{"id":43553,"date":"2021-10-21T15:00:48","date_gmt":"2021-10-21T15:00:48","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=99249"},"modified":"2021-10-21T15:00:48","modified_gmt":"2021-10-21T15:00:48","slug":"franken-phish-todayzoo-built-from-other-phishing-kits","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/","title":{"rendered":"Franken-phish: TodayZoo built from other phishing kits"},"content":{"rendered":"<p>A phishing kit built using pieces of code copied from other kits, some available for sale through publicly accessible scam sellers or are reused and repackaged by other kit resellers, provides rich insight into the state of the economy that drives phishing and email threats today. We uncovered this phishing kit while examining an extensive series of credential phishing campaigns that all sent credentials to a set of endpoints operated by the attackers.<\/p>\n<p>We named the kit \u201cTodayZoo\u201d because of its curious use of these words in its credential harvesting component in earlier campaigns, likely a reference to phishing pages that spoofed a popular video conferencing application. Our prior research on phishing kits told us TodayZoo contained large pieces of code copied from widely circulated ones. The copied code segments even have the comment markers, dead links, and other holdovers from the previous kits.<\/p>\n<p>Today\u2019s phishing attacks operate on a landscape fueled by an evolved <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/09\/21\/catching-the-big-fish-analyzing-a-large-scale-phishing-as-a-service-operation\/\">service-based economy<\/a> filled with efficient, reliable, and profitable offerings. Attackers who wish to launch a phishing campaign may rent their resource and infrastructure needs from phishing-as-a-service (PhaaS) providers, who do the legwork for them. Alternatively, they can make a one-time purchase of a phishing kit that they can \u201cplug and play.\u201d<\/p>\n<p>That\u2019s not to say that attackers who build their kits from the ground up are at a disadvantage. If anything, the abundance of phishing kits and other tools available for sale or rent makes it easy for a lone wolf attacker to pick and choose the best features from these kits. They put these functionalities together in a customized kit and try to reap the benefits all to themselves. Such is the case of TodayZoo: because of the consistency in the redirection patterns, domains, and other techniques, tactics, and procedures (TTPs) of its related campaigns, we believe that the actors behind it came across an old phishing kit template and replaced the credential harvesting part with its own exfiltration logic to make TodayZoo solely for their nefarious purposes.<\/p>\n<p>Since the first observed instances of the TodayZoo phishing kit last December, large email campaigns leading to it have continued without significant pause. Our analysis of its phishing page artifacts, redirection routines, and domain generation algorithm (DGA) methods for the initial sites helps ensure <a href=\"https:\/\/www.microsoft.com\/security\/business\/threat-protection\/office-365-defender\">Microsoft Defender for Office 365<\/a> effectively protect customers from the said campaigns.<\/p>\n<p>Microsoft tracks unique phishing kits, phishing services, and other components used in phishing to better protect customers from malicious emails at a larger scale. Combined with our monitoring of individual credential campaigns and the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/08\/18\/trend-spotting-email-techniques-how-modern-phishing-emails-hide-in-plain-sight\/\">latest evasion techniques<\/a>, our research into kits and services provides us with a better understanding of the structure of phishing email messages. Such threat intelligence and insights, in turn, feed into our protection technologies, such as Defender for Office 365 and <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/threat-protection\/microsoft-365-defender\">Microsoft 365 Defender<\/a>.<\/p>\n<p>This blog post details some of the technical aspects of a phishing campaign based on the TodayZoo kit. It also provides information about \u201cDanceVida,\u201d a potential parent family of kits based on a shared resource link, and how it and other historical patterns figure in TodayZoo\u2019s code structure.<\/p>\n<h2>What\u2019s in a kit?<\/h2>\n<p>A \u201cphishing kit\u201d or \u201cphish kit\u201d can refer to various parts of a set of software or services meant to facilitate phishing. The term refers most commonly to an archive file containing images, scripts, and HTML pages that enable an attacker to quickly set up an undetectable phishing page and collect credentials through it. However, \u201cphishing kit\u201d can also be used to refer specifically to the unique page itself that spoofs a brand and interacts with a user, collects the user\u2019s credentials, and posts them to an asset the attacker owns.