Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    It is reportedly allegedly scrapping websites, it is not believed again

    August 5, 2025

    Jeh Aerospace Net $ 11m to score the supply chain of commercial aircraft in India

    August 5, 2025

    Trump CFTC Pick Brian Quintage questioned Kalshi relations

    August 5, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»CGUI Fishing platform sent 580 million emails to steal credentials
    Security

    CGUI Fishing platform sent 580 million emails to steal credentials

    PineapplesUpdateBy PineapplesUpdateMay 7, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    CGUI Fishing platform sent 580 million emails to steal credentials
    Share
    Facebook Twitter LinkedIn Pinterest Email

    CGUI Fishing platform sent 580 million emails to steal credentials

    A new phishing kit called ‘Kugui’ sent more than 580 million emails to the target between January and April 2025, aimed at stealing account credentials and payment data.

    Messages implement major brands such as Amazon, Rakutane, PayPal, Apple, Tax Agencies and Banks.

    The activity concluded in January 2025, where 170 campaigns sent 172,000,000 fishing messages to the target, but the next months maintained equally impressive versions.

    Proofpoint researchers discovered CGUI campaigns, stating that this is the highest volume fishing campaign they currently track. The attacks mainly target Japan, although small -scale campaigns were also directed in the United States, Canada, Australia and New Zealand.

    Kagui is active at least from October 2024, but Proofpoint started trekking It further in December.

    Fishing email volume generated by Cagui
    Fishing email volume generated by Cagui
    Source: Proofpoint

    Analysts found several similarities for the dark fishing kit, which are associated with the China-based operators, and initially it was believed that the origin of the Kogo attacks is the same.

    However, on deep examination, proofpoint concluded that two fishing kits are unrelated, even though they are used by Chinese danger actors.

    Kogi attack chain

    The attack begins with a fishing email that applies a reliable brand, often requires the action of the recipient.

    Messages include an URL that redirects the host on the Kagui Fishing platform, but the link is solved only when the target fulfills pre-defined specific criteria by the assailants.

    These criteria include their IP address (location), browser language, operating system, screen resolution and device type (mobile or desktop).

    If the criteria is not met, the victims are redirected to the valid site of the brand that was imposed to reduce doubts.

    Called goals are redirected to a fishing page, characterized by a fake login form that mimics the design of the real brand, which helps the victims to enter their sensitive information.

    Fake Amazon Login Page
    Fake Amazon Login Page
    Source: Proofpoint

    Proofpoint has also found that Kagui was behind the operations targeting the United States with ‘outstanding toll payments’. However, it was noted that most of that activity have now moved to Darula.

    Researchers believe that CGUI facilitates operating many danger actors, mainly from China, who mainly target Japanese users.

    However, the kit can be adopted by other cyber criminals at any time with a separate targeting scope, resulting in a large -scale attack waves kill other countries.

    The best way to reduce fishing risks is never to work with a hurry when receiving emails, which request immediate action, and always log in independently on the claimed platform instead of following embedded links.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    CGUI credentials emails Fishing million platform steal
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSamsung announced an unpacked event on 12 May only – Get ready for Galaxy S25 Age
    Next Article The fed keeps the rates stable. Here is how it affects the mortgage rates.
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Certain bug leaked in proton log fixes the totup secrets

    August 5, 2025
    Security

    Rainmware attacks: danger of developing US financial institutions

    August 5, 2025
    Security

    Anthropic AI wants to stop the model from evil – how is here

    August 4, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    It is reportedly allegedly scrapping websites, it is not believed again

    August 5, 2025

    Jeh Aerospace Net $ 11m to score the supply chain of commercial aircraft in India

    August 5, 2025

    Trump CFTC Pick Brian Quintage questioned Kalshi relations

    August 5, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.