Skip to content
StalkPhish

About StalkPhish

We track phishing kits, and the people behind them.

StalkPhish provides tools, data and knowledge to detect phishing, scam and brand impersonation campaigns, and to give SOCs, CERTs and fraud teams what they need to take them down and investigate their authors.

StalkPhish in figures

suspicious websites analysed every day
60,000+
open source YARA rules for phishing kits
850+
brand names monitored
1,200+
TV, radio and press appearances
20+

Our approach

Stopping the actor is the only way to fight phishing efficiently

Taking down a phishing page is necessary, but another one appears the next day. What makes the difference is knowing who deploys the kits, who develops them and where the stolen data goes.

  1. 01

    Detect

    OSINT feeds and our own probes pre-qualify tens of thousands of suspicious URLs every day, with brand, hosting and certificate enrichment.

  2. 02

    Dissect

    We retrieve the phishing kits that scammers leave behind and extract their secrets: exfiltration e-mails, Telegram bots and channels, kit families and developers.

  3. 03

    Deliver

    An actionable feed and a REST API for SOC, CERT, CSIRT and anti-fraud teams, plus a free Web Search anyone can use without an account.

  4. 04

    Share

    Open source tools, public analyses on our blog, talks at security conferences and regular media appearances to raise public awareness.

Our story

From a hunting script to a detection platform

  1. 2017

    PhishingKitHunter is released: it finds phishing kits reusing a brand’s own website files by analysing its web server logs.

  2. 2018

    StalkPhish, “the phishing kits stalker”, is open-sourced to harvest phishing kits from OSINT sources for investigations.

  3. 2019

    Launch of PhishingKit-Yara-Rules and of the StalkPhish blog, with the first phishing kit teardowns.

  4. 2021

    StalkPhish.io goes live: the tools become a detection platform with a REST API.

  5. 2022

    Launch of the first paid plan, and teardowns of kits targeting M&T Bank, DEWA suppliers and LinkedIn users.

  6. 2023

    Talk at the CoRIIN conference on organised French scammer networks; contribution to investigations by franceinfo, Micode and Numerama.

  7. 2024

    Professional plan, phishing kit family enrichment, StalkPhish-OSS, and a talk at Pass the SALT on hunting phishing URLs, scammers and their tools.

  8. 2025

    The YARA rules pass 850, covering 300+ brands and used by VirusTotal; a new API brings boolean search and up to 180 days of history.

  9. 2026

    Talks at CoRIIN and leHack, a free phishing URL scanner in beta, and appearances in Le Monde, franceinfo and Cash Investigation.

Founder

Thomas “tAd” Damonneville

Thomas “tAd” Damonneville

Founder of StalkPhish

Security expert with more than 20 years in the infosec field, Thomas has spent years working on the phishing threat: he builds the detection and investigation tools, analyses the kits, and follows the francophone scammer ecosystem closely, from banking kits to Telegram exfiltration.

A long-time member of the French security community, he regularly shares his work at security conferences and in the media, to help both professionals and the general public protect themselves.

Trusted by the ecosystemThey implement our tools or datasets.

  • VirusTotal
  • IntelOwl
  • urlscan.io

Let’s work together

API access, a demo, custom intelligence for your brand or a press enquiry:

Contact us