<\/p>\n<p>Phishing kits are generally split into the following major components based on function:<\/p>\n<ul>\n<li><strong>Imitation: <\/strong>These components help make the login pages appear legitimate. These can include imagery to imitate welcome banners, as well as dynamically generated logos and branding that are fetched based on the target\u2019s email address. These components may also include legitimate links and \u201chelp\u201d or \u201cpassword reset\u201d buttons that navigate cautious users out of the page and onto legitimate sites.<\/li>\n<li><strong>Obfuscation: <\/strong>These components hide the pages\u2019 true purpose from scanners or automated security detection systems. Obfuscation techniques can be through encoding or individual functions designed to make the extraction of resources more difficult. Obfuscation can also include anti-sandboxing resources on the page or on the site that are called to enforce geofencing, CAPTCHAs, and others.<\/li>\n<li><strong>Credential harvest: <\/strong>These components facilitate the entry, collection, and exfiltration of the credentials the target user provides. These components also include information about where said credentials are sent, how they are stored, and which sites the user is sent to after giving their credentials.<\/li>\n<\/ul>\n<p>These components are seen in the TodayZoo phishing kit, which we will discuss in the following sections.<\/p>\n<h2>Breaking down a TodayZoo-based phishing campaign<\/h2>\n<p>The use of the TodayZoo phishing kit was initially seen in December 2020. Then, in March 2021, we observed a series of phishing campaigns abuse the <em>AwsApps[.]com<\/em> domain to send the email messages that eventually directed users to the final landing pages, leading us to examine the kit more closely. As of this writing, we have already notified Amazon about the abovementioned abuse in their domain, and they promptly took action.<\/p>\n<p>The attackers created malicious accounts at scale. Initially, the sender emails appeared with randomly generated domain names such as <em>wederfs76y3uwedi3uy89ewdu23ye87293eqwhduayqw[.]awsapps[.]com<\/em>. This contrasts legitimate emails\u2014and even some spoofed phishing ones\u2014where the subdomain would represent a company hostname.<\/p>\n<p>The email message itself was relatively simple: it impersonated Microsoft and leveraged <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/08\/18\/trend-spotting-email-techniques-how-modern-phishing-emails-hide-in-plain-sight\/\">a zero-point font obfuscation technique<\/a> in an attempt to evade detection. For example, in the early iterations of their campaign, the attackers used the <em>&lt;ins&gt;&lt;\/ins&gt;<\/em> tags to insert the date of the message every few characters invisibly, as shown below:<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-99273 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig1-zero-point-font-obfuscation.png\" alt=\"Screenshot of HTML code showing zero-point font technique\" width=\"1533\" height=\"271\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig1-zero-point-font-obfuscation.png 1533w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig1-zero-point-font-obfuscation-300x53.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig1-zero-point-font-obfuscation-1024x181.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig1-zero-point-font-obfuscation-768x136.png 768w\" sizes=\"auto, (max-width: 1533px) 100vw, 1533px\"><\/p>\n<p><em>Figure 1. Example of zero-point font obfuscation to insert the date into the HTML code of the email message<\/em><\/p>\n<p>The social engineering lures in the message body repeatedly changed over the months. Campaigns in April and May used password reset, while more the recent campaigns in August were leveraging fax and scanner notifications.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-99276 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig2-Email-lure-TodayZoo.png\" alt=\"Screenshot of email used in this campaign\" width=\"651\" height=\"302\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig2-Email-lure-TodayZoo.png 651w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig2-Email-lure-TodayZoo-300x139.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig2-Email-lure-TodayZoo-539x249.png 539w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig2-Email-lure-TodayZoo-465x215.png 465w\" sizes=\"auto, (max-width: 651px) 100vw, 651px\"><\/p>\n<p><em>Figure 2. Example of an email lure leading to TodayZoo phishing kit<\/em><\/p>\n<p>Regardless of the lure, the following attack chain is consistent, with initial and secondary redirectors, a final landing page, and a credential harvesting page. Below is a sample of TodayZoo\u2019s attack chain URLs:<\/p>\n<ul>\n<li><strong>Initial redirector:<\/strong> hxxp:\/\/2124658742[.]ujsd[.]pentsweser[.]com\/\/fhwpp8sv[.]