<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>StalkPhish blog</title><description>StalkPhish provides B2B tools, data and knowledge to detect phishing, scams and brand impersonation, and to track the threat actors behind them.</description><link>https://stalkphish.com/</link><item><title>[StalkPhish.io] 8 Powerful Use Cases for the StalkPhish API in Anti-Fraud and Anti-Phishing Operations</title><link>https://stalkphish.com/2026/01/01/8-powerful-use-cases-for-the-stalkphish-api-in-anti-fraud-and-anti-phishing-operations/</link><guid isPermaLink="true">https://stalkphish.com/2026/01/01/8-powerful-use-cases-for-the-stalkphish-api-in-anti-fraud-and-anti-phishing-operations/</guid><description>Phishing remains one of the most persistent threats facing organizations today. According to recent reports, phishing attacks account for over 80% of reported…</description><pubDate>Thu, 01 Jan 2026 00:00:00 GMT</pubDate><category>CSIRT</category><category>cti</category><category>hunting</category><category>investigation</category><category>phishing</category><category>phishing kit</category><category>soc</category><category>StalkPhish.io</category><category>threat analysis</category><category>threat intelligence</category><category>vishing</category></item><item><title>[StalkPhish.io] Advanced Phishing Detection with one API</title><link>https://stalkphish.com/2025/11/05/stalkphish-io-advanced-phishing-detection-with-one-api/</link><guid isPermaLink="true">https://stalkphish.com/2025/11/05/stalkphish-io-advanced-phishing-detection-with-one-api/</guid><description>At StalkPhish, we&apos;ve been committed to staying ahead of phishing threats and providing our users with the most comprehensive tools for detecting and…</description><pubDate>Wed, 05 Nov 2025 00:00:00 GMT</pubDate></item><item><title>Smishing à la française, collection Automne-Hiver 2025-2026</title><link>https://stalkphish.com/2025/09/15/smishing-a-la-francaise-collection-automne-hiver-2025-2026/</link><guid isPermaLink="true">https://stalkphish.com/2025/09/15/smishing-a-la-francaise-collection-automne-hiver-2025-2026/</guid><description>Nouvelles techniques de smishing utilisées par les scammers francophones depuis début 2025 pour escroquer leurs victimes.</description><pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate><category>CERT</category><category>CSIRT</category><category>cti</category><category>Etude</category><category>investigation</category><category>StalkPhish.io</category><category>threat intelligence</category></item><item><title>From Phishing Detection to Anti-Fraud Investigation</title><link>https://stalkphish.com/2025/07/06/from-phishing-detection-to-anti-fraud-investigation/</link><guid isPermaLink="true">https://stalkphish.com/2025/07/06/from-phishing-detection-to-anti-fraud-investigation/</guid><description>At StalkPhish, our core business includes, among other things, phishing detection. Every day we detect, enrich, and sort tens of thousands of phishing URLs…</description><pubDate>Sun, 06 Jul 2025 00:00:00 GMT</pubDate></item><item><title>[Phishing kit] MonCompteFormation &apos;Lead&apos; phishing kit - an analysis</title><link>https://stalkphish.com/2025/01/17/phishing-kit-moncompteformation-lead-phishing-kit-an-analysis/</link><guid isPermaLink="true">https://stalkphish.com/2025/01/17/phishing-kit-moncompteformation-lead-phishing-kit-an-analysis/</guid><description>In mid-December 2024, while checking the new findings of Stalkphish.io (our phishing URL detection, enrichment and investigation platform), I noticed that a…</description><pubDate>Fri, 17 Jan 2025 00:00:00 GMT</pubDate><category>CERT</category><category>cti</category><category>hunting</category><category>investigation</category><category>phishing</category><category>phishing kit</category><category>StalkPhish.io</category><category>threat analysis</category><category>threat intelligence</category></item><item><title>[StalkPhish.io] Phishing Kit family