Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Research DeskLatest update July 19, 202659 research entries

Independent Research Desk

Phishing Tradecraft · Infrastructure · Detection Engineering

The research desk for phishing tradecraft.

PhishPond researches how modern phishing operations are built, run, and detected — campaign evolution, adversary infrastructure, phishing kits, OAuth and device-code abuse, AiTM frameworks, and the detection and validation workflows that catch them.

Latest researchGet the intel brief

Research Desk

On the desk this week

  • 9featured investigations
  • 9research notes in the archive
  • 5intel streams for security teams

A working research desk: fast scans for fresh intel, project radar, trend tracking, and deeper tradecraft and detection analysis.

Recurring Intel

What to track this week

Intel brief
Campaign SignalsFast campaign and supplier-risk intelTradecraft WatchActor-informed methods to emulate and detectDetection & ValidationControls, telemetry, and validation workflowsProject RadarGitHub tooling worth a research scan

Attack-Side Tradecraft

Attack Tradecraft

Campaign tradecraft, lure mechanics, adversary infrastructure, identity pressure, and operator workflows worth modeling.

12 attack-side reads

Detection Engineering

Detection & Validation

Detection engineering, telemetry analysis, reporting workflows, and validation that security teams can operationalize.

32 detection reads

APT Tradecraft

Methods Watch

Emerging procedures, tooling, initial-access patterns, and cross-team tradecraft from real-world actor reporting.

15 tradecraft reads

GitHub Trends

Project Radar

20 live
  • Dual-use projectphishdestroy/destroylistHTML · 1,762 stars
  • Blue team toolromainmarcoux/malicious-domainsDIGITAL Command Language · 115 stars
  • Blue team toolromainmarcoux/malicious-outgoing-ipRepo · 40 stars

New Today

Fresh intel since the last refresh

0 new articles, 3 new projects

Projects

  • Blue team toolkawaiipantsu/spamassassin-rules

    59 stars

  • Blue team toolsmed79/easylist-hosts

    15 stars

  • Dual-use projectSagarBiswas-MultiHAT/PhishGuard-AI

    Python17 stars

Blue TeamDefense Pattern

Lead Research

Blue TeamFeaturedDetection & ValidationJul 19, 2026

OAuth Client-ID Spoofing Turns App Identity Into Enumeration Noise

The authentication failures look fragmented by app, but the campaign becomes visible when defenders pivot on missing app names, error semantics, source behavior, and tenant-wide volume.

Two large Entra ID campaigns used hundreds of thousands to millions of fictional OAuth client IDs to spread account enumeration across apparent applications.

Read more:Proofpoint Threat ResearchMicrosoft Learn

By PhishPond Desk · 9 min read

On the Desk

Latest Research

  • The 2024–2026 AitM Phishing-as-a-Service Market: Tycoon, EvilProxy, Mamba, Greatness
  • The Console Is the New Inbox: AiTM Phishing Comes for AWS Sign-In
  • The Hosting Layer Nobody Blocks: Bulletproof Providers, Takedowns, and the CDN Hop
  • ClickFix Grows a Backend: API-Served Payloads and the Windows Terminal Pivot
  • The Admin Calls You: Cross-Tenant Teams Screen-Control to EtherRAT
  • OAuth Client-ID Spoofing Turns App Identity Into Enumeration Noise

Live Collection

Outside Intel Watch

Articles & Analysis

5 tracked
  • Protecting organizations from AI-assisted executive impersonation and invoice fraud

    Microsoft Security BlogSep 10, 2026Vendor Research

    Mailbox and payment workflow abuse creates business risk without malware.

    Read more:Microsoft Security Blog

  • AVEVA Pipeline Integrity Monitor

    CISA AdvisoriesSep 10, 2026Government Advisory

    Identity and session abuse can turn a single successful lure into account takeover.

    Read more:CISA Advisories

  • ST Engineering iDirect iQ-Series Terminals (Update A)

    CISA AdvisoriesSep 10, 2026Government Advisory

    Identity and session abuse can turn a single successful lure into account takeover.

    Read more:CISA Advisories

  • Copyright scammers get Instagram accounts suspended and demand payment

    Malwarebytes LabsSep 10, 2026Vendor Research

    Finance workflows remain exposed when trust signals come from compromised inboxes.

