A new phishing kit called CoGUI is allegedly responsible for sending over 580 million malicious emails between January and April 2025, with the aim of stealing login details and payment information from unsuspecting victims.

These scams appeared as official communications from well-known companies such as Amazon, Rakuten, PayPal, Apple, as well as tax authorities and banking organizations, in order to convince recipients to reveal sensitive data.
In January 2025, 170 malicious campaigns were detected, sending a total of over 172 million misleading messages (although intense activity continued in the following months).
See also: MintsLoader distributes GhostWeaver via Phishing, ClickFix
Experts at Proofpoint, who spotted the CoGUI campaigns, said it was the largest phishing operation they had seen so far. The main target appears to be Japan, with smaller-scale attacks also being reported in the US, Canada, Australia and New Zealand.
Although CoGUI activity appears to have begun in October 2024, Proofpoint analysts began monitoring it closely from December onwards.
Initially, there were indications of a connection to the Darcula phishing kit, which has been attributed to China-based groups. However, upon closer analysis, researchers ruled out a direct connection between the two tools, although both are used by Chinese threat networks.
How a CoGUI phishing kit attack works
The attack begins with a phishing email that appears to be an official communication from well-known companies. Typically, stressful subject lines and messages that urge the recipient to react immediately.
See also: Phishing campaign targets WooCommerce administrators
The messages contain a link that leads to a phishing websitehosted on the CoGUI infrastructure. However, this link is only activated if the recipient meets certain criteria set in advance by the attackers. These filters include factors such as geographic location (via IP), browser language, operating system, screen resolution , and device type (mobile or desktop).
If the victim does not meet the criteria, they are automatically transferred to the real website of the company that "imitated" the original message, in order to avoid raising suspicions.
Instead, “qualified” targets are taken to a fake login page, which is designed to look exactly like the real thing. The goal is to steal credentials and other sensitive information.

Analysts believe that CoGUI serves multiple threat actors, primarily originating in China, with a primary target in Japan. However, it is possible that the tool could fall into the hands of other cybercriminals, thus expanding the scope of attacks to more countries.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
To avoid such attacks, experts recommend that users avoid impulsive reactions to messages that request immediate action, and visit the official website of each service directly instead of clicking on links contained in emails.
See also: New phishing emails mimic Google to steal credentials
Next, they should regularly update their software, including the operating system and applications. These updates often include security that can protect the user from the latest threats.
Using reliable security software, such as an antivirus or security app, can help protect against attacks. These tools can identify and block suspicious websites or messages that are trying to steal user information.
It is also essential to use strong and unique passwords for all online accountsto make it more difficult for attackers to access your information. An additional layer of protection is two-factor authentication.
Source: www.bleepingcomputer.com