enrichment</title><link>https://stalkphish.com/2024/10/10/stalkphish-io-phishing-kit-family-enrichment/</link><guid isPermaLink="true">https://stalkphish.com/2024/10/10/stalkphish-io-phishing-kit-family-enrichment/</guid><description>Since last summer, StalkPhish.io , our advanced platform dedicated to combating bank fraud, phishing, and scams, has been upgraded with a system for…</description><pubDate>Thu, 10 Oct 2024 00:00:00 GMT</pubDate><category>CERT</category><category>CSIRT</category><category>cti</category><category>hunting</category><category>investigation</category><category>OSINT</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category><category>soc</category><category>StalkPhish.io</category><category>threat analysis</category><category>threat intelligence</category><category>tool</category></item><item><title>[Phishing] Current state of phishing threat using Paris 2024 Olympic games branding (June 24)</title><link>https://stalkphish.com/2024/06/20/phishing-current-state-of-phishing-threat-using-paris-2024-olympic-games-branding-june-24/</link><guid isPermaLink="true">https://stalkphish.com/2024/06/20/phishing-current-state-of-phishing-threat-using-paris-2024-olympic-games-branding-june-24/</guid><description>With the Paris 2024 Olympic and Paralympic Games approaching, a host of scams have been developed and deployed, including phishing pages harvesting personal and banking data.</description><pubDate>Thu, 20 Jun 2024 00:00:00 GMT</pubDate><category>cti</category><category>investigation</category><category>phishing</category><category>StalkPhish.io</category><category>threat intelligence</category><category>tool</category></item><item><title>Stalkphish.io - Launch of our Professional Plan</title><link>https://stalkphish.com/2024/03/25/stalkphish-io-professional-plan/</link><guid isPermaLink="true">https://stalkphish.com/2024/03/25/stalkphish-io-professional-plan/</guid><description>We launch our first paid plan for Stalkphish.io our SaaS dedicated to detection and investigation of phishing/brand impersonation.</description><pubDate>Mon, 25 Mar 2024 00:00:00 GMT</pubDate><category>CERT</category><category>CSIRT</category><category>cti</category><category>hunting</category><category>OSINT</category><category>phishing</category><category>phishing kit</category><category>soc</category><category>StalkPhish.io</category><category>threat analysis</category><category>threat intelligence</category></item><item><title>[Phishing kit] Caisse d&apos;Epargne &apos;Don&apos; phishing kit - an analysis</title><link>https://stalkphish.com/2024/01/27/phishing-kit-caisse-epargne-don-an-analysis/</link><guid isPermaLink="true">https://stalkphish.com/2024/01/27/phishing-kit-caisse-epargne-don-an-analysis/</guid><description>This phishing kit impersonates Caisse D&apos;Epargne , a French bank, of BPCE Group. This kit was downloaded at the beginning of December 2023, by our phishing…</description><pubDate>Sat, 27 Jan 2024 00:00:00 GMT</pubDate><category>CERT</category><category>CSIRT</category><category>cti</category><category>investigation</category><category>OSINT</category><category>phishing</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category><category>Stalkphish</category><category>StalkPhish.io</category><category>threat analysis</category></item><item><title>[Threat intelligence] About the Phishing as a Service tool named &quot;Greatness&quot;</title><link>https://stalkphish.com/2023/07/04/threat-intelligence-about-the-paas-named-greatness/</link><guid isPermaLink="true">https://stalkphish.com/2023/07/04/threat-intelligence-about-the-paas-named-greatness/</guid><description>Find a short analysis of the &quot;Greatness&quot; phishing kit used by a new Phishing as a Service infrastructure. Added some original IOCs for detection and hunting.