Phishing Kit - Tool

Threat entity extracted from intelligence sources

Frequency
12
occurrences
First Seen
November 18, 2025
Last Seen
July 14, 2026

Phishing Kit is a tool tracked across 7 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed November 18, 2025; most recent activity July 14, 2026.

Overview

Phishing Kit is a cybercrime toolkit used to create and deploy phishing pages for credential harvesting. The latest report notes a new variant targeting Italian entities, suggesting a tailored campaign focus on Italy and highlighting the ongoing evolution of plug-and-play phishing infrastructure. This is significant because it lowers the technical barrier for attackers and increases the potential impact on Italian organizations.

Related Threat Clusters

  • UNC6783 Exploits BPOs for Data Extortion via Phishing Campaigns

    The Google Threat Intelligence Group (GTIG) reported that a financially motivated cybercriminal group, UNC6783, is targeting business process outsourcing (BPO) companies to infiltrate high-value organizations across…

    8 articles · Updated April 8, 2026
  • Operation Synergia III Dismantles 45,000 Malicious IPs, Arrests 94 Worldwide

    An international cybercrime operation, Operation Synergia III, coordinated by INTERPOL, has dismantled over 45,000 malicious IP addresses and servers linked to phishing, malware, and ransomware attacks. The operation,…

    29 articles · Updated March 13, 2026
  • Vishing Campaign Targets Microsoft 365 Passkey Enrollment Process

    Since April 2026, a threat actor identified as O-UNC-066, also known as 'Pink', has been executing a vishing campaign aimed at Microsoft 365 users. The campaign exploits a new passkey enrollment feature introduced by…

    13 articles · Updated July 8, 2026
  • Scottish Man Pleads Guilty in $8 Million US Cyber Fraud Scheme

    Tyler Buchanan, a 24-year-old from Dundee, Scotland, has pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft in connection with a cyber fraud scheme that targeted at least a dozen companies…

    27 articles · Updated April 18, 2026
  • Welsh Man Sentenced for Encouraging Swatting via Dark Web

    Callum Dare, a 26-year-old from Wales, was sentenced to two years and three months in prison for his role in a dark web network that encouraged swatting incidents in the USA and Canada. Swatting involves making false…

    7 articles · Updated July 14, 2026
  • Phishing Kit Targets Aruba Customers in Italy

    A phishing kit has been identified that impersonates Aruba S.p.A., a major Italian IT and web services provider. This operation aims to deceive users into providing their login credentials, potentially compromising…

    2 articles · Updated November 18, 2025
  • Phishing Kit Targets Aruba Customers in Italy

    A new phishing kit is targeting customers of Aruba S.p.A., an Italian IT and web services provider. Researchers from Group-IB report that the kit impersonates Aruba's login and payment pages to steal user credentials.…

    2 articles · Updated November 18, 2025

Recent Intelligence Reports

  • Man sentenced for role in swatting attacks | brief — Scworld · July 14, 2026
  • Welsh Doxbin admin jailed for egging on swatters from behind a screen — Theregister · July 14, 2026
  • Okta’s advisory — www.okta.com · July 11, 2026
  • Entra passkey enrollment vishing targets Microsoft 365 users — Bleepingcomputer · July 8, 2026
  • Scottish man faces 22 years in prison over £5.9m US cyber fraud scheme — Uk.News.Yahoo · April 18, 2026
  • Scottish man admits role in £5.9m US cyber fraud scheme — News.Stv.Tv · April 18, 2026
  • Scottish man admits role in £5.9m US cyber fraud scheme — Standard · April 18, 2026
  • Scottish man faces 22 years in US prison for $8m virtual currency scam — Independent · April 18, 2026

CVSS v3.1 Breakdown