-rose-tkryjfc0.edgeone.devdetailed-magenta-yarmx8ve.edgeone.devdomain-dpgqiutb5rby.edgeone.devenormous-apricot-bhhnh1v5.edgeone.deves4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.devevolutionary-amethyst-kvkid93g.edgeone.devfrozen-emerald-q41rlk77.edgeone.devgastric-rose-hwpw4awz.edgeone.devgastric-turquoise-uqpzxsmk.edgeone.devghoaspanmacopicv3784648402022727363690303.edgeone.devhelpful-teal-wemfvl3j.edgeone.devimmense-crimson-4bnmix7f.edgeone.devkhjfdgsfsdfhjklljdhgdstryt-dp97141gwv85.edgeone.devkloclibkblink-dp73tqm8r6w5.edgeone.devlimitlessdubai-dp8oxsl60kva.edgeone.devm93g57n8y-dpi68p6e0a00.edgeone.devmailalert.edgeone.devmailbox-dp8ra6c793ra.edgeone.devmailbox-dpkjr4w7vaw1.edgeone.devmailbox-dpr3yixp1qk1.edgeone.devmailupdate.edgeone.devmass-orange-drrrexhk.edgeone.devmisty-bronze-40q0z2bk.edgeone.devportalportalportalportalportal.edgeone.devpromt-dpem7p8ov9s7.edgeone.devpsychological-jade-hbaygccq.edgeone.devscreenshot-jpg.edgeone.devsecure-portal-email.edgeone.devseparate-apricot-hbdffwuz.edgeone.devseri3sawsapprunner-south1-dpkkvw2rkadj.edgeone.devsmiling-bronze-ybcsxxoi.edgeone.devsmilling-long-pannel.edgeone.devupgrade-dp2c1xqj8ejo.edgeone.devverifyemail.edgeone.devvital-amethyst-wjjum5ly.edgeone.devvocational-teal-faxe8a7k.edgeone.devwatery-pink-ycvk2lnd.edgeone.devwedfgbnmoijhgcxvbnm-dpyjx01bl5o7.edgeone.devyourmailaccount.edgeone.dev69faf1f96e16da18b0206fec--chimerical-custard-0c06e1.netlify.app6a018e4588b9f91c8adf0a0b--velvety-churros-49cd43.netlify.appanimated-strudel-d6cdc1.netlify.apparboedu.netlify.appawsweb3apprunner-east0nsitecom.netlify.appcool-concha-3432a2.netlify.appdynamic-yeot-cfe7fa.netlify.appharmonious-marzipan-3f75d2.netlify.appluxury-granita-7237f5.netlify.appmagnificent-arithmetic-3b7216.netlify.appsmtp-authentication-resolve.netlify.appspiffy-pastelito-451dcc.netlify.apptranscendent-quokka-c4c95c.netlify.app0zhngobxnphel0nm-awsapprunner-eq68mu6o5m.edgeone.appcolossal-crimson-l6tdfk7yjh-v6yq13mc72.edgeone.appextra-cyan-zfxl6ma9.edgeone.appfriendly-indigo-f946zusu.edgeone.appsore-indigo-cf1xx4cwja.edgeone.appvaluable-purple-sibu8izm.edgeone.appsaa-s-team-board--technical50.replit.appsecure-documents--files056.replit.appsecure-page-builder--bigpride007.replit.appsecure-site-editor--ceo303.replit.appsecurity-server-page--45678ghj.replit.appserver-docs--scottotf6.replit.appeng650.vercel.appglobal-server-mail.vercel.apponline-secured-access-webmail-confi.vercel.appswvcnm.vercel.appyduwe9r783893392454rf893789ry435645.vercel.appyuixszc.vercel.apppub-2cf86f24b7384ade85d6d431d056254f.r2.devpub-514416403cf64410be0659fb6d5dcdae.r2.devpub-d9445484dc8d4d02a9f12e2341cb5f86.r2.devpub-ef8ace0b5fa0490685d23a3ec77c7d6c.r2.devloveleadsfed-xlcbug2t-petermurphyprivate7-hub.ipfs.4everland.appwebmail-verification-dthojnuj.4everland.appcpecctrummed.github.iofreekickmatch.github.iokor-b8c.pages.devoutlook-production-3689.up.railway.appwebmail-general-session-login1-cuddly-tribble-production.up.railway.apppub-b0349419d21d4a6593fcf8e3fc835.3-a.netwebupgrade394949-dp94sdn9spre.edgeone.coolportserv.s-drc2.cloud.gcore.lupaint-hypnotic-juravenator.glitch.mekryfkreeds.safeserviceaccess.liveblue-tasha-98.tiiny.siteauthy-dpvhz0r23dsk.edgeone.devdocuignsecurddocslfvnuvybfudbvecw-dp5zpgabs840.edgeone.devdocusign-dpd8r8ehxk65.edgeone.devintegrated-brown-wtbhrktn.edgeone.devrelative-blush-o9uhdnja.edgeone.devomlacto-dpwdhzrqnk58.edgeone.devsatisfactory-tomato-cldxywz1.edgeone.devcomprehensive-copper-7dnhfaml.edgeone.devjjddfasdfghgfdfg-dp1b66t5kkiw.edgeone.devdre0806-dpi60k9pni2n.edgeone.devcautious-rose-mbp7zghc.edgeone.devearly-harlequin-utnj57ge.edgeone.appeligible-fuchsia-ya6pp7uq.edgeone.approoysajdgdhjdd.edgeone.appgrrufddfldhlfhhhzvhheng-dpq0qvgctt9r.edgeone.devdemocratic-maroon-rtwqfcc0.edgeone.devaccessible-white-mabjgchs.edgeone.devDetections (6)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- Device Contacting Third Party Branding and IP Lookup Services
- Browser Process Connecting to the Telegram Bot API
- Known Phishing Campaign Email Delivered
- Flag suspicious links in messages that impersonate legitimate services or internal tools
- Monitor for large outbound data transfers to web services such as MEGA, Dropbox, or cloud storage APIs