Multiple GoPhish Login Pages Detected on Various IPs

Multiple GoPhish Login Pages Detected on Various IPs

First seen 10 Sep 2026, 02:46 UTC Redpacketsecurity 36.9

Article Content

Browse articles
ThreatCluster

On September 9, 2026, three separate GoPhish login pages were detected on different IP addresses: 147.182.240.74:3333, 46.101.186.27:3333, and 206.189.236.109:9090. These pages are suspected to be part of phishing campaigns targeting users by mimicking legitimate login interfaces. The detection was reported by RedPacket Security, which cautioned that the status of these pages may change over time and could potentially be false positives. As of the latest updates on September 10, 2026, users are advised to validate the information independently. The scope of impact is currently unclear, but organizations should remain vigilant against potential phishing attempts linked to these IPs.

Key Points: • Three GoPhish login pages detected on different IP addresses. • Detection reported by RedPacket Security on September 9 and 10, 2026. • Users advised to validate the information independently due to potential false positives.

Ask AI about this cluster

Timeline

2026-09-09
GoPhish login page detected on 46.101.186.27:3333
RedPacket Security reported the detection of a phishing login page on this IP address.
Redpacketsecurity
2026-09-09
GoPhish login page detected on 206.189.236.109:9090
Another phishing login page was identified on this IP address, also reported by RedPacket Security.
Redpacketsecurity
2026-09-10
GoPhish login page detected on 147.182.240.74:3333
A third phishing login page was reported on this IP address, with similar warnings about potential false positives.
Redpacketsecurity