← All briefs
high August 18, 2026

LogoKit Phishing-as-a-Service: Victim-Branded Credential Pages with Telegram Exfiltration

Source report →

LogoKit is a phishing-as-a-service platform designed to generate tailored credential-harvesting pages for individual victims. Campaigns typically use phishing emails as the initial delivery vector, presenting routine administrative lures such as password expiry, access restriction, or email verification notices and directing recipients to a malicious link. When a recipient follows the link, JavaScript extracts their email address from the URL, isolates the domain associated with their organisation, and uses it to brand the credential-harvesting page.

At page load, LogoKit uses legitimate commercial APIs to retrieve branding assets and website imagery associated with the victim's organisation, creating a victim-specific imitation of its login environment rather than a generic phishing template. Credentials are exfiltrated directly from the victim's browser to a Telegram bot, without passing through an attacker-controlled server. The victim is then redirected to the legitimate website of the impersonated organisation, helping the interaction appear normal after credential submission.

Vega Threat Research developed a method for enumerating LogoKit infrastructure. While each victim receives a uniquely branded page, the underlying workflow used to produce it remains consistent. Across dynamically branded deployments, the same core sequence was observed: extract an email address from the URL, derive the organisation's domain, query third-party services for domain-specific branding, present a credential form, and exfiltrate submitted credentials through a separate channel such as Telegram. Vega pivoted on branding-service calls and credential-form behaviour exposed in client-side HTML and page-load requests, identifying deployments across multiple themes and hosting platforms. This approach targets functional characteristics of the kit rather than campaign-specific artefacts, enabling broader discovery across LogoKit variants without tying it to individual campaigns.

Vega queried public scanning and indexing services to identify candidate LogoKit pages, then validated them against the functional characteristics described above. This process identified 148 distinct hosts across a wide range of environments, including disposable hosting platforms, object storage, IPFS gateways, static-site and preview services, container platforms, and compromised legitimate websites. The analysis also recovered 117 distinct Telegram bot identifiers used for exfiltration, with limited reuse across hosts. This fragmentation suggests multiple independent users of a shared phishing service rather than a single operator, and makes exfiltration identifiers a useful clustering mechanism for separating individual LogoKit operations.