</description><pubDate>Tue, 04 Jul 2023 00:00:00 GMT</pubDate><category>CERT</category><category>CSIRT</category><category>cti</category><category>hunting</category><category>investigation</category><category>OSINT</category><category>phishing</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category><category>threat intelligence</category></item><item><title>[Phishing kit] Coinbase phishing kit with live admin panel to bypass MFA - an analysis.</title><link>https://stalkphish.com/2023/01/25/phishing-kit-coinbase-phishing-kit-with-live-admin-panel-to-bypass-mfa-an-analysis/</link><guid isPermaLink="true">https://stalkphish.com/2023/01/25/phishing-kit-coinbase-phishing-kit-with-live-admin-panel-to-bypass-mfa-an-analysis/</guid><description>An analysis of a Coinbase phishing kit designed to steal personal data, login, password and the second factor of authentication (MFA/2FA).</description><pubDate>Wed, 25 Jan 2023 00:00:00 GMT</pubDate><category>investigation</category><category>phishing</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category><category>StalkPhish.io</category><category>threat intelligence</category></item><item><title>Une campagne de phishing Netflix, Société Générale, Ameli ou Crit&apos;air pour 10€</title><link>https://stalkphish.com/2022/12/19/une-campagne-de-phishing-netflix-societe-generale-ameli-ou-critair-pour-10-euros/</link><guid isPermaLink="true">https://stalkphish.com/2022/12/19/une-campagne-de-phishing-netflix-societe-generale-ameli-ou-critair-pour-10-euros/</guid><description>Chez Stalkphish nous nous plongeons - depuis plusieurs mois - dans certains réseaux de &quot;scama&quot;, de scammers (arnaqueurs), pratiquant des campagnes de phishing parfois assez volumineuses et qui touchent plusieurs marques, enseignes ou services du gouvernement français, comme Ameli/Carte vitale, la vignette Crit&apos;Air, les împots, ainsi que des services privés comme Netflix ou des services bancaires tels que ceux de la Société Générale, la Banque Postale, et bien d&apos;autres.</description><pubDate>Mon, 19 Dec 2022 00:00:00 GMT</pubDate><category>CERT</category><category>CSIRT</category><category>cti</category><category>Etude</category><category>hunting</category><category>investigation</category><category>OSINT</category><category>phishing</category><category>phishing kit</category><category>soc</category><category>StalkPhish.io</category><category>threat analysis</category><category>threat intelligence</category><category>tool</category></item><item><title>Stalkphish.io - Launch of our Standard Plan to better detect and fight phishing</title><link>https://stalkphish.com/2022/10/16/stalkphish-io-launch-of-our-standard-plan-to-better-detect-and-fight-phishing/</link><guid isPermaLink="true">https://stalkphish.com/2022/10/16/stalkphish-io-launch-of-our-standard-plan-to-better-detect-and-fight-phishing/</guid><description>We launch our first paid plan for Stalkphish.io our SaaS dedicated to detection and investigation of phishing/brand impersonation.</description><pubDate>Sun, 16 Oct 2022 00:00:00 GMT</pubDate><category>CERT</category><category>CSIRT</category><category>cti</category><category>hunting</category><category>OSINT</category><category>phishing</category><category>phishing kit</category><category>soc</category><category>StalkPhish.io</category><category>threat analysis</category><category>threat intelligence</category></item><item><title>[Use case] Hunting for phishing pages</title><link>https://stalkphish.com/2022/09/05/use-case-hunting-for-phishing/</link><guid isPermaLink="true">https://stalkphish.com/2022/09/05/use-case-hunting-for-phishing/</guid><description>Fight phishing (aka &quot;Phight&quot;) is not an easy task, you need to detect a campaign before starting to dismantle it. You can compare that to a race: the faster…</description><pubDate>Mon, 05 Sep 2022 00:00:00 GMT</pubDate><category>CERT</category><category>CSIRT</category><category>cti</category><category>hunting</category><category>OSINT</category><category>phishing</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category><category>soc</category><category>StalkPhish.io</category><category>threat