#aHR0cHM6Ly9saW1lc3RvbmVzbS5jb20vZWRmaC5rZXJmcS8jbm8tcmVwbHlAbWljcm9zb2Z0LmNvbQ==<\/li>\n<li><strong>Secondary redirector:<\/strong> hxxps:\/\/limestonesm[.]com\/edfh.kerfq\/#no-reply@microsoft[.]com<\/li>\n<li><strong>Final landing page: <\/strong>hxxps:\/\/fra1[.]digitaloceanspaces[.]com\/koip\/25_40_24_5E_40_26_40_26_28_29_23_23_5E_23_24_26_5E_25_26_40_5E_28_23_26.html#no-reply@microsoft[.]com<\/li>\n<li><strong>Credential harvesting page: <\/strong>hxxps:\/\/nftduniya[.]com\/cas\/vcoominctodayq[.]php<\/li>\n<\/ul>\n<p>The initial and secondary URLs are either compromised or attacker-created sites and serve as redirectors to funnel the more extensive set of URLs used in the emails to the final landing page where the phishing kit is hosted. The initial URL used infinite subdomains, a previously discussed technique that allows attackers to use a unique URL for each recipient while only purchasing or compromising one domain. The URL also leveraged malformed URLs that consisted of multiple forward slashes at the demarcation of the path, as well as the secondary URL that is encoded along with the recipient\u2019s email address.<\/p>\n<p>In almost every instance of the TodayZoo-based campaign we\u2019ve seen, the final landing page is hosted within the service provider DigitalOcean. This page bears a few tangible differences from a standard Microsoft 365 sign-in page. Notably, it has not substantially changed in appearance from the start of the year to the time of publication of this blog. This lack of change is because, despite the numerous changes in the delivery method, lures, and sites used as indicators of attack (IOAs), the TodayZoo kit stayed nearly identical with only a few strings changing.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-99279 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig3-Phishing-page.jpg\" alt=\"Screenshot of phishing page where credentials are stolen\" width=\"1363\" height=\"913\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig3-Phishing-page.jpg 1363w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig3-Phishing-page-300x201.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig3-Phishing-page-1024x686.jpg 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig3-Phishing-page-768x514.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig3-Phishing-page-293x195.jpg 293w\" sizes=\"auto, (max-width: 1363px) 100vw, 1363px\"><\/p>\n<p><em>Figure 3. An example of TodayZoo\u2019s fake sign-in page in August 2021<\/em><\/p>\n<p>There was little of the obfuscation component within the TodayZoo kit because the landing page\u2019s source code revealed where the stolen credentials would be exfiltrated, which was another compromised site ending in <em>TodayZoo.php<\/em>. Typically, credential harvesting pages process the credentials and forward them to additional email accounts owned by sellers or purchasers of the kit for collection later. It\u2019s unusual for campaigns to store the credentials locally on the site itself.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-99282 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig4-TodayZoo-credential-harvesting.png\" alt=\"Screenshot of code for credential harvesting\" width=\"624\" height=\"312\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig4-TodayZoo-credential-harvesting.png 624w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig4-TodayZoo-credential-harvesting-300x150.png 300w\" sizes=\"auto, (max-width: 624px) 100vw, 624px\"><\/p>\n<p><em>Figure 4. An excerpt from the TodayZoo HTML source depicting credential exfiltration<\/em><\/p>\n<p>It should be noted that based on our analysis, the file name <em>TodayZoo.php<\/em> appears to be derived from a previous version of the phishing kit whose credential processing page ends in <em>Zoom.php<\/em>. The said version also has markers like \u201cToday Zoom Meetings,\u201d indicating that it was initially targeting users of a popular video conferencing application.<\/p>\n<p>The succeeding TodayZoo-based campaigns follow the attack killchain pattern and source code discussed above. While for the first few months of operation, <em>TodayZoo.php<\/em> was utilized, the most recent harvesting pages have maintained the word \u201ctoday\u201d but now may use <em>vcoominctodayq.php<\/em> instead.<\/p>\n<p>The attackers have also moved from abusing a single legitimate mailing service to compromising mailing service accounts for their email campaigns. However, they maintain specific leftover character patterns in their URL paths and subdomains that work with the other TTPs described.<\/p>\n<h2>Piecing the puzzle<\/h2>\n<p>Typically, phishing kits that are resold or reused have indicators of multiple actors using them through their generated email campaigns. For example, these campaigns will have varying redirection techniques and hosting domains for their final landing pages. In the case of TodayZoo, as previously mentioned, there is consistency in the patterns, domains, and TTPs of the related campaigns. While many phishing kits are attributed to a wide variety of email campaign patterns and, conversely, many email campaign patterns are associated with many phishing kits, TodayZoo-based pages exclusively utilized the same email campaign patterns, and any of those subsequent email campaigns only surfaced TodayZoo kits. These lead us to believe that the actors behind this specific TodayZoo implementation are operating on their own.