Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Tykit

179
Global rank
188 infographic chevron month
Month rank
185 infographic chevron week
Week rank
0
IOCs

Tykit is a sophisticated phishing-as-a-service (PhaaS) kit that emerged in May 2025, designed to steal Microsoft 365 corporate credentials through an innovative attack vector: malicious SVG files.

Phishingkit
Type
Unknown
Origin
1 April, 2025
First seen
4 May, 2026
Last seen

How to analyze Tykit with ANY.RUN

Type
Unknown
Origin
1 April, 2025
First seen
4 May, 2026
Last seen

IOCs

IP addresses
104.18.22.222
142.251.20.95
188.114.96.3
150.171.109.193
74.178.76.128
20.73.194.208
91.81.129.181
150.171.27.11
151.101.66.137
35.190.80.1
48.192.1.65
88.221.169.152
150.171.109.101
150.171.28.11
51.124.78.146
2.16.241.214
142.250.154.132
172.211.123.250
142.250.154.101
3.124.33.45
Hashes
db39694c444ea393569aafb2cd8ec865006f3df9ecbcb7996e7b219b30ec366d
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
b361f6c67514f642c8529e98e7740eca954f3883c474567c3aa650d9549179c4
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
3dbd2c90050b652d63656481c3e5871c52261575292db77d4ea63419f187a55b
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
Domains
edge.microsoft.com
xpaywalletcdn.azureedge.net
shrisuryadevelopers.com
code.jquery.com
www.bing.com
self.events.data.microsoft.com
www.microsoft.com
crl.microsoft.com
slscr.update.microsoft.com
api.edgeoffer.microsoft.com
static.edge.microsoftapp.net
www.googleapis.com
linklock.titanhq.com
clients2.googleusercontent.com
config.edge.skype.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
client.wns.windows.com
fe3cr.delivery.mp.microsoft.com
fonts.googleapis.com
fonts.gstatic.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:vrjxnj12ixvbtyg0ilu25hpqxqhr0azxptlhfnkltxc&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1777883728&lafgdate=0
https://linklock.titanhq.com/analyse?url=https%3a%2f%2furl-shield.securence.com%2f%3fp%3d1.1%26r%3doramirez%2540ymflawllp.com%26sid%3d1776715204226-090-00147315%26s%3drmwvrhr6%26n%3dbtwwhvc4e%26ms%3d3.6%252c3.6%252c0.0%252c0.0%26u%3dhttps%253a%252f%252fshrisuryadevelopers.com%252fdocx%252findex.html&data=ejxlke1ugzaqhu9ddibjgyelfqhrvknbxodyk9qqf-gyqujpo05udvfpndnp75m1z2qq4tjvreyz7pv6oadna0yimv5t-khu9ac_7k-nr_c4juotyuma1iq2palogdjwejbpywpeytcqno53sv6_sw5mwezuilhgz6ovxzmmbaerbgpfcaoymf1xngtxqqu64bjpizh5i_bd8lzhu7-6axnuftiywz3hrpouhlogc1myiyszq5to1g1gcec_3dcgjblixpztmzfvagmffvgr1fkx38kq9jflsstzft7mbg3oqc0z-owv90nddvycadpzlpj0vpfhyooge2uw734a5knywq%%
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1777883728&lafgdate=0
https://url-shield.securence.com/?p=1.1&r=oramirez%40ymflawllp.com&sid=1776715204226-090-00147315&s=rmwvrhr6&n=btwwhvc4e&ms=3.6%2c3.6%2c0.0%2c0.0&u=https%3a%2f%2fshrisuryadevelopers.com%2fdocx%2findex.html
https://shrisuryadevelopers.com/docx/index.html
https://globalmuscolightingoreckcorporation.alertalarmxuucompany.vu/$philipf@truenorthloghomes.com
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://globalmuscolightingoreckcorporation.alertalarmxuucompany.vu/$philipf@truenorthloghomes.com?email_from_url=philipf%40truenorthloghomes.com&id=a9aff&sid=acf9597dab7ed82240ffdd2813e8e3e7&r=9f45e4e29a5d8f48&t=1777883731&g=d1&vrs=3.9.1&token=cc2651ff6bf5b8c56fd8605532e5e068
https://globalmuscolightingoreckcorporation.alertalarmxuucompany.vu/67489438847395431111566850?t=eyjpcci6ijnjmmmwodg0zgu4ngixmjeymjblnjg0ytbiy2zjytdmmjk0mmy0oge5nza1ywy0odu2mda4ogrmywi1mzfmztkilcj1ysi6imi5mmmwmgniywu3nzy2mzllyji0mtc3nta4zdk3ytflytljzjfiztfjyjbkymfiognhmwnjowqwzwi2n2fmyjmilcjlehaioje3nzc4odqwmzisimltzyi6m30.62c8266b40a58e12d218d6691e83ed28d0bae94658daeaf7e1e5887149bdc6e9
https://globalmuscolightingoreckcorporation.alertalarmxuucompany.vu/favicon.ico
https://fonts.googleapis.com/css2?family=inter:wght@300;400;500;600;700&display=swap
https://fonts.gstatic.com/s/inter/v20/ucc73fwrk3iltehus_nvmrmxcp50sjia1zl7.woff2
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://a.nel.cloudflare.com/report/v4?s=qcu5bf%2blotm8lozoh2sai7tzthkw64cnhg%2fbagc%2fgym62qmhbqrzc888o%2f%2brd%2bgh%2fosn0tusfjucsrxruwzkjm6ig8ktj8byusjragp%2bizw9hckjbgvwosxddry%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
Last Seen at