analysis</category><category>threat intelligence</category></item><item><title>[Phishing kit] LinkedIn phishing kit targeting Chinese users - an analysis</title><link>https://stalkphish.com/2022/07/28/linkedin-phishing-kit-targeting-chinese-users-an-analysis/</link><guid isPermaLink="true">https://stalkphish.com/2022/07/28/linkedin-phishing-kit-targeting-chinese-users-an-analysis/</guid><description>At StalkPhish we like dissecting Phishing kits, first because we create Yara rules for detection, secondly because we must continually keep up to date with new…</description><pubDate>Thu, 28 Jul 2022 00:00:00 GMT</pubDate><category>phishing</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category><category>StalkPhish.io</category><category>threat analysis</category></item><item><title>[Threat intelligence] Using StalkPhish.io with Intel Owl to speed up threat analysis</title><link>https://stalkphish.com/2022/04/04/threat-intelligence-using-stalkphish-io-with-intelowl-to-speed-up-threat-analysis/</link><guid isPermaLink="true">https://stalkphish.com/2022/04/04/threat-intelligence-using-stalkphish-io-with-intelowl-to-speed-up-threat-analysis/</guid><description>Using StalkPhish.io analyzer as a threat intelligence feed for IntelOwl to speed up your threat analysis.</description><pubDate>Mon, 04 Apr 2022 00:00:00 GMT</pubDate><category>CERT</category><category>CSIRT</category><category>cti</category><category>OSINT</category><category>phishing</category><category>soc</category><category>StalkPhish.io</category><category>threat analysis</category><category>threat intelligence</category></item><item><title>[Phishing kit] M&amp;T Bank - Telegram exfiltration kit, without any Telegram link</title><link>https://stalkphish.com/2022/03/14/phishing-kit-mt-bank-telegram-exfiltration-kit-without-any-telegram-link/</link><guid isPermaLink="true">https://stalkphish.com/2022/03/14/phishing-kit-mt-bank-telegram-exfiltration-kit-without-any-telegram-link/</guid><description>One of the latest kits downloaded by StalkPhish targets customers of the online bank M&amp;T. It has a special feature that we wanted to share with you. We still…</description><pubDate>Mon, 14 Mar 2022 00:00:00 GMT</pubDate><category>phishing</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category><category>tool</category></item><item><title>[Phishing kit] &apos;Moha&apos; kit, targeting DEWA suppliers</title><link>https://stalkphish.com/2022/02/04/phishing-kit-moha-kit-targeting-dewa-suppliers/</link><guid isPermaLink="true">https://stalkphish.com/2022/02/04/phishing-kit-moha-kit-targeting-dewa-suppliers/</guid><description>At StalkPhish we like dissecting Phishing kits, first because we create Yara rules for detection, secondly because we must continually keep up to date with new…</description><pubDate>Fri, 04 Feb 2022 00:00:00 GMT</pubDate><category>phishing</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category></item><item><title>Using PhishingKit-Yara-Rules with ClamAV</title><link>https://stalkphish.com/2022/01/25/using-phishingkit-yara-rules-with-clamav/</link><guid isPermaLink="true">https://stalkphish.com/2022/01/25/using-phishingkit-yara-rules-with-clamav/</guid><description>As a reminder, the PhishingKit-Yara-Rules project is a free and open source project which provides several dozen phishing kit detection rules contained in zip…</description><pubDate>Tue, 25 Jan 2022 00:00:00 GMT</pubDate><category>PhishingKit-Yara-Rules</category><category>tool</category></item><item><title>Several domain names, one protected redirector, one phishing campaign</title><link>https://stalkphish.com/2021/11/14/several-domain-names-one-protected-redirector-one-phishing-campaign/</link><guid isPermaLink="true">https://stalkphish.com/2021/11/14/several-domain-names-one-protected-redirector-one-phishing-campaign/</guid><description>Sometimes phishing campaigns are not conduced with phishing kits