Spiderman phishing kit targeting European banks and crypto services
Malware Activity
Summary
Hide ▲
Show ▼
The Spiderman phishing kit is being used against customers of European banks and crypto services, driving credential theft and account takeover risk. It clones legitimate sites and captures login credentials, 2FA/PhotoTAN/OTP codes, and credit card data. Its modular targeting controls make it easy for operators to adapt to new brands and authentication flows.
Related Happenings
KU Leuven DistriNet crypto wallet browser-extension privacy leaks and cross-site tracking
Technical Analysis
H score24
First: 14.07.2026 14:55
Last: 14.07.2026 14:55
Sources 1
About this happening:
KU Leuven DistriNet published technical findings on 85 crypto wallet browser extensions that leak enough data to link addresses and track users across sites, creating iden...
KU Leuven DistriNet crypto wallet browser-extension privacy leaks and cross-site tracking
Technical AnalysisAbout this happening: KU Leuven DistriNet published technical findings on 85 crypto wallet browser extensions that leak enough data to link addresses and track users across sites, creating iden...
Coruna iOS exploit kit used for crypto-theft payloads
Malware Activity
H score33
First: 04.03.2026 21:06
Last: 04.03.2026 21:06
Sources 1
About this happening:
The Coruna exploit kit is being used in active attacks, giving operators 23 iOS exploits and five exploit chains that reach iOS 13.0 through 17.2.1. The kit can delive...
Coruna iOS exploit kit used for crypto-theft payloads
Malware ActivityAbout this happening: The Coruna exploit kit is being used in active attacks, giving operators 23 iOS exploits and five exploit chains that reach iOS 13.0 through 17.2.1. The kit can delive...
Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service
Threat Actor Meta
H score36
First: 19.02.2026 14:00
Last: 19.02.2026 14:00
Sources 1
About this happening:
The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...
Starkiller dark-web phishing platform scales credential theft as a SaaS-style criminal service
Threat Actor MetaAbout this happening: The Starkiller phishing platform has emerged as a SaaS-style criminal service, raising the scale and durability of credential theft operations. It is sold on the dark we...
Stanley MaaS markets malicious Chrome-extension phishing service
Threat Actor Meta
H score47
First: 27.01.2026 01:46
Last: 27.01.2026 01:46
Sources 1
About this happening:
Stanley is a malware-as-a-service (MaaS) platform for malicious Chrome extensions that helps operators deliver phishing pages through the browser while keeping the...
Stanley MaaS markets malicious Chrome-extension phishing service
Threat Actor MetaAbout this happening: Stanley is a malware-as-a-service (MaaS) platform for malicious Chrome extensions that helps operators deliver phishing pages through the browser while keeping the...
BlackForce, GhostFrame, InboxPrime AI, and Spiderman phishing kits scaling credential theft
Malware Activity
H score36
First: 12.12.2025 16:04
Last: 12.12.2025 16:04
Sources 1
About this happening:
BlackForce, GhostFrame, InboxPrime AI, and Spiderman are newly documented phishing kits that expand credential theft at scale and make it easier to bypass MF...
BlackForce, GhostFrame, InboxPrime AI, and Spiderman phishing kits scaling credential theft
Malware ActivityAbout this happening: BlackForce, GhostFrame, InboxPrime AI, and Spiderman are newly documented phishing kits that expand credential theft at scale and make it easier to bypass MF...
Timeline
-
10.12.2025 16:53 2 articles · 7mo ago
Spiderman phishing kit targets European banks and crypto services
Initial DisclosureVaronis analyzed the Spiderman phishing-as-a-service kit, which uses pixel-perfect replicas of legitimate sites to target customers of European banks and cryptocurrency services. The kit can capture login credentials, 2FA/PhotoTAN/OTP codes, credit card data, and seed phrases for Ledger, Metamask, and Exodus wallets, while operators can view victim sessions in real time, export data with one click, and narrow targeting by country, ISP, and device type. One Signal group associated with the kit reportedly counted 750 members.
Show sources
- New Spiderman phishing service targets dozens of European banks — www.bleepingcomputer.com — 10.12.2025 16:53
- New Spiderman phishing service targets dozens of European banks — www.bleepingcomputer.com — 10.12.2025 16:53