Threats Tagged 'tykit'
View all threats tagged with 'tykit'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'tykit'
Click on any threat for detailed analysis and mitigation recommendations
In October 2025, a wave of sophisticated cyber attacks targeted corporate environments, leveraging phishing campaigns exploiting trusted platforms like Google Careers and ClickUp, abusing Figma for credential theft, and deploying the LockBit 5.0 ransomware variant against ESXi and Linux systems. Attackers used legitimate cloud services and multi-stage redirection to evade detection, while a new phishing kit named TyKit emerged. These campaigns threaten corporate credentials, infrastructure integrity, and data confidentiality across multiple sectors. The attacks do not require known exploits in the wild but rely heavily on social engineering and abuse of trusted platforms. Security operations centers (SOCs) must enhance detection capabilities, harden access controls, and employ advanced threat intelligence to mitigate these evolving threats. The overall severity is medium, reflecting the complexity and multi-vector nature of the attacks but without widespread exploitation of zero-day vulnerabilities. European organizations, especially those using affected platforms and cloud services, face significant risks from credential theft and ransomware infection. Join the discussion | AlienVault OTX General | 10/29/2025, 18:37:27 UTC Added: 10/29/2025, 20:13:19 UTC |
Tykit is a newly identified phishing kit targeting Microsoft 365 accounts, active since May 2025. It uses SVG files as delivery vectors and a multi-stage attack chain to mimic Microsoft login pages and steal credentials. The kit employs evasion techniques including Cloudflare Turnstile anti-bot protection and basic anti-debugging measures. It primarily targets industries such as finance, construction, IT, professional services, government, and telecom, with victims globally including the EMEA region. Stolen credentials are exfiltrated via API calls to attacker-controlled servers. The campaign requires user interaction through phishing but does not require prior authentication. This threat poses a medium severity risk due to its potential impact on confidentiality and the widespread use of Microsoft 365 in Europe. Join the discussion | AlienVault OTX General | 10/21/2025, 21:49:29 UTC Added: 10/22/2025, 08:03:32 UTC |
Showing 1 to 2 of 2 results