only, actors behind those phishing campaigns can use different tricks to prevent their work…</description><pubDate>Sun, 14 Nov 2021 00:00:00 GMT</pubDate><category>phishing</category><category>phishing redirector</category></item><item><title>[Use case] Using Phishing-Kit-Yara-Rules project for phishing kits detection and triage</title><link>https://stalkphish.com/2021/08/17/using-phishing-kit-yara-rules-project-for-phishing-kits-detection-and-triage/</link><guid isPermaLink="true">https://stalkphish.com/2021/08/17/using-phishing-kit-yara-rules-project-for-phishing-kits-detection-and-triage/</guid><description>Since some months now, we maintain specific Yara rules to detect phishing kit sources (.zip files). Phishing kits sources are sometimes left on the host…</description><pubDate>Tue, 17 Aug 2021 00:00:00 GMT</pubDate><category>phishing</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category></item><item><title>How-to use StalkPhish.io</title><link>https://stalkphish.com/2021/06/30/howto-stalkphish-io/</link><guid isPermaLink="true">https://stalkphish.com/2021/06/30/howto-stalkphish-io/</guid><description>StalkPhish.io is a SaaS application which provides enriched data about potential phishing URL or brand impersonation use, with a REST API.</description><pubDate>Wed, 30 Jun 2021 00:00:00 GMT</pubDate><category>phishing</category><category>phishing kit</category><category>tool</category></item><item><title>[Phishing kit] Scammer vs Scammer - backdoored phishing kit</title><link>https://stalkphish.com/2021/04/22/scammer_vs_scammer_backdoored_phishing_kit/</link><guid isPermaLink="true">https://stalkphish.com/2021/04/22/scammer_vs_scammer_backdoored_phishing_kit/</guid><description>Scammer world should be a hard thug life. A merciless world... with no pity... Some scammers try to steal other ones! What a shameless! During our researches we found one of those &apos;backdoored&apos; phishing kit, let&apos;s have a fast dive into it.</description><pubDate>Thu, 22 Apr 2021 00:00:00 GMT</pubDate><category>phishing</category><category>phishing kit</category><category>Stalkphish</category></item><item><title>Phishing kit using Google sheet to exfiltrate stolen data</title><link>https://stalkphish.com/2021/04/09/phishing-kit-using-google-sheet-to-exfiltrate-stolen-data/</link><guid isPermaLink="true">https://stalkphish.com/2021/04/09/phishing-kit-using-google-sheet-to-exfiltrate-stolen-data/</guid><description>Analysis of a Facebook phishing kit which exfiltrate stolen data to an online Google Sheet using ajax POST method.</description><pubDate>Fri, 09 Apr 2021 00:00:00 GMT</pubDate><category>phishing</category><category>phishing kit</category><category>PhishingKit-Yara-Rules</category><category>Stalkphish</category></item><item><title>How phishing kits uses Telegram</title><link>https://stalkphish.com/2020/12/14/how-phishing-kits-use-telegram/</link><guid isPermaLink="true">https://stalkphish.com/2020/12/14/how-phishing-kits-use-telegram/</guid><description>More and more actors uses Telegram chat groups to exfiltrate harvested data, we&apos;ll show you how we can collect informations about those actors. Let’s have a dive into one of this kits.</description><pubDate>Mon, 14 Dec 2020 00:00:00 GMT</pubDate><category>phishing</category><category>phishing kit</category></item><item><title>[Phishing Kit] &apos;Israel&apos; Outlook Web App credentials stealer</title><link>https://stalkphish.com/2019/12/06/israel-outlook-credentials-harvester/</link><guid isPermaLink="true">https://stalkphish.com/2019/12/06/israel-outlook-credentials-harvester/</guid><description>An analysis of a phishing kit found with StalkPhish tool. This phishing kit impersonating a professional Outlook login pattern and exfiltrate credentials on an online portal (FormBuddy)... with no success.</description><pubDate>Fri, 06 Dec 2019 00:00:00 GMT</pubDate><category>phishing</category><category>phishing kit</category></item></channel></rss>