Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Research DeskLatest update July 19, 202659 research entries

Independent Research Desk

Phishing Tradecraft · Infrastructure · Detection Engineering

The research desk for phishing tradecraft.

PhishPond researches how modern phishing operations are built, run, and detected — campaign evolution, adversary infrastructure, phishing kits, OAuth and device-code abuse, AiTM frameworks, and the detection and validation workflows that catch them.

Latest researchGet the intel brief

Research Desk

On the desk this week

  • 9featured investigations
  • 9research notes in the archive
  • 5intel streams for security teams

A working research desk: fast scans for fresh intel, project radar, trend tracking, and deeper tradecraft and detection analysis.

Recurring Intel

What to track this week

Intel brief
Campaign SignalsFast campaign and supplier-risk intelTradecraft WatchActor-informed methods to emulate and detectDetection & ValidationControls, telemetry, and validation workflowsProject RadarGitHub tooling worth a research scan

Attack-Side Tradecraft

Attack Tradecraft

Campaign tradecraft, lure mechanics, adversary infrastructure, identity pressure, and operator workflows worth modeling.

12 attack-side reads

Detection Engineering

Detection & Validation

Detection engineering, telemetry analysis, reporting workflows, and validation that security teams can operationalize.

32 detection reads

APT Tradecraft

Methods Watch

Emerging procedures, tooling, initial-access patterns, and cross-team tradecraft from real-world actor reporting.

15 tradecraft reads

GitHub Trends

Project Radar

20 live
  • Blue team toolsublime-security/sublime-rulesYAML · 368 stars
  • Dual-use project0xDanielLopez/TweetFeedRepo · 671 stars
  • Dual-use projectphishdestroy/destroylistHTML · 1,662 stars

New Today

Fresh intel since the last refresh

1 new article, 2 new projects

Articles

  • 29th June – Threat Intelligence Report

    Check Point ResearchJun 29, 2026

Projects

  • Blue team toolBadSamuraiDev/bs-lists

    31 stars

  • Blue team toolSeelam-Mohith/QuantShield

    JavaScript13 stars

Blue TeamDefense Pattern

Lead Research

Blue TeamFeaturedDetection & ValidationJul 19, 2026

OAuth Client-ID Spoofing Turns App Identity Into Enumeration Noise

The authentication failures look fragmented by app, but the campaign becomes visible when defenders pivot on missing app names, error semantics, source behavior, and tenant-wide volume.

Two large Entra ID campaigns used hundreds of thousands to millions of fictional OAuth client IDs to spread account enumeration across apparent applications.

Read more:Proofpoint Threat ResearchMicrosoft Learn

By PhishPond Desk · 9 min read

On the Desk

Latest Research

  • The 2024–2026 AitM Phishing-as-a-Service Market: Tycoon, EvilProxy, Mamba, Greatness
  • The Console Is the New Inbox: AiTM Phishing Comes for AWS Sign-In
  • The Hosting Layer Nobody Blocks: Bulletproof Providers, Takedowns, and the CDN Hop
  • ClickFix Grows a Backend: API-Served Payloads and the Windows Terminal Pivot
  • The Admin Calls You: Cross-Tenant Teams Screen-Control to EtherRAT
  • OAuth Client-ID Spoofing Turns App Identity Into Enumeration Noise

Live Collection

Outside Intel Watch

Articles & Analysis

5 tracked
  • ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

    The Hacker NewsJul 27, 2026News

    Fake verification steps train users into running attacker-provided instructions.

    Read more:The Hacker News

  • Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

    The Hacker NewsJul 27, 2026News

    A successful click delivers persistent remote access, not just credentials.

    Read more:The Hacker News

  • GitHub, PyPI add time-based defenses against supply chain attacks

    BleepingComputerJul 26, 2026News

    Trusted suppliers and developer channels can carry phishing risk past normal filters.

    Read more:BleepingComputer

  • Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    BleepingComputerJul 25, 2026News

    Fake verification steps train users into running attacker-provided instructions.