<\/p>\n<p>Within the source code of the TodayZoo landing page we analyzed, there were several static references at the very start to external sources. Generally, these external links help a phishing kit properly imitate the login page and other branding elements of the site they are spoofing. However, in TodayZoo\u2019s case, many of these site connections were \u201cdead links\u201d and did not serve a relevant function within the page. Littered throughout the source code as well were various markers like <em>&lt;!\u2013 FORM 1111111111111111 \u2013&gt;<\/em> and <em>&lt;!\u2013 FINISHHHHHHHHHHHHHHHHHHHHH \u2013&gt;<\/em>. Some portions of the source code also utilized multiple languages in different sections, making clear indications of which ones have been replaced.<\/p>\n<p>Upon further investigation, we identified the dead links and markers as holdovers from many other commoditized kits available for free or purchase. We then compared TodayZoo with other phishing kits we have analyzed previously and found that even these kits also contained references to sites like <em>Dancevida[.]com<\/em> but would have different code blocks for their obfuscation or credential harvest components.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-99285 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig5-TodayZoo-landing-page-source-code.png\" alt=\"Screenshot of TodayZoo code showing references to DanceVida \" width=\"1430\" height=\"320\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig5-TodayZoo-landing-page-source-code.png 1430w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig5-TodayZoo-landing-page-source-code-300x67.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig5-TodayZoo-landing-page-source-code-1024x229.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig5-TodayZoo-landing-page-source-code-768x172.png 768w\" sizes=\"auto, (max-width: 1430px) 100vw, 1430px\"><\/p>\n<p><em>Figure 5. An excerpt from a TodayZoo landing page source code referencing DanceVida[.]com<\/em><\/p>\n<h3>The DanceVida connection<\/h3>\n<p>\u201cDanceVida\u201d is more of a code block than a full-fledged phishing kit. As such, kits that use DanceVida are rather diverse in their delivery, lures, and location because they are directly for sale on various forums under kit-naming schemas, as well as under a wider variety of landing page templates, including document download pages. Most of the credentials that the DanceVida-based kits\u2019 harvesting pages gather are exfiltrated to accounts using free email services, such as GMail, Yahoo!, and Yandex.<\/p>\n<p>One of the more notable kits that also reference DanceVida and share components with what we observed in the TodayZoo credential phishing campaigns is \u201cOffice-RD117,\u201d which is related to an online seller known as \u201cFud Tool.\u201d This seller also offers other phishing kits and email and SMS delivery tools on various forums and other websites.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-99288 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig6-TodayZoo-FUD-tool.png\" alt=\"Screenshot of FUD Tool website\" width=\"1430\" height=\"419\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig6-TodayZoo-FUD-tool.png 1430w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig6-TodayZoo-FUD-tool-300x88.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig6-TodayZoo-FUD-tool-1024x300.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig6-TodayZoo-FUD-tool-768x225.png 768w\" sizes=\"auto, (max-width: 1430px) 100vw, 1430px\"><\/p>\n<p><em>Figure 6: Screenshot of<\/em><em> the now-defunct Fud Tool website from the Wayback Machine Internet Archive<\/em><\/p>\n<p>It is interesting to note that when analyzing the Office-RD117 kit, we also saw signatures from multiple sellers within its packaged resources. There are also instances of dead links, such as a reference to a GitHub account that was only live for less than a day in January 2020 (the said account is still carried over to kits online as of this writing). This goes to show that even commercially available phishing kits reuse and repurpose elements from other ones. Such mixing and matching also make it quite challenging to determine where one kit ends and another one begins.<\/p>\n<h3>Comparing TodayZoo with DanceVida and other kits<\/h3>\n<p>In the case of TodayZoo, we observed that its implementations only match the larger superset of kits referencing DanceVida at about 30-35%. As seen in the figures below that compare a TodayZoo sample with a randomly selected DanceVida sample, both initially have similar structure and pieces of code until TodayZoo deviated in the credential harvesting component:<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-99291 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig7-DanceVida-TodayZoo-matching-source-code.png\" alt=\"Screenshots comparing source code for DanceVida and TodayZoo phishing kits\" width=\"1100\" height=\"351\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig7-DanceVida-TodayZoo-matching-source-code.png 1100w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig7-DanceVida-TodayZoo-matching-source-code-300x96.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig7-DanceVida-TodayZoo-matching-source-code-1024x327.