Skip to content
StalkPhish

Phishing · Scam · Brand impersonation

Detect phishing faster.
Unmask who is behind it.

StalkPhish.io collects and dissects phishing sites and kits every day to deliver an actionable feed of malicious URLs, together with the intelligence that matters for takedowns and investigations: exfiltration emails, Telegram bots, kit families and targeted brands.

stalkphish.io
The StalkPhish.io platform

Every single day

We have the data.

Our sensors pre-qualify, crawl and analyse suspicious websites around the clock, then download the phishing kits left behind to extract what scammers would rather keep hidden.

suspicious websites analysed every day
60,000+
phishing kit sources downloaded and dissected daily
100+
brand names monitored
1,200+
exfiltration Telegram bots & channels enriched daily
40+

Products

From detection to investigation

Nearly 1,000 users rely on StalkPhish.io to spot phishing URLs, protect their brand and move fast on takedowns.

Platform

StalkPhish.io

Your daily phishing and brand impersonation feed: enriched URLs, phishing kits, targeted brands and the threat actors behind the campaigns.

  • Actionable feed for SOC, CERT and CSIRT
  • Phishing kit family enrichment
  • Track campaigns and actors over time
Discover the platform
API

REST API

Plug our intelligence into your own tools: search by URL, domain, IP or brand, with boolean queries and up to 180 days of history.

  • Free tier to evaluate
  • Starter to Professional plans
  • Ready for SOAR and CTI platforms
Read the API overview
New

Web Search

Search by URL, domain or IP address and get instant results from our threat database, covering the last 7 days of phishing activity.

  • No account required
  • Free and CAPTCHA-protected
  • Upgrade for emails, kits, brands and Telegram handles
Try it now

Trusted by the ecosystemThey implement our tools or datasets.

  • VirusTotal
  • IntelOwl
  • urlscan.io

Press & Media

Raising public awareness

Our phishing and fraud expertise is regularly featured on TV, radio and in the press, to alert and educate the public.

All press coverage
Cash Investigation · France 2
Cash Investigation · France 2fr

Thomas Damonneville explained, on the prime-time show "Cash Investigation", certain recent techniques used by French scammers, particularly the use of inbound calls and how the call centers are set up.

Watch / read ↗
franceinfo
franceinfofr

Thomas Damonneville describes how "lookups" work, those aggregators of personal databases derived from data breaches. for FranceInfo.

Watch / read ↗
franceinfo
franceinfofr

Some tips from Thomas Damonneville on how best to protect yourself against the potential use of data stolen from the DGFiP (the French General Directorate of Public Finance) for FranceInfo.

Watch / read ↗

Research

Latest from the blog

Phishing kit teardowns, threat intelligence and product news.

All articles

Community

Open source, since day one

We build and maintain free tools used by analysts worldwide to hunt phishing kits.

github.com/t4d

PhishingKit-Yara-Rules

YARA rules to identify phishing kits from their ZIP archives. Integrated into VirusTotal’s detection engine.

StalkPhish-OSS

The phishing kits stalker: finds kit URLs in OSINT sources, downloads sources and extracts exfiltration emails.

PhishingKitHunter

Spots phishing kits reusing your own website files by analysing referers in your web server logs.

Phishing campaigns move fast. So should you.

Start with a free search, or talk to us about API access and custom intelligence for your brand.