DOMAIN 109
inquisitive45tg-sfus88qnn0aklna8q8q9.glitch.me
alldbgdhhdhhdhhhchhchdhdm-dp9hzij3r3mr.edgeone.dev
bnmasdcxzopqweuryuijdkdm127373u484900376.edgeone.dev
brave-tan-h4doupvw.edgeone.dev
cancel-password-reset.edgeone.dev
cheerful-rose-tkryjfc0.edgeone.dev
detailed-magenta-yarmx8ve.edgeone.dev
domain-dpgqiutb5rby.edgeone.dev
enormous-apricot-bhhnh1v5.edgeone.dev
es4dr56tyuikdf6g-dp9xyf4hhc53.edgeone.dev
evolutionary-amethyst-kvkid93g.edgeone.dev
frozen-emerald-q41rlk77.edgeone.dev
gastric-rose-hwpw4awz.edgeone.dev
gastric-turquoise-uqpzxsmk.edgeone.dev
ghoaspanmacopicv3784648402022727363690303.edgeone.dev
helpful-teal-wemfvl3j.edgeone.dev
immense-crimson-4bnmix7f.edgeone.dev
khjfdgsfsdfhjklljdhgdstryt-dp97141gwv85.edgeone.dev
kloclibkblink-dp73tqm8r6w5.edgeone.dev
limitlessdubai-dp8oxsl60kva.edgeone.dev
m93g57n8y-dpi68p6e0a00.edgeone.dev
mailalert.edgeone.dev
mailbox-dp8ra6c793ra.edgeone.dev
mailbox-dpkjr4w7vaw1.edgeone.dev
mailbox-dpr3yixp1qk1.edgeone.dev
mailupdate.edgeone.dev
mass-orange-drrrexhk.edgeone.dev
misty-bronze-40q0z2bk.edgeone.dev
portalportalportalportalportal.edgeone.dev
promt-dpem7p8ov9s7.edgeone.dev
psychological-jade-hbaygccq.edgeone.dev
screenshot-jpg.edgeone.dev
secure-portal-email.edgeone.dev
separate-apricot-hbdffwuz.edgeone.dev
seri3sawsapprunner-south1-dpkkvw2rkadj.edgeone.dev
smiling-bronze-ybcsxxoi.edgeone.dev
smilling-long-pannel.edgeone.dev
upgrade-dp2c1xqj8ejo.edgeone.dev
verifyemail.edgeone.dev
vital-amethyst-wjjum5ly.edgeone.dev
vocational-teal-faxe8a7k.edgeone.dev
watery-pink-ycvk2lnd.edgeone.dev
wedfgbnmoijhgcxvbnm-dpyjx01bl5o7.edgeone.dev
yourmailaccount.edgeone.dev
69faf1f96e16da18b0206fec--chimerical-custard-0c06e1.netlify.app
6a018e4588b9f91c8adf0a0b--velvety-churros-49cd43.netlify.app
animated-strudel-d6cdc1.netlify.app
arboedu.netlify.app
awsweb3apprunner-east0nsitecom.netlify.app
cool-concha-3432a2.netlify.app
dynamic-yeot-cfe7fa.netlify.app
harmonious-marzipan-3f75d2.netlify.app
luxury-granita-7237f5.netlify.app
magnificent-arithmetic-3b7216.netlify.app
smtp-authentication-resolve.netlify.app
spiffy-pastelito-451dcc.netlify.app
transcendent-quokka-c4c95c.netlify.app
0zhngobxnphel0nm-awsapprunner-eq68mu6o5m.edgeone.app
colossal-crimson-l6tdfk7yjh-v6yq13mc72.edgeone.app
extra-cyan-zfxl6ma9.edgeone.app
friendly-indigo-f946zusu.edgeone.app
sore-indigo-cf1xx4cwja.edgeone.app
valuable-purple-sibu8izm.edgeone.app
saa-s-team-board--technical50.replit.app
secure-documents--files056.replit.app
secure-page-builder--bigpride007.replit.app
secure-site-editor--ceo303.replit.app
security-server-page--45678ghj.replit.app
server-docs--scottotf6.replit.app
eng650.vercel.app
global-server-mail.vercel.app
online-secured-access-webmail-confi.vercel.app
swvcnm.vercel.app
yduwe9r783893392454rf893789ry435645.vercel.app
yuixszc.vercel.app
pub-2cf86f24b7384ade85d6d431d056254f.r2.dev
pub-514416403cf64410be0659fb6d5dcdae.r2.dev
pub-d9445484dc8d4d02a9f12e2341cb5f86.r2.dev
pub-ef8ace0b5fa0490685d23a3ec77c7d6c.r2.dev
loveleadsfed-xlcbug2t-petermurphyprivate7-hub.ipfs.4everland.app
webmail-verification-dthojnuj.4everland.app
cpecctrummed.github.io
freekickmatch.github.io
kor-b8c.pages.dev
outlook-production-3689.up.railway.app
webmail-general-session-login1-cuddly-tribble-production.up.railway.app
pub-b0349419d21d4a6593fcf8e3fc835.3-a.net
webupgrade394949-dp94sdn9spre.edgeone.cool
portserv.s-drc2.cloud.gcore.lu
paint-hypnotic-juravenator.glitch.me
kryfkreeds.safeserviceaccess.live
blue-tasha-98.tiiny.site
authy-dpvhz0r23dsk.edgeone.dev
docuignsecurddocslfvnuvybfudbvecw-dp5zpgabs840.edgeone.dev
docusign-dpd8r8ehxk65.edgeone.dev
integrated-brown-wtbhrktn.edgeone.dev
relative-blush-o9uhdnja.edgeone.dev
omlacto-dpwdhzrqnk58.edgeone.dev
satisfactory-tomato-cldxywz1.edgeone.dev
comprehensive-copper-7dnhfaml.edgeone.dev
jjddfasdfghgfdfg-dp1b66t5kkiw.edgeone.dev
dre0806-dpi60k9pni2n.edgeone.dev
cautious-rose-mbp7zghc.edgeone.dev
early-harlequin-utnj57ge.edgeone.app
eligible-fuchsia-ya6pp7uq.edgeone.app
rooysajdgdhjdd.edgeone.app
grrufddfldhlfhhhzvhheng-dpq0qvgctt9r.edgeone.dev
democratic-maroon-rtwqfcc0.edgeone.dev
accessible-white-mabjgchs.edgeone.dev

Detections (6)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • Device Contacting Third Party Branding and IP Lookup Services
  • Browser Process Connecting to the Telegram Bot API
  • Known Phishing Campaign Email Delivered
  • Flag suspicious links in messages that impersonate legitimate services or internal tools
  • Monitor for large outbound data transfers to web services such as MEGA, Dropbox, or cloud storage APIs