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig7-DanceVida-TodayZoo-matching-source-code-768x245.png 768w\" sizes=\"auto, (max-width: 1100px) 100vw, 1100px\"><\/p>\n<p><em>Figure 7. A comparison of DanceVida and TodayZoo kits, showing matching source codes<\/em><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-99294 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig8-DanceVida-TodayZoo-similar-source-codes.png\" alt=\"Screenshots comparing source code for DanceVida and TodayZoo phishing kits\" width=\"1100\" height=\"543\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig8-DanceVida-TodayZoo-similar-source-codes.png 1100w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig8-DanceVida-TodayZoo-similar-source-codes-300x148.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig8-DanceVida-TodayZoo-similar-source-codes-1024x505.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig8-DanceVida-TodayZoo-similar-source-codes-768x379.png 768w\" sizes=\"auto, (max-width: 1100px) 100vw, 1100px\"><\/p>\n<p><em>Figure 8. A comparison of DanceVida and TodayZoo kits showing highly similar source codes. Note how TodayZoo has changed its variables.<\/em><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-99297 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig9-DanceVida-TodayZoo-credential-posting.png\" alt=\"Screenshots comparing source code for DanceVida and TodayZoo phishing kits\" width=\"1100\" height=\"316\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig9-DanceVida-TodayZoo-credential-posting.png 1100w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig9-DanceVida-TodayZoo-credential-posting-300x86.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig9-DanceVida-TodayZoo-credential-posting-1024x294.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig9-DanceVida-TodayZoo-credential-posting-768x221.png 768w\" sizes=\"auto, (max-width: 1100px) 100vw, 1100px\"><\/p>\n<p><em>Figure 9. A comparison of DanceVida and TodayZoo kits showing slightly different implementation for credential posting<\/em><\/p>\n<p>To further illustrate the \u201cFrankenstein\u2019s monster\u201d characteristic of TodayZoo, the table below expands the comparison of one of its current phishing pages with Office-RD117, as well as with four other landing pages. These landing pages are unattributed to specific operators and reference DanceVida or use the same credential-harvesting POST statements. While all these samples share code segments in their imitation, obfuscation, or credential harvesting components, they each still have unique elements that differentiate them.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-99366 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Table1c-related-phish-kits.png\" alt=\"Table comparing different phishing kits and their similarity with TodayZoo\" width=\"800\" height=\"256\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Table1c-related-phish-kits.png 800w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Table1c-related-phish-kits-300x96.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Table1c-related-phish-kits-768x246.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\"><\/p>\n<p><em>Table 1. Similarity areas and percentages of related phish kits to a recent TodayZoo sample<\/em><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-99300 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig10-related-phish-kits-TodayZoo.png\" alt=\"Visual representation of similarity of code between TodayZoo and other phishing kits\" width=\"878\" height=\"654\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig10-related-phish-kits-TodayZoo.png 878w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig10-related-phish-kits-TodayZoo-300x223.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/10\/Fig10-related-phish-kits-TodayZoo-768x572.png 768w\" sizes=\"auto, (max-width: 878px) 100vw, 878px\"><\/p>\n<p><em>Figure 10. Graphical representation of the similarity areas of related phish kits to a recent TodayZoo sample<\/em><\/p>\n<p>The above comparisons show a history of alterations and suggest an existence of a \u201ccore\u201d set of codes being reused by these phishing kits. They are also reminiscent of how remote access Trojans (RAT) and other malware families are continuously retooled by threat actors yet retain large chunks of code blocks across the board.<\/p>\n<h2>How threat intelligence enriches anti-phishing technologies in Microsoft Defender for Office 365<\/h2>\n<p>Our analysis of TodayZoo, DanceVida, and other phishing kits gives us several insights into the underground economy today. First, this research further proves that most phishing kits observed or available today are based on a smaller cluster of larger kit \u201cfamilies.\u201d While this trend <a href=\"https:\/\/www.imperva.com\/blog\/our-analysis-of-1019-phishing-kits\/\">has been observed previously<\/a>, it continues to be the norm, given how phishing kits we\u2019ve seen share large amounts of code among themselves. The continued presence of dead links and callbacks to other kits indicates that many phishing kit distributors and phishing operators have easy access to these existing kits and use parts of them to make new ones faster.