GitHub Trends
Project Radar
- Dual-use projectphishdestroy/destroylistHTML · 1,762 stars
- Blue team toolromainmarcoux/malicious-domainsDIGITAL Command Language · 115 stars
- Blue team toolromainmarcoux/malicious-outgoing-ipRepo · 40 stars
Research DeskLatest update July 19, 202659 research entries
Independent Research Desk
Phishing Tradecraft · Infrastructure · Detection Engineering
PhishPond researches how modern phishing operations are built, run, and detected — campaign evolution, adversary infrastructure, phishing kits, OAuth and device-code abuse, AiTM frameworks, and the detection and validation workflows that catch them.
Recurring Intel
Attack-Side Tradecraft
Campaign tradecraft, lure mechanics, adversary infrastructure, identity pressure, and operator workflows worth modeling.
12 attack-side readsDetection Engineering
Detection engineering, telemetry analysis, reporting workflows, and validation that security teams can operationalize.
32 detection readsAPT Tradecraft
Emerging procedures, tooling, initial-access patterns, and cross-team tradecraft from real-world actor reporting.
15 tradecraft readsGitHub Trends
New Today
Lead Research
The authentication failures look fragmented by app, but the campaign becomes visible when defenders pivot on missing app names, error semantics, source behavior, and tenant-wide volume.
Two large Entra ID campaigns used hundreds of thousands to millions of fictional OAuth client IDs to spread account enumeration across apparent applications.
Live Collection
Mailbox and payment workflow abuse creates business risk without malware.
Read more:Microsoft Security Blog
Identity and session abuse can turn a single successful lure into account takeover.
Read more:CISA Advisories
Identity and session abuse can turn a single successful lure into account takeover.
Read more:CISA Advisories
Finance workflows remain exposed when trust signals come from compromised inboxes.
Read more:Malwarebytes Labs
Identity and session abuse can turn a single successful lure into account takeover.
Read more:The Hacker News
Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats Primary language: HTML. 1,762 stars.
Open project:GitHub
#anti-phishing#blacklist#blocklist#crypto-scam
Aggregation of lists of malicious domains (phishing) that can be integrated into FortiGate firewalls and other products. Primary language: DIGITAL Command Language. 115 stars.
Open project:GitHub
#blocklist#blocklists#domains-blacklist#domains-list
Aggregation of lists of malicious IP addresses (C2, malware, phishing), to be blocked in the LAN > WAN direction, integrated into firewalls: FortiGate, Palo Alto, pfSense, IPtables 40 stars.
Open project:GitHub
#blocklist#blocklists#c2#firewall
TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes. 681 stars.
Open project:GitHub
#blueteam#malware#malware-detection#malware-research
🐟 PhishTank Blocklist for Pi-hole Primary language: Shell. 13 stars.
Open project:GitHub
#blocklist#hosts#phishing#pihole
Coverage Map
Specific campaigns, actor activity, and the lures behind them.
How techniques work end-to-end — walkthroughs and operator workflows.
Adversary infrastructure: kits, AiTM, redirectors, and sending abuse.
Detection engineering, telemetry, validation, and response.
Longer research notes, measurement, and periodic briefs.
Search Tool
Search titles, authors, tags, and body text across the PhishPond research archive.
Showing 8 matching entries.Clear search
Field Analysis
Phishing kits get the headlines, but the hosting underneath them is the durable asset. A May 2026 seizure of 800+ servers, resilient scanning networks, and the routine hop behind a CDN show why takedowns rarely stick and where the defensible signal actually lives.
Read more:CISA (with NSA, DC3, FBI, and international partners)ELLIO
Field Analysis
Arctic Wolf's June 2 follow-up describes the Kali365 operator expanding well beyond Microsoft 365: Okta SSO, Xerox DocuShare, AWS-style endpoints, and a Russian-language cluster including MAX Messenger account takeover via real SMS OTPs. Proofpoint's research places the kit inside a broader cluster of AI-generated device-code lookalikes.
Read more:Arctic Wolf LabsProofpoint
Field Analysis
Mailbox rules, OAuth grants, replayed sessions, RMM agents, and downstream account changes are not the aftermath of an intrusion — they are the point. A field guide to the persistence layer most response playbooks still treat as cleanup.
Read more:FBI IC3The Hacker News
Field Analysis
Vendor headlines about AI phishing blend volume, effectiveness, and survey sentiment into single numbers. Defenders need to separate those measurements to instrument the threat honestly.
Field Analysis
Storm-1747 sells Tycoon 2FA - one of the most prolific reverse-proxy phishing kits in current circulation. This brief is what a defender team needs to know about the operator class.
Read more:Microsoft Threat IntelligenceSekoia
Field Analysis
Device code phishing turns a legitimate OAuth flow into a credential-free token theft technique. Here is how it runs end-to-end and what defenders can hunt on in Sentinel and Defender XDR.
Read more:Microsoft Security BlogIETF
Field Analysis
AitM kits proxy a real identity provider page, so brand and URL checks fail. The detectable artifacts live one layer down - in TLS handshake fingerprints, in the cookies the proxy must rewrite, and in the small page-side tells that betray the relay.
Read more:SekoiaMicrosoft Threat Intelligence
Field Analysis
Storm-1811 chained voice phishing, Microsoft Teams external chats, and Quick Assist into a remote-control persistence path that ended in Black Basta deployments. Here is the chain step by step.
Read more:Microsoft Threat IntelligenceRapid7