    Read more:Malwarebytes Labs

  • Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

    The Hacker NewsSep 10, 2026News

    Identity and session abuse can turn a single successful lure into account takeover.

    Read more:The Hacker News

GitHub Project Radar

5 tracked
  • Dual-use projectphishdestroy/destroylist

    HTML1.8K starspushed Sep 11, 2026

    Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats Primary language: HTML. 1,762 stars.

    Open project:GitHub

    #anti-phishing#blacklist#blocklist#crypto-scam

  • Blue team toolromainmarcoux/malicious-domains

    DIGITAL Command Language115 starspushed Sep 11, 2026

    Aggregation of lists of malicious domains (phishing) that can be integrated into FortiGate firewalls and other products. Primary language: DIGITAL Command Language. 115 stars.

    Open project:GitHub

    #blocklist#blocklists#domains-blacklist#domains-list

  • Blue team toolromainmarcoux/malicious-outgoing-ip

    40 starspushed Sep 11, 2026

    Aggregation of lists of malicious IP addresses (C2, malware, phishing), to be blocked in the LAN > WAN direction, integrated into firewalls: FortiGate, Palo Alto, pfSense, IPtables 40 stars.

    Open project:GitHub

    #blocklist#blocklists#c2#firewall

  • Dual-use project0xDanielLopez/TweetFeed

    681 starspushed Sep 11, 2026

    TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes. 681 stars.

    Open project:GitHub

    #blueteam#malware#malware-detection#malware-research

  • Blue team toolZaczero/pihole-phishtank

    Shell13 starspushed Sep 11, 2026

    🐟 PhishTank Blocklist for Pi-hole Primary language: Shell. 13 stars.

    Open project:GitHub

    #blocklist#hosts#phishing#pihole

Coverage Map

Choose your intel stream

Campaign Analysis

Specific campaigns, actor activity, and the lures behind them.

Tradecraft Labs

How techniques work end-to-end — walkthroughs and operator workflows.

Infrastructure Intelligence

Adversary infrastructure: kits, AiTM, redirectors, and sending abuse.

Detection & Validation

Detection engineering, telemetry, validation, and response.

Research Reports

Longer research notes, measurement, and periodic briefs.

Search Tool

Search Intelligence

Search titles, authors, tags, and body text across the PhishPond research archive.

Showing 16 matching entries.Clear search

Search Results for "Awareness"

Field Analysis

Blue TeamResearch ReportsJul 17, 20268 min read

Vishing Is a Control-Plane Problem, Not an Awareness Statistic

Google's 2026 public-sector M-Trends brief says vishing reached 11 percent of global infections, sharpening the case for stronger help-desk recovery and device-enrollment controls.

Read more:Google CloudMicrosoft Security Blog

By PhishPond Desk

  • #Vishing
  • #Help Desk
  • #Identity Recovery

Field Analysis

Blue TeamInfrastructure IntelligenceJun 12, 202613 min read

Trusted Notification Systems Are Becoming Phishing Delivery

Scammers abusing a real Microsoft account-alert sender are part of a wider pattern: attackers are turning legitimate SaaS notification workflows into authenticated phishing infrastructure.

Read more:TechCrunchAbnormal AI

By PhishPond Desk

  • #Infrastructure Intelligence
  • #Microsoft 365
  • #Trusted Sender Abuse

Field Analysis

Dual UseInfrastructure IntelligenceJun 7, 20269 min read

Kali365 Outgrows Microsoft 365: Operator Pivots to Okta, AWS, and a Russian-Language Cluster

Arctic Wolf's June 2 follow-up describes the Kali365 operator expanding well beyond Microsoft 365: Okta SSO, Xerox DocuShare, AWS-style endpoints, and a Russian-language cluster including MAX Messenger account takeover via real SMS OTPs. Proofpoint's research places the kit inside a broader cluster of AI-generated device-code lookalikes.