<\/p>\n<p>Secondly, our research shows that the players in the cybercrime economy count on a lack of examination into their products. Whether that is a bane or a boon on their part depends on how the products\u2019 codes are implemented. For example, an unchecked reused kit that still calls back to its original creator with copies of stolen credentials potentially translates into an equivalent of a passive income for the said creator.<\/p>\n<p>Insights such as those presented above enrich our protection technologies. Our intelligence on unique phishing kits such as TodayZoo, phishing services, and other components of phishing&nbsp;attacks&nbsp;allows&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/business\/threat-protection\/office-365-defender\">Microsoft Defender for Office 365<\/a> to detect related campaigns and block malicious emails, URLs, and landing pages. Combined with Defender for Office 365\u2019s use of machine learning, heuristics, and advanced&nbsp;detonation technology, such intel also makes it possible to detect kits that attempt&nbsp;to leverage techniques from one or multiple codes, even before a user receives the email or interacts with the content.<\/p>\n<p>Threat intelligence about the latest trends in the phishing landscape also feeds into other Microsoft security solutions, such as <a href=\"https:\/\/docs.microsoft.com\/windows\/security\/threat-protection\/microsoft-defender-smartscreen\/microsoft-defender-smartscreen-overview\">Microsoft Defender SmartScreen<\/a>, which blocks phishing websites and malicious URLs and domains in the browser, and <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/network-protection?view=o365-worldwide\">Network protection<\/a>, which blocks connections to malicious domains and IP addresses. <a href=\"https:\/\/docs.microsoft.com\/microsoft-365\/security\/defender-endpoint\/advanced-hunting-overview?view=o365-worldwide\">Advanced hunting<\/a> capabilities allow analysts to search for phishing kit components and other IOAs.<\/p>\n<p>Organizations can configure the <a href=\"https:\/\/docs.microsoft.com\/microsoft-365\/security\/office-365-security\/recommended-settings-for-eop-and-office365?view=o365-worldwide\">recommended settings in Microsoft Defender for Office 365<\/a>, such as applying anti-phishing, <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/set-up-safe-links-policies?view=o365-worldwide\">Safe Links<\/a>, and <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/set-up-safe-attachments-policies?view=o365-worldwide\">Safe Attachments<\/a> policies. These ensure real-time protection by scanning at the time of delivery and at the time of click. They can further strengthen their protection with&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/threat-protection\/microsoft-365-defender\">Microsoft 365 Defender<\/a>, which correlates signals from emails, endpoints, and other domains, delivering coordinated defense.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/threat-protection\/office-365-defender\">Learn how you can stop&nbsp;credential phishing and other email threats&nbsp;through&nbsp;comprehensive,&nbsp;industry-leading protection&nbsp;with Microsoft Defender for Office 365<\/a>.<\/p>\n<p>Visit our <a href=\"https:\/\/www.microsoft.com\/en-us\/securitynow\">National Cybersecurity Awareness Month page<\/a> for more resources and information on protecting your organization year-round. <strong>Do your part. #BeCyberSmart<\/strong><\/p>\n<p><em>Microsoft 365 Defender Threat Intelligence Team<\/em><\/p>\n<h3>Advanced hunting queries<\/h3>\n<p><strong>Emails with TodayZoo operator patterns<\/strong><\/p>\n<p>Use this query to find emails sent that utilize additional forward slashes at the path and domain split point and utilize the TodayZoo operators\u2019 patterns in the path and the subdomain structure. TodayZoo operators occasionally store URLs in the attachment, so this query would not surface those instances.<\/p>\n<p><code>EmailUrlInfo<br \/>| where Url matches regex \"(ujsd)?\\\\.[a-z]+\\\\.com\\\\\/\\\\\/.+\\\\.#\"<\/code><\/p>\n<p><strong>Endpoint activity where TodayZoo patterns redirect to DigitalOcean<\/strong><\/p>\n<p>Use this query to find emails sent that utilize additional forward slashes at the path and domain split point and utilize the TodayZoo operators\u2019 patterns in the path and the subdomain structure.<\/p>\n<p><code>DeviceNetworkEvents<br \/>| where RemoteUrl matches regex \"(ujsd)\\\\.[a-z]+\\\\.com\\\\\/\\\\\/.+\\\\.#\" or RemoteUrl endswith \"digitaloceanspaces.com\"<br \/>| extend Domain = extract(@\"[^.]+(\\.[^.]{2,3})?\\.[^.]