Recent blog posts

post image
Hunt Malware & Phishing Threats with ANY....
watchers 807
comments 0
post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 5840
comments 0
post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 12585
comments 0

Tykit Unmasked: How the SVG Phishing Kit Hijacks Microsoft 365 Logins

Key Takeaways

  1. Tykit is a phishing kit (not a binary malware) that abuses SVG attachments to stealthily redirect victims to fake Microsoft 365 login pages.
  2. It uses multi-stage redirection, obfuscated JavaScript, and Cloudflare Turnstile CAPTCHA to evade detection.
  3. The principal threat is credential theft, which can lead to serious downstream compromise (email, data, lateral movement).
  4. Known IOCs include hashes and “segy” domains used in exfiltration logic.

Use ANY.RUN’s Threat Intelligence Lookup to search by domain patterns, explore Tykit samples, gather additional IOCs for detection.

domainName:"segy*".

Domains linked to Tykit campaigns found via TI Lookup Domains linked to Tykit campaigns found via TI Lookup

  1. Detection requires combining email/attachment filtering, network monitoring, behavioral telemetry, and threat intelligence.
  2. Prevention hinges on enforcing strong MFA / zero trust, limiting privileges, and sanitizing risky attachments.
  3. Use TI Lookup to pivot from one Tykit artifact to hundreds of related connection points, and use ANY.RUN’s Interactive Sandbox to visualize its redirection chain and extract behavioral indicators.

View a Tykit analysis session in the sandbox:

Tykit sample in the Sandbox Tykit sample detonated in the ANY.RUN Sandbox

What is Tykit Malware?

Tykit emerges in 2025 as a phishing kit that departs from simpler credential-stealers by embedding JavaScript inside SVG image files. These SVGs act as stealthy “redirectors” or “trampolines” rather than being seen as overt phishing HTML pages.

Once the victim interacts (for example, being prompted to “enter the last 4 digits of your phone number” within the SVG), the flow proceeds through a trampoline script or intermediate redirect, then to a phishing page (often imitating Microsoft 365).

The phishing landing page typically contains a Cloudflare Turnstile anti-bot / CAPTCHA widget to block automated scanners or bots, then shows a fake Microsoft login portal. After credential submission, JSON-style API calls are made to attacker-controlled domains (often containing “segy” strings) to validate or exfiltrate data.