Read more:Arctic Wolf LabsProofpoint

By PhishPond Desk

  • #Infrastructure Intelligence
  • #Phishing-as-a-Service
  • #Kali365

Field Analysis

Dual UseCampaign AnalysisJun 7, 20267 min read

SHub Reaper Drops Terminal-Based ClickFix for an AppleScript URL Pivot

SentinelOne's writeup of the SHub Reaper macOS stealer shows the ClickFix family adapting to platform hardening. When macOS Tahoe 26.4 closed the Terminal-based path, the operators moved to the applescript:// URL scheme and Script Editor instead.

Read more:SentinelOneBleepingComputer

By PhishPond Desk

  • #Campaign Analysis
  • #ClickFix
  • #macOS

Field Analysis

Dual UseCampaign AnalysisMay 31, 20266 min read

Ghost CMS ClickFix Wave Turns Trusted Sites Into Paste-and-Run Staging

A reported exploitation wave against Ghost CMS pushed malicious JavaScript onto more than 700 sites, sending visitors into fake verification flows that used ClickFix-style paste-and-run instructions.

Read more:The Hacker NewsMalwarebytes Labs

By PhishPond Desk

  • #Campaign Analysis
  • #ClickFix
  • #Web Compromise

Field Analysis

Dual UseInfrastructure IntelligenceMay 31, 20268 min read

Kali365 and the Productization of Token Theft

An FBI-flagged phishing-as-a-service kit rents Microsoft 365 token theft for $250 a month, packaging device-code and OAuth abuse into a point-and-click dashboard that defeats MFA without a fake login page.

Read more:FBI IC3Malwarebytes

By PhishPond Desk

  • #Infrastructure Intelligence
  • #Phishing-as-a-Service
  • #Microsoft 365

Field Analysis

Dual UseCampaign AnalysisMay 20, 202610 min read

Breaking Down the Code of Conduct Campaign: PDF Lures, CAPTCHA Gates, and AiTM Token Theft

Microsoft detailed an April 2026 campaign that wrapped credential theft in HR disciplinary language, used a CAPTCHA as an anti-analysis gate, and stole tokens through an adversary-in-the-middle proxy.

Read more:Microsoft Security BlogThe Hacker News

By PhishPond Desk

  • #Campaign Analysis
  • #AiTM
  • #Token Theft

Field Analysis

Dual UseTradecraft LabsMay 20, 20269 min read

MuddyWater's Teams Playbook: Screen-Share Credential Theft Behind a False Flag

An Iranian actor opened an intrusion with a Microsoft Teams chat request and a screen-sharing session, harvested credentials live, then staged ransomware as cover for a state-backed operation.

Read more:The Hacker NewsRapid7

By PhishPond Desk

  • #Tradecraft Labs
  • #MuddyWater
  • #Microsoft Teams

Field Analysis

Dual UseTradecraft LabsMay 16, 202610 min read

APT Methods Watch: Geofenced Lures, ClickFix, and Supply Chain Trust

Recent actor reporting points to a practical trend line: adversaries are combining selective delivery, user-driven execution, and trusted developer channels.

Read more:The Hacker NewsDark Reading

By PhishPond Desk

  • #Tradecraft Labs
  • #Initial Access
  • #ClickFix

Radar Shortcuts

  • All GitHub radar projects
  • Red team reads
  • Blue team reads

Trending Topics

  • #AiTM
  • #Device Code
  • #OAuth Abuse
  • #ClickFix
  • #Session Hijacking
  • #Detection Engineering

Latest News

  • Protecting organizations from AI-assisted executive impersonation and invoice fraud

    Microsoft Security BlogSep 10, 2026

  • AVEVA Pipeline Integrity Monitor

    CISA AdvisoriesSep 10, 2026

  • ST Engineering iDirect iQ-Series Terminals (Update A)

    CISA AdvisoriesSep 10, 2026

  • Copyright scammers get Instagram accounts suspended and demand payment

    Malwarebytes LabsSep 10, 2026

Research Standards

  • Every analysis pairs attack tradecraft with detection and gaps.
  • Source links are surfaced with each entry.
  • Authorized research only — no turn-key abuse or live-target guidance.

Subscribe to the Weekly PhishPond Brief

Get campaign breakdowns, threat trend signals, and defender-focused mitigations in one concise publication.

No spam. Unsubscribe anytime. Subscriber details are used only for this publication.