{2,12}$\", 0, RemoteUrl)<br \/>| summarize dcount(Domain), make_set(Domain) by DeviceId,bin(Timestamp, 1h), InitiatingProcessFileName, InitiatingProcessCommandLine<br \/>| where dcount_Domain &gt;= 2<\/code><\/p>\n<h3>Indicators of compromise<\/h3>\n<p><strong>Sample initial base domains<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"208\">pentsweser[.]com<\/td>\n<td width=\"208\">eurhutos[.]com<\/td>\n<td width=\"208\">dalotcii[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">buiyosi[.]com<\/td>\n<td width=\"208\">gsuouyty[.]com<\/td>\n<td width=\"208\">matanictii[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">phmakert[.]com<\/td>\n<td width=\"208\">brepeme[.]com<\/td>\n<td width=\"208\">conncorrd[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">sazmath[.]com<\/td>\n<td width=\"208\">normmavec[.]com<\/td>\n<td width=\"208\">jumperctin[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">selfessdas[.]com<\/td>\n<td width=\"208\">kurvuty[.]com<\/td>\n<td width=\"208\">iotryfuty[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">setmakersl[.]com<\/td>\n<td width=\"208\">vlogctii[.]com<\/td>\n<td width=\"208\">coffimkeer[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">mosyeurty[.]com<\/td>\n<td width=\"208\">qurythuy[.]com<\/td>\n<td width=\"208\">carlssbad[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">chovamb[.]com<\/td>\n<td width=\"208\">tenssmor[.]com<\/td>\n<td width=\"208\">tenssmr[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">coffkeer[.]com<\/td>\n<td width=\"208\">tamsops[.]com<\/td>\n<td width=\"208\">speedoms[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">shageneppi[.]com<\/td>\n<td width=\"208\">shadain[.]com<\/td>\n<td width=\"208\">coffieer[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">cofeer[.]com<\/td>\n<td width=\"208\">carrtwright[.]com<\/td>\n<td width=\"208\">uyfteuty[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">slobhurtiy[.]com<\/td>\n<td width=\"208\">braingones[.]com<\/td>\n<td width=\"208\">beinsmter[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ksfcaghyou[.]com<\/td>\n<td width=\"208\">coffkr[.]com<\/td>\n<td width=\"208\">rtuatatcty[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">lamyot[.]com<\/td>\n<td width=\"208\">tenssm[.]com<\/td>\n<td width=\"208\">kanesatakss[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">brainsdeads[.]com<\/td>\n<td width=\"208\">ourygshry[.]com<\/td>\n<td width=\"208\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Sample initial domains with subdomains<\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"312\">1776769042[.]ujsd[.]iotryfuty[.]com<\/td>\n<td width=\"312\">443577567[.]ujsd[.]iotryfuty[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">646611056[.]ujsd[.]gsuouyty[.]com<\/td>\n<td width=\"312\">1007183231[.]ujsd[.]gsuouyty[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">1469782555[.]ujsd[.]phmakert[.]com<\/td>\n<td width=\"312\">1436029448[.]ujsd[.]buiyosi[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">946552600[.]ujsd[.]buiyosi[.]com<\/td>\n<td width=\"312\">1733787821[.]ujsd[.]buiyosi[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">1988722677[.]ujsd[.]eurhutos[.]com<\/td>\n<td width=\"312\">255622856[.]ujsd[.]eurhutos[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">600774497[.]ujsd[.]sazmath[.]com<\/td>\n<td width=\"312\">1315116569[.]ujsd[.]setmakersl[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">1179340144[.]ujsd[.]sazmath[.]com<\/td>\n<td width=\"312\">516942697[.]ujsd[.]setmakersl[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">1742965301[.]ujsd[.]setmakersl[.]com<\/td>\n<td width=\"312\">124967719[.]ujsd[.]normmavec[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">202271174[.]ujsd[.]pentsweser[.]com<\/td>\n<td width=\"312\">1010306526[.]ujsd[.]iotryfuty[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">728156920[.]ujsd[.]iotryfuty[.]com<\/td>\n<td width=\"312\">1244535616[.]ujsd[.]selfessdas[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">1227334331[.]ujsd[.]selfessdas[.]com<\/td>\n<td width=\"312\">1229648857[.]ujsd[.]kurvuty[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">926765708[.]ujsd[.]kurvuty[.]com<\/td>\n<td width=\"312\">254503147[.]ujsd[.]kurvuty[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">1656812361[.]ujsd[.]dalotcii[.]com<\/td>\n<td width=\"312\">100666740[.]ujsd[.]matanictii[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">404793834[.]ujsd[.]matanictii[.]com<\/td>\n<td width=\"312\">879643450[.]ujsd[.]matanictii[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">658338120[.]ujsd[.]matanictii[.]com<\/td>\n<td width=\"312\">1359496128[.]ujsd[.]dalotcii[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">995216045[.]ujsd[.]dalotcii[.]com<\/td>\n<td width=\"312\">1838392685[.]ujsd[.]dalotcii[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">9725332[.]ujsd[.]brepeme[.]com<\/td>\n<td width=\"312\">1668463162[.]ujsd[.]conncorrd[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"312\">165175575[.]ujsd[.]sazmath[.]com<\/td>\n<td width=\"312\">215852665[.]ujsd[.]brepeme[.]com<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Sample initial URLs<\/strong><\/p>\n<ul>\n<li>odghyuter[.]com\/\/wfvmlpxuhjeq[.]#aHR0cHM6Ly9wb2dmaHJ5ZXQuY29tL2VkZmgua2VyZnEvI25vLXJlcGx5QG1pY3Jvc29mdC5jb20=<\/li>\n<li>ujsd.coffimkeer[.]com\/\/0jw7yklk[.]#aHR0cHM6Ly9sdWh5cnR5ZS5jb20vZWRmaC5rZXJmcS8jbm8tcmVwbHlAbWljcm9zb2Z0LmNvbQ==<\/li>\n<li>ujsd.pentsweser[.]com\/\/iojjyaqw[.]#aHR0cHM6Ly9saW1lc3RvbmVzbS5jb20vZWRmaC5rZXJmcS8jbm8tcmVwbHlAbWljcm9zb2Z0LmNvbQ==<\/li>\n<li>ujsd.brepeme[.]com\/\/bnxvhyex[.]