Researchers have observed that many samples share nearly identical code structure, obfuscation, domain naming patterns, redirect logic, and C2 endpoints. This suggests a templated (or service) model rather than one-off bespoke campaigns.

The first recorded sightings in ANY.RUN’s sandbox traces date to May 2025, with campaign activity peaking in September – October 2025. Tykit has been identified targeting organizations across various sectors globally (US, Canada, EMEA, Southeast Asia) and particularly in industries that rely heavily on Microsoft 365 and corporate email: finance, government, IT, construction, professional services, telecommunications, real estate, education, etc.

Because the core mechanism is phishing / credential capture (rather than remote code execution, file encryption, etc.), it is often classified in reports as a phishing kit rather than a “malware” in the classic sense. But its sophistication, multi-stage execution, use of obfuscation and anti-detection controls, and templated reuse give it traits worth analyzing like malware

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Tykit Malware Victimology

Tykit primarily preys on corporate users in sectors handling sensitive data, with finance and construction leading the pack due to their reliance on Microsoft 365 for financial transactions and project management.

Other targeted industries include IT, professional services, government, and telecommunications, where quick access to cloud resources is critical.

Geographically, North American companies, particularly in the US and Canada, face the brunt, followed by European entities in the EMEA region and Southeast Asian firms.

Victims are often mid-to-large organizations with distributed workforces, making them vulnerable to phishing via email attachments disguised as invoices or diagrams—common lures in construction and finance.

The kit's global reach shows no favoritism toward small businesses; instead, it exploits the ubiquity of Microsoft 365, affecting over 15,000 organizations tracked in related threat reports.

How Tykit Functions

Tykit employs a multi-stage attack architecture designed to evade detection while maximizing credential harvesting efficiency.

Stage 1: Initial Delivery via SVG

The attack begins with an SVG file, typically delivered through phishing emails as an attachment or embedded link. SVG files are XML-based vector image formats that can contain embedded scripts. Tykit exploits this by hiding JavaScript code within the SVG structure.

The malicious code uses XOR encoding and reconstruction techniques to rebuild the payload, which then executes via the dangerous eval() function. This approach bypasses many email security gateways that don't deeply inspect SVG contents, treating them as simple image files.

Stage 2: Trampoline Redirection

When the victim opens the SVG file in their browser, the embedded JavaScript executes automatically, redirecting them to a "trampoline" page (an intermediate server that performs additional checks and forwards the victim to the main phishing infrastructure).

The trampoline typically includes a fake verification step, such as prompting victims to "enter the last 4 digits of your phone number" (though any input is accepted). This creates a false sense of security and legitimacy while collecting additional targeting data.

The victim's email address is encoded in Base64 and passed as a URL parameter (e.g., ?s=[base64-encoded-email]), allowing the phishing page to personalize the attack.

Stage 3: Anti-Bot Protection

The victim is then presented with a Cloudflare Turnstile CAPTCHA, which serves dual purposes:

  • Blocks automated analysis tools and security crawlers
  • Adds perceived legitimacy to the attack

The phishing page also implements basic anti-debugging techniques:

  • Blocking browser developer tools (F12, Ctrl+Shift+I)
  • Disabling right-click context menus
  • Detecting and blocking common analysis tools

Stage 4: Phishing Page Presentation

After passing the CAPTCHA, victims reach a convincing Microsoft 365 login page that closely mimics the legitimate interface, including:

  • Authentic-looking Microsoft branding and logos
  • Proper color schemes and layouts
  • Real-time email validation
  • Progressive authentication flows matching genuine Microsoft login experiences

Stage 5: Credential Exfiltration via API Calls

When victims enter their credentials, obfuscated JavaScript captures the data and transmits it through a series of API calls to the attacker's C2 servers:

  1. POST to /api/validate: Validates the submitted email address and determines next steps

  2. POST to /api/login: Exfiltrates credentials, including email addresses, passwords, expired JWT tokens (for authenticity), session data.

