Recent Phishing Campaign Targets Hungarian Government Officials
Cyble’s threat intelligence team has uncovered a phishing campaign specifically targeting Hungarian government entities. Their investigation suggests that this operation is part of a broader global effort aimed at the banking and logistics sectors, according to their recent blog post.
How the Phishing Campaign Works
The researchers identified the initial phishing link, which redirected users to a counterfeit login page for HunCERT, Hungary’s Computer Emergency Response Team. Notably, this deceptive link automatically filled in the username field with the victim’s email address, significantly increasing the likelihood of credential theft.
Utilizing the LogoKit phishing kit, the malicious links were hosted on Amazon S3 (AWS) to evade detection and enhance their credibility. Cyble pointed out that integrating Cloudflare Turnstile into the fake pages likely contributed to their perceived legitimacy.
These measures might have helped the domain evade detection, as the researchers found no alerts on VirusTotal during their analysis.
Insights into the LogoKit Phishing Kit
The research team at Cyble discovered that the phishing URLs employed in this campaign incorporated a legitimate HunCERT email address in the username field. They cited two specific phishing URLs that were utilized:
- flyplabtk[.]s3.us-east-2.amazonaws.com/q8T1vRzW3L7XpK0Mb9CfN6hJ2sUYgZAxewoQpHDVlt5BmnEjOrGiScFuYXdAv349/[email protected]
- flyplabtk[.]s3.us-east-2.amazonaws.com/q8T1vRzW3L7XpK0Mb9CfN6hJ2sUYgZAxewoQpHDVlt5BmnEjOrGiScFuYXdAv349/[email protected]
As stated by Cyble, the phishing page was crafted to closely mimic a legitimate login portal. Additionally, the presence of the Cloudflare Turnstile verification led victims to believe the page was secure, further entrenching the deception.
Technical Sophistication Behind the Attack
The phishing site employed the Clearbit Logo API to fetch logos from targeted organizations, while Google’s S2 Favicon was used to retrieve Favicon icons based on the domain extracted from the email. This advanced use of technology is one reason why the LogoKit phishing kit remains prevalent in various phishing attacks.
Cyble researchers noted, “LogoKit’s effectiveness stems from its automation and simplicity. By pulling branding icons in real-time based on listed domains, cybercriminals can minimize manual updates, making their operations more convincing and scalable.”
Victim credentials are channeled to mettcoint[.]com/js/error-200.php. This domain contains an open directory that includes numerous .php files and other attack elements. In one instance, they identified a phishing page impersonating the WeTransfer file-sharing service.
Due to OSINT investigations, it was revealed that mettcoint[.]com has been associated with prior phishing incidents. Other victims of this ongoing phishing campaign include the Kina Bank in Papua New Guinea and even entities within the Catholic Church in the U.S. as well as logistics firms in Saudi Arabia. Interestingly, mettcoint[.]com was registered in October 2024 and has been operational for phishing endeavors since February 2025.
“It’s worth noting that this domain currently has no detections on VirusTotal,” Cyble mentioned. “This allows it to operate unnoticed. As it stands, the domain remains active, indicating that the phishing campaign is still ongoing and targeting victims worldwide.”
Strategies for Mitigating Phishing Risks
Insights from Cyble underscore significant gaps in existing cybersecurity measures. The report emphasizes the human aspect as both the strongest and weakest link in cybersecurity. “Caution and responsibility in online behavior can prevent many cyber threats,” the researchers advocate. However, campaigns like this exploit human trust, posing risks even to well-informed individuals.
Alongside utilizing threat intelligence solutions to identify and block potential threats, Cyble offers several best practices to bolster defenses against phishing:
- Remain cautious about links received via SMS or emails.
- Implement robust antivirus and internet security software on all devices.
- Educate employees about recognizing phishing threats and untrusted URLs.
- Use secure email gateways to block phishing emails containing malicious attachments or links.
- Employ multi-factor authentication (MFA) to safeguard against credential exploitation.
- Monitor for unusual login activity or access attempts from suspicious IP addresses.
- Regularly update devices, operating systems, and applications to patch vulnerabilities.