    Read more:BleepingComputer

  • BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

    The Hacker NewsJul 24, 2026News

    Fake verification steps train users into running attacker-provided instructions.

    Read more:The Hacker News

GitHub Project Radar

5 tracked
  • Blue team toolsublime-security/sublime-rules

    YAML368 starspushed Jul 28, 2026

    Sublime rules for email attack detection, prevention, and threat hunting. Primary language: YAML. 368 stars.

    Open project:GitHub

    #email-security#phishing#threat-hunting

  • Dual-use project0xDanielLopez/TweetFeed

    671 starspushed Jul 28, 2026

    TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes. 671 stars.

    Open project:GitHub

    #blueteam#malware#malware-detection#malware-research

  • Dual-use projectphishdestroy/destroylist

    HTML1.7K starspushed Jul 28, 2026

    Real-time phishing & scam domain blocklist — 200k+ curated threats, 888K+ community, free API, multiple formats Primary language: HTML. 1,662 stars.

    Open project:GitHub

    #anti-phishing#blacklist#blocklist#crypto-scam

  • Blue team toolZaczero/pihole-phishtank

    Shell12 starspushed Jul 28, 2026

    🐟 PhishTank Blocklist for Pi-hole Primary language: Shell. 12 stars.

    Open project:GitHub

    #blocklist#hosts#phishing#pihole

  • Blue team toolromainmarcoux/malicious-domains

    DIGITAL Command Language110 starspushed Jul 28, 2026

    Aggregation of lists of malicious domains (phishing) that can be integrated into FortiGate firewalls and other products. Primary language: DIGITAL Command Language. 110 stars.

    Open project:GitHub

    #blocklist#blocklists#domains-blacklist#domains-list

Coverage Map

Choose your intel stream

Campaign Analysis

Specific campaigns, actor activity, and the lures behind them.

Tradecraft Labs

How techniques work end-to-end — walkthroughs and operator workflows.

Infrastructure Intelligence

Adversary infrastructure: kits, AiTM, redirectors, and sending abuse.

Detection & Validation

Detection engineering, telemetry, validation, and response.

Research Reports

Longer research notes, measurement, and periodic briefs.

Search Tool

Search Intelligence

Search titles, authors, tags, and body text across the PhishPond research archive.

Latest Analysis

Field Analysis

Red TeamInfrastructure IntelligenceJul 19, 202612 min read

The 2024–2026 AitM Phishing-as-a-Service Market: Tycoon, EvilProxy, Mamba, Greatness

Reverse-proxy phishing kits commoditized session-token theft over the last two years. The kit market now resembles SaaS, and that has implications for how defenders track operators.

Read more:Microsoft Threat IntelligenceSekoia

By PhishPond Desk

  • #AitM
  • #Threat Intelligence
  • #Phishing Kits

Field Analysis

Dual UseInfrastructure IntelligenceJul 19, 202610 min read

The Console Is the New Inbox: AiTM Phishing Comes for AWS Sign-In

A June 2026 wave of AWS console phishing sites relayed sign-in and MFA to the real AWS in real time, capturing session material from a curated list of engineers. AiTM has moved past Microsoft identity, and the detection has to move with it.

Read more:Datadog Security LabsNVISO Labs

By PhishPond Desk

  • #AitM
  • #AWS
  • #Cloud Identity

Field Analysis

Dual UseInfrastructure IntelligenceJul 19, 202611 min read

The Hosting Layer Nobody Blocks: Bulletproof Providers, Takedowns, and the CDN Hop

Phishing kits get the headlines, but the hosting underneath them is the durable asset. A May 2026 seizure of 800+ servers, resilient scanning networks, and the routine hop behind a CDN show why takedowns rarely stick and where the defensible signal actually lives.