  3. POST to /x.php: Secondary logging endpoint for debugging or additional data collection.

The server response dictates the victim's experience:

  • Success: Displays benign HTML to mask the theft, often redirecting to legitimate Microsoft pages
  • Error: Shows "incorrect password" messages, encouraging re-entry
  • Info status: Triggers additional logging

This multi-request architecture allows attackers to validate credentials in real-time, immediately identifying high-value accounts and potentially bypassing MFA through AitM techniques.

Evasion / anti-detection measures observed:

  • Obfuscation and dynamic reconstruction of JavaScript (XOR, string splitting) to hinder static detection.
  • Use of SVG as a vector (less commonly flagged) rather than pure HTML or script attachments.
  • Use of Cloudflare Turnstile as anti-bot mechanism to block automated crawling or security scanners.
  • Reuse of common templates / code means defenders can cluster via pivoting and identify variants.

To sum up: Tykit’s functionality is not a binary dropper or red team tool, but a cleverly engineered front-end phishing kit with multiple stages, obfuscation, anti-bot measures, and template reuse.

Analysis of a Typical Tykit Phishing Attack Flow

SOC teams can quickly identify Tykit attacks using ANY.RUN’s Interactive Sandbox, which provides a fast, safe, virtual environment for hands-on analysis of malware and phishing.

Check out sandbox analysis of Tykit

Initial Delivery: Common Vectors

Tykit kill chain A common kill chain of a Tykit attack

Tykit phishing attacks tend to start with SVG images that redirect the browser to a fraudulent page. These files typically feature deceptive prompts, such as a "check stub" asking users to input seemingly harmless information, like the last four digits of a phone number, though any input is usually accepted to proceed.

Tykit fake prompt Fake prompt asking the user to enter phone digits

Trampoline and CAPTCHA Stage

After the initial interaction, the page redirects to a trampoline script, which then forwards the victim to the main phishing site. The URL often includes encoded parameters, such as the victim’s email in Base64 format.

The next step usually involves a CAPTCHA page, often using Cloudflare Turnstile or similar anti bot protections. These pages may also incorporate basic anti debugging techniques, like blocking DevTools access or disabling the context menu, to hinder analysis.

Tykit CAPTCHA page Tykit uses anti-bot protection on the phishing page using Cloudflare Turnstile

Credential Capture and C2 Communication

Once the CAPTCHA is bypassed, victims encounter a spoofed login page, commonly mimicking trusted services like Microsoft 365. Simultaneously, a background request is sent to the command and control (C2) server, typically at an endpoint like /api/validate. This request includes a session or license key, a redirect URL, and the victim’s decoded email. The C2 server responds with instructions for the next stage, often embedded in HTML, along with a status update.

Password Exfiltration and Final Actions

The final stage usually presents a password entry form. Obfuscated JavaScript embedded in the page handles the exfiltration of stolen credentials to the C2 server, often via a POST request to an endpoint like /api/login. This request typically includes the victim’s email, password, an authorization token (sometimes expired), and other metadata.

Tykit Suricata rule ANY.RUN's Interactive Sandbox automatically detects Tykit attacks

The server’s response dictates subsequent actions, such as rendering additional HTML, triggering debugging processes, or displaying fake error messages to maintain the illusion of legitimacy.

How Tykit malware threatens businesses and organizations

Although the toolkit itself is not destructive, its threat to organizations is serious because:

Credential compromise leads to further attacks

  • Once attackers gain valid credentials, they can access email, OneDrive, SharePoint, Teams, and other Microsoft 365 services — exposing sensitive data, internal communications, intellectual property, and business information.
  • Attackers can use compromised accounts to send phishing emails internally (“business email compromise” / BEC), impersonate executives, or pivot to other accounts.
  • Attackers may use credentialed access to escalate privileges, move laterally, access endpoint management tools, perform privilege escalation, or deploy ransomware / malware later.
  • The credential compromise could cause regulatory exposure (e.g. GDPR in Europe), reputational damage, financial loss from fraud, and erosion of trust.

