Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Research DeskLatest update October 6, 202663 research entries

Independent Research Desk

Phishing Tradecraft · Infrastructure · Detection Engineering

The research desk for phishing tradecraft.

PhishPond researches how modern phishing operations are built, run, and detected — campaign evolution, adversary infrastructure, phishing kits, OAuth and device-code abuse, AiTM frameworks, and the detection and validation workflows that catch them.

Latest researchGet the intel brief

Research Desk

On the desk this week

  • 10featured investigations
  • 9research notes in the archive
  • 5intel streams for security teams

A working research desk: fast scans for fresh intel, project radar, trend tracking, and deeper tradecraft and detection analysis.

Recurring Intel

What to track this week

Intel brief
Campaign SignalsFast campaign and supplier-risk intelTradecraft WatchActor-informed methods to emulate and detectDetection & ValidationControls, telemetry, and validation workflowsProject RadarGitHub tooling worth a research scan

Attack-Side Tradecraft

Attack Tradecraft

Campaign tradecraft, lure mechanics, adversary infrastructure, identity pressure, and operator workflows worth modeling.

12 attack-side reads

Detection Engineering

Detection & Validation

Detection engineering, telemetry analysis, reporting workflows, and validation that security teams can operationalize.

34 detection reads

APT Tradecraft

Methods Watch

Emerging procedures, tooling, initial-access patterns, and cross-team tradecraft from real-world actor reporting.

17 tradecraft reads

GitHub Trends

Project Radar

20 live
  • Blue team toolromainmarcoux/malicious-outgoing-ipRepo · 42 stars
  • Dual-use projectphishdestroy/destroylistHTML · 1,902 stars
  • Dual-use project0xDanielLopez/TweetFeedRepo · 687 stars

New Today

Fresh intel since the last refresh

5 new articles, 1 new project

Articles

  • Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

    BleepingComputerOct 6, 2026

  • How to secure RMM software: 8 controls MSPs should test

    BleepingComputerOct 6, 2026

  • More RMM Tools In the Wild, (Tue, Oct 6th)

    SANS Internet Storm CenterOct 6, 2026

  • Domino’s customers targeted in credential stuffing attacks

    Malwarebytes LabsOct 6, 2026

Projects

  • Blue team tooldeeztek/Hermes-Secure-Email-Gateway

    JavaScript140 stars

Blue TeamDefense Pattern

Lead Research

Blue TeamFeaturedDetection & ValidationOct 6, 2026

The Passkey Lure Is Not About Passkeys

Enrollment urgency is the oldest helpdesk pretext wearing a new word. The objective is still a session token, and the tell is still Graph.

Microsoft tracked Storm-3121 and Storm-3032 running passkey-themed helpdesk calls since May 2026. The passkey narrative is a pretext that routes victims into AiTM and device-code flows — and the detection lives in what happens after the token lands, not in the lure.

Read more:Microsoft Security BlogBleepingComputer

By PhishPond Desk · 11 min read

On the Desk

Latest Research

  • ClickFix Is Engineering Its Way Out of the Run Dialog
  • Two RMM Agents Are Not Redundancy, They Are Persistence
  • EvilTokens Goes Down: What a PhaaS Takedown Actually Buys You
  • The Passkey Lure Is Not About Passkeys
  • Passkeys Move From Security Project to Front-Line Phishing Control
  • The 2024–2026 AitM Phishing-as-a-Service Market: Tycoon, EvilProxy, Mamba, Greatness

Live Collection

Outside Intel Watch

Articles & Analysis

5 tracked
  • Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

    BleepingComputerOct 6, 2026News

    Identity and session abuse can turn a single successful lure into account takeover.

    Read more:BleepingComputer

  • How to secure RMM software: 8 controls MSPs should test

    BleepingComputerOct 6, 2026News

    A successful click delivers persistent remote access, not just credentials.

    Read more:BleepingComputer

  • More RMM Tools In the Wild, (Tue, Oct 6th)

    SANS Internet Storm CenterOct 6, 2026Analysis

    A successful click delivers persistent remote access, not just credentials.

    Read more:SANS Internet Storm Center

  • Domino’s customers targeted in credential stuffing attacks

    Malwarebytes LabsOct 6, 2026Vendor Research

    Identity and session abuse can turn a single successful lure into account takeover.

    Read more:Malwarebytes Labs

  • Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

    The Hacker NewsOct 6, 2026News

    Trusted suppliers and developer channels can carry phishing risk past normal filters.

    Read more:The Hacker News

GitHub Project Radar

5 tracked
  • Blue team toolromainmarcoux/malicious-outgoing-ip

    42 starspushed Oct 6, 2026

    Aggregation of lists of malicious IP addresses (C2, malware, phishing), to be blocked in the LAN > WAN direction, integrated into firewalls: FortiGate, Palo Alto, pfSense, IPtables 42 stars.

    Open project:GitHub

    #blocklist#blocklists#c2#firewall

  • Dual-use projectphishdestroy/destroylist

    HTML1.9K starspushed Oct 6, 2026

    Real-time phishing & scam domain blocklist - 205k+ curated threats, 1M+ community, free API, multiple formats Primary language: HTML. 1,902 stars.

    Open project:GitHub

    #anti-phishing#blacklist#blocklist#crypto-scam

  • Dual-use project0xDanielLopez/TweetFeed

    687 starspushed Oct 6, 2026

    TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes. 687 stars.

    Open project:GitHub

    #blueteam#malware#malware-detection#malware-research

  • Blue team toolsublime-security/sublime-rules

    YAML376 starspushed Oct 6, 2026

    Sublime rules for email attack detection, prevention, and threat hunting. Primary language: YAML. 376 stars.

    Open project:GitHub

    #email-security#phishing#threat-hunting

  • Blue team toolsjhgvr/oisd

    258 starspushed Oct 6, 2026

    oisd blocklist 258 stars.

    Open project:GitHub

    #adblocking#adblocking-dns#adblocking-list#adblocklist

Coverage Map

Choose your intel stream

Campaign Analysis

Specific campaigns, actor activity, and the lures behind them.

Tradecraft Labs

How techniques work end-to-end — walkthroughs and operator workflows.

Infrastructure Intelligence

Adversary infrastructure: kits, AiTM, redirectors, and sending abuse.

Detection & Validation

Detection engineering, telemetry, validation, and response.

Research Reports

Longer research notes, measurement, and periodic briefs.

Search Tool

Search Intelligence

Search titles, authors, tags, and body text across the PhishPond research archive.

Showing 1 matching entry.Clear search

Search Results for "MSP360"

Field Analysis

Blue TeamCampaign AnalysisOct 6, 202610 min read

Two RMM Agents Are Not Redundancy, They Are Persistence

Microsoft documented a July 2026 campaign dropping MSP360 RMM v2.5.0.67 as the initial agent and ConnectWise ScreenConnect as a second channel. ANY.RUN tracked the wider operation across 46 countries, with 94% of its kit URLs alive for a single day.

Read more:Microsoft Security BlogThe Hacker News

By PhishPond Desk

  • #RMM Abuse
  • #ScreenConnect
  • #MSP360

Radar Shortcuts

  • All GitHub radar projects
  • Red team reads
  • Blue team reads

Trending Topics

  • #AiTM
  • #Device Code
  • #OAuth Abuse
  • #ClickFix
  • #Session Hijacking
  • #Detection Engineering

Latest News

  • Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

    BleepingComputerOct 6, 2026

  • How to secure RMM software: 8 controls MSPs should test

    BleepingComputerOct 6, 2026

  • More RMM Tools In the Wild, (Tue, Oct 6th)

    SANS Internet Storm CenterOct 6, 2026

  • Domino’s customers targeted in credential stuffing attacks

    Malwarebytes LabsOct 6, 2026

Research Standards

  • Every analysis pairs attack tradecraft with detection and gaps.
  • Source links are surfaced with each entry.
  • Authorized research only — no turn-key abuse or live-target guidance.

Subscribe to the Weekly PhishPond Brief

Get campaign breakdowns, threat trend signals, and defender-focused mitigations in one concise publication.

No spam. Unsubscribe anytime. Subscriber details are used only for this publication.