Phishing Kit is a tool tracked across 7 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed November 18, 2025; most recent activity July 14, 2026.
Phishing Kit is a cybercrime toolkit used to create and deploy phishing pages for credential harvesting. The latest report notes a new variant targeting Italian entities, suggesting a tailored campaign focus on Italy and highlighting the ongoing evolution of plug-and-play phishing infrastructure. This is significant because it lowers the technical barrier for attackers and increases the potential impact on Italian organizations.
The Google Threat Intelligence Group (GTIG) reported that a financially motivated cybercriminal group, UNC6783, is targeting business process outsourcing (BPO) companies to infiltrate high-value organizations across…
An international cybercrime operation, Operation Synergia III, coordinated by INTERPOL, has dismantled over 45,000 malicious IP addresses and servers linked to phishing, malware, and ransomware attacks. The operation,…
Since April 2026, a threat actor identified as O-UNC-066, also known as 'Pink', has been executing a vishing campaign aimed at Microsoft 365 users. The campaign exploits a new passkey enrollment feature introduced by…
Tyler Buchanan, a 24-year-old from Dundee, Scotland, has pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft in connection with a cyber fraud scheme that targeted at least a dozen companies…
Callum Dare, a 26-year-old from Wales, was sentenced to two years and three months in prison for his role in a dark web network that encouraged swatting incidents in the USA and Canada. Swatting involves making false…
A phishing kit has been identified that impersonates Aruba S.p.A., a major Italian IT and web services provider. This operation aims to deceive users into providing their login credentials, potentially compromising…
A new phishing kit is targeting customers of Aruba S.p.A., an Italian IT and web services provider. Researchers from Group-IB report that the kit impersonates Aruba's login and payment pages to steal user credentials.…