LogoKit Phishing Kit Targeting Governments and Organizations

Published:

spot_img

Recent Phishing Campaign Targets Hungarian Government Officials

Cyble’s threat intelligence team has uncovered a phishing campaign specifically targeting Hungarian government entities. Their investigation suggests that this operation is part of a broader global effort aimed at the banking and logistics sectors, according to their recent blog post.

How the Phishing Campaign Works

The researchers identified the initial phishing link, which redirected users to a counterfeit login page for HunCERT, Hungary’s Computer Emergency Response Team. Notably, this deceptive link automatically filled in the username field with the victim’s email address, significantly increasing the likelihood of credential theft.

Utilizing the LogoKit phishing kit, the malicious links were hosted on Amazon S3 (AWS) to evade detection and enhance their credibility. Cyble pointed out that integrating Cloudflare Turnstile into the fake pages likely contributed to their perceived legitimacy.

These measures might have helped the domain evade detection, as the researchers found no alerts on VirusTotal during their analysis.

Insights into the LogoKit Phishing Kit

The research team at Cyble discovered that the phishing URLs employed in this campaign incorporated a legitimate HunCERT email address in the username field. They cited two specific phishing URLs that were utilized:

  • flyplabtk[.]s3.us-east-2.amazonaws.com/q8T1vRzW3L7XpK0Mb9CfN6hJ2sUYgZAxewoQpHDVlt5BmnEjOrGiScFuYXdAv349/[email protected]
  • flyplabtk[.]s3.us-east-2.amazonaws.com/q8T1vRzW3L7XpK0Mb9CfN6hJ2sUYgZAxewoQpHDVlt5BmnEjOrGiScFuYXdAv349/[email protected]

As stated by Cyble, the phishing page was crafted to closely mimic a legitimate login portal. Additionally, the presence of the Cloudflare Turnstile verification led victims to believe the page was secure, further entrenching the deception.

Technical Sophistication Behind the Attack

The phishing site employed the Clearbit Logo API to fetch logos from targeted organizations, while Google’s S2 Favicon was used to retrieve Favicon icons based on the domain extracted from the email. This advanced use of technology is one reason why the LogoKit phishing kit remains prevalent in various phishing attacks.

Cyble researchers noted, “LogoKit’s effectiveness stems from its automation and simplicity. By pulling branding icons in real-time based on listed domains, cybercriminals can minimize manual updates, making their operations more convincing and scalable.”

Victim credentials are channeled to mettcoint[.]com/js/error-200.php. This domain contains an open directory that includes numerous .php files and other attack elements. In one instance, they identified a phishing page impersonating the WeTransfer file-sharing service.

Due to OSINT investigations, it was revealed that mettcoint[.]com has been associated with prior phishing incidents. Other victims of this ongoing phishing campaign include the Kina Bank in Papua New Guinea and even entities within the Catholic Church in the U.S. as well as logistics firms in Saudi Arabia. Interestingly, mettcoint[.]com was registered in October 2024 and has been operational for phishing endeavors since February 2025.

“It’s worth noting that this domain currently has no detections on VirusTotal,” Cyble mentioned. “This allows it to operate unnoticed. As it stands, the domain remains active, indicating that the phishing campaign is still ongoing and targeting victims worldwide.”

Strategies for Mitigating Phishing Risks

Insights from Cyble underscore significant gaps in existing cybersecurity measures. The report emphasizes the human aspect as both the strongest and weakest link in cybersecurity. “Caution and responsibility in online behavior can prevent many cyber threats,” the researchers advocate. However, campaigns like this exploit human trust, posing risks even to well-informed individuals.

Alongside utilizing threat intelligence solutions to identify and block potential threats, Cyble offers several best practices to bolster defenses against phishing:

  • Remain cautious about links received via SMS or emails.
  • Implement robust antivirus and internet security software on all devices.
  • Educate employees about recognizing phishing threats and untrusted URLs.
  • Use secure email gateways to block phishing emails containing malicious attachments or links.
  • Employ multi-factor authentication (MFA) to safeguard against credential exploitation.
  • Monitor for unusual login activity or access attempts from suspicious IP addresses.
  • Regularly update devices, operating systems, and applications to patch vulnerabilities.
spot_img

Related articles

Recent articles

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...

Quantum Cybersecurity Careers Emerge as Top Job Opportunity for the Next Decade

Guest Post By Sudiptaa Paul Choudhury is Chief Marketing Officer at QNu Labs, a global leader in quantum cybersecurity, TEDx speaker and a LinkedIn...

CVE-2025-66376 Exploited in Russian Cyberespionage Campaign Targeting Zimbra Webmail

Unit 42 has issued an advisory regarding a persistent cyberespionage campaign identified as CL-STA-1114, which targets Zimbra webmail systems. This campaign is attributed to...

New macOS malware exploits Telegram sessions to target cryptocurrency wallets, warns SlowMist

Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware...