Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Research DeskLatest update June 12, 202651 research entries

Independent Research Desk

Phishing Tradecraft · Infrastructure · Detection Engineering

The research desk for phishing tradecraft.

PhishPond researches how modern phishing operations are built, run, and detected — campaign evolution, adversary infrastructure, phishing kits, OAuth and device-code abuse, AiTM frameworks, and the detection and validation workflows that catch them.

Latest researchGet the intel brief

Research Desk

On the desk this week

  • 8featured investigations
  • 8research notes in the archive
  • 5intel streams for security teams

A working research desk: fast scans for fresh intel, project radar, trend tracking, and deeper tradecraft and detection analysis.

Recurring Intel

What to track this week

Intel brief
Campaign SignalsFast campaign and supplier-risk intelTradecraft WatchActor-informed methods to emulate and detectDetection & ValidationControls, telemetry, and validation workflowsProject RadarGitHub tooling worth a research scan

Attack-Side Tradecraft

Attack Tradecraft

Campaign tradecraft, lure mechanics, adversary infrastructure, identity pressure, and operator workflows worth modeling.

12 attack-side reads

Detection Engineering

Detection & Validation

Detection engineering, telemetry analysis, reporting workflows, and validation that security teams can operationalize.

29 detection reads

APT Tradecraft

Methods Watch

Emerging procedures, tooling, initial-access patterns, and cross-team tradecraft from real-world actor reporting.

10 tradecraft reads

GitHub Trends

Project Radar

20 live
  • Blue team toolromainmarcoux/malicious-domainsDIGITAL Command Language · 99 stars
  • Blue team toolromainmarcoux/malicious-outgoing-ipRepo · 27 stars
  • Blue team toolZaczero/pihole-phishtankShell · 13 stars

New Today

Fresh intel since the last refresh

1 new article, 2 new projects

Articles

  • CISA and Partners Urge Hardening Automatic Tank Gauge Systems

    CISA AdvisoriesJun 2, 2026

Projects

  • Blue team toolChocolate4U/Iran-sing-box-rules

    317 stars

  • Blue team toolChocolate4U/Iran-v2ray-rules

    Shell677 stars

Blue TeamDefense Pattern

Lead Research

Blue TeamFeaturedDetection & ValidationMay 6, 2026

Unmanaged OAuth Grants Are the SaaS Back Door Hiding in Plain Sight

The phishing lesson is that attackers do not always need a fresh credential when a trusted app token already has delegated access.

Persistent OAuth grants let third-party apps keep operating after the original login, password reset, or employee lifecycle event has faded from view.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk · 8 min read

On the Desk

Latest Research

  • Trusted Notification Systems Are Becoming Phishing Delivery
  • Kali365 Outgrows Microsoft 365: Operator Pivots to Okta, AWS, and a Russian-Language Cluster
  • The Step After the Click: Five Persistence Primitives That Survive Your Response
  • The Procedure Is the Threat: Why an Intrusion's Shape Outlives Its Toolkit
  • SHub Reaper Drops Terminal-Based ClickFix for an AppleScript URL Pivot
  • Silent Ransom Group Walks Into the Office: Help-Desk Impersonation Adds a Physical Step

Live Collection

Outside Intel Watch

Articles & Analysis

5 tracked
  • ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

    The Hacker NewsJun 11, 2026News

    Finance workflows remain exposed when trust signals come from compromised inboxes.

    Read more:The Hacker News

  • New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

    The Hacker NewsJun 11, 2026News

    Read more:The Hacker News

  • Why AI-driven threats are exposing the limits of MSP security stacks

    BleepingComputerJun 11, 2026News

    Read more:BleepingComputer

  • ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

    The Hacker NewsJun 11, 2026News

    Trusted suppliers and developer channels can carry phishing risk past normal filters.

    Read more:The Hacker News

  • Yarbo Android/iOS Mobile Application and Cloud Infrastructure

    CISA AdvisoriesJun 11, 2026Government Advisory

    Identity and session abuse can turn a single successful lure into account takeover.

    Read more:CISA Advisories

GitHub Project Radar

5 tracked
  • Blue team toolromainmarcoux/malicious-domains

    DIGITAL Command Language99 starspushed Jun 12, 2026

    Aggregation of lists of malicious domains (phishing) that can be integrated into FortiGate firewalls and other products. Primary language: DIGITAL Command Language. 99 stars.

    Open project:GitHub

    #blocklist#blocklists#domains-blacklist#domains-list

  • Blue team toolromainmarcoux/malicious-outgoing-ip

    27 starspushed Jun 12, 2026

    Aggregation of lists of malicious IP addresses (C2, malware, phishing), to be blocked in the LAN > WAN direction, integrated into firewalls: FortiGate, Palo Alto, pfSense, IPtables 27 stars.

    Open project:GitHub

    #blocklist#blocklists#c2#firewall

  • Blue team toolZaczero/pihole-phishtank

    Shell13 starspushed Jun 12, 2026

    🐟 PhishTank Blocklist for Pi-hole Primary language: Shell. 13 stars.

    Open project:GitHub

    #blocklist#hosts#phishing#pihole

  • Dual-use project0xDanielLopez/TweetFeed

    660 starspushed Jun 12, 2026

    TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes. 660 stars.

    Open project:GitHub

    #blueteam#malware#malware-detection#malware-research

  • Dual-use projectphishdestroy/destroylist

    HTML920 starspushed Jun 12, 2026

    Real-time phishing & scam domain blocklist — 130k+ curated threats, 888K+ community, free API, multiple formats Primary language: HTML. 920 stars.

    Open project:GitHub

    #anti-phishing#blacklist#blocklist#crypto-scam

Coverage Map

Choose your intel stream

Campaign Analysis

Specific campaigns, actor activity, and the lures behind them.

Tradecraft Labs

How techniques work end-to-end — walkthroughs and operator workflows.

Infrastructure Intelligence

Adversary infrastructure: kits, AiTM, redirectors, and sending abuse.

Detection & Validation

Detection engineering, telemetry, validation, and response.

Research Reports

Longer research notes, measurement, and periodic briefs.

Search Tool

Search Intelligence

Search titles, authors, tags, and body text across the PhishPond research archive.

Showing 7 matching entries.Clear search

Search Results for "Supply Chain"

Field Analysis

Blue TeamInfrastructure IntelligenceJun 7, 20268 min read

TrapDoor's Cross-Ecosystem Campaign Adds AI-Assistant Poisoning to Supply-Chain Tradecraft

Socket attributes a coordinated supply-chain campaign called TrapDoor to roughly thirty-four packages across npm, PyPI, and Crates.io, with ecosystem-specific execution paths and a new twist: planted .cursorrules and CLAUDE.md files designed to influence the developer's AI coding assistant.

Read more:SocketThe Hacker News

By PhishPond Desk

  • #Infrastructure Intelligence
  • #Supply Chain
  • #Developer Security

Field Analysis

Dual UseCampaign AnalysisMay 31, 20266 min read

Ghost CMS ClickFix Wave Turns Trusted Sites Into Paste-and-Run Staging

A reported exploitation wave against Ghost CMS pushed malicious JavaScript onto more than 700 sites, sending visitors into fake verification flows that used ClickFix-style paste-and-run instructions.

Read more:The Hacker NewsMalwarebytes Labs

By PhishPond Desk

  • #Campaign Analysis
  • #ClickFix
  • #Web Compromise

Field Analysis

Blue TeamDetection & ValidationMay 31, 20266 min read

npm Staged Publishing Moves Package Security Toward Human-Gated Release

GitHub's staged publishing and new npm install-source controls give maintainers practical ways to slow compromised CI/CD paths before a malicious package becomes installable.

Read more:GitHub ChangelogCISA

By PhishPond Desk

  • #Detection & Validation
  • #Supply Chain
  • #Developer Security

Field Analysis

Dual UseTradecraft LabsMay 16, 202610 min read

APT Methods Watch: Geofenced Lures, ClickFix, and Supply Chain Trust

Recent actor reporting points to a practical trend line: adversaries are combining selective delivery, user-driven execution, and trusted developer channels.

Read more:The Hacker NewsDark Reading

By PhishPond Desk

  • #Tradecraft Labs
  • #Initial Access
  • #ClickFix

Field Analysis

Blue TeamDetection & ValidationMay 6, 20269 min read

The Drift Token Lesson Is SaaS Blast Radius, Not Just Vendor Risk

The Salesloft Drift incident showed how a trusted integration token can become an access path into customer SaaS data without a fresh user login.

Read more:The Hacker NewsThe Hacker News

By PhishPond Desk

  • #OAuth
  • #Supply Chain
  • #Salesforce

Field Analysis

Blue TeamInfrastructure IntelligenceMay 6, 20267 min read

Trusted Email Infrastructure Is Now Part of the Phishing Supply Chain

Abuse of legitimate email services such as Amazon SES shows why authentication pass results are not the same thing as sender trust.

Read more:BleepingComputerMicrosoft Security Blog

By PhishPond Desk

  • #Infrastructure Intelligence
  • #Cloud Abuse
  • #Credential Exposure

Field Analysis

Red TeamCampaign AnalysisApr 23, 202611 min read

Developer Tooling Compromise Turns Trusted Packages Into Phishing Surface

Recent package compromises show how developer trust can be abused to harvest credentials and seed downstream phishing risk.

Read more:BleepingComputerCISA

By PhishPond Desk

  • #Supply Chain
  • #Developer Security
  • #Credential Theft

Radar Shortcuts

  • All GitHub radar projects
  • Red team reads
  • Blue team reads

Trending Topics

  • #AiTM
  • #Device Code
  • #OAuth Abuse
  • #ClickFix
  • #Session Hijacking
  • #Detection Engineering

Latest News

  • ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

    The Hacker NewsJun 11, 2026

  • New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

    The Hacker NewsJun 11, 2026

  • Why AI-driven threats are exposing the limits of MSP security stacks

    BleepingComputerJun 11, 2026

  • ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

    The Hacker NewsJun 11, 2026

Research Standards

  • Every analysis pairs attack tradecraft with detection and gaps.
  • Source links are surfaced with each entry.
  • Authorized research only — no turn-key abuse or live-target guidance.

Subscribe to the Weekly PhishPond Brief

Get campaign breakdowns, threat trend signals, and defender-focused mitigations in one concise publication.

No spam. Unsubscribe anytime. Subscriber details are used only for this publication.