Per-Victim Phishing Pages Evade Static Defenses

LogoKit has moved past simple brand spoofing. It now builds a different login page for each target from live site data, so the usual defenses that look for stable templates, logos, or reusable infrastructure have little to lock onto. Barracuda says the kit pulls the victim’s email from the URL, identifies the employer, then assembles the page with a real logo and a live screenshot of the target site through commercial services. The page is built on demand, then the victim is sent to the genuine site, which makes the lure look more like a login mistake than a standing fake page.

Part of the PlainSec briefing for 2026-07-29

Sources