Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Duo Labs’ 2017 analysis of more than 3,200 recovered phishing kits showed how packaged credential-theft tools could be filtered, reused across hosts, and equipped with code that gave kit developers access to compromised sites. The findings offer a detailed look at that sample—not a measure of phishing activity today.

How researchers assembled the sample

For one month in 2017, Duo Labs monitored phishing URLs reported to the community-driven PhishTank and OpenPhish feeds. The team examined more than 66,000 candidate URLs and retrieved kit archives when the associated hosting directories exposed them. The researchers collected more than 3,200 unique kits, according to Duo Labs’ account of the project and contemporary coverage by SecurityWeek.

Those two counts describe different stages of collection: candidate URLs were feed submissions, while kits were archives the researchers could recover and identify. As researcher Jordan Wright noted in an interview with The CyberWire, anyone could submit a URL to the feeds, so the candidate total should not be read as 66,000 verified malicious sites. Nor does a month-long collection from 2017 establish how common these techniques are now.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a phishing kit does

A phishing kit is a bundle of files that can include a spoofed sign-in page and scripts to collect and forward whatever a visitor enters. It lowers the work required to imitate a target’s login experience and route captured credentials to an operator. Rather than building each campaign from scratch, an attacker can deploy and reuse a prepared package.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

That convenience also creates risk for the person hosting the kit: the package may contain code written by its developer, not just by the campaign operator. Duo Labs’ analysis and SecurityWeek’s report describe both filtering behavior and developer backdoors in the collected files.

Filtering, backdoors, and reuse in the 2017 findings

Filters could hide pages from some visitors

Researchers observed filtering implemented through .htaccess configuration and PHP code. Some code could block connections associated with threat-intelligence services, making a phishing page less visible to certain visitors or scanners. This is evidence of behavior in the recovered sample, not proof that every kit used such filters.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Developer backdoors could expose the host

SecurityWeek reported more than 200 detected instances of backdoors attributed to kit developers. Such code could let a kit author access a host where someone else had installed the kit. The kit therefore could create a second security problem beyond the credential theft its operator intended.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Repeated kits and email addresses offered investigative clues

SecurityWeek reported that 27%—more than 900—of the kits appeared on more than one host, and that two kits appeared on more than 30 hosts. Duo Labs also reported that one email address appeared in more than 115 unique kits. Repeated code, credential-routing details, and email addresses can help investigators connect files, hosts, and possible campaigns; by themselves, they do not establish who controlled each host or account.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What defenders can learn from a recovered kit

When a kit targets an organization, examining a safely acquired copy can help incident responders determine what information its scripts sought to capture and where the data was configured to go. That can inform the response: which credentials may need to be reset, which accounts and systems should be reviewed, and what evidence to preserve for investigation.

  • Protect potentially exposed accounts: Treat credentials entered into a suspected phishing page as compromised, reset them through the legitimate service, and review account activity. Prioritize accounts that can reset other passwords or access sensitive systems.
  • Investigate the routing configuration: If responders have a safely obtained kit copy, identify its collection and forwarding behavior without submitting real credentials or interacting with an active criminal endpoint.
  • Coordinate the response: Preserve relevant logs and artifacts, and work with the affected organization’s security team, hosting provider, or appropriate authorities. Removing files directly from a compromised host can cause collateral damage, as SecurityWeek’s account cautioned.

The 2017 study’s value is methodological as much as numerical: a recovered kit can reveal what an attack was built to collect and how its operators may have linked or reused it. Its counts remain a description of one historical collection, not a current threat-rate estimate.

Rank #4
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.