About StalkPhish
We track phishing kits, and the people behind them.
StalkPhish provides tools, data and knowledge to detect phishing, scam and brand impersonation campaigns, and to give SOCs, CERTs and fraud teams what they need to take them down and investigate their authors.
StalkPhish in figures
- suspicious websites analysed every day
- 60,000+
- open source YARA rules for phishing kits
- 850+
- brand names monitored
- 1,200+
- TV, radio and press appearances
- 20+
Our approach
Stopping the actor is the only way to fight phishing efficiently
Taking down a phishing page is necessary, but another one appears the next day. What makes the difference is knowing who deploys the kits, who develops them and where the stolen data goes.
- 01
Detect
OSINT feeds and our own probes pre-qualify tens of thousands of suspicious URLs every day, with brand, hosting and certificate enrichment.
- 02
Dissect
We retrieve the phishing kits that scammers leave behind and extract their secrets: exfiltration e-mails, Telegram bots and channels, kit families and developers.
- 03
Deliver
An actionable feed and a REST API for SOC, CERT, CSIRT and anti-fraud teams, plus a free Web Search anyone can use without an account.
- 04
Share
Open source tools, public analyses on our blog, talks at security conferences and regular media appearances to raise public awareness.
Our story
From a hunting script to a detection platform
2017
PhishingKitHunter is released: it finds phishing kits reusing a brand’s own website files by analysing its web server logs.
2018
StalkPhish, “the phishing kits stalker”, is open-sourced to harvest phishing kits from OSINT sources for investigations.
2019
Launch of PhishingKit-Yara-Rules and of the StalkPhish blog, with the first phishing kit teardowns.
2021
StalkPhish.io goes live: the tools become a detection platform with a REST API.
2022
Launch of the first paid plan, and teardowns of kits targeting M&T Bank, DEWA suppliers and LinkedIn users.
2023
Talk at the CoRIIN conference on organised French scammer networks; contribution to investigations by franceinfo, Micode and Numerama.
2024
Professional plan, phishing kit family enrichment, StalkPhish-OSS, and a talk at Pass the SALT on hunting phishing URLs, scammers and their tools.
2025
The YARA rules pass 850, covering 300+ brands and used by VirusTotal; a new API brings boolean search and up to 180 days of history.
2026
Talks at CoRIIN and leHack, a free phishing URL scanner in beta, and appearances in Le Monde, franceinfo and Cash Investigation.
Founder

Thomas “tAd” Damonneville
Founder of StalkPhish
Security expert with more than 20 years in the infosec field, Thomas has spent years working on the phishing threat: he builds the detection and investigation tools, analyses the kits, and follows the francophone scammer ecosystem closely, from banking kits to Telegram exfiltration.
A long-time member of the French security community, he regularly shares his work at security conferences and in the media, to help both professionals and the general public protect themselves.
Let’s work together
API access, a demo, custom intelligence for your brand or a press enquiry:
Contact us