European News Update
SEE OTHER BRANDS

The top news stories from Europe

ANY.RUN Exposed Tykit: New Phishing Kit Targeting Microsoft 365 Accounts Across Multiple Sectors

DUBAI, DUBAI, UNITED ARAB EMIRATES, October 21, 2025 /EINPresswire.com/ -- ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, has uncovered Tykit; a new phishing kit responsible for stealing hundreds of Microsoft 365 credentials from companies across North America and Europe. Targeting mainly the finance and construction sectors, Tykit uses SVG-based payloads and a multi-stage credential theft process, pointing to a growing phishing-as-a-service model now spreading across global campaigns.

๐‡๐จ๐ฐ ๐ญ๐ก๐ž ๐€๐ญ๐ญ๐š๐œ๐ค ๐–๐จ๐ซ๐ค๐ฌ

ANY.RUN observed around 180 related submissions, confirming that Tykit operates as a reusable phishing kit active across multiple attacks.

๐—ง๐—ฒ๐—ฐ๐—ต๐—ป๐—ถ๐—ฐ๐—ฎ๐—น ๐—ข๐˜ƒ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฒ๐˜„ ๐—ผ๐—ณ ๐—ง๐˜†๐—ธ๐—ถ๐˜:

๐——๐—ฒ๐—น๐—ถ๐˜ƒ๐—ฒ๐—ฟ๐˜†: SVG files act as the initial payload, embedding JavaScript to trigger redirects.

๐—˜๐˜…๐—ฒ๐—ฐ๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐—ฐ๐—ต๐—ฎ๐—ถ๐—ป: Victims pass through trampoline pages and CAPTCHA validation before reaching the phishing page.

๐—”๐—ป๐˜๐—ถ-๐—ฎ๐—ป๐—ฎ๐—น๐˜†๐˜€๐—ถ๐˜€: Pages use simple anti-debugging methods, such as blocking DevTools and disabling right-click.

๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐˜๐—ต๐—ฒ๐—ณ๐˜: The fake Microsoft 365 page captures login details and sends them to the attackerโ€™s server.

๐—œ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—ฟ๐—ฒ๐˜‚๐˜€๐—ฒ: Multiple samples share the same structure and behavior, confirming a templated phishing kit in circulation.

Read the full analysis, explore live sessions, collect IOCs and detection rules, and learn how to defend against Tykit attacks; all on the ANY.RUN blog.

๐€๐›๐จ๐ฎ๐ญ ๐€๐๐˜.๐‘๐”๐

ANY.RUN is a leading provider of interactive malware analysis and threat intelligence solutions trusted by over 500,000 cybersecurity professionals and 15,000+ organizations worldwide. The interactive sandbox enables teams to observe malware behavior in real time, extract indicators of compromise, and accelerate detection and response. Paired with Threat Intelligence Lookup and TI Feeds, ANY.RUN delivers actionable insights that help SOC teams, MSSPs, and researchers stay ahead of evolving threats.

The ANY.RUN team
ANYRUN FZCO
+1 657-366-5050
email us here
Visit us on social media:
LinkedIn
YouTube
X

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share us

on your social networks:
AGPs

Get the latest news on this topic.

SIGN UP FOR FREE TODAY

No Thanks

By signing to this email alert, you
agree to our Terms & Conditions