#aHR0cHM6Ly92YWVwbGVyLmNvbS9lZGZoLmtlcmZxLyNuby1yZXBseUBtaWNyb3NvZnQuY29t<\/li>\n<\/ul>\n<p><strong>Sample secondary (redirector) URLs<\/strong><\/p>\n<ul>\n<li>pogfhryet[.]com\/edfh[.]kerfq\/#no-reply@microsoft[.]com<\/li>\n<li>luhyrtye[.]com\/edfh[.]kerfq\/#no-reply@microsoft[.]com<\/li>\n<\/ul>\n<p><strong>Sample final landing page<\/strong><\/p>\n<ul>\n<li>nyc3[.]digitaloceanspaces[.]com\/bnj\/25_40_24_5E_40_26_40_26_28_29_23_23_5E_23_24_26_5E_25_26_40_5E_28_23_26_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25_%25[.]html#no-reply@microsoft[.]com<\/li>\n<\/ul>\n<p><strong>Sample credential harvesting page<\/strong><\/p>\n<ul>\n<li>lcspecops[.]com\/psl\/vcoominctodayq[.]php<\/li>\n<\/ul>\n<h3>References<\/h3>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/10\/21\/franken-phish-todayzoo-built-from-other-phishing-kits\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A phishing kit built using pieces of code copied from other kits, some available for sale through publicly accessible scam sellers or are reused and repackaged by other kit resellers, provides rich insight into the state of the economy that drives phishing and email threats today.<br \/>\nThe post Franken-phish: TodayZoo built from other phishing kits appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":43554,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347,7221,188,9584],"class_list":["post-43553","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity","tag-microsoft-security-intelligence","tag-phishing","tag-zero-point-font"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Franken-phish: TodayZoo built from other phishing kits 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Franken-phish: TodayZoo built from other phishing kits 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-21T15:00:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/franken-phish-todayzoo-built-from-other-phishing-kits.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1533\" \/>\n\t<meta property=\"og:image:height\" content=\"271\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Franken-phish: TodayZoo built from other phishing kits\",\"datePublished\":\"2021-10-21T15:00:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/\"},\"wordCount\":3272,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/franken-phish-todayzoo-built-from-other-phishing-kits.png\",\"keywords\":[\"Cybersecurity\",\"Microsoft security intelligence\",\"Phishing\",\"zero-point font\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/\",\"name\":\"Franken-phish: TodayZoo built from other phishing kits 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/franken-phish-todayzoo-built-from-other-phishing-kits.png\",\"datePublished\":\"2021-10-21T15:00:48+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/franken-phish-todayzoo-built-from-other-phishing-kits.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/franken-phish-todayzoo-built-from-other-phishing-kits.png\",\"width\":1533,\"height\":271},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/franken-phish-todayzoo-built-from-other-phishing-kits\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Franken-phish: TodayZoo built from other phishing kits\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Franken-phish: TodayZoo built from other phishing kits 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/","og_locale":"en_US","og_type":"article","og_title":"Franken-phish: TodayZoo built from other phishing kits 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-10-21T15:00:48+00:00","og_image":[{"width":1533,"height":271,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/franken-phish-todayzoo-built-from-other-phishing-kits.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Franken-phish: TodayZoo built from other phishing kits","datePublished":"2021-10-21T15:00:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/"},"wordCount":3272,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/franken-phish-todayzoo-built-from-other-phishing-kits.png","keywords":["Cybersecurity","Microsoft security intelligence","Phishing","zero-point font"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/","url":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/","name":"Franken-phish: TodayZoo built from other phishing kits 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/franken-phish-todayzoo-built-from-other-phishing-kits.png","datePublished":"2021-10-21T15:00:48+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/franken-phish-todayzoo-built-from-other-phishing-kits.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/franken-phish-todayzoo-built-from-other-phishing-kits.png","width":1533,"height":271},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/franken-phish-todayzoo-built-from-other-phishing-kits\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"Franken-phish: TodayZoo built from other phishing kits"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43553","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=43553"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43553\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/43554"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=43553"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=43553"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=43553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}