Jake | JCyberSec_

9.4K posts

Jake | JCyberSec_ banner
Jake | JCyberSec_

Jake | JCyberSec_

@JCyberSec_

Expert in Credential Phishing and Phishing Kit Research. Working in Cyber Security - Threat Intelligence #Phishing

UK Katılım Ağustos 2017
76 Takip Edilen9.7K Takipçiler
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
@Gi7w0rm @UK_Daniel_Card LOL - That has been vibe coded to hell and back! Nice spot. Interesting open redirects abused but the phishing kit is hilarious.
English
1
0
2
46
Gi7w0rm
Gi7w0rm@Gi7w0rm·
#OAuth Token #Phishing Kit for #X .com observed hitting my inbox. The lure is sent by clientservices-tiffany[.]co emails. All links lead to a multi-step redirect. The ultimate goal is to add a malicious application to your X Accounts trusted applications store. 1/4
Gi7w0rm tweet media
English
1
19
39
4.9K
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
You must have heard of #Chenlun - A huge Chinese phishing framework 🌐 🔎All our automated detections are now clustered and attributed on @urlscanio Pro 💥Read our new threat intel report into this framework to know how to attribute, defend & mitigate the risk posed by this kit
urlscan.io@urlscanio

New TI report 📷 Chenlun (“Outsider”) is a feature-rich phishing kit using modern web frameworks, verification flows, and anti-bot techniques. A step up in sophistication across Chinese Phishing-as-a-Service ecosystems. Full analysis + detections 📷 urlscan.io/pricing/urlsca…

English
0
0
1
467
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
This is a much smaller Chinese phishing framework🇨🇳 🪙I bet you won't have heard of it before! 🌐What makes this notable is the targeting of Chinese companies by the framework🔎 🎯This is a Pro only report ✉️Reach out to sales@ if you are not on the pro platform!
urlscan.io@urlscanio

New TI report on urlscan Pro 📷 Flyfish is a lightweight phishing kit built around simple but effective API endpoints. Despite its simplicity, it’s actively used for large-scale victim interaction and data capture. Detection patterns included 📷 urlscan.io/pricing/urlsca…

English
0
2
4
913
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
If you have been tracking phishing kits you will have come across Darcula 🧛 🔢 There are 3 main version as well as fake shops all linked to this framework. 📚 Read the in-depth analysis on urlscan Pro platform, and the free version is on the blog now.
Jake | JCyberSec_ tweet media
urlscan.io@urlscanio

New report: Darcula (“Magic Cat”) is one of the most active phishing frameworks we’re tracking. From API-driven infra to socket-based comms and fake shop deployments, this kit continues to evolve rapidly. Breakdown, detections: urlscan.io/blog/2026/05/1… Full report on urlscan Pro

English
0
1
4
505
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
And we are off! The first in the series. ⚠️This one focuses on the newest and most rampant framework we are observing - ⚓Sailers Framework Previously undocumented at this depth 🎯 🔎Pro intel users: pro.urlscan.io/intel/reports/… 🔑Free report: urlscan.io/blog/2026/05/0…
urlscan.io@urlscanio

New urlscan report 🚨 We’re kicking off our Chinese phishing series with a deep dive into the Sailor framework. A modular kit leveraging client-side storage for session tracking and victim management at scale. Detection included 👇 urlscan.io/blog/2026/05/0…

English
0
0
2
430
Jake | JCyberSec_ retweetledi
urlscan.io
urlscan.io@urlscanio·
New research drop 🚨 We're diving deep into Chinese-language phishing-as-a-service ecosystems powering large-scale global campaigns. From infrastructure to operations, this series uncovers how these platforms scale and evade detection. Starting May 4th: urlscan.io/blog/2026/04/2…
urlscan.io tweet media
English
1
21
63
6.4K
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
@eKg_sec @executemalware @urlscanio - Amazing use of the tool to discover and hunt click fix campaigns. Similar hunting tactics as Magecart attacks with malicious injections after compromising a host.
English
0
0
4
191
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
📅Calendly phishing isn't new therefore we cut through the noise resulting in 7 new clearly defined clusters of campaigns 🔎These clusters allow for clean alerting and attribution supporting follow-on investigations.
urlscan.io@urlscanio

New urlscan Pro Threat Intel Report: We uncovered 7 distinct phishing kit clusters hiding behind Calendly-themed lures. Same brand, very different tooling & infrastructure. The report includes hunting queries & technical fingerprints for defenders.

English
0
0
2
493
Jake | JCyberSec_ retweetledi
The OSINT Newsletter
The OSINT Newsletter@osintnewsletter·
Got a suspicious URL but don't want to click it? 🔒 @urlscanio visits it for you - capturing a screenshot, every domain contacted, every script loaded, and the tech stack behind it. Used by Reuters in a real hacking investigation. Free for basic use: tools.osintnewsletter.com/osint-tools/ur…
The OSINT Newsletter@osintnewsletter

🚨 Launching: The OSINT Tools Library A curated, investigator-first directory of tools used in real cases. → Tools.OSINTNewsletter.com We’re building the largest and best maintained OSINT tools resource and need your help. Reply and tag a tool we should add 👇

English
11
261
1.6K
105.5K
Jake | JCyberSec_ retweetledi
urlscan.io
urlscan.io@urlscanio·
Community: We want to ensure our community platform remains viable to operate for us. To that end, some scan results will have promotions (not ads!) for related services injected into screenshot. These not-ads are very subtle and should not interfere with your operations.
urlscan.io tweet media
English
0
2
6
1.1K
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
JavaScript Proxy frameworks are interesting🖥️ 🔍Have you detected these being used in any campaigns? Investigating these is tricky but the fingerprints caused are simple to track!🎯
urlscan.io@urlscanio

TAs are weaponising client-side proxy frameworks like Ultraviolet & Scramjet to deliver stealthy phishing campaigns that evade traditional detection. Our latest urlscan Pro report covers techniques, artifacts, and detection strategies for this new threat: urlscan.io/pricing/urlsca…

English
0
0
0
1.7K
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
I believe this GitHub is associated with a different threat actor from TA446 🇷🇺 However attribution on the sdji hostname is unknown at this time 🤔
English
0
0
0
239
Jake | JCyberSec_
Jake | JCyberSec_@JCyberSec_·
The lmhtvn repo only came online Fri, 20 Mar 2026 21:35:37 +0700 GMT+7 (or UTC+7) is primarily located in Southeast Asia, covering countries like Thailand, Vietnam, Cambodia, Laos, and parts of Indonesia (Western Indonesia Time) This makes sense with the Philippines targeting
English
1
0
0
313