Evasion and persistence

  • Because the phishing kit uses multi-layer redirections and anti-bot (Turnstile) logic, it may evade automated defenses and static detection.
  • Shared “segy” infrastructure means that once one campaign is known, many related ones can be identified — but until that pivoting is done, many go undetected.

Scale and reuse

  • As a phishing-as-a-service template, Tykit can be reused by multiple threat actors, increasing the number of campaigns and victim exposures.
  • The modular nature allows attackers to customize landing pages, redirect logic, and domain naming to evade blocking.

Indirect risks

  • Exfiltrated credentials can be sold or traded on underground forums.
  • The malicious infrastructure and overlapping campaign infrastructure may help attackers orchestrate broader phishing or even inject malware.
  • Trust in the organization’s security posture can be undermined.

Thus, Tykit's danger is its role as a stepping stone: the initial breach vector that enables far more serious intrusions.

Gathering Threat Intelligence on Tykit Malware

Detection of Tykit is challenging because it is a phishing kit (not a file-based payload). But TI solutions like ANY.RUN’s Threat Intelligence Lookup help with connecting indicators of compromise to the phishkit’s activities and mining additional IOCs.

TI helps map the evolution of Tykit (new domains, variant payloads, new redirect patterns), enabling defenders to anticipate new waves or clusters.

Start exploring the threat by looking it up by the name:

threatName:"tykit"

Tykit samples submitted to the Sandbox Tykit samples submitted to the Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Tykit is a rising phishing kit threat that leverages SVG attachments, multi-stage redirects, and obfuscation logic to steal Microsoft 365 credentials. Though it doesn’t drop malware on endpoints itself, its consequences can be severe, enabling email compromise, lateral movement, and further attacks.

Because of its phishing-based nature, the most effective defenses lie in preventative controls (MFA, conditional access, email filtering), behavioral detection, and threat intelligence to rapidly identify new variants.

Sandboxes like ANY.RUN help uncover Tykit’s execution logic and support pivoting, while TI feeds help defenders block known infrastructure and hunt unknown variants. Together, these solutions and strategies form a layered defense against credential-harvesting kits like Tykit.

Start gathering actionable threat intelligence on Tykit by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

Kamasers screenshot
Kamasers
kamasers
Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.
Read More
Kratos screenshot
Kratos
kratos
Kratos is a mature Phishing-as-a-Service (PhaaS) platform that evolved from the Sneaky2FA kit to specialize in stealing Microsoft 365 credentials through sophisticated Adversary-in-the-Middle (AiTM) techniques. The service provides low-skilled affiliates with a turnkey solution featuring an advanced administrative dashboard, integrated anti-bot defenses, and real-time data exfiltration via the Telegram Bot API. Although an international law enforcement action known as Operation Olympus Blade disrupted its central infrastructure in July 2026, the kit remains a primary example of the industrialization of modern cybercrime.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
VanHelsing Ransomware screenshot
VanHelsing is a sophisticated ransomware strain that appeared in early 2025, operating via the Ransomware-as-a-Service (RaaS) model and targeting primarily USA and France. It threatens mostly Windows systems but has variants for Linux, BSD, ARM, and ESXi, making it a multi-platform malware. It is also notable for its advanced evasion techniques, double extortion tactics, and rapid evolution.
Read More
Ransomware screenshot
Ransomware
ransomware
Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.
Read More
UpCrypter screenshot
UpCrypter
upcrypter
UpCrypter is a sophisticated malware loader that functions as a delivery mechanism for remote access tools. Distributed through global phishing campaigns targeting Windows systems, this actively maintained tool serves as the central framework for deploying various RATs including PureHVNC, DCRat, and Babylon RAT, enabling attackers to establish persistent remote control over compromised systems.
Read More