Known malicious kithighphishing

Prove / small-financial-brand phishing framework (panelFronts devtools-trap kit)

family: prove-financial-framework-202608

Shared phishing framework documented by urlscan 2026-08-04, deployed against deliberately LOW-PROFILE financial and identity brands rather than megabrands: Prove (identity verification), US Bank SinglePoint, AMINA E-Banking, Currency Cloud, Pleo, Slim CD, PayMongo, Aspire. Cloudflare-fronted, several hosts sharing a nameserver pair. Anchored on the kit-unique global __panelFrontsDevtoolsTrapStarted__ (a devtools-detection-trap guard) — a framework identifier coded into the kit logic, so it survives host rotation and minification, unlike IP/domain/hash IoCs.

Anchors

YARA ruleProve_Financial_Phishing_Framework
SMQL queryrun
js_library:socket.io AND (title:"currencycloud" OR title:"paymongo" OR title:"slim cd" OR title:"amina bank" OR title:"singlepoint" OR title:"prove identity")

Provenance

Added: 2026-08-07 13:12
YARA rule is the primary anchor and is FP-validated at scale: the marker (plus hex/unicode/URL/fromCharCode/base64-x3 encodings) matched 0 of 663,031 JS objects + 107,260 HTML captures across all 58,016 scans from 2026-07-01 to 08-06. TRUE-POSITIVE COVERAGE UNVALIDATED — we have never captured this framework, so the rule has never matched a real sample; if the first live hit shows a renamed global, re-anchor on that sample rather than loosening the rule. SMQL half approximates urlscan second pivot (bundled socket.io + a targeted brand in title) because the socket.io file hash itself was withheld from the public report; it is verdict-inert by design (smql-tier sightings are excluded from get_kit_sightings). 7 filter nodes, under the 20-node cron cap.

Sightings (0)

No sightings recorded yet.