Read more:CISA (with NSA, DC3, FBI, and international partners)ELLIO

By PhishPond Desk

  • #Bulletproof Hosting
  • #Threat Intelligence
  • #Infrastructure

Field Analysis

Dual UseDetection & ValidationJul 19, 202610 min read

ClickFix Grows a Backend: API-Served Payloads and the Windows Terminal Pivot

Analysis of roughly 3,000 live ClickFix payloads shows the clipboard command is now served by a backend that hands every visitor a freshly scrambled variant. The delivery moved server-side, and so did the detection problem.

Read more:The Hacker NewsSplunk Security Content

By PhishPond Desk

  • #ClickFix
  • #Detection Engineering
  • #Endpoint

Field Analysis

Dual UseTradecraft LabsJul 19, 202611 min read

The Admin Calls You: Cross-Tenant Teams Screen-Control to EtherRAT

A late-June 2026 intrusion pivoted from an email lure to an external Teams call posing as 'System Administrator,' drove the victim's desktop through Teams screen-control, and staged a Node.js-based EtherRAT that resolves its C2 from an Ethereum smart contract. The trusted channel is the tradecraft.

Read more:Unit 42 (Palo Alto Networks)GBHackers

By PhishPond Desk

  • #Microsoft Teams
  • #Social Engineering
  • #Remote Access

Field Analysis

Dual UseCampaign AnalysisJul 18, 202610 min read

One Opened Email, Two Roundcube Bugs, and an Edge Foothold

Proofpoint's UNK_MassTraction investigation shows how a low-volume email can execute in vulnerable Roundcube, steal the live session, and pivot into server compromise.

Read more:Proofpoint Threat ResearchNIST National Vulnerability Database

By PhishPond Desk

  • #Roundcube
  • #Webmail
  • #Zero-Click

Field Analysis

Blue TeamResearch ReportsJul 17, 20268 min read

Vishing Is a Control-Plane Problem, Not an Awareness Statistic

Google's 2026 public-sector M-Trends brief says vishing reached 11 percent of global infections, sharpening the case for stronger help-desk recovery and device-enrollment controls.

Read more:Google CloudMicrosoft Security Blog

By PhishPond Desk

  • #Vishing
  • #Help Desk
  • #Identity Recovery

Field Analysis

Blue TeamTradecraft LabsJun 12, 202610 min read

The Recruiting Repo Is the Payload

A fake recruiter asking a candidate to review an MVP repo shows why unsolicited source code is not a document. It is an executable threat surface with access to developer secrets.

Read more:Reddit r/cybersecurityMicrosoft Security Blog

By PhishPond Desk

  • #Developer Security
  • #Fake Recruiters
  • #Supply Chain

Field Analysis

Blue TeamInfrastructure IntelligenceJun 12, 202613 min read

Trusted Notification Systems Are Becoming Phishing Delivery

Scammers abusing a real Microsoft account-alert sender are part of a wider pattern: attackers are turning legitimate SaaS notification workflows into authenticated phishing infrastructure.

Read more:TechCrunchAbnormal AI

By PhishPond Desk

  • #Infrastructure Intelligence
  • #Microsoft 365
  • #Trusted Sender Abuse

Radar Shortcuts

  • All GitHub radar projects
  • Red team reads
  • Blue team reads

Trending Topics

  • #AiTM
  • #Device Code
  • #OAuth Abuse
  • #ClickFix
  • #Session Hijacking
  • #Detection Engineering

Latest News

  • ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

    The Hacker NewsJul 27, 2026

  • Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

    The Hacker NewsJul 27, 2026

  • GitHub, PyPI add time-based defenses against supply chain attacks

    BleepingComputerJul 26, 2026

  • Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    BleepingComputerJul 25, 2026

Research Standards

  • Every analysis pairs attack tradecraft with detection and gaps.
  • Source links are surfaced with each entry.
  • Authorized research only — no turn-key abuse or live-target guidance.

Subscribe to the Weekly PhishPond Brief

Get campaign breakdowns, threat trend signals, and defender-focused mitigations in one concise publication.

No spam. Unsubscribe anytime. Subscriber details are used only for this publication.