🦜 Blog - urlscan.io
@urlscan.io.blog@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
urlscan.io Blog - Announcements, Product News, Tutorials, Service Incidents
Your feed and you don't want it here? Just
e-mail the birb.
FluxPanel and FastFlux
https://urlscan.io/blog/2026/09/03/FluxPanelandFastFlux/
Published: September 3, 2026 12:58
The urlscan Threat Research Team identified a suspicious IP address hosting a cluster of phishing sites predominantly targeting UK banks, including HSBC, Lloyds, Metro Bank, Barclays, and Revolut. Pivoting from this IP address using shared nameserver…
Influencer Phishing
https://urlscan.io/blog/2026/08/17/InfluencerPhishing/
Published: August 17, 2026 13:03
This report documents two closely related phishing clusters identified by the urlscan Threat Research Team, both targeting social media users, primarily YouTube content creators, with the goal of gaining access to Google accounts. Both clusters employ a…
Shared Phishing Framework
https://urlscan.io/blog/2026/08/04/ProveFinancialPhishingFramework/
Published: August 4, 2026 13:17
The urlscan Threat Research Team identified a phishing site impersonating Prove, an identity verification provider, which stood out due to the notable nature of the company being targeted. A single distinctive JavaScript global variable present on the page…
CY-Kit
https://urlscan.io/blog/2026/06/22/CnCyKit/
Published: June 22, 2026 14:44
CY-Kit represents a dangerous evolution in phishing, moving beyond simple credential harvesting to a “live puppeteer” model where operators control victim sessions in real time via Socket.IO. This Chinese-backed framework features an invasive toolset that…
Oriental Gudgeon aka. “CoGUI”
https://urlscan.io/blog/2026/06/01/CnOrientalGudgeon/
Published: June 1, 2026 13:50
Oriental Gudgeon, also known as CoGUI, has undergone a major architectural shift toward a centralized encrypted wrapper model to mask its global phishing operations. This latest iteration employs defensive anti-analysis techniques, such as randomized local…
Darcula aka. “Magic Cat”
https://urlscan.io/blog/2026/05/11/CnDarcula/
Published: May 11, 2026 13:12
The Darcula phishing framework continues to evolve, transitioning from early API-driven roots to a sophisticated “Phishing-as-a-Service” model using encrypted WebSockets and wrapper APIs. Our latest research uncovers the inner workings of Darcula, its…
Sailor Framework
https://urlscan.io/blog/2026/05/04/CnSailor/
Published: May 4, 2026 16:22
The Sailor Framework has emerged as a highly specialized Chinese-backed phishing ecosystem, moving away from broad industry attacks to dominate a specific vertical: U.S. state government and tolling infrastructure. By utilizing AES-encrypted WebSockets and…
Beyond the Lure
https://urlscan.io/blog/2026/04/28/Calendly/
Published: April 28, 2026 13:33
Phishing campaigns that impersonate a single brand are often assumed to come from a single source, but that assumption rarely holds up. Calendly is a widely used scheduling platform for booking meetings and interviews, making it a highly believable lure in…
Chinese backed phishing services
https://urlscan.io/blog/2026/04/27/CnIntro/
Published: April 27, 2026 13:16
Over the past several months, the urlscan Threat Research Team has conducted extensive research to identify, cluster, and track some of the most impactful Chinese-language phishing-as-a-service (PhaaS) ecosystems operating at a global scale. This research…
Proxying Trust
https://urlscan.io/blog/2026/04/15/ProxyingTrust/
Published: April 15, 2026 15:02
During routine monitoring of malicious web activity on the urlscan platform, the urlscan Threat Research Team identified a phishing campaign abusing the Ultraviolet (UV) client-side proxy framework. This framework was being leveraged to obscure attacker…